CRYPTO-GRAM, January 15, 2011

Bruce Schneier <[email protected]> Fri, 14 Jan 2011 21:08:12 -0600
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

               January 15, 2011

               by Bruce Schneier
       Chief Security Technology Officer, BT
              [email protected]
             http://www.schneier.com


A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-1101.html>.  These same essays and=20
news items appear in the "Schneier on Security" blog at=20
<http://www.schneier.com/blog>, along with a lively comment section.  An=20
RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
      Security in 2020
      News
      Stealing SIM Cards from Traffic Lights
      Recording the Police
      Schneier News
      Book Review: Cyber War


** *** ***** ******* *********** *************

      Security in 2020



There's really no such thing as security in the abstract. Security can=20
only be defined in relation to something else. You're secure from=20
something or against something. In the next 10 years, the traditional=20
definition of IT security -- that it protects you from hackers,=20
criminals, and other bad guys -- will undergo a radical shift. Instead=20
of protecting you from the bad guys, it will increasingly protect=20
businesses and their business models from you.

Ten years ago, the big conceptual change in IT security was=20
*deperimeterization*. A wordlike grouping of 18 letters with both a=20
prefix and a suffix, it has to be the ugliest word our industry=20
invented. The concept, though -- the dissolution of the strict=20
boundaries between the internal and external network -- was both real=20
and important.

There's more deperimeterization today than there ever was. Customer and=20
partner access, guest access, outsourced e-mail, VPNs; to the extent=20
there is an organizational network boundary, it's so full of holes that=20
it's sometimes easier to pretend it isn't there. The most important=20
change, though, is conceptual. We used to think of a network as a=20
fortress, with the good guys on the inside and the bad guys on the=20
outside, and walls and gates and guards to ensure that only the good=20
guys got inside. Modern networks are more like cities, dynamic and=20
complex entities with many different boundaries within them. The access,=20
authorization, and trust relationships are even more complicated.

Today, two other conceptual changes matter. The first is=20
*consumerization*. Another ponderous invented word, it's the idea that=20
consumers get the cool new gadgets first, and demand to do their work on=20
them. Employees already have their laptops configured just the way they=20
like them, and they don't want another one just for getting through the=20
corporate VPN. They're already reading their mail on their BlackBerrys=20
or iPads. They already have a home computer, and it's cooler than the=20
standard issue IT department machine. Network administrators are=20
increasingly losing control over clients.

This trend will only increase. Consumer devices will become trendier,=20
cheaper, and more integrated; and younger people are already used to=20
using their own stuff on their school networks. It's a recapitulation of=20
the PC revolution. The centralized computer center concept was shaken by=20
people buying PCs to run VisiCalc; now it's iPads and Android smart phone=
s.

The second conceptual change comes from cloud computing: our increasing=20
tendency to store our data elsewhere. Call it *decentralization*: our=20
email, photos, books, music, and documents are stored somewhere, and=20
accessible to us through our consumer devices. The younger you are, the=20
more you expect to get your digital stuff on the closest screen=20
available. This is an important trend, because it signals the end of the=20
hardware and operating system battles we've all lived with. Windows vs.=20
Mac doesn't matter when all you need is a web browser. Computers become=20
temporary; user backup becomes irrelevant. It's all out there somewhere=20
-- and users are increasingly losing control over their data.

During the next 10 years, three new conceptual changes will emerge, two=20
of which we can already see the beginnings of. The first I'll call=20
*deconcentration*. The general-purpose computer is dying and being=20
replaced by special-purpose devices. Some of them, like the iPhone, seem=20
general purpose but are strictly controlled by their providers. Others,=20
like Internet-enabled game machines or digital cameras, are truly=20
special purpose. In 10 years, most computers will be small, specialized,=20
and ubiquitous.

Even on what are ostensibly general-purpose devices, we're seeing more=20
special-purpose applications. Sure, you could use the iPhone's web=20
browser to access the *New York Times* website, but it's much easier to=20
use the NYT's special iPhone app. As computers become smaller and=20
cheaper, this trend will only continue. It'll be easier to use=20
special-purpose hardware and software. And companies, wanting more=20
control over their users' experience, will push this trend.

The second is *decustomerization* -- now I get to invent the really ugly=20
words -- the idea that we get more of our IT functionality without any=20
business relationship. We're all part of this trend: every search engine=20
gives away its services in exchange for the ability to advertise. It's=20
not just Google and Bing; most webmail and social networking sites offer=20
free basic service in exchange for advertising, possibly with premium=20
services for money. Most websites, even useful ones that take the place=20
of client software, are free; they are either run altruistically or to=20
facilitate advertising.

Soon it will be hardware. In 1999, Internet startup FreePC tried to make=20
money by giving away computers in exchange for the ability to monitor=20
users' surfing and purchasing habits. The company failed, but computers=20
have only gotten cheaper since then. It won't be long before giving away=20
netbooks in exchange for advertising will be a viable business. Or=20
giving away digital cameras. Already there are companies that give away=20
long-distance minutes in exchange for advertising. Free cell phones=20
aren't far off. Of course, not all IT hardware will be free. Some of the=20
new cool hardware will cost too much to be free, and there will always=20
be a need for concentrated computing power close to the user -- game=20
systems are an obvious example -- but those will be the exception. Where=20
the hardware costs too much to just give away, however, we'll see free=20
or highly subsidized hardware in exchange for locked-in service; that's=20
already the way cell phones are sold.

This is important because it destroys what's left of the normal business=20
relationship between IT companies and their users. We're not Google's=20
customers; we're Google's product that they sell to their customers.=20
It's a three-way relationship: us, the IT service provider, and the=20
advertiser or data buyer.  And as these noncustomer IT relationships=20
proliferate, we'll see more IT companies treating us as products. If I=20
buy a Dell computer, then I'm obviously a Dell customer; but if I get a=20
Dell computer for free in exchange for access to my life, it's much less=20
obvious whom I'm entering a business relationship with. Facebook's=20
continual ratcheting down of user privacy in order to satisfy its actual=20
customers -- the advertisers -- and enhance its revenue is just a hint=20
of what's to come.

The third conceptual change I've termed *depersonization*: computing=20
that removes the user, either partially or entirely. Expect to see more=20
software agents: programs that do things on your behalf, such as=20
prioritize your email based on your observed preferences or send you=20
personalized sales announcements based on your past behavior. The=20
"people who liked this also liked" feature on many retail websites is=20
just the beginning. A website that alerts you if a plane ticket to your=20
favorite destination drops below a certain price is simplistic but=20
useful, and some sites already offer this functionality. Ten years won't=20
be enough time to solve the serious artificial intelligence problems=20
required to fully realize intelligent agents, but the agents of that=20
time will be both sophisticated and commonplace, and they'll need less=20
direct input from you.

Similarly, connecting objects to the Internet will soon be cheap enough=20
to be viable. There's already considerable research into=20
Internet-enabled medical devices, smart power grids that communicate=20
with smart phones, and networked automobiles. Nike sneakers can already=20
communicate with your iPhone. Your phone already tells the network where=20
you are. Internet-enabled appliances are already in limited use, but=20
soon they will be the norm. Businesses will acquire smart HVAC units,=20
smart elevators, and smart inventory systems. And, as short-range=20
communications -- like RFID and Bluetooth -- become cheaper, everything=20
becomes smart.

The "Internet of things" won't need you to communicate. The smart=20
appliances in your smart home will talk directly to the power company.=20
Your smart car will talk to road sensors and, eventually, other cars.=20
Your clothes will talk to your dry cleaner. Your phone will talk to=20
vending machines; they already do in some countries. The ramifications=20
of this are hard to imagine; it's likely to be weirder and less orderly=20
than the contemporary press describes it. But certainly smart objects=20
will be talking about you, and you probably won't have much control over=20
what they're saying.

One old trend: deperimeterization. Two current trends: consumerization=20
and decentralization. Three future trends: deconcentration,=20
decustomerization, and depersonization. That's IT in 2020 -- it's not=20
under your control, it's doing things without your knowledge and=20
consent, and it's not necessarily acting in your best interests. And=20
this is how things will be when they're working as they're intended to=20
work; I haven't even started talking about the bad guys yet.

That's because IT security in 2020 will be less about protecting you=20
from traditional bad guys, and more about protecting corporate business=20
models from you. Deperimeterization assumes everyone is untrusted until=20
proven otherwise. Consumerization requires networks to assume all user=20
devices are untrustworthy until proven otherwise. Decentralization and=20
deconcentration won't work if you're able to hack the devices to run=20
unauthorized software or access unauthorized data. Decustomerization=20
won't be viable unless you're unable to bypass the ads, or whatever the=20
vendor uses to monetize you. And depersonization requires the autonomous=20
devices to be, well, autonomous.

