If your cipher were secure, this image wouldn't have repeating patterns (2015)
mailarchive.ietf.org
mailarchive.ietf.org
See also: https://github.com/mmcc1/crystalline http://maldr0id.blogspot.com/2015/05/crystalline-cipher-and-...
The authors inability to take any criticism is stunning, sometimes I wonder if a fragile ego isn't one of the greatest barriers to cyber security..
> Designed to be as secure as a one-time pad, without a weakness due to the use of repeating keys,
That immediately shows that the person writing it doesn't know cryptography. You simply can't get the security of one-time pad without having a key the size of the data, and if you do, just use it as the pad.
The idea of a one-time-pad is that you're basically just randomly flipping the bits of your input, which means the output of an OTP cipher is indistinguishable from random data.
If you're using the same key multiple times though, then the output of the cipher (considered over time) won't be random, and you'll be able to detect patterns from the original input in the cipher output (e.g., the shape of an image, frequency of certain letters).
The thing is, if you know the same key has been used a second time, then yes, having both outputs (can? will? must? could?) helps to acquire the key.
But how do you know they're using the same one? Or how are you sure, they're not? All you have, are two pieces of random data.
The output of any _one_ use of the pad is, yes, but the point is to consider all of the data that an attacker may have. If you re-use the key multiple times, then the entirety of the cipher texts an attacker has is not random. (See also: https://xkcd.com/221/)
> But how do you know they're using the same one? Or how are you sure, they're not?
You'll be able to tell because you'll see patterns in the data: https://upload.wikimedia.org/wikipedia/commons/f/f0/Tux_ecb....
You encrypt the data ABCD -> EDGF.
You encrypt the data DEFG -> HGJI
Someone intercepts the data, and has: EDGF and HGJI
And now?
Or maybe like this: Since OTP and data are interchangeable, due to matching lengths, isn't using the same OTP with different data, essentially the same like using the same data with a different key?
That ASCII example is rather extreme, but all messages have patterns as long as you’re given enough of them you can break a reused OTP.
I guess one thing to note is that, if what you were transmitting was just random noise to begin with, OTP re-use may not matter/be evident. But essentially all data that people care about transmitting isn't random noise, it has some structure, and that structure comes through with OTP re-use (more and more the more you re-use and the more data you re-use with).
AIUI, the Enigma machine (not quite an OTP but I think similar) was broken in part because of just a few key re-uses https://en.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma#Op...
From my limited knowledge of the matter, that alone doesn't give you the cypher - you'll need to know additional information about the messages to get the cypher (statistics of words, conditional probabilities of letter sequences etc.). But without the one reuse of your cypher, you couldn't apply these techniques.
Story time: The USSR once reused an OTP key (after years or even decades, can't recall), but a US' three letter agency had the old ciphertext (A') and reused that to break the new ciphertext (B'). They probably had some scheme with a broadcaster saying "use codebook 1234, the secret is GARBLED DATA". At least that's the story a cryptography lecturer told us (and the fragments I remember).
Here's a good illustration of the principle: https://crypto.stackexchange.com/questions/59/taking-advanta...
Obviously it's more complicated with text (where you have less information filled in); for that you have to do crib dragging which is a bit more involved but not fundamentally difficult.
I've always assumed it was just adding the key-value to the data-value, as is described in the Wikipedia article[0].
And those two can't be the same, e.g. with both data and key value 'a' (0x5c), I'd get 0x0 with XOR and 0xb8 with addition.
EDIT: Ah, damnit, second paragraph, it says: "On July 22, 1919, U.S. Patent 1,310,719 was issued to Gilbert Vernam for the XOR operation used for the encryption of a one-time pad."
Everything I've posted in this thread about OTP was under the assumption of an additive cipher. My bad.
Edit for your edit: All of this discussion applies the same for additive OTP as it does for XOR OTP; once you have depths you can start applying the OTP (however it's done) “in reverse” as it were to begin extracting patterns in the data.
It does not appear he's uploaded slides yet but here is link to session: https://bsidessf2020.sched.com/event/Ybgu/break-crypto-like-...
He said he was going to check in his code to GitHub so may be able to find same with some detective work.
Essentially you could xor two encrypted images with the same OTP and see them sort of superimposed on one another.
You can easily discover reused keys if you can guess any part of either plaintext. From that guessed fragment, you can recover both plaintexts and the entire key (pad) using the "Zig Zag" method.
