CRYPTO-GRAM, August 15, 2005 (part 1 of 2)
Bruce Schneier <[email protected]> Mon, 15 Aug 2005 04:58:43 -0500
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
August 15, 2005
by Bruce Schneier
Founder and CTO
Counterpane Internet Security, Inc.
[email protected]
<http://www.schneier.com>
<http://www.counterpane.com>
A free monthly newsletter providing summaries, analyses, insights, and
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at
<http://www.schneier.com/crypto-gram-0508.html>. These same essays
appear in the "Schneier on Security" blog:
<http://www.schneier.com/blog>. An RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Profiling
Cisco and ISS Harass Security Researcher
E-Mail Interception Decision Reversed
Stealing Imaginary Things
Crypto-Gram Reprints
Turning Cell Phones off in Tunnels
Searching Bags in Subways
Plagiarism and Academia: Personal Experience
RFID Passport Security Revisited
Risks of Losing Portable Devices
How to Not Fix the ID Problem
Secure Flight
News
Shoot-to-Kill
Counterpane News
Visa and Amex Drop CardSystems
Comments from Readers
** *** ***** ******* *********** *************
Profiling
Since the London bombings, there has been a lot of discussion about
profiling. To help, here is what I wrote on the subject in "Beyond
Fear" (pp. 133-7):
"Good security has people in charge. People are resilient. People can
improvise. People can be creative. People can develop on-the-spot
solutions. People can detect attackers who cheat, and can attempt to
maintain security despite the cheating. People can detect passive
failures and attempt to recover. People are the strongest point in a
security process. When a security system succeeds in the face of a new
or coordinated or devastating attack, it's usually due to the efforts
of people.
"On 14 December 1999, Ahmed Ressam tried to enter the U.S. by ferryboat
from Victoria Island, British Columbia. In the trunk of his car, he had
a suitcase bomb. His plan was to drive to Los Angeles International
Airport, put his suitcase on a luggage cart in the terminal, set the
timer, and then leave. The plan would have worked had someone not been
vigilant.
"Ressam had to clear customs before boarding the ferry. He had fake ID,
in the name of Benni Antoine Noris, and the computer cleared him based
on this ID. He was allowed to go through after a routine check of his
car's trunk, even though he was wanted by the Canadian police. On the
other side of the Strait of Juan de Fuca, at Port Angeles, Washington,
Ressam was approached by U.S. customs agent Diana Dean, who asked some
routine questions and then decided that he looked suspicious. He was
fidgeting, sweaty, and jittery. He avoided eye contact. In Dean's own
words, he was acting 'hinky.' More questioning -- there was no one else
crossing the border, so two other agents got involved -- and more hinky
behavior. Ressam's car was eventually searched, and he was finally
discovered and captured. It wasn't any one thing that tipped Dean off;
it was everything encompassed in the slang term "hinky." But the system
worked. The reason there wasn't a bombing at LAX around Christmas in
1999 was because a knowledgeable person was in charge of security and
paying attention.
"There's a dirty word for what Dean did that chilly afternoon in
December, and it's profiling. Everyone does it all the time. When you
see someone lurking in a dark alley and change your direction to avoid
him, you're profiling. When a storeowner sees someone furtively looking
around as she fiddles inside her jacket, that storeowner is profiling.
People profile based on someone's dress, mannerisms, tone of voice ...
and yes, also on their race and ethnicity. When you see someone running
toward you on the street with a bloody ax, you don't know for sure that
he's a crazed ax murderer. Perhaps he's a butcher who's actually
running after the person next to you to give her the change she forgot.
But you're going to make a guess one way or another. That guess is an
example of profiling.
"To profile is to generalize. It's taking characteristics of a
population and applying them to an individual. People naturally have an
intuition about other people based on different characteristics.
Sometimes that intuition is right and sometimes it's wrong, but it's
still a person's first reaction. How good this intuition is as a
countermeasure depends on two things: how accurate the intuition is and
how effective it is when it becomes institutionalized or when the
profile characteristics become commonplace.
"One of the ways profiling becomes institutionalized is through
computerization. Instead of Diana Dean looking someone over, a computer
looks the profile over and gives it some sort of rating. Generally
profiles with high ratings are further evaluated by people, although
sometimes countermeasures kick in based on the computerized profile
alone. This is, of course, more brittle. The computer can profile based
only on simple, easy-to-assign characteristics: age, race, credit
history, job history, et cetera. Computers don't get hinky feelings.
Computers also can't adapt the way people can.
"Profiling works better if the characteristics profiled are accurate.
