3 ms·
Cautionary note: UUIDs generally do not meet security requirements
- SAI_Peregrinus 5y agoI'd also note that while "random" (v4) UUIDs have 128 bits of data, they don't have 128 bits of entropy, even if created with a CSPRNG! They've got a few fixed bits, so only 121 to 122 bits in the random part. That doesn't change the brute force difficulty enough to make it practical, but using them for certain purposes could be catastrophic. EG if you used a v4 UUID as the `k` value in ECDSA that would leak your private key, since any leakage of any bits of the `k` value leaks the private key.[1][2][3][4] Don't use UUIDs for security purposes. [1] Dan Boneh and Ramarathnam Venkatesan. Hardness of Computing the Most Significant Bits of Secret Keys in Diffie-Hellman and Related Schemes. In Advances in Cryptology - CRYPTO ’96, 16th Annual International Cryptology Conference, Santa Barbara, California, USA, August 18-22, 1996, Proceedings, pages 129–142, 1996 [2] Nick Howgrave-Graham and Nigel P. Smart. Lattice Attacks on Digital Signature Schemes. Des. Codes Cryptogr., 23(3):283–290, 2001. [3] Phong Q. Nguyen and Igor E. Shparlinski. The Insecurity of the Digital Signature Algorithm with Partially Known Nonces. J. Cryptology, 15(3):151–176, 2002 [4] Phong Q. Nguyen and Igor E. Shparlinski. The Insecurity of the Elliptic Curve Digital Signature Algorithm with Partially Known Nonces. Des. Codes Cryptogr., 30(2):201–217, 2003