CRYPTO-GRAM, June 15, 2006
Bruce Schneier <[email protected]> Thu, 15 Jun 2006 02:08:17 -0500
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
June 15, 2006
by Bruce Schneier
Founder and CTO
Counterpane Internet Security, Inc.
[email protected]
http://www.schneier.com
http://www.counterpane.com
A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0606.html>. These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>. An RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
The Value of Privacy
Movie-Plot Threat Contest Winner
Crypto-Gram Reprints
Diebold Doesn't Understand the Security Threat
News
Hacking Computers Over USB
The Doghouse: KRYPTO 2.0
Counterpane News
Aligning Interest with Capability
Comments from Readers
** *** ***** ******* *********** *************
The Value of Privacy
Last month, revelation of yet another NSA surveillance effort against=20
the American people rekindled the privacy debate. Those in favor of=20
these programs have trotted out the same rhetorical question we hear=20
every time privacy advocates oppose ID checks, video cameras, massive=20
databases, data mining, and other wholesale surveillance measures: "If=20
you aren't doing anything wrong, what do you have to hide?"
Some clever answers: "If I'm not doing anything wrong, then you have no=20
cause to watch me." "Because the government gets to define what's=20
wrong, and they keep changing the definition." "Because you might do=20
something wrong with my information." My problem with quips like these=20
-- as right as they are -- is that they accept the premise that privacy=20
is about hiding a wrong. It's not. Privacy is an inherent human right,=20
and a requirement for maintaining the human condition with dignity and=20
respect.
Two proverbs say it best: "Quis custodiet ipsos custodes?" ("Who=20
watches the watchers?") and "Absolute power corrupts absolutely."
Cardinal Richelieu understood the value of surveillance when he=20
famously said, "If one would give me six lines written by the hand of=20
the most honest man, I would find something in them to have him=20
hanged." Watch someone long enough, and you'll find something to arrest=20
-- or just blackmail -- him with. Privacy is important because without=20
it, surveillance information will be abused: to peep, to sell to=20
marketers, and to spy on political enemies -- whoever they happen to be=20
at the time.
Privacy protects us from abuses by those in power, even if we're doing=20
nothing wrong at the time of surveillance.
We do nothing wrong when we make love or go to the bathroom. We are not=20
deliberately hiding anything when we seek out private places for=20
reflection or conversation. We keep private journals, sing in the=20
privacy of the shower, and write letters to secret lovers and then burn=20
them. Privacy is a basic human need.
A future in which privacy would face constant assault was so alien to=20
the framers of the Constitution that it never occurred to them to call=20
out privacy as an explicit right. Privacy was inherent to the nobility=20
of their being and their cause. Of course being watched in your own=20
home was unreasonable. Watching at all was an act so unseemly as to be=20
inconceivable among gentlemen in their day. You watched convicted=20
criminals, not free citizens. You ruled your own home. It's intrinsic=20
to the concept of liberty.
For if we are observed in all matters, we are constantly under threat=20
of correction, judgment, criticism, even plagiarism of our own=20
uniqueness. We become children, fettered under watchful eyes,=20
constantly fearful that -- either now or in the uncertain future --=20
patterns we leave behind will be brought back to implicate us, by=20
whatever authority has now become focused upon our once-private and=20
innocent acts. We lose our individuality, because everything we do is=20
observable and recordable.
How many of us have paused during conversations in the past=20
four-and-a-half years, suddenly aware that we might be eavesdropped on?=20
Probably it was a phone conversation, although maybe it was an e-mail=20
or instant message exchange or a conversation in a public place. Maybe=20
the topic was terrorism, or politics, or Islam. We stop suddenly,=20
momentarily afraid that our words might be taken out of context, then=20
we laugh at our paranoia and go on. But our demeanor has changed, and=20
our words are subtly altered.
This is the loss of freedom we face when our privacy is taken from us.=20
This was life in the former East Germany, or life in Saddam Hussein's=20
Iraq. And it's our future as we allow an ever-intrusive eye into our=20
personal, private lives.
Too many wrongly characterize the debate as "security versus privacy."=20
The real choice is liberty versus control. Tyranny, whether it arises=20
under threat of foreign physical attack or under constant domestic=20
authoritative scrutiny, is still tyranny. Liberty requires security=20
without intrusion, security plus privacy. Widespread police=20
surveillance is the very definition of a police state. And that's why=20
we should champion privacy even when we have nothing to hide.
