Live data from Hacker News

Show HN: Vanity GPG Keys (and help fund GnuPG!)

vanitykeys.io

31–40 of 54 posts

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#32
post #31

Short key IDs are bad news (with OpenPGP and GNU Privacy Guard) http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...

Absolutely, short keys are bad. Nothing replaces a full fingerprint verification before usage. Keybase [1] does this very nicely IMHO.

[1] - https://keybase.io

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#33
post #10
post #8

I think it's a very bad idea to use this service. Your secret key should never be shared with a 3rd party. Using an untrusted 3rd party service to generate a public/private key pair is like asking a thief to sell you a new door lock.

I agree, this service should never be used for any serious real-life usage. But this is a _vanity_ key service, and there are legitimate uses for such keys where no harm can be done. I'm mainly interested in raising awareness to GnuPG and get more people using it - I also organize CryptoParties [1] in my area, exactly for this purpose. [1] - https://cryptoparty.in/

Is there a technical way to implement a service like that in a non-compromising way? I.e. user sends you his public key, you brute-force some nonce value, until the key's ID is "nice"?

Non-native speaker here, I didn't even know what "vanity" means, just ignored it as noise-word :) Well, after looking it up, I still am not sure that I understand what it means :).

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#34
I have a better service.

Aren't you tired of boring, bland, random passwords?

For just $5 I'll generate you a beautiful, memorable vanity password that you can use for everything and show off to your friends!

See my profile for contact info. Limited time offer!

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#35
post #23
post #3

Hi, I'm getting the following error using Opera 12.17. Unable to complete secure transaction Secure connection: fatal error (40) from server.

it is time to move on, Opera 12 is not supported anymore and bound to be insecure sooner than later. This problem will be a cipher issue.

It is, but I can't be bothered to try making Chrome or Firefox match my needs, if they even can.

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#36
post #9

Sorry but no. This makes your private key compromised by default... The most important rule of public key encryption is... Never (really!) let anybody else handle your private key... And why should I trust some random website for not storing an extra copy? The keys are definitely not "... as secure as if you have generated them by yourself. ". Because, if I generate them, I know that my box is the only one that had e…

I thought that if the user changes the passphrase[1] it could be done... But since the keys (private/public) remain the same, doesn't make any sense in this scenario. As I understand this (didn't try it) you could have 2 computers, same private/public keys different passphrase on each computer.

[1] http://security.stackexchange.com/questions/37510/when-chang...

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#37
post #16

Earlier quoted context omitted.

How do you feel about asking for over $10.000 (I'm bad at counting) for generated keys while GPG is desperately looking for donors? How do you feel about the ethics of your project in general? It looks a lot like domain parking to me.

You know what? You're absolutely right. I'll happily donate 60% of the profits from the service to GnuPG. Let's use this opportunity to fund GnuPG. You buying? :)

I'd rather donate 100% to GnuPG and not get an insecure vanity key.

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#38
Now this is retarded beyond repair. So, the idea is I'll pay money for someone to know my secret key?

Whats next, vanity passwords?

EDIT: reading the comments from the author yuvadam below, its obvious we are being trolled

EDIT2: now i'm getting scared. i wouldn't want software from this guy near my machines https://aur.archlinux.org/packages/?SeB=m&K=yuvadm

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#39
post #38

Now this is retarded beyond repair. So, the idea is I'll pay money for someone to know my secret key? Whats next, vanity passwords? EDIT: reading the comments from the author yuvadam below, its obvious we are being trolled EDIT2: now i'm getting scared. i wouldn't want software from this guy near my machines https://aur.archlinux.org/packages/?SeB=m&K=yuvadm

I agree, it's a really bad idea to buy a private key off of anybody. I mean, seriously?

Re: Show HN: Vanity GPG Keys (and help fund GnuPG!)

#40
post #16

Earlier quoted context omitted.

How do you feel about asking for over $10.000 (I'm bad at counting) for generated keys while GPG is desperately looking for donors? How do you feel about the ethics of your project in general? It looks a lot like domain parking to me.

You know what? You're absolutely right. I'll happily donate 60% of the profits from the service to GnuPG. Let's use this opportunity to fund GnuPG. You buying? :)

By all means donate to GnuPG, but do so directly instead of encouraging bad practice (such as letting someone else generate the key for you). If you are just playing around and generate a vanity/compromised key then verifying the key id is not useful, hence you don't need it to be easy to remember, which negates the reason for generating a vanity key in the first place.
Post reply on HN