Earlier quoted context omitted.
This happens all the time . If I had a nickel for every system I broke with a time based prng, I’d have like 10 bucks by now.
What's the most random and wildly known way, apart from time based, to pick a seed value then?
Researchers cracked an 11-year-old password to a $3M crypto wallet
161–170 of 196 posts
Re: Researchers cracked an 11-year-old password to a $3M crypto wallet
#162Earlier quoted context omitted.
Oh absolutely. Money is the root of all evil. But crypto bros are often delusional about what intrinsical value exists in the normal market, compared to crypto coins where they invent the value. Therefore manipulation of value compared to real world markets becomes a lot more abstract.
One of the greatest uses of crypto is the ability to transfer any amount of money to any point on earth for next to nothing and no questions asked. That is worth more than most any other use for crypto.
Bitcoin did not solve any real problem and you still need an additional mechanism to make sure that the thing you get back, actually happens.
Re: Researchers cracked an 11-year-old password to a $3M crypto wallet
#163"Michael... now has 30 BTC, now worth $3 million, and is waiting for the value to rise to $100,000 per coin." What the ? You presumably go from not a millionaire to having $3,000,000, and you decide to risk it to triple it? That's some next level greed right there.
You want him to swap absolutely scarce Bitcoin for something that can be printed infinitely out of thin air? Swapping to dollars would be the risk here.
Bitcoin only has value because someone else is willing to pay for it. That can hold true until it suddenly doesn't. If Bitcoin disappeared today, the world would go on without blinking. Nothing would stop functioning. That is of how little use it actually is.
That said, I'm a great believer in the meme value of Bitcoin and the greater fools. I hold several, with the belief that someday enough other fools will pay me a lot more fiat money to allow me to retire in style.
Re: Researchers cracked an 11-year-old password to a $3M crypto wallet
#164Earlier quoted context omitted.
but you can't. you can't send Bitcoin or Eth around the world for "next to nothing" today. not in a reasonable time frame. and that isn't accounting at all for the massive power wastage in the Bitcoin case.
My brother, have you heard of HBAR? Hedera is the way.
What happens when the product is faulty or not even arriving?
Re: Researchers cracked an 11-year-old password to a $3M crypto wallet
#165Earlier quoted context omitted.
I mean how weak are they really? These guys knew the algo and still struggled and pestered the user over and over for the other parameters. They also had what I would describe as an extreme motivation to crack this.
The constraint is knowing when the password was created. If you know that within a day or so, that makes the problem much more tractable and you can instead focus on number of characters and the other parameters. Sniffing traffic (yes even encrypted) would be enough to see if you’re going through the login or initial user establishment flow, and that would give you a precise time when the password was generated. This…
Re: Researchers cracked an 11-year-old password to a $3M crypto wallet
#166Earlier quoted context omitted.
You can try millions of passwords on a wallet without anything stopping you. You only get a few guesses on a bank site.
If you only get a few guesses on a bank site, then you can inconvenience large numbers of users cheaply.
Re: Researchers cracked an 11-year-old password to a $3M crypto wallet
#167Earlier quoted context omitted.
You want him to swap absolutely scarce Bitcoin for something that can be printed infinitely out of thin air? Swapping to dollars would be the risk here.
You know what else is absolutely scarce? Litecoin. And Solana. And XRP. And Cardano. And Avalanche. And Chainlink. And Bitcoin Cash. And Tron. And Ethereum Classic. And Stellar. And VeChain. And AlgoRand. And an infinite amount of other coins that anyone can invent at a moments notice. Bitcoin only has value because someone else is willing to pay for it. That can hold true until it suddenly doesn't. If Bitcoin disapp…
Re: Researchers cracked an 11-year-old password to a $3M crypto wallet
#168Earlier quoted context omitted.
One of the greatest uses of crypto is the ability to transfer any amount of money to any point on earth for next to nothing and no questions asked. That is worth more than most any other use for crypto.
but you can't. you can't send Bitcoin or Eth around the world for "next to nothing" today. not in a reasonable time frame. and that isn't accounting at all for the massive power wastage in the Bitcoin case.
You can do those same transfers cheaper and faster on an Ethereum layer 2.
Re: Researchers cracked an 11-year-old password to a $3M crypto wallet
#169Earlier quoted context omitted.
The constraint is knowing when the password was created. If you know that within a day or so, that makes the problem much more tractable and you can instead focus on number of characters and the other parameters. Sniffing traffic (yes even encrypted) would be enough to see if you’re going through the login or initial user establishment flow, and that would give you a precise time when the password was generated. This…
Security people overusing the words serious and critical have really watered down the terms. At this point when I get told something is a serious risk, I file it next to being hit by lightning or eaten by sharks.
Password management is one of those fundamental security foundations- essentially serving as the 'root of trust' for your own personal digital life. If you mess that up, you're in for a world of hurt. I don't mess around with passwords. Taking your analogy, would you intentionally stand outside under a tree in a thunderstorm, figuring that the risk of getting hit by lightning is so small?
Re: Researchers cracked an 11-year-old password to a $3M crypto wallet
#170Earlier quoted context omitted.
Security people overusing the words serious and critical have really watered down the terms. At this point when I get told something is a serious risk, I file it next to being hit by lightning or eaten by sharks.
sorry to hear that. I don't exaggerate, but the unfortunate part is there is a lot of FUD out there- I just had a friend install nordvpn because someone sent her a gift card scam email to her business email address. So there's a lot of misinformation out there, mostly from folks selling product. Password management is one of those fundamental security foundations- essentially serving as the 'root of trust' for your o…
Yes it’s obviously not good that they used the date as a seed, but the realistic risk is pretty much non existent. Even in this case where literal millions of dollars were on the line the “attackers” still had to collaborate heavily with the owner to narrow down the search space. On their own they likely would never crack it.
Absolutely no one is going through all this to get in to your Facebook account when they can just call up some grandma and ask them to transfer a $1000.