Bitcoin Forum
September 22, 2026, 03:52:35 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 [5]  All
  Print  
Author Topic: Seed Generation in Hardware Wallets  (Read 1358 times)
dkbit98 (OP)
Legendary
*
Offline

Activity: 3094
Merit: 8872



View Profile WWW
September 04, 2026, 07:20:25 PM
 #81

There is one interesting new webiste that can be used for offline air-gapped devices only.
We had something similar in the past with Ian Coleman website, but in EntropyLab there are also dice, cards and other options included.
Everything is released as open source, and it is created by OogaBoogaX developer, but please READ carefully, and use at your own risk,
Note that this is early testing phase, and you should NOT use it as your main setup!


https://entropylab.online/
https://github.com/OogaBoogaX/entropylab

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
Forsyth Jones
Legendary
*
Offline

Activity: 2030
Merit: 2269


I love Bitcoin!


View Profile WWW
September 04, 2026, 07:47:39 PM
 #82

There is one interesting new webiste that can be used for offline air-gapped devices only.
We had something similar in the past with Ian Coleman website, but in EntropyLab there are also dice, cards and other options included.
Everything is released as open source, and it is created by OogaBoogaX developer, but please READ carefully, and use at your own risk,
Note that this is early testing phase, and you should NOT use it as your main setup!

Code:
[img height=335]https://www.talkimg.com/images/2026/09/04/UekToT.jpg[/img]
https://entropylab.online/
https://github.com/OogaBoogaX/entropylab
One of its advantages is that it creates the descriptor for supported wallets (like Bitcoin Core, Sparrow, etc), which makes things a bit easier. But, I still think Seed Tools is more complete, with this one, you have to constantly load the current wallet (copying and pasting the seed phrase).

Pmalek
Legendary
*
Offline

Activity: 3626
Merit: 9560



View Profile
September 12, 2026, 03:50:20 PM
Merited by vapourminer (1)
 #83

This doesn't really matter if you are using seed phrase generated with weak entropy.
One developer proved this with example of recent c0oldcard crap addresses, he added multiple passphrases with different complexities, and all addresses got emptied withing minutes.
You can't depend on strongest passphrase when weak base will crumble everything.
The passphrase can make no difference or an enormous difference, depending on its complexity. The examples that Dragon guy is talking about are all bad. Those are weak passphrases that can be bruteforced. Why didn't he do the same experiment with 6-8 words? Why didn't he do it with 10 words? 8 random words in lowercase and uppercase letters, maybe with a few numbers or special characters in the mix aren't hackable even with Coldcard's weak entropy of the foundation as you call it.

Does trezor really have a choice? If their entropy lags behind that of competitors, they will lose marketing ground (market share).
Trezor doesn't lag behind and isn't generating seeds with less entropy than the competition. What you are comparing is the entropy of a 12-word vs a 24-word seed. Of course the latter will have more entropy. It's got double the amount of words. Generate a 24-word seed with Trezor and you will get the same results assuming of course that everything is random enough.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
dkbit98 (OP)
Legendary
*
Offline

Activity: 3094
Merit: 8872



View Profile WWW
September 17, 2026, 09:01:10 PM
 #84

...maybe with a few numbers or special characters in the mix aren't hackable even with Coldcard's weak entropy of the foundation as you call it.
Sorry but that is simply not true and you don't know what you are talking about.
Sure anyone can create super complex mambo-jumbo passphrase with 1024 words and special symbols, in addition to their 12 or 24 words,
and this is the perfect recipe to lose access to all coins, if you don't write and backup that also.
Forgetting or losing passphrase is one of the main reason why people lose their coins, this is a fact.

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
Pmalek
Legendary
*
Offline

Activity: 3626
Merit: 9560



View Profile
September 18, 2026, 06:37:32 AM
 #85

Sorry but that is simply not true and you don't know what you are talking about.
Sure anyone can create super complex mambo-jumbo passphrase with 1024 words and special symbols, in addition to their 12 or 24 words,
and this is the perfect recipe to lose access to all coins, if you don't write and backup that also.
Forgetting or losing passphrase is one of the main reason why people lose their coins, this is a fact.
You are comparing apples to oranges, as they say. I wasn't talking about the difficulty of creating complex passphrases, the problem of backing them up, or entering them in a device to recover a wallet. Forgetting or losing passphrases wasn't the point of discussion either.

I will repeat. You will not be able to brute force a passphrase of 8 random words (or more) with today's technology without prior knowledge of the words and the construction of the passphrase. Add to that numbers, uppercase & lowercase letter, and special characters (as I said earlier) and the search space is simply to big to crack in any lifetime. If you claim the opposite, put some sources on the table. You were already asked about this earlier. The one-to-three-word-passphrase examples you showed earlier have nothing to do with what I am saying.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Forsyth Jones
Legendary
*
Offline

Activity: 2030
Merit: 2269


I love Bitcoin!


View Profile WWW
September 18, 2026, 08:39:15 PM
Merited by Pmalek (3)
 #86

Sorry but that is simply not true and you don't know what you are talking about.
Sure anyone can create super complex mambo-jumbo passphrase with 1024 words and special symbols, in addition to their 12 or 24 words,
and this is the perfect recipe to lose access to all coins, if you don't write and backup that also.
Forgetting or losing passphrase is one of the main reason why people lose their coins, this is a fact.
You are comparing apples to oranges, as they say. I wasn't talking about the difficulty of creating complex passphrases, the problem of backing them up, or entering them in a device to recover a wallet. Forgetting or losing passphrases wasn't the point of discussion either.

I will repeat. You will not be able to brute force a passphrase of 8 random words (or more) with today's technology without prior knowledge of the words and the construction of the passphrase. Add to that numbers, uppercase & lowercase letter, and special characters (as I said earlier) and the search space is simply to big to crack in any lifetime. If you claim the opposite, put some sources on the table. You were already asked about this earlier. The one-to-three-word-passphrase examples you showed earlier have nothing to do with what I am saying.
A user can lose access to their wallet by losing or forgetting the seed phrase or passphrase, regardless of the seed phrase or the strength of the passphrase, it is the user's responsibility to store this sensitive data securely and responsibly. If the user loses or forgets either of these, it is their responsibility, their fault, and they must bear the consequences.

Of course, a strong passphrase helps enhance security by adding more data/entropy to the wallet, it can protect funds if the seed phrase's bit number and entropy are weak (as seen in cold_hack scenarios) and can also be used strategically to hide funds if someone finds your seed phrase or you are forced to hand it over. However, if your seed phrase has already been exposed to someone or leaked online, it would be wise to generate a new seed phrase (i think you don't even  need to create a new passphrase) and move your funds from there, once it's on the internet, who can guarantee that a bot isn't brute-forcing that specific seed phrase? I emphasize here, depending on the strength and length of the passphrase, it is impossible to get access to an hidden wallet protected by a strong passphrase.

In short, a passphrase can be used strategically for 2 purposes: protecting you against brute-force attacks on the seed phrase (of course, a weak passphrase or one consisting of only 2 or 3 words would be easily rekt) and providing plausible deniability. For the latter, it is a good idea to have "decoy wallets" containing a small amount of sats to convince an attacker that it is "all you have."

Cricktor
Legendary
*
Offline

Activity: 1624
Merit: 4485



View Profile
September 19, 2026, 08:40:49 AM
Merited by Pmalek (3)
 #87

In short, a passphrase can be used strategically for 2 purposes: protecting you against brute-force attacks on the seed phrase (of course, a weak passphrase or one consisting of only 2 or 3 words would be easily rekt) and providing plausible deniability. For the latter, it is a good idea to have "decoy wallets" containing a small amount of sats to convince an attacker that it is "all you have."
As long as the underlying entropy of a mnemonic seed phrase (the recovery words) isn't severely flawed and weakened by a defektive RNG or other stupid methods of bad entropy generation, I see no feasible way for brute-force attacks on a good entropy mnemonic seed phrase. There's not enough energy and time left to execute such an attacks on this planet or solar system we're bound to.

I see a use case for an additional mnemonic passphrase to protect a wallet from the risk that somehow the mnemonic seed phrase could become compromised, e.g. at a remote backup location which you can't control and monitor all the time.

For the "decoy wallet" with no added mnemonic passphrase I would recommend to use some "convincing" amount of coins, not just a "small amount" only. How much "convincing" might be, is at your discretion. You should also very much pay attention to have no connection of the sacrificial coins to your main stash, otherwise decoy won't quite work, the blockchain doesn't forget.

The "decoy wallet" also serves as a canary that your mnemonic recovery words have been exposed and compromised when it gets emptied by someone else than you. Therefore the need for a convincing decoy amount which likely will be swept by an attacker.

Another nice use case is that any unique mnemonic passphrase generates a new wallet if you need more than one. You could simply append a number to your mnemonic passphrase and count up for any new wallet you need. No additional redundant backups for the recovery words and base mnemonic passphrase needed which simplifies backup needs significantly.

Sure, this upcounting doesn't add much entropy to the new wallets. I'd argue that this isn't needed when the entropy of your recovery words and your base mnemonic passphrase part are good and strong enough, that brute-force attacks on them aren't any feasible at all.

For me this is simpler than multi-sig setups which have way more redundant backup fuss.

Pages: « 1 2 3 4 [5]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!