CRYPTO-GRAM, August 15, 2005 (part 2 of 2)
Bruce Schneier <[email protected]> Mon, 15 Aug 2005 04:59:30 -0500
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
August 15, 2005 - Part 2
by Bruce Schneier
This issue of Crypto-Gram has been divided into two because long
e-mails get cought in too many spam traps. This is the second
part. If you did not receive the first part, you can always find
Crypto-Gram on the web: <http://www.schneier.com/crypto-gram-0508.html>.
** *** ***** ******* *********** *************
Secure Flight
Last month the GAO issued a new report on Secure Flight. It's couched
in friendly language, but it's not good. Here's an excerpt:
"During the course of our ongoing review of the Secure Flight program,
we found that TSA did not fully disclose to the public its use of
personal information in its fall 2004 privacy notices as required by
the Privacy Act. In particular, the public was not made fully aware of,
nor had the opportunity to comment on, TSA's use of personal
information drawn from commercial sources to test aspects of the Secure
Flight program. In September 2004 and November 2004, TSA issued privacy
notices in the Federal Register that included descriptions of how such
information would be used. However, these notices did not fully inform
the public before testing began about the procedures that TSA and its
contractors would follow for collecting, using, and storing commercial
data. In addition, the scope of the data used during commercial data
testing was not fully disclosed in the notices. Specifically, a TSA
contractor, acting on behalf of the agency, collected more than 100
million commercial data records containing personal information such as
name, date of birth, and telephone number without informing the public.
As a result of TSA's actions, the public did not receive the full
protections of the Privacy Act."
Got that? The TSA violated federal law when it secretly expanded Secure
Flight's use of commercial data about passengers. It also lied to
Congress and the public about it.
Much of this isn't new. Last month we learned that the TSA bought and
is storing commercial data about passengers, even though officials said
they wouldn't do it and Congress told them not to.
Secure Flight is a disaster in every way. The TSA has been operating
with complete disregard for the law or Congress. It has lied to pretty
much everyone. And it is turning Secure Flight from a simple program to
match airline passengers against terrorist watch lists into a complex
program that compiles dossiers on passengers in order to give them some
kind of score indicating the likelihood that they are a terrorist.
Which is exactly what it was not supposed to do in the first place.
This is what I wrote about Secure Flight in January:
"For those who have not been following along, Secure Flight is the
follow-on to CAPPS-I. (CAPPS stands for Computer Assisted Passenger
Pre-Screening.) CAPPS-I has been in place since 1997, and is a simple
system to match airplane passengers to a terrorist watch list. A
follow-on system, CAPPS-II, was proposed last year. That complicated
system would have given every traveler a risk score based on
information in government and commercial databases. There was a huge
public outcry over the invasiveness of the system, and it was cancelled
over the summer. Secure Flight is the new follow-on system to CAPPS-I."
Back then, Secure Flight was intended to just be a more efficient
system of matching airline passengers with terrorist watch lists.
I am on a TSA working group that is looking at the security and privacy
implications of Secure Flight. Before joining the group I signed an NDA
agreeing not to disclose any information learned within the group, and
to not talk about deliberations within the group. But there's no reason
to believe that the TSA is lying to us any less than they're lying to
Congress, and there's nothing I learned within the working group that I
wish I could talk about. Everything I say here comes from public documents.
In January I gave some general conclusions about Secure Flight. These
have not changed:
"One, assuming that we need to implement a program of matching airline
passengers with names on terrorism watch lists, Secure Flight is a
major improvement -- in almost every way -- over what is currently in
place. (And by this I mean the matching program, not any potential uses
of commercial or other third-party data.)
"Two, the security system surrounding Secure Flight is riddled with
security holes. There are security problems with false IDs, ID
verification, the ability to fly on someone else's ticket, airline
procedures, etc.
"Three, the urge to use this system for other things will be
irresistible. It's just too easy to say: "As long as you've got this
system that watches out for terrorists, how about also looking for this
list of drug dealers...and by the way, we've got the Super Bowl to
worry about too." Once Secure Flight gets built, all it'll take is a
new law and we'll have a nationwide security checkpoint system.
"And four, a program of matching airline passengers with names on
terrorism watch lists is not making us appreciably safer, and is a
lousy way to spend our security dollars."
What has changed is the scope of Secure Flight. First, it started using
data from commercial sources, like Acxiom. Technically, they're
testing the use of commercial data, but it's still a violation. Even
the DHS started investigating whether the TSA has violated federal
privacy laws.
The TSA's response to being caught violating their own Privacy Act
statements? Revise them. A news report quotes a TSA official as saying
that it's routine to change Privacy Act statements during testing.
Actually, it's not. And it's better to change the Privacy Act statement
before violating the old one. Changing it after the fact just looks bad.
The point of Secure Flight is to match airline passengers against lists
of suspected terrorists. But the vast majority of people flagged by
this list simply have the same name, or a similar name, as the
suspected terrorist: Ted Kennedy and Cat Stevens are two famous
examples. The question is whether combining commercial data with the
PNR (Passenger Name Record) supplied by the airline could reduce this
false-positive problem. Maybe knowing the passenger's address, or phone
number, or date of birth, could reduce false positives. Or maybe not;
it depends what data is on the terrorist lists. In any case, it's
certainly a smart thing to test.
But using commercial data has serious privacy implications, which is
why Congress mandated all sorts of rules surrounding the TSA testing of
commercial data -- and more rules before it could deploy a final system
-- rules that the TSA has decided it can ignore completely.
Commercial data had another use under CAPPS-II In that now-dead
program, every passenger would be subjected to a computerized
background check to determine their "risk" to airline safety. The
system would assign a risk score based on commercial data: their credit
rating, how recently they moved, what kind of job they had, etc. This
capability was removed from Secure Flight, but now it's back. An AP
story quotes Justin Oberman, the TSA official in charge of Secure
Flight, as saying: "We are trying to use commercial data to verify the
identities of people who fly because we are not going to rely on the
watch list.... If we just rise and fall on the watch list, it's not
adequate."
Oberman also testified in a Congressional hearing:
"THOMPSON: There are a couple of questions I'd like to get answered in
my mind about Secure Flight. Would Secure Flight pick up a person with
strong community roots but who is in a terrorist sleeper cell or would
a person have to be a known terrorist in order for Secure Flight to
pick him up?
"OBERMAN: Let me answer that this way: It will identify people who are
known or suspected terrorists contained in the terrorist screening
database, and it ought to be able to identify people who may not be on
the watch list. It ought to be able to do that. We're not in a position
today to say that it does, but we think it's absolutely critical that
it be able to do that.
"And so we are conducting this test of commercially available data to
get at that exact issue.: Very difficult to do, generally. It's
particularly difficult to do when you have a system that transports 1.8
million people a day on 30,000 flights at 450 airports. That is a very
high bar to get over.
"It's also very difficult to do with a threat described just like you
described it, which is somebody who has sort of burrowed themselves
into society and is not readily apparent to us when they're walking
through the airport. And so I cannot stress enough how important we
think it is that it be able to have that functionality. And that's
precisely the reason we have been conducting this commercial data test,
why we've extended the testing period and why we're very hopeful that
the results will prove fruitful to us so that we can then come up here,
brief them to you and explain to you why we need to include that in the
system."
My fear is that TSA has already decided that they're going to use
commercial data, regardless of any test results. And once you have
commercial data, why not build a dossier on every passenger and give
him or her a risk score? So we're back to CAPPS-II, the very system
Congress killed last summer. Actually, we're very close to TIA
(Total/Terrorism Information Awareness), that vast spy-on-everyone
data-mining program that Congress killed in 2003 because it was just
too invasive.
Secure Flight is a mess in lots of other ways, too. A March GAO report
said that Secure Flight had not met nine out of the ten conditions
mandated by Congress before TSA could spend money on implementing the
program. (If you haven't read this report, it's pretty scathing.) The
redress problem -- helping people who cannot fly because they share a
name with a terrorist -- is not getting any better. And Secure Flight
is behind schedule and over budget.
It's also a rogue program that is operating in flagrant disregard for
the law. It can't be killed completely; the Intelligence Reform and
Terrorism Prevention Act of 2004 mandates that TSA implement a program
of passenger prescreening. And until we have Secure Flight, airlines
will still be matching passenger names with terrorist watch lists under
the CAPPS-I program. But it needs some serious public scrutiny.
July GAO Report:
<http://www.gao.gov/new.items/d05864r.pdf>
My essays on Secure Flight:
<http://www.schneier.com/crypto-gram-0502.html#1>
<http://www.schneier.com/crypto-gram-0501.html#9>
<http://www.schneier.com/crypto-gram-0504.html#11>
News articles:
<http://www.commondreams.org/headlines05/0621-05.htm>
<http://www.secondaryscreening.net/static/archives/2005/06/tsa_lies_coul
d.html#000206> or <http://tinyurl.com/bnmce>
<http://www.airportbusiness.com/article/article.jsp?id=2417&siteSection=5>
<http://www.commondreams.org/headlines05/0621-05.htm>
<http://www.sfgate.com/cgi-bin/article.cgi?f=/n/a/2005/07/22/national/w2
32305D42.DTL> or <http://tinyurl.com/dgy4g>
<http://www.alternet.org/story/23362/>
Congressional hearing:
<http://www6.lexisnexis.com/publisher/EndUser?Action=UserDisplayFullDocu
ment&orgId=685&topicId=14299&docId=l:292818506&start=3> or
<http://tinyurl.com/8kz9r>
March GAO Report:
<http://www.gao.gov/new.items/d05356.pdf>
Secure Flight background:
<http://www.epic.org/privacy/airtravel/secureflight.html>
CAPPS-II background:
<http://www.aclu.org/SafeandFree/SafeandFree.cfm?ID=13356&c=206>
TIA background:
<http://www.epic.org/privacy/profiling/tia/>
Anita Ramasastry's commentary is worth reading:
<http://writ.news.findlaw.com/ramasastry/20050726.html>
** *** ***** ******* *********** *************
News
An absolutely fascinating interview with Robert Pape, a University of
Chicago professor who has studied every suicide terrorist attack since
1980. "The central fact is that overwhelmingly suicide-terrorist
attacks are not driven by religion as much as they are by a clear
strategic objective: to compel modern democracies to withdraw military
forces from the territory that the terrorists view as their homeland."
<http://www.amconmag.com/2005_07_18/article.html>
His book:
<http://www.amazon.com/exec/obidos/tg/detail/-/1400063175/counterpane/10
4-3531369-1082318> or <http://tinyurl.com/c58qv>
Reviews:
<http://www.salon.com/books/review/2005/07/26/pape/index.html>
<http://www.antiwar.com/scheuer/?articleid=6286>
There's a major reorganization going on at the Department of Homeland
Security. One of the effects is the creation of a new post: assistant
secretary for cyber and telecommunications security. Honestly, it
doesn't matter where the nation's chief cybersecurity chief sits in the
organizational chart. If he has the authority to spend money and write
regulations, he can do good. If he only has the power to suggest,
plead, and cheerlead he'll be as frustrated as all the previous ones were.
<http://www.computerworld.com/newsletter/0,4902,103174,00.html>
In yet another "movie-plot threat" defense, the U.S. government is
starting to test anti-missile lasers on commercial aircraft.
<http://news.yahoo.com/news?tmpl=story&u=/usatoday/20050714/ts_usatoday/
airlinersmaygetmissiledefenses> or <http://tinyurl.com/9rwss>
Nice MSNBC piece on domestic terrorism in the U.S.
<http://www.msnbc.msn.com/id/8649078/site/newsweek/>
David Neiwert has some good commentary on the topic:
<http://dneiwert.blogspot.com/2005/07/other-kind-of-terror.html>
See also this U.S. News and World Report article:
<http://www.usnews.com/usnews/news/articles/050712/12natsec.htm>
The Sorting Door project studies the massive databases that will be
created by RFID chips:
<http://www.theregister.co.uk/2005/07/12/sorting_door_project/>
Yet another Microsoft-built-in security bypass:
<http://news.com.com/Microsofts+eye+on+open+source+-+page+3/2008-1082_3-
5796496-3.html> or <http://tinyurl.com/8vgcf>
I am very suspicious of tools that allow you to bypass network security
systems. Yes, they make life easier. But if security is important, than
all security decisions should be made by a central process; tools that
bypass that centrality are very risky.
For $13 a month, you can buy "Wells Fargo Select Identity Theft
Protection." The service includes daily monitoring of one's credit
files and assistance in dealing with cases of fraud. It's a good idea,
and it's reprehensible that Wells Fargo doesn't offer this service for
free. Actually, that's not true. It's smart business for Wells Fargo
to charge for this service. It's reprehensible that the regulatory
landscape is such that Wells Fargo does not feel it's in its best
interest to offer this service for free. Wells Fargo is a for-profit
enterprise, and they react to the realities of the market. We need
those realities to better serve the people.
<http://www.sfgate.com/cgi-bin/article.cgi?file=/c/a/2005/07/22/MNGHADS1
TL1.DTL> or <http://tinyurl.com/cg6tj>
Phil Zimmermann's encrypted VOIP phone:
<http://www.wired.com/news/technology/0,1282,68306,00.html>
Supposedly British police have asked the government for a bunch of new
powers to fight terrorism, including the right to detain a suspect for
up to three months without charge (current limit is 14 days), and make
it a criminal offence not to give police encryption keys. When Sir Ian
Blair was asked why the police wanted the extra time, he said that they
sometimes needed to access encrypted computer files and 14 days was not
enough time for them to break the encryption. That answer makes no
sense. While it's certainly possible that password-guessing programs
are more successful with three months to guess, the Regulation of
Investigatory Powers (RIP) Act -- which went into effect in 2000 --
already allows the police to jail people who don't surrender encryption
keys.
<http://www.guardian.co.uk/print/0,3858,5245014-117079,00.html>
<http://edge.channel4.com/news/2005/07/week_4/26_blair.wmv>
<http://www.guardian.co.uk/theissues/article/0,6512,334007,00.html>
Intel and Microsoft are using DRM technology to cut Linux out of the
content market.
<http://theinquirer.net/?article=24638>
My essay on Microsoft's "Trusted Computing" platform:
<http://www.schneier.com/crypto-gram-0208.html#1>
My essay on the Microsoft monopoly, which predicted this kind of behavior:
<http://www.schneier.com/crypto-gram-0310.html#12>
<http://www.ccianet.org/papers/cyberinsecurity.pdf>
Fascinating research on automatic surveillance via cell phone:
<http://www.wired.com/news/wireless/0,1382,68263,00.html>
<http://reality.media.mit.edu/>
Microsoft wants to make pirated software less useful by preventing it
from receiving patches and updates. At the same time, it is in
everyone's best interest for all software to be more secure: legitimate
and pirated. This issue has been percolating for a while, and I've
written about it twice before. After much going back and forth,
Microsoft is going to do the right thing.
<http://news.com.com/Piracy-check+mandatory+for+Windows+add-ons/2100-101
6_3-5804045.html> or <http://tinyurl.com/9d2qw>
My previous writings:
<http://www.schneier.com/blog/archives/2005/02/pirated_windows.html>
<http://www.schneier.com/crypto-gram-0406.html#4>
Hacking hotel infrared systems:
<http://www.wired.com/news/privacy/0,1848,68370,00.html>
The Department of Homeland Security is testing a program to issue RFID
identity cards to visitors entering the U.S.
<http://www.thewhig.com/webapp/sitepages/content.asp?contentID=119603&ca
tname=Local+News> or <http://tinyurl.com/dzm94>
<http://www.dhs.gov/dhspublic/display?content=4308>
I know nothing about the details of this program or about the security
of the cards. Even so, the long-term implications of this kind of thing
are very chilling.
Eavesdropping on Bluetooth-enabled automobiles.
<http://trifinite.org/blog/archives/2005/07/introducing_the.html>
<http://www.computerworld.com/securitytopics/security/story/0,10801,1036
56,00.html> or <http://tinyurl.com/c6qoe>
Salon has an interesting article about parents turning to technology to
monitor their children, instead of to other people in their community.
This is security based on fear, not reason. And I think people who act
this way make their families less safe.
<http://www.salon.com/mwt/feature/2005/07/25/gpstrackers/index.html>
<http://search.barnesandnoble.com/booksearch/isbnInquiry.asp?isbn=155652
4641> or <http://tinyurl.com/cngkb>
Here's a post-Cold-War risk I had not thought of: caches of explosives
hidden in Moscow:
<http://www.mosnews.com/feature/2005/07/15/bomba.shtml>
Turns out this is not just a Soviet phenomenon. In the 1980s and
1990s, several weapons caches were discovered in Western Europe, left
by the CIA and NATO.
Rules on exporting cryptography outside the United States have been
renewed.
<http://news.com.com/2061-10789_3-5817718.html>
There's a new Windows 2000 vulnerability. When you read the link,
don't fail to notice the sensationalist explanation from eEye. This is
what I call a "publicity attack": it's an attempt by eEye Digital
Security to get publicity for their company. Yes, I'm sure it's a bad
vulnerability. Yes, I'm sure Microsoft should have done more to secure
their systems. But eEye isn't blameless in this; they're searching for
vulnerabilities that make good press releases.
<http://news.com.com/Worm+hole+found+in+Windows+2000/2100-1002_3-5817400
.html> or <http://tinyurl.com/9s2p2>
My essay on publicity attacks:
<http://www.schneier.com/crypto-gram-0001.html#KeyFindingAttacksandPubli
cityAttacks> or <http://tinyurl.com/ayvw8>
The wrong example:
<http://www.schneier.com/crypto-gram-0104.html#2> (note that the
particular example in that essay is wrong)
Here's the basic story: A woman and her dog are riding the Seoul
subways. The dog poops in the floor. The woman refuses to clean it up,
despite being told to by other passengers. Someone takes a picture of
her, posts it on the Internet, and she is publicly shamed -- and the
story will live on the Internet forever. Then, the blogosphere debates
the notion of the Internet as a social enforcement tool.
<http://www.schneier.com/blog/archives/2005/07/dog_poop_girl.html>
Interesting details about the bombs used in the 7/7 London bombings:
<http://www.cnn.com/2005/US/08/03/nypd.london.bomb.ap/>
For those of you upset that the police divulged the recipe -- citric
acid, hair bleach, and food heater tablets -- the details are already
out there.
<http://business.fortunecity.com/executive/674/hmtd.html>
<http://www.fortliberty.org/military-library/Improvised_Primary_Explosiv
es.pdf> or <http://tinyurl.com/cecnl>
<www.roguesci.org/theforum/index.php>
And here are some images of home-made explosives seized in the various
raids after the bombings.
<http://abcnews.go.com/WNT/popup?id=979901l>
Normally this kind of information would be classified. It seems that
the New York Police released this information by mistake.
<http://news.bbc.co.uk/2/hi/uk_news/4746381.stm>
Playing classical music outside your storefront helps prevent loitering:
<http://www.freenewmexican.com/artsfeatures/10701.html>
The idea is at least a decade old:
<http://www.citypages.com/databank/18/842/article3195.asp>
Note that this does not reduce loitering, only moves it around. But if
you're the owner of a 7-Eleven, you don't care if kids are loitering at
the store down the block. You just don't want them loitering at your store.
Profiling humor:
<http://images.ucomics.com/comics/gm/2005/gm050804.gif/>
Orlando Airport is piloting a new pre-screening program called CLEAR.
The idea is that you pay $80 a year and subject yourself to a
background check, and then you can use a faster security line at airports.
<http://www.airportbusiness.com/article/article.jsp?id=2274&siteSection=
5> or <http://tinyurl.com/7ztsw>
<http://www.rednova.com/news/technology/153572/voluntary_airport_securit
y_id_to_debut_in_florida/> or <http://tinyurl.com/9b8ly>
<http://www.securityinfowatch.com/online/Biometrics/Orlando-Airport-Debu
ts-Biometrics-ID-System/4543SIW417> or <http://tinyurl.com/8f2px>
<http://www.flyclear.com/clear.html>
I've already written about this idea, back when Steven Brill first
started talking about it:
<http://www.schneier.com/crypto-gram-0403.html#10>
Nothing in this program is different from what I wrote about last year.
According to their website: "Your Membership will be continuously
reviewed by TSA's ongoing Security Threat Assessment Process. If your
security status changes, your Membership will be immediately
deactivated and you will receive a notification email of your status
change as well as a refund of the unused portion of your annual
enrollment fee." Think about it. For $80 a year, any potential
terrorist can be automatically notified if the Department of Homeland
Security is on to him. Such a deal.
At DefCon earlier this month, a group was able to set up an unamplified
802.11 network at a distance of 124.9 miles.
<http://www.enterpriseitplanet.com/networking/news/article.php/3524491>
<http://pasadena.net/shootout05/>
Even more important, the world record for communicating with a passive
RFID device was set at 69 feet. Remember that the next time someone
tells you that it's impossible to read RFID identity cards at a distance.
<http://blogs.washingtonpost.com/securityfix/2005/08/both_black_hat_.html>
<http://www.makezine.com/blog/archive/2005/07/_defcon_rfid_wo.html>
Whenever you hear a manufacturer talk about a distance limitation for
any wireless technology -- wireless LANs, RFID, Bluetooth, anything --
assume he's wrong. If he's not wrong today, he will be in a couple of
years. Assume that someone who spends some money and effort building
more sensitive technology can do much better, and that it will take
less money and effort over the years. Technology always gets better; it
never gets worse. If something is difficult and expensive now, it will
get easier and cheaper in the future.
This New York Times op-ed argues that panic is largely a myth. People
feel stressed but they behave rationally, and it only gets called
"panic" because of the stress.
<http://www.nytimes.com/2005/08/07/opinion/07fischhoff.html>
Interesting article: "The Hidden Boot Code of the Xbox, or How to fit
three bugs in 512 bytes of security code."
<http://www.xbox-linux.org/wiki/The_Hidden_Boot_Code_of_the_Xbox>
Microsoft wanted to lock out both pirated games and unofficial games,
so they built a chain of trust on the Xbox from the hardware to the
execution of the game code. Only code authorized by Microsoft could run
on the Xbox. The link between hardware and software in this chain of
trust is the hidden "MCPX" boot ROM. The article discusses that ROM.
Lots of kindergarten security mistakes.
An attorney in Australia has successfully used the MD5 Defense -- the
fact that the hash function is broken -- to fight a highway camera that
photographs speeders.
<http://theage.com.au/articles/2005/08/10/1123353368652.html>
<http://www.news.com.au/story/0,10117,16204811-1242,00.htm>
This is interesting. It's true that MD5 is broken. On the other hand,
it's almost certainly true that the speed cameras were correct. If
there's any lesson here, it's that theoretical security is important in
legal proceedings. I think that's a good thing.
<http://www.schneier.com/crypto-gram-0409.html#3>
A comment on the U.K. government using a border-security failure to
push for national ID cards:
<http://www.theregister.co.uk/2005/08/04/uk_border_security_analysis/>
Fingerprinting paper:
<http://www.schneier.com/blog/archives/2005/08/fingerprinting_2.html>
This could make an enormous difference in security against
forgeries. The idea isn't new. I remember currency
anti-counterfeiting research in which fiber-optic bits were added to
the paper pulp, and a "fingerprint" was taken using a laser. It didn't
work then, but it was clever.
Do-it-Yourself Security Checkpoint:
<http://eurobsd.org/2005-WhatTheHack/reports/markhoekstra-030805/DSC0434
5.JPG> or <http://tinyurl.com/7os5z>
The TSA wants you to get spam:
<http://www.schneier.com/blog/archives/2005/08/tsa_and_spam.html>
Cryptographically-secured murder confession:
<http://seattlepi.nwsource.com/local/aplocal_story.asp?category=6420&slu
g=ND%20Idaho%20Missing%20Children%20Duncan>
Remember all thost stories about the terrorists hiding messages in
television broadcasts? They were all false alarms.
<http://www.guardian.co.uk/life/feature/story/0,13026,1546179,00.html>
The Devil's Infosec Dictionary:
<http://www.csoonline.com/read/080105/debrief.html>
I want it to be funnier. And I want the entry that mentions me --
"Cryptography: The science of applying a complex set of mathematical
algorithms to sensitive data with the aim of making Bruce Schneier
exceedingly rich" -- to be more true. Over at my blog, I'm collecting
better and funnier definitions. Join in if you want:
<http://www.schneier.com/blog/archives/2005/08/the_devils_info.html>
LAST MINUTE NEWS: Wired News reports that the Department of Homeland
Security is pushing to let Secure Flight use commercial databases, and
to reduce independent Congressional oversight of the program.
