CRYPTO-GRAM, September 15, 2011
Bruce Schneier <[email protected]> Thu, 15 Sep 2011 03:28:49 -0500
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
September 15, 2011
by Bruce Schneier
Chief Security Technology Officer, BT
[email protected]
http://www.schneier.com
A free monthly newsletter providing summaries, analyses, insights, and
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at
<http://www.schneier.com/crypto-gram-1109.html>. These same essays and
news items appear in the "Schneier on Security" blog at
<http://www.schneier.com/blog>, along with a lively comment section. An
RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Ten-Year Anniversary of 9/11
Terrorism in the U.S. Since 9/11
The Efficacy of Post-9/11 Counterterrorism
News
Funniest Joke at the Edinburgh Fringe Festival
Schneier News
Unredacted U.S. Diplomatic WikiLeaks Cables Published
A Status Report: "Liars and Outliers"
** *** ***** ******* *********** *************
Ten-Year Anniversary of 9/11
There have been lots of articles and essays related to the tenth
anniversary of the 9/11 terrorist attacks. Here's what I think is worth
reading:
This ACLU report is really good: "A Call to Courage: Reclaiming Our
Liberties Ten Years After 9/11."
http://www.aclu.org/national-security/report-call-courage-reclaiming-our-liberties-ten-years-after-911
or http://tinyurl.com/3csjm6h
From Foreign Policy: "Why Is It So Hard to Find a Suicide Bomber These
Days?"
http://www.foreignpolicy.com/articles/2011/08/15/why_is_it_so_hard_to_find_a_suicide_bomber_these_days?page=full
or http://tinyurl.com/4ykq99u
From Stratfor: "Why al Qaeda is Unlikely to Execute Another 9/11."
http://www.stratfor.com/weekly/20110831-why-al-qaeda-unlikely-execute-another-911
or http://tinyurl.com/3ed895v
Me from May 2010: "Where Are All the Terrorist Attacks?"
http://www.schneier.com/essay-314.html
Steven Pinker on Terrorism
http://chronicle.com/article/Era-in-Ideas-Terrorism/128490
Nice essay on the danger of too much security:
http://chronicle.com/article/Era-in-Ideas-Fear/128492
Joseph Stiglitz on the price of 9/11.
http://www.project-syndicate.org/commentary/stiglitz142/English
How 9/11 changed surveillance.
http://m.wired.com/threatlevel/2011/09/911-surveillance/
New scientific research as a result of 9/11.
http://articles.boston.com/2011-09-11/news/30142947_1_terrorist-attacks-mathematics-young-math-whiz
or http://tinyurl.com/3zwcvhq
A good controversial piece.
http://dailyreckoning.com/a-decade-later/
The day we lost our privacy and power.
http://www.theregister.co.uk/2011/09/10/how_september_11_changed_our_world/
or http://tinyurl.com/4ybv7qr
The probability of another 9/11-magnitude terrorist attack.
http://www.cs.unm.edu/~aaron/blog/archives/2011/09/what_is_the_pro.htm
"Let's Cancel 9/11."
http://www.nationofchange.org/lets-cancel-911-1315495318
"How to Beat Terrorism: Refuse to Be Terrorized" from Wired.
http://www.wired.com/dangerroom/2011/09/end-911-era/
"Ten Things I Want My Children To Learn from 9/11"
http://www.popehat.com/2011/09/11/ten-things-i-want-my-children-to-learn-from-911/
The creator of the TSA says it should be dismantled and privatized:
http://www.humanevents.com/article.php?id=46114
Pat Buchanan on Bush after 9/11:
http://www.theamericanconservative.com/blog/2011/09/08/what-terror-wrought-the-bush-legacy/
9/11: Was There an Alternative? by Noam Chomsky
http://www.tomdispatch.com/post/175436/tomgram%3A_noam_chomsky%2C_the_imperial_mentality_and_9_11/#more
Comments from Al-Jazeera:
http://english.aljazeera.net/indepth/opinion/2011/09/20119129922211592.html
The Onion's comment:
http://www.theonion.com/articles/us-commemorates-911-by-toasting-stable-afghan-gove,21332/
I didn't write anything to commemorate the 9/11 anniversary. I couldn't
think of anything to say that I haven't said a gazillion times already.
http://www.schneier.com/essays-terrorism.html
http://www.schneier.com/essays-airline.html
** *** ***** ******* *********** *************
Terrorism in the U.S. Since 9/11
John Mueller and his students analyze the 33 cases of attempted Islamic
extremist terrorism in the U.S. since 9/11. So few of them are actually
real, and so many of them were created or otherwise facilitated by law
enforcement.
The death toll of all these is fourteen: thirteen at Ft. Hood and one in
Little Rock. I think it's fair to add to this the 2002 incident at Los
Angeles Airport where a lone gunman killed two people at the El Al
ticket counter, so that's sixteen deaths in the U.S. to terrorism in the
past ten years.
Given the credible estimate that we've spent $1 trillion on
anti-terrorism security (this does not include our many foreign wars),
that's $62.5 billion per life lost. Is there any other risk that we are
even remotely as crazy about?
Note that everyone who died was shot with a gun. No Islamic extremist
has been able to successfully detonate a bomb in the U.S. in the past
ten years, not even a Molotov cocktail. (In the U.K. there has only
been one successful terrorist bombing in the last ten years; the 2005
London Underground attacks.) And almost all of the 33 incidents (34 if
you add LAX) have been lone actors, with no ties to al Qaeda.
Looking over the incidents, some of them would make pretty good movie
plots. The point of my "movie-plot threat" phrase is not that terrorist
attacks are never like that, but that concentrating defensive resources
against them is pointless because 1) there are too many of them and 2)
it is too easy for the terrorists to change tactics or targets.
I remember the government fear mongering after 9/11. How there were
hundreds of sleeper cells in the U.S. How terrorism would become the
new normal unless we implemented all sorts of Draconian security
measures. You'd think that -- if this were even remotely true -- we
would have seen more attempted terrorism in the U.S. over the past decade.
And I think arguments like "the government has secretly stopped lots of
plots" don't hold any water. Just look at the list, and remember how
the Bush administration would hype even the most tenuous terrorist
incident. Stoking fear was the policy. If the government stopped any
other plots, they would have made as much of a big deal of them as they
did of these 33 incidents.
Mueller's work:
http://polisci.osu.edu/faculty/jmueller/since.html
$1 trillion spent on terrorism security.
http://www.amazon.com/exec/obidos/ASIN/0199795762/counterpane/
To justify the current U.S. spending on homeland security -- not
including our various official and unofficial wars -- we'd have to foil
1,667 Times Square-style plots per year.
http://www.slate.com/id/2303169
Here's data on terrorist incidents from 1970 to 2004.
http://www.schneier.com/blog/archives/2007/06/terrorism_stati.html
And here's Nate Silver with data showing that the 1970s and 1980s were
more dangerous with respect to airplane terrorism than the 2000s.
http://www.schneier.com/blog/archives/2010/01/nate_silver_on.html
According to the State Department's recent report, fifteen American
private citizens died in terrorist attacks in 2010: thirteen in
Afghanistan and one each in Iraq and Uganda. Worldwide, 13,186 people
died from terrorism in 2010. These numbers pale even in comparison to
things that aren't very risky.
http://www.state.gov/documents/organization/170479.pdf
Look at Table 3 on page 16 of this document. The risk of dying in the
U.S. from terrorism is substantially less than the risk of drowning in
your bathtub, the risk of a home appliance killing you, or the risk of
dying in an accident caused by a deer. Remember that more people die
every month in automobile crashes than died in 9/11.
http://polisci.osu.edu/faculty/jmueller/ISA10.PDF
In my blog post, I accidentally typed "lives saved" when I meant to type
"lives lost." I've corrected that above. We generally have a
regulatory safety goal of $1-$10M per life saved. In order for the
$100B we have spent per year on counterterrorism to be worth it, it
would need to have saved 10,000 lives per year.
