-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
How am I feeling at this exact moment?
Answer in MD5 checksum: ef97b40b2245d3690c745cd6e8c663db
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFIYvf/YKLKXJTvB1MRAjNWAJ4sp4lduajrcdZMtfwdnG06KEJzPwCcDRNZ
VeyPsqqeth8jGZzAld6O5Q4=
=QM+7
-----END PGP SIGNATURE-----
Observations:<ul><li>I’ve given the MD5 checksum of my answer, meaning I’ve set the answer in stone without actually giving you the answer. (If someone I didn’t like guessed the right answer, I couldn’t just change the answer.)</li><li>I can’t change the checksum either, because the “This post has been edited by Chris Vogel” thing would show.</li><li>Administrators could edit my checksum without anyone knowing, but that would invalidate my OpenPGP signature.</li></ul>
Flaws:<ul><li>I could give the administrators a different signed message and bribe them to secretly replace it. Alternatively, I could hack into an administrator account. (Administrators can optionally edit messages without the little “edited by” message.)</li><li>The administrators could get their hands on my private key and crack the passphrase, letting them sign a new checksum with my key.</li><li>The administrators could sign their own message and replace it with mine, fooling anyone who validates the signature (or just assumes it’s valid) without actually checking to see who owns the key.</li><li>The administrators could change the key information I have listed in the post signature to match theirs. They could also hack into my Web site and change the key information there, as well as my phone number, address, etc. This would fool people who actually did try to make sure the OpenPGP key belonged to me.</li><li>Obvious words, e.g., the English words for different moods, are probably in an MD5 hash database.</li></ul>
I’d like to turn this into a discussion of security instead of my mood, hence this topic’s location. If one wants to play such a guessing game over the Internet, what’s the best way to carry it out?
Archived topic from Anythingforums, old topic ID:3601, old post ID:66231
Guessing game
- fragged one
- Posts: 1735
- Joined: Thu Jun 24, 2004 5:51 pm
- Red Squirrel
- Posts: 29209
- Joined: Wed Dec 18, 2002 12:14 am
- Location: Northern Ontario
- Contact:
Guessing game
I through that hash in my cracking program and it came out with "ok.". I win?
Archived topic from Anythingforums, old topic ID:3601, old post ID:66342
Archived topic from Anythingforums, old topic ID:3601, old post ID:66342
Honk if you love Jesus, text if you want to meet Him!
-
- Posts: 5140
- Joined: Fri Jan 10, 2003 1:14 am
Guessing game
Err, no.Red Squirrel wrote: I through that hash in my cracking program and it came out with "ok.". I win?
Archived topic from Anythingforums, old topic ID:3601, old post ID:66346
- Red Squirrel
- Posts: 29209
- Joined: Wed Dec 18, 2002 12:14 am
- Location: Northern Ontario
- Contact:
Guessing game
oh wait, I used the wrong algorthm.
The answer is 42!
Archived topic from Anythingforums, old topic ID:3601, old post ID:66347
The answer is 42!
Archived topic from Anythingforums, old topic ID:3601, old post ID:66347
Honk if you love Jesus, text if you want to meet Him!
-
- Posts: 1397
- Joined: Tue Jul 18, 2006 9:57 pm
Guessing game
AHHHH!
Archived topic from Anythingforums, old topic ID:3601, old post ID:66416
Archived topic from Anythingforums, old topic ID:3601, old post ID:66416
[insert signature here ]