Showing posts sorted by relevance for query "one time pad". Sort by date Show all posts
Showing posts sorted by relevance for query "one time pad". Sort by date Show all posts

Tuesday, February 18, 2020

CRYPTO AG Alternatives?

The latest news about insecure Crypto AG equipment, sold not only to foes, but also to some friends, was not that surprising, given the warning signs that popped up in the past. The scale and duration of the operation is a surprise, but it's all part of the game called intelligence collection.

Despite those early red flags, Crypto AG, and its owners CIA and BND, managed to convince customers to maintain confidence in their crypto products. The reputation of the firm and its location in "neutral" Switzerland helped. The question is whether those customers had any choice, or alternatives?

In reality, truly secure communications is all but easy. Communications security is a highly specialised discipline, comprising a whole range of rules, regulations, technical requirements and equipment. Special dedicated equipment can provide such security, but trusting the manufacturer is essential. However, in the field of cryptography, so intertwined with security and intelligence collection, trusting others is not that smart. What are the alternatives? For a start, they are always costly, either in money or in effort.

Since people tend to prefer easy, they often choose cheap and simple. Today, that’s an application from their app store, or an add-on for their e-mail or browser software. Some diligent distrustful might download actual encryption software and have decent anti-virus software. In general, this creates more problems than solve them, and here’s why.

Normal computers, laptops, tablets and smartphones are absolutely not suitable to run encryption software, despite some vendors claiming otherwise. All these devices have numerous processes running in the background. Plug-ins, add-ons and other unidentified software, often downloaded automatically, for the sake of compatibility, convenience, or at the request of the user.

Software developers who claim their software provides secrecy and privacy on your personal computer or smartphone actually do not know what they are talking about. Not because of incompetence, but simply because they really have no idea of all the processes running before or after installing their software. Often, the user is both cause and problem, with kind assistance of your OSI layers, or Open Systems Interconnection (what's in a name). Seven layers of security nightmare.

Therefore, running crypto software might prevent your wife or neighbour from reading your e-mails, but won’t prevent state actors or professional hackers from doing so. Theoretically it takes far too long to crack strong encryption, but in 95% of the cases they don’t waste time and retrieve your data before encryption.

The most secure solution is off-line encryption on a dedicated computer or device. which is never connected to the security nightmare called Internet. This will make it harder, but not always impossible. Should you use commercial software, proprietary secret encryption algorithms, or develop your own crypto algorithm, and would that be secure?

Various publicly available algorithms are peer-reviewed and pretty secure. They take far too much time to crack, in theory. There are however always actors with more brain power and resources who might discover and exploit a mathematical shortcut. It's important that the user fully understands how the encryption works and can verify its performance, which is very hard. So he just has to trust the manufacturer? What's left?

There’s one type of encryption, truly unbreakable today, and in the future, no matter what technology might arise. Unbreakable because it's an equation with two unknowns, mathematically impossible to solve. It’s called one-time pad (OTP). Hailed in the past for protecting communications for diplomacy, military and intelligence, and still used for special purposes, this encryption method, performed on machines or with pencil and paper, provides secure communications, under the condition that it is implemented properly.

The famous Cold War Washington-Moscow hotline, encrypted with ETCRRM one-time tape machines, is a well known example. The paper version, shown below, was the favourite spy encryption for decades, often used in numbers stations. One-time pad has never been broken, and some erroneous claims are in fact cases of implementation errors.

One-time letter pad booklet with reciprocal encryption table.
Image © Dirk Rijmenants
One-time pad has two main drawbacks, which are however not technically insurmountable: true randomness and key distribution. OTP encryption requires truly random keys, as long as the message, and used only once. This creates logistical issues.

In the heydays of one-time pad, this meant a special courier from the organisation – usually state actors – that securely transports the keys. Secure key logistics is the sole reason why this unbreakable encryption is not generally used today, because secure logistics means costs.

Are costs really a problem? Today’s technology enables easy production and secure physical transport of vast amounts of key material (read bytes) on a small carrier, to provide year-long encryption before fully consumed, making it pretty cheap per byte. It's a question of willing to provide the technical infrastructure and funding. Even quantum key distribution already exists and is operational.

Secure transport might cost more than free exchange of  asymmetric cryptography's public-keys, but costs are relative. Ask Crypto AG customers, both adversaries and friendly states. Their costs for the equipment they bought, the training they received, maintenance and, last but least, the costs and damage caused by their compromised communications... for decades. Extremely expensive in terms of security and possibly also economic losses through industrial espionage.

Crypto AG HC-7845 world's first 1 Gigabit VPN encryption in 2009... can we trust it?
Earlier Cold War Hagelin/Crypto AG machines at the History of Hagelin page.
If they had used one-time pad encryption, common practice until the early 1980s, instead of Crypto AG equipment, it would have been less practical, a bit more costly, but in the end far cheaper than trusting their most critical secrets to outsiders and man-made algorithms with all their flaws, weaknesses and, as history showed, hidden intentional weaknesses. One-time pad, on the other hand, is simple, fast, transparent, easy to verify its proper functioning when applied in machines and yes, less practical.

However, if we talk about vital secure communications, what’s most important? Cheap, easy and insecure, or costly, hard and secure. One lesson throughout history is that real security is never cheap, always requires effort, but pays off. Unfortunately, little Joe, big companies and government agencies all want it to be easy and cheap, and they are at the same time addicted to producing and sending ever larger amounts of sensitive information. Weak security? We actually asked for it, and we got it.

Visit the one-time pad page on Cipher Machines and Cryptology to learn more about the history and use of unbreakable encryption. You want to use encryption that is – clearly – more secure than rigged Crypto AG machines? You can, but only if you strictly follow all the one-time pad rules! Read about it in the Guide to Secure Communications with One-time Pad (pdf). It’s unbreakable, free, transparent and fun, if you have some time to spare. There's also the history of Crypto AG and predecessor Hagelin Cryptos.

If you want to know why public-key cryptography solved the key exchange problem but not the actual security of our communications, check out Is One-time Pad History? (pdf). This was written many years ago, and a note was added in 2015 about how reality had surpassed our greatest fears by far. Well, we doubled down on that one again.

Tuesday, July 26, 2011

One-time Pad History Rewritten

Does the discovery in an old telegraph codebook rewrites the history of cryptography? Until now, Gilbert Vernam was generally accepted as the inventor of the unbreakable one-time encryption. His teletype system was later improved by Joseph Mauborgne and paper versions of the systems later became widely used for diplomatic and military communications.

Recently, Steven Bellovin, professor of computer science at the Columbia University School of Engineering, discovered a 1882 telegraph codebook in the Washington Library of Congress. This codebook, compiled by a Frank Miller, describes a superencipherment of telegraph codes by random "shift-numbers" that should not be repeated. Did Bellovin discover the proof that one-time pad was invented 35 years earlier? Should the history of cryptography regarding one-time pads be rewritten?

Let us first explain what was actually discovered. Telegraph codebooks were used extensively in the 19th century to reduce costs of telegrams by compressing words and phrases into codewords or into a combination of letters or digits. Codebooks did not provide any cryptographic security. Therefore, the codes were sometimes superenciphered (an additional layer of encipherment over the code) with a short key to improve its security. Miller's codebook contains 14,000 words or phrases (some are blanks) with their corresponding codewords and a serial number. So far, nothing special.

