CRYPTO-GRAM, January 15, 2006

Bruce Schneier <[email protected]> Sun, 15 Jan 2006 01:36:16 -0600
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

               January 15, 2006

               by Bruce Schneier
                Founder and CTO
       Counterpane Internet Security, Inc.
            [email protected]
            <http://www.schneier.com>
           <http://www.counterpane.com>


A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0601.html>.  These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>.  An RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
      Anonymity and Accountability
      Cell Phone Companies and Security
      Crypto-Gram Reprints
      Dutch Botnet
      Internet Explorer Sucks
      Security Notes from All Over: Electronic Shackles and
        Telephone Communications
      News
      Insider Threat Statistics
      Are Computer-Security Export Controls Back?
      Vehicle Tracking in the UK
      Counterpane News
      NSA and Bush's Illegal Eavesdropping
      The Security Threat of Unchecked Presidential Power
      Project Shamrock
      Comments from Readers

** *** ***** ******* *********** *************

      Anonymity and Accountability



In a recent essay, Kevin Kelly warns of the dangers of anonymity. It's=20
OK in small doses, he maintains, but too much of it is a problem: "(I)n=20
every system that I have seen where anonymity becomes common, the=20
system fails. The recent taint in the honor of Wikipedia stems from the=20
extreme ease which anonymous declarations can be put into a very=20
visible public record. Communities infected with anonymity will either=20
collapse, or shift the anonymous to pseudo-anonymous, as in eBay, where=20
you have a traceable identity behind an invented nickname."=09

Kelly has a point, but it comes out all wrong. Anonymous systems are=20
inherently easier to abuse and harder to secure, as his eBay example=20
illustrates. In an anonymous commerce system -- where the buyer does=20
not know who the seller is and vice versa -- it's easy for one to cheat=20
the other. This cheating, even if only a minority engaged in it, would=20
quickly erode confidence in the marketplace, and eBay would be out of=20
business. The auction site's solution was brilliant: a feedback system=20
that attached an ongoing "reputation" to those anonymous user names,=20
and made buyers and sellers accountable for their actions.

And that's precisely where Kelly makes his mistake. The problem isn't=20
anonymity; it's accountability. If someone isn't accountable, then=20
knowing his name doesn't help. If you have someone who is completely=20
anonymous, yet just as completely accountable, then -- heck, just call=20
him Fred.

History is filled with bandits and pirates who amass reputations=20
without anyone knowing their real names.

EBay's feedback system doesn't work because there's a traceable=20
identity behind that anonymous nickname. EBay's feedback system works=20
because each anonymous nickname comes with a record of previous=20
transactions attached, and if someone cheats someone else then=20
everybody knows it.

Similarly, Wikipedia's veracity problems are not a result of anonymous=20
authors adding fabrications to entries. They're an inherent property of=20
an information system with distributed accountability. People think of=20
Wikipedia as an encyclopedia, but it's not. We all trust Britannica=20
entries to be correct because we know the reputation of that company,=20
and by extension its editors and writers. On the other hand, we all=20
should know that Wikipedia will contain a small amount of false=20
information because no particular person is accountable for accuracy --=20
and that would be true even if you could mouse over each sentence and=20
see the name of the person who wrote it.

Historically, accountability has been tied to identity, but there's no=20
reason why it has to be so. My name doesn't have to be on my credit=20
card. I could have an anonymous photo ID that proved I was of legal=20
drinking age. There's no reason for my e-mail address to be related to=20
my legal name.

This is what Kelly calls pseudo-anonymity. In these systems, you hand=20
your identity to a trusted third party that promises to respect your=20
anonymity to a limited degree. For example, I have a credit card in=20
another name from my credit-card company. It's tied to my account, but=20
it allows me to remain anonymous to merchants I do business with.

The security of pseudo-anonymity inherently depends on how trusted that=20
"trusted third party" is. Depending on both local laws and how much=20
they're respected, pseudo-anonymity can be broken by corporations, the=20
police or the government. It can be broken by the police collecting a=20
whole lot of information about you, or by ChoicePoint collecting=20
billions of tiny pieces of information about everyone and then making=20
correlations. Pseudo-anonymity is only limited anonymity. It's=20
anonymity from those without power, and not from those with power.=20
Remember that anon.penet.fi couldn't stay up in the face of government.

In a perfect world, we wouldn't need anonymity. It wouldn't be=20
necessary for commerce, since no one would ostracize or blackmail you=20
based on what you purchased. It wouldn't be necessary for internet=20
activities, because no one would blackmail or arrest you based on who=20
you corresponded with or what you read. It wouldn't be necessary for=20
AIDS patients, members of fringe political parties or people who call=20
suicide hotlines. Yes, criminals use anonymity, just like they use=20
everything else society has to offer. But the benefits of anonymity --=20
extensively discussed in an excellent essay by Gary T. Marx -- far=20
outweigh the risks.

In Kelly's world -- a perfect world -- limited anonymity is enough=20
because the only people who would harm you are individuals who cannot=20
learn your identity, and not those in power who can.

We do not live in a perfect world. We live in a world where information=20
about our activities -- even ones that are perfectly legal -- can=20
easily be turned against us. Recent news reports have described a=20
student being hounded by his college because he said uncomplimentary=20
things in his blog, corporations filing SLAPP lawsuits against people=20
who criticize them, and people being profiled based on their political=20
speech.

We live in a world where the police and the government are made up of=20
less-than-perfect individuals who can use personal information about=20
people, together with their enormous power, for imperfect purposes.=20
Anonymity protects all of us from the powerful by the simple measure of=20
not letting them get our personal information in the first place.

