- let's start considering passphrase with recovery seeds.
- let's start considering multisig if possible.
While Trezor and others aren't affected, I personally don't feel it's enough to just generate a recovery seed and sit on it as your total security method, the existence of 2FA strengthen the existence of passwords for every websites, so I hope you beginners learn something from this.
This was really a wake up call for me, I had expected that I was much more safer with hardware wallets but when you think about this it was quite clear from the start that something like this was possible. I have used several Ledger wallets and Trezor, but I have not had ColdCard and was lucky to avoid this. But I never used passphrases on any of them before actively, and this made me realize just how insecure my setup was. I would not like to use Multisig that uses several hardware wallets because it seems to me to be very complicated unless it is for something like very deep cold storage of significant amounts. I am currently trying to update all my wallets with new seeds and a passphrase.
- let's start considering the Dice 🎲 rolling method for entropy
I am not so confident about this because when this is not done right it is not good at all. Even if you provide a proper strategy for enough entropy, many users will not understand how important it is and may skip doing some steps or just overlook them and generate a very low entropy wallets which they believe is strong.
This is above basic users' technical knowledge. What people would usually say is to completely avoid coldcard from this point. But I think that this is also going to make everyone who has got the basic knowledge to pursue them to search for more means of securing their wallets.
Just use a passphrase, that is basic knowledge. There is no need for basic users to use complicated methods like generating seed phrase with alternative methods.