Hello guys and girls of Avalon!
I apologize for making so many posts today!
Needless to say, some of us caught some of that incoming solar flare energy!!
This is a complete noob's attempt to get some smart people on-board;
Help me by contributing to this special Avalon-only project:
In the following posts, if they arrive on schedule, there should be a lot to learn.
No one should feel left out, not even speakers of other languages than English;
There is plenty of time for all to participate and enjoy the subtle art of coding.
This thread has been cooking for a long time... don't let its plain appearance and present shortness discourage you from helping make it into something great!
Kudos to the person who can find our very first, very simple coded message in the text above -- and extra points to the person who can tell me how this very rudimentary coding style was recently used jokingly by one government agency to communicate a message via the public press to another government agency -- a practice perhaps more common than we might think!
_______________________________________________________
Disclosure:
Q.) Why am I (the OP) interested in cryptanalysis and speaking to amateur and professional cryptographers and cryptanalysts here on Avalon?
A.) It's been a back-burner (almost non-existent) interest of mine since taking the full-version of the ASVAB in 2003. I did great until the coding section, which was the last part of the test and also the most difficult for many people who take it. In fact, when I looked at the wall of text in front of my eyes, I was overcome by stress and panic, to the point of not even wanting to try to work out the code. I simply selected what I thought to be the most likely answer, choosing many answers completely at random. For some reason, the military didn't disclose the results of the cryptanalysis test. This might be fairly standard, for obvious reasons.
I've read some books over the years that mentioned code, but never in a very interesting or approachable format. It wasn't really until I heard about Dan Brown (Da Vinci Code guy) and people like the infamous (and likely deceased?) "Zodiac Killer" that I acquired an interest in codebreaking (and code-making!). Not to mention, the recently declassified British news releases regarding code-breaking women of WW2.
I am hoping that by learning about code, I can exercise my mind in a positive and constructive manner, while still receiving the benefit of having deconstructed something (if only on paper or in my mind!). Code-breaking is a very stimulating, educated, and non-violent sport/hobby/pastime and should not be regarded as taboo, strange, terroristic, or boring (because it's really quite fascinating!).
Not to mention, it would be really cool if someone was able to decipher the last panel of Kryptos!
Q.) What will you (the OP) be doing with this information (if any is posted), and what is the point of this thread, ultimately?
A.) I am interested in how much information on this subject we users can successfully impart to one another. I have no intention of using the information to be posted in this thread for any purpose other than my own education, along with other users. Whether the thread remains public or private is open to member vote. Again, the point of this thread is introducing cryptanalysis as a hobby and sport for the sake of social opportunity and education.
Q.) Do you (OP) have any goals in regard to what may be produced in this thread?
A.) Well, I am not the brightest bulb on the Christmas tree, but it would be interesting if humans could produce a code that is breakable by humans but not by computer -- by virtue of its subtleties.
Also, it would be interesting to start developing a visual language in order to help people and animals with sensory issues (such as autism) to communicate freely with other human beings at will, with or without the help of technology. A good working knowledge of code, symbology, etc. would be of extreme helpfulness in developing such a language.
___________________________________________
I will be coming back to check on this one soon!
I will try to get some links and book references together as well, and maybe some practice stuff.
p.s.
http://en.wikipedia.org/wiki/Cryptan..._cryptanalysts
http://en.wikipedia.org/wiki/CryptographyHistoric cryptanalysts
Conel Hugh O'Donel Alexander
Charles Babbage
Lambros D. Callimahos
Alastair Denniston
Agnes Meyer Driscoll
Elizebeth Friedman
William F. Friedman, the father of modern cryptology
Meredith Gardner
Friedrich Kasiski
Al-Kindi
Dilly Knox
Solomon Kullback
Marian Rejewski
Joseph Rochefort, whose contributions affected the outcome of the Battle of Midway
Frank Rowlett
Abraham Sinkov
Giovanni Soro, the Renaissance's first outstanding cryptanalyst
John Tiltman
Alan Turing
William T. Tutte
John Wallis - 17th-century English mathematician
Herbert Yardley
http://en.wikipedia.org/wiki/CryptanalysisCryptography (or cryptology; from Greek κρυπτός, "hidden, secret"; and γράφειν, graphein, "writing", or -λογία, -logia, "study", respectively)[1] is the practice and study of techniques for secure communication in the presence of third parties (called adversaries).[2] More generally, it is about constructing and analyzing protocols that overcome the influence of adversaries[3] and which are related to various aspects in information security such as data confidentiality, data integrity, authentication, and non-repudiation.[4] Modern cryptography intersects the disciplines of mathematics, computer science, and electrical engineering. Applications of cryptography include ATM cards, computer passwords, and electronic commerce.
Cryptography prior to the modern age was effectively synonymous with encryption, the conversion of information from a readable state to apparent nonsense. The originator of an encrypted message shared the decoding technique needed to recover the original information only with intended recipients, thereby precluding unwanted persons to do the same. Since World War I and the advent of the computer, the methods used to carry out cryptology have become increasingly complex and its application more widespread.
