It’s become dogma that everyone should use a passphrase and only an idiot would leave their coins “unprotected” by a passphrase. I do not recommend them. In fact, I think they do more harm than good by adding tedium, luring people into an overconfident sense of security, and worst of all causing people to lose funds from typos and forgetfulness. It is more convenient yet equally secure to have a 24-word seed with verifiable entropy and no additional layers.
Passphrase Advantages Refuted
“I’m adding entropy.”
Bitcoin private keys themselves are 256-bit, which equals 24 words, so you cannot make it harder to crack by adding a 25th word and beyond. Long passphrases did save some people in the coldcard incident. But if you are not confident in your seed phrase, making your own with dice is a much better solution.
“I keep my passphrase separate from my seed.”
You have essentially created a 2-of-2 key. This is no better than storing words 1-12 in one place and words 13-24 in another. In fact, it’s less secure unless your passphrase has at least 128 bits of entropy. These moves also increase your risk of losing access. If you really want separate keys, consider 2-of-3 multisig instead, which can survive the loss of 1 key.
“I use the passphrase-less wallet as an early warning system.”
A 24-word seed cannot be cracked. If someone has your seed, either they have your passphrase too, or you were better off splitting the seed (see above).
“I just like having multiple wallets and only one seed to remember.”
BIP-85 is a superior method, because the child wallets don’t compromise the security of the main wallet.
“What about wrench attacks? My passphrase hides my real funds behind a decoy wallet.”
My favorite: your dark fantasy where you lie to some psychopath who has you tied to a chair and he believes you. First, this whole scenario is incredibly rare. Second, if you’re going to lie, there are endless ways to do so without complicating your own access to your coins. Third, there is no easy answer to a situation where someone is torturing you or threatening your family. Fight back, lie, or pay up — those are your options and a passphrase won’t change that.
“What if my hardware wallet has malicious firmware?”
It would probably just export the XPRV directly, not caring whether a passphrase was part of its generation process.
submitted by /u/PoeCollector
[link] [comments]
