[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-talk] Facebook brute forcing hidden services




This is scaring. Can someone calculate how much computer power they used to generate the 11 chars?

----- Message from Sam Pizzey <sam@xxxxxxxxx> ---------
    Date: Fri, 31 Oct 2014 12:47:32 +0000
    From: Sam Pizzey <sam@xxxxxxxxx>
Reply-To: tor-talk@xxxxxxxxxxxxxxxxxxxx
 Subject: Re: [tor-talk] Facebook brute forcing hidden services
      To: tor-talk@xxxxxxxxxxxxxxxxxxxx


So called 'vanity' addresses are essentially a brute force - generating
tons of keys until you get one that starts with the prefix you want. The
difference is that 'bob1d8rhdu2h.onion' is a lot less specific than
facebookwwwi.onion - if Facebook can brute force arbitrary strings like
that, they can instead brute force, say, <address of silk road>, or
<address of David's hidden service> and then impersonate it.
--
tor-talk mailing list - tor-talk@xxxxxxxxxxxxxxxxxxxx
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk


----- End message from Sam Pizzey <sam@xxxxxxxxx> -----



--
tor-talk mailing list - tor-talk@xxxxxxxxxxxxxxxxxxxx
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk