RSSAmplifier

Blog

Matt Blaze's Exhaustive Search

Science, Security, Curiosity

mattblaze.orgRSS feed ↗15 posts

Latest posts

The Cryptography of Orphan Annie and Captain Midnight

Badges? We don't need no badges! Between 1935 and 1949, many North American children (and adults) got their introduction to cryptography through encrypted messages broadcast at the ends of episodes of two popular radio adventure serial programs: Little Orphan Annie and Captain Midnight. Dedicated listeners could join Radio Orphan Annie's Secret Society or (later) Captain Midnight's Secret Squadron…

Testing Phone-Sized Faraday Bags

Reliable tools for the modern paranoid. Back in the not-so-distant past, if you were patient and knowledgeable enough, you could reverse engineer the behavior of almost any electronic device simply by inspecting it carefully and understanding the circuitry. But those days are rapidly ending. Today, virtually every aspect of complex electronic hardware is controlled by microprocessors and software,…

Scientists say no credible evidence of computer fraud in the 2020 election outcome, but policymakers must work with experts to improve confidence

A brief statement from my colleagues and me A PDF of this letter can be found here . See the rest of this (rather long) entry...

A Cryptologic Mystery

Did a broken random number generator in Cuba help expose a Russian espionage network? I picked up the new book Compromised last week and was intrigued to discover that it may have shed some light on a small (and rather esoteric) cryptologic and espionage mystery that I've been puzzling over for about 15 years. Compromised is primarily a memoir of former FBI counterintelligence agent Peter Strzok's…

Exhaustive Search has Moved

But "crypto" still means cryptography. You may have noticed that this blog, and my domain, is now at www.mattblaze.org . Twenty five years ago, back in 1993, I registered the name crypto.com , which I've used as my personal domain as well as to host a variety of cryptography technology and policy resources. During that quarter century the "dotcom" era came and went, but for whatever reason, I held…

How to Hack an Election Without Really Trying

Unraveling the NSA "Russian Election Hacking" story. This Monday, The Intercept broke the story of a leaked classified NSA report [pdf link] on an email-based attack on a various US election systems just before the 2016 US general election. The NSA report, dated May 5, 2017, details what I would assume is only a small part of a more comprehensive investigation into Russian intelligence services'…

When Should the Government Disclose "Stockpiled" Vulnerabilities?

Somewhere between immediately and never. Encryption, it seems, at long last is winning. End-to-end encrypted communication systems are protecting more of our private communication than ever, making interception of sensitive content as it travels over (insecure) networks like the Internet less of a threat than it once was. All this is good news, unless you're in the business of intercepting…

How Law Enforcement Tracks Cellular Phones

A brief taxonomy of wiretapping esoterica. Recent news stories, notably this story in USA Today and this story in the Washington Post , have brought to light extensive use of "Stingray" devices and "tower dumps" by federal -- and local -- law enforcement agencies to track cellular telephones. Just how how does all this tracking and interception technology work? There are actually a surprising…

Voting by Email in New Jersey

Some very preliminary thoughts. New Jersey was hit hard by Hurricane Sandy, and many parts of the state still lack electricity and basic infrastructure. Countless residents have been displaced, at least temporarily. And election day is on Tuesday. There can be little doubt that many New Jerseyans, whether newly displaced or rendered homebound, who had originally intended to cast their votes at…

Having Something to Get Spun Up About

Ten years ago tomorrow. A recent NY Times piece , on the response to a "credible, specific and unconfirmed" threat of a terrorist plot against New York on the tenth anniversary of the September 11 attacks, includes this strikingly telling quote from an anonymous senior law enforcement official: "It's 9/11, baby," one official said. "We have to have something to get spun up about." Indeed. But…

Wikileaking a Cryptography Lesson

Authentication and decryption are different. And sometimes this is important. Everything else aside, the recent Wikileaks/Guardian fiasco (in which the passphrase for a widely-distributed encrypted file containing an un-redacted database of Wikileaks cables ended up published in a book by a Guardian editor) nicely demonstrates an important cryptologic principle: the security properties of keys…

Why (special agent) Johnny (still) Can't Encrypt

One-Way Cryptography and the First Rule of Cryptanalysis. Last week at the 20th Usenix Security Symposium , Sandy Clark, Travis Goodspeed, Perry Metzger, Zachary Wasserman, Kevin Xu, and I presented our paper Why (Special Agent) Johnny (Still) Can't Encrypt: A Security Analysis of the APCO Project 25 Two-Way Radio System [pdf] . I'm delighted and honored to report that we won an "Outstanding…

Wiretapping and Cryptography Today

Report from the sky didn't fall department. The 2010 U.S. Wiretap Report was released a couple of weeks ago, the latest in a series of puzzles published annually, on and off, by congressional mandate since the Nixon administration. The report, as its name implies, summarizes legal wiretapping by federal and state law enforcement agencies. The reports are puzzles because they are notoriously…

Google Plus

I, for one, welcome our Googly overlords. A while back when I tried to sign up for a Facebook account it was almost indistinguishable from a phishing attack -- it kept urging me to give them my email and other passwords to "help" me keep in better contact with my friends. (I ended up giving up, but apparently not completely enough to prevent an endless stream of "friend" requests from showing up…

I'll be on WHYY's Radio Times today

Radio is what our grandparents listened to before there were podcasts. I'll be talking about computer security and cyberwar this morning live at 10am on WHYY-FM's otherwise excellent Radio Times show. For those who aren't up before the crack of noon, I'm told the show will also be repeated at 10pm as well as podcast online. (WHYY is the Philadelphia NPR affiliate).