CRYPTO-GRAM, August 15, 2005 (part 1 of 2)

Bruce Schneier <[email protected]> Mon, 15 Aug 2005 04:58:43 -0500
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

                August 15, 2005

               by Bruce Schneier
                Founder and CTO
       Counterpane Internet Security, Inc.
            [email protected]
            <http://www.schneier.com>
           <http://www.counterpane.com>


A free monthly newsletter providing summaries, analyses, insights, and 
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit 
<http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at 
<http://www.schneier.com/crypto-gram-0508.html>.  These same essays 
appear in the "Schneier on Security" blog: 
<http://www.schneier.com/blog>.  An RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
      Profiling
      Cisco and ISS Harass Security Researcher
      E-Mail Interception Decision Reversed
      Stealing Imaginary Things
      Crypto-Gram Reprints
      Turning Cell Phones off in Tunnels
      Searching Bags in Subways
      Plagiarism and Academia: Personal Experience
      RFID Passport Security Revisited
      Risks of Losing Portable Devices
      How to Not Fix the ID Problem
      Secure Flight
      News
      Shoot-to-Kill
      Counterpane News
      Visa and Amex Drop CardSystems
      Comments from Readers


** *** ***** ******* *********** *************

                     Profiling



Since the London bombings, there has been a lot of discussion about 
profiling. To help, here is what I wrote on the subject in "Beyond 
Fear" (pp. 133-7):

"Good security has people in charge. People are resilient. People can 
improvise. People can be creative. People can develop on-the-spot 
solutions. People can detect attackers who cheat, and can attempt to 
maintain security despite the cheating. People can detect passive 
failures and attempt to recover. People are the strongest point in a 
security process. When a security system succeeds in the face of a new 
or coordinated or devastating attack, it's usually due to the efforts 
of people.

"On 14 December 1999, Ahmed Ressam tried to enter the U.S. by ferryboat 
from Victoria Island, British Columbia. In the trunk of his car, he had 
a suitcase bomb. His plan was to drive to Los Angeles International 
Airport, put his suitcase on a luggage cart in the terminal, set the 
timer, and then leave. The plan would have worked had someone not been 
vigilant.

"Ressam had to clear customs before boarding the ferry. He had fake ID, 
in the name of Benni Antoine Noris, and the computer cleared him based 
on this ID. He was allowed to go through after a routine check of his 
car's trunk, even though he was wanted by the Canadian police. On the 
other side of the Strait of Juan de Fuca, at Port Angeles, Washington, 
Ressam was approached by U.S. customs agent Diana Dean, who asked some 
routine questions and then decided that he looked suspicious. He was 
fidgeting, sweaty, and jittery. He avoided eye contact. In Dean's own 
words, he was acting 'hinky.' More questioning -- there was no one else 
crossing the border, so two other agents got involved -- and more hinky 
behavior. Ressam's car was eventually searched, and he was finally 
discovered and captured. It wasn't any one thing that tipped Dean off; 
it was everything encompassed in the slang term "hinky." But the system 
worked. The reason there wasn't a bombing at LAX around Christmas in 
1999 was because a knowledgeable person was in charge of security and 
paying attention.

"There's a dirty word for what Dean did that chilly afternoon in 
December, and it's profiling. Everyone does it all the time. When you 
see someone lurking in a dark alley and change your direction to avoid 
him, you're profiling. When a storeowner sees someone furtively looking 
around as she fiddles inside her jacket, that storeowner is profiling. 
People profile based on someone's dress, mannerisms, tone of voice ... 
and yes, also on their race and ethnicity. When you see someone running 
toward you on the street with a bloody ax, you don't know for sure that 
he's a crazed ax murderer. Perhaps he's a butcher who's actually 
running after the person next to you to give her the change she forgot. 
But you're going to make a guess one way or another. That guess is an 
example of profiling.

"To profile is to generalize. It's taking characteristics of a 
population and applying them to an individual. People naturally have an 
intuition about other people based on different characteristics. 
Sometimes that intuition is right and sometimes it's wrong, but it's 
still a person's first reaction. How good this intuition is as a 
countermeasure depends on two things: how accurate the intuition is and 
how effective it is when it becomes institutionalized or when the 
profile characteristics become commonplace.

"One of the ways profiling becomes institutionalized is through 
computerization. Instead of Diana Dean looking someone over, a computer 
looks the profile over and gives it some sort of rating. Generally 
profiles with high ratings are further evaluated by people, although 
sometimes countermeasures kick in based on the computerized profile 
alone. This is, of course, more brittle. The computer can profile based 
only on simple, easy-to-assign characteristics: age, race, credit 
history, job history, et cetera. Computers don't get hinky feelings. 
Computers also can't adapt the way people can.

