How To Verify Coldcard's Dice Roll Math

Coinkite
Coinkite
2.8 هزار بار بازدید - 4 سال پیش - 0:17
0:17 Security DISCLAIMER
0:27 Create seed with dice rolls
01:18 Learn more about Tails https://tails.boum.org/about/index.en...
01:44 https://coldcardwallet.com/docs/verif...
02:25 Command to verify :  echo "dice rolls" | python3 rolls.py



Learn to independently verify Coldcard wallet is doing what it says it is when creating a new seed using dice rolls.

With most hardware wallets, it isn't possible to independently verify the randomness used to create your unique seed. This could be a potential attack vector, even if you generated the seed completely separate from any internet connected device ( airgapped).

This guide demonstrates how to reproduce the randomness used to create a seed on separate hardware. We are verifying that Coldcard does in fact use the randomness from the dice rolls and not a non random but random looking value.

Unless you understand all potential security issues with exposing a seed on an internet connected device, NEVER use this method to verify your actual seed.

First we create a new seed using dice rolls on an airgapped Coldcard. For demonstration purposes we use 15 rolls. The minimum number of rolls for a wallet should always be 99. Keep track of the dice rolls, because we need to use that record for verification in the next step.

Write down the seed words created by the 15 dice rolls and then boot up a fresh instance of Tails.

You can use the guides values to verify if you want.
Dice Rolls: 523365252662366

Generated Seed Words
1 dilemma
2 rural
3 physical
4 exhaust
5 divorce
6 escape
7 nut
8 umbrella
9 lawn
10 midnight
11 prosper
12 prevent
13 employ
14 caught
15 mercy
16 student
17 arctic
18 umbrella
19 feed
20 super
21 mad
22 magic
23 crawl
24 fiscal

Tails is a portable operating system that protects against surveillance and censorship. Tails always starts from the same clean state and everything you do disappears automatically when you shut down Tails.Nothing is written to the hard disk and only runs from the memory of the computer. The memory is entirely deleted when you shutdown Tails, erasing all possible traces.

For the purpose of demonstration we use an internet connected instance of Tails to download rolls.py script, which will verify the dice rolls. Once we download the python script, we turn off all network connections and proceed to verify the dice rolls and seed words.

Check out Coldcard's written guide.
https://coldcardwallet.com/docs/verif... Brought to you by
https://coldcardwallet.com/
https://www.keepitsimplebitcoin.com/
4 سال پیش در تاریخ 1399/08/22 منتشر شده است.
2,816 بـار بازدید شده
... بیشتر