Showing posts sorted by date for query "one time pad". Sort by relevance Show all posts
Showing posts sorted by date for query "one time pad". Sort by relevance Show all posts

Monday, December 16, 2024

Operation Tinker Bell has Relocated to the Website!

Operation Tinkel Bell has moved to the Cipher Machines and Cryptology website. The move offers more flexibility for HTML and maintenance, and a broader audience. It's also easier to switch from the operation to the technical and historical research on the website. If you love Cold War spy stories, secret operations, and cryptology, this is the perfect mix for many hours of excitement.

Operation Tinker Bell is a spy case that you solve using cryptography. The year is 1964 and Operation Tinker Bell takes place at the height of the Cold War. You are assigned to the operation as COMSEC officer, and your task is to decrypt the message traffic between intelligence agencies, their stations abroad and agents in the field. All required crypto tools, keys and clear instructions are provided. You get the proper training to work with the TSEC/KL-7 crypto machine, decrypt numbers station broadcasts, and use one-time pad encryption.

You experience spy tradecraft, operations behind the Iron Curtain, illegal border crossings, fake passports and safe houses. CIA transmitter sites in West Germany provide support, and the dreaded East-German Stasi and Czech StB secret police are some of your opponents. British intelligence helps to arrange clandestine meetings, the U.S. Army Security Agency provides SIGINT support and some USMLM operations don't take the rules of engagement too seriously.


Click the banner and join the operation!

The Cold War at its best, with authentic details, many historical photos, and as real as it gets. If you successfully decrypt all messages, your name is engraved in the Wall of Honor. However, this operation is no walk in the park, and failure is not an option. Read up on the operation in the briefing room, and be prepared.

Thursday, April 08, 2021

Operation Tinker Bell Anniversary

Can you solve the case?
Operation Tinker Bell is running exactly eight years. This cryptologic challenge is the ideal introduction to cryptography, crypto equipment and spy tradecraft. The participant worked through all messages, some in a few days and others took their time. Many e-mailed me with kind feedback, but they could never show their achievements to others. I therefore decided to introduce a Wall of Honor to document the result of their hard work (see below).

What is Operation Tinker Bell about? You will learn to work with the TSEC/KL-7, a 1960's state-of-the-art crypto machine (sim available) and decrypt operational one-time pad messages, used for one-way voice links, commonly known as numbers stations. Once you're briefed, you start in the CIA communications center and its crypto room, the inner sanctum where the most sensitive information arrives.

Robert Novak needs your support!
You are immersed in a true Cold War espionage atmosphere and witness the modus operandi of your fellow CIA officers and their KGB counterparts. Experience spy tradecraft first hand, with CIA transmitter sites in West Germany, illegal border crossings, fake passports, safe houses, the dreaded East-German Stasi and Czech StB secret police.

British intelligence helps to arrange clandestine meetings, you receive SIGINT support from the U.S. Army Security Agency and some of the USMLM operations flirt with the rules of engagement. The Cold War at its best. It's all there, authentic details and as real as it gets!

Operation Tinker Bell starts in 1964, at the height of the Cold War. CIA case officer Robert Novak investigates the sudden disappearance of a CIA operative in Moscow. Operation Tinker Bell, the hunt for a KGB colonel starts and Novak travels across the Soviet Union.

Ausweis bitte! Keep calm when East German border guards check your forged papers!

For obvious security reasons, all communications between Langley, the CIA stations abroad and their agents behind the Iron Curtain are encrypted. It's your task as COMSEC officer to decrypt all that message traffic. This sounds harder than it actually is. All required crypto tools, keys and clear instructions are provided and used exactly as in real life. Make sure to carefully read the briefing!


Below the names, engraved in the new Wall of Honor. Get to work, assist your CIA colleagues that operate across the Eastern Bloc and get your name on that wall. Join Operation Tinker Bell.


Update December 10, 2025: Newest case officer, Ege Ă–zdemir.

We can neither confirm nor deny the existence of this operation, but, hypothetically, if such operation were to exist, the subject matter would be classified and could not be disclosed (NCND)

Photo Updates! The details in operation Tinker Bell are quite realistic, and this includes all locations, some of which are known to participants. I recently received photos from Dietmar Sternad, who also completed the operation. He took the trouble to visit the hotel from file TB-0012 and the Stasi building from file TB-0018, and kindly sent me his photos. It's like visiting a favorite movie scene location, so I take that as a compliment. Thanks Dietmar!

The 1964 Hotel Continental in Czechoslovakia and Dietmar's 2021 photo.

The 1960s Stasi building "Runde Ecke" in Leipzig (GDR) and Dietmar's 2022 photo.


Tuesday, February 18, 2020

CRYPTO AG Alternatives?

The latest news about insecure Crypto AG equipment, sold not only to foes, but also to some friends, was not that surprising, given the warning signs that popped up in the past. The scale and duration of the operation is a surprise, but it's all part of the game called intelligence collection.

Despite those early red flags, Crypto AG, and its owners CIA and BND, managed to convince customers to maintain confidence in their crypto products. The reputation of the firm and its location in "neutral" Switzerland helped. The question is whether those customers had any choice, or alternatives?

In reality, truly secure communications is all but easy. Communications security is a highly specialised discipline, comprising a whole range of rules, regulations, technical requirements and equipment. Special dedicated equipment can provide such security, but trusting the manufacturer is essential. However, in the field of cryptography, so intertwined with security and intelligence collection, trusting others is not that smart. What are the alternatives? For a start, they are always costly, either in money or in effort.

Since people tend to prefer easy, they often choose cheap and simple. Today, that’s an application from their app store, or an add-on for their e-mail or browser software. Some diligent distrustful might download actual encryption software and have decent anti-virus software. In general, this creates more problems than solve them, and here’s why.