http://scienceblogs.com/stoat/2011/08/schneier_confuses_life_with_de.php
or http://tinyurl.com/3ljpx2d
$1-$10M per life saved:
http://polisci.osu.edu/faculty/jmueller/STEWJTS.PDF
** *** ***** ******* *********** *************
The Efficacy of Post-9/11 Counterterrorism
This is an interesting article. The authors argue that the whole
war-on-terror nonsense is useless -- that's not new -- but that the
security establishment knows it doesn't work and abandoned many of the
draconian security measures years ago, long before Obama became
president. All that's left of the war on terror is political, as
lawmakers fund unwanted projects in an effort to be tough on crime.
I wish it were true, but I don't buy it. The war on terror is an
enormous cash cow, and law enforcement is spending the money as fast as
it can get it. It's also a great stalking horse for increases in police
powers, and I see no signs of agencies like the FBI or the TSA not
grabbing all the power they can.
The second half of the article is better. The authors argue that
openness, not secrecy, improves security
http://www.theatlantic.com/national/archive/2011/08/who-killed-the-war-on-terror/244273/
or http://tinyurl.com/3f76e24
Here's the report the article was based on.
http://thescienceofsecurity.org/blog/CT%20Since%209-11_by_Breakthrough.pdf
or http://tinyurl.com/3d6pcwo
Counterterrorism as an enormous cash cow:
http://www.latimes.com/news/nationworld/nation/la-na-911-homeland-money-20110828,0,3913741,full.story
or http://tinyurl.com/3u3olzx
** *** ***** ******* *********** *************
News
Interesting research on search-redirection attacks and the illicit
online prescription drug trade:
http://www.lightbluetouchpaper.org/2011/08/10/measuring-search-redirection-attacks-in-the-illicit-online-prescription-drug-trade/
or http://tinyurl.com/3ntug2m
Nice essay by Christopher Soghoian on why cell phone and Internet
providers need to enable security options by default.
http://arstechnica.com/tech-policy/news/2011/08/not-an-option-time-for-companies-to-embrace-security-by-default.ars
or http://tinyurl.com/3krpcnv
A prison in Brazil uses geese as part of its alarm system.
http://www.boston.com/news/nation/articles/2011/08/11/brazil_prison_uses_geese_as_alarm_system
or http://tinyurl.com/
There's a long tradition of this. Circa 400 BC, alarm geese alerted a
Roman citadel to a Gaul attack.
http://www.mariamilani.com/ancient_rome/Roman_Goddess_Juno.htm
New attack on AES:
http://www.schneier.com/blog/archives/2011/08/new_attack_on_a_1.html
Any institution delegated with the task of preventing terrorism has a
dilemma: they can either do their best to prevent terrorism, or they can
do their best to make sure they're not blamed for any terrorist attacks.
I've talked about this dilemma for a while now, and it's nice to see
some research results that demonstrate its effects.
http://opim.wharton.upenn.edu/risk/library/J2011OBHDP_APM,AT,HK_PolicymakersDilemma.pdf
or http://tinyurl.com/3djfle8
Think about this with respect to the TSA. Are they doing their best to
mitigate terrorism, or are they doing their best to ensure that if
there's a terrorist attack the public doesn't blame the TSA for missing it?
Long essay on the value of pseudonymity.
http://www.marrowbones.com/commons/technosocial/2011/07/on_pseudonymity_privacy_and_re.html
or http://tinyurl.com/44nrcuy
This is, of a course, a response to the Google+ names policy.
How Microsoft develops security patches:
http://go.microsoft.com/?linkid=9760867
James Fallows has a nice debunking of a movie-plot threat: open airplane
cockpit doors during bathroom breaks.
http://www.theatlantic.com/national/archive/2011/08/the-latest-terrorism-non-menace-pilot-potty-break-attacks/243725/
or http://tinyurl.com/3qgr5e8
Cheating at casinos with hidden sleeve cameras.
http://www.popsci.com/technology/article/2011-06/spy-vs-spy-casinos-cant-see-cameras-hidden-gamblers-sleeves
or http://tinyurl.com/42ferqt
Worried about someone hacking your implanted medical devices? Here's a
signal-jamming device you can wear.
http://www.technologyreview.com/computing/38338/
Smartphone keystroke logging using the motion sensor.
http://www.theregister.co.uk/2011/08/17/android_key_logger/
http://regmedia.co.uk/2011/08/17/touchlogger_research_paper.pdf
http://hackaday.com/2011/08/18/gyroscope-based-smartphone-keylogging-attack/
or http://tinyurl.com/3daygqo
http://www.extremetech.com/mobile/92946-a-wiggly-approach-to-smartphone-keylogging#
or http://tinyurl.com/3dfe385
Stealing ATM PINs with a thermal camera:
http://gizmodo.com/5831837/stealing-atm-pin-numbers-using-a-thermal-camera-is-dead-easy
or http://tinyurl.com/3e7rdja
http://www.usenix.org/events/woot11/tech/final_files/Mowery.pdf
http://www.theregister.co.uk/2011/08/18/thermal_imaging_atm_fraud/
http://www.wired.com/gadgetlab/2011/08/thermal-imaging-camera-can-read-your-atm-pin/
or http://tinyurl.com/3zgxsdl
The security risks of not teaching malware:
http://www.csl.sri.com/users/neumann/cacm223.pdf
The security problems associated with moving $12B in gold from London to
Venezuela.
http://blogs.reuters.com/felix-salmon/2011/08/23/how-to-get-12-billion-of-gold-to-venezuela/
or http://tinyurl.com/3c9ul7b
Nice essay on the problems with talking about cyberspace risks using
"Cold War" metaphors:
http://www.brookings.edu/articles/2011/0815_cybersecurity_singer_shachtman.aspx
or http://tinyurl.com/42otfe5
This is a picture of a pair of wire cutters secured to a table with a
wire. Someone isn't thinking this through....
http://www.reddit.com/r/pics/comments/juonf/my_boss_was_tired_of_our_wire_cutters_getting/
or http://tinyurl.com/3zotf28
Screenshots of a Chinese hacking tool. It's hard to know how serious
this really is.
http://www.theepochtimes.com/n2/china-news/slip-up-in-chinese-military-tv-show-reveals-more-than-intended-60619.html
or http://tinyurl.com/42mv2u2
http://ept.ms/oxUW6k
http://military.cntv.cn/program/jskj/20110717/100139.shtml
We finally have some details of the RSA attack, even though the company
isn't talking. It was a not-very-sophisticated phishing attack.
http://m.wired.com/threatlevel/2011/08/how-rsa-got-hacked/
This Facebook Privacy Guide is actually pretty good.
https://www.facebook.com/safety/attachment/Guide%20to%20Facebook%20Security.pdf
or http://tinyurl.com/4x4gglx
Also note that the site is redesigning its privacy. As we learned from
Microsoft, nothing motivates a company to improve its security like
competition.
http://gigaom.com/2011/08/23/facebook-privacy-redesign
Social networking sites make it very difficult, if not impossible, to
have undercover police officers.
http://www.techworld.com.au/article/398599/social_media_could_render_covert_policing_impossible_/
or http://tinyurl.com/3t3q2zz
There's another side to this issue as well. Social networking sites can
help undercover officers with their backstory, by building a fictional
history. Some of this might require help from the company that owns the
social networking site, but that seems like a reasonable request by the
police. I am in the middle of reading Diego Gambetta's book "Codes of
the Underworld: How Criminals Communicate." He talks about the lengthy
vetting process organized crime uses to vet new members -- often relying
on people who knew the person since birth, or people who served time
with him in jail -- to protect against police informants. I agree that
social networking sites can make undercover work even harder, but it's
gotten pretty hard even without that.
http://www.amazon.com/exec/obidos/ASIN/0691119376/counterpane/
Job opening: TSA Public Affairs Specialist.
http://www.schneier.com/blog/archives/2011/08/job_opening_tsa.html
There's been a forged Google certificate out in the wild for the past
month and a half. Whoever has it -- evidence points to the Iranian
government -- can, if they're in the right place, launch
man-in-the-middle attacks against Gmail users and read their mail. This
isn't Google's mistake; the certificate was issued by a Dutch CA that
has nothing to do with Google.
https://www.eff.org/deeplinks/2011/08/iranian-man-middle-attack-against-google
or http://tinyurl.com/3r5kxcx
http://www.theregister.co.uk/2011/08/29/fraudulent_google_ssl_certificate/
or http://tinyurl.com/3cjyrhk
http://www.computerworld.com/s/article/9219663/Hackers_may_have_stolen_over_200_SSL_certificates
or http://tinyurl.com/3kbp4so
http://www.f-secure.com/weblog/archives/00002228.html
https://blog.torproject.org/blog/diginotar-damage-disclosure
Fidelity National Information Services Inc. (FIS) lost $13M to an ATM
theft earlier this year:
http://krebsonsecurity.com/2011/08/coordinated-atm-heist-nets-thieves-13m/
or http://tinyurl.com/3vwu7l7
This reminds me of the RBS WorldPay theft from a couple of years ago.
http://voices.washingtonpost.com/securityfix/2009/11/eight_indicted_in_9m_rbs_world.html
or http://tinyurl.com/4xpd65u
New research: Adrian J. Lee and Sheldon H. Jacobson (2011), "The Impact
of Aviation Checkpoint Queues on Optimizing Security Screening
Effectiveness," Reliability Engineering & System Safety, 96 (August):
900-911.
http://www.sciencedirect.com/science/article/pii/S0951832011000391
Interesting article on outing a CIA agent, and how difficult it is to
keep an identity secret in the information age.
http://www.theatlanticwire.com/global/2011/07/did-cia-do-enough-protect-bin-ladens-hunter/39867/
or http://tinyurl.com/6kn7nbf
Mason Rice, Robert Miller, and Sujeet Shenoi (2011), "May the US
Government Monitor Private Critical Infrastructure Assets to Combat
Foreign Cyberspace Threats?" International Journal of Critical
Infrastructure Protection, 4 (April 2011): 3-13.
http://www.sciencedirect.com/science/article/pii/S1874548211000047
I've already written about secret questions, the easier-to-guess
low-security backup password that sites want you to have in case you
forget your harder-to-remember higher-security password. Here's a new
one, courtesy of the National Archives: "What is your preferred
internet password?" I have been told that Priceline has the same one,
which implies that this is some third-party login service or toolkit.
http://37signals.com/svn/posts/2992-while-setting-up-an-account-at-the-national
or http://tinyurl.com/3cenbka
TSA Administrator John Pistole on the future of airport security.
There's a lot here that's worth watching. He talks about expanding
behavioral detection. He talks about less screening for "trusted
travelers."
http://www.tsa.gov/press/speeches/090611_csis.shtm
Cultural differences in risk tolerance:
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1647086
Sharing security information and the Prisoner's Dilemma:
http://www.sciencedirect.com/science/article/pii/S0167923611001151
** *** ***** ******* *********** *************
Funniest Joke at the Edinburgh Fringe Festival
Nick Helm won an award for the funniest joke at the Edinburgh Fringe
Festival:
Nick Helm: "I needed a password with eight characters so I picked
Snow White and the Seven Dwarves."
Note that two other jokes were about security:
Tim Vine: "Crime in multi-storey car parks. That is wrong on so
many different levels."
Andrew Lawrence: "I admire these phone hackers. I think they have
a lot of patience. I can't even be bothered to check my OWN
voicemails."
http://www.theregister.co.uk/2011/08/25/fringe_gag/
** *** ***** ******* *********** *************
Schneier News
I'm speaking at the Information Security Forum Annual World Congress, on
19 September in Berlin.
https://www.securityforum.org/services/publiccongress/
I'm also speaking at the Danish IT Lawyers Conference, on 20 September
in Copenhagen.
