Pages

Sunday, July 6, 2008

If you want any girly mixers, bring them yourself!

cosmo.jpgAlright, folks, let me put it to you plain.

If you want your cocktails in the classic style, you've come to the right place. Boston shaker, strainer, bar measure. Two parts base, one part sweet, one part sour. Ice. Gin, vodka, Bourbon, Cognac, tequila, rum, Scotch, and a couple of blended whiskies from here and there. I get really skittish around infused vodkas, but I've got citrus in my collection and might add some of the stuff that Hanger One is putting out -- particularly the Kaffir Lime. I'd like to try that with a lemongrass infusion or a lemongrass syrup. One of the few fancy and modern cocktails I've had lately was a surprisingly well balanced lemongrass martini.

So I'm not trying to say that any cocktail invented since the 2nd World War is a bad idea. Despite the fact that most of my standards predate the 1st World War, I am open to change.

manhattan-cocktail.jpgBut I will tell you right now that nothing kills a good drink like an excess of sugar. Sure, sweet means easy drinking. And easy drinking means a lot of drinks sold to inexperienced drinkers used to soda pop and liquid desserts from Starbucks. But sweet also means a hard crash and a worse hangover when your body is dealing not just with the nasty metabolic byproducts of the booze but the glycemic slash-and-burn and dehydration brought about by all that sugar.

There's also a glorious branding force at work -- liquor is hip and fashionable and making a signature drink with a signature base is all the rage -- regardless if the flavor profiles fit or not.

So KISS rules again -- keep it simple and use good ingredients. Splash in some fun stuff for color or throw on a sugar rim or a quick squeeze of simple syrup.

But good distillates -- and not fruit drinks -- are the heart of a good drinking cocktails.

There are plenty of place still mixing a good drink. Ask them what goes into their gimlet. If it involves Rose's Lime Juice, stay away. Ask them what goes in their Sidecar. If it involves sours mix, stay away. Order a Manhattan, one of my great evaluative drinks. If it tastes of vermouth more than whisky, ask them to use less vermouth.

A footnote on Manhattans: I make mine with Bourbon instead of rye, which adds a little more distinctive and smoky taste. That's not traditional, but has increasingly become the custom, one change I support (see, I'm not a complete curmudgeon!). But the vermouth:whisky ration is optimum (to me) somewhere around 1:4. I also occasionally make mine with 1/2 sweet vermouth and 1/2 dry vermouth, though getting those quantities right is tricky so I usually am lazy and just use sweet.

31BBVT5C13L._SL500_AA280_.jpgIf you're in Edmonds, the best drinks come at the new-managemented Shell Creek. Down in Seattle, the best mixed cocktails I've had recently are at The Oceanaire and (perhaps surprisingly) Palomino. I've never visited the bar at Sea Star in Bellevue, but I know a couple of folks who work there and can guarantee that the drinks will be top notch.

But what matters above all is that the guys or gals behind the bar care -- that they understand how bartending was once a career, a noble profession with immense traditions and oral histories and skills beyond knowing how to flip a shaker like in that irritating Tom Cruise movie, and not just a way to pay the bills through college. If they understand this and believe that it can be so again, stay for a drink.

Or, if you're having a hard time finding a barstool that fits, stop on by, I've always put some ice in the shaker for a guest.

An interesting discovery

51EJ2XMYMEL._SL500_AA240_.jpgEvery so often an old interest gets dragged up out of the background and brought into the light again. And in that background-to-light-dragging process, I always find that I learn something new about that area of interest or am able to attack it with some new perspective.

Well over the past few weeks, I've rediscovered the world of "crypto" with a certain enthusiasm. And as I've come back to visit those old friends, ADFVGX, NEMA, Dockyard, and the SX-52, I've looked at some of them with a new light. And I've discovered new companions (even if I don't like them very much) like the Rasterschlüssel'44.

And here is another new one -- one that has been known about since the mid-1990's but that I never paid attention to: the Reihenschieber. It translates as "series slide" and both the word and the device bear a noticeable (and noteworthy) relationship with slide rules (Rechenscieber). This interesting device was developed during the 1950's, put into use in the German armed forces in 1957, and used for a decade or so to encrypt information described as "up to top-secret." Since cipher technology of the cold war tends to be much harder to learn about than that of the second, this device holds a lot of potential to see how cryptographic thinking advanced in a decade or two.

