2024-11-10 14:26:38
*note: This version of the article uses some four-letter words some people may not like. If you prefer cartoon-like cussing, you can read it [here](https://marc26z.com/use-a-seed-signer-with-cold-power/).
It's that time, again--The bull market which happens every 4 years like the Winter Olympics. We've surpassed the previous USD/ATH. This is the 498th resurrection of our beloved bitcoin, but you know what really turns my crank? Bitcoin cybersecurity!
I love digging into the nitty-gritty of cryptography not CrYpTo and finding creative ways to use my toy collection. I mean, hardware wallet(a.k.a. signing devices) collection. Nah, they're toys. Yesterday, as I was playing with my toys, I was inspired to use my seed signer after a long hiatus. To be clear, I love the Seed Signer. It has some neat features:
- Generate seeds with the entropy from a picture
- Hand-drawn QR codes for easy seed backup
- You can DIY
![plug](https://i.nostr.build/E3x1Vg7i0QNjU3RJ.png)
It looks cool too, but for the record, I wouldn't use it for a single sig wallet because it does not contain a secure element. According to NVK, there are zero days and supply chain attacks you can't really mitigate with the seed signer. Although I think this is a fair criticism, it can be useful:
- As an educational tool
- Part of a multi-sig backup.
Michael Flaxman, in his [10X Your BTC Security Guide](https://notes.marcleon.work/#root/0vxct4qCx1C5/YxWwjfah4d4D?ntxId=ApLzSR), suggests removing a Wi-Fi card and hard drive from a computer, boot up TAILS, plug your computer into an RJ45 port with an Ethernet cable for Internet access, navigate to https://seedpicker.net/ on the default [TOR](https://www.torproject.org/) browser, unplug the Ethernet cable from the RJ45 port, and generate the seed for your paper wallet. That sentence is too damn long, but this is indicative of how cumbersome this method is.
This was necessary when he wrote it since we did not have as many hardware wallets back then as are on the market today. In my cybersecurity opinion, and I am not a certified cyber security expert, buying a seed signer requires less technical know-how than using Flaxman's guide. This is not a criticism of Flaxman, his guide is one of my favorite things ever written about bitoin because of it's educational value. If you want to learn about extreme cybersecurity, Flaxman's guide makes an excellent lab. **We assume no network security model is 100% secure,** so we never risk compromising our keys by ever connecting to an Internet-connected device. It's a hell of an education.
## Seed Signer Is For Everybody
![seed signer](https://i.nostr.build/KG1VqfQH3sbjCQC5.png)
Say you work a full time job and didn't spend the majority of your free time learning this stuff during a pandemic. Or maybe you're like my wife. She think's Bitcoin is cool now, but this one time she walked in on me with my Cold Card plugged into a 9v battery and said, "See. I'm never using *whatever the fuck* that thing is. My wife is never removing a Wi-Fi card from a laptop. If you're like my wife, the Seed Signer is right for you, if you want to use multisig. It's also not imperative to use the 9v battery if you don't want to. You can just plug it into a wall outlet like everybody else.
I want to start bringing the Seed Signer to my local meetup, but it's at a brewery and I don't want to be a wallflower because I need to plug the damn thing into an outlet so I thought, “Why not try the [Cold Power](https://usbcoldpower.com/) with my Seed Signer?”
I found one of my [magnetic micro-USB adapters](https://www.amazon.com/Magnetic-Micro-USB-Connector-Water-dustproof-antioxidant/dp/B0D2Y4F9FR/ref=sr_1_1_sspa?dib=eyJ2IjoiMSJ9.czIXiLc88NoDXKD5cqfGUojOf-JD766ZLolCTtGJXJxy9B0I-9g9RbLiB95HffRy8-o6Fo-78ijTjcubw93VYwNn9WaFgg9kraKbLDVYEj50RueMTqz75r7ouUMXD_m1YnNWFIEGNmevIO31B8AT6H_CXzK6loS3Em7R96Q-xL24kYO-Ys0WULVpl_OnFm_9_cqOxqAsGpLskXPRKCV7d7I3EYruyQc82ermd_JIZpY.cCmNDmhUM5mhbNY0xoCENKM9Z9cscEe49zAsKzg8UsU&dib_tag=se&keywords=magnetic+micro+usb+adapter&qid=1731162326&sr=8-1-spons&sp_csd=d2lkZ2V0TmFtZT1zcF9hdGY&psc=1) and plugged it into the Seed signer, Then I plugged the battery in. My switch is on because the flimsy plastic switch broke the first time I turned it on, but it still works. I just broke it with my fat thumbs.
