CRYPTO-GRAM, February 15, 2003

Bruce Schneier <[email protected]> Sat, 15 Feb 2003 22:17:46 -0600
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

               February 15, 2003

               by Bruce Schneier
                Founder and CTO
       Counterpane Internet Security, Inc.
            [email protected]
          <http://www.counterpane.com>


A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on computer security and cryptography.

Back issues are available at=20
<http://www.counterpane.com/crypto-gram.html>.  To subscribe, visit=20
<http://www.counterpane.com/crypto-gram.html> or send a blank message=20
to [email protected].

Copyright (c) 2003 by Counterpane Internet Security, Inc.


** *** ***** ******* *********** *************

In this issue:
      Locks and Full Disclosure
      Crypto-Gram Reprints
      Random Notes on the SQL Slammer
      The Doghouse: Meganet
      News
      Counterpane News
      Security Notes from All Over: Anti-Fraud Security at Banks
      The Importance of Authentication
      Comments from Readers


** *** ***** ******* *********** *************

           Locks and Full Disclosure



The full disclosure vs. bug secrecy debate is a lot larger than=20
computer security.  In January, security researcher Matt Blaze=20
published a paper describing a new attack against door locks.  The=20
specific locks are "master key systems," the sorts that allow each=20
person to have a key to his own office and the janitor to have a single=20
key that opens every office.  The specific attack is one where a person=20
with an individual office key can make himself a master key.  The=20
specifics are interesting, and I invite you to read the paper.  It=20
turns out that the ways we've learned to conceptualize security and=20
attacks in the computer world are directly applicable to other areas of=20
security -- like door locks.  But the most interesting part of this=20
entire story is that the locksmith community went ballistic after=20
learning about what Blaze did.

The technique was known in the locksmithing community and in the=20
criminal community for over a century, but was never discussed in=20
public and remained folklore.  Customers who bought these master key=20
systems for over a century were completely oblivious to the security=20
risks.  Locksmiths liked it that way, believing that the security of a=20
system was increased by keeping these sorts of vulnerabilities from the=20
general population.

The bug secrecy position is a lot easier to explain to a layman.  If=20
there's a vulnerability in a system, it's better not to make that=20
vulnerability public.  The bad guys will learn about it and use it, the=20
argument goes.  Last month's SQL Slammer is a case in point.  If the=20
hacker who wrote the worm hadn't had access to the public information=20
about the SQL vulnerability, maybe he wouldn't have written the=20
worm.  The problem, according to this position, is more the information=20
about the vulnerability and less the vulnerability itself.

This position ignores the fact that public scrutiny is the only=20
reliable way to improve security.  There are several master key designs=20
that are immune to the 100-year-old attack that Blaze=20
rediscovered.  They're not common in the marketplace primarily because=20
customers don't understand the risks, and because locksmiths continue=20
to knowingly sell a flawed security system rather than admit and then=20
fix the problem.  This is no different from the computer world.  Before=20
software vulnerabilities were routinely published, vendors would not=20
bother spending the time and money to fix vulnerabilities, believing in=20
the security of secrecy.  And since customers didn't know any better,=20
they bought these systems believing them to be secure.  If we return to=20
a world of bug secrecy in computers, we'll have the equivalent of=20
100-year-old vulnerabilities known by a few in the security community=20
and by the hacker underground.

That's the other fallacy with the locksmiths' argument.  Techniques=20
like this are passed down as folklore in the criminal community as well=20
as in the locksmithing community.  In 1994, a thief made his own master=20
key to a series of safe-deposit boxes and stole $1.5 million in=20
jewels.  The same thing happens in the computer world.  By the time a=20
software vulnerability is announced in the press and patched, it's=20
already folklore in the hacker underground.  Attackers don't abide by=20
secrecy agreements.

What we're seeing is a culture clash; it's happening in many areas of=20
security.  Attorney General Ashcroft is working to keep details of many=20
antiterrorism countermeasures secret so as not to educate the=20
terrorists.  But at the same time, the people -- to whom he is=20
ultimately accountable -- would not be allowed to evaluate the=20
countermeasures, or comment on their efficacy.  Security couldn't=20
improve because there'd be no public debate or public=20
education.  Whatever attacks and defenses people learn would become=20
folklore, never spoken about in the open but whispered from security=20
engineer to security engineer and from terrorist to terrorist.  And=20
maybe in 100 years someone will publish an attack that some security=20
engineers knew about, that terrorists and criminals had been exploiting=20
for much of that time, but that the general public had been blissfully=20
unaware of.

Secrecy prevents people from assessing their own risk.  For example, in=20
the master key case, even if there weren't more secure designs=20
available, many customers might have decided not to use master keying=20
if they knew how easy it was for an attacker to make his own master key.

