waxwing on Nostr: I want to write a whole essay about this Coinkite disaster but I'll resist for now, ...
I want to write a whole essay about this Coinkite disaster but I'll resist for now, and just make one point that I don't think others are making: constrained devices need to source entropy in unusual, more complex ways. /dev/urandom as a PRNG, at least post-2012, has been pretty reliable for software wallets throughout bitcoin's life. There have been several other entropy failures in wallets similar to this one, but they've *all* been based on customized entropy generation methods. I'm dubious that people's conclusion is not to be suspicious of the constrained, single-purpose device model, but instead to conclude 'hardware wallet plus dice rolls and/or multisig across manufacturers' is now the sensible thing. That model is not terrible at all, pros and cons etc., but damn is it asking a lot of ordinary users. I have always advocated for commodity hardware (a laptop) that never sees the internet, if you are serious about security, but I admit the hardware wallet model's advantages are very notable. The thing is, so are its risks.
Published at
2026-07-31 11:47:05 UTCEvent JSON
{
"id": "4f9863960f71f8cd7124eb19053fd6aa86d2c50714af8836d00250cc4e49bafd",
"pubkey": "675b84fe75e216ab947c7438ee519ca7775376ddf05dadfba6278bd012e1d728",
"created_at": 1785498425,
"kind": 1,
"tags": [
[
"alt",
"A short note: I want to write a whole essay about this Coinkite ..."
],
[
"client",
"Amethyst"
]
],
"content": "I want to write a whole essay about this Coinkite disaster but I'll resist for now, and just make one point that I don't think others are making: constrained devices need to source entropy in unusual, more complex ways. /dev/urandom as a PRNG, at least post-2012, has been pretty reliable for software wallets throughout bitcoin's life. There have been several other entropy failures in wallets similar to this one, but they've *all* been based on customized entropy generation methods. I'm dubious that people's conclusion is not to be suspicious of the constrained, single-purpose device model, but instead to conclude 'hardware wallet plus dice rolls and/or multisig across manufacturers' is now the sensible thing. That model is not terrible at all, pros and cons etc., but damn is it asking a lot of ordinary users. I have always advocated for commodity hardware (a laptop) that never sees the internet, if you are serious about security, but I admit the hardware wallet model's advantages are very notable. The thing is, so are its risks.",
"sig": "40fd029ddada5ba7f34eaede485f0501f8b5d461a2a01f8255ca08e3c738e8dab919bd299bb123015c2719e09942c600721369bc8e0912de1dff3e6a0730f5cf"
}