WEBVTT - When Secrets Aren't Secret

0:00:04.240 --> 0:00:07.240
<v Speaker 1>Welcome to Tech Stuff, a production of I Heart Radios

0:00:07.320 --> 0:00:13.880
<v Speaker 1>How Stuff Works. Hey there, and welcome to tech Stuff.

0:00:13.920 --> 0:00:16.919
<v Speaker 1>I'm your host, Jonathan Strickland. I'm an executive producer with

0:00:16.960 --> 0:00:20.040
<v Speaker 1>I Heart Radio and I love all things tech and

0:00:20.120 --> 0:00:23.400
<v Speaker 1>you know. A few months back, I profiled the Chinese

0:00:23.400 --> 0:00:27.960
<v Speaker 1>telecommunications company Huawei, which continues to be the focal point

0:00:28.120 --> 0:00:32.159
<v Speaker 1>of scrutiny around the world. Huawei makes, among lots of

0:00:32.200 --> 0:00:37.360
<v Speaker 1>other stuff, critical components for five gene network infrastructure. There's

0:00:37.400 --> 0:00:41.239
<v Speaker 1>some folks who worry that entrusting telecommunications infrastructure to a

0:00:41.360 --> 0:00:45.680
<v Speaker 1>Chinese company is essentially inviting the government of China to

0:00:45.840 --> 0:00:51.640
<v Speaker 1>spy on everybody, companies, other countries, everyone. Other folks aren't

0:00:51.680 --> 0:00:55.360
<v Speaker 1>as concerned about that, or they took Huawei officials at

0:00:55.360 --> 0:00:58.000
<v Speaker 1>their word that the company has no real ties to

0:00:58.080 --> 0:01:02.080
<v Speaker 1>the Chinese Communist government or its goals. But a recent

0:01:02.120 --> 0:01:05.720
<v Speaker 1>story in The Washington Post and German broadcaster zd F

0:01:05.840 --> 0:01:07.640
<v Speaker 1>China light on why it might be a good idea

0:01:07.680 --> 0:01:11.240
<v Speaker 1>to view Whahwei with a critical eye, and another news

0:01:11.280 --> 0:01:16.280
<v Speaker 1>item from the The Wall Street Journal showed that Huahwei

0:01:16.600 --> 0:01:22.000
<v Speaker 1>has maintained a back door access to its networks for

0:01:22.200 --> 0:01:25.200
<v Speaker 1>ten years So I want to talk about these stories,

0:01:25.280 --> 0:01:28.720
<v Speaker 1>primarily focusing on the one from the Washington Post to

0:01:28.760 --> 0:01:34.000
<v Speaker 1>talk about the business of communication and secrets and also

0:01:34.040 --> 0:01:37.240
<v Speaker 1>the business of eavesdropping and why all of this gets

0:01:37.440 --> 0:01:43.320
<v Speaker 1>real dodgy, real fast. So the initial story doesn't involve

0:01:43.600 --> 0:01:47.560
<v Speaker 1>China or five G networks. It goes further back than that.

0:01:47.680 --> 0:01:51.320
<v Speaker 1>It actually concerns a Swiss company called Crypto a G

0:01:51.960 --> 0:01:55.480
<v Speaker 1>and its ties to the Central Intelligence Agent Agency a

0:01:55.600 --> 0:01:57.680
<v Speaker 1>k a. The c i A in the United States.

0:01:58.000 --> 0:02:01.640
<v Speaker 1>The story is all about the battle between secrecy and surveillance,

0:02:02.040 --> 0:02:04.720
<v Speaker 1>and it's also about trust, as in, whom do you

0:02:04.760 --> 0:02:08.240
<v Speaker 1>trust when you want to send a secure communication to

0:02:08.280 --> 0:02:12.800
<v Speaker 1>someone else? If you're using some sort of technology to

0:02:13.040 --> 0:02:19.320
<v Speaker 1>encrypt your stuff, who makes that that encryption you know, strategy,

0:02:19.360 --> 0:02:23.639
<v Speaker 1>whether it's it's software or uh actual device or whatever

0:02:23.680 --> 0:02:26.680
<v Speaker 1>it may be, who's making that and can they be trusted?

0:02:26.720 --> 0:02:29.800
<v Speaker 1>And as it turns out, those are difficult questions to

0:02:29.840 --> 0:02:33.840
<v Speaker 1>answer then would readily seem a parent Now, the story

0:02:33.919 --> 0:02:37.840
<v Speaker 1>for this really begins with a Swedish inventor named Arvid

0:02:38.000 --> 0:02:43.520
<v Speaker 1>gerard Dom who was born in eighteen sixty nine. He

0:02:43.560 --> 0:02:47.360
<v Speaker 1>worked in textile mills before he would start creating his

0:02:47.400 --> 0:02:51.639
<v Speaker 1>own version of a cipher machine sometime around nineteen fifteen

0:02:51.760 --> 0:02:56.120
<v Speaker 1>or so. So, what the heck is a cipher machine? Heck?

0:02:56.160 --> 0:02:59.720
<v Speaker 1>What's a cipher? Well, a cipher is a code. It's

0:02:59.720 --> 0:03:02.800
<v Speaker 1>a way of hiding the meaning of a message. And

0:03:02.840 --> 0:03:07.520
<v Speaker 1>there are a lot of different approaches to encoding information, uh,

0:03:07.560 --> 0:03:09.680
<v Speaker 1>And there are a lot of strategies that actually employ

0:03:09.840 --> 0:03:14.440
<v Speaker 1>multiple versions of this, multiple schemes. So, for example, one

0:03:14.480 --> 0:03:17.160
<v Speaker 1>way to have a code is to use words that

0:03:17.280 --> 0:03:21.320
<v Speaker 1>refer to something else. So instead of saying a military tank,

0:03:21.440 --> 0:03:24.760
<v Speaker 1>you might say Thomas, you know, because you've got Thomas

0:03:24.800 --> 0:03:27.560
<v Speaker 1>the tank engine. And you go from Thomas the tank

0:03:27.600 --> 0:03:31.440
<v Speaker 1>engine to military tank and there you are. So if

0:03:31.480 --> 0:03:33.840
<v Speaker 1>you referred to a Thomas, you might be talking about

0:03:33.840 --> 0:03:36.640
<v Speaker 1>a tank. That would be a very bad code, or

0:03:36.640 --> 0:03:39.800
<v Speaker 1>at least a very easy to decipher code. But that's

0:03:40.040 --> 0:03:43.000
<v Speaker 1>a version of codes where you have a codebook that

0:03:43.120 --> 0:03:47.320
<v Speaker 1>tells you what certain words or phrases actually are meant

0:03:47.400 --> 0:03:51.240
<v Speaker 1>to convey. Then you have ciphers in which you replace

0:03:51.680 --> 0:03:55.080
<v Speaker 1>the letters of a message with some other letter or symbol,

0:03:55.320 --> 0:03:58.880
<v Speaker 1>And the simplest of these is a shift cipher, sometimes

0:03:58.920 --> 0:04:02.560
<v Speaker 1>also called a c zer cipher. And with these ciphers,

0:04:02.760 --> 0:04:05.080
<v Speaker 1>you write on a message, but you shift all the

0:04:05.160 --> 0:04:10.400
<v Speaker 1>letters some predetermined number down or up the alphabet. So

0:04:10.520 --> 0:04:13.480
<v Speaker 1>if you had a shift cipher with just one shift

0:04:13.680 --> 0:04:16.800
<v Speaker 1>one step, that would mean that you would use the

0:04:16.880 --> 0:04:20.400
<v Speaker 1>letter B to represent the letter A, you would use

0:04:20.440 --> 0:04:23.240
<v Speaker 1>the letter C to represent the letter B, and so

0:04:23.320 --> 0:04:26.040
<v Speaker 1>on down the alphabet. So if someone else were to

0:04:26.080 --> 0:04:29.440
<v Speaker 1>get hold of the message at casual glance, the message

0:04:29.480 --> 0:04:32.160
<v Speaker 1>would appear to be gibberish. But of course that particular

0:04:32.200 --> 0:04:35.920
<v Speaker 1>cipher is super easy to decode, even if you are

0:04:35.920 --> 0:04:38.960
<v Speaker 1>shifting further up or down the alphabet. Let's say you're

0:04:38.960 --> 0:04:42.839
<v Speaker 1>shifting up ten spots instead of one. Well, just because

0:04:43.000 --> 0:04:46.880
<v Speaker 1>of the nature of language, someone with even a little

0:04:46.880 --> 0:04:49.279
<v Speaker 1>bit of patients would be able to probably break that

0:04:49.360 --> 0:04:53.360
<v Speaker 1>code pretty quickly. Well. In the early twentieth century, inventors

0:04:53.360 --> 0:04:57.800
<v Speaker 1>were working on mechanical systems that would create stronger ciphers,

0:04:57.880 --> 0:05:00.520
<v Speaker 1>and initially these were mostly thought of as a way

0:05:00.560 --> 0:05:06.280
<v Speaker 1>to protect business communications like financial communications between banks, for example,

0:05:06.720 --> 0:05:11.919
<v Speaker 1>or sometimes political messages between different parts of the world,

0:05:11.960 --> 0:05:15.440
<v Speaker 1>like a government and its embassy in another country. That

0:05:15.520 --> 0:05:18.800
<v Speaker 1>over time they would be adopted by militaries around the

0:05:18.800 --> 0:05:22.320
<v Speaker 1>world to send secret communications back and forth between headquarters

0:05:22.360 --> 0:05:25.440
<v Speaker 1>and units in the field, and these communications needed to

0:05:25.440 --> 0:05:30.880
<v Speaker 1>be much more secure than a Caesar cipher could potentially offer.

0:05:31.520 --> 0:05:35.640
<v Speaker 1>So the basic idea behind these cipher machines was that

0:05:35.680 --> 0:05:38.440
<v Speaker 1>you would have a device. Sometimes it would look like

0:05:38.480 --> 0:05:41.279
<v Speaker 1>a typewriter, sometimes it would have a hand crank on it,

0:05:41.600 --> 0:05:45.280
<v Speaker 1>but typically there'd be at least one dial, if not

0:05:45.480 --> 0:05:48.640
<v Speaker 1>several dials, and perhaps some other components that would allow

0:05:48.640 --> 0:05:52.359
<v Speaker 1>the operator to set the machine to establish the cipher.

0:05:53.000 --> 0:05:56.520
<v Speaker 1>So you choose your settings, and then the operator would

0:05:56.520 --> 0:06:00.320
<v Speaker 1>take a message that is meant to be encoded and

0:06:00.360 --> 0:06:03.120
<v Speaker 1>then put it through this machine in some way. Maybe

0:06:03.160 --> 0:06:06.359
<v Speaker 1>they're using a keyboard, maybe they're using a series of

0:06:06.440 --> 0:06:10.960
<v Speaker 1>keys and levers. However it may be they're actually typing

0:06:11.000 --> 0:06:15.080
<v Speaker 1>out the message in plain text. But the cipher machines

0:06:15.120 --> 0:06:17.800
<v Speaker 1>would have some sort of gears or other chains or

0:06:17.880 --> 0:06:21.000
<v Speaker 1>systems that would turn with each letter type, and it

0:06:21.000 --> 0:06:23.800
<v Speaker 1>would change the cipher as it did, so change the

0:06:23.880 --> 0:06:26.599
<v Speaker 1>nature of it. And this was a really clever way

0:06:26.720 --> 0:06:30.960
<v Speaker 1>to confound code breakers, particularly if the machine was really

0:06:31.000 --> 0:06:35.359
<v Speaker 1>well designed. So let's say you are an operator and

0:06:35.640 --> 0:06:39.200
<v Speaker 1>you have the word book that you need to encode

0:06:39.400 --> 0:06:41.919
<v Speaker 1>using one of these machines. So you have one of

0:06:41.920 --> 0:06:46.000
<v Speaker 1>these particular machines, You type the letter B into the device, which,

0:06:46.000 --> 0:06:49.560
<v Speaker 1>because of the settings for this particular session, will now

0:06:49.640 --> 0:06:52.960
<v Speaker 1>print out the letter G. So the letter G means

0:06:53.240 --> 0:06:57.159
<v Speaker 1>be with this particular cipher. The gears inside the machine

0:06:57.200 --> 0:07:00.560
<v Speaker 1>turn after you've typed in the letter B, which prints

0:07:00.560 --> 0:07:03.200
<v Speaker 1>out is G, So now the cipher is actually different.

0:07:03.560 --> 0:07:06.400
<v Speaker 1>You type in the first OH in book and you

0:07:06.440 --> 0:07:09.880
<v Speaker 1>get another G because of the way the cipher works.

0:07:10.360 --> 0:07:13.400
<v Speaker 1>Then the gears turn again. You type in the second OH,

0:07:13.440 --> 0:07:16.200
<v Speaker 1>and now the machine prints out the letter F. The

0:07:16.200 --> 0:07:18.880
<v Speaker 1>gears turn again, you type out the letter K, and

0:07:18.960 --> 0:07:22.360
<v Speaker 1>you get the print out of K, so the printed

0:07:22.400 --> 0:07:28.120
<v Speaker 1>word says G G F K rather than book. Well,

0:07:28.160 --> 0:07:31.120
<v Speaker 1>to decode the message, you would typically need the same

0:07:31.160 --> 0:07:33.840
<v Speaker 1>sort of machine that was used to encode it, and

0:07:33.880 --> 0:07:36.280
<v Speaker 1>you would need to know what settings the operator had

0:07:36.320 --> 0:07:38.840
<v Speaker 1>been using when they started the message, and you would

0:07:38.840 --> 0:07:42.960
<v Speaker 1>have to set up your machine to mirror that, and

0:07:43.000 --> 0:07:46.320
<v Speaker 1>then you would end up taking the encoded message and

0:07:46.320 --> 0:07:49.320
<v Speaker 1>you would start typing that out and the process would

0:07:49.400 --> 0:07:52.360
<v Speaker 1>essentially reverse itself, and it would allow the operator to

0:07:52.440 --> 0:07:56.920
<v Speaker 1>read out the original message. So in our example, the

0:07:57.000 --> 0:07:59.560
<v Speaker 1>operator on the other side would take g g F

0:07:59.720 --> 0:08:02.440
<v Speaker 1>K and enter that into their machine and they would

0:08:02.440 --> 0:08:06.320
<v Speaker 1>get the print out book. Now a couple of caveats here.

0:08:07.000 --> 0:08:10.320
<v Speaker 1>Not all cipher machines are created equal right or were

0:08:10.440 --> 0:08:15.400
<v Speaker 1>used to their best advantage. Sometimes people made bad decisions

0:08:15.440 --> 0:08:19.560
<v Speaker 1>when it came to either designing cipher machines or implementing them.

0:08:19.680 --> 0:08:22.720
<v Speaker 1>For example, the big wigs might decide that in no

0:08:22.840 --> 0:08:27.640
<v Speaker 1>circumstance would you ever have a letter represented by itself.

0:08:27.680 --> 0:08:30.440
<v Speaker 1>You would never allow that to happen. So in the

0:08:30.480 --> 0:08:34.959
<v Speaker 1>example I just gave where g g F K means book,

0:08:35.640 --> 0:08:38.880
<v Speaker 1>that last k wouldn't work. You would have to have

0:08:39.000 --> 0:08:42.480
<v Speaker 1>them the device go to a different letter because it

0:08:42.480 --> 0:08:46.120
<v Speaker 1>would not allow itself to replicate a letter with the

0:08:46.160 --> 0:08:50.240
<v Speaker 1>representation of itself. Other rules that could cause problems on

0:08:50.280 --> 0:08:52.800
<v Speaker 1>the role road might be a rule against the doubling

0:08:53.000 --> 0:08:55.920
<v Speaker 1>of letters like the g G in g g F K.

0:08:56.640 --> 0:09:00.480
<v Speaker 1>And the reason that these are problems is that if

0:09:00.520 --> 0:09:03.840
<v Speaker 1>you have a code breaker who's really looking at these

0:09:03.840 --> 0:09:07.120
<v Speaker 1>codes closely, and that code breaker starts to figure out

0:09:07.120 --> 0:09:10.480
<v Speaker 1>that there are restrictions to the code they can build

0:09:10.559 --> 0:09:13.400
<v Speaker 1>that into their code breaking models in an effort to

0:09:13.480 --> 0:09:16.880
<v Speaker 1>crack the code, because as you put in restrictions, that

0:09:16.920 --> 0:09:20.280
<v Speaker 1>means you're reducing variables. And anyone who has worked in

0:09:20.320 --> 0:09:24.480
<v Speaker 1>any sort of mathematics, particularly stuff like algebra, you know

0:09:25.080 --> 0:09:28.880
<v Speaker 1>that to solve complicated problems you need to reduce variables.

0:09:28.920 --> 0:09:33.079
<v Speaker 1>As you reduce variables, you make it easier to solve problems.

0:09:33.120 --> 0:09:35.080
<v Speaker 1>So it was actually this sort of thing that would

0:09:35.160 --> 0:09:38.720
<v Speaker 1>lead to the British cryptographers breaking German codes during World

0:09:38.720 --> 0:09:43.360
<v Speaker 1>War Two. It wasn't that the technology itself was necessarily faulty.

0:09:43.440 --> 0:09:46.720
<v Speaker 1>It was that the Germans were kind of using bad

0:09:46.800 --> 0:09:51.080
<v Speaker 1>methodology with some of their their equipment, and that's what

0:09:51.400 --> 0:09:55.240
<v Speaker 1>gave an in road for code breakers. Now, if you

0:09:55.280 --> 0:09:59.199
<v Speaker 1>want to learn way more about how these machines actually work,

0:09:59.640 --> 0:10:03.319
<v Speaker 1>you can listen to tech Stuff Ponders and Enigma. That's

0:10:03.320 --> 0:10:07.680
<v Speaker 1>a classic episode that originally published way back on October nineteen,

0:10:07.880 --> 0:10:11.079
<v Speaker 1>two thousand eleven, and I actually did a tech Stuff

0:10:11.160 --> 0:10:15.760
<v Speaker 1>classic rerun of that episode on October twelfth, two thousand eighteen.

0:10:16.360 --> 0:10:20.440
<v Speaker 1>The Enigma machine is the most famous cipher device that

0:10:20.520 --> 0:10:23.280
<v Speaker 1>was made in the early twentieth century. It was made

0:10:23.880 --> 0:10:26.840
<v Speaker 1>and used by the Germans, and it was used extensively

0:10:27.040 --> 0:10:30.040
<v Speaker 1>by the German military during World War Two. And in

0:10:30.080 --> 0:10:32.600
<v Speaker 1>that podcast, my old co host Chris Pallette and I

0:10:32.640 --> 0:10:36.840
<v Speaker 1>talked about how a really good cipher, one that's super

0:10:36.920 --> 0:10:40.040
<v Speaker 1>hard to crack, is also a pain in the patukas

0:10:40.520 --> 0:10:44.120
<v Speaker 1>to use because of that complexity, and that's mainly why

0:10:44.160 --> 0:10:47.679
<v Speaker 1>officials would put rules in place that ultimately would serve

0:10:47.720 --> 0:10:51.560
<v Speaker 1>as the downfall for their technology, because using the tech

0:10:51.640 --> 0:10:54.720
<v Speaker 1>without those rules in place was possible, but not always

0:10:54.880 --> 0:10:58.280
<v Speaker 1>fast enough to be practical. This would prove to be

0:10:58.320 --> 0:11:01.080
<v Speaker 1>a problem with cryptography and gen role. You want a

0:11:01.120 --> 0:11:04.880
<v Speaker 1>system that's secure enough that you're reasonably certain a person

0:11:04.920 --> 0:11:08.240
<v Speaker 1>who intercepts the message would be unable to make head

0:11:08.320 --> 0:11:10.320
<v Speaker 1>or tail of it, right, That's the whole purpose of

0:11:10.320 --> 0:11:14.920
<v Speaker 1>cryptography is to make any unauthorized person incapable of reading

0:11:14.960 --> 0:11:18.920
<v Speaker 1>the message. But you also want your solution to be

0:11:18.960 --> 0:11:22.960
<v Speaker 1>practical enough that your intended recipient can decode the message

0:11:23.160 --> 0:11:26.440
<v Speaker 1>with a minimum of fuss, particularly if it relates to

0:11:26.520 --> 0:11:30.200
<v Speaker 1>a time sensitive issue. So in this case, you had

0:11:30.280 --> 0:11:33.920
<v Speaker 1>Germans using the same settings on their Enigma machines for

0:11:34.080 --> 0:11:37.360
<v Speaker 1>longer than they were supposed to, or they were co

0:11:37.600 --> 0:11:41.120
<v Speaker 1>locating codebooks with the Enigma machines and those fell into

0:11:41.200 --> 0:11:45.520
<v Speaker 1>Allied hands who were able to use those to decode messages.

0:11:45.760 --> 0:11:50.400
<v Speaker 1>To this day, balancing out practical applications with security remains

0:11:50.400 --> 0:11:54.320
<v Speaker 1>a challenge. It may make it take longer for a

0:11:54.320 --> 0:11:57.360
<v Speaker 1>message to get through from one point to another, which

0:11:57.400 --> 0:12:00.520
<v Speaker 1>a lot of people don't accept in the age of

0:12:00.920 --> 0:12:04.160
<v Speaker 1>information traveling at the speed of light, or it just

0:12:04.280 --> 0:12:09.199
<v Speaker 1>maybe a pain to encrypt and decrypt, which also ends

0:12:09.280 --> 0:12:13.640
<v Speaker 1>up becoming a barrier to adoption and implementation. Okay, let's

0:12:13.640 --> 0:12:16.920
<v Speaker 1>get back to our story. So it's the nineteen tens.

0:12:17.000 --> 0:12:20.760
<v Speaker 1>Rights around nineteen fifteen, Ared Garad Doam has patented an

0:12:20.840 --> 0:12:24.800
<v Speaker 1>encryption device. He got that patent by nineteen nineteen, and

0:12:24.880 --> 0:12:28.440
<v Speaker 1>to manufacture and market the device, don would work with

0:12:28.480 --> 0:12:33.760
<v Speaker 1>business partners to create a company originally called Cryptograph or

0:12:33.840 --> 0:12:37.480
<v Speaker 1>a b Cryptograph, and one of Dom's investors was a

0:12:37.520 --> 0:12:41.800
<v Speaker 1>guy named Carl Wilhelm Haglin who had made his money

0:12:41.840 --> 0:12:45.000
<v Speaker 1>in Russia in the oil business. But then the Russian

0:12:45.040 --> 0:12:48.480
<v Speaker 1>Revolution happened and Haglin fled with his family and they

0:12:48.520 --> 0:12:52.600
<v Speaker 1>returned to Haglin's homeland of Sweden. They brought the family

0:12:52.640 --> 0:12:56.920
<v Speaker 1>with them and uh and Boris Hagelin was was Carl

0:12:56.960 --> 0:13:00.080
<v Speaker 1>Wilhelm Haglin's son, and Boris was given a position and

0:13:00.640 --> 0:13:04.960
<v Speaker 1>in Dom's company in return for this financial investment from

0:13:05.000 --> 0:13:07.839
<v Speaker 1>his father. Now Boris would actually prove to be quite

0:13:07.840 --> 0:13:11.760
<v Speaker 1>the entrepreneur. In nineteen twenty five, he would take over

0:13:11.960 --> 0:13:15.640
<v Speaker 1>the company entirely. He became the new head of the company.

0:13:15.679 --> 0:13:19.640
<v Speaker 1>He would rename it Crypto Technic in nineteen thirty two,

0:13:20.080 --> 0:13:23.080
<v Speaker 1>and then when the Nazis rose to power, he fled

0:13:23.240 --> 0:13:27.559
<v Speaker 1>Sweden for Switzerland and re established his company there. And

0:13:27.720 --> 0:13:30.880
<v Speaker 1>it was this company that he established that would later

0:13:31.040 --> 0:13:34.559
<v Speaker 1>become known as Crypto a g the focus of our

0:13:34.720 --> 0:13:38.760
<v Speaker 1>episode really. In the meantime, his company continued to produce

0:13:38.920 --> 0:13:42.439
<v Speaker 1>new cipher machines, incorporating new features in an effort to

0:13:42.480 --> 0:13:45.880
<v Speaker 1>build machines that were able to create stronger codes. And

0:13:45.920 --> 0:13:49.480
<v Speaker 1>again this was mostly for business use or occasional government use,

0:13:49.760 --> 0:13:52.160
<v Speaker 1>but the rise of World War Two would create a

0:13:52.160 --> 0:13:55.640
<v Speaker 1>new market as military sought ways to send messages securely

0:13:56.040 --> 0:13:59.040
<v Speaker 1>without fear that their plans would be shown to an enemy,

0:13:59.440 --> 0:14:02.679
<v Speaker 1>and that when the United States would enter into the picture,

0:14:02.920 --> 0:14:06.200
<v Speaker 1>setting the stage for the company's future in ways Haglin

0:14:06.440 --> 0:14:11.240
<v Speaker 1>could not have anticipated. I'll explain more when we come back,

0:14:11.280 --> 0:14:21.920
<v Speaker 1>but first let's take a quick break. So, when World

0:14:21.960 --> 0:14:25.960
<v Speaker 1>War two broke out, the United States military would become

0:14:26.120 --> 0:14:29.280
<v Speaker 1>one of Crypto a g s customers, and when the

0:14:29.360 --> 0:14:34.200
<v Speaker 1>Nazis invaded Norway in Haglin would again move operations. This

0:14:34.240 --> 0:14:38.600
<v Speaker 1>time he moved to the United States. His company's encryption device,

0:14:38.760 --> 0:14:41.640
<v Speaker 1>known as the M two oh nine, would be produced

0:14:41.720 --> 0:14:45.160
<v Speaker 1>in the US. According to The Washington Post, there was

0:14:45.160 --> 0:14:47.960
<v Speaker 1>a typewriter factory in upstate New York that would end

0:14:48.080 --> 0:14:52.160
<v Speaker 1>up making around a hundred forty thousand of these M

0:14:52.200 --> 0:14:56.720
<v Speaker 1>two oh nine encryption devices, and Haglin negotiated with the U. S.

