Coldcard vulnerability was avoidable if they had required user-input based randomness

I don't know Coldcard but it seems from what I've read of the exploit, it's because they let the computer generate the random seed and not use anything outside the computer's software. This is kind of unimaginable to miss at the first architectural stage of building any encryption software.

Outside of password generation for non essential web logins, I don't remember the last time I generated a credential without providing some of the RNG.

Even early bitcoin paper wallet software would have you zigzag your mouse and smash random keys to generate entropy. Same with most open source encryption tools.

I might be missing something else that caused the exploit?

submitted by /u/rgnet1 to r/Bitcoin
[link] [comments]
Quelle: bitcoin-en