CRYPTO-GRAM, May 15, 2005

Bruce Schneier <[email protected]> Sun, 15 May 2005 05:23:11 -0500
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

                  May 15, 2005

               by Bruce Schneier
                Founder and CTO
       Counterpane Internet Security, Inc.
            [email protected]
            <http://www.schneier.com>
           <http://www.counterpane.com>


A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.

Or you can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0505.html>.

Schneier also publishes these same essays in his blog:=20
<http://www.schneier.com/blog>.  An RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
      Blog: Schneier on Security
      REAL ID
      Should Terrorism be Reported in the News?
      New Risks of Automatic Speedtraps
      Crypto-Gram Reprints
      Detecting Nuclear Material in Transport
      The Potential for an SSH Worm
      News
      Biometric Passports in the U.K.
      Lighters Banned on Airplanes
      Counterpane News
      Wi-Fi Minefields
      The PITAC Report on CyberSecurity
      State-Sponsored Identity Theft
      Combating Spam
      Comments from Readers


** *** ***** ******* *********** *************

           Blog: Schneier on Security



For eight months now, I have maintained a blog.  It's basically the=20
same stuff you read in Crypto-Gram, only it comes out every day instead=20
of once a month.  And I try to revise what I write there when I include=20
it here.  Check it out if you're interested.

<http://www.schneier.com/blog>


** *** ***** ******* *********** *************

                    REAL ID



The United States will get a national ID card.  The REAL ID Act=20
establishes uniform standards for state driver's licenses, to go into=20
effect in three years, effectively creating a national ID card.  It's a=20
bad idea, and is going to make us all less safe.  It's also very=20
expensive. And it all happened without any serious debate in Congress.

I've already written about national IDs.  I've written about the=20
fallacies of identification as a security tool.  I'm not going to=20
repeat myself here, and I urge everyone who is interested to read those=20
essays (links at the end).  Remember, the question to ask is not=20
whether a national ID will do any good; the question to ask is whether=20
the good it does is worth the cost.  By that measure, a national ID is=20
a lousy security trade-off.  And everyone needs to understand why.

Aside from the generalities in my previous essays, there are specifics=20
about REAL ID that make for bad security.

The REAL ID Act requires driver's licenses to include a "common=20
machine-readable technology."  This will, of course, make identity=20
theft easier.  Already some hotels take photocopies of your ID when you=20
check in, and some bars scan your ID when you try to buy a=20
drink.  Since the U.S. has no data protection law, those businesses are=20
free to resell that data to data brokers like ChoicePoint and=20
Acxiom.  And they will; it would be bad business not to.  It actually=20
doesn't matter how well the states and federal government protect the=20
data on driver's licenses, as there will be parallel commercial=20
databases with the same information.

(Those who point to European countries with national IDs need to pay=20
attention to this point.  European countries have a strong legal=20
framework for data privacy and protection.  This is why the American=20
experience will be very different than the European experience, and a=20
much more serious danger to society.)

Even worse, there's likely to be an RFID chip in these licenses.  The=20
same specification for RFID chips embedded in passports includes=20
details about embedding RFID chips in driver's licenses.  I expect the=20
federal government will require states to do this, with all of the=20
associated security problems (e.g., surreptitious access).

REAL ID requires that driver's licenses contain actual addresses, and=20
no post office boxes.  There are no exceptions made for judges or=20
police -- even undercover police officers. This seems like a major=20
unnecessary security risk.

REAL ID also prohibits states from issuing driver's licenses to illegal=20
aliens.  This makes no sense, and will only result in these illegal=20
aliens driving without licenses -- which isn't going to help anyone's=20
security.  (This is an interesting insecurity, and is a direct result=20
of trying to take   a document that is a specific permission to drive=20
an automobile, and turning it into a general identification device.)

REAL ID is expensive. It's an unfunded mandate: the federal government=20
is forcing the states to spend their own money to comply with the=20
act.  I've seen estimates that the cost to the states of complying with=20
REAL ID will be tens of billions.  That's money that can't be spent on=20
actual security.

And the wackiest thing is that none of this is required.  In October=20
2004, the Intelligence Reform and Terrorism Prevention Act of 2004 was=20
signed into law.  That law included stronger security measures for=20
driver's licenses, the security measures recommended by the 9/11=20
Commission Report.  That's already done.  It's already law.

REAL ID goes way beyond that.  It's a huge power-grab by the federal=20
government over the states' systems for issuing driver's licenses.

REAL ID doesn't go into effect until three years after it becomes law,=20
but I expect things to be much worse by then.  One of my fears is that=20
this new uniform driver's license will bring a new level of "show me=20
your papers" checks by the government.  Already you can't fly without=20
an ID, even though no one has ever explained how that ID check makes=20
airplane terrorism any harder.  I have previously written about Secure=20
Flight, another lousy security system that tries to match airline=20
passengers against terrorist watch lists.  I've already heard rumblings=20
about requiring states to check identities against "government=20
databases" before issuing driver's licenses.  I'm sure Secure Flight=20
will be used for cruise ships, trains, and possibly even=20
subways.  Combine REAL ID with Secure Flight and you have an=20
unprecedented system for broad surveillance of the population.

Is there anyone who would feel safer under this kind of police state?

Americans overwhelmingly reject national IDs in general, and there's an=20
enormous amount of opposition to the REAL ID Act.

If you haven't heard much about REAL ID in the newspapers, that's not=20
an accident.  The politics of REAL ID was almost surreal.  It was voted=20
down last fall, but was reintroduced and attached to legislation that=20
funds military actions in Iraq.  This was a "must-pass" piece of=20
legislation, which means that there was no debate on REAL ID.  No=20
hearings, no debates in committees, no debates on the=20
floor.  Nothing.  And it's now law.

We're not defeated, though.  REAL ID can be fought in other ways: via=20
funding, in the courts, etc.  Those seriously interested in this issue=20
are invited to attend an EPIC-sponsored event in Washington, DC, on the=20
topic on June 6th.  I'll be there.

Text of the REAL ID Act:
<http://thomas.loc.gov/cgi-bin/bdquery/z?d109:h.r.00418:>

Congressional Research Services analysis:
<http://www.eff.org/Activism/realid/analysis.pdf>

My previous writings on identification and national IDs:
<http://www.schneier.com/crypto-gram-0404.html#1>
<http://www.schneier.com/crypto-gram-0402.html#6>
<http://www.schneier.com/crypto-gram-0112.html#1>

Security problems with RFIDs:
<http://www.schneier.com/crypto-gram-0410.html#3>

My previous writings on Secure Flight:
<http://www.schneier.com/crypto-gram-0502.html#1>

Resources:
<http://www.epic.org/privacy/id_cards/>
<http://www.unrealid.com/>

EPIC's Washington DC event:
<http://www.epic.org/events/id/savethedate.html>


** *** ***** ******* *********** *************

   Should Terrorism be Reported in the News?



In a New York Times op ed, columnist John Tierney argued that the media=20
is performing a public disservice by writing about all the suicide=20
bombings in Iraq.  This only serves to scare people, he claimed, and=20
serves the terrorists' ends.

Some liberal bloggers have jumped on this op-ed as furthering the=20
administration's attempts to hide the horrors of the Iraqi war from the=20
American people, but I think the argument is more subtle than=20
that.  Before you can figure out why Tierney is wrong, you need to=20
understand that he has a point.

