Bitcoin Forum
August 31, 2026, 11:29:23 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: How do we define "airgap" around here?  (Read 394 times)
LoyceV
Legendary
*
Offline

Activity: 4144
Merit: 22592


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 28, 2026, 06:45:13 AM
Merited by vapourminer (1)
 #21

Unlike 32-bit or 64-bit, it's harder to check actual CPU instruction compatibility of the app or OS.
For what it's worth: I never ran into this problem with different older laptops. If you do, maybe Gentoo will work if you just compile the entire OS without that CPU instruction.

Quote
Since it's not mentioned yet, you can enter your own or custom entropy when using iancoleman. Just tick/click "Show entropy details", choose the format (such as hex, binary or even dice) and enter the entropy on the text box.
The reason I'd prefer to do this manually, is that I don't want to trust Ian's software to really use my own entropy. A compromised version of the software could just produce a predefined key. If I flip coins or throw dice, I want to be able to manually verify my seed phrase is made out of this.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
NotATether
Legendary
*
Offline

Activity: 2436
Merit: 10258


┻┻ ︵㇏(°□°㇏)


View Profile WWW
August 30, 2026, 07:43:01 AM
Merited by vapourminer (1)
 #22

My preference for computers is old laptops. If I securely reinstall a barebones linux distro, or run Tails, do you folks consider this airgapped, even if at some point this computer was online?

Just now I opened an old laptop with Linux Mint, shut off the WiFi module (bluetooth was never enabled), opened my copy of iancoleman on Firefox and generated account zpubs for my sites' donation checkout.

When I was done, I rebooted the laptop.

I think this will provide sufficient security for most people even if they don't have hardware devices.

If you want to make a seed with dice rolls offline, go here: https://bitmixlist.org/diceware.html

I would never trust Windows with crypto wallets

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
BlackHatCoiner
Legendary
*
Offline

Activity: 2128
Merit: 10091



View Profile
August 30, 2026, 04:38:13 PM
 #23

An old laptop running Tails offline is okay, but if you want a bulletproof airgap without supply chain anxiety, just build a SeedSigner. It's totally stateless (forgets everything when powered off) and built from generic off-the-shelf Raspberry Pi parts.

It has a native feature to input your dice rolls directly and calculates the 24th checksum word for you on the device itself. Way safer and easier than messing with iancoleman scripts on an old laptop.

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
 
  Open  code isolated Crypto Wallet     Sign Up    
LoyceV
Legendary
*
Offline

Activity: 4144
Merit: 22592


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 30, 2026, 07:07:22 PM
 #24

just build a SeedSigner.
How did we get from from "not your seed, not your coins" to "juist build your own hardware"?

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
BlackHatCoiner
Legendary
*
Offline

Activity: 2128
Merit: 10091



View Profile
August 30, 2026, 10:08:13 PM
 #25

just build a SeedSigner.
How did we get from from "not your seed, not your coins" to "juist build your own hardware"?
Turns out you need hardware to make your own seed! And you either have to trust someone else's or your own!

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
 
  Open  code isolated Crypto Wallet     Sign Up    
vapourminer
Legendary
*
Offline

Activity: 5138
Merit: 6784


what is this "brake pedal" you speak of?


View Profile
Today at 03:46:01 AM
 #26

just build a SeedSigner.
How did we get from from "not your seed, not your coins" to "juist build your own hardware"?


cheap off the shelf DIY compute
LoyceV
Legendary
*
Offline

Activity: 4144
Merit: 22592


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 06:49:09 AM
 #27

Turns out you need hardware to make your own seed! And you either have to trust someone else's or your own!
It still needs hardware. A Raspberry Pie Zero is just as much a black box to me as my laptop.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Satofan44
Hero Member
*****
Offline

Activity: 490
Merit: 1200


Don't hold me responsible for your shortcomings.


View Profile
Today at 01:41:16 PM
 #28

My preference for computers is old laptops. If I securely reinstall a barebones linux distro, or run Tails, do you folks consider this airgapped, even if at some point this computer was online?
Just now I opened an old laptop with Linux Mint, shut off the WiFi module (bluetooth was never enabled), opened my copy of iancoleman on Firefox and generated account zpubs for my sites' donation checkout.

When I was done, I rebooted the laptop.

I think this will provide sufficient security for most people even if they don't have hardware devices.
Reasonable security is always related to the amount of money that is being protected. Most users are too poor to need anything more than this kind of precaution. Over complicating the situation because of paranoia, dogma or other reasons when the value being protected is low is completely contrary to the vision behind Bitcoin. Booting a live Linux Mint should be easy enough for most people as long as they know how to even access the boot menu. If they do not have the technical foundation to even do that, they should stick to hardware wallets.

vapourminer
Legendary
*
Offline

Activity: 5138
Merit: 6784


what is this "brake pedal" you speak of?


View Profile
Today at 01:46:42 PM
 #29

Turns out you need hardware to make your own seed! And you either have to trust someone else's or your own!
It still needs hardware. A Raspberry Pie Zero is just as much a black box to me as my laptop.

how about a commodore 64. ancient tech so reasonably trustworthy. write a BASIC proggie that calculates it.




Satofan44
Hero Member
*****
Offline

Activity: 490
Merit: 1200


Don't hold me responsible for your shortcomings.


View Profile
Today at 01:57:06 PM
 #30

Turns out you need hardware to make your own seed! And you either have to trust someone else's or your own!
It still needs hardware. A Raspberry Pie Zero is just as much a black box to me as my laptop.
how about a commodore 64. ancient tech so reasonably trustworthy. write a BASIC proggie that calculates it.
No. Normal users should absolutely never attempt to do that. Ancient technology =/= cryptographically secure RNG. Simplicity is not always good, it really depends on what you are trying to do and why. If you write a BASIC program it will be easy to audit it and to understand the code, but the problem is can the machine actually generate random enough entropy. By default, usually such ancient machines have predictable software RNG. Furthermore, I would not even attempt to try to make that work as trying to create secure RNG on ancient technology is most likely going to lead to all sorts of errors -- it is technically possible, but don't even try it. A bit different but similar, I remember the attempts of many developers to create their own hashes or cryptography, it basically always leads to a big disaster.

vapourminer
Legendary
*
Offline

Activity: 5138
Merit: 6784


what is this "brake pedal" you speak of?


View Profile
Today at 03:11:06 PM
 #31

how about a commodore 64. ancient tech so reasonably trustworthy. write a BASIC proggie that calculates it.
No. Normal users should absolutely never attempt to do that. Ancient technology =/= cryptographically secure RNG. Simplicity is not always good, it really depends on what you are trying to do and why. If you write a BASIC program it will be easy to audit it and to understand the code, but the problem is can the machine actually generate random enough entropy. By default, usually such ancient machines have predictable software RNG. Furthermore, I would not even attempt to try to make that work as trying to create secure RNG on ancient technology is most likely going to lead to all sorts of errors -- it is technically possible, but don't even try it. A bit different but similar, I remember the attempts of many developers to create their own hashes or cryptography, it basically always leads to a big disaster.

i agree with all of what you said about RNG on random unvetted hardware.

so apologies, i misunderstood what was being discussed. i meant generate entropy with dice rolls, enter the rolls into the C64, and have it calculate the word list plus last checksum word.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!