20 ms·
Passwordle
- drtz 5y agoNo bcrypt?
- drdaeman 5y agoShould've been Argon2id
- TremendousJudge 5y agoliterally made me laugh out loud, well done
- delaaxe 5y agoMe too but this can never be sold right
- core-utility 5y agoWhat, Wired Magazine won't buy this for $3 Million?
- delaaxe 5y agoI meant solved...
- ziml77 5y agoSame here! I love the absurdity of this one given the nature of cryptographic hash functions.
- raesene9 5y agonice, though I'm very disappointed the answer wasn't hunter2
- MichaelVangard 5y agoI don’t get it? Why would the answer be *******?
- torgard 5y agoYeah same. From the source code, the answer is a random 14-character string, generated on load: function randomPassword() { let letters = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ'; let digits = '0123456789'; let punctuation = '!"#$%&\'()*+,-./:;<=>?@[\\]^_`{|}~'; let s = letters.repeat(7) + digits.repeat(4) + punctuation.repeat(3); let length = 14; let res = Array.from({length}, (() => s[randomInt(s.length)])).join(''); debugger; // どうぞ return res; }
- DonHopkins 5y agoI wish it accepted a given password from a url query parameter, so this url would work: https://rsk0315.github.io/playground/passwordle.html?password=hunter2 https://rsk0315.github.io/playground/passwordle.html?passwor... Or the way bikeshed.com lets you configure the color with the domain name, like: https://bisque.bikeshed.com/ https://bisque.bikeshed.com/ Then they could monetize it by selling gullible suckers NFTs of urls pointing to Passwordle games of their passwords.
- politelemon 5y agoPassword is randomized on each load. Author has conveniently left a debugger statement in the code.
- TYMorningCoffee 5y agoI did not know about the debugger statement until I read your comment: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Statements/debugger https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe... . Thank you.
- aerovistae 5y agoMassively useful! I also recently learned you can right click a line of code in the chrome debugger to add a logpoint - i.e. "log the value of this expression when you reach this point in the code" - so I don't have to manually add console.log statements. Basically the reverse of discovering the debugger statement!
- culturestate 5y ago> you can right click a line of code in the chrome debugger to add a logpoint...so I don't have to manually add console.log statements Thank you, this is the best thing I've learned in 2022.
- Vinnl 5y agoNext try https://www.replay.io https://www.replay.io, which allows you to add logpoints to code that has already executed.
- core-utility 5y agoThis was news to me too
- AdamTReineke 5y agoOne more trick: Add a conditional breakpoint with the condition: `value = "someOverrideValue", false` to make the breakpoint change the value when it is reached without actually stopping execution. Great for when you need state changed but the app is always trying to override it. Here's a video from a talk I gave five years ago that demonstrates that: https://youtu.be/uixXOTCNbhs?t=1182 https://youtu.be/uixXOTCNbhs?t=1182
- moritonal 5y agoThere is like... four people I know I could send this to who'd laugh, it's so niche. Yet I also laughed out loud when I got how conventionally impossible it is.
- cco 5y agoAs someone that works at an authentication API company, there are _dozens_ of us who found this hilarious. > Yet I also laughed out loud when I got how conventionally impossible it is. Maybe give it a whirl with https://sha256algorithm.com/ https://sha256algorithm.com/? haha
- eganist 5y agoI ended up crossposting it to the few security rooms I'm in for quick laughs But for what it's worth, this also serves as a great initial CTF-type introduction to how debuggers work in web browsers.
- jerf 5y agoIf the debugger is open, Passwordle automatically breaks the execution right where the answer is determined. Now that's service.
- umvi 5y agoTIL there's a "debugger" keyword[0] in JavaScript that auto-sets a breakpoint at that line. [0] https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Statements/debugger https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...
- therein 5y agoint 3 of Javascript. I use it all the time because webpacked assets make it hard to find the line of code I am looking for.
- 5y ago
- Drew_ 5y agoThis is begging for a hard mode option
- moscovium 5y agoI laughed. I can't wait for this to be used as a problem on some CS final.
- testelastic 5y agothis is insanely funny
- skilled 5y agoWhat the hell.
- quantumite 5y agoThis is hilarious, I love it! I've already shared it half a dozen times...LOL!
- teatoli 5y agoWhat exactly is this showing ?
- dskloet 5y agoIt's Wordle but it hashes your guess before applying hints.
- barbazoo 5y agoIt's a clone of the popular wordle game where you have to guess a word, except here, you have to guess a password but instead of telling you which characters of the password are correct it tells you which characters of the corresponding SHA-256 hash are, which makes this pretty much impossible to solve as the whole point of a hash are that small changes in the input (such as a different character in the password) results in big changes in the hash.
