r/coldcard: Coinomi explains its RNG approach after the Coldcard incident
reddit-coinomi-rng-approach
https://www.reddit.com/r/coldcard/comments/1vke7kg/how_we_handle_rng_at_coinomi/
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 0
- Detected differences
- 0
- Unreviewed
- 0
- Copies held
- 1
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vke7kg author: Coinomi created_utc: 1786347510 title: How we handle RNG at Coinomi body: Given everything that's happened with Coldcard, we wanted to share how Coinomi approaches random number generation. The Coldcard failure came down to an RNG quietly falling back to a predictable software substitute — seeds that looked fine but carried far less entropy than they should have. We've never used a home-grown RNG. Instead we request raw cryptographic randomness directly from the OS. On Android, we read straight from the kernel (/dev/urandom), bypassing the Java provider stack entirely. We wrote about it in more detail here if anyone's interested: [https://medium.com/@coinomi/security-is-not-one-feature-building-layers-of-defence-with-coinomi-171f638ac724?sharedUserId=coinomi](https://medium.com/@coinomi/security-is-not-one-feature-building-layers-of-defence-with-coinomi-171f638ac724?sharedUserId=coinomi) comment: p2sukgo parent: t3_1vke7kg author: CornFly2014 created_utc: 1786352572 edited: false body: Best to use dice 🎲 Other methods cannot be easily audited by the user comment: p2sw8qt parent: t3_1vke7kg author: scrandlle created_utc: 1786353430 edited: false body: Coming into a competitors space to dance on their grave, as funny as it is, isn't really something that engenders trust in you as a company. Not for me at least. comment: p2td8am parent: t3_1vke7kg author: Charming-Designer944 created_utc: 1786361169 edited: false body: To the best of the knowledge of the Coldcard developers the Coldcard firmware also relied on a TRNG source, but things are not always what they seem. comment: p2zcxqsExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.