This essay originally appeared in Wired:
<http://www.wired.com/news/columns/0,70000-0.html>

Kelly's original essay:
<http://www.edge.org/q2006/q06_4.html>

Gary T. Marx on anonymity:
<http://web.mit.edu/gtmarx/www/anon.html>


** *** ***** ******* *********** *************

      Cell Phone Companies and Security



This is a fascinating story of cell phone fraud, security, economics,=20
and externalities.  Its moral is obvious, and demonstrates how economic=20
considerations drive security decisions.  According to "The Globe and=20
Mail":

"Susan Drummond was a customer of Rogers Wireless, a large Canadian=20
cell phone company.  Her phone was cloned while she was on vacation,=20
and she got a $12,237.60 phone bill (her typical bill was $75).  Rogers=20
maintains that there is nothing to be done, and that Drummond has to pay."

Like all cell phone companies, Rogers has automatic fraud detection=20
systems that detect this kind of abnormal cell phone usage.  They don't=20
turn the cell phones off, though, because they don't want to annoy=20
their customers.

"Ms. Hopper [a manager in Roger's security department] said terrorist=20
groups had identified senior cell phone company officers as perfect=20
targets, since the company was loath to shut off their phones for=20
reasons that included inconvenience to busy executives and, of course,=20
the public-relations debacle that would take place if word got out."

As long as Rogers can get others to pay for the fraud, this makes=20
perfect sense.  Shutting off a phone based on an automatic=20
fraud-detection system costs the phone company in two ways: people=20
inconvenienced by false alarms, and bad press.  But the major cost of=20
not shutting off a phone remains an externality: the customer pays for it.

In fact, there seems be some evidence that Rogers decides whether or=20
not to shut off a suspicious phone based on the customer's ability to pay:

"Ms. Innes [a vice-president with Rogers Communications] said that=20
Rogers has a policy of contacting consumers if fraud is suspected. In=20
some cases, she admitted, phones are shut off automatically, but=20
refused to say what criteria were used. (Ms. Drummond and Mr. Gefen=20
believe that the company bases the decision on a customer's=20
creditworthiness. 'If you have the financial history, they let the=20
meter run,' Ms. Drummond said.) Ms. Drummond noted that she has a=20
salary of more than $100,000, and a sterling credit history. 'They knew=20
something was wrong, but they thought they could get the money out of=20
me. It's ridiculous.'"

Makes sense from Rogers' point of view.  High-paying customers are 1)=20
more likely to pay, and 2) more damaging if pissed off in a false=20
alarm.  Again, economic considerations trump security.

Rogers is defending itself in court, and shows no signs of backing down:

"In court filings, the company has made it clear that it intends to=20
hold Ms. Drummond responsible for the calls made on her phone. '. . .=20
the plaintiff is responsible for all calls made on her phone prior to=20
the date of notification that her phone was stolen,' the company says.=20
'The Plaintiff's failure to mitigate deprived the Defendant of the=20
opportunity to take any action to stop fraudulent calls prior to the=20
28th of August 2005.'"

The solution here is obvious: Rogers should not be able to charge its=20
customers for telephone calls they did not make.  Ms. Drummond's phone=20
was cloned; there is no possible way she could notify Rogers of this=20
before she saw calls she did not make on her bill.  She is also=20
completely powerless to affect the anti-cloning security in the Rogers=20
phone system.  To make her liable for the fraud is to ensure that the=20
problem never gets fixed.

Rogers is the only party in a position to do something about the=20
problem.  The company can, and according to the article has,=20
implemented automatic fraud-detection software.

Rogers customers will pay for the fraud in any case.  If they are=20
responsible for the loss, either they'll take their chances and pay a=20
lot only if they are the victims, or there'll be some insurance scheme=20
that spreads the cost over the entire customer base.  If Rogers is=20
responsible for the loss, then the customers will pay in the form of=20
slightly higher prices.  But only if Rogers is responsible for the loss=20
will they implement security countermeasures to limit fraud.

And if they do that, everyone benefits.

<http://www.globetechnology.com/servlet/story/RTGAM.20051217.wxcellphone=20
1217/BNStory/Technology/> or <http://tinyurl.com/ajl83>
<http://it.slashdot.org/article.pl?sid=3D05/12/17/1729245&tid=3D172&tid=3D21=
5>=20
  or <http://tinyurl.com/cb7j2>


** *** ***** ******* *********** *************

      Crypto-Gram Reprints



Crypto-Gram is currently in its ninth year of publication.  Back issues=20
cover a variety of security-related topics, and can all be found on=20
<http://www.schneier.com/crypto-gram-back.html>.  These are a selection=20
of articles that appeared in this calendar month in other years.

Fingerprinting Students:
<http://www.schneier.com/crypto-gram-0501.html#1>

Cyberwar:
<http://www.schneier.com/crypto-gram-0501.html#10>

Diverting Aircraft and National Intelligence:
<http://www.schneier.com/crypto-gram-0401.html#11>

Fingerprinting Foreigners:
<http://www.schneier.com/crypto-gram-0401.html#3>

Color-coded Terrorist Threat Levels:
<http://www.schneier.com/crypto-gram-0401.html#1>

Militaries and Cyber-War:
<http://www.schneier.com./crypto-gram-0301.html#1>

A cyber Underwriters Laboratories?
<http://www.schneier.com/crypto-gram-0101.html#1>

Code signing:
<http://www.schneier.com/crypto-gram-0101.html#10>

Block and stream ciphers:
<http://www.schneier.com/crypto-gram-0001.html#BlockandStreamCiphers>


** *** ***** ******* *********** *************

      Dutch Botnet



Back in October, the Dutch police arrested three people who created a=20
large botnet and used it to extort money from U.S. companies.  When the=20
trio was arrested, authorities said that the botnet consisted of about=20
100,000 computers.  The actual number was 1.5 million computers.

