4 ms·
Steganography conceals the existence of the message, not just the contents. if David Miranda gets stopped at Heathrow and: On the following morning, the g
by brey 13y ago
Steganography conceals the existence of the message, not just the contents.
if David Miranda gets stopped at Heathrow and:
On the following morning, the gener·al requested permission to return the emperor's visit, by waiting on him in his palace.
A pitched battle follow·ed.
But the pride of Iztapalapan, on which its lord had freely l·avished his care and his revenues, was its celebrated gardens.
...
is in his twitter account, it's in no way plausible that they're just innocuous tweets, and he can be compelled to reveal the secret.
A true steganographic message would have looked indistiguishable from any other tweet that he would have made normally. this is a cute system, but it's not steganography.
- dpapathanasiou 13y agoThe output is a function of the corpus. So if Miranda doesn't usually tweet about the history of Mexico, he can pick other texts (written by him or others) which would sound more plausible as something he might normally tweet. Having said that, the middle dot is not as unobtrusive as I would like, so perhaps it's better to rethink that part of the system, using some of the other suggestions in this thread.
- brey 13y agoeven ignoring the middle dot, just picking a more suitable corpus for that person isn't necessarily going to make this technique look innocuous - it's still a collection of excerpts taken from what looks like random positions within a document. it looks suspicious. you could imagine a system which uses entirely normal and habitual tweets, but encodes information in choices of synonyms used in the text, or whether or not punctuation was used in certain places, or the timing of the tweet's publication. lower bitrates, but plausibly deniable as to the message's existence.
- dpapathanasiou 13y agoI would posit that a stream of non-sequitir tweets is not necessarily suspicious (depending on the person/account in question, of course). The classic steganography methods you're describing may appear less obvious (for lack of a better term), but they're also easier to break once the pattern is discovered.
- brey 13y agojust as hard to break if you're doing it properly: one bit per tweet, encoded as 'message ends with period = 1, no period = 0', and that's your ciphertext stream. from then, AES or RSA or a OTP or whatever you want. Then what you're writing will be functionally indistinguishable from random. hmm ... but maybe too random, humans are bad at being truly random - the entropy in your period usage will be too high ... perhaps xor the RSA output with a OTP of something 'random' you scribbled yourself on a page ;-)
- dllthomas 13y ago"perhaps xor the RSA output with a OTP of something 'random' you scribbled yourself on a page ;-)" ... seemingly random bits, xored with anything not directly related to the bits in question produces seemingly random bits... There are other ways of transforming a sequence of bits to look less uniform, though.
- akkartik 13y agoUnless he's constantly making tweets like this.