Re: how to detect breakage -- lures etc.??

Arnold Reinhold via cryptography <[email protected]> Sun, 5 Jan 2020 11:48:10 -0500
Newsgroups gmane.comp.encryption.general
Message-ID <[email protected]>
--===============6516143748770076691==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_2C75D8A3-4F55-4889-99C5-39F63231F22F"


--Apple-Mail=_2C75D8A3-4F55-4889-99C5-39F63231F22F
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8



> On Jan 4, 2020, at 5:12 PM, Charles Jackson <[email protected]> wrote:
>=20
> On Sat, Jan 4, 2020 at 2:24 AM Arnold Reinhold via cryptography =
<[email protected] <mailto:[email protected]>> wrote:
>=20
> >  The SIGABA/ ECM-II sets, which by all accounts was never broken =
during the war,

> In Big Machines: Cryptographic Security of the German Enigma, Japanese =
PURPLE, and US SIGABA/ECM Cipher Machines Kelly states (IIRC) that in =
the 1970s, NSA deputy director Tordella =
(https://en.wikipedia.org/wiki/Louis_W._Tordella =
<https://en.wikipedia.org/wiki/Louis_W._Tordella>) stated that they =
still could not break SIGABA/ECM. =20
>=20
> A paper by Stamp and Chan estimated that the SIGABA had a key of about =
95 bits.  IIRC, they assume that the attacker knows the rotors.  If you =
assume that the attacker has to recover the rotors from observing the =
traffic, then the work required must be much greater.

We all admire how the Poles and later the British were able to recover =
rotor wiring cryptographically.  The Soviets apparently had a different =
approach. The Cryptomuseum page on the U.S. KL-7, =
https://www.cryptomuseum.com/crypto/usa/kl7/ , a successor to SIGABA, =
has a section on the Soviet =E2=80=9CRotor Reader,=E2=80=9D with a photo =
and diagram.  This was a small, folding device, pocket sized, with 36 =
contacts and lights designed to quickly scan and readout the wiring of a =
KL-7 rotor. It was recovered from John Anthony Walker when he was =
arrested in 1985. He had been given it when he started spying in 1967. =
An identical device was recovered from U.S. Army Sergeant Joseph Helmich =
in the mid 70s. The devices are well designed, obviously not one-offs. =
Someone with crypto access could smuggle one into a code room and =
quickly write down the 36 numbers for a rotor while his two-man-rule =
colleague was napping or otherwise not paying attention. No doubt the =
Soviets had a supply of these devices for the KL-7 and other machines =
and systematically looked for cleared people at remote installations =
whom they could bribe or blackmail into recovering rotor wiring.=20

I expect the intelligence agencies of the world today all have USB =
dongles designed to plug into computers to inject malware and grab =
passwords and private keys, just waiting for a compromised person with =
access to plug them in.

Arnold Reinhold


--Apple-Mail=_2C75D8A3-4F55-4889-99C5-39F63231F22F
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D""><br =
class=3D""><div><br class=3D""><blockquote type=3D"cite" class=3D""><div =
class=3D"">On Jan 4, 2020, at 5:12 PM, Charles Jackson &lt;<a =
href=3D"mailto:[email protected]" class=3D"">[email protected]</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><div =
dir=3D"ltr" class=3D""><div class=3D"gmail_quote"><div dir=3D"ltr" =
class=3D"gmail_attr">On Sat, Jan 4, 2020 at 2:24 AM Arnold Reinhold via =
cryptography &lt;<a href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a>&gt; wrote:<br =
class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br class=3D"">
&gt;&nbsp; The SIGABA/ ECM-II sets, which by all accounts was never =
broken during the war, </blockquote><div =
class=3D""></div></div></div></div></blockquote><br class=3D""><blockquote=
 type=3D"cite" class=3D""><div class=3D""><div dir=3D"ltr" class=3D""><div=
 class=3D"gmail_quote"><div class=3D""><div style=3D"font-size:small" =
class=3D"gmail_default">In<i class=3D""> Big Machines: Cryptographic =
Security of the German Enigma, Japanese PURPLE, and US SIGABA/ECM Cipher =
Machines </i>Kelly states (IIRC) that in the 1970s, NSA deputy director =
Tordella (<a href=3D"https://en.wikipedia.org/wiki/Louis_W._Tordella" =
class=3D"">https://en.wikipedia.org/wiki/Louis_W._Tordella</a>) stated =
that they still could not break SIGABA/ECM.&nbsp; <br =
class=3D""></div><div style=3D"font-size:small" =
class=3D"gmail_default"><br class=3D""></div><div =
style=3D"font-size:small" class=3D"gmail_default">A paper by Stamp and =
Chan estimated that the SIGABA had a key of about 95 bits.&nbsp; IIRC, =
they assume that the attacker knows the rotors.&nbsp; If you assume that =
the attacker has to recover the rotors from observing the traffic, then =
the work required must be much greater.<br =
class=3D""></div></div></div></div></div></blockquote><br =
class=3D""></div><div>We all admire how the Poles and later the British =
were able to recover rotor wiring cryptographically. &nbsp;The Soviets =
apparently had a different approach. The Cryptomuseum page on the U.S. =
KL-7, <a href=3D"https://www.cryptomuseum.com/crypto/usa/kl7/" =
class=3D"">https://www.cryptomuseum.com/crypto/usa/kl7/</a> , a =
successor to SIGABA, has a section on the Soviet =E2=80=9CRotor =
Reader,=E2=80=9D with a photo and diagram. &nbsp;This was a small, =
folding device, pocket sized, with 36 contacts and lights designed to =
quickly scan and readout the wiring of a KL-7 rotor. It was recovered =
from&nbsp;John Anthony Walker when he was arrested in 1985. He had been =
given it when he started spying in 1967. An identical device was =
recovered from U.S. Army Sergeant Joseph Helmich in the mid 70s. The =
devices are well designed, obviously not one-offs. Someone with crypto =
access could smuggle one into a code room and quickly write down the 36 =
numbers for a rotor while his two-man-rule colleague was napping or =
otherwise not paying attention. No doubt the Soviets had a supply of =
these devices for the KL-7 and other machines and systematically looked =
for cleared people at remote installations whom they could bribe or =
blackmail into recovering rotor wiring.&nbsp;</div><div><br =
class=3D""></div><div>I expect the intelligence agencies of the world =
today all have USB dongles designed to plug into computers to inject =
malware and grab passwords and private keys, just waiting for a =
compromised person with access to plug them in.</div><div><br =
class=3D""></div><div>Arnold Reinhold</div><br class=3D""></body></html>=

--Apple-Mail=_2C75D8A3-4F55-4889-99C5-39F63231F22F--

--===============6516143748770076691==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
The cryptography mailing list
[email protected]
https://www.metzdowd.com/mailman/listinfo/cryptography

--===============6516143748770076691==--