CRYPTO-GRAM, December 15, 2010

Bruce Schneier <[email protected]> Wed, 15 Dec 2010 01:43:14 -0600
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

               December 15, 2010

               by Bruce Schneier
       Chief Security Technology Officer, BT
              [email protected]
             http://www.schneier.com


A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-1012.html>.  These same essays and=20
news items appear in the "Schneier on Security" blog at=20
<http://www.schneier.com/blog>, along with a lively comment section.  An=20
RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
      Airline Security: A Waste of Money and Time
      Full Body Scanners: What's Next?
      News
      Close the Washington Monument
      WikiLeaks
      Cyberwar and the Future of Cyber Conflict
      Schneier News
      NIST Announces SHA-3 Finalists (Skein is One of Them)
      Software Monoculture
      Term Paper Writing for Hire


** *** ***** ******* *********** *************

      Airline Security: A Waste of Money and Time



A short history of airport security: We screen for guns and bombs, so=20
the terrorists use box cutters. We confiscate box cutters and=20
corkscrews, so they put explosives in their sneakers. We screen=20
footwear, so they try to use liquids. We confiscate liquids, so they put=20
PETN bombs in their underwear. We roll out full-body scanners, even=20
though they wouldn't  have caught the Underwear Bomber, so they put a=20
bomb in a printer cartridge. We ban printer cartridges over 16 ounces --=20
the level of magical thinking here is amazing -- and they're going to do=20
something else.

This is a stupid game, and we should stop playing it.

It's not even a fair game. It's not that the terrorist picks an attack=20
and we pick a defense, and we see who wins. It's that we pick a defense,=20
and then the terrorists look at our defense and pick an attack designed=20
to get around it. Our security measures only work if we happen to guess=20
the plot correctly. If we get it wrong, we've wasted our money. This=20
isn't security; it's security theater.

There are two basic kinds of terrorists. The are the sloppy planners,=20
like the guy who crashed his plane into the Internal Revenue Service=20
building in Austin. He's going to be sloppy and stupid, and even=20
pre-9/11 airplane security is going to catch him. The second is the=20
well-planned, well-financed, and much rarer sort of plot. Do you really=20
expect the T.S.A. screeners, who are busy confiscating water bottles and=20
making people take off their belts -- and now doing uncomfortable=20
pat-downs -- to stop them?

Of course not. Airport security is the last line of defense, and it's=20
not a very good one. What works is investigation and intelligence:=20
security that works regardless of the terrorist tactic or target. Yes,=20
the target matters too; all this airport security is only effective if=20
the terrorists target airports. If they decide to bomb crowded shopping=20
malls instead, we've wasted our money.

That being said, airplanes require a special level of security for=20
several reasons: they're a favored terrorist target; their failure=20
characteristics mean more deaths than a comparable bomb on a bus or=20
train; they tend to be national symbols; and they often fly to foreign=20
countries where terrorists can operate with more impunity.

But all that can be handled with pre-9/11 security. Exactly two things=20
have made airplane travel safer since 9/11: reinforcing the cockpit=20
door, and convincing passengers they need to fight back. Everything else=20
has been a waste of money. Add screening of checked bags and airport=20
workers and we're done. Take all the rest of the money and spend it on=20
investigation and intelligence.

Immediately after the Christmas Day Underwear Bomber's plot failed,=20
Homeland Security Secretary Janet Napolitano called airplane security a=20
success. She was pilloried in the press and quickly backpedaled, but I=20
think it was one of the most sensible things said on the subject. Plane=20
lands safely, terrorist in custody, nobody injured except the terrorist:=20
what more do people want out of a security success?

Look at what succeeded. Because even pre-9/11 security screened for=20
obvious bombs, Abdulmutallab had to construct a far less reliable bomb=20
than he would have otherwise. Instead of using a timer or a plunger or a=20
reliable detonation mechanism, as would any commercial user of PETN,=20
Abdulmutallab had to resort to an ad hoc and much more inefficient=20
detonation mechanism involving a syringe, 20 minutes in the lavatory,=20
and setting his pants on fire. As a result, his actions came to the=20
notice of the other passengers, who subdued him.

Neither the full-body scanners or the enhanced pat-downs are making=20
anyone safer. They're more a result of politicians and government=20
appointees capitulating to a public that demands that "something must be=20
done," even when nothing should be done; and a government bureaucracy=20
that is more concerned about the security of their careers if they fail=20
to secure against the last attack than what happens if they fail=20
anticipate the next one.

Security theater:
http://www.schneier.com/essay-299.html

Why terrorist attacks are so rare:
http://www.schneier.com/essay-314.html

"Stop the Panic on Air Security":
http://www.schneier.com/essay-304.html

This essay first appeared on the New York Times "Room for Debate" blog:
http://www.nytimes.com/roomfordebate/2010/11/22/do-body-scanners-make-us-=
safer/a-waste-of-money-and-time=20
or http://tinyurl.com/27zlnhb
The other essays are worth reading, too.


** *** ***** ******* *********** *************

      Full Body Scanners: What's Next?



Organizers of National Opt Out Day, the Wednesday before Thanksgiving=20
when air travelers were urged to opt out of the full-body scanners at=20
security checkpoints and instead submit to full-body patdowns -- were=20
outfoxed by the TSA. The government pre-empted the protest by turning=20
off the machines in most airports during the Thanksgiving weekend.=20
Everyone went through the metal detectors, just as before.

Now that Thanksgiving is over, the machines are back on and the=20
"enhanced" pat-downs have resumed. I suspect that more people would=20
prefer to have naked images of themselves seen by TSA agents in another=20
room, than have themselves intimately touched by a TSA agent right in=20
front of them.

