Cyber Lessons From The Telegraph Era: Protecting Our Digital World Today

Thanks to Matthew Fisch, CISSP, Founder of FortMesa for inviting me for another visit to The MSP Cyber RoundTable.

This has all happened before, and it will all happen again. — Battlestar Galactica

So many of our present-day concerns and hacks (and some of our mitigations) aren’t new, they’ve happened before.

Let’s hop in a time machine and go back to an era before any practical use of electricity. Think of 1776, Benjamin Franklin and Alexander Hamilton. No electric heat, no electric light or electric motors.

Here’s an earlier blogpost about the World’s first World Wide Web — the Telegraph: https://loistavainfosecurity.com/the-victorian-internet/

Here’s a transcript of our session:

Matthew Fisch, CISSP

Fort Mesa is part of a generation of tools, it’s really built to make cyber security easier. Welcome back to another episode of the MSP Cyber Roundtable. I’m here with Anthony Collette from Loistava Information Security today.We’re actually doing something a little special today, and we’re going to get more into it in a few minutes. But the essence of it is rather than looking at tomorrow’s threats, we’re going to be looking backward at all the things we should have learned but maybe didn’t. We’re going to try to get some lessons we can take into the future today.Anthony, last time you were on, we were talking fortune cookies, which was really fun, and I got to take some fortune cookies on the road and watch a bunch of people open them, which was really interesting to see how people react to fortune cookies. I had never really thought about it before. Some people are really into them, some people are like, what’s that?And I’m like, what do you mean what’s that?

Anthony Collette

Don’t you know what a fortune cookie is?

Matthew Fisch, CISSP

Yeah, I couldn’t even believe it. But anyway, they had cyber fortunes in them, which was great. And that’s basically what you’re going to be doing today.You’re going to be doing some fortune telling.

Anthony Collette

Yeah, fortune telling looking backward.

Matthew Fisch, CISSP

So I can’t wait to talk more about that. So you’re in, I want to say like beautiful Northwest. Do I have that right?

Anthony Collette

Right, the Pacific Northwest. We’re close to Seattle. We’re in a really pretty city called Bellevue, which is over here by the main Microsoft campus in Redmond, and we’re right next door.

Matthew Fisch, CISSP

So beautiful weather. I presume the fires didn’t like, no smoke issues to deal with.

Anthony Collette

Nope, nothing here.

Matthew Fisch, CISSP

Just beauty and unlike where I live, not a frozen hellscape. So and you still got spring to look forward to coming soon.

Anthony Collette

So not bad. I’m not complaining.

Matthew Fisch, CISSP

We’re going to get into The Victorian Internet a little later and talk about some lessons that we can learn by exploring backward. But before we do that, talk to me about how did you end up even looking into this space? I know most of the people I talk to, they fall into two categories, right?Their guidance counselor said cyber pays a lot of money and they said, yeah, I think I could do that. And they went to cyber school, right? Those are the young people these days.Right. Slightly older generation of cyber warriors. They have no idea how they ended up in cyber.They fell into it. It’s an incident smacked them in the face. A series of unfortunate left turns in their career left them with chasing vulnerabilities or what have you.But your story was a little different. So tell me, I know we’ve talked about it personally before, but you didn’t spend your whole life leading up to cyber, right?

Anthony Collette

No, not at all. I had no awareness, no pressing interest. And then, wow, 10 years ago now, I can’t believe it’s been 10 years, but in the summer of 2014, we went to see a movie and there was a preview for an upcoming flick called The Imitation Game with Benedict Cumberbatch in it. And I really liked Benedict Cumberbatch, the movie of course is about Bletchley Park and World War II code breaking.I knew nothing about that. But in the preview, there were all these spinning wheels and dials and gizmos and wires. And that was really intriguing to me.And I thought, wow, that’s really very interesting. And so kind of went down that rabbit hole a little bit to figure out what that was all about. Along the way, I just noticed that there was a lot of talk about ciphers and breaking ciphers, but very little talk about codes.And they would say, cipher, cipher, cipher . . . codes, but we won’t talk about those. And so just the omission of much information about codes caught my attention. I looked into that, and that’s really more about language than math.It’s really about how you pull language apart. It’s sort of like language Legos . . . how do you pull language apart into pieces and then put it back together again in some creative way or some effective way. And that really got me interested.Then we just looked around at how the world was changing. And I really felt that cybersecurity was a really important issue. We’re becoming more and more reliant on the internet and we’ve got to stay safe online.

Matthew Fisch, CISSP

So some of the really geeky colleagues in my network treat vignenner ciphers like they’re playing Sudoku. And they get the pages out, and they write it all out. And did you dig into cipher world to that extent, or was this more like storybook ciphers?

Anthony Collette

No, we actually did dig into it. I wanted to understand what the usefulness of any of that old material was. One of the things that really caught my attention was some new information became available about how the NSA explains the evolution of cybersecurity to itself, to an internal audience.

Matthew Fisch, CISSP

That material- That’s interesting.

