Home › Blog

**Breaking: Britain'S Encryption Found To Be A Very Long Number Nobody Has Looked At** Goo

**BREAKING: BRITAIN'S ENCRYPTION FOUND TO BE A VERY LONG NUMBER NOBODY HAS LOOKED AT**

Good evening. A national audit of cryptographic controls has found that Britain is protected by 4,096 bits, of which 11 are doing anything, and that the remainder are described in the standard as "reserved."

CHYRON: ENTROPY "PRESENT IN SPIRIT"

Encryption, for viewers at home, is mathematics so difficult that no computer on earth could break it. This is correct. Nobody breaks it. They take the key, which is in a repo, in a file called config.yaml, on line 4.

We visited a bank in Edinburgh protected by AES-256. This is the same cipher used by the NSA. It is unbreakable. It is unbroken. It is also in ECB mode, which means identical blocks encrypt identically, which means the database of 9 million customer records is, at sufficient zoom, a PICTURE OF ITSELF. We were shown the ciphertext. It was a penguin.

CHYRON: BANK "ENCRYPTED, LEGIBLE"

The bank also uses a random number generator. We asked where the randomness comes from. They said the system clock. We asked what happens at boot. They said everything starts at the same time. Nine thousand devices generated the same key on Tuesday and have been trusting each other ever since, which the vendor describes as a mesh.

CHYRON: RNG "RETURNED 4. AGAIN."

An expert from the Institute of Applied Hardness explained key rotation. Britain rotates keys every 90 days. We asked what happens to the old key. He said it is retired. We asked where it is retired to. He said "a file." We asked whether anything is re-encrypted with the new key. He said no, that would be enormous, so each key protects its own slice, and after fourteen years the bank has 56 keys, all live, all required, all in the file, which is the only thing you now need to steal and which they call the KEY MANAGEMENT SOLUTION.

The HSM was mentioned. It is a tamper-proof box costing £40,000. It cannot be opened. Nothing can extract the key. It has an API. The API will sign anything you ask it to, for anyone who can reach it, and everyone can reach it, so the key is safe and the signature is free.

CHYRON: HSM "UNBREACHED, FULLY COOPERATIVE"

A nation-state was asked whether it had broken British encryption. It said it had not needed to. It said it collects the traffic now and decrypts it in twelve years when the machines are ready. It said Britain has been generously pre-encrypting everything into a single neat archive, which it appreciates, and which it regards as packaging.

Members of the public should not worry. Your data is encrypted. It is encrypted with a key held by a box that will use it for anybody, in a file next to the data, on a machine that has no randomness, in a mode that draws a picture of what it's hiding.

The penguin is you.

More after this.

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing