Author

Topic: Brain wallet funds instantly relayed! D= (Read 920 times)

legendary
Activity: 924
Merit: 1001
March 29, 2015, 07:38:35 AM
#9
There's very little entropy in the phrase "There is no new thing under the sun" (In this context, I'd guess much less than 20 bits).  It's easily one of the billion phrases most likely to be selected for this use so it's not really surprising to see the funds instantly vanish.

Compare this with another eight-word phrase: "rebel twenty hotel solve zone arena dad east".  These words were selected randomly and uniformly from a list of 2048 words using a secure RNG (you could use coins, dice, cards instead or in conjunction).  Unlike "There is no new thing under the sun", I can be confident that this precise string of words did not exist anywhere until this moment.  Before I revealed this precise passphrase it had, provably, 88 bits of entropy (so I'd guess it to have been about 300 billion billion times stronger).

Even then, I would recommend using something stronger still for a brainwallet.  While I occasionally use brainwallets with as little as 96 bits of entropy, I recommend a minimum of 128 bits to anyone that's not confident in doing the calculations themselves.  For reference:
  • Casascius coin addresses have 128 bits of entropy and they're holding out well.
  • A typical address as generated by Bitcoin Core contains 160 bits of entropy (about 4 billion times stronger than 128 bits).

Diceware, mentioned in tspacepilot's link, gives you about 12.92 bits of entropy per word so you'll want 10 words as a minimum and 13 words for maximum security.

Final note:  Now that I've posted "rebel twenty hotel solve zone arena dad east" online, it would make a poor brainwallet passphrase.  I wouldn't care to guess at its strength but it's certainly far, far less than 88 bits.

Thanks for this! helps a lot  Smiley
legendary
Activity: 1246
Merit: 1011
March 29, 2015, 01:52:31 AM
#8
There's very little entropy in the phrase "There is no new thing under the sun" (In this context, I'd guess much less than 20 bits).  It's easily one of the billion phrases most likely to be selected for this use so it's not really surprising to see the funds instantly vanish.

Compare this with another eight-word phrase: "rebel twenty hotel solve zone arena dad east".  These words were selected randomly and uniformly from a list of 2048 words using a secure RNG (you could use coins, dice, cards instead or in conjunction).  Unlike "There is no new thing under the sun", I can be confident that this precise string of words did not exist anywhere until this moment.  Before I revealed this precise passphrase it had, provably, 88 bits of entropy (so I'd guess it to have been about 300 billion billion times stronger).

Even then, I would recommend using something stronger still for a brainwallet.  While I occasionally use brainwallets with as little as 96 bits of entropy, I recommend a minimum of 128 bits to anyone that's not confident in doing the calculations themselves.  For reference:
  • Casascius coin addresses have 128 bits of entropy and they're holding out well.
  • A typical address as generated by Bitcoin Core contains 160 bits of entropy (about 4 billion times stronger than 128 bits).

Diceware, mentioned in tspacepilot's link, gives you about 12.92 bits of entropy per word so you'll want 10 words as a minimum and 13 words for maximum security.

Final note:  Now that I've posted "rebel twenty hotel solve zone arena dad east" online, it would make a poor brainwallet passphrase.  I wouldn't care to guess at its strength but it's certainly far, far less than 88 bits.
legendary
Activity: 978
Merit: 1001
March 29, 2015, 01:14:42 AM
#7
You underestimate the power of exponential curves...
legendary
Activity: 924
Merit: 1001
March 29, 2015, 12:27:37 AM
#6
You underestimate the power of rainbow tables...
You mean 'they' already got into that long passphrase?
Say goodbye to brainwallet

It's really not surprising that one of the most popular lines from shakespear is in a rainbow table for brainwallet.  There was a recent slashdot story about how to actually create a strong, yet memorable passphrase.  I think the OP would be interested in this as it addresses his concern.

http://yro.slashdot.org/story/15/03/26/2032259/generate-memorizable-passphrases-that-even-the-nsa-cant-guess

Thanks, interesting read. amazing how one word is the difference between 6 months and 3000 years.
legendary
Activity: 1456
Merit: 1081
I may write code in exchange for bitcoins.
March 29, 2015, 12:06:16 AM
#5
You underestimate the power of rainbow tables...
You mean 'they' already got into that long passphrase?
Say goodbye to brainwallet

It's really not surprising that one of the most popular lines from shakespear is in a rainbow table for brainwallet.  There was a recent slashdot story about how to actually create a strong, yet memorable passphrase.  I think the OP would be interested in this as it addresses his concern.

http://yro.slashdot.org/story/15/03/26/2032259/generate-memorizable-passphrases-that-even-the-nsa-cant-guess
hero member
Activity: 784
Merit: 1000
March 28, 2015, 11:50:18 PM
#4
You underestimate the power of rainbow tables...
You mean 'they' already got into that long passphrase?
Say goodbye to brainwallet
legendary
Activity: 978
Merit: 1001
March 28, 2015, 11:45:27 PM
#3
You underestimate the power of rainbow tables...
full member
Activity: 153
Merit: 100
March 28, 2015, 11:43:35 PM
#2
somebody has generated a large database of popular brain wallets

This.
legendary
Activity: 924
Merit: 1001
March 28, 2015, 11:31:04 PM
#1
Hey guys,

I thought I'd start experimenting with brain wallets to store some of my bitcoin in, so I went to the only place I know to do that. https://www.bitaddress.org/bitaddress.org-v2.9.8-SHA256-2c5d16dbcde600147162172090d940fd9646981b7d751d9bddfc5ef383f89308.html?culture=en

I tried a long quote of shakespeare, but the address came out invalid according to my smart phone wallet so I tried a shorter phrase - "There is no new thing under the sun"

I sent 0.001 here 14BwAbCRHJ7xbvG7GQFuxPgErJw6zXQdxQ and instantly it was relayed to this address which had 10BTC in it 1LdUHTEVxWJhrhKfy4H3VuYDnTHQVjsdBn





This is really scary that the funds were relayed instantly, I know its not the strongest phrase but there could only be two things going on here, somebody has generated a large database of popular brain wallets, or bitaddress.org is crooked.

has anybody else had this experience?

Can you make a brain wallet simple enough to be memorable and secure?

Thanks for your thoughts!
Jump to: