Modern-day spying: sometimes old technology is more secure
economist.com
economist.com
They're all on the Internet Archive to read free, e.g. https://archive.md/Ed12X
> The Internet Archive is an American nonprofit digital library founded in 1996 by Brewster Kahle.
https://en.wikipedia.org/wiki/Internet_Archive
In other words, it’s a legal entity and we know who’s behind it.
In contrast, we don’t even know who runs archive.today.
https://gyrovague.com/2023/08/05/archive-today-on-the-trail-...
If you want to cancel your The Economist subscription, you can’t just click a button. You need to wait to talk to a sales rep in a chat room… when they arrive, they will basically beg you to stay; here’s a discount offer and here’s another, you’ve been a subscriber for X years why stop now. Only after insisting for 15min that you really want to cancel will they let you. I’ve gone through that process twice, and find it very off-putting.
I even double checked with a support rep to see if anything had changed. Not only did they confirm that there's no easy option to unsubscribe, they tried to gaslight me into thinking that this was for the customer's benefit!
Are you sure that you can click cancel without talking to a sales rep? If so, are there perhaps local German (not EU/EEA) rules on this?
Why "used to", then? because a couple of years ago I could not basically find a way to have my paper version subscription renewed. I was literally not able to renew it! after a few "chats" with their sales reps, I gave up in frustration and discovered I can live without.
IIRC, thew wanted you to have the electronic version at all costs, while I'm happy with paper.
In any case, in an age of vapourware crappy SEO articles, they have a lot of meat, and a global world-view. It's the best way to spend money on news.
Just makes me rethink does everything thing need internet access. Sometimes perhaps simple safe and secure may fit better. Kind of off topic of this article but the concept just kind of got me thinking out loud.
The cloud-based model might be leaky due to complexity but has the capability to deliver cryptographic assurance, which is a huge win in the long run. Modern cloud delivery is infamously insecure at the current point in time because most companies do not care about the security of their customers, and most customers are not aware of more secure options. But in the end as the technology matures it will be far more secure.
Of course, cutting off internet access is a good practice and most cloud connected systems play happily with a proxy.
I think the big impact here is that mundane systems which are now connected to the internet have become targets for remote vandalism or espionage.
Physical access is not a problem when basic other measures are not taken. If physical access is your largest threat then you already safer than 90% of companies imo.
Why? In my home I have a Synology NAS server, not connected to the internet, where I store unencrypted data. It's not secure out of the box, and I didn't attempt to harden it.
You are welcome to hack me. Good luck.
Offline systems have way fewer failure modes such that they're often "secure and reliable" by just default, at least in comparison to the alternative.
In this case, clearly the simpler tech was a better fit.
Here's a sample of the referenced "Linconshire Poacher": https://priyom.org/media/247818/e3.mp3
That also would use up the pad when there are no messages, requiring some secure way to get a new pad to the operatives when their existing pad is consumed. This is difficult enough (secure delivery of new pad) that it is unlikely that spy-HQ wishes to consume pad data for fill.
> But I suppose that’s bad since if it did accidentally get re-used then that cyphertext would be fully compromised
Yes, if they reused any part of any pad for more than one single message, they have compromised (and revealed) the contents of the reused pad messages. This is the other difficulty with OTP's. The OTP data must never be reused. Which is alo why spy-HQ would not want to use it (the OTP) up for the fill, because to avoid reuse then they have to get new pad material to the operatives in some secure way.
> So, I guess the actual algorithm must be derived from the OTP, but not padded with it?
The 'implication' of the article is that the fill is just random data (without using up any pad material). Possibly with the appropriate headers in place so that it looks indistinguishable from a read message in the same slot.
The further implication is that the Cuban station did something essentially like this:
for (count=0; count<20; count++) {
send(int(rand()*9));
}
With a rand() implementation that returned a number from zero to 1.0 exclusive of 1.0 and an int() implementation that merely truncated any fraction from the multiplication. With the result that 9 is never sent.Lots of ways to mess that up (`rand() % 9`?). I’m more surprised that nobody noticed for so long. It’s not like this was some subtle cryptographic bug that would have required deep analysis to catch… “you had one job”, and just glancing at the output was, evidentially, enough for a lot of other people to catch on.
maybe they were just random digits with an off by one error or some other problem with the symbol set missing one symbol.
or maybe the supposed fill messages can actually be cryptographically confirmed as authentic fill messages via some clever scheme (that the implementation of turned out to be buggy).
or maybe someone from some sort of field operations chain of command just slammed the table and said "my people are tired of trying to decrypt fill messages, i don't care, just cut the nines out so the field agents know if there's a message."
that's what makes numbers stations fun. :)
My guess is there's some cryptographic structure to these indicators that tells agents if the messages are for them, so they can shut down their listening early if none of the three messages are for them. If it were otherwise, I would expect each indicator group to be before (or inserted at a secret agent-specific offset within each message) each message. If you listen to the mp3 recording linked from Matt's article, you'll notice that the three indicator groups are repeated before the actual messages begin. Presumably the repetition is to guard against the indicator groups being garbled, since if the indicator group gets garbled, the whole message is garbled. On the other hand, a garbled regular message group would only result in a few characters of the plaintext being garbled.
Placing the indicator groups at constant (and secret) per-agent offsets within the messages has been known since at least WWII. In the case of an OTP, having a secret offset of the indicator group makes it harder to detect if the fatal error of pad reuse has been made. In the case of other ciphers, making the location of the indicator group secret also complicates cryptanalysis.
It wouldn't make sense to separate out the indicator groups like that unless it provides some operational advantage to offset the small cryptoanalytic toehold provided by highlighting the indicator groups. Allowing agents to shut down their listening early is the most obvious advantage I can think of.
The simplest cryptographic structure (and devoid of bias if the OTP is devoid of bias) would be to simply have the indicator group be the first 5-digit group for the next page in the OTP. The agent would need to check the next several pages of their OTP to verify they hadn't missed any messages. Encrypted headers within the messages could be used to handle the rare cases of collisions across agents, rather than introduce extra stucture (weaknesses!) to prevent any two agents from ever having duplicate indicator groups across their next few pages of OTP material.
Of course, it is also possible that these repeated indicator groups at the start of the transmission are just decoys and the real indicator groups are somehow hidden within the messages in some way that provides redundancy without revealing which groups are the indicator groups. Maybe the first three groups of the OTP page are placed at 3 constant offsets within the message or something.
But, my guess is that these repeated indicator groups at the start of the transmission really are there to let the agents know that they can shut down their listening early when there are no messages for them.
Much more likely is that everybody has a time slot during which he's supposed to listen.
However don't you think your own explanation of improving security against accidental key reuse could be the explanation, with the repetition being there only for that purpose?
Instead of trying to suggest "security by obscurity is fine, actually, and don't worry about it", it's time for us to just stop being pithy and start being precise: your cryptosystem should be secure even if your adversaries understand everything about it. If that is true, then you can (and, in the real world, almost certainly should) add defense in depth by adding layers of obscurity, but not before.
That is the point. It is a good rule of thumb for people who don't know much about security. Anything they create trying to add more security to their system is more likely to do the opposite.
If you think you know better, feel free to ignore it. Just be aware you wouldn't be the first who thought they knew what they were doing or even the first who did know, yet still messed up.
The reason is that, without any exception, every time when some system that used “security by obscurity” has been reverse engineered, regardless if it was used for police communications, mobile phone communications, supposedly secure CPUs etc. it was discovered that those systems have been designed by incompetent amateurs or perhaps by competent but malevolent professionals, so that those systems could be easily broken by those who knew how they worked.
“Security by obscurity” is fine for secret organizations, but for any commercial devices that incorporate functions that must be secure it is stupid for a buyer to accept any kind of “security by obscurity”, because that is pretty much guaranteed to be a scam, regardless how big and important the seller company is.
Obscurity is OK only when it is added by the owner of the devices, over a system that is well known and which has been analyzed publicly.
This history repeated later, with people making shoddy cryptography where they didn't want anyone to know how it worked, and similar things, most of which got broken in embarrassing ways. This sort of obscurity was actively harmful and let people sell defective products that people relied upon to their detriment.
Meanwhile, there are good types of obscurity, too. For example, there are the information disclosure CWEs that tell users of products not to disclose version numbers, stack traces, etc. to users, and this sort of "obscurity" is perfectly reasonable and widely accepted.
