XOR the message with a random pad the same length, used once, and the result is provably unbreakable — the only cipher in this course with that guarantee. Reuse the pad a single time and it becomes trivially breakable. Both halves are here.
crypto.getRandomValues, the browser's cryptographic random source. A pad from Math.random() would look identical and be worthless — the randomness is the entire security.Pick any plaintext you like of the same length. There is always a pad that turns the ciphertext into exactly that — so the ciphertext rules nothing out. This is what perfect secrecy means, and it is why the one-time pad survives an adversary with unlimited computing power.
That pad is just as random-looking as the real one, and nothing in the ciphertext says which is genuine. Chapter 20 states this as H(P | C) = H(P): the ciphertext leaves your uncertainty about the plaintext exactly where it was.
XOR the crib against m₁⊕m₂ and, wherever the guess is right, the other message appears in the clear.
Drag the crib along, guess a word, and each correct guess exposes the same span of the other message. Real traffic has been broken exactly this way — the VENONA project read Soviet cables for years because pads were reused.
c = m XOR k m = c XOR k
Three conditions, all required: the pad is truly random, at least as long as the message, and never reused. Meet all three and the cipher is information-theoretically secure.
That is a far stronger claim than anything else in this course. RSA is secure because factoring is believed hard; a better algorithm could change that tomorrow. The one-time pad is secure because the ciphertext genuinely contains no information about the message — unlimited computing power does not help.
The reason is the panel above: for every candidate plaintext of the right length there is a pad producing that exact ciphertext, and all of them are equally likely. There is nothing to compute.
The guarantee is real and the cost is brutal. Every condition is a logistics problem:
The tool shows the mechanism — the slides show why it is built that way.
The one-time pad is the cleanest idea in cryptography and the least practical. Understanding exactly why is the fastest route to understanding what every other cipher is trading away.