If erratic driving is a good indication that the driver is intoxicated,
then that's a good characteristic for a police officer to use to
determine who he's going to pull over. If furtively looking around a
store or wearing a coat on a hot day is a good indication that the
person is a shoplifter, then those are good characteristics for a store
owner to pay attention to. But if wearing baggy trousers isn't a good
indication that the person is a shoplifter, then the store owner is
going to spend a lot of time paying undue attention to honest people
with lousy fashion sense.
"In common parlance, the term 'profiling' doesn't refer to these
characteristics. It refers to profiling based on characteristics like
race and ethnicity, and institutionalized profiling based on those
characteristics alone. During World War II, the U.S. rounded up over
100,000 people of Japanese origin who lived on the West Coast and
locked them in camps (prisons, really). That was an example of
profiling. Israeli border guards spend a lot more time scrutinizing
Arab men than Israeli women; that's another example of profiling. In
many U.S. communities, police have been known to stop and question
people of color driving around in wealthy white neighborhoods (commonly
referred to as 'DWB' -- Driving While Black). In all of these cases you
might possibly be able to argue some security benefit, but the
trade-offs are enormous: honest people who fit the profile can get
annoyed, or harassed, or arrested, when they're assumed to be attackers.
"For democratic governments, this is a major problem. It's just wrong
to segregate people into 'more likely to be attackers' and 'less likely
to be attackers' based on race or ethnicity. It's wrong for the police
to pull a car over just because its black occupants are driving in a
rich white neighborhood. It's discrimination.
"But people make bad security trade-offs when they're scared, which is
why we saw Japanese internment camps during World War II, and why there
is so much discrimination against Arabs in the U.S. going on today.
That doesn't make it right, and it doesn't make it effective security.
Writing about the Japanese internment, for example, a 1983 commission
reported that the causes of the incarceration were rooted in "race
prejudice, war hysteria, and a failure of political leadership." But
just because something is wrong doesn't mean that people won't continue
to do it.
"Ethics aside, institutionalized profiling fails because real attackers
are so rare: Active failures will be much more common than passive
failures. The great majority of people who fit the profile will be
innocent. At the same time, some real attackers are going to
deliberately try to sneak past the profile. During World War II, a
Japanese American saboteur could try to evade imprisonment by
pretending to be Chinese. Similarly, an Arab terrorist could dye his
hair blond, practice an American accent, and so on.
"Profiling can also blind you to threats outside the profile. If U.S.
border guards stop and search everyone who's young, Arab, and male,
they're not going to have the time to stop and search all sorts of
other people, no matter how hinky they might be acting. On the other
hand, if the attackers are of a single race or ethnicity, profiling is
more likely to work (although the ethics are still questionable). It
makes real security sense for El Al to spend more time investigating
young Arab males than it does for them to investigate Israeli families.
In Vietnam, American soldiers never knew which local civilians were
really combatants; sometimes killing all of them was the security
solution they chose.
"If a lot of this discussion is abhorrent, as it probably should be,
it's the trade-offs in your head talking. It's perfectly reasonable to
decide not to implement a countermeasure not because it doesn't work,
but because the trade-offs are too great. Locking up every Arab-looking
person will reduce the potential for Muslim terrorism, but no
reasonable person would suggest it. (It's an example of 'winning the
battle but losing the war.') In the U.S., there are laws that prohibit
police profiling by characteristics like ethnicity, because we believe
that such security measures are wrong (and not simply because we
believe them to be ineffective).
"Still, no matter how much a government makes it illegal, profiling
does occur. It occurs at an individual level, at the level of Diana
Dean deciding which cars to wave through and which ones to investigate
further. She profiled Ressam based on his mannerisms and his answers to
her questions. He was Algerian, and she certainly noticed that.
However, this was before 9/11, and the reports of the incident clearly
indicate that she thought he was a drug smuggler; ethnicity probably
wasn't a key profiling factor in this case. In fact, this is one of the
most interesting aspects of the story. That intuitive sense that
something was amiss worked beautifully, even though everybody made a
wrong assumption about what was wrong. Human intuition detected a
completely unexpected kind of attack. Humans will beat computers at
hinkiness-detection for many decades to come.
"And done correctly, this intuition-based sort of profiling can be an
excellent security countermeasure. Dean needed to have the training and
the experience to profile accurately and properly, without stepping
over the line and profiling illegally. The trick here is to make sure
perceptions of risk match the actual risks. If those responsible for
security profile based on superstition and wrong-headed intuition, or
by blindly following a computerized profiling system, profiling won't
work at all. And even worse, it actually can reduce security by
blinding people to the real threats. Institutionalized profiling can
ossify a mind, and a person's mind is the most important security
countermeasure we have."
A couple of other points (not from the book):
1. Whenever you design a security system with two ways through -- an
easy way and a hard way -- you invite the attacker to take the easy
way. Profile for young Arab males, and you'll get terrorists that are
old non-Arab females.