Normal computers, laptops, tablets and smartphones are absolutely not suitable to run encryption software, despite some vendors claiming otherwise. All these devices have numerous processes running in the background. Plug-ins, add-ons and other unidentified software, often downloaded automatically, for the sake of compatibility, convenience, or at the request of the user.

Software developers who claim their software provides secrecy and privacy on your personal computer or smartphone actually do not know what they are talking about. Not because of incompetence, but simply because they really have no idea of all the processes running before or after installing their software. Often, the user is both cause and problem, with kind assistance of your OSI layers, or Open Systems Interconnection (what's in a name). Seven layers of security nightmare.

Therefore, running crypto software might prevent your wife or neighbour from reading your e-mails, but won’t prevent state actors or professional hackers from doing so. Theoretically it takes far too long to crack strong encryption, but in 95% of the cases they don’t waste time and retrieve your data before encryption.

The most secure solution is off-line encryption on a dedicated computer or device. which is never connected to the security nightmare called Internet. This will make it harder, but not always impossible. Should you use commercial software, proprietary secret encryption algorithms, or develop your own crypto algorithm, and would that be secure?

Various publicly available algorithms are peer-reviewed and pretty secure. They take far too much time to crack, in theory. There are however always actors with more brain power and resources who might discover and exploit a mathematical shortcut. It's important that the user fully understands how the encryption works and can verify its performance, which is very hard. So he just has to trust the manufacturer? What's left?

There’s one type of encryption, truly unbreakable today, and in the future, no matter what technology might arise. Unbreakable because it's an equation with two unknowns, mathematically impossible to solve. It’s called one-time pad (OTP). Hailed in the past for protecting communications for diplomacy, military and intelligence, and still used for special purposes, this encryption method, performed on machines or with pencil and paper, provides secure communications, under the condition that it is implemented properly.

The famous Cold War Washington-Moscow hotline, encrypted with ETCRRM one-time tape machines, is a well known example. The paper version, shown below, was the favourite spy encryption for decades, often used in numbers stations. One-time pad has never been broken, and some erroneous claims are in fact cases of implementation errors.

One-time letter pad booklet with reciprocal encryption table.
Image © Dirk Rijmenants
One-time pad has two main drawbacks, which are however not technically insurmountable: true randomness and key distribution. OTP encryption requires truly random keys, as long as the message, and used only once. This creates logistical issues.

In the heydays of one-time pad, this meant a special courier from the organisation – usually state actors – that securely transports the keys. Secure key logistics is the sole reason why this unbreakable encryption is not generally used today, because secure logistics means costs.

Are costs really a problem? Today’s technology enables easy production and secure physical transport of vast amounts of key material (read bytes) on a small carrier, to provide year-long encryption before fully consumed, making it pretty cheap per byte. It's a question of willing to provide the technical infrastructure and funding. Even quantum key distribution already exists and is operational.

Secure transport might cost more than free exchange of  asymmetric cryptography's public-keys, but costs are relative. Ask Crypto AG customers, both adversaries and friendly states. Their costs for the equipment they bought, the training they received, maintenance and, last but least, the costs and damage caused by their compromised communications... for decades. Extremely expensive in terms of security and possibly also economic losses through industrial espionage.

Crypto AG HC-7845 world's first 1 Gigabit VPN encryption in 2009... can we trust it?
Earlier Cold War Hagelin/Crypto AG machines at the History of Hagelin page.
If they had used one-time pad encryption, common practice until the early 1980s, instead of Crypto AG equipment, it would have been less practical, a bit more costly, but in the end far cheaper than trusting their most critical secrets to outsiders and man-made algorithms with all their flaws, weaknesses and, as history showed, hidden intentional weaknesses. One-time pad, on the other hand, is simple, fast, transparent, easy to verify its proper functioning when applied in machines and yes, less practical.

However, if we talk about vital secure communications, what’s most important? Cheap, easy and insecure, or costly, hard and secure. One lesson throughout history is that real security is never cheap, always requires effort, but pays off. Unfortunately, little Joe, big companies and government agencies all want it to be easy and cheap, and they are at the same time addicted to producing and sending ever larger amounts of sensitive information. Weak security? We actually asked for it, and we got it.

Visit the one-time pad page on Cipher Machines and Cryptology to learn more about the history and use of unbreakable encryption. You want to use encryption that is – clearly – more secure than rigged Crypto AG machines? You can, but only if you strictly follow all the one-time pad rules! Read about it in the Guide to Secure Communications with One-time Pad (pdf). It’s unbreakable, free, transparent and fun, if you have some time to spare. There's also the history of Crypto AG and predecessor Hagelin Cryptos.

If you want to know why public-key cryptography solved the key exchange problem but not the actual security of our communications, check out Is One-time Pad History? (pdf). This was written many years ago, and a note was added in 2015 about how reality had surpassed our greatest fears by far. Well, we doubled down on that one again.

Tuesday, January 16, 2018

OTP Radiograms 101

I wrote last year about the fascinating life of the Jack Barsky, a former KGB agent who lived and operated in the United States from 1978 to 1988. After his cover was blown, he decided to stay in the United States and broke his ties with the KGB. It still took the FBI nine years to put all pieces together and catch him in 1997.

One of the tricks of the trade that Barsky used was the reception of radiograms that contained operational instructions. These messages were encrypted with one-time pad and broadcast by the KGB in Morse through a so-called numbers station. This is a most secure method because the radiograms are unbreakable and you cannot trace the receiver as anyone at any locations can receive the broadcast. That's why numbers stations are still in use today.

TAG Cyber Media just published a video interview with Jack Barsky where he explains the reception and decryption of these numbers messages.



Also check out Jack Barsky's KGB Radiograms and Family Tales to find that the life of an illegal can take quite a toll on his social life. You can read my review of Jack Barskt's book Deep Undercover that details his extraordinary life and career. More in depth technical and historical information about espionage and communications are found on my web pages about numbers stations and one-time pad. Jack Barsky also talked about other aspects of espionage during the TAG Cyber interview.

