Damus
Schnuartz | ClavaStack profile picture
Schnuartz | ClavaStack
@ClavaStack

Maximal Security on a Transparent comfortable big Touchscreen - Specter Hardware Wallet

Relays (12)
  • ws://202.61.207.49:8090/ – read & write
  • wss://altlas.nostr.land/ – write
  • wss://atlas.nostr.land/ – read
  • wss://community.nostrdvm.com/ – read & write
  • wss://eden.nostr.land/ – write
  • wss://nostr.me/relay – read & write
  • wss://nostr.na.social/ – read & write
  • wss://nostr.wine/ – write
  • wss://relay.bnos.space/ – read & write
  • wss://relay.damus.io/ – read & write
  • wss://waukietok.nostr1.com/ – read & write
  • wss://nostr.einundzwanzig.space/ – read & write

Recent Notes

Schnuartz | ClavaStack profile picture
🚨Updated eure Coldcard NICHT. Die kann dadurch gebrickt werden und dann könnt ihr die nicht mehr verwenden.

In meinem @Einundzwanzig Video hab ich eingeschoben das ihr auch mit dem neuen Coldcard Update eine sichere Seed erstellen könntet.

Nein, es gibt gerade einige Fälle wo die Coldcard dabei in einen Zustand gerät in dem sie sich nicht mehr verwänden lässt.

Stattdessen wie auch schon häufiger von mir empfohlen:
1. Hänge eine lange Passphrase (aufschreiben) an deine unsichere Seedphrase die du mit der Coldcard erstellt hast an
2. Sende die Bitcoin an diese Aller die mehr Entropie besitzt
3. Kaufe dir eine neue sichere Hardware Wallet (z.B. @Specter DIY)
4. Erstelle dir eine sichere Seedphrase mit der Hardware Wallet (evtl. Würfeln / Münzwürfe)
5. Sende die Bitcoin von der Passphrase Wallet auf die neue Sichere Hardware Wallet
https://x.com/northernH0DL/status/2083633778572787862
2
pingstahu · 1d
Macht es nicht Sinn einfach die Firmware vor 4.0 zu installieren? Ich meine, da hat ja noch alles geklappt und der bug war nicht drin… die neuen Versionen sind ja von jetzt auf gleich ohne viel Prüfung released worden
Schnuartz | ClavaStack profile picture
There was this picture around at X from Scott Marmoll.

I answered this:

Thanks for the audit.

However, there are two points about Specter DIY that are particularly misleading.

1. "No verifiable user entropy input"
The opposite is actually the case. With Specter DIY, you can select every individual word of the seed phrase after it has been generated and inspect the bits that define that word. You can then use coin flips or dice rolls to modify those bits. For example, heads changes the bit, while tails leaves it unchanged.
Since both the corresponding word and the checksum word update in real time, users can verify the result against the official BIP39 word list. This allows them to independently confirm that the hardware wallet is processing their manually generated entropy correctly.
With all of the other hardware wallets on your list, users cannot directly inspect how their external randomness is incorporated into the final seed phrase.

2. "No secure element"
The basic Specter DIY configuration without a secure element handles seed storage in a similar way to SeedSigner: it simply does not store the seed phrase permanently. Therefore, there is no stored seed on the device for an attacker to extract after gaining physical access.
Specter DIY also provides an option to store the seed directly on the device without a secure element. However, this is officially not recommended and is intended only for advanced users who understand the associated physical security risks.
Users who want secure persistent storage can use the Specter Shield extension boards, which add secure element support. The seed phrase can then be stored exclusively on the secure element and protected by a PIN. It can also be encrypted using a device encryption key, enabling a dual-chip security architecture.

Regarding "thin maintenance"
Limited maintenance was a valid criticism of Specter after the project was acquired by Swan Bitcoin, as Swan invested very little effort in its continued development.
However, approximately one year ago, we regained the copyrights, social media accounts, website, and other project assets.
Specter is now actively maintained again. We have a highly active developer group and have held weekly developer calls for the past nine months. These calls are also livestreamed on YouTube:
https://youtube.com/playlist?list=PLn2qRQUAAg0zFWTWeuZVo05tUnOGAmWkm
We are currently working behind the scenes on a major UI and UX redesign, support for newer MicroPython libraries, and compatibility with a new development board. There is therefore a significant amount of active development taking place.

But of course it is important that we are not affected by something similar to Coldcard. For entropy, we would still have some good touch entropy if the TRNG were to fail for some reason. Adding explicit continuous TRNG health tests and fail‑closed behavior in case of a silent hardware RNG failure is a good point. Since yesterday we have been discussing this in our dev group and someone has already offered to build a PR.

--
And he agreed to all of my points.
Schnuartz | ClavaStack profile picture
🧬 Liana ist meine Lieblingswallet für Miniscript-based Recovery Wallets.

Gerade für Inheritance extrem spannend: Was passiert mit den Coins, wenn mir etwas passiert?

Das lässt sich nicht mit jeder Wallet sauber abbilden. Genau dafür ist Liana stark.

TuvokSeed · 3d
sofort nach hause fliegen
Erdöpfökasbrot · 3d
Jemand einbrechen lassen (Freunde/ Bitcoiner vom Meetup)
BTCFalk · 3d
Je nach setup und Vertrauensperson jemand schicken der es machen kann, oder an Flughafen gehen und mit dem nächsten Flug zurück! OK, je nach Urlaub, aber für mich sind es die 42k wert abzubrechen 😨
I Am Muslim · 3d
🔴 What Is Islam? 🔴 Islam is not just another religion. 🔵 It is the same message preached by Moses, Jesus and Abraham. 🔴 Islam literally means ‘submission to God’ and it teaches us to have a direct relationship with God. 🔵 It reminds us that since God created us, n...
Küsnachter · 3d
Gleich bei mir. Ich fliege heute zurück. Zum Glück ist ein geplanter Flug
Schnuartz | ClavaStack · 3d
As a reaction to the Coldcard RNG vulnerability, an independent reviewer checked the seed phrase generation of Specter DIY. His conclusion: “to check whether Specter shares that failure class. It d...
Schnuartz | ClavaStack profile picture
He still identified two minor gaps and offered concrete suggestions to close them. He strongly emphasized that these gaps have low impact, even if the hardware TRNG on the developer board failed, the continuous touchscreen entropy would still protect the seed generation.
This is exactly the kind of transparent, community-driven scrutiny we want.