GUR RIBYHGVBA BS PELCGBTENCUL

Jeff Man

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

In "THE EVOLUTION OF CRYPTOGRAPHY" (itself a ROT13 cipher for the talk's actual title), veteran cryptologist and former NSA Red Team architect Jeff Man takes attendees on a comprehensive journey through the history of secret-keeping, from ancient ciphers to modern digital encryption. Man's central thesis challenges the often-interchangeable use of "encoding" and "encryption" in contemporary discourse, arguing for a return to precise definitions rooted in the foundational texts of cryptography. He highlights that while encoding primarily serves for brevity and speed, true encryption is fundamentally about secrecy and confidentiality.

Watch on YouTube

Visual summary for GUR RIBYHGVBA BS PELCGBTENCUL by Jeff Man
Visual summary for GUR RIBYHGVBA BS PELCGBTENCUL by Jeff Man

Key moments

  1. 0:00 Speaker's NSA background and early crypto work
  2. 2:40 Distinguishing between codes and ciphers
  3. 4:00 American Revolution: codes and ciphers in practice
  4. 6:00 Freemasons' Pigpen cipher and National Treasure
  5. 7:00 Ancient transposition ciphers: Scytale and Grille
  6. 8:00 The Playfair cipher: a complex substitution method
  7. 9:00 Setting up the 'wrong words' argument with declassified NSA Bibles

THE EVOLUTION OF CRYPTOGRAPHY

Speakers: Jeff Man, Former NSA Cryptologist, Consultant, Advisor

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=w4M_Z0D1rdY

Overview

In "THE EVOLUTION OF CRYPTOGRAPHY" (itself a ROT13 cipher for the talk's actual title), veteran cryptologist and former NSA Red Team architect Jeff Man takes attendees on a comprehensive journey through the history of secret-keeping, from ancient ciphers to modern digital encryption. Man's central thesis challenges the often-interchangeable use of "encoding" and "encryption" in contemporary discourse, arguing for a return to precise definitions rooted in the foundational texts of cryptography. He highlights that while encoding primarily serves for brevity and speed, true encryption is fundamentally about secrecy and confidentiality.

This talk is crucial for anyone in the cybersecurity field, offering a foundational understanding of cryptographic principles that underpin nearly all modern digital security. Man's unique perspective, honed through decades at the NSA and in industry, provides invaluable context to current cryptographic practices and their potential vulnerabilities. By dissecting the historical progression of codes and ciphers, he empowers defenders to better appreciate the mechanisms they rely on daily and to critically evaluate emerging technologies like homomorphic encryption.

Background

▶ Watch: Speaker's NSA background and early crypto work (0:00)

The human desire to keep secrets dates back millennia, with early efforts predominantly focused on securing military communications. Jeff Man, drawing on his extensive background as an NSA cryptologist and cryptanalyst from the late 1980s and early 90s, emphasizes that historically, two distinct methodologies emerged for protecting messages: codes and ciphers. Man recounts his early career designing cryptographic systems for clients like US Special Forces, even creating a physical cipher wheel, and developing what he believes was the first software-based NSA product for one-time pad key management. This firsthand experience informs his purist stance on cryptographic terminology.

Man's understanding is deeply rooted in declassified NSA texts, specifically "Military Cryptanalytics, Volumes One and Two," authored by highly respected pre-World War II cryptographers Lambros Callimahos and William Friedman. Friedman, often considered the "Godfather of cryptography" alongside his wife Elizabeth Friedman, laid down the precise definitions that Man champions. According to these foundational texts, ciphers deal with individual characters (letters, numbers), scrambling them to obscure meaning, while codes involve replacing entire words, phrases, or ideas with shorter representations, primarily for brevity and transmission efficiency.

Examples from history illustrate this distinction. During the American Revolution, codes like "one if by land, two if by sea" reduced long phrases to simple signals. Armies also used elaborate codebooks where numbers represented entire words or phrases, such as "agent 711" for George Washington. Concurrently, ciphers were employed, ranging from simple substitution ciphers like the Caesar cipher (used by the Confederate Army) to more complex transposition ciphers. Early transposition methods included the ancient Egyptian scytale, where a message was written on a leather strap wrapped around a stick of a specific diameter, then unwound to appear as random letters, only to be reassembled by a recipient with an identical stick. Another method involved stencils or grilles, where messages were written through cutouts, then the stencil rotated, creating a jumbled square of letters. These historical methods set the stage for the increasingly sophisticated cryptographic techniques that would follow.