"Profiling works better if the characteristics profiled are accurate. 
If erratic driving is a good indication that the driver is intoxicated, 
then that's a good characteristic for a police officer to use to 
determine who he's going to pull over. If furtively looking around a 
store or wearing a coat on a hot day is a good indication that the 
person is a shoplifter, then those are good characteristics for a store 
owner to pay attention to. But if wearing baggy trousers isn't a good 
indication that the person is a shoplifter, then the store owner is 
going to spend a lot of time paying undue attention to honest people 
with lousy fashion sense.

"In common parlance, the term 'profiling' doesn't refer to these 
characteristics. It refers to profiling based on characteristics like 
race and ethnicity, and institutionalized profiling based on those 
characteristics alone. During World War II, the U.S. rounded up over 
100,000 people of Japanese origin who lived on the West Coast and 
locked them in camps (prisons, really). That was an example of 
profiling. Israeli border guards spend a lot more time scrutinizing 
Arab men than Israeli women; that's another example of profiling. In 
many U.S. communities, police have been known to stop and question 
people of color driving around in wealthy white neighborhoods (commonly 
referred to as 'DWB' -- Driving While Black). In all of these cases you 
might possibly be able to argue some security benefit, but the 
trade-offs are enormous: honest people who fit the profile can get 
annoyed, or harassed, or arrested, when they're assumed to be attackers.

"For democratic governments, this is a major problem. It's just wrong 
to segregate people into 'more likely to be attackers' and 'less likely 
to be attackers' based on race or ethnicity. It's wrong for the police 
to pull a car over just because its black occupants are driving in a 
rich white neighborhood. It's discrimination.

"But people make bad security trade-offs when they're scared, which is 
why we saw Japanese internment camps during World War II, and why there 
is so much discrimination against Arabs in the U.S. going on today. 
That doesn't make it right, and it doesn't make it effective security. 
Writing about the Japanese internment, for example, a 1983 commission 
reported that the causes of the incarceration were rooted in "race 
prejudice, war hysteria, and a failure of political leadership." But 
just because something is wrong doesn't mean that people won't continue 
to do it.

"Ethics aside, institutionalized profiling fails because real attackers 
are so rare: Active failures will be much more common than passive 
failures. The great majority of people who fit the profile will be 
innocent. At the same time, some real attackers are going to 
deliberately try to sneak past the profile. During World War II, a 
Japanese American saboteur could try to evade imprisonment by 
pretending to be Chinese. Similarly, an Arab terrorist could dye his 
hair blond, practice an American accent, and so on.

"Profiling can also blind you to threats outside the profile. If U.S. 
border guards stop and search everyone who's young, Arab, and male, 
they're not going to have the time to stop and search all sorts of 
other people, no matter how hinky they might be acting. On the other 
hand, if the attackers are of a single race or ethnicity, profiling is 
more likely to work (although the ethics are still questionable). It 
makes real security sense for El Al to spend more time investigating 
young Arab males than it does for them to investigate Israeli families. 
In Vietnam, American soldiers never knew which local civilians were 
really combatants; sometimes killing all of them was the security 
solution they chose.

"If a lot of this discussion is abhorrent, as it probably should be, 
it's the trade-offs in your head talking. It's perfectly reasonable to 
decide not to implement a countermeasure not because it doesn't work, 
but because the trade-offs are too great. Locking up every Arab-looking 
person will reduce the potential for Muslim terrorism, but no 
reasonable person would suggest it. (It's an example of 'winning the 
battle but losing the war.') In the U.S., there are laws that prohibit 
police profiling by characteristics like ethnicity, because we believe 
that such security measures are wrong (and not simply because we 
believe them to be ineffective).

"Still, no matter how much a government makes it illegal, profiling 
does occur. It occurs at an individual level, at the level of Diana 
Dean deciding which cars to wave through and which ones to investigate 
further. She profiled Ressam based on his mannerisms and his answers to 
her questions. He was Algerian, and she certainly noticed that. 
However, this was before 9/11, and the reports of the incident clearly 
indicate that she thought he was a drug smuggler; ethnicity probably 
wasn't a key profiling factor in this case. In fact, this is one of the 
most interesting aspects of the story. That intuitive sense that 
something was amiss worked beautifully, even though everybody made a 
wrong assumption about what was wrong. Human intuition detected a 
completely unexpected kind of attack. Humans will beat computers at 
hinkiness-detection for many decades to come.

"And done correctly, this intuition-based sort of profiling can be an 
excellent security countermeasure. Dean needed to have the training and 
the experience to profile accurately and properly, without stepping 
over the line and profiling illegally. The trick here is to make sure 
perceptions of risk match the actual risks. If those responsible for 
security profile based on superstition and wrong-headed intuition, or 
by blindly following a computerized profiling system, profiling won't 
work at all. And even worse, it actually can reduce security by 
blinding people to the real threats. Institutionalized profiling can 
ossify a mind, and a person's mind is the most important security 
countermeasure we have."

A couple of other points (not from the book):

1. Whenever you design a security system with two ways through -- an 
easy way and a hard way -- you invite the attacker to take the easy 
way. Profile for young Arab males, and you'll get terrorists that are 
old non-Arab females.

