6 ms·
I feel it is important to recognize that schemes like this are not OTP, and drawing an analogy between the two risks inducing false intuitions. This discussion
by mannykannot 1y ago
I feel it is important to recognize that schemes like this are not OTP, and drawing an analogy between the two risks inducing false intuitions.
This discussion started with a proposal to back up Enigma with one-time pads, but harshreality pointed out that OTPs are not vulnerable to anything except compromise of the OTP itself. This has the unstated corollary that if you are using a true OTP system, adding Enigma to the process does nothing to improve security (unless your pre-shared keystream is compromised - and even then, capturing one U-boat's OTP will not compromise any other's communication.)
You then raised the concern of generating keys in sufficient quantity, which is certainly part of the problem (though I suspect that an electro-mechanical solution for that problem was well within the capabilities of contemporary technology, especially as, by then, Konrad Zuse had produced the first digital computer.) If, however, we are restricting our source of keys to the amount of text in a daily newspaper (or even all of the Third Reich's daily newspapers combined), that is something that could be achieved by a corps of dice-rollers, if it came to that, which would avoid one of the other problems of using newspapers: the statistical regularities of newspaper text.
Even then, you still have the problems of key reuse [1] and key distribution, and another which I think might be by far the hardest: training people to use it. Even just considering the submarine fleet, at least one person on each U-boat would have to be trained in properly using the technique. This would delay implementation, and once deployed, even with no mistakes, it would be slow in use.
Alternatively, a machine to do the work might have been developed (together with another to generate physical machine-readable keys), but that itself would have meant considerable delays in implementation.
In view of this, I feel that the measure actually adopted - adding another rotor position to the Enigma machine - was one of the better options (though it would have been even better if the additional rotor were interchangeable with the others.) This took time to implement and was ultimately defeated, but anything other than an OTP system would likely have the latter problem, and all would have had the former.
[1] Maybe not so much of an issue if one is only dealing with submarine communication, given that most of this was with the U-boat High Command in Germany, and assuming that it was of sufficiently low volume for each U-boat to be be given its own unique set of keys for each patrol.
- WalterBright 1y agoAlso, there weren't that many U-Boots, and I expect (but am not sure) that the communications with U-Boots would be pretty short. The shorter the message, the harder it would be to do a statistical attack. I mentioned also that coordinates and times could be offset by a predetermined amount, and be different for each U-Boot.
- mannykannot 1y agoThe German navy did not use latitude and longitude in their messages; it had a coded grid system (the Gradnetzmeldeverfahren.) As you guessed, they also used secret offsets which were changed periodically. Nevertheless, by making use of captured material, the allies became quite successful at figuring out the actual coordinates, suggesting that the German navy was somewhat complacent about the effectiveness of these measures. As for times, my understanding that they would, at least sometimes, specify them in the form of so many hours after a specific trigger message was received. This seems to require the U-boat to be surfaced (or maybe just at periscope depth?) from the start of the window for this message until it was received. None of this addresses the training issue from earlier. The thing is, if you are thinking of using a newspaper-based scheme only for U-boats, you might as well go the extra distance to implement a true OTP system, which seems feasible at that scale and which would turn the use of Enigma in series into an academic exercise.
- WalterBright 1y agoOf courses, a OTP would be better. But there are problems with generating them (I doubt a bingo ball would be fast enough) and then you've got a courier problem (hope your courier isn't a spy), etc. With a newspaper, you just have to supply a date, which can be memorized. BTW, I've used dice rolls to generate passwords, but the dice would always fall off my desk and roll into an inaccessible corner, and I soon tired of that. It also only worked for 6 digits! So I switched to a real RNG.
- mannykannot 1y agoThe point that your scheme requires just one date to select single newspaper as a key for one U-boat per patrol underscores how feasible it would be for an organization with the resources of the German navy to generate the same sized random keys, your personal experience with key generation notwithstanding. As for key interdiction, it would have to be at massive scale, as having a handful of random keys does not enable industrial-scale decryption, which is what the allies needed (and had, some of the time) for signals intelligence to be useful against U-boats. In contrast, the leaking of one date would compromise the entirety of the communications conducted under it (i.e., at least those for one U-boat for the duration of the patrol), especially given that German newspapers were readily available in neutral and occupied countries. OTPs are, in fact, way more resistant to espionage than your newspaper scheme. The failure of the location-shifting scheme (as mentioned in my previous post) to stop the allies interdicting rendezvous, despite its periodic changes, also suggests that one date per patrol is not going to be good enough. We have reached the point where the alleged superiority of your newspaper scheme hangs on the tendency of dice to roll off your desk!