I still have problems with the need for 37 random characters for the 25th word.. and let's say if someone just has 10-15 somewhat random characters, then how long is it going to take to break into the Trezor?
I think a lot of confusion has arisen about how strong a passphrase should be to protect someone's seed in case someone comes into physical possession and tries to extract the seed. What someone wanted to emphasize is that a passphrase of at least 37 random characters would provide the same level of protection as the seed itself (24 words) and is practically impossible to brute force, but that does not mean that 10+ characters are not resistant to brute force.
We can always check how long it actually takes to brute force a password on sites like
https://www.passwordmonster.comOnly 9 characters in this password makes it virtually impossible to brute force ->
By the way, we have a long term member in these here parts that swears by that piece of crap, aka Ledger, and surely there are probably quite a few members who may or may not be in the closest about their use (and apparent belief) in the Ledger crap.
Ledger does not have the problems that Trezor has, but if we take into account that a few years ago almost the entire database of users with all the data was hacked, and that a few months ago they announced the revolutionary
"seed recovery" service, they shot themselves in the knee by giving the possibility at all to one such device shares the user's seed with as many as three different companies.
Of course, the service is optional and you pay $9.99 per month, but when someone does something completely contrary to what they have been advocating for years, I wonder how to trust such a company.
Oh I see that the 39+ pin is different from the extra word...and that 39 character pin would resolve the other issue regarding a hacker getting ahold of the physical device and breaking into it.. so that still leaves the issue of the 13th or 25th word actually not needing to be very complicated, and a 8-15 character passphrase may well make it quite difficult to get at the wallet because they would first need to know (or suspect) that such a wallet (or extra portal to a wallet) actually exists in connection with the 12 or 24 word seed that was extracted from the device.
As I already wrote, I think that the passphrase I mentioned above is more than enough if we take into account today's computers and the time it would take for someone to brute force such a password. Of course, the whole thing doesn't matter at all if someone who knows what he's doing doesn't get hold of our hardware wallet.
Speaking of how to take care of our hardware devices, I always remember an interesting film on that very topic - it's worth watching if you haven't seen it already.
https://www.youtube.com/watch?v=hf97ofTlZhk (Schloss Bitcoin (2020) - deutscher Kurzfilm - Crime Black Comedy Subtitles in English, French & more)