Original URL: http://www.theregister.co.uk/2010/07/30/cyber_challenge_cracked/

Cyber Security Challenge winner announced

Quickest crypto off the mark

By John Leyden

Posted in Security, 30th July 2010 13:07 GMT

The UK's Cyber Security Challenge has announced the winner of its prologue crypto puzzle, as well as the solution - for anyone still struggling to find an answer.

Successful code crackers had to solve a three-stage puzzle of increasing complexity. The task tested basic cryptoanalysis skills, as well as the ability to apply lateral thinking and "read between the lines" to figure out how to proceed from one stage of the puzzle to the next. The first stage involved recognising that the initial ciphertext took the form of a .jpg image, encoded in the base64 system. This .jpg image cartoon contained a binary string on its border, encoded using a simple substitution cipher.

Having solved that stage of the puzzle, would-be codebreakers recovered a message inviting them to visit a specified website. The third phase of the challenge was based on making sense of a bitshift operation applied to a string hosted on this site.

More than 1000 contestants submitted responses to the puzzle with 152 hitting on the right answer. Winner Paul Mutton cracked the code before anyone else and wins a season ticket for Bletchley Park and a personal tour of the refurbished WWII-era Colossus code-breaking computer.

Cyber Security Challenge said it planned to run another code-cracking puzzle at an unspecified time over the coming months, following the success and obvious interest generated by its initial brain teaser.

The cipher challenge was essentially a bit of fun designed to publicise the wider ambitions of the UK's Cyber Security Challenge, which aims to hunt for would-be information security experts and stimulate interest in the topic. The scheme, launched on Monday, aims to address a looming skills shortage by inspiring under-graduates and teenagers to consider a career in cybersecurity.

More than 30 prizes will be awarded during the competition, including internships at net security companies and university bursaries. The scheme has the support of private security firms such as Sophos and Qinetiq, as well as the UK government. ®