I'm sorry, but my post said things worked out - not that they cracked the code. I was clear they wouldn't tell me anything. I had always assumed the mug was from the gift shop. It would be hard to think otherwise.
Here's how I looked at it -- they are 1000x smarter than me on matters of encryption. It was totally unlikely I knew something they didn't. At most, I saved them a few hours on a matter of life and death, and I had minutes to make that decision. And recall, back then, people felt differently about the NSA. If this was a total spoof - the reality is I didn't give anything up. I didn't invent the encryption ciphers. I just packaged common ciphers in a user interface people really liked.
But in response to the people here who think I was tricked. That's not the case. What I didn't put in the post was that a team from the NSA visited me in California a few months later. But again, had I been tricked, it wouldn't have mattered.
You're absolutely right...I forgot the time diff as I wrote the story and some is just plain fuzzy after all this time. I spent hours on the phone with them that night and I was giving them guidance by memory since I was so familiar with the code. Somewhere in the course of that they ventured to ask for he source.
Yeah, makes sense. And I planned it all out even down to timing the post to hit last night after midnight before all the pipe bomb news this morning on TV. Or, much closer to reality, maybe I just wanted to see if I could write a post that got some traction. Don't overthink it.
I did not roll my own. Very few people in the world are smart enough to do that. I just create a very nice user interface to make things easy for ordinary Windows users.
The only thing I did masterfully was write a Medium article that got some attention. I didn't even include a link to the old software which hasn't been updated in a decade. It's nothing more than an interesting story about one night nearly 20 years ago. Sorry to disappoint.
Exactly. TrueCrypt was the big open source product at the time. A great product used by many hundreds of thousands of people -- I know, because I used to track their progress.
The laws were different back then. The State Dept changed the rules a decade or more ago, I forget when, and AES 256 has been the default cipher ever since. Encryption is listed as a munition. I would have gone to jail if I put anything greater than 40-bit encryption on the shareware sites. Look what happened with Phil Z with PGP.
All commercial encryption software uses the same public ciphers. Do you really think nearly 20 years after the fact I'm trying to impress anyone? But, they were impressed at the time about my user interface which wrapped the ciphers, and they later had a group visit me in California about some internal uses of that same UX; but nothing came of it in the end.
The ciphers are public. Providing source for this specific implementation of "user interface" did nothing more than indicate sizes of file headers, etc. No customers were put at risk. All I did was save the NSA maybe a few hours of time during a critical moment. Do you really think they couldn't have figured out there is a 4K file header (see, I've said it here, no harm).
I'm not ashamed! The product was not broken. As others have correctly pointed out, there were export restrictions for public shareware downloads. The product is still sold and has never been reported to have been broken. The ciphers used are all public domain - that's how people trust them. Nothing about a cipher can be secret.
I'm the author. They found me on the firsts call. I have a unique name - the footprint was there. But, I had 5 relatives in the same town. Nobody else got a call. Were they just lucky?
The ciphers are public. What the NSA really wanted was the size of file headers, special markers, etc -- so they could skip over the fluff and home in on the juicy stuff. I gave up nothing that would put the product or users at risk.
I'm the author of the article. All common ciphers are available as open source already. I just packaged it into a product. Encryption done right does not suddenly become vulnerable if published to an open forum. I gave up nothing. I did not put any customers at risk, nor did I put my product at risk. People who think otherwise do not really know how encryption works. It works because the ciphers are public and tested by time. And for the record -- I would do it again if asked.