0:14:56.800 --> 0:15:01.560
<v Speaker 1>Army and landed an eight point six million dollar contract.

0:15:02.000 --> 0:15:06.600
<v Speaker 1>A princely some today, but certainly a princely some way

0:15:06.600 --> 0:15:12.440
<v Speaker 1>back in nineteen Haiglin's devices lacked the sophistication of Germany's

0:15:12.560 --> 0:15:16.720
<v Speaker 1>Enigma machine. They weren't nearly as complex, nor were they

0:15:16.960 --> 0:15:23.440
<v Speaker 1>as capable of creating very tough encryption, so code breakers

0:15:23.560 --> 0:15:27.000
<v Speaker 1>could suss out the original messages that were created on

0:15:27.040 --> 0:15:29.560
<v Speaker 1>an M to two oh nine if they were given

0:15:29.640 --> 0:15:33.040
<v Speaker 1>enough time and attention, and for that reason the army

0:15:33.160 --> 0:15:38.560
<v Speaker 1>primarily relied on these devices to disguise extremely time sensitive orders.

0:15:38.800 --> 0:15:41.720
<v Speaker 1>So the logic was, by the time someone had actually

0:15:41.760 --> 0:15:45.640
<v Speaker 1>broken the code, the information would be worthless anyway, because

0:15:45.680 --> 0:15:49.040
<v Speaker 1>whatever was being covered in the message would have already happened.

0:15:49.400 --> 0:15:52.280
<v Speaker 1>It would have been something that was more imminent, so

0:15:52.320 --> 0:15:54.240
<v Speaker 1>you wouldn't be able to act on the information, even

0:15:54.280 --> 0:15:56.480
<v Speaker 1>though you'd be able to at least decode what had

0:15:56.560 --> 0:15:59.840
<v Speaker 1>been said. So you wouldn't want to use these devices

0:15:59.880 --> 0:16:04.880
<v Speaker 1>for any sort of long term plans because they were crackable.

0:16:05.040 --> 0:16:09.200
<v Speaker 1>People could crack the codes we given enough a time now.

0:16:09.920 --> 0:16:13.720
<v Speaker 1>Around that same time, Haglin became good friends with another

0:16:13.760 --> 0:16:19.080
<v Speaker 1>cryptographer named William Friedman. Freeman was born in Russia. Actually,

0:16:19.120 --> 0:16:24.480
<v Speaker 1>so was Haglin. Haglin's parents were Swedish, but when they

0:16:24.480 --> 0:16:28.280
<v Speaker 1>had Boris he was the family was in Russia, so

0:16:28.400 --> 0:16:31.720
<v Speaker 1>Freedman's family left Russia when Freedman was just a baby

0:16:32.000 --> 0:16:35.040
<v Speaker 1>back in eighteen ninety two due to a rise in

0:16:35.160 --> 0:16:39.360
<v Speaker 1>anti Semitism in Russia, and Freedman his family is Jewish.

0:16:39.600 --> 0:16:44.480
<v Speaker 1>So Freeman grew up loving codes and cryptography and became

0:16:44.520 --> 0:16:49.000
<v Speaker 1>fascinated with them. Uh, he joined a private research lab.

0:16:49.440 --> 0:16:52.440
<v Speaker 1>He met and then courted and then married a woman

0:16:52.520 --> 0:16:57.000
<v Speaker 1>named Elizabeth Smith, who on her own was an accomplished cryptographer,

0:16:57.040 --> 0:17:00.720
<v Speaker 1>a brilliant cryptographer, and they both sort of worked for

0:17:00.880 --> 0:17:03.280
<v Speaker 1>George Fabian, and that was the guy who owned the

0:17:03.320 --> 0:17:06.320
<v Speaker 1>private research lab. Fabian sounds like the sort of person

0:17:06.400 --> 0:17:11.359
<v Speaker 1>who really belonged in the Renaissance as far as I'm concerned.

0:17:11.680 --> 0:17:15.080
<v Speaker 1>In the Renaissance, you had rich nobles who would become

0:17:15.119 --> 0:17:21.560
<v Speaker 1>patrons of great thinkers and philosophers and artists. Fabian he

0:17:21.680 --> 0:17:24.560
<v Speaker 1>established this private research lab in order to look into

0:17:24.600 --> 0:17:26.760
<v Speaker 1>stuff that he just thought was interesting, which I think

0:17:26.840 --> 0:17:30.199
<v Speaker 1>is kind of cool, maybe a little eccentric. Well, when

0:17:30.240 --> 0:17:34.399
<v Speaker 1>the United States entered World War One, the Freedman's husband

0:17:34.440 --> 0:17:37.399
<v Speaker 1>and wife would work in code breaking for the United States,

0:17:37.880 --> 0:17:42.239
<v Speaker 1>and the cryptologic division of the research lab became the

0:17:42.280 --> 0:17:47.600
<v Speaker 1>genesis for the American Cryptography Service, So William Freeman would

0:17:47.640 --> 0:17:50.840
<v Speaker 1>later become the chief crypto analyst. In fact, he termed

0:17:51.000 --> 0:17:54.880
<v Speaker 1>the are, coined the term crypto analysis for the United States,

0:17:54.960 --> 0:17:59.640
<v Speaker 1>and would lead the future Signals Intelligence Service before going

0:17:59.640 --> 0:18:03.800
<v Speaker 1>on to serve in other intelligence agencies as a cryptographer,

0:18:04.080 --> 0:18:07.719
<v Speaker 1>so Freedman was very much working in the same world

0:18:07.840 --> 0:18:10.240
<v Speaker 1>as Hagland, though you could say that these were from

0:18:10.240 --> 0:18:13.920
<v Speaker 1>opposing perspectives, right, because Hagland's company was all about producing

0:18:13.920 --> 0:18:17.800
<v Speaker 1>machines that could in cipher messages, while Freedman was largely

0:18:17.920 --> 0:18:22.000
<v Speaker 1>interested in finding methods to de cipher codes. Though Freeman

0:18:22.040 --> 0:18:24.800
<v Speaker 1>also worked in in theory as well to talk about

0:18:24.880 --> 0:18:28.400
<v Speaker 1>different ways to create stronger ciphers. And we'll come back

0:18:28.440 --> 0:18:31.320
<v Speaker 1>to Freedman in just a moment. So Haglin would stay

0:18:31.320 --> 0:18:34.600
<v Speaker 1>in the US until World War Two ended in Europe,

0:18:34.880 --> 0:18:37.960
<v Speaker 1>and he had become extremely wealthy due to the lucrative

0:18:38.040 --> 0:18:40.640
<v Speaker 1>army contract he had made, and he had built many

0:18:40.680 --> 0:18:43.359
<v Speaker 1>professional and personal relationships in the United States, so he

0:18:43.400 --> 0:18:47.440
<v Speaker 1>would have strong ties to the US. He then returned

0:18:47.520 --> 0:18:52.160
<v Speaker 1>to Europe to again re establish his company there. Meanwhile,

0:18:52.720 --> 0:18:56.120
<v Speaker 1>American intelligence officials were starting to get a little worried

0:18:56.359 --> 0:19:00.680
<v Speaker 1>because code breaking was growing increasingly difficult due to sophisticated

0:19:00.680 --> 0:19:05.720
<v Speaker 1>machines running complicated systems to create these codes. And if

0:19:05.760 --> 0:19:09.600
<v Speaker 1>you had little insight into how those machines worked or

0:19:09.880 --> 0:19:13.840
<v Speaker 1>which systems they were following at any given time, you

0:19:13.880 --> 0:19:16.439
<v Speaker 1>had really little hope of breaking a code in a

0:19:16.480 --> 0:19:19.199
<v Speaker 1>reasonable amount of time. So it's very clear that a

0:19:19.200 --> 0:19:23.240
<v Speaker 1>lot of people were having really secret conversations that American

0:19:23.320 --> 0:19:26.920
<v Speaker 1>spies were unable to decipher, and that just rubbed the

0:19:26.960 --> 0:19:31.400
<v Speaker 1>Americans the wrong way. I'm gonna get a little critical

0:19:31.640 --> 0:19:35.920
<v Speaker 1>of my country in this episode. Uh. Anyway, in nineteen

0:19:36.000 --> 0:19:40.600
<v Speaker 1>fifty one, Haigland's company introduced the c X fifty two

0:19:40.760 --> 0:19:44.359
<v Speaker 1>cipher machine, and this one was sophisticated enough to present

0:19:44.359 --> 0:19:48.960
<v Speaker 1>a code that American intelligence agents viewed as practically unbreakable

0:19:49.000 --> 0:19:53.440
<v Speaker 1>at the time, and that in turn prompted some heated

0:19:53.560 --> 0:19:58.399
<v Speaker 1>internal discussions within the U. S Intelligence community and what

0:19:58.480 --> 0:20:00.960
<v Speaker 1>should officials do about this? Because there was a real

0:20:01.080 --> 0:20:05.840
<v Speaker 1>worry that countries might go out and buy Haglin's products.

0:20:06.040 --> 0:20:08.800
<v Speaker 1>I mean, that's what Haglin was making them for, and

0:20:08.880 --> 0:20:10.920
<v Speaker 1>if they did that, they would all be able to

0:20:10.960 --> 0:20:14.840
<v Speaker 1>communicate secretly and Americans would be unable to snoop out

0:20:14.840 --> 0:20:18.920
<v Speaker 1>what was going on. And boy, howdy does America hate that.

