spacestr

🔔 This profile hasn't been claimed yet. If this is your Nostr profile, you can claim it.

Edit
Penlock
Member since: 2025-09-04
Penlock
Penlock 10d

Yes I know them well, they are a Penlock sponsor along with . But I don't think they'll want to do that because they are a selling that wallet as their main product. :)

Penlock
Penlock 10d

Only enter them into the wallet that will secure/spend the fund -- in this video I'm using Coconut wallet, it's an application to recycle an old phone into an airgap wallet: the phone is meant to stay in plane mode forever after that. To be clear, it is definitely be unsafe to enter your seed phrase into a third party application, and you shouldn't do so: this method works for any wallet, and you only need to enter the words in the wallet that'll secure the funds.

Penlock
Penlock 21d

Alright yes, I get your point and I admit my entropy calculation was naive. Essentially, the biases I measured would result in a much lower loss of entropy than I initially thought because they are obviously non-deterministic, which means everything is more secure than I initially thought. That being said, coins/dices can have significantly higher biases than you assume & I invite you to verify this by yourself (since ultimately, you can always default to doubting whatever I will say on Nostr). Try to compare good nice heavy coins with light ones or various shuffling method & you'll definitely find out that the theory is not meeting the practice. On the other hand, the wash shuffle is an excellent randomizer is used in casinos all around the world. So when it comes to ranking our options, I am pretty sure tiles would come first in any proper study.

Penlock
Penlock 21d

Not at all, I was only asking. And yes you can absolutely do this with dice and coins, in fact I have done so before; but I have discovered this trick on my own and I'm not aware of other methods doing so. About the dice comparison, I think tiles are more accessible and less prone to biases, which is why I picked this method at the end (it used to be coins). It is true that you need to print & cut the tiles, but you're going to need a printer for the wordlist anyway, so I like that it is not introducing any additional requirements. At the end, people will use what they have according to their preference, and since the biases I mentioned are not large enough to create exploitable security risks, it's more a matter of polishing & optimization.

Penlock
Penlock 21d

As a clarification, my bias figures are rough estimates of the worst-case scenario for coins, dice, and tiles under good shuffles/throws. Someone correctly pointed out that not every coin or die will be as bad; but it's also easy to underestimate biases because it's generally twice what you'd intuitively expect. (e.g., a 52/48 coin has a 4% bias and generates only ~96 bits of entropy over 100 throws.) The reason tiles (and cards alike) have a better safety profile is simple: low-quality coins/dice can be severely imbalanced, while the quality of a deck of tiles/cards has much less impact on the randomness of the draw. Moreover, the elements of a given deck are much easier to audit than the balance of a given coin or die. Now, to be clear, even a 20% bias would still result in an unbreakable 12-word seed phrase. You'd still have 102.4 bits of entropy, plus 11 additional bits of security from BIP39 key stretching. But my goal with Penlock was to identify and deliver the method that best combines UX and security, and I believe paper tiles are it.

Penlock
Penlock 21d

You pick a single block of 16 at random and iterate over the words in it, yes; that's how I solve it without relying on external tools, but maybe you don't call this solving then?

Penlock
Penlock 21d

Actually, the process itself takes less than 10 minutes, but since you need to learn, print and cut first it's going to be closer than 30. I don't think other processes let you avoid printing a wordlist, or then you're using a digital wordlist which might not be the most secure thing in the world especially if you have to scroll that thing back and forth to find your words.

Penlock
Penlock 21d

It *does* solve the checksum generation issue, from 5:00

Penlock
Penlock 22d

Hello Jimmy, we just released a video tutorial to generate a seed phrase by hand with Penlock, thought you might be interested. While this requires minimal printing, we also got a manufactured version now, available in multiple Bitcoin spaces and soon on Geyser.

Penlock
Penlock 22d

Here's the video guide ;)

Penlock
Penlock 21d

As a clarification, my bias figures are rough estimates of the worst-case scenario for coins, dice, and tiles under good shuffles/throws. Someone correctly pointed out that not every coin or die will be as bad; but it's also easy to underestimate biases because it's generally twice what you'd intuitively expect. (e.g., a 52/48 coin has a 4% bias and generates only ~96 bits of entropy over 100 throws.) The reason tiles (and cards alike) have a much better safety profile is simple: low-quality coins/dice can be severely imbalanced, while the quality of a deck of tiles/cards has much less impact on the randomness of the draw. Moreover, the elements of a given deck are much easier to audit than the balance of a given coin or die. Now, to be clear, even a 20% bias would still result in an unbreakable 12-word seed phrase. You'd still have 102.4 bits of entropy, plus 11 additional bits of security from BIP39 key stretching. But my goal with Penlock was to identify and deliver the method that best combines UX and security, and I believe paper tiles are it.

Penlock
Penlock 21d

I should have written "up to x%-x%", please read it that way; I lost that nuance while tightening the text and unfortunately I can't edit it now but I definitely found about 8% bias on coins that weren't the absolute worst in my own series of throws. That being said, I really invite you to try this method & I'm genuinely interested in your feedback about how long it took for you compared to others.

Penlock
Penlock 21d

I call bias the net loss of entropy, which is what we care about, and not the deviation from the mean. In that sense, 51/49 is already a 2% bias, out of a big fat coin that's nothing like what you have in your pocket. And no, it doesn't diminishes over turns: it's a whole 2% entropy loss on your final entropy: so you'd get 125,44 bits of entropy instead of 128. Now, to be clear, even a 20% bias would lead you to an unbreakable seed phrase -- so in that sense, maybe it can appear negligible. In any case, my goal with Penlock was to create a fail-proof process, and while my number are rough estimate I stand by paper tiles having the both a better safety and entropy profile.

Penlock
Penlock 21d

Well obviously it depends on the coins, and it seems you took the worst case scenario for the base case. Some countries have very light/unbalanced coins in smaller denominations and I believe 20% is a number I read in a published article on the worst case scenarios. My own research with not-so-great coins were not as bad but the bias was still significantly higher than with cards/tiles.

Welcome to Penlock spacestr profile!

About Me

Penlock is a tool to manually create a robust 2-of-3 backup of any seed phrase. It strengthens your self-custody setup, securing offsite recovery and inheritance without dependence on any third party.

Interests

  • No interests listed.

Videos

Music

My store is coming soon!

Friends