I'd rather have as much information as I can to make an informed=20
decision about security.  I'd rather have the information I need to=20
pressure vendors to improve security.  I don't want to live in a world=20
where locksmiths can sell me a master key system that they know doesn't=20
work or where the government can implement security measures without=20
accountability.

Blaze's home page for his research:
<http://www.crypto.com/masterkey.html>

The paper itself:
<http://www.crypto.com/papers/mk.pdf>

The reaction to the paper:
<http://www.crypto.com/papers/kiss.html>

News articles on the research:
<http://www.nytimes.com/2003/01/23/business/23LOCK.html>
<http://www.mail-archive.com/[email protected]/msg03415.html>

Previous web references to Blaze's technique:
<http://sethf.com/infothought/blog/archives/000164.html>

Jewel theft using the master key vulnerability:
<http://www.nbc4columbus.com/news/1921563/detail.html>


** *** ***** ******* *********** *************

              Crypto-Gram Reprints



Crypto-Gram is currently in its sixth year of publication.  Back issues=20
cover a variety of security-related topics, and can all be found on=20
<http://www.counterpane.com/crypto-gram.html>.  These are a selection=20
of articles that appeared in this calendar month in other years.

Microsoft and "Trustworthy Computing":
<http://www.counterpane.com./crypto-gram-0202.html#1>

Judging Microsoft:
<http://www.counterpane.com./crypto-gram-0202.html#2>

Hard-drive-embedded copy protection:
<http://www.counterpane.com/crypto-gram-0102.html#1>

A semantic attack on URLs:
<http://www.counterpane.com/crypto-gram-0102.html#7>

E-mail filter idiocy:
<http://www.counterpane.com/crypto-gram-0102.html#8>

Air gaps:
<http://www.counterpane.com/crypto-gram-0102.html#9>

Internet voting vs. large-value e-commerce:
<http://www.counterpane.com/crypto-gram-0102.html#10>

Distributed denial-of-service attacks:
<http://www.counterpane.com/crypto-gram-0002.html#DistributedDenial-of-S=20
erviceAttacks>

Recognizing crypto snake-oil:
<http://www.counterpane.com/crypto-gram-9902.html#snakeoil>


** *** ***** ******* *********** *************

         Random Notes on the SQL Slammer



The Internet had its first big worm epidemic since Nimda: the Sapphire=20
Worm, aka SQL Slammer.  Normally, I wouldn't bother mentioning this=20
worm.  It's news, but there are no real lessons to learn from the=20
event.  But there's an interesting Microsoft twist.  During the days of=20
the attack, Microsoft tried to deflect any blame by claiming that they=20
issued a patch for the vulnerability six months previously, and that=20
the only affected companies were the ones who didn't keep their patches=20
up to date.  A couple of days later, news leaked that Microsoft's own=20
network was hit pretty badly by the worm because they didn't patch=20
their own network.

For a couple of years now I've been saying that the idea that we can=20
achieve network security by finding and patching vulnerabilities in the=20
field is fatally flawed.  I don't blame Microsoft sysadmins for not=20
having their patches up to date -- no one does -- but I don't like the=20
hypocrisy out of the company.

The SQL Slammer worm also reopened the full disclosure=20
debate.  Microsoft announced the vulnerability in July 2002, at the=20
same time they released the patch.  A few days later, David Litchfield=20
published exploit code that demonstrated how the vulnerability could be=20
used to break into systems.  January's SQL Slammer worm used that exact=20
code.  Some point to that and say that Litchfield should not have=20
released the code, while others correctly say that the code wasn't hard=20
to write, and that the worm author could have easily written it himself.

An amusing, but irrelevent, incident: A week after the worm, I was=20
invited to speak about it live on CNN.  The program was eventually=20
preempted by the Columbia tragedy, but not before the CNN producers=20
invited Microsoft to appear on the segment with me.  Microsoft's=20
spokesman -- I don't know who -- said that the company was unwilling to=20
appear on CNN with me.  They were willing to appear before me, they=20
were willing to appear after me, but they were not willing to appear=20
with me.  Seems that it is official Microsoft corporate policy not to=20
be seen in public with Bruce Schneier.

