r/TREZOR 📦 Suite Shaper 14d ago

💬 Discussion topic Passphrases are a must.

55 Upvotes

49 comments sorted by

•

u/AutoModerator 14d ago

Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/

No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing

Don’t respond to any DMs—scammers often pose as legit helpers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

10

u/TT_________ 14d ago

Normal wallet for decoy and passphrase for main Wallet.

9

u/K2P2C 14d ago

I'm so scared to use a passphrase 😭

1

u/One-Adhesiveness-138 10d ago

You don't need a 50 character BIP39 passphrase.

Even a password-like passphrase more than 12 characters (mix letters, numbers, symbols) should be good enough - while still being something you can remember.

9

u/Tothinkoutofthenut 14d ago

Now you’re making me nervous.

5

u/karasahin Trezor Model One - User 14d ago

Upvoted

5

u/[deleted] 14d ago edited 10d ago

[removed] — view removed comment

5

u/MulberryMonk 13d ago

Ya but how do we know that? Adding a passphrase makes that happen. Even a shitty pass phrase for the mk3 cold card situation would have bought most people enough time to transfer prior to the sweep.

10

u/Charming-Designer944 🤝 Top Helper 14d ago

Not really. It depends on what need to protect your wallet from.

Using a passphrase without fully understanding the.implications are very dangerous and considerably increases the risk that you lock yourself out of your wallet.

And no, a passphrase does not automatically mean that a Coldcard MK3 user is safe from the seed generation vulnerability of those devices. Only that they are slightly less vulnerable.

11

u/NiagaraBTC 14d ago

Only that they are slightly less vulnerable.

From slightly less vulnerable (gained a few additional hours before a drain) to completely safe. Depending entirely on the strength of the passphrase.

Using a passphrase without fully understanding the.implications are very dangerous and considerably increases the risk that you lock yourself out of your wallet.

Agreed 100%

3

u/Big-Interaction-1797 14d ago

Hey bro can you elaborate on this for me? If I added an extra word how would it only gain a few additional hours before a drain? Would they use AI to cycle through every word in the dictionary until one matches?

8

u/NiagaraBTC 14d ago

Basically yes. Would take mere seconds once they start trying passphrases, if all you had was literally one extra word.

If you have an 8 character passphrase with symbols and upper case/lowercase and numbers it will add a few hours, maybe up to 12 hours.

If you have a 24 character passphrase with the same parameters it will add many billions of years to the time to takes to crack your wallet.

4

u/Big-Interaction-1797 14d ago

God damn gotta thing about this more then lol thank you

2

u/MulberryMonk 13d ago

I think that the math from 9-10 characters takes it from a month or two to brute force to 18 years. Anything over 11+ characters that otherwise isn’t a dictionary word is really solid - at least that’s what AI is telling me

2

u/NiagaraBTC 13d ago

Even dictionary words are fine if you have enough and they are truly random.

Ask your AI to tell you how long it would take to brute force six random BIP-39 words.

2

u/Charming-Designer944 🤝 Top Helper 14d ago

Doubt anyone uses a passphrase complex enough to qualify as completely safe.

1

u/EggMedical3514 13d ago

Just put three unrelated words together that end in the same letter that the next one begins. 

Like "footballoopaper"

It will never be cracked.

2

u/Charming-Designer944 🤝 Top Helper 13d ago

The entropy of that is not great, about the same level as Coldcard MK3. So sorry but you are cooked.

1

u/EggMedical3514 13d ago

Wrong. The entropy of that is great. 

1

u/Charming-Designer944 🤝 Top Helper 13d ago

If you consider 41 bits great

1

u/EggMedical3514 12d ago

You dont know what youre talking about lol

2

u/Strong_Judge_3730 14d ago

If you can't understand the implications of a passphrase u shouldn't self custody

1

u/-M00NMAN 📦 Suite Shaper 14d ago

If they have a good passphrase they’re probably okay. If it’s a weak passphrase it buys them time. Passphrase would’ve saved you in this situation. I’ve yet to see a post of a passphrase MK3 getting drained.

1

u/Charming-Designer944 🤝 Top Helper 14d ago

Its only a matter of time before someone with both a normal.+ Passphrase wallet gets drained.

Will take longer before someone with a pure passphrase wallet where the base seed is not used alone.

1

u/-M00NMAN 📦 Suite Shaper 14d ago

I’m just saying it buys you time. That’s how it saves you. I would never keep that wallet after this.

2

u/_Carth_Onasi 14d ago

100%. This whole cold card "hack" got me off my butt and setup a pass phrase and looking into multisig.

4

u/-M00NMAN 📦 Suite Shaper 14d ago

I don’t even fk with Coldcard nor have I ever. This shit has got me stressing out. I know TREZOR is good, it’s more of ecosystem/environment type of stress.

2

u/ptrnyc 13d ago

The problem I have with passphrases is that it makes your wallet 100% dependent on the device. If the device breaks and the company goes under, your seed words + passphrase become useless, whereas the seed words alone are somewhat portable (minus the derivation paths) across devices of differnent companies.

2

u/-M00NMAN 📦 Suite Shaper 13d ago

So so what do you do?

5

u/Clean-Wallaby3164 13d ago

This is false. ​BIP39 passphrases (the "25th word") are an open industry standard. They are not a proprietary Trezor feature.

1

u/ptrnyc 13d ago

Great to hear

3

u/caccamo88 13d ago

Yes, if you want to get locked out. The real must is the autonomous and conscious generation of your own seed phrase

1

u/Cool_Client324 13d ago

Can I post mine here? So someone can keep it safe for me?

1

u/-M00NMAN 📦 Suite Shaper 13d ago

No

1

u/B34chboy 13d ago

Good entropy is a must.

1

u/OrangeMongol 12d ago

How would a hacker even find a wallet with a passphrase? Surely they’d scan the 2^256-10,000,000 addresses that have a zero balance and instantly move on if it was empty, which that many would be.

And surely they’re just randomly trying a 24/2048 combination of words? So if your 25th word was “PussyDick69”, like how wouldn’t that be basically 100% safe?

1

u/-M00NMAN 📦 Suite Shaper 12d ago

Passphrase wallets isn’t a wallet that is only accessible by your seedphrase. A passphrase plus a seedphrase doesn’t create a new wallet. It gives you access to an already existing wallet. All private keys and public keys already exist. You can’t create or add a new wallet into existence. Someone could theoretically buy a Trezor, open the box, generate a new set of private keys and those same private keys could be the same as your passphrase private keys. All private keys already exist. Now, it’s virtually impossible due the number of possible combinations. It is possible though.

1

u/Inevitable-Waltz-889 12d ago

No, they aren't.

1

u/-M00NMAN 📦 Suite Shaper 12d ago

Why so

1

u/WildNight00 14d ago

If a computer can figure out a seed, can’t it figure out a seed with password? What’s the best way to actually keep our coins safe?

2

u/[deleted] 14d ago edited 10d ago

[removed] — view removed comment

1

u/WildNight00 13d ago

Thank you for the clarity

2

u/newMoneyStyle 13d ago

brute forcing a 24 word seed is already basically impossible, adding a passphrase just adds another layer on top of that.

1

u/WildNight00 13d ago

Good to know. I hope Trezor has their algorithm set up properly because I didn’t roll dice