** *** ***** ******* *********** *************
Unredacted U.S. Diplomatic WikiLeaks Cables Published
It looks as if the entire mass of U.S. diplomatic cables that WikiLeaks
had is available online somewhere. How this came about is a good
illustration of how security can go wrong in ways you don't expect. It
seems that the encrypted file WikiLeaks gave to the Guardian got loose
in the wild, and then the Guardian published the encryption key in their
tell-all book about WikiLeaks.
From pp 138-9 of "WikiLeaks":
Assange wrote down on a scrap of paper:
ACollectionOfHistorySince_1966_ToThe_PresentDay#. "That's
the password," he said. "But you have to add one extra word when
you type it in. You have to put in the word 'Diplomatic' before
the word 'History'. Can you remember that?"
I think we can all agree that that's a secure encryption key.
Memo to the "Guardian": Publishing encryption keys is almost always a
bad idea. Memo to WikiLeaks: Take better care of your encrypted files.
The detailed story.
http://www.spiegel.de/international/world/0,1518,783778,00.html
Finger-pointing between the Guardian and WikiLeaks:
http://www.guardian.co.uk/world/2011/sep/01/unredacted-us-embassy-cables-online
or http://tinyurl.com/3g3zktq
http://www.wikileaks.org/Guardian-journalist-negligently.html
The book:
http://www.amazon.com/exec/obidos/ASIN/B0057D9LJG/counterpane/
** *** ***** ******* *********** *************
A Status Report: "Liars and Outliers"
It's been a long hard year, but the book is almost finished. It's
certainly the most difficult book I've ever written, mostly because I've
had to learn about academic fields I don't have a lot of experience in.
But the book is finally coming together as a coherent whole, and I am
optimistic that the results will prove to be worth the effort.
Table of contents:
1. Introduction
2. A Natural History of Security
3. The Evolution of Cooperation
4. A Social History of Security
5. Societal Dilemmas
6. Societal Security
7. Moral Societal Security
8. Reputational Societal Security
9. Institutional Societal Security
10. Technological Societal Security
11. Competing Interest
12. Organizations and Societal Dilemmas
13. Corporations and Societal Dilemmas
14. Institutions and Societal Dilemmas
15. Understanding Societal Security Failures
16. Societal Security and the Information Age
17. The Future of Societal Security
The old title, "The Dishonest Minority," has been completely expunged
from the book. The phrase appears nowhere in the text -- its only
existence is in old blog posts about the book.
Lastly, I want to apologize to all my readers for the scant pickings on
my blog and in Crypto-Gram. So much of my attention is going into
writing my book that I don't have time for much else. I promise to
write more essays and blog posts once the book is finished. That's
likely to be the December issue of Crypto-Gram. Thank you for your
patience.
The manuscript is due in 45 days; publication is still scheduled for
mid-February. Right now, it's 88,000 words long, with another 30,000
words in notes and references.
Cover:
http://www.schneier.com/blog/archives/2011/08/liars_and_outli.html
Older blog posts about the book:
http://www.schneier.com/blog/archives/2011/05/status_report_t.html
http://www.schneier.com/blog/archives/2011/02/societal_securi.html
** *** ***** ******* *********** *************
Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing
summaries, analyses, insights, and commentaries on security: computer
and otherwise. You can subscribe, unsubscribe, or change your address
on the Web at <http://www.schneier.com/crypto-gram.html>. Back issues
are also available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to
colleagues and friends who will find it valuable. Permission is also
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entirety.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,
Threefish, Helix, Phelix, and Skein algorithms. He is the Chief
Security Technology Officer of BT BCSG, and is on the Board of Directors
of the Electronic Privacy Information Center (EPIC). He is a frequent
writer and lecturer on security topics. See <http://www.schneier.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not
necessarily those of BT.
Copyright (c) 2011 by Bruce Schneier.
** *** ***** ******* *********** *************
To unsubscribe, click this link:
http://listserv.modwest.com/cgi-bin/wa?TICKET=NzM0NDI1IGdjc2MtY3J5cHRvLWdyYW1ATS5HTUFORS5PUkcgQ1JZUFRPLUdSQU0tTElTVClOY/BDlgBP&c=SIGNOFF