5 ms·
Is anybody using this private key?
- joemazerino 1y agoA "dumbass" counter on this site would be interesting.
- kekebo 1y agow/ signed counts
- cryptonym 1y agoIt shows on the response, when you send your genuine private key.
- skrebbel 1y agoCan confirm
- benmmurphy 1y agoVery strange. I sent a test key and didn't get that response but when I sent my real key it did. How did it know the difference between the dummy key and the real key?
- inetknght 1y agoprobably checking the corresponding public key against known public keys in various places
- didgeoridoo 1y agoIt doesn’t, only you see that. The owner of the site just sees *****.
- mondobe 1y agoYou only see hunter2 because I copied and pasted your stars. I just see ****.
- DonHopkins 1y agoHe should install Wordpress! It has lots of dumbass counters. https://wordpress.com/plugins/browse/counter https://wordpress.com/plugins/browse/counter
- smidgeon 1y agoThank goodness, now I know my private keys have not been leaked ...
- qualeed 1y ago"256 bits AES Encryption" should really have a "Military Grade" stamp on it. Perhaps with a metal background and some rivets or whatever for emphasis.
- mdaniel 1y agoI guess it's to be expected, but the IPv6 Ready is bogus, too ; <<>> DiG 9.10.6 <<>> AAAA isanybodyusingthisprivatekey.com. ;isanybodyusingthisprivatekey.com. IN AAAA
- ignoramous 1y agoDo not give out your private keys anywhere except where they're needed. They are meant to be private for a reason. If this service was serious, it'd instead rely on fingerprints (sha256/sha512) and not the key itself.
- mr_toad 1y agoIs there any case where they ever need to be shared? If you need a login, generate a new one.
- chrisweekly 1y agoYeah, I'd strike "except where they're needed". Never share a private key.
- IgorPartola 1y agoOne of the best things you can do is generate a key per device, not per person. That way if you lose your phone you just revoke that key and not the one that you use on your tablet, work laptop, home desktop, etc. Bonus points: monkeysphere and certificate based auth are two other great solutions for making sure the ssh server you log into is not doing a MITM on initial connection (you know, the part where it asks you to manually verify the fingerprint of the server key and you likely just hit y instead). Forwarding your ssh agent to a host that you don’t know for certain is not doing a MITM attack on you can be devastating, as is entering a password into same.
- munchler 1y agoBut that way you can only use each key on that one device. E.g. No starting a private conversation on your phone and then continuing it on your desktop later.
- IgorPartola 1y agoThe service you use should allow you to add more than one key and create a symmetric encryption key for the conversion. Your private key identifies your device, the service should know that you own multiple devices.
- ivanjermakov 1y ago> Guys this is just a meme website. Please do not submit your real private key and do not report phishing. Exactly what a phishing website would say.
- comrade1234 1y agolol. You're kidding me...
- BenjiWiebe 1y agoCloudflare's 1.1.1.1 for families blocks this is phishing. No sense of humor I guess?
- StefanBatory 1y agoOn my home PC Avast blocks it too.
- actinium226 1y agoHahahaha, this is hilarious!
- DonHopkins 1y agoNicely done! It worked flawlessly for me the first time. Does this support bulk upload?
- alberth 1y agoInstead of HaveIbeenPwned.com, maybe the name of this site should be HaveIbeenKeyed.com
- gblargg 1y ago> Is anybody using this private key? They are now!
- TheRealPomax 1y agoIf this is just a meme website, just... take it back down? People are dumb, they are going to fill in real keys, and you knew this before you clicked "deploy".
- nailer 1y agoMy private key came from Debian, they patched the issues reported by Valgrind and now OpenSSL is more secure than ever.
- thasso 1y agoWait why did it say the key was unused when I submitted the first time, but now it shows the key is already taken?
- isoprophlex 1y agoIt could be a bad actor pretending to be a meme actor pretending to be a bad actor
- nativeit 1y agoPresumably, they took it.
- gnyman 1y agoI'm confused by this one. It says it's a joke but it still submits the key to a server. These joke pages have been around since http://ismycreditcardstolen.com/ http://ismycreditcardstolen.com/ And I even made my own version https://hasmypasswordbeenstolen.net/ https://hasmypasswordbeenstolen.net/ The difference is that neither the original nor mine actually submits the secret to the server. I went to great lengths to avoid actually doing it, it's still a bad idea to send a password to my page but at least you can check the source and network traffic and see that it's only checked with JavaScript and a hash is checked against the HIPB password site. This supposed joke site sends and processes the key on their backend. At least it looks like that, I have not tried with a real key.
- Arcuru 1y agoYea..sending it to the server makes it look sketchy. Even for my joke site[1] I make sure everything stays client side. [1]: https://faxyourballs.com https://faxyourballs.com
- knowitnone 1y agoGenerate and send it every possible key
- nativeit 1y ago> The maximum cycle length is 2256 ≈ 1.16×10^77 iterations. If you can evaluate 10^12 hashes per second, then working your way through all possible hashes would take you about 10^65 seconds (about one quindecillion times the age of the earth). Even if you're fortunate enough find a loop in a tiny fraction of that time, you're still liable to be waiting for trillions of years. https://stackoverflow.com/a/43636715 https://stackoverflow.com/a/43636715 Edit: fixed missing exponent notation
- nullc 1y agoHey, that's not the wallet inspector...
- ghusto 1y agoThe word you're looking for is "joke" not "meme", but that isn't hip enough, right?
- daft_pink 1y agoI got invalid captcha :(