Terrorism is a crime against the mind.  The real target of a terrorist=20
is morale, and press coverage helps him achieve his goal.  I wrote in=20
Beyond Fear (pages 242-3):

"Morale is the most significant terrorist target.  By refusing to be=20
scared, by refusing to overreact, and by refusing to publicize=20
terrorist attacks endlessly in the media, we limit the effectiveness of=20
terrorist attacks.  Through the long spate of IRA bombings in England=20
and Northern Ireland in the 1970s and 1980s, the press understood that=20
the terrorists wanted the British government to overreact, and praised=20
their restraint.  The U.S. press demonstrated no such understanding in=20
the months after 9/11 and made it easier for the U.S. government to=20
overreact."

Consider this thought experiment.  If the press did not report the 9/11=20
attacks, if most people in the U.S. didn't know about them, then the=20
attacks wouldn't have been such a defining moment in our national=20
politics.  If we lived 100 years ago, and people only read newspaper=20
articles and saw still photographs of the attacks, then people wouldn't=20
have had such an emotional reaction.  If we lived 200 years ago and all=20
we had to go on was the written word and oral accounts, the emotional=20
reaction would be even less.  Modern news coverage amplifies the=20
terrorists' actions by endlessly replaying them, with real video and=20
sound, burning them into the psyche of every viewer.

Just as the media's attention to 9/11 scared people into accepting=20
government overreactions like the PATRIOT Act, the media's attention to=20
the suicide bombings in Iraq are convincing people that Iraq is more=20
dangerous than it is.

Tiernan writes:

"I'm not advocating official censorship, but there's no reason the news=20
media can't reconsider their own fondness for covering suicide=20
bombings. A little restraint would give the public a more realistic=20
view of the world's dangers.

"Just as New Yorkers came to be guided by crime statistics instead of=20
the mayhem on the evening news, people might begin to believe the=20
statistics showing that their odds of being killed by a terrorist are=20
minuscule in Iraq or anywhere else."

I pretty much said the same thing, albeit more generally, in Beyond=20
Fear (page 29):

"Modern mass media, specifically movies and TV news, has degraded our=20
sense of natural risk.  We learn about risks, or we think we are=20
learning, not by directly experiencing the world around us and by=20
seeing what happens to others, but increasingly by getting our view of=20
things through the distorted lens of the media.  Our experience is=20
distilled for us, and it's a skewed sample that plays havoc with our=20
perceptions.  Kids try stunts they've seen performed by professional=20
stuntmen on TV, never recognizing the precautions the pros take.  The=20
five o'clock news doesn't truly reflect the world we live in -- only a=20
very few small and special parts of it.

"Slices of life with immediate visual impact get magnified; those with=20
no visual component, or that can't be immediately and viscerally=20
comprehended, get downplayed.  Rarities and anomalies, like terrorism,=20
are endlessly discussed and debated, while common risks like heart=20
disease, lung cancer, diabetes, and suicide are minimized.

"The global reach of today's news further exacerbates this problem.  If=20
a child is kidnapped in Salt Lake City during the summer, mothers all=20
over the country suddenly worry about the risk to their children.  If=20
there are a few shark attacks in Florida -- and a graphic movie --=20
suddenly every swimmer is worried.  (More people are killed every year=20
by pigs than by sharks, which shows you how good we are at evaluating=20
risk.)"

One of the things I routinely tell people is that if it's in the news,=20
don't worry about it.  By definition, "news" means that it hardly ever=20
happens.  If a risk is in the news, then it's probably not worth=20
worrying about.  When something is no longer reported -- automobile=20
deaths, domestic violence -- when it's so common that it's not news,=20
then you should start worrying.

Tierney is arguing his position as someone who thinks that the Bush=20
administration is doing a good job fighting terrorism, and that the=20
media's reporting of suicide bombings in Iraq are sapping Americans'=20
will to fight.  I am looking at the same issue from the other side, as=20
someone who thinks that the media's reporting of terrorist attacks and=20
threats has increased public support for the Bush administration's=20
draconian counterterrorism laws and dangerous and damaging foreign and=20
domestic policies.  If the media didn't report all of the=20
administration's alerts and warnings and arrests, we would have a much=20
more sensible counterterrorism policy in America and we would all be=20
much safer.

So why is the argument wrong?  It's wrong because the danger of not=20
reporting terrorist attacks is greater than the risk of continuing to=20
report them. Freedom of the press is a security measure.  The only tool=20
we have to keep government honest is public disclosure.  Once we start=20
hiding pieces of reality from the public -- either through legal=20
censorship or self-imposed "restraint" -- we end up with a government=20
that acts based on secrets.  We end up with some sort of system that=20
decides what the public should or should not know.

Here's one example. Last year I argued that the constant stream of=20
terrorist alerts were a mechanism to keep Americans scared.  This week,=20
the media reported that the Bush administration repeatedly raised the=20
terror threat level on flimsy evidence, against the recommendation of=20
former DHS secretary Tom Ridge.  If the media follows this story, we=20
will learn -- too late for the 2004 election, but not too late for the=20
future -- more about the Bush administration's terrorist propaganda=20
machine.

Freedom of the press -- the unfettered publishing of all the bad news=20
-- isn't without dangers.  But anything else is even more dangerous.=20
That's why Tierney is wrong.

And honestly, if anyone thinks they can get an accurate picture of=20
anyplace on the planet by reading news reports, they're sadly mistaken.

Tierney's essay:
<http://www.iht.com/articles/2005/05/10/opinion/edtierney.php>

Blog reactions:
<http://www.salon.com/politics/war_room/index.html?blog=3D/politics/war_ro=
=20
om/2005/05/10/media/index.html> or <http://tinyurl.com/b33e9>
<http://amcop.blogspot.com/2005/05/john-tierney-conservative-stupid-or.h=20
tml> or <http://tinyurl.com/cl5fj>
<http://littlejohn.blogs.com/beirut/2005/05/tierney_sucks.html>

My essay on terror alerts:
<http://www.schneier.com/essay-055.html>

Tom Ridge's comments:
<http://www.usatoday.com/news/washington/2005-05-10-ridge-alerts_x.htm>=20
or <http://tinyurl.com/bjyfq>


** *** ***** ******* *********** *************

        New Risks of Automatic Speedtraps



Every security system brings about new threats. Here's an example:

"The RAC Foundation yesterday called for an urgent review of the first=20
fixed motorway speed cameras.

"Far from improving drivers' behaviour, motorists are now bunching at=20
high speeds between junctions 14-18 on the M4 in Wiltshire, said Edmund=20
King, the foundation's executive director.

"The cameras were introduced by the Wiltshire and Swindon Safety Camera=20
Partnership in an attempt to reduce accidents on a stretch of the=20
motorway.  But most motorists are now travelling at just under 79mph,=20
the speed at which they face being fined."

In response to automated speedtraps, drivers are adopting the obvious=20
tactic of driving just below the trigger speed for the cameras,=20
presumably on cruise control.  So instead of cars on the road traveling=20
at a spectrum of speeds with reasonable gaps between them, we are=20
seeing "pelotons" of cars traveling closely bunched together at the=20
same high speed, presenting unfamiliar hazards to each other and to=20
law-abiding slower road-users.

