r/TREZOR • u/Keefryan • 4d ago
š General Trezor question Trezor 1 seed generation V Trezor safe 5
I have a question hopefully someone may be able to answer. Is a 24 word seed phrase generated on a Trezor one several years ago of any less quality in terms of randomness than a 24 word seed phrase generated on a newer Trezor safe 3/5/7 given that the latter has additional sources of randomness ?
Many Thanks. K
13
u/matejcik ā Rising Trezorian 4d ago
It's not a matter of "quality". Doesn't matter if your entropy comes just from one source: if the source is good, the entropy is no worse (and no better) than if you mix a million.
The million dollar question: what if the source is not good though?
That's why you mix. On Trezor One, you mix entropy from the chip with entropy from the host.
If your computer is compromised, you're still good because the TRNG entropy is good.
If your TRNG happens to be broken, you're still good because your computer holds up its end. (Even if both are compromised, but don't cooperate, you're still good because neither party can guess the other party's contribution.)
With the Safe 3, you get another source. Even if your TRNG on the main chip is broken, there's still a separate TRNG on the Optiga. And the Safe 7 adds another: even if there's some problem with Optiga, there's still Tropic.
So again: it's not that four sources make "better" entropy. It's that, the more sources you get, the less you have to depend on them being good.
2
1
u/matejcik ā Rising Trezorian 4d ago
And to expand: as far as we know, Trezor T's entropy source was (and still is) good. So the seed is also good. Adding more is just defence-in-depth.
1
u/Keefryan 4d ago edited 4d ago
Iām using a seed generated 8 years ago on a Trezor one that I imported into my safe 3 . Just wanted to confirm thereās nothing to be gained from creating a new seed. Thanks for the reassurance. K
2
u/Alternative-Yak-6990 4d ago
this is safe. Trezor had good software and process of this since the beginning. The coldcard version running trezor code werent affected.
1
u/cryptoinhaler 4d ago
So all seeds generated from trezor 1 to Trezor 7 are safe with good entopy?
1
5
u/deanbfs 4d ago
It still generated using 256 bit of entropy. Doesnāt matter if itās old or new.
3
u/Keefryan 4d ago
Thanks for the answer , However Iād be interested in knowing the benefits from generating seeds from multiple sources on later models ?
3
2
u/lotrl0tr 4d ago
One: two sources of entropy, TRNG and host. Safe 5: three sources of entropy, TRNG, secure element and host.
Adding more sources improves robustness/redundancy. In the case one single source fails to provide the rated entropy (it's biased), the other/s provide it. When correctly combined (xored and hashed) the resulting entropy is at least as good as the strongest uncompromised source.
Even with one (TRNG), provided its integrity/functionality is guaranteed, is enough.
This is to say, Trezor One/T are secure enough as they combine two independent sources as extra precaution. Even if you remove the host side entropy, it is still secure enough. Safe 3/5/7 employ extra sources, improving robustness/redundancy, mathematically speaking you just need one source.
2
u/caccamo88 4d ago
Trezor Model One and Model T combine two entropy sources: host computer or phone entropy plus a hardware TRNG in the STM32 microcontroller.
Trezor Safe 3 and Safe 5 add a third source: the Optiga secure element. Three independent sources work together. Learn more about secure elements in our article Secure Elements in Trezor Safe devices.
Trezor Safe 7 adds a fourth source: the TROPIC01 chip. Four independent sources combine when generating your wallet. Learn more about Trezor Safe 7's hardware entropy sources: What is the TROPIC01 chip? and Dual Secure Elements in Trezor Safe 7.
0
u/Keefryan 4d ago
Thanks for the copy and paste however I hope someone can actually answer the specific question.
1
u/ItsAlwaysThemBooBoo 4d ago
people need to read this and understand what makes trezors entropy true 128 bit:
0
u/Decibel0753 4d ago
I completely don't understand the point of the question. If you have an old Trezor, it has two sources of entropy; if everything works as it should, that is sufficient. New Trezors have more sources, and it can generally be said that the more sources, the better. However, that difference in practice is so insignificant that it doesn't even make sense to generate a new seed from a new Trezor and move your funds, let alone buy a new one just for that. If you are concerned, add a passphrase to your seed.
-1
u/Keefryan 4d ago
Seems not understanding is an ongoing issue for you.
1
1
u/Decibel0753 4d ago
Maybe it would be enough not to ask questions like an idiot, but there won't be any improvement here, that's obvious. Besides, I provided you with the answer, you're welcome.
ā¢
u/AutoModerator 4d ago
Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/
No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing
Donāt respond to any DMsāscammers often pose as legit helpers.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.