{"id":560736,"date":"2024-09-16T19:01:46","date_gmt":"2024-09-16T17:01:46","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=560736"},"modified":"2024-09-17T04:44:11","modified_gmt":"2024-09-17T02:44:11","slug":"secret-crypto-code-that-helped-end-apartheid-cracked-open-sourced","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/software\/560736-secret-crypto-code-that-helped-end-apartheid-cracked-open-sourced.html","title":{"rendered":"Secret crypto code that helped end apartheid cracked, open-sourced"},"content":{"rendered":"\n<p>Cloudflare chief technology officer John Graham-Cumming has cracked a 33-year-old password that protected the source code to a secure communications system used by the ANC during Operation Vula.<\/p>\n\n\n\n<p>This has finally allowed the system&#8217;s designer and programmer, Tim Jenkin, to <a href=\"https:\/\/github.com\/vulacode\" target=\"_blank\" rel=\"noreferrer noopener\">open source the code<\/a> he developed in the 1980s that had helped ANC leaders negotiate a peaceful end to apartheid.<\/p>\n\n\n\n<p>Operation Vula was a mission to infiltrate key leaders such as Mac Maharaj and Charles Nqakula into South Africa while ensuring good lines of communication between them and the ANC&#8217;s headquarters-in-exile in Lusaka, Zambia.<\/p>\n\n\n\n<p>The ANC was using a simple but undefeated paper-based one-time pad (OTP) system for cryptography, which Jenkin had trained operatives in.<\/p>\n\n\n\n<p>Jenkin was living in exile in London after escaping Pretoria Central Prison with two other inmates in 1979 by reverse-engineering the keys of ten separate doors and creating copies of them from wood.<\/p>\n\n\n\n<p>He and co-conspirator Stephen Lee were arrested after being caught moving their equipment for manufacturing pamphlet bombs with anti-apartheid messaging, which they had set off around Cape Town between 1975 and 1978.<\/p>\n\n\n\n<p>Their caper was <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">immortalised in the 2020 film&nbsp;<em>Escape from Pretoria<\/em>, in which Harry Potter star Daniel Radcliffe played<\/span> Jenkin.<\/p>\n\n\n\n<p>After reaching London, Jenkin became the ANC&#8217;s communications officer and developed the OTP-based system for secure communication between operatives and their handlers.<\/p>\n\n\n\n<p>While the encryption itself is uncrackable, provided keys are properly randomly generated, one-time pad systems have several other vulnerabilities.<\/p>\n\n\n\n<p>If an adversary gets their hands on the pre-generated keys and are able to intercept every message from then on, they can decrypt them.<\/p>\n\n\n\n<p>Operatives must also adhere to strict operational security protocols, such as destroying decrypted messages, old key pages, and old enciphered messages.<\/p>\n\n\n\n<p>However, the main problem, Jenkin found, was that encryption and decryption were laborious.<\/p>\n\n\n\n<p>To fix this problem, it had to be easy for operatives and their handlers to send much longer messages.<\/p>\n\n\n\n<p>In the early eighties, computers were getting cheaper, and Jenkin believed a program to automate the cryptography could solve their communications problem.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full wp-duotone-unset-1\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/09\/Toshiba-T1000.jpg\" alt=\"\" class=\"wp-image-560773\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/09\/Toshiba-T1000.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/09\/Toshiba-T1000-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/09\/Toshiba-T1000-768x432.jpg 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><figcaption class=\"wp-element-caption\">Toshiba T1000, personal computer used during Operation Vula<\/figcaption><\/figure>\n\n\n\n<p>Together with new partner-in-crime Ronnie Press, they began work on a system that would eventually become a fully-fledged underground electronic communications network.<\/p>\n\n\n\n<p>Although one of the first rules of cryptography is &#8220;don&#8217;t invent your own&#8221;, Jenkin said that due to the unique circumstances under which they operated, they could not use cryptographic software that was already available.<\/p>\n\n\n\n<p>&#8220;Even in those days, 25 years before Edward Snowden, there was talk about &#8216;backdoors&#8217; in encryption software,&#8221; Jenkin <a href=\"https:\/\/mybroadband.co.za\/news\/security\/131822-how-the-anc-sent-encrypted-messages-in-the-fight-against-apartheid.html\">previously told MyBroadband<\/a>.<\/p>\n\n\n\n<p>Jenkin and Press decided it was too complex to build their own public-key system, so they opted for a computerised version of the one-time pad.<\/p>\n\n\n\n<p>While their cryptography would remain simple, the whole communications system ended up having a lot more moving parts than just the software, as most of the Internet did not yet exist.<\/p>\n\n\n\n<p>Encrypted messages were transmitted into a signal that could be played over a regular telephone call and recorded. This allowed operatives to easily receive messages via public telephones.<\/p>\n\n\n\n<p>The recorded message could then be played back into a computer via a modem and decrypted.<\/p>\n\n\n\n<p>However, keys had to be distributed to the two communicating parties to encrypt or decrypt messages.<\/p>\n\n\n\n<p>For this, Jenkin wrote random data to 1.44MB &#8220;stiffy&#8221; disks. These keys and the encryption program itself then had to be delivered to operatives in the field.<\/p>\n\n\n\n<p>Enter Conny Braam, head of the Dutch anti-apartheid movement, who found a KLM air hostess sympathetic to their cause.<\/p>\n\n\n\n<p>The hostess, Antoinette Vogelsang, helped smuggle the computers, disks, and other equipment ANC operatives in South Africa needed.<\/p>\n\n\n\n<p>Vogelsang&#8217;s role was critical if the system was going to work. Had she provided copies of the disks to the South African authorities, the whole endeavour would have been compromised.<\/p>\n\n\n\n<p>With everything in place, the ANC kicked off Operation Vula.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"569\" height=\"400\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/07\/Tim-Jenkin-then-and-now.jpg\" alt=\"Tim Jenkin - then and now\" class=\"wp-image-131832\"\/><figcaption class=\"wp-element-caption\">Tim Jenkin \u2014 then and now<\/figcaption><\/figure>\n\n\n\n<p>In 1989, Operation Vula would achieve its greatest victory \u2014 re-establishing secure communications between Nelson Mandela in South Africa and ANC president Oliver Tambo in Lusaka, Zambia.<\/p>\n\n\n\n<p>Mandela had been transferred from prison to house arrest as part of negotiations to transition to a democratic South Africa.<\/p>\n\n\n\n<p>However, the apartheid government kept Mandela isolated from the rest of the ANC in the hopes of securing more favourable terms by creating the impression they were negotiating solely with him.<\/p>\n\n\n\n<p>While it was not possible to smuggle a computer and disks to Mandela, messages were relayed in the covers of books.<\/p>\n\n\n\n<p>Mandela&#8217;s replies could then be smuggled out, encrypted using the software, and transmitted to Tambo in Lusaka.<\/p>\n\n\n\n<p>&#8220;Messages from Mandela became a regular feature and in response there were long memos from Oliver Tambo in Lusaka,&#8221; said Jenkin.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/09\/Tim-Jenkin-Operation-Vula-TECOD-encryption-decryption-software.jpg\" alt=\"\" class=\"wp-image-560776\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/09\/Tim-Jenkin-Operation-Vula-TECOD-encryption-decryption-software.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/09\/Tim-Jenkin-Operation-Vula-TECOD-encryption-decryption-software-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/09\/Tim-Jenkin-Operation-Vula-TECOD-encryption-decryption-software-768x432.jpg 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><figcaption class=\"wp-element-caption\">Screenshot of TECOD.EXE, the one-time pad\u2013based encryption and decryption software Tim Jenkin developed for Operation Vula<\/figcaption><\/figure>\n\n\n\n<p>Graham-Cumming <a href=\"https:\/\/blog.jgc.org\/2024\/09\/cracking-old-zip-file-to-help-open.html\" target=\"_blank\" rel=\"noreferrer noopener\">wrote<\/a> that he became interested in Operation Vula a while ago and reached out to Jenkin to find out if the code had ever been open-sourced.<\/p>\n\n\n\n<p>Jenkin explained that the only reason he hadn&#8217;t published the code until now was because he had compressed it into a password-protected ZIP file in 1991 when he returned to South Africa.<\/p>\n\n\n\n<p>Negotiations between the ANC and the apartheid regime were still in full swing, and it was far from certain that they would be successful \u2014&nbsp;hence the need to encrypt the code.<\/p>\n\n\n\n<p>Unfortunately, when Jenkin tried to unzip the file years later, he realised he had forgotten the password.<\/p>\n\n\n\n<p>&#8220;I thought I would never forget the password, but when I tried to decode it a few years later, I couldn&#8217;t remember it,&#8221; he said.<\/p>\n\n\n\n<p>After Graham-Cumming cracked the password, Jenkin uploaded the nearly 40-year-old PowerBASIC code to <a href=\"https:\/\/github.com\/vulacode\" target=\"_blank\" rel=\"noreferrer noopener\">Github<\/a>.<\/p>\n\n\n\n<p>Cracking it was no easy feat, even though the ZipCrypto scheme used in PKZIP from that era has a known plain text vulnerability. There is also an open-source implementation of an exploit for it called bkcrack.<\/p>\n\n\n\n<p>Graham-Cumming explained that all he had to do was predict 12 bytes of plain text at a known location inside the ZIP file.<\/p>\n\n\n\n<p>After crafting an attack on the ZIP files, aided by Jenkin&#8217;s knowledge of their contents, bkcrack ran for 23 minutes to return with a decryption key.<\/p>\n\n\n\n<p>Graham-Cumming compiled and ran two of Jenkin&#8217;s lost programs and posted screenshots and videos of them in action on <a href=\"https:\/\/blog.jgc.org\/2024\/09\/cracking-old-zip-file-to-help-open.html\" target=\"_blank\" rel=\"noreferrer noopener\">his blog<\/a>.<\/p>\n\n\n\n<p>The first generated disks with the random keys necessary for one-time pad encryption, while the other performed the encoding and decoding.<\/p>\n\n\n\n<p>&#8220;There are lots of interesting details of how these programs work that deserve another longer blog post when I have time. Or a detailed study by someone else,&#8221; Graham-Cumming said.<\/p>\n\n\n\n<p>&#8220;For example, the key material is destroyed after use, the RANDOM.EXE program has multiple ways of making randomness and code to check the distribution of the random bytes created. There&#8217;s an emphasis on using the RAM disk for all cryptographic operations.&#8221;<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cloudflare chief technology officer John Graham-Cumming has cracked a 33-year-old password that protected the source code to a secure communications system used by anti-apartheid activists.<\/p>\n","protected":false},"author":15,"featured_media":560744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27,16],"tags":[31516,29694,31518,72954,95273,31510,31512,31508],"class_list":["post-560736","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-software","tag-antoinette-vogelsang","tag-cloudflare","tag-connie-braam","tag-john-graham-cumming","tag-operation-vula","tag-ronnie-press","tag-stephen-lee","tag-tim-jenkin"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/560736"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=560736"}],"version-history":[{"count":4,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/560736\/revisions"}],"predecessor-version":[{"id":560784,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/560736\/revisions\/560784"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/560744"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=560736"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=560736"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=560736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}