(P=plaintext, C=cyphertext, K=reused_pad, ⊕=XOR)
If we capture two ciphertexts that reused the same key
C1 = P1 ⊕ K
C2 = P2 ⊕ K
Then combining the ciphertexts cancels the key D = C1 ⊕ C2 = P1 ⊕ P2
The resulting D is also the plaintexts XORed together. If you can guess any part of either plaintext - a standard header or commonly used words (like "weather" or "Heil Hitler") - then XORing that guess with D reveals part of the other plaintext at the same position. Once a plausible match is found, the rest of the decryption is relatively easy: zig-zaging guesses of neighboring words extending out from the original guess.Professor Brailsford's explanation[1] of the method on Computerphile is nice introduction to this type of cryptanalysis.
In 09:05 ([0]) you can see why, namely that K and K cancel each other out.
I don't think this would be the case with an additive cipher.
EDIT: Continuing the thought with an additive cipher:
P1 + P2 = C1 + C2 + 2K
2K = P1 + P2 - (C1 + C2)
K = P1/2 + P2/2 - C1/2 - C2/2
Uhhh... we know both Cs. And... that's it? P1 + P2 = C1 + C2 - 2K
2K = C1 + C2 - (P1 + P2)
etc... C1 = P1 + K
C2 = P2 + K
C1 - C2 = P1 - P2
And if you can guess part of either plaintext, you'll see the same part of the other plaintext, and know what the key was, exactly the same as for XORing. As somebody else already pointed out, that's because XORing is a variety of addition anyway.Depends how motivated your enemy is
However, this meant there where leftover bits of each key. Though if you think of each bit as a different key then sure, just start each message with the offset.
Would like to know, if my assessment on additive OTP is correct, if anyone knows?
EDIT: I mean, of course you still shouldn't, but where the XOR catastrophically fails after just a single reuse, the additive one should be more robust, even with reuse. The Venona Decrypts were additive-OTP, I postulate, the decryption rate would've probably been higher with XOR-OTP.
Like if ciphertext is "supersecret" then it feels like plaintext can't be more obvious and OTP must be "00000000000", but there's nothing anywhere to logically/mathematically support it. OTP could be something else and plaintext could be "hackernews" or "ycombinato".
In reality a simple XOR with a random sequence preserve enough entropy of data that I've heard you could make out voices if used on media, so payloads must be scrambled, but that's not recovery, only a guess. ANY reuse breaks that notion and make it not an OTP cryptography.
> Crystalline employs information loss as the basis of its security.
If encryption loses information, there’s no way decryption can bring it back.
In the extreme
def encrypt(s):
return “(TOP SECRET)”
is totally secure, but also totally useless. def decrypt("(TOP SECRET)"):
return sa. The author cannot decrypt it either, unless he's cheating somehow, or
b. It's not really losing information and the author is lying.
> That immediately shows that the person writing it doesn't know cryptography. You simply can't get the security of one-time pad [..]
Talking about a one-time pad at all in the context of making something actually secure for internet usage, shows that the talker doesn't know about cryptography.
A one-time pad having "perfect security" is only true in the context of a particular security model that doesn't generally hold true on the internet - one where the adversary cannot change the ciphertext whilst it is in transit.
Under a more realistic security model, we need a message authentication code or some other equivalent, to protect against adversaries changing the ciphertext. It's a well-known theorem of modern cryptography that in fact if you don't have secure authentication under this model, then you cannot achieve secure privacy. In other words, your ciphertext has to be bigger than the plaintext for security on the internet.
(There is in fact a one-time-pad equivalent for MACs where your key is the length of the plaintext and the ciphertext ends up being several multiple times the length of the plaintext, but crackpots when making security arguments about "one-time pads" generally aren't referring to this and aren't even aware of the existence of this. It's a relatively unknown construction and nobody really talks about it in the context of serious modern cryptography.)
Everyone peed on him and he never came back.
The poor sap was right though. The proven algorithms tend to fail catastrophically when used or implemented incorrectly.
— Bruce Schneier
https://www.schneier.com/blog/archives/2011/04/schneiers_law...
I'm fascinated by his gentle nature as an algorithmic thinker who applied computer science to all aspects of his experience
To people like this, arguing is like punching. If you punch someone and they get up, they're a "tough opponent". That doesn't mean that punching is ineffective on other people. They just don't understand at their core that once an argument is shown to be false, it can never be reused. Their mind just doesn't work this way. They think "Well, left-hook didn't work on this guy, but maybe it'll work in that guy" or "This guy didn't fall for this argument, but maybe that guy will."
It's deeply dishonest, but I'm not convinced they're even aware of this.
So, just from a cursory look at his code, the glaring problems I see are:
1) It'll crash if you feed it more than 256MB because of the way the C# BitArray class works. He's also using 32-bit ints in several places that have similar issues. These are implementation details, but it just goes to show how thoughtless the "reference implementation" is.
