Post
Topic
Board Services
Re: Gigamining / Teramining
by
Meni Rosenfeld
on 27/11/2012, 16:26:27 UTC
I have also added an sha256 hashed version of the lists given to me by GLBSE. The list has been obfuscated so that you can easily find your record but not know others records.
I'm not sure this is a great idea. With such a list. If you know someone's email address you can know his number of bonds.

What's worse, even without knowing someone's email address, you can sometimes find his email address and the number of bonds. Emails don't have that much entropy and SHA256 is fast. With a GPU working the case you should be able to deanonymize many of the claimants.

Bitcoin addresses also have very little entropy once they're in the blockchain. Once those addresses are paid by anyone, you can run over all 7M addresses and match them to the hashes.

The Bitcoin address - shares association is likely to become public knowledge anyway. The Email - Bitcoin, however, shouldn't be, and the way this list is written it makes it easy to find in many cases.