So it's not the case that all things that might be termed "obscurity" are bad.
im not sure i understand what this means, can you provide an example and why its controversial?
do you mean a one time pad using memes via image steganography on heavy traffic forums? I recall this is what North Korean spies used to do in early 2000s
There is a longstanding tradition of vendors of mediocre 'security' systems using trade secrets/restrictive license terms/anti-hacking laws to cover up their mediocrity.
If you're shopping for a garage door opener and one vendor publicly documents their security system and well known experts have given it their thumbs up, while another vendor says their system is secret and has sued people for attempting to reverse engineer it? Knowledgeable folk would have far more trust in the former than the latter.
A one-time pad generated correctly and used correctly will remain highly secure, provided you have a highly secure means of sharing the key material. There's a lot rolled into those assumptions.
That type of security comes at a cost.
I don't think it's that hard to get true randomness. Just measure something random in nature like radio static.
Which does kind of further your point that one time pad makes more secure the parts that are already incredibly secure, while not helping the real weaknesses of cryptosystems i.e. the human element.
I've heard other approaches including that static too, ie the famous analog TV without real signal, IIRC its cosmic microwave background, or camera watching water drops fall or similar. There are many other ideas (and probably products too), the only thing is one needs to keep it 100% reliable across long time.
I would think that for crypto it’s very important to not just have random numbers, but to have a uniform random distribution. Many natural sources would be either Poisson or Gaussian; if you make an assumption for the distribution you could of course make it uniform, but that assumption would be a weakness if inaccurate or changing over time.
So how is a true random source usually used to ensure uniform random outputs?
You can take a collection of those values and convert them to an index in the set of all possible permutations of those values. That index will be uniformly distributed in the range of the number of permutations, regardless of the input distribution so long as it's IID.
Once you have a uniform value on a range you can extract uniform bits from it.
See also: Von Neumann's debiasing algorithm.
In practice RNGs use some kind of debiaser, though often they use ones that leave a lot of entropy on the floor. OTOH, stronger debiasers are more harmed by failures to be completely IID (e.g. some inter-output correlation, or the distribution changing over time with temperature).
Yes. No one seems to have mentioned VENONA.[1]
Things are more secure if you share your file with a specific set of users, but that requires your counterpart to have an account with the system you’re using (eg a Google Account for Google Drive). When sharing files with an arbitrary counterparty, it’s often sufficient to generate a publicly available, unlisted/unindexed, hard to guess URL. Even better if it’s time boxed.
I’m sure there are attackers who attempt to identify and enumerate these URLs. If they’re well designed though, it should be infeasible to guess the link.
Unless a service is leaking or spidering the URL into a public index.
https://positive.security/blog/urlscan-data-leaks
https://arstechnica.com/information-technology/2014/05/dropb...
https://security.stackexchange.com/questions/239762/how-are-...
It is much harder than it would seem to keep these links secret. If one of your assets gets caught by other means, they could endanger the entire network if they use the same methodology.
The CIA thought they had a super great system, and then many of their assets got rolled up at once in a hugely embarrassing (and deadly) blunder.
Security by obsolescence.
Clandestine communications in cyber-denied Environments: Numbers stations and radio in the 21st century
https://www.tandfonline.com/doi/epdf/10.1080/18335330.2023.2...
I like how some malware hides in plain sight and relays through google analytics.
Some radio receivers have existed that leak signal at the intermediate frequency, due to inadequate shielding. But it's not just a privacy problem, it also means that receivers operated near to one another can interfere with one another due to crosstalk at the intermediate frequency; it would be inconvenient if your car radio lost signal any time you were stuck in traffic and other drivers were using their radios. So usually designers add more shielding.
It's difficult to know the truth because there are some organisations that benefit from exaggerating the possibilities of things like this - for example, a cable company might hope to deter cable pirates by claiming they have roving detectors that can detect people pirating cable.
They correctly treated many aspects and details that today go ignored and addressed many of the issues that apply to us today with regards to adversaries who can by nature react faster than we can perceive.
The solution had cost tradeoffs, but in the end it proved the correct decision through virtue of the fact that the story continued (and they weren't all killed off in episode one).
In the show’s fictional plot, the decision seems correct because the story continued and the characters survived. However, we shouldn't judge decisions in real life by how they are portrayed in fiction. In modern fiction, decisions are often shaped to please audiences, not to reflect real-world correctness. Thus, it may not be wise to judge these fictional decisions by the same standards we use in real life.
