Comment

yfrog 'secret' email addresses are easy to figure out

18
eightyfiv6/02/2011 12:26:09 pm PDT

Actually… Given that it took you about 25 tries to find two duplicate nonce words, we can very roughly estimate the total size of the dictionary of possibilities — it’s the well-known birthday problem. You should expect to find your first duplicate around when the probability of having one hits on the order of 50%. How many distinct possibilities do there need to be for 50% probability at around 25 samples? It’s about 450 (on the order of 25^2). Amusingly, this is almost identical to the 23 people needed for an expected 50% chance of a duplicate birthday!

I’m sure a statistics buff could give a more rigorous analysis, but roughtly speaking, at the leisurely pace of 1-2 guesses a day, it would take about a year to break someone’s account. FAIL.