Lucius
Legendary

Activity: 4088
Merit: 7792
A swap that needs a hand? zeto.cash@proton.me
|
 |
August 30, 2026, 12:53:28 PM |
|
~snip~ Most hardware wallets make entering a strong passphrase cumbersome. Even if the thing has a decent keyboard (which none do, not even LOL'DCARD), do you really want to type a long passphrase every time you use it? Most hardware wallets encourage the use of weak passphrases. That weakens security through bad design. ~snip~
Have you ever held a Foundation Passport in your hands and tried to type in passphrases? I've already written that it's the same as typing a message on an old model mobile phone and it takes me less than 1 minute to type 20+ characters, noting that I have no need to rush. I don't know why you need a 50-character passphrase, but if you think you're safer that way... Besides, I don't know why the same nonsense is constantly repeated that someone needs to do it every day, considering that such setups are used for long-term storage - and that for everyday use we have other less complicated solutions.
|
|
|
|
mabji1
Jr. Member

Activity: 47
Merit: 1
|
~snip~ Most hardware wallets make entering a strong passphrase cumbersome. Even if the thing has a decent keyboard (which none do, not even LOL'DCARD), do you really want to type a long passphrase every time you use it? Most hardware wallets encourage the use of weak passphrases. That weakens security through bad design. ~snip~
Have you ever held a Foundation Passport in your hands and tried to type in passphrases? I've already written that it's the same as typing a message on an old model mobile phone and it takes me less than 1 minute to type 20+ characters, noting that I have no need to rush. I don't know why you need a 50-character passphrase, but if you think you're safer that way... Besides, I don't know why the same nonsense is constantly repeated that someone needs to do it every day, considering that such setups are used for long-term storage - and that for everyday use we have other less complicated solutions. Users who view the hardware wallet as a frequently accessed tool are rightly frustrated by poor input interfaces. Users who view the hardware wallet as a high-security vault accept the "1-minute penalty" as a necessary cost of protecting their assets.
|
|
|
|
|
|
Meuserna
|
 |
August 30, 2026, 07:14:30 PM |
|
~snip~ Most hardware wallets make entering a strong passphrase cumbersome. Even if the thing has a decent keyboard (which none do, not even LOL'DCARD), do you really want to type a long passphrase every time you use it? Most hardware wallets encourage the use of weak passphrases. That weakens security through bad design. ~snip~
Have you ever held a Foundation Passport in your hands and tried to type in passphrases? I've already written that it's the same as typing a message on an old model mobile phone and it takes me less than 1 minute to type 20+ characters, noting that I have no need to rush. Less than a minute to type a somewhat strong passphrase vs instantly scanning a QR code with a very strong passphrase. If you really sit down to time it, since the Passport doesn't have an alphabetical keyboard, I bet it actually does take longer than you think. That method is fine for a weak passphrase, but not a strong one. I don't know why you need a 50-character passphrase, but if you think you're safer that way...
Ask the people who used ColdCard and got robbed if they wish they'd used a strong passphrase. Hackers began cracking weak passphrases for ColdCard seeds, most likely for seeds with wallets they suspected were just decoys. Here's a video that explains passphrases and how to pick a strong one. Passphrase QR makes it really easy to instantly load a very strong passphrase. Pro-Tip! Want to use a decoy wallet? Don't use it as the seed-only wallet. That gives anyone who finds it a clue that the seed has been used. Instead, hide the decoy behind somewhat weak passphrase. That way, if the decoy wallet gets found, you know for a fact that somebody is trying to crack your passphrase. And by using a strong passphrase, you know you have time to move the wallet.
|
|
|
|
PrivacyG
Legendary

