Bitcoin Forum
May 03, 2024, 11:50:15 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: If your Private Key's are compromised by manufacturer's of hardware wallet's !!  (Read 276 times)
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7126



View Profile
December 22, 2021, 09:15:15 AM
 #21

As for passphrases (sometimes incorrectly called a 25th word)...
It's a called a 25th word intentionally to make it clear that we are talking about the type of passphrase that is added to the end of your seed to extend it with an additional string for better security. It's not the same as the "passphrase" used to refer to a password you use to encrypt your wallet file. It's a bit confusing that we use the same term for two different things.   

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
1714737015
Hero Member
*
Offline Offline

Posts: 1714737015

View Profile Personal Message (Offline)

Ignore
1714737015
Reply with quote  #2

1714737015
Report to moderator
1714737015
Hero Member
*
Offline Offline

Posts: 1714737015

View Profile Personal Message (Offline)

Ignore
1714737015
Reply with quote  #2

1714737015
Report to moderator
1714737015
Hero Member
*
Offline Offline

Posts: 1714737015

View Profile Personal Message (Offline)

Ignore
1714737015
Reply with quote  #2

1714737015
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18509


View Profile
December 22, 2021, 12:39:21 PM
 #22

It's a called a 25th word intentionally
It's intentional, but it's misleading. Your passphrase does not just have to be a word, and indeed, shouldn't just be a word since a single word is easily brute forced and not secure. Passphrase or seed extension is better since it is more clear that you can use a whole phrase or numbers and symbols as well, which are necessary if you want it to be secure. It's also misleading to call it a 25th word since you can use it with seed phrases of any length.

BIP39 refers to it as a passphrase, although BIP39 also refers to seed phrases as mnemonic codes which I strongly disagree with since it implies they should be memorized.

It's not the same as the "passphrase" used to refer to a password you use to encrypt your wallet file.
I would refer to that as a decryption key to avoid confusion.
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7113



View Profile WWW
December 22, 2021, 08:23:11 PM
 #23

There are some relatively reputable hardware wallets that allow you to generate your seed manually instead of having to trust built-in true random number generators.
You can do that with most hardware wallets by using dices or cards and then importing that seed words without depending on any electronical system, but you need to follow some instructions.
Bitbox wallet released step by step instructions for generating your own seed words with dices:
https://shiftcrypto.ch/blog/roll-the-dice-generate-your-own-seed/

For example, in Coldcard, there is an option to generate seeds using dice rolls, coin flips, a combination of both these methods, or a combination of all manual methods with the hardware wallet's own RNG. Upon each roll, you will be shown a hash of the result of each roll, which you can verify manually
Keystone hardware wallet also have the option for generating seed words with casino-grade dices that gives highest degree of entropy.
I think that Keystone verification procedure looks more straightforward than in case of Coldcard, but both of them work and that is important.
https://support.keyst.one/advanced-features/recovery-phrase/use-dice-to-generate-recovery-phrase

I am not sure if any other hardware wallet have built-in feature like this with simple verification, but I think this is something important to have.
Talking about seed generation, I wrote more about that in one of my topics, so if you notice any mistake please correct me or make any suggestion you have:
https://bitcointalk.org/index.php?topic=5317199.0

It's intentional, but it's misleading.
I could also argue that wallet is not really a wallet for bitcoin, because they are not holding coins but only keys.
Cryptocurrency vocabulary is full of errors and wrong phrases  Wink

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
The Sceptical Chymist
Legendary
*
Offline Offline

Activity: 3332
Merit: 6810


Cashback 15%


View Profile
December 23, 2021, 12:04:56 AM
 #24

"decentralised"?
Why does it worry you?
Do you wonder if ATM producer created a backdoor in the machine and may steal your money?
Do you wonder if airbag in your car will be launched correctly? (Yes, I know Tanaka case)
Generally, I don't worry about any of those things because I know that there's some pretty clear legal recourse for me if non-crypto companies steal from me.  But when it comes to anything in the crypto space, once your coins are gone, they're gone--so that's kind of an unfair comparison.

I'm in the class of people Pmalek referred to, i.e., those who are unable to verify that the code behind hardware/software/whatever wallets doesn't contain anything malicious, and therefore I have to trust that other people who know how to analyze code have done so with whatever wallet we're talking about. 

And yeah, sometimes I do wonder about Ledger's products as I know their code is closed-source.  I don't think it's likely that one day everyone's Ledger coins are going to disappear and that whoever runs the company is going to flee the country....but it's possible.  Not probable, but the chance of it happening isn't zero. 

Cryptocurrency vocabulary is full of errors and wrong phrases  Wink
That's going to happen when computer-illiterate folks like myself get into it, but would we really want bitcoin to be for computer science majors exclusively?

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!