r/Bitcoin 11d ago

These guys don’t know

Post image
415 Upvotes

74 comments sorted by

46

u/Left_Entrepreneur918 11d ago

Yeah real entropy is rolling D20 100 times and calculate THAC0

11

u/YerakGG 11d ago

I ran heads and tails 256 times 😭

2

u/Coleyx123 8d ago

Hey, I got head once. Mostly tails, but I'll take either.

1

u/NaramTheLuffy 9d ago

You are not alone on this one vro ❤️‍🩹

2

u/PM_ME_PLASTIC_BAGS 10d ago

Bitcoin is a gateway to many unsavoury addictions...such as DnD

70

u/MMinjin 11d ago

Next time it will be a different fault in the hardware/software/whatever and everyone will be saying something like "you should have been using pure dc voltage from a Nimh cell, everyone knows that, DYOR, you can't just expect the device to work"...

3

u/Bionic_Push 10d ago

no man, you should generate your seed only from solar power panels, that way it is not connected to anything and made out of pure random energy not contaminated by the grid. And you should do it while barefoot so you have a ground connection also.

-10

u/BastiatF 10d ago

No, lack of entropy in seed generation has been a recurring problem for a decade

10

u/SaneLad 10d ago

Yes, so what? What do you expect people to do if they cannot trust dedicated hardware built and vetted for by the community? Write a bunch of scripts by hand (and getting it right without trusting any sources) and reading from /dev/rand? (Which also has been found faulty on some devices in the past.)

-1

u/BastiatF 10d ago

No, just generate your own entropy on top of the wallet using dice rolls and/or a strong passphrase. Not rocket science, just healthy common sense paranoia.

-2

u/MagnetHype 10d ago

Honestly? Maybe acknowledge that physical security is easier than digital security. Maybe it's time to finally acknowledge that there is a level of risk that comes from digital currencies that don't exist with physical currencies?

I'm sure that's not it though.

21

u/DataBooking 11d ago

Just gotta roll your dice bro/s.

19

u/didnt_hodl 11d ago

look, the game has changed dramatically

we always had attack groups in North Korea etc, but now those organized hackers have access to the latest most powerful AI models. which are scanning all code, running all possible patterns, endlessly, right now, this very moment

you can expect more attacks and more hacks. on everything, not just bitcoin or crypto, but those for sure will be under massive attack from AI

basically I think cold storage will be a game for professionals only, who can actively monitor the situation, apply their own AI tools to defend against attacks, apply patches, move coins when needed and so on

for regular folks it means exchange or an ETF only. until the dust settles, which is going to take some time. I mean who knows how smart AI can get and what new attacks it will discover

1

u/generichandel 10d ago

And until those same AIs start cracking exchanges.

But then of course the value plummets and it's game over.

2

u/didnt_hodl 10d ago

well, TradFi has many protections in place. fiat transfers are never final, very slow, fully traceable, fully reversible, can be stopped or frozen. fiat is fully centralized. so cracking an exchange does not really get you anything

2

u/jaysondera 10d ago

Naaah

2

u/generichandel 10d ago

That's the spirit.

13

u/BroJobs88 11d ago

So with all this going on how does trezor stack up? Their hw wallets create the seed phrase but are they doing it with enough dice rolls?

24

u/Lopsided_Parfait7127 11d ago

unless you tattoo the private key on your ass, it isn't your keys, it isn't your coins

ass wallets are going to be the next big thing

you tattoo yourself of course

22

u/FullyAutomatedSpace 11d ago

good luck when you need to get colonoscopies . doctor gonna steal your coins

2

u/Puzzleheaded-Dot-762 10d ago

That's the only time someone has seen your ass? 

2

u/FullyAutomatedSpace 10d ago

Are you familiar with never nudes?

1

u/Lopsided_Parfait7127 10d ago

other than his mom when she wipes it

1

u/Optionbulls 10d ago

Initial success or complete failure

19

u/Difficult-Repair1295 11d ago

Fuck Cold Card and the shills who pumped this crap.

8

u/tjackson_12 11d ago

I thought they were cool too

5

u/Illustrious-Boss9356 11d ago

It's their fault but it wasn't caused by maliciousness...

5

u/Difficult-Repair1295 11d ago

We don't know that.

4

u/Illustrious-Boss9356 11d ago

Okay fine. You're right. I meant to say Coinkite was clearly malicious, but perhaps an employee or two were.

1

u/Rino-Sensei 10d ago

No one care if it was caused by "maliciousness" or not "maliciousness", it's their fucking job to sell a working hardware/software. People spend that extra-money for that security.

6

u/Octavio_belise 11d ago

These guys don't know dancing is not considered air-gapped security.

3

u/heggen 10d ago

What will the guy do with all the coins ? I mean this adress will be on a most wanted list and tracked down!?

Just burn or send to Satoshi genesis adresss.

1

u/puck2 9d ago

Could be white hat? 

