The solution of the Zodiac killer’s 340-character cipher
blog.wolfram.com
blog.wolfram.com
While the puzzle has been solved and it turned out to be real mind bender, it may be the end result that that killer may have wanted all along.
There is so much buzz around it (movie, subreddits, forums, and whatnot) that it really bums me out that we gave such a heinous criminal so much time and attention.
(1) "He sought many things from his act of terror, but one was notoriety - that is why you will never hear me mention his name," Ms Ardern said in an emotional address at New Zealand's parliament.
I find it infuriating how after every mass shooting in the US, the US media (at least the few US papers I tend to follow/read) scramble to get out info about the shooter, with pictures, names and background-stories. Why give such a person a platform? I do realize that it generates clicks and people love to soak up that kind of stuff, but it feels terribly wrong on so many levels.
Unfortunately, you answered your own question. If a news outlet doesn't cover it, people will switch to one that does, affecting their bottom line.
I'm not even white, but it seems to me that there is a very concerted effort by the media in the United States to push a race angle on everything, with whiteness being specifically stigmatized.
They are looking for someone who says it was nice guy and how shocking it all was. Usually some neighbour whose "hello" was answered by "hi". If he is young, he was definitely bullied.
Then, few months later if you follow it, it turns out the killed was causing issues last multiple years, had history of domestic violence and abuse, restraining order against him, beaten up few people and his own friends actually say "he was rough around the edges". Oh yeah, and what was called bullying was actually kids in school avoiding him, cause he was insulting them, stealing their stuff and beating them.
It did lead to the Unabomber's arrest. But in that case of course the newspapers only published the manifesto at the request of the FBI.
In that case, the killer's identity was unknown, but with so much text authored by him, the FBI figured (correctly) that someone would recognize the killer by his writing, and that outweighed the negatives of giving him more publicity; he already had plenty of that.
A man was called in by his girlfriend to her house, who she broke up with. He then pulled out a gun and held her and her best friend hostage for days at gunpoint. Police was called in, of course, and they spent days trying to negotiate with him so he'd let them in.
Of course, this is all the media talked about while it happened. One show host specifically, called Sonia Abrão, somehow managed to call the guy ON LIVE TELEVISION and had the most casual conversation ever, trying to get him to turn himself in.
Some time later, he let her friend go and police decided to raid the place. Only the friend survived.
This resulted in a documentary called Quem Matou Eloá? (Who Killed Eloá?) where her family and feminist figures talk about how her death was more than just a jealous boyfriend, and the media had a significant part of the guilt.
Because people have a right to know, and I don't want big corporations to decide what kind of information to hide from me.
Alternatively, what benefit does reduced coverage offer? Do we know that less notoriety means fewer or less prolific serial killers? Maybe they would be even more prolific trying to get attention.
So if reduced coverage leads to reduced crime, then great. But if not, then denying them notoriety just hurts their feelings.
That’s great, but as it might lead to reduced apprehensions, I don’t think hurting their feelings is worth it.
Note: I don’t mean to belittle your point. I don’t like that society is so fascinated by crime either. But I think that is a separate issue.
I literally do not care one bit about this puzzle being solved. I do care, a lot, about people not getting shot when they go to the supermarket.
We needn’t worry about the stimulating effect revisiting decades-old crimes of an entirely different nature, for scientific purposes, may have.
There is a difference between a 50 year old cold case and a killing that happened last week.
In the case of a recent homicide with an actual arrest the "focus on the victims rather than the criminal" thing makes some sense.
In the case of the zodiac and other ancient cold cases it's rather irrelevant.
There's no detail lost, it's an in-depth retelling, it has all the information you need to get an understanding of the case. It also doesn't feel forced – it took me a while to notice it.
I believe the show does justice to the victim without giving anything to the perpetrator, and it's refreshing.
Perhaps it would be more accurate to say that I felt the show was as respectful to the victim as possible.
> I dislike the degree to which people are fascinated by serial killers/criminals in general
People seek this stuff out ravenously. Most of the supply of information, at least to me, appears to be driven by the demand for it. I've never been particularly interested in it, personally.