The result is that average speeds are going up, not down.


<http://www.telegraph.co.uk/news/main.jhtml;sessionid=3DNRVAJJYZDVRXVQFIQM=
=20
F?xml=3D/news/2005/04/25/ncam25.xml&sSheet=3D/portal/2005/04/25/%3Cbr%20/%3E=
=20
ixportal.html> or <http://tinyurl.com/7my9y>
<http://www.telegraph.co.uk/news/main.jhtml;sessionid=3D4BMMZNI41WICJQFIQM=
=20
GCM5OAVCBQUJVC?xml=3D/news/2004/04/23/nspeed23.xml> or=20
<http://tinyurl.com/7eoz9>


** *** ***** ******* *********** *************

              Crypto-Gram Reprints



Crypto-Gram is currently in its eighth year of publication.  Back=20
issues cover a variety of security-related topics, and can all be found=20
on <http://www.schneier.com/crypto-gram.html>.  These are a selection=20
of articles that appeared in this calendar month in other years.

Warrants as a Security Countermeasure
<http://www.schneier.com/crypto-gram-0405.html#1>

National Security Consumers
<http://www.schneier.com/crypto-gram-0405.html#9>

Encryption and Wiretapping
<http://www.schneier.com/crypto-gram-0305.html#1>

Unique E-Mail Addresses and Spam
<http://www.schneier.com/crypto-gram-0305.html#6>

Secrecy, Security, and Obscurity
<http://www.schneier.com./crypto-gram-0205.html#1>

Fun with Fingerprint Readers
<http://www.schneier.com./crypto-gram-0205.html#5>

What Military History Can Teach Network Security, Part 2
<http://www.schneier.com/crypto-gram-0105.html#1>

The Futility of Digital Copy Protection
<http://www.schneier.com/crypto-gram-0105.html#3>

Security Standards
<http://www.schneier.com/crypto-gram-0105.html#7>

Safe Personal Computing
<http://www.schneier.com/crypto-gram-0105.html#8>

Computer Security: Will we Ever Learn?
<http://www.schneier.com/crypto-gram-0005.html#1>

Trusted Client Software
<http://www.schneier.com/crypto-gram-0005.html#6>

The IL*VEYOU Virus (Title bowdlerized to foil automatic e-mail filters.)
<http://www.schneier.com/crypto-gram-0005.html#ilyvirus>

The Internationalization of Cryptography
<http://www.schneier.com/crypto-gram-9905.html#international>

The British discovery of public-key cryptography
<http://www.schneier.com/crypto-gram-9805.html#nonsecret>


** *** ***** ******* *********** *************

     Detecting Nuclear Material in Transport



One of the few good things that's coming out of the U.S. terrorism=20
policy is some interesting scientific research.  This paper discusses=20
detecting nuclear material in transport.

The authors believe that fixed detectors -- for example, at ports --=20
simply won't work.  Terrorists are more likely to use highly enriched=20
uranium (HEU), which is harder to detect, than plutonium. This=20
difficulty of detection is more based on its natural rate of reactivity=20
than on some technological hurdle.  "The gamma rays and neutrons useful=20
for detecting shielded HEU permit detection only at short distances=20
(2-4 feet or less) and require that there be sufficient time to count a=20
sufficient number of particles (several minutes to hours)."

The authors conclude that the only way to reliably detect shielded HEU=20
is to build detectors into the transport vehicles. These detectors=20
could take hours to record any radioactivity.

Of course, for this system to work you have to assume that the=20
terrorists will use commercial shipping services to transport nuclear=20
material.

<http://www.devabhaktuni.us/research/disarm.pdf>


** *** ***** ******* *********** *************

          The Potential for an SSH Worm



SSH, or secure shell, is the standard protocol for remotely accessing=20
UNIX systems.  It's used everywhere: universities, laboratories, and=20
corporations (particularly in data-intensive back office=20
services).  Thanks to SSH, administrators can stack hundreds of=20
computers close together into air-conditioned rooms and administer them=20
from the comfort of their desks.

When a user's SSH client first establishes a connection to a remote=20
server, it stores the name of the server and its public key in a=20
known_hosts database.  This database of names and keys allows the=20
client to more easily identify the server in the future.

There are risks to this database, though.  If an attacker compromises=20
the user's account, the database can be used as a hit-list of follow-on=20
targets.  And if the attacker knows the username, password, and key=20
credentials of the user, these follow-on targets are likely to accept=20
them as well.

A new paper from MIT explores the potential for a worm to use this=20
infection mechanism to propagate across the Internet.  Already=20
attackers are exploiting this database after cracking passwords.  The=20
paper also warns that a worm that spreads via SSH is likely to evade=20
detection by the bulk of techniques currently coming out of the worm=20
detection community.

While a worm of this type has not been seen since the first Internet=20
worm of 1988, attacks have been growing in sophistication and most of=20
the tools required are already in use by attackers.  It's only a matter=20
of time before someone writes a worm like this.

This is an easy one to fix, though.  One of the countermeasures=20
proposed in the paper is to store hashes of host names in the database,=20
rather than the names themselves.  This is similar to the way hashes of=20
passwords are stored in password databases, so that security need not=20
rely entirely on the secrecy of the database.  It solves the security=20
problem with no loss of functionality to the user.

The authors of the paper have worked with the open source community,=20
and version 4.0 of OpenSSH has the option of hashing the known-hosts=20
database.  There is also a patch for OpenSSH 3.9 that does the same=20
thing.  Unfortunately, the option is not turned on by default.

<http://nms.csail.mit.edu/projects/ssh/>
<http://nms.csail.mit.edu/projects/ssh/sshworm.pdf>

The fix:
<http://www.openbsd.org/cgi-bin/man.cgi?query=3Dssh_config>
<http://www.openbsd.org/cgi-bin/man.cgi?query=3Dssh-keygen>
<http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/hostfile.c?rev=3D1.=
=20
34&content-type=3Dtext/x-cvsweb-markup> or <http://tinyurl.com/8938c>


** *** ***** ******* *********** *************

                      News



License-plate scanning by helicopter:
<http://www.thenewspaper.com/news/03/320.asp>
This is an example of wholesale surveillance, and something I've=20
written about before.
<http://www.schneier.com/essay-061.html>
Of course, once the system is in place, it will be used for privacy=20
violations that we can't even conceive of.  The only way to maintain=20
security is not to field this sort of system in the first place.

A revision of the excellent paper by Daniel Solove and Chris Hoofnagle=20
that gave specific legislative proposals for privacy reform.
<http://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D699701>

"A Taxonomy of Privacy," by Daniel Solove.  Really good work.
<http://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D667622>

More failures in airport screening:
< http://www.cnn.com/2005/TRAVEL/04/16/airport.screeners.ap/>
My commentary on this is here:
<http://www.schneier.com/blog/archives/2005/04/failures_of_air.html>

The Department of Homeland Security is evaluating three different=20
systems to process exit visas.
<http://www.fcw.com/article88459-04-01-05-Web>
Properly evaluating this trade-off would look at the relative ease of=20
attacking the three systems, the relative costs of the three systems,=20
and the relative speed and convenience -- to the traveler -- of the=20
three systems.  My guess is that the system that requires the least=20
amount of interaction with a   person when boarding the plane is best.

