4 ms·
"As long as a key is available, a substitution cipher is a safe, simple way to encrypt a message." ...quality article
by hagreet 8y ago
"As long as a key is available, a substitution cipher is a safe, simple way to encrypt a message." ...quality article
- AppleseedJenny 8y agoYeah. They should just use ROT13 as substitution. Then key availability is not an issue anymore.
- onion2k 8y agoFor extra security it's important to run ROT13 twice.
- AppleseedJenny 8y agoYou get it.
- olliej 8y ago<3
- yorwba 8y agoI can't tell whether you're being sarcastic, but the article is essentially correct. The security of an encryption algorithm doesn't depend on how complex it is if you never reuse the key, because a uniformly random key produces uniformly random output for any input. Only key reuse can introduce statistical regularities that allow cryptanalysis to be applied. The reason most encryption algorithms are more complex than simple substitution is exactly that they are intended to allow applying a relatively short key multiple times, both to encrypt messages longer than the key and to encrypt multiple messages.
- ShorsHammer 8y agoAlso known as a One Time Pad for anyone wanting more info, generally the key and message are xor'd if its digital and that's the entirety of the encryption algorithm. Used properly it's proven to be unbreakable.
- empath75 8y agoIt’s breakable if you use some publically published document as the key as in cipher 2
- olliej 8y agoThe algorithm isn’t broken, the definition of a good encryption scheme is that it can’t be decrypted unless you have the key, in this case the algorithm is to substitute each letter with a lookup into a document. The non-public key is the name of the document not the document itself. Ostensibly the author decrypted the the second document by doing a brute force search of the key space (that is the set of documents available at the time). This is functionally the same as aes - just a much smaller key space.
- shawnz 8y ago> a uniformly random key produces uniformly random output for any input. This is clearly not true for a simple substitution cipher though, otherwise it couldn't be attacked with frequency analysis
- mhluongo 8y agoTwo different techniques here. One-time pad is a strong random cipher, versus a typical "lookup" substitution cipher which is garbage.
- yorwba 8y agoIt is true for any cipher, but remember that you are not allowed to reuse the key. If you are just scrambling the alphabet, you can never encrypt more than a single character without key reuse.
- olliej 8y agoA one time pad is a specific case of substitution cipher (it’s a generalization of vignere) where the key is the length of the document. It is probably secure - as in it is actually impossible to break. The reason one time pads are not used in general is that you need a “perfect” rng, and you have to be able to get the random values to the recipient. Those old “person traveling with brief case of secrets” trope was a real thing. Key distribution is the problem solved by public key cryptography. But you can’t use one time pads with public key crypto, because the weakness is then breaking public keys (which is probably possible). Stream ciphers loosely acted like a one time pad in that you generate a “random” stream and xor with the message. But it doesn’t reach the actual requirement of security for a one time pad because the key is the RNG seed, which means you can brute force the seed key space and only the correct key will produce a completely sensible decrypted output. A true one time pad means that a brute force search of the key space for a message of length N will find every valid message of length N. Eg an 11 letter message would produce (among others) “hello world” and “hello earth” as well as “die planet!”.
- raverbashing 8y agoThere's a world of difference between a substitution cypher that maps the same characters to the same code points and one that doesn't. The former is trivially crackable and the latter is a "one time pad" hard (which is how the texts were created)