How to steal Bitcoins that are protected by weak passphrases
palkeo.com
palkeo.com
Edit: I can upload some rather large and confusing transaction network diagrams if anyone wishes to see them.
I have a few more but they are even more confusing. Red nodes are brainwallets and blue nodes addresses that brainwallets transfer to. You will notice the massive cluster on the left, that is the 'researcher' who is actively probing the network.
The rest are standard brainwallet transactions and thefts.
The big red dot is a bug :P
Hope that was useful
> "Yes, the creator of Brainwallet.org got his start with password based private keys by cracking them. Here is an old IRC log extract I pulled out for someone else who didn't believe this: https://people.xiph.org/~greg/brainwallet.txt*
More recently he really was in IRC asking for information on faster cracking mechanisms, right after whining about needing money. But uh, he might have just been trying to further convince himself that brainwallets really are secure and that it's really the users fault (or a MITM on the site) when they get robbed.
I'm less inclined to assume malice, and more inclined to assume that he's clueless— both of the insecurity of these schemes, the acceptability of blaming the victims when users inevitably choose poor keys, and how scammy his own actions look. But thats just my own impression.
When you choose to use something like that you should start with the assumption that the creator is malicious and ask yourself why its safe to use anyways. For the Bitcoin reference software you can point to the large amount of open public review, processes which prove the binaries agree with the source, etc. For brainwallet.org? Not much.
So if ever you find the prospect that the creator of something might be a bit black-hat and this concerns you thats potentially a red-flag."
Probably more concerning, the first "random" key the website displays is "correct horse battery staple", which people get their funds stolen from almost constantly.
http://blockr.io/address/info/1JwSSubhmg6iPtRjtyqhUYYH7bZg3L...
About a year ago, I generated the Bitcoin addresses derived from single-word passphrases in the English language. I then came across a "top 1000 passwords" list from a large site hack, and added those as well.
Finally, I set up a script that watched Blockchain.info's Websockets endpoint and checked every destination address against the list.
I quickly noticed that there were a large number of ~0.05 BTC transactions to these addresses, and a network analysis showed that many of them ended up in the same handful of addresses. Those addresses were tagged on Blockchain.info as being the destination for coins used to buy off the writer of the ransomware that was making the rounds at the time.
None of the money sat at those addresses for more than a couple of minutes. I'm fairly sure that the coins aren't being stolen from those addresses, but merely quickly run through in a feeble attempt to launder coins.
ETA: I suppose I should add that I didn't take any balances. I was merely satisfying my own curiosity.
It is possible that people would try to find their private key on directory.io for fun. You can do that by jumping to the relevant page. Meanwhile, the servers at directory.io would cache the GET requests and blast through the handful of keys on that page.
The site is likely generating the pages on the fly. You can type directory.io/<any number upto x>
x : 904625697166532776746648320380374280100293470930272690489102837043110636675
The site is definitely generating hashes on the fly. There is not enough known storage in the universe for all possible 32 byte private keys. To be more precise, 1E77 is within a few orders-of-mag of the estimated number of atoms in the universe.
The problem is that some moron can enter his private key there, to see what the site says about it. Then if the owner reads the server logs, he can read the private key. To be clear, never ever never ever never ever put your private key in a random website.
I hope that most morons only know the public address (that is a hash of the public key), and don't know about the private key that is stored in a wallet. In https://www.google.com/search?q=site:Directory.io the numbers are too low, so they are probably only a few random keystrokes, not "real" private keys.
You would think that the word "private" in "private key" would give them a clue... or do most people now not really understand the concept of privacy anymore?
Somebody did set up a website somewhere that allowed users to see if their private key was in the "database". It would jump them to the correct page, and, steal their private key in the process.
I didn't like them potentially stealing my revenue, so I implemented this feature myself. The pluses beside the private key are permalinks.
For example: http://directory.io/warning:understand-how-this-works!/5HpHa...
That's the private key in Bitcoin's importprivkey format.
I purposely didn't add a search box and named the URL's path to discourage its use.
(I don't actually check the logs)
Maybe put a big disclaimer in red on top of every page.
I think we need a lot more security awareness among the general population before Bitcoin becomes a mainstream thing. Right now, it's simply too dangerous to use Bitcoin with most people's security practices and their understanding of security.
