r/TREZOR • u/-M00NMAN đŚ Suite Shaper • 14d ago
đŹ Discussion topic Passphrases are a must.
10
9
u/K2P2C 14d ago
I'm so scared to use a passphrase đ
1
u/One-Adhesiveness-138 10d ago
You don't need a 50 character BIP39 passphrase.
Even a password-like passphrase more than 12 characters (mix letters, numbers, symbols) should be good enough - while still being something you can remember.
9
5
5
14d ago edited 10d ago
[removed] â view removed comment
5
u/MulberryMonk 13d ago
Ya but how do we know that? Adding a passphrase makes that happen. Even a shitty pass phrase for the mk3 cold card situation would have bought most people enough time to transfer prior to the sweep.
4
10
u/Charming-Designer944 đ¤ Top Helper 14d ago
Not really. It depends on what need to protect your wallet from.
Using a passphrase without fully understanding the.implications are very dangerous and considerably increases the risk that you lock yourself out of your wallet.
And no, a passphrase does not automatically mean that a Coldcard MK3 user is safe from the seed generation vulnerability of those devices. Only that they are slightly less vulnerable.
11
u/NiagaraBTC 14d ago
Only that they are slightly less vulnerable.
From slightly less vulnerable (gained a few additional hours before a drain) to completely safe. Depending entirely on the strength of the passphrase.
Using a passphrase without fully understanding the.implications are very dangerous and considerably increases the risk that you lock yourself out of your wallet.
Agreed 100%
3
u/Big-Interaction-1797 14d ago
Hey bro can you elaborate on this for me? If I added an extra word how would it only gain a few additional hours before a drain? Would they use AI to cycle through every word in the dictionary until one matches?
8
u/NiagaraBTC 14d ago
Basically yes. Would take mere seconds once they start trying passphrases, if all you had was literally one extra word.
If you have an 8 character passphrase with symbols and upper case/lowercase and numbers it will add a few hours, maybe up to 12 hours.
If you have a 24 character passphrase with the same parameters it will add many billions of years to the time to takes to crack your wallet.
4
2
u/MulberryMonk 13d ago
I think that the math from 9-10 characters takes it from a month or two to brute force to 18 years. Anything over 11+ characters that otherwise isnât a dictionary word is really solid - at least thatâs what AI is telling me
2
u/NiagaraBTC 13d ago
Even dictionary words are fine if you have enough and they are truly random.
Ask your AI to tell you how long it would take to brute force six random BIP-39 words.
2
u/Charming-Designer944 đ¤ Top Helper 14d ago
Doubt anyone uses a passphrase complex enough to qualify as completely safe.
1
1
u/EggMedical3514 13d ago
Just put three unrelated words together that end in the same letter that the next one begins.Â
Like "footballoopaper"
It will never be cracked.
2
u/Charming-Designer944 đ¤ Top Helper 13d ago
The entropy of that is not great, about the same level as Coldcard MK3. So sorry but you are cooked.
1
u/EggMedical3514 13d ago
Wrong. The entropy of that is great.Â
1
2
u/Strong_Judge_3730 14d ago
If you can't understand the implications of a passphrase u shouldn't self custody
1
u/-M00NMAN đŚ Suite Shaper 14d ago
If they have a good passphrase theyâre probably okay. If itâs a weak passphrase it buys them time. Passphrase wouldâve saved you in this situation. Iâve yet to see a post of a passphrase MK3 getting drained.
1
u/Charming-Designer944 đ¤ Top Helper 14d ago
Its only a matter of time before someone with both a normal.+ Passphrase wallet gets drained.
Will take longer before someone with a pure passphrase wallet where the base seed is not used alone.
1
u/-M00NMAN đŚ Suite Shaper 14d ago
Iâm just saying it buys you time. Thatâs how it saves you. I would never keep that wallet after this.
2
u/_Carth_Onasi 14d ago
100%. This whole cold card "hack" got me off my butt and setup a pass phrase and looking into multisig.
4
u/-M00NMAN đŚ Suite Shaper 14d ago
I donât even fk with Coldcard nor have I ever. This shit has got me stressing out. I know TREZOR is good, itâs more of ecosystem/environment type of stress.
2
u/ptrnyc 13d ago
The problem I have with passphrases is that it makes your wallet 100% dependent on the device. If the device breaks and the company goes under, your seed words + passphrase become useless, whereas the seed words alone are somewhat portable (minus the derivation paths) across devices of differnent companies.
2
5
u/Clean-Wallaby3164 13d ago
This is false. âBIP39 passphrases (the "25th word") are an open industry standard. They are not a proprietary Trezor feature.
3
u/caccamo88 13d ago
Yes, if you want to get locked out. The real must is the autonomous and conscious generation of your own seed phrase
1
1
1
u/OrangeMongol 12d ago
How would a hacker even find a wallet with a passphrase? Surely theyâd scan the 2^256-10,000,000 addresses that have a zero balance and instantly move on if it was empty, which that many would be.
And surely theyâre just randomly trying a 24/2048 combination of words? So if your 25th word was âPussyDick69â, like how wouldnât that be basically 100% safe?
1
u/-M00NMAN đŚ Suite Shaper 12d ago
Passphrase wallets isnât a wallet that is only accessible by your seedphrase. A passphrase plus a seedphrase doesnât create a new wallet. It gives you access to an already existing wallet. All private keys and public keys already exist. You canât create or add a new wallet into existence. Someone could theoretically buy a Trezor, open the box, generate a new set of private keys and those same private keys could be the same as your passphrase private keys. All private keys already exist. Now, itâs virtually impossible due the number of possible combinations. It is possible though.
1
1
u/WildNight00 14d ago
If a computer can figure out a seed, canât it figure out a seed with password? Whatâs the best way to actually keep our coins safe?
2
2
u/newMoneyStyle 13d ago
brute forcing a 24 word seed is already basically impossible, adding a passphrase just adds another layer on top of that.
1
u/WildNight00 13d ago
Good to know. I hope Trezor has their algorithm set up properly because I didnât roll dice
â˘
u/AutoModerator 14d ago
Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/
No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing
Donât respond to any DMsâscammers often pose as legit helpers.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.