@FractalEncrypt@TheBTCGame This tool suggests the last word will be one "of the words in the block of 16 that the last word is found inside; one and only one word will work from the group." Thoughts?
https://t.co/sr3o9lBaUz
@jamesob Suddenly errybody and their mom did "hardcore analysis" and knew about this years ago. "I sent a report to the CC team that I had doubts about whether the true RNG was actually in use."
Neat story, pics or it didn't happen.
@BlockUnmasked@w_s_bitcoin Original: "traced it to weak seed entropy on the device." Here: "kinda sorta had an early working hypothesis." C'mon, you Sherlocked this, or you didn't. Which is it?
@BlockUnmasked "Our analysis pointed to weak seed entropy on the devices themselves. We took our findings to Coldcard, and we filed a complete report with local, state and federal agencies." Post the receipts (analyses with dates), then.
@hodlonaut 1000%. The blog literally confesses to not understanding what they were doing in the switch to libNgU, and a failure to understand the implementation and lib options. Then in the apology it's "Well, we tried to pen test 3 weeks ago with AI. Schucks."
https://t.co/RqAQ6g185X
@KLoaec Is "encryption treated as absent" for USB just an assumption? I thought the PRNG wasn't "faulty," just less random than required. Seems like this specific thing was about reduced search space of HW-only generated seed words; how does that imply the CC can't encrypt USB properly?
@KLoaec@glgrau For paper wallets, private key -> PRNG -> predictable output? But doesn't cracking this still rely on a guessable input in order to have a starting point for reduced search space on the PRNG output? Or is that not the exploit?
@janrothen I think it's worse that it was rushed as part of getting out from the GPL license. The crypto lib change was motivated by preventing competition, not anything that needed to happen to provide security to users.
@sttsfnd@Coinicarus Looks like three users, switck is the owner. scgbckbone owns coldcard firmware, doc-hex looks like an overall btc contributor.
https://t.co/MpfJ2chk0j
https://t.co/73III6ymHh
https://t.co/MpfJ2chk0j
@Coinicarus User switck owns libNgU. How are they tied to Coinkite? I see them thanked on a March 2021 release, but you're saying owned/strictly maintained by Coinkite. Is switck coinkite?
https://t.co/MpfJ2chk0j
https://t.co/ILRkWgxtOt
@Coinicarus Their blog post says "That required adding libNgU, an embedded MicroPython library that exposes libsecp256k1 and other Bitcoin primitives." When I read that, it sounded like it's part of MicroPython. This is their own thing? Wow, plot thickens.