Instead they'd focus on things that it seems like mass killers really don't like to hear about, the names of the victims, stories about the community and etc .... and in a lot of ways those actually seem like the more important things too.
Why haven't FBI analysts done the same already? Is it conceivable that it was already done, just simply never publicized for whatever unknown government reason? One imagines that solving this publicly unsolvable mystery is actually a standard initiation exercise for new recruits into the elite circles of NSA codebreakers.
Because the FBI probably has few or no professional cryptographers. It's possible it could've been solved in a couple of days by the resources in-house at the NSA.
To clarify, I mean they probably have few people who spend time working on the math of crypto. They have lots of people who obviously know how to apply forensic software tools written by others to seized equipment.
Individual analysts from the CIA, DIA, NIST, even foreign ones like the GCHQ, DGSE, Unit 8200, etc. could have tried to decipher the messages, in addition to the FBI. Surely they have the capacity to break this code, if they were inclined to spend some extra time on it. It's not as if these agencies don't recruit from people who already love solving puzzles in their free time.
From the FBI's web page (https://www.fbi.gov/services/laboratory/scientific-analysis/...):
> The Team
> Cryptanalysts and cryptanalyst forensic examiners.
...
> Cryptanalysis
> Decrypt manual codes and ciphers found in letters, notes, diaries, ledgers, and other types of written or electronic communications. Common users of codes include foreign and domestic terrorists, organized crime, gangs, prison inmates, and violent criminals.
Now that the capacity is easily available, I bet they have many more recent cases to which to devote a few months of dedicated work.
Like I said down thread, there's analysts who pursue the solving of the Kryptos sculpture. Why not this puzzle?
> [T]he CIA revealed that their analyst David Stein had solved the same passages in 1998 using pencil and paper techniques, although at the time of his solution the information was only disseminated within the intelligence community.[9] No public announcement was made until July 1999,[10][11] although in November 1998 it was revealed that "a CIA analyst working on his own time [had] solved the lion's share of it".[12]
The FBI is not going to automatically hire the people who will succeed at this vs. fail valiantly. To get the same results they would have to dedicate the same resources which would be huge.
After reading the article, this didn't come across as a "standing on the shoulders of giants" situation, but rather that this person by chance had the problem, found it interesting enough to work on, and happened to try the right path to solve it.
It's the same in many parts of research. You obviously would've had no chance without their expertise but just because a researcher discovers something new does not mean there's no luck involved.
The "decades ago" caveat is especially key, because they used a computer system with raw performance well within an order of magnitude of today's Top500 supercomputers. I like to point out government incompetence too, but spending that kind of resources banging away at a message from a killer we don't believe has been active for several decades isn't exactly a prudent move.
I'm not diminishing the tremendous work done by these codebreakers, I'm just speculating if it was already achievable by institutions, just not revealed publicly.
"It consists of 72 nodes, each with four NVIDIA P100 graphics cards, which can provide a theoretical maximum of around 900 teraflops."
I don't know how much time and computational power they used, but it explains why the problem was not solved for a long time.
This is pretty easy. They are a law enforcement agency. The Zodiac killer was active over 40 years ago and is likely dead of old age. Solving this will not prevent a crime or further any of the FBI's other missions (https://www.fbi.gov/about/mission). It's a great feat, but the capability to do an analysis like this wasn't as generally available when it would have been useful, and now it's just a historical curiosity.
Congratulations to Dr. Blake.
In this case, it's a deranged serial killer that's sending a message to law enforcement. The sender is someone who kills people for personal gratification, so it's pretty safe to assume that someone who does that might also want to mess with people for the sake of personal gratification. Crucially, there is no intended recipient other than law enforcement, so there would be no reason to include any actual sensitive information because there's no one to send it to other than the FBI. There's no reason to believe that he'd write a message that would give himself up. Real life is not like the fable of Rumpelstiltskin where solving a riddle makes someone honor-bound to give themselves up. Continuing to solve these ciphers probably fed into power trips and sexual gratification for the author.
It is not surprising that an investigative agency did not allocate a ton of resources to decode a message that one could anticipate would say something like "are you having fun with my game yet?" without any other prior information.
Take the Taman Shud mystery- only one death, completely without context. Yet it's mentioned that military analysts took a shot at unravelling the mystery:
> In 1978, following a request from ABC-TV journalist Stuart Littlemore, Department of Defence cryptographers analysed the handwritten text. The cryptographers reported that it would be impossible to provide "a satisfactory answer": if the text were an encrypted message, its brevity meant that it had "insufficient symbols" from which a clear meaning could be extracted, and the text could be the "meaningless" product of a "disturbed mind".
https://en.wikipedia.org/wiki/Tamam_Shud_case
I don't think spies are any less interested in perplexing mysteries than the rest of the public. While I don't expect that an agency would throw all of their manpower at a case such as this, I could imagine individual analysts taking a stab at it on their own time. Maybe the organizations themselves might sponsor side projects as a means to test codebreaking techniques and glean lessons along in the process. I mean, why else does the NSA have a page on the Voynich Manuscript:
https://www.nsa.gov/news-features/declassified-documents/voy...
They even did an entire study on it:
https://archive.org/details/VoynichManuscriptAnElegantEnigma...
Serious agencies dive into less-than-serious studies into exotic or sensationalist topics all of the time. Sometimes for general interest, sometimes for good PR, sometimes simply because of bureaucratic waste. Why else do we hear about military studies of UFOs, from Project Blue Book to recent news stories? Given the enduring mystery of the Zodiac Killer, I can't imagine why some of these professionals- beyond the FBI even- might not have tried to crack it, themselves. And perhaps some have already succeeded.
Edit:
> There's no reason to believe that he'd write a message that would give himself up. Real life is not like the fable of Rumpelstiltskin where solving a riddle makes someone honor-bound to give themselves up.
Despite this, perhaps figuring out the message would've given some sort of psychological insight or contextual clues that could have helped investigators determine the identity of the killer.
Not to mention, your point is refuted retroactively by the case of the BTK Killer, whose taunting anonymous puzzles were his downfall. Though admittedly investigators identified him not by actually solving his puzzles, but by analyzing the medium they were conveyed in.
"July 12, 2016 Update: The FBI has redirected resources allocated to the D.B. Cooper case to focus on other investigative priorities."
-- https://www.fbi.gov/history/famous-cases/db-cooper-hijacking
Here is a much more simple explanation: the FBI is notoriously bad at anything involving encryption or novel dynamics. That is why the Secret Service was so heavily involved in the big hacker crackdown decades ago, because the FBI was totally lost in the sauce. Bank robbery, payrolling informants, and CP they've got down pat.
ebeorietemethhpiti
Maybe none.
This person killed several people, and THAT is your biggest problem?
There's a discussion about how strong the cipher is, and:
thatwasunusual> ...and still the killer is unknown. That's pretty good, IMO.
Someone pointed out that measuring the strength of the cipher by the fact that the killer is unknown is a bad metric, and you seem to believe this as a defence of murder?
They are merely pointing out there is no connection between the fact the killer is unknown and if the cipher was strong or weak.
The answer to this can tell how easy it may be to create a similar problem today.
Given he fooled everyone for 40+ years I find it hard to believe he would overlook details, especially when it's about his main publicity tool.
swiches instead of switches, cid instead of kid, figgure instead of figure, cerous instead of curious
There are more.
Even if it was intentional, I am not sure that spelling mistakes would make 60s/70s decryption attempts any worse. They did not work by brute force and it's unlikely he predicted someone will use a supercomputer to crack his code decades later.
That the problem only happens when you reuse that sheet.
This doesn’t apply here specifically, but if you would have told me this previously I would have assumed it was securing through obscurity.
Edit: Forgot the link https://darknetdiaries.com/episode/83/
What makes encryption "perfect"? This is not obvious, so I'll just skip ahead to the conclusion: encryption is perfect when it's impossible to distinguish which candidate plaintext led to a specific ciphertext without knowing the entire key.
It's easy to see that a one-time pad qualifies here. Even knowing all but one character of the plaintext doesn't give you any cryptographic way to determine what the last character is. The list of possible keys associating the known plaintext with the current ciphertext allows for every single character in the unknown position. This isn't a matter of computational power, it's an information-theoretic limit. You just don't have enough information (from the cryptography, anyway) to prefer any choice over another.
