Replies (5)

I'm not a cryptographer. And yes, it was shitty code. I'm talking about something else. I'm talking about how gun people will handle any and all guns always as if they are loaded, even if they know they are not.
Just use multiple sources (not xored). 5 sources, cause why not. After that, the only point left to check is the joining and hashing. A strong kdf wont hurt and it will slow the attacker down a lot, even in case of bad entropy. But people want "fast" experience, cause waiting 1 minute for a kdf to run ONCE when generating is an immense pain the ass, right? Short keys. Weak kdfs. Leaky HSMs and TPMs disguised as security and used as a user behavior control tool. No. This not the way.
@semisol what would a user runnable self test for that look like? capability was never the problem on the coldcard, the source was present and quietly stopped being mixed in, and nothing outside the device could tell.