6 ms·
This is cute, but I'm dubious. It generated "y3aEmic8B217" as my password. Kid just happened to hit the shift key while also pressing E and then B? It looks a l
by brianberns 7y ago
This is cute, but I'm dubious. It generated "y3aEmic8B217" as my password. Kid just happened to hit the shift key while also pressing E and then B? It looks a little too random to me. When I pound on the keyboard, I get results that look more like "fjlsd;lasf".
- jefftk 7y agoMy guess is they're using what the toddler typed to seed an RNG?
- brianberns 7y agoYeah, the verbiage says that his typing is merely the "basis" for the resulting password, so you're probably right.
- robbya 7y agoWhich means the password has much less entropy than it appears to have. It's a fun implementation, but not serious
- tialaramex 7y agoSo, kinda, sorta, mostly no. We have these things called stream ciphers. You put a little bit of randomness in, and you get what seems to be lots of randomness out. For example the cipher might need a 256-bit key and 128-bit nonce and then spit out gigabytes of seemingly random data. Now, mathematically they can't /really/ be making more randomness, there's no random steps it's all deterministic, in principle it ought to be possible to unwind the steps and get back the initial random state. But it turns out that unwinding step just can't actually be done with a good stream cipher, that's the whole point. We do this sort of stuff a lot in real modern cryptography. There's a HN article which might still be on the front page, it was earlier today, explaining how SSH works. It shows that six keys are needed for SSH encryption, but they don't go get six times the randomness you'd need for a single key, they can just use a cryptographically strong hash function and make six different keys from the same shared secret randomness. Let's do an experiment: I've rolled my hex dice a few times to create a 64-bit random number. I've pushed that as ASCII text into MD5 and got back a result, and now I'm going to tell you the first and last characters of the result: F31FB042................81AFD8FA That's 64-bits. If you were correct with this idea about entropy you could tell me what the missing bits are, infact you could prove it to other posters - after all I have given you all the randomness according to your thinking, there can't be any left. But in fact you have no idea what those missing bits are, no idea what the original 64-bit number was, because you are wrong, with cryptographic primitives like hashes or stream ciphers we can in practice take a relatively small amount of entropy (like a few minutes of keyboard bashing by a toddler) and that's enough for all purposes. The _real_ reason you shouldn't use this to make passwords is that the site might be lying and keeping a record of every password that is chosen and which IP address it was given to etcetera.
- esotericn 7y agoThis is not the case because one could enumerate the entire 64bit space and perform a rainbow table attack on your scheme.
- jefftk 7y agoSimple brute force is not a rainbow table. Brute forcing 2^64 bits means calculating 2^63 MD5s in expectation. You can do ~100 GHash/sec, so ~2^37/s, so about 2^29s which is 17 gpu-years. So this is doable, but incredibly expensive.
- thisacctforreal 7y agoNote that a it’s an entirely different story with a “real” kdf like scrypt or bcrypt. MD5 and SHA are specifically designed to be fast to compute, they shouldn’t be used for passphrases. Figured I’d bring it up in case there’s still PHP floating around with the once-typical practice of MySQL + MD5.
- tialaramex 7y agoI'm glad my eyeballing the difficulty came off here. It was tempting to pick say 128-bits of randomness and SHA-512/256 where I'd stake actual money that it just cannot be done - but that's like twice as much die-rolling and typing. On the other hand if I do 32-bits (fewer rolls) and MD5 there's probably some loser out there who has already precomputed all of those for whatever reason and then somebody finds the answer with a Bing search and doesn't end up learning anything. echo -n 'F004672790DB5B1D' | md5sum f31fb042501c2a398974feca81afd8fa -
- esotericn 7y agoGot me. I suppose I thought of 64bit as now being small. 48 would be doable.
- amarena 7y agoThat is a PRNG, not a stream cipher.
- preommr 7y ago> It's a fun implementation, but not serious Well obviously, how was this business going to scale? Op can't keep making more kids in case the business really takes off.
- dredmorbius 7y agoLow-order bits from sufficient timing measurements would be effectively random. You're not looking at the characters, you're looking at the intervals between keypresses, and gathering the least significant digits of those. This is what PGP/GPG use for gathering entropy when generating keys as well. Not saying that's what's being done here, but it's a way to take fairly nonrandom activity and get decent entropy from it.
- cpcallen 7y agoNot necessarily. There's no way to know how much entropy is put in to the mix—it could be quite a lot.
- firekvz 7y agoYeah I also got a really weird password that needs shift and characters way to distant from the others to believe it's comming from a toddler Guessing he's using 2 hands most likely you will get characters around the 1st one he pressed, so if you get a 's' character first, you can expect qweadzc near, but going from a 's' to a capital 'P' and then to a ! doesnt look legit to me
- mxfh 7y agoI just checked some old Winston files my toddler daughter wrote back then. (Great fun btw, but sadly only attracts attention with sound on.) Her pattern is higly repetitive, and you a have a quite high share of fghj (also seen in the video with Max) in there. Single shifted chars? Quite unlikely. http://www.rengelbert.com/winston/ http://www.rengelbert.com/winston/ ydwew346rr764847uruejdjeyytr4t5t5ty8uoff jfgjjhv rr rgr r rrrrh jjjhhhju5m ytj8ikm ,k88o0pfffuyhfjdjuddjcie8kdduuukjfuruuryfuuugtt767yut67y7hcfght h7tyty5y6 uyhtryty gyfg huy tyhrty7 ruy6t5y5777h hyuyu utygj tgytu jtgtu 5ugjuy 5676uvu 2355 hfhghhhhhu7uuuytutut juyy umnhjbbvvgyy6tg7777. bdy7er64y5y574757r04iiiiiutweepiroeiwijwdryyt h7f77fuuvyf77f7uuyutuhturghghyhyggyvbg fyr gfrt6rfytyftr6 tryy hyyyy675g ttyty57 htgtt6t667 t65r7745 y6767nghnggugg7uuupooooooiuuuuytrewq kkha bcx gtytttmhguyuuhuuuygyufh7673y7rtty7yggffrtdyteryurijrf uu4hfyuytttgt7t7yrfyrtuyu
- ta999999171 7y agoLook, Shakespeare.
- WilliamEdward 7y agoDid you really think this came from an actual toddler? It can generate 50 character length passwords in seconds...
- icebraining 7y agoThey say the characters come from a record, not generated in real time. Could be just a FIFO file.
- dhdhebsb 7y agoOmg could you imagine the toddler sitting there, waiting for a request and then banging out a random password of the right length
- em-bee 7y agowell, he could continue banging, and you stop recording when you have enough. now add a realtime api that makes the characters appear as typed, and relay the sound heared from the keyboard and baby and you have a perfect setup.
- deleted 7y ago[deleted]
- Mathnerd314 7y agoThe site just sends a POST request for a password of the specified length, so there's no easy way to verify the site's claims. He did post his address on the Imprint page, so I guess someone in Germany could drive over there.
- tardo99 7y agoI got underscore characters. Seems unlikely.
- mrb 7y agoYou guys are much too naive :) To me it seems obvious the site is just humorous and not serious. Of course the passwords have not been typed by a toddler but are simply generated randomly. I guess the author wanted his site to have mild educational value, in that smashing your keyboard generates passwords stronger than the average password picked by people.
- okusername 7y agoWhen I let my 5 months old investigate my keyboard, he changed my code, started the compiler and locked the device within 30 seconds. The secret? They use both hands. The give away? They re-press the same keys often, so the result would be a lot more repetitive.