2. If we are going to increase security against terrorism, the young
Arab males living in our country are precisely the people we want on
our side. Discriminating against them in the name of security is not
going to make them more likely to help.
3. Despite what many people think, terrorism is not confined to young
Arab males. Shoe-bomber Richard Reid was British. Germaine Lindsay, one
of the 7/7 London bombers, was Afro-Caribbean. Here are some more
examples from a speech by the U.S. Secretary of Transportation Norman
Mineta:
"In 1986, a 32-year-old Irish woman, pregnant at the time, was about to
board an El Al flight from London to Tel Aviv when El Al security
agents discovered an explosive device hidden in the false bottom of her
bag. The woman's boyfriend -- the father of her unborn child -- had
hidden the bomb.
"In 1987, a 70-year-old man and a 25-year-old woman -- neither of whom
were Middle Eastern -- posed as father and daughter and brought a bomb
aboard a Korean Air flight from Baghdad to Thailand. En route to
Bangkok, the bomb exploded, killing all on board.
"In 1999, men dressed as businessmen (and one dressed as a Catholic
priest) turned out to be terrorist hijackers, who forced an Avianca
flight to divert to an airstrip in Colombia, where some passengers were
held as hostages for more than a year and a half."
The 2002 Bali terrorists were Indonesian. The Chechnyan terrorists who
downed the Russian planes were women. Timothy McVeigh and the Unabomber
were Americans. The Basque terrorists are Basque, and Irish terrorists
are Irish. The Tamil Tigers are Sri Lankan.
And many Muslims are not Arabs. Even worse, almost everyone who is Arab
is not a terrorist -- many people who look Arab are not even Muslims.
So not only are there an large number of false negatives -- terrorists
who don't meet the profile -- but there an enormous number of false
positives: innocents that do meet the profile.
Beyond Fear:
<http://www.schneier.com/bf.html>
U.S. Secretary of Transportation Mineta's speech:
<http://www.dot.gov/affairs/042002sp.htm>
Research into the security effectiveness of profiling versus random
searching:
<http://www.firstmonday.org/issues/issue7_10/chakrabarti>
** *** ***** ******* *********** *************
Cisco and ISS Harass Security Researcher
I've written about full disclosure, and how disclosing security
vulnerabilities is our best mechanism for improving security --
especially in a free-market system. (That essay is also worth reading
for a general discussion of the security trade-offs.) I've also written
about how security companies treat vulnerabilities as public-relations
problems first and technical problems second. This week at BlackHat,
security researcher Michael Lynn and Cisco demonstrated both points.
Lynn was going to present security flaws in Cisco's IOS, and Cisco went
to inordinate lengths to make sure that information never got into the
hands of the their consumers, the press, or the public. According to
the Wall Street Journal:
"Cisco threatened legal action to stop the conference's organizers from
allowing a 24-year-old researcher for a rival tech firm to discuss how
he says hackers could seize control of Cisco's Internet routers, which
dominate the market. Cisco also instructed workers to tear 20 pages
outlining the presentation from the conference program and ordered
2,000 CDs containing the presentation destroyed.
"In the end, the researcher, Michael Lynn, went ahead with a
presentation, describing flaws in Cisco's software that he said could
allow hackers to take over corporate and government networks and the
Internet, intercepting and misdirecting data communications. Mr. Lynn,
wearing a white hat emblazoned with the word "Good," spoke after
quitting his job at Internet Security Systems Inc. Wednesday. Mr. Lynn
said he resigned because ISS executives had insisted he strike key
portions of his presentation."
The complete story is even weirder than this. Initially, Cisco and ISS
were happy with Lynn presenting his research result. They changed
their minds at the last minute. Lynn gave an interview to Wired that
talks about some of the details; I am impressed with his integrity in
this matter.
Not being able to censor the information, Cisco decided to act as if it
were no big deal. This is from a SearchSecurity article:
"In a release shortly after the presentation, Cisco stated, "It is
important to note that the information Lynn presented was not a
disclosure of a new vulnerability or a flaw with Cisco IOS software.
Lynn's research explores possible ways to expand exploitations of known
security vulnerabilities impacting routers." And went on to state
"Cisco believes that the information Lynn presented at the BlackHat
conference today contained proprietary information and was illegally
obtained." The statement also refers to the fact that Lynn stated in
his presentation that he used a popular file decompresser to 'unzip'
the Cisco image before reverse engineering it and finding the flaw,
which is against Cisco's use agreement."
The Cisco propaganda machine certainly was working overtime that week.
Cisco and ISS also sued Lynn and BlackHat. The suit was settled the
next day, and it's worth reading Jennifer Granick's blog posts on the
negotiations. The agreement prohibited Lynn or BlackHat from talking
about this matter or distributing any presentation materials or
recordings of the presentation. Not that it mattered; copies of the
presentation slides -- the version with ISS's name on it, before they
changed their mind and objected to the talk -- are all over the Internet.
The security implications of this are enormous. If companies have the
power to censor information about their products they don't like, then
we as consumers have less information with which to make intelligent
buying decisions. If companies have the power to squelch vulnerability
information about their products, then there's no incentive for them to
improve security. (I've written about this in connection with physical
keys and locks.) If free speech is subordinate to corporate demands,
then we are all much less safe.
Full disclosure is good for society. But because it helps the bad guys
as well as the good guys (see my essay on secrecy and security for more
discussion of the balance), many of us have championed "responsible
disclosure" guidelines that give vendors a head start in fixing
vulnerabilities before they're announced.
The problem is that not all researchers follow these guidelines. And
laws limiting free speech do more harm to society than good. (In any
case, laws won't completely fix the problem; we can't get laws passed
in every possible country security researchers live.) So the only
reasonable course of action for a company is to work with researchers
who alert them to vulnerabilities, but also to assume that
vulnerability information will sometimes be released without prior warning.
I can't imagine the discussions inside Cisco that led them to act like
thugs. I can't figure out why they decided to attack Michael Lynn,
BlackHat, and ISS rather than turn the situation into a
public-relations success. I can't believe that they thought they could
have censored the information by their actions, or even that it was a
good idea.
Cisco's customers want information. They don't expect perfection, but
they want to know the extent of problems and what Cisco is doing about
them. They don't want to know that Cisco tries to stifle the
truth. This is from a Computerworld article:
"Joseph Klein, senior security analyst at the aerospace electronic
systems division for Honeywell Technology Solutions, said he helped
arrange a meeting between government IT professionals and Lynn after
the talk. Klein said he was furious that Cisco had been unwilling to
disclose the buffer-overflow vulnerability in unpatched routers. 'I can
see a class-action lawsuit against Cisco coming out of this," Klein said.'"
ISS didn't come out of this looking very good, either. From a Wired
article:
"'A few years ago it was rumored that ISS would hold back on certain
things because (they're in the business of) providing solutions,'
[Ali-Reza] Anghaie, [a senior security engineer with an aerospace firm,
who was in the audience,] said. 'But now you've got full public
confirmation that they'll submit to the will of a Cisco or Microsoft,
and that's not fair to their customers.... If they're willing to back
down and leave an employee ... out to hang, well what are they going to
do for customers?'"
Despite their thuggish behavior, this has been a public-relations
disaster for Cisco and ISS. Now it doesn't matter what they say -- we
won't believe them. We know that the public-relations department
handles their security vulnerabilities, and not the engineering
department. We know that they think squelching information and muzzling
researchers is more important than informing the public. They could
have shown that they put their customers first, but instead they
demonstrated that short-sighted corporate interests are more important
than being a responsible corporate citizen.
And these are the people building the hardware that runs much of our
infrastructure? Somehow, I don't feel very secure right now.
In the weeks after this event, it seemed to me that ISS was pursuing
this out of malice. With Cisco I think it was simple stupidity, but I
think it's malice with ISS.
Of course, hackers are working overtime to reconstruct Lynn's attack
and write an exploit. This, of course, means that we're in much more
danger of there being a worm that makes use of this vulnerability.
The sad thing is that we could have avoided this. If Cisco and ISS had
simply let Lynn present his work, it would have been just another
obscure presentation amongst the sea of obscure presentations that is
BlackHat. By attempting to muzzle Lynn, the two companies ensured that
1) the vulnerability was the biggest story of the conference, and 2)
some group of hackers would turn the vulnerability into exploit code
just to get back at them.
