The whole confusion comes from the fact that tor domains have this random string added to the name you actually want to take, right?
The whole confusion comes from the fact that tor domains have this random string added to the name you actually want to take, right?
Anyone can generate a key with a vanity prefix, it just takes computing power and the longer the match, the greater the computing power involved.
It seems like everything except the 'i' is a prefix, a lot of computing must have went in to generating it.
One tool to do it is called 'Shallot' https://github.com/katmagic/Shallot
The readme includes a table of estimated computing time required. A 15 char prefix like Facebook's is not even on the table, and a 14 char prefix is estimated to take 2.6 million years. There is also a GPU version which should be an order of magnitude faster: https://github.com/lachesis/scallion/blob/gpg/README.md
Also, technically. the onion addresses not public keys, but derived from a public key. It's actually a hash of the public key.
It appears that the hashing algorithm used is SHA1. Source: The last few lines of the easygen function https://github.com/katmagic/Shallot/blob/master/src/math.c
We tried the same thing for PinkApp and got all sorts of much-longer matches that we could retcon into meaning something.
It shouldn't make any difference how the keys were generated.
If Facebook can generate an address with only a single character being random (the trailing ‘i’), couldn’t an attacker generate anyone’s address by just applying 26 times more computing power?
Either Facebook didn’t target the trailing “corewww” or the .onion URL scheme is broken (since Facebook would be able to take over any .onion URL by just spending 26 times as much compute power as they did with https://facebookcorewwwi.onion/).
Also something you may be interested in: OnionNS https://www.freehaven.net/anonbib/cache/onion-ns-pets2017.pd...
[1]: https://tools.ietf.org/html/rfc7686
[2]: http://www.ietf.org/mail-archive/web/ietf-announce/current/m...