Bitcoin Forum
May 09, 2024, 09:56:04 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Cryptocurrency - self generated mnenomic phrase  (Read 47 times)
NEUJ (OP)
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
October 01, 2021, 04:21:19 PM
 #1

As the title suggests, I generated my own mnenomic phrase for my hardware wallet. I'm a cryptography noob and I keep seeing cryptography experts advising not to generate own mnenomic phrase. I used three different sources of pseudorandomness to generate 256 bits: throwing a dice, taking system times from my computer and using the last number to determine wether next bit is one or zero, and picking cards from shuffled deck. I did this 256 times using each method roughly 33%. I used those bits to generate mnenomic using Ian Colemans mnenomic phrase tool on airtight machine.

Does my method seem safe enough or should I follow advice from cryptography experts and use dedicated tool for mnenomic instead?
1715248564
Hero Member
*
Offline Offline

Posts: 1715248564

View Profile Personal Message (Offline)

Ignore
1715248564
Reply with quote  #2

1715248564
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
odolvlobo
Legendary
*
Offline Offline

Activity: 4298
Merit: 3214



View Profile
May 30, 2022, 09:47:20 PM
 #2

It seems safe enough to me. The issue is whether or not your method is biased and if so, whether an attacker might be able to determine the bias. Each of your methods may be biased but not in any way that could be exploited by an attacker.

Experts advise against hand-picking a mnemonic phrase because an attacker knows that people tend to pick certain words or certain orderings of words, and can use that knowledge to narrow down the possible phrases.

Another reason for using a standard tool is that the tool has already been tested. Your ad hoc method may have a flaw that you are unaware of. This happens a lot.

I am not an expert.

Join an anti-signature campaign: Click ignore on the members of signature campaigns.
PGP Fingerprint: 6B6BC26599EC24EF7E29A405EAF050539D0B2925 Signing address: 13GAVJo8YaAuenj6keiEykwxWUZ7jMoSLt
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!