In 2020 -- 10 years from now -- Moore's Law predicts that computers will=20
be 100 times more powerful. That'll change things in ways we can't know,=20
but we do know that human nature never changes. Cory Doctorow rightly=20
pointed out that all complex ecosystems have parasites. Society's=20
traditional parasites are criminals, but a broader definition makes more=20
sense here. As we users lose control of those systems and IT providers=20
gain control for their own purposes, the definition of "parasite" will=20
shift. Whether they're criminals trying to drain your bank account,=20
movie watchers trying to bypass whatever copy protection studios are=20
using to protect their profits, or Facebook users trying to use the=20
service without giving up their privacy or being forced to watch ads,=20
parasites will continue to try to take advantage of IT systems. They'll=20
exist, just as they always have existed, and -- like today -- security=20
is going to have a hard time keeping up with them.

Welcome to the future. Companies will use technical security measures,=20
backed up by legal security measures, to protect their business models.=20
And unless you're a model user, the parasite will be you.

This essay was originally written as a foreword to "Security 2020," by=20
Doug Howard and Kevin Prince.
http://www.amazon.com/exec/obidos/ASIN/0470639555/counterpane/


** *** ***** ******* *********** *************

      News


Fake Amazon receipt generators can be used to scam Amazon Marketplace=20
merchants:
http://sunbeltblog.blogspot.com/2010/12/taking-look-at-fake-amazon-receip=
t.html=20
or http://tinyurl.com/2epfq8h
They're also useful if you want to defraud your employer on expense=20
reimbursement forms.

The FBI has been accused of planting backdoors in OpenBSD.
http://arstechnica.com/open-source/news/2010/12/fbi-accused-of-planting-b=
ackdoor-in-openbsd-ipsec-stack.ars=20
or http://tinyurl.com/32vrot7
http://marc.info/?l=3Dopenbsd-security-announce&m=3D129237531405260&w=3D2
http://www.theregister.co.uk/2010/12/15/openbsd_backdoor_claim/
http://blogs.forbes.com/taylorbuley/2010/12/14/fbi-accused-of-decade-old-=
cryptography-code-conspiracy/=20
or http://tinyurl.com/25ygxa5
http://www.networkworld.com/news/2010/121510-former-contractor-says-fbi-p=
ut.html=20
or http://tinyurl.com/35g58pt
http://www.technewsworld.com/story/71466.html?wlc=3D1292446729
http://blogs.csoonline.com/1296/an_fbi_backdoor_in_openbsd
https://twitter.com/ejhilbert/status/14891845825863680
I doubt this is true.  One, it's a very risky thing to do.  And two,=20
there are more than enough exploitable security vulnerabilities in a=20
piece of code that large.  Finding and exploiting them is a much better=20
strategy than planting them.  But maybe someone at the FBI *is* that dumb=
.

Hiding PETN from full-body scanners:
http://www.schneier.com/blog/archives/2010/12/hiding_petn_fro.html
Stephen Colbert on the issue:
http://www.colbertnation.com/the-colbert-report-videos/368729/december-15=
-2010/scanner-defying-pancakes=20
or http://tinyurl.com/2vkbhqg

I like the phrase "architecture of fear":
http://www.schneier.com/blog/archives/2010/12/architecture_of.html

Interesting article on computational forensics.
http://spectrum.ieee.org/computing/software/beyond-csi-the-rise-of-comput=
ational-forensics/0=20
or http://tinyurl.com/2cqdrob

Adam Shostack on TSA threat modeling:
http://emergentchaos.com/archives/2010/12/the-tsas-approach-to-threat-mod=
eling.html=20
or http://tinyurl.com/262bx7b

In this interview with TSA Administrator John Pistole, he's more=20
realistic than one normally hears.  He still ducks some of the hard=20
questions.
http://www.theatlantic.com/national/archive/2010/12/tsa-chief-well-never-=
eliminate-risk/67682/=20
or http://tinyurl.com/2d992v9
I am reminded my own interview from 2007 with then-TSA Administrator Kip=20
Hawley.
http://www.schneier.com/interview-hawley.html

Interesting interview with Viviane Reding, the vice president of the EU=20
Justice Commission and head of privacy regulation.
http://voices.washingtonpost.com/posttech/2010/12/eu_privacy_chief_to_mee=
t_with.html=20
or http://tinyurl.com/2at6ams

