r/coldcard: call for more user-entropy options in COLDCARD
reddit-user-entropy-options
Latest reviewed change
source content difference between and
New comment reports that a user-entropy option is already in progress, linking Coldcard firmware GitHub pull request 707.
Its not impossible, but its hard, and it takes hard work an dedication.
I will agree with you that i'm not sure coinkite has it in them to do what it takes, but i hope so, otherwise my investments with their devices is lost
+
+comment: p289hy2
+parent: t3_1vcr9uo
+author: CornFly2014
+created_utc: 1786092823
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 2
- Detected differences
- 2
- Unreviewed
- 0
- Copies held
- 3
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
New comment reports that a user-entropy option is already in progress, linking Coldcard firmware GitHub pull request 707.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
Its not impossible, but its hard, and it takes hard work an dedication. I will agree with you that i'm not sure coinkite has it in them to do what it takes, but i hope so, otherwise my investments with their devices is lost + +comment: p289hy2 +parent: t3_1vcr9uo +author: CornFly2014 +created_utc: 1786092823 +edited: false +body: +Update: from GitHub it seems this is already in progress: [https://github.com/Coldcard/firmware/pull/707](https://github.com/Coldcard/firmware/pull/707) + +Looks like things are improving!Extracted text as captured
post: 1vcr9uo author: CornFly2014 created_utc: 1785600418 title: Time for cold card to implement more user entropy options body: To restore 'trust' , i think the best way to do so, is to extend the user provided entropy options in cold card. Just like TrueCrypt did in the old days, and VeraCrypt does today, allow the user to add entropy using: 1. Mashing random buttons in the keyboard, in the Q there are many keys, why not take advantage of that. 2. Using the time between keystrokes as another input. 3. Instead of just 1-6, allow the user to input hex values as added entropy (say from random.org) All just like today, by either using the HW entropy as base, or a known empty string as base. And also just like VeraCrypt, add a visual progress bar showing how much entropy as been inputed by the user. The idea is 'Reproduce-able' results given a given entropy, and but make it as easy as possible for user generated entropy to be added. comment: p13d8sm parent: t3_1vcr9uo author: bullett007 created_utc: 1785601173 edited: false body: Trust them to code that all in correctly do ya? Knowing them, mashing the keyboard will further reduce entropy. 馃槀馃ぃ comment: p13ekbi parent: t3_1vcr9uo author: CraftClear7283 created_utc: 1785601553 edited: 1785601810 body: And then a software bug will simply ignore the user entropy and revert to it's internal clock as the primary source of entropy?Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
2 new Reddit comments were posted, including Interesting-Gear-992,CornFly2014.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
Self reply: elsewhere I saw you comment about how dice rolls do let you verify the math. I didn't think inputting mouse jiggles or keyboard mashing could be verified... but if so, I am wrong above, and in that case, yes: why not make it very convenient in the device itself to generate a big old number, then prove it did what it should. I get your point. + +comment: p1mu60o +parent: t3_1vcr9uo +author: Interesting-Gear-992 +created_utc: 1785844883 +edited: false +body: +I think restore the trust is an impossible mission. + +comment: p1mv7to +parent: t1_p1mu60o +author: CornFly2014 +created_utc: 1785845250 +edited: false +body: +Its not impossible, but its hard, and it takes hard work an dedication. + +I will agree with you that i'm not sure coinkite has it in them to do what it takes, but i hope so, otherwise my investments with their devices is lostExtracted text as captured
post: 1vcr9uo author: CornFly2014 created_utc: 1785600418 title: Time for cold card to implement more user entropy options body: To restore 'trust' , i think the best way to do so, is to extend the user provided entropy options in cold card. Just like TrueCrypt did in the old days, and VeraCrypt does today, allow the user to add entropy using: 1. Mashing random buttons in the keyboard, in the Q there are many keys, why not take advantage of that. 2. Using the time between keystrokes as another input. 3. Instead of just 1-6, allow the user to input hex values as added entropy (say from random.org) All just like today, by either using the HW entropy as base, or a known empty string as base. And also just like VeraCrypt, add a visual progress bar showing how much entropy as been inputed by the user. The idea is 'Reproduce-able' results given a given entropy, and but make it as easy as possible for user generated entropy to be added. comment: p13d8sm parent: t3_1vcr9uo author: bullett007 created_utc: 1785601173 edited: false body: Trust them to code that all in correctly do ya? Knowing them, mashing the keyboard will further reduce entropy. 馃槀馃ぃ comment: p13ekbi parent: t3_1vcr9uo author: CraftClear7283 created_utc: 1785601553 edited: 1785601810 body: And then a software bug will simply ignore the user entropy and revert to it's internal clock as the primary source of entropy?Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vcr9uo author: CornFly2014 created_utc: 1785600418 title: Time for cold card to implement more user entropy options body: To restore 'trust' , i think the best way to do so, is to extend the user provided entropy options in cold card. Just like TrueCrypt did in the old days, and VeraCrypt does today, allow the user to add entropy using: 1. Mashing random buttons in the keyboard, in the Q there are many keys, why not take advantage of that. 2. Using the time between keystrokes as another input. 3. Instead of just 1-6, allow the user to input hex values as added entropy (say from random.org) All just like today, by either using the HW entropy as base, or a known empty string as base. And also just like VeraCrypt, add a visual progress bar showing how much entropy as been inputed by the user. The idea is 'Reproduce-able' results given a given entropy, and but make it as easy as possible for user generated entropy to be added. comment: p13d8sm parent: t3_1vcr9uo author: bullett007 created_utc: 1785601173 edited: false body: Trust them to code that all in correctly do ya? Knowing them, mashing the keyboard will further reduce entropy. 馃槀馃ぃ comment: p13ekbi parent: t3_1vcr9uo author: CraftClear7283 created_utc: 1785601553 edited: 1785601810 body: And then a software bug will simply ignore the user entropy and revert to it's internal clock as the primary source of entropy?Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.