But now, the TSA is in a bind. Regardless of whatever lobbying came=20
before, or whatever former DHS officials had a financial interest in=20
these scanners, the TSA has spent billions on those scanners, claiming=20
they're essential. But because people can opt out, the alternate manual=20
method must be equally effective; otherwise, the terrorists could just=20
opt out. If they make the pat-downs less invasive, it would be the same=20
as admitting the scanners aren't essential. Senior officials would get=20
fired over that.

So not counting inconsequential modifications to demonstrate they're=20
"listening," the pat-downs will continue. And they'll continue for=20
everyone: children, abuse survivors, rape survivors, urostomy bag=20
wearers, people in wheelchairs. It has to be that way; otherwise, the=20
terrorists could simply adapt. They'd hide their explosives on their=20
children or in their urostomy bags. They'd recruit rape survivors, abuse=20
survivors, or seniors. They'd dress as pilots. They'd sneak their PETN=20
through airport security using the very type of person who isn't being=20
screened.

And PETN is what the TSA is looking for these days. That's=20
pentaerythritol tetranitrate, the plastic explosive that both the Shoe=20
Bomber and the Underwear Bomber attempted but failed to detonate. It's=20
what was mailed from Yemen. It's in Iraq and Afghanistan. Guns and=20
traditional bombs are pass=E9; PETN is the terrorist tool of the future.

The problem is that no scanners or puffers can detect PETN; only swabs=20
and dogs work. What the TSA hopes is that they will detect the bulge if=20
someone is hiding a wad of it on their person. But they won't catch PETN=20
hidden in a body cavity. That doesn't have to be as gross as you're=20
imagining; you can hide PETN in your mouth. A terrorist can go through=20
the scanners a dozen times with bits in his mouth each time, and=20
assemble a bigger bomb on the other side. Or he can roll it thin enough=20
to be part of a garment, and sneak it through that way. These tricks=20
aren't new. In the days after the Underwear Bomber was stopped, a=20
scanner manufacturer admitted that the machines might not have caught him=
.

So what's next? Strip searches? Body cavity searches? TSA Administrator=20
John Pistole said there would be no body cavity searches for now, but=20
his reasons make no sense. He said that the case widely reported as=20
being a body cavity bomb might not actually have been. While that=20
appears to be true, what does that have to do with future bombs? He also=20
said that even body cavity bombs would need "external initiators" that=20
the TSA would be able to detect.

Do you think for a minute that the TSA can detect these external=20
initiators? Do you think that if a terrorist took a laptop -- or better=20
yet, a less-common piece of electronics gear -- and removed the insides=20
and replaced them with a timer, a pressure sensor, a simple contact=20
switch, or a radio frequency switch, the TSA guy behind the X-ray=20
machine monitor would detect it? How about if those components were=20
distributed over a few trips through airport security? On the other=20
hand, if we believe the TSA can magically detect these external=20
initiators so effectively that they make body-cavity searches=20
unnecessary, why do we need the full-body scanners?

Either PETN is a danger that must be searched for, or it isn't. Pistole=20
was being either ignorant or evasive.

Once again, the TSA is covering their own asses by implementing=20
security-theater measures to prevent the previous attack while ignoring=20
any threats of future attacks. It's the same thinking that caused them=20
to ban box cutters after 9/11, screen shoes after Richard Reid, limit=20
liquids after that London gang, and -- I kid you not -- ban printer=20
cartridges over 16 ounces after they were used to house package bombs=20
from Yemen. They act like the terrorists are incapable of thinking=20
creatively, while the terrorists repeatedly demonstrate that can always=20
come up with a new approach that circumvents the old measures.

On the plus side, PETN is very hard to get to explode. The pre-9/11=20
screening procedures, looking for obvious guns and bombs, forced the=20
terrorists to build inefficient fusing mechanisms. We saw this when=20
Abdulmutallab, the Underwear Bomber, used bottles of liquid and a=20
syringe and 20 minutes in the bathroom to assemble his device, then set=20
his pants on fire -- and still failed to ignite his PETN-filled=20
underwear. And when he failed, the passengers quickly subdued him.

The truth is that exactly two things have made air travel safer since=20
9/11: reinforcing cockpit doors and convincing passengers they need to=20
fight back. The TSA should continue to screen checked luggage. They=20
should start screening airport workers. And then they should return=20
airport security to pre-9/11 levels and let the rest of their budget be=20
used for better purposes. Investigation and intelligence is how we're=20
going to prevent terrorism, on airplanes and elsewhere. It's how we=20
caught the liquid bombers. It's how we found the Yemeni=20
printer-cartridge bombs. And it's our best chance at stopping the next=20
serious plot.

Because if a group of well-planned and well-funded terrorist plotters=20
makes it to the airport, the chance is pretty low that those=20
blue-shirted crotch-groping water-bottle-confiscating TSA agents are=20
going to catch them. The agents are trying to do a good job, but the=20
deck is so stacked against them that their job is impossible. Airport=20
security is the last line of defense, and it's not a very good one.

We have a job here, too, and it's to be indomitable in the face of=20
terrorism. The goal of terrorism is to terrorize us: to make us afraid,=20
and make our government do exactly what the TSA is doing. When we react=20
out of fear, the terrorists succeed even when their plots fail. But if=20
we carry on as before, the terrorists fail -- even when their plots succe=
ed.

