4 ms·
Just xor bit by bit against real random noise,embed it in a massive stream of other pure random, remember the offset, if it's really that important..
by siliconunit 8y ago
Just xor bit by bit against real random noise,embed it in a massive stream of other pure random, remember the offset, if it's really that important..
- Eliezer 8y agoDon't roll your own crypto. If that was much better encryption, everyone would be using it.
- taylorfinley 8y agoI think we all agree rolling your own crypto is dangerous, but what siliconunit described is just a one time pad. Assuming your key data is truly random and unknown to your attacker, isn't this kind of the gold standard for uncrackable cyphered communication?
- jpatokal 8y agoIn theory, but getting that stream of "real random" and above all distributing that one time pad securely to the recipient (chicken, meet egg) so they can read the message make this highly impractical.
- vectorEQ 8y agodont need the random really. just need an offline method for exchanging the pad :D or just use an unexpected channel like radio or so to send it
- Eliezer 8y agoIf interpreted that way, storing the noise and memorizing the offset, it amounts to having a privately stored one-time pad to be used as key... with a passphrase with as many bits in it as the offset. That’s probably not a lot of bits. You are better off storing the data, encrypted with a real pass phrase, wherever you would have stored the random noise stream that is needed to read the data in any case. Don’t roll your own crypto.
- A2017U1 8y agoUsing a one time pad isn't "rolling your own crypto". It is also provably secure unlike every other cryptosystem.
- function_seven 8y agoSure, except now you have an equal amount of data that needs to be stored somewhere. The pad is as long as the data. Either you have to encrypt that using some other means, or you do the weak "store offset" method.
- penagwin 8y agoI agree with not rolling your own crypto for your primary mechanism, layering it (in the correct order!) is guaranteed to be at least as secure as your strongest crypto. That's what google did with CECPQ1, they use "new hope" which is a quantum resistant algorithm with traditional methods (X25519). That way if new hope is cracked, they are still using an industry standard you'd have to crack as well.
- vectorEQ 8y agothe only proven secure crypto is the one-time pad. rest is all junk relying on computation times to stay 'secure'. and this onee time pad you can never send over a wire to anyone because of chicken-egg problem. so this would be something you would need to exchange offline for decryption to be possible. if you are not doing that, best stick with known good encryption schemes. that being said you can implement a lot of encoding schemes like you say in ways that make it arbirarily hard for people to decide what is junk and what is data, to make it nearly impossible to crack especially if you say do that xor with random values etc. because if you'd receive a data intercept you have a hard time to rebuild the data from the junk and then decode it