Forthcoming book seeks to visualise, locate and expose many numbers stations
vice.com
vice.com
What did I just read? A true one time pad by definition is truly random without any patterns.
https://en.wikipedia.org/wiki/German_tank_problem
Also, I was initially thinking why bother in the age of Pastebin and Twitter, and even Craigslist: the receiving equipment is available way more easily than a shortwave radio. I think the answer is, you can absolutely guarantee nobody knows if a message was received. Those internet methods could be watched.
1) the re-use of common phrases in weather reports, and
2) the fact that a letter could not be encoded as itself in the ciphertext, providing a mechanism of contradiction that drastically sped up elimination of possible settings
https://en.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma#Op...
Numberphile gives a nice, succinct explanation https://www.youtube.com/watch?v=V4V2bpZlqx8
That said, they've been attacked semi-successfully before, due to pad reuse:
Not only, unless there is some technology that I am not aware of, you can also be pretty sure that what is received is what has been transmitted, in other words you remove the possibility of a MITM attack.
Even in western world the ubiquitousness of internet is relatively recent phenomenon; I would expect most of the number stations to be much older than that. And (para-)military like every other large organization changes slowly, especially when turning away from working, tested and true, solution.
And you can do social engineering head games with counter intel officers. Send 37 distinct repeated messages one day... that would seem to strongly imply 37 individual agents, but in reality you could have anything from 0 to 1000. OTP message #24256 might be heard by field agents 351 938 and 271 and it means "check your dead drop signal". One agent sees a chalk mark on the street and gets a real message at his dead drop, the other two see nothing and chill. OTP message 91053 could mean "unrestricted warfare begins tomorrow at noon" for all 1000 agents, perhaps. Or maybe OTP message 91053 means nothing, nothing at all and its all head games for counter intel.
There are also chain strategies such as I own a "suspicious" shortwave radio and listen to it (which in some parts of the world that are not USA, is not unusual or suspicious) and when I get OTP message I am to offer my collectible Dale Earnhardt mint condition collectors plate for $1599 on ebay. The agent who's actually doing something interesting is a well known 90s nascar fan and when he sees my collectors plate offered for $1599 on ebay when the going rate is $5, that's when he steals the secrets or pushes the button or whatever. I listen to shortwave which means I could be a spy but all I ever do is try to sell junk on ebay, whereas the "real" agent is an indistinguishable nascar fan.
There are protocols using OTP where the metadata could quite easily give away an agent even if the data is never cracked even with the rubber hose technology. For example imagine a really bad protocol of page number, word number. Won't take long to figure this out when the first number increases at a predictable rate never exceeding 351 pages and the second number never exceeds the number of words on a page. All you need to do is have customs record the number of pages in each book travelers import, and when you figure out the pad rotates at 351 pages you find the guy who entered the country with a 351 page book, and do absolutely nothing other than alert customs to record the exact name and edition of every book he has ever or will ever import, at which point you now have a copy of his one time pad. That's a horrible protocol that uses OTPs, but its hardly the only crackable one that exists.
Personally, given how incredibly cheap it is to transmit numbers over the radio, and how incredibly expensive it is for counterintel to try to figure it out and track it, even if it were obsolete 20 years ago, I'd still keep doing it as a pure economic attack. That counterintel agent listening to numbers is one agent who's not inspecting the contents of suspicious looking icmp packets or multiplayer video game conversations or funny chalk marks in front of libraries or whatever.
I've had this theory that chat in multiplayer games is probably one of the most reliable methods to bypass dragnet surveillance that exists.
Figure that most popular chat protocols are reverse engineered and actively captured. Moreover, any crypto usage beyond https will simply flag you.
It's concievable that NSA/GCHQ have had people dedicated to reversing videogame chat protocols for some time now, but given the veritable Cambrian explosion of games we've seen in recent years thanks to Steam, I have serious doubts that even major SIGINT agencies can keep up.
