8 ms·
> If you listen to the same station again and again you start to see a pattern. That's what the numbers monitors and enthusiasts are very good at doing. Usual
by tpolzer 9y ago
> If you listen to the same station again and again you
start to see a pattern. That's what the numbers monitors
and enthusiasts are very good at doing. Usually when that
pattern starts to emerge it fits the profile of the kind
of cypher called a one-time pad
What did I just read? A true one time pad by definition is truly random without any patterns.
- imglorp 9y agoThe encrypted data, yeah, but as a practical matter they would need to have some metadata telling the recipient which pad to use. As long as the sender avoids the german tank numbering problem, and never repeats a pad or message, the metadata should be useless to an attacker. https://en.wikipedia.org/wiki/German_tank_problem https://en.wikipedia.org/wiki/German_tank_problem Also, I was initially thinking why bother in the age of Pastebin and Twitter, and even Craigslist: the receiving equipment is available way more easily than a shortwave radio. I think the answer is, you can absolutely guarantee nobody knows if a message was received. Those internet methods could be watched.
- iClaudiusX 9y agoIn this case, a more relevant example from World War II might be the exploitation of flaws in the Enigma machine, namely: 1) the re-use of common phrases in weather reports, and 2) the fact that a letter could not be encoded as itself in the ciphertext, providing a mechanism of contradiction that drastically sped up elimination of possible settings https://en.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma#Operating_shortcomings https://en.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma#Op... Numberphile gives a nice, succinct explanation https://www.youtube.com/watch?v=V4V2bpZlqx8 https://www.youtube.com/watch?v=V4V2bpZlqx8
- roywiggins 9y agoThere's nearly no cryptanalysis that can be done with a properly-arranged one-time-pad scheme. Other than metadata, there's nothing to be learned about the encrypted data. Attacking a one-time-pad is nothing like attacking Enigma. That said, they've been attacked semi-successfully before, due to pad reuse: https://en.wikipedia.org/wiki/Venona_project https://en.wikipedia.org/wiki/Venona_project
- lgas 9y agoI think pad reuse would disqualify it from the "properly-arranged one-time-pad scheme" club :)
- lawnchair_larry 9y agoThere is a potential major weakness even with a one time pad, which is exactly why numbers stations are permanently transmitting - side channel information leakage. By observing an increase or decrease in channel activity, you can learn things.
- secfirstmd 9y agoI get the security of one time pads but don't they rely on randonmess at the very start (e.g printing)? So as in many cases the randomness generator is the risk?
- lozenge 9y agoThis is true but randomness is cheap. I can order 1,000 OTPs made from different locations and discard 999. The chances of it being compromised are minimal.
- jaclaz 9y ago>Also, I was initially thinking why bother in the age of Pastebin and Twitter, and even Craigslist: the receiving equipment is available way more easily than a shortwave radio. I think the answer is, you can absolutely guarantee nobody knows if a message was received. Those internet methods could be watched. Not only, unless there is some technology that I am not aware of, you can also be pretty sure that what is received is what has been transmitted, in other words you remove the possibility of a MITM attack.
- zokier 9y agoIt is likely that not all operatives are deployed in environments with ubiquitous internet (or other infrastructure..). And even if they had internet access now, the situation might be very volatile and operatives lose access the moment they need it the most. Even in western world the ubiquitousness of internet is relatively recent phenomenon; I would expect most of the number stations to be much older than that. And (para-)military like every other large organization changes slowly, especially when turning away from working, tested and true, solution.
- VLM 9y agoRadio is also one to many, inherently. And you can do social engineering head games with counter intel officers. Send 37 distinct repeated messages one day... that would seem to strongly imply 37 individual agents, but in reality you could have anything from 0 to 1000. OTP message #24256 might be heard by field agents 351 938 and 271 and it means "check your dead drop signal". One agent sees a chalk mark on the street and gets a real message at his dead drop, the other two see nothing and chill. OTP message 91053 could mean "unrestricted warfare begins tomorrow at noon" for all 1000 agents, perhaps. Or maybe OTP message 91053 means nothing, nothing at all and its all head games for counter intel. There are also chain strategies such as I own a "suspicious" shortwave radio and listen to it (which in some parts of the world that are not USA, is not unusual or suspicious) and when I get OTP message I am to offer my collectible Dale Earnhardt mint condition collectors plate for $1599 on ebay. The agent who's actually doing something interesting is a well known 90s nascar fan and when he sees my collectors plate offered for $1599 on ebay when the going rate is $5, that's when he steals the secrets or pushes the button or whatever. I listen to shortwave which means I could be a spy but all I ever do is try to sell junk on ebay, whereas the "real" agent is an indistinguishable nascar fan. There are protocols using OTP where the metadata could quite easily give away an agent even if the data is never cracked even with the rubber hose technology. For example imagine a really bad protocol of page number, word number. Won't take long to figure this out when the first number increases at a predictable rate never exceeding 351 pages and the second number never exceeds the number of words on a page. All you need to do is have customs record the number of pages in each book travelers import, and when you figure out the pad rotates at 351 pages you find the guy who entered the country with a 351 page book, and do absolutely nothing other than alert customs to record the exact name and edition of every book he has ever or will ever import, at which point you now have a copy of his one time pad. That's a horrible protocol that uses OTPs, but its hardly the only crackable one that exists. Personally, given how incredibly cheap it is to transmit numbers over the radio, and how incredibly expensive it is for counterintel to try to figure it out and track it, even if it were obsolete 20 years ago, I'd still keep doing it as a pure economic attack. That counterintel agent listening to numbers is one agent who's not inspecting the contents of suspicious looking icmp packets or multiplayer video game conversations or funny chalk marks in front of libraries or whatever.
- 9y ago
- a3847 9y ago>> Usually when that pattern starts to emerge it fits the profile of the kind of cypher called a one-time pad By pattern, I assume they mean the numbers are indistinguishable from uniformly random bits. If the data is publicly available it would be interesting to test this hypothesis.
- foundart 9y agoOne-time refers to usage. They could be repeating one-time pads to ensure they are received. The intended recipients can probably not be counted on to be listening at any particular time.