Bitcoin Forum
May 05, 2024, 06:04:45 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Are Ledger Nano seeds secure?  (Read 254 times)
Lionel (OP)
Sr. Member
****
Offline Offline

Activity: 613
Merit: 305


View Profile
February 18, 2019, 09:12:55 PM
 #1

Brainwallets are not secure,  at least if they have a relatively short seed , like 12 words.
What about Ledger ones that have 24 words?
1714932285
Hero Member
*
Offline Offline

Posts: 1714932285

View Profile Personal Message (Offline)

Ignore
1714932285
Reply with quote  #2

1714932285
Report to moderator
1714932285
Hero Member
*
Offline Offline

Posts: 1714932285

View Profile Personal Message (Offline)

Ignore
1714932285
Reply with quote  #2

1714932285
Report to moderator
There are several different types of Bitcoin clients. The most secure are full nodes like Bitcoin Core, but full nodes are more resource-heavy, and they must do a lengthy initial syncing process. As a result, lightweight clients with somewhat less security are commonly used.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714932285
Hero Member
*
Offline Offline

Posts: 1714932285

View Profile Personal Message (Offline)

Ignore
1714932285
Reply with quote  #2

1714932285
Report to moderator
1714932285
Hero Member
*
Offline Offline

Posts: 1714932285

View Profile Personal Message (Offline)

Ignore
1714932285
Reply with quote  #2

1714932285
Report to moderator
1714932285
Hero Member
*
Offline Offline

Posts: 1714932285

View Profile Personal Message (Offline)

Ignore
1714932285
Reply with quote  #2

1714932285
Report to moderator
TryNinja
Legendary
*
Offline Offline

Activity: 2828
Merit: 6977



View Profile WWW
February 18, 2019, 09:34:27 PM
 #2

What makes the brain wallets insecure isn't really the number of words. It's more about the fact that humans are bad at creating entropy. You may think your seed is "random" and "secure" enough, but it could be an easily brute-forced phrase.

Still, 24 words should be "safer" than 12 words.

there is 256 bits of input entropy for a 24-word seed, meaning that there are 2^256

possible 24-word seeds. This means that in order for the brute-forcer to have a 50% chance of finding your seed, they would need to check 2^256 ÷ 2 keys.

I did the math a while ago... The list is 2048 words. 2048^24 =

29,642,775,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000 (rounded because I'm lazy)

Best of luck figuring that one out..

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
gentlemand
Legendary
*
Offline Offline

Activity: 2590
Merit: 3013


Welt Am Draht


View Profile
February 18, 2019, 11:30:35 PM
 #3

I've never heard of one single case of a Ledger seed, or any properly generated seed, being guessed, other than people who buy them from Ebay with an official looking seed prefilled on a card ready to be swept by the seller as soon as it's loaded.
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5637


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
February 19, 2019, 05:50:46 PM
 #4

Lionel, you get answer from TryNinja regarding a possible hacking / guessing of 24 words for seed. But that's not all about security for Nano S seed, there is a option to add one more word to your seed, and this is called passphrase security. In that way you can further protect yours coins, even if someone get your seed they will need passphrase. For that reason is not good idea to save both in same place.

I think the weakest link in security of seed is the user himself.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
mk4
Legendary
*
Offline Offline

Activity: 2758
Merit: 3830


Paldo.io 🤖


View Profile
February 20, 2019, 02:01:10 AM
 #5

I think the weakest link in security of seed is the user himself.

This. The security of the seeds depends more on how you actually store your seed. If you store it offline on a piece of paper that's locked up somewhere(or digitally through a properly executed air-gapped device), then you're good. As opposed to storing your seed on a text file/word file/notes app/etc, then there's a good chance you're going to get screwed over in the future.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
February 20, 2019, 08:07:26 PM
Merited by bones261 (2), Lionel (2)
 #6

Brainwallets are not secure,  at least if they have a relatively short seed , like 12 words.
What about Ledger ones that have 24 words?
What a lot of people fail to grasp... is that the wallets that utilise seed mnemonics (aka 12/24 words), do not start by generating words.

They start by using a (pseudo) random number generator to create a very large random number... this large random number is then converted into words by following the BIP39 process. (Note that Electrum follows a slightly different method for converting to words, but the underlying theory is the same... large random number -> words).

This is completely opposite to a "brainwallet" where the words are chosen first... and the number is generated from the words. As was already stated, creating your own brainwallet words generally leads to very poor entropy because humans are terrible at creating "random" things.

So, by starting with a random number, then converting to words... you retain the "entropy" to safeguard your coins.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!