Intel's Ronler Acres Plant

Silicon Forest
If the type is too small, Ctrl+ is your friend

Showing posts with label Cryptography. Show all posts
Showing posts with label Cryptography. Show all posts

Monday, December 8, 2025

Substitution Cipher Based on The Voynich Manuscript

The Voynich Manuscript is a hand written book from the 15th century. It is written in an unknown language using unknown characters. People have been trying to decipher it since forever, but as yet there has been no success. There are a couple of theories on what it is, one of which is that it is just gibberish written by a madman. Another theory is that it is an encryption of a text in another language like Latin. Today I found this post on Schneier on Security:

Here’s a fun paper: “The Naibbe cipher: a substitution cipher that encrypts Latin and Italian as Voynich Manuscript-like ciphertext“:

Abstract: In this article, I investigate the hypothesis that the Voynich Manuscript (MS 408, Yale University Beinecke Library) is compatible with being a ciphertext by attempting to develop a historically plausible cipher that can replicate the manuscript’s unusual properties. The resulting cipher­a verbose homophonic substitution cipher I call the Naibbe cipher­ can be done entirely by hand with 15th-century materials, and when it encrypts a wide range of Latin and Italian plaintexts, the resulting ciphertexts remain fully decipherable and also reliably reproduce many key statistical properties of the Voynich Manuscript at once. My results suggest that the so-called “ciphertext hypothesis” for the Voynich Manuscript remains viable, while also placing constraints on plausible substitution cipher structures.

The first problem anyone attempting to decipher this manuscript runs into is deciding just which symbols are letters, since the symbols tend to run into each other. And then there is the problem of assigning tokens. Only after that is done can you begin trying to decipher it using a computer.

 

Saturday, November 9, 2024

Simple Cryptography


The Blue Monday Code (New Order)
Distort the Preamp

Nice, clear explanation of how substitution cyphers work along with a real world example. Okay, it's from the entertainment industry, so it's more like an imaginary world, but still based in reality.


New Order - Blue Monday 88 (Official Music Video)
neworder

Here's the tune he's talking about. I vaguely remember it.


Joy Division Greatest Hits
patrick cosgrove

The name 'Joy Division' struck a spark in my mind, but I found no record of ever having posted anything by them. Could it be that just the name struck a chord with me? Looking through their tunes I'm not finding anything I recognize, but this image pops up, and I do recognize this. Bonus - when the video is played the image is animated. Haven't seen that before.

Monday, May 13, 2024

Bitcoin Heater


This bathhouse makes $$ heating its pools with Bitcoin mining
Morning Brew

Crypto currency is stupid. After transportation, it is one of the biggest energy consumers on the planet. Maybe. Bitcoin miners and their like suck up a ton of electricity and turn it into heat. It's stupid, but it makes money.

Heatbit Mini

However, if you have electric heat, a Bitcoin heater can make some money that can be used to offset your electric bill, which would be nice.

PGE (Portland General Electric not Pacific Gas & Electric, which operates in California) just raised their rates. My last electric bill was for $150. Last time I checked it was like a buck and a half, so I ain't happy.

Friday, December 31, 2021

There's No Good Reason to Trust Blockchain Technology by Bruce Schneier

Stolen from WIRED for some reason. Probably because of all the ads popping up and interfering with my trying to read it. It might be from 2019, but the date is a little hazy, I mean just when is 82 86 2019? Unless those 8's are actually zeros.

Opinion: Cryptocurrencies are useless. Blockchain solutions are frequently much worse than the systems they replace. Here's why.

In his 2008 white paper that first proposed bitcoin, the anonymous Satoshi Nakamoto concluded with: “We have proposed a system for electronic transactions without relying on trust.” He was referring to blockchain, the system behind bitcoin cryptocurrency. The circumvention of trust is a great promise, but it’s just not true. Yes, bitcoin eliminates certain trusted intermediaries that are inherent in other payment systems like credit cards. But you still have to trust bitcoin—and everything about it.

Much has been written about blockchains and how they displace, reshape, or eliminate trust. But when you analyze both blockchain and trust, you quickly realize that there is much more hype than value. Blockchain solutions are often much worse than what they replace.

