3 ms·
> It records a short video of you and then transforms that raw video data into an array of 8-bit unsigned integers. Then it randomly selects an integer from tha
by dsukhin 7y ago
> It records a short video of you and then transforms that raw video data into an array of 8-bit unsigned integers. Then it randomly selects an integer from that array and transforms it into its corresponding UTF-16 character. If that character is a lowercase letter, uppercase letter, digit or special character it will be used for your password.
This is an interesting idea but have you conducted any entropy tests by generating a class of passwords from a family of videos and seeing how different they really are (e.g. character freq)? Without any hard numbers I can pretty confidently assume that the colors (8 bit unsigned perhaps mean R, G, and B pixel values) in a video are not uniformly/randomly distributed in the color space and subsequent frames of the video are also highly correlated. Not to mention you specifically throw away any non ascii character so a large portion of the UTF-16 space is not even allowed). Unless by chance, those you throw away happen to also be the super common int values, I feel that it's likely the entropy of these passwords is going to be surprisingly low.
What do you think? The entropy test would make a great blog post.
- hachibu 7y agoThis is great breakdown. I think doing an entropy test would be a great idea for a followup blog post. I don't know how to run an entropy test. Do you know how I could do that?
- dsukhin 7y agoThe search term you are looking for is Shannon Entropy [0]. That should set you in the right direction. Put in layman terms - your best possible entropy is a case where every allowed character appears with roughly the same chance (i.e. there is no super common or super rare characters). The most extreme low entropy case is where only one character appears all the time so the password is completely predictable if you know how long it is. I would recommend you run two tests. One with the same video over and over video and one with 5 or so videos filmed under similar conditions to measure how much of the randomness actually comes from different videos vs. your algorithm. For your videos genererate 100k+ passwords and count the number of times each character appears to get the probability of each character. Then use what you learned about Shannon Entropy (using the probability of each letter) to determine how much entropy your passwords have. [0] https://planetcalc.com/2476/ https://planetcalc.com/2476/
- hachibu 7y agoThank you, I'll try it out.
- DarthGhandi 7y ago> Do you know how I could do that? Dieharder or TestU01 are considered the gold standards of statistical tests for randomness by many (my claim only, randomness is provably unprovable) You can try the nist one too if you want to go down the corporate route but these tests go further.