0:20:19.400 --> 0:20:22.639
<v Speaker 1>So American officials gave a sort of carrot and a

0:20:22.760 --> 0:20:26.840
<v Speaker 1>stick offer to Haglin. So on the one hand, they

0:20:27.119 --> 0:20:29.840
<v Speaker 1>were a big customer for his company. Right the United

0:20:29.880 --> 0:20:36.000
<v Speaker 1>States represented a significant potential customer for Hagland's products. He

0:20:36.040 --> 0:20:38.520
<v Speaker 1>didn't want that source of revenue to go away. So

0:20:39.000 --> 0:20:42.959
<v Speaker 1>there was that they also had a whole bunch of

0:20:43.000 --> 0:20:47.679
<v Speaker 1>old M two o nine cipher devices that were manufactured

0:20:47.720 --> 0:20:51.760
<v Speaker 1>in America during World War Two, and there was at

0:20:51.800 --> 0:20:56.239
<v Speaker 1>least the implied threat that if Haglin wouldn't be you know,

0:20:56.600 --> 0:21:01.120
<v Speaker 1>cooperative with the US, maybe the America can might let

0:21:01.160 --> 0:21:04.320
<v Speaker 1>a few thousand M two oh nine's get sold off

0:21:04.320 --> 0:21:07.879
<v Speaker 1>to countries around the world, and that would undercut Crypto's

0:21:07.960 --> 0:21:11.160
<v Speaker 1>own sales in the process. I mean, if you are

0:21:12.200 --> 0:21:14.919
<v Speaker 1>a kind of you know, the head of an agency

0:21:15.200 --> 0:21:19.879
<v Speaker 1>in a smaller country with limited resources, and the United

0:21:19.920 --> 0:21:23.119
<v Speaker 1>States says, hey, we'll sell you these old but totally

0:21:23.240 --> 0:21:27.840
<v Speaker 1>working cipher machines for much less than that brand new,

0:21:27.880 --> 0:21:31.040
<v Speaker 1>shiny cipher machine. You're gonna go with the cheaper model

0:21:31.080 --> 0:21:34.240
<v Speaker 1>as long as it works, and that means that Crypto

0:21:34.400 --> 0:21:38.800
<v Speaker 1>would not be making any sales. Uh. Then there was

0:21:38.880 --> 0:21:43.760
<v Speaker 1>William Freedman, Haglin's old buddy. In nineteen fifty one. Freeman

0:21:43.840 --> 0:21:46.840
<v Speaker 1>was then serving as the head of the cryptographic Division

0:21:46.960 --> 0:21:50.840
<v Speaker 1>of the Armed Forces Security Agency or AFSA. A f

0:21:51.280 --> 0:21:54.160
<v Speaker 1>s A. The following year he would become the head

0:21:54.240 --> 0:21:58.199
<v Speaker 1>of the cryptology Department for the National Security Agency or

0:21:58.280 --> 0:22:02.560
<v Speaker 1>the n s A. It was in when Freedman would

0:22:02.560 --> 0:22:05.200
<v Speaker 1>act on behalf of the U. S Government and met

0:22:05.560 --> 0:22:10.199
<v Speaker 1>secretly with Haglin in Washington, d C. So Freedman goes

0:22:10.280 --> 0:22:17.080
<v Speaker 1>up to Haglin with a fairly thorny proposition. The deal

0:22:17.160 --> 0:22:21.239
<v Speaker 1>was this, Haglin was to continue creating cipher machines just

0:22:21.280 --> 0:22:24.920
<v Speaker 1>as the company had been, but Crypto would only sell

0:22:25.200 --> 0:22:29.240
<v Speaker 1>the most sophisticated of those machines to a list of

0:22:29.280 --> 0:22:33.080
<v Speaker 1>countries that the United States would provide to Haglin, and

0:22:33.160 --> 0:22:37.160
<v Speaker 1>that would represent countries with whom the US had very

0:22:37.200 --> 0:22:40.720
<v Speaker 1>good relations, so allies and that sort of thing. They

0:22:40.720 --> 0:22:43.040
<v Speaker 1>were the only countries who would be allowed to buy

0:22:43.600 --> 0:22:47.719
<v Speaker 1>the top of the line products. Crypto would be allowed

0:22:47.760 --> 0:22:52.880
<v Speaker 1>to sell older, more vulnerable or weak machines to any

0:22:52.920 --> 0:22:56.080
<v Speaker 1>country that was not on that list. So, in other words,

0:22:56.280 --> 0:23:00.399
<v Speaker 1>Freeman was asking Haglin to kind of put on a

0:23:00.440 --> 0:23:05.840
<v Speaker 1>preference list certain countries and then everyone else would get older,

0:23:06.600 --> 0:23:11.879
<v Speaker 1>more vulnerable technologies. Uh. However, that's the extent of that deal.

0:23:12.080 --> 0:23:14.040
<v Speaker 1>It didn't go further than that, but it's still a

0:23:14.040 --> 0:23:17.600
<v Speaker 1>pretty big request. And you can kind of understand where

0:23:17.640 --> 0:23:20.639
<v Speaker 1>the US was coming from. At least, you know, they

0:23:21.440 --> 0:23:23.760
<v Speaker 1>clearly did not want the job to be even harder

0:23:23.880 --> 0:23:28.600
<v Speaker 1>when it came to breaking codes. And Haglin would ultimately

0:23:28.640 --> 0:23:31.280
<v Speaker 1>agree to this deal. And whether it was he saw

0:23:31.359 --> 0:23:33.600
<v Speaker 1>a guaranteed payout from the US and so it was

0:23:33.600 --> 0:23:36.720
<v Speaker 1>strictly a business decision. He just felt it was impossible

0:23:36.760 --> 0:23:39.560
<v Speaker 1>to turn down this offer, or he felt a strong

0:23:39.640 --> 0:23:42.320
<v Speaker 1>sense of loyalty toward a country that had made him

0:23:42.320 --> 0:23:45.320
<v Speaker 1>a millionaire, or maybe it was some combination of these

0:23:45.359 --> 0:23:47.959
<v Speaker 1>and other factors. I don't know, but whatever it was,

0:23:48.280 --> 0:23:51.919
<v Speaker 1>he said yes. And this would mark the beginning of

0:23:51.960 --> 0:23:55.840
<v Speaker 1>the U S intelligence community having a direct interest in

0:23:55.920 --> 0:24:00.920
<v Speaker 1>a company that was selling cryptographic equipment, that is Crypto.

0:24:01.240 --> 0:24:04.440
<v Speaker 1>But at this point it was still a fairly limited agreement.

0:24:04.560 --> 0:24:07.639
<v Speaker 1>Crypto could still sell equipment to countries all around the world,

0:24:08.040 --> 0:24:11.280
<v Speaker 1>though any country that was not on the US Best

0:24:11.359 --> 0:24:14.280
<v Speaker 1>Buddy list would only have access to the older devices.

0:24:14.800 --> 0:24:19.480
<v Speaker 1>Now this wasn't because US officials were feeling benevolent or

0:24:19.520 --> 0:24:21.639
<v Speaker 1>anything like that. I don't want to paint paint in

0:24:21.680 --> 0:24:25.320
<v Speaker 1>his that there was a very real desire in America

0:24:25.600 --> 0:24:30.240
<v Speaker 1>to push Crypto for a much more shady deal. Intelligence

0:24:30.280 --> 0:24:33.920
<v Speaker 1>officials were hoping that they could work directly with Crypto

0:24:34.000 --> 0:24:38.040
<v Speaker 1>to design machines that would produced codes that Americans could

0:24:38.200 --> 0:24:42.400
<v Speaker 1>quickly break. People would think they were sending secure messages,

0:24:42.600 --> 0:24:45.160
<v Speaker 1>but in reality the Americans would be able to decode

0:24:45.160 --> 0:24:49.440
<v Speaker 1>those messages fairly quickly. But William Friedman discouraged anyone from

0:24:49.440 --> 0:24:53.360
<v Speaker 1>America from going to Hagland with such an offer for

0:24:53.400 --> 0:24:56.679
<v Speaker 1>several years. He said Haglin would never go for it.

0:24:56.680 --> 0:24:59.199
<v Speaker 1>It would be deeply offensive to him. You're going to

0:24:59.240 --> 0:25:03.000
<v Speaker 1>destroy this or relationship we have. Let's not you know,

0:25:03.080 --> 0:25:06.280
<v Speaker 1>let's let's let's hold back rather than have a loss.

0:25:06.960 --> 0:25:09.320
<v Speaker 1>And hey, there were other companies out there, right, I mean,

0:25:09.480 --> 0:25:12.280
<v Speaker 1>it's it's not like you had to buy from Crypto

0:25:12.440 --> 0:25:14.520
<v Speaker 1>or else you'd have no way to communicate secretly. You

0:25:14.560 --> 0:25:18.600
<v Speaker 1>could always get cipher machines and cryptography machines from some

0:25:18.680 --> 0:25:22.159
<v Speaker 1>other source, right well. Part of the deal that the

0:25:22.280 --> 0:25:26.000
<v Speaker 1>US made included substantial amounts of money meant to go

0:25:26.119 --> 0:25:30.160
<v Speaker 1>toward marketing. The US wanted Crypto to be the world

0:25:30.480 --> 0:25:34.920
<v Speaker 1>leader in the market for this sort of of device,

0:25:35.400 --> 0:25:37.760
<v Speaker 1>mostly in an effort to make sure that some other

0:25:37.840 --> 0:25:41.399
<v Speaker 1>crypto company didn't come along with better, more difficult to

0:25:41.520 --> 0:25:45.240
<v Speaker 1>crack solutions, because that would just set America back again.

0:25:45.320 --> 0:25:48.800
<v Speaker 1>So the US supplied money year after year to Crypto

0:25:48.880 --> 0:25:51.919
<v Speaker 1>to renew this agreement and to keep the company going

0:25:52.119 --> 0:25:54.920
<v Speaker 1>even if things should get lean. All the while trying

0:25:54.960 --> 0:25:58.879
<v Speaker 1>to promote cryptos products and hold back any of cryptos

0:25:58.880 --> 0:26:04.080
<v Speaker 1>competitors was pretty brutal. Things slowly began to change as

0:26:04.119 --> 0:26:07.520
<v Speaker 1>time went on. The invention of the transistor would bring

0:26:07.560 --> 0:26:11.399
<v Speaker 1>on tons of innovation and maniaturization. So in the past,

0:26:11.880 --> 0:26:15.760
<v Speaker 1>electric circuits were physically enormous because you had to have

0:26:15.840 --> 0:26:18.960
<v Speaker 1>components like vacuum tubes, and those took up a lot

0:26:19.000 --> 0:26:21.240
<v Speaker 1>of space, and they also gave off a lot of heat,

0:26:21.320 --> 0:26:24.440
<v Speaker 1>which generally is bad not just for humans but also

0:26:24.560 --> 0:26:28.040
<v Speaker 1>for electronics. But in the mid nineteen sixties that was

0:26:28.080 --> 0:26:31.000
<v Speaker 1>all starting to change. Electronic circuits could now be made

0:26:31.080 --> 0:26:33.919
<v Speaker 1>much smaller thanks to the transistor, and they made it

0:26:33.960 --> 0:26:38.159
<v Speaker 1>possible for all sorts of new gadgets like pocket radios

0:26:38.240 --> 0:26:41.720
<v Speaker 1>and desktop computers. Further down the line, and yes, new

0:26:41.800 --> 0:26:46.920
<v Speaker 1>types of cryptographic machines Haglin was facing a very real

0:26:46.960 --> 0:26:51.600
<v Speaker 1>problem at that point. His company was built around mechanical

0:26:52.200 --> 0:26:57.320
<v Speaker 1>cryptographic devices. These were machines that relied on physical components

0:26:57.359 --> 0:27:02.400
<v Speaker 1>like gears and levers and chains. But the electronic era

0:27:02.560 --> 0:27:06.240
<v Speaker 1>was heading in a different direction and the crypto company

0:27:06.480 --> 0:27:09.840
<v Speaker 1>wasn't in a position to keep up. If Haglin wanted

0:27:09.840 --> 0:27:13.400
<v Speaker 1>to compete, he was going to need help. And when

0:27:13.440 --> 0:27:17.639
<v Speaker 1>someone needs help, that means they are vulnerable. Now, if

0:27:17.640 --> 0:27:19.880
<v Speaker 1>you're in a position to help someone, you can more

0:27:19.960 --> 0:27:23.360
<v Speaker 1>or less selflessly help that person to get them out

0:27:23.400 --> 0:27:28.560
<v Speaker 1>of that vulnerable position, or you can attempt to exploit it.

0:27:29.080 --> 0:27:31.679
<v Speaker 1>And the U S Intelligence community, with the n s

0:27:31.760 --> 0:27:36.080
<v Speaker 1>A at the forefront, took option number two. The n

0:27:36.160 --> 0:27:39.760
<v Speaker 1>s A, as I said, the National Security Agency was

0:27:39.840 --> 0:27:43.199
<v Speaker 1>founded in nineteen fifty two, just five years after the

0:27:43.240 --> 0:27:49.120
<v Speaker 1>Central Intelligence Agency was founded. It's primarily focused on signals intelligence,

0:27:49.480 --> 0:27:52.720
<v Speaker 1>and that is the interception and decoding of messages for

0:27:52.760 --> 0:27:56.800
<v Speaker 1>the purposes of gathering intelligence. Over at the n s A,

0:27:56.800 --> 0:28:01.520
<v Speaker 1>an analyst named Peter Jenks hypothesized that with care, you

0:28:01.560 --> 0:28:06.600
<v Speaker 1>could create an electronic cryptographic system that would seem to

0:28:06.720 --> 0:28:11.600
<v Speaker 1>be random, but it would actually depend upon a repeated

0:28:11.760 --> 0:28:15.760
<v Speaker 1>pattern at regular intervals, and a casual glance of the

0:28:15.800 --> 0:28:17.760
<v Speaker 1>code would make it seem as though the system was

0:28:17.800 --> 0:28:21.879
<v Speaker 1>following a complicated algorithm and producing an uncrackable code because

0:28:21.880 --> 0:28:25.760
<v Speaker 1>of some sort of random element. But the repetition of

0:28:25.760 --> 0:28:29.080
<v Speaker 1>the pattern would actually make code breakers with sufficient computing

0:28:29.080 --> 0:28:33.240
<v Speaker 1>power able to decode the messages. It wouldn't be easy,

0:28:33.480 --> 0:28:36.000
<v Speaker 1>it wouldn't be as simple as just running it through

0:28:36.000 --> 0:28:40.720
<v Speaker 1>a decoder, but because of that pattern, it would become possible. Again,

0:28:41.000 --> 0:28:47.640
<v Speaker 1>patterns represent restrictions. Restrictions are vulnerabilities, and vulnerabilities can be exploited,

0:28:48.080 --> 0:28:50.160
<v Speaker 1>so you can make a system that, at least on

0:28:50.280 --> 0:28:56.040
<v Speaker 1>casual glance, appears to be secure, but in reality it's not. So.

