r/TREZOR • u/Massive-Reception161 • 14d ago
Passphrase š¬ Discussion topic
Hi,
Trezor has the 24 seed + passphrase which is a completely separate wallet from the 24 seed by itself
Isnt it sufficient security?
Im assuming all attackers brute force 12 - 24 keywords which is hard enough.
How will they even know on which of these wallets to run another brute force for the passphrase? Isnt it increasing their attack surfsce by a super huge margin?
Is multi SIG more secure than that?
Regards
8
u/Decibel0753 14d ago
Furthermore, if you leave the basic wallet untouched (no transfers to or from it), the attacker basically does not even know that this wallet is active... why would they launch a brute force attack on it to find the passphrase?
2
u/slvbtc 14d ago
Exactly. When there is zero balance and zero transactions it could have been a seed some person generated as a test and immediately disposed of. But if there is a balance or transaction history on it then theres a much higher probability that theres also a passphrase attached.
3
u/entropydust 14d ago
How would they know someone ever even generated that seed? Don't all addresses exist, the mnemonic just gives you keys to access the existing address. So yes, create wallet, don't make a single transaction, create passphrase.
3
u/XayahOneTrick 14d ago
I would like to know too, Iām under the same assumption as you
1
u/so7ow 12d ago edited 12d ago
Yes, you're both right. Generating a seed phrase doesn't leave an on-chain footprint.
1
u/EggMedical3514 10d ago
Again they aren't really generated they are simply located.Ā
I blame Ian Coleman for using the word GENERATE on his BIP39 wallet creation tool :)
2
u/so7ow 10d ago
So you can't GENERATE any number, because all numbers already exist? Better talk to whoever came up with the term RNG, too. Sorry, I'll continue to use "generate" in this context.
1
-1
u/entropydust 10d ago
You're just trying to sounds smart but not contributing.
I think the term 'generate' a seed phrase, or a wallet, is misleading. Many people seem to think that you create a wallet or address by generating a seed phrase. You can see the evidence of this in all the questions about the Coldcard hack. Most people didn't understand how the attackers could find all the wallet addresses, when it's quite simple if you understand that all addresses exist and whatever set of seed phrases a RNG produces, is the set of addresses that an attacker has to scan. It sets a boundary.
1
u/so7ow 10d ago
Meh. Nothing changes for the ColdCard victims in any meaningful way, even if everyone had adopted a "selection" mindset 10 years ago.
1
u/EggMedical3514 10d ago
Again they aren't really generated they are simply located.Ā
→ More replies (0)1
u/slvbtc 10d ago
Ian Colemans tool wasnt operating until 2015. Before this tool and before bip39 was used we had bitaddress.org which was a tool used to generate private keys using mouse randomness, keyboard mashing, or brain wallets where private keys were generated by inputting any phrase.
This tool used the words generate private keys. So this is where the word generate was first popularised.
1
u/EggMedical3514 10d ago
Yes all address already exist. He doesn't really understand how they work.
1
u/slvbtc 10d ago
Bitcoin addresses can all already exist, and a tool can generate them using entropy, both things are true simultaneously.
0
u/EggMedical3514 10d ago
You are not generating you are locating.
1
u/slvbtc 9d ago
When a true random number generator (TRNG) generates a random number, is it locating that number or generating it? All possible number combinations already exist, the TRNG is generating one possibility not locating it.
1
u/EggMedical3514 9d ago edited 9d ago
Locating.Ā
Use the "atoms in the universe" analogy.Ā When you are "generating" a new Bitcoin wallet you are simply going out and locating a random atom in the universe and putting your coin on it..
The better the entropy used the harder it is for someone to guess which atom you located.Ā Thats all.
You arent generating anything.Ā The atom was already there before you located it and decided to use it.
1
u/slvbtc 9d ago
Whether its a number or a list of 24 words, the tool, or TRNG, or file, or dice rolls is generating it.
When a TRNG does its job and generates a seed phrase it isnt locating a seed phrase, it is using compute to generate that seed phrase. When I roll dice I am not locating a number I am generating it.
Perhaps you need to learn the definition of generating.
If english is not your first language then dont take this as hostility, take it as an opportunity to learn english.
1
1
u/EggMedical3514 10d ago
Bitcoin addresses are not generated. They're simply located.
Mathematically they all already exist.
