Bitcoin Forum
August 10, 2026, 12:49:06 AM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3]  All
  Print  
Author Topic: The paranoid user's security guide for using Electrum safely.  (Read 759 times)
NotATether (OP)
Legendary
*
Offline

Activity: 2422
Merit: 10114


┻┻ ︵㇏(°□°㇏)


View Profile WWW
August 06, 2026, 05:55:45 AM
Merited by LoyceV (4), JayJuanGee (1)
 #41

Hundreds of years to thousands of years might be enough difficulty, perhaps?

No, not with the current rate of GPU advancement.

More powerful graphics cards are unveiled every year which cut the cracking time down by a non-negligible factor. This picture is for the case of running the same graphics card for a long time. So the 100 year passphrase which can't be cracked by an RTX 5090 today may be cracked in just 1 year by, I don't know, a handful of RTX 9090s in 5 years?

This is the paranoid user's security guide. I endorse measures which make theft impractical.  Smiley

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
satscraper
Legendary
*
Offline

Activity: 1554
Merit: 2880



View Profile
August 06, 2026, 07:31:39 AM
Merited by JayJuanGee (1)
 #42


Hundreds of years to thousands of years might be enough difficulty, perhaps?

In some cases the length of the search space really matters, especially when you use the "pattern" approach. My passphrase that extends SEED is 32 characters long filled with  small letters, cups, digits and special characters, and at the same time there is no effort for me at all in reproducing it even with my eyes closed because I use Gibson's trick.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
nc50lc
Legendary
*
Offline

Activity: 3234
Merit: 8969


Self-proclaimed Genius


View Profile
August 06, 2026, 07:42:10 AM
 #43

The passphrase does not even have to be very long in order to get somewhere between light orange and dark orange, and yeah of course, guys might choose even higher levels of protection.
That's if it's totally random characters, adding a dictionary word can be used as an attack vector even if that word is 10 letters long.
Then the chart can be used for the additional symbols and numbers in consideration of how many dictionary words are currently available.

But since NotATether said 12-24 "words" long, that length is practically a requirement since otherwise, it'll be susceptible to dictionary attack.

- NEW: You should definitely use BIP39 passphrases for your seeds. In fact, if I were you, I'd make it at least 12 or 24 words long, just like your seed.
Alternatively, just make it a combination of real words plus random letters, numbers and symbols so it wont have to be 12 words long to be strong against bruteforce.
Either way (12-24 word passphrase or that), the user has to write it down on a separate paper anyways.

LoyceV
Legendary
*
Offline

Activity: 4130
Merit: 22431


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 06, 2026, 02:51:28 PM
Merited by JayJuanGee (1)
 #44

Hundreds of years to thousands of years might be enough difficulty, perhaps?
It depends Tongue A password that would have taken thousands of years to crack in 1990 won't be secure now, and the same can probably be said for a password that's currently safe if you add another 36 years of computing improvements.
I'd say this is an argument for using much heavier encryption: BIP38 for instance is still very expensive to brute-force. Passwords become annoying to type and remember if they're too long. If "one attempt" takes 0.1 seconds, an attacker can't test millions of even billions of passwords per second.



Anything that takes a "normal" hacker a thousand years to brute-force, will still be peanuts to someone with (very expensive) access to an (AI) data center.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
JayJuanGee
Legendary
*
Offline

Activity: 4536
Merit: 14850


Self-Custody is a right. Say no to "non-custodial"


View Profile
August 06, 2026, 05:56:15 PM
 #45

Hundreds of years to thousands of years might be enough difficulty, perhaps?
In some cases the length of the search space really matters, especially when you use the "pattern" approach. My passphrase that extends SEED is 32 characters long filled with  small letters, cups, digits and special characters, and at the same time there is no effort for me at all in reproducing it even with my eyes closed because I use Gibson's trick.

I had to look up Gibson's trick and I think that it is good up to a point- even though it takes away from some randomness, but the filling in of characters likely ends up helping with difficulties to guess the password by others or difficulties to break by password guessing machines.



For example, sometimes we might have created some passwords and then we cannot remember the exact details of how we had varied the base word(s), so maybe if the password base starts out as:

Great Mary

So then we try to consider how to vary our base word, so then maybe we might vary it, yet without practice we cannot recall the exact details of how we had varied it. Maybe the end result looks like this:

34gGgGr88ea88t##mMmM@@ry43 

That seems pretty hard to break, even though it is not random, and we might have to create some kind of a note to ourself to remind us of our password and how we had varied our password within some formula that we will remember based on a note to ourself, no?

The passphrase does not even have to be very long in order to get somewhere between light orange and dark orange, and yeah of course, guys might choose even higher levels of protection.
That's if it's totally random characters, adding a dictionary word can be used as an attack vector even if that word is 10 letters long.
Then the chart can be used for the additional symbols and numbers in consideration of how many dictionary words are currently available.

But since NotATether said 12-24 "words" long, that length is practically a requirement since otherwise, it'll be susceptible to dictionary attack.
- NEW: You should definitely use BIP39 passphrases for your seeds. In fact, if I were you, I'd make it at least 12 or 24 words long, just like your seed.
Alternatively, just make it a combination of real words plus random letters, numbers and symbols so it wont have to be 12 words long to be strong against bruteforce.
Either way (12-24 word passphrase or that), the user has to write it down on a separate paper anyways.

I think that it is good to make clear that there is a difference when we are talking about our passwords and our passphrase.

The recent Coldcard issue ended up causing the initial passwords to be easily crackable, so then the passphrase ended up giving a second layer of protection, and of course, if we knew that our passwords were going to be so vulnerable, then we need even higher levels of protection for our passphrase.

I doubt that in normal cases we need our passphrase to be treated the same as our passwords so 12 characters or more with a combination of characters, numbers, letters, and capital letters is better, even though maybe there might be some lacking in our randomness in the sake of our also wanting to have some abilities to have some memory of it out of convenience and also not wanting to lock ourselves out of our own coins.  And, surely our own level of paranoia might cause us a lot of inconvenience if we end up overdoing it.

Hundreds of years to thousands of years might be enough difficulty, perhaps?
It depends Tongue A password that would have taken thousands of years to crack in 1990 won't be secure now, and the same can probably be said for a password that's currently safe if you add another 36 years of computing improvements.
I'd say this is an argument for using much heavier encryption: BIP38 for instance is still very expensive to brute-force. Passwords become annoying to type and remember if they're too long. If "one attempt" takes 0.1 seconds, an attacker can't test millions of even billions of passwords per second.


Anything that takes a "normal" hacker a thousand years to brute-force, will still be peanuts to someone with (very expensive) access to an (AI) data center.

I agree that a lot of us are likely rethinking the level of complexity of our previous passwords and the extent to which we need to improve them for modern times, as the times are ongoingly evolving.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
nc50lc
Legendary
*
Offline

Activity: 3234
Merit: 8969


Self-proclaimed Genius


View Profile
August 07, 2026, 05:29:36 AM
Merited by Volgastallion (2), JayJuanGee (1)
 #46

I think that it is good to make clear that there is a difference when we are talking about our passwords and our passphrase.

The recent Coldcard issue ended up causing the initial passwords to be easily crackable, so then the passphrase ended up giving a second layer of protection, and of course, if we knew that our passwords were going to be so vulnerable, then we need even higher levels of protection for our passphrase.
You must be talking about the "mnemonic" or "seed phrase" rather than a password.
(electrum uses the "password" term as the wallet-encryption password)
Because the issue in Coldcard is its entropy's size which is lower than what they intended.
That entropy is what's encoded as mnemonic.

And then, the "Passphrase" is used as salt to change the resulting binary seed from the mnemonic.

JayJuanGee
Legendary
*
Offline

Activity: 4536
Merit: 14850


Self-Custody is a right. Say no to "non-custodial"


View Profile
August 07, 2026, 08:28:19 PM
 #47

I think that it is good to make clear that there is a difference when we are talking about our passwords and our passphrase.

The recent Coldcard issue ended up causing the initial passwords to be easily crackable, so then the passphrase ended up giving a second layer of protection, and of course, if we knew that our passwords were going to be so vulnerable, then we need even higher levels of protection for our passphrase.
You must be talking about the "mnemonic" or "seed phrase" rather than a password.
(electrum uses the "password" term as the wallet-encryption password)
Because the issue in Coldcard is its entropy's size which is lower than what they intended.
That entropy is what's encoded as mnemonic.

And then, the "Passphrase" is used as salt to change the resulting binary seed from the mnemonic.

Yes.. maybe ignore everything I said.. since I was not talking about a wallet encryption password.

I was only distinguishing between the seed words and the additional passphrase, and so I misunderstood your use of the term password.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
Pages: « 1 2 [3]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!