News articles:
<http://online.wsj.com/public/article/0,,SB112251394301198260-2zgDRmLtWg
PF5vKgFn1qYJBjaG0_20050827,00.html?mod=blogs> or <http://tinyurl.com/82y9e>
<http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci
1111389,00.html?track=NL-358&ad=523843> or <http://tinyurl.com/74w8f>
<http://www.computerworld.com/securitytopics/security/story/0,10801,1035
39,00.html> or <http://tinyurl.com/bczlk>
<http://www.wired.com/news/privacy/0,1848,68328,00.html> or
<http://tinyurl.com/cytbd>
<http://news.zdnet.co.uk/internet/security/0,39020375,39211011,00.htm>
<http://www.securityfocus.com/news/11259>
<http://hosted.ap.org/dynamic/stories/C/CISCO_SECURITY_CRACKDOWN?SITE=AP
WEB&SECTION=HOME&TEMPLATE=DEFAULT> or <http://tinyurl.com/8oyxh>
<http://news.zdnet.co.uk/0,39020330,39211231,00.htm>
<http://www.wired.com/news/politics/0,1283,68356,00.html>
<http://www.theregister.co.uk/2005/08/02/cisco_exploits/>
<http://news.zdnet.co.uk/internet/security/0,39020375,39212014,00.htm>
Lynn's Wired interview:
<http://www.wired.com/news/privacy/0,1848,68365,00.html>
Commentary:
<http://blogs.businessweek.com/the_thread/techbeat/archives/2005/07/the_
black_hats.html> or <http://tinyurl.com/85q74>
<http://www.eweek.com/article2/0,1895,1842310,00.asp>
<http://searchsecurity.techtarget.com/columnItem/0,294698,sid14_gci11127
73,00.html?track=NL-358&ad=525032HOUSE> or <http://tinyurl.com/b8u9o>
<http://www.computerworld.com/newsletter/0,4902,103634,00.html> or
<http://tinyurl.com/8kcll>
<http://searchsecurity.techtarget.com/columnItem/0,294698,sid14_gci11137
55,00.html> or <http://tinyurl.com/dueur>
Jennifer Granick's blog posts:
<http://www.granick.com/archive/2005_08_01_theshout_archive.html#1123029
21362405957> or <http://tinyurl.com/bykzw>
<http://www.granick.com/archive/2005_08_01_theshout_archive.html#1123118
06179768898> or <http://tinyurl.com/8d2ut>
<http://www.granick.com/archive/2005_08_01_theshout_archive.html#1123200
79983935922> or <http://tinyurl.com/buqfx>
<http://www.granick.com/archive/2005_08_01_theshout_archive.html#1123305
15113516813> or <http://tinyurl.com/a5emv>
A video of Cisco/ISS ripping pages out of the BlackHat conference
proceedings:
<http://www.makezine.com/blog/archive/2005/08/video_of_ciscoi.html>
My essays on full disclosure:
<http://www.schneier.com/crypto-gram-0111.html#1>
<http://www.schneier.com/crypto-gram-0203.html#2>
My essay on secrecy and security:
<http://www.schneier.com/crypto-gram-0205.html#1>
My essay on keys and locks:
<http://www.schneier.com/crypto-gram-0302.html#1>
Copies of Lynn's presentation, or maybe a cease-and-desist letter:
<http://www.infowarrior.org/users/rforno/lynn-cisco.pdf>
<http://www.jwdt.com/~paysan/lynn-cisco.pdf>
<http://www.infowarrior.org/users/rforno/lynn-cisco.pdf>
<http://www.purpleandgrey.com/free/lynn-cisco.pdf>
<http://cryptome.org/lynn-cisco.zip>
<http://www.securitylab.ru/_Exploits/2005/07/lynn-cisco.pdf>
<http://www.jwdt.com/~paysan/lynn-cisco.pdf>
<http://files.bitchx.ru/index.php?dir=ebooks/&file=lynn-cisco.pdf>
<http://s48.yousendit.com/d.aspx?id=1EOE4MPD1E6U53MYQE6ROJID0R>
<http://www.megaupload.com/?d=31GTUIFR>
<http://www.dfconsultants.com/lynn-cisco.pdf>
<http://www.security.nnov.ru/files/lynn-cisco.pdf>
<http://www.mininova.org/get/81889>
<http://www.stephencollins.org/library/linn-cisco.pdf>
<http://teknews.net/~radio/lynn-cisco.pdf>
<http://snafu.priv.at/download/lynn-cisco.pdf>
Photographs of Lynn's actual presentation slides were here:
<http://www.tomsnetworking.com/Sections-article131.php>
Now they're here:
<http://42.pl/lynn/>
Someone is setting up a legal defense fund for Lynn. Send donations via
PayPal to [email protected]. (Does anyone know the URL?) According to
BoingBoing, donations not used to defend Lynn will be donated to the EFF.
<http://www.boingboing.net/2005/07/30/mike_lynn_presentati.html>
** *** ***** ******* *********** *************
E-Mail Interception Decision Reversed
A U.S. federal appeals court has ruled that the interception of e-mail
in temporary storage violates the federal wiretap act, reversing an
earlier court opinion.
Basically, different privacy laws protect electronic communications in
transit and data in storage; the former is protected much more than the
latter. E-mail stored by the sender or the recipient is obviously data
in storage. But what about e-mail on its way from the sender to the
receiver? On the one hand, it's obviously communications on
transit. But the government argued that it's actually stored on
various computers as it wends its way through the Internet; hence it's
data in storage.
The initial court decision in this case sided with the
government. Judge Lipez wrote an inspired dissent in the original
opinion. In the rehearing _en banc_ (more judges), he wrote the
opinion for the majority which overturned the earlier opinion.
The opinion itself is long, but well worth reading. It's well
reasoned, and reflects extraordinary understanding and attention to
detail. And a great last line: "If the issue presented be
'garden-variety'... this is a garden in need of a weed killer."
