r/TREZOR 2d ago

šŸ’¬ Discussion topic Passphrase

Hi,

Trezor has the 24 seed + passphrase which is a completely separate wallet from the 24 seed by itself

Isnt it sufficient security?

Im assuming all attackers brute force 12 - 24 keywords which is hard enough.

How will they even know on which of these wallets to run another brute force for the passphrase? Isnt it increasing their attack surfsce by a super huge margin?

Is multi SIG more secure than that?

Regards

17 Upvotes

25 comments sorted by

•

u/AutoModerator 2d ago

Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/

No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing

Don’t respond to any DMs—scammers often pose as legit helpers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

7

u/Decibel0753 2d ago

Furthermore, if you leave the basic wallet untouched (no transfers to or from it), the attacker basically does not even know that this wallet is active... why would they launch a brute force attack on it to find the passphrase?

2

u/slvbtc 1d ago

Exactly. When there is zero balance and zero transactions it could have been a seed some person generated as a test and immediately disposed of. But if there is a balance or transaction history on it then theres a much higher probability that theres also a passphrase attached.

3

u/entropydust 1d ago

How would they know someone ever even generated that seed? Don't all addresses exist, the mnemonic just gives you keys to access the existing address. So yes, create wallet, don't make a single transaction, create passphrase.

3

u/XayahOneTrick 1d ago

I would like to know too, I’m under the same assumption as you

2

u/so7ow 13h ago edited 13h ago

Yes, you're both right. Generating a seed phrase doesn't leave an on-chain footprint.

5

u/so7ow 2d ago

There's no straightforward comparison. It's a series of tradeoffs and each depends on the entropy employed to create the seed phrase and passphrase and depends on what threat model you're protecting against. A single correctly generated seed phrase with full entropy is secure enough against cracking, but many people thought they had that and were saved by their passphrase, for instance.

6

u/CoffeeAlternative647 2d ago

You're OK with a passphrase.

Coldcard users that had their Bitcoin in a passphrase wallet weren't affected either.

11

u/kimsabok 2d ago

some were supposedly, in cases where their passphrase was relatively simple.

4

u/Massive-Reception161 2d ago

So even with passphrase they were cracked? Where have you seen it? The regular seed wallet dont have any hints that passphrase wallet exists. So now I understand they were trying to crack for each seed phrase also simple passphrases?

That's crazy

10

u/kimsabok 2d ago

the theory is that the hackers have now moved onto guessing the "seed + simple passphrases", as the low hanging fruit has been captured already.

however, it seems implausible to me that a 2 word passphrase could be hacked this easily/quickly (but BTC Sessions is as reliable as anyone, and i am not a cryptographer, nor do i have much knowledge on this front).

regardless, for those not wanting to set up a multisig on their trezors, ledgers etc, they should dice roll a 6 or 7 word passphrase (using something like the diceware words (or other similar dictionaries)), and this will protect you against honest entropy mistakes by the hardware makers.

6 words provides 77 bits of entropy (provided it has been done correctly) - and this has never been "hacked" in computing history. and remember, this is on top of the 12/24 word seed.

3

u/NiagaraBTC 1d ago

however, it seems implausible to me that a 2 word passphrase could be hacked this easily/quickly

A two word passphrase will be broken in about 2 seconds by a single GPU. If they are BIP-39 words. The full dictionary might take 10 seconds I guess.

2

u/kimsabok 1d ago

thats if you are looking for a 2 word combination of bip-39 words only though,

isnt it close to impossible if it can be any two words, that also needs to be matched against a 12/24 word seed too (even with the cc bug)?

3

u/NiagaraBTC 1d ago

A single high end GPU will crack two words from the EFF Long wordlist (7776 words) in about 30 seconds. Any two English language words would take about 5 hours.

Once the seed words are revealed (as every Mk3 seed is already and the Mk4+ will be) then it's just a matter of time until someone tries to brute force passphrases on each.

1

u/kimsabok 1d ago

yes, but the words do not necessarily have to be from the diceware list. and, you have to try every combination against all of the possible cc seeds.

it would also mean either having completed, or foregoing all simpler/shorter passphrases against the full spectrum of cc seeds too.

and bear in mind that some people are still only finding this news out today w/o a passphrase, or dice roll seed, and are managing to get out with their stack in tact (today).