2) Similarly, the reference implementation copies the entire data into the BitArrary (and then back into a byte array) for each "round". This is spectacularly inefficient. He never mentions throughput in terms of MB/s/GHz or any such thing. I wonder why...
3) It's not a stream cipher. You need to encrypt the entire file. Again, he could come up with some sort of streaming version by feeding in the last few KB of the previous encrypted chunk into the next chunk, but he hasn't. As the long history of various streaming ciphers have shown, this is actually a hard problem to solve efficiently and securely. This is why AES-GCM is the hot new thing: it's both.
4) If either the key or salt values are all 0s then the encryption does nothing. AES for comparison will still encrypt your data with some level of security even if the IV initialisation is not perfectly random or skipped.
5) He's calculating the offsets as an "int" from a byte multiplied by a byte. Hence the maximum shift is 65536 positions. This is just big enough to exceed L1 data cache on most platforms, but have a high hit ratio. Whether you hit the L1 cache or not depends on the Key & IV values, so this is a recipe for timing-based side-channel attacks. Constant-time cyphers are basically mandatory these days...
6) Related to the above: The bit shifts are only in an 8KB window, but the byte shifts are in an 64KB window. I wonder if there's some interaction here where this might make some keys insecure.
7) Despite this windowing, the default "protocol" wraps around the end of the file to the beginning using a modulo the data.Length, so it can't be used as a streaming cipher. To do so, he'd have to introduce a breaking change.
8) The encryption is defined in terms of bit-by-bit and byte-by-byte long-range operations, so there's basically no hope of ever making this efficient. E.g.: with SIMD or similar many-bytes-at-a-time instruction sets. The "state" that would have to be kept in CPU registers is over 64KB, so this is just never, ever, EVER going to compete with something like AES-NI.
I could go on, but I'm wasting my time. This is wasting everyone's time.
The author clearly has no interest in producing something that is secure and usable. He's just enjoying the arguments. He's even posted some of the feedback on his GitHub, proudly showing off the debates he's felt he's won.
Don't feed this troll.
So for example, imagine a primitive tribe of humans facing a drought. If they spend too much time discussing options democratically, if they don't all agree, or if they waste time by changing their mind half-way to a source of water, they'll all die. But if they follow an authoritative leader -- even if makes bad arguments or none at all -- they might all make it to the mountain spring in the distance and survive.
The gist of this is that in times of hardship, authoritarian, conservative, or "right-wing" styles of though/argument/politics/whatever can win the day. But in times of relatively low stress, more democractic/left-wing/progressive attitudes can help the tribe discover even more resources than they would have if they always followed the same instructions to go to the same sources. Innovation and exploration can turn the merely adequate into a bountiful plenty, resulting in more healthy babies, etc...
So these attitudes and personality traits are important to have present in the gene pool to make the species as a whole robust against a wide range of challenges and threats.
When someone continues to cargo culting useful fragments of knowledge instead of actually learning how/why those fragments actually work, the cargo cult behavior tends to incorporate increasing levels of magical thinking.
A good example of an extreme form of this are the "sovereign citizens" that try to use their "creative" reinterpretations of legal code and procedure almost as an incantation or spell. The like to read from Black's Law Dictionary as if it was a grimoire.
Not experienced in this field but this seems like a good thing to me. Even just using crypto properly appears to be hard, and this 'do nothing when given 0' trait makes the vulnerability very obvious to a quick basic security examination (or even just looking at it in Wireshark), vs needing an expert to do lengthy analysis and figure out that you subtly fucked up the AES initialization and had been running unsafe code for years.
I suspect you might be confusing a mistake for a conflict, as described here: https://slatestarcodex.com/2018/01/24/conflict-vs-mistake/
You quite naturally see a discussion of a cipher as an attempt to find the truth, and it barely registers for you that it might not be. They probably see a discussion of their cipher as an attempt to persuade, so they use the most effective argument they can think of at a given time, and it barely registers for them that the discussion could be an unbiased attempt to find the truth.
I prefer to think of people's traits not in simple binary terms, but more in terms of high-dimensional attributes. Think: word2vec.
In practice, I find that people are messy. They have their own interests, and hence there's conflict, but they're also lazy, hence the mistakes. There's plenty of room for several kinds of suboptimal behaviour in their squishy meat brains.
Sometimes I feel like I'm The Man From Earth, watching this craziness unfold from the outside.
PS: Watch it, it's a good movie.