Thursday, October 12, 2017

DIANA - A Fast Reciprocal One Time Pad Table

There are various ways to perform one-time pad encryption with letter pads. The Vigenére table is a well known method to combine (e.i. encrypt) plain and key text into cipher text and vice versa. However, Vigenére has some serious drawbacks. It is cumbersome, time consuming and finding the cross section between letter and key is prone to mistakes. Also, key and cipher text must be processed in the same order by both sender and receiver.

A way faster and easier system is the reciprocal DIANA table. For each column letter there is a normal alphabet and a reversed alphabet. For each column, the reversed alphabet is shifted one position against the previous reversed alphabet and the table is statistically secure (1/26 chance to produce any cipher letter). Such reciprocal tables come in various formats but they all use the same principle. Note that this table is not compatible with the Vigenére table.

Thanks to its reciprocal properties, encryption and decryption are identical and require only a single column. The order of plain, key and cipher letter don't matter and may even differ for sender and receiver. The table is easy to use and it's virtually impossible to make a mistake.

The DIANA Reciprocal One-time Pad Table (download text file format)

To encrypt, we either write plaintext under key or key underneath plaintext. The choice is yours. For each combination of key and plain letter we take the table column that corresponds to the first letter and search underneath it for the second letter on the left. The lower-case letter to its right is the result.

In the example below we wrote the plaintext above the key. To encrypt T with X, find column T in the table, go downward to letter X and find cipher letter j at its right. Thanks to the reciprocal system it doesn't matter whether you combine T with X or X with T. Quite handy!
Plaintext : T H I S   I S   T H E  S E C R E T
OTP-Key   : X V H E   U W   G T P  N O P G D Z 
----------------------------------------------
Ciphertext: J X K D   X L   A Z G  U H I C S H

In groups : JXKDX LAZGU HICSH
To decrypt, take column X, go downward to J and find plain letter t at its right. Again, the order of key and cipher letter don't matter. The beauty of this system is the ease and speed of finding plain and cipher letters in whatever order you like best.

There is also a method to memorise the DIANA table and speed up the process even more. When encrypting F + G = O, we can decrypt this as O + G = F, but also as G + O = F. We call this the trigram combination FGO. Because of the reciprocal property, we can use the trigram FGO for any possible combination, that is, FGO, FOG, OFG, OGF, GFO and GOF.

Thus, if you encrypt or decrypt any letter from a trigram with another letter from that trigram you will always get the remaining letter of that trigram, regardless of the order. We therefore only need to remember the trigram FGO and instantly know every variation of the trigram. This reduces the number of combinations to memorise from 676 to 126. FGO can easily be remembered as the word "FOG".

Any user can create his list of mnemonics by memorising the 126 possible trigrams in any desired order. Some other examples are TAG (derived from AGT), BAY (derived from ABY), AIR (as itself), FDR (Franklin D Roosevelt, derived from DFR), HRB (HR Bureau), NNZ (Northern New Zealand), AMN (A-Mu-Nition), BGS (Better Get Smart), MBM (My Best Mate), JTX (Jump The Ex), VHX (Very Hot Ex), WXG (Wild X-Games) or OXO (the game). Tickle your imagination to find your own.

Everyone has his own connotations to easily remember the trigrams. Well trained operators can encrypt and decrypt on-the-fly at high speed without using any table, which is sheer impossible with Vigenére's 676 bigram combinations.

The full list of trigrams (download list in txt format) in alphabetic order to be memorised as any desired combination, e.g. ABY is also AYB, BAY, BYA, YAB and YBA.

AAZ ABY ACX ADW AEV AFU AGT AHS AIR AJQ 
AKP ALO AMN BBX BCW BDV BEU BFT BGS BHR
BIQ BJP BKO BLN BMM BZZ CCV CDU CET CFS
CGR CHQ CIP CJO CKN CLM CYZ DDT DES DFR
DGQ DHP DIO DJN DKM DLL DXZ DYY EER EFQ
EGP EHO EIN EJM EKL EWZ EXY FFP FGO FHN
FIM FJL FKK FVZ FWY FXX GGN GHM GIL GJK
GUZ GVY GWX HHL HIK HJJ HTZ HUY HVX HWW
IIJ ISZ ITY IUX IVW JRZ JSY JTX JUW JVV
KQZ KRY KSX KTW KUV LPZ LQY LRX LSW LTV
LUU MOZ MPY MQX MRW MSV MTU NNZ NOY NPX
NQW NRV NSU NTT OOX OPW OQV ORU OST PPV
PQU PRT PSS QQT QRS RRR


With one-time letter pads, punctuations and figures in the plaintext are usually spelled out. However, to limit the message length you generally omit punctuations where it doesn't affect readability. Alternatively, you could use rare letter combinations as a prefix to convert figures or punctuations into letters, for instance QQ or XX.

In that case XXF could be used to switch to figures and XXL to switch to letters, with ABCDEFGHIJ representing the digits 1234567890. Thus, 2581 would become XXFBEHAXXL or XXFBBEEHHAAXXL to exclude errors, which is more economical than having to write out 2581 in letters. XXP could be a period, XXK a comma and XXS a slant. XXC could be Code, a prefix for three or four-letter codes to replace long words or sentences, like XXCABC, where ABC represents “Request further information” or "My location is..."

And the best of all, one-time pad encrypted messages are absolutely unbreakable if the one-time pads are used once only (hence one-time) and destroyed immediately after use. Of course, the letters should be truly random (no algorithm based pseudo-random) and generated either by hardware or a dedicated computer, never connected to the Internet, and printed on a dedicated printer.
 
More technical and historical information about various one-time letter pads and one-time figure pads at Cipher Machines and Cryptology.