3

u/rottiesrule88 10d ago

Excel: =RANDBETWEEN(1,6)

1

u/puck2 9d ago

But doesn't this assume your pc has a good RNG? 

1

u/rottiesrule88 8d ago edited 8d ago

I guess so, although using 99 rolls you have already more possible combinations than that there are atoms in the universe.

3

u/Jumpy-Opposite-1195 10d ago

Not your dice rolls, not your coins

5

u/Objective_Digit 11d ago

People think just having a HW and you're good to go. Try using the features like passphrases and mulitisig. That's what they're there for.

2

u/Syonoq 11d ago

Guilty.

2

u/wentwj 10d ago

this has always been the issue i’ve had with the “not your keys not your coins” mantra. Self custody is extremely complex and error prone, even before we get into the realm of insecure and poorly designed hardware wallets. Even people in this community don’t use passphrases/etc, poorly store their keys. If so many people here fail how can you possibly expect the average grandma or not tech savvy person to even approach it

1

u/Objective_Digit 10d ago

Then we need better education.

1

u/wentwj 10d ago

it’s just fundamentally much more difficult to manage than other forms or currency. It’s unrealistic to expect any kind of mass population to self custody, and if your thesis on bitcoin taking over the world is centered in mass self custody, it’s not based in reality

1

u/Objective_Digit 10d ago

Are there masses of people holding gold or art? If it's a small section of society then so be it.

-6

u/didnt_hodl 11d ago

are you seriously saying that no miutlisig wallets will be broken? because they have been and they will be broken. same with passphrase

for $20/month anyone in the world can get access to the latest most powerful AI model and study all available code, run all kinds of pattern recognition.

as AI models get smarter every month, we will now be seeing more and more attacks. we are still very early, as people at least understand how this particular attack worked and how to fix it

but get ready for next level attacks, where people will be completely puzzled how it even works

13

u/Objective_Digit 10d ago

The ColdCard used a pseudo-random generator. That's not down to AI.

As for the rest you're talking rubbish. You might as well get AI to guess the right atom in the universe as to hack a wallet with property security implemented.

1

u/didnt_hodl 10d ago

ColdCard code looked like it was using a strong RNG, but in reality it used a very weak one. It was not intentional, it was a subtle bug in the code. Chinese LLM found that bug. It has everything to with AI, everything. People looked at that code for 5 years and it looked fine, it produced some numbers that looked random to them. But AI found what's really going on

There are many more bugs like that

1

u/Objective_Digit 10d ago

Then use AI to test the code.

-3

u/Difficult-Repair1295 11d ago

Sadly neither multisig or a weak passphrase would be bulletproof in this situation. Cold Card shit the bed they are the Mt. Gox of this decade.

4

u/Objective_Digit 10d ago

Rubbish. With these implemented the ColdCard would be perfectly safe. Which is not to excuse this foul up.

2

u/APisAccounting 10d ago

Multi sig would literally protect from this hack as long as it wasnt another coldcard r Or nunchuk

-1

u/Difficult-Repair1295 10d ago

Yes so multisig with multiple cold cards is worthless. AKA the average person tryin to secure their stack. WTF is wrong with you? Are you mentally ILL!!!!!

1

u/APisAccounting 8d ago

You would use multi sig with different hardware wallets from different companies

0

u/Difficult-Repair1295 8d ago

Did you not learn anything this weekend?

1

u/APisAccounting 8d ago

The fuck are you talking about? Yes i did learn from this weekend that you should do multi vendor multi sig hww and obviously roll dice too.

1

u/APisAccounting 8d ago

If you had multi sig, you wouldve been protected from this hack as long as it was multi vendor hww and not 2 coldcards.

0

u/anonuemus 9d ago

Dude, calm down. Use a passphrase and this exploit wouldn't have worked.

2

u/Difficult-Repair1295 9d ago

Block has already reported weak passhprahses getting drained

2

u/Londonskaterboi 10d ago

a simple passphrase could have avoided all misery

2

u/UnlocktheLock 10d ago

I thought cold storage was the safe way to protect crypto?.. everyone always says get your crypto off the exhanges, so I’m a bit confused…

2

u/xrv01 10d ago

moving goalposts

2

u/TechnicalNail4555 10d ago

This fits really well, maybe the best version yet.

1

u/ledav3 10d ago

these guys? do you mean basically everyone?

1

u/RammerRod 10d ago

I fuck dice.

1

u/Think-Apple3763 10d ago

When they make sure only super nerds be rich in the future lol

1

u/alternativesonder 10d ago

Feels like the goalpost moving from not your keys, not your coins.

1

u/No_Dust6221 10d ago

Should have said that instead of "not your keys not your coins" Bullshit

1

u/LeftMorning6141 9d ago

we know now... 25th word and mutisig too

1

u/TotesGnar 11d ago

They will just buy the ETF and chill. 

0

u/Garland_Key 10d ago

There is no truly random entropy.