[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
using pgp to make an otp
-- [ From: amp * EMC.Ver #2.3 ] --
-----BEGIN PGP SIGNED MESSAGE-----
i may have posted this at some time in the past, as i have asked it
elsewhere and gotten different responses. i'm interested in that the
folx here think about it though, so here it is...
i want a source of data for use as a otp. i don't want to have to
hook up any external devices to my pc to do it. (although some of the
methods mentioned in the past few days are quite interesting.)
i'd like to know if there was a reason not to use the output of pgp
to do it. i've been playing with the following method. i take a file
and encrypt it to a key with the '-a' flag on. this generates an
ascii file that is easily editable using simple, standard rexx calls.
i strip the first 20 or so lines and the last 20 or so lines
and put the resulting file aside. then i perform the same operation
again and append the file to the previous result. i repeat until the
file is sufficiently large for my purposes and then give the
resulting file to the person(s) i want to have it.
i still need a program to make use of the otp i've produced, but
havent gotten that far as this is still pretty much a thought
experiment and something for me to waste time with. once i'm ready to
make use of it i'll either find a program or attempt to write
something to use to make the data i've generated useful.
i would think that the output of pgp should be pretty darn random. if
it isn't, then it's usefulness is less than its reputation imo. as
you can tell if you've read this far, i'm not a cryptographer. i just
like the stuff and am working to become more proficient in its use as
i think it is important if we are to maintain our privacy in an
increasingly digital world.
what are the holes in this? why would it be unadvisable to do it?
otoh, would it be a good basis for a otp?
PGP Key = 4A2683C1
November 5, 1995 1:16
-----BEGIN PGP SIGNATURE-----
-----END PGP SIGNATURE-----