Earlier quoted context omitted.
Yeah. They should just use ROT13 as substitution. Then key availability is not an issue anymore.
For extra security it's important to run ROT13 twice.
200-year-old ciphers may reveal the location of treasure buried in Virginia
31–40 of 40 posts
Re: 200-year-old ciphers may reveal the location of treasure buried in Virginia
#32Earlier quoted context omitted.
Also known as a One Time Pad for anyone wanting more info, generally the key and message are xor'd if its digital and that's the entirety of the encryption algorithm. Used properly it's proven to be unbreakable.
It’s breakable if you use some publically published document as the key as in cipher 2
Ostensibly the author decrypted the the second document by doing a brute force search of the key space (that is the set of documents available at the time). This is functionally the same as aes - just a much smaller key space.
Re: 200-year-old ciphers may reveal the location of treasure buried in Virginia
#33Earlier quoted context omitted.
I can't tell whether you're being sarcastic, but the article is essentially correct. The security of an encryption algorithm doesn't depend on how complex it is if you never reuse the key, because a uniformly random key produces uniformly random output for any input. Only key reuse can introduce statistical regularities that allow cryptanalysis to be applied. The reason most encryption algorithms are more complex tha…
> a uniformly random key produces uniformly random output for any input. This is clearly not true for a simple substitution cipher though, otherwise it couldn't be attacked with frequency analysis
The reason one time pads are not used in general is that you need a “perfect” rng, and you have to be able to get the random values to the recipient. Those old “person traveling with brief case of secrets” trope was a real thing. Key distribution is the problem solved by public key cryptography. But you can’t use one time pads with public key crypto, because the weakness is then breaking public keys (which is probably possible).
Stream ciphers loosely acted like a one time pad in that you generate a “random” stream and xor with the message. But it doesn’t reach the actual requirement of security for a one time pad because the key is the RNG seed, which means you can brute force the seed key space and only the correct key will produce a completely sensible decrypted output.
A true one time pad means that a brute force search of the key space for a message of length N will find every valid message of length N.
Eg an 11 letter message would produce (among others) “hello world” and “hello earth” as well as “die planet!”.
Re: 200-year-old ciphers may reveal the location of treasure buried in Virginia
#34Re: 200-year-old ciphers may reveal the location of treasure buried in Virginia
#35Re: 200-year-old ciphers may reveal the location of treasure buried in Virginia
#36Earlier quoted context omitted.
I also believe it was a hoax, but this is not a good argument for it being a hoax: The perpetrator would expect buyers of the pamphlet to try reproduce the decoding of the second ciphertext, so presumably there were versions of the declaration that correctly formed the key. For the edits (compared to original declaration) see also: https://en.wikipedia.org/wiki/Beale_ciphers#Deciphered_messa... I would like to see a…
> The perpetrator would expect buyers of the pamphlet to try reproduce the decoding of the second ciphertext, so presumably there were versions of the declaration that correctly formed the key. The version of the DoI that was used to decode ciphertext #2 was included with the pamphlet. It does not produce an error-free decoding. > I would like to see a python (or other) script with the most important observations rep…
So I was browsing the NSA pdf files "The Beale Papers" from archive.org, and apperently according to these files theres even different versions of the CIPHERTEXTS!
It is unclear to me why there would be different ciphertexts floating around, possibly:
1) the pamphlet author published multiple versions 2) after analysis, later authors "fixed" the ciphertexts as opposed to describing the encryption errors in the decoding mechanism 3) flat out disinformation by: the publisher (how does the anonymous author defend the true ciphertext? would other publishers at the time dare to publish a second version of the cipher? how does this author prove he is the same anonymous person?), disinformation by treasure hunters (you can recognnize your own manipulation, but this confuses everyone else)
Do we know what happened with the publisher? did it merge with others, and is it still in existence under a new name? Do they perhaps have any early original (from the box, or original manuscript from the anonymous person, etc...)
Re: 200-year-old ciphers may reveal the location of treasure buried in Virginia
#37Earlier quoted context omitted.
I also believe it was a hoax, but this is not a good argument for it being a hoax: The perpetrator would expect buyers of the pamphlet to try reproduce the decoding of the second ciphertext, so presumably there were versions of the declaration that correctly formed the key. For the edits (compared to original declaration) see also: https://en.wikipedia.org/wiki/Beale_ciphers#Deciphered_messa... I would like to see a…
> The perpetrator would expect buyers of the pamphlet to try reproduce the decoding of the second ciphertext, so presumably there were versions of the declaration that correctly formed the key. The version of the DoI that was used to decode ciphertext #2 was included with the pamphlet. It does not produce an error-free decoding. > I would like to see a python (or other) script with the most important observations rep…
http://rogergrambihler.tripod.com/BealeHoax.htm
although he doesn't notice his own mismatcc of "hith" instead of "with" (I haven't checked/reproduced his mapping in code, I intend to implement his decoding with quirks by adapting your .c file, if you wish I can send it over when done)
Re: 200-year-old ciphers may reveal the location of treasure buried in Virginia
#38Earlier quoted context omitted.
I also believe it was a hoax, but this is not a good argument for it being a hoax: The perpetrator would expect buyers of the pamphlet to try reproduce the decoding of the second ciphertext, so presumably there were versions of the declaration that correctly formed the key. For the edits (compared to original declaration) see also: https://en.wikipedia.org/wiki/Beale_ciphers#Deciphered_messa... I would like to see a…
> The perpetrator would expect buyers of the pamphlet to try reproduce the decoding of the second ciphertext, so presumably there were versions of the declaration that correctly formed the key. The version of the DoI that was used to decode ciphertext #2 was included with the pamphlet. It does not produce an error-free decoding. > I would like to see a python (or other) script with the most important observations rep…
While encoding is a work in progress this is a perfectly good tool to use, but it is dangerous to explicitly write the letter i.e. "A: 107, 204, ... B: 48, 87, ..." (I made up the numbers) because if the lookup table is found with the ciphertext, the attacker no longer needs to find the correct book (DoI)!
An alternative to actually writing down the letters on the same piece of paper is to have a second strip of paper, to be held above/below the numbers, in an aligned fashion, so that one paper has "A [whitespaces] B [whitespaces] C ..." and the second has some numbers corresponding to the letters. (if you look at things like "indenture" the concept of aligning paper was a commonly used trick for verification etc purpouses)
The grass is always greener on the other side:
1) whenever the encoder was working without lookup table, he labouriously had to traverse the DoI lookinng for a suitable word, wishing he had a lookup table
2) whenever the encoder retried constructing a good lookup table, he (erroneously?) felt he was wasting his time constructing a lookup table instead of encoding the text
this could explain the restarting runs of the alphabet (with letters recurring i.e. aaaabbbccc..., and also explains why the number distribution is flatter compared to N and E as in "Where are the N and E characters" at http://rogergrambihler.tripod.com/BealeHoax.htm )
Re: 200-year-old ciphers may reveal the location of treasure buried in Virginia
#39Earlier quoted context omitted.
The problem would be to define what is considered a successful outcome, measurable by an automated system.
Indeed, even if you decode the supposedly "cracked" Beale letter, you get nearly complete gibberish: ihaie depos otedi nthec opntt olBed oorta boupf ourmi lesfr ombul ordsi nanep caiat ionor iault sipfe stbel owthe surla csoft hhgto undth sfotl owing artic issbe aongi ngjoi otltt othep artfe swhos lnamf sateg iieti nnumb erthr ffhtt ewith https://nibot-lab.livejournal.com/tag/beale%20ciphers It's almost certainly a h…
```cpp #include #include #include #include
using namespace std;
char quirkdecode(int i, vector dict);
int main(int argc, char argv) {
// Load the dictionary
vector dict;
ifstream dictstream("doi.txt");
string str;
while (dictstream >> str)
dict.push_back(str);
int i, j=0;
while (cin >> i) {
j ++;
cout
}char quirkdecode(int i, vector dict){ int delta=0;
if (i==155) return 'a';// Beale Paper DOI has extra 'a' in "institute a new government"
if (i>155) delta-=1; // Compensate for missing 'a' in doi.txt
if (i>=242) delta+=1; // 241 decrypts correct 246 not so delta +1 @ [241-245]
if (i>=480) delta+=10; // 466 decrypts correct 485 not so delta +10 @ [267-285] known misnumbering
if (i>=510) delta-=1; // TODO presicely ocate
if (i>=621) delta+=1; // 620 decrypts correct 643 is not so delta +1 @ [621-643]
if (i>=667) delta+=1; // 666 decrypts correct 807 is not so delta +1 @ [667-807] ? double check ??
// Hardcoded Jokers: NOTE 811 and 1005 are also the highest used codes, so it DOES seem to be intended as real
if (i==811) return 'y' ; // fundamentallY
if (i==1005) return 'x' ; // seXes
i+=delta;
if (i
}
```which gives:
``` ihave depos itedi nthec ounty ofBed forda boutf ourmi lesfr ombuf ordsi nanex cavat ionor vault sixfe etbel owthe surfa ceoft hegro undth efoll owing artic lesbe longi ngjoi ntlyt othep artie swhos ename sareg iveni nnumb erthr eeher ewith thefi rstde posit consi stcdo ftenh undre dandf ourte enpou ndsof golda ndthi rtyei ghthu ndred andtw elvep ounds ofsil verde posit ednov eight eenni netee nthes econd Wasma dedec eight eentw entyo neand consi stedo fnine teenh undre dands evenp ounds ofgol dandt welve hundr edand eight yeigh tofsi lvera lsoje welso btain edins tloui sinex chang etosa vetra nspor tatio nandv alued atthi rteen rhous anddo llars theab oveis secur elypa ckedi niron potsw ithir oncov ersth evaul tisro ughly lined withs tonea ndthe vesse lsres tonso lidst onean darec overe dwith other spape rnumb erone descr ibest hcexa ctloc ality ofthe varlt sotha tnodi fficu ltywi llbeh adinf indin git ```
Re: 200-year-old ciphers may reveal the location of treasure buried in Virginia
#40What is the probability that a trivial variation on the decoding method results in otherwise unreadable text BUT STARTING with "sited at" ??? roughly 26^6?!?
1) I used/fixed Tobin Fricke's (@tobinfricke) doi-decode.c to first fix the indexing/versions of the Declaration of Independence. The result can be found in the thread: https://news.ycombinator.com/item?id=17337421
2) Due to the quasi alphabetic sequences in beale.1 I came to the conclusion that beale.1 is in fact just scratchpad notes containing fragments of look-up table to use while encrypting, so is not the location file. Bummed at the lack of a location file, I just pressed on out of curiosity for the names file (beale.3)
3) I next tried some trivial variations on the cipher concept (second letter of each word, last letter etc) such that the kolmogorov complexity increase of the decoding would be nearly zero, but always got rubbish.
4) Until I tried a trivial variation (not giving yet, perhaps after convincing myself it is absurd coincidence), giving "sitedat...." with "..." being rubbish text.
EDIT1: the same decoding also contains "twograil" somewhere in the middle, but not as convincing, does "two grail" signifiy something in the area?