Bitcoin Forum
September 23, 2024, 02:59:22 AM *
News: Latest Bitcoin Core release: 27.1 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Bitcoin / Development & Technical Discussion / Re: [BRAINWALLETS] NoBrainr - a secure cold wallet generator in 1024 bytes on: November 05, 2013, 03:14:20 PM
That's why I'm surprised you are so confident about it. Most people have dreaded the brainwallet, so to see someone champion it with only seven plain English words is bewildering.

The problem isn't the brainwallet concept in and of itself, but people's poor choices when picking up a passphrase. NoBrainr takes care of that.

I was going to invent my own language, I thought that would be more than sufficient for me. But these initial worries from detractors had me stopped in my tracks...
2  Bitcoin / Development & Technical Discussion / Re: [BRAINWALLETS] NoBrainr - a secure cold wallet generator in 1024 bytes on: November 05, 2013, 02:59:29 PM
At the risk of sounding like a complete dumbass: couldn't a hacker create a rainbow database with all of these brainwallet combinations, and see which ones are filled with dough?

Is it inconceivable that the hacker will be successful in finding BTC in some of his computer generated brainwallet phrases?

Hi, I'm responding from my phone, so sorry for the short answer, but basically the passphrases produced by NoBrainr are each guaranteed to be above 90-bit strong, which makes any brute-force attack (including rainbow tables) prohibitively expensive - think billions of dollars and centuries to crack one passphrase, even for massively distributed supercomputers or botnets.

In my view, higher bit strength in this case is overkill, but the paranoid can further increase the bit strength by changing one line in the code, or even use physical entropy as input (more on that soon!)

Thanks for the speedy reply, appreciate it. I have been getting hammered for favoring brainwallets lately. I have proposed inventing my own language and coming up with a passphrase that way, which has been deemed as a terrible idea.

So please forgive me for displaying shock at your seven plain-English word phrases. The general feedback I seem to get from the naysayers is that it is folly to have the computer generate a passphrase for you, and use that generated passphrase for a brainwallet.

The only appropriate solution that has been offered is to play with some dice, and only to generate the the private keys at that. If your brainwallets are indeed actually safe, I would rather go with brainwallets than roll dice for just private keys each time.

If most NoBrainr passphrases look so deceptively simple to you, it means we are achieving our objective, which is to provide brainwallets and paper wallets that are both easy to remember, and highly resistant to any type of automated guessing/cracking.

It is scary to see how misunderstood the concept of passphrase entropy is, even within the otherwise tech-savvy bitcoin community.

We do recommend users to proceed with caution when using brainwallets. In other words, you really need to know what you are doing. However, one thing that you will NOT see happen is a cold NoBrainr generated brainwallet being snatched by a random hacker.

We will even consider putting up a bounty to anyone who can show a real-life example of a vulnerability in NoBrainr leading to theft of BTC.

That's why I'm surprised you are so confident about it. Most people have dreaded the brainwallet, so to see someone champion it with only seven plain English words is bewildering.

People are losing their money over horrible brainwallets, yet all they needed were seven easy to remember English words, and they are totally unhackable. Unbelievable...
3  Bitcoin / Development & Technical Discussion / Re: [BRAINWALLETS] NoBrainr - a secure cold wallet generator in 1024 bytes on: November 05, 2013, 07:41:41 AM
At the risk of sounding like a complete dumbass: couldn't a hacker create a rainbow database with all of these brainwallet combinations, and see which ones are filled with dough?

Is it inconceivable that the hacker will be successful in finding BTC in some of his computer generated brainwallet phrases?

Hi, I'm responding from my phone, so sorry for the short answer, but basically the passphrases produced by NoBrainr are each guaranteed to be above 90-bit strong, which makes any brute-force attack (including rainbow tables) prohibitively expensive - think billions of dollars and centuries to crack one passphrase, even for massively distributed supercomputers or botnets.

In my view, higher bit strength in this case is overkill, but the paranoid can further increase the bit strength by changing one line in the code, or even use physical entropy as input (more on that soon!)

Thanks for the speedy reply, appreciate it. I have been getting hammered for favoring brainwallets lately. I have proposed inventing my own language and coming up with a passphrase that way, which has been deemed as a terrible idea.

So please forgive me for displaying shock at your seven plain-English word phrases. The general feedback I seem to get from the naysayers is that it is folly to have the computer generate a passphrase for you, and use that generated passphrase for a brainwallet.

The only appropriate solution that has been offered is to play with some dice, and only to generate the the private keys at that. If your brainwallets are indeed actually safe, I would rather go with brainwallets than roll dice for just private keys each time.
4  Bitcoin / Development & Technical Discussion / Re: [BRAINWALLETS] NoBrainr - a secure cold wallet generator in 1024 bytes on: November 05, 2013, 06:47:42 AM
At the risk of sounding like a complete dumbass: couldn't a hacker create a rainbow database with all of these brainwallet combinations, and see which ones are filled with dough?

Is it inconceivable that the hacker will be successful in finding BTC in some of his computer generated brainwallet phrases?
5  Economy / Service Discussion / Re: Paper/Brain Wallet Suggestion (please share your thoughts) on: November 04, 2013, 09:20:33 PM
What if you invented your own language, and used that for the passphrase?

What really bugs me with a brainwallet is if you ever send bitcoins out of there, you wasted your entire time memorizing it.

I would like to remember the phrase for life, and not worry about having to remember another friggin' brainwallet passphrase.

Another thing that should be discussed is how can we mitigate the risks of a brainwallet without compromising the reason why we chose to use a brainwallet?


Such as if you get injured or die, no one will ever know. So, does that mean you have to have copies laying around for your family? Doesn't that kind of defeat the original purpose of the brainwallet?
6  Other / Beginners & Help / Re: What's the safest way to use an awesome brainwallet? on: November 04, 2013, 09:06:33 PM
I've made my points.

You are welcome to do whatever you like.

It's your money.

Your OP asked some specific questions.  Those questions have been answered.  You don't like the answers, that's not my problem.

Good luck.

Sorry, didn't mean to get you flustered or upset. Your responses generally had a snarky tone, so I just went with the flow.

Thanks for all your help though, your answers were very helpful.
7  Other / Beginners & Help / Re: What's the safest way to use an awesome brainwallet? on: November 04, 2013, 08:45:00 PM
Funny how you skirted my comment about the artificial language trick, guess that was too unconventional for you?

12 random English words is still 12 English words. I don't trust it, but it seems like you are okay with it. So what's the big deal if I invented my own language and came up with 12 words?  Huh

And using the internet and bitcoins are apples and oranges. You don't have to know how flying works with the internet, you just have to learn how to fly.

With bitcoins, you have to learn how flying works to understand how to be as secure as you can be.

And no, people don't know much about technology, and look at the consequences: stolen passwords, phished passwords, cracked accounts, etc.

Bitcoin just seems another continuation of that, but with the opportunity to lose a lot more.
8  Other / Beginners & Help / Re: What's the safest way to use an awesome brainwallet? on: November 04, 2013, 08:09:16 PM
Am I being overly paranoid?
My advice. Use an officially supported wallet. Choose a good passphrase, write it down and lock it away in a safe or perhaps give it to your lawyers for safekeeping (being sure to advise them not to copy or expose it). Backup your wallet and keep copies in several safe places. Your biggest risk is relying on your memory alone.

Aren't you also relying on memory for the passphrase to your wallet?

I don't have any lawyers, so I don't have that option for now.
9  Other / Beginners & Help / Re: What's the safest way to use an awesome brainwallet? on: November 04, 2013, 07:54:21 PM
it sounds like you can share your public address, and there will be no security breach if you keep the private key to yourself.

That is correct.

Now I'm lost, I thought exposing your public key weakens the integrity of the security mechanism, allowing for the eventual cracking of your private key.

There is no guarantee that ECDSA will ever be "breached", but there is no guarantee that it won't either.  That is the nature of cryptography.  A cryptographic function is secure until someone finds a way to make it insecure, then people move to a newer secure function.  Fortuntately, as long as it is used properly, bitcoin layers 3 different cryptographic functions between your private key and your public address. It is extremely unlikely that a weakness will be found in all three functions simultaneously.  This means there is time to replace a function in the protocol while bitcoins are still protected by the other two functions.  Bitcoin can there fore grow and change to adapt to new cryptographic discoveries.

If you say so, I don't know how people expect Bitcoin to thrive when somebody like me is being admonished for learning how to take the proper steps to utilize the full potential of its encryption methods. Most of this stuff would sound like nonsense to a mainstream crowd, let alone having to worry about changing encryption methods down the line when they've invested some of their time to learning how it actually works, if they even learned it at all. Hmmm, no wonder there are banks to take care of all of this for the commoners.


Describe these "offline transactions"?  Explain exactly how ownership of the bitcoins (which reside as an output on the blockchain) will be transfered to another individual using your "offline wallet and something like Armory" without the public key being exposed?

Yeah, I really don't get it myself. The idea I think is so you don't have to use your private key on the hot PC?

Another idea: couldn't I just open up a separate offline wallet on my offline PC to send small funds to so that those bitcoins can be used freely?

Send small funds from where?

I was thinking I send a small amount to another Bitcoin wallet, and use that to spend monies. But then I realized after your response that all transactions have to be recorded online.

This also preserves the secure state of my offline savings wallet, correct?

That depends.  Will you be spending/sending any of the bitcoins that are received at that offline savings wallet? Or will it be exclusively receiving bitcoins.  As soon as you try to get any bitcoins out of that offline savings, you are back where we started.

I see what you mean. Which means I'll have to come up with multiple brain wallets to maintain a true offline account. Hopefully, I wouldn't have to do that so many times.


Which has worked very well for many, many years. What is it about paper money that you don't like?

A paper wallet is basically a bundle of cash, correct? So I would basically be keeping a bundle of cash in my domicile or another residence. Yeah, it's a lot smaller and easier to maintain, but you're still keeping a ton of money in your home. Does anyone do this with conventional money except for drug dealers?

So, you'd rather that the hoodlums attack you directly to get at your bitcoins than to attack a safe?  You prefer to be beaten to a bloody pulp and tortured beyond belief for the sake of some money?  Personally, I'd rather they just took my money and moved on.  My life, and health are far more valuable to me than any amount of money could ever be.

Well, I would give it up if I had to, that example was under the idea that the safe would be targeted without my presence.

or keeping it at a bank deposit, which I thought was the direction we were trying to steer away from with this new paradigm shift.

A paper wallet is absolutely nothing like that.  Where did you get that idea?

I have seen people recommend saving paper wallets in bank vaults.

Or it could just get lost or destroyed by fire.

And your memory can't get lost or destroyed by fire? or illness? or fall or other injury?  Just store two copies in two separate secure locations.

I could always encrypt my brainwallet with an audio message if worst came to worst. Of course, better methodologies can be thought up of compared to coming up with one on the spot in a forum post.

As I'll explain later, I think my brainwallet passphrase is going to be amazing,

And I disagree.

People have advocated software seeds that contain 12 English words as being highly secure. C'mon, I can do better than that, is it that hard to believe?

And you can be 100% that none of them will go against your wishes behind your back and write it down so they don't forget it?

Not if it's easy for them to remember, yet nonsensical for others. Just so I don't give everything away, we would all speak some break-off dialect of some artificial language that only we know. But yes, I see what you're saying. I guess I'll have to come up with something clever in the meantime.

You're just not like "other people", right?

See above.

What I meant originally was that if my passphrase does get hacked, no one will ever be able to support a brainwallet ever again once I've shared my compromised passphrase on the internets.

I suspect you are wrong about that, but I've already indicated that I'm already generally against the idea of a brain wallet in most cases anyhow.

See above.

As mentioned earlier, I could use offline transactions, or set up another wallet as a middle man.

Which most likely demonstrates that you have no idea what you are talking about and are just making stuff up in hopes that you can do what you want without someone telling you that it is a bad idea.

Yes, I concede that. But now I have learned a bit more, and can understand where my original plan fails, which is what I wanted to accomplish with this thread. This has all been a great thought experiment so that I can come up with a better plan centered around a brainwallet and/or other methods.

One technique I've seen is someone type a bunch of BS letters over 1000 characters long into a brainwallet to generate keys. That seems pretty secure.

No.  It really doesn't.  That is a bad idea.  You want a good idea?  Grab a handful of very well balanced dice (perhaps from your local casino?).  Roll the dice a bunch of times (until you've rolled at least 62 dice) and then convert from base 6 to get a private key.

How is that a bad idea? Yeah, the dice sounds good, but typing something like this into a brain wallet is bad? :

onthunsoeahtueroah.crhu903409hu0244903gp02g2[93g[hu9[h239g23[9g29j0ud203gf2309g[192[3d0239[23.0,u02u3 (and so on, for as long as you want)


So you've learned nothing then?  You still haven't even bothered to learn the difference between an address and a public key?  Why do I even bother if you aren't going to make an effort?

I meant to say public key instead of public address. But yes, I am having a hard time grasping the difference between public key and an address. I'll make sure to study that thoroughly from here on out.

But if you think the mainstream public could understand all the caveats and nuances of Bitcoin's cryptograhy, then you got another thing coming.

I guess my only other question is: should I just memorize the friggin' private key?

Sure, you could do that if you like.  How will you generate the private key? And will you memorize a new private key every time you spend funds?

It would be a pain to memorize the private key, but it seems like the easiest way without interfacing with layers of garbage each time.

My only question is, if I have the public key: then it's just like entering a password, right? If I get it wrong, no harm, no foul? I could keep going on until I get it.

My worry was entering in an incorrect key and having something horrible happen. If not, then I don't mind memorizing a new key, but I can see how it can get confusing.
10  Other / Beginners & Help / Re: What's the safest way to use an awesome brainwallet? on: November 04, 2013, 05:30:53 AM
When you use something like Electrum to generate a brain wallet, the passphrase is the seed. From this seed, the app generates an unlimited number of addresses, public keys, and private keys that can be deterministically re-generated, given the passphrase. So in this case, you can have one "brain wallet" (the passphrase) but an unlimited number of public keys generated from that seed; and revealing any of these public keys should be perfectly safe. Right?


Could I choose my own passphrase to do that? I don't trust those randomly generated passphrases.

But I want to be able to use a passphrase to pull up my private key without using software that could become deprecated or non-standard overtime. I would like to be able to recall my passphrase 40 years from now, and the standard generator will pull up my offline savings account without worry.
just use brainwallet.org and save a copy of the site, should it go down.

Ugh, but then what if the physical medium in which you are saving the website breaks down all at once? Maybe better to just memorize the private key.

Am I being overly paranoid?
11  Other / Beginners & Help / Re: What's the safest way to use an awesome brainwallet? on: November 04, 2013, 05:10:16 AM
When you use something like Electrum to generate a brain wallet, the passphrase is the seed. From this seed, the app generates an unlimited number of addresses, public keys, and private keys that can be deterministically re-generated, given the passphrase. So in this case, you can have one "brain wallet" (the passphrase) but an unlimited number of public keys generated from that seed; and revealing any of these public keys should be perfectly safe. Right?


Could I choose my own passphrase to do that? I don't trust those randomly generated passphrases.

But I want to be able to use a passphrase to pull up my private key without using software that could become deprecated or non-standard overtime. I would like to be able to recall my passphrase 40 years from now, and the standard generator will pull up my offline savings account without worry.
12  Other / Beginners & Help / Re: What's the safest way to use an awesome brainwallet? on: November 04, 2013, 04:57:27 AM

A public "bitcoin address" and a "public key" are not the same thing.  When you receive bitcoins at an address for the first time, that address is protected by ECDSA, SHA-256, and RIPEMD-160.  The address is public, but the public key is not yet public at that time.  If, in the future, a weakness is discovered any one or two of those cryptographic algorithms, your balance will still be protected by the remaining algorithm giving you time to move to a new algorithm before anyone can take your bitcoins.

The first time you send any bitcoins that have been received at that address, you broadcast the public key.  At that point, the private key is no longer protected by SHA-256 or RIPEMD-160.  It is ONLY protected by ECDSA. Right now ECDSA is secure enough in most cases, so this isn't a concern, but for long term storage you'll want to consider the possibility that a weakness is discovered in ECDSA and you don't hear about it before an attacker does.  If you've never sent any bitcoins that were received at the address it won't matter, since you are still protected by SHA-256 and RIPEMD-160.  If you have sent those bitcoins and continued to re-use the address, then you've lost that additional protection.

If this doesn't concern or worry you, then you can go ahead and re-use your brain wallets. I just assumed that you were very concerned about security.

Okay, I had no idea that the public key served as a protection mechanism. The way its presented to the laymen, it sounds like you can share your public address, and there will be no security breach if you keep the private key to yourself. Thank you for this bit of knowledge, but I doubt the majority of bitcoin users know about this nuance. Frankly speaking, how are they intending to build a secure digital network currency if the encryption method is due for a breach within its lifetime?

So my question then is, couldn't you use an offline wallet and use something like Armory to conduct offline transactions using proprietary keys? Wouldn't this prevent both your public and private keys of your offline saving wallets from ever being exposed?

Another idea: couldn't I just open up a separate offline wallet on my offline PC to send small funds to so that those bitcoins can be used freely? This also preserves the secure state of my offline savings wallet, correct?

I suspect that paper will out-live you and your memory.  Brain-wallets are typically one of the weaker traits of bitcoin.  Most people don't chose a passphrase with enough entropy, and human beings are VERY bad at doing anything in a random way.  We just aren't designed that way.

I am not a big fan of paper, they are basically like paper money to me. In my eyes, it's tantamount to keeping cash in my mattress, or a safe which will targeted by hoodlums, or keeping it at a bank deposit, which I thought was the direction we were trying to steer away from with this new paradigm shift. Or it could just get lost or destroyed by fire.

I am a big fan of memory, that is the securest method in my opinion. As I'll explain later, I think my brainwallet passphrase is going to be amazing, so I can easily memorize it, while it would be nonsense to others. From there, I can share the brainwallet with my trusted family members in case anything happens to me.

I'm not sure what that means, but the brainwallet concept is a rather weak concept for the vast maority of users.

I agree, vast majority, but my circumstances put me in the category of those who will benefit most from a brainwallet, while significantly mitigating its risks. What I meant originally was that if my passphrase does get hacked, no one will ever be able to support a brainwallet ever again once I've shared my compromised passphrase on the internets.

The public address is fine.  It's when you send a transaction and broadcast the public key that you've made the address weaker.

As mentioned earlier, I could use offline transactions, or set up another wallet as a middle man.

The bitcoin address?  Yes.

The public key?  Only when you send a transaction, and after that it's best not to re-use the address if you are concerned about security.

Duly noted, I'll make sure to let other people know about this.

Yes, as recomended by Satoshi and other knowledgeable people.  Always use a private key that is generated from a cryptographically strong source of randomness, and never re-use a receiving address.

I've heard bad things about random generators. One technique I've seen is someone type a bunch of BS letters over 1000 characters long into a brainwallet to generate keys. That seems pretty secure.

Since I don't know which "cumbersome and user-unfriendly tutorials" you are talking about, I am unable to answer this question reliably.

http://georgeoughttohelp.tumblr.com/post/46937654072/transferring-bitcoins-to-a-secure-offline-wallet-using




So I learned after all of this, is to never let my offline savings wallet's public address ever hit the network. A pain in the ass, but good to know.


I guess my only other question is: should I just memorize the friggin' private key?
13  Other / Beginners & Help / Re: What's the safest way to use an awesome brainwallet? on: November 03, 2013, 09:22:58 PM
I actually wanted to create just a hardware brainwallet that never connects. Maybe an old smartphone that never connects would do. But you can't beat a dedicated offline device.
14  Other / Beginners & Help / Re: What's the safest way to use an awesome brainwallet? on: November 03, 2013, 09:08:36 PM
Hey, thanks for your responses.

I'm not really concerned about anonymity, just security breaches.

I thought that public addresses were meant to be exposed to the wild, so what harm is there in using the public key of your offline savings wallet?

I am mostly going through all of this to protect my offline savings wallet. Therefore, it's imperative that it be immortal, so things like corruptible files, shaky hardware, and physical copies like paper wallets won't do it for me. I only trust myself and I am very happy to know that all of my savings can be backed up in my head. This is the single greatest trait I see in Bitcoin, in my humble opinion.

I only considered Brainwallets because I can create a passphrase that can ultimately bankrupt the Brainwallet concept if it is ever compromised, and because it's easier for me to remember. But I am willing to memorize the private key if that is the safest and most secure method to retaining my savings in my head.

I just don't understand why using the public address of my offline savings wallet is such a problem in terms of security. I thought that was the part that was designed to be shared, and only the private key must never see anyone's eyes.

And if that is such a problem, aren't there ways around it? I have seen some very cumbersome and user-unfriendly tutorials on using proprietary software and transaction keys so that offline wallet keys never see the light of day. Is this the best security solution in tandem with memorizing one's private key??
15  Other / Beginners & Help / What's the safest way to use an awesome brainwallet? on: November 03, 2013, 09:46:33 AM
Just to be sure, I'm not asking how to create an awesome Brainwallet, but how to use one that is already awesome in the safest manner.

I like the allure of a Brainwallet: I can memorize something that is easier FOR ME to remember when compared with the private key.

Having said all that, what good is an amazing Brainwallet if you can't use it at will.

Would it be a good idea to recall that Brainwallet on a hot PC? Part of the beauty of a brainwallet is being able to recall it from memory in any place. I think most people will say no due to hot PCs possibly having keyloggers or other malware.

So, would it be okay to use on a cold PC, if that PC is never connected to the network? This would be a pain in the ass because then I would need to get another PC, and I'm currently broke.

And then, if the brainwallet is amazing and the PC being used to recall the keys is disconnected, then would I be safe?

Could I use that same brainwallet to receive bitcoins?

Could I safely withdraw funds from that brainwallet without compromising the original brainwallet?


I ask that last question because I've seen so many tutorials where people go through such an elaborate process with Armory, Electrum, saved Javascript websites, etc. on a cold PC that never connects, and as soon as they use that highly safe private key on a connected PC to do some business, that private key is immediately invalidated as having been compromised or exposed to the wild.

If I have to do that each time, what good is a brainwallet at all? What good is memorizing the private keys even? Is there a way to withdraw funds from a private key without exposing it to the wild??
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!