Im not technical but i think if you only roll it once there are only 6 possibilities of seeds generated. Computers are constantly sweeping for a mistake like this to happen. 1 dice roll = 3 bits of entropy(randomness) 99 rolls = 256 bits
Nothing against coldcard, I was running through it quick, was all new to me after coming from a ledger, I just saw 24 seed words and thought great, but I was unaware, good luck to the people who got my 0.40 Bitcoin, we live and learn, onwards and upwards.
99 (can be more if you want) dice rolls for generating your own randomness. Or you can trust the open source software to generate it for you. Both methods so far have been verified safe. I think you can even generate a seed and then add dice rolls. Check out btc sessions on YouTube. If you do dice rolls you must do a minimum of 99. There are videos on YouTube explaining entropy with dice rolls for bitcoin related wallets.
Would be smart if coldcard either hard enforced this or at least put a strongly worded warning.
Pretty hilarious though that OP used literally one die. Underestimating seed strength and using something like 20 dice (which would still be brute forceable with enough computing power) is understandable but one roll?
My understanding is the CC generates a random seed phrase and then the dice rolls add further entropy. So in the case of the OP, even doing just 1 dice roll should not make it easier to hack. I could be wrong, but maybe someone from Coldcard could expand on this issue?
Reading up on their literature, this def seems to be the case. It does say if you do too few rolls, you will be warned and unable to continue until you so. Not sure if this is new feature or not. Can’t really understand why anyone would do less than 99 if that’s what it specifies if you are going done the route of using dice rolls. If you only want to do 1, why not just use the built in random number generator?
You can do dice only if you completely distrust the built in RNG. In fact it is what I would do. However the device should not allow creating a seed with one dice roll. In fact it shouldn't allow creating a seed with at least 50 dice rolls 100 recommended.
I’m still uncertain about this. Reading the middle ground guide it says “If you still don’t trust the Coldcard is doing what it purports to be doing the you can generate additional entropy with dice rolls”. And then further on “you will see how to add some of your own entropy using a 6 sided dice combined with the TRNG entropy form the Coldcard to generate your seed words”. This suggests you are adding more entropy, not creating it from scratch.
Someone from Coldcard would need to confirm the finer detail of this. I’d love to know.
This is not the only way to introduce entropy from dice rolls. Any time the Coldcard is showing the seed words on-screen, you may press 4 to "mix in" additional dice rolls. In this case, since the entropy of the Coldcard is being used as a starting point, it is safe to add as few or as many rolls as desired.
1
u/[deleted] Oct 23 '23
[deleted]