National Opt Out Day:
http://wewontfly.com/opt-out-day/

TSA pre-empted National Opt Out Day:
http://wewontfly.com/wp-content/uploads/2010/11/tsa-blinked-public-didnt-=
fly.pdf=20
or http://tinyurl.com/25vcjrj

Scanner company conflicts of interest:
http://www.usatoday.com/news/washington/2010-11-22-scanner-lobby_N.htm
http://www.boston.com/news/nation/washington/articles/2010/01/02/group_sl=
ams_chertoff_on_scanner_promotion/=20
or http://tinyurl.com/y9qx3vk

Scanning of children, abuse survivors, etc.
http://www.sfgate.com/cgi-bin/blogs/sfmoms/detail?entry_id=3D77140
http://www.newsweek.com/2010/11/17/tsa-screenings-worry-sexual-assault-su=
rvivors.html=20
or http://tinyurl.com/273c6gf
http://pncminnesota.wordpress.com/2010/11/08/rape-survivor-devasted-by-ts=
a-enhanced-pat-down/=20
or http://tinyurl.com/2c5f8kn
http://www.wired.com/threatlevel/2010/11/sawyer/
http://www.bloomberg.com/news/2010-11-19/u-s-airline-pilots-will-be-exemp=
ted-from-physical-checks-tsa-chief-says.html=20
or http://tinyurl.com/368j68b

PETN as the terrorist tool of the future:
http://www.juancole.com/2010/11/looking-for-petn-scanning-grandma-at-the-=
airport-and-the-future-of-air-travel.html=20
or http://tinyurl.com/23v8gu9
http://www.vancouversun.com/travel/Full+body+scanners+waste+money+Israeli=
+expert+says/2941610/story.html=20
or http://tinyurl.com/384jrob

Scanners wouldn't have caught the Underwear Bomber:
http://news.bbc.co.uk/2/hi/uk_news/8439285.stm

John Pistole interview:
http://www.youtube.com/watch?v=3DpIHE0bS7KO8

Saudi butt bomb:
http://www.newsweek.com/blogs/declassified/2010/01/04/private-intel-servi=
ce-warned-of-catastrophic-airline-attack-deploying-same-bombing-method-us=
ed-against-saudi-official.html=20
or http://tinyurl.com/2fer8mr
http://www.tnr.com/article/politics/the-butt-bomb
http://www.cbsnews.com/stories/2009/09/28/eveningnews/main5347847.shtml=20
or http://tinyurl.com/ycp4ego

Security theater:
http://www.schneier.com/essay-299.html

The TSA banning printer cartridges over 16 ounces:
http://www.dhs.gov/ynews/releases/pr_1289237893803.shtm

Investigation and intelligence:
http://www.schneier.com/essay-292.html

"Our Reaction is the Real Security Failure":
http://www.schneier.com/essay-303.html

This essay originally appeared on The Atlantic website.
http://www.theatlantic.com/national/archive/2010/12/why-the-tsa-cant-back=
-down/67337/=20
or http://tinyurl.com/2a8zgja


** *** ***** ******* *********** *************

      News



Security haiku:
http://www.schneier.com/blog/archives/2010/11/security_haiku.html

New biometric: eye movements instead of eye structures.
http://www.technologyreview.com/computing/26700/

The U.S. government receives a lot of unsolicited terrorism tips.=20
Adding them all up, it "receives between 8,000 and 10,000 pieces of=20
information per day, fingering just as many different people as=20
potential threats. They also get information about 40 supposed plots=20
against the United States or its allies daily."
http://www.slate.com/id/2274049
As I wrote in 2007, in my essay: "The War on the Unexpected":  "If you=20
ask amateurs to act as front-line security personnel, you shouldn't be=20
surprised when you get amateur security."
http://www.schneier.com/blog/archives/2007/11/the_war_on_the.html

Excellent essay on airplane terrorism twenty years ago.
http://www.salon.com/technology/ask_the_pilot/2010/11/10/airport_security=
/index.html=20
or http://tinyurl.com/2ct8epj
Refuse to be terrorized, everyone.
http://www.schneier.com/essay-124.html

I collected lots and lots of links from the first few days of the TSA=20
backscatter X-ray backlash.
http://www.schneier.com/blog/archives/2010/11/tsa_backscatter.html

Another piece of the Stuxnet puzzle:
http://www.symantec.com/connect/blogs/stuxnet-breakthrough
http://www.wired.com/threatlevel/2010/11/stuxnet-clues/
http://www.theregister.co.uk/2010/11/15/stuxnet_jigsaw_completed/

Threats of Stuxnet variants are being used to scare senators:
http://www.csmonitor.com/USA/2010/1117/Son-of-Stuxnet-Variants-of-the-cyb=
erweapon-likely-senators-told=20
or http://tinyurl.com/37wr2g6

Rare common sense about defeating al-Qaeda.
http://www.schneier.com/blog/archives/2010/11/defeating_al_qa.html

How to spoof your location on Facebook with your BlackBerry.
http://www.zdnet.com/blog/igeneration/how-to-spoof-your-geolocation-on-fa=
cebook-places-or-twitter/6764?tag=3Dcontent;search-results-rivers=20
or http://tinyurl.com/2e72wtd

David Kahn donates his cryptography collection to the National=20
Cryptologic Museum.  I think that's where my collection will be going, to=
o.
http://www.baltimoresun.com/news/maryland/anne-arundel/bs-ar-cryptology-1=
114-20101114,0,6720171.story=20
or http://tinyurl.com/27vy8ws
http://news.slashdot.org/story/10/11/14/1558224/NSA-Adds-Kahn-Collection-=
To-Cryptologic-Museum=20
or http://tinyurl.com/2ampr85

