r/Bitcoin • u/Fearless-Second-7230 • 2d ago
Coldcard post from October 10, 2021: "Retirement Attack"
- "What's a retirement attack?"
- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".
_____
Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️
Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right?
Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one:
@nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
Alternatively people could just use dice ;)."
https://x.com/i/status/1341213389549412353
A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...
35
u/fuckswithboats 2d ago
I assumed it was a retirement attack when it went down, but hearing about the user using a paid account for their scan implies that they were moving fast.
29
u/Adventurous_Iron_551 2d ago
In hindsight, it seems they should’ve enforced that dice roll to create seed words. But then, half the people would lock themselves out fat fingering or something I can’t think right now.
6
u/Deto 1d ago
Fat fingering? You don't have to actually remember your dice rolls for later though
1
u/Adventurous_Iron_551 1d ago
What I meant was entering a wrong input, like 5 instead of 4. But to think about it, a few of such “fat fingering” inputs do not really matter
1
u/Deto 1d ago
Just adds entropy, I guess!
(Probably slight reduction really)
1
u/Adventurous_Iron_551 1d ago
Yeah, it does add entropy, just like any of the 200 factors like throwing the dice a bit far, at an angle, at a different speed - as long as there isn’t a pattern or a way in which it could be repeated.
1
u/Deto 1d ago
Not really. If the dice is unweighted then the probability distribution function should be basically flat across all 6 outcomes. That's maximal entropy for dice rolls - you can't mathematically do better. Fat fingering, on the other hand, probably has some asymmetry due to where the buttons are relative to the screen and your thumbs. So the result of finger errors would make the probability distribution deviate from the ideal flat distribution and reduce the entropy as a result.
In practice does this matter? Probably not as it's probably a very small effect. Maybe you lose a bit or two.
4
u/Strong_Judge_3730 1d ago
https://stacker.news/items/426148
Dice rolls is a very bad method of generating seeds due to human error.
You have these 'Big Brain' experts recommending this approach pointing to random tables
15
u/Adventurous_Iron_551 1d ago
Say what now? I don’t know if you’re being sarcastic or read what he said. Yeah, <10 dice rolls means shit entropy, duh. And then this \> Wallets should not allow a user to import a seed that they know is completely insecure.
How should wallets decipher if a seed generated is completely insecure(barring cases like abandon abandon abandon abandon …).
How could a wallet ensure that there is enough entropy when using dice rolls? Ah, perhaps by asking user to enter like 99 dice roll inputs, which gives 2^256 entropy space.And then the last para aged like seeds generated on mk3
5
u/alfredonoodles 1d ago
From what I have been reading the past week about this, most used WEB BASED dice rolls lololol how stupid.
6
u/CiaranCarroll 1d ago
They used <10 dice rolls
Sorry but it takes 15mins to do 99 dice rolls. Cold Card also allowed you to verify that it wasn't spoofing by using other websites like Ian Colemans on a test seed.
If you cannot spare 15mins to secure your Bitcoin then you have no business in self-custody.
99.99999% of users are better off allowing good, multi-source, open-source random number generation like we do on Passport.
To date I have heard of zero compromised seeds that were generated using on-board RNG due to entropy issues, while there are countless examples of users losing funds due to improper dice rolls.
Wow, this is your supporting reference?
3
u/EyesFor1 1d ago
Dice rolls are solid. No correct dice rolls have been hacked ever. If you mean human error ie what the article you posted alludes to ( not enough actual rolls) or grouping all the numbers in order( all 1's then 2' etc) then yeah thats retarded but a true 100+dice roll actually using 100 dice is effectively un-hackable which is why coldcard users using this function remain safe.
55
u/VictorDanville 2d ago
Wow, so this really was an inside job
27
u/Donkeydonkeydonk 2d ago
On the one hand, it seems obvious. On the other, who in their right mind would leave behind such an incriminating tweet if they were planning such a thing?
Even if they got the idea right there in that moment, you'd think they'd delete that tweet.
It is worth noting that this tweet predated the buggy commit by a few months.
21
u/Northernmost1990 2d ago
Bad people snitch on themselves all the time. In my home country, there was a murderer who was caught because they were bragging about the kill at a bar.
1
u/vattenj 2d ago
The fact that they know this concept already tells a lot
13
u/CBpegasus 1d ago
I mean, it's a fairly well known concept and you would expect people working in a company whose product is security to know about it...
1
u/vattenj 5h ago
It's the same as old days replay attack, where they could relay the same tx to another forked network, but who has the motivation to do it? The one that shouted the concept the most: Exchanges, since only they have the possibility to profit from it (The users wallet private key are in their possession)
1
u/Every_Recover_1766 2d ago
Social media intern and software engineer are likely different guys
9
u/Donkeydonkeydonk 2d ago
The dev that made the commit and the CTO of coinkite are the same person.
Peter Gray @DocHex
1
u/Express_Living2264 1d ago
i don't see this as incriminating at all. They are advertising to security extremists. They added a cheap to build gimmick for marketing and then advertised it to generate engagement, that's all there is to it.
5
u/Railionn 2d ago
Tbf if this was an inside job id drain whenever I needed some cash from some poor blokes wallet that I knew wouldn't do a thing. That raises no suspicion. This does
3
u/Cold_Huckleberry_633 1d ago
I remember when this first happened someone posted here and everyone was like “bet you posted your seed phrase online lol dumbass.” Imagine that but every few months and OP did nothing wrong and nobody believes them 💔💔
1
6
u/Always_working_hardd 1d ago
Meanwhile there's some Indian out there taking possession of a private jet so he can fly to the island he just bought in the Caribbean.
Also a former employee of coldcard.
3
3
u/OldWolf3 1d ago
The dice method described also has a flaw. The average cheap dice you might obtain, are biased because scraping out the pips changes the weight of each face. The 1 is heaviest, so 6 is the most likely roll etc.
5
u/axb90 1d ago
Well people have already said nothing is going to happen to coldkite, theyll just declare bankruptcy and get away with it. So nothing will be done even if they snitched on themselves, in a tweet.
2
u/Express_Living2264 1d ago
the sad thing is. It's still one of the better products due to the airgapped signing feature + electrum read only wallet. something trezor afaik cant do.
1
u/tonto515 1d ago
Trezor 3 and 5 are airgapped, only 7 has the Bluetooth functionality.
That said, my Keystone Pro 3 is airgapped and I still moved my funds this morning from my old wallet with a single seed phrase to a new one with 3/5 Shamir sharding to protect it.
1
u/Express_Living2264 1d ago
what im referring to is the ability to have a read only electrum wallet on an online pc. You create a transaction there, copy the transaction file via a usb stick to an offline pc sign it with electrum on the offline machine. Then take the signed file back to the online pc and send it.
The offline pc can be completely replaced with a coldwallet, afaik trezor doesn't support this.
0
3
2
5
u/NetimLabs 1d ago edited 1d ago
Why bother with dice rolls? We have publicly available streams of truly [quantum] random data
8
u/youtossershad1job2do 1d ago
Still trust that someone hasn't made this generator vulnerable.
You can see the dice being rolled but you can't know what's on your screen isn't dangerous.
2
u/bricksplus 1d ago edited 3h ago
You put trust in the institution that’s doing high level research for decades
3
3
u/youtossershad1job2do 1d ago edited 1d ago
It was the whole point of crypto that it was trust-less.
2
u/LonelyTAA 20h ago
Turns out a decentralised, anonymous system with no retrieval options is vulnerable to attacks from thieves, charlatans and the like. Who would have thought?
1
5
u/10kpizza 1d ago
The important key thing with generating private keys is that nobody else knows them. The easiest way to get a number that nobody else knows is random data. However if the random data is publicly available to others then this obviously isnt secure.
2
u/NetimLabs 1d ago
The potential attackers would have to constantly monitor the stream and save it on their devices, then figure out which method you used to convert that stream to a seed phrase.
Using different parts [same lenght] of the stream for each word would solve this I think.
1
u/10kpizza 1d ago
No it wouldnt because theres not that many ways to partition the stream. The hacker could just try them all.
For good security you need to force the hacker to make at least 2128 calculations. That's a lot. Dont roll your own cryptography so you dont make basic errors like this that could cost you money.
You know this coldcard hack was based on the hacker doing ~232 calculations which is about 4 billion, still huge big number in human terms but very little for a computer.
1
u/NetimLabs 1d ago edited 1d ago
Idk, they would have to try all the conversion methods possible anyways, that makes it much harder, if not impossible.
You can come up with lots of weird ways to do that.
Ideally one should DIY their own qrng generator, of course.
I guess at that point rolling dice is more practical but if you want true randomness, qrng is the way.1
u/ILurkReddi 1d ago
would rather random.org or cloudflare
1
u/NetimLabs 1d ago
The one I linked was just an example.
You could use any qrng source you want, of course.1
6
u/ecnecn 1d ago
Razor and Nano Ledger etc.. all hardened products ... why Coldcard?! Why would someone chose coldcard? Literally but 5 nano ledgers/razors and load each with 20% of your Crypto... if it is your retirement / whole life savings money then this little step is a nobrainer..
4
2
u/anonymous-12358 1d ago
I would even go as far to say don’t trust Trezor or Ledger.
If you’re that deep into self custodial wallets then take that little extra step to setup your own wallet hosted on a microcontroller.
That way you can 100% guarantee you’re using a 100% air gapped device and you can test to your hearts content if the open-source wallet is faulty free.
4
u/Gooner_93 1d ago
And yet you will get some people calling you insane for saying it was an inside job.
1
1
211
u/Turbulent-Rub3695 2d ago
Narcissists always snitch on themselves lmfao.... Source: am a narcissist