Interesting law review article on the liabilities of having an open=20
wireless network:
<http://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D692881>

Universal automobile surveillance comes to the United Arab Emirates:
<http://www.thenewspaper.com/news/03/328.asp>
This kind of thing is also being implemented in the UK for insurance=20
purposes:
<http://icnewcastle.icnetwork.co.uk/lifestyle/finance/tm_objectid=3D153927=
=20
22&method=3Dfull&siteid=3D50081&headline=3Dtracking-down-those-insurance-cos=
ts=20
-name_page.html> or <http://tinyurl.com/6wmob>
<http://www.payasyoudriveinsurance.co.uk/>

A really good essay on security trade-offs by an anonymous CSO:
<http://www.csoonline.com/read/040105/undercover.html>

Two penguins going through airport security:
<http://www.thedenverchannel.com/slideshow/4402056/detail.html?qs=3D;s=3D1;w=
=20
=3D320> or <http://tinyurl.com/aju23>

Ants staging ambushes:
<http://www.nature.com/news/2005/050418/full/050418-11.html>

The U.S. State Department is considering implementing its RFID passport=20
in such a way as to require a master key from a reader before the=20
passport broadcasts any of its details.  The devil is in the details,=20
but this is an excellent idea.
<http://www.wired.com/news/privacy/0,1848,67333,00.html>
<http://www.schneier.com/blog/archives/2005/04/rfid_passport_s.html>

"The Emergence of a Global Infrastructure for Mass Registration and=20
Surveillance": a really interesting report.
<http://www.statewatch.org/news/2005/apr/icams-report.pdf>

It's an old story: users disable a security measure because it's=20
annoying, allowing an attacker to bypass the measure.  "A rape=20
defendant accused in a deadly courthouse rampage was able to enter the=20
chambers of the judge slain in the attack and hold the occupants=20
hostage because the door was unlocked and a buzzer entry system was not=20
activated, a sheriff's report says."  Security doesn't work unless the=20
users want it to work. This is true on the personal and national scale,=20
with or without technology.
<http://www.msnbc.msn.com/id/7423184>

Yet another PDF redacting failure: this one regarding classified=20
material in a U.S. report about the shooting of Italian secret agent=20
Nicola Calipari in Iraq.
<http://news.bbc.co.uk/go/em/fr/-/1/hi/world/europe/4504589.stm>
<http://vowe.net/archives/005838.html>
<http://www.livejournal.com/users/annafdd/110745.html>
<http://story.news.yahoo.com/news?tmpl=3Dstory&cid=3D535&ncid=3D535&e=3D3&u=
=3D/ap/=20
20050502/ap_on_re_eu/italy_us_iraq> or <http://tinyurl.com/cq7y2>

Nice essay about the implications of the ChoicePoint data theft (and=20
all the other data thefts, losses, and disclosures making headlines).
<http://www.csoonline.com/read/050105/choicepoint.html>

The U.S. government is considering another chief cybersecurity=20
position, this one at the Department of Homeland Security.  Sadly, this=20
isn't going to amount to anything. Yes, it's good to have a=20
higher-level official in charge of cybersecurity. But responsibility=20
without authority doesn't work.  A bigger bully pulpit isn't going to=20
help without a coherent plan behind it, and we have none.  The absolute=20
best thing the DHS could do for cybersecurity would be to coordinate=20
the U.S. government's enormous purchasing power and demand more secure=20
hardware and software.
<http://www.infoworld.com/article/05/04/20/HNhousesecurity_1.html>
<http://www.govtrack.us/congress/billtext.xpd?bill=3Dh109-285>

Nice essay on identity theft:
<http://members.optusnet.com.au/paul.mcgowan/phishing.html>

Company continues bad information security practices:
<http://www.baltimoresun.com/business/bal-bz.safenet05may05,1,3741390.st=20
ory>
My commentary:
<http://www.schneier.com/blog/archives/2005/05/company_continu.html>

The Onion takes on identity theft:
<http://www.theonion.com/news/index.php?issue=3D4118>


** *** ***** ******* *********** *************

         Biometric Passports in the U.K.



The UK government tried, and failed, to get a national ID. Now they're=20
adding biometrics to their passports.  According to the report:=20
"Financing for the Passport Office is planned to rise from =A3182 million=20
a year to =A3415 million a year by 2008 to cope with the introduction of=20
biometric information such as fingerprints.  A Home Office spokesman=20
said the aim was to cut out the 1,500 fraudulent applications found=20
through the postal system last year alone."

Okay, let's do the math. Eliminating 1,500 instances of fraud will cost=20
=A3233 million a year. That comes to =A3155,000 per instance of fraud.

Does this kind of security trade-off make sense to anyone?  Is there=20
absolutely nothing better the UK government can do to ensure security=20
and safety with =A3233 million a year?

Yes, adding additional biometrics to passports -- there's already a=20
picture -- will make them more secure.  But I don't think that the=20
additional security is worth the money and the additional risks. It's a=20
bad security trade-off.


<http://www.telegraph.co.uk/news/main.jhtml;sessionid=3DJNGZZXYX5WEYTQFIQM=
=20
FSM5OAVCBQ0JVC?xml=3D/news/2005/04/06/nelec506.xml> or=20
<http://tinyurl.com/bfsms>
<http://www.telegraph.co.uk/news/main.jhtml?xml=3D/news/2005/04/13/nid13.x=
=20
ml&sSheet=3D/portal/2005/04/13/ixportal.html> or <http://tinyurl.com/akccz>


** *** ***** ******* *********** *************

           Lighters Banned on Airplanes



Lighters are now banned on U.S. commercial flights, but not matches.

The senators who proposed the bill point to Richard Reid, who=20
unsuccessfully tried to light explosives on an airplane with=20
matches.  They were worried that a lighter might have worked.

That, of course, is silly.  The reason Reid failed is because he tried=20
to light the explosives in his seat, so he could watch the faces of=20
those around him.  If he'd gone into the lavatory and lit them in=20
private, he would have been successful.

Hence, the ban is silly.

But there's a serious problem here.  Airport security screeners are=20
much better at detecting explosives when the detonation mechanism is=20
attached.  Explosives without any detonation mechanism -- like Richard=20
Reid's -- are much harder to detect.  As are explosives carried by one=20
person and a detonation device carried by another.  I've heard that=20
this was the technique the Chechnyan women used to blow up a Russian=20
airplane.

<http://www.wtkr.com/Global/story.asp?S=3D3210493>


** *** ***** ******* *********** *************

                Counterpane News



Counterpane is offering managed DDOS protection, in alliance with Prolexic:
<http://www.counterpane.com/pr-20050516.html>

Schneier and Doug Howard, also of Counterpane, are speaking at the=20
Gartner IT Security Summit in Washington DC on June 6th:
<http://www.counterpane.com/gartner-dc.html>
<http://www.gartner.com/2_events/conferences/sec11.jsp>

Schneier is speaking at the Seoul Digital Forum on May 20th:
<http://www.seouldigitalforum.org>

Schneier is speaking at AusCERT, somewhere near Brisbane, on May 23rd:
<http://conference.auscert.org.au/conf2005/program_overview.php>

Schneier is speaking at Corporate Security 2005 in Helsinki on May 26th:
<http://www.teleware.fi/corpsec2004/ohjelma.html>

Schneier is speaking at the EPIC conference titled "National ID at the=20
Crossroads" in Washington, DC, on June 6th:
<http://www.epic.org/events/id/savethedate.html>

This is an interview with me from SecurityFocus:
<http://www.securityfocus.com/columnists/324>

I was recently interviewed on ITConversations:
<http://www.itconversations.com/shows/detail119.html>

And last month, my encryption algorithm Blowfish was mentioned on the=20
Fox show "24."  An alleged computer expert from the fictional=20
anti-terror agency CTU was trying to retrieve some files from a=20
terrorist's laptop.  This is the exchange between the agent and the=20
terrorist's girlfriend:

	"They used Blowfish algorithm."

