Puzzle
As usual, I had my packet sniffer on during the visit to Microstrategy, and intercepted these two seemingly random but apparently interesting bit steams:


Although each message would be perfectly secure by itself (assuming a perfectly random key was used), you may be able to figure out their contents using the same technique John Tiltman used to determine the key used from the two intercepted messages.
You may find this Python code helpful for doing bit manipulations.
Note added 27 October: The encrypted messages unforuntately have a
long overlapping part where both messages are identical! This makes
it so that you don't actually have a two-time pad for that segment,
but a one-time pad, which is unbreakable (other than any possible
weaknesses in Python's Crypto.Random which I used to generate the
key). The text that is identical in the two messages is into this
crypto stuff
. Sorry for the touble this caused to anyone who tried
to break the impossible part of the puzzle! Congratulations to
Gabriel Espinola Ibarra for essentially solving it (other than the
impossible part).
Annotated Slides
Academics focus on the shiny, complicated parts. Attackers go after the flimsy, plastic parts. Engineers should focus mostly on using the rusty, solid, well-understood parts and avoiding introducing flimsy, plastic parts. |
|
Lax Security at LinkedIn Is Laid Bare, New York Times, 10 June 2012 (you will understand enough to not make these kinds of mistakes by the second sesson) Encryption Flaw Makes Phones Possible Accomplices in Theft, New York Times, 21 July 2013. (this was partly a result of implementing systems today using legacy technologies that are not nearly strong enough to thwart low-resource attacks today) |
|
Next: Kerckhoffs' Principle
Jefferson's Wheel
Cryptanalysis
Modern Symmetric Ciphers