← Back to context

Comment by mmsc

9 hours ago

For anybody interested, the actual encrypted message:

  BTTE UM ANGABE DES MARSQWEGES X BEFINDE MIQ IN X ROSENOW ROSENOW X SOFORT FUNKANTWORT X WASCHBBSCH

which, given misspellings, translates approximately to:

  Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio. Waschbusch.

    I am in Rosenow, Rosenow. 

From the article:

    After trying many different approaches, GPT–6 
    Astra focused on using the repeated place name 
    ROSENOW ROSENOW as a crib. 

This feels extremely underexplained! Why would Astra think to use that as a "crib"? Was it common to repeat the place name in these messages?

(Is it possible that this is a misreported detail? It feels like a singular ROSENOW would be an equally effective crib)

  • This was explained in the article right there:

    > it suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message

    It makes sense that Nr. 172 and Nr. 173 might be related since they were sent at around the same time.

    In Nr. 173, "ROSENOW ROSENOW" was also present.

    It also makes sense that a longer crib would generally be more effective than a shorter one.

    • It was partially explained by the article. It was not stated that ROSENOW was repeated in 173, and it was not obvious from the article text why ROSENOW would ever be repeated. Thus my curiosity.

      A sibling commenter explained it - Rosenow is both a municipal name and a district name, so naturally it would be repeated. (Like "New York, New York")

          It also makes sense that a longer crib 
          would generally be more effective than a 
          shorter one.
      

      It would seem to me that the odds of looking for even a single ROSENOW in the decrypted message would be plenty. The odds of a single ROSENOW randomly occurring in incorrectly decrypted output are vanishingly small. So it seems to me that looking for ROSENOW is a safer bet vs. looking for ROSENOW ROSENOW -- a single ROSENOW is a great sign you've got the correct key, whereas looking for ROSENOW ROSENOW seems like it would deliver false negatives (think of all the times we say "New York" rather than "New York, New York")

      I'm a novice at crypto though, so, maybe I've got that totally wrong.

      1 reply →

  • Maybe naive of me, but could it simply just be the overfitting of the same tokens being sent on the input twice because of repetition rather than some unknown implied intelligence.

Do we have any kind of transcript as to how the message was cracked, and whether this was cheaper or more expensive than simply Bombe-style trying all the combinations?

  • As the article states, the LLM built code for both an enigma simulator and a bombe simulator.

    Breaking enigma is often about using lucky or educated guesses to heuristically reject large chunks of keyspace to leave the remaining keyspace computationally tractable.

    Note that the key (lol) complication with this message seems to be that it had a wheel rollover that most messages do not have to deal with, and that rollover drastically reduces how much you can reduce the potential keyspace using all the techniques noticed by the original crackers.

    The wheel rollover I think just requires more brute force. Unfortunately, this might be an example of OpenAI the company having vastly more compute time and effort than your average enigma nerd. For example, modern compute clusters like supercomputers can tractably brute force enigma with no cleverness in like a day or less, while home computers would still take thousands of years to compute that. It's very scalable. Did astra have access to significant compute?

    However, even considering that, the inferences made by the LLM are good, and picking this specific message to attack, precisely because it should be soluble but might have had an extra wheel rollover that made it more computationally intractable for hobbyists but not a large company is a clever thing to do for the LLM.

    • This was done by an OpenAI subscriber, not an employee, so Astra would not have had access to OpenAI's massive compute for brute forcing. The scripts it wrote presumably ran on the computer of the customer. (ChatGPT can run scripts on OpenAI's servers, but it has a 45 second execution limit.)

    • > Unfortunately, this might be an example of OpenAI the company having vastly more compute time and effort than your average enigma nerd.

      I don't think this applies, isn't this just the researcher using ChatGPT Codex on their machine?

    • > Unfortunately, this might be an example of OpenAI the company having vastly more compute time and effort than your average enigma nerd.

      It seems like a lot of the recent "breakthroughs" come down to this: spending millions of dollars in compute to solve problems that essentially amount to recreational math problems

Interesting. Do we know the reason why those specific messages were sent with different keys? I would imagine that there were separate keys for special high-security messages or something like that, but the almost identical content and the way the key was changed here (first only part of the configuration, then suddenly everything) makes it look more like an error or a test.

That's crazy. Can someone share context of the message.

  • Slopped up site https://mvueh-enigma-solved.carterl.chatgpt.site/ seems to indicate it's due to:

      The SS-Totenkopf Division was advancing east during the opening weeks of Operation Barbarossa, the German invasion of the Soviet Union. 10 July 1941, the division had just fought its way through the Soviet border defenses around Sebezh. It had moved through Lithuania and Latvia, crossed the Dvina area, and advanced through Dagda toward a place German records called "Rosenow." The division moved out of the Rosenow area around 6 July, fought around Sebezh on 8-9 July, and then continued east/northeast toward Opochka and eventually Porkhov.

was the misspellings deliberate?

  • i would assume yes, to throw off decyphering. even more impressive that they managed to crack it

    • I'm surprised "Bitte" --> "btte" was a hurdle. "Bitte," or "please," is ubiquitous in German. The more common the term, them more likely you'd be to see some contractions. Dropping the "i" is pretty logical- anyone looking at it would see immediately what it meant.

    • > i would assume yes, to throw off decyphering. even more impressive that they managed to crack it

      Were operators of enigma machines aware enough of cryptology or the weaknesses of enigma, for that to have been done intentionally to prevent decryption? I doubt it, otherwise _many_ things should have been done _much_ differently by the operators.

The place is Rosenau actually.