You can apply a pigeonhole principle argument here and see that this requires the key to have the same size as the message. (Something along the lines of each key specifying a permutation between messages of the same length, and you need the key size to be big enough to specify every possible permutation for that message length.)
That argument can then be used to demonstrate the information-theory quality of the encryption is related to the ratio between the lengths of the message and the key.
When you look at modern cryptography, you can see that we're not depending on information-theoretic security at all. If you had all but one characters of the plaintext and all the ciphertext, it's quite likely there'd only be one key that matches the known permutation. We've gone in a different direction: computational security. It should require an implausible amount of computation to derive what the key is, even when you know matching plaintext and ciphertext.
It's certainly more convenient than moving terabytes of key around, and computational limits are actually pretty compelling, as long as flaws aren't found in the construction.
But it lacks the satisfaction of provably unbreakable.
The base step:
Start with one bit. The key is also a bit chosen at random, and the cipher text is plain XOR key.
You can then work out that no matter what key is chosen, you have no reason to believe 0 or 1 is the original plain text.
The inductive step is simply to add a new random bit of key that is independent from the prior key, and a new bit of plaintext.
What I like about this explanation is that you can actually work out the decision trees for a few bits to convince yourself that the encryption still holds.
This algorithm is information-theoretic secure for a bitstring of length N
The grantparent's argument is to first convince yourself that a) this is true for a bitstring of length 1, and b) if it's true for a bitstring of length N, then it's also true for a bitstring of length N+1 (or alternately formulated: if it's true for bitstrings of length M and N, you can concat them and it will be true for a bitstring of length M+N)
The inductive step is then to apply this to show that because it's true for length 1, it's also true for length 2. And if it's true for length 2 then it's true for length 3. etc etc.
https://www.douglas.stebila.ca/teaching/visual-one-time-pad/
IIRC this is exactly how OTP was used by some spies during the Cold War. (My compsci teacher actually showed us an 'original' pair of sheets that encoded a Chinese character).
Also shows it very neatly why reusing the sheet is a bad idea.
Did a ROT-13/15 (vowels vs consonants, if it matters) test on _smart_ collegues. Turns out they fear the worst and start top-down.
Plenty of smart people don't jump straight to a solution when seeing a ROT13 ciphertext, whereas I think most people who are experienced would realize pretty quickly there seems to be a simple transformation going on.
It's sounds like you're saying that something like a substitution cypher, or even a one-time pad, would be security by obscurity, because they key is "obscure."
My understanding is rather that security by obscurity means you're relying on the attacker not to have knowledge about you system -- e.g. that you have an admin backdoor at /s3cr3t-admin-pag3.html (real-world example), or that you can ping the server at an unpublished end point to get a token.
The opposite of security by obscurity is when the entire structure of your system is a complete open book (e.g. everything is completely open sourced) except the password, and yet the system is sound enough to resist an attack. But note that possessing a "secret" (a password, a key, a one-time pad, the substitution rules, etc) doesn't mean it's now security by obscurity.
1/how do we know we found the solution and not a decryption that gives a plausible message/solution. Aka how do we know this isn’t a false positive solution
2/have cryptologists studied possibility of “synthetic” cypher generation to bootstrap examples upon which an ML model could be trained to decrypt such message in the future ?
Also the way the cipher was done is plausible to the time period (that is, it's something you can do with pencil and paper), and the steps seem like something a human would do.
[0] https://mysteriouswritings.com/six-top-unsolved-codes-and-ci...
I’d love to be wrong though.
https://scienceblogs.de/klausis-krypto-kolumne/2020/07/26/mo...
Of course, for any statistical pattern that we might associate with human language, it is possible to design a random process which produces output with that pattern, but the more complex that algorithm is, the less likely it is that someone living 500 years ago would have come up with it, especially when a much simpler process would have been enough to trick their contemporaries.
One interesting example of statistical oddity is the presence of "words" (or "vords") repeated three or four times. That doesn't seem like a very natural sequence to find in a genuine text (especially in an era when documents were slow and expensive to write out longhand), but nor is it something that such an elaborate hoaxer would choose to include either, if they were trying to convince people that the text had meaning.
