CRYPTO-GRAM, August 15, 2005 (part 2 of 2)

Bruce Schneier <[email protected]> Mon, 15 Aug 2005 04:59:30 -0500
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

            August 15, 2005 - Part 2

               by Bruce Schneier


This issue of Crypto-Gram has been divided into two because long 
e-mails get cought in too many spam traps.  This is the second 
part.  If you did not receive the first part, you can always find 
Crypto-Gram on the web: <http://www.schneier.com/crypto-gram-0508.html>.


** *** ***** ******* *********** *************

                 Secure Flight



Last month the GAO issued a new report on Secure Flight. It's couched 
in friendly language, but it's not good.  Here's an excerpt:

"During the course of our ongoing review of the Secure Flight program, 
we found that TSA did not fully disclose to the public its use of 
personal information in its fall 2004 privacy notices as required by 
the Privacy Act. In particular, the public was not made fully aware of, 
nor had the opportunity to comment on, TSA's use of personal 
information drawn from commercial sources to test aspects of the Secure 
Flight program. In September 2004 and November 2004, TSA issued privacy 
notices in the Federal Register that included descriptions of how such 
information would be used. However, these notices did not fully inform 
the public before testing began about the procedures that TSA and its 
contractors would follow for collecting, using, and storing commercial 
data. In addition, the scope of the data used during commercial data 
testing was not fully disclosed in the notices. Specifically, a TSA 
contractor, acting on behalf of the agency, collected more than 100 
million commercial data records containing personal information such as 
name, date of birth, and telephone number without informing the public. 
As a result of TSA's actions, the public did not receive the full 
protections of the Privacy Act."

Got that? The TSA violated federal law when it secretly expanded Secure 
Flight's use of commercial data about passengers. It also lied to 
Congress and the public about it.

Much of this isn't new. Last month we learned that the TSA bought and 
is storing commercial data about passengers, even though officials said 
they wouldn't do it and Congress told them not to.

Secure Flight is a disaster in every way. The TSA has been operating 
with complete disregard for the law or Congress. It has lied to pretty 
much everyone. And it is turning Secure Flight from a simple program to 
match airline passengers against terrorist watch lists into a complex 
program that compiles dossiers on passengers in order to give them some 
kind of score indicating the likelihood that they are a terrorist.

Which is exactly what it was not supposed to do in the first place.

This is what I wrote about Secure Flight in January:

"For those who have not been following along, Secure Flight is the 
follow-on to CAPPS-I. (CAPPS stands for Computer Assisted Passenger 
Pre-Screening.) CAPPS-I has been in place since 1997, and is a simple 
system to match airplane passengers to a terrorist watch list. A 
follow-on system, CAPPS-II, was proposed last year. That complicated 
system would have given every traveler a risk score based on 
information in government and commercial databases. There was a huge 
public outcry over the invasiveness of the system, and it was cancelled 
over the summer. Secure Flight is the new follow-on system to CAPPS-I."

Back then, Secure Flight was intended to just be a more efficient 
system of matching airline passengers with terrorist watch lists.

I am on a TSA working group that is looking at the security and privacy 
implications of Secure Flight. Before joining the group I signed an NDA 
agreeing not to disclose any information learned within the group, and 
to not talk about deliberations within the group. But there's no reason 
to believe that the TSA is lying to us any less than they're lying to 
Congress, and there's nothing I learned within the working group that I 
wish I could talk about. Everything I say here comes from public documents.

In January I gave some general conclusions about Secure Flight. These 
have not changed:

"One, assuming that we need to implement a program of matching airline 
passengers with names on terrorism watch lists, Secure Flight is a 
major improvement -- in almost every way -- over what is currently in 
place. (And by this I mean the matching program, not any potential uses 
of commercial or other third-party data.)

"Two, the security system surrounding Secure Flight is riddled with 
security holes. There are security problems with false IDs, ID 
verification, the ability to fly on someone else's ticket, airline 
procedures, etc.

"Three, the urge to use this system for other things will be 
irresistible. It's just too easy to say: "As long as you've got this 
system that watches out for terrorists, how about also looking for this 
list of drug dealers...and by the way, we've got the Super Bowl to 
worry about too." Once Secure Flight gets built, all it'll take is a 
new law and we'll have a nationwide security checkpoint system.

"And four, a program of matching airline passengers with names on 
terrorism watch lists is not making us appreciably safer, and is a 
lousy way to spend our security dollars."

What has changed is the scope of Secure Flight. First, it started using 
data from commercial sources, like Acxiom.  Technically, they're 
testing the use of commercial data, but it's still a violation. Even 
the DHS started investigating whether the TSA has violated federal 
privacy laws.

The TSA's response to being caught violating their own Privacy Act 
statements? Revise them.  A news report quotes a TSA official as saying 
that it's routine to change Privacy Act statements during testing.

Actually, it's not. And it's better to change the Privacy Act statement 
before violating the old one. Changing it after the fact just looks bad.

