Hey everyone
I'm messing around with a 6 dice to create a 12-word seed. I’ve tried both Ian Coleman’s site and Bitcoin.guide, and they give me different seed phrases with the same input. Anyone know why this is happening? I also noticed the bit calculation: Coleman says 1.67 bits per roll, while Bitcoin.guide shows 2.58. What gives?
Entropy Dice and Seed Generation Confusion
13 replies 82 views
swiftdiamondMember
Posts: 224 · Reputation: 87
#2Jan 17, 2018, 02:12 PM
Not really a standard for translating dice results.
Entropy equals X bits, and you need to convert the 6 outcomes into binary.
So, when rolling, you get 1-6, right? Some might say 1-3 is 0 and 4-6 is 1, giving you 1 bit per roll. Others might go odd vs even for the same result.
I tested both sites, and they show the same thing for my method.
For Coleman: 1=01, 2=10, 3=11, 4=0, 5=1, 6=00.
For Bitcoin.guide: 1=00, 2=01, 3=10, 4=11, 5=0, 6=1.
swiftdiamondMember
Posts: 224 · Reputation: 87
#4Jan 17, 2018, 09:20 PM
Wait, I’m confused. Your info seems off.
I meant I got the same results using the method you suggested. Both have 4 numbers for 2 bits and 2 numbers for 1 bit.
Check here if you wanna see for yourself:
https://iancoleman.io/bip39/
https://bitcoiner.guide/seed/.
swiftdiamondMember
Posts: 224 · Reputation: 87
#6Jan 18, 2018, 02:51 AM
If those translations are right, then it makes sense why different rolls give different seeds.
For example, if I roll 5, 6, 2, 2, 3:
Coleman would say 1 00 10 10 11,
while Bitcoin.guide would say 0 1 01 01 10.
Yeah, that clicked for me now. But about the 1.67 bits vs 2.58 thing... is there a mistake there?
swiftdiamondMember
Posts: 224 · Reputation: 87
#8Jan 18, 2018, 09:03 AM
Definitely. The average entropy for Coleman is 1.67 because:
1 bit x 2 outcomes + 2 bits x 4 outcomes = 10 bits total / 6 outcomes = 1.67.
About 2.58... that’s just log2(6). You can’t get that from the dice rolls.
I get what you’re saying, and I’m not a math expert either, but I thought the entropy from rolling a die would be 2.58, specifically Shannon entropy.
If I roll the dice, p(x) would be 1/6 for all outcomes.
Just a last question.
If I use Ian Coleman and input this 6-dice result: 1236212615165132315133131313123121561312313215615315313212132123132123123135653 21123132151311231231, I get this seed:
"over spot rate two junior rice maze people animal swap model wet".
But I see the raw binary: 01101100100 11000011010...
How does that work?
The raw binary isn’t the seed. You can change the mnemonic length, but the raw binary stays the same even though the BIP39 seed changes.
The seed comes from the mnemonic, not the other way around. That’s probably your confusion. You put the mnemonic through PBKDF2 rounds to generate the seed.
Why do 2048 PBKDF2 rounds for the seed when the raw binary could just give it?
swiftdiamondMember
Posts: 224 · Reputation: 87
#13Jan 18, 2018, 09:39 PM
According to Andreas Antonopoulos in Mastering Bitcoin:
The recovery code is 128-256 bits of entropy. You use this to derive a longer 512-bit seed with PBKDF2.
It’s about making it tough to brute-force by using salt.
ledger_walletMember
Posts: 22 · Reputation: 235
#14Jan 19, 2018, 12:04 AM
BIP39 needs multiples of 32 bits, and your entropy string gives 188 bits. 188 mod 32 = 28.
So, Coleman’s script generates 3 words per 32 bits. You’ll need to add 4 bits of padding to reach 192 bits to get the right word indexes.
Related topics
- Issues with Random Number Generation Methods 3
- Issues with ripemd160 on Ubuntu 22 9
- New Bitcoin Improvement Proposal with $100 Reward 9
- Clipboard Vulnerabilities in Cryptocurrency Transactions 8
- Understanding the Differences Between Traditional and Simplified Chinese Mnemonics 6
- Running Bitcoin Core on a Laptop with Limited Storage 20