2. If we are going to increase security against terrorism, the young 
Arab males living in our country are precisely the people we want on 
our side. Discriminating against them in the name of security is not 
going to make them more likely to help.

3. Despite what many people think, terrorism is not confined to young 
Arab males. Shoe-bomber Richard Reid was British. Germaine Lindsay, one 
of the 7/7 London bombers, was Afro-Caribbean. Here are some more 
examples from a speech by the U.S. Secretary of Transportation Norman 
Mineta:

"In 1986, a 32-year-old Irish woman, pregnant at the time, was about to 
board an El Al flight from London to Tel Aviv when El Al security 
agents discovered an explosive device hidden in the false bottom of her 
bag. The woman's boyfriend -- the father of her unborn child -- had 
hidden the bomb.

"In 1987, a 70-year-old man and a 25-year-old woman -- neither of whom 
were Middle Eastern -- posed as father and daughter and brought a bomb 
aboard a Korean Air flight from Baghdad to Thailand. En route to 
Bangkok, the bomb exploded, killing all on board.

"In 1999, men dressed as businessmen (and one dressed as a Catholic 
priest) turned out to be terrorist hijackers, who forced an Avianca 
flight to divert to an airstrip in Colombia, where some passengers were 
held as hostages for more than a year and a half."

The 2002 Bali terrorists were Indonesian. The Chechnyan terrorists who 
downed the Russian planes were women. Timothy McVeigh and the Unabomber 
were Americans. The Basque terrorists are Basque, and Irish terrorists 
are Irish. The Tamil Tigers are Sri Lankan.

And many Muslims are not Arabs. Even worse, almost everyone who is Arab 
is not a terrorist -- many people who look Arab are not even Muslims. 
So not only are there an large number of false negatives -- terrorists 
who don't meet the profile -- but there an enormous number of false 
positives: innocents that do meet the profile.

Beyond Fear:
<http://www.schneier.com/bf.html>

U.S. Secretary of Transportation Mineta's speech:
<http://www.dot.gov/affairs/042002sp.htm>

Research into the security effectiveness of profiling versus random 
searching:
<http://www.firstmonday.org/issues/issue7_10/chakrabarti>


** *** ***** ******* *********** *************

    Cisco and ISS Harass Security Researcher



I've written about full disclosure, and how disclosing security 
vulnerabilities is our best mechanism for improving security -- 
especially in a free-market system. (That essay is also worth reading 
for a general discussion of the security trade-offs.) I've also written 
about how security companies treat vulnerabilities as public-relations 
problems first and technical problems second. This week at BlackHat, 
security researcher Michael Lynn and Cisco demonstrated both points.

Lynn was going to present security flaws in Cisco's IOS, and Cisco went 
to inordinate lengths to make sure that information never got into the 
hands of the their consumers, the press, or the public.  According to 
the Wall Street Journal:

"Cisco threatened legal action to stop the conference's organizers from 
allowing a 24-year-old researcher for a rival tech firm to discuss how 
he says hackers could seize control of Cisco's Internet routers, which 
dominate the market. Cisco also instructed workers to tear 20 pages 
outlining the presentation from the conference program and ordered 
2,000 CDs containing the presentation destroyed.

"In the end, the researcher, Michael Lynn, went ahead with a 
presentation, describing flaws in Cisco's software that he said could 
allow hackers to take over corporate and government networks and the 
Internet, intercepting and misdirecting data communications. Mr. Lynn, 
wearing a white hat emblazoned with the word "Good," spoke after 
quitting his job at Internet Security Systems Inc. Wednesday. Mr. Lynn 
said he resigned because ISS executives had insisted he strike key 
portions of his presentation."

The complete story is even weirder than this.  Initially, Cisco and ISS 
were happy with Lynn presenting his research result.  They changed 
their minds at the last minute.  Lynn gave an interview to Wired that 
talks about some of the details; I am impressed with his integrity in 
this matter.

Not being able to censor the information, Cisco decided to act as if it 
were no big deal.  This is from a SearchSecurity article:

"In a release shortly after the presentation, Cisco stated, "It is 
important to note that the information Lynn presented was not a 
disclosure of a new vulnerability or a flaw with Cisco IOS software. 
Lynn's research explores possible ways to expand exploitations of known 
security vulnerabilities impacting routers." And went on to state 
"Cisco believes that the information Lynn presented at the BlackHat 
conference today contained proprietary information and was illegally 
obtained." The statement also refers to the fact that Lynn stated in 
his presentation that he used a popular file decompresser to 'unzip' 
the Cisco image before reverse engineering it and finding the flaw, 
which is against Cisco's use agreement."

The Cisco propaganda machine certainly was working overtime that week.

Cisco and ISS also sued Lynn and BlackHat.  The suit was settled the 
next day, and it's worth reading Jennifer Granick's blog posts on the 
negotiations.  The agreement prohibited Lynn or BlackHat from talking 
about this matter or distributing any presentation materials or 
recordings of the presentation.  Not that it mattered; copies of the 
presentation slides -- the version with ISS's name on it, before they 
changed their mind and objected to the talk -- are all over the Internet.

The security implications of this are enormous. If companies have the 
power to censor information about their products they don't like, then 
we as consumers have less information with which to make intelligent 
buying decisions. If companies have the power to squelch vulnerability 
information about their products, then there's no incentive for them to 
improve security. (I've written about this in connection with physical 
keys and locks.) If free speech is subordinate to corporate demands, 
then we are all much less safe.

Full disclosure is good for society. But because it helps the bad guys 
as well as the good guys (see my essay on secrecy and security for more 
discussion of the balance), many of us have championed "responsible 
disclosure" guidelines that give vendors a head start in fixing 
vulnerabilities before they're announced.

The problem is that not all researchers follow these guidelines. And 
laws limiting free speech do more harm to society than good. (In any 
case, laws won't completely fix the problem; we can't get laws passed 
in every possible country security researchers live.) So the only 
reasonable course of action for a company is to work with researchers 
who alert them to vulnerabilities, but also to assume that 
vulnerability information will sometimes be released without prior warning.

I can't imagine the discussions inside Cisco that led them to act like 
thugs. I can't figure out why they decided to attack Michael Lynn, 
BlackHat, and ISS rather than turn the situation into a 
public-relations success. I can't believe that they thought they could 
have censored the information by their actions, or even that it was a 
good idea.

Cisco's customers want information. They don't expect perfection, but 
they want to know the extent of problems and what Cisco is doing about 
them. They don't want to know that Cisco tries to stifle the 
truth.  This is from a Computerworld article:

"Joseph Klein, senior security analyst at the aerospace electronic 
systems division for Honeywell Technology Solutions, said he helped 
arrange a meeting between government IT professionals and Lynn after 
the talk. Klein said he was furious that Cisco had been unwilling to 
disclose the buffer-overflow vulnerability in unpatched routers. 'I can 
see a class-action lawsuit against Cisco coming out of this," Klein said.'"

ISS didn't come out of this looking very good, either.  From a Wired 
article:

"'A few years ago it was rumored that ISS would hold back on certain 
things because (they're in the business of) providing solutions,' 
[Ali-Reza] Anghaie, [a senior security engineer with an aerospace firm, 
who was in the audience,] said. 'But now you've got full public 
confirmation that they'll submit to the will of a Cisco or Microsoft, 
and that's not fair to their customers.... If they're willing to back 
down and leave an employee ... out to hang, well what are they going to 
do for customers?'"

Despite their thuggish behavior, this has been a public-relations 
disaster for Cisco and ISS. Now it doesn't matter what they say -- we 
won't believe them. We know that the public-relations department 
handles their security vulnerabilities, and not the engineering 
department. We know that they think squelching information and muzzling 
researchers is more important than informing the public. They could 
have shown that they put their customers first, but instead they 
demonstrated that short-sighted corporate interests are more important 
than being a responsible corporate citizen.

And these are the people building the hardware that runs much of our 
infrastructure? Somehow, I don't feel very secure right now.

In the weeks after this event, it seemed to me that ISS was pursuing 
this out of malice.  With Cisco I think it was simple stupidity, but I 
think it's malice with ISS.

Of course, hackers are working overtime to reconstruct Lynn's attack 
and write an exploit. This, of course, means that we're in much more 
danger of there being a worm that makes use of this vulnerability.

The sad thing is that we could have avoided this. If Cisco and ISS had 
simply let Lynn present his work, it would have been just another 
obscure presentation amongst the sea of obscure presentations that is 
BlackHat. By attempting to muzzle Lynn, the two companies ensured that 
1) the vulnerability was the biggest story of the conference, and 2) 
some group of hackers would turn the vulnerability into exploit code 
just to get back at them.

News articles:
<http://online.wsj.com/public/article/0,,SB112251394301198260-2zgDRmLtWg 
PF5vKgFn1qYJBjaG0_20050827,00.html?mod=blogs> or <http://tinyurl.com/82y9e>
<http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci 
1111389,00.html?track=NL-358&ad=523843> or <http://tinyurl.com/74w8f>
<http://www.computerworld.com/securitytopics/security/story/0,10801,1035 
39,00.html> or <http://tinyurl.com/bczlk>
<http://www.wired.com/news/privacy/0,1848,68328,00.html> or 
<http://tinyurl.com/cytbd>
<http://news.zdnet.co.uk/internet/security/0,39020375,39211011,00.htm>
<http://www.securityfocus.com/news/11259>
<http://hosted.ap.org/dynamic/stories/C/CISCO_SECURITY_CRACKDOWN?SITE=AP 
WEB&SECTION=HOME&TEMPLATE=DEFAULT> or <http://tinyurl.com/8oyxh>
<http://news.zdnet.co.uk/0,39020330,39211231,00.htm>
<http://www.wired.com/news/politics/0,1283,68356,00.html>
<http://www.theregister.co.uk/2005/08/02/cisco_exploits/>
<http://news.zdnet.co.uk/internet/security/0,39020375,39212014,00.htm>