Activity: 1638
Merit: 3068
♻️ Automatic Exchange
|
 |
August 30, 2026, 08:30:13 PM |
|
How does that work? Say you have a Trezor: do you enter that complex seed extension each time you use the device, using those 2 small keys scrolling through characters?
I have some experience with both kinds of Hardware Wallets. The button kind and the touch screen kind. Both are absolute horror to use for complex keys, but I believe buttons do have a some what advantage considering the touch screen ones are easier to mistype on.
|
░░░░▄▄████████████▄ ░▄████████████████▀ ▄████████████████▀▄█▄ ▄███████▀▀░░▄███▀▄████▄ ▄██████▀░░░▄███▀░▀██████▄ ██████▀░░▄████▄░░░▀██████ ██████░░▀▀▀▀░▄▄▄▄░░██████ ██████▄░░░▀████▀░░▄██████ ▀██████▄░▄███▀░░░▄██████▀ ▀████▀▄████░░▄▄███████▀ ▀█▀▄████████████████▀ ▄████████████████▀░ ▀████████████▀▀░░░░ | | CCECASH | | | | |
|
|
|
|
Meuserna
|
 |
August 30, 2026, 09:35:10 PM Last edit: August 31, 2026, 12:44:36 AM by Meuserna |
|
How does that work? Say you have a Trezor: do you enter that complex seed extension each time you use the device, using those 2 small keys scrolling through characters?
I have some experience with both kinds of Hardware Wallets. The button kind and the touch screen kind. Both are absolute horror to use for complex keys, but I believe buttons do have a some what advantage considering the touch screen ones are easier to mistype on. It depends on the source of input. With seed QR and passphrase QR, there's nothing to type. This makes using very complex keys very easy. Scan the seed. Scan the passphrase. Done. Or, for a 2/3 multisig: Scan seed 1. Scan seed 2. Done. For setting up complex transactions... that's all done on Sparrow, Blue Wallet, Nunchuk, or whatever coordinator app you're using. I love Sparrow for desktop and Blue Wallet for mobile (Nunchuk too). Edited to add: Transactions are confirmed and signed on the airgapped device using QR codes. Scan, scan. Done. Another great thing about working this way is, if you have any doubts, you can use 2 different signers in order to confirm everything you're seeing is legit. I like using a Krux and a ShieldSigner. Obviously, not all touchscreen wallets are this easy to use. Some intentionally make the process clunky because they want to tie users to their specific devices. I'm not going to name names, but you probably know which devices I mean. They look cool, but in use, they're clunky. Part of the reason I like Krux and ShieldSigner is that they're fully open source, but they're also stateless. That means your seed & wallet aren't saved on the device. It also means you're never tied to that device. The same encrypted QRs I use for one work on the other. Super easy.
|
|
|
|
LoyceV
Legendary

Activity: 4158
Merit: 22707
Thick-Skinned Gang Leader and Golden Feather 2021
|
 |
August 31, 2026, 08:22:22 AM |
|
It depends on the source of input. With seed QR and passphrase QR, there's nothing to type. This makes using very complex keys very easy. I wouldn't want to have all my secrets laying around as as QR-code. That's really the achilles heel of self storage. I can manage online threats by simply keeping things offline, but "offline" needs a physical place, and you'll need all your QR-codes together to sign a transaction.
|
¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
|
|
|
tvbcof
Legendary

Activity: 5320
Merit: 1367
|
 |
August 31, 2026, 10:55:53 AM Last edit: August 31, 2026, 12:41:41 PM by tvbcof |
|
Firstly, I put some of my recent thoughts about off-line management on a new thread: Kid's camera -> offline printer https://bitcointalk.org/index.php?topic=5592818.0--- On the topic of off-line, air-gapped, stateless signers, I certainly would like to have the options for a pin. I think it the case that: (low-entropy pin + high-entropy opening seed) |XOR| wallet card seed = npub but would be safe only if the address is not known on the blockchain. The simple reason for this is that there would be no test for brute-forcing, but the attacker must not have access to important fingerprints. This implies that some sort of system with: - different kinds of wallets (with the 'middle ground' one in middle value use) and really deep storage for to-be-broken-out ones are kept and remain independent of one another. - some sort of a dead-man's switch or trigger would send a whole block of deep storage to the unused deep storage addresses. Could be accomplished by signed transactions to be broadcast in and emergency or in the case of a desire to break out a cold storage block (if one feel comfortable that their cards have never been compromised.) - In-situ addresses for cold storage funds protected by some combination of multi-sig and geography. - It would be pretty important that the pin could not be coaxed out of the device by a determined and well funded attacker. I'm not sure how practical that is with DIY-grade hardware. Some of the hardware guys are pretty smart. By this time things are getting kind of complicated and there are probably better ways and/or ways that are part of Bitcoin proper that I've never studies (time-locks, etc.) --- I do not think it excessively paranoid for some people (e.g., whales, criminals, etc) to seriously consider the threat of a motivated and well funded attacker having access to everything in their home and a good understanding of what various things might mean. If/when/where holding self-custody BTC becomes illegal, a lot of us will automatically become criminals and subject to search warrants.
|
sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
|
|
|
Lucius
Legendary

Activity: 4088
Merit: 7792
A swap that needs a hand? zeto.cash@proton.me
|
 |
August 31, 2026, 01:57:01 PM |
|
Less than a minute to type a somewhat strong passphrase vs instantly scanning a QR code with a very strong passphrase.
If you really sit down to time it, since the Passport doesn't have an alphabetical keyboard, I bet it actually does take longer than you think. That method is fine for a weak passphrase, but not a strong one.~snip~
How weak do you think a passphrase of 20+ random characters including letters, numbers and special characters is? The difference between what you use (50 characters) and what I use (20+ characters) is several trillion years, but again it is about something that is practically impenetrable for today's technology. I'm writing to you about my experience, you're implying that I'm mistaken - but it's great that you saved an extra minute or two with your QR code, I hope you'll use that time for something smart 
|
|
|
|
Cricktor
Legendary

Activity: 1610
Merit: 4478
|
Let's assume you want your optional mnemonic passphrase to have roughly an entropy of ~128bit.
It's not complicated to calculate how many bits of entropy one character of your passphrase contributes. Lowercase letters (a-z): 26 characters Uppercase letters (A-Z): 26 characters Numbers (0-9): 10 characters Special characters/symbols: 32-33 characters In total that's about 94 to 95 printable characters
Entropy per character (if passphrase is uniformly random, doesn't consist of known words): log2(symbol pool size=94) equals about 6.55 bits per symbol
Even conservatively assuming ~6 bits/symbol you exceed the wanted entropy level with a mnemonic passphrase length of 22.
You can go crazy with more, but frankly that's overkill and kicks your ass every time you have to enter it with the insufficient key or touch input hardware of "normal" hardware wallets.
I don't think anyone can brute-force a truely random mnemonic passphrase of at least 16 symbols length, twenty is plenty enough.
Maybe not digress too much with this stuff?
|
|
|
|
|
Meuserna
|
It depends on the source of input. With seed QR and passphrase QR, there's nothing to type. This makes using very complex keys very easy. I wouldn't want to have all my secrets laying around as as QR-code. That's really the achilles heel of self storage. I can manage online threats by simply keeping things offline, but "offline" needs a physical place, and you'll need all your QR-codes together to sign a transaction. They're encrypted. That's why I use and recommend ShieldSigner, not SeedSigner. SeedSigner uses unencrypted seed QRs, so anyone who finds them can scan them. ShieldSigner and Krux use encrypted seed QRs. If somebody finds one, they can't even scan it without the decryption key.
|
|
|
|
joker_josue
Legendary

Activity: 2506
Merit: 7491
**In BTC since 2013**
|
 |
August 31, 2026, 05:13:33 PM |
|
It depends on the source of input. With seed QR and passphrase QR, there's nothing to type. This makes using very complex keys very easy. I wouldn't want to have all my secrets laying around as as QR-code. That's really the achilles heel of self storage. I can manage online threats by simply keeping things offline, but "offline" needs a physical place, and you'll need all your QR-codes together to sign a transaction. They're encrypted. That's why I use and recommend ShieldSigner, not SeedSigner. SeedSigner uses unencrypted seed QRs, so anyone who finds them can scan them. ShieldSigner and Krux use encrypted seed QRs. If somebody finds one, they can't even scan it without the decryption key. What is the ShieldSigner link? How does it encrypt the QR code, and then how do we decrypt it?
|
| MoBit | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | NO LOGS LOW FEES PGP GUARANTEE | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | | ▄██████▄▄▄ █████████████▄▄ ███████████████ ███████████████ ███████████████ ███████████████ ███░░█████████ ███▌▐█████████ █████████████ ███████████▀ ██████████▀ ████████▀ ░▀▀██▀▀ |
|
|
|
|
Meuserna
|
 |
August 31, 2026, 05:39:10 PM |
|
It depends on the source of input. With seed QR and passphrase QR, there's nothing to type. This makes using very complex keys very easy. I wouldn't want to have all my secrets laying around as as QR-code. That's really the achilles heel of self storage. I can manage online threats by simply keeping things offline, but "offline" needs a physical place, and you'll need all your QR-codes together to sign a transaction. They're encrypted. That's why I use and recommend ShieldSigner, not SeedSigner. SeedSigner uses unencrypted seed QRs, so anyone who finds them can scan them. ShieldSigner and Krux use encrypted seed QRs. If somebody finds one, they can't even scan it without the decryption key. What is the ShieldSigner link? How does it encrypt the QR code, and then how do we decrypt it? Here's a link for ShieldSigner. And here's a video made by the main dev. The project wasn't named ShieldSigner yet when he made that video though. The project has been around for a few years, but the name is new (it used to be called SeedSigner + Smartcard fork, but the devs at SeedSigner asked them to give it a specific name). ShieldSigner is also compatible with smartcards like SeedKeeper and Satochip. I'm a fan of SedKeeper in particular. BTC Hardware Solutions usually sells a smartcard version of their SeedSigner hardware with instructions for running ShieldSigner, though I'm nut currently seeing it listed. But, of course, you can build one yourself. ShieldSigner has a process for saving your seed phrase as an encrypted seed QR. One really easy way to save your encrypted seed QR in physical form is buy one of those toy thermal printer cameras. They're junk, but they do a good job. I take my thermal prints and slip 'em into plastic sleeves, like you'd put a credit card or wallet photo in. As for a decryption key: You can type it manually or make a QR for it too. A decryption key can be anything. It's just text. So, the process for using an encrypted seed QR works like this: Scan the encrypted seed QR. ShieldSigner recognizes that it's encrypted and asks you for the decryption key. You can either type it or scan it as a QR. Krux works the same way. And since the encryption is industry standard, an encrypted seed QR made by ShieldSigner can be used with Krux, Kern, etc, and vice versa. There's nothing proprietary or closed source.
|
|
|
|
joker_josue
Legendary