And I've heard reports from reputable sources that the actual actual=20
number was "significantly higher."

And it may still be growing.  The bots continually scan the network and=20
try to infect other machines.  They do this autonomously, even after=20
the command and control node was shut down.  Since most of those 1.5=20
million machines -- or however many there are -- still have the botnet=20
software running on them, it's reasonable to believe that the botnet is=20
still growing.

<http://informationweek.com/story/showArticle.jhtml?articleID=3D172303265>=
=20
  or <http://tinyurl.com/95s5e>


** *** ***** ******* *********** *************

      Internet Explorer Sucks



This study is from August, but I missed it.  The researchers tracked=20
three browsers (MSIE, Firefox, Opera) in 2004 and counted which days=20
they were "known unsafe."  Their definition of "known unsafe": a=20
remotely exploitable security vulnerability had been publicly announced=20
and no patch was yet available.

MSIE was 98% unsafe.  There were only 7 days in 2004 without an=20
unpatched publicly disclosed security hole.

Firefox was 15% unsafe.  There were 56 days with an unpatched publicly=20
disclosed security hole.  30 of those days were a Mac hole that only=20
affected Mac users.  Windows Firefox was 7% unsafe.

Opera was 17% unsafe: 65 days.  That number is accidentally a little=20
better than it should be, as two of the unpatched periods happened to=20
overlap.

This underestimates the risk, because it doesn't count vulnerabilities=20
known to the bad guys but not publicly disclosed (and it's foolish to=20
think that such things don't exist).  So the "98% unsafe" figure for=20
MSIE is generous, and the situation might be even worse.

<http://bcheck.scanit.be/bcheck/page.php?name=3DSTATS2004>


** *** ***** ******* *********** *************

      Security Notes from All Over: Electronic Shackles and
        Telephone Communications



The article is in Hebrew, but the security story is funny in any language.

It's about a prisoner who was forced to wear an electronic shackle to=20
monitor that he did not violate his home arrest.  The shackle is pretty=20
simple: if the suspect leaves the defined detention area, the=20
electronic shackle signals through the telephone line to the local police.

How do you defeat a system such as this?  Just stop paying your phone=20
bill and wait for the phone company to shut off service.

<http://www.haaretz.co.il/hasite/pages/ShArt.jhtml?contrassID=3D1&subContr=
=20
assID=3D5&sbSubContrassID=3D0&itemNo=3D660328> or <http://tinyurl.com/bjhth>


** *** ***** ******* *********** *************

      News



Two stories that shamelessly hype computer crime:
<http://www.cnn.com/SPECIALS/2005/online.security/>
<http://www.usatoday.com/tech/news/internetprivacy/2005-12-14-meth-onlin=20
e-theft_x.htm> or <http://tinyurl.com/a2be8>
Beware the Four Horsemen of the Information Apocalypse: terrorists,=20
drug dealers, kidnappers, and child pornographers.  Seems like you can=20
scare the public into allowing the government to do anything with those=20
four.

Microsoft received a Common Criteria (CC) EAL 4+ certification for=20
Windows, demonstrating how weak such a certification really is:
<http://www.eweek.com/article2/0,1895,1901965,00.asp>

After FBI agents expressed frustration that the Office of Intelligence=20
Policy and Review wasn't approving their orders under Section 215 of=20
the Patriot Act, procedural changes were made allowing the FBI to=20
bypass that office.
<http://www.epic.org/foia_notes/note10.html>
Remember, the issue here is not whether or not the FBI can engage in=20
counterterrorism.  The issue is the erosion of judicial oversight --=20
the only check we have on police power.  And this power grab is=20
dangerous regardless of which party is in the White House at the moment.

Meanwhile, the U.S. military is spying on Americans.  Specifically, the=20
Department of Defense is collecting data on legal and peaceful war=20
protesters, in violation of U.S. law.
<http://www.msnbc.msn.com/id/10454316/>

Four hundred pounds of high explosive stolen from a "bunker" outside=20
Albuquerque owned by Cherry Engineering.  Note that it had no guards=20
and no surveillance cameras:
<http://www.abcnews.go.com/GMA/story?id=3D1424214>
It was recovered:
<http://www.atf.gov/press/fy06press/field/122405pho_atf_new_mexico.htm>=20
or <http://tinyurl.com/d6gc4>

An interesting interview with OpenSSH developer Damien Miller:
<http://www.securityfocus.com/columnists/375>

Adaptable criminals: as automobile security devices become more=20
effective, thieves are more likely to break into homes in order to=20
steal the keys.
<http://www.themercury.news.com.au/common/story_page/0,5936,17605616^346=20
2,00.html> or <http://tinyurl.com/8ytkp>

Idiotic article on TPM:
<http://www.msnbc.msn.com/ID/10441443>
My commentary:
<http://www.schneier.com/blog/archives/2005/12/idiotic_article.html>

Here's a child pornographer who received the Sober.Y worm.  This worm=20
has an official-sounding message to entice recipients to open the=20
attachment.  He got so scared that he turned himself into the police.
<http://news.yahoo.com/s/nm/20051220/wr_nm/crime_germany_worm_dc>

The story of the UMass Dartmouth student who claimed that Homeland=20
Security agents visited him after he requested Mao Zedong's "Little Red=20
Book" from the library is a hoax:
<http://www.southcoasttoday.com/daily/12-05/12-24-05/a01lo719.htm>
I don't know what the moral is, here. 1) He's an idiot. 2) Don't=20
believe everything you read. 3) We live in such an invasive political=20
climate that such stories are easily believable. 4) He's definitely an=20
idiot.

New TSA guidelines from The Onion:
<http://www.theonion.com/content/node/43716>

Richard M Smith has some interesting ideas on how to test if the NSA is=20
eavesdropping on your e-mail.
<http://www.computerbytesman.com/privacy/emailsnooping.htm>
The only problem is that you might get a knock on your door by some=20
random investigative agency.  Or get searched every time you try to get=20
on an airplane.  But I think that risk is pretty low, actually.  If=20
people actually do this, please report back.  I'm very curious.

Good essay on bug bounties, and why they're not a substitute for=20
security auditing:
<http://www.pebbleandavalanche.com/weblog/2005/12/19/blog-20051219T0454>=20
  or <http://tinyurl.com/896bh>
This is not to say that bug bounties aren't a good idea.  They're a=20
good addition to rigorous software development and testing.

Bomb-sniffing wasps may be more effective--and cheaper--than alternatives:
<http://www.usatoday.com/tech/news/2005-12-26-wasps-terrorism_x.htm>
Bomb-sniffing bees, too:
<http://www.defensetech.org/archives/001754.html>

Here's how to make an RFID-blocking wallet out of duct tape:
<http://www.rpi-polymath.com/ducttape/RFIDWallet.php>

The U.S. Department of Justice is no better than anyone else at=20
protecting individual privacy:
<http://www.informationweek.com/news/showArticle.jhtml?articleID=3D1754001=
=20
50> or <http://tinyurl.com/exs27>

Good stuff about the unforeseen security effects of weak ID cards:
<http://www.theregister.co.uk/2005/12/28/lords_voluntary_id_register_pla=20
n> or <http://tinyurl.com/7nvz4>

EPIC's Top Ten Privacy Stories of 2005, and their Top Ten Issues to=20
Watch in 2006.  Definitely worth reading.
<http://www.epic.org/alert/EPIC_Alert_yir2005.html>

The Treasury Department estimates that cybercrime netted $105 billion=20
in 2004, more than illegal drugs.  The question always is: how did they=20
calculate that number?  If I download an audio CD, is that $15 in=20
cybercrime?  If so, don't believe the total.
<http://money.cnn.com/2005/12/29/technology/computer_security/index.htm>=20
  or <http://tinyurl.com/aaskv>

A hand-held device that disables passive RFID chips:
<https://events.ccc.de/congress/2005/wiki/RFID-Zapper(EN)>

A fascinating data-mining experiment using Amazon wish lists:
<http://www.applefritter.com/node/view/10074>
Now, imagine the false alarms and abuses that are possible if you have=20
lots more data, and lots more computers to slice and dice it.  Of=20
course, there are applications where this sort of data mining makes a=20
whole lot of sense.  But finding terrorists isn't one of them.  It's a=20
needle-in-a-haystack problem, and piling on more hay doesn't help=20
matters much.

In Wisconsin, electronic voting machines must produce paper ballots and=20
have open-source software.
<http://wistechnology.com/article.php?id=3D2585>
My previous essays on electronic voting:
<http://www.schneier.com/essay-068.html>
<http://www.schneier.com/crypto-gram-0312.html#9>
<http://www.schneier.com/crypto-gram-0012.html#1>

An airline passenger wrote the words "suicide bomber" in his journal,=20
and was arrested.
<http://news.yahoo.com/s/nm/20060105/od_uk_nm/oukoe_uk_life_passenger>
<http://www.mercurynews.com/mld/mercurynews/news/local/states/california=20
/the_valley/13551154.htm> or <http://tinyurl.com/b2yu7>
My commentary is here:
<http://www.schneier.com/blog/archives/2006/01/stupid_band_nam.html>

Anyone can get anyone's phone records:
<http://www.suntimes.com/output/news/cst-nws-privacy05.html>
<http://www.concurringopinions.com/archives/2006/01/cell_phone_reco_1.html>
<http://www.boingboing.net/2006/01/08/online_service_claim.html>
<http://west.epic.org/archives/2006/01/pretexting_isnt.html>
Seems like this is done by something called "pretexting," which means=20
calling up the phone company and lying about who you are.  Sounds like=20
fraud to me.

Annoying people anonymously on the Internet is against U.S. law:
<http://news.com.com/Create+an+e-annoyance%2C+go+to+jail/2010-1028_3-602=20
2491.html> or <http://tinyurl.com/a2kqp>
See the comment by an attorney, who says this was previously true:
<http://www.boingboing.net/2006/01/09/flame_someone_anonym.html>
What does it mean for our society when obviously stupid laws like this=20
get passed, and we have to rely on the police being nice enough to not=20
enforce them?

Security checks for space travelers, including physical screening and=20
matching people against a watch list:
<http://www.cnn.com/2006/TECH/space/01/04/space.travel.reut>
<http://news.bbc.co.uk/1/hi/sci/tech/4589072.stm>

"Residents of a trendy London neighbourhood are to become the first in=20
Britain to receive 'Asbo TV' -- television beamed live to their homes=20
from CCTV cameras on the surrounding streets."
<http://www.timesonline.co.uk/article/0,,2087-1974974,00.html>

Interesting story about forged credentials and security:
<http://www.schneier.com/blog/archives/2006/01/forged_credenti.html>

REAL ID is turning out to be more expensive than initially anticipated.
<http://news.yahoo.com/s/ap/20060112/ap_on_re_us/real_id>
Remember, security is a trade-off.  REAL ID is a bad idea primarily=20
because the security gained is not worth the enormous expense.

The ACLU has a new site on REAL ID:
<http://www.realnightmare.org/>


** *** ***** ******* *********** *************

      Insider Threat Statistics



Interesting statistics from Europe.  (I doubt they're any different in=20
the U.S.)

* One in five workers (21%) let family and friends use company laptops=20
and PCs to access the Internet.

* More than half (51%) connect their own devices or gadgets to their=20
work PC.