	"How can you tell?"

	"By the tab on the file headers."

	"Can you decrypt it?"

	"CTU has a proprietary algorithm. It shouldn't take that long.  We'll=20
start by trying to hack the password.  Let's start with the basics.=20
Write down nicknames, birthdays, pets -- anything you think he might=20
have used."


** *** ***** ******* *********** *************

                 Wi-Fi Minefields



The U.S. is laying a minefield in Iraq that can be controlled by a=20
soldier with a wi-fi-enabled laptop.

Put aside arguments about the ethics and efficacy of landmines. Assume=20
they exist and are being used.  Given that, the question is whether=20
radio-controlled landmines are better or worse than regular landmines.=20
This comment, for example, seems to get it wrong: "'We're concerned the=20
United States is going to field something that has the capability of=20
taking the man out of the loop when engaging the target, ' said senior=20
researcher Mark Hiznay of Human Rights Watch.  'Or that we're putting a=20
19-year-old soldier in the position of pushing a button when a blip=20
shows up on a computer screen. '"

With conventional landmines, the man is out of the loop as soon as he=20
lays the mine.  Even a 19-year-old seeing a blip on a computer screen=20
is better than a completely automatic system.

Were I the U.S. military, I would be more worried whether the mines=20
could accidentally be triggered by radio interference.  I would be more=20
worried about the enemy jamming the radio control mechanism.

<http://www.usatoday.com/tech/news/2005-04-12-laptop-mines_x.htm>
<http://www.theinquirer.net/?article=3D22522>


** *** ***** ******* *********** *************

        The PITAC Report on CyberSecurity



I finally got around to reading the President's Information Technology=20
Advisory Committee (PITAC) report entitled "Cyber Security: A Crisis of=20
Prioritization" (dated February 2005).  The report looks at the current=20
state of federal involvement in cybersecurity research, and makes=20
recommendations for the future.  It's a good report, and one which the=20
administration would do well to listen to.

The report's recommendations are based on two observations.  The=20
observations are that 1) cybersecurity research is primarily focused on=20
current threats, and not long-term threats, and 2) there simply aren't=20
enough cybersecurity researchers, and no good mechanism for producing=20
them.  The federal government isn't doing enough to foster=20
cybersecurity research, and the effects of this shortfall will be felt=20
more in the long term than the short term.

To remedy this problem, the report makes four specific recommendations=20
(in much more detail than I summarize here).  One, the government needs=20
to increase funding for basic cybersecurity research.  Two, the=20
government needs to increase the number of researchers working in=20
cybersecurity.  Three, the government need to better foster the=20
transfer of technology from research to product development.  And four,=20
the government needs to improve its own cybersecurity coordination and=20
oversight.  Four good recommendations.

More specifically, the report lists ten technologies that need more=20
research. They are (not in any priority order):

	Authentication Technologies
	Secure Fundamental Protocols
	Secure Software Engineering and Software Assurance
	Holistic System Security
	Monitoring and Detection
	Mitigation and Recovery Methodologies
	Cyber Forensics
	Modeling and Testbeds for New Technologies
	Metrics, Benchmarks, and Best Practices
	Non-Technology Issues that Can Compromise Cyber Security

It's a good list, and I am especially pleased to see the tenth item --=20
one that is usually forgotten.  I would add something on the order of=20
"Dynamic Cyber Security Systems" -- I think we need serious basic=20
research in how systems should react to new threats and how to update=20
the security of already fielded systems -- but that's all I would change.

The report itself is a bit repetitive, but it's definitely worth skimming.

<http://www.nitrd.gov/pitac/reports/20050301_cybersecurity/cybersecurity=20
.pdf> or <http://tinyurl.com/79vj6>


** *** ***** ******* *********** *************

         State-Sponsored Identity Theft



In an Ohio sting operation at a strip bar, a 22-year-old student intern=20
with the United States Marshals Service was given a fake identity so=20
she could work undercover at the club.  But instead of giving her a=20
fabricated identity, the police gave her the identity of another woman=20
living in another Ohio city. And they didn't tell the other woman.

Oddly enough, this is legal. According to Ohio's identity theft law,=20
the police are allowed to do it.  Identity theft cannot be prosecuted=20
if:  "The person or entity using the personal identifying information=20
is a law enforcement agency, authorized fraud personnel, or a=20
representative of or attorney for a law enforcement agency or=20
authorized fraud personnel and is using the personal identifying=20
information in a bona fide investigation, an information security=20
evaluation, a pretext calling evaluation, or a similar matter."

I have to admit that I'm stunned.  I naively assumed that the police=20
would have a list of Social Security numbers that would never be given=20
to real people, numbers that could be used for purposes such as=20
this.  Or at least that they would use identities of people from other=20
parts of the country after asking for permission.  (I'm sure people=20
would volunteer to help out the police.)  It never occurred to me that=20
they would steal the identity of random citizens.  What could they be=20
thinking?

<http://www.officer.com/article/article.jsp?siteSection=3D5&id=3D22852>

The Ohio law:
<http://www.legislature.state.oh.us/bills.cfm?ID=3D126_HB_48_>


** *** ***** ******* *********** *************

                 Combating Spam



Spam is back in the news, and it has a new name.  This time it's=20
voice-over-IP spam, and it has the clever name of "spit" (spam over=20
Internet telephony).  Spit has the potential to completely ruin=20
VoIP.  No one is going to install the system if they're going to get=20
dozens of calls a day from audio spammers.  Or, at least, they're only=20
going to accept phone calls from a white list of previously known callers.

VoIP spam joins the ranks of e-mail spam, Usenet newsgroup spam,=20
instant message spam, cell phone text message spam, and blog comment=20
spam.  And, if you think broadly enough, these computer-network spam=20
delivery mechanisms join the ranks of computer telemarketing (phone=20
spam), junk mail (paper spam), billboards (visual space spam), and cars=20
driving through town with megaphones (audio spam).  It's all basically=20
the same thing -- unsolicited marketing messages -- and only by=20
understanding the problem at this level of generality can we discuss=20
solutions.

In general, the goal of advertising is to influence people.  Usually=20
it's to influence people to purchase a product, but it could just as=20
easily be to influence people to support a particular political=20
candidate or position.  Advertising does this by implanting a marketing=20
message into the brain of the recipient.  The mechanism of implantation=20
is simply a tactic.

Tactics for unsolicited marketing messages rise and fall in popularity=20
based on their cost and benefit.  If the benefit is significant, people=20
are willing to spend more.  If the benefit is small, people will only=20
do it if it is cheap.  A 30-second prime-time television ad costs 1.8=20
cents per adult viewer, a full-page color magazine ad about 0.9 cents=20
per reader.  A highway billboard costs 0.21 cents per car.  Direct mail=20
is the most expensive, at over 50 cents per third-class letter=20
mailed.  (That's why targeted mailing lists are so valuable; they=20
increase the per-piece benefit.)

