Bitcoin Forum
May 09, 2024, 02:14:14 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: How easy is it to brute force an electrum wallet password?  (Read 1439 times)
mcplums (OP)
Full Member
***
Offline Offline

Activity: 146
Merit: 100


View Profile
July 09, 2015, 09:40:30 PM
 #1

Hello hello,

I'm just wondering how strong, or how many 'bits of entropy' as you chaps like to say, my electrum wallet password should be.

If my password was just a dictionary word, would that make it trivial, or is it still a major undertaking to crunch all dictionary words?

Thanks chaps!
1715264054
Hero Member
*
Offline Offline

Posts: 1715264054

View Profile Personal Message (Offline)

Ignore
1715264054
Reply with quote  #2

1715264054
Report to moderator
1715264054
Hero Member
*
Offline Offline

Posts: 1715264054

View Profile Personal Message (Offline)

Ignore
1715264054
Reply with quote  #2

1715264054
Report to moderator
Be very wary of relying on JavaScript for security on crypto sites. The site can change the JavaScript at any time unless you take unusual precautions, and browsers are not generally known for their airtight security.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715264054
Hero Member
*
Offline Offline

Posts: 1715264054

View Profile Personal Message (Offline)

Ignore
1715264054
Reply with quote  #2

1715264054
Report to moderator
Mikestang
Legendary
*
Offline Offline

Activity: 1274
Merit: 1000



View Profile
July 09, 2015, 10:28:04 PM
 #2

Electrum wallet or email account, it doesn't matter, a password is a password is a password.  Check out https://www.grc.com/haystack.htm, might help you out.

Real words are about the easiest passwords to break, but ultimately is has to do with the characters that make up the password.

As ever, google has all the aswers: https://www.google.com/search?q=brute+force+password+time
CryptKeeper
Legendary
*
Offline Offline

Activity: 2044
Merit: 1055



View Profile
July 10, 2015, 08:39:15 AM
 #3

Hello hello,

I'm just wondering how strong, or how many 'bits of entropy' as you chaps like to say, my electrum wallet password should be.

If my password was just a dictionary word, would that make it trivial, or is it still a major undertaking to crunch all dictionary words?

Thanks chaps!

Extracted from their wiki at http://electrum.orain.org/wiki/Frequently_Asked_Questions#How_secure_is_the_seed.3F

Quote
How secure is the seed?
The seed created by Electrum has 128 bits of entropy. This means that it provides the same level of security as a Bitcoin private key (of length 256 bits). Indeed, an elliptic curve key of length n provides n/2 bits of security.

Follow me on twitter! I'm a private Bitcoin and altcoin hodler. Giving away crypto for free on my Twitter feed!
mcplums (OP)
Full Member
***
Offline Offline

Activity: 146
Merit: 100


View Profile
July 11, 2015, 09:29:12 AM
 #4

Hello hello,

I'm just wondering how strong, or how many 'bits of entropy' as you chaps like to say, my electrum wallet password should be.

If my password was just a dictionary word, would that make it trivial, or is it still a major undertaking to crunch all dictionary words?

Thanks chaps!

Extracted from their wiki at http://electrum.orain.org/wiki/Frequently_Asked_Questions#How_secure_is_the_seed.3F

Quote
How secure is the seed?
The seed created by Electrum has 128 bits of entropy. This means that it provides the same level of security as a Bitcoin private key (of length 256 bits). Indeed, an elliptic curve key of length n provides n/2 bits of security.

I don't think the seed has anything to do with this? I'm talking specifically about my electrum wallet password- NOT my seed.

My question is, if someone gets a hold of my wallet for whatever reason, how easy is it for them to brute force it?

Re the first response, you are surely incorrect- brute forcing takes a different amount of time depending on what you want to brute force? I suppose the specific question I am asking is: on a reasonably powerful computer, how many microseconds does it take to test one password? If a billion can be tested per second that's a problem- but if ten can be, that's not.
Abdussamad
Legendary
*
Offline Offline

Activity: 3612
Merit: 1564



View Profile
July 11, 2015, 11:37:12 PM
 #5

Quote
My question is, if someone gets a hold of my wallet for whatever reason, how easy is it for them to brute force it?

I believe it's not really designed to withstand brute forcing from an attacker. Just a single pass of AES 256. Bitcoin core, for example, does a variable number of passes depending on how much CPU power you have.



Bitdonator
Legendary
*
Offline Offline

Activity: 1223
Merit: 1002


View Profile
July 12, 2015, 09:27:45 AM
 #6

It depends on what kind of variation of characters your password is.

And on what kind of pc/computer (quick/slow) the atatcker has.
criptix
Legendary
*
Offline Offline

Activity: 2464
Merit: 1145


View Profile
July 12, 2015, 01:17:40 PM
 #7

Hello hello,

I'm just wondering how strong, or how many 'bits of entropy' as you chaps like to say, my electrum wallet password should be.

If my password was just a dictionary word, would that make it trivial, or is it still a major undertaking to crunch all dictionary words?

Thanks chaps!

Extracted from their wiki at http://electrum.orain.org/wiki/Frequently_Asked_Questions#How_secure_is_the_seed.3F

Quote
How secure is the seed?
The seed created by Electrum has 128 bits of entropy. This means that it provides the same level of security as a Bitcoin private key (of length 256 bits). Indeed, an elliptic curve key of length n provides n/2 bits of security.

I don't think the seed has anything to do with this? I'm talking specifically about my electrum wallet password- NOT my seed.

My question is, if someone gets a hold of my wallet for whatever reason, how easy is it for them to brute force it?

Re the first response, you are surely incorrect- brute forcing takes a different amount of time depending on what you want to brute force? I suppose the specific question I am asking is: on a reasonably powerful computer, how many microseconds does it take to test one password? If a billion can be tested per second that's a problem- but if ten can be, that's not.

We are talking about billions of pw per second depending on the hardware.

The average time depends on characters used, lenght of password, repititions etc

                     █████
                    ██████
                   ██████
                  ██████
                 ██████
                ██████
               ██████
              ██████
             ██████
            ██████
           ██████
          ██████
         ██████
        ██████    ██████████████████▄
       ██████     ███████████████████
      ██████                   █████
     ██████                   █████
    ██████                   █████
   ██████                   █████
  ██████
 ███████████████████████████████████
██████████████████████████████████████
 ████████████████████████████████████

                      █████
                     ██████
                    ██████
                   ██████
                  ██████
                 ████████████████████
                 ▀██████████████████▀
.LATTICE - A New Paradigm of Decentralized Finance.

 

                   ▄▄████
              ▄▄████████▌
         ▄▄█████████▀███
    ▄▄██████████▀▀ ▄███▌
▄████████████▀▀  ▄█████
▀▀▀███████▀   ▄███████▌
      ██    ▄█████████
       █  ▄██████████▌
       █  ███████████
       █ ██▀ ▀██████▌
       ██▀     ▀████
                 ▀█▌
 

             ▄████▄▄   ▄
█▄          ██████████▀▄
███        ███████████▀
▐████▄     ██████████▌
▄▄██████▄▄▄▄█████████▌
▀████████████████████
  ▀█████████████████
  ▄▄███████████████
   ▀█████████████▀
    ▄▄█████████▀
▀▀██████████▀
    ▀▀▀▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!