Toddler Password – Get a secure password generated by a toddler
toddlerpassword.com
toddlerpassword.com
We have these things called stream ciphers. You put a little bit of randomness in, and you get what seems to be lots of randomness out. For example the cipher might need a 256-bit key and 128-bit nonce and then spit out gigabytes of seemingly random data.
Now, mathematically they can't /really/ be making more randomness, there's no random steps it's all deterministic, in principle it ought to be possible to unwind the steps and get back the initial random state. But it turns out that unwinding step just can't actually be done with a good stream cipher, that's the whole point.
We do this sort of stuff a lot in real modern cryptography. There's a HN article which might still be on the front page, it was earlier today, explaining how SSH works. It shows that six keys are needed for SSH encryption, but they don't go get six times the randomness you'd need for a single key, they can just use a cryptographically strong hash function and make six different keys from the same shared secret randomness.
Let's do an experiment:
I've rolled my hex dice a few times to create a 64-bit random number.
I've pushed that as ASCII text into MD5 and got back a result, and now I'm going to tell you the first and last characters of the result:
F31FB042................81AFD8FA
That's 64-bits. If you were correct with this idea about entropy you could tell me what the missing bits are, infact you could prove it to other posters - after all I have given you all the randomness according to your thinking, there can't be any left.
But in fact you have no idea what those missing bits are, no idea what the original 64-bit number was, because you are wrong, with cryptographic primitives like hashes or stream ciphers we can in practice take a relatively small amount of entropy (like a few minutes of keyboard bashing by a toddler) and that's enough for all purposes.
The _real_ reason you shouldn't use this to make passwords is that the site might be lying and keeping a record of every password that is chosen and which IP address it was given to etcetera.
Brute forcing 2^64 bits means calculating 2^63 MD5s in expectation. You can do ~100 GHash/sec, so ~2^37/s, so about 2^29s which is 17 gpu-years. So this is doable, but incredibly expensive.
MD5 and SHA are specifically designed to be fast to compute, they shouldn’t be used for passphrases.
Figured I’d bring it up in case there’s still PHP floating around with the once-typical practice of MySQL + MD5.
It was tempting to pick say 128-bits of randomness and SHA-512/256 where I'd stake actual money that it just cannot be done - but that's like twice as much die-rolling and typing. On the other hand if I do 32-bits (fewer rolls) and MD5 there's probably some loser out there who has already precomputed all of those for whatever reason and then somebody finds the answer with a Bing search and doesn't end up learning anything.
echo -n 'F004672790DB5B1D' | md5sum
f31fb042501c2a398974feca81afd8fa -I suppose I thought of 64bit as now being small. 48 would be doable.
Well obviously, how was this business going to scale? Op can't keep making more kids in case the business really takes off.
Not saying that's what's being done here, but it's a way to take fairly nonrandom activity and get decent entropy from it.
Guessing he's using 2 hands most likely you will get characters around the 1st one he pressed, so if you get a 's' character first, you can expect qweadzc near, but going from a 's' to a capital 'P' and then to a ! doesnt look legit to me
http://www.rengelbert.com/winston/
ydwew346rr764847uruejdjeyytr4t5t5ty8uoff jfgjjhv rr rgr r rrrrh jjjhhhju5m
ytj8ikm ,k88o0pfffuyhfjdjuddjcie8kdduuukjfuruuryfuuugtt767yut67y7hcfght h7tyty5y6 uyhtryty gyfg
huy tyhrty7 ruy6t5y5777h hyuyu utygj tgytu jtgtu 5ugjuy 5676uvu 2355 hfhghhhhhu7uuuytutut juyy
umnhjbbvvgyy6tg7777.
bdy7er64y5y574757r04iiiiiutweepiroeiwijwdryyt h7f77fuuvyf77f7uuyutuhturghghyhyggyvbg fyr
gfrt6rfytyftr6 tryy hyyyy675g ttyty57 htgtt6t667 t65r7745
y6767nghnggugg7uuupooooooiuuuuytrewq kkha bcx
gtytttmhguyuuhuuuygyufh7673y7rtty7yggffrtdyteryurijrf
uu4hfyuytttgt7t7yrfyrtuyuI guess the author wanted his site to have mild educational value, in that smashing your keyboard generates passwords stronger than the average password picked by people.
https://www.gettyimages.com/detail/photo/cute-baby-boy-sitti...
Why does this need analytics and thus tracking cookies? I'm genuinely asking. What kind of data does this even need tracking?
Even if it weren't due to the keyboard's fixed layout (between two smashes), it's largely because of our non-random nature — a human being cannot reliably output random objects even in thought / speech. Don't ask me why (I don't think anyone knows or could prove it theoretically) but it's been verified countless times (war secrets help make such research important).
We're at best capable of pseudo-randomness mathematically. Some controversial neuroscience even places us far into the deterministic scope. A child is probably way more determined than an adult for that matter, due to a much simpler schema of reality, with 'weird obsessions' (e.g. it feels nice to smash the same place over and over again, our brain is quick to play games like that, such as walking on specific tiles to avoid the lava in the street).
I wouldn't trust most animals to output randomness. We have crypto packages suited for that purpose. ;-)
> Knowing what the computer will guess, you can guarantee that it is always wrong by picking the other direction. Doing the opposite of what a computer tells you isn’t quite free will though!
Seems like someone is using the imagery of a cute child to make a few extra bucks, at best.
Joking aside, will I break this if I request too many characters? Does it loop after running out of Max's prior input? Is Max really just a script?
What's likely is the kid's input was used as a seed (string to int?) and then put into a random number generator.
Kind of cute :)
Questionable
the limitation is the speed at which the human can translate that entropy into machine readable data
In 2034, all the passwords will be "lol duh"
I have a feeling toddlers might be worse than other entropy sources.
https://twitter.com/lukevers_/status/1181217729216425984 https://twitter.com/lukevers_/status/1181217968287559680
I have a toddler, so I identify. She constantly mashes my laptop keyboard, often deleting large blocks of code or typing gibberish into slack.
My biggest revelation here is how terrible the new MBP keyboard is. Just a bit of keyboard mashing and many keys are rendered useless. They require some gentle massaging to get back to a semi working state.
Bad idea?
password 20 high
password 10 low
"frosty starfish snuff bluff"