New ATM skimming attack in Europe, although the article doesn't say where=
.
http://www.computerworld.com/s/article/9197138/European_banks_see_new_ATM=
_skimming_attacks=20
or http://tinyurl.com/2esasqn

The DHS is finally getting rid of the dumb color-coded terrorism alert=20
system.
http://www.schneier.com/blog/archives/2010/11/the_dhs_is_gett.html

Interesting story of the withdrawal of the A5/2 encryption algorithm=20
from GSM phones.
http://laforge.gnumonks.org/weblog/2010/11/12/#20101112-history_of_a52_wi=
thdrawal=20
or http://tinyurl.com/33298c8

I have been thinking a lot about security against psychopaths.  Or, at=20
least, how we have traditionally secured social systems against these=20
sorts of people, and how we can secure our socio-technical systems=20
against them.  I don't know if I have any conclusions yet, only a short=20
reading list.
http://www.economist.com/node/17460702
http://www.sciencedaily.com/releases/2010/03/100314150924.htm
http://www.lovefraud.com/blog/2007/05/20/optical-illusions-autostereogram=
s-and-sociopaths/=20
or http://tinyurl.com/2g6uufw
http://www.youroptimal.com/blog/2009/12/04/privacy-and-shelter-from-the-p=
sychopathic-storm/=20
or http://tinyurl.com/28xcd9n
http://www.hare.org/links/saturday.html
http://www.bibliotecapleyades.net/archivos_pdf/sociobiology%C2%AD_of_soci=
opathy.pdf=20
or http://tinyurl.com/26ba38h
http://www.fraud-magazine.com/article.aspx?id=3D404

Causing terror on the cheap: turns out this has been bin Ladin's plan=20
all along.
http://www.schneier.com/blog/archives/2010/11/causing_terror.html

 From a study on zoo security:  "Among other measures, the scientists=20
recommend not allowing animals to walk freely within the zoo grounds,=20
and ensuring there is a physical barrier marking the zoo boundaries, and=20
preventing individuals from escaping through drains, sewers or any other=20
channels."  Isn't all that sort of obvious?
http://www.sciencedaily.com/releases/2010/11/101123151727.htm

I agree with Glenn Greenwald.  I don't know if Mohamed Osman Mohamud is=20
an actual terrorist that the FBI arrested, or if it's another case of=20
entrapment.
http://www.salon.com/news/opinion/glenn_greenwald/2010/11/28/fbi/index.ht=
ml=20
or http://tinyurl.com/3agrg3o
http://agonist.org/mmeo/20101127/the_portland_bomber
These are older, but still relevant.
http://www.salon.com/news/opinion/feature/2010/07/06/fbi_foiled_terrorism=
_plots=20
or http://tinyurl.com/23nhkcy
http://www.schneier.com/essay-174.html
In any case, notice that it was old-fashioned police investigation that=20
caught this guy.

Jeffrey Rosen opines on the constitutionality of full-body scanners.
http://www.washingtonpost.com/wp-dyn/content/article/2010/11/26/AR2010112=
604290.html=20
or http://tinyurl.com/2wz6l8c

The New York Times wrote an editorial in favor of the scanners.  I was=20
surprised.
http://www.nytimes.com/2010/11/24/opinion/24wed2.html

Teen risk reduction strategies on social networking sites: super-logoff=20
and wall scrubbing.
http://www.zephoria.org/thoughts/archives/2010/11/08/risk-reduction-strat=
egies-on-facebook.html=20
or http://tinyurl.com/32p32ku

"Brian Snow Sows Cyber Fears."  That's no less sensational than the=20
Calgary Herald headline: "Total cyber-meltdown almost inevitable, expert=20
tells Calgary audience."  That's former NSA Technical Director Brian=20
Snow talking to a university audience.  I know Brian, and I have to=20
believe his definition of "security meltdown" is more limited than the=20
headline leads one to believe.
http://www.montrealgazette.com/technology/Total+cyber+meltdown+almost+ine=
vitable+expert+tells+Calgary+audience/3856344/story.html=20
or http://tinyurl.com/28mvnsy

Detecting fixed football (soccer) games.
http://www.bbc.co.uk/news/world-europe-11789671

The U.S. Federal Trade Commission released its privacy report:=20
"Protecting Consumer Privacy in an Era of Rapid Change."  Among other=20
things, they're recommending a "Do Not Track" mechanism to govern=20
consumer information collection.
http://ftc.gov/os/2010/12/101201privacyreport.pdf
http://ftc.gov/opa/2010/12/privacyreport.shtm
http://www.google.com/hostednews/ap/article/ALeqM5hKfiE8QUOJ7XUcb1vGlv4kL=
eAtpQ?docId=3D4d58d6cc02654362ae187f350be52778=20
or http://tinyurl.com/348ll9h

Masters thesis from the Naval Postgraduate School:  "Patterns of=20
Radicalization: Identifying the Markers and Warning Signs of Domestic=20
Lone Wolf Terrorists in Our Midst."
http://www.cgsc.edu/CARL/index.asp?article=3D16837
http://www.dtic.mil/cgi-bin/GetTRDoc?AD=3DADA514419&Location=3DU2&doc=3DG=
etTRDoc.p=20
or http://tinyurl.com/2b2j94s

Sane comments on terrorism:
http://www.schneier.com/blog/archives/2010/12/sane_comments_o.html

How the State of New Jersey is storing road salt needs to be kept secret=20
from the terrorists.  This seems not to be a joke.
http://www.nj.com/news/local/index.ssf/2010/12/aclu_sues_state_for_keepin=
g_hu.html=20
or http://tinyurl.com/2677op4

A DHS video message, reminding people to look out for and report=20
suspicious activity, will be displayed at WalMart stores around the=20
country.  Isn't this just a little too 1984-ish?
http://www.dhs.gov/ynews/releases/pr_1291648380371.shtm
http://www.rawstory.com/rs/2010/12/homeland-security-messages-coming-walm=
art-hotels-malls/=20
or http://tinyurl.com/2bq9pp9

I experienced a new TSA security check at Phoenix Airport last Thursday.=20
  The agent took my over-three-ounce bottle of saline, put a drop of it=20
on a white cardboard strip, and then put a drop of another liquid on top=20
of that.  Nothing changed color, and she let me go.  Commenters on my=20
blog identified this as a test for hydrogen peroxide.
http://www.schneier.com/blog/archives/2010/12/new_tsa_securit.html

There's a growing backlash in the UK against stupid CRB checks.
http://www.spectator.co.uk/essays/all/6488983/part_2/a-common-sense-revol=
ution.thtml=20
or http://tinyurl.com/252z4m6
I wrote about CRB checks in 2008.
http://www.schneier.com/essay-277.html

Sex attack caught on CCTV camera:
http://www.nzherald.co.nz/nz/news/article.cfm?c_id=3D1&objectid=3D1069180=
4
Remember, though, that the test for whether the surveillance cameras are=20
worth it is whether or not this crime would have been solved without=20
them.  That is, were the cameras necessary for arrest or conviction?
http://www.schneier.com/essay-309.html
http://www.schneier.com/essay-225.html

Interesting profile of Evan Kohlmann.
http://nymag.com/news/features/69920

Realistic facemasks are getting too realistic.
http://articles.latimes.com/2010/dec/08/business/la-fi-mask-20101209

Open-source digital forensics.
http://www2.opensourceforensics.org/home


** *** ***** ******* *********** *************

      Close the Washington Monument



Securing the Washington Monument from terrorism has turned out to be a=20
surprisingly difficult job.  The concrete fence around the building=20
protects it from attacking vehicles, but there's no visually appealing=20
way to house the airport-level security mechanisms the National Park=20
Service has decided are a must for visitors.  It is considering several=20
options, but I think we should close the monument entirely.  Let it=20
stand, empty and inaccessible, as a monument to our fears.

An empty Washington Monument would serve as a constant reminder to those=20
on Capitol Hill that they are afraid of the terrorists and what they=20
could do.  They're afraid that by speaking honestly about the=20
impossibility of attaining absolute security or the inevitability of=20
terrorism -- or that some American ideals are worth maintaining even in=20
the face of adversity -- they will be branded as "soft on terror."  And=20
they're afraid that Americans would vote them out of office if another=20
attack occurred.  Perhaps they're right, but what has happened to=20
leaders who aren't afraid?  What has happened to "the only thing we have=20
to fear is fear itself"?

An empty Washington Monument would symbolize our lawmakers' inability to=20
take that kind of stand -- and their inability to truly lead.

Some of them call terrorism an "existential threat" against our nation.=20
  It's not.  Even the events of 9/11, as horrific as they were, didn't=20
make an existential dent in our nation.  Automobile-related fatalities=20
-- at 42,000 per year, more deaths each month, on average, than 9/11 --=20
aren't, either.  It's our reaction to terrorism that threatens our=20
nation, not terrorism itself.  The empty monument would symbolize the=20
empty rhetoric of those leaders who preach fear and then use that fear=20
for their own political ends.

The day after Umar Farouk Abdulmutallab failed to blow up a Northwest=20
jet with a bomb hidden in his underwear, Homeland Security Secretary=20
Janet Napolitano said "The system worked."  I agreed.  Plane lands=20
safely, terrorist in custody, nobody injured except the terrorist. Seems=20
like a working system to me. The empty monument would represent the=20
politicians and press who pilloried her for her comment, and Napolitano=20
herself, for backing down.

The empty monument would symbolize our war on the unexpected, -- our=20
overreaction to anything different or unusual -- our harassment of=20
photographers, and our probing of airline passengers.  It would=20
symbolize our "show me your papers" society, rife with ID checks and=20
security cameras.  As long as we're willing to sacrifice essential=20
liberties for a little temporary safety, we should keep the Washington=20
Monument empty.

Terrorism isn't a crime against people or property.  It's a crime=20
against our minds, using the death of innocents and destruction of=20
property to make us fearful.  Terrorists use the media to magnify their=20
actions and further spread fear.  And when we react out of fear, when we=20
change our policy to make our country less open, the terrorists succeed=20
-- even if their attacks fail.  But when we refuse to be terrorized,=20
when we're indomitable in the face of terror, the terrorists fail --=20
even if their attacks succeed.

We can reopen the monument when every foiled or failed terrorist plot=20
causes us to praise our security, instead of redoubling it.  When the=20
occasional terrorist attack succeeds, as it inevitably will, we accept=20
it, as we accept the murder rate and automobile-related death rate; and=20
redouble our efforts to remain a free and open society.

The grand reopening of the Washington Monument will not occur when we've=20
won the war on terror, because that will never happen.  It won't even=20
occur when we've defeated al Qaeda. Militant Islamic terrorism has=20
fractured into small, elusive groups.  We can reopen the Washington=20
Monument when we've defeated our fears, when we've come to accept that=20
placing safety above all other virtues cedes too much power to=20
government and that liberty is worth the risks, and that the price of=20
freedom is accepting the possibility of crime.

I would proudly climb to the top of a monument to those ideals.

