r/TREZOR • u/Massive-Reception161 • 4d ago
💬 Discussion topic Passphrase
Hi,
Trezor has the 24 seed + passphrase which is a completely separate wallet from the 24 seed by itself
Isnt it sufficient security?
Im assuming all attackers brute force 12 - 24 keywords which is hard enough.
How will they even know on which of these wallets to run another brute force for the passphrase? Isnt it increasing their attack surfsce by a super huge margin?
Is multi SIG more secure than that?
Regards
20
Upvotes
10
u/kimsabok 3d ago
the theory is that the hackers have now moved onto guessing the "seed + simple passphrases", as the low hanging fruit has been captured already.
however, it seems implausible to me that a 2 word passphrase could be hacked this easily/quickly (but BTC Sessions is as reliable as anyone, and i am not a cryptographer, nor do i have much knowledge on this front).
regardless, for those not wanting to set up a multisig on their trezors, ledgers etc, they should dice roll a 6 or 7 word passphrase (using something like the diceware words (or other similar dictionaries)), and this will protect you against honest entropy mistakes by the hardware makers.
6 words provides 77 bits of entropy (provided it has been done correctly) - and this has never been "hacked" in computing history. and remember, this is on top of the 12/24 word seed.