Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: One-Time Pad software? |
|---|---|
| Date: | Sat, 3 Feb 2007 21:27:18 -0500 (EST) |
On Sat, 3 Feb 2007, FocusHacks wrote:
Thanks for the information, guys. As far as one-time pads being the same length as the cleartext, I know how it works. If a spy of days past had a very long message to encrypt, he may need to use more than one page of his paper pad. By the same token, if I have a large binary file to encrypt, but have stored several small files of random data to use as my pad (and the receiving party has the same files and knows in which order to utilize them), I would expect a tool to be able to handle the task. It's not convenient to generate a perfect-length pad file for every ciphertext message I wish to transmit. Looping a 20k file over a larger cleartext message would not be OTP, it'd be a simple running key algorithm that'd be a lot easier to break with simple heuristics. Sure, it'd be a 20 kilobyte key, a lot less trivial than looping an eight-letter lowercase word as a key, but it wouldn't be nearly as good as a genuine OTP.
=====================================
The reason I'm thinking small files is because on solid state media (for instance, volatile storage in a PDA), it's easy to securely erase one file at a time, which is much like burning the piece of paper you just used. correctly implemented, OTP is both computationally trivial to perform, yet "perfectly secret", so long as the pad remains secure.
=====================================
-- ...atom
________________________ http://atom.smasher.org/ 762A 3B98 A3C3 96C9 C6B7 582A B88D 52E4 D9F5 7808 -------------------------------------------------
"The proposition that intelligence has any long-term
survival value remains to be demonstrated."
-- Arthur C. Clarke| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | VA Loses another Hard Drive with data on 48,000 veterans, Saqib Ali |
|---|---|
| Next by Date: | memory unwiping, Fabio Nigi - |
| Previous by Thread: | Re: One-Time Pad software?, FocusHacks |
| Next by Thread: | Re: One-Time Pad software?, profeten |
| Indexes: | [Date] [Thread] [Top] [All Lists] |