When I think of the longer-term implications of the Coldcard entropy bug, I find myself coming back & thinking about the basic fundamental security stack protecting my bitcoin.
1 - can I generate a true 256 bit seedphrase?
2 - if I have a true 256 bit seedphrase which has never been exposed, is it impossible for that seedphrase to be found?
3 - does the open source technology stack I use for signing transactions, generating addresses, etc ensure my seedphrase is never leaked so I can rely on 2 above?
4 - does the open source security model provide sufficient security so I can rely on 3 above?
5 - can I personally & continuously verify 3 & 4 above?
This is a cascading security framework & the failure of any item can lead to the total loss of funds.
The only item I can currently be certain of is item 1. We know that item 2 will eventually flip to a "no", unless a new signature scheme is implemented.
While I understand the Coldcard entropy bug related to item 1, given the catastrophic bug was hiding in plain sight & lot of people who have the skills to identify it had a large financial incentive to find it but didn't, I find myself spending a lot of time thinking about items 3 & 4.
Can I ever rely on these? Currently the answer is use "multi-vendor signing devices to diversify the risk", but it seems to me that many of these projects rely on common libraries, shared code, etc. True diversification does not seem possible & this approach does not meet the requirement for items 4 & 5.
In the immediate term, if I am signing transactions with an air-gaped device via qr code, is it possible to have an independent software stack that can scan the qr code and ensure my signing software has not emended my private key into the qr code. I do not know if this is technically possible, but I would very much like that missing piece of independent software in my stack as a backstop to items 4 & 5 not being able to ensure item 3.
Following this, I would very much like item 2 to be addressed as soon as there is a good chance it will fail at some point.
When I think about the victims of this disaster, I also find myself thinking about my exposure to item 3 and the failure of item 4 to enable reliance on it ... not sure where that leaves me & all of us?
mobiusmoe
mobius@nostraddress.com
npub12qc8...rgrq
w/e
sue me
(but only if it's payable in BTC)