- core-utility 5y agoHard mode: Password + Salt
- davidfactorial 5y agoOh my goodness this is the out loudest I have laughed at a tech thing in a long time. Cheers to you :)
- judofyr 5y agoPlain SAH256? Come on, use a salt please!
- c0nsumer 5y agoThinking about this a bit deeper, it's a pretty good system for explaining a bunch of technologies to others (those mentoring, etc). There's the reason why it's not possible to win via the front door, how basic client side JS apps are put together, basics of using debugging tools...
- nathias 5y agomaybe wordle is just a frontend for a human powered distributed dictionary attack
- hbn 5y agoI won*! *grabbed the expected hash from judgeEvent(), then made hash() return it edit: I see from other comments he actually pre-loaded randomPassword() with a debugger statement. Oh well!
- marginalia_nu 5y agoI've tried 123456, password, and secret, and I'm all out of ideas.
- takeda 5y agohint: it needs to be 14 characters
- remram 5y agoSo password123456 then?
- VanillaIceWater 5y ago
- boothby 5y agoGot it in one "guess." Apparently どうぞ means "here you are." Makes me think the brick was deliberately left in the door for folks who look for such things.
- samwillis 5y agoMy wife was looking at me when I opened this. “What are you grinning at?” I just locked my phone and put it face down on the table…
- jdthedisciple 5y agoWhy would you do that xD - I'd have explained it to her instead, doing what you did I'm not sure I'd be happy about as wifey ...
- qzw 5y agoYou see, if he does that when it’s perfectly innocent, then his wife would be conditioned to ignore the behavior in the future. So when he’s truly up to no good at some point, he won’t be doing anything different than “normal”. The man is probably some kind of criminal mastermind.
- samwillis 5y agoHa! Quite true, maybe poor attempt at humour stopping the story there. I actually did explain after that ellipsis, her response: “That’s niche!” She is also well aware of what hashing is.
- dezmou 5y agodo I gain a bitcoin if I win ?
- Anunayj 5y agowell if you manage to break sha256, sure you do ;)
- ledoge 5y agoAlso see dwordle, where you have to guess a function pointer: https://twitter.com/zhuowei/status/1482175505185095682 https://twitter.com/zhuowei/status/1482175505185095682
- aspyct 5y agoAaah this hurts my brain
- travisgriggs 5y agoThey cynical side of me notes what a great phish this could be. People are inclined to enter passwords they regularly use just to see the visualization of their favorite passwords. With a little logging -> send home, you'd be harvesting passwords left and right.
- peanut_worm 5y agois a password very useful without any other identifier though?
- deleted 5y ago[deleted]
- grp000 5y agoWould the type of people amused by this have that weakness though?
- hbn 5y agoIt's hosted on Github Pages which is just static file serving. And thanks to CORS restrictions I don't think you could phone home. Unless there's a workaround I'm not thinking of.
- heartbeats 5y agoCan't you embed off-site images?
- jamespwilliams 5y agoGitHub pages are served with Access-Control-Allow-Origin: *, so the SOP doesn’t apply. They also don’t set a CSP header, which opens up the opportunity to exfiltrate data by other means, e.g having the browser load an image on your.site/$password.jpg.
- hbn 5y agoAh right. Simple!
- moltenguardian 5y agoSomeone more capable than I should make the final form of this: No green or yellow feedback is provided, but only the timing information used to calculate it. If cryptographers are serious about side-channel attacks, why not show off the danger using no-information Wordle? (edit: Absurdle was taken)
- p4bl0 5y agoAbsurdle already exists: https://qntm.org/files/absurdle/absurdle.html https://qntm.org/files/absurdle/absurdle.html ;)
- Narishma 5y agoThey should name it something else as absurdle is already taken. https://qntm.org/files/absurdle/absurdle.html https://qntm.org/files/absurdle/absurdle.html
- brainfish 5y agoAn Absurdle exists[1], but instead of giving no hints it is adversarial, e.g. changing the secret word to dodge your guesses. [1] https://qntm.org/files/absurdle/absurdle.html https://qntm.org/files/absurdle/absurdle.html
- SamPatt 5y agoThat's actually quite fun!
- pvity 5y agoIf you like this, you might like Quantum Childminding too: https://www.puzzlescript.net/play.html?p=f7712f978d624c66f1f2dd9cb0b47f82 https://www.puzzlescript.net/play.html?p=f7712f978d624c66f1f... It's about looking after Schrodinger's daughter; similar to the above, she appears only if you prove she cannot be anywhere else. I like this game a lot, especially how it's easy to understand & fun to play with.
- rf_pcb_designer 5y ago
- gfody 5y agothis would be a good variant for Grant Sanderson to point his information theoretical solver at as a way to educate us on how/why sha256 leaks information that might be leveraged to crack a password, why to salt our hashes, etc.
- agys 5y agoMore or less how PoW works…
- burke 5y agoThis would be kind of fun to write a solver for. You'd burn the first few guesses to get some positional constraints, then filter a rainbow table down to viable guesses. I'm not sure you'd be able to get a very good success rate in just 10 possible guesses though.
- onionisafruit 5y agoIf passwordle had a list of all possible solutions like wordle does, this would be doable.
- jfk13 5y agoIf it had a list of all possible solutions, it'd take quite a bit more bandwidth to load...
- FabHK 5y agoIt could work theoretically (the password contains around 90 bits, and from each row you can glean, dunno, some 64 bits of info (64 characters that can be yellow, gray or green, so 101 bits, but there are constraints on that - very unlikely that all characters are gray, for example)). In practice, I don't think it's computationally feasible. You can't keep all 2^90 = 10^27 possible solutions around in memory. Bitcoin does 200 EH/s, so 2e20 hashes/s. So the entire bitcoin mining network would have to work for 2 months (5e6 seconds) or so - don't see how you can meaningfully reduce the work (it would indicate a flaw in SHA256, no?).
- runnerup 5y agoTo me it seems like the password is 14 bytes, because they're 14 characters (112 bits). How do you get 90 bits? It also uses 96 possible characters for each digit. Just storing the 96^14 different passwords without even adding their corresponding SHA hashes would require 5646 yottabytes. Which is more than 4 orders of magnitude larger than all the world's digital storage capacity combined together.
- 5y ago
- dschulz 5y agothe wordle craze is getting out of hand
- rabuse 5y agoSolved mine in Firefox, using the JS debugger, and viewing the scope of the randomPassword function. "nSQXy3Qwl3E<qV". All your wordle are belong to me!
- umvi 5y agoYou could do a version of this with a two-way function like base64 and it would still be possible but very difficult without programmatic guessing.
- daneel_w 5y agoThere's something interesting to note in the visualized gradient distribution after guessing some common English words: https://i.imgur.com/hDSBaYw.png https://i.imgur.com/hDSBaYw.png
- eganist 5y agoThat's a consequence of certain characters not reappearing in the hash as compared to the hash of the actual password. This would become more apparent if this traded in sha512s instead.
- MailNerd 5y agoPlease do not use SHA256 for storing passwords, use Argon2 ;)
- syngrog66 5y agobrilliant. now someone do this for Bitcoin/Ethereum address private keys (asking for a friend. cough)
- Kluny 5y agoIt's not hunter2, correcthorsebatterystaple, password123, swordfish, or my gmail password. Anyone got it?
- susrev 5y agoThis is great fun. Thank you.
- d--b 5y agoJust checked the source, I am so sad that the answer is actually random. Couldn't read the comments in Japanese though
- VanillaIceWater 5y ago
- dorianmariefr 5y agopassWORDLE 1/1064 0 ⬜0 https://rsk0315.github.io/playground/passwordle.html https://rsk0315.github.io/playground/passwordle.html on Chrome, open Dev Tools and type `res` to get the password :)
- Thorentis 5y agoGee, I'm so glad somebody posted this so that I can cheat on a game that is not competitive and that I'm playing voluntarily and that has no bragging rights because of how niche it is.
- IncRnd 5y agoYes, but the point is to show that each password produces a sha256 not correlated to the sha256 of other passwords. That people actually tried to guess this way shows that not everyone is aware of the sha256's purpose.
- KerryJones 5y agoNot defined for me
- circa 5y agoI feel like Kramer with the moviefone number. "why don't you just tell me..."
- srinathkrishna 5y agoI was expecting the hash to be MD5 to at least give people a chance! :D
- srinathkrishna 5y agoAt least let people change the hash function to MD5 to give them a chance! :D
- twopsix 5y agoSeems kinda impossible to do, lel
- pjerem 5y agoWell, that’s not "dolphins".
- manceraio 5y agoThis is a masterpiece.
- CGamesPlay 5y agoWordle has a "hard mode" where guesses aren't accepted unless they reuse hints previously given. This is clearly missing from this adaptation.
- stevewodil 5y ago0/10 literally unplayable.
- wbecher 5y agopassWORDLE X/10 5 46 ⬜13 5 46 ⬜13 1 44 ⬜19 4 46 ⬜14 5 42 ⬜17 3 42 ⬜19 6 44 ⬜14 0 45 ⬜19 5 41 ⬜18 3 43 ⬜18
- deleted 5y ago[deleted]
- testelastic 5y agoThis is insanely funny
- deleted 5y ago[deleted]
- girafffe_i 5y agoIncredible. Lol'd pretty hard.
- o4b 5y agoI have not laughed like this for weeks. Well done OP.
- IMAYousaf 5y agoI will successfully solve this one day.