The best technical write-up of the worm and how it propagated (very=20
interesting reading):
<http://www.silicondefense.com/research/sapphire/>

Microsoft's internal network problems from the worm:
<http://www.theregister.co.uk/content/56/29073.html>
<http://news.com.com/2100-1001-982305.html>
<http://www.cnn.com/2003/TECH/biztech/01/28/microsoft.worm.ap/>
<http://www.nytimes.com/2003/01/28/technology/28SOFT.html>

Here's my essay on the patch treadmill from two years ago:
<http://www.counterpane.com./crypto-gram-0103.html#1>

Microsoft's original security alert:
<http://www.microsoft.com/technet/treeview/default.asp?url=3D/technet/secu=
=20
rity/bulletin/ms02-039.asp> or <http://tinyurl.com/vel>

Litchfield's comments on the similarity between his code and the worm:
<http://groups.google.com/groups?selm=3Db19f28%2411oo%241%40FreeBSD.csie.N=
=20
CTU.edu.tw&oe=3Dutf-8&output=3Dgplain> or <http://tinyurl.com/5qo6>

Korean civic group considers suing Microsoft:
<http://times.hankooki.com/lpage/nation/200302/kt2003020318021611960.htm=20
 > or <http://tinyurl.com/5qob>


** *** ***** ******* *********** *************

            The Doghouse: Meganet



Back in 1999 I wrote an essay about cryptographic snake oil and the=20
common warning signs.  Meganet's Virtual Matrix Encryption (VME) was a=20
shining example.  It's four years later and they're still around,=20
peddling the same pseudo-mathematical nonsense, albeit with a more=20
professional-looking website.  I get at least one query a month about=20
these guys, and recently they convinced a reporter to write an article=20
that echoes their nonsensical claims.  It's time to doghouse these=20
bozos, once and for all.

First, an aside.  If you're a new reader, or someone who doesn't know=20
about cryptography, this is going to seem harsh.  You might think: "How=20
does he KNOW that this is nonsense?  If it's so bad, why can't he break=20
it?"  That's actually backwards.  In the world of cryptography, we=20
assume something is broken until we have evidence to the=20
contrary.  (And I mean evidence, not proof.)  Everything Meganet writes=20
clearly indicates that they haven't the faintest idea about how modern=20
cryptography works.  It's as if you went to a doctor who talked about=20
bloodletting and humors and magical healing properties of=20
pyramids.  Sure, it's possible that he's right, but you're going to=20
switch doctors.  Two essays of mine at the bottom of this section, one=20
on snake oil and the other on amateur cipher designers, will help put=20
this into context.

Back to Meganet.  They build an alternate reality where every=20
cryptographic algorithm has been broken, and the only thing left is=20
their own system.  "The weakening of public crypto systems commenced in=20
1997.  First it was the 40-bit key, a few months later the 48-bit key,=20
followed by the 56-bit key, and later the 512 bit has been=20
broken..."  What are they talking about?  Would you trust a=20
cryptographer who didn't know the difference between symmetric and=20
public-key cryptography?  "Our technology... is the only unbreakable=20
encryption commercially available."  The company's founder quoted in a=20
news article: "All other encryption methods have been compromised in=20
the last five to six years."  Maybe in their alternate reality, but not=20
in the one we live in.

Their solution is to not encrypt data at all.  "We believe there is one=20
very simple rule in encryption =AD- if someone can encrypt data, someone=20
else will be able to decrypt it.  The idea behind VME is that the data=20
is not being encrypted nor transferred.  And if it's not encrypted and=20
not transferred =AD there is nothing to break.  And if there's nothing to=20
break =AD- it's unbreakable."  Ha ha; that's a joke.  They really do=20
encrypt data, but they call it something else.

Reading their Web site is like reading a litany of snake-oil warning=20
signs and stupid cryptographic ideas.  They've got "proprietary=20
technology."  They've got one-million-bit keys.  They've got appeals to=20
new concepts: "It's a completely new approach to data=20
encryption."  They've got a "mathematical proof" that their VME is=20
equal to a one-time pad.  A mathematical proof, by they way, with no=20
mathematics: they simply show that the encrypted data is statistically=20
random in both cases.  (The "proof" is simply hysterical to read;=20
summarizing it here just won't do it justice.)

They've got pseudo-scientific gobbledygook galore, including paragraphs=20
like this: "Stated simply, the content of the message is not sent with=20
the encrypted data.  Rather, the encrypted data consists of pointers to=20
locations within a virtual matrix, a large (infinitely large in=20
concept), continuously changing array of values."  I just love stuff=20
like this.  It almost just barely makes sense.  It's as if someone took=20
a cryptography book, had it machine-translated from language to=20
language to language, and then tried to write similar-sounding=20
text.  Some of the words and phrases are scientific, but the paragraph=20
makes no sense.  (Although, sadly, their stuff looks very much like the=20
virtual one-time pad that TriStrata came up with some years ago.)

They have unfair cracking contests and challenges, unsubstantiated=20
claims, outright lies, and a weird "evaluation" from one professor and=20
even weirder "experimental results" from another.  It's every snake-oil=20
warning sign in the book in one convenient-to-make-fun-of place.

Unfortunately, this stuff seems to have continued to hoodwink=20
buyers.  According to a press release on their Web site, the U.S.=20
Department of Labor recently gave them $4M.  Various smaller companies=20
are supposedly using this stuff.  SC Magazine gave them a five-star=20
rating, for goodness' sake!  I am amazed at the sheer stubbornness that=20
can be exhibited by a company that simply refuses to accept reality.

Another quote from the news article: "Most of the encryption community=20
called our product snake oil.  Everyone competed to throw stones at us=20
and didn't bother trying to understand the product."  What does Meganet=20
expect?   Most snake oil is subtly bad; their marketing is so=20
over-the-top it's entertaining, their "science" is so eccentric it's=20
ridiculous, and their claims are so laughable it's dangerous.

Meganet's technology Web site:
<http://www.meganet.com/Technology/default.htm>

Funny news article on Meganet:
<http://www.israel21c.org/bin/en.jsp?enPage=3DBlankPage&enDisplay=3Dview&enD=
=20
ispWhat=3Dobject&enDispWho=3DArticles%5El306&enZone=3DTechnology&enVersion=
=3D0&>=20
  or <http://tinyurl.com/5nny>

My original snake-oil essay:
<http://www.counterpane.com./crypto-gram-9902.html#snakeoil>

My "Memo to the Amateur Cipher Designer" essay:
<http://www.counterpane.com./crypto-gram-9810.html#cipherdesign>


** *** ***** ******* *********** *************

                      News



The U.S. shut down Somalia's Internet, but it was a low-tech attack:
<http://news.bbc.co.uk/1/hi/world/africa/1672220.stm>

People don't erase personal information from their hard drives before=20
selling them:
<http://rss.com.com/2100-1040-980824.html>
<http://sfgate.com/cgi-bin/article.cgi?f=3D/news/archive/2003/01/15/nation=
=20
al1617EST0765.DTL> or <http://tinyurl.com/4i4l>

Essay by Whitfield Diffie on the relationship between openness and=20
security:
<http://news.com.com/2010-1071-980462.html>

The ACLU has just published a new report, "Bigger Monster, Weaker=20
Chains: The Growth of an American Surveillance Society."
<http://www.aclu.org/Privacy/Privacylist.cfm?c=3D39>

Many Sprint DSL modems are configured with the password "1234":
<http://www.wired.com/news/infostructure/0,1377,57342,00.html>

Anyone can get their own .mil domain.
<http://212.100.234.54/content/55/29026.html>

A company that makes automatic garage-door openers is using the DMCA to=20
halt the distribution of a competing product:
<http://www.extremetech.com/article2/0,3973,842083,00.asp>

This Internet Security Threat Report is filled with interesting=20
statistics and information.  I recommend reading it.  (Symantec=20
requires you to give them some personal information before they'll let=20
you download the report, presumably so they can market to you, but you=20
can make up information on the form.)
<http://enterprisesecurity.symantec.com/Content.cfm?articleID=3D1964&EID=3D0=
=20
 > or <http://tinyurl.com/5qoq>

Tips on implementing cryptography in systems:
<http://www.cs.auckland.ac.nz/~pgut001/pubs/crypto_guide.txt>

Richard Clarke is leaving the position of White House Security Czar,=20
and Howard Schmidt is replacing him.  The following article repeats the=20
rumor that Clarke's stand on protecting personal privacy put him at=20
odds with the Bush administration.
<http://www.washingtonpost.com/wp-dyn/articles/A6320-2003Jan31.html>

Good essay on software liabilities:
<http://www.bos.frb.org/economic/nerr/rr2002/q3/perspective.pdf>

The Senate Committee on National Security and Defense in Canada
recently released a report on the new airport security measures.  It's=20
well written and sensible, unlike a lot of security reports I read.
<http://www.parl.gc.ca/37/2/parlbus/commbus/senate/com-e/defe-e/rep-e/re=20
p05jan03-e.htm> or <http://tinyurl.com/5tzk>

Buyer doesn't trust seller, so he uses an escrow site to protect=20
himself from fraud.  But what happens if the escrow site is untrustworthy?
<http://www.msnbc.com/news/854552.asp?0cl=3DcR>

Lawyers as a threat to computer security:
<http://www.osopinion.com/perl/story/20581.html>

Interesting interview with Kevin Mitnick:
<http://interviews.slashdot.org/article.pl?sid=3D03/02/04/2233250&mode=3Dthr=
=20
ead&tid=3D103&tid=3D123&tid=3D172> or <http://tinyurl.com/5fum>

The U.S. military is developing rules for cyber-warfare:
<http://www.vnunet.com/News/1138573>
<http://www.washingtonpost.com/wp-dyn/articles/A38110-2003Feb6.html>
<http://www.gcn.com/vol1_no1/daily-updates/21122-1.html>

Send your suggestions for the World's Most Stupid Security=20
Measure.  Awards will be given.
<http://www.privacyinternational.org/activities/stupidsecurity>
<http://www.theregister.co.uk/content/55/29279.html>

Good essay on the dangers of identity theft, and ideas on how to fix=20
the problem:
<http://www.businessweek.com/technology/content/feb2003/tc20030211_7896_=20
tc047.htm> or <http://tinyurl.com/5u0a>

Forensics on Windows:
<http://online.securityfocus.com/infocus/1661>
<http://online.securityfocus.com/infocus/1665>

Interesting cyber-extortion scam.  Innocent user visits Web site.  Web=20
server downloads files into innocent's computer.  Server owner then=20
sends innocent e-mail, telling him that he has child porn on his=20
computer and that he will inform various authorities if the innocent=20
doesn't pay.
<http://www.csoonline.com/read/020103/undercover.html>


** *** ***** ******* *********** *************

                Counterpane News



Hot on the heels of our $20M funding, Counterpane has announced two=20
additions to our executive team: Paul Stich as President and COO, and=20
Rahoul Seth as CFO.  Tom Rowley remains at the helm as CEO.

<http://www.counterpane.com/pr-stich.html>
<http://www.counterpane.com/pr-seth.html>


** *** ***** ******* *********** *************

  Security Notes from All Over: Anti-Fraud Security at Banks



Banks generally don't verify signatures on checks and credit card=20
charges.  Instead, they rely on the customer to notify them about=20
fraudulent transactions and to then investigate.  The bank assumes=20
debits are correct unless the customer complains.  The costs may be=20
higher, in the aggregate, for all the customers to do the checking than=20
for the bank to, but the bank reduces its costs by relying on the=20
customer to do its work.  Even though the bank is supposed to be acting=20
in the interests of the customer, the bank has chosen a security=20
solution that is more expensive in time and inconvenience for the customer.


** *** ***** ******* *********** *************

        The Importance of Authentication



Authentication is more important than encryption.  Most people's=20
security intuition says exactly the opposite, but it's true.  Imagine a=20
situation where Alice and Bob are using a secure communications channel=20
to exchange data.  Consider how much damage an eavesdropper could do if=20
she could read all the traffic.  Then think about how much damage Eve=20
could do if she could modify the data being exchanged.  In most=20
situations, modifying data is a devastating attack, and does far more=20
damage than merely reading it.

Here's another example: a Storage Area Network over IP within a=20
corporate LAN.  Eavesdropping on traffic is passive, and doesn't=20
necessarily expose private data (particularly on a switched=20
network).  But a lack of authentication allows sector-level data=20
tampering that was never possible with direct-attached storage.  Adding=20
authentication avoids that problem entirely.

Or consider your own personal computer.  Because data isn't=20
authenticated, you are much more likely to be the victim of viruses,=20
Trojans, and malware.  Encryption is important; authentication is more=20
important.  If your computer is controlled by someone on the other end=20
of a Trojan, it doesn't really matter what kind of encryption you've=20
implemented.

Of course any secure system should have both encryption and=20
authentication, but to the novice, per-packet authentication seems like=20
a painful and superfluous overhead.  Again and again I see protocols=20
designed by otherwise-intelligent committees that mandate encryption=20
but not authentication: WEP, Bluetooth, etc.  An early version of the=20
IPsec standard had a mode that encrypted but did not authenticate.

Last year I had a conversation with an engineer involved with security=20
for the Bluetooth wireless protocol.  I told him that Bluetooth has=20
only privacy and not per-packet authentication.  He responded with the=20
prototypical lame responses:  1) pseudorandom frequency hopping makes=20
it "nearly impossible" for an attacker to get in, and 2) the range is=20
only 8 feet, so the attacks are naturally limited.

I tried to argue the point, but eventually gave up.  Then I said=20
something like: "I can hardly wait for Bluetooth to become universal,=20
because I really want a wireless keyboard and mouse with the "base=20
station" built into my computer."  He said: "Yes, but you really=20
probably don't want to use Bluetooth for that, because then somebody=20
could stuff keystrokes or mouse clicks into your system."  I didn't=20
know whether to laugh or cry.  Talk about not getting it.


** *** ***** ******* *********** *************

              Comments from Readers



From: Ira Winkler <[email protected]>
Subject: Counterattack

I am concerned with Jennifer Granick's comments in response to=20
Counterattack.  First, Counterattack as a habit and policy are bad;=20
however, there should be some conditions where taken action is=20
permissible, such as the DoD handling of a planned protest and=20
bombardments arising from known attacks like Code Red.