Thursday, August 10, 2017

Secret Splitting Revisited

I wrote about secret splitting some ten years ago and decided to fresh things up and create a new easy-to-use template. You only need a pen, paper and first grade math to obtain absolute security. But first, a quick reminder on what secret splitting is, how it works and why everyone should know this interesting system.

Secret splitting (also called secret sharing) enables you to split a secret code into multiple shares and give those shares in the custody of several persons. Retrieving the original code is only possible if the shareholders agree upon putting their shares together. The secret could be the code to a combination lock, safe deposit box, electronic key or password. You can split passwords to access a computer, encrypted files, a digital lock to enter a building or disable an alarm system.

An interesting property of secret splitting is that more people with shares means more security, because more people have to agree on putting their shares together, which is the opposite of sharing the secret itself, where more people means more risk.

There are many useful applications for secret splitting where you need to delegate access to your secret code in a specific situations. You can appoint several persons that will be able to open your safe with money or critical information in case of emergency. None of them can act alone and a single trustworthy person among them is enough to prevent misuse.

A parent who has stored his money, documents or valuables in a safe deposit box can split the number combination and all children receive a share. In case of emergency or the parent's decease they can only access the safe when all of them agree upon opening the safe. Each shareholder can even split his own share again into two shares, to hide his sub-shares separately as backup or destroy his original share and store his sub-shares at different places to increase security.

You can use secret splitting for secure remote delegation through insecure channels. Create a share for yourself and one or more shares for other persons. This way, you can be on the other side of the world and send your share to all other shareholders to give them access to a computer file or the pin code of a credit card, to name a few. The shareholders can only retrieve the code at the moment that you decide to give them your share and they all need to agree. You can use any insecure method like e-mail, chat or telephone to send your share, because that single share never reveals any useful information to an eavesdropper.

The template to create your own secure shares (download pdf here)

For our template we use the method where all shares are required to retrieve the original. It is mathematically impossible to retrieve the original if a single shareholder refuses to disclose his share. This method is information theoretically secure, read unbreakable.

There is another method, called secret splitting with threshold, which requires less shares than the total number of shares to retrieve the original. It's security is based on mathematical complexity. Unfortunately, this method does not guarantee information theoretical security.

Of course, you cannot simple cut a code or password in half or quarters, as this would reveal at least part of the code and provide clues to find the rest of the code or reduce the number of combinations to try out. The secret splitting we use is based on the principle of one-time pad encryption and all calculations are performed modulo 10 (addition without carry and subtraction without borrowing). The secret code is encrypted with one or more truly random keys and, in contrast to sending the encrypted secret to the receiver, we use the random keys and the encrypted code as shares.

We can only retrieve the original code when the encrypted code and all keys are put together. Take one share out of the equation and it will be mathematically impossible to decrypt the code. The only requirements are the use of truly random digits and, obviously, secure physical separation of the shares. The small number of required truly random digits are easily generated manually.

Secret splitting may sound complicated but it's quite simple to apply. If you can add and subtract, then you can create secure shares, and all it requires is a pen and paper. You can download the new version of the easy-to-use Secure Code Splitter which comes with clear instructions and examples, a blank calculation sheet and share template. More to read about secret splitting at my website.

Wednesday, July 26, 2017

Martha Peterson and TRIGON

Martha Peterson on her
1975 Russian driver license
The story of CIA operations officer Martha Peterson Shogi and her work related to Soviet spy Aleksandr Ogorodnik is quite remarkable and also sheds some light on how the two communicated in Moscow.

Martha 'Marti' Peterson, née Denny, met her first husband John Peterson at Drew University and married him in 1969. John enlisted as Green Beret to serve in Vietnam and was later hired by the Central Intelligence Service for covert operations in Laos. In 1971, Martha and John travelled to Laos, where John was killed one year later in a helicopter crash during a mission in Laos.
 
The Source Inside

In 1972, the CIA recruited Aleksandr Ogorodnik, a Soviet diplomat at the Soviet embassy in Bogota, Colombia. He was given the codename TRIGON. Ogorodnik provided the CIA with communications between Soviet ambassadors in South America, giving the CIA an insight in Soviet foreign politics. In 1974 he was recalled to Moscow to work at the Soviet Ministry of Foreign Affairs. His new job provided him access to communications and reports of Soviet ambassadors from all over the world. The CIA struck gold.

Aleksandr Ogorodnik
Before he returned to Moscow, the CIA provided him with a pen with miniature camera to photograph documents, a schedule to make dead drops, special carbon paper for invisible writing and trained him in the use of these materials. Ogorodnik also insisted on having a suicide pill, to use in case he got caught. CIA provided him with such so-called L-pill, concealed in a pen.

Martha Peterson returned to the Washington after her husband's death and applied for a job at the CIA. She was hired as CIA operations officer and agreed to be sent to Moscow. She received operational training and took a Russian language course. Peterson arrived in Moscow in November 1975.

Marti at the Front Line
 
At the age of 30 she became the first ever female CIA officer to be stationed in Moscow and was now responsible for the exchange of communications and spy items with TRIGON. Moscow was what is called a denied area, a term used by intelligence for a hostile area where conducting operations is extremely difficult due to heavy surveillance.

Peterson had an important advantage over here male CIA colleagues. The Soviet Intelligence Service did not believe that an American female would be a CIA officer and assumed that she was a low-level clerk. Peterson was therefore never under surveillance and, in contrary to other CIA officers, could travel around Moscow without being followed.

Peterson never met TRIGON in person. He delivered photographed documents and messages through pre-arranged dead drops, mostly in parks. During such operations, Peterson always wore an SRR-100 surveillance receiver to intercept and detect KGB surveillance communications (see also videos below).

After extensive surveillance detection runs, she collected the content of the dead drops, at the same time supplying him with a new pen-camera with film, instructions and one-time pad duplicates, through that same dead drop, which he in turn collected later on. TRIGON used the one-time pads to decrypt messages that he received trough CIA numbers station broadcasts from West Germany.

