Re: how to detect breakage -- lures etc.??
Arnold Reinhold via cryptography <[email protected]> Sun, 5 Jan 2020 11:48:10 -0500
| Newsgroups | gmane.comp.encryption.general |
|---|---|
| Message-ID | <[email protected]> |
--===============6516143748770076691== Content-Type: multipart/alternative; boundary="Apple-Mail=_2C75D8A3-4F55-4889-99C5-39F63231F22F" --Apple-Mail=_2C75D8A3-4F55-4889-99C5-39F63231F22F Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 > On Jan 4, 2020, at 5:12 PM, Charles Jackson <[email protected]> wrote: >=20 > On Sat, Jan 4, 2020 at 2:24 AM Arnold Reinhold via cryptography = <[email protected] <mailto:[email protected]>> wrote: >=20 > > The SIGABA/ ECM-II sets, which by all accounts was never broken = during the war, > In Big Machines: Cryptographic Security of the German Enigma, Japanese = PURPLE, and US SIGABA/ECM Cipher Machines Kelly states (IIRC) that in = the 1970s, NSA deputy director Tordella = (https://en.wikipedia.org/wiki/Louis_W._Tordella = <https://en.wikipedia.org/wiki/Louis_W._Tordella>) stated that they = still could not break SIGABA/ECM. =20 >=20 > A paper by Stamp and Chan estimated that the SIGABA had a key of about = 95 bits. IIRC, they assume that the attacker knows the rotors. If you = assume that the attacker has to recover the rotors from observing the = traffic, then the work required must be much greater. We all admire how the Poles and later the British were able to recover = rotor wiring cryptographically. The Soviets apparently had a different = approach. The Cryptomuseum page on the U.S. KL-7, = https://www.cryptomuseum.com/crypto/usa/kl7/ , a successor to SIGABA, = has a section on the Soviet =E2=80=9CRotor Reader,=E2=80=9D with a photo = and diagram. This was a small, folding device, pocket sized, with 36 = contacts and lights designed to quickly scan and readout the wiring of a = KL-7 rotor. It was recovered from John Anthony Walker when he was = arrested in 1985. He had been given it when he started spying in 1967. = An identical device was recovered from U.S. Army Sergeant Joseph Helmich = in the mid 70s. The devices are well designed, obviously not one-offs. = Someone with crypto access could smuggle one into a code room and = quickly write down the 36 numbers for a rotor while his two-man-rule = colleague was napping or otherwise not paying attention. No doubt the = Soviets had a supply of these devices for the KL-7 and other machines = and systematically looked for cleared people at remote installations = whom they could bribe or blackmail into recovering rotor wiring.=20 I expect the intelligence agencies of the world today all have USB = dongles designed to plug into computers to inject malware and grab = passwords and private keys, just waiting for a compromised person with = access to plug them in. Arnold Reinhold --Apple-Mail=_2C75D8A3-4F55-4889-99C5-39F63231F22F Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; = charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;" class=3D""><br = class=3D""><div><br class=3D""><blockquote type=3D"cite" class=3D""><div = class=3D"">On Jan 4, 2020, at 5:12 PM, Charles Jackson <<a = href=3D"mailto:[email protected]" class=3D"">[email protected]</a>> = wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><div = dir=3D"ltr" class=3D""><div class=3D"gmail_quote"><div dir=3D"ltr" = class=3D"gmail_attr">On Sat, Jan 4, 2020 at 2:24 AM Arnold Reinhold via = cryptography <<a href=3D"mailto:[email protected]" = class=3D"">[email protected]</a>> wrote:<br = class=3D""></div><blockquote class=3D"gmail_quote" style=3D"margin:0px = 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <br class=3D""> > The SIGABA/ ECM-II sets, which by all accounts was never = broken during the war, </blockquote><div = class=3D""></div></div></div></div></blockquote><br class=3D""><blockquote= type=3D"cite" class=3D""><div class=3D""><div dir=3D"ltr" class=3D""><div= class=3D"gmail_quote"><div class=3D""><div style=3D"font-size:small" = class=3D"gmail_default">In<i class=3D""> Big Machines: Cryptographic = Security of the German Enigma, Japanese PURPLE, and US SIGABA/ECM Cipher = Machines </i>Kelly states (IIRC) that in the 1970s, NSA deputy director = Tordella (<a href=3D"https://en.wikipedia.org/wiki/Louis_W._Tordella" = class=3D"">https://en.wikipedia.org/wiki/Louis_W._Tordella</a>) stated = that they still could not break SIGABA/ECM. <br = class=3D""></div><div style=3D"font-size:small" = class=3D"gmail_default"><br class=3D""></div><div = style=3D"font-size:small" class=3D"gmail_default">A paper by Stamp and = Chan estimated that the SIGABA had a key of about 95 bits. IIRC, = they assume that the attacker knows the rotors. If you assume that = the attacker has to recover the rotors from observing the traffic, then = the work required must be much greater.<br = class=3D""></div></div></div></div></div></blockquote><br = class=3D""></div><div>We all admire how the Poles and later the British = were able to recover rotor wiring cryptographically. The Soviets = apparently had a different approach. The Cryptomuseum page on the U.S. = KL-7, <a href=3D"https://www.cryptomuseum.com/crypto/usa/kl7/" = class=3D"">https://www.cryptomuseum.com/crypto/usa/kl7/</a> , a = successor to SIGABA, has a section on the Soviet =E2=80=9CRotor = Reader,=E2=80=9D with a photo and diagram. This was a small, = folding device, pocket sized, with 36 contacts and lights designed to = quickly scan and readout the wiring of a KL-7 rotor. It was recovered = from John Anthony Walker when he was arrested in 1985. He had been = given it when he started spying in 1967. An identical device was = recovered from U.S. Army Sergeant Joseph Helmich in the mid 70s. The = devices are well designed, obviously not one-offs. Someone with crypto = access could smuggle one into a code room and quickly write down the 36 = numbers for a rotor while his two-man-rule colleague was napping or = otherwise not paying attention. No doubt the Soviets had a supply of = these devices for the KL-7 and other machines and systematically looked = for cleared people at remote installations whom they could bribe or = blackmail into recovering rotor wiring. </div><div><br = class=3D""></div><div>I expect the intelligence agencies of the world = today all have USB dongles designed to plug into computers to inject = malware and grab passwords and private keys, just waiting for a = compromised person with access to plug them in.</div><div><br = class=3D""></div><div>Arnold Reinhold</div><br class=3D""></body></html>= --Apple-Mail=_2C75D8A3-4F55-4889-99C5-39F63231F22F-- --===============6516143748770076691== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ The cryptography mailing list [email protected] https://www.metzdowd.com/mailman/listinfo/cryptography --===============6516143748770076691==--