The codebook also provides instructions for a superencipherment. These instructions are what makes his work extraordinary. In his preface, Miller writes: "the sender and receiver must each cancel "shift-numbers" as soon as they are used". He further states that "if the senders finds that the addition of the key (to the serial-number) produces a sum greater than the highest serial number (14,000) in this book, he must deduct said last serial number (14,000) from said sum." If the receiver finds that the enciphered word "is less than the key which is to unlock it, he must temporarily add to said serial-number the highest number in this book (14,000) and deduct the key from the sum".

Now, let us recapitulate this: to calculate the ciphertext, the sender adds a key (the shift-numbers) to the plaincode numbers (serial numbers). When the total is more than 14,000, he subtracts 14,000. To decipher, the receiver subtracts the key from the ciphertext. However, if the ciphertext is smaller than the key, he first adds 14,000 to the ciphertext and than subtracts the key. This is essentially a modulo 14,000 additive cipher.

Further down, Miller describes the shift-numbers as "a list of irregular numbers" and "the difference between such numbers must not be regular". He also explains that when a shift-number has been used, it should be erased from the list and not used again. Next, some examples are given where words are replaced by their serial-number (plaincode) and a shift-number (key) is added.

This is clearly the essence of one-time pad encryption. Text is converted into numbers, a random key is added by modular arithmetic and the key should not be used again. Moreover, Miller explains that each correspondent should wirte his own shift-numbers list in black ink in a book and the correspondent's list in red ink upon the opposite page. He clearly distinguishes the black (encipher) and red (decipher) shift-numbers. By doing so, he avoids simultaneous use of the same shift-numbers, something that could occur when both correspondents use one single list of shift-numbers.

Unfortunately, Miller falls short in explaining that each shift-number should have a value between 0 and 14,000. He neither addresses the issue of generating truly random values. This could affect the security of the cipher as the user could be seduce into selecting smaller shift-values that don't require the cumbersome modulo 14,000 calculations. The complicated modulo 14,000 might well be the reason why his system never received the attention and success it deserved. Taking the individual digits of the serial numbers as independent, and applying a modulo 10 (add without carry, subtract without borrowing) would have been much easier and faster. We can only speculate about the reason why Frank Miller's one-time encryption never became publicly know.

Steven Bellovin speculates whether Miller's work might somehow, indirectly through Parker Hitt and Joseph Mauborgne, have reached Gilbert Vernam. However, Vernam, as an electrical engineer, approached the one-time encryption from an entirely different angle and discovered a completely different solution of teletype five-bit punched paper tapes using modulo 2 on each of its five bits. Fact is that Frank Miller's work disappeared in oblivion.

It is indisputable that Frank Miller was the first to invent the one-time pad encryption, albeit less practical than in its current form. 35 years later, Gilbert Vernam invented a completely different electromechanical cipher system that incidentally had the same mathematical properties as Miller's pencil-and-paper cipher. Finally, it were the German cryptologists Werner Kunze, Rudolf Schauffler and Erich Langlotz who developed a one-time pad system for use with pencil and paper, thus re-inventing Frank Miller's encryption scheme.

We may conclude that both Miller and Vernam independently invented one-time pad, and both deserve credit for the same achievement, although in a completely different form. But ultimately, we must acknowledge Frank Miller as the first to have invented the one-time pad concept. Sadly, as far as we know, his invention did not influence the history of cryptography. Nevertheless, history rewritten! And finally, not to be forgotten, Steven Bellovin can be credited for discovering the inventor of one-time pad. Congratulations, Steven!

More details about Miller's 1882 telegraphic codebook are found in Steven Bellovin's paper on Frank Miller (direct link to pdf). The history and use of one-time pads is found on my website. More on various old telegraphic codebooks is found on my post about the Nick Gessler collection.

Thursday, September 09, 2010

One-time encryption in Today's World

Miniature one-time pad
© Dirk Rijmenants
One-time pad encryption is a most basic encryption algorithm where a truly random key is applied on the same amount of data. This type of encryption, invented 93 years ago, is mathematically unbreakable.

There's no way to crack it with current or future computer power, simply because it is mathematically impossible. Although this sounds impressive, there are some drawbacks. The key must be truly random, must be as long as the actual data that should be encrypted, and you can use a particular key only once. The consequence is a cumbersome key distribution with associated security problems.

Before we go any further, I must point out here that we're going to talk about modern one-time encryption applications, not the pencil-and-paper spy craft a shown in the picture. Neither is this article about small one-time passwords or one-time keys which are only valid for a single encryption session with some algorithm under control of that key, and certainly not about the many snake-oil applications that pretend to be unbreakable because they claim to be using one-time encryption, while they actually are not. Remember: key as long as the data, truly random and used only once. There's no way around these three conditions without messing up the unbreakable part (although many wrongly claim to have a solution)!

So, cumbersome key distribution is where the mathematicians, or crypto-experts as you like, come in the play. In 1973, they invented asymmetric encryption which solves the problem of key distribution. Symmetric encryption requires the same key for encryption and decryption, and all people involved need a copy of that same key. With asymmetric public key cryptography however, you have key pairs that consist of a public key for encryption which you can share openly with everybody, and a private key for decryption that you keep secret. This solves the problem of key exchange. Since the invention of asymmetric key encryption, many crypto experts are buzzing around that it is the holy grail. Well...not quite.

Their system has nothing to do with the message security, only with the - unproven - key exchange security. Unfortunately, asymmetric encryption is not suitable for the encryption of large amounts of data. Hence, we only use it to encrypt a random key. Next, the actual data is encrypted with a traditional symmetric encryption algorithm, under control of that key. Finally, we send the complete package, encrypted key and encrypted data, to the recipient. Key distribution problem solved! What actually happened is that they took traditional symmetric algorithms, of which they are not really sure whether they are secure (they are not, as they are deterministic), but hey, they found an easy/lazy way to exchange the keys for those traditional algorithms. Problem solved. Doooh!?

Bearing this in mind I just love David Boak's (NSA) magnificent quote: "the ‘approved’ systems have simply been shown to adequately resist whatever kinds of crypto-mathematical attacks we, with our finite resources and brains, have been able to think up. We are by no means certain that the [opponent] equivalent can do no better". This says a lot, if not all.

How secure their asymmetric encryption might be, it doesn't change the fact that the actual data is encrypted with a traditional symmetric encryption algorithm and that's not a question of so-called insurmountable mathematical problems to crack asymmetric encryption, but a question of cryptanalysis of man-made algorithms, prone to weaknesses (not to mention mathematical shortcuts, back doors or bluntly faulty application). By the way, didn't Auguste Kerckhoffs and Claude Shannon learned us that, if we don't know how to break it, it isn't unbreakable, and any system that reduces a large secret (the data) to a smaller secret (a key) is deterministic and will never be unbreakable,

What happened is that, by focusing on the practical advantages of asymmetric key encryption and welcoming its large scale application and commercialization, many mathematicians lost track of what really matters: message security. They say that one-time encryption is rendered superfluous in the era of asymmetric encryption. Just because it's less practical? By saying this, they actually prove themselves wrong, as the one has nothing to do with the other. They solved the key distribution problem and not the message security problem.

