BA jihadist relied on Jesus-era encryption
theregister.co.uk
theregister.co.uk
By modern standards, his data was simply "not" encrypted. That's not very interesting. An interesting story would have been, this guy didn't believe AES was safe, so he took a generic block cipher design and customized it, and that got broken. Of course, that would never in a million years happen; had he simply taken DES and added a few rounds to it, nobody ever would have broken his cryptography.
I did a quick search on "islam cryptography" and came up with this:
Cryptography in Islamic Civilization http://en.islamstory.com/cryptography-islamic-civilization.h...
There's a series of howlers in this allegedly academic text:
"For transposition to be effective and secure, letters rather than words need to be rearranged, this effectively scrambles the message and produces an "Anagram". Transposition could be done for example by writing the order of letters in a word backwards, so that word becomes drow. It is more effective to rearrange the letters in whole sentences or the whole message rather than single words.
If transposition was not limited to words or a certain order the number of different possibilities for rearranging a thirty five letter message rises to 50,000,000,000,000,000,000,000,000,000,000 different distinct rearrangements making the task of working out the correct rearrangement impossible even if all the people on earth were to check a single rearrangement every minute."
...notice the careful attention paid to frequency distribution analysis, which the author later claims is another output of Islamic civilisation. Additionally, if you preserve word boundaries cryptanalysis can include word length, which makes breaking the cipher all the more easier.
"Substitution is the other method by the meaning of a message may be concealed...Working with the plain English alphabet, allowing the algorithm to be any arrangement of the different letter, it is possible to generate more 400,000,000,000,000,000,000,000,000 different distinct rearrangements of letters and so the same number of different ciphers, thus producing a high level of security, baring in mind that the recipient need only to keep the key safe."
Besides mis-spelling bearing, how, exactly, were you planning on distributing the key again? Is the distribution channel more secure than your allegedly secure cipher? What happens when you re-use the key? For the love of God...you'd have thought they didn't bother reading "Cryptanalysis" by Helen Gaines, if they even wanted to pretend to make an effective cipher.
No evidence for this, but I bet you the BA plotter was drinking the koolaid a bit too much and thought too highly of the 1400s.
Instead, they developed their own encoding mechanism in the hopes that it would evade detection or decryption by possible backdoors in existing algorithms.
In many cases, security by obscurity is a viable tactic, especially in combination with other tactics.
Guess what, if you're so purist you can't trust experts in your own field because they use "contaminated knowledge", then you better be a true genius, or you're not going to be very effective.
And I don't think it's a coincidence. It really boils down to them not being able to figure out which people (especially, which "authorities") to trust.
Like I said, there is a security-by-obscurity game to be played with this stuff: tamper with a known algorithm (even if you don't trust it, it's not like you can tell the difference between AES and TEA just by looking at ciphertexts).
Timing also plays a big role. Many times a piece of intelligence is only useful for a duration of x.
Narus boxes are not magic, they can only do so much ;).
Sorry I wasn't more explicit (or if you already realized that).
(from HPMOR: http://www.fanfiction.net/s/5782108/62/Harry_Potter_and_the_...)
"There are two kinds of cryptography in this world: cryptography that will stop your kid sister from reading your files, and cryptography that will stop major governments from reading your files."
Wow.