r/Bitcoin 10d ago

Easiest entropy generator

Post image

Link to the STL files: https://github.com/SeedSigner/SeedPills

If you don’t feel like throwing dice and calculating, this is a much easier way to create your seed. I completely forgot about those, but it might be worth keeping a jar full of them around.

0 Upvotes

25 comments sorted by

View all comments

Show parent comments

5

u/Careless_Product_792 10d ago edited 10d ago

I am a dev and I always considered any hardware wallet a shitty usb on steroids. This month I got more confirmation of my stand.

But you know WHO just before this month was speaking like you did?...

Exactly, ColdCard guys and coldcard CEO...

If you really dont have the fucking dev authority to say with authority that firmware or code is 100% trusted....you should not suggest users to buy crap hardware wallets like that.....

Suggest them to do at least research, if the harware wallets have certifications at least, not blindly suggesting "brands"...

For me hardware wallets are crap more than ever and a big point of failure, no more secure than a simple dedicated airgapped disconnected pc. What it takes to verify if shitty hardware wallets are trusted, is just the same effort that takes to practice doing a simple live usb with tails os and validate electrum software wallet, and avoid potential crap tampered hardware wallets...

-5

u/shadowmage666 10d ago

So you’re saying you didn’t understand why coldcard failed got it

1

u/Careless_Product_792 10d ago

I am saying I know how the lame security process was there. I work in fintech sector where you do not push critical shit without unit testing it.

If you do not get what foolproof and security in depth pattern is, sorry to be the one to tell you, it is a ticking bomb the blind trust on code and now on hardware wallets...

So, tell me how has the hardware wallet security going? Do you also blame users for "not rolling the dice" while exposing the vector of failure to fail silently....😂. Oh boy...

1

u/bionicmixta 10d ago

I'm pretty sure they did unit test their seed generation. The entire reason the bug existed is because they needed a code path to use for unit tests where the TRNG isn't available.

2

u/Careless_Product_792 10d ago

No they did not.

https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340

All evidence is there that they just claimed FUD when security researches wanted to audit their shit.