CRYPTO-GRAM, February 15, 2003
Bruce Schneier <[email protected]> Sat, 15 Feb 2003 22:17:46 -0600
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
February 15, 2003
by Bruce Schneier
Founder and CTO
Counterpane Internet Security, Inc.
[email protected]
<http://www.counterpane.com>
A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on computer security and cryptography.
Back issues are available at=20
<http://www.counterpane.com/crypto-gram.html>. To subscribe, visit=20
<http://www.counterpane.com/crypto-gram.html> or send a blank message=20
to [email protected].
Copyright (c) 2003 by Counterpane Internet Security, Inc.
** *** ***** ******* *********** *************
In this issue:
Locks and Full Disclosure
Crypto-Gram Reprints
Random Notes on the SQL Slammer
The Doghouse: Meganet
News
Counterpane News
Security Notes from All Over: Anti-Fraud Security at Banks
The Importance of Authentication
Comments from Readers
** *** ***** ******* *********** *************
Locks and Full Disclosure
The full disclosure vs. bug secrecy debate is a lot larger than=20
computer security. In January, security researcher Matt Blaze=20
published a paper describing a new attack against door locks. The=20
specific locks are "master key systems," the sorts that allow each=20
person to have a key to his own office and the janitor to have a single=20
key that opens every office. The specific attack is one where a person=20
with an individual office key can make himself a master key. The=20
specifics are interesting, and I invite you to read the paper. It=20
turns out that the ways we've learned to conceptualize security and=20
attacks in the computer world are directly applicable to other areas of=20
security -- like door locks. But the most interesting part of this=20
entire story is that the locksmith community went ballistic after=20
learning about what Blaze did.
The technique was known in the locksmithing community and in the=20
criminal community for over a century, but was never discussed in=20
public and remained folklore. Customers who bought these master key=20
systems for over a century were completely oblivious to the security=20
risks. Locksmiths liked it that way, believing that the security of a=20
system was increased by keeping these sorts of vulnerabilities from the=20
general population.
The bug secrecy position is a lot easier to explain to a layman. If=20
there's a vulnerability in a system, it's better not to make that=20
vulnerability public. The bad guys will learn about it and use it, the=20
argument goes. Last month's SQL Slammer is a case in point. If the=20
hacker who wrote the worm hadn't had access to the public information=20
about the SQL vulnerability, maybe he wouldn't have written the=20
worm. The problem, according to this position, is more the information=20
about the vulnerability and less the vulnerability itself.
This position ignores the fact that public scrutiny is the only=20
reliable way to improve security. There are several master key designs=20
that are immune to the 100-year-old attack that Blaze=20
rediscovered. They're not common in the marketplace primarily because=20
customers don't understand the risks, and because locksmiths continue=20
to knowingly sell a flawed security system rather than admit and then=20
fix the problem. This is no different from the computer world. Before=20
software vulnerabilities were routinely published, vendors would not=20
bother spending the time and money to fix vulnerabilities, believing in=20
the security of secrecy. And since customers didn't know any better,=20
they bought these systems believing them to be secure. If we return to=20
a world of bug secrecy in computers, we'll have the equivalent of=20
100-year-old vulnerabilities known by a few in the security community=20
and by the hacker underground.
That's the other fallacy with the locksmiths' argument. Techniques=20
like this are passed down as folklore in the criminal community as well=20
as in the locksmithing community. In 1994, a thief made his own master=20
key to a series of safe-deposit boxes and stole $1.5 million in=20
jewels. The same thing happens in the computer world. By the time a=20
software vulnerability is announced in the press and patched, it's=20
already folklore in the hacker underground. Attackers don't abide by=20
secrecy agreements.
What we're seeing is a culture clash; it's happening in many areas of=20
security. Attorney General Ashcroft is working to keep details of many=20
antiterrorism countermeasures secret so as not to educate the=20
terrorists. But at the same time, the people -- to whom he is=20
ultimately accountable -- would not be allowed to evaluate the=20
countermeasures, or comment on their efficacy. Security couldn't=20
improve because there'd be no public debate or public=20
education. Whatever attacks and defenses people learn would become=20
folklore, never spoken about in the open but whispered from security=20
engineer to security engineer and from terrorist to terrorist. And=20
maybe in 100 years someone will publish an attack that some security=20
engineers knew about, that terrorists and criminals had been exploiting=20
for much of that time, but that the general public had been blissfully=20
unaware of.
Secrecy prevents people from assessing their own risk. For example, in=20
the master key case, even if there weren't more secure designs=20
available, many customers might have decided not to use master keying=20
if they knew how easy it was for an attacker to make his own master key.
