Drug cartels use dollar bill serial numbers as random keys for delivery receipts
twitter.com
twitter.com
1. Is a piece of paper torn in half really cryptography? Wikipedia says:
>Cryptography or cryptology is the practice and study of techniques for secure communication in the presence of third parties called adversaries
I don't see how this is any different than any other anti-counterfeiting schemes that uses a hard to duplicate physical object.
2. I get how the tear might be used for authentication purposes (hard to duplicate), but what's the point of validating the contents on the other half of the note? If you matched the public half the note exactly, it's not like the private half will help you authenticate it.
Cryptography is not just about confidentiality, ensuring authenticity is also cryptography.
> If you matched the public half the note exactly
The point is that it is hard to duplicate even the "public half" of the note.
So by that logic, a wax seal is also cryptography?
Of course, reading by breaking means armed thugs killed you. But we'll leave that analogy aside!
The "crypt" in "cryptography" means "hidden" (e.g. we hide dead bodies away in a "crypt"). Certainly if you don't know what's on the other side it s literally hidden from you.
The tear itself is a key. Depending on your level of technology you could make a matching part by inspection of the part you have, but consider the tearing a somewhat random process given the influence of the medium (paper money will be more random than polymer). It's a quick way to exclude candidates for the match.
The actual authentication then is through the completion of the text which is presumably a harder problem. You could make some text that matches, but it's presumably hard -- not perhaps has hard as finding a hash collision.
> The term comes from the medieval English "indenture of retainer"[1] — a legal contract written in duplicate on the same sheet, with the copies separated by cutting along a jagged (toothed, hence the term "indenture") line so that the teeth of the two parts could later be refitted to confirm authenticity
https://en.wikipedia.org/wiki/Chirograph
> A chirograph is a medieval document, which has been written in duplicate, triplicate or very occasionally quadruplicate (four copies) on a single piece of parchment, with the Latin word chirographum (occasionally replaced by some other term) written across the middle, and then cut through to separate the parts.
[1] I am thinking that the vast majority of info that I know about business was not learned in business school.
Responsible for the 1834 burning of Parliament:
https://addiator.blogspot.com/2011/05/tally-sticks-and-burni...
But they're not random keys at all, they're just guaranteed to be unique. Uniqueness and randomness are totally different aspects, one that often trips up some developers who think that UUIDs (which are guaranteed to be unique) are also guaranteed to be random (not necessarily).
That sentence is an oxymoron. They are called "serial" numbers because they are applied in series, i.e. one right after the other.
The randomness is not important. The person setting up the drop already has the dollar bill in hand. The important thing is that the bill can't be duplicated.
And it's nonrepudiation without identity, the identifying info is destroyed in the transaction.
The courier could just take a cell phone photo of the drop, but no one wants that evidence trail. One time use serials are perfect.
And despite some characterizations, seems to me like uniqueness is more important than randomness here, which is good, because serial numbers are better at that.
I'm not sure randomness is important here.
So I think they're mainly trying to prevent the drop from stealing the money (claiming the courier never showed), and prevent the courier from stealing the money (claiming the drop has it). If C steals, D can now say, "I still have the Boss's whole dollar, why didn't C come take it?" If D steals, C can say "I have part of the dollar, proving delivery."
The boss is also trying to simplify this protocol, make sure low level drug offenders don't have to do a complex ledger entry during the commission of a major crime.
The tear might be purely symbolic, to make it look more symmetric to both parties, who may or may not have read Schneier.
Or... the tear could be preventing the D from ambushing C during the exit. Once the bill is torn, it would be hard to claim the courier never showed, even if they could get both parts of it back.
I see what you're saying otherwise, and it's not like I can really think of a specific situation where re-joining the dollar would be important, but I am curious if you've got any thoughts on how that might be useful, if at all.
How are they making use of this feature set? I'd like to see a diagram with arrows and stuff.
Boss: "Courier, deliver this money to <address>, code is 12345678" Courier: at <address>, "Hey Drop, what is the code?" Drop: "Code is 12345678" Courier: "That's correct, Here's you're money" Drop: Tears bill in half and hands part with serial number to Courier as proof
Our money (US Currency) has two (of the same) serial numbers on each bill; one on the lower left and one on the upper right for dollar bills. Other denominations also have two; one on each side of the front of the bill, however they are in opposite places i.e. upper left, and lower right--at least the current bills in my wallet are that way.
People do this because having more than ~3000$ cash (in Rupees) is illegal, but people use it anyway.
So I can tell you that the Drop has the note.
And yes, here the whole note (bill) is given to the courier by Drop as receipt, not by tearing in half.
And I don't think even there people tear the serial number into half. Just the note.
Wait, really?
Do you mean no one is allowed to keep that much money in a safe in their house etc., or what?
Why?
The dealership, when time came to close, absolutely freaked when I pulled out the cash. Another set of IRS forms... and sorted it after several phone calls.
Where are you getting that from? [1] There is nothing even close to being illegal to possess in the US any amount of cash. There are laws to prevent illegal activity and against structuring (attempting to deposit below some limit to avoid disclosure).
Now to what appears to be your point having $100,000 in cash in open display in your car when you are stopped by the police will definitely raise suspicions. But then again so will many other things that are not illegal but might raise suspicions depending on the context of where they appear. (Walk into a bank with a toy pistol vs. walk around your friends backyard with a toy pistol).
