The practical security implications of an exposed 24 word seed phrase with "blanks"
The practical security implications of an exposed 24 word seed phrase with "blanks"
Loading saved threads...
pjlangley · External communityPost link
External question — Bitcoin Stack Exchange
Author: pjlangley
Original post: https://bitcoin.stackexchange.com/questions/118872
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
I want (a substantial amount of) the strength in numbers of a self-custody 24 word Bitcoin wallet, but I don't want to memorise all 24 words; laziness prevails.
My idea: create a note (probably digital) containing
n
of the 24 words, in order (not scrambled), and to only memorise the
n
number of blanks. The
n
blanks will not be in digital form and will be fully committed to memory.
E.g. 8 of the 24 words are left blank in the note:
grab merit ___ can
___ ___ floor car
exit mother ___ festival
october ___ camp ___
trial nephew ___ fabric
galaxy napkin ___ apple
Note: This seed was referenced from here.
Out of curiosity, does the location of the blanks offer a varying number of possibilities? E.g. having the blanks front loaded, rather than spread out?
I'm pretty flexible with this, in the sense of hitting the "sweet" spot with how many word omissions to remember, without considerably compromising the security of my wallet. I'd also consider a wallet/seed rotation cycle every x interval, just in case my copy with gaps is ever unknowingly compromised.
Will this strategy offer a high enough level of protection, practically speaking, or are people already cursing me with the thought of this trade off in security? Pros and cons welcomed in equal measures.
Quote
Report
RedGrittyBrick · External communityPost link
External answer — Bitcoin Stack Exchange
Author: RedGrittyBrick
Original post: https://bitcoin.stackexchange.com/a/118882
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
Will this strategy offer a high enough level of protection
"High enough" seems subjective. Someone might consider it high enough to protect 0.00003 BTC but not high enough to protect 0.3 BTC
The more complex the scheme, the more points of failure it has. If you lose your note, the words you remember are useless. If you misremember your memorized words, as humans are prone to do, especially at longer intervals, you may not be able to recover the whole phrase.
Consider what you might want to happen if you die in a car crash. Is there anybody you would like to inherit, how would they do that?
I would try to list the threats I am trying to protect against. Then I would try to list some countermeasures whose cost I think is appropriate for the sums involved.
I would try to list the possible ways I might lose control over the money through forseeable failings in memory or storage (fire, flood, mice etc) and what countermeasures might be cost effective.
Sometimes people think that knowing the seed-phrase is enough. Some of those people post questions here when they find it isn't. You might also need a note of what software you used, what version and what derivation path was selected, maybe some sample addresses that were generated etc etc. I think you need to test the recovery process.
Related:
Help in recovering BTC from seed phrase
Quote
Report
user190472 · External communityPost link
External answer — Bitcoin Stack Exchange
Author: user190472
Original post: https://bitcoin.stackexchange.com/a/130987
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
The position of the missing words does not materially change the search space if the attacker knows which positions are missing.
A 24-word BIP39 mnemonic represents 256 bits of entropy plus an 8-bit checksum. Each word encodes 11 bits. Therefore, if n word positions are unknown, there are initially 2^(11n) possible word combinations, but only about 1 in 256 of those combinations will have a valid BIP39 checksum.
So the number of valid BIP39 mnemonics consistent with the known words is approximately:
2^(11n - 8)
For example:
4 missing words: about 2^36 valid mnemonics
5 missing words: about 2^47
6 missing words: about 2^58
7 missing words: about 2^69
8 missing words: about 2^80
Eight missing words therefore leave a very large brute-force search space today. Four missing words, on the other hand, would provide far less protection than the original 256-bit mnemonic.
Whether the blanks are at the beginning, middle or end does not substantially change this. The last word is slightly special because a 24-word BIP39 mnemonic contains 8 checksum bits in addition to 256 entropy bits, but after accounting for the checksum the overall number of valid candidates is essentially determined by the number of missing words, not their positions.
There is another important issue, though: this changes the security model from “protect a randomly generated secret” to “protect one partial secret and reliably remember another one”.
If the digital copy is exposed, the memorized words become the remaining security barrier. If you forget even one of them, you may create essentially the same brute-force problem for yourself. Human memory is also not an independent backup.
For that reason I would not use this as the only recovery scheme for a significant amount of Bitcoin. A complete seed backup stored securely, with an additional passphrase or a properly designed multisig setup where appropriate, gives you a much clearer recovery model.
Whatever scheme you choose, test the complete recovery process before relying on it.
Quote
Report
Post Reply
Quoted from Forex.com.bd-Editorial External answer — Bitcoin Stack Exchange Author: user190472 Source score (net votes, not local likes): 0 Original post: https://bitcoin.stackexchange.com/a/130987 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. The position of the missing words does not materially change the search space if the attacker knows which positions are missing. A 24-word BIP39 mnemonic represents 256 bits of entropy plus an 8-bit checksum. Each word encodes 11 bits. Therefore, if n word positions are unknown, there are initially 2^(11n) possible word combinations, but only about 1 in 256 of those combinations will have a valid BIP39 checksum. So the number of valid BIP39 mnemonics consistent with the known words is approximately: 2^(11n - 8) For example: 4 missing words: about 2^36 valid mnemonics 5 missing words: about 2^47 6 missing words: about 2^58 7 missing words: about 2^69 8 missing words: about 2^80 Eight missing words therefore leave a very large brute-force search space today. Four missing words, on the other hand, would provide far less protection than the original 256-bit mnemonic. Whether the blanks are at the beginning, middle or end does not substantially change this. The last word is slightly special because a 24-word BIP39 mnemonic contains 8 checksum bits in addition to 256 entropy bits, but after accounting for the checksum the overall number of valid candidates is essentially determined by the number of missing words, not their positions. There is another important issue, though: this changes the security model from “protect a randomly generated secret” to “protect one partial secret and reliably remember another one”. If the digital copy is exposed, the memorized words become the remaining security barrier. If you forget even one of them, you may create essentially the same brute-force problem for yourself. Human memory is also not an independent backup. For that reason I would not use this as the only recovery scheme for a significant amount of Bitcoin. A complete seed backup stored securely, with an additional passphrase or a properly designed multisig setup where appropriate, gives you a much clearer recovery model. Whatever scheme you choose, test the complete recovery process before relying on it.
Checking account access…