Key Findings

▶ Watch: American Revolution: codes and ciphers in practice (4:00)

Jeff Man’s core argument revolves around what he perceives as a critical erosion of precise language in cryptography, particularly the conflation of encoding and encryption. He asserts that this blurring of definitions, even appearing in widely referenced sources like Wikipedia, undermines a fundamental understanding of security principles. Man's "purist" stance is not subjective, but rather grounded in the authoritative definitions established by cryptographic pioneers like Lambros Callimahos and William Friedman, whose declassified NSA texts serve as his "Bibles of cryptography."

Man meticulously differentiates:

  • Codes or Encoding: Primarily serve for brevity and speed of transmission. They compress information or replace common phrases with shorter symbols (e.g., "one if by land, two if by sea," or codebooks where "agent 711" meant George Washington). While they might offer a superficial layer of obscurity to an uninformed observer, their main purpose is not secrecy from a determined adversary.
  • Ciphers or Encryption: Fundamentally designed for secrecy and confidentiality. They scramble individual characters or bits of information using an algorithm and a key, making the message unintelligible to unauthorized parties. The goal is to deny intelligible content to an interceptor, making decryption without the correct key computationally infeasible.

Man laments that modern usage often treats "encryption" as synonymous with "encoding," leading to a misunderstanding of what true data protection entails. He cites a personal anecdote from his podcast, Paul Security Weekly, where a listener insisted the terms were interchangeable. This experience prompted his deep dive into the historical definitions, which he believes are still highly relevant in the digital age. He argues that while confidentiality has long been the primary focus of encryption in the digital age, the rise of threats like ransomware has highlighted the equal importance of availability, and a clear understanding of cryptographic mechanisms is crucial for both.

Furthermore, Man expresses skepticism about emerging technologies such as homomorphic encryption. While acknowledging its "neat technology" and "neat idea" for performing computations on encrypted data without decrypting it, he struggles to reconcile it with the traditional purpose of encryption: keeping information secret and entirely inaccessible. He suggests that while useful, perhaps it should not be called "encryption" if it allows meaningful information extraction without full decryption, illustrating his commitment to rigorous terminology even in the face of innovation.

Technical Deep Dive

▶ Watch: Freemasons' Pigpen cipher and National Treasure (6:00)

The historical evolution of cryptography, as detailed by Jeff Man, showcases an escalating arms race between secret-keepers and secret-breakers, leading to increasingly complex methods. Early substitution ciphers like the Caesar cipher (also known as a ROT cipher in the tech industry, for "rotation") simply shift letters a fixed number of places in the alphabet. Man demonstrates this with the talk's title, "GUR RIBYHGVBA BS PELCGBTENCUL," which is a ROT13 cipher for "THE EVOLUTION OF CRYPTOGRAPHY." While simple, such ciphers were effective against the uninitiated. The Pig Pen cipher, favored by Freemasons, represented letters with shapes derived from a grid, adding another layer of visual obscurity.

Transposition ciphers, conversely, rearrange the order of letters without changing the letters themselves. Man references the ancient Egyptian scytale, a physical device where a message written on a strip wrapped around a stick became jumbled when unwound, requiring an identical stick to decipher. Another historical example is the grille cipher, a square stencil with cutouts, used to write messages in stages by rotating the stencil, resulting in a seemingly random grid of letters. The Ottendorf cipher (popularized in "National Treasure" but historically known as the Arnold cipher), used numbers to denote a specific page, line, and letter in a pre-agreed book, illustrating a form of code combined with a positional cipher.

More advanced classical ciphers include the Playfair cipher, which uses a 5x5 square containing the alphabet (often combining J and K) and a keyword to create digraphic substitutions. This method encrypts pairs of letters rather than single ones, significantly increasing complexity over simple substitution. The common thread in all these early systems was the agreed-upon method or "key" — whether it was the shift amount for Caesar, the stick diameter for scytale, or the keyword for Playfair.