One time encryption, on the other hand, solves the message security perfectly (isn't that what we really need) but has a nasty key distribution issue. It would have been nice if those wizz kids solved that one! Well, maybe they did, but just don't tell us... but I doubt that. Cryptography is always a balancing between effort (comfort), costs and security. You can favor one of those - a bit - to the prejudice of the others, for a particular situation, but you can't say that comfort is better than security, and should never nibble on security in favor of comfort, when security is important.

Modern crypto algorithms provide reasonable but practical security and privacy, essential to our economy and everyday life. Sure, it made our lives easier and how else could we do all those things like buying on the Internet, using credit cards on-line, and many other things. But let us be serious, the combination of traditional encryption algorithms and asymmetric key algorithms provides nothing more or less than 'reasonable' security, and it will never provide real security or long term security.

But what is worse, is that the general public has become blinded by today's easy encryption systems and their commercial success. They don't realize that real privacy and security comes with a price called "effort & discipline", not to be confused with, and unfortunately incompatible with "easy-to-use". This might not be essential to the average man in the street, but it does matter if we talk about a company's production secrets, trade secrets or political activism, to name a few.

Some experts argue that the distribution of large quantities of keys, inherent to one-time encryption, is impractical. However, today’s electronics are capable of generating large numbers of truly random keys, and current one-time encryption software can process large quantities of data at high speed. Current data storage technology such as USB sticks, DVD’s, external hard disks or solid-state drives enable the physically transport of enormous quantities of truly random keys.

Actual sensitive communications are often limited to a small number of users. In such cases, one-on-one communications with the associated key distribution, possibly in configuration with a star topology to connect multiple users, is no longer really a practical problem, especially considering the security benefits (this quote will not be popular with cryptologists, but it is true).

By using a co-called sneakernet (transferring data on removable media by physically couriering), you can reach a throughput (amount of data per unit time) of one-time key material that is greater than what a network can process on data that must be encrypted. In other words, it could take a few hours to get a terabyte of key material, stored on an external drive, by car to someone, but it will take days or even weeks to consume that amount of keys on a broadband network.

A terabyte sized key can easily encrypt you e-mail traffic for a year, including attachments (you just try to send or receive a terabyte of data, most Internet providers won’t even offer such amount of traffic). Therefore, if security is preferred above practical key distribution, and physical key exchange is possible beforehand, then one-time pad is the right choice. Some commercial firms offer such one-time encryption solutions, mostly to government and defense agencies, and for good reasons.

Conclusion: yes, public key algorithms are useful and have earned their place in the market of reasonably secure large scale communications, and yes, one time encryption will stay the preferred solution when unconditional security is required. Stop comparing apples and oranges, we need both! And for anyone who states that one-time encryption is history, I have one advice: provide the actual mathematical proof that your asymmetric system and accompanied symmetric algorithm are safe, today and tomorrow (I can with one-time encryption). Bring it on, Bruce!

I wrote a paper called Is One-time Pad History, about one-time encryption and the illusions of modern computer cryptography. More about the history of one-time pad on my website. On Mils Electronic, a key technology company, there's more about one-time encryption (pdf) and secure message exchange (pdf).

Tuesday, February 10, 2015

BAPCO 's Use of One Time Pads During WWII

Mounted camel guard at the refinery.
Source: BAPCO
The Bahrain Petroleum Company (BAPCO) was a Canadian subsidiary, founded in 1929 by the American Standard Oil of California (Socal) to run its operations at the Awali oil fields on Bahrain Island, at the inlet of the Persian Gulf.

BAPCO became a possible target of Axis forces when Britain declared war on Germany. In 1940, the Bahrain oil refinery was targeted by Italian bombers, forcing the Allies to strengthen Bahrain's defense. Bahrain, in 1943 still a British Protectorate, decided to implement a censorship on messages that were sent over commercial cable and wireless, to prevent disclosure of information that might be useful to the enemy.

This censorship, however, greatly restricted the communications and operations of BAPCO. The majority of their messages contained information about oil production, shipping, personnel and food supply. Those messages fell into three main categories: a) cables that could be sent in plain text without objection, b) security cables that contained information that, in conjunction with other information, might indirectly be useful to the enemy, and c) secret cables that would be of direct use to the enemy if intercepted, such as ship movements, especially oil tankers.

On April 4, 1943, Ward P. Anderson, the general manager and chief local representative of BAPCO, asked E. B. Wakefield, the British Political Agent in Bahrain, permission to encrypted their cables between the local branch and their New York office. This would allow them to send security related cables, at the same time respecting Bahrain's censorship. Anderson proposed a secret company code, superimposed (enciphered a second time) with a transposition cipher for added security.


The Political Resident of the Persian Gulf in Camp Bahrain forwarded the request on April 8 to the Secretary of State for India in London, who approved the use of a secret code, provided that censorship received a plain text version of all messages, sent in that code, BAPCO should continue to send messages through the Navy if they contained vital information that would be of direct use to the enemy, and messages regarding political matters were to be sent through the Political Agent. After consulting the New York office, Ward Anderson agreed to these conditions.

P.A.I.C. in Baghdad asked whether the code had already been vetted for security. As this was not the case, the British Political Resident forwarded the request to SNOPG (Senior Naval Officer in the Persian Gulf) in Basra but they had no officer qualified to vet the code. Therefore, PAIFORCE suggested to vet the code.

The new code, proposed by the California Texas Oil Company, arrived from New York on October 24, and Bahrain forwarded the code on November 10 by courier for examination to the Cipher Security Officer of P.A.I.C. in Baghdad. After reviewing the code, the Security Officer responded that the code offered little resistance against cryptanalysis and provided no security whatsoever.

Note: P.A.I.C. (Persia and Iraq Command) in Baghdad was the headquarters of PAIFORCE (Persia and Iraq Force), the British and Commonwealth military formation in the Middle East from 1942 to 1943.


Surprised by this answer, Ward Anderson explained that the code was allocated by the U.S. Navy Department and considered the most secure known, used for the most secret messages. He clarified that "each page of the pad of sheets is used only once and destroyed after use". He continues, "In fact, the code changes with each succeeding letter of the message. When the pad is exhausted, a new set of pads is produced".

To Anderson, it seemed unlikely that British military authorities would be unfamiliar with the proper use of this type of code, so he asked to verify whether the code was indeed insecure, adding that U.S. authorities would be most interested if the British claims proved correct.

This was probably his polite way to hint the Political Agency and the PAIFORCE Security Officer that they were going to embarrass themselves. To their defense, it might be possible that the code was not accompanied with the complete and proper coding instructions, thus failing to show that the code was for one-time use.


Soon after, the Secretary of State for India in London informed the Political Resident in Bushire, Iran, that the U.S. Chief of Cable Censorship urgently requested permission to use the code, adding that it was a one-time pad, similar to the one used by the Ministry of War Transport in London. P.A.I.C. also received note of this. Apparently, someone pulled some strings.

Subsequently, the Political Resident confirmed to its agency in Bahrain that the code was indeed a one-time pad from the U.S. Navy Department. Eventually, the agent informed the BAPCO representative that objection to the code had been withdrawn and that "the one-time pad can be used on the understanding that the pad is not worked through more than once".




BAPCO started using the one-time pads as of January 15, 1944, more than eight months after their initial request. Yes, even during wartime, bureaucrats persist. Of course, we have to take in account that transportation and communication means in 1943 were quite different from today, and codes were always transferred safe-hand by courier.

Once the war had ended, BAPCO requested on August 22, 1945 permission from Bahrain to commence the use of the company's own cable code again, as used before the outbreak of hostilities in 1939.

Below one of the BAPCO coded messages from Bahrain to New York, with plain version included, submitted to Censorship as agreed with British authorities.


These archived conversations are a rare example of a commercial firm using the unbreakable one-time pad in the early 1940s. At that time, the use of such strong encryption was generally limited to governments, their military, intelligence agencies and diplomacy. BAPCO's use of one-time pads, allocated to them by the U.S. Navy Department, is a nice example of how government and commercial firms teamed up to ensure the highest level of communications security for those companies that were somehow important to the war effort.

All letters and cables regarding this request for using one-time pads are found in the British Library: India Office Records and Private Papers as File 10/5 BAPCO CODES, reference IOR/R/15/2/423. More examples of coded messages and their plain text version, submitted to censorship, are found in File 10/23 Code Messages - BAPCO, reference IOR/R/15/2/450. These records are archived in the Qatar Digital Library. More on the 1940 bombing raid on Bahrain in the Qatar Library, and an account of the attack on the BAPCO refinery is available at the Saudi Aramco website.

These documents are also unique as a reference, because the use of one-time pads is hardly mentioned in official documents from that era (for obvious security reasons) and they are, as far as I know, the earliest I came across. They confirm the use of one-time letter pads  by Political Residents of the British Imperial Civil Administration, the British Army, the Ministry of War Transport in London and the U.S. Navy, at least as early as 1943. Both British and U.S. authorities were quite familiar with the system and surprisingly even shared it with commercial firms. The archives also show that British Residents in the Middle East regularly received sets of two-way one-time pads.

More historical and technical information about one-time pad is available at my Cipher Machines and Cryptology website.

The Bahrain Petroleum Company (BAPCO), one of the oldest oil companies in the Middle East, was established in 1929 by Standard Oil Company of California. BAPCO obtained in 1930 the only oil concession in Bahrain. In 1936 they discovered the Awali oil field and opened a refinery with a capacity of 10,000 barrels per day. That same year, Standard Oil Company of California signed an agreement with Texaco, creating the joint venture California Texas Oil Company (Caltex). These companies are now known as Chevron and Texaco. The Bahrain government took over all BAPCO shares in 1980 and acquired full ownership in 1997. Visit their website to read  BAPCO's history.

Tuesday, June 10, 2008

One-time Pad Tool

I just uploaded the new software tool CT-46 OTP to perform one-time pad encryption. The training tool takes a plaintext and one-time pad key, converts the plaintext into digits and calculates the ciphertext. The CT-46 checkerboard is used to convert the text into digits. The program contains instructions on how to use the pencil-and-paper version and the conversion table.

CT-46 OTP Training Tool (click to visit download page)

The software is meant for training purposes only, as we all know there's no such thing as a secure computer. The only secure computer is a stand-alone laptop, stored in a 100% burglar proof vault. It's useless to run a perfect crypto system, or any crypto software for that matter, on a normal computer, given the many viruses, trojans, spyware and countless unidentified processes. The software however is ideal to train your encryption skills. The only truly secure way to apply one-time pad encryption still is simply with pencil and paper.

More about one-time pads at my one-time pad page, including an extensive Guide To Secure Communications with One-time Pad (pdf). The freeware CT-46 Tool is available at my download page.

Sunday, August 07, 2005

Is One-Time Pad Encryption History?

I came across an article about one-time pads on Bruce Schneier's newsletter. He says that, although it's the only provably secure crypto system we know of, it has no future. He argues that one-time pads turn a message security problem into a just-as-difficult key distribution problem.

This is correct, assuming we don't want to be occupied with running around with briefcases, handcuffed to our wrist. And indeed, there is no need to go through all that trouble. We now have asymmetric public key algorithms, based on factoring large primes. They securely protect the message key of the symmetric encryption, used to encrypt the data. But there's a problem.

Although it has taken lots of time, defactoring (limited) primes is possible and already done. Imagine what would happen when someone finds a mathematical shortcut for the factoring problem, or a hardware solution, speeding up the process, as expected from quantum computers? Imagine a world where asymmetric encryption no longer resists against maths, or any symmetric cipher is brute forced within minutes?

One-time pads would be the only solution, although a very expensive one due to the key distribution problems. It's a bit like using Morse code on radio. Several armed forces abandoned Morse. Yes, it's stone-age technology, and one can say it's ridicules in these Megabit-rate days of data communication. And what do we see now... we start teaching Morse again to Army signal operators. When things go bad, Morse is the only system getting across, all others failing. So, I think we should never throw away those solid systems like one-time pads too fast.

One-time pad gained a reputation as a simple yet solid encryption system with an absolute security which is unmatched by today's modern crypto algorithms. Whatever technological progress may come in the future, one-time pad encryption is, and will remain, the only truly unbreakable system that provides real long-term message secrecy. Here's more detailed information about one-time pad.

Wednesday, December 10, 2014

WPS - The secret Numbers in Letters

We all have secrets. Some we keep and some we share. The secrets we keep are generally easily managed. Our brain is an excellent safe that holds numerous secrets that no one will ever know. The secrets we share are harder to keep. If we want to send them to others then we need to encrypt them.

However, sometimes we don't want anyone to know that we share a secret. When the secret becomes a secret, we need more than cryptography to send it. We need steganography, the art of hiding messages.

By using steganography (lit. hidden writing) we can send a message through any open insecure channel without others even knowing that a message was sent. It doesn't draw attention or suspicion, as an encrypted e-mail or letter would, and the hidden message is deniable.

In this age of non-existing digital privacy there is still a method of processing and sending messages that resists even the best hackers and "Men in Black" organizations: the pen and the paper. Just as there is unbreakable pen-and-paper encryption, there is also fully deniable steganography.

Many steganographic techniques were invented in past centuries. Drawings with embedded codes or signs, invisible ink, harmless looking text with minuscule typographic differences or grammatical alterations under control of some algorithm. Most of them, however, fail when it comes to hiding the fact that steganography has been used.

Typographic changes, how little they may be, are visible, since the receiver should be able to see them. Obviously, unusual font changes or extra spaces in digital text files are easily detected. Secret words, embedded at certain places, might be out of context. The required grammatical changes or rules, applied on cover text, often don't stand against the scrutiny of a human reader, as he can easily spot subtle but suspicious changes in natural language that don't fit in the content or style of the cover text.

Fully deniable steganography has some important requirements: it should be impossible to detect the use of steganography, as this would in essence be a failure. After all, its goal was to hide the fact that an encrypted message was sent. Also, any attempt to extract the hidden message should never reveal the message nor the use of steganography, even when the method is known. Therefore, the message should always be encrypted prior to hiding. Otherwise, any eavesdropper who knows the steganographic method could extract the plain message.

One method that meets these conditions is the Words-Per-Sentence system or WPS. It's a simple yet effective text-based method to conceal  a message without the use of complex mathematical or grammatical tricks and offers complete freedom of writing style and content. The system consist of three steps: converting text into digits, encrypt those digits and hide them in an innocent cover text.

Step 1 - Convert text into digits

This can be done by a straddling checkerboard. Such a table converts the high frequency letters into one-digit values and the other letters in two-digit values, producing a relatively economical conversion. 
 
