[3153] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: OTP Revival?

daemon@ATHENA.MIT.EDU (Marcus J. Ranum)
Thu Aug 6 10:25:46 1998

Date: Thu, 06 Aug 1998 09:57:52 -0400
To: horns@t-online.de, cryptography@c2.net
From: "Marcus J. Ranum" <mjr@nfr.net>
In-Reply-To: <m0z4K88-0003CYC@fwd04.btx.dtag.de>

>http://www.wired.com/news/news/technology/story/13920.html

One could almost write a book on one-time-pad braindamage...

What's so amazing is that the folks who push this stuff
sometimes have "credentials" (though not anymore!) in
security and encryption. Atalla, for example, squandered
his reputation on the Tristrata nonsense.* There were
the Assymetrix(sic) guys and their "Power One Time pad"
which was a fairly basic autokey that used IP addresses
and login passwords as a seed, etc, etc, etc...

For those who care, the official one-time-pad FAQ is:
http://www.clark.net/pub/mjr/pubs/otpfaq/index.htm

I wonder if I should add a section on "Bogus One-time-pads
I have known" to the FAQ -- but it'd be much much too long...

mjr.
----
*(Sending "OTP"s around encrypted with blowfish? Get outta here!)
--
Marcus J. Ranum, CEO, Network Flight Recorder, Inc.
work - http://www.nfr.net
home - http://www.clark.net/pub/mjr

home help back first fref pref prev next nref lref last post