First, a caveat. By blockchain, I mean something very specific: the data structures and protocols that make up a public blockchain. These have three essential elements. The first is a distributed (as in multiple copies) but centralized (as in there’s only one) ledger, which is a way of recording what happened and in what order. This ledger is public, meaning that anyone can read it, and immutable, meaning that no one can change what happened in the past.

The second element is the consensus algorithm, which is a way to ensure all the copies of the ledger are the same. This is generally called mining; a critical part of the system is that anyone can participate. It is also distributed, meaning that you don’t have to trust any particular node in the consensus network. It can also be extremely expensive, both in data storage and in the energy required to maintain it. Bitcoin has the most expensive consensus algorithm the world has ever seen, by far.

Finally, the third element is the currency. This is some sort of digital token that has value and is publicly traded. Currency is a necessary element of a blockchain to align the incentives of everyone involved. Transactions involving these tokens are stored on the ledger.

Private blockchains are completely uninteresting. (By this, I mean systems that use the blockchain data structure but don’t have the above three elements.) In general, they have some external limitation on who can interact with the blockchain and its features. These are not anything new; they’re distributed append-only data structures with a list of individuals authorized to add to it. Consensus protocols have been studied in distributed systems for more than 60 years. Append-only data structures have been similarly well covered. They’re blockchains in name only, and—as far as I can tell—the only reason to operate one is to ride on the blockchain hype.

All three elements of a public blockchain fit together as a single network that offers new security properties. The question is: Is it actually good for anything? It's all a matter of trust.

Blockchain Tweet

Trust is essential to society. As a species, humans are wired to trust one another. Society can’t function without trust, and the fact that we mostly don’t even think about it is a measure of how well trust works.

The word “trust” is loaded with many meanings. There’s personal and intimate trust. When we say we trust a friend, we mean that we trust their intentions and know that those intentions will inform their actions. There’s also the less intimate, less personal trust—we might not know someone personally, or know their motivations, but we can trust their future actions. Blockchain enables this sort of trust: We don’t know any bitcoin miners, for example, but we trust that they will follow the mining protocol and make the whole system work.

Most blockchain enthusiasts have a unnaturally narrow definition of trust. They’re fond of catchphrases like

in code we trust,”

in math we trust,” and

in crypto we trust.”

This is trust as verification. But verification isn’t the same as trust.

In 2012, I wrote a book about trust and security, Liars and Outliers. In it, I listed four very general systems our species uses to incentivize trustworthy behavior. The first two are morals and reputation. The problem is that they scale only to a certain population size. Primitive systems were good enough for small communities, but larger communities required delegation, and more formalism.

The third is institutions. Institutions have rules and laws that induce people to behave according to the group norm, imposing sanctions on those who do not. In a sense, laws formalize reputation. Finally, the fourth is security systems. These are the wide varieties of security technologies we employ: door locks and tall fences, alarm systems and guards, forensics and audit systems, and so on.

These four elements work together to enable trust. Take banking, for example. Financial institutions, merchants, and individuals are all concerned with their reputations, which prevents theft and fraud. The laws and regulations surrounding every aspect of banking keep everyone in line, including backstops that limit risks in the case of fraud. And there are lots of security systems in place, from anti-counterfeiting technologies to internet-security technologies.

In his 2018 book, Blockchain and the New Architecture of Trust, Kevin Werbach outlines four different “trust architectures.” The first is peer-to-peer trust. This basically corresponds to my morals and reputational systems: pairs of people who come to trust each other. His second is leviathan trust, which corresponds to institutional trust. You can see this working in our system of contracts, which allows parties that don’t trust each other to enter into an agreement because they both trust that a government system will help resolve disputes. His third is intermediary trust. A good example is the credit card system, which allows untrusting buyers and sellers to engage in commerce. His fourth trust architecture is distributed trust. This is emergent trust in the particular security system that is blockchain.

What blockchain does is shift some of the trust in people and institutions to trust in technology. You need to trust the cryptography, the protocols, the software, the computers and the network. And you need to trust them absolutely, because they’re often single points of failure.

When that trust turns out to be misplaced, there is no recourse. If your bitcoin exchange gets hacked, you lose all of your money. If your bitcoin wallet gets hacked, you lose all of your money. If you forget your login credentials, you lose all of your money. If there’s a bug in the code of your smart contract, you lose all of your money. If someone successfully hacks the blockchain security, you lose all of your money. In many ways, trusting technology is harder than trusting people. Would you rather trust a human legal system or the details of some computer code you don’t have the expertise to audit?

Blockchain enthusiasts point to more traditional forms of trust—bank processing fees, for example—as expensive. But blockchain trust is also costly; the cost is just hidden

For bitcoin, that's the cost of the additional bitcoin mined, the transaction fees, and the enormous environmental waste.

Blockchain doesn’t eliminate the need to trust human institutions. There will always be a big gap that can’t be addressed by technology alone. People still need to be in charge, and there is always a need for governance outside the system. This is obvious in the ongoing debate about changing the bitcoin block size, or in fixing the DAO attack against Ethereum

There’s always a need to override the rules, and there’s always a need for the ability to make permanent rules changes. As long as hard forks are a possibility—that’s when the people in charge of a blockchain step outside the system to change it—people will need to be in charge.

Any blockchain system will have to coexist with other, more conventional systems. Modern banking, for example, is designed to be reversible. Bitcoin is not. That makes it hard to make the two compatible, and the result is often an insecurity. Steve Wozniak was scammed out of $70K in bitcoin because he forgot this.

Blockchain technology is often centralized. Bitcoin might theoretically be based on distributed trust, but in practice, that’s just not true. Just about everyone using bitcoin has to trust one of the few available wallets and use one of the few available exchanges. People have to trust the software and the operating systems and the computers everything is running on. And we've seen attacks against wallets and exchanges. We’ve seen Trojans and phishing and password guessing. Criminals have even used flaws in the system that people use to repair their cell phones to steal bitcoin.

Moreover, in any distributed trust system, there are backdoor methods for centralization to creep back in. With bitcoin, there are only a few miners of consequence. There’s one company that provides most of the mining hardware. There are only a few dominant exchanges. To the extent that most people interact with bitcoin, it is through these centralized systems. This also allows for attacks against blockchain-based systems.

These issues are not bugs in current blockchain applications, they’re inherent in how blockchain works. Any evaluation of the security of the system has to take the whole socio-technical system into account. Too many blockchain enthusiasts focus on the technology and ignore the rest.

To the extent that people don’t use bitcoin, it’s because they don’t trust bitcoin. That has nothing to do with the cryptography or the protocols. In fact, a system where you can lose your life savings if you forget your key or download a piece of malware is not particularly trustworthy. No amount of explaining how SHA-256 works to prevent double-spending will fix that.

Similarly, to the extent that people do use blockchains, it is because they trust them. People either own bitcoin or not based on reputation; that’s true even for speculators who own bitcoin simply because they think it will make them rich quickly. People choose a wallet for their cryptocurrency, and an exchange for their transactions, based on reputation. We even evaluate and trust the cryptography that underpins blockchains based on the algorithms’ reputation.

To see how this can fail, look at the various supply-chain security systems that are using blockchain. A blockchain isn’t a necessary feature of any of them. The reasons they’re successful is that everyone has a single software platform to enter their data in. Even though the blockchain systems are built on distributed trust, people don’t necessarily accept that. For example, some companies don’t trust the IBM/Maersk system because it’s not *their* blockchain.

Irrational? Maybe, but that’s how trust works. It can’t be replaced by algorithms and protocols. It’s much more social than that.

Still, the idea that blockchains can somehow eliminate the need for trust persists. Recently, I received an email from a company that implemented secure messaging using blockchain. It said, in part: “Using the blockchain, as we have done, has eliminated the need for Trust.” This sentiment suggests the writer misunderstands both what blockchain does and how trust works.

