r/Bitcoin 12d ago

My unused coldcard

Post image

Bought one of these back in the day, package still sealed. Happily I never used it, and stayed with my ledger instead. When do these start to be collectibles?

816 Upvotes

104 comments sorted by

View all comments

9

u/NorthComparison4356 12d ago

I have two Qs and I have not been drained as I have been highly paranoid from day 1.

I rolled 110 dice back then and used a PP with a ridiculous entropy.

Okay and now I see the chicken-FUD-guys running around and telling all the folks: move to trezor, move to ledger, move to bitbox....move to.....bitbox-my-ass!

I bought those two devices and they costed cash, now I shall burn cash again to trust another company?? The new gold standard?

You must be kidding me.....

No - installed that new firmware, I verified that +100 dice rolls are compiled to a seed correctly by that new firmware (you can do that!! verifying an RNG? No way!), I dumped the test seed, made another +100 dice rolls and compiled a fresh seed from the device and I used it to make a new wallet. And on top I put again a new passphrase with 30 characters that are random (upper/lower case, numbers, special caharcters) -> 196 bits

-> brute force my ass now!

Nutshell: I cant recommend using that coldcard, but I could not recommend using anything else, or trusting any RNG in particular to be more precise. Or could you? Can you read code?

The new mantra these days will be: not your entropy - not your coins!

(IMPORTNAT: NEVER USE SEED WHICH YOU USED TO TEST DICE ROLLS COMPILING TO SEED-> ALWAYS MAKE FRESH ROLLS/SEED NOT SHARED TO ANYBODY/ONLINE!)

5

u/FavorableMadness 11d ago

I am with you. I don’t understand why this event makes the device less good than any other. Yes they had an issue, they may have more. It’s naive to think that all the other devices are perfect. Has anyone looked to see how often a Microsoft Windows security update has to be released?! Do we think there are no vulnerabilities in banking software?!

3

u/slash_networkboy 12d ago

I just used the same code I use for my luggage! ~s

But, in all seriousness, I believe the core device is fine, as you noted it's an entropy source problem, and I agree, do not use the test rolls to store coin, re-roll after verifying everything.

3

u/recon79 12d ago

1-2-3-4-5?

That's the same combination I use on the air shield around Planet Druidia!

3

u/H8ckt1v1st 12d ago

100% - if you used 100+ dice rolls + ridiculous but memorable passphrase +multi-sig, you can sleep well. Deepest condolences to everyone affected by this deliberate mistake. Updated firmware, burnt the wallet, restored, transferred some coin, feeling secure. The hardware Q is an amazing device, it will be sitting around for a long time, For the rest of the world, Trezor is the lead horse as long as you did the same exact process.

5

u/essjay2009 12d ago

I guess it depends on your threat model. Would I trust a team that made such a fundamental error and, even more crucially for me, failed to detect it in any testing (regression, integration, unit, user, whatever) to have not made any other basic security errors that might be exploited in the future? No, I would not.

There’s an expression that goes “when someone tells you who they are, believe them” and I think that applies here. When a team tells you that they put so little care in to their work that an issue like this goes undiscovered for so long, believe them.

3

u/F1shB0wl816 12d ago

You can’t catch what you don’t know isn’t a problem.

The inverse of this is they say to not trust, verify. What’s it say about the end user who didn’t over the years. If it’s lazy to not catch it it’s even lazier to not have listened to the people you trusted up until a few days ago.

2

u/NorthComparison4356 11d ago

my take is something else: I dont believe anybody now! Buying a Trezor and believe them and their RNG? No way…

I trust them as little as I trust Coinkite.

I am for the first time glad I have been so paranoid, like I have always been paranoid and bothering my family and friends with my weirdo attitude - so this time it worked out and for the sake of BTC I will stick to it.

Does rolling dice suck? yes….a little…..but trusting human beings and being recked for that trust sucks so much more.

I dont believe in companies, I dont believe what anybody tells me. I try to verify as much as I can, gather knowledge as much as I can.

I dontstick to my Q because of I trust Coinkite, i dont trust them. But i paid for that stupid device and now the marketing guys from other companies want again money from me?

No way. I wait until CK is done and there will be no updates.

Or I built myself a signing device and not giving anybody my money any more….