Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No. With 10^12 possible account numbers and a hash rate of ~10^10 H/s using off the shelf hardware [1] it would only take 100*(10^12/10^10) = 10000 seconds to deanonymise the token.

[1] https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27...



With 10^12 possible account numbers, it should be relatively easy to build a rainbow table for tokens of any practical complexity.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: