I see a lot of services with short vanity addresses that are 9 characters or less. I've found when people see the vanity prefix on an address they automatically assume it isn't a phishing link. I'm begging you to at least do some rough math to figure out how easy it would be to generate a clone before settling on an address. If I rented a single server at a mere €3 an hour I could generate 2,560,000,000 onion keys per second which could generate a copycat in the following times.
Length
Time
Practical?
7 characters
13 seconds
Yes
8 characters
7 minutes
Yes
9 characters
4 hours
Yes
10 characters
5 days
Yes
11 characters
5 months
Maybe
12 characters
14 years
No
You might think in order to generate the initial real address it would also take that amount of time. No it wouldn't. Take a page out of Facebook's book and generate a massive amount of keys over a long period then cherry pick the best ones. You'll find exceedingly long addresses that are unique and memorable yet would still take an unfathomable amount of time to clone. Using this method I've generated addresses overnight up to 21 characters long in normal English words that you could easily remember which would take a casual 502,128,104,857,936 years to clone.
Now for some alternatives to all this vanity bullshit. JUST PGP VERIFY AND BOOKMARK YOUR LINKS. This way you don't have to remember anything! It is a one time process that will save you a lot of grief. If you don't want to PGP verify and bookmark for whatever reason just memorize the beginning few characters, the middle few characters, and the end few characters. For example for tforum I just remember tforumytofat at the beginning, onoyno in the middle, and ubrad at the end. You can do this with any link and find memorable bits easily.
By the way the times for up to 9 characters are absolutely feasible even on a single computer at your house.
Great info! Just to be clear. These is only about the prefix, correct?
So if the anti phishing method relies on other parts of the URL, this would not as big of an issue right?
Of course an issue then is that more is expected from the user, so not saying we're all good and everything. So yeah agree on this one:
> Now for some alternatives to all this vanity bullshit. JUST PGP VERIFY AND BOOKMARK YOUR LINKS.
So if the anti phishing method relies on other parts of the URL, this would not as big of an issue right?
Of course an issue then is that more is expected from the user, so not saying we're all good and everything. So yeah agree on this one:
> Now for some alternatives to all this vanity bullshit. JUST PGP VERIFY AND BOOKMARK YOUR LINKS.
It depends. Most users only check the prefix. Also it depends on how many characters you check total. Sometimes it is only 4 or 5 characters in the prefix then the last 3 characters plus the .onion which is trivial to spoof because hidden service addresses always end with D and often the second to last character is the same set of characters too.
> last 3 characters plus the .onion which is trivial to spoof
Yep, I noticed this quite a few times. It seems wasteful. The only small advantage i can think of is that it does give the user some "anchor" to look at.
Yep, I noticed this quite a few times. It seems wasteful. The only small advantage i can think of is that it does give the user some "anchor" to look at.