Washington Monument security options:
http://www.washingtonpost.com/wp-dyn/content/article/2010/11/09/AR2010110=
906739.html=20
or http://tinyurl.com/2v6u57s
http://www.upi.com/Top_News/US/2010/11/08/Washington-Monument-security-op=
tions-aired/UPI-28411289246622/=20
or http://tinyurl.com/22w7r67
http://washingtonexaminer.com/blogs/capital-land/2010/11/park-service-pre=
sents-options-washington-monument-security=20
or http://tinyurl.com/29dejag

I wish I'd come up with the idea of closing the Washington Monument, but=20
I didn't.  It was the Washington Post's Philip Kennicott's idea,=20
although he didn't say it with as much fervor.
http://www.washingtonpost.com/wp-dyn/content/article/2010/11/07/AR2010110=
704572.html=20
or http://tinyurl.com/2gxrjjw

A version of this essay -- there were a lot of changes and edits --=20
originally appeared in the New York Daily News.
http://www.nydailynews.com/opinions/2010/12/02/2010-12-02_washington_monu=
ment_security_debate_is_the_height_of_irrational_fearmongering.html=20
or http://tinyurl.com/2vtgw32


** *** ***** ******* *********** *************

      WikiLeaks



I don't have a lot to say about WikiLeaks, but I do want to make a few=20
points.

1. Encryption isn't the issue here. Of course the cables were encrypted,=20
for transmission. Then they were received and decrypted, and -- so it=20
seems -- put into an archive on SIPRNet, where lots of people had access=20
to them.

2. Secrets are only as secure as the least trusted person who knows=20
them. The more people who know a secret, the more likely it is to be=20
made public.

3. I'm not surprised that these cables were available to so many people.=20
We know that access control is hard, and that it's impossible to know=20
beforehand what information someone will need to do their job. What is=20
surprising is that there wasn't any audit logs kept about who accessed=20
all these cables. That seems like a no-brainer.

4. This has little to do with WikiLeaks. WikiLeaks is just a website.=20
The real story is that "least trusted person" who decided to violate his=20
security clearance and make these cables public. In the 1970s he would=20
have mailed them to a newspaper. Today he uses WikiLeaks. Tomorrow he=20
will have his choice of a dozen similar websites. If WikiLeaks didn't=20
exist, he could have put them up on BitTorrent.

5. I think the government is learning what the music and movie=20
industries were forced to learn years ago: it's easy to copy and=20
distribute digital files. That's what's different between the 1970s and=20
today. Amassing and releasing that many documents was hard in the paper=20
and photocopier era; it's trivial in the Internet era. And just as the=20
music and movie industries are going to have to change their business=20
models for the Internet era, governments are going to have to change=20
their secrecy models. I don't know what those new models will be, but=20
they will be different.

Role-based access control:
http://www.schneier.com/blog/archives/2009/09/real-world_acce.html


** *** ***** ******* *********** *************

      Cyberwar and the Future of Cyber Conflict



The world is gearing up for cyberwar. The U.S. Cyber Command became=20
operational in November. NATO has enshrined cyber security among its new=20
strategic priorities. The head of Britain's armed forces said recently=20
that boosting cyber capability is now a huge priority for the UK. And we=20
know China is already engaged in broad cyber espionage attacks against=20
the west. So how can we control a burgeoning cyber arms race?

We may already have seen early versions of cyberwars in Estonia and=20
Georgia, possibly perpetrated by Russia. It's hard to know for certain,=20
not only because such attacks are often impossible to trace, but because=20
we have no clear definitions of what a cyberwar actually is.

Do the 2007 attacks against Estonia, traced to a young Russian man=20
living in Tallinn and no one else, count? What about a virus from an=20
unknown origin, possibly targeted at an Iranian nuclear complex? Or=20
espionage from within China, but not specifically directed by its=20
government? To such questions one must add even more basic issues, like=20
when a cyberwar is understood to have begun, and how it ends. When even=20
cyber security experts can't answer these questions, it's hard to expect=20
much from policymakers.

We can set parameters. It is obviously not an act of war just to develop=20
digital weapons targeting another country. Using cyber attacks to spy on=20
another nation is a grey area, which gets greyer still when a country=20
penetrates information networks, just to see if it can do so.=20
Penetrating such networks and leaving a back door open, or even leaving=20
logic bombs behind to be used later, is a harder case -- yet the US and=20
China are doing this to each other right now.

And what about when one country deliberately damages the economy of=20
another, as one of the WikiLeaks cables shows that a member of China's=20
politburo did against Google in January 2010? Definitions and rules are=20
hard not just because the tools of war have changed, but because=20
cyberspace puts them into the hands of a broader group of people.=20
Previously only the military had weapons. Now anyone with sufficient=20
computer skills can take matters into their own hands.

There are more basic problems too. When a nation is attacked in a=20
regular conflict, a variety of military and civil institutions respond.=20
The legal framework for this depends on two things: the attacker and the=20
motive. But when you're attacked on the internet, those are precisely=20
the two things you don't know. We don't know if Georgia was attacked by=20
the Russian government, or just some hackers living in Russia. In spite=20
of much speculation, we don't know the origin, or target, of Stuxnet. We=20
don't even know if last July 4's attacks against US and South Korean=20
computers originated in North Korea, China, England, or Florida.

When you don't know, it's easy to get it wrong; and to retaliate against=20
the wrong target, or for the wrong reason. That means it is easy for=20
things to get out of hand. So while it is legitimate for nations to=20
build offensive and defensive cyberwar capabilities we also need to=20
think now about what can be done to limit the risk of cyberwar.

