Bitcoin Forum
July 03, 2024, 12:04:56 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 ... 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 [138] 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 ... 334 »
2741  Bitcoin / Bitcoin Discussion / Re: A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 06:08:33 PM
yes there are many techniques that would be possible.  most important thing is have enough components to ensure high entropy.

Not only enough but not to use stupid things like *famous years* or *football teams that won a grand final*, etc.
2742  Bitcoin / Bitcoin Discussion / Re: A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 05:58:33 PM
Then finally add a smiley you are partial to:

buzfap01$02%014STK1456cAonImA;)

and perhaps a lucky number as well.

buzfap01$02%014STK1456cAonImA;)7

Even at this stage my guess is that we are at a level of pretty safe entropy (provided you have not followed my formula but instead created your own).

Such a passphrase is not so difficult to learn (but does take time). So I think that most people are capable of creating a brainwallet but I think it will take them some time to develop it (but if you really care about your investment you'll spend the time to protect it).
2743  Bitcoin / Bitcoin Discussion / Re: A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 05:56:47 PM
and after this lets add a swear word translated into a different language than our native one (mixing the case)

buzfap01$02%014STK1456cAonImA
2744  Bitcoin / Bitcoin Discussion / Re: A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 05:53:53 PM
You are right on to my wavelength here.

So let's see where we can go next with my simple experiment.

After our stock ticker addition lets add a number that we can come up with without anyone else easily knowing such as the number of lines of code we had committed to github in the year before we started creating this passphrase.

Now we are at say: buzfap01$02%014STK1456


2745  Bitcoin / Bitcoin Discussion / Re: A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 05:40:55 PM
Perhaps you have followed some stocks in the past and there is one that you don't tell anyone about because you didn't do very well with it (or perhaps the one you never invested in but wish you had).

Let's add its ticker (in upper case).

So now maybe we have: buzfap01$02%014STK
2746  Bitcoin / Bitcoin Discussion / Re: A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 05:38:18 PM
Once you have your nonsense word then maybe add a date (but format the date in an unusual manner such as dd$mm%yyy).

So now we have: buzfap01$02%014
2747  Bitcoin / Bitcoin Discussion / Re: A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 05:34:27 PM
My suggestion is to build up your secure pass phrase over time.

Start with something small (and don't ever use it publicly - perhaps use it for encrypting some private files locally or the like).

A nonsense word can be a good start if it is something that is only known to yourself and say a couple of friends (e.g. buzfap).
2748  Bitcoin / Bitcoin Discussion / Re: A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 05:30:12 PM
as long as we're challenging conventional wisdom,
I would also argue that humans are capable of creating
high entropy passphrases.

I agree - and would like this topic to perhaps focus on *how* this can be achieved (in a general enough manner not to give away my own passphrase of course). Smiley

Let's start with what you should *not do*.

1) Do not use a published phrase from literature or pop-culture (i.e. some lyrics of a hit song are never going to be a good idea).
2749  Bitcoin / Bitcoin Discussion / Re: A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 05:28:25 PM
Does anyone here mind telling me what a Brain wallet is please ? Basically you remember your Private key from your Wallet or how does it work exactly ? Shocked

Trying to memorise a private key would be even challenging to people with very good memories - so no - in general you'd memorise a long passphrase that gets hashed.
2750  Bitcoin / Bitcoin Discussion / Re: A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 05:24:32 PM
For sure I am not *recommending* them but just putting the case forward that they are actually feasible if you have the ability (this is in no way trying to encourage any noobs to use brainwallets).

As a counterpoint I was playing around with raw txs and stupidly re-used an address that had been published before (in an uncompressed version). My compressed version was relieved of its funds almost immediately after making the tx (luckily it was a trivial amount).
2751  Bitcoin / Development & Technical Discussion / Re: Bitcoin protocol standarization on: December 07, 2014, 05:13:07 PM
I think that separate library (or specialized libraries) is an very good idea. I don't understand why a VM could be required.   

I agree with this - Linux has had a long history of libs written in C that end up being available for other languages - why the need to go against that and create a Java thing (as I assume is being suggested)?
2752  Bitcoin / Bitcoin Discussion / A challenge to the idea that no-one can create a good brainwallet on: December 07, 2014, 04:38:51 PM
So here is a brainwallet address I created two years ago: https://blockchain.info/address/1Au4v6dZacFVsWXeKUMJd99AtyBZeqti2L

Originally I had stored 10 BTC there but after reading so many posts from people such as Gavin I decided to reduce the risk to 1 BTC but kept that just to see if my brainwallet would be discovered.

So after 2 years no-one has discovered it (and it is an address that was created via a passphrase that I have remembered successfully since then - I retested my memory of the passphrase just prior to making this post).

I don't dispute that creating brainwallets is not for everyone but I *do dispute* the idea that no-one is capable of creating a decent brainwallet.

