Wednesday, November 23, 2011

My Public Blog About Privacy

This Blog, A. Fly's Cryptanalysis, was the very first blog I ever created. I am fairly incompetent when it comes to computers, and was a little distraught in the beginning of the semester when my First Year Seminar professor assigned us to make a blog and update it weekly. Not only was I taken aback by the idea that I would actually have to figure out how to set up a blog (my sister had to set up my Facebook and email accounts, for I am not kidding when I say I know nothing about computers!) but I was also surprised to hear the topic of these blogs was anything to do with secrecy and privacy. Firstly, I don't do so well with extremely broad topics. It will take me forever just to narrow it down enough to write something substantial! But most importantly, I was perplexed by the concept of writing about secrecy and privacy on a PUBLIC blog. Anything posted on a blog can be accessed by anyone who has internet access. It seemed rather ironic and paradoxical to write about privacy through a media in which privacy doesn't seem to exist. I also wondered how many people would actually read it. Over the course of the semester, I have had a substantial amount of viewers! In the 200's! Now, I know not all of those can come from other people in my seminar. I was also surprised to see I also have an audience from  Russia and Germany!  It is truly amazing how the internet can connect people from across the world, but I often wonder how these people find my posts. I am totally clueless as to how blogs work, or even why they exist! Who wants to read the posts of someone he or she doesn't know on completely random topics? These were all the questions I had when i first started this blog, but I guess it is good to get opinions from a different point of view and start a conversation. Maybe that's what the creator of blogs had in mind... What do you think?

A Holiday Message

Here's the catch! The message is encoded...So grab your enigma machines, (for those of you who broke yours or just don't have one, there is a website below that simulates an enigma machine!) and get to work! Make sure you have the correct initial settings, or you will never be able to break the code!

Reflector settings: 3 7 9

Rotor Type (rotor 1): 3
Rotor Type (rotor 2): 4
Rotor Type (rotor 3): 1

Initial Position (rotor 1): 5
Initial Position (rotor 2): 7
Initial Position (rotor 3): 6

Cipher text:  TFFQJQIQHFWCOG

Website for those that need an enigma machine - http://russells.freeshell.org/enigma/  

First person to post the plaintext message WINS!!!

Wednesday, November 16, 2011

FBI Seeks Help From Public to Solve Murder Cases Involving Cryptology

I found this article online about a man who was found murdered, the only evidence in the case being two handwritten ciphers in his pocket. 12 years after the murder, the FBI has published the ciphers to the public in hopes that someone out there is able to solve them. This is not the first time the police have relied on public help with ciphers. It was a school teacher who was able to break a cipher from the Zodiac killer. Does breaking these codes make the person who broke them a suspect in the case? If trained experts can't break these codes, but a school teacher can, why wouldn't this be suspicious? However, if they were automatically suspects, what would be the incentive the help the police in these cases?

http://news.yahoo.com/fbi-seeks-publics-cryptology-help-baffling-murder-20110330-112600-451.html

Little Cryptology Quiz

Here is a little test to see exactly how much we have learned from our Cryptology class. I just took it and it doesn't take that long, and it has many question that, having read the Code Book, we should all hopefully be familiar with! I hope you all take it. It's only about 23 questions and really fun to see how much we have learned. I got an 84%. how did you do???



http://www.okcupid.com/tests/the-basic-cryptology-test

Thursday, November 10, 2011

Dickinson Gateway Passwords

                      Not long after we all got settled in here at our new home, Dickinson College, we finally got used to how things work around here. We learned our way around the campus and threw away our no longer needed campus maps. We understood what our professors expected of us and learned to balance homework, socialization, and the occasional call home to inform our mothers that we are, in fact, still alive and well. We discovered how to navigate the Gateway website and some of us even customized our Web outlook email page. Then, one day when signing into our accounts on a Dickinson public computer, a warning popped up unexpectedly informing us that our passwords would expire in 11 days. At first, most of us didn’t think anything of this and just ignored it, until the next day it said our passwords would expire in 10 days. Thus some of us realized, this was a real countdown and not a mistake to simply be ignored. Some of us took the hint and changed our passwords. Then again, some of us again, just ignored it, hoping it would go away. After ten days passed, we were forced to change our passwords. Some even claimed to have been locked out of gateway. Why is it that the College forces us to change our passwords on a regular basis? Was there an incident in the past that inspired a change in students’ security? Do you think it is the responsibility of the College to enforce this routine of changing passwords and ensuring higher levels of security to students, or is it the responsibility of the students themselves to pick a secure password and change it according to when they feel they need higher security? If you weren’t forced to change your gateway password every so often, would you change it at all?

