@GHOSTawyeeBOB Passphrase is methodologically and procedurally wrong approach. The only justification for single-sig is doing shitcoins. But at that point better use SLIP39 or PenLock, rather than ill-defined passphrase derivations
@SeanObud111@ferenckovacs That's a fundamental aspect of private-public key schemes: a key length of N bits can invert from the pubkey in a number of steps which is N/2.
Therefore, the effective complexity of a 256-bit private key is 128 bits, and you can generate it with 128 source bits of randomness.
@raw_avocado@KLoaec@rperezmarco Imho the point is that even using bad dice would result in minimal entropy degradation, whereas using bad TRNG (bad physical or bad processing pipe line) can be catastrophic
@nullconst0@peterktodd You still need a HWW, you use their seed restore procedure (instead of letting it generate a fresh one with potentially bad randomness)
They don't want you to know you can do this. How hard is it really and how long does it take?
I've seen a lot of aggressive fear porn raging against the idea that people can or will roll dice to generate a seed - I was curious how long it'd take to sit there and do the process from beginning to end...
I turned up some music loud and went into an adjoining room with no electronics. The music both masks the dice roll and keyboard entry sounds, and is fun to listen to.
Results: It takes about 4 minutes to roll a 12-word seed phrase and enter it into a Seedsigner. Skill level - kindergarten
I was able to go through everything below in 75 minutes
🎲 roll three unique 12-word seed phrases
✅ load them into seedsigner,
✅ Verify the fingerprints
✅ Verify the words
✅ Write down the words
✅ Export xpubs into Sparrow
✅ Create a watch-only multisig wallet over airgap between Sparrow and Seedsigner
✅ Receive testnet coins from the @mempool faucet
✅ Create a batch transaction sending back the coins to the faucet as well as another 2 wallets in Sparrow
✅ Send he tx over airgap back to the Seedsigner for the first signature,
✅ Sending the partially signed PSBT back to Sparrow to display the next PSBT QR,
✅ Sending the fully signed PSBT back to Sparrow and finally
✅ Broadcasting
And I did this all before Widespread Panic could even finish the first set of the concert! I basically started rolling dice at Stop-Go, and was done before the end of One By One.
Note: transactions all sent on testnet4. (Both Sparrow and Seedsigner were also set to Testnet/4.)
@peterktodd Not necessarily. Arbitrarily biased dice do arbitrarily low fraction of bits at each roll. Trivially, a magician's die (gimmick makes it always roll the same result) contributes exactly zero bits.
@bergealex4@lorenzolfm@ThiagoMot_ OK, but those aren't unrelated: the poor man's covenant -in use today- consists in pre-signing and deleting the key. Which crucially requires that the key source can't be rebuilt...
@Vladcostea@Stacking_sats_@andhans_jail And you know what's low too? The price of bcash and the other shit that you shill. Grave dancing is disgusting, really.
The issue here was the no free code, not the BTConly approach, which remains a strict attack-surface reductor.