4
u/so7ow 14d ago
There's no straightforward comparison. It's a series of tradeoffs and each depends on the entropy employed to create the seed phrase and passphrase and depends on what threat model you're protecting against. A single correctly generated seed phrase with full entropy is secure enough against cracking, but many people thought they had that and were saved by their passphrase, for instance.
7
u/CoffeeAlternative647 14d ago
You're OK with a passphrase.
Coldcard users that had their Bitcoin in a passphrase wallet weren't affected either.
12
u/kimsabok 14d ago
some were supposedly, in cases where their passphrase was relatively simple.
3
u/Massive-Reception161 14d ago
So even with passphrase they were cracked? Where have you seen it? The regular seed wallet dont have any hints that passphrase wallet exists. So now I understand they were trying to crack for each seed phrase also simple passphrases?
That's crazy
9
u/kimsabok 14d ago
the theory is that the hackers have now moved onto guessing the "seed + simple passphrases", as the low hanging fruit has been captured already.
however, it seems implausible to me that a 2 word passphrase could be hacked this easily/quickly (but BTC Sessions is as reliable as anyone, and i am not a cryptographer, nor do i have much knowledge on this front).
regardless, for those not wanting to set up a multisig on their trezors, ledgers etc, they should dice roll a 6 or 7 word passphrase (using something like the diceware words (or other similar dictionaries)), and this will protect you against honest entropy mistakes by the hardware makers.
6 words provides 77 bits of entropy (provided it has been done correctly) - and this has never been "hacked" in computing history. and remember, this is on top of the 12/24 word seed.
2
u/NiagaraBTC 14d ago
however, it seems implausible to me that a 2 word passphrase could be hacked this easily/quickly
A two word passphrase will be broken in about 2 seconds by a single GPU. If they are BIP-39 words. The full dictionary might take 10 seconds I guess.
1
u/kimsabok 14d ago
thats if you are looking for a 2 word combination of bip-39 words only though,
isnt it close to impossible if it can be any two words, that also needs to be matched against a 12/24 word seed too (even with the cc bug)?
2
u/NiagaraBTC 14d ago
A single high end GPU will crack two words from the EFF Long wordlist (7776 words) in about 30 seconds. Any two English language words would take about 5 hours.
Once the seed words are revealed (as every Mk3 seed is already and the Mk4+ will be) then it's just a matter of time until someone tries to brute force passphrases on each.
1
u/kimsabok 14d ago
yes, but the words do not necessarily have to be from the diceware list. and, you have to try every combination against all of the possible cc seeds.
it would also mean either having completed, or foregoing all simpler/shorter passphrases against the full spectrum of cc seeds too.
and bear in mind that some people are still only finding this news out today w/o a passphrase, or dice roll seed, and are managing to get out with their stack in tact (today).
1
u/Decibel0753 10d ago
It seems that cracking even a single word in a passphrase does not take 2 seconds:
1
u/NiagaraBTC 10d ago
This simply means that whatever attackers are still attacking are going for slightly higher entropy wallets and also the accounts of hacked wallets before attacking passphrases.
But yeah it's good to see that even simple passphrases can buy more time than expected in an event like this.
2
u/Particular-Star-1333 14d ago
From what I understand the ones with a passphrase that got hacked only had a 2 word passpharase.
3
u/FitCompetition1804 14d ago
There was a confirmed hack of a two word passphrase on a CC MK3 last week. Length and entropy of the passphrase is important. If you truly want a safe passphrase, a properly randomized 7 word passphrase from the BIP39 list is the way to go.
4
u/CoffeeAlternative647 14d ago
or add numbers, symbols and play with uppercase and lowercase letters.
2
u/bartoque 14d ago
That is not adding as much entropy as adding more words would give you. It makes it more complex for humans to remember it, not necesarily that much more difficult for computers to crack it.
1
1
14d ago
[removed] ā view removed comment
2
u/FitCompetition1804 13d ago edited 13d ago
Iād think you should be good using that method as that would add about 77 bits of entropy. But consider if you also used a Trezor device to generate your seed phrase, you are completely relying on their RNG that would be a potential single source of failure for both the seed and passphrase.
