Why is a 24-word seed phrase even necessary if a 7-word Diceware passphrase would take millions of years to crack?

I am about to create my new seed for my Trezor (either using the Trezor itself or did I haven’t decided) after the CC fiasco and I have been thinking about this for several days now.

Imagine there was no seed phrase at all. Instead, you generated seven completely random words yourself using physical dice and a 7776 word Diceware list, and those seven words were your entire secret.

That gives roughly 90 bits of entropy, or around 1.2 × 10²⁷ possible combinations. Even assuming an attacker could test one trillion guesses every second, it would take roughly 20 million years on average to find the correct combination.

So why do we need a 24-word BIP39 seed containing 256 bits of entropy?
Wouldn’t ~90 bits of genuinely random, independently generated entropy already make brute forcing effectively impossible?

I’m not suggesting anyone actually replace their BIP39 seed with seven words just to be clear! I’m asking the more fundamental question of why we need 256 bits of entropy when seven properly dice-generated words already seem to provide vastly more brute force resistance than we could realistically need.

submitted by /u/Skinny_Human to r/Bitcoin
[link] [comments]
Quelle: bitcoin-en