I participated in an Amicus Curiae ("friend of the court") brief in the
case.
There's a larger issue here, and it's the same one that the
entertainment industry used to greatly expand copyright law in
cyberspace. They argued that every time a copyrighted work is moved
from computer to computer, or CD-ROM to RAM, or server to client, or
disk drive to video card, a "copy" is being made. This ridiculous
definition of "copy" has allowed them to exert far greater legal
control over how people use copyrighted works.
The ruling:
<http://www.epic.org/privacy/councilman/kerr_amicus.pdf>
Summary of the case and privacy implications:
<http://www.epic.org/privacy/councilman/>
My brief:
<http://www.csoonline.com/read/080105/debrief.html>
A brief by six different civil liberties organizations:
<http://www.epic.org/privacy/councilman/kerr_amicus.pdf>
** *** ***** ******* *********** *************
Stealing Imaginary Things
There's a new Trojan that tries to steal World of Warcraft passwords.
That reminded me of people paying programmers to find exploits to make
virtual money in multiplayer online games, and then selling the
proceeds for real money.
And here's a page about ways people steal fake money in the online game
Neopets, including cookie grabbers, fake login pages, fake contests,
social engineering, and pyramid schemes.
I regularly say that every form of theft and fraud in the real world
will eventually be duplicated in cyberspace. Perhaps every method of
stealing real money will eventually be used to steal imaginary money, too.
<http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.wowcraf
t.html> or <http://tinyurl.com/djkth>
<http://www.1up.com/do/feature?cId=3141815>
<http://star-girl.org/pages/reads/neopets/avoidscams.php>
** *** ***** ******* *********** *************
Crypto-Gram Reprints
Crypto-Gram is currently in its seventh year of publication. Back
issues cover a variety of security-related topics, and can all be found
on <http://www.schneier.com/crypto-gram.html>. These are a selection
of articles that appeared in this calendar month in other years.
Bob on Board:
<http://www.schneier.com/crypto-gram-0408.html#1>
Alibis and the Kindness of Strangers:
<http://www.schneier.com/crypto-gram-0408.html#3>
Houston Airport Rangers:
<http://www.schneier.com/crypto-gram-0408.html#7>
Websites, Passwords, and Consumers:
<http://www.schneier.com/crypto-gram-0408.html#8>
Flying on Someone Else's Airplane Ticket:
<http://www.schneier.com/crypto-gram-0308.html#6>
Hidden Text in Computer Documents:
<http://www.schneier.com/crypto-gram-0308.html#8>
Palladium and the TCPA:
<http://www.schneier.com/crypto-gram-0208.html#1>
Arming Airplane Pilots:
<http://www.schneier.com/crypto-gram-0208.html#8>
Code Red:
<http://www.schneier.com/crypto-gram-0108.html#1>
Protecting Copyright in the Digital World:
<http://www.schneier.com/crypto-gram-0108.html#7>
Vulnerabilities, Publicity, and Virus-Based Fixes:
<http://www.schneier.com/crypto-gram-0008.html#2>
Bluetooth:
<http://www.schneier.com/crypto-gram-0008.html#8>
A Hardware DES Cracker:
<http://www.schneier.com/crypto-gram-9808.html#descracker>
Biometrics: Truths and Fictions:
<http://www.schneier.com/crypto-gram-9808.html#biometrics>
Back Orifice 2000:
<http://www.schneier.com/crypto-gram-9908.html#BackOrifice2000>
Web-Based Encrypted E-Mail:
<http://www.schneier.com/crypto-gram-9908.html#Web-BasedEncryptedE-Mail>
** *** ***** ******* *********** *************
Turning Cell Phones off in Tunnels
In response to the London bombings, officials turned off cell phones in
tunnels around New York City, in an attempt to thwart bombers who might
use cell phones as remote triggering devices. (Phone service has been
restored in two of the four tunnels. As far as I know, it is still not
available in the other two.)
This is as idiotic as it gets. It's a perfect example of what I call
"movie plot security": imagining a particular scenario rather than
focusing on the broad threats. It's completely useless if a terrorist
uses something other than a cell phone: a kitchen timer, for example.
Even worse, it harms security in the general case. Have people
forgotten how cell phones saved lives on 9/11? Communication benefits
the defenders far more than it benefits the attackers.
<http://www.nytimes.com/reuters/technology/tech-security-cellphones.html>
<http://www.ny1.com/ny1/content/index.jsp?stid=1&aid=52050>
<http://www.computerworld.com/mobiletopics/mobile/story/0,10801,103125,0
0.html> or <http://tinyurl.com/72g8h>
** *** ***** ******* *********** *************
Searching Bags in Subways
The New York City police will begin randomly searching people's bags on
subways, buses, commuter trains, and ferries. Other cities are
following suit.
