Gaming Can one-time pads leak plaintext?

  • Thread starter Thread starter Deleted User
  • Start date Start date
  • Views Views 762
  • Replies Replies 1
D

Deleted User

Guest
One-time pads are said to be mathematically impossible to crack provided you only use them once. I was thinking about them the other day and thought of a possibility that it may leak plaintext. One-time pads are a very long string of random numbers*.

Let's pretend I want to send the string "Fuck you Costello" to someone here. We have already shared the one-time pad and it is not compromised.
Code:
ASCII:       F        u        c        k                 y        o        u                 C        o        s        t        e        l        l        o
String:      01000110 01110101 01100011 01101011 00100000 01111001 01101111 01110101 00100000 01000011 01101111 01110011 01110100 01100101 01101100 01101100 01101111
Key:         00010000 01100001 00010000 10000000 11100001 00000100 01100001 00100000 10100101 00010000 10011100 11100100 00100000 11011100 01001000 11010100 10011100
Cipher text: 01010110 00010100 01110011 11101011 11000001 01111101 00001110 01010101 10000101 01010011 11110011 10010111 01010100 10111001 00100100 10111000 11110011
In this example the one-time pad successfully distorts the plain-text beyond recognition. The chance that every bit in the one-time pad is 0 is 1/2^136. The next part of the maths is beyond me. If you are a spy using a 1TB one-time pad then perhaps there is a realistic chance that somewhere in the pad there is a long section of 0's. In real-world situations if there is a byte consisting of all 0 or 1 bits will it be removed from the pad?

* Random in the sense that the distribution of bits is statistically random and unpredictable. The philosophical debate of truly random numbers is beyond the scope of this post.
 
Pad generation is a fun one.

The 360 was noted as having "randomness detection" built into the startup routine for its effectively one time key for memory crypto. Though in practice this was more just a check to make sure someone did not null it out as part of an attack.

All 0 or all 1 is a known problem in crypto for many things so some pads in turn will check to see what goes. Others will go more with probability that there will not be a significant run or even if there was the attacker will not know whether it was essentially random or false flag (wasting cryptanalyst time is often a solid plan, stick a list of codenames of their stuff in there and smoosh it up but still have it guessable and you never know)..

That said for one time pad XOR type stuff, and pad to match message length it seems rather than repeated key, I would be more worried about other methods of leaks and analysis.
 

Site & Scene News

Popular threads in this forum