However, she went on to comment about the legality of spam.  Her=20
pro-spam analogies are a major concern and misrepresentation of the=20
issue.  Specifically, she claims that spam should be treated like=20
noise.  She claims that noise travels over air or "ether", and that=20
noise that travels over boundaries is best classified as a=20
nuisance.  Let's assume that this is somehow correct.  The spam analogy=20
to noise is not someone playing their stereo loud enough that a=20
neighbor can hear it on their own property.  Spam is equivalent to a=20
neighbor blasting their stereo specifically so anyone, anywhere in the=20
world, can hear it.  On top of that, the person blasting the stereo has=20
a personal interest to blast the stereo, usually money.  That is not an=20
unintentional nuisance, but an intentional infliction of distress for=20
purely selfish reasons.  Forgive me for not being a lawyer and knowing=20
the legal definitions of things.  It is inconceivable that any court=20
would classify this behavior as a
  "nuisance."  On top of that, governments do have noise ordinances=20
that blanketly classify types of noise as unacceptable.  Spam is much=20
more comparable to telemarketing calls, which are being regulated now=20
to the point of universal opt outs.

Spam, however, is not like noise.  While overhearing a neighbor's music=20
does not cost people money, the proliferation of spam costs companies,=20
and inevitably the general public, billions of dollars.  The latest=20
reliable studies indicate that spam is now 40% of e-mail.  E-mail=20
storage costs money.  E-mail transactions cost bandwidth, which has to=20
be upgraded for traffic, including spam traffic.  E-mail transactions=20
cost processor utilization, which would have to be upgraded for=20
increased traffic volume.  Spam filters, and the maintenance of those=20
filters, cost money.  Sifting through spam costs lost productivity for=20
businesses and home users.  Home users cancel Internet accounts because=20
spam takes up too much of their valuable time, despite the major=20
inconvenience of letting people know about the change of address.

Then there are the pornography issues.  Well-supported studies indicate=20
that more than 25% of spam is for pornographic sites.  Since spammers=20
don't keep track of who is an adult or child, children receive the=20
pornographic spams as well.  Worse is that spammers go out of their way=20
to get around spam- and porn-blocking filters.  Even using noise=20
analogies, public profanity and lewdness is illegal.

Then there is the business issue of pornographic spam.  It is not=20
inconceivable that a disgruntled employee could sue their employer when=20
they receive pornographic spam, claiming that the employer created a=20
hostile work environment by poorly filtering that spam.

However the most troubling of Jennifer's comments involved her=20
contention that the Internet is a "Public Commons" and there should be=20
no implication of ownership of computers on the Internet, such as mail=20
servers.  God help us if any court upholds that argument.  That means=20
that if a computer is connected to the Internet in any way, anyone can=20
do with it what they want.  In her argument, the computer becomes=20
public property.  Anybody has a right to use the computer and its data=20
as they see fit.  If you follow and extend her argument, if you have a=20
computer connected to the Internet in any way, it would be illegal to=20
limit access to that computer.  She bemoans the argument that hooking=20
up to the Internet does not force someone to give up their ownership=20
rights to those computers in the same way that driving your car on a=20
public street does not mean that you give up ownership right to your car.

Jennifer claims that protecting ownership rights of computers connected=20
to the Internet is "detrimental to socially beneficial=20
uses."  Extending that argument to the real world doesn't work, and it=20
doesn't make sense for the Internet either.



From: "Jennifer S. Granick" <[email protected]>
Subject: Counterattack

Ira and I agree that counterattack as habit and policy is=20
undesirable.  We also agree that there should be some conditions under=20
which counterattack is legally permissible, just as we discourage=20
punching people, but sometimes allow it in self-defense.  What's a=20
punch and what's self-defense is a more delicate question, which=20
lawyers have spent hundreds of years answering and refining.  More to=20
the point, I disagree with Ira's implication that self-defense is a=20
privilege that only the government may exercise.

As for the Intel v. Hamidi discussion, calling messages spam obfuscates=20
the real issues.  Ira is obviously very concerned about spam,=20
pornography, and lewd language, perhaps more concerned, even, than the=20
law, which says that all these are protected to varying degrees by the=20
First Amendment.  Rather, the question is whether and when the owner of=20
an Internet-connected computer can control what messages I send, Web=20
pages I serve, files I transmit.

I believe Intel has the right to agree with its employees about how=20
they can use their workplace computers and to enforce that agreement,=20
against the employees.  Intel should have no right to tell me, a member=20
of the public, what e-mail addresses I can type into my Eudora=20
program.  Intel also has the right to protect its computer systems from=20
damage, to seek redress if I damage their systems intentionally or=20
through negligence.  Intel can try to filter out messages, [a practice=20
I feel a lot better about if the users are notified, particularly when=20
we're talking about ISPs and not private companies].  I also believe=20
that I as an individual user should be able to opt out of receiving=20
unsolicited commercial messages that I don't want to receive.

However, the rule Intel seeks in the Hamidi case is that the server=20
owner can get injunctions stopping members of the public from sending=20
any packets through their servers at the owner's discretion, regardless=20
of what the end user might want.  This rule would apply to more than=20
just private employers, and to more than just spam.  And since we're=20
really talking about packets, this same rule could be used to force=20
Hamidi to put a filter on his Web page so that no Intel employees could=20
view it.  I don't think that my ISP should be able to make that=20
decision on my behalf.

