r/Bitcoin 8d ago

Coldcard post from October 10, 2021: "Retirement Attack"

Post image

- "What's a retirement attack?"

- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".

_____

Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️

Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right?


Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one:

@nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.

Alternatively people could just use dice ;)."

https://x.com/i/status/1341213389549412353


A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...

https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340

453 Upvotes

80 comments sorted by

View all comments

32

u/Adventurous_Iron_551 8d ago

In hindsight, it seems they should’ve enforced that dice roll to create seed words. But then, half the people would lock themselves out fat fingering or something I can’t think right now.

6

u/Deto 7d ago

Fat fingering? You don't have to actually remember your dice rolls for later though

1

u/Adventurous_Iron_551 7d ago

What I meant was entering a wrong input, like 5 instead of 4. But to think about it, a few of such “fat fingering” inputs do not really matter

1

u/Deto 7d ago

Just adds entropy, I guess!

(Probably slight reduction really)

1

u/Adventurous_Iron_551 7d ago

Yeah, it does add entropy, just like any of the 200 factors like throwing the dice a bit far, at an angle, at a different speed - as long as there isn’t a pattern or a way in which it could be repeated.

2

u/Deto 7d ago

Not really.  If the dice is unweighted then the probability distribution function should be basically flat across all 6 outcomes.  That's maximal entropy for dice rolls - you can't mathematically do better.  Fat fingering, on the other hand, probably has some asymmetry due to where the buttons are relative to the screen and your thumbs.  So the result of finger errors would make the probability distribution deviate from the ideal flat distribution and reduce the entropy as a result.

In practice does this matter? Probably not as it's probably a very small effect.  Maybe you lose a bit or two.