Do you need a public blockchain? The answer is almost certainly no. A blockchain probably doesn’t solve the security problems you think it solves. The security problems it solves are probably not the ones you have. (Manipulating audit data is probably not your major security risk.) A false trust in blockchain can itself be a security risk. The inefficiencies, especially in scaling, are probably not worth it. I have looked at many blockchain applications, and all of them could achieve the same security properties without using a blockchain—of course, then they wouldn’t have the cool name.

Honestly, cryptocurrencies are useless. They're only used by speculators looking for quick riches, people who don't like government-backed currencies, and criminals who want a black-market way to exchange money.

To answer the question of whether the blockchain is needed, ask yourself: Does the blockchain change the system of trust in any meaningful way, or just shift it around? Does it just try to replace trust with verification? Does it strengthen existing trust relationships, or try to go against them? How can trust be abused in the new system, and is this better or worse than the potential abuses in the old system? And lastly: What would your system look like if you didn’t use blockchain at all?

If you ask yourself those questions, it's likely you'll choose solutions that don't use public blockchain. And that'll be a good thing—especially when the hype dissipates.


Wednesday, December 22, 2021

Numbers Stations


The Mysterious and Fascinating World of ‘Numbers Stations’
Today I Found Out

I've always been a bit curious about Numbers Stations. Simon doesn't have all the answers, but he has compiled a bunch of info. It's an entertaining video.

He mentions The Conet Project. Wikipedia has a page and so does SoundCloud. He also mentions several tunes have incorporated sounds recorded from Numbers Stations. This is the only one I found.


Jean Michel Jarre - Magnetic Field
Jarre98

It's not much of a tune, it's kind of long and the bits I've listened to are strange. Listen if you like.

I did another post about communications last year that included another video about numbers stations. It has a slightly different take on the subject.

Thursday, March 5, 2020

Communications

Old and new.


AT&T Archives: The Step-By-Step Switch

Back in 1951, a $2 million switch could serve 20,000 homes. That's $100 for each line. If each household was paying $4 a month each it would take Ma Bell two years to recoup her investment. Nowadays, thanks to microelectronics, a $2 million switch could probably serve two million homes, but now they charge $50 a month for high speed internet. Somebody is making some money.


HM01 - The Ultimate Radio Mystery

This is a pretty great overview of radio, encryption, espionage and numbers stations. It doesn't really cover any new ground, but he ties several pieces together.

Tuesday, February 5, 2019

Blockchain

Danish researcher Thomas Silkjaer is using Google's BigQuery to map publicly available information about XRP cryptocurrency addresses. The craters represent some of cryptocurrency's largest exchanges.
I found this picture in a Forbes story about the crypto-currency universe. I don't know that it actually tells you anything, but it's good that someone is at least trying to make some sense out of it.

Blockchains exist in the cloud, that is, all the data lives on anonymous servers housed in warehouses (or someone's basement) scattered all over the world. Well, maybe not in North Korea. Cloud-computing makes sense, as long as you have reliable communications. I mean, I use it. I try and keep most of my stuff on Google Drive, saves me from having to make backups, which I was never very good at. Plus it doesn't cost me anything, other than privacy, but somebody is paying to use it:
"When it comes to cloud computing, Google is far behind Amazon and Microsoft. Last year Google pocketed an estimated $3 billion in revenue from cloud ser­vices. Amazon and Microsoft, meanwhile, generated about $27 billion and $10 billion, respectively." - Michael del Castillo

Thursday, January 10, 2019

Ethereum

One year Ethereum price history
It's been a while since I checked on my Ethereum holdings, so today I took a peak. The current price is roughly $125 per imaginary coin, down from the $300 it was just over a year ago. My 'wallet' has accumulated 0.18 of an Ether coin, which works out to $23. So not as good as originally forecasted, but it hasn't completely disappeared either, so I guess I will it ride.

Friday, August 10, 2018

Encoding Curses

Yes, I am not a robot.

I do not like people I don't know calling me on the telephone and telling me some kind of bull$#!+. If I am feeling charitable I simply hang up. If not, I reach into the gutter and pull up some kind of garbage and spew it into their ear. The later is worse than useless as it is unlikely to change the situation and subjects the caller to verbal abuse. If the caller was the instigator that would be fair, but usually that is not the case. Usually they are working for someone else who has somehow managed to find a way to make money badgering people.