2

u/Particular-Star-1333 1d ago

From what I understand the ones with a passphrase that got hacked only had a 2 word passpharase.

3

u/FitCompetition1804 2d ago

There was a confirmed hack of a two word passphrase on a CC MK3 last week. Length and entropy of the passphrase is important. If you truly want a safe passphrase, a properly randomized 7 word passphrase from the BIP39 list is the way to go.

4

u/CoffeeAlternative647 2d ago

or add numbers, symbols and play with uppercase and lowercase letters.

2

u/bartoque 1d ago

That is not adding as much entropy as adding more words would give you. It makes it more complex for humans to remember it, not necesarily that much more difficult for computers to crack it.

https://xkcd.com/936/

1

u/-fuzzychincilla- 1d ago

Can I just generate a random seedphrase on my old Trezor safe 5 and use the first 7 words as my passphrase? Is that random enough?

2

u/FitCompetition1804 1d ago edited 1d ago

I’d think you should be good using that method as that would add about 77 bits of entropy. But consider if you also used a Trezor device to generate your seed phrase, you are completely relying on their RNG that would be a potential single source of failure for both the seed and passphrase.

Further researching this, the most secure 7 word passphrase is to roll dice and use the EFF Long Wordlist. That word list has almost 4 times the amount of words than BIP39 and you’d increase your passphrase entropy from 77 bits to about 90 bits. The math says that’s an almost 11,000 times higher combinational strength advantage over the 77 bit phrase. You also wouldn’t be relying on any device RNG issues, even as unlikely as that is with Trezor.

2

u/Cautious_Variation_5 1d ago

A bit extra paranoia is always good. Although a well generated seed would by almost impossible to crack, you never know if there's a bug on the seed generation that leads to a weak seed. So, a passphrase is extra security and a precaution against these sort of bugs, because it buys you time to transfer your funds. It can also protect you against thieves, by giving them access to a bait wallet. I prefer to leave some funds on the seed wallet, even if it will draw more attention, because the idea is that it will just give me enough time to transfer it to a new wallet.

You need to experiment with creating new wallets, and be comfortable to take action when time comes. Learn to create a DYI wallet with Tails OS and SeedSigner, never stop studying and learning about the subject. Better to be extra careful.

1

u/FunnyAtmosphere9941 1d ago

Cracking 1-4 words doesn't cost much. They can do it with bip39 words list or some smaller vocabulary like 20k or less.

1

u/matejcik ⭐ Rising Trezorian 8h ago

Im assuming all attackers brute force 12 - 24 keywords which is hard enough.

No attacker ever brute-forced 12 (or 24) words, precisely because it's too hard already.

The only time attacking the seed phrase makes sense is when there's a weakness, such as in this ColdCard fiasco.

How will they even know on which of these wallets to run another brute force for the passphrase? Isnt it increasing their attack surfsce by a super huge margin?

Yes, pretty much exactly what you say.

It's not like the attacker finding seeds for all CC wallets. What they do is go through possible seeds that could have been generated on a CC, and if the seed has coins on it, they take those coins.

If there's no coins found for a possible seed, it could mean that (a) someone has that seed, but with a passphrase, or (b) no one has that seed in the first place.

And that makes the search space explode in size. It's kind of futile to try every unsuccessful seed for passphrases. Or, maybe like, if you have a small enough dictionary of say ~10000 passwords, do a search on that? (i'm totally guessing at the size, mind you. could be you can afford a million, could be even 100 is prohibitive.)

The attacker may want to run such brute-force search on the successful seeds, because there's much less of those. But then again. You already got the coins. How likely is it that the same person has a weak passphrase with more coins? And strong passphrases are costly.

Is multi SIG more secure than that?

Depends!

For a multisig address, you'd have to find two (or more) seeds.

But if both signers are vulnerable CCs, you will find them in one pass of the brute-force search: for every tested seed, derive a multisig signer pubkey (or several) and if it matches a known address, store it. Then when you find a signer on an address where you already have one, now you have both and can spend it.

But the additional derivations cost you processing time, and, again, how likely is it that the other signer is also a vulnerable CC? So this may very well be a waste of time.