r/Bitcoin: whether a 10-character passphrase is enough after the Coldcard incident
reddit-passphrase-entropy-ten-char
https://www.reddit.com/r/Bitcoin/comments/1vhux2b/is_my_understanding_of_the_security_of_a_25th/
Latest reviewed change
source content difference between and
Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.
edited: false
body:
Checkout this site for good info on this. [https://drop.amboss.tech/entropy-explainer.html](https://drop.amboss.tech/entropy-explainer.html)
+
+comment: p2n9p1e
+parent: t1_p2bwmui
+author: Londonskaterboi
+created_utc: 1786283480
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 1
- Detected differences
- 1
- Unreviewed
- 0
- Copies held
- 2
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
Reddit served 2 additional comment record(s); the diff preserves their text and any edits to existing records.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
edited: false body: Checkout this site for good info on this. [https://drop.amboss.tech/entropy-explainer.html](https://drop.amboss.tech/entropy-explainer.html) + +comment: p2n9p1e +parent: t1_p2bwmui +author: Londonskaterboi +created_utc: 1786283480 +edited: false +body: +yes but some wallets only accept bip39 words + +comment: p2ncvz8 +parent: t1_p2n9p1e +author: na3than +created_utc: 1786284458 +edited: false +body: +1. Picking "four words that are easy to remember" from a list of only 2048 words is absolutely not random. + +2. Every wallet that accepts a passphrase accepts any combination of letters, numbers and special characters as a passphrase. That's what a passphrase is. Check the specification. It's NOT meant to be a few more words from the canonical list of 2048. If you've found a wallet that stupidly constrains your passphrase that way, stop using that shitty wallet. There's no telling what other dumb decisions the authors made is implementing the specifications.Extracted text as captured
post: 1vhux2b author: Maleficent_Pool_4456 created_utc: 1786091663 title: Is my understanding of the security of a 25th word Passphrase correct? body: So the number of different characters you can use ASCII etc for things like Ledger is 94, so the base (number of possible things for each character) would be 94 and the exponent would be the length right, so let's say if you had 10 characters, a strong hacker who is check 10million per second (including the 2048 rounds of hashing) it would take them 85,000 years, and would take like a nation state with a lot of funds checking 1 billion per second 853 years. Does this mean, that if you have a random password of 10 characters for your 25th password, that you would have 59 bits of entropy, therefore you are relatively safe even if they had your first 24? Of course keep your first 24 hidden, but I'm asking in a case like ColdCard, you would be safe right and **10 characters is enough?** comment: p2889x7 parent: t3_1vhux2b author: Pleasant_Tap2641 created_utc: 1786092230 edited: false body: So you're basically asking if 10 random chars is enough to sleep at night even if someone swipes your seed words short answer yeah probably but the real question is why stop at 10 when you can just mash the keyboard a few more times and call it a day comment: p288dcc parent: t3_1vhux2b author: ivanjurman created_utc: 1786092275 edited: false body: Yes you’re correct, but if you want to be extra safe just by increasing the length to 20 characters, it would take them 10 septillion years (thats 10 trillion trillion years) comment: p288ymj parent: t3_1vhux2b author: Londonskaterboi created_utc: 1786092563 edited: false body: you can add multiple words like the actual seed phrase, so pick 4 words that are easy to remember but have no real life connection. comment: p2896as parent: t3_1vhux2bExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vhux2b author: Maleficent_Pool_4456 created_utc: 1786091663 title: Is my understanding of the security of a 25th word Passphrase correct? body: So the number of different characters you can use ASCII etc for things like Ledger is 94, so the base (number of possible things for each character) would be 94 and the exponent would be the length right, so let's say if you had 10 characters, a strong hacker who is check 10million per second (including the 2048 rounds of hashing) it would take them 85,000 years, and would take like a nation state with a lot of funds checking 1 billion per second 853 years. Does this mean, that if you have a random password of 10 characters for your 25th password, that you would have 59 bits of entropy, therefore you are relatively safe even if they had your first 24? Of course keep your first 24 hidden, but I'm asking in a case like ColdCard, you would be safe right and **10 characters is enough?** comment: p2889x7 parent: t3_1vhux2b author: Pleasant_Tap2641 created_utc: 1786092230 edited: false body: So you're basically asking if 10 random chars is enough to sleep at night even if someone swipes your seed words short answer yeah probably but the real question is why stop at 10 when you can just mash the keyboard a few more times and call it a day comment: p288dcc parent: t3_1vhux2b author: ivanjurman created_utc: 1786092275 edited: false body: Yes you’re correct, but if you want to be extra safe just by increasing the length to 20 characters, it would take them 10 septillion years (thats 10 trillion trillion years) comment: p288ymj parent: t3_1vhux2b author: Londonskaterboi created_utc: 1786092563 edited: false body: you can add multiple words like the actual seed phrase, so pick 4 words that are easy to remember but have no real life connection. comment: p2896as parent: t3_1vhux2bExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.