Optionally, to compress the message considerably, you can use three or four-digit codes (preceded by 0 - CODE) that represent common words, expressions or even whole phrases, taken from a code book or sheet (more about code books in section VI of this paper (pdf).


Let's convert the phrase "meeting at 14 PM in NY." Note that we repeat figures three times to exclude errors.

M  E E T I N G     A T     1   4     P  M     I N    N Y  (.)
79 2 2 6 3 4 74 99 1 6 90 111 444 90 80 79 99 3 4 99 4 88 91

Step 2 - Encrypt the digits

The letter-to-digit conversion is no protection whatsoever! We could scramble the letters of the checkerboard, but this provides only very limited protection. So, we must encrypt the digits. There are various manual cipher systems, but the most secure one is the unbreakable one-time pad. More detailed info in this paper.

Suppose our truly random one-time pad key starts with the following groups:

68496 47757 10126 36660 25066 07418 79781 48209 28600

The one-time pad key is written out underneath the plaintext digits. The first group of the pad serves as key indicator for the receiver and must be skipped in the encryption process. The key is subtracted from left to right from the plaintext without borrowing (a so-called modulo 10 subtraction):

Plain : KEYID 79226 34749 91690 11144 49080 79993 49948 89191
OTP(-): 68496 47757 10126 36660 25066 07418 79781 48209 28600
        -----------------------------------------------------
Cipher: 68496 32579 24623 65030 96188 42672 00212 01749 61591

Step 3 - Hide the encrypted digits

Now that we have a secure message, we must hide the ciphertext digits in a text. For each digit, a sentence is composed with as many words as the digit + 5 (or any other pre-arranged value). Adding 5 to the total ensures that all sentences have at least five words. Words like “it’s”, “you’re” or “set-up” are regarded as one word. To avoid statistical bias, some sentences with less than 5 or more than 14 words should be added (these are later simply ignored). The first ciphertext group 68496 from our example message is hidden in the first part of a letter, shown here below:

Dear John,

I Hope everything is going well with you and the family. If possible, Katherine and I would love to visit you somewhere next month. We could make it a weekend at the lake. The next few weeks are rather quiet so any date is fine for us. What do you think? If you’re interested, just pick a date and I arrange everything.

To retrieve the original digits, the receiver simply subtracts 5 from the total number of words in each sentence, ignoring sentences with less than 5 or more than 14 words. He counts 11 words in the first sentence and thus knows that the first digit is 11 – 5 = 6, and so one. He writes the proper one-time pad key underneath the extracted digits (skipping the key indicator) and adds ciphertext and key together without carry (modulo 10 addition). Finally, he converts the plaintext digits back into readable text with his own checkerboard.

The advantages of WPS are an excellent literary freedom and the lack of complex calculations or algorithms. Always start by writing a meaningful text and then play with the words to obtain the required sentence length. Exclude the salutation in a letter from the system, as a nine-letter salutation would obviously arouse suspicion.

Thanks to WPS, the hidden message is fully deniable. There is no way to ever prove the existence of a message inside the innocent looking letter without having the proper one-time pad key. Even when the eavesdropper knows the method used, he can merely extract some meaningless digits, as he would retrieve from any other "clean" text. We now have a safe method to send encrypted messages openly by postal mail, e-mail or Internet forums.

Or how you can hide numbers in letters ;-)

This pen and paper WPS system is an important advantage in today's digital world where secure  personal computers, smartphones or tablets are a fairytale and virtually all means to communicate are prone to eavesdropping. Of course, the cover text itself can be read by anyone and you will need a good excuse for the nonsense you wrote and to whom you wrote it. It's better to write a meaningfull text and story based on facts.

Further reading:

Thursday, October 12, 2017

DIANA - A Fast Reciprocal One Time Pad Table

There are various ways to perform one-time pad encryption with letter pads. The Vigenére table is a well known method to combine (e.i. encrypt) plain and key text into cipher text and vice versa. However, Vigenére has some serious drawbacks. It is cumbersome, time consuming and finding the cross section between letter and key is prone to mistakes. Also, key and cipher text must be processed in the same order by both sender and receiver.

A way faster and easier system is the reciprocal DIANA table. For each column letter there is a normal alphabet and a reversed alphabet. For each column, the reversed alphabet is shifted one position against the previous reversed alphabet and the table is statistically secure (1/26 chance to produce any cipher letter). Such reciprocal tables come in various formats but they all use the same principle. Note that this table is not compatible with the Vigenére table.

Thanks to its reciprocal properties, encryption and decryption are identical and require only a single column. The order of plain, key and cipher letter don't matter and may even differ for sender and receiver. The table is easy to use and it's virtually impossible to make a mistake.

The DIANA Reciprocal One-time Pad Table (download text file format)

To encrypt, we either write plaintext under key or key underneath plaintext. The choice is yours. For each combination of key and plain letter we take the table column that corresponds to the first letter and search underneath it for the second letter on the left. The lower-case letter to its right is the result.

In the example below we wrote the plaintext above the key. To encrypt T with X, find column T in the table, go downward to letter X and find cipher letter j at its right. Thanks to the reciprocal system it doesn't matter whether you combine T with X or X with T. Quite handy!
Plaintext : T H I S   I S   T H E  S E C R E T
OTP-Key   : X V H E   U W   G T P  N O P G D Z 
----------------------------------------------
Ciphertext: J X K D   X L   A Z G  U H I C S H

In groups : JXKDX LAZGU HICSH
To decrypt, take column X, go downward to J and find plain letter t at its right. Again, the order of key and cipher letter don't matter. The beauty of this system is the ease and speed of finding plain and cipher letters in whatever order you like best.

There is also a method to memorise the DIANA table and speed up the process even more. When encrypting F + G = O, we can decrypt this as O + G = F, but also as G + O = F. We call this the trigram combination FGO. Because of the reciprocal property, we can use the trigram FGO for any possible combination, that is, FGO, FOG, OFG, OGF, GFO and GOF.

Thus, if you encrypt or decrypt any letter from a trigram with another letter from that trigram you will always get the remaining letter of that trigram, regardless of the order. We therefore only need to remember the trigram FGO and instantly know every variation of the trigram. This reduces the number of combinations to memorise from 676 to 126. FGO can easily be remembered as the word "FOG".

Any user can create his list of mnemonics by memorising the 126 possible trigrams in any desired order. Some other examples are TAG (derived from AGT), BAY (derived from ABY), AIR (as itself), FDR (Franklin D Roosevelt, derived from DFR), HRB (HR Bureau), NNZ (Northern New Zealand), AMN (A-Mu-Nition), BGS (Better Get Smart), MBM (My Best Mate), JTX (Jump The Ex), VHX (Very Hot Ex), WXG (Wild X-Games) or OXO (the game). Tickle your imagination to find your own.

Everyone has his own connotations to easily remember the trigrams. Well trained operators can encrypt and decrypt on-the-fly at high speed without using any table, which is sheer impossible with Vigenére's 676 bigram combinations.

The full list of trigrams (download list in txt format) in alphabetic order to be memorised as any desired combination, e.g. ABY is also AYB, BAY, BYA, YAB and YBA.

AAZ ABY ACX ADW AEV AFU AGT AHS AIR AJQ 
AKP ALO AMN BBX BCW BDV BEU BFT BGS BHR
BIQ BJP BKO BLN BMM BZZ CCV CDU CET CFS
CGR CHQ CIP CJO CKN CLM CYZ DDT DES DFR
DGQ DHP DIO DJN DKM DLL DXZ DYY EER EFQ
EGP EHO EIN EJM EKL EWZ EXY FFP FGO FHN
FIM FJL FKK FVZ FWY FXX GGN GHM GIL GJK
GUZ GVY GWX HHL HIK HJJ HTZ HUY HVX HWW
IIJ ISZ ITY IUX IVW JRZ JSY JTX JUW JVV
KQZ KRY KSX KTW KUV LPZ LQY LRX LSW LTV
LUU MOZ MPY MQX MRW MSV MTU NNZ NOY NPX
NQW NRV NSU NTT OOX OPW OQV ORU OST PPV
PQU PRT PSS QQT QRS RRR


With one-time letter pads, punctuations and figures in the plaintext are usually spelled out. However, to limit the message length you generally omit punctuations where it doesn't affect readability. Alternatively, you could use rare letter combinations as a prefix to convert figures or punctuations into letters, for instance QQ or XX.

In that case XXF could be used to switch to figures and XXL to switch to letters, with ABCDEFGHIJ representing the digits 1234567890. Thus, 2581 would become XXFBEHAXXL or XXFBBEEHHAAXXL to exclude errors, which is more economical than having to write out 2581 in letters. XXP could be a period, XXK a comma and XXS a slant. XXC could be Code, a prefix for three or four-letter codes to replace long words or sentences, like XXCABC, where ABC represents “Request further information” or "My location is..."

And the best of all, one-time pad encrypted messages are absolutely unbreakable if the one-time pads are used once only (hence one-time) and destroyed immediately after use. Of course, the letters should be truly random (no algorithm based pseudo-random) and generated either by hardware or a dedicated computer, never connected to the Internet, and printed on a dedicated printer.
 
More technical and historical information about various one-time letter pads and one-time figure pads at Cipher Machines and Cryptology.

Saturday, January 09, 2010

VENONA Declassified

The National Security Agency's Center for Cryptologic History published a large number of documents about the VENONA project on its Declassification Initiatives section. The VENONA story is a summary of the Intelligence, derived from deciphered VENONA messages, and explains how the codebreakers succeeded in deciphering these important messages.

The top secret VENONA project was initiated in 1943 by the U.S. Army Signal Intelligence Service in Arlington Hall, Virginia, and was continued by its successor, the NSA, until 1980. What started as an attempt to exploit and decipher Soviet diplomatic and trade communications would soon become a vital source of information about Soviet Intelligence operations in the United States. Analysts discovered that portions of the encrypted Soviet diplomatic communications contained espionage related information.

Miniature one-time pad
Richard Hallock, Cecil Phillips and Meredith Gardner were the key players in the VENONA decryption efforts. Analysis identified five different ciphering systems on the diplomatic traffic. The messages were encoded into digits with the aid of different sets of codebooks and additionally enciphered with so-called one-time pads (see image right). These one-time pads, containing series of truly random numbers, are added to the message digits. A one-time pad provides mathematically unbreakable encryption, if used only once.

However, the codebreakers discovered that the Soviets mistakenly reused a small portion of these pads. Time pressure and tactical circumstances during the Second World War lead in some cases to the distribution of more than two copies of certain keys. Although VENONA is often referred to as the project that broke Soviet one-time pads, they never actually broke one-time pads, but exploited a most fatal implementation error: you should never ever reuse a one-time pad.

Nonetheless, the codebreakers faced an enormous challenge. Due to the vast quantity of intercepted messages, the few reused pads and the lack of Soviet codebooks they had to decipher and reconstruct the messages and codebooks painstakenly, piece by piece, solely relying on cryptanalysis. It took 37 years before they closed project VENONA.

From 1946 on, they began to read portions of KGB (Soviet Security Service) messages that had been sent between the KGB station (rezidentura) in New York and Moscow Center. The derived Intelligence was sensational. When VENONA ended, around 3,000 messages (only a fraction of the intercepted traffic) were partially or completely deciphered. These were mostly communications between the KGB's First Chief Directorate (Foreign Intelligence) and its KGB Station Chiefs.

The messages revealed critical information on KGB and GRU (Military Intelligence) operations in the United States and Great Britain, and the KGB's role in the Soviet consulates, the TASS news agency, COMINTERN and the AMTORG Trading Corporation. The decrypts disclosed massive espionage efforts against the U.S. Departments of State and Justice, the Department of the Treasury, the Office of Strategic Services (OSS), and the War Department.

Kim Philby
Information, derived from VENONA, identified many Soviet Intelligence operations, hundreds of Soviet agents and people who collaborated with the Soviets. This enabled the arrest of major Soviet spies such as Klaus Fuchs and Harry Gold (MANHATTAN Project and A-Bomb), the Rosenberg's spy ring, and the identification of Donald Maclean, which lead to the unmasking of "Cambridge Five" members Kim Philby and Guy Burgess.

Because of its importance, and the difficulty to decipher and identify the covernames and codenames in the messages, the VENONA project lasted until 1980, providing the FBI and CIA over the years with vital counter-intelligence information to solve many spy cases. VENONA is a good example of "we will get you, sooner or later", as many spies were arrest upto decades after they stopped spying.

The VENONA story (pdf), many of its deciphered messages and other related documents are found on NSA's VENONA project page. Another very good reference is The Secret Sentry, recently declassified by The National Security Archive. It contains the extensive 66 page VENONA document (alt. link) and other previously top secret documents, related to the Korean war and Vietnam.

Update: A great tip from Mark Stout is the VENONA Names Cross Reference, created by John Taber. It comprises an index of names and identifications, and an index of names to decrypts, both as Excel files. A very extensive work that links thousands of files, names and locations from the VENONA decrypts.

Saturday, June 28, 2008

Secret Splitting

An interesting way to use one-time pad encryption is Secret Splitting. We all know what sharing a secret is (people tend to have problems not to share secrets). The opposite of sharing secrets is to split them.

Suppose Charlie has a secret password or a safe combination he wants to share with someone in case of emergency. Wouldn't it be great if he could split his secret and give one share to Alice and one share to Bob? The secret could only be retrieved when both Alice and Bob agree on sharing their secret. Of course, cutting it simply in two and give each person half the secret would reveal already that part, so that would not be safe.

Well, there's a simple solution and it's called one-time pad. Secret Splitting is a special way of using one-time pad, since you don't send a secret message, and the key isn't destroyed. Here's how it goes: Charlie subtracts a truly random key, digit by digit, modulo 10 (without borrowing), from his safe combination. For instance, 4 - 6 = 8 because [1]4 - 6 = 8. He gives one share (they key) to Alice and one share (the result) to Bob.

Charlie's Combination      21 46 03 88
Random key (first share) - 25 01 77 61
                           -----------
Results (second share)     06 45 36 27

Alice's share = 2501 7761
Bob's share   = 0645 3627


To retrieve the original combination, Alice and Bob just add their keys together, again modulo 10 (without carry). For instance 7 + 6 = 3 because 7 + 6 = [1]3. Of course, one could also split text by first converting the letters into digits (f.i. A=01, B=02 and so on through Z=26). You can download a practical Secure Code Splitter (pdf) template that supports up to 4 shares of 10 digits.