0:28:56.560 --> 0:28:59.040
<v Speaker 1>The n s A reaches out the Crypto, which is

0:28:59.120 --> 0:29:00.920
<v Speaker 1>really in need of x pertise in the form of

0:29:00.960 --> 0:29:06.080
<v Speaker 1>building electronic cryptographic machines, and Haglin welcomes the help because

0:29:06.080 --> 0:29:10.120
<v Speaker 1>otherwise his business is going to completely lose out. So

0:29:10.240 --> 0:29:12.800
<v Speaker 1>Crypto goes on to produce a machine called the H

0:29:12.960 --> 0:29:17.400
<v Speaker 1>four sixty based off the NSA's design. The company actually

0:29:17.400 --> 0:29:22.520
<v Speaker 1>made two versions of the H four sixty. One was compromised.

0:29:22.760 --> 0:29:25.120
<v Speaker 1>It used the n s as repeating pattern, so that

0:29:25.240 --> 0:29:27.960
<v Speaker 1>the agency could, with time and effort to code any

0:29:27.960 --> 0:29:31.720
<v Speaker 1>messages that were composed on that particular machine. The other

0:29:31.800 --> 0:29:35.360
<v Speaker 1>one was more secure, it didn't repeat the pattern. So

0:29:35.520 --> 0:29:39.320
<v Speaker 1>the United States was still fine with Crypto selling those machines,

0:29:39.400 --> 0:29:42.280
<v Speaker 1>the the good ones two countries that were still on

0:29:42.320 --> 0:29:45.840
<v Speaker 1>the US Best Buddy list. Everyone else would get the

0:29:45.880 --> 0:29:49.400
<v Speaker 1>compromised version. Now. While the n s a's assistance meant

0:29:49.440 --> 0:29:52.480
<v Speaker 1>that Crypto would remain a viable company as the world

0:29:52.520 --> 0:29:55.840
<v Speaker 1>moved away from mechanical systems, it also meant that Crypto

0:29:55.960 --> 0:29:59.920
<v Speaker 1>was a company that was becoming increasingly dependent upon American

0:30:00.000 --> 0:30:04.880
<v Speaker 1>intelligence agencies. Toward the end of the sixties, folks in

0:30:04.920 --> 0:30:08.600
<v Speaker 1>the CIA were starting to get a little bit antsy

0:30:08.800 --> 0:30:12.680
<v Speaker 1>with the company Crypto. It was a valuable asset, and

0:30:12.840 --> 0:30:16.760
<v Speaker 1>countries around the world depended upon equipment from Crypto, which

0:30:16.800 --> 0:30:19.680
<v Speaker 1>met the US had incredible advantages when it came to

0:30:19.720 --> 0:30:24.120
<v Speaker 1>deciphering intelligence. But Haglin was getting up there in years.

0:30:24.120 --> 0:30:26.800
<v Speaker 1>He was getting into his eighties, and there was no

0:30:26.880 --> 0:30:30.560
<v Speaker 1>guarantee that his successor would be as amenable to the

0:30:30.600 --> 0:30:34.960
<v Speaker 1>intelligence agents as Hagelin had been. Initially, it appeared as

0:30:35.000 --> 0:30:37.160
<v Speaker 1>though he was going to hand over control of his

0:30:37.240 --> 0:30:42.040
<v Speaker 1>company to his son, Bo Haglin. The CIA was not

0:30:42.360 --> 0:30:46.520
<v Speaker 1>crazy about that idea. The agency was not convinced that

0:30:46.560 --> 0:30:51.400
<v Speaker 1>bo Haglin would be as pliable as Boris Hagelin had been,

0:30:51.800 --> 0:30:54.040
<v Speaker 1>and the nature of the company's relationship with the U. S.

0:30:54.080 --> 0:30:58.160
<v Speaker 1>Intelligence community had been kept a secret from Bow. So

0:30:58.280 --> 0:31:02.560
<v Speaker 1>Boris Hagelin's own son did not apparently know about this

0:31:02.840 --> 0:31:07.320
<v Speaker 1>relationship with uh the n s A and later the CIA.

0:31:07.880 --> 0:31:10.240
<v Speaker 1>So Boris and his son Bow were also not on

0:31:10.280 --> 0:31:15.800
<v Speaker 1>the best of terms. They frequently had pretty massive fights.

0:31:16.320 --> 0:31:19.720
<v Speaker 1>Bo had felt he had been left out of some

0:31:19.920 --> 0:31:25.040
<v Speaker 1>pretty important patents that he had contributed to, and so

0:31:25.160 --> 0:31:28.960
<v Speaker 1>he was not on good speaking terms with his father.

0:31:29.800 --> 0:31:34.280
<v Speaker 1>Uh So this was a complicated issue, and the the U. S.

0:31:34.360 --> 0:31:38.920
<v Speaker 1>Government wasn't entirely sure how it was going to play out. Meanwhile,

0:31:39.080 --> 0:31:42.800
<v Speaker 1>over in Europe, you had intelligence agencies in West Germany

0:31:43.040 --> 0:31:46.160
<v Speaker 1>because you know, after World War Two, Germany was split

0:31:46.360 --> 0:31:49.560
<v Speaker 1>up into West Germany and East Germany. So West Germany

0:31:49.600 --> 0:31:52.240
<v Speaker 1>and an intelligence agency in France were both eager to

0:31:52.400 --> 0:31:57.280
<v Speaker 1>purchase crypto from Hageland. You know, Hagland's getting very old,

0:31:57.320 --> 0:31:59.520
<v Speaker 1>and so they think, hey, if we buy this company,

0:32:00.120 --> 0:32:04.400
<v Speaker 1>then we can benefit from this technology. They they had

0:32:04.440 --> 0:32:07.000
<v Speaker 1>figured out that the United States had some sort of

0:32:07.200 --> 0:32:11.400
<v Speaker 1>beneficial relationship with Crypto. I'm not sure if they knew

0:32:11.400 --> 0:32:13.400
<v Speaker 1>the full extent of it, but they at least knew

0:32:13.480 --> 0:32:15.800
<v Speaker 1>that there was some buddy buddy stuff going on there,

0:32:16.120 --> 0:32:18.960
<v Speaker 1>and they wanted to get in on that action. Haglin

0:32:19.120 --> 0:32:22.240
<v Speaker 1>rejected this initial offer and told the c I A

0:32:22.240 --> 0:32:25.160
<v Speaker 1>about it. So then we get to nineteen seventy, and

0:32:25.200 --> 0:32:30.240
<v Speaker 1>then two really big things happen. First, Bo Haglin Boris's

0:32:30.360 --> 0:32:35.000
<v Speaker 1>son would die in a car accident. UH. And no

0:32:35.440 --> 0:32:39.240
<v Speaker 1>conspiracy theorists does not appear that this was, you know,

0:32:39.320 --> 0:32:43.200
<v Speaker 1>engineered or manufactured in some way. Uh. It appears to

0:32:43.280 --> 0:32:46.640
<v Speaker 1>have been just a car accident and Bo dies as

0:32:46.680 --> 0:32:50.640
<v Speaker 1>a result of this. The CIA cooperates with West Germany's

0:32:50.760 --> 0:32:55.280
<v Speaker 1>Federal Intelligence Service also known as b n D. It's

0:32:55.320 --> 0:32:59.520
<v Speaker 1>called that because in German federal intelligence service is a different,

0:33:00.040 --> 0:33:02.000
<v Speaker 1>very long word that I am not even going to

0:33:02.080 --> 0:33:06.080
<v Speaker 1>attempt to pronounce, and they create an agreement in which

0:33:06.120 --> 0:33:11.240
<v Speaker 1>these two agencies would co own the company in secret. UH.

0:33:11.400 --> 0:33:14.640
<v Speaker 1>The CIA told West Germany, hey will totally go in

0:33:14.800 --> 0:33:17.000
<v Speaker 1>Z's with you on this one, but you got to

0:33:17.040 --> 0:33:20.120
<v Speaker 1>cut France out of the deal, and West Germany said,

0:33:20.560 --> 0:33:28.560
<v Speaker 1>uh okay by France, uh al vita Zane. Haglin would

0:33:28.560 --> 0:33:31.280
<v Speaker 1>be presented with this deal and would agree to the terms,

0:33:31.360 --> 0:33:35.240
<v Speaker 1>and the agencies would rely upon a company in Liechtenstein

0:33:35.840 --> 0:33:39.680
<v Speaker 1>that was called Mark ser and Goop at the time.

0:33:39.920 --> 0:33:42.840
<v Speaker 1>Great name, but Mark Staring Goop would draw up the

0:33:42.920 --> 0:33:46.120
<v Speaker 1>agreement in such a way that the agency's identities would

0:33:46.120 --> 0:33:49.280
<v Speaker 1>be protected through a series of shell companies and other

0:33:49.800 --> 0:33:54.160
<v Speaker 1>you know, ob you skation, So even if you were

0:33:54.200 --> 0:33:56.680
<v Speaker 1>to dig into it, you would not be able to

0:33:56.760 --> 0:33:59.720
<v Speaker 1>see that the C, I, A, and B and D

0:34:00.120 --> 0:34:03.600
<v Speaker 1>were co owners of this company. Instead, you would get

0:34:03.640 --> 0:34:06.240
<v Speaker 1>all these this sort of a runaround, you know, a

0:34:06.280 --> 0:34:10.000
<v Speaker 1>wild goose chase about the ownership of Crypto. It would

0:34:10.040 --> 0:34:12.960
<v Speaker 1>not appear to be owned by any intelligence agencies, however,

0:34:13.400 --> 0:34:17.759
<v Speaker 1>So Hagln sold his company for just under six million dollars. Uh.

0:34:18.000 --> 0:34:22.440
<v Speaker 1>He would pass away in three after a very long illness,

0:34:22.880 --> 0:34:26.520
<v Speaker 1>so he kind of leaves our story. But meanwhile, the

0:34:26.640 --> 0:34:29.920
<v Speaker 1>two intelligence agencies now had secret control of a company

0:34:29.920 --> 0:34:34.040
<v Speaker 1>that manufactured products meant to make communications secret I think

0:34:34.080 --> 0:34:36.799
<v Speaker 1>you can see where this is going. Right. If you're

0:34:37.280 --> 0:34:40.960
<v Speaker 1>if your agency is all about uncovering secrets, and then

0:34:40.960 --> 0:34:44.560
<v Speaker 1>you get control of a leading company that makes stuff

0:34:44.560 --> 0:34:48.560
<v Speaker 1>that's supposed to create things secretly, you're like a kid

0:34:48.560 --> 0:34:50.680
<v Speaker 1>in a candy store. I mean it was like it

0:34:50.760 --> 0:34:54.000
<v Speaker 1>was like they were selling locks to everyone in the world,

0:34:54.000 --> 0:34:56.200
<v Speaker 1>but they were holding on to all the skeleton keys

0:34:56.200 --> 0:35:00.799
<v Speaker 1>that would give them access to those locks. It was incredible. Now,

0:35:00.840 --> 0:35:04.160
<v Speaker 1>I should be clear that the list of clients for

0:35:04.280 --> 0:35:08.600
<v Speaker 1>Crypto did not include everybody. Not everyone in the world

0:35:09.160 --> 0:35:12.239
<v Speaker 1>was eager to purchase the products from this company. To

0:35:12.920 --> 0:35:16.280
<v Speaker 1>potential customers in particular were not on the list. China

0:35:16.640 --> 0:35:20.600
<v Speaker 1>and Russia were both suspicious about Crypto for years by

0:35:20.640 --> 0:35:24.759
<v Speaker 1>the time the CIA gained partial ownership, so they did

0:35:24.800 --> 0:35:29.719
<v Speaker 1>not purchase those products. They were figured something was up.

