Representing SHA-256 Hashes as Avatars
francoisbest.com
francoisbest.com
# sha3sum <<< 'textprotocol@github' | urbit | sigil | convert svg:- jpg:- | jp2a -
It’s less useful once you realize that if you can attack the SHA you don’t need to get one exactly matching, just something that causes a “similar” color scheme.
in the end, onces ubiquity sets in, the novelty wears off and every website blurrs into a single undifferentiable mess.
theres no escape from educating users
[1] Create as much perceptible variation as possible - TV static and minor color changes are not. [2] Make representations humans can remember - faces or images over abstract objects/shape color combinations [3] Make generating each representation expensive, so that searching for a visually similar fingerprint is expensive.
IMO most hash visualizers fail at all 3.
[3] is similar to hashing itself, except "visually similar" is substituted for "exactly equal". This is already taken care of by the hashing algorithm if it is slow, e.g. password hashing algorithms.
[1,2,3] could be solved with a GAN. Note that the GAN does not have to worry about making similar hashes produce dissimilar outputs, because finding a similar hash is already hard.
Seems like you need something like a small cartoon with variables like: 1-8 characters, 16 skies (moon, sun, storm, windy, snowing, hail, etc), 32 scenes (playground, beach, office, home, yard, forest, ski slope ...), species of each character, emotional state, etc.
Then people would remember things like 4 characters, it was snowing, and a mad cat was talking to a sad dog and 2 kids dancing on a mountain top.
Because: (EDIT: Unfortunately, HN seems to strip emojis).
1..n..8 characters, assuming 1000 emojis, is somewhere ~along 1000^9 bits of emoji.
16 skies is 16 bits of entropy.
32 scenes is 32 bits of entropy.
You multiply those together, and you get 5.12e29, or 2^98. That is considerably smaller than 2^256.
-----
To get to 2^256 bits of entropy with an emoji set, you need 25 emojis. That's very long. That's like (HN stripped emojis).
Can you tell a difference between that and ? At a glance?
Seems like the best you can hope for is enough bits in a fingerprint that users can tell when it changes and make it harder to find a fingerprint that fools the user.
https://code.sgo.to/2021/06/14/sha256.html https://code.sgo.to/2021/06/14/avatars.html
Amazing work.
You could also easily switch the GAN for different types of hash-like sequences, e.g. people for public keys, cats for bitcoin addresses, etc
https://medium.com/@elg0nz/what-are-ssh-fingerprint-randomar...
Well, admittedly just a feeling. I have neither done the math nor any testing how big differences are likely to go undetected.
The best verification in openssh is to copy-paste the correct fingerprint as an answer instead of replying yes/no.
Not trying to be difficult. Just looking for technical possibilities.
Or sharing a screenshot of the avatar on signal to confirm its authencity?
QR codes are for computers to read. These are for humans to read.