CRYPTO-GRAM, September 15, 2011

Bruce Schneier <[email protected]> Thu, 15 Sep 2011 03:28:49 -0500
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

              September 15, 2011

               by Bruce Schneier
       Chief Security Technology Officer, BT
              [email protected]
             http://www.schneier.com


A free monthly newsletter providing summaries, analyses, insights, and 
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit 
<http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at 
<http://www.schneier.com/crypto-gram-1109.html>.  These same essays and 
news items appear in the "Schneier on Security" blog at 
<http://www.schneier.com/blog>, along with a lively comment section.  An 
RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
      Ten-Year Anniversary of 9/11
      Terrorism in the U.S. Since 9/11
      The Efficacy of Post-9/11 Counterterrorism
      News
      Funniest Joke at the Edinburgh Fringe Festival
      Schneier News
      Unredacted U.S. Diplomatic WikiLeaks Cables Published
      A Status Report: "Liars and Outliers"


** *** ***** ******* *********** *************

      Ten-Year Anniversary of 9/11



There have been lots of articles and essays related to the tenth 
anniversary of the 9/11 terrorist attacks.  Here's what I think is worth 
reading:

This ACLU report is really good: "A Call to Courage: Reclaiming Our 
Liberties Ten Years After 9/11."
http://www.aclu.org/national-security/report-call-courage-reclaiming-our-liberties-ten-years-after-911 
or http://tinyurl.com/3csjm6h

 From Foreign Policy: "Why Is It So Hard to Find a Suicide Bomber These 
Days?"
http://www.foreignpolicy.com/articles/2011/08/15/why_is_it_so_hard_to_find_a_suicide_bomber_these_days?page=full 
or http://tinyurl.com/4ykq99u

 From Stratfor: "Why al Qaeda is Unlikely to Execute Another 9/11."
http://www.stratfor.com/weekly/20110831-why-al-qaeda-unlikely-execute-another-911 
or http://tinyurl.com/3ed895v

Me from May 2010: "Where Are All the Terrorist Attacks?"
http://www.schneier.com/essay-314.html

Steven Pinker on Terrorism
http://chronicle.com/article/Era-in-Ideas-Terrorism/128490

Nice essay on the danger of too much security:
http://chronicle.com/article/Era-in-Ideas-Fear/128492

Joseph Stiglitz on the price of 9/11.
http://www.project-syndicate.org/commentary/stiglitz142/English

How 9/11 changed surveillance.
http://m.wired.com/threatlevel/2011/09/911-surveillance/

New scientific research as a result of 9/11.
http://articles.boston.com/2011-09-11/news/30142947_1_terrorist-attacks-mathematics-young-math-whiz 
or http://tinyurl.com/3zwcvhq

A good controversial piece.
http://dailyreckoning.com/a-decade-later/

The day we lost our privacy and power.
http://www.theregister.co.uk/2011/09/10/how_september_11_changed_our_world/ 
or http://tinyurl.com/4ybv7qr

The probability of another 9/11-magnitude terrorist attack.
http://www.cs.unm.edu/~aaron/blog/archives/2011/09/what_is_the_pro.htm

"Let's Cancel 9/11."
http://www.nationofchange.org/lets-cancel-911-1315495318

"How to Beat Terrorism: Refuse to Be Terrorized" from Wired.
http://www.wired.com/dangerroom/2011/09/end-911-era/

"Ten Things I Want My Children To Learn from 9/11"
http://www.popehat.com/2011/09/11/ten-things-i-want-my-children-to-learn-from-911/ 


The creator of the TSA says it should be dismantled and privatized:
http://www.humanevents.com/article.php?id=46114

Pat Buchanan on Bush after 9/11:
http://www.theamericanconservative.com/blog/2011/09/08/what-terror-wrought-the-bush-legacy/ 


9/11: Was There an Alternative? by Noam Chomsky
http://www.tomdispatch.com/post/175436/tomgram%3A_noam_chomsky%2C_the_imperial_mentality_and_9_11/#more 


Comments from Al-Jazeera:
http://english.aljazeera.net/indepth/opinion/2011/09/20119129922211592.html

The Onion's comment:
http://www.theonion.com/articles/us-commemorates-911-by-toasting-stable-afghan-gove,21332/ 


I didn't write anything to commemorate the 9/11 anniversary.  I couldn't 
think of anything to say that I haven't said a gazillion times already.
http://www.schneier.com/essays-terrorism.html
http://www.schneier.com/essays-airline.html


** *** ***** ******* *********** *************

      Terrorism in the U.S. Since 9/11



John Mueller and his students analyze the 33 cases of attempted Islamic 
extremist terrorism in the U.S. since 9/11.  So few of them are actually 
real, and so many of them were created or otherwise facilitated by law 
enforcement.

The death toll of all these is fourteen: thirteen at Ft. Hood and one in 
Little Rock.  I think it's fair to add to this the 2002 incident at Los 
Angeles Airport where a lone gunman killed two people at the El Al 
ticket counter, so that's sixteen deaths in the U.S. to terrorism in the 
past ten years.

Given the credible estimate that we've spent $1 trillion on 
anti-terrorism security (this does not include our many foreign wars), 
that's $62.5 billion per life lost.  Is there any other risk that we are 
even remotely as crazy about?

Note that everyone who died was shot with a gun.  No Islamic extremist 
has been able to successfully detonate a bomb in the U.S. in the past 
ten years, not even a Molotov cocktail.  (In the U.K. there has only 
been one successful terrorist bombing in the last ten years; the 2005 
London Underground attacks.)  And almost all of the 33 incidents (34 if 
you add LAX) have been lone actors, with no ties to al Qaeda.

Looking over the incidents, some of them would make pretty good movie 
plots.  The point of my "movie-plot threat" phrase is not that terrorist 
attacks are never like that, but that concentrating defensive resources 
against them is pointless because 1) there are too many of them and 2) 
it is too easy for the terrorists to change tactics or targets.

I remember the government fear mongering after 9/11.  How there were 
hundreds of sleeper cells in the U.S.  How terrorism would become the 
new normal unless we implemented all sorts of Draconian security 
measures.  You'd think that -- if this were even remotely true -- we 
would have seen more attempted terrorism in the U.S. over the past decade.

And I think arguments like "the government has secretly stopped lots of 
plots" don't hold any water.  Just look at the list, and remember how 
the Bush administration would hype even the most tenuous terrorist 
incident.  Stoking fear was the policy.  If the government stopped any 
other plots, they would have made as much of a big deal of them as they 
did of these 33 incidents.

Mueller's work:
http://polisci.osu.edu/faculty/jmueller/since.html

$1 trillion spent on terrorism security.
http://www.amazon.com/exec/obidos/ASIN/0199795762/counterpane/

To justify the current U.S. spending on homeland security -- not 
including our various official and unofficial wars -- we'd have to foil 
1,667 Times Square-style plots per year.
http://www.slate.com/id/2303169

Here's data on terrorist incidents from 1970 to 2004.
http://www.schneier.com/blog/archives/2007/06/terrorism_stati.html

And here's Nate Silver with data showing that the 1970s and 1980s were 
more dangerous with respect to airplane terrorism than the 2000s.
http://www.schneier.com/blog/archives/2010/01/nate_silver_on.html

According to the State Department's recent report, fifteen American 
private citizens died in terrorist attacks in 2010: thirteen in 
Afghanistan and one each in Iraq and Uganda.  Worldwide, 13,186 people 
died from terrorism in 2010.  These numbers pale even in comparison to 
things that aren't very risky.
http://www.state.gov/documents/organization/170479.pdf

Look at Table 3 on page 16 of this document.  The risk of dying in the 
U.S. from terrorism is substantially less than the risk of drowning in 
your bathtub, the risk of a home appliance killing you, or the risk of 
dying in an accident caused by a deer.  Remember that more people die 
every month in automobile crashes than died in 9/11.
http://polisci.osu.edu/faculty/jmueller/ISA10.PDF

In my blog post, I accidentally typed "lives saved" when I meant to type 
"lives lost."  I've corrected that above.  We generally have a 
regulatory safety goal of $1-$10M per life saved.  In order for the 
$100B we have spent per year on counterterrorism to be worth it, it 
would need to have saved 10,000 lives per year.
http://scienceblogs.com/stoat/2011/08/schneier_confuses_life_with_de.php 
or http://tinyurl.com/3ljpx2d

$1-$10M per life saved:
http://polisci.osu.edu/faculty/jmueller/STEWJTS.PDF


** *** ***** ******* *********** *************

      The Efficacy of Post-9/11 Counterterrorism



This is an interesting article.  The authors argue that the whole 
war-on-terror nonsense is useless -- that's not new -- but that the 
security establishment knows it doesn't work and abandoned many of the 
draconian security measures years ago, long before Obama became 
president.  All that's left of the war on terror is political, as 
lawmakers fund unwanted projects in an effort to be tough on crime.

