4 ms·
> a one time pad is and will remain highly secure A one-time pad generated correctly and used correctly will remain highly secure, provided you have a highly s
by dllthomas 2y ago
> a one time pad is and will remain highly secure
A one-time pad generated correctly and used correctly will remain highly secure, provided you have a highly secure means of sharing the key material. There's a lot rolled into those assumptions.
- bawolff 2y agoAt the same time "highly secure" is significantly underselling it. One time pads (if properly implemented) are information-theoretically secure. Even if you solve P=NP your one time pad will not be cracked. It is safe against an adversary with both infinite time and infinite compute. That type of security comes at a cost.
- dreamcompiler 2y agoAnd the cost is that one-time pads are a royal pain in the ass. But if you're willing to pay that price without cutting corners, you get a completely unbreakable crypto system that will laugh in the face of the NSA and quantum computers.
- bawolff 2y agoIn fairness, quantum doesn't really help against normal crypto (of the type that is being discussed - symmetric). AES-256 will also laugh in the face of QC.
- dreamcompiler 2y agoIndeed. Quantum is only useful (in principle) against some types of asymmetric algorithms.
- dllthomas 2y agoTBH, I think "highly secure" might be overselling it. Yes, assuming you're generating random numbers well, there's actually zero chance your security will be breached because of an attack on your encryption algorithm. But there's not actually zero chance that your random number generation is flawed, and (very much more important) the cost is in making harder the pieces of your system that are probably more likely to fail in the first place. And of course you're still potentially vulnerable to traffic analysis and such even if all the rest goes right.
- dtx1 2y ago> But there's not actually zero chance that your random number generation is flawed, and (very much more important) the cost is in making harder the pieces of your system that are probably more likely to fail in the first place. I don't think it's that hard to get true randomness. Just measure something random in nature like radio static.
- c22 2y agoPerhaps not, but truly secure randomness is much harder. If someone else can measure the same thing you're measuring then it doesn't matter if it's random. If they can influence what you're measuring that's even worse. In the case of radio static, for example, your RNG could be compromised by a another compromised device simply colocated nearby.
- bawolff 2y agoIn the event your adversary knows so much about your procedures that they can tune into the radio used to generate randomness, presumably it would be much easier just to steal the piece of paper the pad is written on. Which does kind of further your point that one time pad makes more secure the parts that are already incredibly secure, while not helping the real weaknesses of cryptosystems i.e. the human element.
- jajko 2y agoThere are server cards (or were at least some time ago) with tiny bit of mildly radioactive material, well enclosed of course, and a good sensor for those isotopes/particles. I've heard other approaches including that static too, ie the famous analog TV without real signal, IIRC its cosmic microwave background, or camera watching water drops fall or similar. There are many other ideas (and probably products too), the only thing is one needs to keep it 100% reliable across long time.
- rubslopes 2y agoThe Lavarand is a cool example: https://en.m.wikipedia.org/wiki/Lavarand https://en.m.wikipedia.org/wiki/Lavarand
- Animats 2y ago> There's a lot rolled into those assumptions. Yes. No one seems to have mentioned VENONA.[1] [1] https://en.wikipedia.org/wiki/Venona_project https://en.wikipedia.org/wiki/Venona_project