4 ms·
OTPs are impractical to use for average people, while their use is entirely tractable (and widespread) for covert operations.
by blattimwind 7y ago
OTPs are impractical to use for average people, while their use is entirely tractable (and widespread) for covert operations.
- bob1029 7y agoEverything technological is impractical to use for average people until people like us go out and build a practical solution. OTP is not a very complicated scheme. All you need is a good source of entropy, a place to store a big fat array of it all, some XOR operations, and a safe way to hand the codebook to your trusted parties (e.g. phone-to-phone transfer options).
- cesarb 7y agoYou don't even need XOR, just modular addition (XOR is basically addition modulo 2). The Wikipedia article has an example doing it by hand with letters (using addition modulo 26).
- mindslight 7y agoOne time pads are not secure by modern cryptographic standards. Elaboration: https://news.ycombinator.com/item?id=6008695 https://news.ycombinator.com/item?id=6008695
- urda 7y agoHuh? First off citing yourself isn't an elaboration. Second if you are arguing that one-time-pads don't work / won't work in modern times that goes against our entire understanding of certain bits of cryptography. You'll need to yield some real sources first.
- mindslight 7y agoI referenced my own comment because I didn't feel like rephrasing what I had previously written, nor just spamming a copy of it. A logical argument doesn't rely on a "source": > A one-time pad XORed with a message doesn't provide integrity, and therefore can't reliably secure an arbitrary protocol The point is that sure, one time pads "work" the way they're described. But their properties don't actually fulfill what we require from modern cryptosystems. Note the sibling comments talking about augmenting them with half baked authentication schemes. Which are all into the realm of computational-complexity cryptography, and no longer "mathematically unbreakable!!1!"
- dependenttypes 7y agoIf integrity is an issue you can just add a poly1305/ghash tag to the message. They are not encryption algorithms so it is unlikely that they are going to be banned, and just like OTP they are provably secure. In addition they are not difficult to implement (or execute by hand).
- mindslight 7y agoNo encryption algorithms would be "banned" by the proposed law. Rather corporate service providers would be compelled to act as bona fide MITM, regardless of what primitive(s) they use. Once we're past the point of users doing something beyond downloading an app from a corporate app store, all secure encryption would be back on the table. Of course we can foresee a true ban on encryption some years out, but at that point XOR has the exact same signature as AES. Steganography is the corresponding approach for that attack.
- bob1029 7y agoSo the concern then is that the message might be tampered with on the wire? Is there some hypothetical reason we can't just append the SHA256 of the message to the message before encrypting it? It should be impossible for an attacker to alter any message bits undetected with this scheme.
- mindslight 7y agoYour scheme fails for replay attacks, and allows modification of messages with low entropy. I'd say easy fixes are to add a counter and a random nonce to each message, but then there is probably something else I am missing. In general there's no "just" in cryptography, which is why cryptosystems are formally defined and then analyzed whole.
- Buttons840 7y agoOTPs are not a replacement for our current encryption systems, but I love them as an example of how encryption isn't going to go away. A children's book would be a great demonstration of this, and should be protected speech (let's hope). Teach kids how to use OTPs in an illustrated book. Maybe the story ends with 5 year old Jimmy getting hauled away by the feds for doing some illegal math.