I'd rather have as much information as I can to make an informed=20
decision about security. I'd rather have the information I need to=20
pressure vendors to improve security. I don't want to live in a world=20
where locksmiths can sell me a master key system that they know doesn't=20
work or where the government can implement security measures without=20
accountability.
Blaze's home page for his research:
<http://www.crypto.com/masterkey.html>
The paper itself:
<http://www.crypto.com/papers/mk.pdf>
The reaction to the paper:
<http://www.crypto.com/papers/kiss.html>
News articles on the research:
<http://www.nytimes.com/2003/01/23/business/23LOCK.html>
<http://www.mail-archive.com/[email protected]/msg03415.html>
Previous web references to Blaze's technique:
<http://sethf.com/infothought/blog/archives/000164.html>
Jewel theft using the master key vulnerability:
<http://www.nbc4columbus.com/news/1921563/detail.html>
** *** ***** ******* *********** *************
Crypto-Gram Reprints
Crypto-Gram is currently in its sixth year of publication. Back issues=20
cover a variety of security-related topics, and can all be found on=20
<http://www.counterpane.com/crypto-gram.html>. These are a selection=20
of articles that appeared in this calendar month in other years.
Microsoft and "Trustworthy Computing":
<http://www.counterpane.com./crypto-gram-0202.html#1>
Judging Microsoft:
<http://www.counterpane.com./crypto-gram-0202.html#2>
Hard-drive-embedded copy protection:
<http://www.counterpane.com/crypto-gram-0102.html#1>
A semantic attack on URLs:
<http://www.counterpane.com/crypto-gram-0102.html#7>
E-mail filter idiocy:
<http://www.counterpane.com/crypto-gram-0102.html#8>
Air gaps:
<http://www.counterpane.com/crypto-gram-0102.html#9>
Internet voting vs. large-value e-commerce:
<http://www.counterpane.com/crypto-gram-0102.html#10>
Distributed denial-of-service attacks:
<http://www.counterpane.com/crypto-gram-0002.html#DistributedDenial-of-S=20
erviceAttacks>
Recognizing crypto snake-oil:
<http://www.counterpane.com/crypto-gram-9902.html#snakeoil>
** *** ***** ******* *********** *************
Random Notes on the SQL Slammer
The Internet had its first big worm epidemic since Nimda: the Sapphire=20
Worm, aka SQL Slammer. Normally, I wouldn't bother mentioning this=20
worm. It's news, but there are no real lessons to learn from the=20
event. But there's an interesting Microsoft twist. During the days of=20
the attack, Microsoft tried to deflect any blame by claiming that they=20
issued a patch for the vulnerability six months previously, and that=20
the only affected companies were the ones who didn't keep their patches=20
up to date. A couple of days later, news leaked that Microsoft's own=20
network was hit pretty badly by the worm because they didn't patch=20
their own network.
For a couple of years now I've been saying that the idea that we can=20
achieve network security by finding and patching vulnerabilities in the=20
field is fatally flawed. I don't blame Microsoft sysadmins for not=20
having their patches up to date -- no one does -- but I don't like the=20
hypocrisy out of the company.
The SQL Slammer worm also reopened the full disclosure=20
debate. Microsoft announced the vulnerability in July 2002, at the=20
same time they released the patch. A few days later, David Litchfield=20
published exploit code that demonstrated how the vulnerability could be=20
used to break into systems. January's SQL Slammer worm used that exact=20
code. Some point to that and say that Litchfield should not have=20
released the code, while others correctly say that the code wasn't hard=20
to write, and that the worm author could have easily written it himself.
An amusing, but irrelevent, incident: A week after the worm, I was=20
invited to speak about it live on CNN. The program was eventually=20
preempted by the Columbia tragedy, but not before the CNN producers=20
invited Microsoft to appear on the segment with me. Microsoft's=20
spokesman -- I don't know who -- said that the company was unwilling to=20
appear on CNN with me. They were willing to appear before me, they=20
were willing to appear after me, but they were not willing to appear=20
with me. Seems that it is official Microsoft corporate policy not to=20
be seen in public with Bruce Schneier.
