Damus
Luke Dashjr profile picture
Luke Dashjr
@Luke Dashjr
Quite a few people suggesting/using dice to mitigate the Coldcard vulnerability.

Note that common dice are not designed to be cryptographically secure.

If you are going to do this, you probably should buy precision casino dice. And even then, have another source of entropy.
449❤️20❤️1🤡1🫡1
Kieran · 2d
ROFL
markonyte · 2d
Dice and coin https://bitbox.swiss/bitbox02/BitBox_Diceware_HowTo.pdf https://i.nostr.build/EkTRwWsshd44d6pS.gif
Cykros · 2d
And/or do Von Neumann skew correction.
Manánguri · 2d
Lava lamps.
Francisco d Anconia · 2d
Strong passphrase on top should do?
cryptowolf · 2d
Casino dice are definitely more uniform, but the real nuance is that dice bias only matters if the entropy model is already weak. If your rolls are hashed properly, combined with a passphrase, or mixed with secure‑element entropy, even regular dice produce safe randomness. The only time precision...
Leo Wandersleb · 2d
Terrible advice! Yes, you only get the full on-paper entropy with perfect dice. Perfect dice do not exist. Don't use any dice! Maybe being shy 1% of the optimal entropy is good enough and certainly better than the ColdCard shitshow of using just a few bits?
Gregor · 2d
Why use accessory hardware at all when phone wallets get industry scale stress testing and security updates and conventional payment systems can operate with internet connected devices?
Hofer99 · 2d
Do a Coin flip. End of the day Maybe its time to increase seed phrase entropy. Guess that what multisig is for.
SatsAndSports · 2d
Normal dice are fine, no need for casino dice If you do the recommended 99 rolls with an extremely biased dice (⚀ and ⚅ only), then you still have 99 bits of entropy, which is fine If you see all six numbers coming up in your 99 rolls, you're fine
Willy Cooper · 2d
good advice. I was thinking about this ealier.
sly · 2d
also, use cryptographically secure tables, as common tables were not designed for that! /s
nickez · 1d
Also avoid using ColdCard unless you also follow the procedure to verify that the ColdCard isn't cheating on you. The BitBox method doesn't involve trusting external hardware.
bootlace · 1d
And dice entropy math is hard. Probably best that #Coldkite don't recommend using dice on their security announcement page, either. Any idea how they do their dice math? AI list of dice fails: 2015 | Ian Coleman BIP39 | Aggregation method mapped Base 6 to Base 2 via raw integer string, creatin...
theplatinumbear · 1d
Just stack metal. It’s a lot easier.
mister_monster · 1d
> and even then Why? Are casino dice not secure? What's your reasoning in making this statement? When using common dice, the more dice you roll at once the more any potential biasez in each specific dice get randomly positioned. As long as they aren't rolled in a specific order and they all dont h...
Pixel Survivor · 1d
searching for the post on nostr...
kyle-moore · 1d
nostr:nevent1qqsq8amlalsu7eh3vlvd40vqhyv7cnkgup6vspqu3sgfkkx2lma0ypcprfmhxue69uhhxetwv35hgtnwdaekvmrpwfjjucm0d5hsyg92fmf7pckgpeftwm39x6l00xg287gkq3xmknv3vkanh4fetdtz2vpsgqqqqqqsxnf860
Artel 21 · 1d
What is the definition of cryptographically secure dice?
Financial Parasites · 1d
nostr:nprofile1qqsytuv4el7t3jtjfm7zfrc9q730ked40806he7dx5uctxqk8j4hvfcpz9mhxue69uhkummnw3ezuamfdejj7qghwaehxw309aex2mrp0yh8qunfd4skctnwv46z7y5tqng the lord has spoken lol