Lynn's Wired interview:
<http://www.wired.com/news/privacy/0,1848,68365,00.html>

Commentary:
<http://blogs.businessweek.com/the_thread/techbeat/archives/2005/07/the_ 
black_hats.html> or <http://tinyurl.com/85q74>
<http://www.eweek.com/article2/0,1895,1842310,00.asp>
<http://searchsecurity.techtarget.com/columnItem/0,294698,sid14_gci11127 
73,00.html?track=NL-358&ad=525032HOUSE> or <http://tinyurl.com/b8u9o>
<http://www.computerworld.com/newsletter/0,4902,103634,00.html> or 
<http://tinyurl.com/8kcll>
<http://searchsecurity.techtarget.com/columnItem/0,294698,sid14_gci11137 
55,00.html> or <http://tinyurl.com/dueur>

Jennifer Granick's blog posts:
<http://www.granick.com/archive/2005_08_01_theshout_archive.html#1123029 
21362405957> or <http://tinyurl.com/bykzw>
<http://www.granick.com/archive/2005_08_01_theshout_archive.html#1123118 
06179768898> or <http://tinyurl.com/8d2ut>
<http://www.granick.com/archive/2005_08_01_theshout_archive.html#1123200 
79983935922> or <http://tinyurl.com/buqfx>
<http://www.granick.com/archive/2005_08_01_theshout_archive.html#1123305 
15113516813> or <http://tinyurl.com/a5emv>

A video of Cisco/ISS ripping pages out of the BlackHat conference 
proceedings:
<http://www.makezine.com/blog/archive/2005/08/video_of_ciscoi.html>

My essays on full disclosure:
<http://www.schneier.com/crypto-gram-0111.html#1>
<http://www.schneier.com/crypto-gram-0203.html#2>

My essay on secrecy and security:
<http://www.schneier.com/crypto-gram-0205.html#1>

My essay on keys and locks:
<http://www.schneier.com/crypto-gram-0302.html#1>

Copies of Lynn's presentation, or maybe a cease-and-desist letter:
<http://www.infowarrior.org/users/rforno/lynn-cisco.pdf>
<http://www.jwdt.com/~paysan/lynn-cisco.pdf>
<http://www.infowarrior.org/users/rforno/lynn-cisco.pdf>
<http://www.purpleandgrey.com/free/lynn-cisco.pdf>
<http://cryptome.org/lynn-cisco.zip>
<http://www.securitylab.ru/_Exploits/2005/07/lynn-cisco.pdf>
<http://www.jwdt.com/~paysan/lynn-cisco.pdf>
<http://files.bitchx.ru/index.php?dir=ebooks/&file=lynn-cisco.pdf>
<http://s48.yousendit.com/d.aspx?id=1EOE4MPD1E6U53MYQE6ROJID0R>
<http://www.megaupload.com/?d=31GTUIFR>
<http://www.dfconsultants.com/lynn-cisco.pdf>
<http://www.security.nnov.ru/files/lynn-cisco.pdf>
<http://www.mininova.org/get/81889>
<http://www.stephencollins.org/library/linn-cisco.pdf>
<http://teknews.net/~radio/lynn-cisco.pdf>
<http://snafu.priv.at/download/lynn-cisco.pdf>

Photographs of Lynn's actual presentation slides were here:
<http://www.tomsnetworking.com/Sections-article131.php>
Now they're here:
<http://42.pl/lynn/>

Someone is setting up a legal defense fund for Lynn. Send donations via 
PayPal to [email protected]. (Does anyone know the URL?) According to 
BoingBoing, donations not used to defend Lynn will be donated to the EFF.
<http://www.boingboing.net/2005/07/30/mike_lynn_presentati.html>


** *** ***** ******* *********** *************

E-Mail Interception Decision Reversed



A U.S. federal appeals court has ruled that the interception of e-mail 
in temporary storage violates the federal wiretap act, reversing an 
earlier court opinion.

Basically, different privacy laws protect electronic communications in 
transit and data in storage; the former is protected much more than the 
latter.  E-mail stored by the sender or the recipient is obviously data 
in storage.  But what about e-mail on its way from the sender to the 
receiver?  On the one hand, it's obviously communications on 
transit.  But the government argued that it's actually stored on 
various computers as it wends its way through the Internet; hence it's 
data in storage.

The initial court decision in this case sided with the 
government.  Judge Lipez wrote an inspired dissent in the original 
opinion.  In the rehearing _en banc_ (more judges), he wrote the 
opinion for the majority which overturned the earlier opinion.