It teaches us about the human propensity for propaganda.
For some background, Lifton, Meerloo, New Discourses (youtube), inform.
In a way, I'm almost envious of the ability to experience a story without being distracted the "meta" knowledge that what happens at every step is a deliberate choice by the writer. I'd probably be a lot more into movies if I could somehow believe that events in them unfolded organically like in reality rather than sometimes being forced for plot convenience.
That said, the development of meta knowledge is a sign of maturity.
It means you've watched or read enough of the same story to see the repeating pattern and by extension to see the holes that poor quality storytelling leaves.
It is magic for the reader when a story is crafted that can fully suspend disbelief especially when it is masterfully done. Some mediums and structures are really difficult to do this, like with the book The Reality Dysfunction (1400 pages?). There are something like 12 concurrent threads that jump around, its not that entertaining until you alter your reading habits and decide to skim or skip the threads of characters that don't interest you (saving them for a second read through if interest remains as a whole).
Needless to say, there are very few examples today of higher level of craft in current media because the corners have been cut beyond the point where they can remain in the finished product. The market has shrunk over time with the suppression of wages. You have to go back to much older production to really see this. If you haven't already watched it, check out the 1934 Count of Monte Cristo with Robert Donat, and a few of his other films (The 39 Steps) as a starter. Depending on your taste for more abstract film you might enjoy Ink with Christopher Soren Kelly, since it has many elements that are bit of a throwback to earlier cinema (if you haven't already seen it).
Overall, all it just means you need to focus on higher quality stories that surprise you. The meta knowledge helps you discern the trash from the gold.
There is far more trash today because most production companies have dual purposes. Making a profit, and seeking to distort reflected appraisal, pavlovian association of unrelated stimulus (associative priming), or destructively interfere with self concept of the viewer (without their knowledge), for thought reform and control; John Meerloo and Robert Lifton have background in that subject matter if you are interested in how actual brainwashing works in practice (its not absurd like they show in the movies, but it is often quite evil and dark not light reading).
You might enjoy reading The Hero of a Thousand Faces.
It is important to develop a cultured palette.
My point is that Jurassic Park movies always involve dinosaurs running around freely and causing havoc rather than a fun trip to a fancy zoo, and I assumed that was everyone's expectation going in, whereas this friend genuinely thought there was a chance that no dinosaurs would escape their cages during the duration of the film. Re-reading my comment, it's not obvious to me why it doesn't make sense to you, so I think it's safer to assume that there's a miscommunication happening here rather than in the conversation I had almost a decade ago.
Stories should provoke flexible thinking and perspective shifts in an entertaining way, they should not make you unhappy.
If you get hung up on surface level things like that assuming the worst, you close your eyes to higher levels of perspective and thinking.
The series is largely about a single theme which is primarily about nature vs. man, and man's hubris and fallibility.
That said, the handling of the tech received a seal of approval from me, and I've quite a bit of professional background in IT System's Engineering, and a periphery of Cyber.
I mean what they do really is not that much of a leap, and would improve existing security by orders of magnitude by eliminating swatches of attack surface that the worst of the worst malware out there uses today.
Punch cards (upgraded) -> Optical printouts that can be physically changed to load firmware and and the functional software from a physically modifiable medium. (A known working, knokwn safe state at the lowest level).
No persistent internal state at the hardware/firmware controller levels (for bad actors to abuse with an APT such as some of the DMA shennanigans, hooking, and bus tricks).
Non-networked except between critical fortified systems (to limit spread).
Sure you take some performance hits, but its resilient with few single points of failure (such as the physical medium).
https://en.wikipedia.org/wiki/The_Conet_Project
audio now free on the internet archive:
Actually the one interesting point made is that nobody can track whether you're tuning into a particular station. On a network, there has to be some traceable path of connections between the transmitter and receiver: even if the message is hidden in some other content or transmitted through a bunch of proxies, that traceable flow of data must exist. It makes me wonder how common it is to open ephemeral p2p connections over shortwave to transmit data between two computers - I'm sure someone's thought of it, and I think I brought it up one time during a quant firm system design interview.
That’s a juicy enough piece of information that they probably have something for it. Does the radio emit any heterodyne signals when tuned to particular frequency? Maybe a super-sensitive satellite, drone or other sensors can pick it up.
Another option I could think of is to somehow infiltrate and compromise popular short wave radio models sold. Make them emit some signal marker which would identify the radio station it’s tuned to.
Pretty far fetched but the three letter agencies have spent money on crazier stuff than that in the past
I'm sure your counter-counter-counter measures might start from the premise that, with you also knowing the location of the broadcast station, you might be able to guess at the most likely receiving orientations if you knew the most likely places for a receiver to be located. Eg a shortwave reciever equipped with a faraday cage + aperture listening to codes from Russia in Manhattan would emit a cone in the direction of Stamford. But I also suppose that I might know my receiver emits this kind of signal, and use some other device to emit junk signals that look similar, or scatter around a bunch of receivers while only using one.
Or I might try to only set up receivers in places where the cone would be inconvenient for you to intercept, or obvious that you were trying to intercept. Eg over the ocean.
some youtubers are pushing LoRa but its hardly secure or encrypted
creating your own number station requires shortwave broadcast which takes up a ton of power and your station is known
the only way to break 5E is good old paper with one time pad encryption with dead drops but its hardly efficient
Any kind of forwarding system with static IDs is very much not triangulation resistant.
so far im seeing starlink + modded smartphone
"s4tll1te p1r4cy" that ppl outside N America ignore but supposedly risky for everyone else
variations on LoRa (still not convinced it can evade tri)
Meshtastic is not really designed to avoid that, but more for resiliency and off-grid type scenarios. Your best bet of really avoiding triangulation by state or telco level infratructure is to get creative with frequency and even transport layer hopping. None of which is really consumer friendly.
[edit-to-add] another tactic to for low probability detection is to hide in noise on high traffic channels. basically figure out what their filter sensitivty is and see if you can go below that threshold and still maintain coherent channel, etc.
You'd need to avoid providing information about the time the beam crosses over your position, which means you'd only activate your connection sporadically, at carefully planned times. You might pick a location relatively near you and down-orbit from you, and connect when that location comes into view of a new spot beam, and disconnect when it's directly over that location, perhaps.
and they do this right alongside active, legit meant US military users. It’s wild.
I can’t imagine how that would work, I could be in a foreign country or international waters. Who would have your jurisdiction? I don’t think it’s forbidden to send radio waves into space
The other options involving radios, satellites is far more sexy
Depends.
Anything with high enough power is triangulateable, if you have either enough time, or enough listening equipment.
also what precision are we talking about?
on longwave you can bounce radio signals about quite a lot, but you lack bandwith, and the antenna are huge.
If you have a high band width transmitter, and you are doing async transmission, ie send a message when you are far away, then its not as critical.
The triangulation will not be to your location to to the ionospheric bounce. Locally it'll propagate via groundwave but that will quickly die out with the first hills and valleys.
A network of ~300 mi seperated stations doing NVIS could be fairly hard to locate. To make it slightly harder you could try using ultrawide bandwidth modulations (UWB) at HF freqs but propagations differences between the freqs will make it hard.
I say all of this but it depends on your threat model. Nowadays major nations have electromagnetic signals intelligence satellites even for HF up in orbit and have a line of sight to everything.
As well, as any honest engineer knows, new tech is rarely reliable and bug free. You may adopt it for other benefits, but assurance is generally not one of them. So if lives depend on something, you may keep using things that have been proven reliable.
They seemed to have communicated a lot with radio and coded messages. They also used some Windows software to decode some of those messages. And exactly there they made a mistake and some messages could be restored.
It seems like they only got very limited recurring training after their initial training in the 90s. So they might have had very limited IT opsec knowledge.
The analog radio technology is also far from perfect. In their case the neighbours became suspicious, because they never opened the door at specific times, probably when their transmissions were scheduled. They also sent some radio transmissions from a nearby hill, that might have played a part in their capture.
I'm convinced that some encrypted messages over a commonly used messenger or email provider would be way more secure. They would just disappear within billions of other encrypted messages.
It’s even harder to train new people in Old technology. Just write a code base in Fortran And see how hard it is to find a developer.
I’m quite confident you could send messages all day using the methods of Ancient Rome without being ever detected.
My thought is, that new people are trained on modern technology (how to acquire and set up a secure laptop OS or how to configure a smartphone), and older employees still "run" on the old technology.