Modern cryptography is heavily based on mathematical theory and computer science practice; cryptographic algorithms are designed around computational hardness assumptions, making such algorithms hard to break in practice by any adversary. It is theoretically possible to break such a system but it is infeasible to do so by any known practical means. These schemes are therefore termed computationally secure; theoretical advances, e.g., improvements in integer factorization algorithms, and faster computing technology require these solutions to be continually adapted. There exist information-theoretically secure schemes that provably cannot be broken even with unlimited computing power—an example is the one-time pad—but these schemes are more difficult to implement than the best theoretically breakable but computationally secure mechanisms.
Cryptology-related technology has raised a number of legal issues. In the United Kingdom, additions to the Regulation of Investigatory Powers Act 2000 require a suspected criminal to hand over his or her decryption key if asked by law enforcement. Otherwise the user will face a criminal charge.[5] The Electronic Frontier Foundation (EFF) was involved in a case in the United States which questioned whether requiring suspected criminals to provide their decryption keys to law enforcement is unconstitutional. The EFF argued that this is a violation of the right of not being forced to incriminate oneself, as given in the fifth amendment.[6]
Cryptanalysis (from the Greek kryptós, "hidden", and analýein, "to loosen" or "to untie") is the art and science of analyzing information systems in order to study the hidden aspects of the systems.[1] Cryptanalysis is used to breach cryptographic security systems and gain access to the contents of encrypted messages, even if the cryptographic key is unknown.
In addition to mathematical analysis of cryptographic algorithms, cryptanalysis also includes the study of side-channel attacks that do not target weaknesses in the cryptographic algorithms themselves, but instead exploit weaknesses in their implementation.
Even though the goal has been the same, the methods and techniques of cryptanalysis have changed drastically through the history of cryptography, adapting to increasing cryptographic complexity, ranging from the pen-and-paper methods of the past, through machines like the British Bombes and Colossus computers at Bletchley Park in World War II, to the mathematically advanced computerized schemes of the present. Methods for breaking modern cryptosystems often involve solving carefully constructed problems in pure mathematics, the best-known being integer factorization.
http://en.wikipedia.org/wiki/Kryptos
Pretty much the most famous wall of text on earth at present.Kryptos is an encrypted sculpture by American artist Jim Sanborn located on the grounds of the Central Intelligence Agency (CIA) in Langley, Virginia. Since its dedication on November 3, 1990, there has been much speculation about the meaning of the encrypted messages it bears. Of the four messages, three have been solved, with the fourth remaining one of the most famous unsolved codes in the world. The sculpture continues to provide a diversion for cryptanalysts, both amateur and professional, who are attempting to decrypt the final section.
EMUFPHZLRFAXYUSDJKZLDKRNSHGNFIVJ
YQTQUXQBQVYUVLLTREVJYQTMKYRDMFD
VFPJUDEEHZWETZYVGWHKKQETGFQJNCE
GGWHKK?DQMCPFQZDQMMIAGPFXHQRLG
TIMVMZJANQLVKQEDAGDVFRPJUNGEUNA
QZGZLECGYUXUEENJTBJLBQCRTBJDFHRR
YIZETKZEMVDUFKSJHKFWHKUWQLSZFTI
HHDDDUVH?DWKBFUFPWNTDFIYCUQZERE
EVLDKFEZMOQQJLTTUGSYQPFEUNLAVIDX
FLGGTEZ?FKZBSFDQVGOGIPUFXHHDRKF
FHQNTGPUAECNUVPDJMQCLQUMUNEDFQ
ELZZVRRGKFFVOEEXBDMVPNFQXEZLGRE
DNQFMPNZGLFLPMRJQYALMGNUVPDXVKP
DQUMEBEDMHDAFMJGZNUPLGEWJLLAETG
ABCDEFGHIJKLMNOPQRSTUVWXYZABCD
AKRYPTOSABCDEFGHIJLMNQUVWXZKRYP
BRYPTOSABCDEFGHIJLMNQUVWXZKRYPT
CYPTOSABCDEFGHIJLMNQUVWXZKRYPTO
DPTOSABCDEFGHIJLMNQUVWXZKRYPTOS
ETOSABCDEFGHIJLMNQUVWXZKRYPTOSA
FOSABCDEFGHIJLMNQUVWXZKRYPTOSAB
GSABCDEFGHIJLMNQUVWXZKRYPTOSABC
HABCDEFGHIJLMNQUVWXZKRYPTOSABCD
IBCDEFGHIJLMNQUVWXZKRYPTOSABCDE
JCDEFGHIJLMNQUVWXZKRYPTOSABCDEF
KDEFGHIJLMNQUVWXZKRYPTOSABCDEFG
LEFGHIJLMNQUVWXZKRYPTOSABCDEFGH
MFGHIJLMNQUVWXZKRYPTOSABCDEFGHI
ENDYAHROHNLSRHEOCPTEOIBIDYSHNAIA
CHTNREYULDSLLSLLNOHSNOSMRWXMNE
TPRNGATIHNRARPESLNNELEBLPIIACAE
WMTWNDITEENRAHCTENEUDRETNHAEOE
TFOLSEDTIWENHAEIOYTEYQHEENCTAYCR
EIFTBRSPAMHHEWENATAMATEGYEERLB
TEEFOASFIOTUETUAEOTOARMAEERTNRTI
BSEDDNIAAHTTMSTEWPIEROAGRIEWFEB
AECTDDHILCEIHSITEGOEAOSDDRYDLORIT
RKLMLEHAGTDHARDPNEOHMGFMFEUHE
ECDMRIPFEIMEHNLSSTTRTVDOHW?OBKR
UOXOGHULBSOLIFBBWFLRVQQPRNGKSSO
TWTQSJQSSEKZZWATJKLUDIAWINFBNYP
VTTMZFPKWGDKZXTJCDIGKUHUAUEKCAR
NGHIJLMNQUVWXZKRYPTOSABCDEFGHIJL
OHIJLMNQUVWXZKRYPTOSABCDEFGHIJL
PIJLMNQUVWXZKRYPTOSABCDEFGHIJLM
QJLMNQUVWXZKRYPTOSABCDEFGHIJLMN
RLMNQUVWXZKRYPTOSABCDEFGHIJLMNQ
SMNQUVWXZKRYPTOSABCDEFGHIJLMNQU
TNQUVWXZKRYPTOSABCDEFGHIJLMNQUV
UQUVWXZKRYPTOSABCDEFGHIJLMNQUVW
VUVWXZKRYPTOSABCDEFGHIJLMNQUVWX
WVWXZKRYPTOSABCDEFGHIJLMNQUVWXZ
XWXZKRYPTOSABCDEFGHIJLMNQUVWXZK
YXZKRYPTOSABCDEFGHIJLMNQUVWXZKR
ZZKRYPTOSABCDEFGHIJLMNQUVWXZKRY
ABCDEFGHIJKLMNOPQRSTUVWXYZABCD
When it's all stacked up like above, it almost looks like an unrolled log!
Imagine the outer edges of the message making a big circle from side to side and connecting with the letter on the opposite end, like the edges of the same piece of paper meeting.
It seems very similar to the strange code depicted in the alien blueprints in the movie adaptation of Carl Sagan's CONTACT.
It was not until the analysts viewed the documents in 3D that they broke the code!
In the case of Kryptos it would be coming full circle or closing the loop!
If only it was that easy.close the loop
Web definitions
To follow up on and/or close out an area of discussion. Closely related to "circle back around" and "loop in."
http://www.johnsmurf.com/jargon.htm
Closed-Loop vs. Open-Loop Authentication
Posted on April 3, 2013 by Francisco Corella
This is the second of a series of posts discussing the paper A Comprehensive Approach to Cryptographic and Biometric Authentication from a Mobile Perspective.
In this post I want to take the time to explain and emphasize the distinction made in the paper between closed-loop authentication and open-loop authentication. This may seem an unimportant matter of vocabulary, but the distinction is essential for two reasons: first, because it helps understand the privacy posture of authentication technologies; second, because it leads to what we think is the best choice of cryptographic authentication technologies for mobile devices.
The concepts of closed-loop and open-loop authentication are defined in the introduction, and examples are given. In open-loop authentication, a party such as a certificate authority or, more generally a credential authority, issues a cryptographic credential to the user’s device, and then is “out of the loop” when the device presents the credential to a relying party. Credentials used in open-loop authentication are typically public key certificates, but could also be U-Prove tokens or Idemix anonymous credentials. In closed-loop authentication, on the other hand, the credential authority is involved in the authentication process, taking care of verifying possession of the credential by the device. In third-party closed-loop authentication, the credential authority is an identity or attribute provider, which communicates user attributes to a relying party after verifying that the device possesses the credential. In two-party authentication, there is only one party besides the user’s device, so two-party authentication can only be closed-loop authentication.
The distinction between closed-loop and open-loop authentication makes it possible to make two observations.
The first observation is that closed-loop authentication can rely on an uncertified key pair, i.e. a key pair that is not bound to any attributes by a certificate. (As a matter of vocabulary, we say that an uncertified key pair is registered by the device with the credential authority, rather than issued by the credential authority to the device, because the credential authority plays no role in generating the key pair; the paper refers to the credential authority as “the party that issues or registers the credential”.) An uncertified key pair can be used because the credential authority can store user attributes in its internal storage and retrieve them at authentication time. Therefore the attributes need not be included in the credential.
The second observation is that, in third-party closed-loop authentication, the credential authority, i.e. the identity or attribute provider, is informed of the authentication transaction and, typically, is told what relying party the user is authenticating to. This impinges on the user’s privacy, especially if the user has no choice of identity or attribute provider and does not trust the provider. This is not just a theoretical consideration. The identity providers most commonly used today have track records of privacy violations, and users are wary of being spied upon.








Reply With Quote
.
