Bitcoin Forum
September 03, 2026, 04:52:40 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: How do we define "airgap" around here?  (Read 510 times)
LoyceV
Legendary
*
Offline

Activity: 4158
Merit: 22602


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 28, 2026, 06:45:13 AM
Merited by vapourminer (1)
 #21

Unlike 32-bit or 64-bit, it's harder to check actual CPU instruction compatibility of the app or OS.
For what it's worth: I never ran into this problem with different older laptops. If you do, maybe Gentoo will work if you just compile the entire OS without that CPU instruction.

Quote
Since it's not mentioned yet, you can enter your own or custom entropy when using iancoleman. Just tick/click "Show entropy details", choose the format (such as hex, binary or even dice) and enter the entropy on the text box.
The reason I'd prefer to do this manually, is that I don't want to trust Ian's software to really use my own entropy. A compromised version of the software could just produce a predefined key. If I flip coins or throw dice, I want to be able to manually verify my seed phrase is made out of this.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
NotATether
Legendary
*
Offline

Activity: 2450
Merit: 10264


┻┻ ︵㇏(°□°㇏)


View Profile WWW
August 30, 2026, 07:43:01 AM
Merited by vapourminer (1)
 #22

My preference for computers is old laptops. If I securely reinstall a barebones linux distro, or run Tails, do you folks consider this airgapped, even if at some point this computer was online?

Just now I opened an old laptop with Linux Mint, shut off the WiFi module (bluetooth was never enabled), opened my copy of iancoleman on Firefox and generated account zpubs for my sites' donation checkout.

When I was done, I rebooted the laptop.

I think this will provide sufficient security for most people even if they don't have hardware devices.

If you want to make a seed with dice rolls offline, go here: https://bitmixlist.org/diceware.html

I would never trust Windows with crypto wallets

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
BlackHatCoiner
Legendary
*
Offline

Activity: 2128
Merit: 10093



View Profile
August 30, 2026, 04:38:13 PM
 #23

An old laptop running Tails offline is okay, but if you want a bulletproof airgap without supply chain anxiety, just build a SeedSigner. It's totally stateless (forgets everything when powered off) and built from generic off-the-shelf Raspberry Pi parts.

It has a native feature to input your dice rolls directly and calculates the 24th checksum word for you on the device itself. Way safer and easier than messing with iancoleman scripts on an old laptop.

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
 
  Open  code isolated Crypto Wallet     Sign Up    
LoyceV
Legendary
*
Offline

Activity: 4158
Merit: 22602


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 30, 2026, 07:07:22 PM
 #24

just build a SeedSigner.
How did we get from from "not your seed, not your coins" to "juist build your own hardware"?

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
BlackHatCoiner
Legendary
*
Offline

Activity: 2128
Merit: 10093



View Profile
August 30, 2026, 10:08:13 PM
 #25

just build a SeedSigner.
How did we get from from "not your seed, not your coins" to "juist build your own hardware"?
Turns out you need hardware to make your own seed! And you either have to trust someone else's or your own!

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
 
  Open  code isolated Crypto Wallet     Sign Up    
vapourminer
Legendary
*
Offline

Activity: 5152
Merit: 6788


what is this "brake pedal" you speak of?


View Profile
August 31, 2026, 03:46:01 AM
 #26

just build a SeedSigner.
How did we get from from "not your seed, not your coins" to "juist build your own hardware"?


cheap off the shelf DIY compute
LoyceV
Legendary
*
Offline

Activity: 4158
Merit: 22602


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 31, 2026, 06:49:09 AM
 #27

Turns out you need hardware to make your own seed! And you either have to trust someone else's or your own!
It still needs hardware. A Raspberry Pie Zero is just as much a black box to me as my laptop.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Satofan44
Hero Member
*****
Offline

Activity: 504
Merit: 1202


Don't hold me responsible for your shortcomings.


View Profile
August 31, 2026, 01:41:16 PM
 #28

My preference for computers is old laptops. If I securely reinstall a barebones linux distro, or run Tails, do you folks consider this airgapped, even if at some point this computer was online?
Just now I opened an old laptop with Linux Mint, shut off the WiFi module (bluetooth was never enabled), opened my copy of iancoleman on Firefox and generated account zpubs for my sites' donation checkout.

When I was done, I rebooted the laptop.

I think this will provide sufficient security for most people even if they don't have hardware devices.
Reasonable security is always related to the amount of money that is being protected. Most users are too poor to need anything more than this kind of precaution. Over complicating the situation because of paranoia, dogma or other reasons when the value being protected is low is completely contrary to the vision behind Bitcoin. Booting a live Linux Mint should be easy enough for most people as long as they know how to even access the boot menu. If they do not have the technical foundation to even do that, they should stick to hardware wallets.

vapourminer
Legendary
*
Offline

Activity: 5152
Merit: 6788


what is this "brake pedal" you speak of?


View Profile
August 31, 2026, 01:46:42 PM
 #29

Turns out you need hardware to make your own seed! And you either have to trust someone else's or your own!
It still needs hardware. A Raspberry Pie Zero is just as much a black box to me as my laptop.

how about a commodore 64. ancient tech so reasonably trustworthy. write a BASIC proggie that calculates it.




Satofan44
Hero Member
*****
Offline

Activity: 504
Merit: 1202


Don't hold me responsible for your shortcomings.


View Profile
August 31, 2026, 01:57:06 PM
Merited by ABCbits (2)
 #30

Turns out you need hardware to make your own seed! And you either have to trust someone else's or your own!
It still needs hardware. A Raspberry Pie Zero is just as much a black box to me as my laptop.
how about a commodore 64. ancient tech so reasonably trustworthy. write a BASIC proggie that calculates it.
No. Normal users should absolutely never attempt to do that. Ancient technology =/= cryptographically secure RNG. Simplicity is not always good, it really depends on what you are trying to do and why. If you write a BASIC program it will be easy to audit it and to understand the code, but the problem is can the machine actually generate random enough entropy. By default, usually such ancient machines have predictable software RNG. Furthermore, I would not even attempt to try to make that work as trying to create secure RNG on ancient technology is most likely going to lead to all sorts of errors -- it is technically possible, but don't even try it. A bit different but similar, I remember the attempts of many developers to create their own hashes or cryptography, it basically always leads to a big disaster.

vapourminer
Legendary
*
Offline

Activity: 5152
Merit: 6788


what is this "brake pedal" you speak of?


View Profile
August 31, 2026, 03:11:06 PM
Merited by Satofan44 (1)
 #31

how about a commodore 64. ancient tech so reasonably trustworthy. write a BASIC proggie that calculates it.
No. Normal users should absolutely never attempt to do that. Ancient technology =/= cryptographically secure RNG. Simplicity is not always good, it really depends on what you are trying to do and why. If you write a BASIC program it will be easy to audit it and to understand the code, but the problem is can the machine actually generate random enough entropy. By default, usually such ancient machines have predictable software RNG. Furthermore, I would not even attempt to try to make that work as trying to create secure RNG on ancient technology is most likely going to lead to all sorts of errors -- it is technically possible, but don't even try it. A bit different but similar, I remember the attempts of many developers to create their own hashes or cryptography, it basically always leads to a big disaster.

i agree with all of what you said about RNG on random unvetted hardware.

so apologies, i misunderstood what was being discussed. i meant generate entropy with dice rolls, enter the rolls into the C64, and have it calculate the word list plus last checksum word.
ABCbits
Legendary
*
Offline

Activity: 3724
Merit: 10353



View Profile
September 01, 2026, 08:07:31 AM
Merited by vapourminer (1), Satofan44 (1)
 #32

i meant generate entropy with dice rolls, enter the rolls into the C64, and have it calculate the word list plus last checksum word.

FYI, it's already exist, c64wallet - Commodore 64 Bitcoin Wallet. N64 version also exist, Open source N64 encryption app & wallet generator (needs code review).

P.S. both of them probably never went through proper security review, so there's possibility of bug or other security issue.

Satofan44
Hero Member
*****
Offline

Activity: 504
Merit: 1202


Don't hold me responsible for your shortcomings.


View Profile
September 02, 2026, 01:23:54 PM
 #33

i agree with all of what you said about RNG on random unvetted hardware.

so apologies, i misunderstood what was being discussed. i meant generate entropy with dice rolls, enter the rolls into the C64, and have it calculate the word list plus last checksum word.
I still wouldn't do it. For the paranoid, it is simpler and safer to Faraday-cage a modern laptop after disabling physically wireless ways of connecting to it.  Tongue

P.S. both of them probably never went through proper security review, so there's possibility of bug or other security issue.
The issue with many things, this is why people need to be careful not to complicate things. One risk or problem gets replaced by another, potentially worse one.

DYING_S0UL
Legendary
*
Offline

Activity: 1134
Merit: 1208


The Alliance Of Bitcointalk Translator - AOBT


View Profile WWW
September 02, 2026, 04:29:05 PM
 #34

Just now I opened an old laptop with Linux Mint, shut off the WiFi module (bluetooth was never enabled), opened my copy of iancoleman on Firefox and generated account zpubs for my sites' donation checkout.

By saying shutting down the Wifi module, did you mean like physically removing the network interface card/the hardware that enables Wifi connection? Or like disabling/blocking it through setting/terminal commands (without actually removing any hardware) Huh

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
NotATether
Legendary
*
Offline

Activity: 2450
Merit: 10264


┻┻ ︵㇏(°□°㇏)


View Profile WWW
September 02, 2026, 05:02:00 PM
 #35

By saying shutting down the Wifi module, did you mean like physically removing the network interface card/the hardware that enables Wifi connection? Or like disabling/blocking it through setting/terminal commands (without actually removing any hardware) Huh

Most laptops have a physical airplane mode switch. Just turn that on and you'll be fine. Otherwise on Linux, the network manager lets you enable and disable WiFi directly. Or even better, boot into a Linux distro without the WiFi drivers loaded, but this is overkill.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
goldkingcoiner
Legendary
*
Online Online

Activity: 2898
Merit: 3099


HoDL


View Profile WWW
Today at 06:32:18 AM
 #36

If I securely reinstall a barebones linux distro, or run Tails, do you folks consider this airgapped, even if at some point this computer was online?
I'd say airgapping is more about future actions than about past actions: make sure the data on it can never reach the internet in the future (including accidentally plugging in an ethernet cable).

Quote
I trust an old laptop with wifi disabled or removed, far more than I trust a new laptop purchased online.
What do you consider "old"? Anything older than Bitcoin itself will lack processing power, anything a few years old won't be much different than anything you buy new now.

I completely agree with your initial statement and the comment on what air-gap truly means in definition.

But I would also like to add:

An old laptop will do fine, especially with the  possibility of an internet connection removed, but it should also be scrubbed clean. Depending on how old the laptop is, and how much you used it, you might find data destroying viruses, bugs and faulty hardware/software could lead to a complete destruction of any Bitcoin data that you save on it.

In fact I would say saving seeds on a very old computer would be a bit concerning. We should keep in mind that things break down even if we are not using them.

LoyceV
Legendary
*
Offline

Activity: 4158
Merit: 22602


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 07:07:13 AM
Merited by vapourminer (1), ABCbits (1)
 #37

Depending on how old the laptop is, and how much you used it, you might find data destroying viruses, bugs and faulty hardware/software could lead to a complete destruction of any Bitcoin data that you save on it.
That's what shred is for Smiley

Quote
In fact I would say saving seeds on a very old computer would be a bit concerning. We should keep in mind that things break down even if we are not using them.
If keeping your Bitcoin depends on your computer not breaking down, you're doing something wrong.
There are two kinds of people in this world...
People who back up their files and people who haven't experienced losing all their files yet.
Image loading...

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Satofan44
Hero Member
*****
Offline

Activity: 504
Merit: 1202


Don't hold me responsible for your shortcomings.


View Profile
Today at 01:20:34 PM
 #38

In fact I would say saving seeds on a very old computer would be a bit concerning. We should keep in mind that things break down even if we are not using them.
Technically, any kind of seed phrase backup is prone to break down in one way or another including those metal seed phrases. It is just a question of what kind of retention period you are looking for and what kind of ways of destruction you want to take precautions against. A lot of people praise the metal seed phrases as if they don't come with tradeoffs. A seed phrase stored on that is completely vulnerable to discovery but is not prone to hardware failure, a seed phrase stored in an old and disconnect laptop is completely secure from discover but then it is prone to hardware failure or even improbable cosmic ray bit flips. It is always a trade off.

Depending on how old the laptop is, and how much you used it, you might find data destroying viruses, bugs and faulty hardware/software could lead to a complete destruction of any Bitcoin data that you save on it.
That's what shred is for Smiley
This does not work reliably on SSDs, it works only for HDDs.

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!