Cryptography Intermediate

One-Time Pad & the Two-Time Pad Attack

XOR the message with a random pad the same length, used once, and the result is provably unbreakable — the only cipher in this course with that guarantee. Reuse the pad a single time and it becomes trivially breakable. Both halves are here.

XOR with a random pad
Any plaintext is possible
Live key-reuse attack
Live
Message and Pad
The pad is generated with crypto.getRandomValues, the browser's cryptographic random source. A pad from Math.random() would look identical and be worthless — the randomness is the entire security.
Message length0 bytes
Pad length0 bytes
Status—
Ciphertext
Ciphertext (hex)
Decrypting again with the same pad
XOR is its own inverse: (m ⊕ k) ⊕ k = m. Encryption and decryption are the same operation, which is why the pad must never be used twice.
Why It Cannot Be Broken

Pick any plaintext you like of the same length. There is always a pad that turns the ciphertext into exactly that — so the ciphertext rules nothing out. This is what perfect secrecy means, and it is why the one-time pad survives an adversary with unlimited computing power.

That pad is just as random-looking as the real one, and nothing in the ciphertext says which is genuine. Chapter 20 states this as H(P | C) = H(P): the ciphertext leaves your uncertainty about the plaintext exactly where it was.

The two-time pad attack
Use the pad twice and it all collapses. If c₁ = m₁ ⊕ k and c₂ = m₂ ⊕ k, then c₁ ⊕ c₂ = m₁ ⊕ m₂ — the pad cancels completely and an attacker is left with the XOR of two English sentences, which is readable.
c₁ ⊕ c₂ = m₁ ⊕ m₂ (hex)

XOR the crib against m₁⊕m₂ and, wherever the guess is right, the other message appears in the clear.

Message 2, revealed

Drag the crib along, guess a word, and each correct guess exposes the same span of the other message. Real traffic has been broken exactly this way — the VENONA project read Soviet cables for years because pads were reused.

The Only Provably Unbreakable Cipher
c = m XOR k m = c XOR k

Three conditions, all required: the pad is truly random, at least as long as the message, and never reused. Meet all three and the cipher is information-theoretically secure.

That is a far stronger claim than anything else in this course. RSA is secure because factoring is believed hard; a better algorithm could change that tomorrow. The one-time pad is secure because the ciphertext genuinely contains no information about the message — unlimited computing power does not help.

The reason is the panel above: for every candidate plaintext of the right length there is a pad producing that exact ciphertext, and all of them are equally likely. There is nothing to compute.

Shannon proved in 1949 that perfect secrecy requires a key at least as long as the message. So the one-time pad is not merely one solution — it is essentially the only one.
Why Nobody Uses It

The guarantee is real and the cost is brutal. Every condition is a logistics problem:

  • Key distribution. To send a gigabyte securely you must first deliver a gigabyte of key securely — which is the original problem, unsolved.
  • True randomness. A pad from an ordinary random number generator is predictable and the guarantee evaporates. It needs a physical entropy source.
  • Never reusing it. One repeat and the attack above applies. This is the failure that keeps happening in practice, not in theory.
  • No integrity at all. Flip a bit of ciphertext and you flip exactly that bit of plaintext, undetected. The pad hides content; it does nothing to stop tampering.
Diplomatic hotlines and some espionage traffic really did use one-time pads. Everything else uses a short key and settles for computational security — which is what the rest of the course is about.
Put It Into Practice

The tool shows the mechanism — the slides show why it is built that way.

Perfect secrecy, and its price

The one-time pad is the cleanest idea in cryptography and the least practical. Understanding exactly why is the fastest route to understanding what every other cipher is trading away.

Book a Free Consultation →