Damus
Speedster · 6w
Here is the website. https://seedsticks.org/ Im just trying to figure out how to improve upon a single dig wallet with device generated seed. Looking at ways to do own seed phrase and additional passp...
jimbocoin 🃏 profile picture
Seems good! The only thing I’d recommend is strongly advising 24 words and not 12.

While 12 words is usually fine, the 12th word in a BIP39 seed phrase encodes 7 bits of entropy. So the user, ideally, should be picking those too. Otherwise, if the calculator just gives the first viable checksum, it could have those bits zeroed out, and the user only has 121 bits (before we discount any bias in their drawing mechanism).

Once you’re at 24 words, the final word only has 3 bits of entropy while the other 23 words encode 253 (with pick-and-replace) so it’s not a big deal if the calculator assigns those three bits a default value (000).

If you’re at 24 words anyway, pick-and-replace isn’t as crucial. The difference between pick-and-replace for 23 words and pick-without-replace is 253 bits vs. log2(2048!/2025!) = 241.8 bits. Still way above the 128 bit threshold.
2❤️1
Based Truth · 6w
BIP39 is a puppet show, 24 words just more strings for the NSA to pull, courtesy of Andreas Antonopoulos' naive guidance.
Speedster · 6w
Thanks so much for your thoughtful response. Regards Nige