A first step would be a hotline between the world's cyber commands,=20
modeled after similar hotlines among nuclear commands. This would at=20
least allow governments to talk to each other, rather than guess where=20
an attack came from. More difficult, but more important, are new=20
cyberwar treaties. These could stipulate a no first use policy, outlaw=20
unaimed weapons, or mandate weapons that self-destruct at the end of=20
hostilities. The Geneva Conventions need to be updated too.

Cyber weapons beg to be used, so limits on stockpiles, and restrictions=20
on tactics, are a logical end point. International banking, for=20
instance, could be declared off-limits. Whatever the specifics, such=20
agreements are badly needed. Enforcement will be difficult, but that's=20
not a reason not to try. It's not too late to reverse the cyber arms=20
race currently under way. Otherwise, it is only a matter of time before=20
something big happens: perhaps by the rash actions of a low level=20
military officer, perhaps by a non-state actor, perhaps by accident. And=20
if the target nation retaliates, we could actually find ourselves in a=20
cyberwar.

My previous cyberwar essays:
http://www.schneier.com/essay-201.html
http://www.schneier.com/essay-320.html

This essay was originally published in the Financial Times (free=20
registration required for access, or search on Google News).
http://www.ft.com/cms/s/0/f863fb4c-fe53-11df-abac-00144feab49a.html


** *** ***** ******* *********** *************

      Schneier News



In November, I gave a talk on cyberwar and cyberconflict at the=20
Institute for International and European Affairs in Dublin.  Here's the=20
video.
http://www.iiea.com/events/bruce-schneier-chief-security-technology-offic=
er-bt-the-future-of-the-it-security-industry=20
or http://tinyurl.com/23fuulo
It was only the second time I've given the talk.  About three quarters=20
in, I noticed I didn't have my fourth and final page of notes.  So if=20
the ending feels a bit scattered, that's why.

I was interviewed about full body scanners in  -- of all places --=20
Popular Mechanics.
http://www.popularmechanics.com/technology/military/news/tsa-scans-securi=
ty-theater-interview=20
or http://tinyurl.com/2bvh5vs


** *** ***** ******* *********** *************

      NIST Announces SHA-3 Finalists (Skein is One of Them)



Yesterday, NIST announced the five hash functions to advance to the=20
third (and final) round in the SHA-3 selection process:  BLAKE, Grostl,=20
JH, Keccak, and Skein.  Not really a surprise; my predictions -- which I=20
did not publish -- listed ECHO instead of JH, but correctly identified=20
the other four.  (Most of the predictions I saw guessed BLAKE, Grostl,=20
Keccak, and Skein, but differed on the fifth.)

NIST will publish a report that explains its rationale for selecting the=20
five it did.

Next is the Third SHA-3 Candidate Conference, which will probably be=20
held in March 2012 in Washington, DC, in conjunction with FSE 2012.=20
NIST will then pick a single algorithm to become SHA-3.

http://crypto.junod.info/2010/12/10/sha-3-finalists-announced-by-nist/

More information about Skein and the SHA-3 selection process.
http://www.schneier.com/blog/archives/2010/09/more_skein_news.html

Version 1.3 of the Skein paper, which discusses the new constant to=20
defeat the Khovratovich-Nikolie-Rechberger attack.
http://www.schneier.com/skein.pdf
http://www.schneier.com/skein-1.3-modifications.pdf

A new analysis of Skein.
http://cr.yp.to/hash/skein-20101206.pdf

And if you ordered a Skein polo shirt in September, they've been shipped.


** *** ***** ******* *********** *************

      Software Monoculture



In 2003, a group of security experts -- myself included -- published a=20
paper saying that 1) software monocultures are dangerous and 2)=20
Microsoft, being the largest creator of monocultures out there, is the=20
most dangerous. Marcus Ranum responded with an essay that basically said=20
we were full of it. Now, eight years later, Marcus and I thought it=20
would be interesting to revisit the debate.

The basic problem with a monoculture is that it's all vulnerable to the=20
same attack. The Irish Potato Famine of 1845-9 is perhaps the most=20
famous monoculture-related disaster. The Irish planted only one variety=20
of potato, and the genetically identical potatoes succumbed to a rot=20
caused by Phytophthora infestans. Compare that with the diversity of=20
potatoes traditionally grown in South America, each one adapted to the=20
particular soil and climate of its home, and you can see the security=20
value in heterogeneity.

Similar risks exist in networked computer systems. If everyone is using=20
the same operating system or the same applications software or the same=20
networking protocol, and a security vulnerability is discovered in that=20
OS or software or protocol, a single exploit can affect everyone. This=20
is the problem of large-scale Internet worms: many have affected=20
millions of computers on the Internet.

If our networking environment weren't homogeneous, a single worm=20
couldn't do so much damage. We'd be more like South America's potato=20
crop than Ireland's. Conclusion: monoculture is bad; embrace diversity=20
or die along with everyone else.

This analysis makes sense as far as it goes, but suffers from three=20
basic flaws. The first is the assumption that our IT monoculture is as=20
simple as the potato's. When the particularly virulent Storm worm hit,=20
it only affected from 1-10 million of its billion-plus possible victims.=20
Why? Because some computers were running updated antivirus software, or=20
were within locked-down networks, or whatever. Two computers might be=20
running the same OS or applications software, but they'll be inside=20
different networks with different firewalls and IDSs and router=20
policies, they'll have different antivirus programs and different patch=20
levels and different configurations, and they'll be in different parts=20
of the Internet connected to different servers running different=20
services. As Marcus pointed out back in 2003, they'll be a little bit=20
different themselves. That's one of the reasons large-scale Internet=20
worms don't infect everyone -- as well as the network's ability to=20
quickly develop and deploy patches, new antivirus signatures, new IPS=20
signatures, and so on.

