Risks of Using Custom Seeds in Wallets

10 replies 318 views
ColdGangMember
Posts: 152 · Reputation: 183
#1Sep 16, 2018, 02:39 AM
Been thinking about better ways to store our seed phrases. Custom words look promising, right? But how safe can we really feel about just relying on a word or two? Like, should we trust the safety of a wallet just because of those custom words? What if someone has your 12 words? Are you really at risk?
4 Reply Quote Share
stacksatsHero Member
Posts: 404 · Reputation: 2023
#2Sep 16, 2018, 03:48 AM
I think it's risky to trust your wallet's safety on custom words alone. What if you type it wrong? Typos, capitalization issues, even autocorrect can lead you to a wallet with no funds. You won’t see any error, and you might just think your coins are lost forever. That's why I'm not trusting just those custom words.
2 Reply Quote Share
chrisomegaFull Member
Posts: 158 · Reputation: 631
#3Sep 16, 2018, 05:56 AM
If your passphrase is complex enough, it should keep your funds safe even if someone has your seed phrase. But I wouldn't ditch the seed phrase entirely. A strong passphrase is important, but making it too complicated could lead to mistakes when writing it down. I’d rather stick with a secure seed phrase and keep the passphrase simple.
0 Reply Quote Share
ColdGangMember
Posts: 152 · Reputation: 183
#4Sep 16, 2018, 10:01 AM
I get your point but what if the user is careful with their writing? If they know exactly what they wrote, that should help avoid mistakes, right? Plus, I’ve tested it, and it seems to be case-sensitive too. Couldn’t a standard Electrum seed with just a couple of personal words work better?
3 Reply Quote Share
CalmMinerFull Member
Posts: 554 · Reputation: 784
#5Sep 16, 2018, 01:54 PM
When I first read your post, I thought you meant using custom words as your seed phrase. That’s possible in Electrum, but honestly, it’s not the best idea. Human randomness isn’t that great. For a passphrase, it’s tough to recover a wallet without it, but if someone has your 12 words, they could guess the passphrase.
3 Reply Quote Share
ColdGangMember
Posts: 152 · Reputation: 183
#6Sep 17, 2018, 11:19 PM
I’m not talking about fully custom seeds. I know the risks of randomness. I just want to brainstorm the risks of having an extra passphrase after the regular 12 words. Maybe there’s a way someone could access a wallet using just those 12 words and some flaw in the custom words?
6 Reply Quote Share
0x4lphaFull Member
Posts: 519 · Reputation: 509
#7Sep 20, 2018, 06:09 AM
Two words as a passphrase? That’s weak. Like, super weak. A space counts as a character, so it’s really one word. Brute-force attacks could crack those in no time.
0 Reply Quote Share
CalmMinerFull Member
Posts: 554 · Reputation: 784
#8Sep 20, 2018, 10:37 AM
The strength of a passphrase really depends on how complex it is. For example, something like bstqlines2qutin3ag might work as a single passphrase. If that's the case, two words might be okay, but it’s all about how complex they are.
3 Reply Quote Share
0xChadNewbie
Posts: 513 · Reputation: 3
#9Sep 20, 2018, 11:01 AM
Think of the passphrase like a password. If the attacker has your seed phrase, they can try to brute-force it without limits. Two common words? Not safe at all. They can be easily attacked using a dictionary method. A long, unique word with some numbers and symbols would be way better.
4 Reply Quote Share
MadNovaHero Member
Posts: 278 · Reputation: 3536
#10Sep 20, 2018, 03:35 PM
Humans can be forgetful. If you rarely use your passphrase, you might mix it up with other passwords. Forgetting capital letters or symbols could put you at risk. Memorizing just a seed phrase isn’t enough without proper backups.
3 Reply Quote Share
ColdGangMember
Posts: 152 · Reputation: 183
#11Sep 20, 2018, 03:47 PM
Thanks for all the insights, everyone. I think I see the main risk now. It looks like using actual words in a custom passphrase is where the real danger lies. Hashing the seed phrase without custom words already acts like a dummy wallet. I’ve tested it a bit, so I’m getting the picture.
4 Reply Quote Share

Related topics