solana-labs / solana

Web-Scale Blockchain for fast, secure, scalable, decentralized apps and marketplaces.
https://solanalabs.com
Apache License 2.0
13.19k stars 4.3k forks source link

Asking for public security audit concern to profanity vulnerability #28360

Closed psixoz-korvin closed 1 year ago

psixoz-korvin commented 2 years ago

Good day, Solana adopters, as i'm a part of big solana dev familiy, I'm trully worried about profanity well known vulnerability in Eth network. As we know profanity gave an opportunity to create "smooth adresses" like 0x9999111110000aaabf on Eth using BIP-39 base such as Solana. https://github.com/johguse/profanity/issues/61 showed security vulnerability of "smooth adresses" -> generated public\private keys based on eliptic curve encryption and that they much more likely can be force bruted.

So i would rather ask a team memebers, if it's possible, to audit and sound the results of such security audit: if Solana public keys\vote keys like these ones: Frog1Fks1AVN8ywFH3HTFeYojq6LQqoEPzgQFx2Kz5Ch LSV1G6qbrCWhsPQLmm623cqXU58Ha2mZKHJ9ZadbcLv C1ocKDYMCm2ooWptMMnpd5VEB2Nx4UMJgRuYofysyzcA Cogent51kHgGLHr7zpkpRjGYFXM57LgjHjDdqXd4ypdA Certusm1sa411sMpV9FPqU5dXAYhmmhygvxJ23S6hJ24 are fully secure. Thank you.

steveluscher commented 1 year ago

Asked our resident cryptographer @samkim-crypto for some input here, and it sounded to me like there's nothing concrete we can do here. If you have suggestions, please feel free to reopen this!