PIN fraud

Apr 15, 2004 196 Replies

The 'key' to the obfuscation/encryption is the key to translate from whatever encoding is used to write the numbers as binary (assuming they are in some sort of binary code) on the magnetic stripe. It may be a very simple key but it's still a key nonetheless.

Without a hint of irony, "Tim" astounded uk.finance on 21 Apr

2004 by announcing:

Since when has that been the definition of encryption? What is the secret key used to decrypt the message on a mag stripe?

Without a hint of irony, snipped-for-privacy@isbd.co.uk astounded uk.finance on 21 Apr

2004 by announcing:

By your argument, *everything* is encrypted.

"unaltered"

"algorithm" /

There is a semantically subtle difference between what the algorithm is and what the key is.

When digital data is written on a CD it undergoes EFM (eight-to-fourteen modulation) whereby every 8 digits is 'encoded' into 14 digits to ensure you don't get over-long runs of repeated digits.

There is a table which shows which input gets translated to which output. This is not a key.

Since the EFM always translates 42 (binary 01000010) into (10010000100100) I think this is part of the algorithm. It would be feasible to have a number of different encoding tables to do the EFM, and in this case the key would be whatever you use to indicate which table to use.

Neil

"Neil Jones" wrote

Just the same as - once the key is known, it can be applied to all messages.

"Neil Jones" wrote

Yes - but *only* when the algorithm has been cracked. This is exactly the same as the situation with a key, when the "algorithm+key" has been cracked.

"Neil Jones" wrote

Call the system which uses the first key, "system1". Sure, as you say - when the enemy has cracked "system1", it can then decrypt all messages encrypted under "system1". If they then intercept a message which was instead encrypted under "system2" (which uses the same algorithm, but a different key), then they will *not* be able to decrypt that (unless they then also crack "system2").

Now suppose that you have two other systems *without* keys - "system3" and "system4". If the enemy intercept & crack "system3", this will not help them to later decrypt a message that used "system4". In fact, it'll give them even less to help with cracking "system4" than with "system1" & "system2" - because under the algorithm+key systems, the only part the enemy needs to crack in the second system is the key - they already know the algorithm used!!

No, because noone in their right mind would use the same key to encrypt all their messages using this scheme.

In cryptography the algorithm is normally assumed to be known, becasue to rely on the algorithm being secret is generally too big a risk because a) it won't be subject to peer review to fid obvious flaws you didn't spot and b) it won't stay a secret for ever. These days there is little point investing your own encrpyion algorithm - use a bublic domain scheme such as AES.

encrypted

Systems 1&2 are both system 1, with different keys.

'Only'? How hard do you think it is to guess a key in a modern encryption scheme?

In your way of doing things you have to invent 3 different schemes which are secure enough. This is not trivial. Far better to invent one really good strong scheme (better still, use a well known one as I mentioned before) and manage your keys well.

Neil

"Neil Jones" wrote

Are you suggesting that if someone used a different table to "normal" - this then being determined by a key - that, (let's call it) EFM2 or EFM3 or EFM4 (depending on the table used), would then constitute "encryption"?

But that EFM (using the usual table) constitutes "encoding".?

"normal" - this

That would appear to be what I'm suggesting, yes! It was Ronald Raygun who drew the distinction between 'encryption' and 'encoding', though.

Neil

Yes, exactly, you've got it! :-)

Writing is an encrypted form of speech. Morse is an encrypted form of writing, etc. The only unencrypted form of speech is speech itself (assuming the same language of course).

"Neil Jones" wrote

Hmmm. You can just as easily say "noone in their right mind would use the same *algorithm*(without a key) to encrypt all their messages".

Whatever you have said about different "algorithm+key" systems, can also be said about different "algorithm" systems. After all, a method+key combination is just another system - just as much as an algorithm on its own is.

"Neil Jones" wrote

Ah, so you are making *assumptions*. On the other hand, I am not! ;-)

"Neil Jones" wrote

Well, hey - perhaps you can live with that. It doesn't stop the algorithm being a valid encryption, though!

"Neil Jones" wrote

Hardly surprising if you've put it up for public review!!

"Neil Jones" wrote

Systems 1&2 are definitely different "things". If they were not, then the enemy could decrypt a message using system2 simply after cracking system1. Ergo, they are different *systems*.

You may like to consider them as one system with different keys. Perhaps you'd prefer to call them "sub-systems"? It doesn't really matter what you

*call* them. They are separate entities.

"Neil Jones" wrote

How hard do you think it is to guess an entire *algorithm* ???

After all, algorithms don't run in order like keys do (which are effectively just numbers). You can make a simple list of *all* keys simply by putting them into numerical order (OK, this'll be a big list - but not as big as the number of possible algorithms).

You cannot do this with algorithms, because there may be an infinite number of any one type, then an infinite number of another type ... and even an infinite number of types!!