The opinion itself is long, but well worth reading.  It's well 
reasoned, and reflects extraordinary understanding and attention to 
detail.  And a great last line: "If the issue presented be 
'garden-variety'... this is a garden in need of a weed killer."

I participated in an Amicus Curiae ("friend of the court") brief in the 
case.

There's a larger issue here, and it's the same one that the 
entertainment industry used to greatly expand copyright law in 
cyberspace.  They argued that every time a copyrighted work is moved 
from computer to computer, or CD-ROM to RAM, or server to client, or 
disk drive to video card, a "copy" is being made.  This ridiculous 
definition of "copy" has allowed them to exert far greater legal 
control over how people use copyrighted works.

The ruling:
<http://www.epic.org/privacy/councilman/kerr_amicus.pdf>

Summary of the case and privacy implications:
<http://www.epic.org/privacy/councilman/>

My brief:
<http://www.csoonline.com/read/080105/debrief.html>

A brief by six different civil liberties organizations:
<http://www.epic.org/privacy/councilman/kerr_amicus.pdf>


** *** ***** ******* *********** *************

            Stealing Imaginary Things



There's a new Trojan that tries to steal World of Warcraft passwords.

That reminded me of people paying programmers to find exploits to make 
virtual money in multiplayer online games, and then selling the 
proceeds for real money.

And here's a page about ways people steal fake money in the online game 
Neopets, including cookie grabbers, fake login pages, fake contests, 
social engineering, and pyramid schemes.

I regularly say that every form of theft and fraud in the real world 
will eventually be duplicated in cyberspace. Perhaps every method of 
stealing real money will eventually be used to steal imaginary money, too.

<http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.wowcraf 
t.html> or <http://tinyurl.com/djkth>
<http://www.1up.com/do/feature?cId=3141815>
<http://star-girl.org/pages/reads/neopets/avoidscams.php>


** *** ***** ******* *********** *************

              Crypto-Gram Reprints



Crypto-Gram is currently in its seventh year of publication.  Back 
issues cover a variety of security-related topics, and can all be found 
on <http://www.schneier.com/crypto-gram.html>.  These are a selection 
of articles that appeared in this calendar month in other years.


Bob on Board:
<http://www.schneier.com/crypto-gram-0408.html#1>

Alibis and the Kindness of Strangers:
<http://www.schneier.com/crypto-gram-0408.html#3>

Houston Airport Rangers:
<http://www.schneier.com/crypto-gram-0408.html#7>

Websites, Passwords, and Consumers:
<http://www.schneier.com/crypto-gram-0408.html#8>

Flying on Someone Else's Airplane Ticket:
<http://www.schneier.com/crypto-gram-0308.html#6>

Hidden Text in Computer Documents:
<http://www.schneier.com/crypto-gram-0308.html#8>

Palladium and the TCPA:
<http://www.schneier.com/crypto-gram-0208.html#1>

Arming Airplane Pilots:
<http://www.schneier.com/crypto-gram-0208.html#8>

Code Red:
<http://www.schneier.com/crypto-gram-0108.html#1>

Protecting Copyright in the Digital World:
<http://www.schneier.com/crypto-gram-0108.html#7>

Vulnerabilities, Publicity, and Virus-Based Fixes:
<http://www.schneier.com/crypto-gram-0008.html#2>

Bluetooth:
<http://www.schneier.com/crypto-gram-0008.html#8>

A Hardware DES Cracker:
<http://www.schneier.com/crypto-gram-9808.html#descracker>

Biometrics: Truths and Fictions:
<http://www.schneier.com/crypto-gram-9808.html#biometrics>

Back Orifice 2000:
<http://www.schneier.com/crypto-gram-9908.html#BackOrifice2000>

Web-Based Encrypted E-Mail:
<http://www.schneier.com/crypto-gram-9908.html#Web-BasedEncryptedE-Mail>


** *** ***** ******* *********** *************

       Turning Cell Phones off in Tunnels



In response to the London bombings, officials turned off cell phones in 
tunnels around New York City, in an attempt to thwart bombers who might 
use cell phones as remote triggering devices. (Phone service has been 
restored in two of the four tunnels. As far as I know, it is still not 
available in the other two.)

This is as idiotic as it gets. It's a perfect example of what I call 
"movie plot security": imagining a particular scenario rather than 
focusing on the broad threats. It's completely useless if a terrorist 
uses something other than a cell phone: a kitchen timer, for example. 
Even worse, it harms security in the general case. Have people 
forgotten how cell phones saved lives on 9/11? Communication benefits 
the defenders far more than it benefits the attackers.

<http://www.nytimes.com/reuters/technology/tech-security-cellphones.html>
<http://www.ny1.com/ny1/content/index.jsp?stid=1&aid=52050>
<http://www.computerworld.com/mobiletopics/mobile/story/0,10801,103125,0 
0.html> or <http://tinyurl.com/72g8h>


** *** ***** ******* *********** *************

            Searching Bags in Subways



The New York City police will begin randomly searching people's bags on 
subways, buses, commuter trains, and ferries.  Other cities are 
following suit.

