3 ms·
I'm curious - if you encrypt the message before embedding it in the image, it should be impossible to prove that a message exists (unless prosecution has its ha
by conanite 16y ago
I'm curious - if you encrypt the message before embedding it in the image, it should be impossible to prove that a message exists (unless prosecution has its hands on the original), because changing only the lowest-order bit of each byte of image data probably has less impact than the noise from the camera itself, especially if it's an old camera. Alternatively, given any image and any message small enough, you could prove the message is hidden in the image.
- btilly 16y agoThat is exactly the idea. Incidentally any form of encryption becomes even harder to break if you compress the message first. Furthermore this results in a shorter encrypted message, which is easier to hide. So the correct strategy is always compress, then encrypt, then encode.
- CWuestefeld 16y agoI don't think this is correct, at least if you're using a decent algorithm. What's more, if you encrypt by using, say, ZIP, then the resulting file will have a known header, and that makes it tremendously easier to decrypt. I've read that one of the factors that led to breaking Enigma was that Germans would habitually end their messages with "Heil Hitler". By assuming that was the ending of most messages, the mathematicians were able to work backward to find the key.
- KirinDave 16y agoEnigma was much more vulnerable to known plaintext attacks than modern ciphers are, because enigma was actually fantastically flawed as ciphers go. When space isn't a constraint, it's fairly easy to greatly reduce the advantage a known plaintext block gives an attacker by using random padding. Now instead of having to try every key looking for your zip header from offset 0, they have N places to start. There are techniques to mitigate this problem as well, but it's much more of a hassle. In any case, SOME simple compression is generally the order of the day with stenography message passing; you only get a few bits per pixel (usually not even a byte per pixel) so space becomes a premium. Perhaps known-plaintext attacks are how the FBI managed to produce an example of a message with hidden data in it. To me, it seems like such a thing would be very difficult to prove. Anyone with sufficient sophistication to carry out such an attack probably has the sophistication to hide their ability to do it (via, say, hidden truecrypt volumes as workspaces). Because the FBI & DHS has leveled some pretty absurd allegations at suspected terrorists in the past, including random doodles being secret attack plans, simple home movies being terrorist scouting videos (“Do you see the way the camera flicked towards that trash can? That's signaling the terrorists that this trashcan is a good place for a bomb.”), and innocuous phone conversations being elaborate code systems. In all cases, the DHS and FBI experts swore that only someone hyper-trained could ever detect the hidden messages; a normal person could not even if they were told it was there. It was BS, of course, but people can be so afraid of terrorism that they're too scared not to give that kind of argument credibility.
- btilly 16y agoIn truth if you're using a decent algorithm, then breaking it is effectively impossible anyways. But that said, techniques for breaking encryption rely on identifying redundant information in a message. The less redundant information there is, the harder this is to do. Sure, the known header on a ZIP is useful redundancy. But the amount of introduced redundancy is much, much less than the redundancy you got rid of by moving from a document in English to binary gibberish. Underlying this is a fundamental fact of information theory, which is that messages with a high information density look like white noise. A slight mistake in the message you have results in something that looks like another potentially valid message rather than something that is obviously wrong. This makes it much harder to verify that you're on an intermediate step towards properly decrypting the message. Therefore increasing information density makes an attacker's life harder. Compression increases information density by a lot, and so makes the encryption harder to break.
- CWuestefeld 16y agoI think I'm understanding your argument, but I don't think it's correct. A well-encrypted message -- whether pre-compressed or not -- is indistinguishable from noise. If it was not pre-compressed, then its information density is lower, which means the S/N is lower. Information theory tells us that the worse the S/N, the harder it is to extract the information.
- btilly 16y agoWhether or not you agree with it, the argument is believable enough to have been presented in a graduate level course that I was in a number of years ago. (The course was on wavelets, but background review on information theory was presented at the beginning.) You are correct that a perfectly encrypted message is indistinguishable from noise. Decryption is the art of distinguishing imperfectly encrypted messages from noise. Anything that makes the message harder to distinguish, makes decryption harder. Which means that the more the message looks like noise, the harder it is to decrypt. Your attempted counter argument fails on the fact that a redundant message has very little noise, and therefore has a high S/N despite having not that much signal per bit. However that said, it is true that if you take a redundant message, remove some redundancy by adding some random noise to it, then encrypt it, the result will be harder to decrypt than if you just encrypted the original redundant message. Of course the fundamental reason behind that is that detecting redundant information is at the heart of decryption. In that light it is interesting to compare the two known perfect encryption mechanisms. The first is the one-time pad. In that case the transmitted message has absolutely no redundancy because the definition of the encryption method contains as much information as the transmitted message. The second is for the two end points to have a list of pre-agreed messages of equal likelyhood, which they will refer to in binary code. This offers perfect compression with absolutely no redundancy, and therefore the attacker again has absolutely no way to guess what the pre-encoded messages are. (This is much harder to do properly in practice than one time pads, which themselves are pretty tricky.)
- stcredzero 16y agoIncidentally any form of encryption becomes even harder to break if you compress the message first. Furthermore this results in a shorter encrypted message, which is easier to hide. It's true in general that shorter messages are harder for an attacker to decrypt. http://en.wikipedia.org/wiki/Unicity_distance http://en.wikipedia.org/wiki/Unicity_distance It's not really significant in this case, though. The password was written on a slip of paper.