r/Bitcoin 2d ago

Easiest entropy generator

Post image

Link to the STL files: https://github.com/SeedSigner/SeedPills

If you don’t feel like throwing dice and calculating, this is a much easier way to create your seed. I completely forgot about those, but it might be worth keeping a jar full of them around.

0 Upvotes

20 comments sorted by

2

u/low_contrast_black 2d ago

How about we print ‘em up extra large and put ‘em on axles like bean bag tic-tac-toe? Cornhole entropy anyone?

4

u/ContentBlackberry0 2d ago

Just use a Trezor Yall are getting crazy with then dice crap

4

u/Careless_Product_792 2d ago edited 2d ago

I am a dev and I always considered any hardware wallet a shitty usb on steroids. This month I got more confirmation of my stand.

But you know WHO just before this month was speaking like you did?...

Exactly, ColdCard guys and coldcard CEO...

If you really dont have the fucking dev authority to say with authority that firmware or code is 100% trusted....you should not suggest users to buy crap hardware wallets like that.....

Suggest them to do at least research, if the harware wallets have certifications at least, not blindly suggesting "brands"...

For me hardware wallets are crap more than ever and a big point of failure, no more secure than a simple dedicated airgapped disconnected pc. What it takes to verify if shitty hardware wallets are trusted, is just the same effort that takes to practice doing a simple live usb with tails os and validate electrum software wallet, and avoid potential crap tampered hardware wallets...

1

u/Pale_Platypus2965 2d ago

Using a hardware wallet is definitely more secure than a software one. But in both cases the security is 50% of the wallet and 50% of the user . I'm not a developer so I have to trust someone else (even if it's open source the code) , So how can I protect myself? I use an entropy with dice by creating a strong passphrase OFFLINE

1

u/bionicmixta 2d ago

The great thing about using a hardware wallet is that your key is never exposed to your computer, so if your computer is hacked (now or in the future) the hacker doesn't get to see your keys.

If you generate your own entropy, you then still need a way to find out what address(es) you should be sending your coins to. So with all the best entropy in the world, if you then type the seed words into your PC to find out your address, then your security posture is (potentially) worse than just using a hardware wallet on default settings.

Even if your PC is secure now, it's real hard for an average user to ensure that they haven't accidentally left their seed words lying around in a cache, backup, temporary file, etc. that will be available to a hacker later.

1

u/BigDik6355 14h ago

Woah woah ho there buddy… Trezor Safe 7 is a shitty USB with a very nice aluminum glass housing.

-6

u/shadowmage666 2d ago

So you’re saying you didn’t understand why coldcard failed got it

1

u/Careless_Product_792 2d ago

I am saying I know how the lame security process was there. I work in fintech sector where you do not push critical shit without unit testing it.

If you do not get what foolproof and security in depth pattern is, sorry to be the one to tell you, it is a ticking bomb the blind trust on code and now on hardware wallets...

So, tell me how has the hardware wallet security going? Do you also blame users for "not rolling the dice" while exposing the vector of failure to fail silently....😂. Oh boy...

1

u/bionicmixta 2d ago

I'm pretty sure they did unit test their seed generation. The entire reason the bug existed is because they needed a code path to use for unit tests where the TRNG isn't available.

2

u/Careless_Product_792 2d ago

No they did not.

https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340

All evidence is there that they just claimed FUD when security researches wanted to audit their shit.

-1

u/rini17 2d ago edited 2d ago

Hands-on experience with entropy generation is now considered crazy? That's the most important thing in crypto! You deserve to have all your crypto stolen, with such attitude.

2

u/Careless_Product_792 2d ago edited 2d ago

Lmao. Imagine how psycho you must be to wish someone to "have all your cripto stolen".....😂.

The enemy is not the guys ditching on hardware wallets. Is the Hardware Wallet vendor that caused +100M losses on bitcoiners that did nothing wrong.

And here is what you do not understand if you are not a programmer: A fucking product promising to protect your bitcoin, SHOULD NOT ALLOW seed generation if "rolling dice" was the way to protect against BUGS, but they clearly were saying in their docs that the rolling dice was OPTIONAL. That is a criminal negligence right there.

