Post
Topic
Board Service Discussion
Re: Buteforced attacked Instawallet
by
Stephen Gornick
on 24/10/2012, 20:51:49 UTC
Instawallet account identifiers have too high entropy for brute forcing them being profitable.

If those in that pastebin were actual funded Instawallet accounts, the URLs weren't discovered through brute force cracking.

And that is quantified here:

16 bytes of random data is 128 bits, which means there are 2^128 = 340282366920938463463374607431768211456 possible Instawallet URLs. Let's say there are 10000 Instawallets in use (in reality the number is nowhere this large, but let's be optimistic and assume that Instawallet will grow). So you have a chance of 10000 to 2^128 to find a wallet with coins if you just guess once.