* A quarter of these do so every day.

* Around 60% admit to storing personal content on their work PC.

* One in ten confessed to downloading content at work they shouldn't.

* Two thirds (62%) admitted they have a very limited knowledge of IT=20
Security.

* More than half (51%) had no idea how to update the anti-virus=20
protection on their company PC.

* Five percent say they have accessed areas of their IT system they=20
shouldn't have.

One caveat: the study is from McAfee, who has a vested interest in=20
inflating this sort of threat.

I like their "four types of employees who put their workplace at=20
risk":  the Security Softie, the Gadget Geek, the Squatter, and the=20
Saboteur.

<http://www.theregister.co.uk/2005/12/15/mcafee_internal_security_survey=20
/> or <http://tinyurl.com/8rjz5>


** *** ***** ******* *********** *************

      Are Computer-Security Export Controls Back?



I thought U.S. export regulations were finally over and done with, at=20
least for software.   Then why is Symantec sending this to foreign=20
customers:

"Unfortunately, due to strict US Government export regulations Symantec=20
is only able to fulfill new LC5 orders or offer technical support=20
directly with end-users located in the United States and commercial=20
entities in Canada, provided all screening is successful.

"Commodities, technology or software is subject to U.S. Dept. of=20
Commerce, Bureau of Industry and Security control if exported or=20
electronically transferred outside of the USA. Commodities, technology=20
or software are controlled under ECCN 5A002.c.1, cryptanalytic.

"You can also access further information on our web site at the=20
following address:=20
<http://www.symantec.com/region/reg_eu/techsupp/enterprise/index.html>"

The software in question is the password breaking and auditing tool=20
called LC5, better known as L0phtCrack.  Look to me like they're just=20
killing it, and using the government as an excuse.

<http://www.theregister.co.uk/2005/11/25/symantec_l0phtcrack_export_cont=20
roversy/> or <http://tinyurl.com/89vto>
<http://it.slashdot.org/article.pl?sid=3D05/12/22/1548209>


** *** ***** ******* *********** *************

      Vehicle Tracking in the UK



Universal automobile surveillance is coming.  According to "The=20
Independent":

"Britain is to become the first country in the world where the=20
movements of all vehicles on the roads are recorded. A new national=20
surveillance system will hold the records for at least two years.

"Using a network of cameras that can automatically read every passing=20
number plate, the plan is to build a huge database of vehicle movements=20
so that the police and security services can analyse any journey a=20
driver has made over several years.

"The network will incorporate thousands of existing CCTV cameras which=20
are being converted to read number plates automatically night and day=20
to provide 24/7 coverage of all motorways and main roads, as well as=20
towns, cities, ports and petrol-station forecourts.

"By next March a central database installed alongside the Police=20
National Computer in Hendon, north London, will store the details of 35=20
million number-plate "reads" per day. These will include time, date and=20
precise location, with camera sites monitored by global positioning=20
satellites. "

In another article, "The Independent" opines that this is only the=20
beginning:

"The new national surveillance network for tracking car journeys, which=20
has taken more than 25 years to develop, is only the beginning of plans=20
to monitor the movements of all British citizens. The Home Office=20
Scientific Development Branch in Hertfordshire is already working on=20
ways of automatically recognising human faces by computer, which many=20
people would see as truly introducing the prospect of Orwellian street=20
surveillance, where our every move is recorded and stored by machines.

"Although the problems of facial recognition by computer are far more=20
formidable than for car number plates, experts believe it is only a=20
matter of time before machines can reliably pull a face out of a crowd=20
of moving people.

"If the police and security services can show that a national=20
surveillance operation based on recording car movements can protect the=20
public against criminals and terrorists, there will be a strong=20
political will to do the same with street cameras designed to monitor=20
the flow of human traffic. "

I've already written about the security risks of what I call "wholesale=20
surveillance."  Once this information is collected, it will be misused,=20
lost, and stolen.  It will be filled with errors. The problems and=20
insecurities that come from living in a surveillance society more than=20
outweigh any crimefighting (and terrorist-fighting) advantages.

<http://news.independent.co.uk/uk/transport/article334686.ece>
<http://news.independent.co.uk/world/science_technology/article334684.ece>

My previous essays on wholesale surveillance:
<http://www.schneier.com/essay-061.html>
<http://www.schneier.com/essay-057.html>


** *** ***** ******* *********** *************

      Counterpane News



Counterpane announced a partnership with Verano to extend monitoring to=20
real-time control systems.
<http://www.counterpane.com/pr-20060109.html>

Schneier is speaking at the RSA Conference, February 14-26, in San=20
Jose. He will speak on "The Economics of Security" at 4:30 PM on the=20
14th, and again on "Why Security Has So Little to Do with Security" at=20
2:00 PM on the 15th. He will participate in a main-stage panel on ID=20
cards at 8:00 AM on the 16th.
<http://2006.rsaconference.com/us/>

Gartner has named Counterpane as the leading visionary company in its=20
December 2005 Managed Security Services Provider Magic Quadrant report.
<http://www.counterpane.com/pr-20060113.html>



** *** ***** ******* *********** *************

      NSA and Bush's Illegal Eavesdropping



(Note: I wrote this essay in the days after the scandal broke.)

When President Bush directed the National Security Agency to secretly=20
eavesdrop on American citizens, he transferred an authority previously=20
under the purview of the Justice Department to the Defense Department=20
and bypassed the very laws put in place to protect Americans against=20
widespread government eavesdropping. The reason may have been to tap=20
the NSA's capability for data-mining and widespread surveillance.

Illegal wiretapping of Americans is nothing new. In the 1950s and '60s,=20
in a program called "Project Shamrock," the NSA intercepted every=20
single telegram coming into or going out of the United States. It=20
conducted eavesdropping without a warrant on behalf of the CIA and=20
other agencies. Much of this became public during the 1975 Church=20
Committee hearings and resulted in the now famous Foreign Intelligence=20
Surveillance Act (FISA) of 1978.

The purpose of this law was to protect the American people by=20
regulating government eavesdropping. Like many laws limiting the power=20
of government, it relies on checks and balances: one branch of the=20
government watching the other. The law established a secret court, the=20
Foreign Intelligence Surveillance Court (FISC), and empowered it to=20
approve national-security-related eavesdropping warrants. The Justice=20
Department can request FISA warrants to monitor foreign communications=20
as well as communications by American citizens, provided that they meet=20
certain minimal criteria.

The FISC issued about 500 FISA warrants per year from 1979 through=20
1995, and has slowly increased subsequently -- 1,758 were issued in=20
2004. The process is designed for speed and even has provisions where=20
the Justice Department can wiretap first and ask for permission later.=20
In all that time, only four warrant requests were ever rejected: all in=20
2003. (We don't know any details, of course, as the court proceedings=20
are secret.)

FISA warrants are carried out by the FBI, but in the days immediately=20
after the terrorist attacks, there was a widespread perception in=20
Washington that the FBI wasn't up to dealing with these new threats --=20
they couldn't uncover plots in a timely manner. So instead the Bush=20
administration turned to the NSA. They had the tools, the expertise,=20
the experience, and so they were given the mission.

The NSA's ability to eavesdrop on communications is exemplified by a=20
technological capability called Echelon. Echelon is the world's largest=20
information "vacuum cleaner," sucking up a staggering amount of voice,=20
fax, and data communications -- satellite, microwave, fiber-optic,=20
cellular and everything else -- from all over the world: an estimated 3=20
billion communications per day. These communications are then processed=20
through sophisticated data-mining technologies, which look for simple=20
phrases like "assassinate the president" as well as more complicated=20
communications patterns.

Supposedly Echelon only covers communications outside of the United=20
States. Although there is no evidence that the Bush administration has=20
employed Echelon to monitor communications to and from the U.S., this=20
surveillance capability is probably exactly what the president wanted=20
and may explain why the administration sought to bypass the FISA=20
process of acquiring a warrant for searches.

Perhaps the NSA just didn't have any experience submitting FISA=20
warrants, so Bush unilaterally waived that requirement. And perhaps=20
Bush thought FISA was a hindrance -- in 2002 there was a widespread but=20
false belief that the FISC got in the way of the investigation of=20
Zacarias Moussaoui (the presumed "20th hijacker") -- and bypassed the=20
court for that reason.

Most likely, Bush wanted a whole new surveillance paradigm. You can=20
think of the FBI's capabilities as "retail surveillance": It eavesdrops=20
on a particular person or phone. The NSA, on the other hand, conducts=20
"wholesale surveillance." It, or more exactly its computers, listens to=20
everything. An example might be to feed the computers every voice, fax,=20
and e-mail communication looking for the name "Ayman al-Zawahiri." This=20
type of surveillance is more along the lines of Project Shamrock, and=20
not legal under FISA. As Sen. Jay Rockefeller wrote in a secret memo=20
after being briefed on the program, it raises "profound oversight issues."

It is also unclear whether Echelon-style eavesdropping would prevent=20
terrorist attacks. In the months before 9/11, Echelon noticed=20
considerable "chatter": bits of conversation suggesting some sort of=20
imminent attack. But because much of the planning for 9/11 occurred=20
face-to-face, analysts were unable to learn details.

The fundamental issue here is security, but it's not the security most=20
people think of. James Madison famously said: "If men were angels, no=20
government would be necessary. If angels were to govern men, neither=20
external nor internal controls on government would be necessary."=20
Terrorism is a serious risk to our nation, but an even greater threat=20
is the centralization of American political power in the hands of any=20
single branch of the government.

Over 200 years ago, the framers of the U.S. Constitution established an=20
ingenious security device against tyrannical government: they divided=20
government power among three different bodies. A carefully thought out=20
system of checks and balances in the executive branch, the legislative=20
branch, and the judicial branch, ensured that no single branch became=20
too powerful.

After watching tyrannies rise and fall throughout Europe, this seemed=20
like a prudent way to form a government. Courts monitor the actions of=20
police. Congress passes laws that even the president must follow. Since=20
9/11, the United States has seen an enormous power grab by the=20
executive branch. It's time we brought back the security system that's=20
protected us from government for over 200 years.

A version of this essay originally appeared in Salon:
<http://www.salon.com/opinion/feature/2005/12/20/surveillance/>

Text of FISA:
<http://www.law.cornell.edu/uscode/html/uscode50/usc_sup_01_50_10_36_20_=20
I.html> or <http://tinyurl.com/d7ra4>

Summary of annual FISA warrants:
<http://www.epic.org/privacy/wiretap/stats/fisa_stats.html>

Rockefeller's secret memo:
<http://talkingpointsmemo.com/docs/rock-cheney1.html>

Much more here:
<http://www.schneier.com/blog/archives/2005/12/nsa_and_bushs_i.html>


** *** ***** ******* *********** *************

      The Security Threat of Unchecked Presidential Power



Last Thursday [15 December 2005], the "New York Times" exposed the most=20
significant violation of federal surveillance law in the post-Watergate=20
era. President Bush secretly authorized the National Security Agency to=20
engage in domestic spying, wiretapping thousands of Americans and=20
bypassing the legal procedures regulating this activity.

This isn't about the spying, although that's a major issue in itself.=20
This is about the Fourth Amendment protections against illegal search.=20
This is about circumventing a teeny tiny check by the judicial branch,=20
placed there by the legislative branch, placed there 27 years ago -- on=20
the last occasion that the executive branch abused its power so broadly.

