Antwort auf: Können geheime Passphrasen mit Gewalt erzwungen werden?

Home Foren Trezor Wallet Können geheime Passphrasen mit Gewalt erzwungen werden? Antwort auf: Können geheime Passphrasen mit Gewalt erzwungen werden?

#1781708
matejcik
Gast
Up
0
Down
::

> Can secret passphrases be brute forced?

Yes if they’re weak.

Knowing that you posted this, I will generously assume that you’re picking out of a list of 100 000 historical figures. If I can get my hands on the full seed phrase, I’m going to be able to brute-force this in a couple seconds probably.

With six words known and six missing, I’ll need to brute-force 66 bits from the words, minus 4 bits of checksum, gives me 62 bits to go through, which is juuust about where it’s not worth the robbers‘ time to try. But totally doable if you’re a three letter agency.

With the Trezor in hand, brute-forcing the PIN is not feasible because you only get 16 tries.

…however, because this is a Trezor One, a skilled hardware hacker will crack it open, extract the seed via the Kraken hack, which will incidentally also tell them the PIN. Then it’s just a matter of looking up people born in that year. (or on that day, if your pin is DDMMYYYY).

In conclusion, figure out a better passphrase scheme. Multiple words would be cool — a sentence out of a book, a verse of a poem, etc.