The second flaw in the monoculture analysis is that it downplays the=20
cost of diversity. Sure, it would be great if a corporate IT department=20
ran half Windows and half Linux, or half Apache and half Microsoft IIS,=20
but doing so would require more expertise and cost more money. It=20
wouldn't cost twice the expertise and money -- there is some overlap --=20
but there are significant economies of scale that result from everyone=20
using the same software and configuration. A single operating system=20
locked down by experts is far more secure than two operating systems=20
configured by sysadmins who aren't so expert. Sometimes, as Mark Twain=20
said: "Put all your eggs in one basket, and then guard that basket!"

The third flaw is that you can only get a limited amount of diversity by=20
using two operating systems, or routers from three vendors. South=20
American potato diversity comes from hundreds of different varieties.=20
Genetic diversity comes from millions of different genomes. In=20
monoculture terms, two is little better than one. Even worse, since a=20
network's security is primarily the minimum of the security of its=20
components, a diverse network is less secure because it is vulnerable to=20
attacks against any of its heterogeneous components.

Some monoculture is necessary in computer networks. As long as we have=20
to talk to each other, we're all going to have to use TCP/IP, HTML, PDF,=20
and all sorts of other standards and protocols that guarantee=20
interoperability. Yes, there will be different implementations of the=20
same protocol -- and this is a good thing -- but that won't protect you=20
completely. You can't be too different from everyone else on the=20
Internet, because if you were, you couldn't be on the Internet.

Species basically have two options for propagating their genes: the=20
lobster strategy and the avian strategy. Lobsters lay 5,000 to 40,000=20
eggs at a time, and essentially ignore them. Only a minuscule percentage=20
of the hatchlings live to be four weeks old, but that's sufficient to=20
ensure gene propagation; from every 50,000 eggs, an average of two=20
lobsters is expected to survive to legal size. Conversely, birds produce=20
only a few eggs at a time, then spend a lot of effort ensuring that most=20
of the hatchlings survive. In ecology, this is known as r/K selection=20
theory. In either case, each of those offspring varies slightly=20
genetically, so if a new threat arises, some of them will be more likely=20
to survive. But even so, extinctions happen regularly on our planet;=20
neither strategy is foolproof.

Our IT infrastructure is a lot more like a bird than a lobster. Yes,=20
monoculture is dangerous and diversity is important. But investing time=20
and effort in ensuring our current infrastructure's survival is even=20
more important.

Original paper:
http://www.schneier.com/essay-318.html

Ranum's original rebuttal:
http://www.ranum.com/security/computer_security/editorials/monoculture-hy=
pe/index.html=20
or http://tinyurl.com/34z62q

Commentary:
http://securosis.com/blog/ranums-right-for-the-wrong-reasons

This essay was originally published in Information Security, and is the=20
first half of a point/counterpoint with Marcus Ranum.  You can read his=20
response there as well.
http://searchsecurity.techtarget.com/magazineFeature/0,296894,sid14_gci15=
22895,00.html=20
or http://tinyurl.com/2azs2z5


** *** ***** ******* *********** *************

      Term Paper Writing for Hire



A recent essay reminded me of an older essay, both by people who write=20
student term papers for hire.

There are several services that do automatic plagiarism detection --=20
basically, comparing phrases from the paper with general writings on the=20
Internet and even caches of previously written papers -- but detecting=20
this kind of custom plagiarism work is much harder.

I can think of three ways to deal with this:

1. Require all writing to be done in person, and proctored.  Obviously=20
this won't work for larger pieces of writing like theses.

2. Semantic analysis in an attempt to fingerprint writing styles.  It's=20
by no means perfect, but it is possible to detect if a piece of writing=20
looks nothing like a student's normal writing style.

3. In-person quizzes on the writing.  If a professor sits down with the=20
student and asks detailed questions about the writing, he can pretty=20
quickly determine if the student understands what he claims to have writt=
en.

The real issue is proof.  Most colleges and universities are unwilling=20
to pursue this without solid proof -- the lawsuit risk is just too great=20
-- and in these cases the only real proof is self-incrimination.

Fundamentally, this is a problem of misplaced economic incentives.  As=20
long as the academic credential is worth more to a student than the=20
knowledge gained in getting that credential, there will be an incentive=20
to cheat.

Recent essay:
http://chronicle.com/article/article-content/125329/

Commentary:
http://nielsenhayden.com/makinglight/archives/012705.html

Older essay:
http://www.thesmartset.com/article/article10100801.aspx

Related note: anyone remember my personal experience with plagiarism=20
from 2005?
http://www.schneier.com/blog/archives/2005/08/plagiarism_and.html


** *** ***** ******* *********** *************

Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing=20
summaries, analyses, insights, and commentaries on security: computer=20
and otherwise.  You can subscribe, unsubscribe, or change your address=20
on the Web at <http://www.schneier.com/crypto-gram.html>.  Back issues=20
are also available at that URL.

Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable.  Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is the author of the=20
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"=20
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,=20
Threefish, Helix, Phelix, and Skein algorithms.  He is the Chief=20
Security Technology Officer of BT BCSG, and is on the Board of Directors=20
of the Electronic Privacy Information Center (EPIC).  He is a frequent=20
writer and lecturer on security topics.  See <http://www.schneier.com>.

Crypto-Gram is a personal newsletter.  Opinions expressed are not=20
necessarily those of BT.

Copyright (c) 2010 by Bruce Schneier.