I'd frame it as that it doesn't matter to them. People who aren't in a feedback reward loop with the reality or with others feel no consequences, need of change or improvement. An engineer like you would generally want things to be correct regardless of outcome, but for general internet idiots or lots of startup self-appointed C-classes, sadly that is often not the case.
If you include the fragile egos of sysadmins and executives who refuse to fix their systems, then yes, absolutely.
As for the elitist arrogance, whilst I'm sure these exist in other security-related interactions across the world, the interaction that's the subject of this thread involves plenty of polite comments that
- point out author's lack of background knowledge - refer to short-cut theorems that help evaluate a cipher, implying the author should learn about these theorems - explicitly tell the author to learn about these theorems
In response to this, the very first reply the author gives is "It almost sounds like you have had your soul crushed by bureaucracy over the years and have lost all passion for this field. I hope that's not true."
Yeah, however much "arrogant" you interpret the security people in this thread to be, it's only fair to interpret the OP (Mark McCarron) to be 2-3x as arrogant.
At the end of the day for me, it mostly boils down to some ulterior agenda which seeks to keep competition or perceived threats to the incumbents' control at bay.
Does the NSA have a vested interest in most technology workers being able to competently roll their own encryption schemes? From my very jaded political perspective, I would say absolutely not. It arguably makes their mission exponentially harder if they have to deal with novel approaches to securing communications. They would probably prefer everyone just use ECC with their hand-selected curve parameters.
NSA and GCHQ would absolutely love it if people used novel approaches to cryptography and started kludging together dumb crypto systems. This makes their stated mission considerably easier.
Unfortunately I find that this is all too common.
Mostly these aren't just heavily stylised exercises that have limited practical value as fighting styles, they're woo like energy blasts or psychic power that can't work at all. Practitioners wave their hands or say magic words and seemingly defeat groups of skilled foes. Except it's bullshit.
The video includes some unpleasant though relatively brief excerpts showing what happens when a practitioner of such a fake won't back down and fights someone who knows what they're doing. They generally seem initially very confident and then within seconds they're on the ground just trying to keep from getting further hurt. That they'd show up and fight rather than make thin excuses and vanish suggests these people are delusional rather than (or as well as) crooks.
Fighting and cryptography are both disciplines where it isn't just a matter of opinion whether you're right.
I'd add the following three generic warning signs of crackpots, all of which are on display here.
1. Person doesn't know mailing list etiquette, for example top-posting and failing to send hard-wrapped plain text messages. Also not understanding the purpose of a mailing list intended for something else.
2. Person claims that others are rejecting basic principles of open-mindedness and making trivial errors in reasoning, or that they don't understand foundational elements of their field. Accusations of rudeness and threats to professional reputation.
3. Person uses just enough technical jargon to give the impression that they have some fluency in the relevant field. When corrected, they often seem to just barely misunderstand the correction, in order to give correspondents the false hope that they are open to being shown their errors.
Thanks for the Trisector link, it's been a couple years since I've read that one.
Whatever their "idea" is, is infallible. Minds cannot be changed with logic or debate when clearly wrong/false.
A belief is unbreakable if the person holding it wishes it to be so. Discussing such topics over the internet will never lead to yielding any ground.
Perhaps at the core of it is the fear of being rejected or wrong. Or that their world as they know it is crumbling and keeping it together is of the highest requirement + cost.
I keep hope for these discussions in that people can change. As cheesy as it is to say, I've only seen people really change when it's with love. That we reach out the other side and simply love the person first. Daryl Davis is my hero on this[0].
Unrealistic in a forum about cryptographic schemes, but it hurts for me to read the circles the author plays himself into.
I recently had to regrettably leave a fandom Discord server because a sizable portion of the populace including the admin devolved into screeching banshees with no capacity for rational thought at some /slightly different/ view than they preferred being posted in their politics channel, and I could no longer justify expending any energy trying to engage in a reasonable fashion with these people or supporting a server with such a rotten administration I'd lost all respect for. I wonder if those of us who can consider ideas without throwing ourselves on the floor in a tantrum over the fact someone disagreed with us should just move to another planet then come back and conquer Earth in the five years it would take us to develop the capacity to do so without such people in our way.
Also, please don’t think yourself above, as you say, “The vast majority of people”. You yourself are like this too (and me). It’s just that you have different things which you think are important. It’s only when we aren’t attached to any particular view that any of us can reason with any semblance of logic. Which is why, I guess, that some religions urge detachment.
But no, no evidence, only my impression.
That's basically eugenics, which is largely considered a negative today.
Has anybody ever really debated a "flat earther" let alone found one? As-in found somebody who actually believed it and wasn't just screwing with you to get a reaction?
