Brainwallet inputs -> public keys are deterministic. It's true that the method of creating the key pair is as much of a password as the password, it's easy to select the most common methods (sha-256 hashes, bitaddress.org's method, etc.)
I cracked thousands of passwords for the https://keybase.io/warp competition (I lost by a few minutes... the answer to the top one is Je).
Once you have those public, private key pairs you can simply make an index of them and watch the blockchain for any of them to show up.
I've also noticed quite a few people who've posted threads on bitcointalk after having fallen victim to one of these brainwallet crackers. It really boggles the mind why someone would entrust significant amounts of money to an incredibly weak passphrase.
Comments
You are right and here's why:
Brainwallet inputs -> public keys are deterministic. It's true that the method of creating the key pair is as much of a password as the password, it's easy to select the most common methods (sha-256 hashes, bitaddress.org's method, etc.)
I cracked thousands of passwords for the https://keybase.io/warp competition (I lost by a few minutes... the answer to the top one is Je).
Once you have those public, private key pairs you can simply make an index of them and watch the blockchain for any of them to show up.
I've also noticed quite a few people who've posted threads on bitcointalk after having fallen victim to one of these brainwallet crackers. It really boggles the mind why someone would entrust significant amounts of money to an incredibly weak passphrase.