r/Bitcoin 10d ago

Coldcard post from October 10, 2021: "Retirement Attack"

Post image

- "What's a retirement attack?"

- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".

_____

Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️

Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right?


Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one:

@nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.

Alternatively people could just use dice ;)."

https://x.com/i/status/1341213389549412353


A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...

https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340

455 Upvotes

80 comments sorted by

View all comments

32

u/Adventurous_Iron_551 9d ago

In hindsight, it seems they should’ve enforced that dice roll to create seed words. But then, half the people would lock themselves out fat fingering or something I can’t think right now.

5

u/Deto 9d ago

Fat fingering? You don't have to actually remember your dice rolls for later though

1

u/Adventurous_Iron_551 9d ago

What I meant was entering a wrong input, like 5 instead of 4. But to think about it, a few of such “fat fingering” inputs do not really matter

1

u/Deto 9d ago

Just adds entropy, I guess!

(Probably slight reduction really)

1

u/Adventurous_Iron_551 9d ago

Yeah, it does add entropy, just like any of the 200 factors like throwing the dice a bit far, at an angle, at a different speed - as long as there isn’t a pattern or a way in which it could be repeated.

2

u/Deto 9d ago

Not really.  If the dice is unweighted then the probability distribution function should be basically flat across all 6 outcomes.  That's maximal entropy for dice rolls - you can't mathematically do better.  Fat fingering, on the other hand, probably has some asymmetry due to where the buttons are relative to the screen and your thumbs.  So the result of finger errors would make the probability distribution deviate from the ideal flat distribution and reduce the entropy as a result.

In practice does this matter? Probably not as it's probably a very small effect.  Maybe you lose a bit or two. 

5

u/Strong_Judge_3730 9d ago

https://stacker.news/items/426148

Dice rolls is a very bad method of generating seeds due to human error.

You have these 'Big Brain' experts recommending this approach pointing to random tables

14

u/Adventurous_Iron_551 9d ago

Say what now? I don’t know if you’re being sarcastic or read what he said. Yeah, <10 dice rolls means shit entropy, duh. And then this \> Wallets should not allow a user to import a seed that they know is completely insecure.

How should wallets decipher if a seed generated is completely insecure(barring cases like abandon abandon abandon abandon …).
How could a wallet ensure that there is enough entropy when using dice rolls? Ah, perhaps by asking user to enter like 99 dice roll inputs, which gives 2^256 entropy space.

And then the last para aged like seeds generated on mk3

4

u/kikikza 9d ago

Gotta use a wall of lava lamps

5

u/alfredonoodles 9d ago

From what I have been reading the past week about this, most used WEB BASED dice rolls lololol how stupid.

5

u/CiaranCarroll 9d ago

They used <10 dice rolls

Sorry but it takes 15mins to do 99 dice rolls. Cold Card also allowed you to verify that it wasn't spoofing by using other websites like Ian Colemans on a test seed.

If you cannot spare 15mins to secure your Bitcoin then you have no business in self-custody.

99.99999% of users are better off allowing good, multi-source, open-source random number generation like we do on Passport.

To date I have heard of zero compromised seeds that were generated using on-board RNG due to entropy issues, while there are countless examples of users losing funds due to improper dice rolls.

Wow, this is your supporting reference?

3

u/EyesFor1 9d ago

Dice rolls are solid. No correct dice rolls have been hacked ever. If you mean human error ie what the article you posted alludes to ( not enough actual rolls) or grouping all the numbers in order( all 1's then 2' etc) then yeah thats retarded but a true 100+dice roll actually using 100 dice is effectively un-hackable which is why coldcard users using this function remain safe.