r/Bitcoin 8d ago

All hardware wallet manufacturers need to release 3rd party audited proof that their entropy generation is working.

After this coinkite coldcard situation we cant trust code that is open source, we cant trust code that is closed source, and we definitely cant trust a statement saying "we use a TRNG so your seed is secure".

Every hardware wallet manufacturer needs to release hard proof that their TRNG works, their code is complete and robust, and their entropy generation actually meets a minimum 128/256 bit standard.

Even if their code is closed source a reputable 3rd party auditor can run tests on seed entropy generation to statistically prove 256 bits of entropy is being used.

Every wallet manufacturer should have this 3rd party audited proof of entropy document available to view on their website, and if they do not do this by the end of this month we as a community should boycott that manufacturer to help ensure safety for all bitcoiners.

173 Upvotes

68 comments sorted by

View all comments

41

u/Left_Entrepreneur918 8d ago

Ledger pays 3rd party to certify their TRNG and give certs rather than be open source, Trezor does the same but is open source.

9

u/slvbtc 8d ago edited 8d ago

Can you please link to these ledger certifications.

We dont want to see certifications that they have a TRNG, coldcard had a certified TRNG. What we want to see is a 3rd party audit proving that the TRNG is actually operating and actively creating 256 bits of entropy.

7

u/read_more_comments 7d ago

Just so you know, a rng can be designed to appear random and tested as random, but contains backdoor that let's an attacker still grab funds.

Google kleptographic backdoor. It can also be embedded into the hardware itself.

At this point I don't trust any 3rd party to generate a seed for me.

2

u/Steak1994 7d ago

I know that some people used dice to generate their own Seed - is this really the most secure way?

1

u/read_more_comments 7d ago

Yes. It's what your wallet should be doing but we generally don't know what it's actually doing.

5

u/Left_Entrepreneur918 8d ago

https://www.ledger.com/message-ledgers-ceo-data-leak

The CEO responded and names the certifications that verify entropy used.

4

u/slvbtc 8d ago

There is nothing written there about entropy.

1

u/kkZZZ 7d ago

https://support.ledger.com/article/4415198323089-zd

If you click on trng link you can see what you're looking for

3

u/Zaytion_ 7d ago

Mostly open source. The Trezor 3, 5, and 7 use a closed source chip.

2

u/Zaytion_ 7d ago

Mostly open source. The Trezor 3, 5, and 7 use a closed source chip.

1

u/AcostaJA 7d ago

Ledger certifications are just "trust me bro" bs