"foo bar baz" is a terribly passphrase, for instance. "foo bar baz lyndsy@lyndsysimon.com" is a much better passphrase - it's trivial to use a bit of personal information as a salt, thereby providing substantial protection against non-targeted attacks.
Say I have a private key with some money. All I have to do is type 'importprivkey <private key>' in a new client and the money shows up (am I missing something)? If everyone randomly starts entering a couple of completely random combinations, is there a finite possibility that someone might simply steal a wallet? Is it like spinning a wheel of fortune?
Found a very interesting analogy here : http://www.reddit.com/r/BitcoinBeginners/comments/1uhuge/wha...
"Imagine you hide some money in a hole in the ground, and take note its GPS coordinates. Now imagine someone publishing a list of all valid GPS coordinates on the planet, down to 10cm resolution. In that list, there will be also the position of your money."
Your brain is not equipped to handle numbers on the scale of 2^-160.
If your unit is "the volume of the observable universe" you get a pretty large volume (on a human scale, anyway): https://www.wolframalpha.com/input/?i=%282^-160%29+*+%28the+...
edit: oh, the units came from the grand-parent post to yours, but wouldn't the correct conversion be "2^-160 earth's surface-areas"? That's actually bigger than the planck area- but still stupid small.
https://www.wolframalpha.com/input/?i=%28The+surface+area+of...
I'm not sure which finite probability is larger, but I'm not holding my breath for either one.
Edit: redit threads: http://www.reddit.com/r/Bitcoin/comments/1rua34/all_bitcoin_... http://www.reddit.com/r/Bitcoin/comments/1ruk0z/dont_panic_d...
Edit2: This is one of those basic security things I have trouble getting an intuitive grasp of (but need to). How much can being able to determine a random small part of a random large key space hurt? I've worried about this before with 256-bit key spaces and been reassured with calculations, but I still don't intuitively get it.
Why would anyone find this to be a good idea?
There are plenty of ways of avoiding losing a key, or generating pneumonics from secure keys.
However, obviously idiots who will pick a 2 word passphrase should not be encouraged to use a brainwallet.
I think that describes about 0.1% of the population, maybe 10% of whom are interested in using a brain wallet.
Brain wallets will appeal far more to the other 99.9% of people, who will of course use crappy pass-phrases.
First, for those curious, the passphrases of the wallets taken from so far:
19JsLFDRxuTsAjapE79FgoVNdNdB2hNU5M - "alfanumerico" (0.36875 BTC)
1PQiixL1SyytXoUGFBGA5ptW9uTjsBrdhX - "emergency" (0.00085 BTC)
1CqRJYoztkWifUYadFg13MHdmECx6uEdy7 - "butterfly" (0.00025 BTC)
16ga2uqnF1NqpAuQeeg7sTCAdtDUwDyJav - "password" (0.00085 BTC)
1HZwkjkeaoZfTSaJxDw6aKkxp45agDiEzN - "" (0.474972 BTC)
1HoSFymoqteYrmmr7s3jDDqmggoxacbk37 - "hello" (0.000555 BTC)
1C7zdTfnkzmr13HfA2vNm5SJYRK6nEKyq8 - "correct horse battery staple" (0.243762 BTC)
1JwSSubhmg6iPtRjtyqhUYYH7bZg3Lfy1T - "correct horse battery staple" (0.000079 BTC)
The implementation isn't particularly exciting. I have a PostgreSQL database containing a single `address' table storing (address, privKey, passphrase). Of course, the passphrase doesn't actually need to be stored, but I kept it around to satisfy my own curiosity. I run a modified bitcoind client that checks each transaction it hears about (in CTxMemPool::accept) to see if any of the outputs are in my database. If they are, a transaction is created, signed and broadcast to send the same number of BTC (minus fees) to 1brain7kAZxPagLt2HRLxqyc3VgGSa1GR.
