top of page

Steganography


Steganography is the practice of hiding secret messages inside other seemingly innocuous messages. The term comes from the ancient practice of disguising messages in other messages, such as craving text onto the wooden base of a wax tablet before covering it with the wax which is inscribed on, or writing something under the postage stamps affixed to an envelope for a letter.

In the digital age, data can be manipulated in a variety of ways to conceal messages. You can also use the OpenPuff software to accomplish the task of hiding one electronic file inside other files. This free program can be downloaded here. You just need to download the linked to OpenPuff zip file, extract the files to a folder, and double-click on 'OpenPuff.exe'.

Click where it says 'Hide', and you will be taken to the Data Hiding window.

You begin by setting three different passwords in the upper left section, and then selecting the file you want to hide in the second step. The passwords must each be at least 8 characters. You will need to select alphanumeric passwords that together are of a sufficient length so the the password check box turns green indicating OpenPuff accepts them.

Then in step 3 you select one or more 'carrier' files, until the total size is enough to conceal the file you are encrypted. The combined carrier files will need to be several times larger than the file you are hiding. The carrier files cannot be in any format. You'll have to use bitmap, JPEG, MPG, or one of a few other common graphic file formats. When you're ready, click 'Hide Data!'

When the recipient receives the encrypted files, she or he needs to also have OpenPuff installed. They will have to click 'UnHide' on the opening screen, and then enter the three passwords in the same order, and also select the carrier files in the same order.

Click Unhide!, and the encrypted file will be exported from the graphic files.

This technique has the advantage over standard methods of encryption in that anyone coming across the files will have every reason to dismiss them as being unimportant.


Sean O'Shea has more than 20 years of experience in the litigation support field with major law firms in New York and San Francisco.   He is an ACEDS Certified eDiscovery Specialist and a Relativity Certified Administrator.

​

The views expressed in this blog are those of the owner and do not reflect the views or opinions of the owner’s employer.

​

If you have a question or comment about this blog, please make a submission using the form to the right. 

Your details were sent successfully!

© 2015 by Sean O'Shea . Proudly created with Wix.com

bottom of page