Talk:Identicon

From Wikipedia, the free encyclopedia

What about wawatars? Shouldn't they also be added to the list?


The statement that it is "impossible" to obtain the IP address from a MD5 Identicon is untrue. Identicons are both interesting and useful, but adding MD5 hashing does not significantly enhance privacy.

There are ~4 billion unique IPv4 addresses. It is entirely computationally feasible to generate all possible IPv4 MD5 identicons and exhaustively compare them to one or more unknown identicons. Just as 32-bit keys are trivial to break in encryption, 32-bit IP addresses are likewise trivial to recover from a "one-way" hash via exhaustive search.

The IPs are impossible to obtain from the hash alone if you use a secret salt, which is the case for Don Park implementation. --MichalKwiatkowski (talk) 17:12, 9 June 2008 (UTC)