<http://www.wired.com/news/privacy/0,1848,68518,00.html?tw=wn_tophead_1>
** *** ***** ******* *********** *************
Shoot-to-Kill
London's Metropolitan Police has a shoot-to-kill policy when dealing
with suspected suicide terrorists. And the International Association
of Chiefs of Police have issued new guidelines that also recommend a
shoot-to-kill policy. The theory is that only a direct headshot will
kill the terrorist immediately, and thus destroy the ability to execute
a bombing attack.
What might cause a police officer to think you're a suicide bomber, and
then shoot you in the head?
"The police organization's behavioral profile says such a person might
exhibit 'multiple anomalies,' including wearing a heavy coat or jacket
in warm weather or carrying a briefcase, duffel bag or backpack with
protrusions or visible wires. The person might display nervousness, an
unwillingness to make eye contact or excessive sweating. There might be
chemical burns on the clothing or stains on the hands. The person might
mumble prayers or be 'pacing back and forth in front of a venue.'"
Is that all that's required?
"The police group's guidelines also say the threat to officers does not
have to be 'imminent,' as police training traditionally teaches.
Officers do not have to wait until a suspected bomber makes a move,
another traditional requirement for police to use deadly force. An
officer just needs to have a 'reasonable basis' to believe that the
suspect can detonate a bomb, the guidelines say."
This policy is based on the extremely short-sighted assumption that a
terrorist needs to push buttons to make a bomb explode. In fact, ever
since World War I, the most common type of bomb carried by a person has
been the hand grenade. It is entirely conceivable, especially when a
shoot-to-kill policy is known to be in effect, that suicide bombers
will use the same kind of dead-man's trigger on their bombs: a
detonator that is activated when a button is released, rather than when
it is pushed. This is a difficult one. Whatever policy you choose, the
terrorists will adapt to make that policy the wrong one.
It's also a policy that puts people at risk rather than making them
safer. The security question to ask is not: "How else can we stop a
suicide bomber?" The real question is: "When the police suspect
someone of being able to detonate a bomb, what should they
do?" Backpack bombers are very rare, so much so that anyone whom the
police suspect will most likely be innocent.
The London police are now sorry they accidentally killed an innocent
they suspected of being a suicide bomber, but I can certainly
understand the mistake. In the end, the best solution is to train
police officers and then leave the decision to them. But honestly,
policies that are more likely to result in living incarcerated suspects
who can be interrogated are better than policies that are more likely
to result in corpses, especially when most suspects will be found innocent.
London policy:
<http://news.bbc.co.uk/2/hi/uk_news/4707781.stm>
International Association of Chiefs of Police policy:
<http://www.washingtonpost.com/wp-dyn/content/article/2005/08/03/AR20050
80301867.html> or <http://tinyurl.com/acmd9>
** *** ***** ******* *********** *************
Counterpane News
WilTel Communications is now offering Counterpane managed services to
its customers:
<http://www.counterpane.com/alliances-news.html>
Schneier was interviewed in Government Technology:
<http://www.govtech.net/magazine/story.php?id=95671>
** *** ***** ******* *********** *************
Visa and Amex Drop CardSystems
Remember CardSystems Solutions, the company that exposed over 40
million identities to potential fraud? (The actual number of identities
that will be the victims of fraud is almost certainly much, much lower.)
Both Visa and American Express are dropping them as a payment
processor: "Within hours of the disclosure that Visa was seeking a
replacement for CardSystems Solutions, American Express said Tuesday it
would no longer do business with the company beginning in October."
The biggest problem with CardSystems' actions wasn't that it had bad
computer security practices, but that it had bad business practices. It
was holding exception files with personal information, even though it
was not supposed to. It was not for marketing, as I originally
surmised, but to find out why transactions were not being authorized.
It was disregarding the rules it agreed to follow.
Technical problems can be remediated. A dishonest corporate culture is
much harder to fix. That was what I sense reading between the lines:
"Visa had been weighing the decision for a few weeks but as recently as
mid-June said that it was working with CardSystems to correct the
problem. CardSystems hired an outside security assessor this month to
review its policies and practices, and it promised to make any
necessary upgrades by the end of August. CardSystems, in its statement
yesterday, said the company's executives had been "in almost daily
contact" with Visa since the problems were discovered in May.
"Visa, however, said that despite 'some remediation efforts' since the
incident was reported, the actions by CardSystems were not enough."
And this:
"CardSystems Solutions Inc. 'has not corrected, and cannot at this
point correct, the failure to provide proper data security for Visa
accounts,' said Rosetta Jones, a spokeswoman for Foster City,
Calif.-based Visa....
"Visa said that while CardSystems has taken some remediating actions
since the breach was disclosed, those could not overcome the fact that
it was inappropriately holding on to account information -- purportedly
for 'research purposes' -- when the breach occurred, in violation of
Visa's security rules."
At this point, it is unclear what MasterCard and Discover will do.
"MasterCard International Inc. is taking a different tack with
CardSystems. The credit card company expects CardSystems to develop a
plan for improving its security by Aug. 31, 'and as of today, we are
not aware of any deficiencies in its systems that are incapable of
being remediated,' spokeswoman Sharon Gamsin said.
"'However, if CardSystems cannot demonstrate that they are in
compliance by that date, their ability to provide services to
MasterCard members will be at risk,' she said.
"Jennifer Born, a spokeswoman for Discover Financial Services Inc.,
which also has a relationship with CardSystems, said the Riverwoods,
Ill.-based company was 'doing our due diligence and will make our
decision once that process is completed.'"
I think this is a positive development. I have long said that companies
like CardSystems won't clean up their acts unless there are
consequences for not doing so. Credit card companies dropping
CardSystems sends a strong message to the other payment processors:
improve your security if you want to stay in business.
News articles:
<http://www.ajc.com/news/content/business/0705/20bizcardsystems.html>
<http://www.nytimes.com/2005/07/19/business/19visa.html?adxnnl=1&oref=lo
gin&adxnnlx=1121913372-DMgsxuIkCLls0Cz84OcAlw> or
<http://tinyurl.com/ax4qa>
<http://news.yahoo.com/news?tmpl=story&cid=528&e=3&u=/ap/20050720/ap_on_
bi_ge/credit_cards_breach> or <http://tinyurl.com/bau3s>
My original essay on CardSystems:
<http://www.schneier.com/crypto-gram-0507.html#3>
Some interesting legal opinions on the larger issue of disclosure:
<http://writ.news.findlaw.com/ramasastry/20050713.html>
** *** ***** ******* *********** *************
Comments from Readers
From: Ed Gerck <[email protected]>
Subject: Comment on CardSystems article
As you report, credit card companies can and do force companies that
process credit card data to increase their security. However, how about
the "acceptable risk" concept that underlies the very security
procedures of these same credit card companies?
The dirty little secret of the credit card industry is that they are
very happy with 10% of credit card fraud, over the Internet or not.
In fact, if they would reduce fraud to _zero_ today, their revenue
would decrease as well as their profits. So, there is really no
incentive to reduce fraud. On the contrary, keeping the status quo is
just fine.
This is so because of insurance -- up to a certain level, which is well
within the operational boundaries of course, a fraudulent transaction
does not go unpaid through Visa, American Express or MasterCard
servers. The transaction is fully paid, with its insurance cost paid
by the merchant and, ultimately, by the customer.
"Acceptable risk" has been for a long time an euphemism for that
business model that shifts the burden of fraud to the customer.
Thus, the credit card industry has successfully turned fraud into a
sale. This is the same attitude reported to me by a car manufacturer
representative when I was talking to him about simple techniques to
reduce car theft -- to which he said: "A car stolen is a car sold."
In fact, a car stolen will need replacement that will be provided by
insurance or by the customer working again to buy another car, while
the stolen car continues to generate revenue for the manufacturer in
service and parts.
Whenever we see continued fraud, we should be certain: the defrauded is
profiting from it, because no company will accept a continued loss
without doing anything to reduce it. Arguments such as "we don't want
to reduce the fraud level because it would cost more to reduce the
fraud than the fraud costs" are just a marketing way to say that a
fraud has become a sale.
Because fraud is an hemorrhage that adds up, while efforts to fix it --
if done correctly -- are mostly an up front cost that is incurred only
once. So, to accept fraud debits is to accept that there is also a
credit that continuously compensates the debit. Which credit ultimately
flows from the customer -- just like in car theft.
What is to blame? Not only the twisted ethics behind this attitude but
also that traditional security school of thought which focus on risk,
surveillance and insurance as the solution to security problems.
There is no consideration of what trust really would mean in terms of
bits and machines, no consideration that the insurance model of
security cannot scale in Internet volumes and cannot even be ethically
justifiable.
"A fraud is a sale" is the only outcome possible from using such
security school of thought. Also sometimes referred to as "acceptable
risk" -- acceptable indeed, because it is paid for.
From: Tom Welsh <[email protected]>
Subject: Re: IEDs in Iraq
"After a while, U.S. troops got good at spotting and killing the
triggermen when bombs went off."
Well yes... kinda. Think for a moment, and you can imagine how it would
go. "If a bomb goes off while we're driving along the road, take out
any hajis who look as if they might be holding a remote detonator".
Rat-a-tat-tat! Goodbye to lots of locals, most of whom were checking
their mobile phones, reading books, getting money out of their wallets,
etc.
Of course this is exactly what the insurgents are trying to accomplish.
Killing infidels is OK, but it's not the main goal. Getting the
infidels to kill civilians is the main goal, and boy do they oblige
when you goose them right.
