logoalt Hacker News

MattPalmer1086yesterday at 8:50 AM1 replyview on HN

I was wondering about the overall security. How did you determine that 3 pass codes and brute force will reveal the secret key?


Replies

MattPalmer1086yesterday at 9:19 AM

Thinking about it, there are only 10 billion different keys and somewhat fewer sboxes.

So given a single pass code and the login time, you can just compute all possible pass codes. Since more than one key could produce the same pass code, you would need 2 or 3 to narrow it down.

In fact, you don't even need to know the login time really, even just knowing roughly when would only increase the space to search by a bit.

show 2 replies