Bitcoin Forum
August 30, 2026, 06:33:51 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 [34]
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 11081 times)
Pmalek
Legendary
*
Offline

Activity: 3598
Merit: 9497



View Profile
Today at 07:24:56 AM
 #661

The only thing I still have some confidence in are air-gapped wallets, but even there things are clearly not completely secure considering what happened.
Nothing has changed. Airgapped solutions are great and they work. Airgapped and stateless systems are even better. The problem was in the implementation, resulting in not enough randomness during seed creation.

Most hardware wallets make entering a strong passphrase cumbersome. Even if the thing has a decent keyboard (which none do, not even LOL'DCARD), do you really want to type a long passphrase every time you use it?
I am doing that. My Jade is probably the most cumbersome one, but I am still using long and complex passphrases with it. It takes me several minutes to enter. But as I said earlier, I am fine with giving up convenience for an increase in security. Besides, it's not like I am using it daily. One part of my holdings are on that Jade but I haven't accessed the wallet for over a year. I have a watch-only wallet on a different machine I can access if I need t see my balance.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Lucius
Legendary
*
Offline

Activity: 4074
Merit: 7742



View Profile WWW
Today at 12:53:28 PM
 #662

~snip~
Most hardware wallets make entering a strong passphrase cumbersome. Even if the thing has a decent keyboard (which none do, not even LOL'DCARD), do you really want to type a long passphrase every time you use it? Most hardware wallets encourage the use of weak passphrases. That weakens security through bad design.
~snip~


Have you ever held a Foundation Passport in your hands and tried to type in passphrases? I've already written that it's the same as typing a message on an old model mobile phone and it takes me less than 1 minute to type 20+ characters, noting that I have no need to rush. I don't know why you need a 50-character passphrase, but if you think you're safer that way...

Besides, I don't know why the same nonsense is constantly repeated that someone needs to do it every day, considering that such setups are used for long-term storage - and that for everyday use we have other less complicated solutions.

mabji1
Newbie
*
Offline

Activity: 36
Merit: 0


View Profile
Today at 04:52:12 PM
 #663

~snip~
Most hardware wallets make entering a strong passphrase cumbersome. Even if the thing has a decent keyboard (which none do, not even LOL'DCARD), do you really want to type a long passphrase every time you use it? Most hardware wallets encourage the use of weak passphrases. That weakens security through bad design.
~snip~


Have you ever held a Foundation Passport in your hands and tried to type in passphrases? I've already written that it's the same as typing a message on an old model mobile phone and it takes me less than 1 minute to type 20+ characters, noting that I have no need to rush. I don't know why you need a 50-character passphrase, but if you think you're safer that way...

Besides, I don't know why the same nonsense is constantly repeated that someone needs to do it every day, considering that such setups are used for long-term storage - and that for everyday use we have other less complicated solutions.
Users who view the hardware wallet as a frequently accessed tool are rightly frustrated by poor input interfaces.
Users who view the hardware wallet as a high-security vault accept the "1-minute penalty" as a necessary cost of protecting their assets.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 [34]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!