Bitcoin Forum
May 05, 2024, 07:36:50 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Non-random words patterns more vulnerable for attacks?  (Read 407 times)
Tungsten (OP)
Member
**
Offline Offline

Activity: 73
Merit: 10



View Profile WWW
January 11, 2016, 07:29:49 PM
 #1

With Electrum 2.5.4 I noticed that generated words following certain pattern where order of words matters.

For example " ... word1 word2 word3" pattern is valid, but " ... word1 word3 word2" pattern is not considered as valid - Electrum won't allow to restore wallet like this.

I want to understand why is this so - because if words are sequenced according to certain predefined algorithm - than it is possible for attacker to scan web/computer for "valid" sequences of 12-13 words that might belong to Electrum wallets.

Ideally I want Electrum to allow any order of words to prevent such guessing.

• 188888888qZ5Mv4u5C2Bve6eyVJBFR5EEj • Get personalized bitcoin address like that at http://vanitycoin.com/
1714894610
Hero Member
*
Offline Offline

Posts: 1714894610

View Profile Personal Message (Offline)

Ignore
1714894610
Reply with quote  #2

1714894610
Report to moderator
1714894610
Hero Member
*
Offline Offline

Posts: 1714894610

View Profile Personal Message (Offline)

Ignore
1714894610
Reply with quote  #2

1714894610
Report to moderator
1714894610
Hero Member
*
Offline Offline

Posts: 1714894610

View Profile Personal Message (Offline)

Ignore
1714894610
Reply with quote  #2

1714894610
Report to moderator
"There should not be any signed int. If you've found a signed int somewhere, please tell me (within the next 25 years please) and I'll change it to unsigned int." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
BARR_Official
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500



View Profile WWW
January 11, 2016, 07:48:00 PM
 #2

Maybe the phrase has to hash to a key in wallet import format that validates in Base58, so certain phrases don't work?

Buying At Retail and Restaurants - BarrCryptocurrency.com
xhomerx10
Legendary
*
Offline Offline

Activity: 3836
Merit: 7993



View Profile
January 11, 2016, 08:03:15 PM
 #3

A password could be grapes, apples, oranges and pineapples.  A fruit salad is any combination of grapes, apples, oranges and pineapples.  You don't care what order it's in, because it's just a fruit salad!  Now, should everyone's fruit salad be able to open your wallet?  That would be cause for concern.  Order matters.

Tungsten (OP)
Member
**
Offline Offline

Activity: 73
Merit: 10



View Profile WWW
January 11, 2016, 08:08:06 PM
 #4

A password could be grapes, apples, oranges and pineapples.  A fruit salad is any combination of grapes, apples, oranges and pineapples.  You don't care what order it's in, because it's just a fruit salad!  Now, should everyone's fruit salad be able to open your wallet?  That would be cause for concern.  Order matters.

If any combination of words can be valid - then it makes it harder for brute force your wallet by scanning text files in your hard drive.

• 188888888qZ5Mv4u5C2Bve6eyVJBFR5EEj • Get personalized bitcoin address like that at http://vanitycoin.com/
xhomerx10
Legendary
*
Offline Offline

Activity: 3836
Merit: 7993



View Profile
January 12, 2016, 04:26:31 AM
 #5

A password could be grapes, apples, oranges and pineapples.  A fruit salad is any combination of grapes, apples, oranges and pineapples.  You don't care what order it's in, because it's just a fruit salad!  Now, should everyone's fruit salad be able to open your wallet?  That would be cause for concern.  Order matters.

If any combination of words can be valid - then it makes it harder for brute force your wallet by scanning text files in your hard drive.


 Then perhaps I fail to understand your concern properly.
If you remove the order,  you reduce the complexity and it becomes easier to cracker your passphrase.


   
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!