Live data from Hacker News

Show HN: Vanity GPG Keys (and help fund GnuPG!)

vanitykeys.io

51–54 of 54 posts

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#51
Interesting concept, but no. People should not be having a 3rd party generating their keys.

If people want a vanity short key ID, then educating them on how OpenPGP packets work, and how the fingerprint is generated from the timestamp is the right way to go. Teach a man to fish.

Here is some Java code that creates a partial collision on the fingerprint for the desired short key ID:

http://www.halfdog.net/Projects/PgpKeyTools/KeyGenDSA.java

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#52
post #35
post #23

Earlier quoted context omitted.

it is time to move on, Opera 12 is not supported anymore and bound to be insecure sooner than later. This problem will be a cipher issue.

It is, but I can't be bothered to try making Chrome or Firefox match my needs, if they even can.

I know the pain. Settled for using them both but it is still so inferior. :(

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#53
post #41

Earlier quoted context omitted.

Is there a technical way to implement a service like that in a non-compromising way? I.e. user sends you his public key, you brute-force some nonce value, until the key's ID is "nice"? Non-native speaker here, I didn't even know what "vanity" means, just ignored it as noise-word :) Well, after looking it up, I still am not sure that I understand what it means :).

vanity base word is vane; or to be so focused on how pretty or appealling you are to others. often used when talking about asthetically pleasing names when talking about tech stuff (vanity hostnames for example.. dns names which are excessively showy, this used to be common on IRC to look "cool").

Would that not be "vain"?

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#54
Werner Koch (the guy who develops GnuPG), when asked about this website:

http://lists.gnupg.org/pipermail/gnupg-users/2015-January/05...

"I have not heard about it but given that the Wau Holland Stiftung is collecting GnuPG donations also via Bitcoin, it is likely that this can't be tracked.

However, if that processing power is used to find many dups for long keyids we will sooner or later neet to invest work to mitigate the effect of this (e.g. adding a fingerprint as signed attribute to each signature)."

Post reply on HN