注册并分享邀请链接,可获得视频播放与邀请奖励。

Kevin Loaec 🧙‍♂️🐟
@KLoaec
@wizardsardine CEO 🪄🐟. ⬛🟨 ex Breaking Bitcoin and BoB. @btcazores @revaultdev @lianabitcoin
加入 March 2013
799 正在关注    11.6K 粉丝
By NOT rolling dice, you did NOTHING WRONG. You never were expected to roll dice or add a passphrase. Human generated entropy, even of great quality like dice, is LOWER than device generated entropy. The problem is, the device you bought to do that job was not doing it. Same as if you bought casino dice but they only roll 6s. Not your fault. The quoted tweet below is explaining why. How to protect yourself in the future, against a BUG in a signing device? The solution is not dice, that code could have been buggy too. The solution is MULTI-VENDOR MULTISIG. Any type of bug or attack in one device, you are still protected. Entropy, Key derivation (from dice for example), Signing (nonce), Malicious cryptographic library (Key exfil), Supply chain attack (physical RNG not random, not a code issue), etc, etc.
显示更多
0
74
542
81
转发到社区