Author: Pavol Rusnak 2013-11-16 23:49:04
Published on: 2013-11-16T23:49:04+00:00
In an email conversation on 03/11/13, Timo Hanke described a neat trick employed by Trezor where the device picks random s and sends S=s*G to the computer while keeping s secret. However, one question remained regarding how to ensure the mnemonic written down corresponds to the secret in Trezor. Pavol Rusnak suggested proving external entropy was used while generating the master seed as a solution. Additionally, he suggested allowing users to use their own firmware if they do not trust the provided one.
Updated on: 2023-06-07T18:20:40.120999+00:00