Latest reviewed change
source content difference between and
New post by Satofan44 arguing that a good passphrase is the practical best setup for most users and that paranoid advanced setups are only warranted for hobbyists or very high values.
but if you then keep it on a sheet of paper... bad
if you don't put the passphrase, bad
it's a whole journey, not a single mega paranoid action
+Title: Re: dice or not dice
+Post by: Satofan44 on August 07, 2026, 12:13:21 PM
+Quote from: babo on Today at 08:05:49 AM
+These are all interesting discussions, and they are all more or less paranoid methods.
+However, as a cybersecurity expert I always remind people that the strength of a chain is always measured by weighing its weakest link.
First lines only. The complete diff is in the timeline below.
- Organisation
- BitcoinTalk
- Evidence role
- Community discussion
- Published
- 2026-08-06
- Source changes
- 1
- Detected differences
- 2
- Unreviewed
- 0
- Copies held
- 3
babo relaying a Telegram debate over casino-grade dice for seed generation, citing what another user describes as a 1971 Harvard study of 219 commercial dice that found bias worth at most about one bit of entropy on a 24-word seed. Replies argue the dice response to the COLDCARD issue is overblown and that physical coercion dwarfs entropy bias. The forum's dice-paranoia record, carrying a specific checkable claim that is the posters' own and not verified here.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
New post by Satofan44 arguing that a good passphrase is the practical best setup for most users and that paranoid advanced setups are only warranted for hobbyists or very high values.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 15 lines
but if you then keep it on a sheet of paper... bad if you don't put the passphrase, bad it's a whole journey, not a single mega paranoid action +Title: Re: dice or not dice +Post by: Satofan44 on August 07, 2026, 12:13:21 PM +Quote from: babo on Today at 08:05:49 AM +These are all interesting discussions, and they are all more or less paranoid methods. +However, as a cybersecurity expert I always remind people that the strength of a chain is always measured by weighing its weakest link. +that's the strength index of a chain +if you generated the seed using fairy farts which are random, good +but if you then keep it on a sheet of paper... bad +if you don't put the passphrase, bad +it's a whole journey, not a single mega paranoid action +Sure, but you need to think about it more simply and especially in the context of what happened recently. One should not invest $100k to create a vault that takes 5 days of verification to enter in order to protect $5000. Most users should neither do dice setups, nor multisignatures. The security setup must be as practical as it is safe in relation to the value that it is supposed to be protecting, everything else is wrong for one reason or another. A good passphrase solves: +1) Weak seed generation by the user. +2) Weak seed generation by the company. +3) Any other potential human error that could be introduced in these advanced setups. +It just works, and it does not need any special knowledge. The same knowledge regarding the backing up of your seed applies to the seedphrase, redundancy, avoid keeping the whole thing in a single place, etc. This is the best setup for most users.Being paranoid is never warranted, advanced setups should stay primarily for hobby users who are personally interested in them and those that are protecting very high values. Powered by SMF 1.1.19 | SMF © 2006-2009, Simple MachinesExtracted text as captured
Bitcoin Forum Bitcoin => Bitcoin Discussion => Topic started by: babo on August 06, 2026, 07:25:08 AM Title: dice or not dice Post by: babo on August 06, 2026, 07:25:08 AM There's a lot of confusion about this and people are really going crazy after the COLDCARD issue, I just wanted to share with you the discussion I had with some people on Telegram On Telegram, as I was saying earlier, there's a lot of excitement in the serious Bitcoin groups and all they do is talk about dice and bullshit like that... always related to seed generation. There are people who are sick and overdo it and recommend the AAA grade dice from the casino because they are perfect and balanced. but could something like this ever be true? If they ask you, the answer is no. I had it calculated and the deviation would be 1% in the case of cheap commercial dice... that is to say a die that has a percentage on one face not of 16,..% but of 17/19% maximum... (otherwise it is rigged) Another user went to look through the statistical mathematics literature Quote I found a Harvard University study published in 1971, when Bitcoin didn't even exist. The researchers analyzed 219 commercial dice from four different brands, rolling each die 20,000 times, for a total of 4,380,000 rolls. The study found small statistical biases in some commercial dice, but if we translate those results into the entropy of a 24-word BIP39 seed, the loss is on the order of a few tenths of a bit, at most about 1 bit under the most pessimistic assumptions. In practice, a 256-bit seed would still be a seed with approximately 255-256 bits of effective entropy. This difference is theoretically measurable, but completely irrelevant from a security perspective: the search space remains astronomical and impossible to explore with any existing technology. so commercial dice are more than fine, this is the conclusion about dice Title: Re: dice or not dice Post by: pooya87 on August 06, 2026, 08:41:18 AM There is no such thing as perfect in this world. There will always be some flaw or bias in anything you can find. The real question is does it matter? In case of a 256-bit entropy, you are already overdoing it by 2x since you only needed 128 bits of entropy to be secure. So a little bias in it doesn't affect anything. I also think in this case people are overreacting to the news. Lets see some statistics... how many bitcoin keys were created so far? Some sources say 1.5 billion. How many of them were created using a dice? 10? 1000? I doubt it is any more than that. How many of the rest of the 99.9999% of the addresses that were created by a computer were vulnerable? 0 as long as the code didn't have bugs! The CSPRNG people are trying to replace by rolling a dice is safe enough as it has been proven by bitcoin for 17 years. Title: Re: dice or not dice Post by: Catenaccio on August 06, 2026, 09:54:00 AM Quote from: pooya87 on August 06, 2026, 08:41:18 AM There is no such thing as perfect in this world. There will always be some flaw or bias in anything you can find. The real question is does it matter? In case of a 256-bit entropy, you are already overdoing it by 2x since you only needed 128 bits of entropy to be secure. So a little bias in it doesn't affect anything. Could you explain why we only need 128 bits of entropy to be secure, please. Because I know that there are 24 seed words for 256 bits of entropy and it is available to use easily so why we don't use 24 seed words for better security? Between 12 seed words with 128 bits of entropy and passphrase, and 24 seed words with 256 bits of entropy without passphrase, which one is more secure? I am considering to create a new wallet with a passphrase to use but not sure I should use 12 seed words or 24 seed words. Title: Re: dice or not dice Post by: Zoomic on August 06, 2026, 10:46:15 AM One mistake we do sometimes is confusing "not perfect" with "not usable". The truth is there are some level of bias or imperfection in almost everything we use. What we should be concerned about is wether that bias actually reduce the entropy enough to make a brute force attack more practical. If the loss of entropy is very small, then it is still practically impossible for a 24-word BIP39 seed to crack. Instead of chasing mathematical perfection, why not we focus on real world security? Title: Re: dice or not dice Post by: babo on August 06, 2026, 11:42:36 AM Quote from: Zoomic on August 06, 2026, 10:46:15 AMExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
Bitcoin Forum Bitcoin => Bitcoin Discussion => Topic started by: babo on August 06, 2026, 07:25:08 AM Title: dice or not dice Post by: babo on August 06, 2026, 07:25:08 AM There's a lot of confusion about this and people are really going crazy after the COLDCARD issue, I just wanted to share with you the discussion I had with some people on Telegram On Telegram, as I was saying earlier, there's a lot of excitement in the serious Bitcoin groups and all they do is talk about dice and bullshit like that... always related to seed generation. There are people who are sick and overdo it and recommend the AAA grade dice from the casino because they are perfect and balanced. but could something like this ever be true? If they ask you, the answer is no. I had it calculated and the deviation would be 1% in the case of cheap commercial dice... that is to say a die that has a percentage on one face not of 16,..% but of 17/19% maximum... (otherwise it is rigged) Another user went to look through the statistical mathematics literature Quote I found a Harvard University study published in 1971, when Bitcoin didn't even exist. The researchers analyzed 219 commercial dice from four different brands, rolling each die 20,000 times, for a total of 4,380,000 rolls. The study found small statistical biases in some commercial dice, but if we translate those results into the entropy of a 24-word BIP39 seed, the loss is on the order of a few tenths of a bit, at most about 1 bit under the most pessimistic assumptions. In practice, a 256-bit seed would still be a seed with approximately 255-256 bits of effective entropy. This difference is theoretically measurable, but completely irrelevant from a security perspective: the search space remains astronomical and impossible to explore with any existing technology. so commercial dice are more than fine, this is the conclusion about dice Title: Re: dice or not dice Post by: pooya87 on August 06, 2026, 08:41:18 AM There is no such thing as perfect in this world. There will always be some flaw or bias in anything you can find. The real question is does it matter? In case of a 256-bit entropy, you are already overdoing it by 2x since you only needed 128 bits of entropy to be secure. So a little bias in it doesn't affect anything. I also think in this case people are overreacting to the news. Lets see some statistics... how many bitcoin keys were created so far? Some sources say 1.5 billion. How many of them were created using a dice? 10? 1000? I doubt it is any more than that. How many of the rest of the 99.9999% of the addresses that were created by a computer were vulnerable? 0 as long as the code didn't have bugs! The CSPRNG people are trying to replace by rolling a dice is safe enough as it has been proven by bitcoin for 17 years. Title: Re: dice or not dice Post by: Catenaccio on August 06, 2026, 09:54:00 AM Quote from: pooya87 on August 06, 2026, 08:41:18 AM There is no such thing as perfect in this world. There will always be some flaw or bias in anything you can find. The real question is does it matter? In case of a 256-bit entropy, you are already overdoing it by 2x since you only needed 128 bits of entropy to be secure. So a little bias in it doesn't affect anything. Could you explain why we only need 128 bits of entropy to be secure, please. Because I know that there are 24 seed words for 256 bits of entropy and it is available to use easily so why we don't use 24 seed words for better security? Between 12 seed words with 128 bits of entropy and passphrase, and 24 seed words with 256 bits of entropy without passphrase, which one is more secure? I am considering to create a new wallet with a passphrase to use but not sure I should use 12 seed words or 24 seed words. Title: Re: dice or not dice Post by: Zoomic on August 06, 2026, 10:46:15 AM One mistake we do sometimes is confusing "not perfect" with "not usable". The truth is there are some level of bias or imperfection in almost everything we use. What we should be concerned about is wether that bias actually reduce the entropy enough to make a brute force attack more practical. If the loss of entropy is very small, then it is still practically impossible for a 24-word BIP39 seed to crack. Instead of chasing mathematical perfection, why not we focus on real world security? Title: Re: dice or not dice Post by: babo on August 06, 2026, 11:42:36 AM Quote from: Zoomic on August 06, 2026, 10:46:15 AMExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
1 presentation-noise difference. Sidebar, ticker and other page chrome churn that our review classified as not being a change to what the source says.
- +1 -1 Only Bitcointalk's relative quote date rolled from Today to an absolute date.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.