The best technical write-up of the worm and how it propagated (very=20
interesting reading):
<http://www.silicondefense.com/research/sapphire/>
Microsoft's internal network problems from the worm:
<http://www.theregister.co.uk/content/56/29073.html>
<http://news.com.com/2100-1001-982305.html>
<http://www.cnn.com/2003/TECH/biztech/01/28/microsoft.worm.ap/>
<http://www.nytimes.com/2003/01/28/technology/28SOFT.html>
Here's my essay on the patch treadmill from two years ago:
<http://www.counterpane.com./crypto-gram-0103.html#1>
Microsoft's original security alert:
<http://www.microsoft.com/technet/treeview/default.asp?url=3D/technet/secu=
=20
rity/bulletin/ms02-039.asp> or <http://tinyurl.com/vel>
Litchfield's comments on the similarity between his code and the worm:
<http://groups.google.com/groups?selm=3Db19f28%2411oo%241%40FreeBSD.csie.N=
=20
CTU.edu.tw&oe=3Dutf-8&output=3Dgplain> or <http://tinyurl.com/5qo6>
Korean civic group considers suing Microsoft:
<http://times.hankooki.com/lpage/nation/200302/kt2003020318021611960.htm=20
> or <http://tinyurl.com/5qob>
** *** ***** ******* *********** *************
The Doghouse: Meganet
Back in 1999 I wrote an essay about cryptographic snake oil and the=20
common warning signs. Meganet's Virtual Matrix Encryption (VME) was a=20
shining example. It's four years later and they're still around,=20
peddling the same pseudo-mathematical nonsense, albeit with a more=20
professional-looking website. I get at least one query a month about=20
these guys, and recently they convinced a reporter to write an article=20
that echoes their nonsensical claims. It's time to doghouse these=20
bozos, once and for all.
First, an aside. If you're a new reader, or someone who doesn't know=20
about cryptography, this is going to seem harsh. You might think: "How=20
does he KNOW that this is nonsense? If it's so bad, why can't he break=20
it?" That's actually backwards. In the world of cryptography, we=20
assume something is broken until we have evidence to the=20
contrary. (And I mean evidence, not proof.) Everything Meganet writes=20
clearly indicates that they haven't the faintest idea about how modern=20
cryptography works. It's as if you went to a doctor who talked about=20
bloodletting and humors and magical healing properties of=20
pyramids. Sure, it's possible that he's right, but you're going to=20
switch doctors. Two essays of mine at the bottom of this section, one=20
on snake oil and the other on amateur cipher designers, will help put=20
this into context.
Back to Meganet. They build an alternate reality where every=20
cryptographic algorithm has been broken, and the only thing left is=20
their own system. "The weakening of public crypto systems commenced in=20
1997. First it was the 40-bit key, a few months later the 48-bit key,=20
followed by the 56-bit key, and later the 512 bit has been=20
broken..." What are they talking about? Would you trust a=20
cryptographer who didn't know the difference between symmetric and=20
public-key cryptography? "Our technology... is the only unbreakable=20
encryption commercially available." The company's founder quoted in a=20
news article: "All other encryption methods have been compromised in=20
the last five to six years." Maybe in their alternate reality, but not=20
in the one we live in.
Their solution is to not encrypt data at all. "We believe there is one=20
very simple rule in encryption =AD- if someone can encrypt data, someone=20
else will be able to decrypt it. The idea behind VME is that the data=20
is not being encrypted nor transferred. And if it's not encrypted and=20
not transferred =AD there is nothing to break. And if there's nothing to=20
break =AD- it's unbreakable." Ha ha; that's a joke. They really do=20
encrypt data, but they call it something else.
Reading their Web site is like reading a litany of snake-oil warning=20
signs and stupid cryptographic ideas. They've got "proprietary=20
technology." They've got one-million-bit keys. They've got appeals to=20
new concepts: "It's a completely new approach to data=20
encryption." They've got a "mathematical proof" that their VME is=20
equal to a one-time pad. A mathematical proof, by they way, with no=20
mathematics: they simply show that the encrypted data is statistically=20
random in both cases. (The "proof" is simply hysterical to read;=20
summarizing it here just won't do it justice.)
They've got pseudo-scientific gobbledygook galore, including paragraphs=20
like this: "Stated simply, the content of the message is not sent with=20
the encrypted data. Rather, the encrypted data consists of pointers to=20
locations within a virtual matrix, a large (infinitely large in=20
concept), continuously changing array of values." I just love stuff=20
like this. It almost just barely makes sense. It's as if someone took=20
a cryptography book, had it machine-translated from language to=20
language to language, and then tried to write similar-sounding=20
text. Some of the words and phrases are scientific, but the paragraph=20
makes no sense. (Although, sadly, their stuff looks very much like the=20
virtual one-time pad that TriStrata came up with some years ago.)
They have unfair cracking contests and challenges, unsubstantiated=20
claims, outright lies, and a weird "evaluation" from one professor and=20
even weirder "experimental results" from another. It's every snake-oil=20
warning sign in the book in one convenient-to-make-fun-of place.
Unfortunately, this stuff seems to have continued to hoodwink=20
buyers. According to a press release on their Web site, the U.S.=20
Department of Labor recently gave them $4M. Various smaller companies=20
are supposedly using this stuff. SC Magazine gave them a five-star=20
rating, for goodness' sake! I am amazed at the sheer stubbornness that=20
can be exhibited by a company that simply refuses to accept reality.
Another quote from the news article: "Most of the encryption community=20
called our product snake oil. Everyone competed to throw stones at us=20
and didn't bother trying to understand the product." What does Meganet=20
expect? Most snake oil is subtly bad; their marketing is so=20
over-the-top it's entertaining, their "science" is so eccentric it's=20
ridiculous, and their claims are so laughable it's dangerous.
Meganet's technology Web site:
<http://www.meganet.com/Technology/default.htm>
Funny news article on Meganet:
<http://www.israel21c.org/bin/en.jsp?enPage=3DBlankPage&enDisplay=3Dview&enD=
=20
ispWhat=3Dobject&enDispWho=3DArticles%5El306&enZone=3DTechnology&enVersion=
=3D0&>=20
or <http://tinyurl.com/5nny>
My original snake-oil essay:
<http://www.counterpane.com./crypto-gram-9902.html#snakeoil>
My "Memo to the Amateur Cipher Designer" essay:
<http://www.counterpane.com./crypto-gram-9810.html#cipherdesign>
** *** ***** ******* *********** *************
News
The U.S. shut down Somalia's Internet, but it was a low-tech attack:
<http://news.bbc.co.uk/1/hi/world/africa/1672220.stm>
People don't erase personal information from their hard drives before=20
selling them:
<http://rss.com.com/2100-1040-980824.html>
<http://sfgate.com/cgi-bin/article.cgi?f=3D/news/archive/2003/01/15/nation=
=20
al1617EST0765.DTL> or <http://tinyurl.com/4i4l>
Essay by Whitfield Diffie on the relationship between openness and=20
security:
<http://news.com.com/2010-1071-980462.html>
The ACLU has just published a new report, "Bigger Monster, Weaker=20
Chains: The Growth of an American Surveillance Society."
<http://www.aclu.org/Privacy/Privacylist.cfm?c=3D39>
Many Sprint DSL modems are configured with the password "1234":
<http://www.wired.com/news/infostructure/0,1377,57342,00.html>
Anyone can get their own .mil domain.
<http://212.100.234.54/content/55/29026.html>
A company that makes automatic garage-door openers is using the DMCA to=20
halt the distribution of a competing product:
<http://www.extremetech.com/article2/0,3973,842083,00.asp>
This Internet Security Threat Report is filled with interesting=20
statistics and information. I recommend reading it. (Symantec=20
requires you to give them some personal information before they'll let=20
you download the report, presumably so they can market to you, but you=20
can make up information on the form.)
<http://enterprisesecurity.symantec.com/Content.cfm?articleID=3D1964&EID=3D0=
=20
> or <http://tinyurl.com/5qoq>
Tips on implementing cryptography in systems:
<http://www.cs.auckland.ac.nz/~pgut001/pubs/crypto_guide.txt>
Richard Clarke is leaving the position of White House Security Czar,=20
and Howard Schmidt is replacing him. The following article repeats the=20
rumor that Clarke's stand on protecting personal privacy put him at=20
odds with the Bush administration.
<http://www.washingtonpost.com/wp-dyn/articles/A6320-2003Jan31.html>
Good essay on software liabilities:
<http://www.bos.frb.org/economic/nerr/rr2002/q3/perspective.pdf>
The Senate Committee on National Security and Defense in Canada
recently released a report on the new airport security measures. It's=20
well written and sensible, unlike a lot of security reports I read.
<http://www.parl.gc.ca/37/2/parlbus/commbus/senate/com-e/defe-e/rep-e/re=20
p05jan03-e.htm> or <http://tinyurl.com/5tzk>
Buyer doesn't trust seller, so he uses an escrow site to protect=20
himself from fraud. But what happens if the escrow site is untrustworthy?
<http://www.msnbc.com/news/854552.asp?0cl=3DcR>
Lawyers as a threat to computer security:
<http://www.osopinion.com/perl/story/20581.html>
Interesting interview with Kevin Mitnick:
<http://interviews.slashdot.org/article.pl?sid=3D03/02/04/2233250&mode=3Dthr=
=20
ead&tid=3D103&tid=3D123&tid=3D172> or <http://tinyurl.com/5fum>
The U.S. military is developing rules for cyber-warfare:
<http://www.vnunet.com/News/1138573>
<http://www.washingtonpost.com/wp-dyn/articles/A38110-2003Feb6.html>
<http://www.gcn.com/vol1_no1/daily-updates/21122-1.html>
Send your suggestions for the World's Most Stupid Security=20
Measure. Awards will be given.
<http://www.privacyinternational.org/activities/stupidsecurity>
<http://www.theregister.co.uk/content/55/29279.html>
Good essay on the dangers of identity theft, and ideas on how to fix=20
the problem:
<http://www.businessweek.com/technology/content/feb2003/tc20030211_7896_=20
tc047.htm> or <http://tinyurl.com/5u0a>
Forensics on Windows:
<http://online.securityfocus.com/infocus/1661>
<http://online.securityfocus.com/infocus/1665>
Interesting cyber-extortion scam. Innocent user visits Web site. Web=20
server downloads files into innocent's computer. Server owner then=20
sends innocent e-mail, telling him that he has child porn on his=20
computer and that he will inform various authorities if the innocent=20
doesn't pay.
<http://www.csoonline.com/read/020103/undercover.html>
** *** ***** ******* *********** *************
Counterpane News
Hot on the heels of our $20M funding, Counterpane has announced two=20
additions to our executive team: Paul Stich as President and COO, and=20
Rahoul Seth as CFO. Tom Rowley remains at the helm as CEO.
<http://www.counterpane.com/pr-stich.html>
<http://www.counterpane.com/pr-seth.html>
** *** ***** ******* *********** *************
Security Notes from All Over: Anti-Fraud Security at Banks
Banks generally don't verify signatures on checks and credit card=20
charges. Instead, they rely on the customer to notify them about=20
fraudulent transactions and to then investigate. The bank assumes=20
debits are correct unless the customer complains. The costs may be=20
higher, in the aggregate, for all the customers to do the checking than=20
for the bank to, but the bank reduces its costs by relying on the=20
customer to do its work. Even though the bank is supposed to be acting=20
in the interests of the customer, the bank has chosen a security=20
solution that is more expensive in time and inconvenience for the customer.
** *** ***** ******* *********** *************
The Importance of Authentication
Authentication is more important than encryption. Most people's=20
security intuition says exactly the opposite, but it's true. Imagine a=20
situation where Alice and Bob are using a secure communications channel=20
to exchange data. Consider how much damage an eavesdropper could do if=20
she could read all the traffic. Then think about how much damage Eve=20
could do if she could modify the data being exchanged. In most=20
situations, modifying data is a devastating attack, and does far more=20
damage than merely reading it.
Here's another example: a Storage Area Network over IP within a=20
corporate LAN. Eavesdropping on traffic is passive, and doesn't=20
necessarily expose private data (particularly on a switched=20
network). But a lack of authentication allows sector-level data=20
tampering that was never possible with direct-attached storage. Adding=20
authentication avoids that problem entirely.
Or consider your own personal computer. Because data isn't=20
authenticated, you are much more likely to be the victim of viruses,=20
Trojans, and malware. Encryption is important; authentication is more=20
important. If your computer is controlled by someone on the other end=20
of a Trojan, it doesn't really matter what kind of encryption you've=20
implemented.
Of course any secure system should have both encryption and=20
authentication, but to the novice, per-packet authentication seems like=20
a painful and superfluous overhead. Again and again I see protocols=20
designed by otherwise-intelligent committees that mandate encryption=20
but not authentication: WEP, Bluetooth, etc. An early version of the=20
IPsec standard had a mode that encrypted but did not authenticate.
Last year I had a conversation with an engineer involved with security=20
for the Bluetooth wireless protocol. I told him that Bluetooth has=20
only privacy and not per-packet authentication. He responded with the=20
prototypical lame responses: 1) pseudorandom frequency hopping makes=20
it "nearly impossible" for an attacker to get in, and 2) the range is=20
only 8 feet, so the attacks are naturally limited.
I tried to argue the point, but eventually gave up. Then I said=20
something like: "I can hardly wait for Bluetooth to become universal,=20
because I really want a wireless keyboard and mouse with the "base=20
station" built into my computer." He said: "Yes, but you really=20
probably don't want to use Bluetooth for that, because then somebody=20
could stuff keystrokes or mouse clicks into your system." I didn't=20
know whether to laugh or cry. Talk about not getting it.
** *** ***** ******* *********** *************
Comments from Readers
From: Ira Winkler <[email protected]>
Subject: Counterattack
I am concerned with Jennifer Granick's comments in response to=20
Counterattack. First, Counterattack as a habit and policy are bad;=20
however, there should be some conditions where taken action is=20
permissible, such as the DoD handling of a planned protest and=20
bombardments arising from known attacks like Code Red.
However, she went on to comment about the legality of spam. Her=20
pro-spam analogies are a major concern and misrepresentation of the=20
issue. Specifically, she claims that spam should be treated like=20
noise. She claims that noise travels over air or "ether", and that=20
noise that travels over boundaries is best classified as a=20
nuisance. Let's assume that this is somehow correct. The spam analogy=20
to noise is not someone playing their stereo loud enough that a=20
neighbor can hear it on their own property. Spam is equivalent to a=20
neighbor blasting their stereo specifically so anyone, anywhere in the=20
world, can hear it. On top of that, the person blasting the stereo has=20
a personal interest to blast the stereo, usually money. That is not an=20
unintentional nuisance, but an intentional infliction of distress for=20
purely selfish reasons. Forgive me for not being a lawyer and knowing=20
the legal definitions of things. It is inconceivable that any court=20
would classify this behavior as a
"nuisance." On top of that, governments do have noise ordinances=20
that blanketly classify types of noise as unacceptable. Spam is much=20
more comparable to telemarketing calls, which are being regulated now=20
to the point of universal opt outs.
Spam, however, is not like noise. While overhearing a neighbor's music=20
does not cost people money, the proliferation of spam costs companies,=20
and inevitably the general public, billions of dollars. The latest=20
reliable studies indicate that spam is now 40% of e-mail. E-mail=20
storage costs money. E-mail transactions cost bandwidth, which has to=20
be upgraded for traffic, including spam traffic. E-mail transactions=20
cost processor utilization, which would have to be upgraded for=20
increased traffic volume. Spam filters, and the maintenance of those=20
filters, cost money. Sifting through spam costs lost productivity for=20
businesses and home users. Home users cancel Internet accounts because=20
spam takes up too much of their valuable time, despite the major=20
inconvenience of letting people know about the change of address.
Then there are the pornography issues. Well-supported studies indicate=20
that more than 25% of spam is for pornographic sites. Since spammers=20
don't keep track of who is an adult or child, children receive the=20
pornographic spams as well. Worse is that spammers go out of their way=20
to get around spam- and porn-blocking filters. Even using noise=20
analogies, public profanity and lewdness is illegal.
Then there is the business issue of pornographic spam. It is not=20
inconceivable that a disgruntled employee could sue their employer when=20
they receive pornographic spam, claiming that the employer created a=20
hostile work environment by poorly filtering that spam.
However the most troubling of Jennifer's comments involved her=20
contention that the Internet is a "Public Commons" and there should be=20
no implication of ownership of computers on the Internet, such as mail=20
servers. God help us if any court upholds that argument. That means=20
that if a computer is connected to the Internet in any way, anyone can=20
do with it what they want. In her argument, the computer becomes=20
public property. Anybody has a right to use the computer and its data=20
as they see fit. If you follow and extend her argument, if you have a=20
computer connected to the Internet in any way, it would be illegal to=20
limit access to that computer. She bemoans the argument that hooking=20
up to the Internet does not force someone to give up their ownership=20
rights to those computers in the same way that driving your car on a=20
public street does not mean that you give up ownership right to your car.
Jennifer claims that protecting ownership rights of computers connected=20
to the Internet is "detrimental to socially beneficial=20
uses." Extending that argument to the real world doesn't work, and it=20
doesn't make sense for the Internet either.
From: "Jennifer S. Granick" <[email protected]>
Subject: Counterattack
Ira and I agree that counterattack as habit and policy is=20
undesirable. We also agree that there should be some conditions under=20
which counterattack is legally permissible, just as we discourage=20
punching people, but sometimes allow it in self-defense. What's a=20
punch and what's self-defense is a more delicate question, which=20
lawyers have spent hundreds of years answering and refining. More to=20
the point, I disagree with Ira's implication that self-defense is a=20
privilege that only the government may exercise.
As for the Intel v. Hamidi discussion, calling messages spam obfuscates=20
the real issues. Ira is obviously very concerned about spam,=20
pornography, and lewd language, perhaps more concerned, even, than the=20
law, which says that all these are protected to varying degrees by the=20
First Amendment. Rather, the question is whether and when the owner of=20
an Internet-connected computer can control what messages I send, Web=20
pages I serve, files I transmit.
I believe Intel has the right to agree with its employees about how=20
they can use their workplace computers and to enforce that agreement,=20
against the employees. Intel should have no right to tell me, a member=20
of the public, what e-mail addresses I can type into my Eudora=20
program. Intel also has the right to protect its computer systems from=20
damage, to seek redress if I damage their systems intentionally or=20
through negligence. Intel can try to filter out messages, [a practice=20
I feel a lot better about if the users are notified, particularly when=20
we're talking about ISPs and not private companies]. I also believe=20
that I as an individual user should be able to opt out of receiving=20
unsolicited commercial messages that I don't want to receive.
However, the rule Intel seeks in the Hamidi case is that the server=20
owner can get injunctions stopping members of the public from sending=20
any packets through their servers at the owner's discretion, regardless=20
of what the end user might want. This rule would apply to more than=20
just private employers, and to more than just spam. And since we're=20
really talking about packets, this same rule could be used to force=20
Hamidi to put a filter on his Web page so that no Intel employees could=20
view it. I don't think that my ISP should be able to make that=20
decision on my behalf.