TRIGON Disappears

In early 1977, the CIA started worrying about the quality of the material that TRIGON provided and grew concerned about his security. Eventually, on June 26, TRIGON failed to retrieve a dead drop and there was no more communications. TRIGON neither showed up after a numbers station broadcast, instructing him to meet at a pre-arranged location on July 14.

In the evening of July 15, after the usual surveillance detection runs, Peterson arrived at the Krasnoluzhskiy railroad bridge over the Moscow river, near Lenin Central Stadium. At 2230 hours she placed a dead drop package, concealed as a hollow piece of concrete, in a niche in one of the bridge’s towers. As soon as she walked out of the tower, she was grabbed by three men who immediately strip-searched her, took photos and put her in a van that drove straight to Lubyanka prison in KGB headquarters.

KGB photo of Martha Peterson's apprehension at the Krasnoluzhskiy bridge

Martha Peterson during the interrogation at Lubyanka prison
Peterson's arrival for interrogation was filmed (see video at 48:58). She was interrogated while all items from the dead drop package and her SRR-100 receiver were displayed in front of her.

The U.S. Consul was summoned to Lubyanka prison to explain who she was and what she was doing. The KGB had no other choice than to release Peterson because she had a diplomatic status as vice consul (which of course was a cover for her CIA work). She was returned to the U.S. embassy and flown to Washington the next day. Declared persona non grata, Martha Peterson would never return to Russia.

The displayed espionage items, retrieved from the dead drop, and the SRR-100 receiver

In 1978, the Soviets released the story in the Izvestia newspaper, and the heavily publicised spy case also ended up in U.S. press. The Soviets alleged that Peterson smuggled poison to kill a Soviet citizen that interfered with a spy's criminal activities (see Washington Post archive June 13, June 15 and June 21, 1978). These accusations at the height of the Cold War were later proven false by the KGB itself.

The Downfall of TRIGON

The fate of Aleksandr Ogorodnik was unknown until the Soviets aired the 1984 TV series TASS Is Authorized to Declare. Its script was almost a copy of TRIGON’s story. In that movie, the spy committed suicide during interrogation with a pill from his pen. KGB accounts confirmed that Ogorodnik was arrested a month before Peterson got caught. During interrogation, he pretended to write a confession, took the special pen and quickly used the L-pill.

However, even today accounts vary on what actually happened to Ogorodnik and some even believe that he was killed by the KGB. We will probably never know the real story. The CIA believes that Karl Koecher, an agent of the Czechoslovak intelligence service StB that infiltrated the CIA as translator and analyst, betrayed TRIGON to the Soviets.

Martha Peterson continued to work as CIA officer in operations, including 10 years of foreign assignments, married her second husband Joseph Shogi in 1978 and retired in 2003 after a distinguished 32-year career in the Agency. 

The Veteran Tells Her Story

Find at Amazon
Peterson wrote The Widow Spy. The book is a fascinating personal and detailed account of her time in Laos, how she joined the CIA and her work as CIA officer in Moscow. I can highly recommend the book. More at her website Widow Spy.

Eight years after its release, a Russian version of her book was released in October, 2020. Find the Russian version at Labirint (translation).

The CIA published a short Featured Story on TRIGON. CNN's DECLASSIFIED page tells how she revealed her secret spy life to her kids, including several images of her Moscow era. They also aired Trigon: The KGB Chess Game (see below).

The Spy Museum published the podcast Caught by the KGB where Martha Peterson tells about how she was captured by the KGB. She also talks about her life in Moscow in the SPY: The Exhibit video. An account of Peterson's arrest is found at the The Espionage History Archive which also has the Russian view on the death of Aleksandr Ogorodnik.

The first female CIA officer in Cold War Moscow, is the first part of the Cold War Conversions two-part interview with Marti Peterson. where she tells about her life in Laos with het husband who worked for the CIA, why she returned to the U.S. In part two, Arrested by the KGB and taken to the Lubyanka prison, she tells the harrowing story of exchanging dead drops with TRIGON, how she was caught by the KGB and taken to the notorious Lubyanka Prison in Moscow for interrogation.

More about TRIGON's communications by Andrei Sinelnikov (translation) and there's also the Russian documentary Trianon. Encryption from Beyond.

More information about the equipment, used in this spy case, is found at the Crypto Museum's Martha Peterson page. Numbers-station.com published TRIGON Numbers Station and on my website there's more on number stations and use of one-time pads.


Declassified Spy Stories - Trigon: KGB Chess Game

Below her fascinating talk about her time in Moscow as case officer with many details on TRIGON. Highly recommended!

 
Former CIA Chief of Disguise Jonna Mendez explains some of the tradecraft, used to mislead KGB surveillance in denied areas like Moscow. In the video she also explains the SRR-100 and the pen with suicide pill, used by TRIGON.

Thursday, November 24, 2016

Operation Vula's Secure Communications

Operation Vula was the creation of an underground ANC leadership with supporting secure communications network in South Africa to fight against the apartheid regime. The operation ran from 1988 to 1991 and is also the fascinating story of Tim Jenkin, who played a key role in providing secure communications.

Going Underground

Tim Jenkin today
Tim Jenkin came into contact with the anti-apartheid movement when he visited the African National Congress (ANC) office in London. He was eager to support the fight against apartheid. Jenkin was trained in covert operations and returned to South Africa where he and his good friend Stephen Lee started underground work for ANC in 1975.

They ran a propaganda shop but got arrested in 1978 and were sentence to respectively 12 and 8 years imprisonment. Amazingly, they escaped 18 months later from a Pretoria high security prison with keys that Jenkin made out of wood. This gives you an idea of how creative he was. Jenkin left South Africa and made his way to the ANC office in London where he became a trainer for underground operatives.