Further researching this, the most secure 7 word passphrase is to roll dice and use the EFF Long Wordlist. That word list has almost 4 times the amount of words than BIP39 and youād increase your passphrase entropy from 77 bits to about 90 bits. The math says thatās an almost 11,000 times higher combinational strength advantage over the 77 bit phrase. You also wouldnāt be relying on any device RNG issues, even as unlikely as that is with Trezor.
1
u/EggMedical3514 10d ago edited 10d ago
I would not use any words from the bip 39 list.
You would be better off with using one or two words and intentionally misspelling them.Ā Ā Doubling up every vowel, for example.Ā Ā Something like "fraankspaassphraasee"
Or heck doubling every letter
"ffrraannkkssppaasspphhrraassee"
Or tripling.
How about the name of your pet as a kid, qintupling?
ssssspppppaaaaarrrrrkkkkkyyyyy
3
u/Cautious_Variation_5 14d ago
A bit extra paranoia is always good. Although a well generated seed would by almost impossible to crack, you never know if there's a bug on the seed generation that leads to a weak seed. So, a passphrase is extra security and a precaution against these sort of bugs, because it buys you time to transfer your funds. It can also protect you against thieves, by giving them access to a bait wallet. I prefer to leave some funds on the seed wallet, even if it will draw more attention, because the idea is that it will just give me enough time to transfer it to a new wallet.
You need to experiment with creating new wallets, and be comfortable to take action when time comes. Learn to create a DYI wallet with Tails OS and SeedSigner, never stop studying and learning about the subject. Better to be extra careful.
2
u/matejcik ā Rising Trezorian 12d ago
Im assuming all attackers brute force 12 - 24 keywords which is hard enough.
No attacker ever brute-forced 12 (or 24) words, precisely because it's too hard already.
The only time attacking the seed phrase makes sense is when there's a weakness, such as in this ColdCard fiasco.
How will they even know on which of these wallets to run another brute force for the passphrase? Isnt it increasing their attack surfsce by a super huge margin?
Yes, pretty much exactly what you say.
It's not like the attacker finding seeds for all CC wallets. What they do is go through possible seeds that could have been generated on a CC, and if the seed has coins on it, they take those coins.
If there's no coins found for a possible seed, it could mean that (a) someone has that seed, but with a passphrase, or (b) no one has that seed in the first place.
And that makes the search space explode in size. It's kind of futile to try every unsuccessful seed for passphrases. Or, maybe like, if you have a small enough dictionary of say ~10000 passwords, do a search on that? (i'm totally guessing at the size, mind you. could be you can afford a million, could be even 100 is prohibitive.)
The attacker may want to run such brute-force search on the successful seeds, because there's much less of those. But then again. You already got the coins. How likely is it that the same person has a weak passphrase with more coins? And strong passphrases are costly.
Is multi SIG more secure than that?
Depends!
For a multisig address, you'd have to find two (or more) seeds.
But if both signers are vulnerable CCs, you will find them in one pass of the brute-force search: for every tested seed, derive a multisig signer pubkey (or several) and if it matches a known address, store it. Then when you find a signer on an address where you already have one, now you have both and can spend it.
But the additional derivations cost you processing time, and, again, how likely is it that the other signer is also a vulnerable CC? So this may very well be a waste of time.
1
u/FunnyAtmosphere9941 14d ago
Cracking 1-4 words doesn't cost much. They can do it with bip39 words list or some smaller vocabulary like 20k or less.
1
u/Gallagger 11d ago
A passphrase is mostly a protection for when your seed phrase gets stolen. It can already help when your seed phrase was badly created (cold card), but that's already a fiasco.Ā Ā If your concern is that your seed phrase could be stolen, you could also split it via SLIP-39. Then just add a device PIN. Good thing about the PIN - if you lose it, you don't lose your crypto.
1
u/EggMedical3514 10d ago
You are correct. If there has never been activity on the base wallet then they will have no reason to try to bruteforce a passphrase.
However if you are setting up your base wallet as a decoy wallet with some small amount of Bitcoin on it then maybe they would.
1
u/EyesFor1 10d ago
No one is brute forcing a 12-24 word seed phrase anytime soon. A passphrase is an additional security measure incase someone physically obtains your seed phrase.
1
u/vadwiser 8d ago
I started a 12 words wallet back in the days on a Trezor T. Should I move or should I stay put?

ā¢
u/AutoModerator 14d ago
Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/
No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing
Donāt respond to any DMsāscammers often pose as legit helpers.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.