0:35:30.000 --> 0:35:34.320
<v Speaker 1>But other countries, including lots of US allies, were Crypto

0:35:34.400 --> 0:35:39.200
<v Speaker 1>customers frequent ones. While these two agencies would share ownership

0:35:39.239 --> 0:35:41.359
<v Speaker 1>of the company for a couple of decades, things were

0:35:41.400 --> 0:35:45.080
<v Speaker 1>not always super smooth between them. The West Germans noted

0:35:45.160 --> 0:35:47.720
<v Speaker 1>in their own history about the project that was shared

0:35:47.760 --> 0:35:51.360
<v Speaker 1>with The Washington Post that the Americans were eager to

0:35:51.440 --> 0:35:57.000
<v Speaker 1>spy on everybody really, enemy or ally alike. The West

0:35:57.040 --> 0:36:00.680
<v Speaker 1>German officials were really they were focusing on countries that

0:36:00.760 --> 0:36:05.200
<v Speaker 1>were not allies, but the Americans wanted to snoop on everybody.

0:36:05.480 --> 0:36:09.920
<v Speaker 1>CIA historians meanwhile, note that the American officials felt that

0:36:09.960 --> 0:36:13.600
<v Speaker 1>the West Germans were more interested in running crypto as

0:36:13.640 --> 0:36:16.560
<v Speaker 1>a straightforward business to earn money, and they were looking

0:36:16.600 --> 0:36:18.719
<v Speaker 1>at as a revenue generator, not as a way to

0:36:19.239 --> 0:36:22.840
<v Speaker 1>you know, dip into secrets. So both the CIA and

0:36:22.920 --> 0:36:26.200
<v Speaker 1>the B and D would take in millions of dollars

0:36:26.200 --> 0:36:29.160
<v Speaker 1>over the years as they operated crypto, and they would

0:36:29.160 --> 0:36:32.600
<v Speaker 1>pour that money into other projects around the world. So

0:36:32.640 --> 0:36:36.480
<v Speaker 1>if you ever wondered how some CIA operations appear to

0:36:36.520 --> 0:36:39.719
<v Speaker 1>happen under the radar, it's not all just you know,

0:36:40.080 --> 0:36:43.440
<v Speaker 1>dark deals that are behind closed doors and d C.

0:36:44.080 --> 0:36:46.799
<v Speaker 1>Some of that money comes straight from c I A

0:36:47.520 --> 0:36:52.239
<v Speaker 1>backed operations that are appearing to be you know, honest businesses.

0:36:52.719 --> 0:36:56.080
<v Speaker 1>So that's fun. We're going to take a break for

0:36:56.480 --> 0:36:59.759
<v Speaker 1>actual honest businesses, but we'll be right back after these

0:36:59.800 --> 0:37:11.200
<v Speaker 1>mess stages. So in the c I A history for

0:37:11.239 --> 0:37:14.120
<v Speaker 1>this project, and I have not read the entire history

0:37:14.160 --> 0:37:18.040
<v Speaker 1>because it was not made available. The Post was only

0:37:18.120 --> 0:37:22.120
<v Speaker 1>granted the right to produce excerpts from the report, not

0:37:22.200 --> 0:37:26.600
<v Speaker 1>the entire report. But the agency refers to Crypto with

0:37:26.680 --> 0:37:30.440
<v Speaker 1>a code name. That code name is Minerva, and the

0:37:30.560 --> 0:37:35.440
<v Speaker 1>project of running Crypto in an effort to UH to

0:37:35.600 --> 0:37:39.319
<v Speaker 1>produce equipment that could be exploited around the world, had

0:37:39.520 --> 0:37:42.680
<v Speaker 1>two different code names. The first one was the Saurus

0:37:43.120 --> 0:37:48.040
<v Speaker 1>and the second one was Rubicon UH. So German intelligence

0:37:48.080 --> 0:37:52.680
<v Speaker 1>agents would later bring in officials from Siemens, the company

0:37:52.800 --> 0:37:58.920
<v Speaker 1>Siemens to serve as advisors, technical advisors and entrepreneurial advisors

0:37:59.160 --> 0:38:02.440
<v Speaker 1>for Crypto, and in return, Siemens would get five pc

0:38:02.760 --> 0:38:07.480
<v Speaker 1>of Cryptos sales. The Americans they brought in Motorola to

0:38:07.760 --> 0:38:10.520
<v Speaker 1>take some of cryptos products and to tweak them to

0:38:10.600 --> 0:38:15.160
<v Speaker 1>make them, you know, work better, make them more commercially viable.

0:38:15.880 --> 0:38:21.839
<v Speaker 1>So we've got two intelligence agencies and two major companies

0:38:22.120 --> 0:38:26.200
<v Speaker 1>all working together as part of this, and all indications

0:38:26.280 --> 0:38:29.399
<v Speaker 1>seemed to point that at least some people in those

0:38:29.440 --> 0:38:33.520
<v Speaker 1>two big companies knew what was up. By the nineteen eighties,

0:38:33.880 --> 0:38:37.359
<v Speaker 1>more than half of all the intelligence gathered by the

0:38:37.400 --> 0:38:40.720
<v Speaker 1>CIA that came from places other than China or Russia

0:38:41.160 --> 0:38:45.760
<v Speaker 1>were encrypted by crypto machines. So when you look at

0:38:45.800 --> 0:38:50.359
<v Speaker 1>all the information that the CIA was bringing in, uh,

0:38:50.440 --> 0:38:53.360
<v Speaker 1>if it wasn't from Russia and if it wasn't from China,

0:38:53.560 --> 0:38:55.719
<v Speaker 1>more than half of the information had passed through a

0:38:55.760 --> 0:38:59.640
<v Speaker 1>crypto machine, meaning that the CIA could decrypt it and

0:38:59.719 --> 0:39:02.759
<v Speaker 1>read the underlying messages. There are sometimes where they said

0:39:02.760 --> 0:39:06.279
<v Speaker 1>that they could read messages from certain countries with eight

0:39:06.520 --> 0:39:11.240
<v Speaker 1>to nine success, which is pretty phenomenal in the world

0:39:11.239 --> 0:39:15.440
<v Speaker 1>of cryptography and code breaking. While neither Russia nor China

0:39:15.719 --> 0:39:19.000
<v Speaker 1>would use crypto devices, a lot of countries that we're

0:39:19.080 --> 0:39:22.839
<v Speaker 1>dealing with, those countries with Russia and China did use

0:39:22.920 --> 0:39:26.440
<v Speaker 1>crypto devices, so the CIA was able to learn a

0:39:26.480 --> 0:39:30.279
<v Speaker 1>lot about operations going on in Russia and China indirectly

0:39:30.560 --> 0:39:33.360
<v Speaker 1>through that means. This is also a good time to

0:39:33.400 --> 0:39:36.480
<v Speaker 1>point out a parallel in our daily lives, which is

0:39:36.520 --> 0:39:42.400
<v Speaker 1>that even if the content of our messages is safe,

0:39:43.120 --> 0:39:47.360
<v Speaker 1>the act of sending messages can sometimes provide enough information

0:39:47.400 --> 0:39:53.080
<v Speaker 1>for people to draw some pretty accurate conclusions. It shows

0:39:53.160 --> 0:39:57.920
<v Speaker 1>us that metadata is really an important thing to remember.

0:39:58.719 --> 0:40:03.799
<v Speaker 1>Metadata is the formation about information, and sometimes you don't

0:40:03.800 --> 0:40:06.400
<v Speaker 1>need to know the content of something in order to

0:40:06.480 --> 0:40:12.239
<v Speaker 1>draw some pretty damaging or valuable conclusions. I guess it

0:40:12.239 --> 0:40:15.920
<v Speaker 1>all depends upon your perspective. So this is kind of

0:40:15.920 --> 0:40:18.200
<v Speaker 1>an example of that that even though Russia and China

0:40:18.280 --> 0:40:21.720
<v Speaker 1>weren't using crypto devices, countries that we're dealing with, Russia

0:40:21.719 --> 0:40:24.000
<v Speaker 1>and China were, and that meant the CIA could read

0:40:24.040 --> 0:40:28.359
<v Speaker 1>at least that side of the messages. In nineteen one,

0:40:28.440 --> 0:40:32.800
<v Speaker 1>Saudi Arabia would become the biggest crypto customer and it

0:40:32.840 --> 0:40:35.759
<v Speaker 1>would play a very important role. The crypto technology would

0:40:35.760 --> 0:40:38.200
<v Speaker 1>play a very important role in the Middle East. This

0:40:38.360 --> 0:40:41.720
<v Speaker 1>also leads to a point in the Washington Post article

0:40:42.120 --> 0:40:47.480
<v Speaker 1>where the authors state that it's kind of an open

0:40:47.600 --> 0:40:51.160
<v Speaker 1>question as to how much the CIA knew about different

0:40:51.719 --> 0:40:56.120
<v Speaker 1>operations around the world throughout this time, and what the

0:40:56.160 --> 0:41:00.520
<v Speaker 1>agency did or didn't do in preparation for the events,

0:41:00.560 --> 0:41:03.600
<v Speaker 1>like whether or not they should have acted in some cases,

0:41:03.600 --> 0:41:06.239
<v Speaker 1>like if they were aware of an assassination attempt, did

0:41:06.320 --> 0:41:09.759
<v Speaker 1>they do anything to prevent that or to let anyone know?

0:41:10.320 --> 0:41:13.000
<v Speaker 1>And if not, was it just because they were worried

0:41:13.000 --> 0:41:17.319
<v Speaker 1>about compromising the fact that they knew about this information.

0:41:17.520 --> 0:41:21.360
<v Speaker 1>At what point does the value go away? From knowing

0:41:21.400 --> 0:41:23.960
<v Speaker 1>information if you don't act on that information. These are

0:41:23.960 --> 0:41:26.040
<v Speaker 1>big questions that are not answered in the article, by

0:41:26.040 --> 0:41:28.160
<v Speaker 1>the way, uh, and they bring up a lot of

0:41:29.440 --> 0:41:34.360
<v Speaker 1>deep ethical problems with what was going on. So crypto

0:41:34.440 --> 0:41:37.440
<v Speaker 1>would also receive a lot of direction from the CIA

0:41:37.600 --> 0:41:43.960
<v Speaker 1>and from BND two actively try and disparage competitors to

0:41:44.080 --> 0:41:50.800
<v Speaker 1>essentially run marketing campaigns that said, you know, cryptography devices

0:41:50.880 --> 0:41:54.000
<v Speaker 1>from such and such a company are total crap. Don't

0:41:54.000 --> 0:41:58.200
<v Speaker 1>buy them. Come to us by our stuff, we are secure. Uh.

0:41:58.400 --> 0:42:03.120
<v Speaker 1>They also were encouraged to bribe government officials to adopt

0:42:03.160 --> 0:42:07.280
<v Speaker 1>crypto tech. So there's some pretty awful stories about crypto

0:42:07.360 --> 0:42:10.839
<v Speaker 1>executives doing all sorts of stuff in order to you know,

0:42:11.120 --> 0:42:15.759
<v Speaker 1>bribe governments from all over the world to adopt crypto technology.

0:42:16.320 --> 0:42:23.880
<v Speaker 1>Skiezy scheezy stuff really makes me proud um. US President

0:42:23.960 --> 0:42:28.120
<v Speaker 1>Ronald Reagan inadvertently revealed that the US had intercepted and

0:42:28.160 --> 0:42:32.560
<v Speaker 1>decrypted communications out of a Libyan embassy in East Berlin

0:42:32.800 --> 0:42:36.040
<v Speaker 1>to Tripoli, and that tipped off Libya that something was

0:42:36.120 --> 0:42:40.280
<v Speaker 1>up right, that America somehow was able to decrypt messages,

0:42:40.960 --> 0:42:45.799
<v Speaker 1>and considering the company they were relying upon for their cryptography.

