About passphrases:🔐

Should they be …

1) short and easy to remember like „peter1“ or „12345“?

2) more complex like „Fvc5j82H&GZI@92h“?

3) Or is a passphrase using a hand full of random BIP39 words seperated by spaces a good sweetspot like „abandon ability able about above“?

What do you think? 🤔

Reply to this note

Please Login to reply.

Discussion

There’s a very good rule of thumb 😉

It’s all about information entropy and how fast a password can be brute forced. If you prefer a string of random numbers/symbols, it should be at least 21 chars long. Alternatively, any sequence of 4-5 regular words separated by dashes has higher entropy than that.

I am thinking not only about security from brute forcing. Complexity also makes it more difficult to remember or to restore for your heirs 🤔

That’s why i am thinking about this atm. Short and easy could also be an advantage if you yourself forget it and have to brute force it

And that's why I said it's all about how much you care.

Hard to decide 😅 it’s a pretty new concept to me

Not really. My grandmother kept paper copies of all her accounts and assets. When she spoke to agents on the phone she would bring in a folder with numbers the agents requires for her. Now you just need to punch that shit into a steel plate and read them off, 12 to 24 words at a time. Or multi-sign with a thumbprint or passphrase. Which some people do today. You don't have to remember the words, you could remember a passcode. My grandma used a key, physical not logical.

Followed 🫵🫡🫂💜

Don't let your seed anywhere near an internet connected device.

You should have something airgapped like a cold card as a minimum.

I used galvanized washers for my seed. You can connect them together with a bolt. This is fire and future proof. Make sure your nut, bolt, and washers are made of the same material to minimize electrolysis.

The washer set up cost me about $12 and is far more fire resistant than the plates you can get online.

The passphrase is what really matters.

If you have a significant amount. Multisig is the only way to go that makes sense.

2/3 cold wallets must be there to send funds.

All 3 wallets should have a passphrase, and be stored in different locations.

Stamp all 3 seed phrases onto different washer set ups.

Stamp the pass phrasesi on one washer and keep that hidden.

Keep a small amount of bitcoin in each seed phrase wallet, and seed phrase+pass phrase wallet to satisfy thief's in case of theft or 5$ wrench attack, this will keep your primary stack safe.

Never talk about your stack.

Opsec will keep you safe.

Really valuable advice, thanks mate 🙏💜🫂

Happy to help

„Never talk about your stack“ — probably the best of all 🫡💜

:)

#plebchain

Yes, for absolutely critical things, I would go for shorter 4-5 words passwords. They are easy to remember and still have high complexity = entropy.

For regular websites/services one could use a password manager like Bitwarden, Keepass, Enpass, etc.

Funny. Just downloaded bitwarden 😅 but not reallzusing it since i don’t understand yet how far it can be trusted… since it stores all my passwords in the cloud 🤔

Bitwarden doesn’t have to be trusted at all if you run your own vaultwarden on your node. This is gonna be your cloud then 😉

Check BTC sessions on how to set it up.

Oh boy this rabbit hole is so deep 😅🙏

You can’t even imagine 🤣😂

If you’re paranoid, it doesn’t mean they ain’t watching you 🫵🫡

Don't use any password manager that touches the internet.

I would use something like keepass with a hard token+password to open.

That way if your password backup is stolen remotely it would be an extream task to brute force.

💯

You mean 4-5 words or characters? 🤔

Regular words separated by dashes. As you can see from the xkcd figure, it has a higher entropy than a seemingly complicated password with random characters, symbols and numbers. But it is super easy to remember.

Thanks for your advice mate 🙏

Highly appreciate it 🫂💜

If you are absolutely paranoid like some of us here and still want to have your passwords written down somewhere, you may use Shamir Secret Sharing Scheme (SSSS) to encrypt your passwords and split the encrypted pieces at different safe locations.

Heard about that, want to look into that too

Download the web page and use it offline to encrypt and split your passwords.

https://iancoleman.io/shamir/

Bookmarked 💪

Ah i remember that on… i think aantonop shared it in one of his videos 🙏💪

Why do you want a passphrase?

I'd say the first one. Though I always discommend using a passphrase. One miswritten of forgotten character is all or nothing. In contrast to the BIP39 directory words which can be decerned from one another with missing characters.

But how about using bip39 words as passphrase? Some wallets even have the function to enter it just like a seed by choosing the words after entering first characters

Yeah that would solve for that. It depends on how you store the info and who will need to access it. Brainwallet of paper? Will your family need to regenerate your wallet under circumstances? How technically proficient are they? How accessable is your wallet now and what's the chance of leaking seedwords? What are single points of failure?

And don't post answers to those questions on nostr 😅‼️

Thanks mate 🙏🫂💜

As for the seed phrases it's 2048 words with 12 to 24 total in random order so you do the math. But as far as passphrases, they still work too. They are the 12th word or sometimes 24th word even. Also if random generated you are measuring bits not length. So 16 random numbers, special characters, letters, and symbols are pretty much random too. Some people reduce it down to a very large number, that would take hundreds of millions of years to crack. It all kind of depends on how much you care.

Yes, but:

nostr:note1ntj6r8cj34m2c4qgq6ha0k3d3apt8454ly2q2fhdv3ssrhjzly0q9933ad