[1] And what is 'nearly illegal' is that like 'nearly pregnant' (the classical example actually 'pregnant' or 'not').
“Only criminals carry large quantities of cash”.
Because the way people talk about civil forfeiture is as though this happens all the time, but ostensibly there's not supposed to be a problem if the cash is traceable.
Stories about civil forfeiture abuses that I've read don't delve into whether the victim actually was able to prove the source of the money in a normal way.
The problem is that this cash is essentially their entire savings. Which means their ability to fight the forfeiture is limited, and the arresting police can infer that. Rich people tend not to need to have even that amount of cash: they can take advantage of the normal banking system to transfer money. And if they were stopped, it's easy to infer that someone is at least rich enough to quickly hire good lawyers to fight the seizure.
However, with that said, I think caymanjim was being intentionally unspecific to prove a point. It's not against the written laws to have large sums of cash. But if such cash represents most of your wealth, and you're transporting it across certain areas, you're at the mercy of various law enforcement who may overstep their actual authority.
You're implying that people with reasonable documentation for the source of their cash can't just fill out some forms, but need to hire lawyers or something. Have you seen news articles or other sources describing such a situation?
I'm aware of stories like this, and I've read them before, but I wasn't asking for more. I used to donate to the IJ, in fact.
I just checked and the bank I had an account with for many years requires $50 deposited to open an account and no minimum balance or monthly fee, includes free checks and debit card.
The credit union I use now has no minimum balance, no monthly fee, and no fee for writing checks. You have to deposit $1 for a share of the credit union, which you get back if you close your account.
My impression is these days they are making over 2% on deposits absolutely risk free, so they better not charge anything.
Like I said, my credit union requires a deposit of one (1) dollar, which you get back when you close your account.
People here show concern over digital privacy and net neutrality etcetera but that's just tightening the noose, because apparently they've already put one on the bare basics.
And then taking out more than a limit of cash is a very lengthy process now.
So yes, it's not illegal to store cash but it's very difficult. And doing cash transactions above a certain limit are illegal.
Why? Because many business people in India don't pay taxes.
Assuming the actual transaction is reasonably atomic, which it should be unless there's a fight or something, the the carrier can always prove that they delivered to the correct drop if they have a physical copy of the agreed upon serial while the drop can prove that they didn't receive a delivery if they can reproduce an undamaged copy of the whole bill. The ripping of the bill itself could plausibly serve as a step in a multi step process where the carrier may demand that the bill be ripped after the serial and goods are confirmed but before not yet exchanged so that the drop can't claim that a delivery was not at least attempted on the part of the courier. We could also do it with two bills, one from each party such that each party can have some proof that a transaction was or wasn't completed and with the right party in the case of a double exchange.
The upfront cost of forging passable $1 bills is too high to be economical to pull off just for these low volume transactions, especially after the logistical cost of injecting the bills or otherwise tricking someone to using a fake as well as keeping a copy on hand but even if you achieved that. You'd also have to contend with the fed's coming after you for forging currency if the bills you distributed ever got into public circulation in any significant quantity so it should be pretty secure as long as they're sourced from a fairly high volume location like mcdonalds or something.
The entropy might be somewhat useful too in bookkeeping like maybe using only bills ending with a 0 are for small cash transactions, 1 for large cash transactions, 2 is for drugs A, 3 for drug B etc... Entropy might be important but there are much easier sources.
My guess is that such a list can generalize to HCI and help reveal some of the garbage assumptions behind a lot of common software (esp. cryptography-related software).
Yup, looks like it's more commonly written DTO/MLO.
SSL certificate passwords were easy to remember as long as nobody removed the bookmark no that useless dictionary.
But after the initial exchange, another random element is generated: the bill is torn in half, so if you want to forge your part, you'll have to tear it in just the right way to match the other part. This is probably going to be even more difficult than forging dollar bills in the first place.
A gift in the amount of $1 divided by the total number of dollars.
The parent is wrong that it's a gift of $1 to the Treasury.
It is a gift to the government however, as you note in your own explanation. It just increased the government's USD purchasing power. The US Government is an epic scale spender of USD (millions of employees, $4.x trillion budget).
The government does not possess all wealth.
It also issues a lot of USD-denominated debt; deflating the dollar makes that worse.
If the government's dollar liabilities exceed its dollar assets, the impact of destroying a dollar on the government's financial health is negative.
If you destroyed a coin that would be a “gift” to the Treasury, except the metal and cost of production to replace the coin might be larger than the worth of the coin (I.e. you destroy an old copper cent)
[0] dollar bills circulate like mad and are accounted for every time a bank gets a hold of them (often, due to vending machines, strippers, and diner waitresses). If a bill stops showing up, you can assign a high degree of probability that it will never show up again. Every one bill is probably long tailed, but money is fungible, so who cares if any one bill ends up re-appearing?
> Destroy the bill, destroy the liability
Except it is illegal to randomly destroy a banknote (coins are different).
We're talking about drug dealers and other major crime perpetrators... And you're thinking they care about the crime of 'destroying a bank note'?
I think it'd be safe to chalk that up to "I don't think they care".