3 ms·
> This encryption is perfect secrecy Sending your key in plaintext over a separate channel isn’t really perfect secrecy but okay... it’s interesting, but laden
by natcombs 6y ago
> This encryption is perfect secrecy
Sending your key in plaintext over a separate channel isn’t really perfect secrecy but okay... it’s interesting, but laden with assumptions.
- m3kw9 6y agoWhat do you mean plain text? It’s scrambled using the OTP then sent. Each sent on a separate channel. The only way to crack is to intercept both. Or if the random generator is weak and can be predicted.
- natcombs 6y ago> What do you mean plain text? This: "We will send the ciphertext through Signal and the one-time pad through WeChat." You're sending the OTP in plaintext. This is the age-old key distribution problem, and that's not magically solved by using a separate channel.
- ljlolel 6y agoI used those words, but if you understand how OTP/XOR works, they're both kind of OTP. They're both totally random 0's and 1's. Only putting them together (using simple XOR) makes them a message. The separate channels is important since each is mostly E2EE secure except for the whole government spying problems, but usually not all of them cheaply on each service. We live in unique times now where this wasn't as relevant or possible before. Does that make sense?
- hinkley 6y agoNo, it doesn’t. People who are anonymous can generally have anonymous conversations. Once anyone becomes interested in those conversations, they are not anonymous and none of their existing strategies are applicable. State actors have the resources to store messages now and correlate them later. If either is plain text, the other will fall.
- hinkley 6y agoWe make keys long to prevent people being able to guess them. If I intercept 40% of the key, haven’t I reduced the effective key strength by 40%?