In defending this secret spying on Americans, Bush said that he relied=20
on his constitutional powers (Article 2) and the joint resolution=20
passed by Congress after 9/11 that led to the war in Iraq. This=20
rationale was spelled out in a memo written by John Yoo, a White House=20
attorney, less than two weeks after the attacks of 9/11. It's a dense=20
read and a terrifying piece of legal contortionism, but it basically=20
says that the president has unlimited powers to fight terrorism. He can=20
spy on anyone, arrest anyone, and kidnap anyone and ship him to another=20
country ... merely on the suspicion that he might be a terrorist. And=20
according to the memo, this power lasts until there is no more=20
terrorism in the world.

Yoo starts by arguing that the Constitution gives the president total=20
power during wartime. He also notes that Congress has recently been=20
quiescent when the president takes some military action on his own,=20
citing President Clinton's 1998 strike against Sudan and Afghanistan.

Yoo then says: "The terrorist incidents of September 11, 2001, were=20
surely far graver a threat to the national security of the United=20
States than the 1998 attacks. ... The President's power to respond=20
militarily to the later attacks must be correspondingly broader."

This is novel reasoning. It's as if the police would have greater=20
powers when investigating a murder than a burglary.

More to the point, the congressional resolution of Sept. 14, 2001,=20
specifically refused the White House's initial attempt to seek=20
authority to preempt any future acts of terrorism, and narrowly gave=20
Bush permission to go after those responsible for the attacks on the=20
Pentagon and World Trade Center.

Yoo's memo ignored this. Written 11 days after Congress refused to=20
grant the president wide-ranging powers, it admitted that "the Joint=20
Resolution is somewhat narrower than the President's constitutional=20
authority," but argued "the President's broad constitutional power to=20
use military force ... would allow the President to ... [take] whatever=20
actions he deems appropriate ... to pre-empt or respond to terrorist=20
threats from new quarters."

Even if Congress specifically says no.

The result is that the president's wartime powers, with its armies,=20
battles, victories, and congressional declarations, now extend to the=20
rhetorical "War on Terror": a war with no fronts, no boundaries, no=20
opposing army, and -- most ominously -- no knowable "victory."=20
Investigations, arrests, and trials are not tools of war. But according=20
to the Yoo memo, the president can define war however he chooses, and=20
remain "at war" for as long as he chooses.

This is indefinite dictatorial power. And I don't use that term=20
lightly; the very definition of a dictatorship is a system that puts a=20
ruler above the law. In the weeks after 9/11, while America and the=20
world were grieving, Bush built a legal rationale for a dictatorship.=20
Then he immediately started using it to avoid the law.

This is, fundamentally, why this issue crossed political lines in=20
Congress. If the president can ignore laws regulating surveillance and=20
wiretapping, why is Congress bothering to debate reauthorizing certain=20
provisions of the Patriot Act? Any debate over laws is predicated on=20
the belief that the executive branch will follow the law.

This is not a partisan issue between Democrats and Republicans; it's a=20
president unilaterally overriding the Fourth Amendment, Congress and=20
the Supreme Court. Unchecked presidential power has nothing to do with=20
how much you either love or hate George W. Bush. You have to imagine=20
this power in the hands of the person you most don't want to see as=20
president, whether it be Dick Cheney or Hillary Rodham Clinton, Michael=20
Moore or Ann Coulter.

Laws are what give us security against the actions of the majority and=20
the powerful. If we discard our constitutional protections against=20
tyranny in an attempt to protect us from terrorism, we're all less safe=20
as a result.

This essay was published on December 21 as an op-ed in the "Minneapolis=20
Star Tribune."
<http://www.startribune.com/562/story/138326.html>

Here's the opening paragraph of the Yoo memo.  Remember, think of this=20
power in the hands of your least favorite politician when you read it:

"You have asked for our opinion as to the scope of the President's=20
authority to take military action in response to the terrorist attacks=20
on the United States on September 11, 2001. We conclude that the=20
President has broad constitutional power to use military force.=20
Congress has acknowledged this inherent executive power in both the War=20
Powers Resolution, Pub. L. No. 93-148, 87 Stat. 555 (1973), codified at=20
50 U.S.C. =A7=A7 1541-1548 (the "WPR"), and in the Joint Resolution passed=
=20
by Congress on September 14, 2001, Pub. L. No. 107-40, 115 Stat. 224=20
(2001). Further, the President has the constitutional power not only to=20
retaliate against any person, organization, or State suspected of=20
involvement in terrorist attacks on the United States, but also against=20
foreign States suspected of harboring or supporting such organizations.=20
Finally, the President may deploy military force preemptively against=20
terrorist organizations or the States that harbor or support them,=20
whether or not they
  can be linked to the specific terrorist incidents of September 11."

There's a similar reasoning in the Braybee memo, which was written in=20
2002 about torture:

Yoo memo:
<http://www.usdoj.gov/olc/warpowers925.htm>

Braybee Memo:
<http://www.washingtonpost.com/wp-srv/nation/documents/dojinterrogationm=20
emo20020801.pdf>

This story has taken on a life of its own.  But there are about a=20
zillion links and such listed here:
<http://www.schneier.com/blog/archives/2005/12/the_security_th_1.html>
I am especially amused by the bit about NSA shift supervisors making=20
decisions legally reserved for the FISA court.


** *** ***** ******* *********** *************

      Project Shamrock



Decades before 9/11, and the subsequent Bush order that directed the=20
NSA to eavesdrop on every phone call, e-mail message, and=20
who-knows-what-else going into or out of the United States, U.S.=20
citizens included, they did the same thing with telegrams.  It was=20
called Project Shamrock, and anyone who thinks this is new legal and=20
technological terrain should read up on that program.

