3 ms·
> You literally just suggested using standardized encryption algorithms to protect your OTP key. I suggested using standardized (or non-standardized, but other
by plugnburn 11y ago
> You literally just suggested using standardized encryption algorithms to protect your OTP key.
I suggested using standardized (or non-standardized, but other than OTP) encryption algorithms for an initial key data distribution channel that completely differs from the main communication channel and exists for a relatively short period of time. That's my key point.
> Or you could...you know...just use standardized crypto across the board.
I'm not going to dive deep into the topic of why I consider "just using standardized crypto" unsafe and prefer rolling another custom end-to-end encryption layer on top of it.
> OTP is by definition impractical. I'm sorry that you don't see that.
I'm sorry that you can't see beyond the algorithms. We're far ahead of the time when OTP was the only active instrument (aside from straddling checkerboards and Enigmas). Modern crypto can be combined in such a way that every encryption scheme finds its natural place. I honestly don't see why OTP cannot have one.
- rnovak 11y ago> I'm not going to dive deep into the topic of why I consider "just using standardized crypto" unsafe and prefer rolling another custom end-to-end encryption layer on top of it. please, by all means, enlighten us. > I'm sorry that you can't see beyond the algorithms. Please keep in mind that you have no idea what my background is (or what experience I have), so don't assume that I "can't see beyond the algorithms".
- plugnburn 11y agoIf you can really see beyond the algorithms, you should understand what I mean. Exploring a "spherical algorithm in the vacuum" begins being useless at some point. One should explore its properties when used in a real environment. Protocols where OTP usage is plausible and practical definitely exist. I'm not saying that OTP is practical for every possible use case though. In fact, in my first comment here I had asked the OP about how he's going to solve key distribution problem among multiple users. Because when such a simple algorithm is used, the actual protocol matters much more.