{"type":"rich","version":"1.0","author_name":"npub1wh6j4sjw7nc97f64slljrznfexaekvzk4s0zq60erztskmtagvxsq4v3gj","author_url":"https://nostr.ae/npub1wh6j4sjw7nc97f64slljrznfexaekvzk4s0zq60erztskmtagvxsq4v3gj","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2019-02-04\n📝 Original message:Unlike mouse movement it works in a CLI software, which is great. However,\nisn't there something else you can use instead of cards? Something with\ninvariant culture and maybe more common.\n\nOn Sun, Feb 3, 2019 at 7:27 PM Ryan Havar via bitcoin-dev \u003c\nbitcoin-dev at lists.linuxfoundation.org\u003e wrote:\n\n\u003e More of a shower-thought than a BIP, but it's something I've long wish\n\u003e (hardware) wallets supported:\n\u003e\n\u003e ---\n\u003e\n\u003e Abstract: Bitcoin Wallets generally ask us to trust their seed generation\n\u003e is both correct and honest. Especially for hardware and air gapped wallets,\n\u003e this is both a big ask and more or less impossible to practically verify.\n\u003e So we propose a bring-your-own-entropy approach in which the wallet can\n\u003e function completely deterministically. Our method is based on shuffling\n\u003e physical deck of cards. There are 52!  (2^219.88) different shuffle order,\n\u003e which is a big enough space to be secure against collision and brute force\n\u003e attacks. Conveniently a shuffled deck of cards also can serve as a physical\n\u003e backup which is easy to hide in plain sight with great plausible\n\u003e deniability.\n\u003e\n\u003e\n\u003e Representation:\n\u003e\n\u003e Each card has a suit which can be represented by one of SCHD (spades,\n\u003e clubs, hearts, diamonds) and a value of one of 23456789TJQKA where the\n\u003e numbers are obvious and (T=ten, J=jack, Q=queen, K=king, A=ace) so \"7 of\n\u003e clubs\" would be represented by \"7C\" and a \"Ten of Hearts\" would be\n\u003e represented with \"TH\".\n\u003e\n\u003e An deck of cards looks like:\n\u003e\n\u003e\n\u003e 2S,3S,4S,5S,6S,7S,8S,9S,TS,JS,QS,KS,AS,2C,3C,4C,5C,6C,7C,8C,9C,TC,JC,QC,KC,AC,2H,3H,4H,5H,6H,7H,8H,9H,TH,JH,QH,KH,AH,2D,3D,4D,5D,6D,7D,8D,9D,TD,JD,QD,KD,AD\n\u003e\n\u003e And can be verified by making sure that every one of the 52 cards appears\n\u003e exactly once.\n\u003e\n\u003e\n\u003e Step 1.  Shuffle your deck of cards\n\u003e\n\u003e This is a lot harder than you'd imagine, so do it quite a few times, with\n\u003e quite a few different techniques. It is advised to do at *least* 7 good\n\u003e quality shuffles to achieve a true cryptographically secure shuffle. Do not\n\u003e look at the cards while shuffling (to avoid biasing) and don't be afraid to\n\u003e also shuffle them face down on the table. Err on the side over\n\u003e over-shuffling.\n\u003e See also:\n\u003e https://en.wikipedia.org/wiki/Shuffling#Sufficient_number_of_shuffles\n\u003e\n\u003e Step 2. Write out the order (comma separated)\n\u003e\n\u003e And example shuffle is:\n\u003e\n\u003e\n\u003e 5C,7C,4C,AS,3C,KC,AD,QS,7S,2S,5H,4D,AC,9C,3H,6H,9D,4S,8D,TD,2H,7H,JD,QD,2D,JC,KH,9S,9H,4H,6C,7D,3D,6S,2C,AH,QC,TH,TC,JS,6D,8H,8C,JH,8S,KD,QH,5D,5S,KS,TS,3S\n\u003e\n\u003e Step 3.  Sha512 it to create a seed\n\u003e\n\u003e In the example above you should get:\n\u003e\n\u003e dc04e4c331b1bd347581d4361841335fe0b090d39dfe5e1c258c547255cd5cf1545e2387d8a7c4dc53e03cacca049a414a9269a2ac6954429955476c56038498\n\u003e\n\u003e Step 4. Interpret it\n\u003e\n\u003e e.g. For bip32 you would treat the first 32 bytes as the private key, and\n\u003e the second 32 bytes as as the extension code.\n\u003e\n\u003e\n\u003e\n\u003e\n\u003e -Ryan\n\u003e\n\u003e\n\u003e _______________________________________________\n\u003e bitcoin-dev mailing list\n\u003e bitcoin-dev at lists.linuxfoundation.org\n\u003e https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev\n\u003e\n\n\n-- \nBest,\nÁdám\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20190204/0bc324ae/attachment.html\u003e"}