Their best hope is that the game uses IRC, a cloud service, or some other standardized chat protocol as a backing for its in-game chat. If it's some obscure game with a custom-but-unencrypted chat protocol, I highly doubt it's automatically interpreted. At best the raw data itself is probably captured and stored for a short period of time. It is possible however that they're applying automated methods to anomalous traffic that are able to pull out unencrypted text streams.
Of course, why use in-game chat when you could just pick a game that has a way to write out a message in the game itself. Minecraft clones and certain multiplayer paint apps become more or less perfect steganography in that case.
Obviously if someone's already targeted it's simple for any self-respecting SIGINT agency to just install implants and get whatever they want. I was describing measures that would likely foil automated bulk analysis.
Now if you're implying there's some sort of bulk, indiscriminate implantation program, that would be news to pretty much every private sector security expert on the planet. May as well just tap fiber for appearances at that point.
Are you sure? I thought it was widely accepted that you couldn't trust chinese hardware or most american firmware.
Implants are the payloads that persistently infect target systems, surveil or modify the envrionment, and exfiltrate data.
So unless you want to suggest the majority of consumer systems are actively compromised to the point of exfiltrating screen caps on a regular basis, my original point still stands. Even then, good luck conducting successful automated analysis on hidden messages made out of blocks in Minecraft. Reconstructing game state as it went across the wire would be easier than making sense of screenshots in that scenario.
I don't believe every computing device ever is exfilling the amount of data you describe, but I'd be very very surprised if it weren't an option for nation level actors at the flick of a switch.
Screw minecraft, all I need is access to your USB/ethernet controllers and that's not remotely difficult.
I believe your threat model is flawed if you don't assume any existing known vulnerability isn't being at least passively used to surveil remote systems.
"I was describing measures that would likely foil automated bulk analysis."
Nothing you just said is relevant in that context. Yes, obviously anything can be easily compromised if it's targeted. I said as much in the very same post.
Automated bulk analysis exists to find targets in the first place.
Recall Stuxnet and some of its successors were partially reverse engineered, and just recently Intel's Management Engine is being torn apart.
Most users simply couldn't give a crap and we're gonna pay for the loss of accountability at some point
To most people, it's just another dumb piece of spam with a crappy JPEG attached.
To others, it's an encrypted message hidden within the JPEG, identified by certain key phrases in the come-on text, possibly within the Bayesian poisoning which amounts to sequences of random words anyway.
To GCHQ and the NSA, it's... well, if they want to dig through all the spam in the world looking for hidden messages which might not be there, let them.
One issue there would be that each time they go out to parks or other places to check for dead drops they are risking getting exposed.
I think by now most counter intel people expect OTP to be used so they are probably not spending an inordinate amount of resource on cracking them.
As for broadcasting, maybe have OTP pads for groups and individuals. The first part of the message is encrypted with a group OTP which then either broadcasts a message to all members or indicates a particular member to use their individual pad to read the rest of the message. Even during transmission those can be compartmentalized so for example the head of the group can send a one to one message and encode it with that recipients OTP pad, but then hand the encrypted message to the radio person in charge of transmitting general the general group message.
By pattern, I assume they mean the numbers are indistinguishable from uniformly random bits. If the data is publicly available it would be interesting to test this hypothesis.
My understanding was that it was easy to triangulate the location of a transmitter (if you're close enough to it and not receiving reflections). Shouldn't a transmitter in the middle of Virginia be trivial to verify?
Buy a small, white, Chevrolet van, plaster AT&T logos on the sides, put a flashing yellow light on top, and mount a holder for some orange road cones on the rear bumper. I figure with a vehicle like that, you can park just about anywhere, wander around, poke at stuff, and do all sort of shit, without anybody batting an eye. Especially wearing coveralls and a safety vest and hardhat, and carrying a clipboard.
http://telstarlogistics.typepad.com/telstarlogistics/2006/09...
One of my fun projects I have planned is to script a "number station" in python based on the general patterns these number stations have.