If the choice is between random searching and profiling, then random 
searching is a more effective security countermeasure. But are some 
enormous trade-offs in liberty.  And I don't think we're getting very 
much security in return.  Especially considering that passengers are 
free to turn around and leave the subway station if they don't want to 
be searched.

"Okay guys; here are your explosives. If one of you gets singled out 
for a search, just turn around and leave. And then go back in via 
another entrance, or take a taxi to the next subway stop."

(To be fair, while that was reported in the news, I have not heard from 
anyone who has tried to refuse a search and leave.)

And I don't think they'll be truly random, either. I think the police 
doing the searching will profile, because that's what happens.

It's another "movie plot threat." It's another "public relations 
security system." It's a waste of money, it substantially reduces our 
liberties, and it won't make us any safer.

Final note: I often get comments along the lines of "Stop criticizing 
stuff; tell us what we should do." My answer is always the same. 
Counterterrorism is most effective when it doesn't make arbitrary 
assumptions about the terrorists' plans. Stop searching bags on the 
subways, and spend the money on 1) intelligence and investigation -- 
stopping the terrorists regardless of what their plans are, and 2) 
emergency response -- lessening the impact of a terrorist attack, 
regardless of what the plans are. Countermeasures that defend against 
particular targets, or assume particular tactics, or cause the 
terrorists to make insignificant modifications in their plans, or that 
surveil the entire population looking for the few terrorists, are 
largely not worth it.

<http://www.nytimes.com/2005/07/21/nyregion/21cnd-security.html>
<http://www.washingtonpost.com/wp-dyn/content/article/2005/07/21/AR20050 
72101127_pf.html> or <http://tinyurl.com/aowbf>

A Citizen's Guide to Refusing New York Subway Searches:
<http://www.flexyourrights.org/subway/>


** *** ***** ******* *********** *************

  Plagiarism and Academia: Personal Experience



A paper published in the December 2004 issue of the SIGCSE Bulletin, 
"Cryptanalysis of some encryption/cipher schemes using related key 
attack," by Khawaja Amer Hayat, Umar Waqar Anis, and S. 
Tauseef-ur-Rehman, is the same as a paper that John Kelsey, David 
Wagner, and I published in 1997.

It's clearly plagiarism. Sentences have been reworded or summarized a 
bit and many typos have been introduced, but otherwise it's the same 
paper. It's copied, with the same section, paragraph, and sentence 
structure -- right down to the same mathematical variable names. It has 
the same quirks in the way references are cited. And so on.

We wrote two papers on the topic; this is the second. They don't list 
either of our papers in their bibliography. They do have a lurking 
reference to "[KSW96]" in the body of their introduction and design 
principles, presumably copied from our text; but a full citation for 
"[KSW96]" isn't in their bibliography. Perhaps they were worried that 
one of the referees would read the papers listed in their bibliography, 
and notice the plagiarism.

The three authors are from the International Islamic University in 
Islamabad, Pakistan. The third author, S. Tauseef-Ur-Rehman, is a 
department head (and faculty member) in the Telecommunications 
Engineering Department at this Pakistani institution. If you believe 
his story -- which is probably correct -- he had nothing to do with the 
research, but just appended his name to a paper by two of his students. 
(This is not unusual; it happens all the time in universities all over 
the world.) But that doesn't get him off the hook. He's still 
responsible for anything he puts his name on.

And we're not the only ones. The same three authors plagiarized a paper 
by French cryptographer Serge Vaudenay and others.  And one of my blog 
readers found a third plagiarized paper, and potentially a fourth.

I wrote to the editor of the SIGCSE Bulletin, who removed the paper 
from their website and demanded official letters of admission and 
apology. They said that they would ban them from submitting again, but 
have since backpedaled. Mark Mandelbaum, Director of the Office of 
Publications at ACM, now says that ACM has no policy on plagiarism and 
that nothing additional will be done. I've also written to 
Springer-Verlag, the publisher of my original paper.

I don't blame the journals for letting these papers through. I've 
refereed papers, and it's pretty much impossible to verify that a piece 
of research is original. We're largely self-policing.

Mostly, the system works. These three have been found out, and should 
be fired and/or expelled. Certainly ACM should ban them from submitting 
anything, and I am very surprised at their claim that they have no 
policy with regards to plagiarism. Academic plagiarism is serious 
enough to warrant that level of response. I don't know if the system 
works in Pakistan, though. I hope it does. These people knew the risks 
when they did it. And then they did it again.

If I sound angry, I'm not. I'm more amused. I've heard of researchers 
from developing countries resorting to plagiarism to pad their CVs, but 
I'm surprised to see it happen to me. I mean, really; if they were 
going to do this, wouldn't it have been smarter to pick a more obscure 
author?

And it's nice to know that our work is still considered relevant eight 
years later.

