Bitcoin Forum
May 07, 2024, 03:07:14 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: how sensitive is wallet.dat  (Read 152 times)
citb0in (OP)
Hero Member
*****
Offline Offline

Activity: 672
Merit: 656


Bitcoin g33k


View Profile
October 02, 2022, 03:08:20 PM
Merited by LFC_Bitcoin (2), vapourminer (1), ABCbits (1)
 #1

Hello everybody,

Assuming that someone manages to steal the wallet.dat (which is password-protected of 16 characters alphanumeric + special chars) of my computer, how (bad are my and how) good are his chances that he will gain full access to my coins? Is this something I have to worry about or nothing to worry about ? Let's assume in this example that he has gained absolutely no other information of me and even does not know anything about the owner/me so he couldn't construct a personalized brute-force attack on the wallet.dat

Looking forward to your comments.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
"I'm sure that in 20 years there will either be very large transaction volume or no volume." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715094434
Hero Member
*
Offline Offline

Posts: 1715094434

View Profile Personal Message (Offline)

Ignore
1715094434
Reply with quote  #2

1715094434
Report to moderator
1715094434
Hero Member
*
Offline Offline

Posts: 1715094434

View Profile Personal Message (Offline)

Ignore
1715094434
Reply with quote  #2

1715094434
Report to moderator
OmegaStarScream
Staff
Legendary
*
Offline Offline

Activity: 3472
Merit: 6125



View Profile
October 02, 2022, 03:22:53 PM
Merited by NeuroticFish (2), LFC_Bitcoin (1), ABCbits (1)
 #2

-snip-
Let's assume in this example that he has gained absolutely no other information of me and even does not know anything about the owner/me so he couldn't construct a personalized brute-force attack on the wallet.dat

In this case, no. There's nothing to be worried about. But if someone manages to remotely steal your wallet.dat (with malware) it would be safe to assume that he has your keystrokes too.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
PawGo
Legendary
*
Offline Offline

Activity: 952
Merit: 1367


View Profile
October 02, 2022, 03:23:15 PM
 #3

16 characters (alphanumeric + special characters) are (IMHO) unbreakable, 8 is a quite easy task, anything more needs so much time and resources, that it is undoable - so you may sleep safe.
There is only one remark - that is correct reasoning if password is somehow “random”. If you used any dictionary word and then just added “123!” at the end, it is not safe at all. Even worst if you used any password which is on any list of used/leaked passwords.
LoyceV
Legendary
*
Offline Offline

Activity: 3304
Merit: 16616


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
October 02, 2022, 03:24:44 PM
 #4

I think your scenario isn't realistic: if someone gets their hands on your wallet.dat, they can probably install a keylogger too.
Brute-forcing 16 characters is going to take a while, but there are specialized services out there.

citb0in (OP)
Hero Member
*****
Offline Offline

Activity: 672
Merit: 656


Bitcoin g33k


View Profile
October 02, 2022, 04:00:06 PM
Merited by vapourminer (1)
 #5

Thanks for the helpful responses. I just wanted to understand if and how far the wallet.dat is protected by such a scenario. Of course the password should be cleverly chosen that it doesn't appear in any dictionary, isn't a common word or could be built from permutations of it. I know the process of brute-force cracking. But that there are special "services" out there that can crack 16-digit passwords of the type mentioned in reasonable time ... didn't know that. I always thought with 16 digits you were already on the safe side. But well, then I'll just raise it to 26 chars and then I'll sleep better  Tongue

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
October 02, 2022, 04:37:51 PM
 #6

It depends on whether the alphanumeric code is truly random or not. As long as you have 16 characters that are random then you should be fine for now..

If you happen to have words in there then the password might become solvable for an attacker.
citb0in (OP)
Hero Member
*****
Offline Offline

Activity: 672
Merit: 656


Bitcoin g33k


View Profile
October 02, 2022, 04:45:33 PM
Merited by o_e_l_e_o (4)
 #7

it's truly /dev/urandom  Cool

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18510


View Profile
October 02, 2022, 06:53:50 PM
Merited by LFC_Bitcoin (2), ABCbits (2)
 #8

If you have 16 random characters from the full set of 95 printable ASCII characters, then you have 9516 possibilities, which comes out to a little over 105 bits of entropy. The bitcoin network currently has a hashrate of around 250 EH/s. Given that each of those is two SHA256s, then that means it would take the entire bitcoin network around 2,800 years at current rates to perform 2105 hashes. So your password is quite safe against random brute forcing.

But, as Loyce correctly points out, if someone has managed to steal your wallet.dat file from your computer, then your entire set up is now compromised either physically or electronically, and a secure password is no guarantee of safety.
Sarah Azhari
Hero Member
*****
Offline Offline

Activity: 868
Merit: 737


View Profile
October 03, 2022, 11:40:23 AM
 #9

it's truly /dev/urandom  Cool
so what can you do when you run out of entropy?
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!