5 ms·
From the github README: > Designed to be as secure as a one-time pad, without a weakness due to the use of repeating keys, That immediately shows that the per
by thethirdone 7y ago
From the github README:
> Designed to be as secure as a one-time pad, without a weakness due to the use of repeating keys,
That immediately shows that the person writing it doesn't know cryptography. You simply can't get the security of one-time pad without having a key the size of the data, and if you do, just use it as the pad.
- cryptonector 7y agoAnd you can't reuse the keys in a one-time pad system.
- jascii 7y agoLol, I always wondered what the "one-time" bit meant ;)
- klingonopera 7y agoNitpick: You can, but you shouldn't.
- jascii 7y agoNitpick: the moment you do, it stops being a one-time pad.
- klingonopera 7y agoI've always wondered if the assumption, they're never using the same one twice, would suffice to practically always use the same one then (assuming data-length never changes).
- alecbenzer 7y agoNot sure what you're asking? If you use the same key over and over again, then you're using the same key much more than just twice. The idea of a one-time-pad is that you're basically just randomly flipping the bits of your input, which means the output of an OTP cipher is indistinguishable from random data. If you're using the same key multiple times though, then the output of the cipher (considered over time) won't be random, and you'll be able to detect patterns from the original input in the cipher output (e.g., the shape of an image, frequency of certain letters).
- klingonopera 7y agoThe output is always random, regardless how often the key has been used. The thing is, if you know the same key has been used a second time, then yes, having both outputs (can? will? must? could?) helps to acquire the key. But how do you know they're using the same one? Or how are you sure, they're not? All you have, are two pieces of random data.
- alecbenzer 7y ago> The output is always random, regardless how often the key has been used. The output of any _one_ use of the pad is, yes, but the point is to consider all of the data that an attacker may have. If you re-use the key multiple times, then the entirety of the cipher texts an attacker has is not random. (See also: https://xkcd.com/221/ https://xkcd.com/221/) > But how do you know they're using the same one? Or how are you sure, they're not? You'll be able to tell because you'll see patterns in the data: https://upload.wikimedia.org/wikipedia/commons/f/f0/Tux_ecb.jpg https://upload.wikimedia.org/wikipedia/commons/f/f0/Tux_ecb....
- klingonopera 7y agoAssume you have the OTP: 4242. You encrypt the data ABCD -> EDGF. You encrypt the data DEFG -> HGJI Someone intercepts the data, and has: EDGF and HGJI And now? Or maybe like this: Since OTP and data are interchangeable, due to matching lengths, isn't using the same OTP with different data, essentially the same like using the same data with a different key?
- wnkrshm 7y agoEDGF encrypted with HGJI is now the same as ABCD encrypted with DEFG. In this example, that means the distance between characters of the encrypted messages is the same as the distance between the original messages. From my limited knowledge of the matter, that alone doesn't give you the cypher - you'll need to know additional information about the messages to get the cypher (statistics of words, conditional probabilities of letter sequences etc.). But without the one reuse of your cypher, you couldn't apply these techniques.
- oh_sigh 7y agoAllies detected in WWII when the same pad was mistakenly used multiple times. Depends how motivated your enemy is
- Retric 7y agoNitpick: You can as long as you only use each bit on the OTP once.
- BubRoss 7y agoThat's just saying the same thing.
- Retric 7y agoHistorically OTP where shared as physical pads of paper with a different sheet of paper for each message. This is useful as lost messages did not stop communication. If a sheet did not decode the message then try the next sheet. However, this meant there where leftover bits of each key. Though if you think of each bit as a different key then sure, just start each message with the offset.
- klyrs 7y agoIf yor rot13 your OTP the second time around, it's probably fine. In the same way that turning your underwear inside out is probably fine. As long as nobody sniffs...
- cryptonector 7y ago"Can" as in "you could possibly do it, yeah", and "shouldn't" as in "really, really, REALLY shouldn't". The Venona cable decrypts were made possible by one-time pad reuse.
- klingonopera 7y agoI'm not sure, definitely not if you use XOR-OTP, not so sure about additive-OTP, see my reply here[0] for reasons. Would like to know, if my assessment on additive OTP is correct, if anyone knows? EDIT: I mean, of course you still shouldn't, but where the XOR catastrophically fails after just a single reuse, the additive one should be more robust, even with reuse. The Venona Decrypts were additive-OTP, I postulate, the decryption rate would've probably been higher with XOR-OTP. [0]: https://news.ycombinator.com/item?id=22448966 https://news.ycombinator.com/item?id=22448966
- numpad0 7y agoI thought the notion of OTP is that there is absolutely nothing to decode, prove or disprove ciphertext? Like if ciphertext is "supersecret" then it feels like plaintext can't be more obvious and OTP must be "00000000000", but there's nothing anywhere to logically/mathematically support it. OTP could be something else and plaintext could be "hackernews" or "ycombinato". In reality a simple XOR with a random sequence preserve enough entropy of data that I've heard you could make out voices if used on media, so payloads must be scrambled, but that's not recovery, only a guess. ANY reuse breaks that notion and make it not an OTP cryptography.
- Someone 7y agoThere’s also the claim > Crystalline employs information loss as the basis of its security. If encryption loses information, there’s no way decryption can bring it back. In the extreme def encrypt(s): return “(TOP SECRET)” is totally secure, but also totally useless.
- segfaultbuserr 7y agoNot useless. This is, in fact, the most widely used encryption algorithm in declassified government documents! /joke
- khazhoux 7y agoNot totally useless. You just need the dual: def decrypt("(TOP SECRET)"): return s
- alexeiz 7y agoI know how to fix it. Blockchain!
- dreamcompiler 7y agoI noticed this too. One of two things is going on: a. The author cannot decrypt it either, unless he's cheating somehow, or b. It's not really losing information and the author is lying.
- infinity0 7y ago>> Designed to be as secure as a one-time pad, > That immediately shows that the person writing it doesn't know cryptography. You simply can't get the security of one-time pad [..] Talking about a one-time pad at all in the context of making something actually secure for internet usage, shows that the talker doesn't know about cryptography. A one-time pad having "perfect security" is only true in the context of a particular security model that doesn't generally hold true on the internet - one where the adversary cannot change the ciphertext whilst it is in transit. Under a more realistic security model, we need a message authentication code or some other equivalent, to protect against adversaries changing the ciphertext. It's a well-known theorem of modern cryptography that in fact if you don't have secure authentication under this model, then you cannot achieve secure privacy. In other words, your ciphertext has to be bigger than the plaintext for security on the internet. (There is in fact a one-time-pad equivalent for MACs where your key is the length of the plaintext and the ciphertext ends up being several multiple times the length of the plaintext, but crackpots when making security arguments about "one-time pads" generally aren't referring to this and aren't even aware of the existence of this. It's a relatively unknown construction and nobody really talks about it in the context of serious modern cryptography.)