Ira assumes that a certain type of ownership right applies to computers=20
connected to the Internet, the absolute right to exclude.  Why presume=20
that?  That right applies in the real world only to real property=20
(land).  Private property traditionally does not come with an absolute=20
right to exclude.  (This is the debate over the definition of trespass=20
to chattels that occupies the main briefs in the case.)  So long as the=20
user does not deprive the owner of use of the private property, as in=20
stealing his car, and does not harm the property, the owner's right to=20
the property is not sufficiently infringed for the law to get=20
involved.  I can pet your dog, even if you don't want me to.

A nuisance rule allows the courts to balance the interests of the=20
server owner with the interests of the speaker and the interests of the=20
public in receiving information before issuing a ban.  Commercial=20
speech may be less valuable than political speech.  A flood of=20
irrelevant e-mails may be less protected than a bunch of e-mails=20
targeted to the relevant audience.  The users' desire to read what the=20
sender has to say is a factor.  Server owners are protected, but so are=20
speakers and users.  The Intel rule, and the one advocated by Winkler,=20
certainly is better for companies.  The public can send only approved=20
messages, and the users receive only approved messages, and the=20
companies, whether it's Intel or Earthlink, decide what's=20
approved.  AOL refuses to carry MSN Messenger packets.  Earthlink sues=20
to stop competitors from sending e-mails or Web pages advertising=20
cheaper service to its customers.  Great for them, but that's not a=20
world I want to live in.  Nor does the law require things to be this way.

For a law review article that does far more justice to this argument,=20
please see: Dan Burk, "The Trouble with Trespass" (2000) 4 J. Small &=20
Emerging Bus. L. 27, 49, available at the following link:
<http://www.law.umn.edu/FacultyProfiles/BurkD.htm>.



From: Ira Winkler <[email protected]>
Subject: Counterattack

I did not imply government can only perform self-defense.  I used two=20
examples of acceptable self-defense, in my opinion, which were the most=20
publicly known.  While the DoD example is government, the Code Red=20
self-defense was employed by commercial and government entities.

To first summarize the Intel vs. Hamidi case, Hamidi was an Intel=20
employee who was fired and sued Intel.  The courts sided with Intel,=20
and instead of going on with his life, Hamidi basically decided to make=20
himself a thorn in Intel's side.  For several years thereafter, Hamidi=20
did various things, including sending unsolicited e-mails to 29,000=20
Intel employees.  As a result of this, Intel sought an injunction=20
against Hamidi sending unsolicited mass mailings to its employees again.

Hamidi's behavior appears obsessive.  As I previously noted, spam costs=20
individuals and businesses billions of dollars.  Intel is not an ISP=20
providing guaranteed delivery of e-mail to its employees.  I do admit I=20
think it is too kind to call people who send unsolicited e-mail "the=20
scum of the Earth."

Concerning unsolicited e-mail as protected First Amendment speech,=20
Jennifer's position means that any party of the choosing of the sender=20
is required to utilize their resources at the discretion of anyone who=20
chooses to spam the accounts they maintain.  I disagree.  E-mail is not=20
just the forwarding of data packets as she states, but requires the=20
receiver to use their computer resources.

The issue that stopping people from spamming implies that they must=20
limit their own Web sites is not a valid argument and borders on=20
ridiculous.  Intel may choose to block the Web site at their own=20
router, but cannot tell anyone else what they can do.

Jennifer's argument that there really are no rights of ownership in the=20
real and Internet worlds is also questionable.  In her argument, to=20
convict someone of theft of anything, you have to prove that they did=20
not intend to return it and that you also intended to use it.  Imagine=20
that if you notice your car missing.  However even with this argument,=20
spam costs storage, processing, bandwidth, and electric utilization,=20
which costs money.  As I said before, God help us if people no longer=20
have discretion over the use of computers they own and maintain because=20
they decide to attach it to the Internet.

There is nothing in Intel's case or their argument that says that they=20
want to limit e-mail or other Internet services to only preauthorized=20
people.  They only want to stop someone who has previously sent their=20
employees unsolicited e-mails, and states they will again and again,=20
from doing so.  Hamidi can use his own resources and take Opt-In=20
requests from Intel employees to their home accounts; however, he and=20
you know that they are probably tired of his rantings or they would=20
have done so already.  Again, nothing is stopping him from using his=20
own resources for exercising his First Amendment rights, except of=20
course for the fact that few people seem to care about his personal=20
opinion.



From: "Jennifer S. Granick" <[email protected]>
Subject: Counterattack

 >Jennifer's argument that there really are no rights of ownership
 >in the real and Internet worlds is also questionable.  In her
 >argument, to convict someone of theft of anything you have to
 >prove that they did not intend to return it and that you also
 >intended to use it.

