When random.bytes() runs but doesn't work
When random.bytes() runs but doesn't work by mishaderidder.eth13093 🥝 • 2mo • 0 views • 0 clicks | |
AI summary of the linked articleddustin, a Core-Lightning developer, analyzes the Coldcard firmware commit history to explain how weak entropy in the device's wallet generation arose. The key commit, titled "runs" and changing 1534 lines, set MICROPY_HW_ENABLE_RNG to 0, which disabled the STM32 hardware random number generator and switched to the weaker Yasmarang RNG. According to the analysis, the change was made to silence a "duplicate symbol" compiler error caused by redefining pyb_rng_get_obj, and the overridden functions are not called by make_new_wallet(), which uses random.bytes(32) and therefore falls through to the weak generator. The post concludes that developers must fully understand and verify code they ship, especially in security-critical sections. | |
Characters remaining: 10,000 comment guidelines | |
