3 ms·
The checksum algorithm they used will only produce 73 different checksums (00000000-99999999: 0-72) - and all of them even. There is space for 9999 different va
by jo-han 11y ago
The checksum algorithm they used will only produce 73 different checksums (00000000-99999999: 0-72) - and all of them even. There is space for 9999 different values.
Tips to improve:
f(x) = ( x * secret) mod 1000
- mod 10000 instead of mod 1000 (as mentioned in the article)
- make sure the 'x' varies between 0-9999 (e.g. by splitting the number in half and adding the parts 03001909 > 0300+1909 = 2209)
- make sure the 'secret' is larger than 10000 and non-divisible by factors of 10000 (2 and 5) (e.g.: 54321)
Pretty sure it wouldn't be so easy to hack then.
- nocsaer1 11y agoIt is probably just a barcode checksum/error code, otherwise they wouldn't have to rely on the values of the first 8 digits. Instead they should generate 4 random digits and store them in the database along with other information, then it basically works like a pin number (and xor it with a proper checksum). Edit: If it is really a checksum, it is a crappy one.
- jschwartzi 11y agoA lot of symbologies support some kind of modulo check digit. It's mostly there to detect erasure and substitution errors, because those are relatively common errors in decode. A modulo sum is better than nothing, considering that each additional digit increases the length of the barcode. If you're length-constrained, then adding more check-data is a difficult trade-off between stronger protection and smaller module size, meaning that you could add so much data that the barcode becomes too dense to print or read.
- andrewla 11y agoA secret larger than 10,000 is not useful -- since the multiplication is mod 10,000, the first digit of the secret could be ignored anyway (54321 = 5 * 10000 + 4321 === 4321 mod 10000).