Actually, under the English common law, for hundreds of years, this was=20
exactly the case.  Theft was the taking of property of another with=20
_the intent to deprive permanently_.  If I intended to return it, it=20
wasn't theft.  In many states, that has been changed by statute,=20
particularly for crimes like joyriding.  What you're thinking of as=20
"ownership" isn't a single natural, logical and indivisible right, but=20
a set or subset of all possible rights that human beings have=20
intentionally decided over time to associate with different types of=20
property for the overall benefit of society.



From: Mike Robinson <[email protected]>
Subject: Re:  Counterattack

Particularly with Internet issues, one must take a careful look at both=20
sides of the coin, and consider how (not whether) a well-intentioned=20
law or principle can be turned against its makers in cyberspace.

For example, if the principle of "counterattack" is permitted under=20
law, then "I in the black hat" can savage your system and claim, as my=20
defense, that you were attacking me and that I defended myself.  To=20
support my claim I can fabricate whatever information-files I might=20
require.  Since your machine has been destroyed in my attack, you have=20
nothing to refute me with, and "the law is on my side."  And while all=20
of this legal gerrymandering is going on (perhaps I have persuaded the=20
authorities to seize your equipment), you are well on your way to going=20
out of business.

This is why laws are written the way they are, and why I think that at=20
least for the moment we can do no better.  Well-intentioned laws that=20
"legalize lynching" will dress a lot of telephone-poles with the=20
remains of victims...killed, as it were, by the law itself.



From: Dorothy Denning <[email protected]>
Subject:  Disabling the Internet

Another reason a government might not want to take out an adversary's=20
Internet connections is to launch a psyops campaign.  Look at=20
<http://www.fcw.com/fcw/articles/2003/0113/web-iraq-01-16-03.asp>.  The=20
U.S. Department of Defense sent e-mail messages to Iraqi officials.



From: [email protected] (Ketil Z. Malde)
Subject:  Disabling the Internet

There's another reason why a country might want to disable the
Internet connections of an enemy.  Wars are less and less about
weapons, and more and more about information, and you certainly want to=20
avoid the enemy freely distributing information (think vivid and=20
colourful images of killed and maimed children -- an inevitable result=20
of any war) to your public.  Look how that worked in the Vietnam war!

This is particularly important for USA and its allies, who are much=20
better equipped and trained than the adversary, and can fight without=20
suffering severe losses.  The people are kept far from the=20
battleground, which keeps them happy.  But the Internet lets any geek=20
with a Web camera bring the battleground a lot closer, without any=20
military censorship (or regards to viewer ratings, which is probably=20
even more effective)



From: Arturo Bejar <[email protected]>
Subject: Yahoo in the Doghouse

Got doghoused!  Alas, the information on that is inaccurate.  If a user=20
needs to recover account access, their birthday is only one of several=20
pieces of information we request.  First, we ask for the birthday, zip=20
code, and either user ID or alternate e-mail address.  If that's=20
entered correctly, we then authenticate the account by asking a secret=20
question designated by the user when they registered.

If the user can't remember the answer to their secret question, we also=20
support recovery by use of a verified alternative e-mail address (you=20
can only verify by proving knowledge of the password), once the initial=20
identifying information (birthday, zip, user ID/alternate e-mail) has=20
been provided.

We only greet you with your birthday once you've logged in (assumes=20
ownership of the account), and on that day of the year (server side=20
controlled date).

If you ever hear anything about Yahoo! that raises a concern, you can=20
let me, or [email protected], know.  We take user privacy and=20
security very seriously and try to be very responsive to any issues raised.


** *** ***** ******* *********** *************


CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on computer security and cryptography.  Back=20
issues are available on <http://www.counterpane.com/crypto-gram.html>.

To subscribe, visit <http://www.counterpane.com/crypto-gram.html> or=20
send a blank message to [email protected].  To=20
unsubscribe, visit <http://www.counterpane.com/unsubform.html>.

Please feel free to forward CRYPTO-GRAM to colleagues and friends who=20
will find it valuable.  Permission is granted to reprint CRYPTO-GRAM,=20
as long as it is reprinted in its entirety.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is founder and CTO=20
of Counterpane Internet Security Inc., the author of "Secrets and Lies"=20
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,=20
and Yarrow algorithms.  He is a member of the Advisory Board of the=20
Electronic Privacy Information Center (EPIC).  He is a frequent writer=20
and lecturer on computer security and cryptography.

Counterpane Internet Security, Inc. is the world leader in Managed=20
Security Monitoring.  Counterpane's expert security analysts protect=20
networks for Fortune 1000 companies world-wide.

<http://www.counterpane.com/>

Copyright (c) 2003 by Counterpane Internet Security, Inc.