4 ms·
> Normally, it is undesirable for users’ passwords to be cracked. However, in the case of law enforcement, we often need to obtain suspects’ passwords in order
by mcpar-land 1y ago
> Normally, it is undesirable for users’ passwords to be cracked. However, in the case of law enforcement, we often need to obtain suspects’ passwords in order to access encrypted evidence. The obvious solution is to build powerful (and expensive) dictionary cryptanalysis computers. A less obvious approach is to use the distributed power of web users’ computers, as has been done in the Seti@Home (https://setiathome.berkeley.edu/ https://setiathome.berkeley.edu/ — suspended project) or Folding@Home projects (https://foldingathome.org/ https://foldingathome.org/). The proposed approach can therefore support law enforcement activities while providing the desired functionality to the web community
"You're not allowed to visit this website unless you submit your computer to being part of the fed's password cracking botnet" that's a whole fresh hell. A better use case is right there in their own description! I'd love my captchas to be little Folding@Home problems.
- ronsor 1y agoCan't we just submit bogus hashes?
- sieabahlpark 1y ago[dead]
- ethersteeds 1y agoGenerally that is countered by asking for a mix of known and unknown solutions; your accuracy on the unknown is assessed through your accuracy on the known.
- GoblinSlayer 1y agoBut there are only a few suspect passwords, you can just know all of them, and thus reliably differentiate.
- VladVladikoff 1y agoIs it possible to do some other sort of cryptographic trick than simply seeding the mix with known and knowns. Some sort of sum of many answers combined? Maybe it isn’t possible in this use case though (brute forcing passwords). For example is crypto POW really just doing a mix of known and unknowns or is there more cryptographic magic to it than that?
- downrightmike 1y agoThat is shady as hell. Welp this is dead on the vine
- GoblinSlayer 1y agoBitcoin network used to bruteforce 85 bits per year, which is slightly bigger than capacity of [a-z0-9]{16}
- tiagozip 1y agobtw no, cap does not contribute to any "fed botnet". you can build the WASM binaries yourself and compare the hashes. added a clarification about that to the docs.
- p0w3n3d 1y ago2030: to enter the site you must allow us to mine few ethereal on your pc...