How did the Enigma Machine work? (2021) [video]
youtube.com
youtube.com
(1) Lamps light on the key downstroke, rotors move on the upstroke. Rotors advance their neighbours from different positions, sometimes from two positions, etc.
Many are in museums behind glass, but a private collector brought one to a bunker museum I volunteered at, I asked if I could try it out and he obliged.
In Maryland at the NSA's National Cryptologic Museum in Fort Meade visitors can try their hand at using one to encipher and decipher messages (per Wikipedia).
TLDW & AFAIK: it's crackable (just as it was back then, using a bag of approaches & heuristics), but you still couldn't plain brute force an encrypted message today if you didn't have any portion of the plain text, the Enigma was using 10 plugboard pairs, etc.
The analysis you link to shows that it has about 76-bits of keystate based on the most generous analysis for the 3 of 5 rotor machines. This should be within the range of a motivated nation-state attacker using custom hardware to just outright brute force.
Even if you don't know the plaintext, you can do a quasi plaintext attack where you just try every long enough word in the dictionary at every non-prohibited location and apply the classic attack-- and I expect this would still be much faster than a brute force search while only having extremely limited assumptions about the plaintext.
Meanwhile, the Allies had multiple encryption technologies fielded during the war that were far superior:
https://en.wikipedia.org/wiki/SIGABA
https://en.wikipedia.org/wiki/SIGSALY
https://en.wikipedia.org/wiki/SIGTOT
But that's only part of the story - the allies were far more robust operationally. The Nazis were terrible at intelligence and counterintelligence (something to do with the subtlety required). And because they didn't take spying or intelligence seriously, they never "pentested" their own processes very well. They were fairly happy enough to create the Enigma machine and use it everywhere.
Meanwhile, the allies were much more careful about what sort of encryption was used in each circumstance, and much more cautious about how much information (even encrypted) they made available for their enemy to intercept.
If you really want to get into the details of how and why the Enigma was a failure, I strongly recommend Seizing the Enigma by David Kahn. It does an excellent job of combining the technical details of the Enigma codebreaking with the overall story of naval intelligence.
I think it's worth giving a mention of https://en.wikipedia.org/wiki/Code_talker as well. (The Allies were not sure if their encryption was secure, and attempted to find other means of securing their comms.)
So what happens if ‘k’ randomly returns to itself and the switch is in the battery contact position and not the lightbulb position—no light?
Pressing a key makes one of those 26 circuits hot. Now attach the reflector: it necessarily connects that hot circuit to a different one.
This is an understatement. It was well enough as a movie, but I think you will come away with a worse understanding of Turing and Bletchley Park than if you had never watched it. I cannot say enough about how it mischaracterized Turing's work, his personality, the nature of the codebreaking endeavors, or the contribution of others.
Pretty funny that the lessons learned here are still relevant to this day.
This even further reduces the difficulty of guessing pin codes.
Germany was in particular unaware that Poland - understandably nervous of an increasingly combative Germany years before the war started - had cracked Enigma when it was a commercial system in the 1930s. This knowledge was transmitted to the British in 1939, and the cryptanalytic team who did it began leaving Warsaw before (inevitably) Germany invaded in September.
There's a small memorial to the Polish code breakers at Bletchley Park, it's not exactly on the main tour, so if you care ask someone when you're there to tell you where. People who were there suggest it made maybe 12 months difference, specifically to Enigma (Bletchley Park did other less famous cryptographic work) which is a pretty significant difference.
Enigma is interesting because it's so famous and yet it's completely the wrong design, and this is exactly the era when people stop doing that. The Colossus computer, also at Bletchley park, is to break the Lorenz cipher not Enigma, because Lorenz is a much more "normal" design to us today. It's a Vernam stream cipher, it encrypts bit streams and it merely so happens that those bit streams are Morse code. You could perhaps say Lorenz is a (distant) ancestor of, say, ChaCha20.
In contrast Enigma looks like cryptography from previous centuries, it encrypts symbols, one symbol in -> one encrypted symbol out. No letter on your Engima machine's keyboard representing the symbol you wanted? Say it in words or don't encrypt it. This is in some ways more practical (Enigma was actually used with radio traffic, but in principle you could send letters, or encrypt your diary, or whatever) but in cryptographic terms it's a complete nightmare.
The allies sigaba was basically the same design-- but it lacked the reflector so letters could encrypt to themselves. The down side of this is that it needed a complex mechanism to reverse the signal flow when switching between encrypting and decrypting.
(there were many other improvements in sigaba, but the big one that made it hard to crack was eliminating that one weakness)
> You could perhaps say Lorenz is a (distant) ancestor of, say, ChaCha20.
The first cracked Lorenz message happened because a signal re-transmission was needed so they sent the same message again using the same keystream-- except it wasn't the same message: the operator abbreviated a word, shifting the following characters. So they effectively reused the same keystream with different messages.
Systems using stream ciphers (e.g. CTR mode) are still falling to this today.
Seems we haven't learned that much after all!
I love Jared Owen. He’s so damn good at explaining how stuff works.
It reminds me of my grandpa always taking time to explain how things worked by taking it apart and showing me what the insides looked like. Things like his transistor radio, table fan, etc.