Ira assumes that a certain type of ownership right applies to computers=20
connected to the Internet, the absolute right to exclude. Why presume=20
that? That right applies in the real world only to real property=20
(land). Private property traditionally does not come with an absolute=20
right to exclude. (This is the debate over the definition of trespass=20
to chattels that occupies the main briefs in the case.) So long as the=20
user does not deprive the owner of use of the private property, as in=20
stealing his car, and does not harm the property, the owner's right to=20
the property is not sufficiently infringed for the law to get=20
involved. I can pet your dog, even if you don't want me to.
A nuisance rule allows the courts to balance the interests of the=20
server owner with the interests of the speaker and the interests of the=20
public in receiving information before issuing a ban. Commercial=20
speech may be less valuable than political speech. A flood of=20
irrelevant e-mails may be less protected than a bunch of e-mails=20
targeted to the relevant audience. The users' desire to read what the=20
sender has to say is a factor. Server owners are protected, but so are=20
speakers and users. The Intel rule, and the one advocated by Winkler,=20
certainly is better for companies. The public can send only approved=20
messages, and the users receive only approved messages, and the=20
companies, whether it's Intel or Earthlink, decide what's=20
approved. AOL refuses to carry MSN Messenger packets. Earthlink sues=20
to stop competitors from sending e-mails or Web pages advertising=20
cheaper service to its customers. Great for them, but that's not a=20
world I want to live in. Nor does the law require things to be this way.
For a law review article that does far more justice to this argument,=20
please see: Dan Burk, "The Trouble with Trespass" (2000) 4 J. Small &=20
Emerging Bus. L. 27, 49, available at the following link:
<http://www.law.umn.edu/FacultyProfiles/BurkD.htm>.
From: Ira Winkler <[email protected]>
Subject: Counterattack
I did not imply government can only perform self-defense. I used two=20
examples of acceptable self-defense, in my opinion, which were the most=20
publicly known. While the DoD example is government, the Code Red=20
self-defense was employed by commercial and government entities.
To first summarize the Intel vs. Hamidi case, Hamidi was an Intel=20
employee who was fired and sued Intel. The courts sided with Intel,=20
and instead of going on with his life, Hamidi basically decided to make=20
himself a thorn in Intel's side. For several years thereafter, Hamidi=20
did various things, including sending unsolicited e-mails to 29,000=20
Intel employees. As a result of this, Intel sought an injunction=20
against Hamidi sending unsolicited mass mailings to its employees again.
Hamidi's behavior appears obsessive. As I previously noted, spam costs=20
individuals and businesses billions of dollars. Intel is not an ISP=20
providing guaranteed delivery of e-mail to its employees. I do admit I=20
think it is too kind to call people who send unsolicited e-mail "the=20
scum of the Earth."
Concerning unsolicited e-mail as protected First Amendment speech,=20
Jennifer's position means that any party of the choosing of the sender=20
is required to utilize their resources at the discretion of anyone who=20
chooses to spam the accounts they maintain. I disagree. E-mail is not=20
just the forwarding of data packets as she states, but requires the=20
receiver to use their computer resources.
The issue that stopping people from spamming implies that they must=20
limit their own Web sites is not a valid argument and borders on=20
ridiculous. Intel may choose to block the Web site at their own=20
router, but cannot tell anyone else what they can do.
Jennifer's argument that there really are no rights of ownership in the=20
real and Internet worlds is also questionable. In her argument, to=20
convict someone of theft of anything, you have to prove that they did=20
not intend to return it and that you also intended to use it. Imagine=20
that if you notice your car missing. However even with this argument,=20
spam costs storage, processing, bandwidth, and electric utilization,=20
which costs money. As I said before, God help us if people no longer=20
have discretion over the use of computers they own and maintain because=20
they decide to attach it to the Internet.
There is nothing in Intel's case or their argument that says that they=20
want to limit e-mail or other Internet services to only preauthorized=20
people. They only want to stop someone who has previously sent their=20
employees unsolicited e-mails, and states they will again and again,=20
from doing so. Hamidi can use his own resources and take Opt-In=20
requests from Intel employees to their home accounts; however, he and=20
you know that they are probably tired of his rantings or they would=20
have done so already. Again, nothing is stopping him from using his=20
own resources for exercising his First Amendment rights, except of=20
course for the fact that few people seem to care about his personal=20
opinion.
From: "Jennifer S. Granick" <[email protected]>
Subject: Counterattack
>Jennifer's argument that there really are no rights of ownership
>in the real and Internet worlds is also questionable. In her
>argument, to convict someone of theft of anything you have to
>prove that they did not intend to return it and that you also
>intended to use it.