Proprietary encryption in car immobilizers cracked.
http://www.newscientist.com/article/mg20827894.500-criminals-find-the-key=
-to-car-immobilisers.html=20
or http://tinyurl.com/28jz72j

Cyberwar movie plot from an actual thriller writer.  It could make a=20
good movie.
http://www.dailymail.co.uk/news/article-1337334/WikiLeaks-As-hackers-laun=
ch-attacks-Tom-Cain-imagines-terrifying-scenario.html=20
or http://tinyurl.com/2bxy5r9

PlugBot:  "PlugBot is a hardware bot. It's a covert penetration testing=20
device designed for use during physical penetration tests. PlugBot is a=20
tiny computer that looks like a power adapter; this small size allows it=20
to go physically undetected all the while powerful enough to scan,=20
collect and deliver test results externally."
http://www.schneier.com/blog/archives/2010/12/plugbot.html

Garfield Christmas comic.
http://www.gocomics.com/features/72/feature_items/560781?msg_id=3D1068090=
,560781=20
or http://tinyurl.com/25za389

Is it suspicious to photograph someone who is suspiciously taking=20
photographs?
http://www.schneier.com/blog/archives/2010/12/this_suspicious.html

An honest privacy policy: funny.
http://www.itworld.com/print/129778

This interview discusses five books about terrorism (none of which I've=20
read, by the way).
http://thebrowser.com/interviews/mary-habeck-on-terrorism

The TSA is now inspecting thermoses.
http://www.nydailynews.com/news/national/2010/12/24/2010-12-24_tsa_issues=
_warning_on_insulated_drink_containers_like_thermoses_for_holiday_trav.ht=
ml=20
or http://tinyurl.com/24nto6v

Civil War message decoded.
http://www.aolnews.com/2010/12/25/civil-war-message-in-a-bottle-opened-de=
coded/=20
or http://tinyurl.com/284mjo8
http://www.alertboot.com/blog/blogs/endpoint_security/archive/2010/12/29/=
data-encryption-bottled-civil-war-message-used-vigenere-cipher.aspx=20
or http://tinyurl.com/49c4abe
http://www.leftcoastrebel.com/2010/12/pictures-civil-war-vignere-cipher-c=
ode.html=20
or http://tinyurl.com/4fbayh6
http://intrepidusgroup.com/insight/2010/12/civil-war-ciphers-fall/
The key was "Manchester Bluff".

Home routers that automatically run Tor.
http://www.technologyreview.com/web/26981/

Guard towers at Walmart.
http://www.schneier.com/blog/archives/2011/01/guard_towers_at.html

It's easy and cheap to eavesdrop on GSM calls.
http://www.schneier.com/blog/archives/2011/01/eavesdropping_o_5.html

Sony used an ECDSA signature scheme to protect the PS3.  Trouble is, it=20
didn't pay sufficient attention to its random number generator.
http://psgroove.com/content.php?581-Sony-s-PS3-Security-is-Epic-Fail-Vide=
os-Within=20
or http://tinyurl.com/2vex9l2
http://www.bbc.co.uk/news/technology-12116051

"SMS of death": messages you can send to crash other people's phones.
http://www.technologyreview.com/communications/27021/
Be sure to read the response from one of the researchers.
http://www.schneier.com/blog/archives/2011/01/sms_of_death.html#c498685=20
or http://tinyurl.com/2enhoc3
The talk is online:
http://www.youtube.com/watch?v=3D8bkg3AjY6fs
http://mirror.fem-net.de/CCC/27C3/mp4-h264-HQ/27c3-4060-en-attacking_mobi=
le_phones.mp4.torrent=20
or http://tinyurl.com/4zacwwk

Good essay on the social dynamics of terror, separating "terror" from=20
"terrorism."
http://www.stratfor.com/weekly/20101229-separating-terror-terrorism

James Fallows on political shootings.
http://www.theatlantic.com/politics/archive/2011/01/the-cloudy-logic-of-p=
olitical-shootings/69147/=20
or http://tinyurl.com/335ycsb

"Homeland Security Hasn't Made Us Safer":  This will be nothing new to=20
Crypto-Gram readers, but it's nice to read other people saying it too.
http://www.foreignpolicy.com/articles/2011/01/02/unconventional_wisdom?pa=
ge=3D0,2=20
or http://tinyurl.com/4f4ldpe