If the choice is between random searching and profiling, then random
searching is a more effective security countermeasure. But are some
enormous trade-offs in liberty. And I don't think we're getting very
much security in return. Especially considering that passengers are
free to turn around and leave the subway station if they don't want to
be searched.
"Okay guys; here are your explosives. If one of you gets singled out
for a search, just turn around and leave. And then go back in via
another entrance, or take a taxi to the next subway stop."
(To be fair, while that was reported in the news, I have not heard from
anyone who has tried to refuse a search and leave.)
And I don't think they'll be truly random, either. I think the police
doing the searching will profile, because that's what happens.
It's another "movie plot threat." It's another "public relations
security system." It's a waste of money, it substantially reduces our
liberties, and it won't make us any safer.
Final note: I often get comments along the lines of "Stop criticizing
stuff; tell us what we should do." My answer is always the same.
Counterterrorism is most effective when it doesn't make arbitrary
assumptions about the terrorists' plans. Stop searching bags on the
subways, and spend the money on 1) intelligence and investigation --
stopping the terrorists regardless of what their plans are, and 2)
emergency response -- lessening the impact of a terrorist attack,
regardless of what the plans are. Countermeasures that defend against
particular targets, or assume particular tactics, or cause the
terrorists to make insignificant modifications in their plans, or that
surveil the entire population looking for the few terrorists, are
largely not worth it.
<http://www.nytimes.com/2005/07/21/nyregion/21cnd-security.html>
<http://www.washingtonpost.com/wp-dyn/content/article/2005/07/21/AR20050
72101127_pf.html> or <http://tinyurl.com/aowbf>
A Citizen's Guide to Refusing New York Subway Searches:
<http://www.flexyourrights.org/subway/>
** *** ***** ******* *********** *************
Plagiarism and Academia: Personal Experience
A paper published in the December 2004 issue of the SIGCSE Bulletin,
"Cryptanalysis of some encryption/cipher schemes using related key
attack," by Khawaja Amer Hayat, Umar Waqar Anis, and S.
Tauseef-ur-Rehman, is the same as a paper that John Kelsey, David
Wagner, and I published in 1997.
It's clearly plagiarism. Sentences have been reworded or summarized a
bit and many typos have been introduced, but otherwise it's the same
paper. It's copied, with the same section, paragraph, and sentence
structure -- right down to the same mathematical variable names. It has
the same quirks in the way references are cited. And so on.
We wrote two papers on the topic; this is the second. They don't list
either of our papers in their bibliography. They do have a lurking
reference to "[KSW96]" in the body of their introduction and design
principles, presumably copied from our text; but a full citation for
"[KSW96]" isn't in their bibliography. Perhaps they were worried that
one of the referees would read the papers listed in their bibliography,
and notice the plagiarism.
The three authors are from the International Islamic University in
Islamabad, Pakistan. The third author, S. Tauseef-Ur-Rehman, is a
department head (and faculty member) in the Telecommunications
Engineering Department at this Pakistani institution. If you believe
his story -- which is probably correct -- he had nothing to do with the
research, but just appended his name to a paper by two of his students.
(This is not unusual; it happens all the time in universities all over
the world.) But that doesn't get him off the hook. He's still
responsible for anything he puts his name on.
And we're not the only ones. The same three authors plagiarized a paper
by French cryptographer Serge Vaudenay and others. And one of my blog
readers found a third plagiarized paper, and potentially a fourth.
I wrote to the editor of the SIGCSE Bulletin, who removed the paper
from their website and demanded official letters of admission and
apology. They said that they would ban them from submitting again, but
have since backpedaled. Mark Mandelbaum, Director of the Office of
Publications at ACM, now says that ACM has no policy on plagiarism and
that nothing additional will be done. I've also written to
Springer-Verlag, the publisher of my original paper.
I don't blame the journals for letting these papers through. I've
refereed papers, and it's pretty much impossible to verify that a piece
of research is original. We're largely self-policing.
Mostly, the system works. These three have been found out, and should
be fired and/or expelled. Certainly ACM should ban them from submitting
anything, and I am very surprised at their claim that they have no
policy with regards to plagiarism. Academic plagiarism is serious
enough to warrant that level of response. I don't know if the system
works in Pakistan, though. I hope it does. These people knew the risks
when they did it. And then they did it again.
If I sound angry, I'm not. I'm more amused. I've heard of researchers
from developing countries resorting to plagiarism to pad their CVs, but
I'm surprised to see it happen to me. I mean, really; if they were
going to do this, wouldn't it have been smarter to pick a more obscure
author?
And it's nice to know that our work is still considered relevant eight
years later.
