3 ms·
copied from Reddit No, when properly implemented, it can not be broken. "Properly implemented" pretty much implies a paper version where there are only two cop
by NatoshiSakimoto 7y ago
copied from Reddit
No, when properly implemented, it can not be broken. "Properly implemented" pretty much implies a paper version where there are only two copies of any pad page, and both are immediately destroyed after use.
Computerized versions share the same vulnerabilities as the computer it is on. It can't be "cracked", per se, but there are side-channel attacks that can be effective.
Here is a paper by Dirk Rijmenants which explains it in the context of Cuban spy communications: http://users.telenet.be/d.rijmenants/papers/cuban_agent_communications.pdf http://users.telenet.be/d.rijmenants/papers/cuban_agent_comm...
I've experimented with generating them manually, using 10-sided dice to generate the code groups and an old manual typewriter (not electric!) with a very used cloth ribbon and 2 part carbonless forms. Works pretty well, and once you get into a rhythm you can make a considerable amount of key material. I just grabbed some random 10-sided die at the local gaming store, but if you were serious about it, I'd get Game Science 10-sided die: http://www.gamesciencedice.com/Gamescience-White--d10--Ten-sided-die--Plain-_p_53.html http://www.gamesciencedice.com/Gamescience-White--d10--Ten-s...
- qw3rty01 7y agoYou're saying we shouldn't spend time to make sure the algorithm is mathematically sound...because the implementation will have side channels? Using your metaphor, that's like saying we should never bother designing a secure lock because someone will just break a window to get in anyway.
- NatoshiSakimoto 7y agoThat's not a correct analogy. It's a window into the key, allowing the lock to be opened, not a window into a room that is protected by a lock. The point is that security is a defense mechanism, not an absolute guarantee, yet responses like the above and the sarcastic "Math, mostly" one go to show why we need to educate people about the context in which encryption exists. It does not exist in a vacuum. And there is no such thing as a perfect lock in the real world, where we live which is the only place where the discussion about the value of encryption has any value.