Note that the Reihenschieber was developed before the revelations about British cryptanalytic success during the war were made public in 1977 -- and therefore may not embody the full state of the art that the agencies privy to that information had at hand. It was also an artifact of the early Bundeswehr, and so developed under some significant restrictions as imposed by the allied powers.

Note that in this article I'm choosing, unusually, to analyze the cipher and perform my back-of-the-envelope cryptanalysis first, rather than opening with a description of the device and its operation. I'm working primarily from John Savard's excellent description which, never the less, contains some areas of ambiguity on the actual use of the cipher. I haven't yet decided to spring the $35 for a reprint of the 1996 Cryptologia article that is the definitive source of Reihenschieber information and until then, my knowledge of its implementation may remain a little sketchy.

The result of these advances and constraints is an interesting device -- half mechanical crypto and half classical. It is a mechanical series of rods that generate a (hopefully) pseudorandom number sequence. This pseudorandom sequence is in turn used to select which column (from one of ten) and which table (one of two) is to be used to perform a simple substitution of each letter in the plaintext.

Does this sound familiar? A polyalphabetic substitution where the cryptographic strength lies in the fact that the alphabets change frequently? Think about how an Enigma machine works -- or any other machine of the period for that matter. At any given point, it consists of a single arrangement of input letters to output letters. Press a key, your input letter gets enciphered according to that arrangement, and then a new arrangement is selected for the next letter using a very complex mechanical (or electro-mechanical) scheme.

Effectively, this is the exact same method used by the Reihenschieber. Instead of a series of wheels, pins, cams, and wires that generates an ever-changing series of substitution alphabets from a vast menu (in the case of some of the machines the number of possible alphabets could be 26! or more -- 4.032914611266057x10^26 if you like), the Reihenschieber select one of twenty pre-generated alphabets according to a complex (but nothing like Enigma or its friends) series of sliding rods.

This is also similar the Dockyard cipher as described in an earlier post. Dockyard also used twenty (or in later versions thirty) substitution tables, but only five of them at any time and they were combined with an interesting fractionation step. Note that fractionation is very out of favor by this point -- apparently the statistical camouflage it offers was finally found to be more illusory than effective once a sufficiently large amount of traffic was generated (though some fractionation is used in the great Soviet spy ciphers).

It might seem that this new cipher would be more like Dockyard than the machines by virtue of its more limited pool of alphabets. This may not be true, however. First off, the 20 alphabets are all in play at any given point, not just five per day. And since the selection of alphabet does vary in a pseudorandom fashion (rather than repeating cyclically through out the message) it will be much more difficult to amass the required traffic in each alphabet that is necessary for a break. Given that a new substitution table is issued monthly, given good precautions the tables may not themselves be broken in time.

The real security in any such cipher, however, depends not on the simple substitution that takes place for each letter, but on the process by which the alphabet varies from letter to letter. And here is where another offsetting advantage might play into the hands of the Reihenschieber. Machine based systems generate both their alphabets and their alphabetic sequences on the fly, in the field, according to a pre-determined algorithm. Even the most secure such systems have historically possessed flaws, unknown or accepted by the designers, that result in patters, repeats, or other notable variations from the truly random.

The American SIGABA was probably the high point of this era, largely because it separated the process of varying the alphabet from the process of creating that alphabet. But I get ahead of myself. Musings on the amazing SIGABA and the equally amazing William Friedman will have to wait for a different day, one probably embodying bourbon and not coffee.

2423PH702C.jpgMy thought, returning to our cipher-du-jour, is that the alphabets used by the Reihenscieber have the potential to be much more carefully selected and vetted than those created internally by the rotor machines. Similarly, the combinations of numbers on the rods that arrange to select the alphabet tables are selected in an office back home -- and therefore have the potential for considerably more algorithmic complexity and analysis to eliminate weak combinations. Heck, in 1957, they might have even used one of those new computers to do some of the work!

Quality over quantity, in other words.

That said, the Reihenschieber did not have a flawless mechanism for generating the pseudorandom sequence that governed substitution table selection. And now, at last, we must with our imperfect understanding, attempt to actually analyze the device.