I don't know whether it was Vietnam or Mogadishu that was the turning
point, but at some stage the Pentagon decided that as few American boys
were going to be hurt as possible when they were in other people's
countries setting the world to rights. Give a bunch of green troops the
heaviest firepower that soldiers have ever had at their disposal, and
tell them to be sure and get their retaliation in first -- as if they
needed any encouragement -- and guess what happens? Freakily low U.S.
casualties, tens of thousands of dead and maimed civilians, and a
popularity rating that is steadily catching up with the Waffen-SS. Give
them time, they'll be challenging the Allgemeine-SS.
My point is that, from a security expert's point of view, you can win
the battles and lose the war - and taking out any and all
"suspicious-looking people" is a great way to do so.
From: Les Jones <[email protected]>
Subject: RE: CRYPTO-GRAM, July 15, 2005
"This advice would have helped Brennan Hawkins, the 11-year-old boy who
was lost in the Utah wilderness for four days last month. He avoided
people searching for him because he had been taught not to talk to
strangers."
Avoiding rescuers is a common reaction in people who have been lost in
the woods. See Dwight McCarter's book, "Lost," an account of search and
rescue operations in the Great Smoky Mountains National Park. In one
chapter McCarter tells the story of two backpackers in the park who got
separated while traveling off-trail in the vicinity of Thunderhead. The
less-experienced hiker quickly got lost.
After a day or two wandering around he was going through his pack and
found a backpacking how-to book that explained what to do in case you
got lost in the woods. Following the advice, he went to a clearing and
built a signal fire. A rescue helicopter saw the smoke and hovered
overhead above the tree tops as he waved his arms to attract their
attention. The helicopter dropped a sleeping bag and food, with a note
saying they couldn't land in the clearing, but that they would send in
a rescue party on foot.
The lost hiker sat down, tended his fire, and waited for rescue. When
the rescuers appeared at the edge of the clearing, he panicked, jumped
up, and ran in the other direction. They had to chase him down to
rescue him. This despite the fact that he wanted to be rescued, had
taken active steps to attract rescuers, and knew that rescuers were
coming to him. Odd but true.
From: Tamas K Papp
Subject: Re: Talking to Strangers
You claim that "'don't talk to strangers" is just about the worst
possible advice you can give a child."
The "security policy" of not talking to strangers actually covers two
distinct situations:
(A) Don't initiate conversation with strangers.
(B) Do not respond if strangers try to talk to you.
In (A), we are dealing with the prior probability (e.g., their
proportion in the population of the area, etc) of strangers being
harmless or dangerous (p(H) and p(D), respectively). I agree with your
conclusion that in any normal society, p(D) is very small, hence the
advice of paranoid parents doesn't make much sense in this case.
However, careful analysis of (B) shows that here we are dealing with
the posterior probability of strangers being dangerous _given_ that
they initiated the conversation (we will denote that by T). You can
use Bayes' Rule to calculate this; i.e.:
p(D|T) = p(T|D)p(D)/p(T)
where p(T) = p(T|D)p(D) + p(T|H)p(H) is the probability that strangers
of any kind talk to you. In a society where "normal" people don't talk
to strangers, p(T|H) is close to zero, while it is possible that
dangerous people (child molesters, criminals) will talk to children
with significant probability, thus p(T|D) will be larger than zero.
Thus even if p(D) is low, p(D|T) might be high enough for part (B) to
make sense: you use the information in the signal to revise your
estimate of strangers being dangerous.
Parents might think that the distinction between (A) and (B) is too
subtle for a little child, and resort to the suboptimal but simple rule
of not talking to strangers.
I agree with you that "[i]n a world where good guys are common and bad
guys are rare, assuming a random person is a good guy is a smart
security strategy". However, ignoring signals that help revise your
probability estimates is a bad security strategy.
** *** ***** ******* *********** *************
CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,
insights, and commentaries on security: computer and otherwise. You
can subscribe, unsubscribe, or change your address on the Web at
<http://www.schneier.com/crypto-gram.html>. Back issues are also
available at that URL.
Comments on CRYPTO-GRAM should be sent to
[email protected]. Permission to print comments is assumed
unless otherwise stated. Comments may be edited for length and clarity.
Please feel free to forward CRYPTO-GRAM to colleagues and friends who
will find it valuable. Permission is granted to reprint CRYPTO-GRAM,
as long as it is reprinted in its entirety.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of
the best sellers "Beyond Fear," "Secrets and Lies," and "Applied
Cryptography," and an inventor of the Blowfish and Twofish
algorithms. He is founder and CTO of Counterpane Internet Security
Inc., and is a member of the Advisory Board of the Electronic Privacy
Information Center (EPIC). He is a frequent writer and lecturer on
security topics. See <http://www.schneier.com>.
Counterpane is the world's leading protector of networked information -
the inventor of outsourced security monitoring and the foremost
authority on effective mitigation of emerging IT threats. Counterpane
protects networks for Fortune 1000 companies and governments
world-wide. See <http://www.counterpane.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not
necessarily those of Counterpane Internet Security, Inc.
Copyright (c) 2005 by Bruce Schneier.