ANC Going Blind in Exile

The ANC leadership had fled to Lusaka in Zambia after many of their leaders and members were jailed or tortured. This left the ANC with no representatives in South Africa. Among the exiled members were ANC president Oliver Tambo, commander of the military wing (MK) Siphiwe Nyanda and ANC strategist Mac Maharaj, whose mission was to revive the freedom movement and ignite revolution in South Africa.

This proved to be a mission impossible because of the problems to communicate and coordinate with the few ANC members that were still in South Africa. In the mid 1980s, communications between London, Lusaka and operatives in South Africa were still protected by manual one-time pad encryption that was too cumbersome for long reports that took many hours up to days to encrypt by hand.

Oliver Tambo tasked Siphiwe Nyanda to join MK's Chief of Staff Joe Slovo in starting up Operation Vula. The goal of this extensive operation was to set up a secure covert communications network and to smuggle ANC leaders and weapons into South Africa to install a leadership that would take over command of the underground work. This is where Tim Jenkin comes into play.

Jenkin met Mac Haharaj while training ANC agents on radio communications in Lusaka. Haharaj asked him to set up secure communications between covert operatives in South Africa and the ANC office in London. At that time, Jenkin was experimenting with computer communications.

Establishing Secure Communications

Personal computers were quite a novelty in the 1980s but handyman Jenkin developed one-time pad encryption software that used floppy disks, filled with random data, to serve as key. During encryption, used key bytes were automatically wiped from the disk, making the system unbreakable. The software also increased encryption speed for Vula messages considerably, compared to the slow pen-and-paper system.

Jenkin's office in London, nicknamed GCHQ (after the British Signals Intelligence organisation) served as the main Vula communications hub for messages between London, Lusaka and South Africa. In his computer shack he developed, tested and ran secure communications to cope with the increasing amount of reports from and to the ANC underground leadership.

Tim Jenkin in his communications hub

Jenkin devised a system to convert encrypted message digits into DTMF (dual-tone multi-frequency) telephone dial tones that were then recorded onto cassette tapes for transmission by pay phone later one. They provided ANC operatives with several DTMF tone generators that were disguised as electronic calculators. Later on, they dropped the method of manually keying in the DTMF tones and drastically increased communication speed by  recording the computer modem sound directly to tape.

Setting Up the Network

Conny Braam, a Dutch anti-apartheid activist, became responsible for the Vula logistics. She ran a network of people that supported the entire operation. First task was to get the network running. She had to find someone to travel several times a month between Amsterdam and Johannesburg. Air hostess Antoinette Vogelsang volunteered as courier. Being an air hostess, she didn't had to go through airport checks and could safely smuggle into South Africa the Toshiba laptops and software that secured the network. She also provided the communication hubs with a regular supply of floppy disks, containing new one-time pad keys.

The Dutch Lucia Raadschelders was sent to Lusaka to run a communications hub from a small house in the slums. She also served as contact between Jenkin and ANC headquarters in Lusaka. Janet Love, the ANC underground operative in Johannesburg switched from the slow manual one-time pad encryption to its fast computerised version. Everything was finally up and running. In 1988, Mac Maharaj and Siphiwe Nyanda  were the first Vula leaders to clandestinely infiltrated into South Africa.

Meanwhile, Janet Love's communications hub in Johannesburg was also operational. Tim Jenkin received the first long reports from Mac Maharaj a few weeks later. ANC's freedom movement finally was able to communicate securely with Jenkin's London office as central hub. From then on, Janet Love encrypted all Johannesburg messages and recorded the computer modem sound on cassette tape.

From South Africa over London to Mandela

The operative in South Africa chose a random pay phone to call an answering machine in London and played back the tape with the message that he had encrypted and recorded earlier. The London office checked the message and called the operative's pager with a specific code to signal that the message had arrived well. London then relayed this message to, for instance, ANC headquarters in Lusaka.

The London office also used a specific pager code to warn operatives in South Africa that there were messages for them to receive. To retrieve a message, the operative again chose a random pay phone and called another answering machine in London on which the London HQ had recorded an encrypted message from Lusaka or from other operatives.

From the manual encryption of long reports, taking many hours to encrypt and days to get across, they now were able to get a message to London in one or two hours. Jenkin relayed the messages almost real-time back and forth between the ANC headquarter in Lusaka and the operatives in South Africa. The South African security services could not track these messages as they were sent anonymously from randomly chosen pay phones. It would require them to monitor each and every pay phone and even if they managed to intercept such a message, it would merely contain what seemed like unintelligible fax or computer tones, giving them no clue about their purpose.

Mac Maharaj succeeded in setting up covert communications with the imprisoned Nelson Mandela through his lawyers. By then, the South African government held secret talks with Mandela, who they believed to be clueless about the situation in the country. Little did they know that Mandela was in direct contact with ANC president Oliver Tambo and a well organised underground leadership. In fact, without realising it, the apartheid regime was negotiating directly with the ANC. When Nelson Mandela was released from prison in February 1990, the Vula operation continued underground to protect the actual leadership and its communications with Mandela.

Caught But Mission Accomplished

The operation was eventually compromised in July 1990 after the police followed Siphiwe Nyanda and discovered encryption disks and plain messages in a Vula hide-out. Mac Maharaj, Siphiwe Nyanda and six other Vula members were arrested and imprisoned. Others fled the country or went into hiding. Despite this setback, Tim Jenkin was able to reboot the Vula network within 24 hours. All Vula members eventually received amnesty as part of the political transition that lead to the end of apartheid.

Tim Jenkin's story is an amazing example of people with no background in intelligence, espionage tradecraft or secure communications who used their creativity to set up an ingenious international secure network that changed South Africa's history. It should be noted that their communications system, which was quite novel and therefore secure in the 1980s, would pose serious risks in today's world with advanced signals intelligence capabilities, ranging from hacking computers to extensive electonic surveillance and geolocation.