I wish it were true, but I don't buy it.  The war on terror is an 
enormous cash cow, and law enforcement is spending the money as fast as 
it can get it.  It's also a great stalking horse for increases in police 
powers, and I see no signs of agencies like the FBI or the TSA not 
grabbing all the power they can.

The second half of the article is better.  The authors argue that 
openness, not secrecy, improves security

http://www.theatlantic.com/national/archive/2011/08/who-killed-the-war-on-terror/244273/ 
or http://tinyurl.com/3f76e24

Here's the report the article was based on.
http://thescienceofsecurity.org/blog/CT%20Since%209-11_by_Breakthrough.pdf 
or http://tinyurl.com/3d6pcwo

Counterterrorism as an enormous cash cow:
http://www.latimes.com/news/nationworld/nation/la-na-911-homeland-money-20110828,0,3913741,full.story 
or http://tinyurl.com/3u3olzx


** *** ***** ******* *********** *************

      News



Interesting research on search-redirection attacks and the illicit 
online prescription drug trade:
http://www.lightbluetouchpaper.org/2011/08/10/measuring-search-redirection-attacks-in-the-illicit-online-prescription-drug-trade/ 
or http://tinyurl.com/3ntug2m

Nice essay by Christopher Soghoian on why cell phone and Internet 
providers need to enable security options by default.
http://arstechnica.com/tech-policy/news/2011/08/not-an-option-time-for-companies-to-embrace-security-by-default.ars 
or http://tinyurl.com/3krpcnv

A prison in Brazil uses geese as part of its alarm system.
http://www.boston.com/news/nation/articles/2011/08/11/brazil_prison_uses_geese_as_alarm_system 
or http://tinyurl.com/
There's a long tradition of this.  Circa 400 BC, alarm geese alerted a 
Roman citadel to a Gaul attack.
http://www.mariamilani.com/ancient_rome/Roman_Goddess_Juno.htm

New attack on AES:
http://www.schneier.com/blog/archives/2011/08/new_attack_on_a_1.html

Any institution delegated with the task of preventing terrorism has a 
dilemma: they can either do their best to prevent terrorism, or they can 
do their best to make sure they're not blamed for any terrorist attacks. 
  I've talked about this dilemma for a while now, and it's nice to see 
some research results that demonstrate its effects.
http://opim.wharton.upenn.edu/risk/library/J2011OBHDP_APM,AT,HK_PolicymakersDilemma.pdf 
or http://tinyurl.com/3djfle8
Think about this with respect to the TSA.  Are they doing their best to 
mitigate terrorism, or are they doing their best to ensure that if 
there's a terrorist attack the public doesn't blame the TSA for missing it?

Long essay on the value of pseudonymity.
http://www.marrowbones.com/commons/technosocial/2011/07/on_pseudonymity_privacy_and_re.html 
or http://tinyurl.com/44nrcuy
This is, of a course, a response to the Google+ names policy.

How Microsoft develops security patches:
http://go.microsoft.com/?linkid=9760867

James Fallows has a nice debunking of a movie-plot threat: open airplane 
cockpit doors during bathroom breaks.
http://www.theatlantic.com/national/archive/2011/08/the-latest-terrorism-non-menace-pilot-potty-break-attacks/243725/ 
or http://tinyurl.com/3qgr5e8

Cheating at casinos with hidden sleeve cameras.
http://www.popsci.com/technology/article/2011-06/spy-vs-spy-casinos-cant-see-cameras-hidden-gamblers-sleeves 
or http://tinyurl.com/42ferqt

Worried about someone hacking your implanted medical devices?  Here's a 
signal-jamming device you can wear.
http://www.technologyreview.com/computing/38338/

Smartphone keystroke logging using the motion sensor.
http://www.theregister.co.uk/2011/08/17/android_key_logger/
http://regmedia.co.uk/2011/08/17/touchlogger_research_paper.pdf
http://hackaday.com/2011/08/18/gyroscope-based-smartphone-keylogging-attack/ 
or http://tinyurl.com/3daygqo
http://www.extremetech.com/mobile/92946-a-wiggly-approach-to-smartphone-keylogging# 
or http://tinyurl.com/3dfe385

Stealing ATM PINs with a thermal camera:
http://gizmodo.com/5831837/stealing-atm-pin-numbers-using-a-thermal-camera-is-dead-easy 
or http://tinyurl.com/3e7rdja
http://www.usenix.org/events/woot11/tech/final_files/Mowery.pdf
http://www.theregister.co.uk/2011/08/18/thermal_imaging_atm_fraud/
http://www.wired.com/gadgetlab/2011/08/thermal-imaging-camera-can-read-your-atm-pin/ 
  or http://tinyurl.com/3zgxsdl

The security risks of not teaching malware:
http://www.csl.sri.com/users/neumann/cacm223.pdf

The security problems associated with moving $12B in gold from London to 
Venezuela.
http://blogs.reuters.com/felix-salmon/2011/08/23/how-to-get-12-billion-of-gold-to-venezuela/ 
or http://tinyurl.com/3c9ul7b

Nice essay on the problems with talking about cyberspace risks using 
"Cold War" metaphors:
http://www.brookings.edu/articles/2011/0815_cybersecurity_singer_shachtman.aspx 
or http://tinyurl.com/42otfe5

This is a picture of a pair of wire cutters secured to a table with a 
wire.  Someone isn't thinking this through....
http://www.reddit.com/r/pics/comments/juonf/my_boss_was_tired_of_our_wire_cutters_getting/ 
or http://tinyurl.com/3zotf28

Screenshots of a Chinese hacking tool.  It's hard to know how serious 
this really is.
http://www.theepochtimes.com/n2/china-news/slip-up-in-chinese-military-tv-show-reveals-more-than-intended-60619.html 
or http://tinyurl.com/42mv2u2
http://ept.ms/oxUW6k
http://military.cntv.cn/program/jskj/20110717/100139.shtml

We finally have some details of the RSA attack, even though the company 
isn't talking.  It was a not-very-sophisticated phishing attack.
http://m.wired.com/threatlevel/2011/08/how-rsa-got-hacked/

This Facebook Privacy Guide is actually pretty good.
https://www.facebook.com/safety/attachment/Guide%20to%20Facebook%20Security.pdf 
or http://tinyurl.com/4x4gglx
Also note that the site is redesigning its privacy.  As we learned from 
Microsoft, nothing motivates a company to improve its security like 
competition.
http://gigaom.com/2011/08/23/facebook-privacy-redesign

Social networking sites make it very difficult, if not impossible, to 
have undercover police officers.
http://www.techworld.com.au/article/398599/social_media_could_render_covert_policing_impossible_/ 
or http://tinyurl.com/3t3q2zz
There's another side to this issue as well.  Social networking sites can 
help undercover officers with their backstory, by building a fictional 
history.  Some of this might require help from the company that owns the 
social networking site, but that seems like a reasonable request by the 
police.  I am in the middle of reading Diego Gambetta's book "Codes of 
the Underworld: How Criminals Communicate."  He talks about the lengthy 
vetting process organized crime uses to vet new members -- often relying 
on people who knew the person since birth, or people who served time 
with him in jail -- to protect against police informants.  I agree that 
social networking sites can make undercover work even harder, but it's 
gotten pretty hard even without that.
http://www.amazon.com/exec/obidos/ASIN/0691119376/counterpane/

Job opening: TSA Public Affairs Specialist.
http://www.schneier.com/blog/archives/2011/08/job_opening_tsa.html

There's been a forged Google certificate out in the wild for the past 
month and a half.  Whoever has it -- evidence points to the Iranian 
government -- can, if they're in the right place, launch 
man-in-the-middle attacks against Gmail users and read their mail.  This 
isn't Google's mistake; the certificate was issued by a Dutch CA that 
has nothing to do with Google.
https://www.eff.org/deeplinks/2011/08/iranian-man-middle-attack-against-google 
or http://tinyurl.com/3r5kxcx
http://www.theregister.co.uk/2011/08/29/fraudulent_google_ssl_certificate/ 
or http://tinyurl.com/3cjyrhk
http://www.computerworld.com/s/article/9219663/Hackers_may_have_stolen_over_200_SSL_certificates 
or http://tinyurl.com/3kbp4so
http://www.f-secure.com/weblog/archives/00002228.html
https://blog.torproject.org/blog/diginotar-damage-disclosure

Fidelity National Information Services Inc. (FIS) lost $13M to an ATM 
theft earlier this year:
http://krebsonsecurity.com/2011/08/coordinated-atm-heist-nets-thieves-13m/ 
or http://tinyurl.com/3vwu7l7
This reminds me of the RBS WorldPay theft from a couple of years ago.
http://voices.washingtonpost.com/securityfix/2009/11/eight_indicted_in_9m_rbs_world.html 
or http://tinyurl.com/4xpd65u

New research: Adrian J. Lee and Sheldon H. Jacobson (2011), "The Impact 
of Aviation Checkpoint Queues on Optimizing Security Screening 
Effectiveness," Reliability Engineering & System Safety, 96 (August): 
900-911.
http://www.sciencedirect.com/science/article/pii/S0951832011000391

Interesting article on outing a CIA agent, and how difficult it is to 
keep an identity secret in the information age.
http://www.theatlanticwire.com/global/2011/07/did-cia-do-enough-protect-bin-ladens-hunter/39867/ 
or http://tinyurl.com/6kn7nbf

Mason Rice, Robert Miller, and Sujeet Shenoi (2011), "May the US 
Government Monitor Private Critical Infrastructure Assets to Combat 
Foreign Cyberspace Threats?" International Journal of Critical 
Infrastructure Protection, 4 (April 2011): 3-13.
http://www.sciencedirect.com/science/article/pii/S1874548211000047

I've already written about secret questions, the easier-to-guess 
low-security backup password that sites want you to have in case you 
forget your harder-to-remember higher-security password.  Here's a new 
one, courtesy of the National Archives:  "What is your preferred 
internet password?"  I have been told that Priceline has the same one, 
which implies that this is some third-party login service or toolkit.
http://37signals.com/svn/posts/2992-while-setting-up-an-account-at-the-national 
or http://tinyurl.com/3cenbka

TSA Administrator John Pistole on the future of airport security. 
There's a lot here that's worth watching.  He talks about expanding 
behavioral detection.  He talks about less screening for "trusted 
travelers."
http://www.tsa.gov/press/speeches/090611_csis.shtm

Cultural differences in risk tolerance:
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1647086

Sharing security information and the Prisoner's Dilemma:
http://www.sciencedirect.com/science/article/pii/S0167923611001151


** *** ***** ******* *********** *************

      Funniest Joke at the Edinburgh Fringe Festival



Nick Helm won an award for the funniest joke at the Edinburgh Fringe 
Festival:

     Nick Helm: "I needed a password with eight characters so I picked
     Snow White and the Seven Dwarves."

Note that two other jokes were about security:

     Tim Vine: "Crime in multi-storey car parks. That is wrong on so
     many different levels."

     Andrew Lawrence: "I admire these phone hackers. I think they have
     a lot of patience. I can't even be bothered to check my OWN
     voicemails."

http://www.theregister.co.uk/2011/08/25/fringe_gag/


** *** ***** ******* *********** *************

      Schneier News


I'm speaking at the Information Security Forum Annual World Congress, on 
19 September in Berlin.
https://www.securityforum.org/services/publiccongress/

I'm also speaking at the Danish IT Lawyers Conference, on 20 September 
in Copenhagen.


** *** ***** ******* *********** *************

      Unredacted U.S. Diplomatic WikiLeaks Cables Published



It looks as if the entire mass of U.S. diplomatic cables that WikiLeaks 
had is available online somewhere.  How this came about is a good 
illustration of how security can go wrong in ways you don't expect.  It 
seems that the encrypted file WikiLeaks gave to the Guardian got loose 
in the wild, and then the Guardian published the encryption key in their 
tell-all book about WikiLeaks.