RS.jpg


As you can see, we have a series of ten imprinted rods (I can't help but picture them as chopsticks!). These rods are arranged according to a procedure (and here we hit the point where my information sources break down) that involves a daily key assigned by HQ (or whomever the responsible cryptographic agency would be) and an area key that is either similarly assigned by HQ or else is selected by the cipher clerk much in the manner of a message indicator. Given the name "area key" I also wonder if it might not be a centrally assigned key, but one that is assigned based on regional sectors, communications nets, or levels of security. In other words the daily key remains constant for the entire Bundeswehr for a given 24 hour period but quartermasters operating near Bonn would have a different area key than artillerymen operating in the Rhineland.

In any case, the daily key consisted of ten letters A-Z that governed the selection of ten sticks out of 26 and the order in which they were placed in the frame (the ten chopsticks were labeled, as you can probably guess, A-Z). The area key, combined with a second numeric portion of the daily key, to specify which of the four sides of each stick was placed to the front as well as the lateral position of each stick relative to its peers.

The exact method remains obscure, but involves the group of lower case letters towards the left side of each stick. They were aligned to a sequence generated, somehow, by a combination of the puzzling area key and the ten digit numeric daily key. This sounds complicated, but I can picture the process taking but a few seconds for an experienced operator. Its the kind of simple operation that can be performed in the field, by flashlight, in the middle of the rain. Notice that this system has no electrical requirements and no "moving parts" in a mechanical sense?

After these alignments, the small grid section would be slid along the large table of numbers that was produced by the arrangement of the sticks. At each stopping place, the digits visible in the windows would be used, in pairs, to select the encipherment table. One digit would be used to select one of the ten columns in a given table, the second digit would select between one of two tables (0-4 = table one, 5-9 = table two). Note that (other than the first and last digit of the sequence) each digit was used twice: once to select a table and then for the next letter to select the table.

Unfortunately, I don't yet have access to the full details of this system that are often as revealing as are the details of the algorithm. How were indicators created and transmitted? How were numbers handled? Were there provisions for using separate codewords for common names (much like RS'44?). I'm particularly interested in the question of message indicators and the actual role of the area key. Since the analysis of this sort of cipher tends to depend on getting a "depth" of multiple messages enciphered with identical alphabets, were there provisions to prevent this from happening? There are a staggering number of ways to arrange the sticks (I haven't done the math on that yet) so there should be an ability to support some sort of message variable key.

In any case, this cipher is an interesting hybrid. It really is a "paper Enigma" -- a non-mechanical attempt to mirror the sort of cipher scheme that was used by rotor machines. I suspect that, despite the vulnerabilities of rotor machines, they were well understood and that the national security agencies of the infant West Germany liked the well understood security that they offered. It is almost a paper-and-pencil cipher, but has the potential to offer much more security than anything else of that era. We shall see.

Saturday, July 5, 2008

Werftschlüssel and Rasterschlüssel '44

180px-Enigma.jpgIt is now time for the second and third of my promised favorite ciphers. And, just to let you know, I am now planning on creating an entry for Vic cipher and some of the other very elaborate spy ciphers of the cold war. Operationally Vic and its cousins were not effective for the field -- requiring too much precision, time, and care and training for a field radio operator or cipher clerk who may well be working under fire. The importance of ensuring that ciphers can realistically be used in field conditions sometimes escapes the notice of the experts charged with developing cipher systems. As we will see, this weakness played an important role in undermining one of the ciphers planned for study today. ADFGVX, on the other hand, certainly can be implemented under field conditions.

I feel I proved this when I wrote my last crypo blog entry -- the examples were all typed while riding the bus!

The Werftschlüssel is more generally known by its anglicized name "Dockyard Cipher" or just "Dockyard." It was the standard mid-grade code used by the German navy during WW2, a companion to the famous Enigma machine that was better suited to auxiliary vessels, small units, and others situations where the expensive and valuable Enigmas could not reasonably be issued. Dockyard is best known for the role it played in routine breaking of Enigma ciphers. Always ready to help out their foes with some bad practice, the German navy would often send identical (or at the very largely similar) messages in the two systems. The easier-to-break Dockyard would yield the known-plaintext crib that was necessary for the folks at Bletchley Park to break that day's Enigma settings.