Attacking high-frequency trading networks.
http://www.schneier.com/blog/archives/2011/01/attacking_high-.html

The security threat of forged law-enforcement credentials.
http://www.schneier.com/blog/archives/2011/01/the_security_th.html

Stealing SIM cards from traffic lights.
http://www.schneier.com/blog/archives/2011/01/stealing_sim_ca.html

Interesting reading, mostly for the probable effects of a=20
terrorist-sized nuclear bomb.
http://www.theatlantic.com/national/archive/2011/01/the-unexpected-return=
-of-duck-and-cover/68776/

A loaded gun slips past the TSA.  I'm not really worried about mistakes=20
like this. Sure, a gun slips through occasionally, and a knife slips=20
through even more often.  (I'm sure the TSA doesn't catch 100% of all=20
bombs in tests, either.)  But these items are caught by the TSA often=20
enough, and when the TSA does catch someone, they're going to call the=20
police and totally ruin his day.  A terrorist can't build a plot around=20
succeeding.  It's things like liquids that are the real problem.=20
Because there are no consequences to trying -- the bottle of water just=20
gets thrown into the trash -- a terrorist can repeatedly try until he=20
succeeds in slipping it through.
http://abcnews.go.com/Blotter/loaded-gun-slips-past-tsa-screeners/story?i=
d=3D12412458
I asked then-TSA Administrator Kip Hawley about this in 2007.  He didn't=20
have a good answer.
http://www.schneier.com/interview-hawley.html


** *** ***** ******* *********** *************

      Recording the Police



I've written a lot on the "War on Photography," where normal people are=20
harassed as potential terrorists for taking pictures of things in=20
public.  The article below is different; it's about recording the=20
police, and how that often is illegal.

This is all important.  Being able to record the police is one of the=20
best ways to ensure that the police are held accountable for their=20
actions.  Privacy has to be viewed in the context of relative power.=20
For example, the government has a lot more power than the people.  So=20
privacy for the government increases their power and increases the power=20
imbalance between government and the people; it decreases liberty.=20
Forced openness in government -- open government laws, Freedom of=20
Information Act filings, the recording of police officers and other=20
government officials, WikiLeaks -- reduces the power imbalance between=20
government and the people, and increases liberty.

Privacy for the people increases their power.  It also increases=20
liberty, because it reduces the power imbalance between government and=20
the people.  Forced openness in the people -- NSA monitoring of=20
everyone's phone calls and e-mails, the DOJ monitoring everyone's credit=20
card transactions, surveillance cameras -- decreases liberty.

I think we need a law that explicitly makes it legal for people to=20
record government officials when they are interacting with them in their=20
official capacity.  And this is doubly true for police officers and=20
other law enforcement officials.

http://reason.com/archives/2010/12/07/the-war-on-cameras

Anthony Graber, the Maryland motorcyclist in the article, had all the=20
wiretapping charges cleared.
http://articles.baltimoresun.com/2010-09-27/news/bs-md-recorded-traffic-s=
top-20100927_1_police-officers-plitt-cell-phones=20
or http://tinyurl.com/33z4vw6

FBI monitoring credit card transactions:
http://www.wired.com/threatlevel/2010/12/realtime/

My "War on Photography" essay:
http://www.schneier.com/blog/archives/2008/06/the_war_on_phot.html


** *** ***** ******* *********** *************

      Stealing SIM Cards from Traffic Lights



Johannesburg installed hundreds of networked traffic lights on its=20
streets. The lights use a cellular modem and a SIM card to communicate.

Those lights introduced a security risk I'll bet no one gave a moment's=20
thought to: that criminals might steal the SIM cards from the traffic=20
lights and use them to make free phone calls. But that's exactly what=20
happened.

Aside from the theft of phone service, repairing those traffic lights is=20
far more expensive than those components are worth.

I wrote about this general issue before:

"These crimes are particularly expensive to society because the=20
replacement cost is much higher than the thief's profit. A manhole is=20
worth $5=96$10 as scrap, but it costs $500 to replace, including labor. A=
=20
thief may take $20 worth of copper from a construction site, but do=20
$10,000 in damage in the process. And the increased threat means more=20
money being spent on security to protect those commodities in the first=20
place.

"Security can be viewed as a tax on the honest, and these thefts=20
demonstrate that our taxes are going up. And unlike many taxes, we don't=20
benefit from their collection. The cost to society of retrofitting=20
manhole covers with locks, or replacing them with less re=ADsalable=20
alternatives, is high; but there is no benefit other than reducing theft.=
"

http://www.joburg.org.za/index.php?option=3Dcom_content&view=3Darticle&id=
=3D6068&catid=3D88&Itemid=3D266

My essay:
http://www.schneier.com/essay-266.html


** *** ***** ******* *********** *************

      Schneier News



Last week, I spoke at an airport security conference hosted by EPIC:=20
"The Stripping of Freedom: A Careful Scan of TSA Security Procedures."=20
Here's the video of my half-hour talk.
http://www.c-spanvideo.org/program/Schne
EPIC event:
http://epic.org/events/tsa/


** *** ***** ******* *********** *************

      Book Review: Cyber War



"Cyber War: The Next Threat to National Security and What to do About=20
It" by Richard Clarke and Robert Knake, HarperCollins, 2010.

"Cyber War" is a fast and enjoyable read.  This means you could give the=20
book to your non-techy friends, and they'd understand most of it, enjoy=20
all of it, and learn a lot from it.  Unfortunately, while there's a lot=20
of smart discussion and good information in the book, there's also a lot=20
of fear-mongering and hyperbole as well.  Since there's no easy way to=20
tell someone what parts of the book to pay attention to and what parts=20
to take with a grain of salt, I can't recommend it for that purpose.=20
This is a pity, because parts of the book really need to be widely read=20
and discussed.

The fear-mongering and hyperbole is mostly in the beginning.  There, the=20
authors describe the cyberwar of novels.  Hackers disable air traffic=20
control, delete money from bank accounts, cause widespread blackouts,=20
release chlorine gas from chemical plants, and -- this is my favorite --=20
remotely cause your printer to catch on fire.  It's exciting and scary=20
stuff, but not terribly realistic.  Even their discussions of previous=20
"cyber wars" -- Estonia, Georgia, attacks against U.S. and South Korea=20
on July 4, 2009 -- are full of hyperbole.  A lot of what they write is=20
unproven speculation, but they don't say that.

Better is the historical discussion of the formation of the U.S. Cyber=20
Command, but there are important omissions. There's nothing about the=20
cyberwar fear being stoked that accompanied this:  by the NSA's General=20
Keith Alexander -- who became the first head of the command -- or by the=20
NSA's former director, current military contractor, by Mike McConnell,=20
who's Senior Vice President at Booz Allen Hamilton, and by others.  By=20
hyping the threat, the former has amassed a lot of power, and the latter=20
a lot of money.  Cyberwar is the new cash cow of the military-industrial=20
complex, and any political discussion of cyberwar should include this as=20
well.

Also interesting is the discussion of the asymmetric nature of the=20
threat.  A country like the United States, which is heavily dependent on=20
the Internet and information technology, is much more vulnerable to=20
cyber-attacks than a less-developed country like North Korea.  This=20
means that a country like North Korea would benefit from a cyberwar=20
exchange: they'd inflict far more damage than they'd incur.  This also=20
means that, in this hypothetical cyberwar, there would be pressure on=20
the U.S. to move the war to another theater: air and ground, for=20
example.  Definitely worth thinking about.

Most important is the section on treaties.  Clarke and Knake have a lot=20
of experience with nuclear treaties, and have done considerable thinking=20
about how to apply that experience to cyberspace.  The parallel isn't=20
perfect, but there's a lot to learn about what worked and what didn't,=20
and -- more importantly -- *how* things worked and didn't.  The authors=20
discuss treaties banning cyberwar entirely (unlikely), banning attacks=20
against civilians, limiting what is allowed in peacetime, stipulating no=20
first use of cyber weapons, and so on.  They discuss cyberwar=20
inspections, and how these treaties might be enforced.  Since cyberwar=20
would be likely to result in a new worldwide arms race, one with a more=20
precarious trigger than the nuclear arms race, this part should be read=20
and discussed far and wide.  Sadly, it gets lost in the rest of the=20
book.  And, since the book lacks an index, it can be hard to find any=20
particular section after you're done reading it.

In the last chapter, the authors lay out their agenda for the future,=20
which largely I agree with.

1. We need to start talking publicly about cyber war.  This is certainly=20
true.  The threat of cyberwar is going to consume the sorts of resources=20
we shoveled into the nuclear threat half a century ago, and a realistic=20
discussion of the threats, risks, countermeasures, and policy choices is=20
essential.  We need more universities offering degrees in cyber=20
security, because we need more expertise for the entire gamut of threats.

