Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Hexadecimal Sucks (tylercipriani.com)
32 points by thcipriani on May 31, 2024 | hide | past | favorite | 27 comments


ED25519 key fingerprint is SHA256:XrvNnhQuG1ObprgdtPiqIGXUAsHT71SKh9/WAcAKoS0.

Am I the only one who finds patterns and pronounces mentally such things, and thus can easily recognise seemingly random letters and numbers? My mental voice reading that one goes 'zervinh... progdit... [...] slash wacko-so' and I'd nickname it 'wacko'.


I wonder if many people here, on this reasonably tech savvy website, actually recognize ssh keys based on their random art images?

I don’t…

I think recognizing ssh keys is not very useful, because we mostly only use a handful of computers, and they can be told to memorize the keys instead.


You mean, I'm expected to remember the ssh art images?

Ya learn something new every day!


I always thought they were supposed to represent how much "entropy" or something they got. So if the art looked "boring" you maybe want to generate another one.


The random art is too random for me, and I will never be able to identify mine from any other random ASCII art.


Matching SSH keys is useful because many common SSH setups use TOFU. You can tell your computer to memorize the key, but how do you know you got the right key?


https://bytes.zone/posts/what-is-the-randomart-image-for/

> what is the randomart image for?

> you can set VisualHostKey to yes in your SSH client config to get that information every time.

> I left this on for a while and see if I started to be able to recognize the randomart images in the way the manual implies I'd be able to, and it turns out it worked! For example, I've started seeing the GitHub fingerprint (above) as something like the Statue of Liberty if it were a cat (don't ask why; that's just how my brain sees it), and the signature for git.bytes.zone (below) as the Vagrant logo. How interesting!


I wonder how much effective entropy randomart really has. More specifically, I wonder how hard it would be to model “looks the same” and brute force a “collision” that most people would recognize as the same ascii image.


I've wondered the same. Ben Cox's blog[0] shows there is some bias for the random art generation.

[0]: <https://blog.benjojo.co.uk/post/ssh-randomart-how-does-it-wo...>


This brings to mind Chernoff faces[1], a type of visualization where facial features are mapped to data points.

  [1]: https://en.wikipedia.org/wiki/Chernoff_face


The author is talking about base64 sucking, not base16.


I should have explained this in the post, but didnt—"hexadecimal sucks" was the title of the slide from Dan Kaminsky's presentation way back in 2006.

Since then, by default ssh shows the SHA256 fingerprint in base64 (minus trailing `=` padding), rather than an MD5 fingerprint in hex. I probably shouldn't have elided this detail since it's confusing.

Titles are hard.


The problem of course is that you will never do this repeatedly. You will add a trusted key permanently after verifying it somehow, so getting familiar with the appearance of a key's mnemonic stuff is a waste of time. If you have the key's mnemonic to look at, you probably have the actual text too and can just copy it.


Even just reducing the hash to a single word chosen from a list of a 1,000 words or so should be "good enough security" for most cases as long as the hash→word algo is unbiased.

It's a TOFU check that's done once; you don't need a whole lot of randomness here to make attack hard.

Also your list of names has some junk in it:

  Gan(4)
  Huan(7)
  (podcaster)
  {++/Pin/Shan}
  O'
  Mell'O'
  C.N.O.T.E.
  Cachivache,
  Mister^Fly
  G***
And more. I know it's not your list, but just FYI. Probably want to filter on non-[a-zA-Z] or something.


Choosing a 1/1000 word won't work. An attacker just has to generate 1000ish hostkeys until they find one that hashes to the same word.


Eh, right; that's publicly available to anyone who connects of course >_<


Maybe title should have been base64 sucks.


Is 9 times F actually fleventy-five?


It's 87, pronounced 'eight-seven'.


Or you can realize that none of this text-based stuff can save you and move to rich images and colors or even better - to better integration with password managers so you're never forced to become a machine and do diffs manually


This is a great idea, but, I'm not sure when the last time I needed to recognize an ssh fingerprint was.

I'm sure it has uses in other places, and, I'm generally all for remembering large strings of data via "Darmok and Jalad, at Tanagra"


It's not easy to memorize a long hex string, but hex is extremely useful for lots of other purposes. It's very nice that it cleanly aligns with bytes and words so it's perfect for inspecting binary data.


BADC0FFEE

DEADBEEF

FEEDFACE

71077345


Nit:

> The web service what3words maps every three cubic meters (3m²)

Those are square, not cubic, meters.


tl;dr: let’s replace this arbitrary set of numbers with an arbitrary set of words. Everyone loves rote memorization, but only for words, not numbers


"what three words" says you're right


But nobody likes "what three words"




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: