spacestr

🔔 This profile hasn't been claimed yet. If this is your Nostr profile, you can claim it.

Edit
jimbocoin
Member since: 2023-04-03
jimbocoin
jimbocoin 14h

#Bitcoin #memestr

#bitcoin #memestr
jimbocoin
jimbocoin 1d

Listen, if you’re leaving ColdCard due to this issue and switching to Bitkey, just know that you haven’t changed your risk posture towards this class of issue. You’re still trusting someone else with your seed generation. #Bitcoin

#bitcoin
jimbocoin
jimbocoin 1d

PSA: I’m available for podcast appearances if anyone needs someone to explain of the problem, describe mitigations, or discuss entropy generation approaches. 🙏 #Bitcoin

#bitcoin
jimbocoin
jimbocoin 1d

Today in #Bitcoin

#bitcoin
jimbocoin
jimbocoin 8h

The sufficiency comes from the number of dice rolls. If you roll one die, you get 1, 2, 3, 4, 5, or 6. (6 options) If you roll two dice, you get 11, 12, 13, 14, 15, 16, 21, 22, 23, 24, 25, 26, 31, 32, 33, 34, 35, 36, 41, 42, 43, 44, 45, 46, 51, 52, 53, 54, 55, 56, 61, 62, 63, 64, 65, or 66. (6 x 6 = 36 options) If you roll three dice, you get 111, 112, 113, 114, …, 663, 664, 665 or 666. (6 x 6 x 6 = 216 options) And so on. Each dice you roll multiplies the total number of options by 6. So if you roll 100 dice, the number of options is 6^100 = 6.533×10⁷⁷ This is an unimaginably vast number. Vetting that the rolls produce the seed is secondary. The important point is that each roll multiplies the search space, and 100 is plenty.

jimbocoin
jimbocoin 1d

In Bitcoin, ownership is what you KNOW. You either know the keys and can move coins, or you don’t. So, how do you KNOW that nobody that you has your seed? The only way is to generate it yourself. If you trust ANYONE ELSE to generate your seed material, then you DON’T KNOW that no one else has it. Therefore, you MUST generate your OWN ENTROPY in order to KNOW that it’s safe. #Bitcoin

#bitcoin
jimbocoin
jimbocoin 1d

For people freaking out, here are a two relatively quick mitigations that don’t require any new hardware: 1. Using your existing ColdCard and seed, you can set up a passphrase. This acts like an entirely separate wallet on the same device. You can then sweep the coins to the passphrase sub-wallet. 2. Using your existing ColdCard and seed, set up a 2-of-2 wallet using that device and a software seed using Sparrow or Blue Wallet. Your attacker would have to both exploit the ColdCard vulnerability AND hack your software wallet to move those coins. Stay frosty out there. #Bitcoin

#bitcoin
jimbocoin
jimbocoin 1d

E N T R O P Y

jimbocoin
jimbocoin 1d

#Bitcoin #memestr

#bitcoin #memestr
jimbocoin
jimbocoin 1d

The point of the airgap is to reduce the likelihood your seed leaks during signing. The alternative is to plug the device into the machine (USB) or have it communicate over some other channel (BlueTooth, camera + QR codes). Airgapped with PSBT or QR is the least leaky available option. But again, the point is to protect the seed during signing. Not to generate seeds. Not to protect data at rest.

jimbocoin
jimbocoin 1d

Think of it this way: a single dice roll produces a number from 1-6. The information content of this is log2(6) = 2.585. That is, each roll produces about two and a half bits worth of entropy. A 12-word seed phrase encodes 128 bits of entropy. 128 / 2.585 = 49.516. So, yes, to generate a 12-word seed phrase, you need to combine the entropy from 50+ independent dice rolls. The same logic holds for a 24-word seed phrase which encodes 256 bits of entropy. For that you need the combined entropy of 100+ dice rolls. BUT the key factor here that most people miss is HOW those rolls are combined. Somehow, your sequence of dice rolls (5-4-5-2-1-…-6-6-4) has to be converted into words (bacon-celery-zoo-…). If that mechanism is the hardware wallet, then you’re STILL TRUSTING the device, albeit a different code path. How do you know that those rolls produce THAT seed? So yes, dice rolls are a big step up from just trusting the device’s random number generator. But you’re still vulnerable to other not-yet-discovered bugs in the hardware. To immunize yourself from ANY hardware bugs, you have to roll your own seed material OFFLINE.

jimbocoin
jimbocoin 1d

If you roll the dice and put them in the machine to produce your seed, you’re STILL TRUSTING THE DEVICE. How do you know that those dice rolls yield THAT seed? You’re out here thinking you’re paranoid using dice with a hardware wallet. I’m telling you, you are NOT PARANOID ENOUGH. #Bitcoin

#bitcoin
jimbocoin
jimbocoin 1d

He’s saying that knowing where the coin went won’t get it back.

jimbocoin
jimbocoin 1d

Multi-vendor multisig is even better. Any given provider may have a bug. Multiple independent vendors means you’re protected from any particular one.

jimbocoin
jimbocoin 1d

Possession may be 9/10 of the law. But it’s 10/10 of the #Bitcoin

#bitcoin
jimbocoin
jimbocoin 1d

When you generate your seeds, don’t just let the device produce it. You have to add your own entropy in some form. Many people use dice rolls. I use playing cards. Multi-vendor multisig is ideal. That way, if any particular vendor has a vulnerability (as in this case) your attacker still can’t move your coin.

jimbocoin
jimbocoin 1d

Great question. At some point, in order to use Bitcoin, you’re going to need a computer. Hardware wallets compute all the time. For example, they compute addresses from XPUBs. They compute XPUBs from seeds and so on. A BIP-39 checksum word contains bits from the SHA256 of the actual entropy payload. Calculating this SHA256 sum by hand is intractable. So, in my opinion, the hardware wallet SHOULD be wiling to generate a checksum word for you based on the incoming entropy. ColdCard will do this. I believe SeedSigner will as well. Last I checked, Sparrow WILL NOT do this for you. There are various other tools that may have this capability. But yeah, at the end of the day, you need multiple independent vendors to perform these kinds of calculations: - Generating the last word of a BIP39 seed phrase - Generating an XPUB from a seed phrase - Generating a master key fingerprint (XFP) from a seed phrase - Generating addresses from an XPUB Hardware wallets are powerful enough to do these things. Whether and how many is up to the vendor to implement.

jimbocoin
jimbocoin 1d

Well, I meant hypothetically 😅

jimbocoin
jimbocoin 1d

You can get out in front of these by messaging your friends and family first.

jimbocoin
jimbocoin 1d

Plenty of months left in the year 🤝

Welcome to jimbocoin spacestr profile!

About Me

The SUPERCYCLE guy.

Interests

  • No interests listed.

Videos

Music

My store is coming soon!

Friends