Showing posts with label locksporting. Show all posts
Showing posts with label locksporting. Show all posts

Thursday, November 29, 2018

Charles Babbage: Codebreaker

Few names stand out in the history of computing as do Charles Babbage and his Difference Engine. The Difference Engine was only a demonstration model in his lifetime. Larger more complete engines have been built in our time by museums. He also proposed a more complex and sophisticated Analytical Engine, again, never built at all in his own time but constructed in our time by museums from his plans. You may also know about his work with Lady Ada Augusta Lovelace. The daughter of George Gordon, Lord Byron, she was arguably the first computer programmer. What you may not know is that among Babbage’s hobbies were cryptology and lock picking. He said that lock picking and cryptology were very similar pursuits intellectually. 

(This is based on a presentation to the Austin OWASP Crypto Party held at National Instruments Bldg. C, January 23, 2018.)

At this time – we are talking the middle third of the 19thcentury, say 1823 to 1868—codes and ciphers were all the rage. In America, Edgar Allen Poe’s “The Gold-Bug” laid bare for public consumption the means for breaking any mono-alphabetic substitution cipher. 

Newspapers ran columns known as “Miseries.” They were Lonely Hearts messages by which lovers set up rendezvous, and they typically relied on some kind of encryption, most often single alphabet substitutions, sometimes transpositions. 
This is where Babbage comes in and wherein lies some mystery about his work. The polyalphabetic cipher goes back to the late Renaissance. We call them Vigenere ciphers. They are commonly attributed to Blaise de Vigene in the year 1585. However, the first publication can be attributed to Gian Battista Belaso in 1553. In fact, the means of breaking monoalphabetic ciphers also goes back to this time, but was not widely known outside of the black chambers of governments.

This is a 26x26 Vigenere Table. German with its umlauts would have 29 letters. Greek would have 24 letters. You encipher your message down the rows, the 13th letter being encrypted against the 13th row.

As you can see, the two Es are enciphered differently. The consecutive Rs in MARRY are enciphered to different outputs.

The man sees the end of the line.
The most common letter in English is E. The most common trigraph is THE. As you can see, the letters E all are encrypted differently. The three instances of THE have different outputs. It is for this reason that for 300 years, the Vigenere cipher was called the indecipherable cipher. It could not be broken.


But there was a war on.  The Crimean War saw Russia pitted against the UK, France, and the Ottoman Empire. Secret codes were essential to military communication. 

Enter Babbage.

First of all, Babbage promised but never published his treatise on cryptanalysis. That was unusual because he had an ego big enough to fill this room. Babbage was one of a handful of liberal scientists who purposely and purposefully restructured their society. Among them were Lady Ada Augusta Lovelace and Charles Darwin, William Herschel, and William Whewell. It was Whewell who coined the word scientist in an ad hoc debate with the poet Samuel Taylor Coleridge at the first meeting of the British Association for the Advancement of Science on June 24, 1833. 

Several scholars today theorize that Babbage was working for the War Department. So, he did publish some insights and suggestions in his autobiography of 1864. But he never let the cat out of the bag.

Babbage created a massive set of dictionaries of the English language organized by word length and then sorted by initial letters and then printed up by their second letters. He made tables of common digraphs and trigraphs. He listed all of the words with repeated letters. He could do this because he was independently wealthy, having inherited from his father an estate valued at £100,000, call it $50 million in our money. All of that just prepared his mind to attack the unbreakable cipher, which he did.

Not Babbage but a hacker at DefCon 512
Like all codebreakers, Babbage attacked the human element. We say in hacking that amateurs target systems while professionals target people. Babbage’s study of language and cryptography opened the door … and we do not know for sure just what door that was. He kept it secret. But he did mention it in passing in his autobiography. As big as his ego was, he was a man of his word. He meant what he said and proved it with mathematics. He held the same Lucasian Chair at Cambridge as Sir Isaac Newton.

The way the Vigenere worked in practice is that each agent, each minister or other user would be given a word, preferably a long word, and ideally with no repeating letters.

