Damus
Ava · 2w
Let’s forget for a moment that #COLDCARD was built on the back of open-source software, including GPLv3-licensed code developed by #Trezor. Let’s forget that nostr:nprofile1qqsw3znfr6vdnxrujezjrh...
bootlace profile picture
probably best that @Coinkite don't recommend using dice on their security announcement page, either

Any idea how they do their dice math?

2015 | Ian Coleman BIP39 | Aggregation method mapped Base 6 to Base 2 via raw integer string, creating subtle bit bias

2017 | Coldcard Dice Roll | Allowed users to input fewer than 99 rolls, generating dangerously low entropy seed phrases

2019 | Standard Plastic Dice| Non-precision consumer dice showed statistical bias towards 1 and 6 due to engraved weight loss

2020 | Base-6 Modulo Bias | Naive mod 6-to-2 conversions left upper bits unevenly distributed, shrinking effective keyspace

2021 | Pre-SHA256 Truncation| Early SeedSigner tools used unhashed dice strings, leading to cross-device seed mismatches

2023 | Human "Random" Input | Users manually picking "random" dice numbers collapsed keyspaces into predictable human patterns