Anthony Collette

Yeah, that material has only been around for about 15 years, maybe not quite 15. That was very interesting. Cybersecurity has evolved and information security has evolved, and you can look in a history book, but how does the NSA explain it from the podium in their own auditorium to their own audience?That really intrigued me. Looking through that, we just noticed some really interesting odd bits that I didn’t see anywhere else. We thought, huh, why not look at this as a product and see what you can do here?We have explored it quite extensively.

Matthew Fisch, CISSP

Yeah, and it’s not the topic of today, but let’s just talk about your recent adventures there. So what was the first one?

Anthony Collette

Recent adventures with codes and looking at those?

Matthew Fisch, CISSP

Oh, no, no. You had some projects around that, right?

Anthony Collette

Yes, we did. For codes, we looked at codes, and we said, now, is there any possibility, does this have any usefulness in the modern world? And we started looking about that and looking into it.And then we noticed that one cybersecurity company that’s fairly well known had filed a patent application for such a reimagined telegraphic codebook for modern use. And so we weren’t the only people thinking about it. So yes, we looked into that, checked into it, worked through some of the odd bits that came from this new material.One of the top cybersecurity experts at the NSA, in fact, the guy who was in charge of the cryptographic academy there, he was the one who said, if you design a telegraphic code the right way and use it the right way, you achieve a result similar to the use of one-time pads, which seems kind of odd. But he would know, because he was in charge of all that. So it took some thinking and a little more time to dig into that and figure out where he was going with that.But anyway, it is possible to create a product that does serve a useful purpose for some set of people.

Matthew Fisch, CISSP

So wait, just to slow down for just one moment. So a one-time pad, for anyone that doesn’t know, or maybe you’ve heard the word and you think you know what it means, but it’s a perfect cipher because it’s not crackable. The idea is for every bit of information you want to encode with the pad, you have a unique piece of randomness that the universe doesn’t know about, the world doesn’t know about, it’s non-discoverable, and you never reuse any of the randomness.And because you don’t reuse any of the randomness, there’s nothing to learn from to crack the cipher, unless you find the one-time pad and steal it, there’s no way to crack the cipher. So that’s perfect security. Almost no one uses a one-time pad because it’s super impractical to carry around giant books of paper that you have to keep secret.But I just wanted to point that out.

Anthony Collette

One of the interesting issues on this new material that was available from the NSA was, for a long time, people only thought there were two kinds of one-time pads, a number version and a letter version. But in this new material, what the director of that department [David Boak] was saying was, we’ve got an almost endless variety of these things. And so here’s a few different kinds of one-time pads we use.That was interesting that for, what the NSA calls their “customers,” they design and develop all sorts of different implementations of that (one-time pads). But as he was, in this particular instance, he just mentioned that if it’s (telegraphic code book) well-designed, you get a result that’s similar, not uncrackable, not unbreakable, but similar. And that was really intriguing.So anyway, we’ve looked into that. We’ve built a prototype. We’re very interested to see if that is useful in any way.So that’s our more recent involvement in codes. We’re just trying to understand what the practicalities are.

Matthew Fisch, CISSP

So, and you’ve got the fortune cookies, you’ve got the password creator book that I’ve seen. You have to get the password dice, right? Did I miss anything?

Anthony Collette

So yeah. So the dice, CASTALOT® Dice are those 14 large dice that create the kind of password that (password manager company) 1Password says is the strongest kind of password.Same kind of password that would be created if you were using the Google built-in password manager to create a password. And then the Electronic Frontier Foundation (EFF) talks about, so password managers are great for securing your online accounts, but they don’t do anything for your end points — your phone, your laptop, your iPad. To secure those, the Electronic Frontier Foundation suggests using random phrases, that’s Diceware basically.We looked at Diceware and as consumer product developers, we thought, well, how do you make this more colorful, more interesting? We did a prototype to show how you would not change the technology at all, but how you would just make it more interesting and colorful. So that’s our version of Diceware.

Matthew Fisch, CISSP

Yeah. And I really liked that one. I happen to use, myself, I use a memory palace for those in-person passwords that need to be sort of randomish.But describing a meditative technique to password solutions, it’s a difficult conversation to have. People are like, what do you mean you meditate your passwords? Like, you know, you imagine this space in your, anyway.So we’re getting lost here. Let’s bring it back in. We, so, you know, actually I want to go back to the NSA.So for a long time, and this was happening on both sides of the pond, right? Because Bletchley Park, the buildings all run down and basically a disaster these days. But until very recently, I believe that that’s where they were still doing their cryptology training.And here in the US, you know, we’ve got a similar history until not too long ago, a lot of that cryptology was super secret. And there were history books about cryptography and cryptology, but it was ancient history, basically. And the 20th century, most of the 20th century, that stuff remained secret until basically the 90s.And even then, it took some time for that culture change. And I don’t know when that curriculum change happened in the NSA, but it used to be, I mean, you don’t talk about crypto, was like the government’s line. And then they realized, great, we’ve raised an entire generation that don’t know anything about crypto, who’s going to make our crypto work.So they about faced there, but.

Anthony Collette

The newly available material brings it up to like the 1960s, 1970s. So as far as, to some extent, how the NSA talks about it internally. Those materials were made available through something like the Freedom of Information Act, it’s another program.That stuff’s available now. And it’s kind of interesting to read through. I mean, maybe you have to be a bit of a crypto nerd.I’m not sure, but I mean, I found it interesting.

Matthew Fisch, CISSP

In my spare time, which I don’t have much of, that stuff’s super interesting to me. All right. So let’s get it, let’s narrow this down.Cause like, I totally want to get lost in like the crypto of times past, like a thousand years ago. But I think if we just fast forward to the last couple hundred years into the telegraph era, what was really unique about that technical era was it really set the stage for the internet, right? Which was real time communication between these distant points.And just like today on the internet, you really had no idea what’s on the other side of that wire, right?

Anthony Collette

You hope you’re talking to a responsible person, but you never know, right?

Matthew Fisch, CISSP

Yeah. Yeah. And there’s, there’s all sorts of examples of how that’s abused today.And we all know them because like, like everyone’s grandma’s been scammed. Everyone’s like, everyone’s been scammed, right. Or at least been partway through one.And we get those messages every single day. But what, what did this, what did this world look like a couple, a couple hundred years ago? I’m just going to throw the, the question prompt up here.I don’t know if anyone wants to ask questions about this era, but Anthony has been on a deep history dive here. Where do you want to start your story?

Anthony Collette

Well, we’ve got that image of The Victorian Internet book. Yeah. This is like 20, 20, 20 ish years ago.It was a real big hit when it first came out. It’s still very popular. Really the general gist of this is that this reminds me of Battlestar Galactica because it’s all about, “This has all happened before, and it will all happen again.”So many of the concerns and hacks, we’re familiar with today, they happened before and more than once — over and over. With this book, if you were going to hop into a time machine and go back to a time before any practical use of electricity. If you think of 1776 with Benjamin Franklin and Alexander Hamilton, in that period, there’s no electric heat, no electric light, there’s no electric anything. Homes were heated with oil and coal and lighting was by candles and oil lamps.During that period, as far as information, it moved really slowly. It moved from place to place only as fast as a horse could gallop or a train could barrel down the tracks or a ship could sail. Information took weeks and sometimes a month and a half for information to travel from London to New York back then.So people understood that there needed to be a better way to move information around more quickly. There are people all over the world who are experimenting with electricity, trying to figure electricity out, if electricity could somehow accomplish moving information quicker. In 1792, there were these two French brothers named Claude and Rene, and they tried some stuff with electricity, but they couldn’t figure it out.It’s really tricky. They started experimenting with sending information at a distance with sound. They started banging pots and pans together.This is kind of tricky, a little weird, but they started doing that and to experiment with how far could you send a signal with sound. And they figured out that that didn’t work very well because of, well…

Matthew Fisch, CISSP

Yeah, the inverse square law with sound, you know, it’s the same thing that kills us in radio, right?

Anthony Collette

So they gave up on that. And then they decided, well, what if we made something visual? What they did was they built these towers with wooden arms on top called Optical Telegraphs.

Matthew Fisch, CISSP

Oh, wait, we have one of those here.

Anthony Collette

Right. Inside the tower, in the bottom section, there’s two guys operating that Optical Telegraph. They put these towers 5 to 20 miles apart.They used a codebook from the very beginning, and they sent messages down this line of towers. Napoleon was a really big fan and they became really popular. Eventually there were over a thousand of these Optical Telegraphs.

Matthew Fisch, CISSP

This is like a mirror and it just like flashes or what’s happening in this thing?

Anthony Collette

The arms get positioned in a certain position and that relates to something in the codebook. In each tower, there’s a guy with a telescope looking at the tower behind them. The spotter is looking behind them to the previous tower and the message is there.Then he tells the other operator in his tower, hey, make the same message and send it down the line. There was something like this in the…

Matthew Fisch, CISSP

So wait, wait, I can’t get over the tower thing. Hold on. This was, is there a flag on the thing or something like…

Anthony Collette

Those arms bend in certain positions and so they (the operators) move the arms. There was something like this in the Lord of the Rings movie where they lit fire to these towers and then the lights went down miles and miles apart. And that was the signal.It was a very simple signal. That was a call to arms, “come to our aid.” But in this case, they were sending really complex messages down these Optical Telegraph lines.

Matthew Fisch, CISSP

Okay. I could vaguely see how this would be definitely a lot faster than a horse. Right. Questionably faster than a human.Yup. Super expensive. And presumably, like you couldn’t share this entire system.Like it was just like one person’s system because, I mean, how would you even share, how would you even know who the message was about? Right. Like I…

Anthony Collette

Well, it was owned by the state. So when Napoleon was around, he wouldn’t use it for the public. He only allowed use for the state and for the military.It was like a fairly tightly controlled system. Yeah. But there were…But it was super popular for like 50, 60 years. There were some limitations with it. It only worked during the day because you had to have line of sight and you had to see what was going on.The signals couldn’t go around mountains or anything like that. In some places in Europe, you can have a lot of mist, which we don’t deal with much here. But in that time, it was an issue.This was really, really popular. But there were people who took advantage of the system. And there was this famous scandal at the time.These two brothers were government bond traders. And there were, in addition to just the characters, regular characters, there were some functional characters, including a backspace key and other functions like that. These two guys conspired with a telegraph operator to put in some extra backspace characters.That way, they could do this and manipulate things. They manipulated the financial markets that way. And at the time…

Matthew Fisch, CISSP

Oh, wait, wait. So, this is such a great story. So, this was not just like, hey, like we’re being invaded in this direction or like ship me some more troops or food. This was used for any data that the state thought was important enough to beam by tower. Is that right?

Anthony Collette

Right.

Matthew Fisch, CISSP

Yeah. And it was, these towers were basically moving all day because there was lots of, there was information flowing.

Anthony Collette

Absolutely. Yeah. They spent an enormous fortune to build this thing and they…Eventually, they had a thousand of these things all over Europe. It was a huge leap forward. It seems so basic and so rudimentary to us.But at the time, it was a huge improvement. But there’s always a way to collude with people and do something screwy. And so, these guys figured out, well, hey, let’s do this extra backspace.And if we put an extra backspace here and if we put an extra backspace there, then that means something to the operator that they were colluding with. They did manage to get themselves into a really big scandal, but they got away with it because, at the time, there was no law against what they did. Then these guys go on to become these really wealthy casino owners, of all things.

Matthew Fisch, CISSP

That sort of makes sense.

Anthony Collette

There’s the system, the Optical Telegraph, and it’s working great, but everyone is still really fixated on the idea of using electricity to do something better.

Matthew Fisch, CISSP

Wait, what year was that? Let’s call it a hack. I don’t know if hack is the right word for that, but what year was that?

Anthony Collette

That would have been the 1790s.

Matthew Fisch, CISSP

That was like the equivalent of, I guess, racing a commodities exchange to hack a stock sale, the tower equivalent of that or something?

Anthony Collette

Right. One of the things that’s a little hard to imagine is that because information moved so slowly, there were enormous differences in where information was and wasn’t. People were looking to find a way to…I can’t remember exactly what the term is.

Matthew Fisch, CISSP

They were arbitraging to great outcomes, it sounds like.

Anthony Collette

Yes. We’ll see that again here a little while. But yeah, so that’s back from the 1700s, people were taking advantage of technology, new technology, to do a little scam kind of stuff.

Matthew Fisch, CISSP

Okay. So, 1790, haven’t quite figured out electricity yet in terms of communications, but clearly we know there’s this thing called electricity. We think there’s a promise, and then what?

Anthony Collette

Right. People are experimenting with electricity all over the world, but they couldn’t get it to travel very far down a wire. There were just issues with how far can you send it.Then we’re in the 1840s and there’s this guy named Samuel Morse. He had a tragedy in his life. His wife, his fairly young wife, died.He was away from home at the time. The news of his wife’s death took so long to reach him. By the time he got home, she had already been buried.This traumatized him for the rest of his life. He was really focused on the idea of how do you make information move quicker? You’ve got Samuel Morse here in the US.This is now in the 1840s. You’ve got Samuel Morse in the US working through this personal tragedy, really intrigued by this idea of electricity. And then in England, you’ve got a couple of guys named Wheatstone and Cook.They’re doing the same thing there. Here in the US, you’ve got Samuel Morse and he’s doing some experiments and getting it to work longer. He convinces the government to do a test line.The first electric test line is between Washington DC and Baltimore. It’s about, I think, 40 miles maybe. And they get it to work.Then the people in England get it to work. People look at it and say, well, that’s really interesting, but nobody cared.

Matthew Fisch, CISSP

So, this huge- Well, because 40 miles is like, so what, right? Like we can get on a horse and be there in an hour, right?

Anthony Collette

Right.

Matthew Fisch, CISSP

Right. Exactly.

Anthony Collette

They were like, this seems to be a solution looking for a problem. I mean, it just didn’t really click with people. On both sides of the ocean, people did not respond that big.But then, strangely enough, and this sort of mirrors what we experienced with social media here, there were some incidents that really caught the public’s attention. It’s sort of their version of the tabloids and social media, but the popularity of the (electrical) Telegraph took a huge leap forward when it was used to announce the birth of Queen Victoria’s second child. That caught people’s attention.Whoa, that was great. People thought that was amazing. And there was a lot of hoopla made about that.

Matthew Fisch, CISSP

And then- Whoa, whoa, wait, slow down. So, this was like, clearly someone was ready for it, right? And planned that.And this was like, instead of a horse rider, instead of a smoke signal, because there’s a lot of ceremony there, right? Right. And no one’s allowed onto the estate.So, I guess the wire is the safe way to interact. That’s interesting, actually.

Anthony Collette

Yeah. And so, that really caught the public’s attention. And then, all of the royal family went off to one of the castles for an event related to this birth of the second child.One of the royals had left their suit back home. So they used the Telegraph to request to bring the suit back to the castle for this event around the birth of the second child. That was also reported in the news.People thought that was just awesome.

Matthew Fisch, CISSP

This sounds like a setup, Anthony. Like, the royal family must have had some pieces of that, of whatever.

Anthony Collette

Maybe. But that’s like this [modern day] activity around celebrities.

Matthew Fisch, CISSP

Yeah. Okay.

Anthony Collette

Made up a technology.

Matthew Fisch, CISSP

So, a really amazing 1840s marketing campaign that we could all learn from, right?

Anthony Collette

Right.

Matthew Fisch, CISSP

And it’s actually super familiar, really, if you think about what’s happening these days, right?

Anthony Collette

Sure.

Matthew Fisch, CISSP

Sure. Then, people got excited about this thing. But how did that turn into a business?

Anthony Collette

Well, yeah. It caught on really quickly. In 1846, there was only one Telegraph line, and it was only 40 miles long.Two years later, there was 2,000 miles of wire strung up in the US. And two years after that, there was 12,000 miles of Telegraph wire operated by 20 different companies. It just exploded in popularity.

Matthew Fisch, CISSP

So, Western Union, presumably, was a big buyer, right? Because they were racing around on trains, I presume, with mailbags. Yep.

Anthony Collette

Yep. Western Union was the biggest and pretty much a monopoly, basically. Not a total monopoly, but an almost monopoly.And yeah, Western Union was pretty much it. Yeah.

Matthew Fisch, CISSP

There was a lot of capital available for that at that time, right?

Anthony Collette

Yes, there was. Because, where do you string the wires? Well, the railroads already had railroad right of way, where the railroad tracks were.It was a natural fit for them to string Telegraph wire right next to the railroad tracks. The railroads were a big customer of the Telegraph right from the beginning. Because in addition to the celebrity gossip, there was also a true crime angle.Because at that time, these criminals would rob people on a busy train platform and then hop on the train and escape that way. And there was no way to get information about who the criminal was.

Matthew Fisch, CISSP

Not faster than the train they were on, right?

Anthony Collette

Exactly. They basically always got away with it. There were two big networks of these type of pickpocket robbers who got busted by the railroad companies because now they could telegraph ahead and say, hey, this guy who was dressed like this did this, and they would be able to arrest them at the next station.

Matthew Fisch, CISSP

So, one of the earliest, I mean, clearly people were making money on this, right? But one of the earliest social impacts, what you’re describing, is actually sort of crime fighting tactics. So, that’s really interesting.Yeah.

Anthony Collette

Right. Eventually, police departments on both sides of the ocean put together telegraphic code books to send criminal descriptions and information about criminals in a more compressed way over the Telegraph. It became a thing related to law enforcement also.The Telegraph was the world’s first worldwide web. It was their own version of the internet.

Matthew Fisch, CISSP

I guess if you are wealthy, you might have an actual Telegraph in your house, but who knows if you’d be able to operate one, right? You’d have to be trained to operate one because they weren’t originally something that… I think sometimes we see these movies about the early 20th century where they actually had ticker tape that would come out of them in an automated fashion, but that was not the way they started, right?So, this was like you’d have to be trained to operate these things, I presume.

Anthony Collette

Right. You’d have to be trained to operate them, and that created a whole culture that was a lot like the early internet culture. People who…It was a really cool profession to be a Telegraph operator because you got to know things first before anybody else did. Anything interesting that happened in the world, you would know about it. It was also a profession that was open to women because it wasn’t terribly strenuous.That was a part of the culture. And yeah, there were quite a few similarities between the Telegraph operator culture and some of the early internet crowd.

Matthew Fisch, CISSP

Yeah. I know we’re not going to go all the way into the digital era, but I imagine that that job, that Telegraph operator job, not only did it open that job to women, it created the position called “computer,” which used to be a job title, not a thing you buy.

Anthony Collette

Right.It used to be a person.

Matthew Fisch, CISSP

So, the Telegraph network is spanning the world, and then what types of… This is like before there’s a transatlantic cable system yet, right?

Anthony Collette

Right. This was before the ocean cables were put down. There were some echoes of the past, once that system is up and running and businesses are using it like crazy and every business is using it. One of the things they created that was a bit of an echo to our time was they created a nickname system.If you were sending a Telegram to a certain business, you would normally include the whole address, street and city and state and all that business. Well, they charged per the word. So, they came up with a nickname system and each company got to reserve a special word or phrase as their Telegraphic address.Instead of putting the whole physical address, you can just use that one word or phrase to get it to the company you were sending it to. Yhere was a central catalog and this created additional revenue for the post office because there was an annual charge to renew these addresses. I mean, it was a lot like a URL.

Matthew Fisch, CISSP

Yeah, that’s really interesting. So, was there essentially e-commerce happening in this era? I mean, people creating, like basically placing orders by Telegraph and would that go directly to a company that could then fulfill the order?

Anthony Collette

Oh, exactly. Yeah. Ford Motor Company had a Telegraph code.All of these companies conducted business over the Telegraph because it sped things up so fast. And in fact, the people who created the one-time pad in the 1880s, that was one of the largest independent banks. You had banks conducting banking business over the internet, well, over their internet, which was the Telegraph, which, they knew it was totally insecure, but they’re sending money.So, they have to figure out how to conduct business securely over an insecure network. That’s what so many of these security issues were. And that was the driving force because there was so much commerce going on.

Matthew Fisch, CISSP

So, you could redirect money until they figured out, presumably, the banks learned real quick on that one.

Anthony Collette

They sure did.

Matthew Fisch, CISSP

They learned how to encode that, but I could also imagine my mind spinning about the ways you could redirect product.You could order things to an address and then disappear cartloads of goods and no one would ever get that back, right? No one would ever track that down.

Anthony Collette

It happened. There was a lot of fraud, and that’s why that drove the development, the evolution of these different security systems. There were these hacks that were on the Optical Telegraphs, those guys who did the extra backspace keys.And then, in the 1800s, there were hacks where various different types of people were doing all sorts of crime over the Telegraph. And then, even in 1903, you’re moving into later times where you’re talking wireless. Marconi was the guy who was credited with making radio, and he had a Wireless Telegraph, which he was demonstrating.He said, basically, “no one can hack into my Wireless Telegraph. It’s not possible.” He was giving a demonstration to the Royal Society, and somebody totally hacked into his system during the demonstration and said some nasty things about him, which were reported in the press.These kinds of things happen over and over again.

Matthew Fisch, CISSP

And Wireless Telegraph, of course, just being they’re going to send this over the shortwave, I presume.

Anthony Collette

Yeah, just over radio waves.

Matthew Fisch, CISSP

And until very recently, we still had number stations operating that were still sort of beaming those numbers around the world by, essentially, Wireless Telegraph.So, what year are we in now where Wireless Telegraph was just being carted out onto the stage?

Anthony Collette

Yeah. That was demonstrated in 1903 by Marconi. One of the interesting things he did, he thought it would be a really good fit for shipping, the world of international shipping.One of the problems they had was that there were 5, 6, 8, 9 different languages that were really very popular in the world of shipping at the time. Marconi did this thing where he did this Wireless Telegraph, but he created multilingual, automatically translating code books. The same phrases would be in multiple different languages, and the Italians, and the French, and the Spanish, and the English world could use the same materials.

Matthew Fisch, CISSP

That’s super interesting, actually. Yeah. That worked out really well for them.So, I’m just imagining how that would work, which is you have one set of codes, but the translation book is just in your language, basically.

Anthony Collette

Correct. Right. Right.And he was the first person who thought about doing that. Because there was so much of a diversity in language and international shipping, it worked out really well.

Matthew Fisch, CISSP

Yeah. Well, and also in shipping, unlike, I imagine, terrestrial Telegraph, there’s a real limited set of things you really need to communicate. So, they actually could do that, right?Whereas if you’re just trying to freeform language, that would be very challenging.

Anthony Collette

Very challenging. Yeah. Yep.Exactly. The concept we were talking about before was taking advantage of information imbalances. Before, when information was moving really slow, you could have the results of a horse race in one area, but it would take a long time for that information to get to the bookies, or in places where that was legal to do that.But if you could game the system somehow, and people did by using some really colorful, interesting approaches, they would game the system and send a message that was maybe about their scarf, or the tartan, or the color of their scarf, and that would indicate which horse to place a bet on, which was totally illegal. But they did this sort of stuff and tried to get away with it.

Matthew Fisch, CISSP

Well, and in cyber, there’s a concept called a race condition, which is something you have to check for when you’re developing a secure system, which is that there’s sometimes time can be used against you. And you have to check for these things, or it will be, essentially. And this was the first time people had sort of really had to confront that, which is, normally, everyone hold time as a constant, and the amount of time it takes information to travel was sort of a constant, right?And all of a sudden, the speed at which information can travel changed, right? Which even if you weren’t taking advantage of the actual telegraph system, you could use the telegraph system to take advantage of the security of the real world, too, I imagine. And that’s what you were describing, right?Which is, you know, you had bookmaking, which previously, you know, was more or less predictable, right? And then the telegraph happened, and all of a sudden, like, it doesn’t work anymore, right?

Anthony Collette

Right. And they tried to make that illegal to do, and all the Western Union offices and other offices were on guard for that. But they would create these seemingly innocent-sounding messages that they’d send over the telegraph, but they had hidden, sort of like steganography, they had hidden, words and phrases or descriptions of a seemingly innocent thing, but that communicated the idea of, this is the horse you need to bet on, place a bet on this one, and then they would clean up, because they’d make a lot of money on that sort of thing.

Matthew Fisch, CISSP

Now, I feel like I should have done a little bit of telegraph history research before we jumped into today, but I know you’re the expert of the day. So, the thing that’s always been super interesting to me is when we cross the ocean with these signals, how truly strange that is, really, and we all take it for granted, but, I mean, well, first of all, the wireless telegraph, did they figure out how to bounce the signals off to Europe? Was that happening wirelessly?

Anthony Collette

Yeah, eventually they did, but, you know, the big push was to put those cables, the sea cables, and stretch them from coast to coast.

Matthew Fisch, CISSP

And that’s even stranger to me, because honestly, I mean, people just take it for granted, because it’s been around a long time, but I literally cannot imagine a cable that long. I know. I, it’s, it’s the bottom of the ocean, which is already like, you know, it’s like miles deep, right?We’re talking five miles deep in some places, right? And who knows what’s down there. And sometimes they would just stretch this cable across continents.And, you know, we all take that for granted, because like technology does all sorts of um, difficult to fathom things. And we just sort of, oh, of course you could bend reality to like, whatever humanity can invent, think up, like we could just figure out how to do. But this was like a real, like the first time there was a real reality bend, right?Yeah. I think.

Anthony Collette

They got the first one, transatlantic cable down. There was huge celebration. It was considered this enormous technological accomplishment, cost a fortune for these companies to get that cable across the ocean.They had all these parties and it was all, a lot of media excitement about it. And the Queen transmitted a message to the US president. It was a really big deal.And one month later, the thing permanently stopped working.

Matthew Fisch, CISSP

I did remember that. Did we ever find out why or sabotage or bad design or what?

Anthony Collette

Probably not sabotage. Unlike what we see happening today, which is very much sabotage, but for this first cable, no, it was probably just, they had lain cables in water across lakes and across rivers. They had a lot of experience with that, but it’s a long way between the US and Europe.That’s a really long way. And it just took them a while to figure out, how to make the cable consistently of a high enough quality that it would work. There were also some issues with resistance and they had to figure some of those issues out, but yeah, that was a big accomplishment.But then eventually they figured it out. A few years later, they had specialized boats. They had improved the boats, the ships that were laying the cable and improved all the equipment to do that.But with what we see today is, seems like some very intentional.

Matthew Fisch, CISSP

Yeah. And for anyone who’s not paying attention, we have, we have these cables strung all over the planet, more of them today than ever. And near the shore, they’re big, thick things like this.But as soon as you get into deep waters, they’re not that thick because you can’t, you can’t make a 4,000 mile long cable that thick. So they get quite thin and they’re easy to damage. And like, honestly, all you got to do is drop an anchor and drag it, right?

Anthony Collette

Exactly. Exactly.

Matthew Fisch, CISSP

You don’t even have to do it out in the middle of the ocean. You can just do it like a couple miles offshore. And yeah, we’re seeing cable attacks in the last couple of years that I don’t recall in living history.I, I, I’m not even sure that that’s ever happened. Have people ever attacked these cables in the past the way that we’re seeing now?

Anthony Collette

Yes. On the day that World War I was announced, cables were cut. It’s an old tactic.It’s been used before. So yeah, so it’s not new. It’s just pretty egregious.

Matthew Fisch, CISSP

Well, and we’re, we really depend on these things now. You can, you can repair them and there are repair ships, but it takes two years to lay a new cable. And if you need to raise capital for it longer.So you got to make the cable, you got to lay it, all that stuff. You got to get in line. There’s, there’s only so many cable ships, so much cable.And we’re, it is being cut. And you know, there’s, there’s, you know, people shooting lasers around the planet now too. But, but really our cable system’s important because, you know, you might think, oh, shoot, shooting, shooting digital information through the sky with lasers is like, of course that’s going to replace cables, but it’s really not.There’s, there’s limited, there’s limited bandwidth in the sky. Unlike, you know, a glass cable where there’s a, it’s really a limited resource, but we can beam around with lasers. And in addition to that, the sky is vulnerable to all sorts of things.You know, a cable, if no one cuts it intentionally is really resilient to pretty much anything that mother nature can put out there. So it’s a little, it’s a little worrying. It’s a little worrying that some like really big systems in the world, right.That depend on these things are, you know, we haven’t heard in the public talks of holding, holding ransom around this, but like the, the unsaid thing between super, unsaid, unsaid truth between superpowers is like, you know, we don’t, we don’t have to drop bombs. All we got to do is drag an anchor, you know.

Anthony Collette

Right. And you’re seeing Finland and Sweden being far more aggressive about seizing the ships that do this, dragging them into their own waters, investigating, boarding your ships, investigating, both Finland and Sweden have done this in the past two months. They’re getting pretty serious about trying to, trying to encourage whoever’s doing that to stop doing it.

Matthew Fisch, CISSP

Now people may not know this and I’m, I’m, I’m looking for maybe if there’s a telegraph equivalent to this, but in the last several decades we’ve had this cable system and it was copper. And recently we’ve, we’ve pretty much phased copper out. These days we’re, we’re all fiber, but whether it’s copper or fiber, the US government’s been down at the bottom of the ocean tapping these cables.Right. So we have the NRO, the the National Reconnaissance Office, it’s literally in their mission to do this. They maintain a fleet of submersible, submersibles built to do that exact thing.Right. And they can literally dock a submarine on the ocean floor and they pull that cable inside. They, they splice it.And all of a sudden that, that they got a copy of everything in that cable and they run their own like sort of trunk splice line to wherever they want. And they have a copy of that information. And actually I’m, I’m comfortable talking about that in public because these concepts are a little dated.We’ve got other ways to steal information these days. And I don’t know that that’s happening as much as it was happening, say a couple of decades ago, this was sort of like really sophisticated stuff. But I mean, was this happening in the Telegraph era, people tapping into cables and, and just like, I guess, is that where the word tap came from?

Anthony Collette

Yes. To answer your question. Yes.It happened during the Telegraph era. It was a real issue during the Civil War because the other side, whichever side you’re on, the other side would do their best to gain access to the Telegraph line. And it was pretty easy to do.So that was a very common thing there. More use of ciphers and codes for the military, that was one of the issues that facilitated the evolution of codes and ciphers then during the Civil War was that people were tapping the Telegraph lines.

Matthew Fisch, CISSP

Now that this is because they’re sitting on the side of the road and you can just drive up to a right there, strip a little insulator off and just go up that, go up that pole.

Anthony Collette

They had people who would climb the poles and just physically attach equipment to them. And yeah, it was a thing.

Matthew Fisch, CISSP

I, I, I, I shared this story when we were in the green room. But I just want to, you know, when I was studying for my cybersecurity credential, there’s all sorts of case studies. You have to, when you’re reading textbooks, right.One of the, one of them was that the, these Telegraphs into, into World War I, we had, we had radios, the military had radios. But for security reasons, they would drag Telegraph wires out into, into trenches to secure their, their orders. So they couldn’t be picked up on the, out of the ether, so to speak.This is like trench warfare, super new. They’re trying to figure out how to like dispatch and stuff. And I, I’m sure it was someone in the accounting department asked, Hey, can we save some money on wire?And they realized they didn’t need to drag two wires, a pair of wires out to the trench. They could just drag one wire and then they could stake it into the ground and the ground would be the return path for the Telegraph. But of course, if you’re on the other side, all you have to do is stick your own stake in the ground, pretty much anywhere.And you’d be able to tap the signal from that Telegraph. And I’m, I’m wondering, I mean, I, I, I know technically how you could do this. We use these concepts even to, to yank encryption keys out of a computer from 10, 10, 15 feet away.We can do this these days. I’m wondering if people were pulling signals out of these wires without even climbing the pole. Is that something that could be done?

Anthony Collette

I bet it, I bet it could. I bet you could like poke a stake into the ground nearby and pick up the bleed over. Yeah.Right. Right. Yeah.It’s like an early day version of Tempest, — all those issues about the security of moving information through different environments and signals going far outside of the lines of the equipment that they were meant to stay within, but yeah. Yeah.

Matthew Fisch, CISSP

Well, I, I could just keep talking about this. And it seems like you could too. We’re running out of time here.I want to make sure we take a moment to just remind everyone about Loistava. So you are on a little bit of a mission. So we talked about some of your, some of your projects and the, was the fortune cookies the latest, we didn’t talk about the stickers, right?What other, what other things are, what do you want to talk about? Tell people about Loistava Information Security.

Anthony Collette

Oh, sure. We really like the idea of using physical products to help people clue into cybersecurity ideas. We created this fun Cyber Fortune Cookie project, mostly as a cybersecurity awareness product that businesses could use.There’s the Cyber Fortune Cookies themselves. There’s some stickers, there’s some enamel pins. It’s colorful and interesting and odd, and it attracts people’s attention.Just the experience of opening a fortune cookie with a cyber fortune inside is something different, kind of interesting. These other products that we created were to find ways to make colorful, interesting products that are physical, because from our point of view, physical products and physical teaching aids have always been used to help people understand unfamiliar concepts. There’s a lot about cybersecurity that’s not really well understood by the general public yet.So we think there’s some opportunity there to help people understand better.

Matthew Fisch, CISSP

Yeah. And fortunately, I think I have to say that even specialists are not as informed as they should be. Frankly, the world is moving too fast for all of us.So we have to, we have to, we have to help each other.

Anthony Collette

Yeah.

Matthew Fisch, CISSP

Next week we have security KPIs. We’re bringing, we’re giving, bringing Garrett Grayjack from YouAttest back with, with Bill Lauterbach, Kashif Mahmood. We’re going to be talking about security KPIs.You know, YouAttest has this new cyber trust score around personal identities. We’re going to be digging into that as well. I can’t wait to have that conversation.So come on back everyone and join us next week. But until then, thanks for joining us and like, share, subscribe to us on YouTube or LinkedIn. Have a great weekend.Yep. Bye.

Scroll to Top