Show HN: Vanity GPG Keys (and help fund GnuPG!)
vanitykeys.io
vanitykeys.io
The most important rule of public key encryption is... Never (really!) let anybody else handle your private key...
And why should I trust some random website for not storing an extra copy? The keys are definitely not "... as secure as if you have generated them by yourself. ". Because, if I generate them, I know that my box is the only one that had ever touched it...
[1] http://security.stackexchange.com/questions/37510/when-chang...
Using an untrusted 3rd party service to generate a public/private key pair is like asking a thief to sell you a new door lock.
I'm mainly interested in raising awareness to GnuPG and get more people using it - I also organize CryptoParties [1] in my area, exactly for this purpose.
[1] - https://cryptoparty.in/
For testing and explaining GPG to people, nobody needs vanity keys. You don't raise awareness for GPG by having "DEADBEEF" on your business card.
Non-native speaker here, I didn't even know what "vanity" means, just ignored it as noise-word :) Well, after looking it up, I still am not sure that I understand what it means :).
No. That is not possible.
I'd invite folks reading this to donate directly to https://www.gnupg.org/donate/ and ensure 100% of your charity reaches the folks & help them attain their funding goal + keep one of the most essential tools under active development.
[1] - https://keybase.io
http://lists.gnupg.org/pipermail/gnupg-users/2015-January/05...
"I have not heard about it but given that the Wau Holland Stiftung is collecting GnuPG donations also via Bitcoin, it is likely that this can't be tracked.
However, if that processing power is used to find many dups for long keyids we will sooner or later neet to invest work to mitigate the effect of this (e.g. adding a fingerprint as signed attribute to each signature)."
Aren't you tired of boring, bland, random passwords?
For just $5 I'll generate you a beautiful, memorable vanity password that you can use for everything and show off to your friends!
See my profile for contact info. Limited time offer!
In this sense, it's probably more efficient (both power and money wise) than mining for BTC directly, but it still feels like a waste of energy to me. Waste, because I don't think anyone with security in mind would buy a private key off some random website and anyone with no security in mind would never get the idea to buy a GPG key.
Also, I'm still wondering why "FF8243E1" costs 5$. Because it's only 7 out of 8 possible different characters?
I can see how you would sell keys with fingerprints like "1234BEEF" for 100 bucks, but those 5$ keys are just ... I don't get it. But that's okay, it's not the first time I don't understand why people spend money on something ;-)
If people want a vanity short key ID, then educating them on how OpenPGP packets work, and how the fingerprint is generated from the timestamp is the right way to go. Teach a man to fish.
Here is some Java code that creates a partial collision on the fingerprint for the desired short key ID:
Whats next, vanity passwords?
EDIT: reading the comments from the author yuvadam below, its obvious we are being trolled
EDIT2: now i'm getting scared. i wouldn't want software from this guy near my machines https://aur.archlinux.org/packages/?SeB=m&K=yuvadm
I severely doubt the guy who develops GnuPG (Werner Koch) would approve of this.
[edit] This is the worse thing I've ever seen on Hacker News.
Unable to complete secure transaction
Secure connection: fatal error (40) from server.I was wondering how exactly are the keys priced.
I'll happily donate 60% of the profits from the service to GnuPG. Let's use this opportunity to fund GnuPG.
You buying? :)