The digital age brought a paradigm shift. Man, having designed systems in the late 80s as computers became prevalent, witnessed this transition firsthand. Early efforts involved creating secure, self-contained encryption systems like the KL-43, a portable device with a keyboard and LCD screen that encrypted messages locally before transmission or printing. This represented a move away from "little black boxes" attached to radios or phones towards integrated solutions.

A significant leap was the development of secure telephones like the STU-III (Secure Telephone Unit, 3rd generation). These devices were among the first to incorporate public key cryptography (PKC), moving beyond purely symmetric systems. PKC introduced the concept of key pairs: a public key, which can be freely distributed, and a private key, kept secret by its owner. Messages encrypted with a recipient's public key can only be decrypted with their corresponding private key. This innovation solved the challenging problem of secure key exchange inherent in symmetric encryption, where both parties need to share the same secret key beforehand. Man describes the STU-III's early half-duplex (push-to-talk) operation and the "Donald Duck" voice artifacts caused by early encryption, highlighting the technological hurdles overcome to achieve modern, full-duplex secure communication on smartphones.

Modern cryptography, as Man explains, relies on highly complex mathematical algorithms and robust key management. It broadly falls into two categories:

  • Symmetric Encryption: Uses the same secret key for both encryption and decryption (e.g., AES). This is efficient but requires secure key distribution.
  • Asymmetric (Public Key) Encryption: Uses a pair of mathematically related keys (public and private). This enables secure key exchange and digital signatures, forming the backbone of secure internet communication (e.g., RSA, Diffie-Hellman, which Man notes he took a course on with Whitfield Diffie himself).

Man also touches upon cutting-edge areas like quantum cryptography and homomorphic encryption. While he doesn't delve deeply into quantum, he expresses his long-standing discomfort with homomorphic encryption. His concern stems from the fact that it allows computations on encrypted data, yielding meaningful results without ever decrypting the data. For Man, who has spent a career focused on keeping information absolutely secret, this concept challenges the very definition of "encryption" as a process of making data unintelligible to all but authorized parties. He concedes he is "losing that battle," but his purist stance underscores the philosophical challenges introduced by such advanced techniques.

Ultimately, modern encryption relies on generating "huge random streams" and applying "very complex mathematical algorithms" that are computationally infeasible to reverse without the correct key, which is now often managed through certificates. This evolution from simple substitutions to sophisticated, algorithmically driven, key-dependent systems demonstrates the continuous pursuit of robust confidentiality in an increasingly interconnected world.

Demo / Proof of Concept

▶ Watch: The Playfair cipher: a complex substitution method (8:00)

While Jeff Man's talk does not feature a live software demonstration in the contemporary sense, he effectively "demonstrates" the evolution of cryptography through a rich array of historical examples and physical artifacts. He illustrates the simplicity and mechanics of early ciphers, such as the Caesar cipher, by revealing the talk's ROT13 title. He visually describes the Pig Pen cipher using tombstone engravings and explains the concept of transposition ciphers with the ancient scytale and grille cipher methods.

Man also presents images and recounts his personal involvement with key physical cryptographic devices. He mentions the cipher wheel he designed for US Special Forces, which was inspired by historical examples and later put on display at the National Cryptologic Museum in Fort Meade, Maryland. He shows images of key injectors and discusses the KL-43, an early self-contained encryption system he worked with at NSA. Furthermore, he describes the STU-III secure telephone, explaining its function and the early challenges of integrating public key cryptography into communication devices. These historical tools and his personal anecdotes serve as tangible proofs of concept for the cryptographic principles he discusses, bridging the gap between abstract theory and practical application throughout history.

Defensive Implications

▶ Watch: Setting up the 'wrong words' argument with declassified NSA Bibles (9:00)

Understanding the fundamental distinctions between codes/encoding and ciphers/encryption, as articulated by Jeff Man, is paramount for cybersecurity defenders. The core defensive implication is to recognize that true security, specifically confidentiality, is achieved through robust encryption, not merely through obfuscation or data compression techniques often mislabeled as encoding.

Defenders must ensure that systems are employing strong, modern encryption algorithms (e.g., AES for symmetric, RSA/ECC for asymmetric) with appropriately sized and securely managed keys. The historical context highlights that the strength of a cipher lies not in its secrecy of algorithm (Kerckhoffs's Principle), but in the secrecy and randomness of its key. Therefore, key management — including generation, distribution, storage, rotation, and revocation — is a critical defensive control. Weak key management can render even the strongest algorithms vulnerable.

Man's emphasis on the purpose of encryption (secrecy) versus encoding (brevity/speed) provides a lens through which to evaluate data protection strategies. When a defender aims to protect sensitive data from unauthorized access, they must deploy cryptographic solutions designed for secrecy, not just for efficient data transmission or superficial obscurity. This means using ciphers with strong mathematical underpinnings and robust pseudo-random encryption keys, rather than relying on simple character substitutions or data compression methods that offer little to no cryptographic security.

Furthermore, Man’s discussion of the evolution from basic ciphers to public key infrastructure underscores the importance of a layered security approach. Modern network security protocols like TLS/SSL, which rely heavily on both symmetric and asymmetric encryption, are essential for protecting data in transit. For data at rest, full disk encryption or file-level encryption is crucial. Defenders should also be wary of the potential implications of emerging technologies like homomorphic encryption, carefully assessing whether their use cases genuinely align with the confidentiality requirements of their data. While innovative, such technologies must be understood within the traditional framework of cryptographic goals to avoid inadvertently compromising data secrecy.

Finally, the talk implicitly reinforces the Confidentiality, Integrity, and Availability (CIA) triad. While encryption primarily addresses confidentiality, Man notes that the rise of ransomware has brought availability to the forefront, demonstrating how the compromise of one aspect can impact others. Robust encryption, when properly implemented, can contribute to availability by making data inaccessible to attackers even if systems are breached, potentially reducing the impact of ransomware attacks if backups are also encrypted and secure. By appreciating the historical "why" behind cryptographic mechanisms, defenders can make more informed decisions about the "how" of securing modern digital assets.

Key Takeaways

  • Distinguish Codes from Ciphers: Codes (encoding) primarily aim for brevity and speed, while ciphers (encryption) are fundamentally designed for secrecy and confidentiality. This distinction is crucial for understanding true data protection.
  • Historical Roots are Relevant: The evolution of cryptography from ancient substitution and transposition ciphers to modern digital methods provides essential context for current security practices.
  • Keys are Paramount: The strength of any cryptographic system, from simple Caesar ciphers to complex public-key algorithms, hinges on the secrecy, randomness, and secure management of its key.
  • Modern Encryption is Complex: Digital cryptography relies on sophisticated mathematical algorithms and robust key management, forming the backbone of secure digital communications and data storage.
  • Beware of Terminology Blurring: The casual interchangeability of "encoding" and "encryption" can lead to misunderstandings of actual security capabilities and risks.
  • Evaluate Emerging Technologies Critically: New cryptographic paradigms like homomorphic encryption should be assessed against the core principles of confidentiality and secrecy to understand their true security implications.

About the Speaker(s)

Jeff Man is a highly experienced and respected figure in the cybersecurity and cryptography community. He introduces himself as a former NSA cryptologist and cryptanalyst, a role he held during the late 1980s and early 1990s, where he was involved in designing cryptographic systems and analyzing ciphers. Man is also notably recognized as one of the architects and founders of what came to be known as the first NSA red team, conducting pen testing in the early to mid-90s. After leaving the NSA almost 30 years ago, he transitioned into the industry, notably becoming involved in PCI (Payment Card Industry) compliance about 20 years ago. Currently, he serves as a consultant and advisor, bringing his extensive historical and practical knowledge to modern security challenges. He is also a co-host of the podcast "Paul Security Weekly," where he continues to engage with and educate the cybersecurity community. Man's deep expertise and historical perspective underscore his authority on the evolution and fundamental principles of cryptography.

All talks from DEF CON 32 Creator Stage