Tim Jenkin's story of operation Vula is published at the Nelson Mandela Centre of Memory. More details about the encryption systems and equipment at the web page How the ANC sent encrypted messages. Also listen to a podcast with Anti-Apartheidsactiviste Conny Braam  (only in Dutch) and visit Conny Braam's website with here bio and books.

Below an excellent eNCA documentary about operation Vula and a NGC documentary of Tim Jenkin's escape from Pretoria prison.



Monday, October 10, 2016

Jack Barsky's KGB Radiograms and Family Tales

Commercial SW radio. A Spy's
favourite tool to receive messages
Jack Barsky's espionage career was a quite remarkable one with a surprising ending. Barsky was born as Albrecht Dittrich in East Germany. He was scouted by the Stasi, recruited and trained by the KGB and sent to the United States as a so-called illegal under the false identity of Jack Barsky.

In contrast to intelligence officers that operate under official cover (often pretending to be embassy personnel), illegals do not enjoy diplomatic protection if they are caught. They usually stay low-profile and only have contact to their agency through their handler, a career intelligence officer. Illegals are often regarded as the elite of spies but their live, although quite risky, is usually all but glamorous or exciting.

Barsky's spying career lasted from 1978 until 1988, when his cover was blown. He refused KGB orders to return to East Germany, where he had a wife and son, and chose to stay with his American wife and daughter. Amazingly, the KGB bought his excuse that he had contracted AIDS and allowed him his final years in the United States.

Eventually, the FBI tracked him down thanks to information from the vast collection of documents that KGB archivist Vasili Mitrokhin smuggled out of the Russia in 1992. Barsky, already inactive for several years, decided to cooperate with the FBI. He was extensively debriefed on KGB spy techniques and in return has never been indicted or put on trial.

Illegal agent's one-time pad
booklet and microdot reader
Source: CSIS
Jack Barsky is one more source that confirmed the use of one-way shortwave communications by intelligence organisations, known as numbers stations. Every Thursday evening Barsky tuned his shortwave radio to a predetermined frequency and listened for a so-called radiogram from the KGB. Barsky believes that his radiograms were broadcast from Cuba. His radiograms contained operational instructions that were encrypted into digits and sent in groups of five.

His radiograms could take an hour to receive and write down and up to three hours to decrypt. Anyone could hear the message, you had no idea who was actually listening and no one could decrypt or read it. When encrypted with a one-time pad, this pen-and-paper system is proven unbreakable.

The Americans: fiction and
real-life spy stories interwoven
Watch Jack Barsky's interview at TAG Cyber Media in which talks about the radiograms. In Podcast Nuggets Episode 7 there's a two-part interview with Jack at Cold War Conversations.

The Guardian also has a long article on Barsky. An excellent Spiegel TV documentary follows Jack Barsky in 2014 on his first trip into Germany in 30 years, as he explains how he became a KGB spy. The actual life of Jack Barsky as an illegal may not be that spectacular and full of action, compared to Phillip and Elizabeth Jennings in The Americans, but the work of illegals can take quite a toll on their personal life.

Donald Heithfield and Tracy Foley lived a seemingly ordinary life with their two sons Tim and Alex until their house was raided by the FBI in 2010. To their children's surprise, Donald and Tracy, whose real names were Andrei Bezrukov and Elena Vavilova, turned out to be members of a Russian spy ring in the United States, controlled by the illegals department of the SVR, the Russian Foreign Intelligence Service. Eventually, Canadian born Tim and Alex were deported with their parents to Russia in one of the biggest spy swaps ever. Their life as they knew it ended instantly. They received Russian passports and had to build a whole new life. The fascinating story of Tim and Alex was published last May in The Guardian and on McLean's you can read about their struggle to return Canada and their fight in court.

Andreas and Heidrun Anschlag, the spy couple arrested in German in 2011, also had a grown up daughter. Her life was undoubtedly also turned upside down by the spying career of her parents. But spies are not the only ones to pay a high personal price. The wives and children of defectors often suffered the same consequences.

When Igor Gouzenko, a GRU officer (military intelligence) and cipher clerk at the Soviet embassy to Canada decided to defect, taking along most sensitive intelligence documents, this also changed the life of his wife and child dramatically. The interview with his wife and the story of his daughter who, as a child, never knew that her father was not the man she believed him to be, are striking examples of the price for living a fabricated live. Remember, think twice before you start a spy career when you're a family man!

Further reading: numbers stations, one-time pad and Cold War signals.

Thursday, November 26, 2015

U.S. COMSEC History - Additional Releases

The National Security Agency (NSA) just published an update of the 2007 release of the David Boad lectures on communications security (see my old post). Many blank pages of the old version are now unredacted and show newly released information on various crypto systems, such as the TSEC/KL-7, KW-7, KW-26, KW-37 and one-time pad systems.

After the 2011 FOIA releases of the KL-7 operating instructions, I'm happy to see another bit of information on that pretty crypto machine ooze out of Fort Meade. More on the KL-7 at my website (including an accurate simulation). Of course there's much more to discover in the wonderful David Boak lectures. The unredacted version available in A History of U.S. Communications Security (Volumes I and II) 

Tuesday, February 10, 2015

BAPCO 's Use of One Time Pads During WWII

Mounted camel guard at the refinery.
Source: BAPCO
The Bahrain Petroleum Company (BAPCO) was a Canadian subsidiary, founded in 1929 by the American Standard Oil of California (Socal) to run its operations at the Awali oil fields on Bahrain Island, at the inlet of the Persian Gulf.

BAPCO became a possible target of Axis forces when Britain declared war on Germany. In 1940, the Bahrain oil refinery was targeted by Italian bombers, forcing the Allies to strengthen Bahrain's defense. Bahrain, in 1943 still a British Protectorate, decided to implement a censorship on messages that were sent over commercial cable and wireless, to prevent disclosure of information that might be useful to the enemy.

