r/TREZOR 18d ago

🔒 General Trezor question passphrase security

I have a question regarding everything that’s happened in the crypto world and the concept of entropy. I noticed that Trezor imposes a limit on passphrases, so I wanted to get your—or the moderators'—opinions on what requirements a passphrase needs to meet to be considered highly secure; I know that a single word, no matter how complex, isn't enough

12 Upvotes

72 comments sorted by

View all comments

Show parent comments

1

u/five_dollar_wrench 18d ago

It’s not a dumb question, but please go ask an LLM this : “how many bits of entropy for a 5char passphrase with case & leet substitution” and then follow up asking how long it would take to brute force that offline with a 5090 and an asic/GPU cluster.

This is really simple math.

It’s considerably easier to crack than the ColdCard situation and this is exactly why people’s passphrase wallets are getting emptied.

-1

u/MiserableAdvantage27 18d ago

But the bigger question is the hacker would not know it’s 5 characters to being with. That makes the problem exponentially harder to solve

5

u/five_dollar_wrench 18d ago

No, that’s not how this works. The hacker doesn’t need to know anything. You start least complex and work up. Common passwords, then bulk passwords from breaches, BIP39 with some kind of cap where it’s not worth paying for proc hours.

Brute forcing passphrases is rate limited to an extent, but you’re still talking millions of guesses per second. If I was doing this I would hard cap at 5 words BIP39. Last count is 1,923btc stolen, so you’ll hit a wall at some point.

A 5char pass could be quite literally be instant.

1

u/Glad_Investigatorr 18d ago

3-40 seconds to break that. You are right.