Your phone or laptop is doing dice rolls better than you ever could. Will an adversary somehow learn and then model the state of a bunch of jittery circuits on your device, reduce the possibile number of combinations to some easily calculable value, to steal your seed? I suspect recreating a specific table top and dice throws would be easier. That doesn't mean you shouldn't roll the dice yourself. Just be aware of how much entropy you need and make sure it's generated with a battle tested method. I haven't seen it said yet but it's important to note: you *cannot prove that you have the randomness once its generated. You can only TRUST the method is sound and was followed correctly. It's not that much entropy in the grand scheme of things. But that is your *own entropy and nobody else's. #bitcoin #monero

Replies (11)

Kind of out there, but this is why I don't do shit to constrain results. I use my cat bowl as an example. Had one roll off into the floor and into the cat bowl. Recorded it. I use word lottery now but same thing. Wherever it lands. Blow on it if necessary. Takes forever to draw 24 properly but worth it. If you won't do any of that well, yeah, a computer is probably going to beat you out. I think a lot of this is overly complicated. Im just doing it myself from now on.
I'm totally shocked at how many people are spinning in circles on entropy not realizing all that shit is just replicating you drawing words from a bowl. Like if you're that worried just do that offline. Obviously it has to be done well like all the other stuff, but it's the simplest to understand. You literally watch it happen
"Your phone or laptop is doing dice rolls better than you ever could. " This is false and superstitious. Entropy is measured in bits. 256 bits = 256 bits. The only question is trust. The bits you get from dice are best because you know how they were made.
Fair enough. I like the SS photo method. 256 isn't a lot, get it wherever you're comfortable getting it. But if we're trusting implementations of elliptic curve multiplication to produce unique pubkeys seems ok to trust many available RNGs, if we go by number of different autists who obsess over these things.