The English film "The Imitation Game" about Alan Turing was released this week in Germany, so we picked up the film in English at Odeon with some mathematically inclined friends. The theater was well-filled, a good sign, as I like having a movie theater close by that shows English-language original films. And has SALTED buttered popcorn.
A review on the radio was positively gushing about the film, while the Wikipedia article in English has a long section about various controversies, the short German Wikipedia article is completely dominated by criticism. Turing is portrayed as a traitor for not exposing a spy! He never worked with the guy! He wasn't that close to June Clarke! The maths are wrong! There's an error in the machine! He was arrested in 1952, not 1951! Etc. etc.
Just ignore all this. It's not supposed to be a documentary and they only have two hours to tell the story so that people can sort of begin to understand what drives some people to spend hours and hours pouring over mathematical formulas and computing machinery. And that some of these people have issues understanding social cues and relating to people. They're odd ones. Maybe he was an Aspie and maybe he wasn't, it is still a wonderful film.
The actor Benedict Cumberbatch gives quite some insight into what it might have been like to be Alan Turing, to have had this mad idea of building a machine to break codes, and to have had his contribution to ending the war kept secret. His homosexuality, gently woven throughout the film, which caused the country he saved to put him on trial and have him chemically castrated, is well-treated. It's not in-your-face and it's not something mentioned off-hand. It is part of him, full stop. And it is a disgrace to England that it took until 2013 for Queen Elizabeth to pardon him.
The last few minutes of the film flash cards noting how the story plays out. They call Turing's death a suicide, although there are any number of alternative ideas from inhaling fumes from his chemical experiments to GCHQ having their hand in it. From what we have heard from Edward Snowden the past year and a half, that is actually starting to make a lot of sense. Turing understood the art of cryptography and cryptanalysis, the GCHQ doesn't want a lot of that going around.
Anyway: a film that makes people think about how gays are treated, about how deadly secrets are kept in a war, and about math being important gets a thumbs up from me. I shall recommend it to my students. And I suggest reading Andrew Hodges' book "Alan Turing: The Enigma" as well as Turing's publications. Oh, and learn cryptography while you are at it.
2015-01-24
The Imitation Game
at
00:42
0
comments
Labels: cryptography, film England
2014-08-04
Bletchley Park
We spent Saturday at Bletchley Park. That is a little town north of London where Alan Turing worked trying to crack the code that the Germans were using in World War II. At the peak there were apparently 10.000 people working there, also building a magnificent single-purpose computer, the Colossus, to crack open the one-time pad generated by the Lorenz Machine for use be the German High Command.
Saturdays are wonderful days, as there are volunteers out there enthusiastically explaining how the machines work. The only down side is that the National Computer Science Museum and Bletchley Park are on the same grounds, but they don't cooperate, so you have to pay two entrance fees if you want to see both machines running. But it is worth it! And if you are heading up by train, there's a 2-for-1 coupon that you can print out in advance, that saves 15 pounds.
It was nice to see a lot of material in person and to be able to photograph it. There were live demonstrations of a rebuilt Bombe and the rebuilt Colossus. All machines and material were to have been destroyed after the war, as this was a top-secret operation, but luckily there were a few photos and diagrams, and there were still some of the engineers alive as groups started re-producing the parts.
The Colossus was primarily built out of standard telephone exchange parts, as the telephone engineers built it. When British Telecom was upgrading their analog parts to digital, one of the members of the rebuild team drove around with a truck, picking up all the analogue parts (especially valves) he could. The presenter requested that everyone have a look in their garage and attic to see if they happened to have a few lying around, as they are too expensive to produce any more. They consist of hand-blown glass with metal and plastic parts. I wonder if there will ever be a 3D printer for retro parts.
I must have taken 100 pictures, far too many to post here. I guess I'll have to teach cryptography again only in order to use them - and in order to explain how the codes were cracked. The "unbreakable" Lorenz cipher was broken when a soldier re-used the same one-time pad to resend a message that was slightly different - with abbreviations. And the Enigma was brute-forced after some lateral thinking showed that there was a flaw - a character could never be mapped to itself. And since the Germans love wordy, standard terminology, and had a tendency to send messages at the exact same time every day (like the Wettervorhersage, the weather report, or regular reports that nothing had happened worth reporting - Keine besondere Vorkommnisse) so the engineers could compare the intercepted code with typical words that they expected to be in the text, and were thus able to rule out quite a number of cases. With the Bombe they then brute-forced the rest of the possibilities, using a machine called the Type-X that you could set a possible key and type in the message and see if it fell out in plain text. What a disappointment that must have been to spend all day decoding and then to learn that the Kleiderpauschale had been raised by one Reichsmark or something equally boring.
It was a fascinating day, I could have spent lots more time AND bought one of everything in the gift shop. But I'm flying and already close to the weight limit, so I just purchased some postcards and a DVD.
at
00:21
0
comments
Labels: cryptography, England
2010-01-16
The Potemkin Airport
I haven't seen this on any English-language news, so I am translating and referencing it here, so that perhaps the one or the other might pick it up.
You have probably heard about a Potemkin village: mock towns built up along the Dnieper river in order to impress the Russian Empress Catharine II during an inspection visit.
Well, airport security has been called "security theater" by many, including Bruce Schneier. The German hacker's organization Chaos Computer Club (CCC) has demonstrated that airport security is not just theater, but in many places just a facade, put up to impress the traveling public.
While the poor people paying for transport are queuing up to have their underwear inspected and to dispose of their liquids purchased outside on the free market, the determined terrorist just has to invest about 200 Euros and walk around and use the side entrance.
Spiegel Online reporter Matthias Kremp reports on this simple hack in January 2010, as demonstrated on the public TV show Kontraste (ARD) (the 6:30 minute video by Matthias Deiß is available at this link, in German).
Entrance to the security areas is organized by an RFID chip-based challenge-response system. Personnel with a security clearance has an ID card that many wear on a lanyard around their necks. When they pass a guarded entrance point, an electromagnetic challenge is sent to the card, and the card responds.
Two CCC members purchased an RFID kit and set it up so that it can query an ID card. The card responds, and the kit records the response. The kit (which fits nicely into a pocket) can then be switched to respond mode, and when it passes a control point, the recorded response is replayed and the door opens.
The recorder must get within 70 cm of the card in order to record, but in a crowded airport it is easy to bump into someone on purpose and make it look like an accident.
The hackers alerted the airport security people, as they were not out to blow up airplanes, but had been interested in a security puzzle. As one of the men says on camera, they were shocked that it was so easy. Did security start insisting that people keep a one meter distance from all people with security clearances? Did they beef up security? No. They did nothing.
Exasperated, they turned to Kontraste, an investigative, publicly funded TV show which (apart from series like Tatort) is the only reason I am still willing to pay my TV tax without too much grumbling. Kontraste loves this kind of story. They demonstrated how easy it is to enter the building on film.
Then they contacted airport security, who was not willing to talk to them. By email they answered "for security reasons we will not be giving any additional information". Aha. Security by obscurity.
The system used for security is from the Swiss company Legic Identsystems and is called Legic Prime. From their online presentation:
LEGIC prime is widely used in access control related applications such as multiapplication company cards, in large-scale ticketing projects or in the leisure industry. Easier organisational processes and to increase the convenience are thereby the main focus.Um, leisure industry? Convenience? I thought airports were focused on security! Kontraste But they were all unwilling to make public statements. quickly determined that not only did the Hamburg airport use this system, Stuttgart, Dresden, Hanover, and Berlin also use it. You see, it used "encryption", and that makes it secure. It also has "key management". Wooooo.
The gentlemen from CCC demure. No, they didn't find any trace of encryption, not even ROT13. So Kontraste headed down to the Swiss headquarters to try and get a statement on camera, but were rebuffed. However, their efforts did effect a change on the web page. Instead of "high security" this system now offers "basic security".
A speaker for the police union was quite willing to go on camera and demand that someone DO SOMETHING RIGHT NOW. They are the ones who have to put their lives on the line when some terrorist decides to start something. But of course, Hamburg alone would have to exchange 15.000 cards and numerous transponders, the cards run about 10 € apiece. At least, according to the web page, they could upgrade to Legic advant, which has
- Advanced security
- AES 128/256 bit / DES / 3DES encryption
- Mutual authentication between reader and transponder
- Diversified authentication and data encryption
- Physical Master-Token System Control and Automatic Key Management
at
12:40
1 comments
Labels: cryptography, security
2008-06-18
Long Science Night 2008
The Berliners have a thing for "Long Nights of ....". I don't know who was first, but the Long Science Nights have been around for a good may years. Most of the universities and colleges and science institutions get some experiments set up to show the taxpayers what they are funding, the bus company organizes shuttle busses, there's food all over the place, and from 5 pm until 1 am Average Joes (and university folk not showing experiments) mill around looking at stuff.
I started off at the TU, as I will be teaching Cryptography next semester and there was to be a crypto-lab there. The lecture was boooooring, and the young man who then tried to explain to me how to send an encrypted email couldn't actually speak in coherent sentences. I couldn't even follow, although I knew what I was supposed to be doing. And then their email broke down and then all sorts of stuff was broken, and then at least I could generate a key pair, but he admonished me to "choose a small passphrase so it gets made quicker." Duh. People need to be trained to use long passphrases. I made myself known, but he just was not hearing what I was saying.
Disgusted, I hopped on a shuttle and made my way down to the Federal Printing Office. This is where the money is printed (they have a big tube of shredded notes on display) and the new biometric passports are made. I slided up to the guy explaining the wonders of the new passport and started asking questions. It soon turned out that we were two computing women and one computing guy who acutally knew a bit about crypto. The poor guy got rather into a bad spot, as he could not really tell us much.
Apparently, with the data read from the machine-readable portion of your passport they encode your picture. I strongly suspect that with the special structure a picture file has and the situation that much of the key is fundamental law of cryptography is that the strength of a method lies only in the keys, not in any secret algorithms.
Anyway, the fingerprints are then encoded with another secret key that is available at all passport issuing places. Duh again.
Moving on to the 3D facial scanner, one begins to feel uneasy. A little beamer projects a mesh to a face, two cameras take one picture each, the software calculates a little bit, and presto - 3D image of the head, suitable for storage and identification.
Upstairs is a great coppersmith showing how he made stamps in the years gone by.
I took the bus on to the State Criminal Investigations Agency (Landeskriminalamt). They were participating for the first time. They set up a murder scene outside of the building, including a second scene with the getaway car. Inside they had people from all the departments explaining what they did in this case. And there were documents prepared for the case, just as they would be for a real murder.
It was highly informative and highly entertaining. I spoke with a fingerprint specialist about how she became a dactylologist. She said she was just a normal police investigator, but good at fingerprints, so she got in deeper and deeper and now that is her job, which she likes a lot.
I also heard 2 lectures, one explaining DNA-sequencing and identification of people with DNA that was very clear and one by the head of the murder commission explaining how they work.
Got both my admission fee's worth and some value for the taxes I pay. The LKA did a smashing job of explaining what they do to us.
Bedtime now.
at
23:55
2
comments
Labels: cryptography, DNA, lange nacht der wissenschaften