4 ms·
Something I don't understand: how are UUIDs not safe given that they are probably better than 99.9999% of passwords generated by users?
by human 4y ago
Something I don't understand: how are UUIDs not safe given that they are probably better than 99.9999% of passwords generated by users?
- rr808 4y agoUUIDs are nearly half the mac address of the server + a timestamp. They are in no way random.
- throwanem 4y agoThat's UUID v1. The random one that everyone uses is v4.
- kube-system 4y agoI have seem some common libraries that default to v1, so I can see why there’s some confusion in here.
- nordsieck 4y ago> Something I don't understand: how are UUIDs not safe given that they are probably better than 99.9999% of passwords generated by users? UUIDs are 128 bits. Which is beat by a 5 character a-z random string. It's certainly possible that they're better than the median password - especially if there isn't a check against a common password list. But it's pretty easy for user chosen passwords to be much, much better. I strongly doubt that your 6 9s estimate is accurate.
- prutschman 4y agoA 5 character a-z random string has log2(26^5) =~ 23.5 bits of entropy, way less than 128.
- deleted 4y ago[deleted]
- andreareina 4y agoThe best case for a 5 ascii character password is 7 * 5 = 35 bits.
- lolinder 4y ago> UUIDs are 128 bits. Which is beat by a 5 character a-z random string. A sibling gives the actual math that shows how wrong this is, but this doesn't even pass the most rudimentary sniff test. The most common encoding for a lowercase string would be in 8 bits per character, so a 5 character string can get you at most to 40 bits. And that's assuming you allowed every one of the 256 possible characters. You're restricting it down to 26 characters. EDIT: I was curious, so I checked. Even if you allowed every current Unicode character, 5 characters only gets you to ~86 bits of entropy: log2(149186^5) ~= 85.9 As for the original 6 nines claim, I also calculated the entropy for a 14 character random password that allows all 62 letters+numbers plus 8 special characters: log2(70^14) ~= 85.8 It's not until 20 characters that it matches a UUID v4. So, yeah, I'm okay with OP's 6 nines.
- pmontra 4y ago128 bits are 16 bytes, which is at best a binary string of 16 characters. Remove some bits for the not random parts of the UUID and still you don't get down to 5 characters. Furthermore "a 5 character a-z random string" is less than 5 bits per character. Make them less than 6 by adding A-Z and the ten digits. About storage, at least PostgreSQL has been using 16 bits of storage since at least version 8 many years ago. https://www.postgresql.org/docs/current/datatype-uuid.html https://www.postgresql.org/docs/current/datatype-uuid.html https://www.jacoelho.com/blog/2021/06/postgresql-uuid-vs-text/ https://www.jacoelho.com/blog/2021/06/postgresql-uuid-vs-tex...
- monocasa 4y agoDoes your UUID library use a cryptographic safe RNG?
- lolinder 4y agoJava's does, and that's the implementation the article discusses.
- lll-o-lll 4y agoBut this is the point though, UUID is the wrong tool for the job. You want a cryptographically random blob of entropy and you reach for a UUID because it happens to contain some of that in a specific implementation. UUIDs are for uniqueness and involve implicit trust. Cryptographic libraries are what you need to generate entropy blobs without weakening security/confusing the next developer etc.