2. We need to better defend our military networks, the high-level ISPs,=20
and our national power grid.  Clarke and Knake call this the "Defensive=20
Triad."  The authors and I disagree strongly on how this should be done,=20
but there is no doubt that it should be done.  The two parts of that=20
triad currently in commercial hands are simply too central to our=20
nation, and too vulnerable, to be left insecure.  And their value is far=20
greater to the nation than it is to the corporations that own it, which=20
means the market will not naturally secure it.  I agree with the authors=20
that regulation is necessary.

3. We need to reduce cybercrime.  Even without the cyber warriors bit,=20
we need to do that.  Cybercrime is bad, and it's continuing to get=20
worse.  Yes, it's hard.  But it's important.

4. We need international cyberwar treaties.  I couldn't agree more about=20
this.  We do.  We need to start thinking about them, talking about them,=20
and negotiating them now, before the cyberwar arms race takes off.=20
There are all kind of issues with cyberwar treaties, and the book talks=20
about a lot of them.  However full of loopholes they might be, their=20
existence will do more good than harm.

5. We need more research on secure network designs.  Again, even without=20
the cyberwar bit, this is essential.  We need more research in=20
cybersecurity, a lot more.

6. We need decisions about cyberwar -- what weapons to build, what=20
offensive actions to take, who to target -- to be made as far up the=20
command structure as possible.  Clarke and Knake want the president to=20
personally approve all of this, and I agree.  Because of its nature, it=20
can be easy to launch a small-scale cyber attack, and it can be easy for=20
a small-scale attack to get out of hand and turn into a large-scale=20
attack.  We need the president to make the decisions, not some low-level=20
military officer ensconced in a computer-filled bunker late one night.

This is great stuff, and a fine starting place for a national policy=20
discussion on cybersecurity, whether it be against a military,=20
espionage, or criminal threat.  Unfortunately, for readers to get there,=20
they have to wade through the rest of the book.  And unless their=20
bullshit detectors are already well-calibrated on this topic, I don't=20
want them reading all the hyperbole and fear-mongering that comes=20
before, no matter how readable the book.

Note:  I read "Cyber War" in April, when it first came out.  I wanted to=20
write a review then, but found that while my Kindle is great for=20
reading, it's terrible for flipping back and forth looking for bits and=20
pieces to write about in a review.  So I let the review languish.=20
Finally, I borrowed a paper copy from my local library.

Cyber War: The Next Threat to National Security and What to do About It:
http://www.amazon.com/dp/0061962236/counterpane/

Some other reviews:
http://www.wired.com/threatlevel/2010/04/cyberwar-richard-clarke/
http://www.nytimes.com/2010/04/27/books/27book.html
http://online.wsj.com/article/SB10001424052748704671904575193942114368842=
.html=20
or http://tinyurl.com/2gxno4r
http://www.washingtonpost.com/wp-dyn/content/article/2010/05/21/AR2010052=
101860.html=20
or http://tinyurl.com/3y3puse
http://www.bookreviewsweekly.com/cyber-war-by-richard-clarke/
http://www.ft.com/cms/s/2/6ba1923e-66bc-11df-aeb1-00144feab49a.html
http://www.slate.com/id/2252391/
http://www.networkworld.com/news/2010/040710-clarke-book-review.html
See also the reviews on the  Amazon page:
http://www.amazon.com/exec/obidos/ASIN/0061962236/counterpane/

I've written two essays on cyberwar.
http://www.schneier.com/essay-320.html
http://www.schneier.com/essay-334.html


** *** ***** ******* *********** *************

Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing=20
summaries, analyses, insights, and commentaries on security: computer=20
and otherwise.  You can subscribe, unsubscribe, or change your address=20
on the Web at <http://www.schneier.com/crypto-gram.html>.  Back issues=20
are also available at that URL.

Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable.  Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is the author of the=20
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"=20
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,=20
Threefish, Helix, Phelix, and Skein algorithms.  He is the Chief=20
Security Technology Officer of BT BCSG, and is on the Board of Directors=20
of the Electronic Privacy Information Center (EPIC).  He is a frequent=20
writer and lecturer on security topics.  See <http://www.schneier.com>.

Crypto-Gram is a personal newsletter.  Opinions expressed are not=20
necessarily those of BT.

Copyright (c) 2011 by Bruce Schneier.