The thing I'm stuck on though, isn't it still possible to do semantic analysis on the various permutations. Basically reading permutations for cogent statements? So do some sort of a-posteriori analysis
Infeasible for a human to do, but assuming one could construct a significantly advanced parser (non-trivial of course), wouldn't it be possible to brute force still? What am I missing?
"The swallow flies at midnight"
May (with a one time pad) be encrypted into
"WD4oXOl8yO0QtD4sOf7ip0P7ScIia"
(which, incidentally, is indistinguishable from random noise)
If you just bruteforced that by xor'ing every character with every other possible character you could derive every possible message of that length, such as:
"garfield hate lasagna someday"
"men are cats why even bother?"
"pocket knives go to space yay"
etc ad infinitum
No measure of semantic analysis will help you here!
If you use the same one time pad to encode two or more different messages, then all the sorts of attack proposed here become plausible again.
The security provided by a one time pad relies entirely on the fact that it is only ever used once.
Computerphile recently showed how this was done.
Imagine a one time pad made for encoding numbers that used a "MOD 10" operation on each digit.
Then imagine the key is:
6926560279774
And the message is: 0000000000000
The output is: 6926560279774
Alternative messages: 1234567890123 -> 7150027069897
1111111111111 -> 7037671370885
In all cases, the patterns that you can discern may be from my message and may be from the key. As an analyst, you can't tell.If this were English letters rather than numbers, and you know 'e' is very common, you still can't get anywhere because each 'e' is encoded with a unique character from the key.
With public key crypto it's a lot more likely that something might be broken. But then again if you somehow solve the problem of swapping secret keys/OTPs with everyone you want to talk to, you don't need public key crypto.