The recent Coldcard vulnerability involved a firmware bug that caused devices to use a weak software pseudo-random generator instead of the hardware true random number generator (TRNG).
Wouldn’t it be safer to generate a seed phrase by rolling casino-grade dice? The last word of the seedphrase is easily computed by entering the first 11 or 23 words into any hardware wallet without affecting entropy as it’s just a checksum. This would entirely bypass the device’s internal RNG, giving 100% independent entropy taht no attacker could predict.
submitted by /u/djscoox [link] [comments]r/CryptoCurrencyRead More
You might also be interested in reading Newark airport chaos: Task force with FAA, Verizon and L3Harris execs set up.
