Post coldcard fiasco, the new standard should be: hardware wallets never generate seed phrases from their own randomness, however sourced, but only accept user generated entropy.
Hardware wallet that generates its own 24 word seedphrase is a Red Flag.
Great Idea39.1%
Terrible Idea. 60.9%
23 votes \ 13h left
I think you're wading into best practices and generic advice rather than black and white nevers. The problem is that many people trusted their device to source sufficient entropy. Dice rolls don't solve that problem if there's a bug in how dice rolls are used. The problem is trusting without verifying - dice rolls or not.
but you still didn't vote terrible idea.
I don't think it's a terrible idea as a thing we encourage. It's also not a great idea for the reason I explained. Forgive my desire for nuance, but do this not that podcaster maxims are exactly how we got here.
Well said.
Learn to build your own cold storage free of reliance upon third party HW touts.
Its fucking easy and almost free- it just requires you gain some basic knowledge.
Knowledge that empowers you and builds your self sovereignty security...
https://electrum.readthedocs.io/en/latest/coldstorage.html
https://www.fosslinux.com/10212/how-to-install-a-complete-ubuntu-on-a-usb-flash-drive.htm
I bantered with the AIs about this a bit. The AIs gave the usual counterarguments.
One point I surfaced in support that I'd like to share.
(me to the AI)
reply from the clanky:
I gave it proper emphasis so the people in the back hear it too
Yes! This ^^
Even if you supply your own entropy to the hardware wallet, you still have to trust it to actually use your entropy.
Best way to know that your seed is truly random is to print out the word list, cut the words out and then randomly pick 11 words. The twelth word needs to be chosen with the help of the hardware wallet, since it contains a checksum.
I wouldn’t say the lesson is simply “hardware RNG bad, dice good.”
Both can fail in different ways. Combining device-generated randomness with enough properly collected dice entropy seems safer than trusting only one source.
I like what BitBox has on their website to guide folks through dice rolls/coin flip. It’s easy and takes no technical ability.
I’m all for rolling one’s own skew corrected entropy. If that or spending 20 hours learning about self custody best practices is a barrier to entry for someone than maybe that person isn’t ready to hold their own sats and that is okay.
I think that if we let a beginner generate their own entropy, there’s a good chance they’ll make mistakes, for example, always flipping a coin or rolling a die in the same way, or introducing other patterns into the process.
These seemingly small biases could reduce the randomness and result in entropy that isn’t generated correctly.
Another mistake is to NOT put the individual seed words back after you have drawn them!
I voted "Terrible idea".
My personal point of view is to use multisig with different vendors.
Though realistically since others I know don't share my views I have suggested singlesig with a hardware wallet which has a budget for security and certifications.
Although certifications can lead to skewed results, at least it shows work has been done to improve security.
Additionally I don't know reports of stolen funds with wallets generated with bitcoin-cli (besides I guess those kept as hot wallets, but I don't know what Luke Dashjr used)
I don't think its a good idea, for many people they want a secure way to store it - in a simple and easy way. Is that too much to ask for? haha
Lolz 🤣🤣🤣
#426148
that one aged well! 🤠
Bold of you to assume there was ever a standard. We have people in our ranks ready to convert multiple whole coins of BTC into SHIB because a YouTuber's donkey said Kazakhstan can't be trusted.
Alongside dice only I'm seeing a lot of "Use Bitcoin core client for seed generation" advice.
I always thought all (most) HWW we're using the same libraries to do it?
It's ok, only ok... 😅👍, but I think only dice entropy is not a good direction...
For example:
https://njump.me/nevent1qvzqqqqqqypzpyvps02e3t8jmj5qelqvm6j2pmjc3yj3w4ll836u2s20qpkknxh9qyfhwumn8ghj7mmxve3ksctfdch8qatz9uqzquwgh0x9nnlj5pjlyzpat76ccq2jtjp9tcnc4vahphlgc8wq2t8q03v3h6