The point of Secure Flight is to match airline passengers against lists 
of suspected terrorists. But the vast majority of people flagged by 
this list simply have the same name, or a similar name, as the 
suspected terrorist: Ted Kennedy and Cat Stevens are two famous 
examples. The question is whether combining commercial data with the 
PNR (Passenger Name Record) supplied by the airline could reduce this 
false-positive problem. Maybe knowing the passenger's address, or phone 
number, or date of birth, could reduce false positives. Or maybe not; 
it depends what data is on the terrorist lists. In any case, it's 
certainly a smart thing to test.

But using commercial data has serious privacy implications, which is 
why Congress mandated all sorts of rules surrounding the TSA testing of 
commercial data -- and more rules before it could deploy a final system 
-- rules that the TSA has decided it can ignore completely.

Commercial data had another use under CAPPS-II In that now-dead 
program, every passenger would be subjected to a computerized 
background check to determine their "risk" to airline safety. The 
system would assign a risk score based on commercial data: their credit 
rating, how recently they moved, what kind of job they had, etc. This 
capability was removed from Secure Flight, but now it's back.  An AP 
story quotes Justin Oberman, the TSA official in charge of Secure 
Flight, as saying: "We are trying to use commercial data to verify the 
identities of people who fly because we are not going to rely on the 
watch list....  If we just rise and fall on the watch list, it's not 
adequate."

Oberman also testified in a Congressional hearing:

"THOMPSON: There are a couple of questions I'd like to get answered in 
my mind about Secure Flight. Would Secure Flight pick up a person with 
strong community roots but who is in a terrorist sleeper cell or would 
a person have to be a known terrorist in order for Secure Flight to 
pick him up?

"OBERMAN: Let me answer that this way: It will identify people who are 
known or suspected terrorists contained in the terrorist screening 
database, and it ought to be able to identify people who may not be on 
the watch list. It ought to be able to do that. We're not in a position 
today to say that it does, but we think it's absolutely critical that 
it be able to do that.

"And so we are conducting this test of commercially available data to 
get at that exact issue.: Very difficult to do, generally. It's 
particularly difficult to do when you have a system that transports 1.8 
million people a day on 30,000 flights at 450 airports. That is a very 
high bar to get over.

"It's also very difficult to do with a threat described just like you 
described it, which is somebody who has sort of burrowed themselves 
into society and is not readily apparent to us when they're walking 
through the airport. And so I cannot stress enough how important we 
think it is that it be able to have that functionality. And that's 
precisely the reason we have been conducting this commercial data test, 
why we've extended the testing period and why we're very hopeful that 
the results will prove fruitful to us so that we can then come up here, 
brief them to you and explain to you why we need to include that in the 
system."

My fear is that TSA has already decided that they're going to use 
commercial data, regardless of any test results. And once you have 
commercial data, why not build a dossier on every passenger and give 
him or her a risk score? So we're back to CAPPS-II, the very system 
Congress killed last summer. Actually, we're very close to TIA 
(Total/Terrorism Information Awareness), that vast spy-on-everyone 
data-mining program that Congress killed in 2003 because it was just 
too invasive.

Secure Flight is a mess in lots of other ways, too. A March GAO report 
said that Secure Flight had not met nine out of the ten conditions 
mandated by Congress before TSA could spend money on implementing the 
program. (If you haven't read this report, it's pretty scathing.) The 
redress problem -- helping people who cannot fly because they share a 
name with a terrorist -- is not getting any better. And Secure Flight 
is behind schedule and over budget.

It's also a rogue program that is operating in flagrant disregard for 
the law. It can't be killed completely; the Intelligence Reform and 
Terrorism Prevention Act of 2004 mandates that TSA implement a program 
of passenger prescreening. And until we have Secure Flight, airlines 
will still be matching passenger names with terrorist watch lists under 
the CAPPS-I program. But it needs some serious public scrutiny.

July GAO Report:
<http://www.gao.gov/new.items/d05864r.pdf>

My essays on Secure Flight:
<http://www.schneier.com/crypto-gram-0502.html#1>
<http://www.schneier.com/crypto-gram-0501.html#9>
<http://www.schneier.com/crypto-gram-0504.html#11>

News articles:
<http://www.commondreams.org/headlines05/0621-05.htm>
<http://www.secondaryscreening.net/static/archives/2005/06/tsa_lies_coul 
d.html#000206> or <http://tinyurl.com/bnmce>
<http://www.airportbusiness.com/article/article.jsp?id=2417&siteSection=5>
<http://www.commondreams.org/headlines05/0621-05.htm>
<http://www.sfgate.com/cgi-bin/article.cgi?f=/n/a/2005/07/22/national/w2 
32305D42.DTL> or <http://tinyurl.com/dgy4g>
<http://www.alternet.org/story/23362/>

Congressional hearing:
<http://www6.lexisnexis.com/publisher/EndUser?Action=UserDisplayFullDocu 
ment&orgId=685&topicId=14299&docId=l:292818506&start=3> or 
<http://tinyurl.com/8kz9r>

March GAO Report:
<http://www.gao.gov/new.items/d05356.pdf>

Secure Flight background:
<http://www.epic.org/privacy/airtravel/secureflight.html>

CAPPS-II background:
<http://www.aclu.org/SafeandFree/SafeandFree.cfm?ID=13356&c=206>

TIA background:
<http://www.epic.org/privacy/profiling/tia/>

Anita Ramasastry's commentary is worth reading:
<http://writ.news.findlaw.com/ramasastry/20050726.html>


** *** ***** ******* *********** *************

                      News



An absolutely fascinating interview with Robert Pape, a University of 
Chicago professor who has studied every suicide terrorist attack since 
1980.  "The central fact is that overwhelmingly suicide-terrorist 
attacks are not driven by religion as much as they are by a clear 
strategic objective: to compel modern democracies to withdraw military 
forces from the territory that the terrorists view as their homeland."
<http://www.amconmag.com/2005_07_18/article.html>
His book:
<http://www.amazon.com/exec/obidos/tg/detail/-/1400063175/counterpane/10 
4-3531369-1082318> or <http://tinyurl.com/c58qv>
Reviews:
<http://www.salon.com/books/review/2005/07/26/pape/index.html>
<http://www.antiwar.com/scheuer/?articleid=6286>

There's a major reorganization going on at the Department of Homeland 
Security. One of the effects is the creation of a new post: assistant 
secretary for cyber and telecommunications security.  Honestly, it 
doesn't matter where the nation's chief cybersecurity chief sits in the 
organizational chart. If he has the authority to spend money and write 
regulations, he can do good. If he only has the power to suggest, 
plead, and cheerlead he'll be as frustrated as all the previous ones were.
<http://www.computerworld.com/newsletter/0,4902,103174,00.html>

In yet another "movie-plot threat" defense, the U.S. government is 
starting to test anti-missile lasers on commercial aircraft.
<http://news.yahoo.com/news?tmpl=story&u=/usatoday/20050714/ts_usatoday/ 
airlinersmaygetmissiledefenses> or <http://tinyurl.com/9rwss>

Nice MSNBC piece on domestic terrorism in the U.S.
<http://www.msnbc.msn.com/id/8649078/site/newsweek/>
David Neiwert has some good commentary on the topic:
<http://dneiwert.blogspot.com/2005/07/other-kind-of-terror.html>
See also this U.S. News and World Report article:
<http://www.usnews.com/usnews/news/articles/050712/12natsec.htm>

The Sorting Door project studies the massive databases that will be 
created by RFID chips:
<http://www.theregister.co.uk/2005/07/12/sorting_door_project/>

Yet another Microsoft-built-in security bypass:
<http://news.com.com/Microsofts+eye+on+open+source+-+page+3/2008-1082_3- 
5796496-3.html> or <http://tinyurl.com/8vgcf>
I am very suspicious of tools that allow you to bypass network security 
systems. Yes, they make life easier. But if security is important, than 
all security decisions should be made by a central process; tools that 
bypass that centrality are very risky.

For $13 a month, you can buy "Wells Fargo Select Identity Theft 
Protection."  The service includes daily monitoring of one's credit 
files and assistance in dealing with cases of fraud.  It's a good idea, 
and it's reprehensible that Wells Fargo doesn't offer this service for 
free.  Actually, that's not true. It's smart business for Wells Fargo 
to charge for this service. It's reprehensible that the regulatory 
landscape is such that Wells Fargo does not feel it's in its best 
interest to offer this service for free. Wells Fargo is a for-profit 
enterprise, and they react to the realities of the market. We need 
those realities to better serve the people.
<http://www.sfgate.com/cgi-bin/article.cgi?file=/c/a/2005/07/22/MNGHADS1 
TL1.DTL> or <http://tinyurl.com/cg6tj>

Phil Zimmermann's encrypted VOIP phone:
<http://www.wired.com/news/technology/0,1282,68306,00.html>

Supposedly British police have asked the government for a bunch of new 
powers to fight terrorism, including the right to detain a suspect for 
up to three months without charge (current limit is 14 days), and make 
it a criminal offence not to give police encryption keys.  When Sir Ian 
Blair was asked why the police wanted the extra time, he said that they 
sometimes needed to access encrypted computer files and 14 days was not 
enough time for them to break the encryption.  That answer makes no 
sense.  While it's certainly possible that password-guessing programs 
are more successful with three months to guess, the Regulation of 
Investigatory Powers (RIP) Act -- which went into effect in 2000 -- 
already allows the police to jail people who don't surrender encryption 
keys.
<http://www.guardian.co.uk/print/0,3858,5245014-117079,00.html>
<http://edge.channel4.com/news/2005/07/week_4/26_blair.wmv>
<http://www.guardian.co.uk/theissues/article/0,6512,334007,00.html>

Intel and Microsoft are using DRM technology to cut Linux out of the 
content market.
<http://theinquirer.net/?article=24638>
My essay on Microsoft's "Trusted Computing" platform:
<http://www.schneier.com/crypto-gram-0208.html#1>
My essay on the Microsoft monopoly, which predicted this kind of behavior:
<http://www.schneier.com/crypto-gram-0310.html#12>
<http://www.ccianet.org/papers/cyberinsecurity.pdf>

Fascinating research on automatic surveillance via cell phone:
<http://www.wired.com/news/wireless/0,1382,68263,00.html>
<http://reality.media.mit.edu/>

Microsoft wants to make pirated software less useful by preventing it 
from receiving patches and updates. At the same time, it is in 
everyone's best interest for all software to be more secure: legitimate 
and pirated. This issue has been percolating for a while, and I've 
written about it twice before. After much going back and forth, 
Microsoft is going to do the right thing.
<http://news.com.com/Piracy-check+mandatory+for+Windows+add-ons/2100-101 
6_3-5804045.html> or <http://tinyurl.com/9d2qw>
My previous writings:
<http://www.schneier.com/blog/archives/2005/02/pirated_windows.html>
<http://www.schneier.com/crypto-gram-0406.html#4>

Hacking hotel infrared systems:
<http://www.wired.com/news/privacy/0,1848,68370,00.html>

The Department of Homeland Security is testing a program to issue RFID 
identity cards to visitors entering the U.S.
<http://www.thewhig.com/webapp/sitepages/content.asp?contentID=119603&ca 
tname=Local+News> or <http://tinyurl.com/dzm94>
<http://www.dhs.gov/dhspublic/display?content=4308>
I know nothing about the details of this program or about the security 
of the cards. Even so, the long-term implications of this kind of thing 
are very chilling.

Eavesdropping on Bluetooth-enabled automobiles.
<http://trifinite.org/blog/archives/2005/07/introducing_the.html>
<http://www.computerworld.com/securitytopics/security/story/0,10801,1036 
56,00.html> or <http://tinyurl.com/c6qoe>

Salon has an interesting article about parents turning to technology to 
monitor their children, instead of to other people in their community. 
This is security based on fear, not reason. And I think people who act 
this way make their families less safe.
<http://www.salon.com/mwt/feature/2005/07/25/gpstrackers/index.html>
<http://search.barnesandnoble.com/booksearch/isbnInquiry.asp?isbn=155652 
4641> or <http://tinyurl.com/cngkb>

Here's a post-Cold-War risk I had not thought of: caches of explosives 
hidden in Moscow:
<http://www.mosnews.com/feature/2005/07/15/bomba.shtml>
Turns out this is not just a Soviet phenomenon.   In the 1980s and 
1990s, several weapons caches were discovered in Western Europe, left 
by the CIA and NATO.

Rules on exporting cryptography outside the United States have been 
renewed.
<http://news.com.com/2061-10789_3-5817718.html>

There's a new Windows 2000 vulnerability.  When you read the link, 
don't fail to notice the sensationalist explanation from eEye. This is 
what I call a "publicity attack": it's an attempt by eEye Digital 
Security to get publicity for their company. Yes, I'm sure it's a bad 
vulnerability. Yes, I'm sure Microsoft should have done more to secure 
their systems. But eEye isn't blameless in this; they're searching for 
vulnerabilities that make good press releases.
<http://news.com.com/Worm+hole+found+in+Windows+2000/2100-1002_3-5817400 
.html> or <http://tinyurl.com/9s2p2>
My essay on publicity attacks:
<http://www.schneier.com/crypto-gram-0001.html#KeyFindingAttacksandPubli 
cityAttacks> or <http://tinyurl.com/ayvw8>
The wrong example:
<http://www.schneier.com/crypto-gram-0104.html#2> (note that the 
particular example in that essay is wrong)

Here's the basic story: A woman and her dog are riding the Seoul 
subways. The dog poops in the floor. The woman refuses to clean it up, 
despite being told to by other passengers. Someone takes a picture of 
her, posts it on the Internet, and she is publicly shamed -- and the 
story will live on the Internet forever. Then, the blogosphere debates 
the notion of the Internet as a social enforcement tool.
<http://www.schneier.com/blog/archives/2005/07/dog_poop_girl.html>

Interesting details about the bombs used in the 7/7 London bombings:
<http://www.cnn.com/2005/US/08/03/nypd.london.bomb.ap/>
For those of you upset that the police divulged the recipe -- citric 
acid, hair bleach, and food heater tablets -- the details are already 
out there.
<http://business.fortunecity.com/executive/674/hmtd.html>
<http://www.fortliberty.org/military-library/Improvised_Primary_Explosiv 
es.pdf> or <http://tinyurl.com/cecnl>
<www.roguesci.org/theforum/index.php>
And here are some images of home-made explosives seized in the various 
raids after the bombings.
<http://abcnews.go.com/WNT/popup?id=979901l>
Normally this kind of information would be classified.  It seems that 
the New York Police released this information by mistake.
<http://news.bbc.co.uk/2/hi/uk_news/4746381.stm>

Playing classical music outside your storefront helps prevent loitering:
<http://www.freenewmexican.com/artsfeatures/10701.html>
The idea is at least a decade old:
<http://www.citypages.com/databank/18/842/article3195.asp>
Note that this does not reduce loitering, only moves it around. But if 
you're the owner of a 7-Eleven, you don't care if kids are loitering at 
the store down the block. You just don't want them loitering at your store.

Profiling humor:
<http://images.ucomics.com/comics/gm/2005/gm050804.gif/>

Orlando Airport is piloting a new pre-screening program called CLEAR. 
The idea is that you pay $80 a year and subject yourself to a 
background check, and then you can use a faster security line at airports.
<http://www.airportbusiness.com/article/article.jsp?id=2274&siteSection= 
5> or <http://tinyurl.com/7ztsw>
<http://www.rednova.com/news/technology/153572/voluntary_airport_securit 
y_id_to_debut_in_florida/> or <http://tinyurl.com/9b8ly>
<http://www.securityinfowatch.com/online/Biometrics/Orlando-Airport-Debu 
ts-Biometrics-ID-System/4543SIW417> or <http://tinyurl.com/8f2px>
<http://www.flyclear.com/clear.html>
I've already written about this idea, back when Steven Brill first 
started talking about it:
<http://www.schneier.com/crypto-gram-0403.html#10>
Nothing in this program is different from what I wrote about last year. 
According to their website:  "Your Membership will be continuously 
reviewed by TSA's ongoing Security Threat Assessment Process. If your 
security status changes, your Membership will be immediately 
deactivated and you will receive a notification email of your status 
change as well as a refund of the unused portion of your annual 
enrollment fee." Think about it. For $80 a year, any potential 
terrorist can be automatically notified if the Department of Homeland 
Security is on to him. Such a deal.

At DefCon earlier this month, a group was able to set up an unamplified 
802.11 network at a distance of 124.9 miles.
<http://www.enterpriseitplanet.com/networking/news/article.php/3524491>
<http://pasadena.net/shootout05/>
Even more important, the world record for communicating with a passive 
RFID device was set at 69 feet. Remember that the next time someone 
tells you that it's impossible to read RFID identity cards at a distance.
<http://blogs.washingtonpost.com/securityfix/2005/08/both_black_hat_.html>
<http://www.makezine.com/blog/archive/2005/07/_defcon_rfid_wo.html>
Whenever you hear a manufacturer talk about a distance limitation for 
any wireless technology -- wireless LANs, RFID, Bluetooth, anything -- 
assume he's wrong. If he's not wrong today, he will be in a couple of 
years. Assume that someone who spends some money and effort building 
more sensitive technology can do much better, and that it will take 
less money and effort over the years. Technology always gets better; it 
never gets worse. If something is difficult and expensive now, it will 
get easier and cheaper in the future.

This New York Times op-ed argues that panic is largely a myth. People 
feel stressed but they behave rationally, and it only gets called 
"panic" because of the stress.
<http://www.nytimes.com/2005/08/07/opinion/07fischhoff.html>

Interesting article: "The Hidden Boot Code of the Xbox, or How to fit 
three bugs in 512 bytes of security code."
<http://www.xbox-linux.org/wiki/The_Hidden_Boot_Code_of_the_Xbox>
Microsoft wanted to lock out both pirated games and unofficial games, 
so they built a chain of trust on the Xbox from the hardware to the 
execution of the game code. Only code authorized by Microsoft could run 
on the Xbox. The link between hardware and software in this chain of 
trust is the hidden "MCPX" boot ROM. The article discusses that ROM. 
Lots of kindergarten security mistakes.

An attorney in Australia has successfully used the MD5 Defense -- the 
fact that the hash function is broken -- to fight a highway camera that 
photographs speeders.
<http://theage.com.au/articles/2005/08/10/1123353368652.html>
<http://www.news.com.au/story/0,10117,16204811-1242,00.htm>
This is interesting.  It's true that MD5 is broken. On the other hand, 
it's almost certainly true that the speed cameras were correct. If 
there's any lesson here, it's that theoretical security is important in 
legal proceedings.  I think that's a good thing.
<http://www.schneier.com/crypto-gram-0409.html#3>

A comment on the U.K. government using a border-security failure to 
push for national ID cards:
<http://www.theregister.co.uk/2005/08/04/uk_border_security_analysis/>

Fingerprinting paper:
<http://www.schneier.com/blog/archives/2005/08/fingerprinting_2.html>
This could make an enormous difference in security against 
forgeries.  The idea isn't new.  I remember currency 
anti-counterfeiting research in which fiber-optic bits were added to 
the paper pulp, and a "fingerprint" was taken using a laser.  It didn't 
work then, but it was clever.

Do-it-Yourself Security Checkpoint:
<http://eurobsd.org/2005-WhatTheHack/reports/markhoekstra-030805/DSC0434 
5.JPG> or <http://tinyurl.com/7os5z>

The TSA wants you to get spam:
<http://www.schneier.com/blog/archives/2005/08/tsa_and_spam.html>

Cryptographically-secured murder confession:
<http://seattlepi.nwsource.com/local/aplocal_story.asp?category=6420&slu 
g=ND%20Idaho%20Missing%20Children%20Duncan>

Remember all thost stories about the terrorists hiding messages in 
television broadcasts?  They were all false alarms.
<http://www.guardian.co.uk/life/feature/story/0,13026,1546179,00.html>

The Devil's Infosec Dictionary:
<http://www.csoonline.com/read/080105/debrief.html>
I want it to be funnier.  And I want the entry that mentions me -- 
"Cryptography: The science of applying a complex set of mathematical 
algorithms to sensitive data with the aim of making Bruce Schneier 
exceedingly rich" -- to be more true.  Over at my blog, I'm collecting 
better and funnier definitions.  Join in if you want:
<http://www.schneier.com/blog/archives/2005/08/the_devils_info.html>

LAST MINUTE NEWS:  Wired News reports that the Department of Homeland 
Security is pushing to let Secure Flight use commercial databases, and 
to reduce independent Congressional oversight of the program.
<http://www.wired.com/news/privacy/0,1848,68518,00.html?tw=wn_tophead_1>


** *** ***** ******* *********** *************

                 Shoot-to-Kill



London's Metropolitan Police has a shoot-to-kill policy when dealing 
with suspected suicide terrorists.  And the International Association 
of Chiefs of Police have issued new guidelines that also recommend a 
shoot-to-kill policy.  The theory is that only a direct headshot will 
kill the terrorist immediately, and thus destroy the ability to execute 
a bombing attack.

What might cause a police officer to think you're a suicide bomber, and 
then shoot you in the head?

"The police organization's behavioral profile says such a person might 
exhibit 'multiple anomalies,' including wearing a heavy coat or jacket 
in warm weather or carrying a briefcase, duffel bag or backpack with 
protrusions or visible wires. The person might display nervousness, an 
unwillingness to make eye contact or excessive sweating. There might be 
chemical burns on the clothing or stains on the hands. The person might 
mumble prayers or be 'pacing back and forth in front of a venue.'"

Is that all that's required?

"The police group's guidelines also say the threat to officers does not 
have to be 'imminent,' as police training traditionally teaches. 
Officers do not have to wait until a suspected bomber makes a move, 
another traditional requirement for police to use deadly force. An 
officer just needs to have a 'reasonable basis' to believe that the 
suspect can detonate a bomb, the guidelines say."

This policy is based on the extremely short-sighted assumption that a 
terrorist needs to push buttons to make a bomb explode. In fact, ever 
since World War I, the most common type of bomb carried by a person has 
been the hand grenade. It is entirely conceivable, especially when a 
shoot-to-kill policy is known to be in effect, that suicide bombers 
will use the same kind of dead-man's trigger on their bombs: a 
detonator that is activated when a button is released, rather than when 
it is pushed.  This is a difficult one. Whatever policy you choose, the 
terrorists will adapt to make that policy the wrong one.

It's also a policy that puts people at risk rather than making them 
safer.  The security question to ask is not: "How else can we stop a 
suicide bomber?"  The real question is: "When the police suspect 
someone of being able to detonate a bomb, what should they 
do?"  Backpack bombers are very rare, so much so that anyone whom the 
police suspect will most likely be innocent.

The London police are now sorry they accidentally killed an innocent 
they suspected of being a suicide bomber, but I can certainly 
understand the mistake. In the end, the best solution is to train 
police officers and then leave the decision to them. But honestly, 
policies that are more likely to result in living incarcerated suspects 
who can be interrogated are better than policies that are more likely 
to result in corpses, especially when most suspects will be found innocent.

London policy:
<http://news.bbc.co.uk/2/hi/uk_news/4707781.stm>

International Association of Chiefs of Police policy:
<http://www.washingtonpost.com/wp-dyn/content/article/2005/08/03/AR20050 
80301867.html> or <http://tinyurl.com/acmd9>


** *** ***** ******* *********** *************

                Counterpane News



WilTel Communications is now offering Counterpane managed services to 
its customers:
<http://www.counterpane.com/alliances-news.html>

Schneier was interviewed in Government Technology:
<http://www.govtech.net/magazine/story.php?id=95671>


** *** ***** ******* *********** *************

Visa and Amex Drop CardSystems



Remember CardSystems Solutions, the company that exposed over 40 
million identities to potential fraud? (The actual number of identities 
that will be the victims of fraud is almost certainly much, much lower.)

Both Visa and American Express are dropping them as a payment 
processor:  "Within hours of the disclosure that Visa was seeking a 
replacement for CardSystems Solutions, American Express said Tuesday it 
would no longer do business with the company beginning in October."

The biggest problem with CardSystems' actions wasn't that it had bad 
computer security practices, but that it had bad business practices. It 
was holding exception files with personal information, even though it 
was not supposed to. It was not for marketing, as I originally 
surmised, but to find out why transactions were not being authorized. 
It was disregarding the rules it agreed to follow.

Technical problems can be remediated. A dishonest corporate culture is 
much harder to fix. That was what I sense reading between the lines:

"Visa had been weighing the decision for a few weeks but as recently as 
mid-June said that it was working with CardSystems to correct the 
problem. CardSystems hired an outside security assessor this month to 
review its policies and practices, and it promised to make any 
necessary upgrades by the end of August. CardSystems, in its statement 
yesterday, said the company's executives had been "in almost daily 
contact" with Visa since the problems were discovered in May.

"Visa, however, said that despite 'some remediation efforts' since the 
incident was reported, the actions by CardSystems were not enough."

And this:

"CardSystems Solutions Inc. 'has not corrected, and cannot at this 
point correct, the failure to provide proper data security for Visa 
accounts,' said Rosetta Jones, a spokeswoman for Foster City, 
Calif.-based Visa....

"Visa said that while CardSystems has taken some remediating actions 
since the breach was disclosed, those could not overcome the fact that 
it was inappropriately holding on to account information -- purportedly 
for 'research purposes' -- when the breach occurred, in violation of 
Visa's security rules."

At this point, it is unclear what MasterCard and Discover will do.

"MasterCard International Inc. is taking a different tack with 
CardSystems. The credit card company expects CardSystems to develop a 
plan for improving its security by Aug. 31, 'and as of today, we are 
not aware of any deficiencies in its systems that are incapable of 
being remediated,' spokeswoman Sharon Gamsin said.

"'However, if CardSystems cannot demonstrate that they are in 
compliance by that date, their ability to provide services to 
MasterCard members will be at risk,' she said.

"Jennifer Born, a spokeswoman for Discover Financial Services Inc., 
which also has a relationship with CardSystems, said the Riverwoods, 
Ill.-based company was 'doing our due diligence and will make our 
decision once that process is completed.'"

I think this is a positive development. I have long said that companies 
like CardSystems won't clean up their acts unless there are 
consequences for not doing so. Credit card companies dropping 
CardSystems sends a strong message to the other payment processors: 
improve your security if you want to stay in business.

News articles:
<http://www.ajc.com/news/content/business/0705/20bizcardsystems.html>
<http://www.nytimes.com/2005/07/19/business/19visa.html?adxnnl=1&oref=lo 
gin&adxnnlx=1121913372-DMgsxuIkCLls0Cz84OcAlw> or 
<http://tinyurl.com/ax4qa>
<http://news.yahoo.com/news?tmpl=story&cid=528&e=3&u=/ap/20050720/ap_on_ 
bi_ge/credit_cards_breach> or <http://tinyurl.com/bau3s>

My original essay on CardSystems:
<http://www.schneier.com/crypto-gram-0507.html#3>

Some interesting legal opinions on the larger issue of disclosure:
<http://writ.news.findlaw.com/ramasastry/20050713.html>


** *** ***** ******* *********** *************

              Comments from Readers



From: Ed Gerck <[email protected]>
Subject: Comment on CardSystems article

As you report, credit card companies can and do force companies that 
process credit card data to increase their security. However, how about 
the "acceptable risk" concept that underlies the very security 
procedures of these same credit card companies?

The dirty little secret of the credit card industry is that they are 
very happy with 10% of credit card fraud, over the Internet or not.

In fact, if they would reduce fraud to _zero_ today, their revenue 
would decrease as well as their profits. So, there is really no 
incentive to reduce fraud. On the contrary, keeping the status quo is 
just fine.

This is so because of insurance -- up to a certain level, which is well 
within the operational boundaries of course, a fraudulent transaction 
does not go unpaid through Visa, American Express or MasterCard 
servers.  The transaction is fully paid, with its insurance cost paid 
by the merchant and, ultimately, by the customer.

"Acceptable risk" has been for a long time an euphemism for that 
business model that shifts the burden of fraud to the customer.

Thus, the credit card industry has successfully turned fraud into a 
sale.  This is the same attitude reported to me by a car manufacturer 
representative when I was talking to him about simple techniques to 
reduce car theft -- to which he said: "A car stolen is a car sold."

In fact, a car stolen will need replacement that will be provided by 
insurance or by the customer working again to buy another car, while 
the stolen car continues to generate revenue for the manufacturer in 
service and parts.

Whenever we see continued fraud, we should be certain: the defrauded is 
profiting from it, because no company will accept a continued loss 
without doing anything to reduce it. Arguments such as "we don't want 
to reduce the fraud level because it would cost more to reduce the 
fraud than the fraud costs" are just a marketing way to say that a 
fraud has become a sale.

Because fraud is an hemorrhage that adds up, while efforts to fix it -- 
if done correctly -- are mostly an up front cost that is incurred only 
once.  So, to accept fraud debits is to accept that there is also a 
credit that continuously compensates the debit. Which credit ultimately 
flows from the customer -- just like in car theft.

What is to blame? Not only the twisted ethics behind this attitude but 
also that traditional security school of thought which focus on risk, 
surveillance and insurance as the solution to security problems.

There is no consideration of what trust really would mean in terms of 
bits and machines, no consideration that the insurance model of 
security cannot scale in Internet volumes and cannot even be ethically 
justifiable.

"A fraud is a sale" is the only outcome possible from using such 
security school of thought.  Also sometimes referred to as "acceptable 
risk" -- acceptable indeed, because it is paid for.



From: Tom Welsh <[email protected]>
Subject: Re: IEDs in Iraq

"After a while, U.S. troops got good at spotting and killing the 
triggermen when bombs went off."

Well yes... kinda. Think for a moment, and you can imagine how it would 
go. "If a bomb goes off while we're driving along the road, take out 
any hajis who look as if they might be holding a remote detonator". 
Rat-a-tat-tat! Goodbye to lots of locals, most of whom were checking 
their mobile phones, reading books, getting money out of their wallets, 
etc.

Of course this is exactly what the insurgents are trying to accomplish. 
Killing infidels is OK, but it's not the main goal. Getting the 
infidels to kill civilians is the main goal, and boy do they oblige 
when you goose them right.

