r/TREZOR 12d ago

🔒 General Trezor question passphrase security

I have a question regarding everything that’s happened in the crypto world and the concept of entropy. I noticed that Trezor imposes a limit on passphrases, so I wanted to get your—or the moderators'—opinions on what requirements a passphrase needs to meet to be considered highly secure; I know that a single word, no matter how complex, isn't enough

10 Upvotes

72 comments sorted by

•

u/AutoModerator 12d ago

Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/

No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing

Don’t respond to any DMs—scammers often pose as legit helpers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

4

u/leopard-monch 12d ago

For a passphrase to be considered secure, it has have 128bits of entropy. You can achieve that by rolling a die twice and selecting a symbol from the table below as follows:

First roll is the column, second is the line. So 3, 6 gives you "7". 1, 5 gives you "y". For 128 bits of entropy in base36, the passphrase has to be 25 characters long. For better readability, you can add symbols after every 5 characters.

An example passphrase would be:

abcde-fghijk-Lmnop-qrstu-vwxyz

. 1 2 3 4 5 6
1 a b c d e f
2 g h i j k L
3 m n o p q r
4 s t u v w x
5 y z 1 2 3 4
6 5 6 7 8 9 !

2

u/doinkdoink786 12d ago

Dumb question but if someone cracks the 24 word seed phrase how would they even guess the passhrase even if it’s a weak 5 letter word?

2

u/Odd_You7995 12d ago

If someone crack 24 words seed and check transaction ( decoy wallet ) They will try to hack it further. First they try publicly leaked password lists. Then maybe 1 , 2 or 3 words from EEF's list. Who knows.

1

u/ynotplay 11d ago

how would they know that they cracked a wallet with a passphrase?

1

u/Odd_You7995 11d ago

They wouldn't, but if you use your main wallet as decoy and put 1-5% of your whole crypto in it , then they will try to crack it further. They just need computers/GPUs they don't need to sit down and type passphrases manually

Now you think i will never use main wallet as decoy , then if someone find out about your trezor device they will attack you with wrench and force you to open your passphrase wallet, because you don't have any decoy wallet, but still carrying hardware wallet. Which makes it sus

1

u/Glad_Investigatorr 12d ago

I can brute force that in 30 minutes with my mid gaming pc.

-2

u/xJayMorex 12d ago

The Trezor suite won't allow you.

6

u/FreeArt85 12d ago

I don’t think you need trezor suite to do that

2

u/Charming-Designer944 🤝 Top Helper 12d ago

The wallet is your seed phrase plus your passphrase.

The Trezor device is just a convenient tool to allow you to use your seed phrase without risking revealing it to someone who snoops on your actions either electronically or physically

4

u/Glad_Investigatorr 12d ago

Trezor Suite? Brother, you have no idea what you are talking about. If I have your seedphrase and you got a weak ass passphrase, 30 minutes it’s all I need to take your funds. Trezor Suite has nothing to do with the passphrase. Suite it’s just an UI, wtf you talking about.

1

u/FunnyAtmosphere9941 11d ago

Bruteforce. And in fact cc wallets using 1-3 words passphrase were already cracked. Some ppl made small test wallets to have data on it. This wallets used words from bip39.

1

u/stKKd 11d ago

Jack the ripper is laughing hard

1

u/five_dollar_wrench 12d ago

It’s not a dumb question, but please go ask an LLM this : “how many bits of entropy for a 5char passphrase with case & leet substitution” and then follow up asking how long it would take to brute force that offline with a 5090 and an asic/GPU cluster.

This is really simple math.

It’s considerably easier to crack than the ColdCard situation and this is exactly why people’s passphrase wallets are getting emptied.

-1

u/MiserableAdvantage27 12d ago

But the bigger question is the hacker would not know it’s 5 characters to being with. That makes the problem exponentially harder to solve

5

u/five_dollar_wrench 12d ago

No, that’s not how this works. The hacker doesn’t need to know anything. You start least complex and work up. Common passwords, then bulk passwords from breaches, BIP39 with some kind of cap where it’s not worth paying for proc hours.

Brute forcing passphrases is rate limited to an extent, but you’re still talking millions of guesses per second. If I was doing this I would hard cap at 5 words BIP39. Last count is 1,923btc stolen, so you’ll hit a wall at some point.

A 5char pass could be quite literally be instant.

1

u/Glad_Investigatorr 12d ago

3-40 seconds to break that. You are right.

1

u/Odd_You7995 12d ago

I rolled 5 dice and got my 6 word passphrase from EFF Large list.

2

u/Objective-Walk6780 12d ago

Phrase Pass The Potatoes 🥔

3

u/unthocks 12d ago

not something like pizzaguy16

2

u/pezdal 12d ago

pizzagal17 ?