My paper:
<http://www.schneier.com/paper-relatedkey.html>
The plagiarized version:
<http://portal.acm.org/citation.cfm?doid=1041624.1041665>
Another paper:
<http://lasecwww.epfl.ch/php_code/publications/search.php?ref=CHVV03>
The plagiarized version:
<http://www.ansinet.org/fulltext/itj/itj33327-331.pdf>
A third paper:
<http://www.iki.fi/vph/files/rtp_security.pdf>
The plagiarized version:
<http://www.ansinet.org/fulltext/itj/itj33311-314.pdf>
The apologies are at the bottom of this page:
<http://www.schneier.com/paper-relatedkey-p.html>
There is a lot of discussion, much of it from students at the
International Islamic University, in the comments section of my blog post:
<http://www.schneier.com/blog/archives/2005/08/plagiarism_and.html>
And there's some news about the incident. (Note that my name is
completely wrong.)
<http://www.onlinenews.com.pk/details.php?id=85519>
** *** ***** ******* *********** *************
RFID Passport Security Revisited
I've written previously about RFID chips in passports. Two recent
articles summarize the latest State Department proposal, and it looks
pretty good. They're addressing privacy concerns, and they're doing it
right.
The most important feature they've designed is an access-control system
for the RFID chip. The data on the chip is encrypted, and the key is
printed on the passport. The officer swipes the passport through an
optical reader to get the key, and then the RFID reader uses the key to
communicate with the RFID chip. This means that the passport-holder can
control who has access to the information on the chip; someone cannot
skim information from the passport without first opening it up and
reading the information inside. Good security.
The new design also includes a thin radio shield in the cover,
protecting the chip when the passport is closed. More good security.
If the State Department implements these features (an assumption at
this point), and the features work as advertised (a big "if," I grant
you), then I am no longer opposed to the idea. And, more importantly,
we have an example of an RFID identification system with good privacy
safeguards. We should demand that any other RFID identification cards
have similar privacy safeguards.
<http://www.usatoday.com/travel/news/2005-08-08-electronic-passports_x.h
tm> or <http://tinyurl.com/bgclm>
<http://www.wired.com/news/privacy/0,1848,68451,00.html?tw=wn_tophead_2>
My previous writings:
<http://www.schneier.com/essay-060.html>
<http://www.schneier.com/blog/archives/2004/10/rfid_passports.html>
<http://www.schneier.com/blog/archives/2005/04/rfid_passport_s.html>
** *** ***** ******* *********** *************
Risks of Losing Portable Devices
As PDAs become more powerful, and memory becomes cheaper, more people
are carrying around a lot of personal information in an easy-to-lose
format.
I've noticed this in my own life. If I didn't make a special effort to
limit the amount of information on my Treo, it would include detailed
scheduling information from the past six years. My small laptop would
include every e-mail I've sent and received in the past dozen years.
And so on. A lot of us are carrying around an enormous amount of very
personal data.
And some of us are carrying around personal data about other people, too.
There are several ways to deal with this -- password protection and
encryption, of course. More recently, some communications devices can
be remotely erased if lost.
<http://www.washingtonpost.com/wp-dyn/content/article/2005/07/24/AR20050
72401135.html> or <http://tinyurl.com/drnap>
** *** ***** ******* *********** *************
How to Not Fix the ID Problem
Several of the 9/11 terrorists had Virginia driver's licenses in fake
names. These were not forgeries; these were valid Virginia IDs that
were illegally sold by Department of Motor Vehicle workers.
So what did Virginia do to correct the problem? They required more
paperwork in order to get an ID.
But the problem wasn't that it was too easy to get an ID. The problem
was that insiders were selling them illegally. Which is why the
Virginia "solution" didn't help, and the problem remains:
"The manager of the Virginia Department of Motor Vehicles office at
Springfield Mall was charged yesterday with selling driver's licenses
to illegal immigrants and others for up to $3,500 apiece.
"The arrest of Francisco J. Martinez marked the second time in two
years that a Northern Virginia DMV employee was accused of fraudulently
selling licenses for cash. A similar scheme two years ago at the DMV
office in Tysons Corner led to the guilty pleas of two employees."
And after we spend billions on the REAL ID act, and require even more
paperwork to get a state ID, the problem will still remain.
<http://www.washingtonpost.com/wp-dyn/content/article/2005/07/12/AR20050
71201421.html> or <http://tinyurl.com/cr4w7>
Virginia license requirements:
<http://www.dmvnow.com/webdoc/pdf/dmv141.pdf>
** *** ***** ******* *********** *************
This issue of Crypto-Gram has been divided into two e-mails, because
long e-mails get cought in too many spam traps. The rest of the issue
will arrive soon. If you don't receive it, you can always find
Crypto-Gram on the web: <http://www.schneier.com/crypto-gram-0508.html>.
Copyright (c) 2005 by Bruce Schneier.