<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated></updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by </title>
  <author>
    <name></name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1hzpahez9uhvlsfge4xvu3tkz492dwdwhpznykp455s6fg5x5thpqeug52u.rss" />
  <link href="https://nostr.ae/npub1hzpahez9uhvlsfge4xvu3tkz492dwdwhpznykp455s6fg5x5thpqeug52u" />
  <id>https://nostr.ae/npub1hzpahez9uhvlsfge4xvu3tkz492dwdwhpznykp455s6fg5x5thpqeug52u</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://nostr.ae/nevent1qqs93x0cufezy0a9khaelkzte6c3uljunpnp9xjzmau8w2crt76049czyzug8klyghjan7p9rx5enj9wc254f4e46uy2vjcxkjjrf9zs63wuy308x2g</id>
    
      <title type="html">📅 Original date posted:2018-01-08 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs93x0cufezy0a9khaelkzte6c3uljunpnp9xjzmau8w2crt76049czyzug8klyghjan7p9rx5enj9wc254f4e46uy2vjcxkjjrf9zs63wuy308x2g" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvae8kygprhvdrhargwrj6p9y8ajzyxa5085cc7dh4prneaed9n5cv7jqmh&#39;&gt;nevent1q…jqmh&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2018-01-08&lt;br/&gt;📝 Original message:&amp;gt; This sounds very dangerous. As Gregory Maxwell pointed out, the key&lt;br/&gt;derivation&lt;br/&gt;&amp;gt; function is weak enough that passphrases could be easily brute forced&lt;br/&gt;&lt;br/&gt;So you are essentially imagining that a perpetrator will combine the&lt;br/&gt;crypto-nerd fantasy (brute forcing the passphrase) *with* the 5-dollar&lt;br/&gt;wrench attack, merging both panes of Randall Munroe&amp;#39;s comic? Seems&lt;br/&gt;vanishingly unlikely to me - attackers are generally either the wrench&lt;br/&gt;type, or the crypto-nerd type.&lt;br/&gt;&lt;br/&gt;This thread started by you asking Pavol to give an example of a real-life&lt;br/&gt;scenario in which this functionality would be used, and your rebuttal is a&lt;br/&gt;scenario that is even less likely to occur. &amp;#34;Very dangerous&amp;#34; is a huge&lt;br/&gt;stretch.&lt;br/&gt;&lt;br/&gt;When living in Brazil I often carried two (IRL) wallets - one a decoy to&lt;br/&gt;give to muggers, the other with more value stored in it. I heard of plenty&lt;br/&gt;of people getting mugged, but I never heard of anyone who gave a decoy&lt;br/&gt;wallet getting more thoroughly searched and the second wallet found,&lt;br/&gt;despite the relative ease with which a mugger could do this. I&amp;#39;m sure it&lt;br/&gt;has happened, probably many times, but point is there is rarely time for&lt;br/&gt;contemplation in a shakedown, and most perpetrators will take things at&lt;br/&gt;face value and be satisfied with getting something. And searching a&lt;br/&gt;physical person&amp;#39;s body is a hell of a lot simpler than cracking a&lt;br/&gt;passphrase.&lt;br/&gt;&lt;br/&gt;Moreover, there&amp;#39;s no limit to the number of passphrases you can use. If you&lt;br/&gt;were an atttacker, at what point would you stop, satisfied? After the&lt;br/&gt;first, second, third, fourth wallet that you find/they admit to owning?&lt;br/&gt;Going beyond two is already Bond-supervillain level implausible.&lt;br/&gt;&lt;br/&gt;*Ben Kloester*&lt;br/&gt;&lt;br/&gt;On 9 January 2018 at 06:37, Peter Todd via bitcoin-dev &amp;lt;&lt;br/&gt;bitcoin-dev at lists.linuxfoundation.org&amp;gt; wrote:&lt;br/&gt;&lt;br/&gt;&amp;gt; On Mon, Jan 08, 2018 at 02:00:17PM &#43;0100, Pavol Rusnak wrote:&lt;br/&gt;&amp;gt; &amp;gt; On 08/01/18 13:45, Peter Todd wrote:&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; Can you explain _exactly_ what scenario the &amp;#34;plausible deniability&amp;#34;&lt;br/&gt;&amp;gt; feature&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; refers to?&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &lt;a href=&#34;https://doc.satoshilabs.com/trezor-user/advanced_settings&#34;&gt;https://doc.satoshilabs.com/trezor-user/advanced_settings&lt;/a&gt;.&lt;br/&gt;&amp;gt; html#multi-passphrase-encryption-hidden-wallets&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; This sounds very dangerous. As Gregory Maxwell pointed out, the key&lt;br/&gt;&amp;gt; derivation&lt;br/&gt;&amp;gt; function is weak enough that passphrases could be easily brute forced, at&lt;br/&gt;&amp;gt; which&lt;br/&gt;&amp;gt; point the bad guys have cryptographic proof that you tried to lie to them&lt;br/&gt;&amp;gt; and&lt;br/&gt;&amp;gt; cover up funds.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; What model of human memory are you assuming here? What specifically are you&lt;br/&gt;&amp;gt; assuming is easy to remember, and hard to remember? What psychology&lt;br/&gt;&amp;gt; research&lt;br/&gt;&amp;gt; backs up your assumptions?&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; --&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://petertodd.org&#34;&gt;https://petertodd.org&lt;/a&gt; &amp;#39;peter&amp;#39;[:-1]@petertodd.org&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; bitcoin-dev mailing list&lt;br/&gt;&amp;gt; bitcoin-dev at lists.linuxfoundation.org&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&#34;&gt;https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&lt;/a&gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180109/4701a311/attachment.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180109/4701a311/attachment.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T20:09:27&#43;02:00</updated>
  </entry>

</feed>