0:42:45.840 --> 0:42:50.960
<v Speaker 1>That started to raise some doubts about Crypto's authenticity, and

0:42:51.040 --> 0:42:54.680
<v Speaker 1>not just with Libya. Other countries took notice to employees

0:42:54.719 --> 0:42:58.680
<v Speaker 1>at Crypto. Meanwhile, didn't know about the arrangement. Right they

0:42:58.719 --> 0:43:03.120
<v Speaker 1>were working under the assumption that they were actually making genuine,

0:43:03.719 --> 0:43:09.080
<v Speaker 1>reliable cryptography equipment, And occasionally an employee might look at

0:43:09.120 --> 0:43:12.080
<v Speaker 1>something and say, ha, this is weird based upon what

0:43:12.200 --> 0:43:15.399
<v Speaker 1>I know. This algorithm we're using or this system we're

0:43:15.480 --> 0:43:19.359
<v Speaker 1>using has vulnerabilities. Their their problems with it. We should

0:43:19.440 --> 0:43:23.160
<v Speaker 1>fix those before we ship this because we could make

0:43:23.200 --> 0:43:27.239
<v Speaker 1>it more secure. They would get discouraged from doing that,

0:43:27.280 --> 0:43:31.280
<v Speaker 1>they would be told not to implement solutions. In one case,

0:43:31.880 --> 0:43:34.839
<v Speaker 1>it went much further than that. Uh. There was an

0:43:34.840 --> 0:43:42.120
<v Speaker 1>employee named Peter Fruitager who was very frustrated with what

0:43:42.160 --> 0:43:45.440
<v Speaker 1>was going on. He felt that that Crypto was just

0:43:45.520 --> 0:43:52.040
<v Speaker 1>being complacent or maybe negligent, and not responding to very

0:43:52.080 --> 0:43:56.879
<v Speaker 1>real concerns that Furniture had with clients in Damascus. So

0:43:57.040 --> 0:44:00.480
<v Speaker 1>his clients and Damascus were complaining about their stuff. So

0:44:00.520 --> 0:44:03.800
<v Speaker 1>he went to Damascus and he fixed their crypto equipment.

0:44:04.080 --> 0:44:07.279
<v Speaker 1>In other words, he removed the vulnerabilities that had been

0:44:07.320 --> 0:44:12.200
<v Speaker 1>engineered to go into this stuff, and the Crypto CEO

0:44:12.520 --> 0:44:15.720
<v Speaker 1>at the time would fire Friutiture as a result, because

0:44:16.000 --> 0:44:19.400
<v Speaker 1>Frititor had had messed things up. He had actually made

0:44:19.560 --> 0:44:21.600
<v Speaker 1>a what was supposed to be a secure system and

0:44:21.760 --> 0:44:25.200
<v Speaker 1>actual secure system. Of course he didn't know that that

0:44:25.360 --> 0:44:31.080
<v Speaker 1>was against the goals of the operation itself, and the

0:44:31.120 --> 0:44:34.759
<v Speaker 1>c i A got very mad at the CEO for

0:44:34.800 --> 0:44:37.560
<v Speaker 1>Crypto at that point, saying that he should have found

0:44:37.560 --> 0:44:39.920
<v Speaker 1>a way to sort of bring Frutiture in under the

0:44:39.960 --> 0:44:43.240
<v Speaker 1>fold to smooth things over, rather than fire him because

0:44:43.239 --> 0:44:48.440
<v Speaker 1>it brought undoe scrutiny to Crypto and its activities. Crypto

0:44:48.520 --> 0:44:53.160
<v Speaker 1>also hired an electrical engineer named Manjia Ca Flesh and

0:44:53.200 --> 0:44:57.400
<v Speaker 1>I'm sure I'm butchering these names, and I do apologize. Uh.

0:44:57.560 --> 0:45:00.319
<v Speaker 1>That also upset the n s A this time, not

0:45:00.400 --> 0:45:02.160
<v Speaker 1>the c i A, but the n s A because

0:45:02.280 --> 0:45:05.120
<v Speaker 1>N s A knew about this this electrical engineer, and

0:45:05.120 --> 0:45:08.960
<v Speaker 1>they said, she is way too smart, she's going to

0:45:09.040 --> 0:45:12.000
<v Speaker 1>figure out something's going on. You should not hire her.

0:45:12.280 --> 0:45:16.920
<v Speaker 1>But Crypto hired her because she's was brilliant and was

0:45:17.360 --> 0:45:20.640
<v Speaker 1>seen as a valuable asset. Turns out she was brilliant.

0:45:20.840 --> 0:45:23.920
<v Speaker 1>She still is brilliant, and she kept trying to initiate

0:45:24.000 --> 0:45:28.680
<v Speaker 1>fixes and improvements because she kept finding weaknesses and vulnerabilities

0:45:29.000 --> 0:45:32.720
<v Speaker 1>in the systems, but she was always discouraged from actually

0:45:32.760 --> 0:45:37.279
<v Speaker 1>implementing solutions, and she wondered what was going on, but

0:45:37.400 --> 0:45:39.920
<v Speaker 1>she was a little worried about speaking up because she

0:45:40.000 --> 0:45:44.640
<v Speaker 1>wasn't sure exactly what the extent was. The company would

0:45:44.640 --> 0:45:48.960
<v Speaker 1>actually produce a machine using an algorithm she had designed

0:45:49.360 --> 0:45:53.480
<v Speaker 1>that the n s A could not crack, So the

0:45:53.600 --> 0:45:56.239
<v Speaker 1>n s A reached out to the CIA, and the

0:45:56.280 --> 0:46:02.520
<v Speaker 1>CIA ordered the company Crypto to stop the manufacturing process, saying,

0:46:02.560 --> 0:46:06.440
<v Speaker 1>we can't produce these machines because we can't crack the code.

0:46:07.160 --> 0:46:11.200
<v Speaker 1>You've gotta break it. So only fifty or so of

0:46:11.239 --> 0:46:14.720
<v Speaker 1>these machines were actually manufactured. The company wind up selling

0:46:14.719 --> 0:46:18.680
<v Speaker 1>those two banks because the thought was, well, banks have

0:46:18.719 --> 0:46:21.200
<v Speaker 1>a need for security, and we don't really need to

0:46:21.239 --> 0:46:25.800
<v Speaker 1>snoop on them. That's not where our concern is. Uh,

0:46:25.800 --> 0:46:28.879
<v Speaker 1>But from now on, when you make this device, make

0:46:28.920 --> 0:46:32.319
<v Speaker 1>it with the algorithm that's broken on purpose, because we

0:46:32.360 --> 0:46:34.960
<v Speaker 1>want to be able to crack those codes. So that's

0:46:35.000 --> 0:46:40.680
<v Speaker 1>pretty dodgy anyway. There was also a mathematics professor from

0:46:40.680 --> 0:46:46.520
<v Speaker 1>Stockholm whose name I would butcher terribly. He actually studied

0:46:46.560 --> 0:46:49.600
<v Speaker 1>in the United States and his American family, like me,

0:46:49.960 --> 0:46:53.200
<v Speaker 1>would have trouble saying his name, so they called him

0:46:53.239 --> 0:46:58.880
<v Speaker 1>Henry Henry Vidman. He was brought into craft more sophisticated

0:46:58.920 --> 0:47:03.800
<v Speaker 1>but vulnerable out rhythms. So he was actually told about

0:47:03.840 --> 0:47:08.239
<v Speaker 1>the real relationship between the CIA and then B and

0:47:08.320 --> 0:47:12.880
<v Speaker 1>D and crypto. He was given the inside scoop and

0:47:12.920 --> 0:47:16.000
<v Speaker 1>asked to become part of the team, and his purpose

0:47:16.520 --> 0:47:21.360
<v Speaker 1>was to design algorithms that looked really super secure but

0:47:21.520 --> 0:47:26.600
<v Speaker 1>secretly weren't. So he was trying to make stuff that

0:47:26.680 --> 0:47:29.719
<v Speaker 1>appeared to be more on the up and up, but

0:47:29.840 --> 0:47:34.759
<v Speaker 1>in fact had vulnerabilities built into it, and meanwhile to

0:47:34.880 --> 0:47:38.120
<v Speaker 1>have those vulnerabilities designed in such a way that it

0:47:38.200 --> 0:47:42.000
<v Speaker 1>created plausible deniability. In other words, if someone found the vulnerability,

0:47:42.320 --> 0:47:45.400
<v Speaker 1>you could say, oh, that's due to human error or

0:47:45.440 --> 0:47:48.359
<v Speaker 1>it was an implementation error, but it was not put

0:47:48.400 --> 0:47:51.880
<v Speaker 1>there on purpose, even though it toats was. The CIA

0:47:52.440 --> 0:47:57.000
<v Speaker 1>used crypto communications to suss out where Manuel Noriega was

0:47:57.080 --> 0:48:00.759
<v Speaker 1>based off communications from the Vatican. They intercepted those communications,

0:48:00.800 --> 0:48:03.480
<v Speaker 1>decoded them, and were able to find Noriega. As a result,

0:48:04.239 --> 0:48:11.200
<v Speaker 1>in Iran arrested a Crypto salesman named Hans Bueller, and

0:48:11.320 --> 0:48:15.520
<v Speaker 1>Bueller didn't know about the relationship between Crypto and the

0:48:15.560 --> 0:48:18.400
<v Speaker 1>CIA or the B and D. He had no knowledge

0:48:18.400 --> 0:48:21.760
<v Speaker 1>of any of that. So he was literally an innocent

0:48:21.840 --> 0:48:28.200
<v Speaker 1>salesman who thought he was selling legit cryptographic equipment. Iran

0:48:28.520 --> 0:48:31.000
<v Speaker 1>had figured out something was going on. They had been

0:48:31.040 --> 0:48:35.080
<v Speaker 1>suspicious ever since that incident with Libya I had mentioned earlier,

0:48:35.480 --> 0:48:40.520
<v Speaker 1>and so they arrested him and they essentially tortured him

0:48:40.560 --> 0:48:45.880
<v Speaker 1>for nine months. Uh the Iran demanded a one million

0:48:45.880 --> 0:48:49.200
<v Speaker 1>dollar ransom from Crypto, and the company did pay it.

0:48:49.280 --> 0:48:53.080
<v Speaker 1>The CIA did not chip in because the CIA has

0:48:53.120 --> 0:48:57.279
<v Speaker 1>a policy against paying ransoms. We don't negotiate with terrorists,

0:48:57.480 --> 0:49:00.600
<v Speaker 1>is the way America would put it. So this guy

0:49:00.800 --> 0:49:05.560
<v Speaker 1>suffered for nine months in captivity before Crypto would pay

0:49:05.600 --> 0:49:08.120
<v Speaker 1>the ransom and get him back. And he legit didn't

0:49:08.160 --> 0:49:12.600
<v Speaker 1>know anything. He didn't know that the relationship existed, but

0:49:12.680 --> 0:49:15.400
<v Speaker 1>he certainly suspected it by the time he was released,

0:49:15.960 --> 0:49:19.960
<v Speaker 1>and he was worried about the fact that this foreign

0:49:20.040 --> 0:49:22.360
<v Speaker 1>government seemed to know more about the company he was

0:49:22.400 --> 0:49:25.920
<v Speaker 1>working for than he did. He ended up going to

0:49:25.960 --> 0:49:31.040
<v Speaker 1>the press and talking about his experiences and it caused

0:49:31.160 --> 0:49:34.160
<v Speaker 1>a bit of a stir in Europe. The CIA would

0:49:34.200 --> 0:49:37.680
<v Speaker 1>actually refer to this entire incident with a code name.

0:49:38.160 --> 0:49:42.360
<v Speaker 1>That code name was Hydra, so that's fun. Around that

0:49:42.440 --> 0:49:47.600
<v Speaker 1>same time, Germany was reunified, right the Soviet Union fell,

0:49:47.960 --> 0:49:51.920
<v Speaker 1>East Germany and West Germany unified into Germany. The Berlin

0:49:52.000 --> 0:49:55.160
<v Speaker 1>Wall came down, and it was around that same time

0:49:55.160 --> 0:49:59.040
<v Speaker 1>that the B and D felt that crypto's usefulness had

0:49:59.080 --> 0:50:02.319
<v Speaker 1>pretty much expied eared that now it was more of

0:50:02.360 --> 0:50:07.480
<v Speaker 1>a risk that if the full extent of B and

0:50:07.520 --> 0:50:11.279
<v Speaker 1>D's involvement in cryptos activities were known, that could put

0:50:11.360 --> 0:50:14.480
<v Speaker 1>Germany at risk. And so they ended up selling off

0:50:14.640 --> 0:50:19.120
<v Speaker 1>their interest in Crypto to the CIA for around seventeen

0:50:19.200 --> 0:50:24.480
<v Speaker 1>million dollars. So at that point forward, Crypto operated as

0:50:25.120 --> 0:50:31.080
<v Speaker 1>a c I A backed operation secretly, but yeah, CIA

0:50:31.200 --> 0:50:36.040
<v Speaker 1>had full ownership from around until two thousand eighteen. That's

0:50:36.040 --> 0:50:39.080
<v Speaker 1>when CIA would liquidate the company and sold it off

0:50:39.360 --> 0:50:43.520
<v Speaker 1>to to other companies. Um. The reason they did that

0:50:44.120 --> 0:50:48.680
<v Speaker 1>is that by the time rolled around, the cryptographic community

0:50:48.760 --> 0:50:51.640
<v Speaker 1>was very different. It no longer was so dependent upon

0:50:51.719 --> 0:50:57.520
<v Speaker 1>standalone machines, electronic or otherwise. A lot of solutions are

0:50:57.600 --> 0:51:02.560
<v Speaker 1>software based or web based. Uh, they're not based on

0:51:02.560 --> 0:51:07.799
<v Speaker 1>on physical equipment, so they're The usefulness of Crypto as

0:51:07.880 --> 0:51:11.839
<v Speaker 1>a company had pretty much gone out the window. Uh.