Dockyard was simple to implement -- the plaintext was written out in five columns (apparently there were specially printed tables to help with this process).

Using the plaintext "It was the best of times, it was the worst of times" would set up columns like this:

I T W A S
T H E B E
S T O F T
I M E S I
T W A S T
H E W O R
S T O F T
I M E S X


Each vertical pair of letters (or digraph) would be encrypted together according to one of a set of tables published on a monthly or bimonthly basis. IT would be looked up and replaced with its cipher pair, TH with its pair, WE with its, and so on. Each column would be enciphered with using the keypairs from a separate table. These columns were selected from the book of 20 or 30 columns mentioned earlier -- I don't know if the procedure was to use a daily set of columns or for the operator to select five for each message and somehow communicate that in an indicator group.

The idea of using 20 or 30 different digraph substitutions was an interesting one -- presumably intending to reduce the amount of traffic that was generated for each. The seriation step also helped break up common digraphs (e.g. the "ch" that is as common in German as the "th" is in English). Digraphic substitution is a nice way of diffusing the statistical predictability of language -- no single digraph has the same obvious statistical dominance as "e" for example. There still are trends, and with a large enough sample, they are noticeable.

The seriation of Dockyard works to further diffuse the common elements of language, but the resulting digraphs still do not have a random distribution, much as we might think that they would. The statistical frequency of individual letters and certain patterns of letter use still result in digraphs appearing more often than others. The EE pairing is more common than any other, for example, because there are simply more e's going around to possibly end up stacked on top of each other.

As a result, the Naval Section at Bletchley could slowly compile up a key for each of the tables in a set. Using the statistical procedures discussed together with some guesses about message content (all the tools of classical cryptanalysis), the tables would be recovered. Once the tables were recovered, identifying which five were in use on a given message was a relatively simple matter of frequency counts. From all of this, the Dockyard cipher was probably the greatest source of intercept information to the Allies about German naval movements -- particularly considering its role as a source of Enigma plaintext cribs. From 1941 to 1945, about 33,000 dockyard messages were intercepted. 90% of them were read the same day they were intercepted...

The second cipher of the day, Rasterschlüssel '44, was not quite as thoroughly broken by the Allies, but more because of its late arrival than because of its security. An unfortunate example of the distance between field operators and back-room-thinkers, RS44 was issued with ambiguous instructions and a complicated operational procedure that resulted in frequent resending of messages, slow operation, and frustrated cipher clerks. And since frustrated cipher clerks have been known to violate procedure and just send the damn thing in the clear once in a while, RS44 ended up as its own worst enemy.

Picture 1.jpgThough I titled this thread of blogging "My Favorite Cipher," and I am a big fan of ADFGVX and find something nifty about the simple tables of Dockyard, I don't particularly like the Rasterschlüssel. It is a transposition cipher alone -- something which a certain truthiest superstition tells me can't possibly be as secure as a mix of transposition and substitution (remember -- diffusion and confusion) as used by ADFGVX. How can it be, I just feel, that a cipher that preserves all the right letters can have the security of one that changes them? Just move then around -- like a big word scramble!

I know, it is wrong, but I can't help but feel that way...

RS 44 was a fairly complex table based transposition. The grid above was specially issued -- one per day -- to all units using the cipher. The clerk would randomly select a square to start in and begin filling in the message in the open spaces, working from left to right, wrapping down columns and back up to the beginning if the message ran off the bottom of the printed grid. The grid was printed on cardboard and was placed behind a thin "flimsy" printed with a grid that let the light and dark squares show through. That way the clerk knew what spaces could be filled in and what couldn't. Once the message was filled in, taking off began.

Using a complex and troublesome formula, the cipher clerk would then determine the column to begin taking the message text off. This process would proceed from top to bottom, moving from left to right as each column was completed. Once the leftmost column was transcribed off, the process would start at the rightmost and work through until the message was done. Indicator groups would indicate both the starting position of the message and the column from which the taking off to the final cipher text began.

That's it. This has been described as the ultimate hand field cipher -- but I can't help but feel a certain "that's it?" at the end of the procedure. But yeah, that's it. I suspect that we see another case of the "possibly combinations" fallacy. Based on the formula that created the daily grid tables, there was an absurdly large number of possible combinations. More, in fact, than rotor settings on the Enigma machine.

And again, German cipher designers let themselves be overwhelmed by the mathematical possibilities of a system and ignore implementation details.

I look back on these two, on Dockyard and RS'44, and can't help that they lack the certain elegance of ADFGVX. RS'44 in particular relies on the tired old misconception that a larger number of possibilities equates with increased security. Dockyard has the cleverness to use multiple keys within each message -- effectively decreasing the traffic in each substitution key. Unfortunately, it still generates a significant amount of traffic in each table. The designers of Dockyard probably thought that each combination of tables would effectively constitute an entirely new key (and picking 5 of 20 tables yields 1,860,480 possibly combinations, 5 of 30 yields 17,100,720).

Each table in dockyard was composed along the lines of some fairly strict rules. Any given letter pair and its cipher were reciprocal -- if EH enciphered as DG then DG enciphered as EH. No letter from the plaintext pair could appear in the ciphertexext pair. For the plaintext digraph ML the cipher digraph could contain neither the letter M nor the letter L in either position. This dramatically limited the possibilities that needed to be tried and gave the cryptanalyst a few extra clues. It simplified the job of creating the tables and sped things up for the cipher clerk and helped to introduce some self-checking features into the cipher. Nice idea -- but at a cost in security. A cost that was probably accepted in light of the massive number of tables available (or rather, of the massive number of combinations of tables that might be used in any given day's key).

Since the cryptanalysts at Bletchley learned to look at each column as essentially a separate entity, they were able to aggregate samples large enough to bring statistical tools to bear. With the result, as mentioned, that Dockyard was despite good intentions one of the most well read of German wartime ciphers.

Thursday, July 3, 2008

What do I collect?

My former boss, a man about whom tact and professionalism demand that I say no more, used to ask me "what do you collect?" The fact that has asked me this question at least three times during our interview process and my short ten month's tenure as his employee should have told me something about how much interest he actually had in his staff's well being, but that's water under the bridge (or whisky down the throat, if you want a more accurate image of that time).
But his question was an interesting one because, in many ways and for all his flaws, he was an astute observer of human nature and had a disturbingly accurate arsenal of stereotypes at his disposal. His question was the product of an assessment that people with my personality inevitable collect something. Typically something obscure or marginalized. So what is it?

Action figures? No, but it fits the type, doesn't it?

Slide rules?  Obscurely enough, I do own to, one a glorious Faber 2/83N arguably the finest slide rule ever produced, but I can't see myself investing in dozens, seeking out obscure models for Deitgzen, Hemi, Pickett, Aristo, or K&E.

Calculators? I thought about that one -- and I do want to get an HP-25 or an HP-67 and I'd gladly give a nut to have an HP-65 in my collection. Space (and budget) permitting, I'd love to have one of the RPN members of the HP-98XX family and an HP-9100 would be amazing... But I don't actually do these things.

Nor have I built my cryptology collection beyond the one NEMA machine. No Enigma, no little Hagelin wheel machines, just the one. There simply isn't enough on the market that is affordable to make it possible.

Books? Sure, I have hundreds, but its not really collecting. There is no purposeful seeking out of missing volumes, pride in obtaining a rare edition, etc. I love and treasure them, but as tools.
Vintage airplanes in a hangar somewhere, smelling vaguely of fuel and paint? No. I wish...but lacking Paul Allen's budget I need to keep my collecting under control. But what'd I'd give to have a half dozen classic aircraft sitting somewhere. I'd spend all my weekends lost in complex fantasies, sitting in the cockpits with a sandwich and a beer, playing with all the knobs and levers.
But wait a second (and my inductive writing style is finally reaching its almost inevitable conclusion), I can do that, only without the cockpit to sit in! I have it, the thing I collect: vintage aircraft manuals. I do carefully seek out missing spots, I genuinely feel a thrill when I get an obscure or rare item to add. I've done it for years, but with the internet, over the past three years the collection has grown from a half dozen to hundreds. Don't ask me how many.
I've got pilot's manuals or other documentation on everything from the obscure (BTD-1 Destroyer) to the pervasive (Boeing 737). From the doomsday (B-52) to the innocent (Cessna Mustang). From the complex (C-17) to the simple (Staggerwing). From the secret (F-117) to the well known (P-51). From the high performance (SR-71) to the mundane (Twin Otter).
They are fascinating for student of technology, tracing the evolution of one particular segment from almost its dawn (I don't think that Orville and Wilbur wrote a lot of documentation...) to its very cutting edge. There is plenty of potential for Walter-Mitty moments of mental digression. There is a chance to really get under the skin of some historic airplanes and, by extension, of those who designed and flew them.

