Bitcoin Forum

Other => Beginners & Help => Topic started by: bnjmnkent on October 27, 2013, 02:18:13 PM



Title: Safety of Generated Bitcoinaddresses
Post by: bnjmnkent on October 27, 2013, 02:18:13 PM
Hello everybody,

given two private keys, both importable into bitcoind-wallet, but created by
an unknown tool.
Is there a possibility that one pair is easier to crack than the other?

The thought crossed my mind, when thinking about 3rd party generators like
bitaddress.org or vanitygen.



Title: Re: Safety of Generated Bitcoinaddresses
Post by: favdesu on October 27, 2013, 03:01:04 PM
they're as safe as any other key.

There are other potential safety issues, so I'd create them with vanity gen and offline.


Title: Re: Safety of Generated Bitcoinaddresses
Post by: SkillfulHacking on October 27, 2013, 03:29:29 PM
If the tool is unknown there is alot of room for concern, particularly when it comes to the implementation of brain wallets.  If the keys were generated with a weak passphrase it is trivial to steal your coins.  Read through this thread https://bitcointalk.org/index.php?topic=251037.0 and see just how quickly your coins will get be taken if you try to store them in an address protected by a weak passphrase. 


Title: Re: Safety of Generated Bitcoinaddresses
Post by: bnjmnkent on October 27, 2013, 06:33:38 PM
Thank you for your contribution. Yes, a weak password on a brainwallet is a severe mistake/attack vector.


Title: Re: Safety of Generated Bitcoinaddresses
Post by: bnjmnkent on October 27, 2013, 06:40:38 PM
they're as safe as any other key.

There are other potential safety issues, so I'd create them with vanity gen and offline.
Thank you for your reply!


Title: Re: Safety of Generated Bitcoinaddresses
Post by: brand_new on October 27, 2013, 09:03:46 PM
Thanks for making this thread. I was wondering the same thing. This thought crossed my mind  a few weeks ago but I had totally forgotten about it.


Title: Re: Safety of Generated Bitcoinaddresses
Post by: schwillyshill on October 27, 2013, 10:14:09 PM
they're as safe as any other key.

There are other potential safety issues, so I'd create them with vanity gen and offline.
Thank you for your reply!

As mentioned above, they may not be safe at all. Hard to know since they were created by an unknown tool. But yes many users have been robbed of many bitcoins because they used tools that use low entropy or other implementation errors. Especially do NOTdo things that increase the danger with such keys like re-using the addresses, accepting several payments to the same address. If you're concerned about these keys, and since you don't know how they were generated I think you have good reason to be, just sweep the funds and be done with them.