Bitcoin Forum
May 13, 2024, 04:25:11 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 [8]  All
  Print  
Author Topic: If you used Brainwallet.org - MUST READ! - Security Breach!  (Read 52764 times)
Anon136
Legendary
*
Offline Offline

Activity: 1722
Merit: 1217



View Profile
November 25, 2013, 03:19:10 PM
 #141

The owner of that site needs to shut it down. This kind of thing was inevitable and we warned about it from the start. Someone has calculated a rainbow table and the passphrase you chose is in it.

Which wallet software did you import the key into? Do we need to put a warning about this site into wallet apps? We need to find some way to kill this stupid and dangerous site asap.

over-react much? of course someone has made rainbow tables, so what? the lesson to be learned here is not that we should crucify brainwallet.org, it is that we should make strong passphrases.

Rep Thread: https://bitcointalk.org/index.php?topic=381041
If one can not confer upon another a right which he does not himself first possess, by what means does the state derive the right to engage in behaviors from which the public is prohibited?
1715617511
Hero Member
*
Offline Offline

Posts: 1715617511

View Profile Personal Message (Offline)

Ignore
1715617511
Reply with quote  #2

1715617511
Report to moderator
1715617511
Hero Member
*
Offline Offline

Posts: 1715617511

View Profile Personal Message (Offline)

Ignore
1715617511
Reply with quote  #2

1715617511
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715617511
Hero Member
*
Offline Offline

Posts: 1715617511

View Profile Personal Message (Offline)

Ignore
1715617511
Reply with quote  #2

1715617511
Report to moderator
1715617511
Hero Member
*
Offline Offline

Posts: 1715617511

View Profile Personal Message (Offline)

Ignore
1715617511
Reply with quote  #2

1715617511
Report to moderator
howzar
Hero Member
*****
Offline Offline

Activity: 574
Merit: 500


View Profile
November 25, 2013, 03:30:47 PM
 #142

This site just seem too much of a risk since you are either using a weak word or a difficult one which isn't easy to remember,it would be much simpler to just make a wallet (and add a password//encrypt keys) or just make paper ones.
franky1
Legendary
*
Offline Offline

Activity: 4214
Merit: 4485



View Profile
November 25, 2013, 04:48:42 PM
 #143

it has been asked many times for the simple snip-it of code that makes a private key. the answer is always view source of brainwallet. pfft i dont need all 1383 lines of code that do all the different functions. we just need the basic convert random characters + checksum and then convert to public. which should be under 100 lines of code

this will then allow people to make their own programs that hash words into giberish in any form they like. EG a mix of md5, sha256 followed by another passthrough of sha, before then converting.

then they atleast can make their own scripts to

take the first page of moby dick and MD5 it.
take the 6th page of the bible and MD5 it
take the 207th page of 50 shades of gray and MD5 it

put all 3 codes into a sha256
add a MD5 of Moses 10 commandments
sha256 again

and then put this through the 'brainwallet converter code'.

then next time they just put in those pages


I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
BurtW
Legendary
*
Offline Offline

Activity: 2646
Merit: 1136

All paid signature campaigns should be banned.


View Profile WWW
November 25, 2013, 05:48:43 PM
 #144

it has been asked many times for the simple snip-it of code that makes a private key. the answer is always view source of brainwallet. pfft i dont need all 1383 lines of code that do all the different functions. we just need the basic convert random characters + checksum and then convert to public. which should be under 100 lines of code

this will then allow people to make their own programs that hash words into giberish in any form they like. EG a mix of md5, sha256 followed by another passthrough of sha, before then converting.

then they atleast can make their own scripts to

take the first page of moby dick and MD5 it.
take the 6th page of the bible and MD5 it
take the 207th page of 50 shades of gray and MD5 it

put all 3 codes into a sha256
add a MD5 of Moses 10 commandments
sha256 again

and then put this through the 'brainwallet converter code'.

then next time they just put in those pages



Oops, now we know your brainwallet Wink

Our family was terrorized by Homeland Security.  Read all about it here:  http://www.jmwagner.com/ and http://www.burtw.com/  Any donations to help us recover from the $300,000 in legal fees and forced donations to the Federal Asset Forfeiture slush fund are greatly appreciated!
bitcoinbeliever
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
December 23, 2013, 05:42:12 AM
 #145

Whoever runs this site needs to shut it down now. It's negligent to do anything less.

