5 ms·
I wonder if it ever becomes viable to try to brute-force the private key of such a valuable address, rather than devoting the brute force power to mining. Edit
by rheide 13y ago
I wonder if it ever becomes viable to try to brute-force the private key of such a valuable address, rather than devoting the brute force power to mining.
Edit: got curious and found an answer: http://bitcoin.stackexchange.com/questions/2847/how-long-would-it-take-a-large-computer-to-crack-a-private-key http://bitcoin.stackexchange.com/questions/2847/how-long-wou...
If I understand correctly, it's still not viable even if you tried your brute-forced keys on all addresses in the network.
- cpach 13y agoSo much easier to crack the box holding the key.
- ams6110 13y agoWhich is why the key hopefully isn't stored on any system that is remotely accessible.
- nwh 13y agoGiven it got broken up into 4000BTC chunks after the box TX, we can assume they are on paper wallets, probably distributed up using secret sharing. That's standard in the Bitcoin world.
- qixxiq 13y agoI'm not sure people are aware/scared enough of possible physical access. People have been kidnapped / banks robbed / etc for far less than $150MM.
- ye 13y agoThat's the cool thing about Bitcoin. You can create a wallet on a completely offline computer or even a virtual computer, save the address and the private key, and send the money to it. You only need the internet connection to do something with the coins.
- pfortuny 13y agoProbably a well-crafted phone call would be as useful... "I am the administrator of MtGox, I need you to send us a copy of your private key..."
- johnchristopher 13y agoI seriously doubt it would work for the key(s) related to that $150,000,000 transfer.
- Zoomla 13y agohacking people on #bitcoin, #bitcoin-otc, etc. on freenode might or might not be a good start
- phaer 13y agoIt might become the lottery of the 21th century. ;)
- nwh 13y agoThat's the entire point of asymmetric crypto, the amount of effort you would need to brute force 2^160 keys is staggering. Even if you made billions of ASIC processors and ran them until the end of time, you probably wouldn't find the funds you were looking for. This is constantly suggested, and it's always useless. If you could attack keys like this the system would be broken.
- mikeash 13y agoIt's important to note that asymmetric crypto behaves somewhat differently. RSA is a particularly notable example of this: a 160-bit RSA key is almost trivial to break, 512-bit keys are possible, and there are good reasons to think that large organizations with lots of cash and motivation are able to break individual 1024-bit keys when they want to. The ECDSA keys used in Bitcoin are much stronger than RSA keys at the same size, and they seem quite safe, but don't make the mistake of looking at the time needed to brute force e.g. a 128-bit AES key and assume that applies to asymmetric algorithms too.
- maaku 13y agoNo. What the GP is quoting is "security bits" a measure explicitly designed to mitigate that difference. Bitcoin addresses have 160 bits of security, 128 bits if the public key is known. This is directly comparable to symmetric key sizes.
- mikeash 13y agoThanks for clarifying that. The mismatch between the key size quoted and what's used in Bitcoin should have tipped me off.
- meowface 13y agoIt's completely infeasible (without quantum computers anyway). However, in cases where the private key is generated from a hash of a passphrase, like brainwallets, then it is far more feasible. There are people running bruteforcers constantly looking for private keys corresponding to brainwallet passphrases; that's their form of "mining". To test it, if you make a brainwallet with a password of "password" and then send 0.01 BTC into your account, you'll see it vanish in a few minutes (or a few seconds).
- deleted 13y ago[deleted]
- ars 13y ago> What about looking for keys generated using the broken Debian RNG? You'd need a time machine, and if you had one I can think of better uses. Actually even a time machine wouldn't help since bitcoin showed up long after the RNG was fixed.
- deleted 13y ago[deleted]
- waps 13y agoI don't think so. Brainwallets are generated as a hash. So if the input is secure, the output is secure. It's not possible to generate the input from the output. And frankly the connection between password -> private key and private key -> public key is very similar in brainwallets. To crack a brainwallet, given only the public key and sufficient bits in the password, is actually harder than directly attacking the private key. Plus you have to balance "my own fuckup" risk against "someone attacked me" risk, right. Wallets depend on your backup habits, and you backup provider's security. Going through the fora, I'd say "oops. I lot my wallet.dat" is a much more serious threat to your bitcoins, on average, than someone got a hold of your password. Both of those, for most people (including me) are ... lacking. Brainwallets depend on my memory for passwords. A hardware brainwallet would guarantee you're 100% not exposed. As for ECSDA attacks. It's true that the algorithm itself is near-unhackable. However, make one single transaction on a computer which chooses a non-random k value, and you're exposed. So the risks don't end just because