Bitcoin Forum
August 31, 2026, 12:23:26 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 [34]
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 11130 times)
Lucius
Legendary
*
Offline

Activity: 4074
Merit: 7742



View Profile WWW
August 30, 2026, 12:53:28 PM
 #661

~snip~
Most hardware wallets make entering a strong passphrase cumbersome. Even if the thing has a decent keyboard (which none do, not even LOL'DCARD), do you really want to type a long passphrase every time you use it? Most hardware wallets encourage the use of weak passphrases. That weakens security through bad design.
~snip~


Have you ever held a Foundation Passport in your hands and tried to type in passphrases? I've already written that it's the same as typing a message on an old model mobile phone and it takes me less than 1 minute to type 20+ characters, noting that I have no need to rush. I don't know why you need a 50-character passphrase, but if you think you're safer that way...

Besides, I don't know why the same nonsense is constantly repeated that someone needs to do it every day, considering that such setups are used for long-term storage - and that for everyday use we have other less complicated solutions.

mabji1
Jr. Member
*
Offline

Activity: 32
Merit: 1


View Profile
August 30, 2026, 04:52:12 PM
Merited by vapourminer (1)
 #662

~snip~
Most hardware wallets make entering a strong passphrase cumbersome. Even if the thing has a decent keyboard (which none do, not even LOL'DCARD), do you really want to type a long passphrase every time you use it? Most hardware wallets encourage the use of weak passphrases. That weakens security through bad design.
~snip~


Have you ever held a Foundation Passport in your hands and tried to type in passphrases? I've already written that it's the same as typing a message on an old model mobile phone and it takes me less than 1 minute to type 20+ characters, noting that I have no need to rush. I don't know why you need a 50-character passphrase, but if you think you're safer that way...

Besides, I don't know why the same nonsense is constantly repeated that someone needs to do it every day, considering that such setups are used for long-term storage - and that for everyday use we have other less complicated solutions.
Users who view the hardware wallet as a frequently accessed tool are rightly frustrated by poor input interfaces.
Users who view the hardware wallet as a high-security vault accept the "1-minute penalty" as a necessary cost of protecting their assets.
Meuserna
Sr. Member
****
Offline

Activity: 365
Merit: 638


View Profile WWW
August 30, 2026, 07:14:30 PM
 #663

~snip~
Most hardware wallets make entering a strong passphrase cumbersome. Even if the thing has a decent keyboard (which none do, not even LOL'DCARD), do you really want to type a long passphrase every time you use it? Most hardware wallets encourage the use of weak passphrases. That weakens security through bad design.
~snip~


Have you ever held a Foundation Passport in your hands and tried to type in passphrases? I've already written that it's the same as typing a message on an old model mobile phone and it takes me less than 1 minute to type 20+ characters, noting that I have no need to rush.

Less than a minute to type a somewhat strong passphrase vs instantly scanning a QR code with a very strong passphrase.

If you really sit down to time it, since the Passport doesn't have an alphabetical keyboard, I bet it actually does take longer than you think. That method is fine for a weak passphrase, but not a strong one.


I don't know why you need a 50-character passphrase, but if you think you're safer that way...

Ask the people who used ColdCard and got robbed if they wish they'd used a strong passphrase.

Hackers began cracking weak passphrases for ColdCard seeds, most likely for seeds with wallets they suspected were just decoys.

Here's a video that explains passphrases and how to pick a strong one.

Passphrase QR makes it really easy to instantly load a very strong passphrase.

Pro-Tip! Want to use a decoy wallet? Don't use it as the seed-only wallet. That gives anyone who finds it a clue that the seed has been used. Instead, hide the decoy behind somewhat weak passphrase. That way, if the decoy wallet gets found, you know for a fact that somebody is trying to crack your passphrase. And by using a strong passphrase, you know you have time to move the wallet.

PrivacyG
Legendary
*
Offline

Activity: 1624
Merit: 2985


Fight for Privacy.


View Profile
August 30, 2026, 08:30:13 PM
 #664

How does that work? Say you have a Trezor: do you enter that complex seed extension each time you use the device, using those 2 small keys scrolling through characters?
I have some experience with both kinds of Hardware Wallets.  The button kind and the touch screen kind.  Both are absolute horror to use for complex keys, but I believe buttons do have a some what advantage considering the touch screen ones are easier to mistype on.
Meuserna
Sr. Member
****
Offline

Activity: 365
Merit: 638


View Profile WWW
August 30, 2026, 09:35:10 PM
Last edit: August 30, 2026, 11:15:21 PM by Meuserna
 #665

How does that work? Say you have a Trezor: do you enter that complex seed extension each time you use the device, using those 2 small keys scrolling through characters?
I have some experience with both kinds of Hardware Wallets.  The button kind and the touch screen kind.  Both are absolute horror to use for complex keys, but I believe buttons do have a some what advantage considering the touch screen ones are easier to mistype on.

It depends on the source of input. With seed QR and passphrase QR, there's nothing to type. This makes using very complex keys very easy.

Scan the seed. Scan the passphrase. Done.

Or, for a 2/3 multisig: Scan seed 1. Scan seed 2. Done.

For setting up complex transactions... that's all done on Sparrow, Blue Wallet, Nunchuk, or whatever coordinator app you're using. I love Sparrow for desktop and Blue Wallet for mobile (Nunchuk too). Edited to add: Transactions are confirmed and signed on the airgapped device using QR codes. Scan, scan. Done. Another great thing about working this way is, if you have any doubts, you can use 2 different signers in order to confirm everything you're seeing is legit. I like using a Krux and a ShieldSigner.

Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 [34]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!