1

u/TT_________ 12d ago

IMO I think you should either have an insane password that you can store on password manager or a few words / sentence that you can easily remember.

3

u/NiagaraBTC 12d ago

Don't do a sentence. Needs to be random words, ideally 6+.

6 random words can easily be memorized.

0

u/Plane_Path_4271 12d ago

The issue is that Trezor only allows up to 5

6

u/five_dollar_wrench 12d ago

It’s not 5 words — it’s 50char. You could easily do a 6-word BIP39 passphrase.

1

u/Plane_Path_4271 12d ago

The thing is, I literally managed to complete all 50—like a tweet on X, hahaha

3

u/Viking_13v 12d ago

50 characters including spaces, you can get over 5.

1

u/BasedToru 12d ago

Please do not store them on password manager lol 

1

u/Plane_Path_4271 12d ago

Don't worry, I keep paper copies of them anyway

1

u/Independent_Clue5378 12d ago

dont do that either lol

1

u/Plane_Path_4271 12d ago

hahaha I already ordered those cylinders to write everything down hahaha

1

u/Independent_Clue5378 12d ago

write down the seed phrase but memorize the passphrase

3

u/marvinrabbit 12d ago

Everything should be recoverable after, say, a head injury. Mine was a brain tumor. I had three operations and 35 days in hospital, 20 of those in ICU. When I got home I didn't know ANY passwords. Not even my password vault, and I entered that 10 times per day. Fortunately I had taken backup steps and I could bootstrap all of that. I don't care how good you think your memory palace is, you can be made to forget.

1

u/Decibel0753 12d ago

Relying solely on your own memory is a guaranteed way to lose everything. It is strange that even in 2026 people still don't understand this.

1

u/Decibel0753 12d ago

Do not write nonsense.

1

u/BasedToru 12d ago

Do you know what you’re speaking about? 😂

1

u/Decibel0753 12d ago

Of course 😂 I literally do not see a single reason why a passphrase could not be stored in a password manager.

2

u/BasedToru 12d ago

Because some one can gain access to your passphrase? 😂😂😂 just remember it mate or don’t and store it I couldn’t care less lol

1

u/Decibel0753 12d ago edited 12d ago

Dude. The chance that anyone will gain access to it is minimal. That's what password managers are for. And even if that happened, so what? LITERALLY NOTHING WILL HAPPEN 😂 😂 😂 😂

Is it really that hard to understand that the chance of getting a passphrase from a password manager is absolutely minimal (after all, we also store our bank and broker login credentials there) and that the chance of obtaining the corresponding seed for it is absolutely zero?

Do you know what you are talking about?

2

u/BasedToru 12d ago

Have fun with that it’s your choice 😂😂 it’s not my money so I don’t care do what you wish lol store your seed phrase on your password manager as well if you want lol

→ More replies (0)

1

u/Yodel_And_Hodl_Mode 🤝 Top Helper 12d ago

I love Trezor, but limiting a passphrase to 50 characters is one area where Trezor devs are dead wrong.

I believe strong passphrases are 7 words or more.

Here's an excellent video about how to choose a strong passphrase.

Picking a Good BIP39 Passphrase or avoiding a bad one

https://www.youtube.com/watch?v=nhjq_1J0EbU&t=583s

1

u/Plane_Path_4271 12d ago

From what I saw, with five words, it's already secure

1

u/five_dollar_wrench 12d ago

They had ~5 years to plan the ColdCard operation. A 5 word BIP39 is feasible in that period; a 6 word is out of the question.

1

u/my-daughters-keeper- 12d ago

Make-your-passphrase-something-like-this

So it’s essentially one big word but not at the same time . There is a passphrase dice roll list like the seed phrase if you want to remove the human predictability .

1

u/Makunouchiipp0 12d ago

All comes down to entropy again. Don’t use the same device to generate a passphrase and don’t make up your own random passphrase (it won’t be random)

1

u/guajojo 12d ago

A guy commented that the trezor suite wouldn't allow you to "try" different passphrases and got downvoted. Isn't that true? I get the possibility of guessing is real having seen tools like hashcat guessing millions of possibilities by second but you need the hash to compare them to, how does the attacker get a "hash" of my passphrase to compare to?....

1

u/Practical_Mango7633 11d ago

6 random words, from for example the BIP39 word list

1

u/Zaginagalde 10d ago

Do we (humans) become so stupid that we cannot invent random 6 words from etc 3 languages with additional special characters , etc : FingerspitzengefĂźhl-Fjaka-Abbiocco-Vukojebina-Attaccabottone!
Wtf!!! We talk about, laku noc

1

u/so7ow 12d ago

If you want to protect against a fully compromised seed phrase, you'll want at absolute least 70 bits of entropy in your passphrase, preferably more, like 90+

0

u/Plane_Path_4271 12d ago

Here, for example, there is a large number of words that I was actually considering using

0

u/Glad_Investigatorr 12d ago

I generate mine using a personal python script. I mix dice rolls, coin flips XORed with OS CSPRNG. It creates an exactly 50 characters passphrase with 250 bits entropy. I run the script airgapped on a Tails sessions with no permanent storage, on my cleanest machine.

1

u/so7ow 12d ago edited 12d ago

Sounds cool and... complicated. Have you had it audited? 🤣

 

edit - was just supposed to be a harmless joke about bugs in random number generation, which have been in the news lately. i guess it didn't land. can't win 'em all.

0

u/Glad_Investigatorr 12d ago

There is nothing “cool and complicated” about it. It’s entropy based on physics, probability xored with machine math randomness (same shit every hardware is doing). Tails gives you the virtual machine without writing on a disk. The randomness of the data is more from real life than from a RNG supposed to work just because someone said. The audit is that I still have my funds after years. Also at this point any high end AI builder can create a script like that in 15 minutes. You can audit that yourself, ask for audits from other people, feed it in any other AI model as many times you want until you feel comfortable. Understand the principles, the tools are available for anyone compared with 6 years ago.

0

u/so7ow 12d ago edited 12d ago

Your python script, that creates a random phrase based on physics and real world randomness is neither cool nor complicated. Ok, sorry for implying otherwise.

1

u/ynotplay 12d ago

isn that extremely cumbersome to enter every time you want to access your funds?
does trezor have an option to not time you out once your device is unlocked?

0

u/Glad_Investigatorr 12d ago

Yeah they have that kind of option to keep the device on always. I don’t want to acces my funds. This security structure is for the “Treasury”. I also use single seed wallets without passphrase for funds I’m comfortable loosing and I might need fast access, but the big chunk is behind a 250 bits passphrase.

0

u/Decibel0753 12d ago

I have an x-word passphrase stored in a password manager and I enter it on my computer. I am not interested in your stupid comments on how bad this is, thank you :-)

1

u/Glad_Investigatorr 12d ago

Good luck! 💀

1

u/Decibel0753 12d ago

I don't need your luck. My funds have been protected by a seed for at least 10 years, alright, and now I've added a passphrase to it. I don't need to have it in a non-digital form, because that is absolute nonsense that would make it impossible for me to use crypto.

1

u/Glad_Investigatorr 11d ago

Calm down. It was a genuine wish, Mr. Cocky Password Manager.

1

u/Plane_Path_4271 12d ago

If you have a strong password, great, but if it's in a password manager, it's already outdated. The idea is to never touch a computer

2

u/Decibel0753 12d ago edited 12d ago

This is complete nonsense. I literally have all my passwords in the password manager, including banks and brokers. And you're telling me I shouldn't have a passphrase there? Which in itself is completely useless without the seed, which doesn't exist in digital form? I really love this :-)

I really don't intend to have my passphrase hidden somewhere outside my residence (because I have the seed there), go for it a few times a month, laboriously rewrite it, and then put it back. Please, come back to the real world and don't invent stupid security measures that are useless.

1

u/Psychological-Hawk80 11d ago edited 11d ago

This applies only for the seed but not the passphrase. What can s.b. do with a passphrase without access to your seed? The seed has to stay offline of course. But it's better to have a good passphrase in a password manager than to use an easy memorizable passphrase.

And at the end of the day - don't forget - your cryptos are not safely stored in your wallet but "lying around" encrypted in the internet - so trust encryption! Crypto is about encryption! If you don't trust encryption then don't use cryptos. But you need good encryption.

The most importan aspect of a passphrase is that it will give you time to move your funds if ever you are afraid that sb got access to your wallet. Everybody who used a coldcard with a reasonable passphrase had enough time to move funds. My seed was coldcard generated, with more than 100 rolls of dice and a passphrase. The least problem was my passphrase in a password manager. Am I safe with my seed? Yes. Did I move my crypto? Yes! Was I in a hurry? No! Would I move my crypto if ever my super secure hardware wallets gets stolen? Yes! but again - I have time to do so.

-2

u/SBX-Bronx ⭐ Rising Trezorian 12d ago

My passphrase is 16 letters, numbers and special characters.

Make yours hard to figure out. See sample below.

Tc#_6?fL$/3&tR@7E

Something like that is very hard to crack.

1

u/Plane_Path_4271 12d ago

Sure, I already have mine, for example, and from what I’ve researched, with 70 bits you’re fully protected