Can you Crack It? Break this cypher, get an interview with GCHQ
canyoucrackit.co.uk
canyoucrackit.co.uk
Let's assume you have a cyphertext c, of length l (ie |c| = l). Now I take a plaintext p of length also l (|p| = l). Let the key k be c xor p. Now
c xor k = c xor (c xor p) = (c xor c) xor p = 0^l xor p = p
Where 0^l is a string of l zeros. So yeah, given one cyphertext, I can craft a pair of key and plaintext such that there is a cypher (simple xor) that, given the cyphertext and the key, outputs the plaintext.What is worse? I can craft |E|^l of such plaintexts (where |E| is the size of the alphabet).
So yeah: this test only checks if people know basic cryptography and boolean algebra. Which tends not to be a very good test[1,2]
[1] http://techcrunch.com/2011/05/07/why-the-new-guy-cant-code/
But, it's a good publicity ruse.
edit: the pay's not even that great.
Actually, I'd say that mob is after assembly language programmers at the moment, not people who know "basic cryptography and boolean algebra".
Moreover, they don't really care if the solution gets plastered all over the net, because from their perspective the point is not the code, but the message (that they have jobs available to British citizens with those skills). And I know that because, according to the press, they said so.
And the word cipher is on the title.
Just because you can construct any plaintext of that size and a suitable key to generate that ciphertext doesn't mean you've broken it or know anything about its content (aside from the maximum length of the plaintext).
The answer is supposed to be a keyword, I seriously doubt it's an OTP they are asking for...
Pr0t3ct!on#cyber_security@12*12.2011+
I literally have little to no idea how to start.
Give me a reading list, or outline the first few steps!
http://www2.warwick.ac.uk/fac/soc/pais/people/aldrich/vigila...
If they sound interesting to you then read the plenteous clues in the HN thread from this morning.
It would be pretty hilarious if no actual British citizens figure it out for themselves.
also we're lucky they exclude non-british folks, that way they interchange doubtable trust measures with infosec beginners.