A perhaps related observation is the lack of crossings out or "mistakes" in the text. This might suggest that the person (or persons) writing the text didn't know or care what they were writing, or alternatively that they held the work in such high regard that they started with a fresh sheet whenever they made a mistake.
https://www.zodiackillersite.com/viewtopic.php?f=81&t=3198
Although it's a Windows executable, it looks like it's possible to build from the source in this repo:
https://zodiackiller.com/MyNameIsLetter.html
Given what we know of his methods, you'd think it would be possible to brute force this by now?
ebeorietemethhpiti
I "tiph" (work? type?) in a navy called Demeter (or Metheor or Demeteiro)?
Demetrio is also a name
The FBI budget isn't unlimited and making them waste time breaking difficult ciphers, along with some early successes to keep the hope alive might make them overconfident in expending resources in cracking the ciphers instead of good old fashioned police work.
Then again...
(prior to Dave solving this, I was also taking a crack at trying to solve this puzzle https://twitter.com/BlockJon/status/1292555925564395521)
I use and hear it occasionally still.
Except that was, once upon a time, a very common phrasing. As the writer was coming from the 60/70s, you need to adjust your expectations of English.
"in trying to" is actually incredibly common for what might be called "Oxford English". You'll still find it in heavy use in newspapers.
So rather than suggesting the speaker is making a deliberate mistake, or is not a native speaker, it might simply be suggesting a formal education - something that already matches the profile of the Zodiac killer.
Now choose a set of 40+ symbols to do the homophonic substitution. You randomly assign these to the letters A-Z making sure you assign more to the letters that you use the most in your plaintext (probably e and t having the most)
Now decide on an arrangement of the plaintext (transposition cipher), this may involve writing diagonally or spirally or in any pattern that can be conveyed as a key and is easy to write out.
Finally, substitute the symbols, where you have a choice of more than one symbol pick one randomly. This should be done randomly rather than methodically to make the cipher the toughest to decrypt, you could use dice to do this.
The decryption key that you pass to anyone wanting to decrypt the ciphertext is the set of symbol substitutions and the way that you have transposed the symbols. (E.g. spiral going clockwise from top right)
The problem is nobody has guessed the method for K4 (and the message is much shorter at 97 characters). With Z340 there was the important context of Z408 and the underlying method of homophonic substitution. With K4 if people get into it enough, they usually try the polyalphabetic substitution of K1 or K2, or combine that with transposition ideas, influenced by K3, try that for while, and give up. Nobody will know the method for sure until it's been solved.
Another parallel: Z340 "rates at about a 7 or 8 out of 10 in difficulty to decipher" according to Oranchak. When Ed Scheidt, the designer of the Kryptos codes, was asked the same question about K4 he said "I would think like a nine, it's way up there".
I think "paradice" is likely an intentional mistake on the Zodiac's part, though. His apparent level of education doesn't fit with him being unfamiliar with that word.
It's possible he did it intentionally but I don't think this cipher is proof he was highly educated.
In related news, Japanese teachers lament the fact that predictive text entry systems on their students' phones mean that they don't know how to write kanji anymore. They can recognize them, but don't have enough practice to write them consistently anymore.
What I am saying is trivially true for a very short plaintext, think of txyz and invent any work you like. So there must be a trade-off between the space of solutions and the message length, a signal to noise ratio. The solution propose 3 part of the z340, and each one add new capacity to the channel of solutions. Perhaps something like the VC dimension. caveat: I am not a cryptographer.
Perhaps something like: https://www.mdpi.com/1099-4300/22/4/438/htm
Well...we have one asset figured out.
Seems like many tools/approaches used were english-specific, and unless some lucky guess/hit, they wouldn't be applicable to other languates.
I read 'Blake' and thought, "oh neat I wonder if this person also did a popular crypto hash that I've seen?" I looked it up and found out that in fact they didn't and it's not named after anyone AFAICT. So I meant this as purely informational for anyone else who might've thought the same thing.
Sorry if it was an off-topic comment.
"Superior IQs are associated with mental and physical disorders, research suggests"