Google Search

Showing posts with label British. Show all posts
Showing posts with label British. Show all posts

Monday, August 19, 2013

British cryptographic hacking from WW2 – how well would *you* have done?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

If you were taken prisoner and wanted to send messages home right under your captors' noses, what would you do?

You don't have access to a computer or email, not only because you're a captive, but because they haven't been invented yet.

You know that your captors will only let your letters out if you write convincingly and fluently about largely inconsequential things, and give a positive impression of how they are treating you.

And you know that if your letters too obviously contain a secret subtext, you might be shot, or worse.

Worse than being shot because the enemy might let you carry on writing letters for a while, milking them for intelligence about your countrymen and your fellow captives, and then shoot you and your chums.

? That's what happened to Mary, Queen of Scots, though she was beheaded, not shot, and her co-conspirator Babington was hanged. Elizabeth's spymaster Walsingham was able not only to read their traitorous correspondence but also to forge messages of his own to extract more information from the conspirators.

If you were a British captive in a Nazi prison camp during the Second World War, like Sub Lieutenant John Pryor of the Royal Navy, you might well have used a code devised by No. 9 Intelligence School.

Selected officers were trained before leaving Britain in what we would today call steganography, the art of hiding one message inside another.

As a trained steganographer, you had a code number, such as 45, which told the decoding staff to skip four words ahead, then five, then four, and so forth, when extracting the hidden text from your letters.

This gave a competent coded letter writer just enough "noise words" to create a fluent and believable narrative to surround the secret message.

It's not as easy as it sounds.

Let's try it out with this fiften-word bulletin:

INCREASED RAILWAY MOVEMENTS WITH 24 HOUR ARTILLERY AND AIR COVER, GUARD DOUBLED, BUNGALOWS SEARCHED DAILY

To make things a little less obvious to the German censors, the words from the hidden message were written out of order.

You imagined a rectangle made up of sufficiently many imaginary tiles to hold your message, say 5x3 for a 15-word message.

You mentally filled the rectangle diagonally, moving upwards from the bottom right, with the numbers 1 to 15.

Then you inserted the secret words into your letter in the numeric order given by reading the rectangle naturally from top to bottom.

If your code number was 45, your codewords would be inserted as the fourth word, then five words further on, then four, and so on.

So, your cover letter would need to cushion and contain the secret message as follows:

. . . DAILY . . . . SEARCHED . . . DOUBLED . . . . AIR . . . HOUR . . . . BUNGALOWS . . . GUARD . . . . AND . . . 24 . . . . MOVEMENTS . . . COVER . . . . ARTILLERY . . . WITH . . . . RAILWAY . . . INCREASED

Give it a go! By adding just 52 words of your own, see if you can write a convincingly innocent-sounding paragraph about your most recent week at work.

? If you take on the challenge, why not post your paragraph as a comment below? (You can post anonymously if you like.) But be warned: it's harder than it looks!

What we now call in-band signals were used for four special purposes:

You signalled the size of your word-order rectangle by the lengths of the first two words in your letter, such as opening with Every day to signify a 5x3 rectangle and thus a 15-word secret message.You used the codeword the to switch from codeword mode into "spelling" mode, a special but cumbersome system for spelling out words that could never realistically appear in a letter home.

You used but as an extra codeword after your secret message as a double-check that the message was complete and thus to reassure the reader he had decoded correctly.You included a telltale mark, such as writing the date in a special way or underlining your signature, to signal to MI9 that the letter contained a hidden message. (This avoided wasting time battling to decode messages that were just plain messages.)

Did the system work?

Apparently, it did, because academics at the University of Plymouth have just decoded a message sent by the abovementioned Lt. Pryor from his captivity at the Marlag und Milag Nord prison camp in Northern Germany.

What we don't know, of course, is whether the secret messages in a cache of letters now kept as a memoir by John Pryor's son, Stephen, were ever successfully decoded by MI9.

That still really is a secret!

Follow @duckblog


View the original article here

Thursday, September 13, 2012

'Assange to be ARRESTED' - British police in document dissemination gaffe

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Look out!

Hot on the oh-dear-that-wasn't-supposed-to-happen heels of the organisation which allowed a password-and-a-half to be broadcast on Polish TV...come the British police.

A uniformed police officer at a recent Assange-oriented press briefing fell under the lens of a Press Association snapper. The officer was carrying a clipboard, and zooming in on the paper under the clip revealed a meaningful snippet of what looks like the hapless copper's dutifully-taken meeting notes.

Under the pre-printed headings RESTRICTED - DECISIONS is a half-page of handwritten text partly obscured by the officer's arm; two separate pictures allow the first two sentences to be reconstructed in their entirety, as shown below:

The revelations in the leaked text are hardly surprising: Assange is to be arrested if he leaves the embassy. ARRESTED. Who would have thought?

But the nature of the leak - old-fashioned handwriting captured and disseminated digitally - ought to be a reminder to us all.

In the words of our very own IT Security DOs and DON'Ts guide, which features ten handy poster-sized tips you can print and pin up around the office:

Don't leave printouts containing private information on your desk. Lock them in a drawer or shred them. It's very easy for a visitor to glance down at your desk and see sensitive documents.

Keep your desk tidy and documents locked away. It makes the office look more organized, and reduces the risk of information leaks.

Remember: you don't need to parade your confidential stuff in front of a press photographer for it to be at risk of getting snapped up. Nokia's latest mobile phone, for example - and this is a phone, remember! - sports a 41 megapixel camera. (You read that correctly. Forty-one.)

Any documents lying anywhere in your office are an easily-accessible target for visitors, cleaners and passers-by.

(The Sophos IT Security Toolkit is a free download. No sign-up, no registration, no email address required.)

http://twitter.com/duckblog
-


View the original article here

Wednesday, May 23, 2012

British hacker jailed for one year for breaking into Facebook account

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Southwark Crown Court has sentenced a 21-year-old British man to a year in prison after he admitted hacking into the Facebook account of a US citizen, and accessing private messages.

Gareth Crosskey, of the village of Sompting, near Lancing, in West Sussex, was jailed yesterday after admitting he had hacked into a private Facebook account.

Scotland Yard. Image from Shutterstock

The hack was initially reported to the FBI, who traced the source of the unauthorised access to the UK. The Metropolitan Police Service's Police Central e-Crime Unit (PCeU) arrested Crosskey in July last year, and took away from his home computers and other storage devices for analysis.

Crosskey was subsequently charged with two offenses under the Computer Misuse Act

A statement issued by the PCeU underlined their hope that the jail sentence would act as a warning to others that Facebook hacking is an offence that will be taken seriously by the authorities:

"The PCeU are working to detect and bring before the courts those responsible for this type of offence. Today's result should act as a deterrent to any individuals thinking of participating in this type of criminal activity."

http://twitter.com/gcluley

New Scotland Yard image courtesy of ShutterStock


View the original article here

Monday, May 14, 2012

Thatcher is NOT dead. False news of former British Prime Minister's death spreads on Twitter

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Margaret ThatcherIf Margaret Thatcher was to die, would you expect the news to first emerge from the French media rather than the British?

And, if you were a French media outlet actively posting news via Twitter, would you believe an unverified account claiming to be Carla Bruni if she was the one to reveal the news of the demise of Britain's former Prime Minister "officially"?

Unfortunately, @LesNews did mistakenly report the death of Margaret Thatcher this evening - causing rumours of her death to sweep across the service, but strangely no confirmation from any other news outlets.

A little digging revealed that the news appeared to have originated from an unofficial-looking account claiming to belong to Carla Bruni, the wife of recently deposed French president Nicolas Sarkozy.

False Carla Bruni tweet

The @CBruniOfficial Twitter account, which you will notice does not carry a "verified" icon, announced the "news" of Thatcher's death, claiming that it had just been announced by the British Ambassador. I don't know that the real Carla Bruni isn't in charge of that account - but I must admit that I would be very surprised if she was.

Nevertheless, the tweet was clearly enough for @LesNews to rebroadcast the news to its 100,000+ followers, causing the story to spread worldwide.

Fortunately some news agencies were a little more skeptical, including CNN's Gill Penlington who contacted Thatcher's official spokesperson and debunked the claims.

All that remained was for @LesNews to sheepishly delete its original tweets, and post up an apology.

Les News apologises

Media agencies are struggling to cope in a world where news breaks in an instant, and can be shared across the world in seconds via social networks. The pressure to be always up-to-date can be so great that false stories can spread like wildfire.

Those of us who are interested in computer security know all too well the importance of not believing everything we read, not rushing to click on a link nor open an attachment without thinking about the possible consequences. Maybe @LesNews and others could learn something from that.

Update: @mmesarkozy appears to be the authentic Twitter account for Carla Bruni. Judging by her low number of tweets (at the time of writing she hasn't posted anything since February 2009) she isn't an enormous fan of twittering.