 From Wikipedia:  "Project SHAMROCK...was an espionage exercise that=20
involved the accumulation of all telegraphic data entering into or=20
exiting from the United States. The Armed Forces Security Agency (AFSA)=20
and its successor NSA were given direct access to daily microfilm=20
copies of all incoming, outgoing, and transiting telegraphs via the=20
Western Union and its associates RCA and ITT. Operation Shamrock lasted=20
well into the 1960s when computerized operations (HARVEST) made it=20
possible to search for keywords rather than read through all=20
communications.

"Project SHAMROCK became so successful that in 1966 the NSA and CIA set=20
up a front company in lower Manhattan (where the offices of the=20
telegraph companies were located) under the codename LPMEDLEY. At the=20
height of Project SHAMROCK, 150,000 messages a month were printed and=20
analyzed by NSA agents. In May 1975 however, congressional critics=20
began to investigate and expose the program. As a result, NSA director=20
Lew Allen terminated it. The testimony of both the representatives from=20
the cable companies and of director Allen at the hearings prompted=20
Senate Intelligence Committee chairman Sen. Frank Church to conclude=20
that Project SHAMROCK was 'probably the largest government interception=20
program affecting Americans ever undertaken.'"

If you want details, the best place is James Bamford's books about the=20
NSA: his 1982 book, "The Puzzle Palace," and his 2001 book, "Body of=20
Secrets."  This quote is from the latter book, page 440:

"Among the reforms to come out of the Church Committee investigation=20
was the creation of the Foreign Intelligence Surveillance Act (FISA),=20
which for the first time outlined what NSA was and was not permitted to=20
do.  The new statute outlawed wholesale, warrantless acquisition of raw=20
telegrams such as had been provided under Shamrock.  It also outlawed=20
the arbitrary compilation of watch list containing the names of=20
Americans. Under FISA, a secret federal court was set up, the Foreign=20
Intelligence Surveillance Court.  In order for NSA to target an=20
American citizen or a permanent resident alien--a "green card"=20
holder--within the United States, a secret warrant must be obtained=20
from the court.  To get the warrant, NSA officials must show that the=20
person they wish to target is either an agent of a foreign power or=20
involved in espionage or terrorism."

A lot of people are trying to say that it's a different world today,=20
and that eavesdropping on a massive scale is not covered under the FISA=20
statute, because it just wasn't possible or anticipated back=20
then.  That's a lie.  Project Shamrock began in the 1950s, and ran for=20
about twenty years.  It too had a massive program to eavesdrop on all=20
international telegram communications, including communications to and=20
from American citizens.  It too was to counter a terrorist threat=20
inside the United States.  It too was secret, and illegal.  It is=20
exactly, by name, the sort of program that the FISA process was=20
supposed to get under control.

Twenty years ago, Senator Frank Church warned of the dangers of letting=20
the NSA get involved in domestic intelligence gathering.  He said that=20
the "potential to violate the privacy of Americans is unmatched by any=20
other intelligence agency."   If the resources of the NSA were ever=20
used domestically, "no American would have any privacy left.... There=20
would be no place to hide....   We must see to it that this agency and=20
all agencies that possess this technology operate within the law and=20
under proper supervision, so that we never cross over that abyss. That=20
is an abyss from which there is no return."

Bush's eavesdropping program was explicitly anticipated in 1978, and=20
made illegal by FISA.  There might not have been fax machines, or=20
e-mail, or the Internet, but the NSA did the exact same thing with=20
telegrams.

We can decide as a society that we need to revisit FISA.  We can debate=20
the relative merits of police-state surveillance tactics and=20
counterterrorism.  We can discuss the prohibitions against spying on=20
American citizens without a warrant, crossing over that abyss that=20
Church warned us about twenty years ago.  But the president can't=20
simply decide that the law doesn't apply to him.

This issue is not about terrorism.  It's not about intelligence=20
gathering.  It's about the executive branch of the United States=20
ignoring a law, passed by the legislative branch and signed by=20
President Jimmy Carter: a law that directs the judicial branch to=20
monitor eavesdropping on Americans in national security investigations.

It's not the spying, it's the illegality.

Wikipedia entry:
<http://en.wikipedia.org/wiki/Project_SHAMROCK>


** *** ***** ******* *********** *************

      Comments from Readers



There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog.  Search for the story you want to comment on, and=20
join in.

<http://www.schneier.com/blog>


** *** ***** ******* *********** *************

CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise.  You=20
can subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>.  Back issues are also=20
available at that URL.

Comments on CRYPTO-GRAM should be sent to=20
[email protected].  Permission to print comments is assumed=20
unless otherwise stated.  Comments may be edited for length and clarity.

Please feel free to forward CRYPTO-GRAM to colleagues and friends who=20
will find it valuable.  Permission is granted to reprint CRYPTO-GRAM,=20
as long as it is reprinted in its entirety.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is the author of=20
the best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography,"  and an inventor of the Blowfish and Twofish=20
algorithms.  He is founder and CTO of Counterpane Internet Security=20
Inc., and is a member of the Advisory Board of the Electronic Privacy=20
Information Center (EPIC).  He is a frequent writer and lecturer on=20
security topics.  See <http://www.schneier.com>.

Counterpane is the world's leading protector of networked information -=20
the inventor of outsourced security monitoring and the foremost=20
authority on effective mitigation of emerging IT threats. Counterpane=20
protects networks for Fortune 1000 companies and governments=20
world-wide.  See <http://www.counterpane.com>.

Crypto-Gram is a personal newsletter.  Opinions expressed are not=20
necessarily those of Counterpane Internet Security, Inc.

Copyright (c) 2006 by Bruce Schneier.