3 ms·
So it still fits the definition of perfect secrecy, but (with vanishingly small probability when the key is large) it's possible for a key to be chosen that is
by davidshepherd7 11y ago
So it still fits the definition of perfect secrecy, but (with vanishingly small probability when the key is large) it's possible for a key to be chosen that is more "guessable"?
I don't think this is a problem. Depending on the guess for the key an attacker could get back any possible message as the plaintext. So there is no reason for them to believe that the message they obtain by using a simple key (e.g. AAAAAAAAAAAA as in the example) is the original plaintext?
- w0000t 11y agoYes. They don't know if the string ONETIMEPAD was produced by the key AAAAAAAAAA or GHASDIJAWE. And thus they don't know if ONETIMEPAD is actually the plaintext or not.
- charriu 11y agoYes. Guessing the correct key by chance doesn't give you the (necessary) information that the key was correct, because any number of other keys results in correct-looking messages.