<oembed><type>rich</type><version>1.0</version><author_name>npub1hzpahez9uhvlsfge4xvu3tkz492dwdwhpznykp455s6fg5x5thpqeug52u</author_name><author_url>https://nostr.ae/npub1hzpahez9uhvlsfge4xvu3tkz492dwdwhpznykp455s6fg5x5thpqeug52u</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2018-01-08&#xA;📝 Original message:&gt; This sounds very dangerous. As Gregory Maxwell pointed out, the key&#xA;derivation&#xA;&gt; function is weak enough that passphrases could be easily brute forced&#xA;&#xA;So you are essentially imagining that a perpetrator will combine the&#xA;crypto-nerd fantasy (brute forcing the passphrase) *with* the 5-dollar&#xA;wrench attack, merging both panes of Randall Munroe&#39;s comic? Seems&#xA;vanishingly unlikely to me - attackers are generally either the wrench&#xA;type, or the crypto-nerd type.&#xA;&#xA;This thread started by you asking Pavol to give an example of a real-life&#xA;scenario in which this functionality would be used, and your rebuttal is a&#xA;scenario that is even less likely to occur. &#34;Very dangerous&#34; is a huge&#xA;stretch.&#xA;&#xA;When living in Brazil I often carried two (IRL) wallets - one a decoy to&#xA;give to muggers, the other with more value stored in it. I heard of plenty&#xA;of people getting mugged, but I never heard of anyone who gave a decoy&#xA;wallet getting more thoroughly searched and the second wallet found,&#xA;despite the relative ease with which a mugger could do this. I&#39;m sure it&#xA;has happened, probably many times, but point is there is rarely time for&#xA;contemplation in a shakedown, and most perpetrators will take things at&#xA;face value and be satisfied with getting something. And searching a&#xA;physical person&#39;s body is a hell of a lot simpler than cracking a&#xA;passphrase.&#xA;&#xA;Moreover, there&#39;s no limit to the number of passphrases you can use. If you&#xA;were an atttacker, at what point would you stop, satisfied? After the&#xA;first, second, third, fourth wallet that you find/they admit to owning?&#xA;Going beyond two is already Bond-supervillain level implausible.&#xA;&#xA;*Ben Kloester*&#xA;&#xA;On 9 January 2018 at 06:37, Peter Todd via bitcoin-dev &lt;&#xA;bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&#xA;&gt; On Mon, Jan 08, 2018 at 02:00:17PM +0100, Pavol Rusnak wrote:&#xA;&gt; &gt; On 08/01/18 13:45, Peter Todd wrote:&#xA;&gt; &gt; &gt; Can you explain _exactly_ what scenario the &#34;plausible deniability&#34;&#xA;&gt; feature&#xA;&gt; &gt; &gt; refers to?&#xA;&gt; &gt;&#xA;&gt; &gt;&#xA;&gt; &gt; https://doc.satoshilabs.com/trezor-user/advanced_settings.&#xA;&gt; html#multi-passphrase-encryption-hidden-wallets&#xA;&gt;&#xA;&gt; This sounds very dangerous. As Gregory Maxwell pointed out, the key&#xA;&gt; derivation&#xA;&gt; function is weak enough that passphrases could be easily brute forced, at&#xA;&gt; which&#xA;&gt; point the bad guys have cryptographic proof that you tried to lie to them&#xA;&gt; and&#xA;&gt; cover up funds.&#xA;&gt;&#xA;&gt;&#xA;&gt; What model of human memory are you assuming here? What specifically are you&#xA;&gt; assuming is easy to remember, and hard to remember? What psychology&#xA;&gt; research&#xA;&gt; backs up your assumptions?&#xA;&gt;&#xA;&gt; --&#xA;&gt; https://petertodd.org &#39;peter&#39;[:-1]@petertodd.org&#xA;&gt;&#xA;&gt; _______________________________________________&#xA;&gt; bitcoin-dev mailing list&#xA;&gt; bitcoin-dev at lists.linuxfoundation.org&#xA;&gt; https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&#xA;&gt;&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180109/4701a311/attachment.html&gt;</html></oembed>