My paper:
<http://www.schneier.com/paper-relatedkey.html>
The plagiarized version:
<http://portal.acm.org/citation.cfm?doid=1041624.1041665>

Another paper:
<http://lasecwww.epfl.ch/php_code/publications/search.php?ref=CHVV03>
The plagiarized version:
<http://www.ansinet.org/fulltext/itj/itj33327-331.pdf>

A third paper:
<http://www.iki.fi/vph/files/rtp_security.pdf>
The plagiarized version:
<http://www.ansinet.org/fulltext/itj/itj33311-314.pdf>

The apologies are at the bottom of this page:
<http://www.schneier.com/paper-relatedkey-p.html>

There is a lot of discussion, much of it from students at the 
International Islamic University, in the comments section of my blog post:
<http://www.schneier.com/blog/archives/2005/08/plagiarism_and.html>

And there's some news about the incident. (Note that my name is 
completely wrong.)
<http://www.onlinenews.com.pk/details.php?id=85519>


** *** ***** ******* *********** *************

         RFID Passport Security Revisited



I've written previously about RFID chips in passports. Two recent 
articles summarize the latest State Department proposal, and it looks 
pretty good. They're addressing privacy concerns, and they're doing it 
right.

The most important feature they've designed is an access-control system 
for the RFID chip. The data on the chip is encrypted, and the key is 
printed on the passport. The officer swipes the passport through an 
optical reader to get the key, and then the RFID reader uses the key to 
communicate with the RFID chip. This means that the passport-holder can 
control who has access to the information on the chip; someone cannot 
skim information from the passport without first opening it up and 
reading the information inside. Good security.

The new design also includes a thin radio shield in the cover, 
protecting the chip when the passport is closed. More good security.

If the State Department implements these features (an assumption at 
this point), and the features work as advertised (a big "if," I grant 
you), then I am no longer opposed to the idea. And, more importantly, 
we have an example of an RFID identification system with good privacy 
safeguards. We should demand that any other RFID identification cards 
have similar privacy safeguards.


<http://www.usatoday.com/travel/news/2005-08-08-electronic-passports_x.h 
tm> or <http://tinyurl.com/bgclm>
<http://www.wired.com/news/privacy/0,1848,68451,00.html?tw=wn_tophead_2>

My previous writings:
<http://www.schneier.com/essay-060.html>
<http://www.schneier.com/blog/archives/2004/10/rfid_passports.html>
<http://www.schneier.com/blog/archives/2005/04/rfid_passport_s.html>


** *** ***** ******* *********** *************

       Risks of Losing Portable Devices



As PDAs become more powerful, and memory becomes cheaper, more people 
are carrying around a lot of personal information in an easy-to-lose 
format.

I've noticed this in my own life. If I didn't make a special effort to 
limit the amount of information on my Treo, it would include detailed 
scheduling information from the past six years. My small laptop would 
include every e-mail I've sent and received in the past dozen years. 
And so on. A lot of us are carrying around an enormous amount of very 
personal data.

And some of us are carrying around personal data about other people, too.

There are several ways to deal with this -- password protection and 
encryption, of course. More recently, some communications devices can 
be remotely erased if lost.

<http://www.washingtonpost.com/wp-dyn/content/article/2005/07/24/AR20050 
72401135.html> or <http://tinyurl.com/drnap>


** *** ***** ******* *********** *************

          How to Not Fix the ID Problem



Several of the 9/11 terrorists had Virginia driver's licenses in fake 
names. These were not forgeries; these were valid Virginia IDs that 
were illegally sold by Department of Motor Vehicle workers.

So what did Virginia do to correct the problem? They required more 
paperwork in order to get an ID.

But the problem wasn't that it was too easy to get an ID. The problem 
was that insiders were selling them illegally. Which is why the 
Virginia "solution" didn't help, and the problem remains:

"The manager of the Virginia Department of Motor Vehicles office at 
Springfield Mall was charged yesterday with selling driver's licenses 
to illegal immigrants and others for up to $3,500 apiece.

"The arrest of Francisco J. Martinez marked the second time in two 
years that a Northern Virginia DMV employee was accused of fraudulently 
selling licenses for cash. A similar scheme two years ago at the DMV 
office in Tysons Corner led to the guilty pleas of two employees."

And after we spend billions on the REAL ID act, and require even more 
paperwork to get a state ID, the problem will still remain.

<http://www.washingtonpost.com/wp-dyn/content/article/2005/07/12/AR20050 
71201421.html> or <http://tinyurl.com/cr4w7>

Virginia license requirements:
<http://www.dmvnow.com/webdoc/pdf/dmv141.pdf>


** *** ***** ******* *********** *************

This issue of Crypto-Gram has been divided into two e-mails, because 
long e-mails get cought in too many spam traps.  The rest of the issue 
will arrive soon.  If you don't receive it, you can always find 
Crypto-Gram on the web: <http://www.schneier.com/crypto-gram-0508.html>.

Copyright (c) 2005 by Bruce Schneier.