Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But the OTP is still secure against that attack because the “key” is never reused. It is literally just noise, no useful information whatsoever.



It isn’t secure against the attack because the oracle uses the same key.

The oracle is a tool used to formalize our definition. You’re right that the fact that OTP isn’t CCA secure doesn’t matter in practice because the key is only used for one message so such an oracle doesn’t generally exist.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: