pull down to refresh

For myself, I am realizing I need to get much more serious about using the tools to check on the tools I use.

It can be a dayjob so be careful what you wish for.

More important: what made some coldcard users secure despite using the vulnerable hardware?

Adding other layers of security.

Yes, and perhaps time is better spent trying to remove single points of failure.

But it smarts a little when such a famous and "reputable" product had such a glaring problem...and none of us were able to say, wait a minute...

reply
Adding other layers of security.

I'd suggest: doing the dice rolls. That's truly what helped. Multisig only buys time.

reply
126 sats \ 1 reply \ @Scoresby 1 Aug
multisig only buys time

...if you only used one hardware vendor...which, to be fair, most of us do.

Sure dice rolls, but aren't I still trusting the hardware wallet not to screw up turning my dice roll entries into a key?

Maybe instead of adding layers, I should have said spread out your trust.

Go through your setup and ask: if this part is pwnd what happens? Hopefully the answer is: you have time to get to safety.

reply
but aren't I still trusting the hardware wallet not to screw up turning my dice roll entries into a key?

No you're not because you don't trust, you verify. Thursday night when someone here asked me about that I opened the code and ran through it (as in besides code glaring, stub it and execute) end-to-end, to be absolutely sure I wouldn't give the wrong answer. That was for someone else. They should have done that themselves imho, but I try to be nice and do the effort, even for a stacker that I extremely dislike, which was the case.

Go through your setup and ask: if this part is pwnd what happens?

That is the way. Also: what do I do when unlikely event xyz happens anyway. Like... some crazy RNG integration error.

reply

ok what if you did the dice rolls to the keys in the multisig?

reply

then the dice rolls protect you while the multisig doesn't have direct additional value (in the case of both vulns from last week)

reply

if you create a seed with 100+ rolls of a dice, does it matter what software or hardware wallet that you use to interact with it?

reply

Of course. Weaknesses other than that of entropy need to be defended against too.

Wasn't there this shitcoiner HWW that logged all seeds to their server? Tangent I think?

reply