Activity: 2506
Merit: 7491
**In BTC since 2013**
|
 |
August 31, 2026, 06:20:53 PM |
|
So, the process for using an encrypted seed QR works like this:
Scan the encrypted seed QR. ShieldSigner recognizes that it's encrypted and asks you for the decryption key. You can either type it or scan it as a QR.
So basically, you need two QR codes. One for the encrypted key, and another to decrypt the main key. I think it's already worth complicating things. But it still makes sense to keep the QR code more secure and less exposed.
|
| MoBit | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | NO LOGS LOW FEES PGP GUARANTEE | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | | ▄██████▄▄▄ █████████████▄▄ ███████████████ ███████████████ ███████████████ ███████████████ ███░░█████████ ███▌▐█████████ █████████████ ███████████▀ ██████████▀ ████████▀ ░▀▀██▀▀ |
|
|
|
|
Meuserna
|
 |
September 01, 2026, 12:01:49 AM |
|
So, the process for using an encrypted seed QR works like this:
Scan the encrypted seed QR. ShieldSigner recognizes that it's encrypted and asks you for the decryption key. You can either type it or scan it as a QR.
So basically, you need two QR codes. One for the encrypted key, and another to decrypt the main key. Or, type the decryption key, just like you type a PIN to unlock a traditional hardware wallet. Aside from being airgapped and encrypted, the real benefit of working this way is, the device itself is stateless. In other words, neither your seed nor your wallet is saved on the device. They get wiped when the device shuts off or reboots. Think of it like this. Imagine you're traveling with your hardware wallet. Is it in your pocket? In your carry on bag? In your luggage? What if it gets stolen? How good is the secure element, REALLY? With a ShieldSigner, it doesn't matter since your seed isn't on the device. Your wallet isn't on it either. A ShieldSigner doesn't even have a PIN code to unlock it, since there's nothing on it to lock. When I travel, I flash a game onto it. If it gets stolen, or if TSA makes me boot it to prove what it is, all they see is a video game, because that's what it is until I flash ShieldSigner back onto it.
|
|
|
|
LoyceV
Legendary

Activity: 4158
Merit: 22707
Thick-Skinned Gang Leader and Golden Feather 2021
|
 |
September 01, 2026, 06:02:00 AM |
|
When I travel, I flash a game onto it. If it gets stolen, or if TSA makes me boot it to prove what it is, all they see is a video game, because that's what it is until I flash ShieldSigner back onto it. Does that mean you've memorized your seed and passphrase?
|
¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
|
|
|
joker_josue
Legendary