It's mathematically impossible to retrieve the secret information without having all shares, under the condition that the random share contains truly random digits, and all shares are physically and securely separated.

There are some interesting applications for this system. It's a secure method to give a code or password in the custody of multiple persons when you're abroad. Each person receives a share. All persons involved have to agree to combine their shares to retrieve the code or password. But if you want to have the final decision to disclose your secret code, there's another solutions.

You can create two shares, take one with you on a business trip and give the second share to a trustee from your company. In case of emergency, you can sent your share by open e-mail or telephone to the trustee. Combined with his own share, he can retrieve the secret code and open your safe or whatever. Because the share and result share are trule random, sending one of the shares by insecure channel will never disclose the secret code, as long as both share are never disclosed simultaneously.
 
It's also a clever way to share things with people who don't trust each other. Suppose grandpa, old and sick, splits the secret combination of a safe that contains his savings and gives each of his children one share of that secret. They can only get their hands on his money if they all agree (not that this will make grandpa live longer).

Of course, after using the shares, you should always set a new secret code or password to your safe and create a completely new set of shares to avoid unauthorised use of the old combination.

More about Secret Splitting and one-time pad on my Secret Splitting page.

Update: a new version of the Secure Code Splitter is available. More information at this blog post.

Friday, April 03, 2009

Crypto Machines with One-time Keys

BID-590 NOREEN OTT
In my previous post I already mentioned the ETCRRM, a device to encrypt teletype signals with one-time tapes (OTT). Systems that use the principle of one-time key encryption were very popular until the 1980's, because of their absolute security. Most of these machines encrypted five-bit teletype signals by mixing (Exclusive Or function - XOR ) the plain signal with a one-time key tape. Each OTT consisted of truly random five-bit values and there were only two copies of each tape, one for both ends of the teletype link. Each tape was to be used only once, and destroyed after used.

Of course, the OTT method required a complex logistical support to securely distribute large amounts of OTT's. That could only be supported by government departments such as the military, intelligence services and diplomacy. As you can imagine, an enormous amount of OTT's travelled around the world by courier or in diplomatic bags, since you needed as much OTT's as there were message to be send.

A five bit teletype punched paper tape. Can you read it?

Although a pretty old system, developed by Gilbert Vernam in 1917, its unbreakable encryption kept it popular until sophisticated electronic crypto machines and modern computer algorithms provided enough security. Nevertheless, some electronic or software one-time key systems still exist for special purposes where absolute secrecy has priority.

Some of the OTT ciphering machines are the American TELEKRYPTON, B-2 PYTHON, SIGTOT and SIGSALY (which used one-time noise), the British BID-590 NOREEN and 5-UCO, the Canadian ROCKEX, the Dutch ECOLEX series, the Swiss Hagelin CD-57, CX-52 and T-55 with superencipherment, the German Siemens T-37-ICA and M-190, the East-German and T-304 LEGUAN, the Czech SD1, the Russian M-100 SMARAGD and M-105 N AGAT, and the Polish T-352/T-353 DUDEK, and of course, the Norwegian ETCRRM, famous from the Washington/Moscow hotline. I'm sure I forgot many more, any suggestions are welcome.

Apart from being unbreakable, OTT systems were quite simple and did not have any secret crypto technology aboard, as mixing one-time keys with plain text is a commonly known basic method of encryption. Whereas other encryption machines were considered as listed secret crypto equipment, OTT devices were mostly unclassified. Only the OTT's themselves were considered secret material. More about one-time pad on my website.

Thursday, November 24, 2016

Operation Vula's Secure Communications

Operation Vula was the creation of an underground ANC leadership with supporting secure communications network in South Africa to fight against the apartheid regime. The operation ran from 1988 to 1991 and is also the fascinating story of Tim Jenkin, who played a key role in providing secure communications.

Going Underground

Tim Jenkin today
Tim Jenkin came into contact with the anti-apartheid movement when he visited the African National Congress (ANC) office in London. He was eager to support the fight against apartheid. Jenkin was trained in covert operations and returned to South Africa where he and his good friend Stephen Lee started underground work for ANC in 1975.

They ran a propaganda shop but got arrested in 1978 and were sentence to respectively 12 and 8 years imprisonment. Amazingly, they escaped 18 months later from a Pretoria high security prison with keys that Jenkin made out of wood. This gives you an idea of how creative he was. Jenkin left South Africa and made his way to the ANC office in London where he became a trainer for underground operatives.

ANC Going Blind in Exile

The ANC leadership had fled to Lusaka in Zambia after many of their leaders and members were jailed or tortured. This left the ANC with no representatives in South Africa. Among the exiled members were ANC president Oliver Tambo, commander of the military wing (MK) Siphiwe Nyanda and ANC strategist Mac Maharaj, whose mission was to revive the freedom movement and ignite revolution in South Africa.

This proved to be a mission impossible because of the problems to communicate and coordinate with the few ANC members that were still in South Africa. In the mid 1980s, communications between London, Lusaka and operatives in South Africa were still protected by manual one-time pad encryption that was too cumbersome for long reports that took many hours up to days to encrypt by hand.

Oliver Tambo tasked Siphiwe Nyanda to join MK's Chief of Staff Joe Slovo in starting up Operation Vula. The goal of this extensive operation was to set up a secure covert communications network and to smuggle ANC leaders and weapons into South Africa to install a leadership that would take over command of the underground work. This is where Tim Jenkin comes into play.

Jenkin met Mac Haharaj while training ANC agents on radio communications in Lusaka. Haharaj asked him to set up secure communications between covert operatives in South Africa and the ANC office in London. At that time, Jenkin was experimenting with computer communications.

Establishing Secure Communications

Personal computers were quite a novelty in the 1980s but handyman Jenkin developed one-time pad encryption software that used floppy disks, filled with random data, to serve as key. During encryption, used key bytes were automatically wiped from the disk, making the system unbreakable. The software also increased encryption speed for Vula messages considerably, compared to the slow pen-and-paper system.

Jenkin's office in London, nicknamed GCHQ (after the British Signals Intelligence organisation) served as the main Vula communications hub for messages between London, Lusaka and South Africa. In his computer shack he developed, tested and ran secure communications to cope with the increasing amount of reports from and to the ANC underground leadership.

Tim Jenkin in his communications hub

Jenkin devised a system to convert encrypted message digits into DTMF (dual-tone multi-frequency) telephone dial tones that were then recorded onto cassette tapes for transmission by pay phone later one. They provided ANC operatives with several DTMF tone generators that were disguised as electronic calculators. Later on, they dropped the method of manually keying in the DTMF tones and drastically increased communication speed by  recording the computer modem sound directly to tape.

Setting Up the Network

Conny Braam, a Dutch anti-apartheid activist, became responsible for the Vula logistics. She ran a network of people that supported the entire operation. First task was to get the network running. She had to find someone to travel several times a month between Amsterdam and Johannesburg. Air hostess Antoinette Vogelsang volunteered as courier. Being an air hostess, she didn't had to go through airport checks and could safely smuggle into South Africa the Toshiba laptops and software that secured the network. She also provided the communication hubs with a regular supply of floppy disks, containing new one-time pad keys.

The Dutch Lucia Raadschelders was sent to Lusaka to run a communications hub from a small house in the slums. She also served as contact between Jenkin and ANC headquarters in Lusaka. Janet Love, the ANC underground operative in Johannesburg switched from the slow manual one-time pad encryption to its fast computerised version. Everything was finally up and running. In 1988, Mac Maharaj and Siphiwe Nyanda  were the first Vula leaders to clandestinely infiltrated into South Africa.

Meanwhile, Janet Love's communications hub in Johannesburg was also operational. Tim Jenkin received the first long reports from Mac Maharaj a few weeks later. ANC's freedom movement finally was able to communicate securely with Jenkin's London office as central hub. From then on, Janet Love encrypted all Johannesburg messages and recorded the computer modem sound on cassette tape.

From South Africa over London to Mandela

The operative in South Africa chose a random pay phone to call an answering machine in London and played back the tape with the message that he had encrypted and recorded earlier. The London office checked the message and called the operative's pager with a specific code to signal that the message had arrived well. London then relayed this message to, for instance, ANC headquarters in Lusaka.

The London office also used a specific pager code to warn operatives in South Africa that there were messages for them to receive. To retrieve a message, the operative again chose a random pay phone and called another answering machine in London on which the London HQ had recorded an encrypted message from Lusaka or from other operatives.

From the manual encryption of long reports, taking many hours to encrypt and days to get across, they now were able to get a message to London in one or two hours. Jenkin relayed the messages almost real-time back and forth between the ANC headquarter in Lusaka and the operatives in South Africa. The South African security services could not track these messages as they were sent anonymously from randomly chosen pay phones. It would require them to monitor each and every pay phone and even if they managed to intercept such a message, it would merely contain what seemed like unintelligible fax or computer tones, giving them no clue about their purpose.

Mac Maharaj succeeded in setting up covert communications with the imprisoned Nelson Mandela through his lawyers. By then, the South African government held secret talks with Mandela, who they believed to be clueless about the situation in the country. Little did they know that Mandela was in direct contact with ANC president Oliver Tambo and a well organised underground leadership. In fact, without realising it, the apartheid regime was negotiating directly with the ANC. When Nelson Mandela was released from prison in February 1990, the Vula operation continued underground to protect the actual leadership and its communications with Mandela.

Caught But Mission Accomplished

The operation was eventually compromised in July 1990 after the police followed Siphiwe Nyanda and discovered encryption disks and plain messages in a Vula hide-out. Mac Maharaj, Siphiwe Nyanda and six other Vula members were arrested and imprisoned. Others fled the country or went into hiding. Despite this setback, Tim Jenkin was able to reboot the Vula network within 24 hours. All Vula members eventually received amnesty as part of the political transition that lead to the end of apartheid.

Tim Jenkin's story is an amazing example of people with no background in intelligence, espionage tradecraft or secure communications who used their creativity to set up an ingenious international secure network that changed South Africa's history. It should be noted that their communications system, which was quite novel and therefore secure in the 1980s, would pose serious risks in today's world with advanced signals intelligence capabilities, ranging from hacking computers to extensive electonic surveillance and geolocation.

Tim Jenkin's story of operation Vula is published at the Nelson Mandela Centre of Memory. More details about the encryption systems and equipment at the web page How the ANC sent encrypted messages. Also listen to a podcast with Anti-Apartheidsactiviste Conny Braam  (only in Dutch) and visit Conny Braam's website with here bio and books.

Below an excellent eNCA documentary about operation Vula and a NGC documentary of Tim Jenkin's escape from Pretoria prison.



Monday, October 10, 2016

Jack Barsky's KGB Radiograms and Family Tales

Commercial SW radio. A Spy's
favourite tool to receive messages
Jack Barsky's espionage career was a quite remarkable one with a surprising ending. Barsky was born as Albrecht Dittrich in East Germany. He was scouted by the Stasi, recruited and trained by the KGB and sent to the United States as a so-called illegal under the false identity of Jack Barsky.

In contrast to intelligence officers that operate under official cover (often pretending to be embassy personnel), illegals do not enjoy diplomatic protection if they are caught. They usually stay low-profile and only have contact to their agency through their handler, a career intelligence officer. Illegals are often regarded as the elite of spies but their live, although quite risky, is usually all but glamorous or exciting.

Barsky's spying career lasted from 1978 until 1988, when his cover was blown. He refused KGB orders to return to East Germany, where he had a wife and son, and chose to stay with his American wife and daughter. Amazingly, the KGB bought his excuse that he had contracted AIDS and allowed him his final years in the United States.

Eventually, the FBI tracked him down thanks to information from the vast collection of documents that KGB archivist Vasili Mitrokhin smuggled out of the Russia in 1992. Barsky, already inactive for several years, decided to cooperate with the FBI. He was extensively debriefed on KGB spy techniques and in return has never been indicted or put on trial.

Illegal agent's one-time pad
booklet and microdot reader
Source: CSIS
Jack Barsky is one more source that confirmed the use of one-way shortwave communications by intelligence organisations, known as numbers stations. Every Thursday evening Barsky tuned his shortwave radio to a predetermined frequency and listened for a so-called radiogram from the KGB. Barsky believes that his radiograms were broadcast from Cuba. His radiograms contained operational instructions that were encrypted into digits and sent in groups of five.

His radiograms could take an hour to receive and write down and up to three hours to decrypt. Anyone could hear the message, you had no idea who was actually listening and no one could decrypt or read it. When encrypted with a one-time pad, this pen-and-paper system is proven unbreakable.

The Americans: fiction and
real-life spy stories interwoven
Watch Jack Barsky's interview at TAG Cyber Media in which talks about the radiograms. In Podcast Nuggets Episode 7 there's a two-part interview with Jack at Cold War Conversations.

The Guardian also has a long article on Barsky. An excellent Spiegel TV documentary follows Jack Barsky in 2014 on his first trip into Germany in 30 years, as he explains how he became a KGB spy. The actual life of Jack Barsky as an illegal may not be that spectacular and full of action, compared to Phillip and Elizabeth Jennings in The Americans, but the work of illegals can take quite a toll on their personal life.

Donald Heithfield and Tracy Foley lived a seemingly ordinary life with their two sons Tim and Alex until their house was raided by the FBI in 2010. To their children's surprise, Donald and Tracy, whose real names were Andrei Bezrukov and Elena Vavilova, turned out to be members of a Russian spy ring in the United States, controlled by the illegals department of the SVR, the Russian Foreign Intelligence Service. Eventually, Canadian born Tim and Alex were deported with their parents to Russia in one of the biggest spy swaps ever. Their life as they knew it ended instantly. They received Russian passports and had to build a whole new life. The fascinating story of Tim and Alex was published last May in The Guardian and on McLean's you can read about their struggle to return Canada and their fight in court.

Andreas and Heidrun Anschlag, the spy couple arrested in German in 2011, also had a grown up daughter. Her life was undoubtedly also turned upside down by the spying career of her parents. But spies are not the only ones to pay a high personal price. The wives and children of defectors often suffered the same consequences.

When Igor Gouzenko, a GRU officer (military intelligence) and cipher clerk at the Soviet embassy to Canada decided to defect, taking along most sensitive intelligence documents, this also changed the life of his wife and child dramatically. The interview with his wife and the story of his daughter who, as a child, never knew that her father was not the man she believed him to be, are striking examples of the price for living a fabricated live. Remember, think twice before you start a spy career when you're a family man!

Further reading: numbers stations, one-time pad and Cold War signals.