Creating a BIP39 Mnemonic Generator in Python

18 replies 113 views
Posts: 224 · Reputation: 87
#1Apr 15, 2017, 12:22 AM
I whipped up a quick script for generating BIP39 mnemonics. Just a fun project, not gonna use it for real money. Here’s the code: To run it: 1. Create a file (let's say mnemonic_gen.py). 2. Copy the code from above. 3. Make another file called bip39_wordlist.txt and paste the wordlist there. 4. Keep both files in the same folder. 5. Run it using python mnemonic_gen.py. Sample output below.
5 Reply Quote Share
cobra51Newbie
Posts: 100 · Reputation: 31
#2Apr 15, 2017, 09:44 AM
Might want to ditch the zfill. Doesn't really help when you've already got SHA256 hashing afterward. Should just regenerate entropy if it's less than what's needed instead. Also, a quick check on entropy before hashing could make it more secure.
1 Reply Quote Share
Posts: 224 · Reputation: 87
#3Apr 15, 2017, 01:28 PM
I updated the script based on your input. Now, it keeps regenerating entropy until it hits 128 bits. Thanks for your advice.
3 Reply Quote Share
D4rkHawkSenior Member
Posts: 9 · Reputation: 1367
#4Apr 15, 2017, 01:51 PM
You’ve actually made it a bit biased now... This is a common pitfall. By looping until it’s exactly 128 bits, you remove the chance of generating a true 128-bit value with a leading bit of 0. In hex, that means your entropy will always start from 8 upwards, which isn’t ideal.
3 Reply Quote Share
Posts: 224 · Reputation: 87
#5Apr 17, 2017, 11:11 AM
Thanks for that, PowerGlove! I’ll take a deeper look later. This is how I learn better, by coding.
0 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#6Apr 17, 2017, 03:18 PM
Generating extra rounds of entropy averages it out. Like, you’re just gonna get the mean of all the rounds. If you're trying to strengthen the RNG, it might not be the best move. OpenSSL's RNG outperforms it.
1 Reply Quote Share
D4rkHawkSenior Member
Posts: 9 · Reputation: 1367
#7Apr 17, 2017, 08:43 PM
Yeah, slicing a 128-bit string from a longer random string can help fix that bias. But it seems like you might not have grasped the bias issue fully. Let me explain: pretend you’re running a test...
0 Reply Quote Share
Posts: 5 · Reputation: 8
#8Apr 18, 2017, 12:14 AM
Hey there! Appreciate your efforts, even if it’s not a huge upgrade. Suggesting a slight change here could make it flow better.
3 Reply Quote Share
m1kes4tFull Member
Posts: 167 · Reputation: 252
#9Apr 18, 2017, 12:02 PM
I took a deep get into entropy, made cool tweaks like adding a random secp256k1 point and different entropy salt methods. Also, using random hashes to avoid predictability. If entropy is close to 50%, that’s better in theory. What do you think?
3 Reply Quote Share
Posts: 5 · Reputation: 8
#10Apr 20, 2017, 11:32 AM
Interesting approach. But are you sure you have a better source of entropy? Randomly picking from three sources doesn’t guarantee that. Also, what’s the deal with not storing the function result?
4 Reply Quote Share
m1kes4tFull Member
Posts: 167 · Reputation: 252
#11Apr 21, 2017, 08:57 PM
Yeah, now all three methods blend together.
1 Reply Quote Share
Posts: 5 · Reputation: 8
#13Apr 22, 2017, 12:04 PM
It seems like the mnemonic generated doesn’t align with Ian Coleman’s website... am I missing something?
2 Reply Quote Share
0xChadNewbie
Posts: 513 · Reputation: 3
#14Apr 22, 2017, 05:36 PM
For those 24 words, it’s the checksum issue. It should follow BIP39 rules where the checksum is the first 8 bits of the SHA256 hash from the entropy. Here’s how to fix it: Also, the 12 words are using incorrect 256-bit entropy instead of the expected 128 bits.
3 Reply Quote Share
Posts: 5 · Reputation: 8
#15Apr 24, 2017, 08:28 AM
Just curious, can someone explain why this might be a problem? And what’s better in the other members’ code?
1 Reply Quote Share
m1kes4tFull Member
Posts: 167 · Reputation: 252
#16Apr 24, 2017, 11:14 AM
You’re right, I’ve adjusted it to follow BIP39 standards.
3 Reply Quote Share
Posts: 224 · Reputation: 87
#17Apr 24, 2017, 02:26 PM
Time flies, and I forgot some key replies. Thanks for the detailed feedback. I reviewed the issues you pointed out and made corrections. Can you check them out before I update my main post?
2 Reply Quote Share
D4rkHawkSenior Member
Posts: 9 · Reputation: 1367
#18Apr 26, 2017, 06:00 PM
No worries! Looks good to me.
6 Reply Quote Share
Posts: 3523 · Reputation: 35
#19Apr 26, 2017, 07:08 PM
One trick I’ve picked up: run hash-based cumulative testing. Just loop your code with predictable random bits, then hash the generated mnemonics. I used this with a million inputs: Here’s what I got: After testing my own BIP39 code this way, I got the same result, so I feel confident about the correctness of mnemonics.
4 Reply Quote Share

Related topics