Cryptography Worldcryptographyworld.com

Section 4 — The Pad

Reuse is fatal

Use the same pad page twice and the one-time pad becomes a two-time pad — and the mathematics of unbreakability vanish.

SectionThe Pad
RegisterEntry 16 of 22
LengthShort entry
Vintage typewriter, handwritten note, envelope and pocket watch on a wooden desk
The one system in the register with a proof behind it, and the only one whose difficulty is entirely logistical.Photograph — collection credit

The guarantee dissolves on second use

The one-time pad earns its guarantee from a single condition: each key stream is used exactly once. Break that condition, and the cipher does not weaken gracefully. It collapses.

The arithmetic is blunt. If two plaintexts are enciphered with the same key material — whether by accident, carelessness, or the pressure of wartime — an adversary who intercepts both ciphertexts can combine them. The key cancels out entirely, leaving the XOR (or modular sum, in older additive systems) of the two plaintexts against each other. That combined stream is no longer random. It carries the statistical shape of two languages interleaved. A patient analyst, working with guessed words or known cribs, can peel the messages apart.

A reel of punched paper tape on a bench
Teleprinter traffic is enciphered character by character as the tape runs, with no operator between the two.Photo: Nikita Korchagin / Pexels

The technique is called "cribbing into depth." Two messages enciphered on the same key are said to be in depth, and depth is exploitable. Guess a probable word in one message — a greeting, a sender's name, a standard phrase — subtract it from the combined stream, and test whether the residue looks like plausible text in the other. A good guess propagates; a bad one produces nonsense. Working outward from confirmed fragments, a skilled cryptanalyst can recover both messages with no knowledge of the key at all.

Soviet signals intelligence succumbed precisely this way. During the Second World War, NKVD/NKGB and GRU one-time pad material was duplicated under production pressure and issued to multiple stations. American and British analysts, working from the late 1940s onward in a programme eventually disclosed as VENONA, spent years exploiting those depths. Thousands of messages yielded at least partial recoveries — identifying agents, tracing networks, reading traffic that had been assumed permanently sealed.

The lesson is not subtle. The pad's mathematical proof of security holds only when randomness is fresh for every message. Reuse is not a small compromise or an acceptable shortcut; it is a category error that retroactively destroys every assumption the system was built on. The key is the security. Using it twice hands a version of it to anyone with both ciphertexts and patience.

A single rotor wheel showing its contacts, macro
Twenty-six pins on one face, twenty-six plates on the other, and a single fixed permutation between them.Photograph — collection credit