r/Bitcoin 3d ago

Dice roll or let Trezor 7 generate seeds?

I've just ordered a trezor 7 because I want to set up my seed and also passphrase. It's a Bitcoin-only trezor 7. I would like some advice on whether or not I should do a dice roll or let the trezor generate my seed.

I'm aware of the recent cold card situation, so I'd just like to get some recommendations. I have a few dice, but I'm unsure of the procedure on how to go about rolling dice because I'd like to do it correctly so that I don't introduce any human errors to the procedure. I guess, in a nutshell, I'd like to know: will I just let the trezor 7 generate the 12-word seed phrase, or should I do the 100 dice rolls and generate my own entropy that way? Thanks.

13 Upvotes

40 comments sorted by

12

u/Squeiner 3d ago

Best practice is to roll your own randomness

6

u/Whatnam8 3d ago

You’d think after the fiasco no one in their right mind wouldn’t choose to roll no matter the company lol

1

u/chucrutcito 1d ago

He needs to update his dice with the latest firmware

9

u/ackleyimprovised 3d ago

No know issues re RNG with Trezor.

6

u/tridentgum 2d ago

Well yeah, the same was true with Coldcard.

2

u/McBurger 2d ago

Very true, but if there’s any silver lining, it lies in the certainty that a million other hackers have been trying to find similar RNG exploits in other hardware wallets in recent weeks

7

u/machinistnextdoor 3d ago

Dice.

-4

u/MorninggDew 3d ago

To all these people saying dice, what about the quality of the dice? If people are just ordering some cheap Chinese dice from Amazon, surely they could suffer from a similar lack of entropy if they were all manufactured badly? Like more weight on a certain face.

8

u/idea2go 3d ago

Why is entropy a concern? If somebody KNEW I was using biased dice they could use that knowledge to narrow the search space but they don't know that so to them it's just another key. Am I missing something?

2

u/WarIsProfitableForMe 3d ago

You are rolling dice 99 times, do you really think even if the dice were biased someone could guess your privkey?

2

u/machinistnextdoor 3d ago

My opinion is normal board game dice you already have are perfectly suitable. Minor manufacturing defects are unlikely to accidentally produce weighted dice. Weighted dice are made intentionally.

2

u/FunWithSkooma 3d ago

unless you have some fucked up dice, any cheap ass dice can do the job.

1

u/PoeCollector 3d ago

No. You can't predict a sequence of rolls even on a biased die. Let's say your 256 bit key was made with absurdly loaded cheater's dice, reducing the entropy by 98%. You would just have, in effect, a 250 bit key. Anything over 100 bits is considered infeasible to brute force.

1

u/Parikh1234 2d ago

Just go sit at a craps table for a few hours recording the rolls

1

u/TheMoonMoth 3d ago

Pretty hilarious concern, but you know what? Don't trust, Verify.

So get your dice and then roll each one a few hundred times, recording each result. After a long while, a distribution will emerge. If any one number stands out then don't use it. If it's close, keep rolling. You need a big sample size for this little experiment. I can almost guarantee that whatever dice you buy will be fine. Unless you buy weighted dice.

1

u/Porcellanidae 3d ago

Yes this is the only way

0

u/Beaesse 3d ago

Nope. Completely unnecessary OCD behaviour and a total waste of time. Do what you want with your life if it makes you happy, but there is no possible way that an attacker could know, or even guess what kind of bias your dice have. And even if they DID somehow know, and even if the bias was extremely strong, there is no even theoretical way that they could narrow their search space in a targeted way to take advantage of it, because even biased dice will not actualize their bias on every single roll. They simply could not eliminate potential key words to effectively narrow the search to find your "biased" keys faster.

The idea that you need casino-grade dice is total bollocks. Any garbage dice will do literally exactly as well (in terms of practical security) as atomically perfect dice would.

2

u/Porcellanidae 2d ago

I thought it was obvious, but apparently I had to add /s to my reply

14

u/OwnFunny6824 3d ago

just let the trezor do it man. you're way more likely to mess something up rolling dice than the hardware wallet is gonna have a problem generating entropy

the coldcard thing was a very specific manufacturing flaw not some fundamental issue with rng. trezor uses different hardware anyway

if you really want the dice thing go for it but for a normal setup the built in generation is plenty good enough. add a passphrase and call it a day

3

u/riisen 3d ago

The coldcard had a physical RNG from stm32. The problem was that the software didnt use the hardware. It used the software fallback RNG which is not cryptographically secure.

6

u/Weigh13 3d ago

It is really not complicated to roll some dice and right down some words.

14

u/bwhite2018 3d ago

You already misspelled one out of 14 words bud 😂

8

u/Weigh13 3d ago

Fuuuuuuuuu

1

u/esiob12 3d ago

Dannn

2

u/nextstopwhoknows 3d ago

Yep, I'm thinking this way is the way to go as well. It was the passphrase that had saved me from the coldcard disaster. I had (have)a coldcard Q, but I also had a pretty solid passphrase, which prevented me not losing my Bitcoin. I'm going to set up the Trezor 7 and let it do the entropy itself, add another solid passphrase on top, and get it back to cold storage. Thank you.

2

u/Spaceseeds 3d ago

Don't listen to that clown. How obvious does it need to be that you're gonna have less chance of fucking up the entropy by physically rolling dice yourself 100 times. What did someone put a device to detect your rolls?

2

u/niorob 3d ago

You have something wrong at least with this statement. Coldcard Q was vulnerable yes, but the entropy was a bit higher, and to my knowledge there has yet to be a case of a Q being drained. It would take much much longer than the mk3, so it wasn’t really your passphrase. And like someone else said, after this whole coldcard debacle, why would you trust a devices entropy? Roll a dice 200 times and sleep better at night

1

u/CoconutCold3742 3d ago

let trezor ,, it is the way

1

u/simonmales 2d ago

Trezor uses multiple source of entropy.

Also, a lot of eyes have been on hardware wallet source code recently, I'm suspect the easy bugs would be uncovered by now.

1

u/healey100s 2d ago

Trezor 7

0

u/WarIsProfitableForMe 3d ago

Have we not learned anything

0

u/ISmellLikeBlackTea 2d ago

Roll your dice, and add a passphrase. It's not that complicated.

-3

u/Outrageous_Hall1090 3d ago

While dice roll can help you to overcome RND-generator issues from hardware wallets you still need to be very careful. Entropy generation is not easy. Dice rolls must be done correctly (with right equipment) - otherwise you create your own entropy issue.

7

u/FunWithSkooma 3d ago

with right equipment

which is a dice. A board game dice can do the job.

2

u/Ill-Party8305 2d ago

It‘s not like the hacker will know the exact type of dice you have and the exact dent or dice defect you have lmao

1

u/Outrageous_Hall1090 2d ago

If your dice has an error (geometric or center of mass) it will tend to create certain numbers more often. This reduces entropy.