I just wanted to point out that, when I started this, it was not for financial gain. I simply saw it as a fun and interesting exercise about the Bitcoin protocol. I wanted to see if I was capable to "winning the race" -- trust me when I say there are loads of people out there "mining" brainwallets, and whosever transaction is included in a block first tends to win and get the Bitcoin. I never expected to gain over 1 BTC, I think I got rather lucky. My database contains 19,412,020 passphrases (mostly single passwords, actually) which all came from various wordlists I found online. I consider this to be a fairly small dictionary, based on what I've read about other people doing the same thing. I originally had plans to make the database much bigger, however I've since moved onto other projects.
I'm happy to answer questions if people have any. There's a signed version of this comment at http://pastebin.com/s29kk2bb, which you can verify (rather ironically) at http://brainwallet.org/#verify.
Side note: I ran this attack months ago and you would be shocked at how many weak passphrases actually had money in them at some point.
This should give you fairly decent security.
Something that uses key stretching like WarpWallet might be acceptable: https://keybase.io/warp/
In the end, the best password right now is a 16+ random password made up of uppercase letters, lowercase letters, numbers and symbols. Use a password manager to manage and store your passwords.
echidna:~ gwillen$ wc -l /usr/share/dict/words
235886 /usr/share/dict/words
You get something like 17 bits of password strength per word, depending on the size of your dictionary. (The relevant xkcd estimates more like 11 -- which makes sense because /usr/share/dict/words has a lot of obscure words, shitty words, and alternate forms of words, that you would probably exclude when generating a password.)So if you want a passphrase that's secure against brute force, you'd want more like 7-12 words.
Simply enough to remember and harder to crack than most passwords in the world.
Full stop.
You should be very carefull with your Bitcoin.
I would go with one of the zero trust multisignature wallets because I like 2factor and I don't like the idea of some malware taking the funds away at will when it finds a key in memory.
There are safe(r) ways to use a brain wallet, but it shouldn't be done without understanding the math and the risks. At the end of the day, redundant and physically secure paper wallets will always be the best option.
The most promising web wallet i've seen so far is https://greenaddress.it which seems pretty much like "Electrum" online but with two factor which in theory means a local keylogger can't steal your bitcoin.
Anyway, if a brain wallet has a weak password, you have quite a good chance of cracking it easily. But you have to know that it's a brain wallet. But using a brain wallet is just silly.
Also, don't forget cracking private keys using weak signatures, although good luck finding someone who has a wallet and a weak signature...
http://www.nilsschneider.net/2013/01/28/recovering-bitcoin-p...
EDITED - I didn't read the post correctly, my apologies.
https://en.bitcoin.it/wiki/Private_key
"In Bitcoin, a private key is a 256-bit number, which can be represented one of several ways. Here is a private key in hexadecimal..."
Edit : The bitcoin private key being a number was in response to your redacted comment.
A private key IS a number : https://en.bitcoin.it/wiki/Private_key The one you shown was just encoded in base58 !
Why isn't the address+balance just signed with a key pair?
That way me knowing a key pair wouldn't get me an address with a balance in it...
is there something i'm missing?
EDIT: I guess it doesn't matter, since the address space is so large. Either way, if i were targeting an account, i would know what key pair to attack..
Really the only way people now get educated is by using enforced formats on password fields [1]. That is not are not solid in any way, nor is the proposed 4 random words method (although better). But both are still better than allowing people to use weak passwords when it's involving money.
Every bank these days has 2-factor auth to allow transactions. Sure someone can phish your credentials from whatever, but the transaction authorization itself is only one-time, while with Bitcoin you can transfer money if you've stolen the wallet.dat and can bruteforce the key...
There is no protection (throtteling, locking) on bruteforcing wallets. Usually with banks, or most 2-factor auth implementations, there is.
- Magic the Gathering's BitCoin Cookbook http://www.warplife.com/tips/finance/money/bitcoin/mt-gox/fo...
tl;dr: Forensic Accounting is the way the Feds busted Al Capone for tax evasion; they never did pin a murder rap on him.
Even if no one is cooking the books a shop like Mt. Gox needs Forensic Accountants anyway, because someone could always have made an honest mistake.
I myself Found Religion the day I decided I'd grown weary of a ten-cent error in my quickbooks. I required eighteen hours to clue in to that it was two separate errors that totalled ten cents, as well as to locate the actual errors.
(Now I use GnuCash. There's a damn good reason for double-entry accounting; GnuCash uses it but Quicken and QuickBooks do not!)