In the example above…

The message was I LOVE YOU. MARRY ME and the key word was UNPREDICTABLY which gave us 13 different ciphers. However, the longer the message the more likely that you will cycle through the key and eventually encipher the same words or at least the same letters with the same keys. 

Babbage figured out that you do not need to find the key of you can find the length of the key.
 
 “It may have been as efficacious as it is formidable,
but neither an index to its symbolism,
nor any clue to its purpose exist.” 
– 

David Kahn, The Codebreakers, Chapter 6,
“The Contributions of the Dilettantes,” pg. 207
Babbage had a lifelong interest in cryptology and cryptanalysis. He and his friends William Whelwell and William Herschel among other savants of the day all dabbled in it. Babbage and his nephew exchanged challenges, which Charles Babbage deconstructed to its table based on the word SOMERSET by guessing that it began with DEAR UNCLE and ended with NEPHEW HENRY. That was in 1846. Babbage later took apart another small Vigenere that a dentist, John Thwaite, was attempting to get patented in 1854, shortly after the start of the Crimean War. Babbage broke that cipher, and though he promised to publish fully, he never did.
Passages from The Life of a Philosopher
Edited autobiography of Charles Babbage
Unfortunately, all we have is tantalizing scraps from his personal notes and notebooks. He never published a definitive treatise.


I read through about a dozen books – 14 in all, I think – by and about Babbage. You can get lost in his work. Because of his wealth and station, he was involved in almost every aspect of this revolutionary time from the most advanced mathematics to the most advanced manufacturing. Of all those books, The Philosophical Breakfast Club by Laura J. Snyder (Broadway Books, 2011) is the one volume that I recommend as the best overview. 

PREVIOUSLY ON NECESSARY FACTS


Saturday, April 2, 2016

BSides Austin 2016

The seventh annual BSides Austin computer security conference ran March 31-April 1, 2016. I served as a Host for breakout sessions, introducing speakers, and keeping track of time. It was an overflow crowd of 350 with 150 turned away at the door, or denied a slot on the wait list. In addition, several student groups could not be accommodated at all. 
 
Breakfast with the Sponsors.
We had two tracks on Thursday and three on Friday. You can find the full schedule on the conference website here.  Many of the sessions were easy to label. “I am a Software Developer. What do you mean I’m on the Blue Team?” by Aaron Poffenberger was clearly for the Blue Team. “It’s not About the Technology. It is About the Psychology” by Dr. Hend Ezzeddine and Flora Moon was easy to label for Social Engineering.
 
32 Formal Technical Sessions
The first night also included open mike
"Fire Marshall Talks"
But many others crossed several lines on the corporate org chart, and the sessions were not narrowly defined. You had to pick your presentations. That said, all of the hands-on workshops were held in the same room on the same day.
 
Rapper "Dual Core"
Each track had a Host and a room Monitor.  The monitors counted the room three times (beginning, middle, end) and interfaced with the hotel staff when needed.
 
Waiting for the Keynote by Ed Skoudis from SANS.
The convention would have cost ten times as much to attend were it not for the sponsors. 
Digital Defense, Rapid 7, SANS, and Splunk were gold sponsors this year. 
The silver sponsors were RSA, Log-MD, ISSA, Pluralsight, Checkmarx,
Anomali, and Netskope.
The five core sponsors were Velocitystorm, Expressworks,
Fusion-X (thanks for the beer!),
No Starch Press, and Pentester Academy.
As a technical writer, my interests are more general. I am seldom held accountable for information security, except as we all are. These were among my take-aways:
  • The best lockpicking tools for the money are the Sparrow Tuxedo ($40) and the Tremendous Twelve by Toools from Southern Specialties ($30). 
  • The best locks are biaxials from Medeco and the Schlage Primus. You can spend $75 for one of these and secure your servers, or you can buy a dozen others at $5.95 each and let us all have access to your servers.
  • For a knowledge worker your credibility is your product. 
  • The highest priorities for information security should be Asset and Inventory Management, Decision and Remediation Workflows, and Visualization and Metrics. The lowest priorities are vulnerability assessment and scanning, penetration testing, and buying cool tools. 
  • Work the OWASP Top Ten vulnerabilities. 
  • Amateurs target systems. Professionals target people. 
  • Security will not be accepted until and unless IT is made personal: it is you in your home who will be violated by your release of company information at work.

