Comment by mmsc
9 hours ago
For anybody interested, the actual encrypted message:
BTTE UM ANGABE DES MARSQWEGES X BEFINDE MIQ IN X ROSENOW ROSENOW X SOFORT FUNKANTWORT X WASCHBBSCH
which, given misspellings, translates approximately to:
Please specify the route of march. I am in Rosenow, Rosenow. Immediate reply by radio. Waschbusch.
From the article:
This feels extremely underexplained! Why would Astra think to use that as a "crib"? Was it common to repeat the place name in these messages?
(Is it possible that this is a misreported detail? It feels like a singular ROSENOW would be an equally effective crib)
This was explained in the article right there:
> it suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message
It makes sense that Nr. 172 and Nr. 173 might be related since they were sent at around the same time.
In Nr. 173, "ROSENOW ROSENOW" was also present.
It also makes sense that a longer crib would generally be more effective than a shorter one.
It was partially explained by the article. It was not stated that ROSENOW was repeated in 173, and it was not obvious from the article text why ROSENOW would ever be repeated. Thus my curiosity.
A sibling commenter explained it - Rosenow is both a municipal name and a district name, so naturally it would be repeated. (Like "New York, New York")
It would seem to me that the odds of looking for even a single ROSENOW in the decrypted message would be plenty. The odds of a single ROSENOW randomly occurring in incorrectly decrypted output are vanishingly small. So it seems to me that looking for ROSENOW is a safer bet vs. looking for ROSENOW ROSENOW -- a single ROSENOW is a great sign you've got the correct key, whereas looking for ROSENOW ROSENOW seems like it would deliver false negatives (think of all the times we say "New York" rather than "New York, New York")
I'm a novice at crypto though, so, maybe I've got that totally wrong.
1 reply →
Rosenow is a municipal (around 32km²) and in there is a district also called Rosenow. So the sender just specified his current position a bit more.
akin to "New York, New York" (as in NYC, NY)
Ah, thank you! That makes sense.
Maybe naive of me, but could it simply just be the overfitting of the same tokens being sent on the input twice because of repetition rather than some unknown implied intelligence.
Out of interest, what was the ciphertext?
Edit: Found it from here: https://mvueh-enigma-solved.carterl.chatgpt.site/
Do we have any kind of transcript as to how the message was cracked, and whether this was cheaper or more expensive than simply Bombe-style trying all the combinations?
As the article states, the LLM built code for both an enigma simulator and a bombe simulator.
Breaking enigma is often about using lucky or educated guesses to heuristically reject large chunks of keyspace to leave the remaining keyspace computationally tractable.
Note that the key (lol) complication with this message seems to be that it had a wheel rollover that most messages do not have to deal with, and that rollover drastically reduces how much you can reduce the potential keyspace using all the techniques noticed by the original crackers.
The wheel rollover I think just requires more brute force. Unfortunately, this might be an example of OpenAI the company having vastly more compute time and effort than your average enigma nerd. For example, modern compute clusters like supercomputers can tractably brute force enigma with no cleverness in like a day or less, while home computers would still take thousands of years to compute that. It's very scalable. Did astra have access to significant compute?
However, even considering that, the inferences made by the LLM are good, and picking this specific message to attack, precisely because it should be soluble but might have had an extra wheel rollover that made it more computationally intractable for hobbyists but not a large company is a clever thing to do for the LLM.
This was done by an OpenAI subscriber, not an employee, so Astra would not have had access to OpenAI's massive compute for brute forcing. The scripts it wrote presumably ran on the computer of the customer. (ChatGPT can run scripts on OpenAI's servers, but it has a 45 second execution limit.)
> Unfortunately, this might be an example of OpenAI the company having vastly more compute time and effort than your average enigma nerd.
I don't think this applies, isn't this just the researcher using ChatGPT Codex on their machine?
> Unfortunately, this might be an example of OpenAI the company having vastly more compute time and effort than your average enigma nerd.
It seems like a lot of the recent "breakthroughs" come down to this: spending millions of dollars in compute to solve problems that essentially amount to recreational math problems
Why wasn't this in the article?
Interesting. Do we know the reason why those specific messages were sent with different keys? I would imagine that there were separate keys for special high-security messages or something like that, but the almost identical content and the way the key was changed here (first only part of the configuration, then suddenly everything) makes it look more like an error or a test.
That's crazy. Can someone share context of the message.
Slopped up site https://mvueh-enigma-solved.carterl.chatgpt.site/ seems to indicate it's due to:
was the misspellings deliberate?
Looks like Q is used as an abbreviation for CH
i would assume yes, to throw off decyphering. even more impressive that they managed to crack it
I'm surprised "Bitte" --> "btte" was a hurdle. "Bitte," or "please," is ubiquitous in German. The more common the term, them more likely you'd be to see some contractions. Dropping the "i" is pretty logical- anyone looking at it would see immediately what it meant.
> i would assume yes, to throw off decyphering. even more impressive that they managed to crack it
Were operators of enigma machines aware enough of cryptology or the weaknesses of enigma, for that to have been done intentionally to prevent decryption? I doubt it, otherwise _many_ things should have been done _much_ differently by the operators.
The place is Rosenau actually.
https://en.wikipedia.org/wiki/Rosenow
Did you mean https://de.wikipedia.org/wiki/Rosenow
I believe Germans spell it achtually.
Ich glaube, dass Deutsche buchstabieren es "aktuelle", eigentlich.
(apologies for my broken learner German, I decided not to use a translator).
4 replies →
Your account will be flagged for using humor, we are only dealing here, with the very serious subject, of killing humanity with AI.
1 reply →