4 ms·
I wrote some "home made" crypto about a year ago. It's a one-time pad implementation. http://16s.us/FreeOTP/nsa/ http://16s.us/FreeOTP/nsa/ The math behind OT
by 16s 13y ago
I wrote some "home made" crypto about a year ago. It's a one-time pad implementation.
http://16s.us/FreeOTP/nsa/ http://16s.us/FreeOTP/nsa/
The math behind OTP is pretty simple, but I may have made a mistake. I've posted the source code to crypto forums, HN, wilders security and emailed it to several prominent crypto developers/experts. No one seems to care nor want to look at it in-depth.
I've worked as a dev where we encrypted research data using standard, industry-accepted crypto (RSA and symmetric AES, etc) as well.
Having said that, I'm not an expert. And the real experts (Bruce Schneier) won't verify anything. They just say, "It's not been broken yet, which is a good indication."
Dive in and write some crypto code. Do it and make mistakes. That's how you learn. Not every program is life or death/mission critical. And if you never do it, you won't learn how. We learn by making mistakes.
Tarsnap is nice crypto code if you like C. It's easy to read too. I have no relation to Colin Percival or tarsnap. He's an expert, and even he makes mistakes:
http://www.daemonology.net/blog/2011-01-18-tarsnap-critical-security-bug.html http://www.daemonology.net/blog/2011-01-18-tarsnap-critical-...
- jessaustin 13y agoNo one seems to care nor want to look at it in-depth. I'm not an expert, but I wouldn't look at an OTP implementation either. Key management is already hard enough. It's hard to imagine a useful system you could build on a one-time pad.
- 16s 13y agoAnyone wanting to learn more about information theory, decrypting to multiple plaintext messages or unbreakable encryption would find it interesting. OTP is an edge case and it does not scale (I understand that), but is useful for small messages between two parties when privacy is paramount. Government states have used it. Also, I can't find any other OTP source code that compiles and works.
- jessaustin 13y agoSure, learning is good. Any introductory crypto class would consider OTP for a bit. But you seem to be asking people to critique the system as if it would be used for a non-educational purpose. (If that's not what you mean I apologize for misunderstanding.) That just seems really unlikely.
- 6d0debc071 13y agoYou take a file an xor it with the pad. It's like five minutes work, tops. The user interface on top of that might be very interesting, but I honestly find it hard to imagine that the underlying algorithm could be messed up and that you'd still have something that could use the keyfile on something encoded to produce a readable plaintext. Not wishing to be a drag here, but it's been done over and over again in every intro to cryptography class I've seen. Sorry ^^;