Some of my favorites are from the late 1940's on through the middle 1960's. This era gave us amazing advancement in aviation -- the stimulus of the war pushed the envelope and then then period of consolidation when that amazing surge gathered itself up and pushed the electromechanical, slide rule, vacuum tube, and aluminum stage of engineering artistry to its conclusion.

It was an era when the ballpark sums of the slide rule demanded filtering through the mind of an inspired engineer. It was a time when a single gifted brain (Kelly Johnson, Edgar Schmued, Ed Heineman, Frank Whittle, Werner Von Braun, and a half dozen other titans) could shape a design from intuition and lead a project by sheer force of will. The resulting products were often bedeviled by vices and idiosyncrasies but pushed the state of the art at a pace unequaled since. And they rewarded the deft hands of a skillful pilot (and punished the ham fists of a clumsy one). It was an era when pilots were real pilots, engineers were real engineers (and let's not forget the small furry creatures from Alpha Centuri -- they were real too!).
For a variety of reasons, some of my favorites are not the actual flight manuals, the detailed collections of technical specifics and procedures, but the training manuals provided to introduce pilots to their new mounts during the 2nd World War. Thin on technical details, they never the less provide a wonderful zeitgeist. A smilingly benevolent picture of General Arnold on the inside cover, cheerful anecdotes of field successes, little humorous drawings of wayward Ensigns of Lieutenants who used too much throttle on the runup and the comic fate they suffered, and the pervasive use of all those wartime epithets of "Jap" or "Jerry" or "Hun" or whatever. The writing style is half legitimate indoctrination and half propaganda. Always positive on the friendly side, always optimistic. As I once put it in an email to a fellow collector:I love those training manuals from the 1940's and early 1950's, with their snappy and cheerful style. Phrases like "Your Corsair is a snappy flying bird!" instead of "Your Corsair will have nearly uncontrollable roll characteristics in the landing pattern!" And, if it is an AAF manual, the smiling face of Hap Arnold on the inside cover...kind of fatherly, experienced and stern yet supportive of young 2nd Lieutenants...

The drawings, moving in to the 1950's just got better for a time. The other picture above is from the pilot's manual to an F-89, an obscure 1950's all-weather interceptor. What more could I say? So overtly sexist as to be comical, aimed at the entirely male audience of military aviation. But again, there is a potentially telling look at the era and the community here.

Its not just the irony of that important information stacked buxom brunette. The technology of the late 1950's is also something I enjoy reading about. It was "chunky" in a way that made it easy to understand. You could truly look at a diagram of an airplane's
 flight control system (and the comparatively rare service manuals are the place to go for this) and understand what things did and how they worked.

Eventually things get less interesting. The Navy, in particular, starts to carve the information up into classified and non-classified sections. The aircraft, military and commercial, get sufficiently complex that the reading gets denser and denser. Still fascinating, from the airplane lover standpoint, but no longer the full retro experience on top. Thing hit their nadir, probably, in the Navy's current manual for the F/A-18, a volume so dryly procedural and simultaneously obtuse and neurotically obsessed with minutiae as to read like Tolkien's Silmarillion, only without the elves. Boeing's current commercial offerings are no better -- the 767's and 777's reading more like giant VCR manuals than the sort of in-depth technical examination that I enjoy -- and I tend to believe a qualified pilot needs. It is as if the F/A-18 manual substitutes prepared drills for every contingency for actual understanding and the 767 and 777 manuals are afraid of spilling any corporate secrets.

Part of this is increased complexity. The current generation of aircraft are incredibly complex but largely self monitoring. But, that said, Airbus actually produces significantly more interesting training documentation than Boeing does.