I like to set up and fund brainwallet accounts for people I know who are new to bitcoin.  Then, all I have to do is give them the passphrase.

How else can I achieve this, without either 1) waiting for action from the recipient before I get an address to fund, or 2) having to associate an online account with an email address - which is either mine (the wrong one) or theirs (and they are tipped off about the gift)?
DeathAndTaxes
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
December 23, 2013, 05:47:59 AM
 #146

Whoever runs this site needs to shut it down now. It's negligent to do anything less.

I like to set up and fund brainwallet accounts for people I know who are new to bitcoin.  Then, all I have to do is give them the passphrase.

How else can I achieve this, without either 1) waiting for action from the recipient before I get an address to fund, or 2) having to associate an online account with an email address - which is either mine (the wrong one) or theirs (and they are tipped off about the gift)?

Paper wallet?  using a random (aka 256 bit of entropy) private key rather than some almost guaranteed to be bruted forced brainwallet scheme?

What a great way to introduce someone to Bitcoin, give them a brainwallet, later when it is worth a small  fortune they go to check on it and find out someone robbed it years ago.
Rampion
Legendary
*
Offline Offline

Activity: 1148
Merit: 1018


View Profile
December 23, 2013, 10:05:32 AM
 #147

Whoever runs this site needs to shut it down now. It's negligent to do anything less.

I like to set up and fund brainwallet accounts for people I know who are new to bitcoin.  Then, all I have to do is give them the passphrase.

How else can I achieve this, without either 1) waiting for action from the recipient before I get an address to fund, or 2) having to associate an online account with an email address - which is either mine (the wrong one) or theirs (and they are tipped off about the gift)?

Wow. If you think a brain wallet with a "memorable" password is secure you shouldn't be managing people's money at all. Why don't you just print out paper wallets?

Abdussamad
Legendary
*
Offline Offline

Activity: 3612
Merit: 1564



View Profile
December 23, 2013, 10:34:56 AM
 #148

Does anyone know who runs that site or how to contact them? The site itself has no contact info on it, the source code is owned by a user just called "brainwallet", the only thing resembling a contact address is a twitter account also called "brainwallet", etc.

You would think the Bitcoin "brain trust" would communicate with each other better:

I actually have IRC logs about the creation of the phrase brainwallet and brainwallet.org.  It was created by someone who introduction to the subject matter was his own efforts to crack peoples insecure keys, and he was irritated that he only found a few coins. No kidding.
TheButterZone
Legendary
*
Offline Offline

Activity: 3052
Merit: 1031


RIP Mommy


View Profile WWW
December 23, 2013, 08:53:52 PM
 #149

Does anyone know who runs that site or how to contact them? The site itself has no contact info on it, the source code is owned by a user just called "brainwallet", the only thing resembling a contact address is a twitter account also called "brainwallet", etc.

You would think the Bitcoin "brain trust" would communicate with each other better:

I actually have IRC logs about the creation of the phrase brainwallet and brainwallet.org.  It was created by someone who introduction to the subject matter was his own efforts to crack peoples insecure keys, and he was irritated that he only found a few coins. No kidding.


Joric, I found him in #bitcoin-dev once, and IIRC he ragequit because of the core team bitching about bw.org

Also
https://github.com/brainwallet/brainwallet.github.com

Saying that you don't trust someone because of their behavior is completely valid.
kuverty
Sr. Member
****
Offline Offline

Activity: 770
Merit: 250


View Profile
December 24, 2013, 04:07:08 PM
 #150

People are too worried about this. Everything that should be done is add a disclaimer not to use the Brainwallet site if you don't know what you're doing/can't come up with a proper passphrase. I like my brainwallet and I'll keep using it, it's a very nice idea. No surprise it's not suitable for the masses, just look at any list of leaked plaintext passwords. Or a list of leaked md5 passwords and see how many per cent you can crack.
Financisto
Hero Member
*****
Offline Offline

Activity: 632
Merit: 768

BTC⇆⚡⇄BTC


View Profile WWW
December 27, 2013, 02:51:28 AM
 #151

Definitely, brain wallets are not for newbies!

Paper wallets are easier to manage at early learning stages.

Brain wallets are for pros!  Cool

LIST • ESCROW providers • Ranking & Scores available!LIST • FOSS BrainwalletsBTC ⇆⚡⇄ BTCBTC aka BTC: 16MBvhaJoRBxW3Vk6apnvz3UYT9HAgraVS ⚡ PGP: 2680207AA9A1B69FE7A033D80DE0F221074384C4 ⚡ If you think freedom matters, please support the development of these privacy projects→DONATE some sats: TailsQubes OSWhonixVeraCryptPicocryptKryptorSimpleX Chat
giszmo
Legendary
*
Offline Offline

Activity: 1862
Merit: 1105


WalletScrutiny.com


View Profile WWW
December 27, 2013, 03:09:53 PM
 #152

For noobs: Brain wallets are rat poison and will get people to loose their money.

For pros: I like brainwallets as it allows me to give bitcoins totally offline with only pen and paper. I told a friend to make up some 5 long completely unrelated, maybe slang words and write them down. I wrote them down, too and she paid me for one bitcoin back then when it was around $10. I sent a bitcoin there when I got home. Worst thing that can happen is that she loses a paper with meaningless words on it Smiley

ɃɃWalletScrutiny.comIs your wallet secure?(Methodology)
WalletScrutiny checks if wallet builds are reproducible, a precondition for code audits to be of value.
ɃɃ
princes12
Newbie
*
Offline Offline

Activity: 7
Merit: 0


View Profile
January 28, 2014, 09:42:12 PM
 #153

Your worst nightmares has come to reality!!! Please read following post if you haven't seen it before.

https://bitcointalk.org/index.php?topic=421842.60

BurtW
Legendary
*
Offline Offline

Activity: 2646
Merit: 1136

All paid signature campaigns should be banned.


View Profile WWW
January 29, 2014, 01:39:24 PM
 #154

Your worst nightmares has come to reality!!! Please read following post if you haven't seen it before.

https://bitcointalk.org/index.php?topic=421842.60

Dear obvious sock puppet princes12:

That thread is total bullshit.  See my response to that thread here:

https://bitcointalk.org/index.php?topic=437220.msg4813821#msg4813821

and if you do not get the humor of that post, then try the more direct response here:

https://bitcointalk.org/index.php?topic=421842.msg4814386#msg4814386

Our family was terrorized by Homeland Security.  Read all about it here:  http://www.jmwagner.com/ and http://www.burtw.com/  Any donations to help us recover from the $300,000 in legal fees and forced donations to the Federal Asset Forfeiture slush fund are greatly appreciated!
Beliathon
Hero Member
*****
Offline Offline

Activity: 784
Merit: 1000


https://youtu.be/PZm8TTLR2NU


View Profile WWW
June 27, 2014, 04:34:42 AM
 #155

Does anyone know who runs that site or how to contact them? The site itself has no contact info on it, the source code is owned by a user just called "brainwallet", the only thing resembling a contact address is a twitter account also called "brainwallet", etc.

Whoever runs this site needs to shut it down now. It's negligent to do anything less.

For someone who lives in a direct democracy that has a lot of personal freedom, and hence, a lot of required personal responsibility, you sure as hell like to impose your moral standards on other people.

Bitcoin source code was authored by some unknowable pseudonym, SHUT IT DOWN, PADRE-MIKEHEARN SAYS NO ANONYMYMOUS CODINGZ!!!
I love you Carlton. Truly and with all my heart.

Remember Aaron Swartz, a 26 year old computer scientist who died defending the free flow of information.
Pages: « 1 2 3 4 5 6 7 [8]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!