Follow @gcluley

View the original article here

Friday, June 24, 2011

Hackers target British anti-crime agency website

WASHINGTON (AFP) – Hackers who have hit the websites of the CIA, US Senate, Sony and others during a month-long rampage claimed on Monday to have knocked the site of Britain's Serious Organized Crime Agency (SOCA) offline.

"Tango down - soca.gov.uk - in the name of #AntiSec," the hacker group known as Lulz Security said in a message on their Twitter feed @lulzsec.

"Tango down" refers to the elimination of an enemy while "AntiSec" refers to "Operation Anti-Security," a campaign launched by Lulz Security against government websites.

Computer security firm Sophos said the SOCA website was sporadically inaccessible on Monday following the Lulz Security attack.

Sophos said it appeared to be a distributed denial of service attack in which a website is overwhelmed with traffic and becomes sluggish or unresponsive.

Lulz knocked the CIA's public website, cia.gov, out of commission for about two hours last week using a DDoS attack and also hacked into the US Senate's public website.

The group has also released tens of thousands of user names and passwords stolen from Sony and other sites.


View the original article here

British police arrest alleged hacker - Albany Times Union

LONDON -- The police in Britain arrested a 19-year-old man in connection with digital attacks on businesses and government agencies "by a single hacking group," the Metropolitan Police said Tuesday in a statement.

The police did not identify the man (Deutsche Presse-Agentur said his name was Ryan Cleary) or the hacking organization. Suspicion immediately fell on two groups: Anonymous, a shadowy international network of computer hackers, and Lulz Security, a group that has claimed responsibility in recent weeks for attacks on the websites of the Central Intelligence Agency and the U.S. Senate as well as Sony and, on Monday, the website of a British agency that combats organized crime.

The arrest resulted from a joint investigation by a British cybercrime unit, local police and the Federal Bureau of Investigation into attacks on "a number of international business and intelligence agencies," the police said, without naming specific targets.

The British police said man was being questioned in a London police station and was suspected of violating several British computer and fraud laws. After his arrest, they said, officers searched a home in Wickford, about 35 miles north of London, and turned up material that police said was under examination.

They said the search was conducted late Monday night.

Attacks this spring on the websites of several companies, including Sony and Bethesda Softworks, a gaming site, exploited holes in Internet security systems that are meant to protect hundreds of thousands of private user accounts. In a letter posted last week, Lulz Security said that it was now teaming with Anonymous. "Prime targets are banks and other high-ranking establishments."

Lulz Security seemed to dismiss speculation that one of its hackers had been the target of the British arrest.


View the original article here

Thursday, June 23, 2011

Hackers bring down British police Website

WASHINGTON/LONDON (Reuters) – Hackers temporarily knocked offline a Website run by the British police Serious Organised Crime Agency (SOCA), which targets organized crime in Britain and overseas.

Lulz Security, a loosely aligned hacker group which said it brought down the SOCA Website on Monday, has gone after a long list of government and corporate Websites in the past month. Like the others, it was likely a denial-of-service attack where Lulz hackers bombarded the site with so many messages that it went offline.

"We are aware of claims that the SOCA Website has been attacked. The picture is not clear at this time but we are investigating the matter with our service provider," said SOCA spokesman Richard Sellors.

Lulz also hacked into a U.S. Senate server, and claimed responsibility for temporarily knocking offline the CIA's public Website.

In a posting on Sunday, Lulz Security declared that the "Lulz Lizard battle fleet is now declaring immediate and unremitting war" on government and whitehat security.

As part of that, Lulz, which derives its name from the plural variant of Internet slang for "laugh out loud," urged its followers to hack into and deface government Websites.

"Top priority is to steal and leak any classified government information, including e-mail spools and documentation. Prime targets are banks and other high-ranking establishments," Lulz said in the statement on Sunday.

Lulz said it was working with Anonymous, a second international group of hackers.

The groups' stated goals have been murky. In the past, Anonymous has sought to support Julian Assange and Bradley Manning, who face charges after releasing U.S. government documents as part of Wikileaks.

Lulz has also sought to punish Sony Corp for failing to secure data but did so by releasing the data of Sony customers, exposing them to potential identity theft.

Meanwhile, a less public and more damaging series of hackers have targeted the International Monetary Fund and RSA, the security division of EMC Corp.

(Additional reporting by Georgina Prodhan in London; Editing by Gunna Dickson)


View the original article here