I keep hearing about these people who believe the earth is flat but I've yet to ever come across anybody who actually believes that.
Make of that what you will!
And then there's "Mad" Mike Hughes, who just managed to kill himself in a rocket he was hoping to fly high enough to see that the Earth wasn't curved... or something. https://www.bbc.com/news/world-us-canada-51602655
“He did have some governmental conspiracy theories. But don’t confuse it with that flat Earth thing. That was a PR stunt we dreamed up.”
https://www.youtube.com/watch?v=2gFsOoKAHZg
The short summary is that flat earthers are probably seen as a rejection of established institutions (like capitalism/neoliberalism) that the (correctly) see as a major source of the problems in their life. Unfortunately, lacking the social/political background required to actually understand these problem, they work with what they can understand.
"The government/etc has been consistently lying to us for decades while our jobs were shipped overseas and our quality of life keeps sliding lower and lower. If they are consistent liars, why should I believe anything they've said?"
"Thirdly, we deliberately introduced confusion over the systems architecture. This was not to protect any secrets we had, it was just another tactic in the controversial marketing tactic."
So it's not that he can't explain how it works, he deliberately introduced errors in the explanation, which allows him to conveniently claim that people poking holes in his crap don't actually understand the system, because he hasn't accurately described the system! Haha! Gotcha! Therefore the system is perfect!
"I had done it, I was the first in the world to prove, beyond any doubt, that the pyramids of the Giza Necropolis were, in fact, a scale representation of the three inner planets."
Wow. Just wow. That took a turn.
Extensive pattern matching is a marker for mental illness, and is no joke. That explains so much about the author.
Unfortunately, he seems to have missed the idea of just adding a new envelope header and SMTP command, and instead gone the route of throwing the baby out with the bathwater and reinventing not only the wheel, but quite possibly the concept of circularity itself. Not only was GEIS to have replaced SMTP (in an entirely incompatible way), but he even went so far as to declare that “all 'GIEIS' servers will run on a separate transmission protocol (not TCP/IP).”
Add to that protocol megalomania some impenetrable architecture diagrams, a curious bit of Egyptology, self-admitted arrogance, and a very suspicious bit of sock-puppetry, and it's no wonder that the Register gave him such a send-up.
¹(include a nonce when sending an email, which the recipient can check with the originating server to confirm that the email is genuine)
Was all that the result of excessive praise during childhood that made him unable to self-criticize in adult life?
https://mailarchive.ietf.org/arch/msg/cfrg/cdeJ91NBT_-yU24Q3...
That part is one of the best dressing downs I've ever read on the internet.
> In response, Harry Wood of the Communications Working Group tries to reason with Mr. Acela (Appendix A.3), and Sorin continues his rude replies, claiming that the redaction process was STUPID and that the community members [...] are terrorists (Appendix A.4).
> [...]
> It never came to a Skype session because mediation requires a certain base level of respect and understanding between the parties.
I doubt the author realises that the system must be resistant against a class of attacks (in this case, I believe a chosen plaintext attack). From reading the thread, and comparing it to the example in the book, it seems like the non-uniform patterns in the output highlight a possibility of a CPA.
And of course, the author wants a fully implemented + concrete attack instead of pointing to what's an obvious flaw to the crypto community.
Computes all the primes less than 0? Already.
Achieve compression approaching 100% on a string of zeroes? Easy.
Losslessly compress an image with all pixels having opacity of 0? Easy
This is totally, utterly and critically wrong. Ciphers with "no obvious holes" are dime a dozen. Nobody is interested in looking at your cipher unless you both have strong evidence that it's beats the existing ones in at least one area and that you did your homework to check for known weaknesses.
Sure, you can’t recover the data, but it’s compressed and encrypted so that your adversaries also can’t.
Round robin load balancing or fewest connections? Maybe a flag for both.
This gives me some serious Kryptochef vibes.
If you haven't come across that name before: way back when, some guy was trying to sell his "Vollbitverschlüsselung" (Full-bit-encryption) software which he touted as the most secure in the world with an utterly bizarre explanation on how it was supposed to work. I'm not absolutely sure to this day if it was an elaborate hoax or whether he was actually serious.
The Kryptochef Website (German):
https://web.archive.org/web/20111011174408/http://kryptochef...
English translation with broken page layout:
https://web.archive.org/web/20111024003746/http://kryptochef...
And then just fast forward a bit in time.
More information: https://en.wikipedia.org/wiki/Spectral_test
Call it something like "crackpot.js"
[0] https://www.todayonline.com/world/covid-19-far-more-likely-s...