This is only a joke. Don't do it in real life!
If you make a dice that is not 100% random, it would not generate enough entropy. You will become the next coldcard.
View quoted note →
Well, no, the imperfection are a bias, so you effectively reduce the output distribution. But...if nobody knows about the bias, and the bias itself is not extreme, there is no real way for an attacker to target it, because they don't know to target it.
Yes. Sure if the dice only return 1, it’s bad, but if you rotate them randomly do your own weird entropy with it, it’s quite good. The problem of the coldcard is a SPF, if only one person used it and the RNG was kept secret, it would have been secured.
That’s why I’m so wary of any hardware wallet, everybody use the exact same RNG, if a pattern is found, game over. External entropy on such small dumb device is tiny.
@Petter ⚡ making your own dice also means you can check them. weigh each one and roll it a few hundred times before you trust it with a seed, since a biased die quietly costs you entropy you think you have.
Cryptography is interesting because it's often counterintuitive. I'll try to explore this further.
In the meantime, we've opened up a new rabbit hole: dice :)
I am more of a smoke and lasers person myself.
in terms of counter-intuition in this regard:
The attacker probably has a lot more awarness of all the possible biasses out there it could leverage, than any user/regular person would. So odds are whenever a user thinks they are clever, they are bound to produce something that is trivial to unravel. Good randomness is not easy per se, but it for sure is dumb, but thats the point; there is nothing to latch onto