Hard question that haunts me for a while. Maybe for someone as smart as nostr:npub1lz8xv2dnyryrk4vswkcgf52vqqzruqwuyp53s7pvusx4fef9fh2s7hh86s

12 word seed is protected by 2^132 while 24 word seed is 2^256.

Why the heck did we allow that compromise? That is like 38 levels of magnitude worse defense against possible brute force hack. Am I right or wrong?

#bitcoin #grownostr #asknostr

Reply to this note

Please Login to reply.

Discussion

Miluju jak každej miluje Hynka😂😩 I já jsem mužovi doma říkala, že ten kluk je skvělej a hrozně chytrej.😂

There is an argument here that 12 words in enough and 24 does not add much

I don't know enough to form a strong opinion about this

Common sense tells me 24 is orders of magnitude more secure

But the author claims otherwise

Your take?

https://foundationdevices.com/2023/06/make-12-words-the-standard/

12 words is enough. And should be a default.

More words adds to key generation entropy, but doesn't make your private key more secure. On the other hand it makes it much harder to store/backup (and enter) it.

Bruteforce attack on 12 word seed phrase is ifeasible (would require billions of years to guess with the most modern computers) and you don't know if it holds any bitcoin! Isn't it better to use that power to mine bitcoin instead?

So much better way for an attacker is to actually try to get to private key directly from a known address with bitcoin and public key (solving ECDLP).

Which similarily infeasible as guessing random seed ohrases, but at least you know that it actually allows you to access some bitcion.

nostr:npub1tv8gmfhalwnxxquxjzeh6gtdsdz6vg7vx0s3rt7s7uuw6aujh32qn77wn2 made some excellent threads on it but i think it was on twitter 🤔?

a) It's not 2^132 but 2^128 because of checksum

b) It's not a compromise, or better, every N words is a compromise compared to N+1. Where would you like to stop? For me, billion years of brute forcing is enough. https://nostrcheck.me/media/public/nostrcheck.me_9264794442599559671704806069.webp

By the way, the reason why Trezor One has 24word seed by default is that when you type it on PC, it can hypothetically have a keylogger so the word ordering itself must be enough to secure your funds. With Model T's touchscreen 12 words are perfectly safe.

Ok… you managed to ease my mind.