The one-time pad: unbreakable on paper

Two identical sheets covered in columns of small marks, half overlapping on a desk, with a pencil and a die beside them.

Everything on this site runs on a computer doing sums with numbers you cannot reach. Not this chapter. Here you make a cipher you carry out with a pencil, on a sheet of paper you put in your pocket, and which is proven to be unbreakable. No supercomputer, no quantum computer, nobody. And then you see why almost nobody uses it.

Words you might need

One-time pad
A list of random letters, printed twice: one for you, one for the other person. You use every letter on that list exactly once.
Modulo 26
Doing sums with the alphabet as a clock with 26 hours. After Z comes A again. You know this from chapter 6, where it was a clock with 23.
Proven secure
Not "never been cracked", but mathematically shown that there is nothing to crack. That is a strong claim, and this is about the only cipher it holds for.
Key distribution
The problem of how you get a key to the other person without anyone else reading it on the way. At the bottom of this chapter it turns out the whole problem sits here.

How it works

Give every letter its number: A is 0, B is 1, up to Z is 25. Take the first letter of your message, take the first letter of your pad, add the two numbers together. If you go above 25, subtract 26. The number you have left is your cipher letter. Then the second letter, with the second letter of the pad. And so on.

cipher letter = (message + pad) mod 26

message = (cipher letter − pad) mod 26

That is all. Add to close, subtract to open. It can be done with a pencil, and during the Cold War it was done exactly like that for years, with little pads of paper the size of a stamp.

Why this cannot be cracked

Suppose you intercept the ciphertext XQFMB. You try every pad. With one pad out comes HOUSE. With another SLEEP. With yet another NIGHT. All three are perfectly good English words, and there is no reason at all to think one is more right than another.

That is the difference with everything you have seen so far. With a Caesar the right answer gives readable text and the other 24 give nonsense, so you know straight away which it is. Here every possible message of that length gives a valid pad. The ciphertext tells you literally nothing about the message except how long it is.

Three rules, and not one of them is negotiable. The pad has to be as long as the message. It has to be really random, so rolled and not made up, see chapter 2. And you may use it only once. Drop one of the three and the whole proof collapses, and further down this page you see how hard.

Make your own pad

A pad of random letters

Everything happens in your browser. Nothing is sent to the server, and nothing is stored.

  1. Choose how many letters you want and click Make the pad.
  2. Click Print. Print twice: one sheet for you, one for the person you are going to write to. Hand it over when you see each other.
  3. Close this tab and come back. The pad is gone. That is on purpose: what you have not printed no longer exists.

Encrypt by hand

Everything happens in your browser. Nothing is sent to the server.

  1. Type your message. Make a pad above first if you have not done so.
  2. Work out the first five letters yourself, on paper. Put your answer in My answer and click Check me.
  3. Then click Show the addition to see how the demo did it, letter by letter.

What happens if you use the pad twice

You have pad left over and you want to send something else. Tempting, and fatal. Call the two messages m1 and m2, and the pad k. Then one ciphertext is m1 + k and the other is m2 + k. Subtract them:

(m1 + k) − (m2 + k) = m1 − m2

The k drops out. The eavesdropper is left with the difference of your two messages, and there is not a scrap of secret in it any more. From that moment one guess is enough: guess part of one message and the other rolls out by itself.

Two messages, one pad

Everything happens in your browser. Nothing is sent to the server.

  1. Click Send them both. You see the two ciphertexts and their difference.
  2. Now pretend you are the eavesdropper. You suspect the first message starts with ATTACK. Type that in My guess and click So what is in the other one?
  3. Try a guess that is not in there, and see what comes out then.

Why almost nobody uses this

You have just made the best cipher in the world, and it cost you a sheet of paper. So why is this not in your phone?

Because you had to hand the pad over first. The two of you had to meet. And if you can meet without anyone listening in anyway, you might as well have whispered the message there and then. If you want to send a hundred letters tonight, you have to hand over a hundred letters today. For an hour of chatting on a messaging app you need millions.

That is the reason the rest of this site exists. chapter 6 solves exactly this: agreeing on a secret without ever having met. You pay for it with a cipher that is no longer provably unbreakable, only unbreakable as long as nobody finds a clever trick. That is the trade, and practically the whole world has made it.

One group has not. For links where it really matters, one-time pads on paper still exist, rolled with a die and handed over by hand. Not because it is convenient, but because it is the only thing you do not have to hope is right.

This is math: perfect secrecy

Claude Shannon, the same one behind the entropy in chapter 2, wrote down in 1949 what "unbreakable" exactly means: a cipher is perfectly secret if the chance of a given message after seeing the ciphertext is exactly the same as it was before. You have learned nothing. He proved that the one-time pad manages it, and right behind that something far less pleasant: that it is only possible if your key holds at least as much entropy as your message. That is not a shortcoming of this one system but a lower bound for all of them. So every time you use a 256-bit key on a two-gigabyte film, you are not buying perfect secrecy but something weaker: a system that can be broken, just not in the time anybody has. That distinction between "cannot" and "takes too long" runs through the whole of modern cryptography, and this is where you first see it sharply.