So now that you know the address - let's see if anyone can work out my passphrase and steal the 1 BTC.

Smiley

Also I'd be interested to know from those who are keen on analysing the blockchain how much BTC they think I might have based upon this address.
2753  Bitcoin / Development & Technical Discussion / Re: Bitcoin protocol standarization on: December 06, 2014, 06:23:18 PM
The issue that @gmaxwell has mentioned is that any alternative implementation that fails to do something that the current implementation does (which may have never been even witnessed before) would result in a fork.

So the unfortunate situation is that Bitcoin is not a protocol like HTTP but instead is the behaviour of a specific C++ program (who's every currently unknown *quirk* would have to be replicated in any other implementation).

The only way you could create a Bitcoin equivalent in another language would be to have something that behaves identically at the binary level (and that would most likely only perform slower than Bitcoin does).
2754  Bitcoin / Project Development / Re: 20 BTC bounty for first AT *atomic cross-chain transfer* with Script clone on: December 06, 2014, 05:06:07 PM
I understand that the Qora AT implementation is now quite close to completion and Qora will be going open source in the next few days (AT will most likely not make the initial open source release but will be included in a follow up as some final tweaks and testing still needs to be performed).

There will be another non-Bitcoin clone that will be running live with AT very soon but we are still waiting to see if anyone is going to try and claim the 40 BTC possible before the end of the year for getting a Bitcoin clone to implement AT and do an atomic cross-chain transfer with Qora (or the other yet to be announced coin).
2755  Economy / Services / Re: Wallet Encryption Password Lost - 10 BTC! on: December 06, 2014, 03:56:40 PM
So in future maybe you shouldn't be so ignorant!

If I missed that you explained you were using Keepass then it seems so did a few others (although I notice something in the OP now which I don't recall seeing before).

Very strange that you would say you "forgot" your 30-40 character password anyway - if you were using a tool then you would never have "remembered" such a password in the first place. Smiley

There have been a few newbies before wanting to work out how to crack encrypted wallets that looked rather suspicious (hence my question).

In any case as has been pointed out 30-40 unknown characters is not going to be able to be cracked.
2756  Economy / Services / Re: Wallet Encryption Password Lost - 10 BTC! on: December 06, 2014, 03:47:47 PM
He could have generated a password in KeePass or similar, and then forget to save KeePass once he had the password generated, losing access to the wallet. I use KeePass and I know a couple of times I've almost shut off my machine without saving my new KeePass entries.

Indeed - now that you have given him an explanation I'm sure he'll use it (I was actually trying to see if he would come up with such an explanation himself).

Doh!

(maybe next time you might consider waiting before feeding people answers)
2757  Economy / Services / Re: Wallet Encryption Password Lost - 10 BTC! on: December 06, 2014, 03:41:05 PM
Well this seams like a dead loss.

Are you seriously saying you think that your wallet is encrypted with a 30-40 character password of which you can't remember any of it?

(because if that is what you are saying then I would be seriously doubting that it actually is your wallet at all)
2758  Other / Off-topic / Re: Secret Greetings in pgp on: December 06, 2014, 03:31:25 PM
So your first post on this forum is a scrambled piece of text which nobody can read but decode first?
/confused  Huh

He has posted a PGP/GPG public key - if you use PGP/GPG then you can import this public key then publish your own public key and an encrypted message that he can only read.

OP here is my public key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.9 (MingW32)

mQENBE9uqwgBCAC0w1vtDMi2Ry4eSk7tsgc8qhv9OF2qMIEYBuSFQpRS/GSvinxA
sJfxz/MEA3F8LEQKj/yd46RkKkTPypRyQRQ2XokafDrkmEyDyISzKvzCJC0nvPMo
sM5FSXA6QkgmMI/HBAhtMUtE1CaiipDehPbRAKMLVTkQ5Jt9fdrEztzS2RjBJ4t5
J4rbw1ALyQhKbSyJUQIATPKEOm3WxkuZwXFKdEziiIr9aFGlP7hUm2/sw16SEJYW
pf2jP1o8qMbwZUqXk9nKzP1cuQv0naMvP75AwXQw3TkWFKDBekwg6czPZOGpY/Er
sUqihyuUIuTRE8wN/wUocIVml2/9ChMxEpERABEBAAG0G0lhbiBLbm93bGVzIDxp
YW5AY2l5YW0uY29tPokBOQQTAQIAIwIbLwYLCQgHAwIEFQIIAwQWAgMBAh4BAheA
BQJPb/7HAhkBAAoJEFcEJ0zSVDDtYO4H/3uiGwejly9y6rxkO4819sxwmm0I/25e
5lWGqzrXft2HOm2FY5dnoT0Jc85XhTQ3fj0/r/K6NJqi4nyR1PJ6aANP3pP8x5j6
+XE+QUImjIoP4Nk8tRlBe05zKuQ4ZgHrLfbTsx0TwqaPTcUtlsKInDRdgOFER8HP
OQeAMSAc8UMOmxechujBIztiif+9wNiV3R8VjhYIT1PGNr4YOGphOhujBUFzu5Oq
DkKi538FsgVKtNrfnn5zf0PQEj60Z/HYAsisGLCxXfAZW+RFSvEQZmRcsGbGgYdS
Iz8w+yPDzpRbG9vwxg+6BCiA8kCeFD/m8MVyVA5zTGSGa9mlrxPY1Lg=
=RNh8
-----END PGP PUBLIC KEY BLOCK-----


and here is an encrypted message for you:

-----BEGIN PGP MESSAGE-----
Version: GnuPG v1.4.9 (MingW32)

hQIMA9o/ZPrSo/cJAQ//Q+/XWMXTLpxEKLdo7AI68ueDgrLE8eck2JXdTVg/B2fO
l1h2xHgnLU7SjsL+pz3NfqnJD5O86cvA+fJFRKeBEL33/3no0hvMEdy/tYt6xTDQ
dUBadEoJ+VDmfNc0vLTRinER82/hb8AXXVe27VpMdaqjGZRWB+VE2GGflbrsYPuW
lYS1NmhByJn92X5cC1d142/vd1iswYqUkgvS/VD4KKke2gd1dWMHCM0lP4ao8Nmt
fPNbaChi3biIs/SGnJBVtpwj1hEsZbYlGPuVIi8zf96QHbxvwtFzWwGOMJSpScnL
BMe0zZNu5P3yD7vzssD6Q7gryiCwGnAlyq9FcL5eiXkrAicPYVn1Q7xInw3O1T5J
+m5H43W4cY9h0hRtjpdcF5jFGic44roybIpJW/vEMssn2BRrd2ML2F2oyCAytN6d
hou5mINT/cdLRi0e/oJI/dcNycrRxCn0a5Q+gRnnbwePElCMHTb5msKEo/F6r/Se
6EH7cU/PO8Wqq+JUdAa5/MVJlkrKEJpXGvqQWKE0yNSaYKksL023qPTVvjgCDhmt
6eOf76SRPQEL0QJbeUnOfDzV9LWvnVLi8Nnve7IPesyYWMbgPO4H6Vh0nr5WNBsz
93EyRGmq/mjNM1Bl+5E/Hm1ko+5MndB7LuEIqUv///5R3om3GaApEML+yWGhZrLS
wLYBJ/FD/Jm8kh04YKIbccABO590FU8SbC+oPpXNNmXqmrUxiVoBquyvQ85mou0+
YcKsVueqqV472xWnbn+XA5wFJx8RDQSLXsmFbM6w32mzNVIpL/SHnnF/lYULhqiK
i/AyzgH3V1XpaznlKEWgBk1jpLjtvC9in2v9uFr4JVtjICR8QNSajZi1/X+qGBob
MmCwYxDE/gww6p4KZY+zV0Fd5k9C539nqxmNRkOAxohHwqvzoiqUxRgngkwRAx8t
y4NI1dNFsm9L9ZIK6bOMSBIs9Xgz0BsoUkVMipDI3YRvqUogcOUOxISNon5bKW5b
7Zc+ziw4dlS15+uPZbpgIVE4w1wm+byvF7zKr53f8f6F//fNQIxT8pNdhzoiIjUo
k26cYvpKeORe8bt9bZkgXwpldAnBTA0lpuGnArgFcS/2l0mllOa29qADncJGePSk
J1UP1iUlRJ3H8j6/IvFTQ5RW4kxmBu+U2XfJuzgu56trglNLQBSzdQ==
=mPMJ
-----END PGP MESSAGE-----
2759  Bitcoin / Development & Technical Discussion / Re: How Perfect Offline Wallets Can Still Leak Bitcoin Private Keys on: December 05, 2014, 06:19:28 PM
It seems to me that using multisig or Shamir's would be technically much simpler than trying to use complicated (and not very well battle tested) stuff like zero-knowledge proofs (admittedly those are beyond my current technical skills to really understand).

For any organisation that has a lot of offline BTC to protect I am pretty sure they'd always want to have those funds locked up by several offline devices rather than one anyway.

(so I am not really sure if the problem needs to be solved at all - i.e. why is this actually needed?)
2760  Bitcoin / Development & Technical Discussion / Re: How Perfect Offline Wallets Can Still Leak Bitcoin Private Keys on: December 05, 2014, 06:02:55 PM
Showing K doesn't seem prudent.  Better to just sign twice and compare the results: they should be identical.  If you really wanted to show K, better to show H(K).  Otherwise someone could just use the revealed K to immediately compromise the security if they could see the device's screen. Smiley

Indeed one does have to worry about nasties like cams taking shots of your offline computer's screen. Smiley
Pages: « 1 ... 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 [138] 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 ... 334 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!