ED25519 key fingerprint is SHA256:XrvNnhQuG1ObprgdtPiqIGXUAsHT71SKh9/WAcAKoS0.
Am I the only one who finds patterns and pronounces mentally such things, and thus can easily recognise seemingly random letters and numbers? My mental voice reading that one goes 'zervinh... progdit... [...] slash wacko-so' and I'd nickname it 'wacko'.
I always thought they were supposed to represent how much "entropy" or something they got. So if the art looked "boring" you maybe want to generate another one.
Matching SSH keys is useful because many common SSH setups use TOFU. You can tell your computer to memorize the key, but how do you know you got the right key?
> you can set VisualHostKey to yes in your SSH client config to get that information every time.
> I left this on for a while and see if I started to be able to recognize the randomart images in the way the manual implies I'd be able to, and it turns out it worked! For example, I've started seeing the GitHub fingerprint (above) as something like the Statue of Liberty if it were a cat (don't ask why; that's just how my brain sees it), and the signature for git.bytes.zone (below) as the Vagrant logo. How interesting!
I wonder how much effective entropy randomart really has. More specifically, I wonder how hard it would be to model “looks the same” and brute force a “collision” that most people would recognize as the same ascii image.
I should have explained this in the post, but didnt—"hexadecimal sucks" was the title of the slide from Dan Kaminsky's presentation way back in 2006.
Since then, by default ssh shows the SHA256 fingerprint in base64 (minus trailing `=` padding), rather than an MD5 fingerprint in hex. I probably shouldn't have elided this detail since it's confusing.
The problem of course is that you will never do this repeatedly. You will add a trusted key permanently after verifying it somehow, so getting familiar with the appearance of a key's mnemonic stuff is a waste of time. If you have the key's mnemonic to look at, you probably have the actual text too and can just copy it.
Even just reducing the hash to a single word chosen from a list of a 1,000 words or so should be "good enough security" for most cases as long as the hash→word algo is unbiased.
It's a TOFU check that's done once; you don't need a whole lot of randomness here to make attack hard.
Also your list of names has some junk in it:
Gan(4)
Huan(7)
(podcaster)
{++/Pin/Shan}
O'
Mell'O'
C.N.O.T.E.
Cachivache,
Mister^Fly
G***
And more. I know it's not your list, but just FYI. Probably want to filter on non-[a-zA-Z] or something.
Or you can realize that none of this text-based stuff can save you and move to rich images and colors or even better - to better integration with password managers so you're never forced to become a machine and do diffs manually
It's not easy to memorize a long hex string, but hex is extremely useful for lots of other purposes. It's very nice that it cleanly aligns with bytes and words so it's perfect for inspecting binary data.
Am I the only one who finds patterns and pronounces mentally such things, and thus can easily recognise seemingly random letters and numbers? My mental voice reading that one goes 'zervinh... progdit... [...] slash wacko-so' and I'd nickname it 'wacko'.