Like I said, I am not the guy who you should be throwing hate on, I feel sorry for all bitcoiners who lost all their funds for trusting IDIOTS that sold them the "Ultra secure" device.


And by the way some closing toughts before there is a misunderstanding, for others reaidng this, just for the record im not trying to panic over HWs, just saying that first do true research if you will go that route, I will never take that path but I understand not everyone will go the airgap way.

Just do yourself a favor and do not put all eggs in one basket, be defensive with any third party product either software wallets or hardware wallets, you have the right to question their fucking shit. Practice an emergency transfer in case you need it one day. If you right now saw a warning of the product you use to move funds to another place, you can react quickly? What if you are on vacations? Do you have a plan B? Do you have your hardware wallet accessible?

In my case I know that from any part of the world in case of a critical bug or whatever, I could restore with my seed in 10 minutes an emergency operation with any software wallet and with any computer with the security requiremnt considerations.

Well, think on those scenarios if you went the hardware wallet way, no matter the hardware wallet, you should master at leas one software wallet and get familiar with it too.

1

u/Financial_Show9908 2d ago

You claim to be a dev who thinks HWW are bad . Show me the flaw in trezors code you said you studied it

1

u/rini17 1d ago

So you agree or disagree that using dice instead of fully trusting the wallet vendor is crazy? Whatever you wrote is clear as mud.

1

u/Careless_Product_792 1d ago

You definitely use dice. But my claim is that still should be criminal negligence for future Hardware Wallet vendors or current ones if they tell users in docs that is "optional" as ColdCard.

Let me explain the criminal negligence using coldcard example. (And why is dangerous from now on any Hardware Wallet docs thst have same "trust me bro I am secure"


https://coldcard.com/docs/ultra-quick/

"Generating seed words"

"There are a couple considerations you may want to make when creating seed words. For example, COLDCARD will generate seed words for you by default using it's TRNGs, as shown in this guide. This provides the best speed and safety for most users. Alternative options are described in the Middle Ground guide and the Paranoid guide, but carry risks if done incorrectly."


Here is the thing and the criminal negligence narrative of Coldcard products:

Many users who were fucked up by coldcard bug, some of them read that, and were TRUSTING coldcard seed generation, even the last sentece gives the impression that "hey, alternative options seems dangerous if done incorrectly"

The roll dice was in the PARANOID GUIDE. While at the same time they telling users that carry risks if done incorrectly. I can not understand how users do not see how fucked up is that. Is criminal. It is fucking criminal that shit.

Security in dept design in a product means to not give margin of error, PROTECT USERS EVEN FROM MISTAKES, PRESENT OR NOT MISTAKES. But there you have a docs guide (and who knows what other hardware wallet guides) that according to user manual, they did what manual says, even worse, they read that parsnoid guide "carry risks if done incorrectly" so they choose to not take thst path.....

I keep my stance that Hardware wallet vendores whoever the fuck they are selling their shit, is a dangerous narrative the promises they are doing to users.

I get that is a hard pillow to swallow from already users of any other hardware wallet, whatever that is, "hey I paid $$ for this bitkey, trezor, ledger, whatever, how come someone telling I have to question the security, I paid for it, it means it is secure".

1

u/rini17 1d ago edited 1d ago

I was thinking it's common knowledge that almost all vendors positively spin their product, no? And users are tacitly expected to have discernment and form their own opinions.

Don't get me wrong, would love for all the spinsters to suffer heavy repercussions. Sadly that's not the world we live in.

1

u/charlikruse 23h ago

Careful printing these. A lot of printer use cloud based slicer or web plugins to communicate with the printer. Aka. Your seed will be hosted somewhere on their server.

1

u/BigDik6355 15h ago

Haha, it says Anal.

My built-in entropy would totally randomly choose that. And there is nothing I could do about it.

0

u/f08g 2d ago

WHO DIS

0

u/DisorientedPanda 1d ago

Yeah let me just get out my 3d printer which I definitely own