Activity: 2506
Merit: 7491
**In BTC since 2013**
|
 |
September 01, 2026, 06:09:09 AM |
|
When I travel, I flash a game onto it. If it gets stolen, or if TSA makes me boot it to prove what it is, all they see is a video game, because that's what it is until I flash ShieldSigner back onto it. Does that mean you've memorized your seed and passphrase? No. The seed is in the QR code. In the case of SeedSigner, you can then have a 25th word, which protects your coins. In the case of ShieldSigner, the QR code is encrypted (meaning the scanner doesn't understand what's inside), which is described using that PIN. In fact, it's an interesting approach taken by these solutions.
|
| MoBit | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | NO LOGS LOW FEES PGP GUARANTEE | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | | ▄██████▄▄▄ █████████████▄▄ ███████████████ ███████████████ ███████████████ ███████████████ ███░░█████████ ███▌▐█████████ █████████████ ███████████▀ ██████████▀ ████████▀ ░▀▀██▀▀ |
|
|
|
|
Meuserna
|
When I travel, I flash a game onto it. If it gets stolen, or if TSA makes me boot it to prove what it is, all they see is a video game, because that's what it is until I flash ShieldSigner back onto it. Does that mean you've memorized your seed and passphrase? No. It's on an encrypted seed QR. To anybody who find the QR, it's just a QR that won't scan for some reason. Here's an example of an encrypted seed QR. What do you see? That's just a test, to show how encrypted QRs work. Here's the extremely lame key for that test seed QR, to decrypt it: hidden pass word inside Ain't encryption awesome? And for anybody who dares to suggest encrypted seed QRs aren't safe... crack this: Here's a real exampleThat's a 12 word seed. The first word of that seed is "damp" and the last word is "wear". I could leave that seed QR on this forum for fifty years and nobody could crack it.
|
|
|
|
LoyceV
Legendary

Activity: 4158
Merit: 22707
Thick-Skinned Gang Leader and Golden Feather 2021
|
 |
September 01, 2026, 07:23:34 AM |
|
No. It's on an encrypted seed QR. To anybody who find the QR, it's just a QR that won't scan for some reason. Here's an example of an encrypted seed QR. What do you see? It does scan, and just shows "testing". Here's the extremely lame key for that test seed QR, to decrypt it: My phone can't decrypt it by default, and I don't want to install software for it. But I believe you 
Do you really need a hardware wallet (which you need to flash first) and encrypted seed QR when you travel? I just bring a hot wallet for the rare ( unicorn rare) restaurant that accepts Bitcoin. I wouldn't bring an amount that justifies more than a hot wallet.
|
¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
|
|
|
|
Meuserna
|
 |
September 01, 2026, 08:03:45 AM |
|
It's on an encrypted seed QR. To anybody who find the QR, it's just a QR that won't scan for some reason. Here's an example of an encrypted seed QR. What do you see? It does scan, and just shows "testing". It didn't scan. You saw a picture of the QR on imgur. I labelled it "testing". Try scanning the QR. My phone can't decrypt it by default, and I don't want to install software for it. But I believe you  Exactly. Without the decryption key, no one can decrypt it. Even the FBI couldn't decrypt that thing. Do you really need a hardware wallet (which you need to flash first) and encrypted seed QR when you travel? I just bring a hot wallet for the rare (unicorn rare) restaurant that accepts Bitcoin. I wouldn't bring an amount that justifies more than a hot wallet.
Isn't asking "Do you really need" the wrong question? We're talking about Bitcoin security. For an everyday purchase, of course a hot wallet is fine. But what about all of the people who just got robbed because they trusted ColdCard? There's a better way. It's fully open source, and it requires no "Do you really need" excuses. After all, most people don't realize what they really need until after they've been robbed. The way I'm describing... If the device gets stolen, no worries. There's nothing on it. If the QR gets found, no worries. It's encrypted. Nobody can read it. Also: With something like a ShieldSigner, the hardware is just a Raspberry Pi and a micro SD card. Flash a game onto the micro SD card when you travel and it's just hardware for a game. When you get where you're going, use your laptop to flash ShieldSigner onto the micro SD card and pop it into the device. Boom. It's a hardware wallet again. Nice!
|
|
|
|
LoyceV
Legendary

Activity: 4158
Merit: 22707
Thick-Skinned Gang Leader and Golden Feather 2021
|
 |
September 01, 2026, 08:37:30 AM |
|
It does scan, and just shows "testing". It didn't scan. You saw a picture of the QR on imgur. I labelled it "testing". Try scanning the QR. That's what I did. The label is read from the QR. Your other QR reads "Bet you can't!". So without understanding the encryption, it still reads something. Isn't asking "Do you really need" the wrong question? We're talking about Bitcoin security. For an everyday purchase, of course a hot wallet is fine. But what about all of the people who just got robbed because they trusted ColdCard? I guess I was put off by the idea of bringing everything you own when you travel.
|
¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
|
|
|
|