3 ms·
To be fair, when I read the title I thought that if the string is truly random then it's actually a very good technique. This is the core operating principle be
by sigkill 14y ago
To be fair, when I read the title I thought that if the string is truly random then it's actually a very good technique. This is the core operating principle behind the one-time pad which is provably secure.
Now that I read the article twice, I literally got a panic attack when I realized that it wasn't a random string that they were xor'ing their data with, but a string called "RANDOM_STRING". Although it sounds bad, one must realize that this is not security by obscurity since the key has been leaked, and nobody guarantees encryption against a leaked key.
- Dylan16807 14y ago'very good technique' The important part of a one time pad isn't the xor, it's the length. This does not even begin to resemble a one time pad. It's an xor cipher.
- sigkill 14y agoYeah exactly. I cannot convey the utter disappointment I had when I realized that it was "RANDOM_STRINGRANDOM_STRINGRANDOM_STRING...." that they were XOR'ing with.