0:51:11.920 --> 0:51:15.239
<v Speaker 1>It had provided the CIA with a ton of information,

0:51:16.120 --> 0:51:19.120
<v Speaker 1>but they were you know, there's no no need to

0:51:19.200 --> 0:51:22.040
<v Speaker 1>keep it running, so they sold it off for parts essentially.

0:51:22.920 --> 0:51:28.120
<v Speaker 1>Um And you know, part of me says, this is

0:51:28.120 --> 0:51:31.560
<v Speaker 1>spy stuff. Of course, spies are going to be sneaky.

0:51:31.680 --> 0:51:35.080
<v Speaker 1>That's what spies do. Spies operate in a way where

0:51:35.120 --> 0:51:37.759
<v Speaker 1>they are trying to avoid detection while they try to

0:51:37.800 --> 0:51:40.800
<v Speaker 1>figure out what everyone else knows. That is the nature

0:51:40.840 --> 0:51:44.440
<v Speaker 1>of spying, and everybody does it. At the same time,

0:51:44.920 --> 0:51:51.640
<v Speaker 1>there's something really sinister about secretly owning a security firm

0:51:52.440 --> 0:51:56.880
<v Speaker 1>and uh using it to to do the opposite of

0:51:56.920 --> 0:51:59.600
<v Speaker 1>what the security firm says it's doing. Right. It says

0:51:59.640 --> 0:52:03.880
<v Speaker 1>it's tecting secrets, but in reality, it's leaving those secrets

0:52:03.920 --> 0:52:07.239
<v Speaker 1>open for people to see. Now. I mentioned Huawei at

0:52:07.280 --> 0:52:09.600
<v Speaker 1>the beginning of this episode, and the reason I did

0:52:09.640 --> 0:52:12.200
<v Speaker 1>that is because, again, around the same time that this

0:52:12.239 --> 0:52:15.880
<v Speaker 1>story was breaking, we were hearing about how Huawei, the

0:52:16.000 --> 0:52:21.400
<v Speaker 1>Chinese company telecommunications company, has had back door access to

0:52:21.680 --> 0:52:25.400
<v Speaker 1>networks that it it has rolled out for a decade.

0:52:25.760 --> 0:52:29.799
<v Speaker 1>So Whahwei makes all sorts of telecommunications equipment, including components

0:52:29.960 --> 0:52:33.080
<v Speaker 1>for networks. UH they are a leading provider for five

0:52:33.160 --> 0:52:37.320
<v Speaker 1>G components, for example, And there's been a concern around

0:52:37.680 --> 0:52:39.960
<v Speaker 1>much of the world, but particularly in the United States,

0:52:40.480 --> 0:52:43.319
<v Speaker 1>that this would mean that Huawei as a company would

0:52:43.360 --> 0:52:46.680
<v Speaker 1>have at least some capability of snooping on communications that

0:52:46.800 --> 0:52:51.960
<v Speaker 1>go across those networks. And since Huawei has some connections

0:52:52.360 --> 0:52:59.040
<v Speaker 1>to the communist government of China, because China requires companies

0:52:59.120 --> 0:53:02.200
<v Speaker 1>that operate in China to have this connection, that that

0:53:02.239 --> 0:53:06.319
<v Speaker 1>would mean that those networks would be used specifically as

0:53:06.440 --> 0:53:10.000
<v Speaker 1>surveillance tools. And in America you can kind of understand

0:53:10.239 --> 0:53:14.279
<v Speaker 1>where they're coming from, because that's what Americans do. Like,

0:53:14.400 --> 0:53:18.080
<v Speaker 1>if you're the one who spying on everybody, you probably

0:53:18.120 --> 0:53:21.520
<v Speaker 1>are really paranoid about everyone spying on you. It's just

0:53:21.600 --> 0:53:25.520
<v Speaker 1>kind of how it works. Also, again, that report showed

0:53:25.680 --> 0:53:28.960
<v Speaker 1>that for ten years, Whahwei actually did have that capability.

0:53:29.000 --> 0:53:31.600
<v Speaker 1>Whether they did anything with it or not, it's still

0:53:31.600 --> 0:53:35.279
<v Speaker 1>an open question. But with Whahwei, the story goes that

0:53:35.320 --> 0:53:39.120
<v Speaker 1>they were building in these back door access channels for

0:53:39.200 --> 0:53:42.360
<v Speaker 1>law enforcement officials. You know, law enforcement wants to have

0:53:42.480 --> 0:53:45.359
<v Speaker 1>that kind of access so that if they're conducting investigation,

0:53:45.880 --> 0:53:50.600
<v Speaker 1>they can look into communications going between various suspects so

0:53:50.640 --> 0:53:55.560
<v Speaker 1>that they can better do their investigations. Uh. The problem

0:53:55.600 --> 0:53:57.440
<v Speaker 1>is that Huahwei was not just building these in for

0:53:57.520 --> 0:54:01.480
<v Speaker 1>law enforcement, but was retaining its own access to those channels.

0:54:01.960 --> 0:54:04.400
<v Speaker 1>And again, whether it was using it or not, I

0:54:04.440 --> 0:54:07.320
<v Speaker 1>don't know, but the story goes that they were actually

0:54:07.320 --> 0:54:11.640
<v Speaker 1>retaining that ability. Uh. And this leads me to another

0:54:11.680 --> 0:54:14.080
<v Speaker 1>point I want to make before I conclude, which is

0:54:14.160 --> 0:54:19.800
<v Speaker 1>that back door channels are always a terrible idea, always, always, always,

0:54:19.800 --> 0:54:24.239
<v Speaker 1>always Uh. They inherently make systems less secure. So if

0:54:24.280 --> 0:54:27.160
<v Speaker 1>your job is to make a secure system, building in

0:54:27.200 --> 0:54:31.319
<v Speaker 1>a way to bypass that security is you might as

0:54:31.360 --> 0:54:34.319
<v Speaker 1>well not have any security. It's a terrible idea. I

0:54:34.400 --> 0:54:37.840
<v Speaker 1>get it why law enforcement and intelligence agencies want it,

0:54:38.040 --> 0:54:41.160
<v Speaker 1>because information is valuable and getting access to the information

0:54:41.480 --> 0:54:45.040
<v Speaker 1>could mean the difference between life or death in some cases,

0:54:45.120 --> 0:54:51.480
<v Speaker 1>and really can. But then you know, if you have

0:54:51.520 --> 0:54:54.880
<v Speaker 1>those backdoor channels, it means that you don't have to

0:54:54.920 --> 0:54:57.120
<v Speaker 1>go through the whole security process, and it means that

0:54:57.200 --> 0:55:00.320
<v Speaker 1>someone else might potentially discover that and expl laid it.

0:55:00.920 --> 0:55:05.759
<v Speaker 1>So one you've got the danger of the authorized parties

0:55:06.440 --> 0:55:10.440
<v Speaker 1>abusing this power. Right, you've got the potential for an

0:55:10.480 --> 0:55:13.960
<v Speaker 1>agency committing overreach, like we've heard about the n s

0:55:14.040 --> 0:55:18.319
<v Speaker 1>A and how that agency was collecting way more information

0:55:18.640 --> 0:55:22.359
<v Speaker 1>than they should have been able to, including information from

0:55:22.400 --> 0:55:26.000
<v Speaker 1>people that weren't under any direct surveillance, and how that

0:55:26.040 --> 0:55:29.319
<v Speaker 1>can be abused. That's a terrible thing. So you don't

0:55:29.360 --> 0:55:32.399
<v Speaker 1>want that capability. You don't want the ability of some

0:55:32.840 --> 0:55:37.360
<v Speaker 1>agency that had had authorized backdoor access to abuse that power.

0:55:37.719 --> 0:55:40.520
<v Speaker 1>You also don't want some third party that is not

0:55:40.680 --> 0:55:44.360
<v Speaker 1>authorized at all finding out about that back channel and

0:55:44.400 --> 0:55:47.360
<v Speaker 1>figuring out how to access it, because now your secure

0:55:47.400 --> 0:55:51.920
<v Speaker 1>system has no security. So I guess the in message

0:55:51.960 --> 0:55:55.799
<v Speaker 1>I want to give everybody is protect yourself as best

0:55:55.800 --> 0:55:59.000
<v Speaker 1>you can, which is increasingly difficult when we don't know

0:55:59.480 --> 0:56:03.640
<v Speaker 1>necessary who is behind the systems that are actually making

0:56:04.360 --> 0:56:08.239
<v Speaker 1>the security we depend upon. Another great example is people

0:56:08.280 --> 0:56:13.759
<v Speaker 1>have pointed out is should we trust the security company Kasperski,

0:56:14.120 --> 0:56:16.759
<v Speaker 1>which comes from Russia or is it possible that that

0:56:16.800 --> 0:56:21.239
<v Speaker 1>could be a state backed operation that is slowly or

0:56:21.360 --> 0:56:27.280
<v Speaker 1>quietly sewing in vulnerabilities from people who are using its products. Uh.

0:56:27.360 --> 0:56:31.000
<v Speaker 1>I have not seen any specific reports on that. I'm

0:56:31.040 --> 0:56:34.360
<v Speaker 1>just seeing people ask that question. But that leads us

0:56:34.400 --> 0:56:37.960
<v Speaker 1>to start asking questions about everything. Probably not a bad idea,

0:56:38.000 --> 0:56:40.520
<v Speaker 1>but it starts to, you know, it starts to create

0:56:40.560 --> 0:56:44.239
<v Speaker 1>this system where we're not trusting anything, and at the

0:56:44.320 --> 0:56:47.560
<v Speaker 1>end of the day, you either have to figure out

0:56:48.360 --> 0:56:50.560
<v Speaker 1>you've got to trust somebody, or you've got to just

0:56:50.640 --> 0:56:54.880
<v Speaker 1>kind of disengage, or I guess you just resign yourself

0:56:54.920 --> 0:56:58.200
<v Speaker 1>that all of your stuff is going to be findable

0:56:58.200 --> 0:57:02.360
<v Speaker 1>and readable by everyone at some point or another. Happy Days.

0:57:03.200 --> 0:57:06.879
<v Speaker 1>That wraps up this episode of text stuff, And this

0:57:06.920 --> 0:57:10.240
<v Speaker 1>is a pretty heavy topic. So in our next episode,

0:57:10.239 --> 0:57:12.839
<v Speaker 1>I'm gonna have a special guest join us, at least

0:57:12.840 --> 0:57:17.360
<v Speaker 1>that's the plan, and we're gonna have a conversation about

0:57:17.560 --> 0:57:21.080
<v Speaker 1>misinformation on the Internet and how it can quickly get

0:57:21.640 --> 0:57:27.200
<v Speaker 1>spread and evolve in rapid succession to the point where

0:57:27.200 --> 0:57:30.280
<v Speaker 1>it's passed as gospel. But that will be for our

0:57:30.360 --> 0:57:33.240
<v Speaker 1>next episode. If you have suggestions for future topics I

0:57:33.240 --> 0:57:36.600
<v Speaker 1>should cover on tech stuff, reach out to me on Facebook.

0:57:36.680 --> 0:57:39.520
<v Speaker 1>Or Twitter. I use the handle text stuff h s

0:57:39.760 --> 0:57:42.280
<v Speaker 1>W at both. I look forward to hearing from you,

0:57:42.640 --> 0:57:50.400
<v Speaker 1>and I'll talk to you again really soon. Text Stuff

0:57:50.440 --> 0:57:52.760
<v Speaker 1>is a production of I Heart Radio's How Stuff Works.

0:57:52.960 --> 0:57:55.760
<v Speaker 1>For more podcasts from my heart Radio, visit the I

0:57:55.880 --> 0:57:59.120
<v Speaker 1>heart Radio app, Apple Podcasts, or wherever you listen to

0:57:59.160 --> 0:58:02.000
<v Speaker 1>your favorite show. Ye