Actually, under the English common law, for hundreds of years, this was=20
exactly the case. Theft was the taking of property of another with=20
_the intent to deprive permanently_. If I intended to return it, it=20
wasn't theft. In many states, that has been changed by statute,=20
particularly for crimes like joyriding. What you're thinking of as=20
"ownership" isn't a single natural, logical and indivisible right, but=20
a set or subset of all possible rights that human beings have=20
intentionally decided over time to associate with different types of=20
property for the overall benefit of society.
From: Mike Robinson <[email protected]>
Subject: Re: Counterattack
Particularly with Internet issues, one must take a careful look at both=20
sides of the coin, and consider how (not whether) a well-intentioned=20
law or principle can be turned against its makers in cyberspace.
For example, if the principle of "counterattack" is permitted under=20
law, then "I in the black hat" can savage your system and claim, as my=20
defense, that you were attacking me and that I defended myself. To=20
support my claim I can fabricate whatever information-files I might=20
require. Since your machine has been destroyed in my attack, you have=20
nothing to refute me with, and "the law is on my side." And while all=20
of this legal gerrymandering is going on (perhaps I have persuaded the=20
authorities to seize your equipment), you are well on your way to going=20
out of business.
This is why laws are written the way they are, and why I think that at=20
least for the moment we can do no better. Well-intentioned laws that=20
"legalize lynching" will dress a lot of telephone-poles with the=20
remains of victims...killed, as it were, by the law itself.
From: Dorothy Denning <[email protected]>
Subject: Disabling the Internet
Another reason a government might not want to take out an adversary's=20
Internet connections is to launch a psyops campaign. Look at=20
<http://www.fcw.com/fcw/articles/2003/0113/web-iraq-01-16-03.asp>. The=20
U.S. Department of Defense sent e-mail messages to Iraqi officials.
From: [email protected] (Ketil Z. Malde)
Subject: Disabling the Internet
There's another reason why a country might want to disable the
Internet connections of an enemy. Wars are less and less about
weapons, and more and more about information, and you certainly want to=20
avoid the enemy freely distributing information (think vivid and=20
colourful images of killed and maimed children -- an inevitable result=20
of any war) to your public. Look how that worked in the Vietnam war!
This is particularly important for USA and its allies, who are much=20
better equipped and trained than the adversary, and can fight without=20
suffering severe losses. The people are kept far from the=20
battleground, which keeps them happy. But the Internet lets any geek=20
with a Web camera bring the battleground a lot closer, without any=20
military censorship (or regards to viewer ratings, which is probably=20
even more effective)
From: Arturo Bejar <[email protected]>
Subject: Yahoo in the Doghouse
Got doghoused! Alas, the information on that is inaccurate. If a user=20
needs to recover account access, their birthday is only one of several=20
pieces of information we request. First, we ask for the birthday, zip=20
code, and either user ID or alternate e-mail address. If that's=20
entered correctly, we then authenticate the account by asking a secret=20
question designated by the user when they registered.
If the user can't remember the answer to their secret question, we also=20
support recovery by use of a verified alternative e-mail address (you=20
can only verify by proving knowledge of the password), once the initial=20
identifying information (birthday, zip, user ID/alternate e-mail) has=20
been provided.
We only greet you with your birthday once you've logged in (assumes=20
ownership of the account), and on that day of the year (server side=20
controlled date).
If you ever hear anything about Yahoo! that raises a concern, you can=20
let me, or [email protected], know. We take user privacy and=20
security very seriously and try to be very responsive to any issues raised.
** *** ***** ******* *********** *************
CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on computer security and cryptography. Back=20
issues are available on <http://www.counterpane.com/crypto-gram.html>.
To subscribe, visit <http://www.counterpane.com/crypto-gram.html> or=20
send a blank message to [email protected]. To=20
unsubscribe, visit <http://www.counterpane.com/unsubform.html>.
Please feel free to forward CRYPTO-GRAM to colleagues and friends who=20
will find it valuable. Permission is granted to reprint CRYPTO-GRAM,=20
as long as it is reprinted in its entirety.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is founder and CTO=20
of Counterpane Internet Security Inc., the author of "Secrets and Lies"=20
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,=20
and Yarrow algorithms. He is a member of the Advisory Board of the=20
Electronic Privacy Information Center (EPIC). He is a frequent writer=20
and lecturer on computer security and cryptography.
Counterpane Internet Security, Inc. is the world leader in Managed=20
Security Monitoring. Counterpane's expert security analysts protect=20
networks for Fortune 1000 companies world-wide.
<http://www.counterpane.com/>
Copyright (c) 2003 by Counterpane Internet Security, Inc.