It must work, right? They make a thousand phone calls a day, 50% of them don't connect because the numbers have been abandoned or the phone is off or something. Half of those that connect don't answer, and half of those that answer hang up immediately. So right off, just using wild-@$$ guesses for numbers, we have over a hundred people who will talk to the caller. Now in ten days, one caller might actually talk to a thousand people, and out of that thousand they might get one person who actually signs up for some kind of bull$#!+ that will cost them $10 a month.

How much is a perpetual agreement to pay $10 a month worth? A thousand dollars? That would take ten years to pay off. I'm thinking it might be worth $100. Some people will cancel immediately, some will cancel after a few months, some will keep it until they change credit cards or phone numbers or something so they might keep it for a year. A very few will keep it longer than that and that's where you make your money. If you were in the business I would expect you would know exactly what the percentages were for each of these situations, but I'm not so we're stuck using 50% for everything.

So if you are paying your operators a dollar a day, and it takes them ten days to make a sale that puts $100 in your pocket, you just made $90. I think English speakers in India are getting more like a dollar an hour, which would make the margins a little thin. Then there are those in the US for whom any money is better than nothing and they are willing to work for promises of commission. To me, it sounds like a horrible job but I imagine there are people who are suited for it. Hard to imagine, but I suppose it's possible that there are people who actually enjoy it.

What I really want to know is why no one has put a spike button on the telephone keypad? A button that would spike the caller and prevent them from ever making any more telephone calls. You know the telecom companies could do it, but if you ask why they'll give you some kind of bull$#!+ about how they can't keep track of who is making those robo-calls. But you know they d@mn well do know who is making those calls, and they probably give them preferential treatment because they are paying their bills.




The original version of this post contained a bunch of curse words spelled out using punctuation symbols from the numeric keys on the keyboard (like you see in the @#$%^&* comics). I got to looking at that and I started wondering if that set of keys is large enough to encode all the letters in all of our popular curse words. Turns out no, the number keys only give you ten symbols and my list of popular curse words contains 16 letters. There are three other keys in the number row of the keyboard that each contain two characters, so you could do it, but then you still have to figure out how to assign the letters.

Looking at the ASCII code for those characters shows me that most of them differ from the letters of the alphabet by 0x20 (20 hex = 32 decimal), so we would have an easy correspondence for the first ten letters of the alphabet. But not all of those first ten letters are on our list.

Anyway, I thought maybe a spread sheet could help me find a solution, but the first thing I wanted was to do some hexadecimal arithmetic, so I ask for help and it points me to an article on the help forum, an article that I wrote about eight years ago.

Okay, that's enough of that.

Thursday, December 14, 2017

Who knows what

Illustration of the idea behind Diffie-Hellman key Exchange

I'm reading about the Diffie–Hellman Key Exchange and I come across this phrase:
The chart below depicts who knows what,
Who knows what? Are you kidding me? Isn't that the phrase we use when we don't know what the subject is? Does this mean that whoever is writing the description of this chart does not know what it depicts? Well, that's dumb. How can you write a description of something you don't understand? But then I realize that the chart shows what information is known by which people, i.e. who knows what.

Monday, November 10, 2014

The Imitation Game


The Imitation Game Official Trailer #1 (2014) - Benedict Cumberbatch Movie HD

Keira Knightley plays Joan Clarke, one of the codebreakers who worked with Alan Turing at Bletchley Park in WW2. Joan got 'a double first in mathematics' at Cambridge, whatever that is. I suppose it's a good thing, I mean it must be, The Weinstein Company made a movie about her.
The Bletchley Park codebreaking operation during World War 2 was made up of nearly 10,000 people (about 75% of this number was women). However, there are very few women of that are formally recognised as cryptanalysts working at the same level as their male peers. - Bletchley Park Research
WW2 just won't go away. Other posts that mention Bletchley (what a weird name) Park. Unfortunately Google has lost most of the pictures and I don't have the patience to go dig them up. They are probably on my old computer, sitting in the corner, unloved and unplugged.
Via Stu and a BBC News story.

Update April 2019 replaced missing video.