Basic security
They call it “BSides” in honor of the old rock ‘n’ roll 45 rpm single releases of the 1950s and 60s. The producer picked a hit for Side A and put something else (usually mediocre) on Side B. Elvis Presley’s “Don’t Be Cruel” was an exception. The Beatles releases were all exceptions.
Presentations crossed organization lines
The concept began in the US in 2009 with Mike Dahn, Jack Daniel, and some others because the CFP [Capture the Flag: computer intrusion challenge – MEM] for Black Hat Vegas or DEF CON was oversubscribed and those unable to present decided to hold their own conference on the 'b side'. -- https://en.wikipedia.org/wiki/BSides

PREVIOUSLY ON NECESSARY FACTS


Saturday, May 21, 2011

Locksporting

Opening locks without keys is one of the challenges historically associated with computer hacking, like gaming and Chinese food, chronicled in Steven Levy's classic, Hackers: Heroes of the Computer Revolution (Anchor Doubleday, 1984;O'Reilley 2010;  but available all over the Internet as a PDF).  So, it is fitting that at the SUMIT_2010 Conference (Security @ the University of Michigan IT, October 7, 2010), Deviant Ollam of The Core Group was again a guest speaker.  Sandwiched between techies Whitfield Diffie and Christopher Hoff, and government agents Melissa Hathaway and Marcus J. Ranum, Deviant Ollum was a hit with the crowd.  After his talk, outside the auditorium, he set up a corral of tables with locks and tools for people to play with; and he answered questions for about an hour.

His on-stage demonstration was fascinating, compelling, shocking, and revealing.  We throw shackles on our cages of servers, buying them at hardware stores and big box stores, and never considering how vulnerable they leave us.  It is pretty easy for someone to let themself into your racks, insert or copy what they want and then leave without a trace.  Or almost without a trace.  Deviant Ollam's presentation included forensics, showing the evidence of tampering.  But you have to know what you are looking for and looking at.
"Physical security is an oft-overlooked component of data and system security in the technology world. While frequently forgotten, it is no less critical than timely patches, appropriate password policies, and proper user permissions. You can have the most hardened servers and network but that doesn’t make the slightest difference if someone can gain direct access to your network equipment and server racks."  - Deviant Ollam, The CORE Group. "The Four Types of Lock: Physical Security is Data Security."
Shortly after that October 7, 2010, conference, I got interested in the problem of archiving and reporting on modern paper money (here on Necessary Facts).  I made a presentation about that at ArbSec, a local Ann Arbor computer security group that grew out of the DefCon734 chapter here.  Via ArbSec, I met A2 Locksporting, the lockpicking club.  Attending club meetings once a month, I learned how to pick a lock. 


Numismatists study all forms of money.
The threat of counterfeiting led governments to make their notes more secure.
It also led the USA government in Washington to install software,
firmware, and hardware on all personal computer scanners.
If you scan a current-issue Federal Reserve Note, they will know about it.
The EURion Project here on NecessaryFacts.

I also learned how to take a lock apart and put it back together, how to match a lock to its key, and other techniques.  It so happened that because of the Levy book - which I read when it came out, having hacked my first password in 1977 - I always kept keys. I have lots of them.  They can be useful.  You can make a lock "bump" with a old key.  An old key can be recut.  It might work on its own: locks are disappointingly generic.  If you only care about keeping out honest people, you can save money, time and grief, by paying attention to the codes on the locks, buying four or five identical ones at the same time. 

If you browse for lockpicking tools, you will find many sellers.  The Ann Arbor Locksporting Club seems to like Lockpicker's Mall. I like their website. From 2004-2010, I reviewed websites for the American Numismatic Association and I learned to look for reliable information, free articles, and open and honest statement of who owns the site and the company and where to find them in real life.  They meet those requirements. 

Core of Lock disassembled.
ALSO ON NECESSARY FACTS