 From pp 138-9 of "WikiLeaks":

     Assange wrote down on a scrap of paper:
     ACollectionOfHistorySince_1966_ToThe_PresentDay#.  "That's
     the password," he said.  "But you have to add one extra word when
     you type it in.  You have to put in the word 'Diplomatic' before
     the word 'History'.  Can you remember that?"

I think we can all agree that that's a secure encryption key.

Memo to the "Guardian":  Publishing encryption keys is almost always a 
bad idea.  Memo to WikiLeaks: Take better care of your encrypted files.

The detailed story.
http://www.spiegel.de/international/world/0,1518,783778,00.html

Finger-pointing between the Guardian and WikiLeaks:
http://www.guardian.co.uk/world/2011/sep/01/unredacted-us-embassy-cables-online 
or http://tinyurl.com/3g3zktq
http://www.wikileaks.org/Guardian-journalist-negligently.html

The book:
http://www.amazon.com/exec/obidos/ASIN/B0057D9LJG/counterpane/


** *** ***** ******* *********** *************

      A Status Report: "Liars and Outliers"



It's been a long hard year, but the book is almost finished.  It's 
certainly the most difficult book I've ever written, mostly because I've 
had to learn about academic fields I don't have a lot of experience in. 
  But the book is finally coming together as a coherent whole, and I am 
optimistic that the results will prove to be worth the effort.

Table of contents:

      1. Introduction
      2. A Natural History of Security
      3. The Evolution of Cooperation
      4. A Social History of Security
      5. Societal Dilemmas
      6. Societal Security
      7. Moral Societal Security
      8. Reputational Societal Security
      9. Institutional Societal Security
      10. Technological Societal Security
      11. Competing Interest
      12. Organizations and Societal Dilemmas
      13. Corporations and Societal Dilemmas
      14. Institutions and Societal Dilemmas
      15. Understanding Societal Security Failures
      16. Societal Security and the Information Age
      17. The Future of Societal Security

The old title, "The Dishonest Minority," has been completely expunged 
from the book.  The phrase appears nowhere in the text -- its only 
existence is in old blog posts about the book.

Lastly, I want to apologize to all my readers for the scant pickings on 
my blog and in Crypto-Gram.  So much of my attention is going into 
writing my book that I don't have time for much else.  I promise to 
write more essays and blog posts once the book is finished.  That's 
likely to be the December issue of Crypto-Gram.  Thank you for your 
patience.

The manuscript is due in 45 days; publication is still scheduled for 
mid-February.  Right now, it's 88,000 words long, with another 30,000 
words in notes and references.

Cover:
http://www.schneier.com/blog/archives/2011/08/liars_and_outli.html

Older blog posts about the book:
http://www.schneier.com/blog/archives/2011/05/status_report_t.html
http://www.schneier.com/blog/archives/2011/02/societal_securi.html


** *** ***** ******* *********** *************

Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing 
summaries, analyses, insights, and commentaries on security: computer 
and otherwise.  You can subscribe, unsubscribe, or change your address 
on the Web at <http://www.schneier.com/crypto-gram.html>.  Back issues 
are also available at that URL.

Please feel free to forward CRYPTO-GRAM, in whole or in part, to 
colleagues and friends who will find it valuable.  Permission is also 
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entirety.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is the author of the 
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies," 
and "Applied Cryptography," and an inventor of the Blowfish, Twofish, 
Threefish, Helix, Phelix, and Skein algorithms.  He is the Chief 
Security Technology Officer of BT BCSG, and is on the Board of Directors 
of the Electronic Privacy Information Center (EPIC).  He is a frequent 
writer and lecturer on security topics.  See <http://www.schneier.com>.

Crypto-Gram is a personal newsletter.  Opinions expressed are not 
necessarily those of BT.

Copyright (c) 2011 by Bruce Schneier.

** *** ***** ******* *********** *************

To unsubscribe, click this link:

http://listserv.modwest.com/cgi-bin/wa?TICKET=NzM0NDI1IGdjc2MtY3J5cHRvLWdyYW1ATS5HTUFORS5PUkcgQ1JZUFRPLUdSQU0tTElTVClOY/BDlgBP&c=SIGNOFF