Tuesday, November 1, 2011

Just a Question from Someone Technologically Challenged

                I have never considered myself savvy in the technology department (and probably never will!) In fact, if it were not for school, I probably wouldn’t even own a computer. So as I was posting some comments on other blogs, it occurred to me, why does it always come up with the word verification. The word is always slanted and hard to read, but it offers a handicapped version, if you will, for those having a hard time reading the slanted version. What is the purpose of this extra step before posting a comment? This does not come up when I post a blog, but always when I post a comment. It is not like I need to enter a secret password or anything, just retype the word that pops up on the screen. I do not see the purpose. Someone please enlighten me.

Controversy About A High Versus Low Security Encryption Standard


One of the homework readings said that our stance on the internet versus privacy issue is based on who we fear most: the government or criminals. If we fear criminals more, than we would want a low encryption standard to expedite the government’s job of protecting us from hackers and terrorists. However, if we feared what the government did with our private information, then we would want a higher encryption standard, which then gives criminals the upper hand. There is a saying that the only people who want privacy are those who have something to hide. Who really cares if the government has access to everything you do, as long as you don’t do anything wrong or suspicious. This is where the line becomes thin. What is considered suspicious? As we said in class, innocently looking up murders on the internet for a class could be seen as something much more threatening. Also, if you knew someone was watching you, would you act differently? Would this knowledge of someone constantly surveying your every move make you more likely to not do something wrong, or to just be sneakier about your illicit behavior?

Internet Versus Privacy


Recently I came across a CBS story about the internet versus privacy issue. The story argued that, today, our private lives are no longer private. This is obviously uncontroversial, but the reason our privacy is depleting is where the debate is centered. In the CBS story, it was stated, when we talk about privacy, we are talking about our right to control information we consider to be private. With the increase in technology, we are not losing control of our privacy, we are giving it away. Every time we use we use a credit card, Facebook, emails, or cell phones, we trade our privacy for convenience and entertainment. The CBS story also related the tale of a teacher who lost her job because she had a picture on Facebook of her holding a glass of alcohol. She was fired on the grounds of promoting alcohol. There are two arguments here. One could stand firm that this teacher gave away her privacy to this picture when she posted it on the internet. The other argument is that if one were to see this teacher drinking at a restaurant, would this be grounds to fire her? What is the difference? The teacher argued that she would never bring alcohol into the classroom and that her posting on Facebook was not meant to be seen by her students.  However, by posting it on the internet, her students, as well as anyone else with internet access, could have accessed it. What are your views on this issue?

Thursday, October 27, 2011

DES Controversy


                In a previous blog, I talked about the controversy regarding how much the government should be allowed to “invade the public’s privacy.” Now, I am pondering a similar, yet completely different question. Should the government be allowed to restrict the means by which the public gets its privacy? This controversy stems from the idea of DES. The government wants to restrict the security of the codes businesses use to  keep their products safe so it can in turn keep the public safe. However, by doing this, the businesses themselves are putting themselves at risk on the chance that there are hackers out there capable of breaking DES. With technology continuing to advance, how often should the standard be changed? Should the government be more focused on building its hacking capabilities rather than weakening the security of the standard coding system?

DirecTV's War With Hackers

                        After reading about the security (or lack thereof) of DirecTV’s programming signal from the online article DirecTV’s War on Hackers, what I found the most interesting was actually the reader’s comments on the article. The first couple presented the idea that decrypting air signals is not actually stealing TV. I was surprised by this, because while I was reading the article, it never even occurred to me that the people receiving this free TV weren’t doing anything wrong! It seemed obvious to me that if you weren’t paying for the programs, but you received the signal through direct action on your part, then that was stealing. However, the first few comments proposed the idea that “When you steal something, the person that you stole it from no longer possesses it. An example of stealing TV would be smashing a shop window, grabbing a television set under your arm, and running. This is by no means the same thing. DirecTV are broadcasting their signal over satellite. Whether you pay for their service or not, it gets beamed into your property. If you have a dish, you will pick up the signal. If you happen to have the means of decoding this signal, you can watch their TV shows. How is this stealing?” I do not think this changes my mind about the fact that what was going on here is wrong, but it is definitely and interesting point that made me stop and think.