Cyph3rp9nk's avatar
Cyph3rp9nk
cyph3rp9nk@getalby.com
npub1lnms...rrnt
Non nobis, Domine, non nobis, sed nomini tuo da gloriam.
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
Urgent: It seems they are already stealing funds from seed phrases protected with a passphrase; specifically, it involved a seed phrase consisting of two simple words. To make things easier, here are some simple instructions for creating a secure passphrase. Download KeePassXC, open the password generator, and generate a passphrase. By default, it uses 7 words and 90 bits of entropy, making it practically impossible to crack by brute force. Write it down just as you would the seed phrase, and never store the seed phrase and the passphrase together. Stay safe. image
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
The Samourai developers might as well commit seppuku for handing over all the xpub keys to the NSA, and for being able to track coinjoin inputs and outputs through faulty Tor circuits. image
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
How much damage professional encroachment is doing to Bitcoin.
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
A Trezor T with Secure SD is better than a Trezor 7 from the point of view of cryptography. Refer to Kerckhoffs' principle of cryptography. View quoted note →
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
Here we have one of the influencers who has never worked professionally in IT, one of those who recommended Scamourai's flawed solution and a crappy wallet like Coldcard, talking nonsense once again. That "vulnerability" of the Trezor One or T was actually its greatest strength. It forced you to use a passphrase or Secure SD in the case of the Trezor T, meaning all the security relied on the algorithm and the strength of the password, which is exactly how it should be in a perfect cryptographic system, rather than on black-box solutions like Secure Elements. image
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
It's possible that this bug had already been exploited more discreetly, or that one user simply generated the same seed as another. image
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
Just to clarify, the hack had nothing to do with secure elements; the issue of secure elements is a personal crusade of mine. The hack was a rookie mistake—they failed at the most basic level: the seed entropy.
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
Guys, you need to be prepared for all this crap. Remember, if you use a passphrase, make sure it has at least 128 bits of entropy. Otherwise, use multi-signature. I'm afraid more vulnerabilities will come to light over the next few months.
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
Today I'll only say one more thing. Satoshi's coins have not been hacked, even though hardware wallets and multisignature didn't exist back then. Think.
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
Just to clarify, I wouldn't use the Trezor 1 for many reasons. The main one is that you can't enter the passphrase on the device, and it doesn't have MicroSD card encryption for the PIN either. View quoted note →
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
Applying this principle, right from the start you should only use wallets that have no secure hardware component and are fully open-source—and the only ones that meet these criteria are: - Trezor 1 and Trezor T - Jade - SeedSigner Add a passphrase with more than 128 bits of entropy, and as of today, these are the most secure options. Failing that, you can use them for multi-signature transactions. Anyone who doesn’t understand why I’m saying this knows nothing about cryptography and is just an uninformed idiot. And an old, offline PC running Linux encrypted via LUKS is also perfectly valid as a signing device, as long as you use a passphrase and avoid using TPM to encrypt the disk. View quoted note →
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
The main Bitcoin program/podcast in Spanish has only been recommending failed solutions from the very beginning. They ignored my recommendation not to promote secure-element hardware wallets (HWW), especially ColdCard, which I have been very critical of. They ignored my recommendation not to promote Samourai because it was a flawed solution. They ignored my recommendation not to promote HODLHODL as a non-KYC service. The problem is that the host is an industrial engineer, and his main assistant, who gives opinions on privacy, is not a computer scientist either. They are simply outsiders to a profession they do not practice, and this is the result: they have done a great deal of harm to the community by teaching things incorrectly.
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
@N You have zero dignity. How dare you repost this? image