Spam is such a common tactic not because it's particularly effective;=20
the response rates for spam are very low.  It's common because it's=20
ridiculously cheap.  Typically, spammers charge less than a hundredth=20
of a cent per e-mail.  (And that number is just what spamming houses=20
charge their customers to deliver spam; if you're a clever hacker, you=20
can build your own spam network for much less money.)  If it is worth=20
$10 for you to successfully influence one person -- to buy your=20
product, vote for your guy, whatever -- then you only need a 1 in a=20
100,000 success rate.  You can market really marginal products with spam.

So far, so good.  But the cost/benefit calculation is missing a=20
component: the "cost" of annoying people.  Everyone who is not=20
influenced by the marketing message is annoyed to some degree.  The=20
advertiser pays a partial cost for annoying people; they might boycott=20
his product.  But most of the time he does not, and the cost of the=20
advertising is paid by the person: the beauty of the landscape is=20
ruined by the billboard, dinner is disrupted by a telemarketer, spam=20
costs money to ship around the Internet and time to wade through,=20
etc.  (Note that I am using "cost" very generally here, and not just=20
monetarily. Time and happiness are both costs.)

This is why spam is so bad.  For each e-mail, the spammer pays a cost=20
and receives benefit.  But there is an additional cost paid by the=20
e-mail recipient.  Because so much spam is unwanted, that additional=20
cost is huge -- and it's a cost that the spammer never sees.  If=20
spammers could be made to bear the total cost of spam, then its level=20
would be more along the lines of what society would find acceptable.

This economic analysis is important, because it's the only way to=20
understand how effective different solutions will be.  This is an=20
economic problem, and the solutions need to change the fundamental=20
economics.  (The analysis is largely the same for VoIP spam, Usenet=20
newsgroup spam, blog comment spam, and so on.)

The best solutions raise the cost of spam.  Spam filters raise the cost=20
by increasing the amount of spam that someone needs to send before=20
someone will read it.  If 99% of all spam is filtered into trash, then=20
sending spam becomes 100 times more expensive.  This is also the idea=20
behind white lists -- lists of senders a user is willing to accept=20
e-mail from -- and blacklists: lists of senders a user is not willing=20
to accept e-mail from.

Filtering doesn't just have to be at the recipient's e-mail.  It can be=20
implemented within the network to clean up spam, or at the=20
sender.  Several ISPs are already filtering outgoing e-mail for spam,=20
and the trend will increase.

Anti-spam laws raise the cost of spam to an intolerable level; no one=20
wants to go to jail for spamming.  We've already seen some convictions=20
in the U.S.  Unfortunately, this only works when the spammer is within=20
the reach of the law, and is less effective against criminals who are=20
using spam as a mechanism to commit fraud.

Other proposed solutions try to impose direct costs on e-mail=20
senders.  I have seen proposals for e-mail "postage," either for every=20
e-mail sent or for every e-mail above a reasonable threshold.  I have=20
seen proposals where the sender of an e-mail posts a small bond, which=20
the receiver can cash if the e-mail is spam.  There are other proposals=20
that involve "computational puzzles": time-consuming tasks the sender's=20
computer must perform, unnoticeable to someone who is sending e-mail=20
normally, but too much for someone sending e-mail in bulk.  These=20
solutions generally involve re-engineering the Internet, something that=20
is not done lightly, and hence are in the discussion stages only.

All of these solutions work to a degree, and we end up with an arms=20
race.  Anti-spam products block a certain type of spam.  Spammers=20
invent a tactic that gets around those products.  Then the products=20
block that spam.  Then the spammers invent yet another type of=20
spam.  And so on.

Blacklisting spammer sites forced the spammers to disguise the origin=20
of spam e-mail.  People recognizing e-mail from people they knew, and=20
other anti-spam measures, forced spammers to hack into innocent=20
machines and use them as launching pads.  Scanning millions of e-mails=20
looking for identical bulk spam forced spammers to individualize each=20
spam message.  Semantic spam detection forced spammers to design even=20
more clever spam.  And so on.  Each defense is met with yet another=20
attack, and each attack is met with yet another defense.

Remember that when you think about host identification, or postage, as=20
an anti-spam measure.  Spammers don't care about tactics; they want to=20
send their e-mail.  Techniques like this will simply force spammers to=20
rely more on hacked innocent machines.  As long as the underlying=20
computers are insecure, we can't prevent spammers from sending.

This is the problem with another potential solution: re-engineering the=20
Internet to prohibit the forging of e-mail headers.  This would make it=20
easier for spam detection software to detect spamming IP addresses, but=20
spammers would just use hacked machines instead of their own computers.

Honestly, there's no end in sight for the spam arms race.  Currently=20
about 80 - 90% of email is spam, and that percentage is rising.  I am=20
continually battling with comment spam in my blog.  But even with all=20
that, spam is one of computer security's success stories.  The current=20
crop of anti-spam products work pretty well, if people are willing to=20
do the work to tune them.  I get almost no spam, and very few=20
legitimate e-mails end up in my spam trap.  I wish they would work=20
better -- Crypto-Gram is occasionally classified as spam by one service=20
or another, for example -- but they're working pretty well.  It'll be a=20
long time before spam stops clogging up the Internet, but at least=20
there are technologies to ensure that we don't have to look at it.


** *** ***** ******* *********** *************

              Comments from Readers



From: Keith Martin <[email protected]>
Subject:  Mitigating Identity Theft

In Europe (and in Ireland in particular) we have extensive rules for=20
dealing with what you refer to as "open[ing] a credit card account by=20
simply filling out a bunch of information on a form".  There's a legal=20
requirement on any bank or credit card company in Ireland to verify the=20
identity of any applicant for a bank account or a credit card using (at=20
least) two separate and different methods.

For example, one is usually a photo ID - passport or driver's license=20
are the most usual (most Irish people would have a passport, but I'm=20
not sure that option would work in the US), and the other is a proof of=20
address (e.g., a telephone or other utility bill).  It's quite possible=20
to get one or the other, but it would be difficult to get both.  Also,=20
the utility bill has to be no more than six weeks old, so the=20
possibility for using old addresses or fake addresses is limited=20
(although not entirely mitigated).

It's not 100% secure, but it's better than some of the systems used in=20
other countries.  The legislation was originally introduced to deter=20
money laundering, but had a useful duplicate purpose, which I know=20
(having asked them!) the legislators hadn't intended at the start.



From: Charles H Baker <[email protected]>
Subject: Mitigating Identity Theft

One thing I would like to bring to your attention is that once FACTA=20
goes into effect on June 1st, consumers will become responsible for the=20
fraudulent charges if they don't notify the financial institution=20
within 60, or in some cases 30, days.  This is very problematic because=20
most victims don't become aware that they are victims until more than=20
year has passed, FTC numbers.

In addition the FTC says that only 26% of ID theft is credit or=20
financial in nature.  The rest is healthcare fraud, tax fraud,=20
etc.  How would validating the transaction help if someone uses my=20
Social Security number to get a job, and then doesn't pay any=20
taxes?  The IRS is going to come looking for me!



