What is a brain wallet? A brain wallet is an iterative type of Bitcoin wallet in which the password is not stored digitally, but in the user's memory. Brainwallets, originally conceived to keep sensitive wallet data offline and make Bitcoin addresses easier to remember, use a single long password and phrase that converts it into a private key, a public key, and an address. Are brain wallets safe? It seems not safe. A white hat hacker has released a tool whose purpose is to illustrate the insecurity of brain wallets. This tool uses an offline attack method to quickly guess possible passwords to see if they are correct. Ryan Castellucci, a security researcher at digital anti-fraud company White Ops, published the study, pointing out that brain wallets have major flaws. He stressed that the final Bitcoin address is recorded on the blockchain as a password hash. When the password hash is used for website authentication, it helps you determine whether the word or phrase provided is correct, which means that this data can be used by hackers as a reference to find passwords. Castellucci unveiled the brain wallet decryption tool, called Castellucci said that when the brute force cracking software is applied to ASCII passwords and XKCD passwords, which are four-character passwords, a botnet can check all Bitcoin addresses that have received funds in a day. In the interview, Castellucci stressed that while his tool could be used by criminals, he hopes its release will encourage bitcoin users to adopt better, more secure practices. Following the release of the tool, BrainWallet.org, a website that used JavaScript to generate user private keys, decided to go offline, a move that was widely praised by members of the Bitcoin security community. Origin of the projectAccording to Castellucci, the idea for the project first came about in mid-2013, when bitcoin users first raised security concerns about using brainwallets. Around the same time, a white hat hacker on Reddit going by the name Inspired by this, Castellucci created a primitive version of Brainflayer that was able to guess 10,000 passwords per second, a far cry from the current Brainflayer capabilities. Still, he recalls, the simple program still achieved outstanding results. When he returned to his computer, he discovered that the prototype version of Brainflayer had retrieved Castellucci said he faced a moral dilemma and he didn't know what to do. “For a while I stopped my research,” he said. “I hoped the problem would go away on its own. After all, many experts were saying that brain wallets were bad.” But the problem did not go away, so he decided to return to his research. He wrote in a recent blog post: "My idea is that if someone finds a bug like I did, they'll work hard to get it fixed before sharing it with the world. I've done that in the past, and I think it's the right way to go." suggestion In addition, he suggested that those who are using brain wallets should consider With WarpWallets, the " Of course, Castellucci also recommends that those who use such wallets use diceware to generate passwords, which produces passwords through a pair of dice and a random number generator. "It seems like it's going to be very hard to get people to stop using things like their dog's name and their birthday as passwords, and Scrypt won't save people who use 'P@ssw0rd' as their password," he said. "A lot of people seem to think that a long password is a secure password, and I think I've proven that's not necessarily true." Next StepsWhen asked by reporters how he planned to continue his work, Castellucci said he was still considering next steps. Finally, he sighed:
---- |
<<: Multiple U.S. agencies jointly investigate Bitcoin money laundering case involving arms dealers
Are people with full foreheads very capable? Peop...
Palmistry can tell whether two people are compati...
Short side takes the initiative and waits and see...
Regarding the proportions of a person's three...
Last week, multiple sectors of the crypto industr...
Chin to see who has true feelings The chin can re...
Although few people in life would discuss whether...
The Philippines central bank governor, one of the...
The position of moles can tell your life fortune ...
Bitcoin prices fluctuated after falling from high...
What are the palm characteristics of people who a...
Yellow helps improve financial luck, orange helps...
A person’s luck in having children can be seen fro...
Taiyin, which belongs to Yin water, is a star of ...
The forehead is called the forehead in physiognom...