Hacker News new | ask | show | jobs
by kvthweatt 171 days ago
The point is you can perform a box dimension attack.

If you have a known input, you can match all outputs.

Example: Document that DOJ took down and reuploaded that redacted Trump's name when it was previously available. They used the same size boxes in each location.

You cannot do this with handwriting, but fonts have known widths.

1 comments

Couldn’t it be the same letters in a different order?
A probabilistic attack on redaction is still an attack.

You'd never be blase about the same information about your password.

Plus with redaction there's a pretty small number of posible words when the boxes are small.

depending on the font used, the spacing between letters can change depending on what letters are next to each other.
ie. Twerp