This censorship, however, greatly restricted the communications and operations of BAPCO. The majority of their messages contained information about oil production, shipping, personnel and food supply. Those messages fell into three main categories: a) cables that could be sent in plain text without objection, b) security cables that contained information that, in conjunction with other information, might indirectly be useful to the enemy, and c) secret cables that would be of direct use to the enemy if intercepted, such as ship movements, especially oil tankers.

On April 4, 1943, Ward P. Anderson, the general manager and chief local representative of BAPCO, asked E. B. Wakefield, the British Political Agent in Bahrain, permission to encrypted their cables between the local branch and their New York office. This would allow them to send security related cables, at the same time respecting Bahrain's censorship. Anderson proposed a secret company code, superimposed (enciphered a second time) with a transposition cipher for added security.


The Political Resident of the Persian Gulf in Camp Bahrain forwarded the request on April 8 to the Secretary of State for India in London, who approved the use of a secret code, provided that censorship received a plain text version of all messages, sent in that code, BAPCO should continue to send messages through the Navy if they contained vital information that would be of direct use to the enemy, and messages regarding political matters were to be sent through the Political Agent. After consulting the New York office, Ward Anderson agreed to these conditions.

P.A.I.C. in Baghdad asked whether the code had already been vetted for security. As this was not the case, the British Political Resident forwarded the request to SNOPG (Senior Naval Officer in the Persian Gulf) in Basra but they had no officer qualified to vet the code. Therefore, PAIFORCE suggested to vet the code.

The new code, proposed by the California Texas Oil Company, arrived from New York on October 24, and Bahrain forwarded the code on November 10 by courier for examination to the Cipher Security Officer of P.A.I.C. in Baghdad. After reviewing the code, the Security Officer responded that the code offered little resistance against cryptanalysis and provided no security whatsoever.

Note: P.A.I.C. (Persia and Iraq Command) in Baghdad was the headquarters of PAIFORCE (Persia and Iraq Force), the British and Commonwealth military formation in the Middle East from 1942 to 1943.


Surprised by this answer, Ward Anderson explained that the code was allocated by the U.S. Navy Department and considered the most secure known, used for the most secret messages. He clarified that "each page of the pad of sheets is used only once and destroyed after use". He continues, "In fact, the code changes with each succeeding letter of the message. When the pad is exhausted, a new set of pads is produced".

To Anderson, it seemed unlikely that British military authorities would be unfamiliar with the proper use of this type of code, so he asked to verify whether the code was indeed insecure, adding that U.S. authorities would be most interested if the British claims proved correct.

This was probably his polite way to hint the Political Agency and the PAIFORCE Security Officer that they were going to embarrass themselves. To their defense, it might be possible that the code was not accompanied with the complete and proper coding instructions, thus failing to show that the code was for one-time use.


Soon after, the Secretary of State for India in London informed the Political Resident in Bushire, Iran, that the U.S. Chief of Cable Censorship urgently requested permission to use the code, adding that it was a one-time pad, similar to the one used by the Ministry of War Transport in London. P.A.I.C. also received note of this. Apparently, someone pulled some strings.

Subsequently, the Political Resident confirmed to its agency in Bahrain that the code was indeed a one-time pad from the U.S. Navy Department. Eventually, the agent informed the BAPCO representative that objection to the code had been withdrawn and that "the one-time pad can be used on the understanding that the pad is not worked through more than once".




BAPCO started using the one-time pads as of January 15, 1944, more than eight months after their initial request. Yes, even during wartime, bureaucrats persist. Of course, we have to take in account that transportation and communication means in 1943 were quite different from today, and codes were always transferred safe-hand by courier.

Once the war had ended, BAPCO requested on August 22, 1945 permission from Bahrain to commence the use of the company's own cable code again, as used before the outbreak of hostilities in 1939.

Below one of the BAPCO coded messages from Bahrain to New York, with plain version included, submitted to Censorship as agreed with British authorities.


These archived conversations are a rare example of a commercial firm using the unbreakable one-time pad in the early 1940s. At that time, the use of such strong encryption was generally limited to governments, their military, intelligence agencies and diplomacy. BAPCO's use of one-time pads, allocated to them by the U.S. Navy Department, is a nice example of how government and commercial firms teamed up to ensure the highest level of communications security for those companies that were somehow important to the war effort.

All letters and cables regarding this request for using one-time pads are found in the British Library: India Office Records and Private Papers as File 10/5 BAPCO CODES, reference IOR/R/15/2/423. More examples of coded messages and their plain text version, submitted to censorship, are found in File 10/23 Code Messages - BAPCO, reference IOR/R/15/2/450. These records are archived in the Qatar Digital Library. More on the 1940 bombing raid on Bahrain in the Qatar Library, and an account of the attack on the BAPCO refinery is available at the Saudi Aramco website.

These documents are also unique as a reference, because the use of one-time pads is hardly mentioned in official documents from that era (for obvious security reasons) and they are, as far as I know, the earliest I came across. They confirm the use of one-time letter pads  by Political Residents of the British Imperial Civil Administration, the British Army, the Ministry of War Transport in London and the U.S. Navy, at least as early as 1943. Both British and U.S. authorities were quite familiar with the system and surprisingly even shared it with commercial firms. The archives also show that British Residents in the Middle East regularly received sets of two-way one-time pads.

More historical and technical information about one-time pad is available at my Cipher Machines and Cryptology website.

The Bahrain Petroleum Company (BAPCO), one of the oldest oil companies in the Middle East, was established in 1929 by Standard Oil Company of California. BAPCO obtained in 1930 the only oil concession in Bahrain. In 1936 they discovered the Awali oil field and opened a refinery with a capacity of 10,000 barrels per day. That same year, Standard Oil Company of California signed an agreement with Texaco, creating the joint venture California Texas Oil Company (Caltex). These companies are now known as Chevron and Texaco. The Bahrain government took over all BAPCO shares in 1980 and acquired full ownership in 1997. Visit their website to read  BAPCO's history.