Saturday, May 23, 2015

The OSS Bern station and the compromise of State Department codes in WWII

In the course of WWII both the Allies and the Axis powers were able to gain information of great value from reading their enemies secret communications. In Britain the codebreakers of Bletchley Park solved several enemy systems with the most important ones being the German Enigma and Tunny cipher machines and the Italian C-38m. Codebreaking played a role in the Battle of the Atlantic, the North Africa Campaign and the Normandy invasion. In the United States the Army and Navy codebreakers solved many Japanese cryptosystems and used this advantage in battle. The great victory at Midway would probably not have been possible if the Americans had not solved the Japanese Navy’s code.

On the other side of the hill the codebreakers of Germany, JapanItaly and Finland also solved many important enemy cryptosystems both military and diplomatic. The German codebreakers could eavesdrop on the radio-telephone conversations of Franklin Roosevelt and Winston Churchill, they could decode the messages of the British and US Navies during their convoy operations in the Atlantic and together with the Japanese and Finns they could solve State Department messages (both low and high level)  from embassies around the world.
The M-138-A strip cipher was the State Department’s high level system and it was used extensively in the period 1941-44. Although we still don’t know the full story the information available points to a serious compromise both of the circular traffic (Washington to all embassies) and special traffic (Washington to specific embassy) in the period 1941-44. In this area there was cooperation between Germany, Japan and Finland. The German success was made possible thanks to alphabet strips and key lists they received from the Japanese in 1941 and these were passed on by the Germans to their Finnish allies in 1942. The Finnish codebreakers solved several diplomatic links in that year and in 1943 started sharing their findings with the Japanese. German and Finnish codebreakers cooperated in the solution of the strips during the war, with visits of personnel to each country. The Axis codebreakers took advantage of mistakes in the use of the strip cipher by the State Department’s cipher unit.

Apart from diplomatic messages their success against the strip cipher also allowed them to read some OSS -Office of Strategic Services messages from the Bern station. The compromise of OSS traffic did not remain secret for long. In 1943 Allen Dulles (head of the OSS Bern station) received word from Admiral Canaris and General Schellenberg that his communications had been compromised and in addition the German officials Hans Bernd Gisevius and Fritz Kolbe showed him actual decoded US messages. It’s not clear what measures the US authorities took to protect their communications but the diplomatic traffic continued to be read by the Germans and the Finns in the period 1943-44. It seems that the US authorities attributed the German success to physical compromise (probably a spy in the embassy) and thus didn’t realize that their ciphers could be solved cryptanalytically. They would realize how wrong they were in late 1944 when more information became available on the compromise of State Department codes and ciphers.
In September 1944 Finland signed an armistice with the Soviet Union. The people in charge of the Finnish signal intelligence service anticipated this move and fearing a Soviet takeover of the country had taken measures to relocate the radio service to Sweden. This operation was called Stella Polaris (Polar Star). In late September roughly 700 people, comprising members of the intelligence services and their families were transported by ship to Sweden. The Finns had come to an agreement with the Swedish intelligence service that their people would be allowed to stay and in return the Swedes would get the Finnish crypto archives and their radio equipment. At the same time colonel Hallamaa, head of the signals intelligence service, gathered funds for the Stella Polaris group by selling the solved codes in the Finnish archives to the Americans, British and Japanese.

The Finns revealed to the American representatives that they had solved several State Department codes and could read the messages from a number of embassies including Berne (Carlson-Goldsberry report). Obviously the OSS leadership was interested in finding out whether OSS communications passing over diplomatic links were also read.


 

Unfortunately the relevant files in the OSS collection do not reveal the final outcome of this investigation.
It seems that during the same period the OSS received more concrete evidence regarding the compromise of the communications of the Bern embassy. In the US National Archives and Records Administration, RG 226 ‘Records of the Office of Strategic Services’ - Entry 123 there are intelligence reports from Bern received in late 1944. Some of them contain summaries of decoded US messages of the Bern embassy that must have come from German reports given to the OSS by members of the German Resistance (probably Gisevius and Kolbe). For example:


 
Looking at these files it seems that the OSS leadership shouldn’t have been so surprised by the Finnish disclosures. They already had enough information from their German sources to conclude that some of their traffic was read by the Axis powers. It’s not clear if this material was shown to other US agencies, as there is no mention of them in postwar reports dealing with the compromise of US codes (European Axis Signal Intelligence in World War II volumes).

Sources: NARA-RG 226-entry 123-Bern-SI-INT-29 -Box 3-File 34 ‘German intelligence, Hungary’, ‘Hitler, the Allies, and the Jews

Thursday, May 21, 2015

Awesome!

This doesn’t have anything to do with WWII or codes and ciphers but it’s too awesome not to upload (provided you watch the show)



Sunday, May 17, 2015

Update

1). The following reports are available from the NSA’s website:

Flicke vol2

Interrogation of Samarughi, Giuseppe

Interrogation of Augusto Bigi

I’ve also added them in my TICOM collection (both google drive and scirbd).

2). I added the following paragraph in German intelligence on operation Overlord:
Division Field Code of the 29th Infantry Division

The US Division Field Code was a 4-letter codebook of approximately 10.000 groups, used primarily for training purposes. In 1944 the 29th Infantry Division, stationed in the UK, was using the 28th edition of the DFC for training messages. Some of these messages were solved by NAAS 5 which was the cryptanalytic centre of KONA 5 (Signals Intelligence Regiment 5), covering Western Europe. The reports of that unit show that these decoded messages allowed the Germans to identify the 29th Infantry Division and considering the unit’s rule during operation Overlord it is possible that they gave the Germans vital clues about the upcoming invasion of France.

3). I added the following paragraph in US military attaché codes of WWII:
It seems that both were referring to a telegram sent on July 24 1942 by Leland B. Harrison, US ambassador to Switzerland, to assistant secretary Gardiner Howland Shaw (who was in charge of the State Departments cipher unit) warning him that an Italian official had met with Harold Tittmann (US representative to the Vatican) and had told him that the US diplomatic code used by the embassy in Egypt was compromised. The Germans obviously solved this message and thus attributed the end of the Fellers telegrams to Italian treachery. However looking at the dates it’s clear that this was not true. Fellers changed his cryptosystem in June 1942, while this telegram was sent in July.

4). I added the following links in Italian codebreakers of WWII:
CSDIC/CMF/Y 29First detailed interrogation of Samarughi, Giuseppe’, CSDIC/CMF/Y 4First detailed interrogation of Bigi, Augusto’, CSDIC (main)/ Y 12 First detailed interrogation of Vassalio Todaro

Saturday, May 9, 2015

The compromise of the communications of General Barnwell R. Legge, US military attache to Switzerland

In the course of WWII both the Allies and the Axis powers were able to gain information of great value from reading their enemies secret communications. In Britain the codebreakers of Bletchley Park solved several enemy systems with the most important ones being the German Enigma and Tunny cipher machines and the Italian C-38m. Codebreaking played a role in the Battle of the Atlantic, the North Africa Campaign and the Normandy invasion. In the United States the Army and Navy codebreakers solved many Japanese cryptosystems and used this advantage in battle. The great victory at Midway would probably not have been possible if the Americans had not solved the Japanese Navy’s code.

On the other side of the hill the codebreakers of Germany, Japan, Italy and Finland also solved many important enemy cryptosystems both military and diplomatic. The German codebreakers could eavesdrop on the radio-telephone conversations of Franklin Roosevelt and Winston Churchill, they could decode the messages of the British and US Navies during their convoy operations in the Atlantic and together with the Japanese and Finns they could solve State Department messages (both low and high level)  from embassies around the world.
The State Department made many mistakes in the use of its cipher systems and thus compromised not only US diplomatic communications but also the messages of other organizations that were occasionally enciphered with State Department systems, such as the Office of Strategic Services and the Office of War Information. Another similar case concerns the communications of General Barnwell R. Legge, US military attache to Switzerland during WWII.


Sunday, May 3, 2015

Friedman collection released by NSA

The NSA has released a huge collection of documents relating to William Friedman. Their statement says:This collection, composed of over 52,000 pages in more than 7,600 documents, including some sound recordings and photographs, has been preserved in the NSA Archives for its historic significance and value. The bulk of the material dates from 1930–1955 and represents Mr. Friedman’s work at the Signals Intelligence Service, the Signal Security Agency , the Armed Forces Security Agency, and NSA’.

You can search their database for specific reports. Here are the links to some files that I found interesting:
Security of our high-grade cryptographic systems - 1945

Study of decoded State Department messages (very interesting…)

Japanese telegram containing decode of US attaché message and the original

American Consul in Madras, India complains about the new cipher machine M-325

TICOM DF list

Work done on TICOM material by AFSA

OTTICO MECCANICA ITALIANA cipher machine

Special conference on M-209 security – 1950 (even in 1950 Friedman didn’t know about the work of NAAS 5 and their decoding device)

Interrogation of Vassalio Todaro

Interrogation of two Italian signals personnel

Italian official informs State Department of code compromise in Cairo (mentioned by Flicke in ‘War Secrets in the Ether’)
Security of Allied Ciphers – 25 August 1945 (contains Soviet intelligence messages from Harbin embassy)

War histories list

Sunday, April 26, 2015

The unscrupulous Italian official and the code of colonel Fellers

One of the most damaging compromises of Allied communications security, during WWII, was the case of Colonel Bonner Fellers, US military attaché in Cairo during 1940-2. Fellers sent back to Washington detailed reports concerning the conflict in North Africa and in them he mentioned morale, the transfer of British forces, evaluation of equipment and tactics, location of specific units and often gave accurate statistical data on the number of British tanks and planes by type and working order. In some cases his messages betrayed upcoming operations.

Fellers used the Military Intelligence Code No11, together with substitution tables. The Italian codebreakers had a unit called Sezione Prelevamento (Extraction Section). This unit entered embassies and consulates and copied cipher material. In 1941 they were able to enter the US embassy in Rome and they copied the MI Code No11. A copy was sent to their German Allies, specifically the German High Command's deciphering department – OKW/Chi. The Germans got a copy of the substitution tables from their Hungarian allies and from December 1941 they were able to solve messages. Once the substitution tables changed they could solve the new ones since they had the codebook and they could take advantage of the standardized form of the reports. Messages were solved till 29 June 1942 and they provided Rommel with so much valuable information that he referred to Fellers as his ‘good source’.
The British realized that a US code was being read by the Germans when they, in turn, decoded German messages containing information that could only have come from the US officials in Egypt. The Americans however were not easily convinced that their representative’s codes had been ‘broken’ and it took them months before they changed Colonel Fellers code.

The Germans didn’t know that the Brits had solved messages enciphered on their Enigma machine and thus had different ideas about who betrayed their codebreaking success. Wilhelm Flicke, who worked in the intercept department of OKW/Chi wrote in TICOM report DF-116-Z about this case:
During the war there was stationed at the Vatican a diplomatic representative of the U.S.A. who stood in radio communications with Washington like any other ambassador or minister. In a radiogram sent to Washington in June 1942, enciphered by means of a diplomatic code book, one could read of a conversation which representative of the Vatican had had with an Italian of high position. During this conversation the Italian had mentioned that the Germans could read the most important cryptographic system of the American Military Attaché. The American representative had learned this at the Vatican through a Vatican official and was therefore warning the American War Department against any further use of this cryptographic system.

 
 


Weisser (a cryptanalyst of OKW/Chi) also said that it was the Italians who betrayed the German success in his report TICOM I-201:


 

Did the Germans have a reason to mistrust their Italian allies?
It seems that the answer is yes. On July 24 1942 Leland B. Harrison, US ambassador to Switzerland, sent a telegram to assistant secretary Gardiner Howland Shaw (who was in charge of the State Departments cipher unit) warning him that an Italian official had met with Harold Tittmann (US representative to the Vatican) and had told him that the US diplomatic code used by the embassy in Egypt was compromised.

 
 
The Germans clearly solved this message and thus attributed the end of the Fellers telegrams to Italian treachery. However looking at the dates it’s clear that this was not true. Fellers changed his cryptosystem in June 1942, while this telegram was sent in July.

Sunday, April 19, 2015

NAAS 5 reports retrieved from France - 1945

During WWII the German Army’s signal intelligence agency OKH/In 7/VI had signal intelligence regiments assigned to Army Groups in order to supply them with radio intelligence on Allied formations. Western Europe was covered by KONA 5 (Signals Intelligence Regiment 5), whose cryptanalytic centre NAAS 5 (Nachrichten Aufklärung Auswertestelle - Signal Intelligence Evaluation Center) was based in Saint-Germain-en-Laye, a suburb of Paris.

In summer 1944 the Germans had to evacuate France and it seems that this unit tried to destroy some of its reports but they didn’t have time to properly dispose of them. Instead many reports were buried.
The US authorities were able to locate the site and they recovered many of these documents. A US report, dated 25 January 1945, says that about 2.000 sheets of paper were recovered and were 30% readable. They included intercepts and decrypts of the M-209 cipher machine, the War Department Telegraph Code, possibly Combined Cipher Machine traffic, as well as the British Aircraft movement’s Code and Syko system.

There was even a message from Washington to the US Military Mission in China from 1942 sent via the gunboat TUTUILA.

Sunday, April 12, 2015

The US Division Field Code

When the United States entered WWII, in December 1941, US military and civilian agencies were using several cryptologic systems in order to protect their sensitive communications. The Army and Navy only had a small number of SIGABA cipher machines so they had to rely on older systems such as the M-94/M-138 strip ciphers and on codebooks such the War Department Telegraph Code, the Military Intelligence Code and the War Department Confidential Code.

Another system prepared for the Army was the Division Field Code. This was a 4-letter codebook of approximately 10.000 groups and in the 1930’s several editions were printed by the Signal Intelligence Service (1). However the introduction of the SIGABA and especially the M-209 cipher machine made this system obsolete. Still it seems that the DFC was used on a limited scale, during 1942-44, by the USAAF and by US troops stationed in Iceland and the UK.
Examples of DFC training edition No 2:








Solution of DFC by German codebreakers
The German Army and AF signal intelligence agencies were able to exploit this outdated system and they read US military messages from Iceland, Central America, the Caribbean and Britain. Most of the work was done by field units, specifically the Army’s fixed intercept stations (Feste Nachrichten Aufklärungsstelle) Feste 9 at Bergen, Norway and Feste 3 at Euskirchen, Germany.

According to Army cryptanalyst Thomas Barthel several editions of the Division Field Code were read, some through physical compromise (2):

The DFCs (Divisional Field Codes).
(a). DFC 15

In use in autumn 42, broken in Jan 43. Traffic was intercepted on a frequency of 4080 Kos from US Army links in ICELAND (stas at REYKJAVIK, AKUREYRI and BUDAREYRI). Stas used fixed call-signs till autumn 43, and thereafter daily call -signs. This field code was current for one month only. It was a 4-letter code, non-alphabetical, with variants and use of "duds" (BLENDERN). It was broken by assuming clear routine messages were the basis of the encoded text, such as Daily Shipping Report, Weather Forecast etc.
(b) DFC 16

This was current for one month, probably in Nov 42. It was similar to  the DFC 15 above.
(c) DFC 17

This was current from Dec 42 to Feb 43. About the latter date one or two copies of the table were captured. Very good material was intercepted from ICELAND, also from 6 (?) USAAF links in Central America, Caribbean Sea etc. Traffic was broken and read nearly up to 100%.
(d) DFC 21

This succeeded the DFC 17. Results were the same.
(e) DFC 25

Current only in CARIBBEAN SEA area, and read in part.
(f) DFC 28 

This succeeded the DFC 21 in summer 43. It was used by the ICELAND links and the 28 (or 29) US Div in the South of ENGLAND. The code was read, Now and again it was reciphered by means of alphabet substitution tables ("eine Art von Buchstabentauschtafel") changing daily. This method was broken because the systematic construction of the field code was known.
(g) DFC 29

A copy of this table was captured in autumn 43. It was never used, PW did not know why.


The War Diary of the German Army’s signal intelligence agency OKH/In 7/VI shows that the DFC was called AC 6 (American Code 6) and several editions were solved in the period 1943-44. Most of the processing was left to field units, with only a few messages solved by Referat 1 (USA section) of Inspectorate 7/VI. The report of March 1943 says that the captured specimen DFC 17 could be used to solve the preceding and following versions (since they were constructed in the same way) and it showed that the code values retrieved by field units and the central department through cryptanalysis were mostly correct (3).
The Luftwaffe’s Chi Stelle was also interested in the DFC and according to Dr. Ferdinand Voegele, the Luftwaffe's chief cryptanalyst in the West, USAAF messages from the Mediterranean area were read (4).


The 29th Infantry Division and the invasion of Normandy
In 1943 the M-209 cipher machine replaced the M-94 strip cipher as the standard crypto system used at division level by the US Army, however older systems like the DFC continued to be used for training purposes. The US military forces in Britain took part in many exercises during the latter part of 1943 and early 1944, since they were preparing for the invasion of Western Europe and some of their training messages were sent on the 28th edition of the Division Field Code.

These messages were intercepted and decoded by the German Army’s KONA 5 (Signals Intelligence Regiment 5), covering Western Europe.  NAAS 5 was the cryptanalytic centre of KONA 5 and its quarterly reports (5) show that training messages from the US V Expeditionary Corps and the 29th Infantry Division were solved.



The solution of these messages allowed the Germans to identify the 29th Infantry Division and considering the unit’s rule during operation Overlord it is possible that they gave the Germans vital clues about the upcoming invasion of France.

Notes:
(1). Rowlett-1974 and Kullback-1982 NSA oral history interviews

(2). CSDIC/CMF/Y 40 – ‘First Detailed Interrogation on Report on Barthel Thomas
(3).War diary Inspectorate 7/VI - March 1943

(4). TICOM IF-175 Seabourne Report, Vol XIII, p9 and 16.
(5). E-Bericht der NAASt 5 Nr 1/44 and Nr 2/44.

Sources: Frank Rowlett NSA oral history interview - 1974, Solomon Kullback NSA oral history interview - 1982, CSDIC/CMF/Y 40 – ‘First Detailed Interrogation on Report on Barthel Thomas’, War diary Inspectorate 7/VI, War diary NAAS 5, TICOM IF-175 Seabourne Report, Vol XIII ‘Cryptanalysis within the Luftwaffe SIS’, DFC training edition No 2, Division Field Code No 4
Acknowledgments: I have to thank Rene Stein of the National Cryptologic Museum for the Rowlett and Kullback interviews and Mike Andrews for the DFC pics.