It felt as if it took as long as a difficulty adjustment to boot-up, but in reality it was about the time it takes the Liquid Network to find a block. I proceeded to take a picture and write down a 12 word seed. I plan on using this with the Nunchuck testnet wallet to show people at my local Meetup how to create seeds and take self-custody of their Bitcoin. Again, I would not use this as a single sign because there are more secure options, but it is a great tool for teaching Bitcoin cybersecurity and can be a great wallet that can mitigate the risk of supply-chain and retirement attacks when used as part of a multi-sig quorum. I can also now use it in the middle of a brewery. I'll write about how this goes the next time I get down there.
### Why We Use The Cold Power
![Cold Power](https://i.nostr.build/2rokrWyXSsJemLxb.png)
I placed one of those magnetic adapters I bought on Amazon into one of the power holes. Power holes is a technical term for microUSB. This is because the Cold Power does hooks up to a cable that does not transmit data, only Power. Get it? It's like a cold wallet, but instead of a wallet, it's a power cable. You hook this cable up to a technology which was invented in 1836, a [battery]. 9V batteries contain no data. It is only Power, but most of us must trust Coinkite. Maybe they programmed the green part to be a bitcoin stealing script. I doubt this and think Coinkite is an honest company, but the awesome sauce thing is, the little magnet I bought on Amazon does not allow the transmittal of data. I don't need to plug in a charger that might be compromised.
This might sound paranoid, but in [Tools of Titans](https://www.amazon.com/Tools-Titans-Billionaires-World-Class-Performers/dp/1328683788), [Samy Kamkar](https://en.wikipedia.org/wiki/Samy_Kamkar), malware has even been found in cigarette lighter chargers. Imagine a fix of nicotine costing you you entire life savings. That's not likely to happen, but why take a chance? It's better to spend several thousand [sats](https://www.investopedia.com/terms/s/satoshi.asp) on a charger and a 9v battery than lose your whole stack.
According to [Wired Magazine](https://www.wired.com/story/infrared-laser-microphone-keystroke-surveillance/), he can also learn the keystrokes you're typing on your laptop keyboard through a window. This means typing a seed onto a laptop might not be the best idea even if you are afraid of this. It is better to take a picture and use the entropy from the random picture.
#### Powering The Seed Signer With A Coinkite Product
Seed Signer and NVK, the CEO of Coinkite seem to have some beef on [nostr](https://nostr.com/), but it's none of my business. The part I find interesting is a product made by Coinkite works with a product made by Seed Signer. This was made for the Cold Card, but it works with a hardware wallet made from someone else. Too bad politics isn't more like that. It's nice to see two rival companies make products that are compatible with each other, but that's just the way free and open source software like bitcoin is. Seeds from Coinkite can be used with the Seed Signer. Maybe that's okay if it's only $1,000 worth of bitcoin on the Seed Signer. You don't need to go to Defcon 5 for every single sat. It's not practical. Sure, if the NSA was after you and wanted to steal your $1,000 worth of bitcoin from you, they could probably do it. Why would they spend ten thousand dollars to do this to you? This is not in most people's threat models.
**Wait...Then why do you need to use the 9v battery thing-a-ma-jig?** I technically don't need to , but we could also use this for a multi-signature quorum? What if you took your wallet to a safe deposit box, but the vault does not have a plug?
![no plug](https://i.nostr.build/TIKA3suY8aun0BTI.png)
I created this key with no power outlet at all. This means I could do this in the middle of Alaska where there's no cell phones, where you only need to worry about bears stealing your seed phrase... That's a bit much, but it's possible.
I was not able to take a picture on the same battery charge so You might want to use a fresh battery if you ever try this yourself.
Thanks for reading.
- If you like this blogs with no swear words, send sats to **marc26z@strike.me/**
- If you like this blog with swear words, send sats to **marc@npub.pro/**
✌️
[npub1marc26z8nh3xkj5rcx7ufkatvx6ueqhp5vfw9v5teq26z254renshtf3g0no](nostr:npub1marc26z8nh3xkj5rcx7ufkatvx6ueqhp5vfw9v5teq26z254renshtf3g0)
[869,719](https://mempool.marcleon.work/block/0000000000000000000173e894282485050b6113e984bafb9a1931dd62e38553)
As Seen On TIR:
http://p66dxywd2xpyyrdfxwilqcxmchmfw2ixmn2vm74q3atf22du7qmkihyd.onion/use-a-seed-signer-with-cold-power/