From: Andrew Blank <[email protected]>
Subject: Mitigating Identity Theft

You make the point in recent Crypto-Grams that transaction=20
authentication, rather than user authentication, is the key point in=20
financial transactions.  The Dutch agree with you.  Here's what we've=20
been doing in Holland for the last few years with internet banking.

1. Bank customers have ATM cards with a chip that holds their PIN.

2. Internet banking customers have a challenge-response calculator (a=20
token). The calculator is not unique to the individual, but every=20
calculator must be unlocked by inserting the ATM card and entering the=20
PIN.  This personalizes the calculator to the user, as long as the ATM=20
card is inserted. Once unlocked, the calculator will go to sleep after=20
a few minutes and require the PIN to be re-entered to wake it up.

3. Users login to internet banking on the web by providing their bank=20
account number and the serial number (not the PIN, of course) of their=20
ATM card.  The bank provides a challenge (8 digits) which the user=20
enters into the calculator and replies with the computed 6-digit response.

4. At this point the user has access to the account; he can prepare --=20
but not send -- payments.  Typically the user pays accounts that are in=20
his bank address book.  Each new account entry to the address book=20
generates a challenge-response from the bank (and that probably also=20
means the user has to re-enter his PIN to wake up his calculator,=20
too).  If a user makes a large payment to an account that isn't in the=20
address book, then there is also a challenge-response required to=20
validate the receiving account details.

5. Finally, when all payments have been queued, the user selects "Send=20
to bank".  A list of all the queued transactions (payees and amount to=20
be paid) is displayed and a final challenge-response is required before=20
the batch of payments is sent.

This system isn't perfect, but it seems pretty good.  It gives any=20
man-in-the-middle a real difficulty to invent a payment and somehow=20
convince the user to authenticate a transaction that he didn't=20
originate.  There is obviously some extra work for the user, but in=20
return he gets pretty good assurance that he, and not some stranger, is=20
in charge of his money.



From: Andy Clark <[email protected]>
Subject: Mitigating Identity Theft

With regards to the liability for credit card fraud, this is changing=20
in the UK with the introduction of the chip and PIN system.  When we=20
make transactions, the card has to be inserted into a device and a PIN=20
entered for the transaction.  The good point of this is that the card=20
does not leave the person who is making the transaction; the charging=20
devices are commonly brought to the table of the restaurant, for example.

In addition to this, most of the card companies are changing their=20
terms and conditions to shift the liability onto the card holder and=20
also to give them the responsibility of keeping their card and PIN=20
safe.  Historically, if someone had a card stolen and reported it an=20
hour later, they were only liable for the first $50; now they are=20
liable for all transactions made in that hour.

For example, see some UK card terms and conditions:

	<http://www.firstdirect.com/legals/creditcard.shtml>
	<http://www.barclaycard.co.uk/Products/Apply/tandc.html>



From: [email protected]
Subject: Mitigating Identity Theft

In the Eighties and early Nineties I lived in Germany.  The bank system=20
there was far more advanced than what we have in the US now.  All of my=20
utility, subscription, and insurance bills were automatically deducted=20
from my account (after my one-time written authorization) and I had six=20
weeks to cancel any deduction for any reason. I did not have to write=20
checks; any criminal activity would have been far more suspicious.  The=20
use of chipcards as cashcards and my VISA card showing my photograph on=20
the front side were also little additions to the security.

Almost 20 years ago the security was higher there than it is now in the=20
US. My bank handed me a list of transaction authentication numbers=20
(TANs), each to be used only once.  For online banking I had to=20
authenticate myself with the usual username/pass-phrase combination and=20
also had to provide the next transaction number from the printed=20
list.  No malicious software could get into the drawer of my desk to=20
get the list.  Even secretly making a photocopy of the list was of=20
limited use, because I would notice it at typing in my next transaction=20
number.  Online spoofing the TAN, or MitM attacks could allow a=20
malicious person to change one single transaction, but it would be=20
immediately apparent to the legitimate user: his own transaction fails=20
or does not produce the expected account balance.  A telephone call=20
would prevent any damage.

The problem in the US is that there is so much competition for new=20
customers that even their tiniest inconvenience, like typing in a=20
transaction number and marking it used, may result in losing a few=20
customers.  It is simple math: if a very easy-to-use banking system=20
attracts more customers, and the resulting extra profit is more than=20
what the bank is expected to lose on fraud, then the insecure, simple=20
system will be used.  Especially if banks could push the loss to the=20
affected customers or merchants. As you say, the solution is making the=20
financial institutions liable for fraudulent transactions.



From: John <[email protected]>
Subject:  Mitigating Identity Theft

I am one of the senior technical architects on the point of sale team=20
of a national retail chain, and I can assure you that I am intimately=20
familiar with the credit authorization and settlement processes.

The way credit works is if we get a positive credit authorization from=20
Visa (that "auth code" you see printed on your receipts is evidence of=20
that), then Visa has assumed liability for the transaction, and we do=20
get paid through a process called settlement.

There are many network links to take an authorization request from POS=20
to the issuing Visa bank (and back again.)  Nothing is perfect, and=20
credit authorization systems sometimes go offline.  In that case we=20
have our call center process authorization requests over the phone=20
(normally they handle account questions, billing and/or dunning, or=20
authorization calls for cards that may require additional=20
processing.)  But this phone processing is very expensive in terms of=20
cashier time and customer frustration, not to mention the additional=20
load placed on the call center staff, so we have what is called a=20
"floor limit" -- any offline charge below this limit is automatically=20
approved by our corporation. That means we have assumed liability for=20
that charge.

Typically the floor limit is irrelevant -- we're online to credit far=20
more than 99% of the time.  But when we do go offline, the amount of=20
that limit serves to act as a throttle to the call center.  If we have=20
the limit set at $1.00, we might get a thousand phone calls a=20
minute.  And if we set it to $10,000.00, we might get one call an=20
hour.  So we vary that limit based on the risk we're willing to assume=20
vs. the capacity of our call center to process calls in an offline=20
situation.

If we assume liability for a transaction in the case where we were=20
offline to Visa, and there is a subsequent problem with the transaction=20
(the customer complains of fraudulent usage, or otherwise refuses to=20
pay) then Visa issues a "chargeback" to us, and we eat that loss.  No=20
auth code, no payment.  Needless to say, it's considered very important=20
that we keep the systems online to avoid this risk.

It is also important to keep the current value of the floor limit=20
secret because news of system failures spreads rapidly amongst=20
criminals; people with forged or fraudulent cards or cards for closed=20
or delinquent accounts descend upon our stores in droves if they think=20
we're offline.  Knowledge that they can safely spend $7.99 with=20
impunity vs. getting declined for an $8.00 charge leads to a lot of=20
little fraudulent transactions.  The problem isn't as dramatic in an=20
intermittent or transient failure mode, but in a disaster scenario=20
(such as after the Florida hurricanes) we get taken advantage of=20
quickly.  After restoring power and some telephone service (a working=20
cell phone is considered adequate), enough network bandwidth for online=20
credit authorizations tops the priority list for restoration.

Also, we're not the only link in the authorization chain.  For example,=20
we do not have direct lines to every Visa member bank.  We use a=20
third-party consolidator service to act as our gateway into the Visa=20
network.  And they also employ floor limits to control the volume in=20
their systems as well.  If they stand in for Visa authorization, then=20
we can reassign our chargebacks to them, since they are the ones liable=20
to us for any fraudulent charges they approve.