I don't know whether it was Vietnam or Mogadishu that was the turning 
point, but at some stage the Pentagon decided that as few American boys 
were going to be hurt as possible when they were in other people's 
countries setting the world to rights. Give a bunch of green troops the 
heaviest firepower that soldiers have ever had at their disposal, and 
tell them to be sure and get their retaliation in first -- as if they 
needed any encouragement -- and guess what happens? Freakily low U.S. 
casualties, tens of thousands of dead and maimed civilians, and a 
popularity rating that is steadily catching up with the Waffen-SS. Give 
them time, they'll be challenging the Allgemeine-SS.

My point is that, from a security expert's point of view, you can win 
the battles and lose the war - and taking out any and all 
"suspicious-looking people" is a great way to do so.



From: Les Jones <[email protected]>
Subject: RE: CRYPTO-GRAM, July 15, 2005

"This advice would have helped Brennan Hawkins, the 11-year-old boy who 
was lost in the Utah wilderness for four days last month.  He avoided 
people searching for him because he had been taught not to talk to 
strangers."

Avoiding rescuers is a common reaction in people who have been lost in 
the woods. See Dwight McCarter's book, "Lost," an account of search and 
rescue operations in the Great Smoky Mountains National Park. In one 
chapter McCarter tells the story of two backpackers in the park who got 
separated while traveling off-trail in the vicinity of Thunderhead. The 
less-experienced hiker quickly got lost.

After a day or two wandering around he was going through his pack and 
found a backpacking how-to book that explained what to do in case you 
got lost in the woods. Following the advice, he went to a clearing and 
built a signal fire. A rescue helicopter saw the smoke and hovered 
overhead above the tree tops as he waved his arms to attract their 
attention. The helicopter dropped a sleeping bag and food, with a note 
saying they couldn't land in the clearing, but that they would send in 
a rescue party on foot.

The lost hiker sat down, tended his fire, and waited for rescue. When 
the rescuers appeared at the edge of the clearing, he panicked, jumped 
up, and ran in the other direction. They had to chase him down to 
rescue him. This despite the fact that he wanted to be rescued, had 
taken active steps to attract rescuers, and knew that rescuers were 
coming to him. Odd but true.



From: Tamas K Papp
Subject: Re: Talking to Strangers

You claim that "'don't talk to strangers" is just about the worst 
possible advice you can give a child."

The "security policy" of not talking to strangers actually covers two 
distinct situations:

(A)  Don't initiate conversation with strangers.

(B)  Do not respond if strangers try to talk to you.

In (A), we are dealing with the prior probability (e.g., their 
proportion in the population of the area, etc) of strangers being 
harmless or dangerous (p(H) and p(D), respectively).  I agree with your 
conclusion that in any normal society, p(D) is very small, hence the 
advice of paranoid parents doesn't make much sense in this case.

However, careful analysis of (B) shows that here we are dealing with 
the posterior probability of strangers being dangerous _given_ that 
they initiated the conversation (we will denote that by T).  You can 
use Bayes' Rule to calculate this; i.e.:

p(D|T) = p(T|D)p(D)/p(T)

where p(T) = p(T|D)p(D) + p(T|H)p(H) is the probability that strangers 
of any kind talk to you.  In a society where "normal" people don't talk 
to strangers, p(T|H) is close to zero, while it is possible that 
dangerous people (child molesters, criminals) will talk to children 
with significant probability, thus p(T|D) will be larger than zero.

Thus even if p(D) is low, p(D|T) might be high enough for part (B) to 
make sense: you use the information in the signal to revise your 
estimate of strangers being dangerous.

Parents might think that the distinction between (A) and (B) is too 
subtle for a little child, and resort to the suboptimal but simple rule 
of not talking to strangers.

I agree with you that "[i]n a world where good guys are common and bad 
guys are rare, assuming a random person is a good guy is a smart 
security strategy".  However, ignoring signals that help revise your 
probability estimates is a bad security strategy.


** *** ***** ******* *********** *************

CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses, 
insights, and commentaries on security: computer and otherwise.  You 
can subscribe, unsubscribe, or change your address on the Web at 
<http://www.schneier.com/crypto-gram.html>.  Back issues are also 
available at that URL.

Comments on CRYPTO-GRAM should be sent to 
[email protected].  Permission to print comments is assumed 
unless otherwise stated.  Comments may be edited for length and clarity.

Please feel free to forward CRYPTO-GRAM to colleagues and friends who 
will find it valuable.  Permission is granted to reprint CRYPTO-GRAM, 
as long as it is reprinted in its entirety.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is the author of 
the best sellers "Beyond Fear," "Secrets and Lies," and "Applied 
Cryptography,"  and an inventor of the Blowfish and Twofish 
algorithms.  He is founder and CTO of Counterpane Internet Security 
Inc., and is a member of the Advisory Board of the Electronic Privacy 
Information Center (EPIC).  He is a frequent writer and lecturer on 
security topics.  See <http://www.schneier.com>.

Counterpane is the world's leading protector of networked information - 
the inventor of outsourced security monitoring and the foremost 
authority on effective mitigation of emerging IT threats. Counterpane 
protects networks for Fortune 1000 companies and governments 
world-wide.  See <http://www.counterpane.com>.

Crypto-Gram is a personal newsletter.  Opinions expressed are not 
necessarily those of Counterpane Internet Security, Inc.

Copyright (c) 2005 by Bruce Schneier.