"Neil Jones" wrote

We're not talking here about the effectiveness or security of any given system/scheme. We are simply discussing what constitutes "encryption". Just because it might be harder to create several systems without keys (than it is to create one algorithm plus many keys) wouldn't stop an algorithm without a key from being an encryption.

"Neil Jones" wrote

That seems a remarkably inconsistent use of language! :-

Using "EFMalgorithm" with "Table1" is *ENCODING*. Using "EFMalgorithm" with "Table2" is *Encryption*. Using "EFMalgorithm" with "Table3" is *Encryption*.

What is so special about Table1, apart from the fact that a few people happened to agree that was the one that they'd use?!!

"Neil Jones" wrote

... and wasn't it yourself that said that obfuscation was *not* a form of encryption?

------------------------------------------ "Neil Jones" wrote

There is a difference between using EFM to encode your data, and using "EFMalgorithm with Table1" to encode your data, even though the end results will be identical. In the first, you don't have a choice. In the second, you have opted to use a specific table to encode your data. The fact that you need to know which table (what the key was) is the point at which it has become encryption. [Albeit encryption with a 2-bit key which is trivially easy to descypt with a brute force attack].

I did say that, and I don't think I've contradicted myself.

Absolutely. I would say that too :-)

True, but it might be so easy to break as to be worthless.

How are you going to communicate your choice of system to your counterpart? You need to signal which 'system' you have used.

In other words, all your systems are part of the algorithm, and the way you tell your corespondent which 'scheme' to use is the key :-)

It might be easier than you seem to think :-) You may not even need to guess the actual algorithm - it may have produced output which gives subtle clues to the real message contained.

Don't they? How can you tell that two algorithms will produce different output?

Now who's making assumptions :-) In my fictional scenario you have now chosen to use AES with 256 bit keys - I'd like to see your enemy write down all the keys to that!

Neil

"Neil Jones" wrote

Hmmm. When the enemy intercepts the message, they do not care whether you used Table1 out of necessity or choice. And since the only real reason for encoding/encrypting the data in the first place, is so that the enemy has less chance of reading it -- then both systems are actually *exactly* the same!

"Neil Jones" wrote

What if the enemy didn't happen to know what the "usual" table used for EFM was? Would you then call it "encryption", just because the enemy needs to (brute force) crack the "key"?

But that it is "encoded" if the enemy just happens to know what the usual table is?

Now - here's the cruncher - what if your *first* enemy knows the usual table, but your *second* enemy does not? Did you "encrypt" it, or "encode" it????

Well, clearly the designer of this scheme (ie me) wasn't very good at it, were they? The 'normal' table shouldn't have been used in the scheme. I allowed it - it is a bad design flaw. In EFMalgorithm1.1 we'll invalidate '1' as a key...

The point still remains though - he can read *only* those messages where Table1 was used.

As far as I can see, he hasn't cracked the 'key', he has reverse-engineered the first table. It won't do him any good if I use Table 2 next time.

As I said before, it was Ronald Raygun drew the distinction between encoding and encrypting, not I.

"Neil Jones" wrote

Ah, that bit's easy. You both decide beforehand when you happen to be together ...

"Neil Jones" wrote

As said before - it is not the security/effectiveness of the system we are really considering here, but just whether a system can be "encryption" without a key. I haven't seen you explain anywhere why obfuscation is not encryption.

"Neil Jones" wrote

Well, if they truly *were* two (different) algorithms, then they would necessarily produce different output (if the data was large enough). If the same output is *always* produced, then that is an indicator that they are, in fact, the same algorithm.

[I say "if enough data" because two different algorithms may produce the same output if you are only encrypting one character...]

"Neil Jones" wrote

Not me!

It's simply like saying that there are more fractional numbers than whole numbers - OK, so there are an infinite number of whole numbers. But then there are an infinite number of fractional numbers *in between* each consecutive whole number - hence there are obviously many more fractional numbers than whole numbers!

"Neil Jones" wrote

As I said before, just because there may be around 10^77 numbers in the list, this doesn't stop you being able to list them all! [You can imagine writing down a (infinite) list of whole numbers - 0, 1, 2,

3, 4, 5, 6, ... (it continues as before) ... Try doing this for fractions! (well OK, that is possible -- just -- but much more difficult. For the real test, try doing this with irrational numbers!)]

Bearing in mind there are thought to be only 2^261 atoms in the universe, writing down 2^256 numbers means you have 32 atoms for each number. Good luck!

"Neil Jones" wrote

Well, RR can answer for himself. In your own terminologies - what do *you* think it is - "encryption" or "obfuscation"??

In other words - you agree a "key" :-)

Previously on "PIN fraud" I said:-

"Neil Jones" wrote

In a "thought exercise" (as here), you are allowed to use more atoms than you can see/feel/know about. More, even, than in the entire universe!

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required