The same system even scales to Mom & Pop's store, where they have a=20
Verifone credit authorizing terminal.  If they get an auth code from=20
their Visa authorizing service, then they get paid.  If they take your=20
card on an old-fashioned imprinter and do not make a phone call, they=20
won't get paid for a fraudulent charge.  But if they call and write the=20
auth code on the carbonless slip and make an imprint of the card to=20
verify its presence, they do get paid.  It's in their contract.

For the most part, the credit companies eat the losses.  That's one of=20
the reasons why they charge exorbitant interest rates that are far over=20
prime -- to cover their risk.



From: Anton Holzherr <[email protected]>
Subject:  Mitigating Identity Theft

Transaction authentication (or lack of it) is not just an e-commerce=20
problem. In Switzerland there have been newspaper reports of abuses of=20
the banks payment systems where payments made by bank customers via=20
snail-mail have been redirected illicitly to third-party accounts. See=20
for example:

	<http://www.beo-news.ch/BNS2004/nov2004/klau17.htm>

In Switzerland, payments of Bills are not executed like in the U.S. by=20
sending a check to cover a creditor's claim for payment.  It works the=20
other way around. Each creditor sends you, together with his bill, a=20
deposit slip which contains his bank account details and a reference=20
number.  Using this information, the bank  customer issues a payment=20
order to the bank by going to the bank counter, using a secure=20
transaction over the internet, or by sending a payment order via snail=20
mail.

As a rule, the snail mail payment system uses authentication only for=20
the total sum of all the transactions contained in one  payment=20
batch.  The way it works, at the end of the month, Joe Bloggs collects=20
all his creditors' payment slips, adds up the total of all transaction=20
requests, fills in a lump sum payment order for the bank containing=20
this total, signs by hand and sends this payment order together with=20
all the payment slips to the bank in a sealed envelope.

What has been happening is that thieves steal these (paper) payment=20
orders in the middle of the night.  Using duplicated keys, slings or=20
sticky tape, they fish out the posted letters out of the outgoing post=20
boxes.  Then they substitute their own deposit slips, making sure the=20
total matches, and thus divert the money to their own accounts.  The=20
bank customer only finds out that he has been taken for a ride when he=20
receives his bank statement at the end of the month and discovers some=20
other person, not his creditors, have obtained the money.

This scam works because the banks only require a valid legal signature=20
authenticating the total amount, not one for each transaction processed.

What the newspaper article does not mention is how the thieves, who=20
divert the money into their own accounts, manage to stay anonymous.



From: Joseph K Huffman <[email protected]>
Subject: Lighters Banned on Airplanes

One of my hobbies is explosives.  I have a ATFE license to manufacture=20
high explosives.  I do so recreationally on a fairly regular basis.

I made the explosives for a recent event wearing gloves.  Then had to=20
rework some things later and did that without gloves.  A few minutes=20
later I handled a rifle case without cleaning up.  On April 13th, three=20
days later, that same rifle case went through airport security at Pasco=20
Washington.  I watched a TSA agent wipe down the handle and interior of=20
the case and test them for explosives.  Everything passed.  The rifle=20
case went with me to Albuquerque, New Mexico. On April 16th, that same=20
rifle case made the return trip and again went through a TSA screening=20
without questions.  I have numerous stories of this nature.  This is=20
only the most recent.

As near as I can determine, airport "security", from one end to the=20
other, only exists to make people feel better.  It does not represent a=20
deterrent to even a moderately skilled adversary.  We are wasting=20
something like $1.8 billion per year on this activity to make some=20
people feel better.



From: "Mike Glendinning" <[email protected]>
Subject: Two-Channel Authentication with Cell Phones and SMS

In the March Crypto-Gram, you write about the use by a bank of a=20
"two-channel" authentication mechanism involving cell phones and=20
SMS.  The technique is given further endorsement in the April issue by=20
the follow-up from Jonathan Tuliani.

I must however raise a word of caution.  As a consultant to the=20
telecoms industry, I have designed several systems using this technique=20
in the past, but believe it is rapidly becoming much less useful.  The=20
technique makes the assumption that the cellular network is closed,=20
well-controlled, and in particular envelops both the originator of the=20
message (e.g., the bank) and the user's cell phone.  But three=20
technological trends in the telecoms industry mean this assumption no=20
longer holds true:

1) The cellular industry is moving away from the use of proprietary=20
network-level protocols for the delivery of services such as SMS.  For=20
example, the newer Multimedia Messaging Service (MMS) is based on open=20
Internet protocols such as HTTP.  The knowledge needed for the creation=20
and spoofing of messages is therefore becoming much more widespread.

2) The closed and secure networks offered by the telcos are being=20
opened up and interconnected with the public Internet to offer the=20
"wireless web" experience as well as third-party messaging=20
services.  Therefore, these networks no longer represent a completely=20
separate and independent channel to the Internet.  The origination of=20
messages is becoming easier as it no longer requires a specialised and=20
dedicated network connection to the telco.

3) Older "dumb" handsets where the software is completely controlled by=20
the manufacturer and network operator are being replaced with "smart"=20
devices that are fully programmable by the end user.   There are now=20
many possibilities for trojan and man-in-the-middle attacks from rogue=20
applications running on the cell phone itself.  For example, with=20
smartphones using the Symbian operating system (and to a lesser extent=20
Java/J2ME) it is possible for applications to intercept all incoming=20
SMS messages as well as have full control over the user interface.

As you can see, it is simultaneously becoming easier to inject false=20
messages into the "two-channel" authentication mechanism as well as to=20
intercept valid ones.  Unfortunately, I find that these issues are not=20
very well understood by many in the telecoms industry, nor by those who=20
rely on this technology for the purposes of user authentication .

The lesson is, I suppose, that it's important to understand clearly all=20
the assumptions on which any security mechanism is based.  And that=20
these assumptions must be continuously re-evaluated in the light of a=20
changing environment.


** *** ***** ******* *********** *************

CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise.  You=20
can subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>.  Back issues are also=20
available at that URL.

Comments on CRYPTO-GRAM should be sent to=20
[email protected].  Permission to print comments is assumed=20
unless otherwise stated.  Comments may be edited for length and clarity.

Please feel free to forward CRYPTO-GRAM to colleagues and friends who=20
will find it valuable.  Permission is granted to reprint CRYPTO-GRAM,=20
as long as it is reprinted in its entirety.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is the author of=20
the best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography,"  and an inventor of the Blowfish and Twofish=20
algorithms.  He is founder and CTO of Counterpane Internet Security=20
Inc., and is a member of the Advisory Board of the Electronic Privacy=20
Information Center (EPIC).  He is a frequent writer and lecturer on=20
security topics.  See <http://www.schneier.com>.

Counterpane is the world's leading protector of networked information -=20
the inventor of outsourced security monitoring and the foremost=20
authority on effective mitigation of emerging IT threats. Counterpane=20
protects networks for Fortune 1000 companies and governments=20
world-wide.  See <http://www.counterpane.com>.

Crypto-Gram is a personal newsletter.  Opinions expressed are not=20
necessarily those of Counterpane Internet Security, Inc.

Copyright (c) 2005 by Bruce Schneier.=20