“51/49 = 2% entropy loss” is the wrong calculation.
If we're asking how secure the resulting key is against an attacker who knows the bias and guesses optimally, there is a formal measure called guesswork.
For 128 independent 51/49 flips, doing that calculation gives an average of roughly 2^126.8 guesses, i.e. about 126.8 bits of average guessing security, versus 2^127 guesses out of 127 bits for a perfectly uniformly random 128-bit key for comparison.
That's about 0.2 bits loss.
Source: https://www.isiweb.ee.ethz.ch/archive/massey_pub/pdf/BI633.pdf
Tbf, I just learned about guesswork entropy today. I was using Shannon entropy to calculate before which tells us we'd have an effective entropy of 127.963 bits but that's not the most appropriate measure to use for this case apparently.
But also an approximate 2% loss is also not appropriate.
Also this all assumes there is a known bias. The bias in a coin is "51% chance it lands the same as what you had facing up before you flipped it". So it's not even as bad.
And you were right, I got my wires crossed, the bias doesn't diminish over turns, it's effect on entropy follows a log curve so a small bias.
Btw, I wouldn't call 20% entropy loss negligible. That isn't what I was saying.
127.963 out of 128 is negligible, 126.8 out of 127 is negligible.
And coins can't have 20% bias. Even if you unevenly weighted a coin, it would have approximately 51/49 odds because we're talking about rotation over a central point in mid air. Uneven weight distribution doesn't affect the coin flip.
I know we are talking about shit that doesn't practically matter to most people, but I am defending the idea that shuffling paper like you do is going to produce better entropy than coins or dice or that you need casino dice for a fair outcome. That is all just FUD.
