This video is a very deep dive on all of the different ways that you can covertly send and receive data. I'm going to show you how to secretly store encrypted files in music that sounds completely normal [music] to the human ear. I've even made a little web app where somebody could paste a link to a Spotify song and it unlocks a completely [music] secret separate audio stream. What do you do >> with a dead chemist? >> I'm going to show you how you can send and receive encrypted messages via ultrasound with no cell service or Wi-Fi required by turning your phone into a modem. We're going to be exploiting Meta's copyright protection to store ebooks inside Instagram videos. And I'm going to show you how I stored, hosted, and shared malware inside of a harmless Facebook photo of my friend Gary here. >> [music] [music] >> In 499 BC, [music] Greek ruler Histiaeus wanted to instigate a revolt against the Persian king, but sending a traditional letter was too risky. So, he shaved one of his servant's heads, tattooed a message to his scalp, and then waited for the hair to grow back. He then sent the servant to enter Persian territory as an ordinary traveler to visit Histiaeus' son-in-law where he said, "Yo, shave my head. Your dad has a secret message for you." And how exactly this is more efficient than just having your servant memorize a secret message is lost on me, but this may be the first example of steganography in recorded history. It also started the Ionian Revolt and Greco-Persian War, which lasted over 50 years and killed hundreds of thousands of people. It turns out that wax was invented like 500 years before paper, so people used to jot stuff down by pouring wax on wood tablets, then carving in their thoughts, and rubbing the wax to erase it when they make a mistake. In the same war that I just mentioned, Demaratus, an exiled [music] Greek living in Persia, heard some gossip of a plot to invade Greece. So, he scraped off all of the wax off of a tablet, carved the news [music] into the wood, and then poured fresh new wax on the tablet over the message. It made it through the guards, and in Sparta, everyone was like, "Why the did this dude send us a blank tablet?" until Gorgo, aka the queen of Sparta, was a little sus about it and figured out how to read the secret message. During the Roman Empire, Pliny the Elder figured out that the transparent fluid from milkweed plants charred at much lower temperatures than wood [music] or paper, making it the perfect candidate for invisible ink. A short time after that, Roman military commanders got sick of picking milkweed and figured out that their own urine had the exact same invisible ink properties. So, for many years, the Romans sent piss messages back and forth to and from spies. In 1499, German monk and mathematician Johannes Trithemius wrote a series of books called Steganographia, and they were about magic, basically the complete idiot's guide to using angels to communicate over long distances. And it was actually banned by the Catholic Church, as I suppose the FCC didn't allow angel comms at the time. It wasn't until a century later in 1606 when people started realizing that some of these books were actually cover texts for material on cryptography. These books were analyzed for give or take 400 years, and it was widely believed that the third book was actually about angel communications. And it wasn't until 1996 that third book was finally deciphered to also be about methods of [music] hiding information. Post-classical Italy was full of encryption. Leon Alberti made the first cipher disk in the late 1400s, [music] which allowed text to be easily encoded into random characters and then decoded by someone else who [music] had that particular decryption cipher. This is called a shift cipher or a Caesar cipher, as this method of encryption was used by Julius Caesar centuries earlier. It's pretty simple. If you visualize the alphabet on a wheel, the number of shifted keys is the distance between two [music] sets of letters. I made some simple HTML code that can encode and decrypt this easily, [music] and it would have blown Julius Caesar's mind. In 1550, mathematician Gerolamo Cardano published a collection of physical experiments and inventions called The Subtlety [music] of Things. And among these inventions was what is now called the Cardan grill. It's a simple physical decryption key that can be placed over pre-existing text to outline a hidden message. In 1772, Philip Thicknesse Philip Thicknesse, what a name. He was a travel writer, an eccentric, [music] and a liar, I guess. He wrote a book about writing music with a harmonic alphabet as a way to secretly transmit information. A few decades later, classical composer Joseph Haydn's little brother Michael sorted out a simple musical cipher system where the alphabet could be represented by notes across a span of octaves. In 1936, Alan Turing had an idea for what he called a universal machine, but it wasn't until World War II a few years later when countries started pouring resources into conceptual computing devices to try and break this thing, Enigma, the infamous impossible Nazi encryption puzzle. Fun fact, while there aren't many fun facts about Nazis, Enigma was initially developed by the Dutch to communicate banking secrets and Germany bought the patent in 1923. Germany then improved Enigma and would communicate with troops using nonsensical codes that thousands of mathematicians around the world tried to crack. The machine scrambled letters using a plugboard, a series of rotors, and a reflector. Every time a key was pressed, [music] the machine's internal wiring shifted, meaning that the same letter could be encrypted differently each time. Jerry Don made probably one of my favorite YouTube videos of all time demonstrating exactly how Enigma worked. So, I'm just going to link that in the description. But military historians estimate that cracking Enigma shortened the length of World War II by nearly half a decade, thus saving millions of lives and possibly changing the political map of Europe forever. Throughout the Cold War, there was a whole lot of hiding in other but my favorite were the microdots used by the KGB and ultimately CIA and whatever other nefarious organization. [music] I actually obtained a KGB replica that a collector made and it's inside a quarter. And And you put this quarter inside of a special wedding ring and slam it against a desk a few times, it opens up with a secret container. And inside that container is this tiny speck of film that is hardly even visible by the human eye. And when you view that film under a powerful microscope, you have a cipher sheet that was used as a reference for decrypting communications from [music] things like Soviet number stations. And a number station is a mysterious remote shortwave broadcast transmitter that repeats recordings [music] of mysterious codes or text via Morse code. The radio signal can travel around the world by bouncing [music] off of the ionosphere, which acts as a large mirror for electromagnetic waves. These signals [music] then can land on an entirely different continent communicating the secret message. And the cipher for that message is printed on a [music] tiny little micro dot smaller than a grain of sand hidden inside of a quarter. And by the way, creepy number stations still exist today, although not nearly as much as they did during the Cold War. In modern times, encryption standards have gotten incredibly complex. So complex that I would have no idea how to understand them well enough to visualize or explain them [music] properly in a YouTube video, but that doesn't matter because this video isn't about encryption, it's about hiding in other And my first experiment is a pretty simple concept. Could I hide a computer virus or malware in an image [music] and then upload that image to Facebook and then have the malware survive being recompressed by Facebook's image handler? Believe it or not, I actually have a little bit of experience related to this. A lot of people get really cranky about the pronunciation of malware. Like four out of five people say >> malware. >> But I feel weird saying it that way because I wouldn't say malicious software. I would say >> malicious. >> Anyway. I created and patented an AI music detection algorithm that works really well because it has nothing to do with detecting AI itself. Let me explain. When a musician finishes or masters a song [music] and saves it from Pro Tools or FL Studio or whatever, the file that they're uploading to Spotify or YouTube is uncompressed and lossless. [music] Meaning every single byte of audio data is preserved the way that it was saved. To save on bandwidth, streaming services like Spotify use a variety of compression formats to make the files much, much smaller, [music] but the vast majority of listeners can't really tell the difference. This compression method works using something called discrete cosine transform, and since AI music sites typically just ripped music files from streaming platforms instead of obtaining the master files from the artists or paying them for it, my algorithm essentially forensically [music] detects frag ments of that compression in the training data, and we're going to use that same math to hide a file in an image. Discrete cosine transform is used just about everywhere in your day-to-day internet life. It's the reason this video isn't 200 GB, and why 5 minutes [music] of browsing Instagram doesn't run you over your cell phone carrier's data limit. In images, discrete cosine transform [music] works by deciding what is useful and what isn't. When you take a raw photo with an SLR, the camera measures the electrical charge of each pixel, [music] estimates the color, and then stores the data. On this 33-megapixel camera, that's happening for over 32 million pixels every single time you take a photo. I'm going to try and give you a visible example. Let's take a photo of this beautiful hen of mine and her new babies, turn it to grayscale, and then pull a complicated 8x8 pixel box out of it. Let's bring it into my little example program that I whipped up, and we get to see what the unblended pixels look like. Over here, we have 64 different coefficients or pixel values, but we can decrease that all the way down to 24 before we notice any meaningful change in [music] the image. And when you zoom out, those lost details are going to be completely unnoticeable to the human eye. This alone makes the image use 2/3 less data storage. [music] Now, let's try and exploit that algorithm to hide a file. Many forms of steganography in images utilize a trick called the least [music] significant bit. When pixel data is stored in 8-bit images or video, the color is decided by three ranges of numbers from 0 to 255, red, [music] green, and blue. This allows 16.7 million different combinations of these three colors, covering almost all of the colors your eyes can see in the visible light spectrum. In fact, for the casual viewer as demonstrated earlier, this is actually overkill because you can't tell the difference between purple with a red value of 121 or purple with a red value of 122. Most people don't seem to notice a change until the color is changed by four [music] or five values and that presents a very unique opportunity for us. So, check this out. If you press a key on your keyboard, this is how that character breaks down in binary. To store that binary into some pixels, [music] we're going to need to change the least significant bit, which in this case will be in red. But, all of these things that I've talked about in this section [music] are at odds with one another because image and video sites use similar pixel [music] quantification to reduce file size, thus corrupting the subtle secret messages that we could store in the pixels. There's a really clever and fascinating workaround for this. JPEG file compression typically only pays attention to higher frequencies as our eyes are less likely to notice the subtle color or data changes due to the Weber-Fechner law. I know this is getting really dorky, but this is cool. Basically, human brains are really good at noting subtle differences in smaller quantities and really shitty at noticing them in larger quantities. So, if I had three books on a bookshelf and I added [music] one, you'd definitely notice that by glancing at them. If I had 100 books on a bookshelf and added one, you'd not notice it unless you manually counted them. The same theory applies for color [music] frequencies, whether we're looking at the color itself or visualizing the waveform. If I were to increase this frequency by one or two compressions or rarefactions in the periodic [music] function, you would almost certainly notice a difference. But, if I were to add one or two to this higher frequency down here, you probably wouldn't. Fortunately, we have Jabit Steganography. [music] It hides the file by targeting those lower frequencies that JPEG compression usually ignores and then manually brightens the entire group of pixels. The original source code only supports hiding [music] text or other images, but a pot of coffee and a few hours later, I've made a simple web interface that supports other file [music] formats including archives. So, let's head over to Church of Malware and download nexpose for Microsoft Server Message Block and run my Javid script with the web UI. Then, let's take a picture of my emo dog Gary, drag and drop [music] the exploit into the image, put in a password, and adjust some settings, and upload it to Facebook. Now, [music] let's download it off of Facebook, pop it back into Javid, and there you go. We've hidden and stored a major dangerous exploit inside of a Facebook image. By the way, if you just want to hide stuff locally in your image files and don't intend on putting it on a social media service like Facebook where it'll be recompressed, there's a free program called OpenStego that does just this. It even encrypts them. So, for example, if you wanted to have a text file with a password or decryption key in it, you could inject that file into the Windows desktop [music] shortcut file for, I don't know, Microsoft Word, and it could just live inconspicuously there with only [music] you knowing about it. This channel has some history of hiding data in audio files. I've explored things like Medicine, I've poison pill music files to confuse AI models, and I've even stored data in a bird song. But, what if, I don't know, you lived in some type of dictatorship that made certain types [music] of communication forbidden? Could we covertly hide data in audio? The easiest trick to hide data in audio can be done in any audio editor. You take a stereo file, and then you make it mono by making both the left and right channels identical. Then, invert the waveform of only one of the channels, and then paste [music] in an audio data transmission at a lower volume. In this case, I'll use Morse code. When you convert or listen to the audio file in mono, only the transmission remains. A more savvy and complex way of doing this is with spectral modulation. When you analyze an audio file, you're likely looking at a much larger amount of data than your ears are actually utilizing to listen to the music or content. And just like with images, audio compression uses techniques like discrete [music] cosine transform to save disk space by removing what isn't thought to be useful. But, spectral modulation, on the other hand, works the opposite way [music] by hiding random chunks of noise within the audio spectrum that most people cannot hear. I wanted to make some software that could cram enough data into an audio file to be able to store [music] a completely separate second secret audio layer. Before we dive into the different algorithms and how well they worked, allow me to introduce you to my pyramid of expectations. I can definitely hide stuff in an audio file while preserving the original music or sounds. I can also store a decent amount of data in that audio, and I can do this in a way that can survive being encoded to more efficient files and streaming services. All of these three things are possible, but one of those will need to be sacrificed in order to have the other two. Or think of it like a little slider that you can just place anywhere in this triangle. I released a short test [music] album under a random name with quite possibly the simplest and most minimal music possible. It's just me [music] playing a soft analog synthesizer melody. The complete lack of drums or any diversity in the instrumentation makes [music] hiding anything extremely difficult. So, this is that music file ripped from Apple Music and Tidal with their highest quality setting enabled. >> [music] >> To me, it sounds completely identical to my original recording, but let's listen to the hidden stream. What do you do with a dead chemist? Bury him. And if you haven't figured it out, the hidden stream is me telling science jokes. At higher compression ratios and the lower quality, like a 360p or 480p YouTube video, it didn't work quite so well. You can certainly hear the hidden layer, but you can't easily make out what I'm saying. But now I wanted to try hiding an actual file. And in this case, it would be a 344 kilobyte zipped ebook. To do this, the encoder converts the audio to a spectrogram and then applies the exact same type of technique we used with the images, [music] hiding data by manipulating the least significant bit. This results in this 86-second long recording being completely indistinguishable from the original while being able to store literally any file under 400 kilobytes. In my tests, this survived Spotify and Tidal's high quality settings, but Apple's standard AAC compression and YouTube either stripped the data needed to identify the file or broke the archive. To survive the lower quality compression ratios on YouTube videos and streaming platforms, I added in the option to use multi-frequency shift keying, which is much more robust, but can only store about 2 kilobytes per minute of audio, and at higher levels could also be more noticeable in the audio. I included a stego strength slider so you could test it out yourself and see what works for you. If you have or are willing to run the Python 3 installer, you can easily launch this yourself on your own web browser, and of course, if you want to improve it, all the source code is there. I have a few more ideas and programs. Some years back, Georgi Gerganoff, who by the way has the best profile photo on all of GitHub, made a program called GG Wave, which was a brilliant acoustic messaging protocol that could run on Android phones. >> [music] >> It hasn't been updated in quite a while and is formally obsolete, but I figured his source code was the perfect place to start. I wanted to update some libraries so this protocol could run on newer Android devices, and I wanted to add some optional ranges: audible, ultrasound, and inaudible. Not all devices will be able to pick up or transmit the inaudible sounds as it depends on the frequency response of your phone's microphone and speakers. I also added a call sign feature and encryption. [music] So, for example, if you were on an airplane with a big group of friends, you could chat about your plans for dinner when you land or your plans [music] to hijack the airplane or whatever, it's up to you. I added a fancy little waveform and spectrogram so you could see the audio signals coming in, and a loopback test to make [music] sure that everything is encoding and decoding correctly on your device. Since the old Android build of GG Wave was called Waver, I guess we can call this one Wavist, which most people will probably read as Wave Street, which is probably a cooler name anyway. I did a lot of testing with Bluetooth [music] speakers, quietly embedding messages in media, and ultimately hacking an FM radio signal and transmitting the encrypted wavest messages to my car stereo. This involved setting up a high-end SDR to receive and decode [music] FM signals, add in a layer of ultrasonic messaging noise, and then encode and transmit it on the same [music] frequency. By the way, my transmission wasn't all that powerful, and I really don't know how legal it is. I also don't know how useful it is, but it was fun to see that it worked. Combining these encrypted communications [music] and the steganography earlier in this video, I ended up just making an easy-to-use playground called bum [music] 16, which stands for Ben's ultrasonic modem that uses 16 FSK or frequency shift keying by default to encode [music] and decode messages and files. It also supports parallel shift keying for sending data in [music] quiet environments and forward error correction for very noisy ones. You can also select the speed per symbol [music] to make the data rate slower and more robust. I've posted this also, it's free and open source, and there's a rough build of an Android app that's basically just [music] a quick conversion of the web app. So, if you ever want to send someone a selfie over PA system in a place with no Wi-Fi or cell service, >> [music] >> I guess we've made that possible today. I found that Meta had published a video watermarking tool called Video Seal, and it's used to verify content and its origin. So, for example, if I upload something to Instagram, and then somebody else copies it, Meta will be able to tell that the content is an original, and then it will be able to adjust the algorithm accordingly to reward the person [music] who created the content. Pretty cool, seems to work. It's also used to help identify ethical AI video problems like [music] deepfakes. And this mechanism is just hiding a tiny bit of information in a video, after all, and it's made for the sole purpose of surviving social media file compression. It's also open source with an MIT license, so this might be our baby. I borrowed the encoders and decided to repurpose this into something that simply cramps data into the raw output of the Video Seal model. Instead of embedding codes into random frames of video, it just utilizes as much of the video container as possible to maximize [music] data storage, which ends up looking [clears throat] like an animated mixture of static and QR codes. I'm calling it video zuck, and it's actually pretty good. I was able to store an ePub of George Orwell's 1984 and a video file that was under 2 seconds long, and then retrieve the data with 100% [music] accuracy. I uploaded a whole lot of private Facebook reels to test this out, and it didn't seem as robust as I had hoped, but as long as [music] I was using full HD resolution and large block sizes, I was repeatedly able to store and extract an ebook inside of a few seconds of a Facebook [music] or Instagram reel. I personally would not call this a success. After seeing how much data I could cram into images and audio, I imagined that with advanced video encoders, my 4K YouTube videos could secretly store hundreds of megabytes. But it turns out, and an obvious conclusion here, is that advanced video encoders are advanced at finding and removing unnecessary or unwanted data. So if we combined our most functionally robust audio and video decoders together, we'd be lucky to get like 100 kilobytes per second. And the longer the video, the more error correction needs to be done, which means that the storage ratio gets less efficient as the file gets bigger. Most importantly and honestly, I wouldn't call any of these reliable. [music] If you actually wanted to send someone a secret message via Spotify or an Instagram post, you'll need to test [music] it yourself first to make sure that it works, as none of these methods are 100% effective. Now you're wondering, was this video full of secret files? There is one in here, and I won't know if it survived YouTube compression until it's uploaded. If you learned something today, enjoyed this video, or found the code useful, and if you want to see more stuff like this, or help the ongoing projects I have with investigating the efficacy of flock safety, or building a low-cost device that can measure and standardize infrasound noise pollution and air quality around data centers, or if you just want to access a bunch of dumb synthesizers and music and audio assets, or if you just want access to an amazing and healthy community of like-minded folks, my Patreon is for you, and you can join for as little as $1. Thanks for watching. Keep creating. Bye.