pull down to refresh
It seems like it's weak RNG. So if the user added entropy to the ColdCard's RNG (100+ dice rolls) it's ok. But whether the user really trusts it at this point is up to them. I'm not sure what to believe.
reply
pull down to refresh
It seems like it's weak RNG. So if the user added entropy to the ColdCard's RNG (100+ dice rolls) it's ok. But whether the user really trusts it at this point is up to them. I'm not sure what to believe.
Thats actually a very good point. Hmmm....I know people have said that these were completely airgapped, so in theory we can rule out exfiltration.
A real high-entropy passphrase would seem to mitigate a RNG or library issue....unless the bug somehow affects CC private keys after a passphrase has been applied? Would be interesting to know if any users who did not have a passphrase have been compromised...