A version of this essay originally appeared on Wired.com.
http://www.wired.com/news/columns/0,70886-0.html
Daniel Solove comments:
http://www.concurringopinions.com/archives/2006/05/is_there_a_good.html=20
or http://tinyurl.com/nmj3u
** *** ***** ******* *********** *************
Movie-Plot Threat Contest Winner
I can tell you one thing, you guys are really imaginative. The=20
response to my Movie-Plot Threat Contest was more than I could imagine:=20
892 comments. I printed them all out -- 195 pages, double sided -- and=20
spiral bound them, so I could read them more easily. The cover read:=20
"The Big Book of Terrorist Plots." I tried not to wave it around too=20
much in airports.
I almost didn't want to pick a winner, because the real point is the=20
enormous list of them all. And because it's hard to choose. But after=20
careful deliberation, the winning entry is by Tom Grant. Although=20
planes filled with explosives is already cliche, destroying the Grand=20
Coulee Dam is inspired. Here it is:
"Mission: Terrorize Americans. Neutralize American economy, make=20
America feel completely vulnerable, and all Americans unsafe.
"Scene 1: A rented van drives from Spokane, WA, to a remote setting in=20
Idaho and loads up with shoulder-mounted rocket launchers and a couple=20
of people dressed in fatigues.=09
"Scene 2: Terrorists dressed in 'delivery man' garb take over the UPS=20
cargo depot at the Spokane, WA, airport. A van full of explosives is=20
unloaded at the depot.
"Scene 3: Terrorists dressed in 'delivery man' garb take over the UPS=20
cargo depot at the Kamloops, BC, airport. A van full of explosives is=20
unloaded at the depot.
"Scene 4: A van with mercenaries drives through the Idaho forests en=20
route to an unknown destination. Receives cell communiqu=E9 that=20
locations Alpha and Bravo are secured.
"Scene 5: UPS cargo plane lands in Kamloops and is met at the depot by=20
terrorists who overtake the plane and its crew. Explosives are loaded=20
aboard the aircraft. The same scene plays out in Spokane moments=20
later, and that plane is loaded with explosives. Two pilots board=20
each of the cargo planes and ask for takeoff instructions as night=20
falls across the West.
"Scene 6: Two cargo jets go airborne from two separate locations. A=20
van with four terrorists arrives at its destination, parked on an=20
overlook ridge just after nightfall. They use infrared glasses to scope=20
the target. The camera pans down and away from the van, exposing the=20
target. Grand Coulee Dam. The cell phone rings and notification comes=20
to the leader that 'Nighthawks alpha and bravo have launched.'
"Scene 7: Two radar operators in separate locations note with alarm=20
that UPS cargo jets they have been tracking have dropped off the radar=20
and may have crashed. Aboard each craft the pilots have turned off=20
navigational radios and are flying on 'manual' at low altitude. One=20
heading South, one heading North.
"Scene 8: Planes are closing in on the 'target' and the rocket=20
launcher crew goes to work. With precision they strike lookout and=20
defense positions on the dam, then target the office structures=20
below. As they finish, a cargo jet approaches from the North at high=20
velocity, slamming into the back side of the dam just above the=20
waterline and exploding, shuddering the earth. A large portion of the=20
center-top of the dam is missing. Within seconds a cargo plane coming=20
from the South slams into the front face of the dam, closer to the=20
base, and explodes in a blinding flash, shuddering the earth. In=20
moments, the dam begins to fail, and a final volley from four rocket=20
launchers on the hill above helps break open the face of the dam. The=20
40-mile-long Lake Roosevelt begins to pour down the Columbia River=20
Valley, uncontrolled. No warning is given to the dams downriver, other=20
than the generation at G.C. is now offline.
"Scene 9: Through the night, the surging wall of water roars down the=20
Columbia waterway, overtopping dam after dam and gaining momentum (and=20
huge amounts of water) along the way. The cities of Wenatchee and=20
Kennewick are inundated and largely swept away. A van of renegades=20
retreats to Northern Idaho to hide.
"Scene 10: As day breaks in the West, there is no power from Seattle=20
to Los Angeles. The Western power grid has failed. Commerce has ground=20
to a halt west of the Rocky Mountains. Water is sweeping down the=20
Columbia River gorge, threatening to overtop Bonneville dam and wipe=20
out the large metro area of Portland, OR.
"Scene 11: Bin Laden releases a video on Al Jazeera that claims=20
victory over the Americans.
"Scene 12: Pandemonium, as water sweeps into a panicked Portland,=20
Oregon, washing all away in its path, and surging water well up the=20
Willamette valley.
"Scene 13: Washington situation room...little input is coming in from=20
the West. Some military bases have emergency power and sat phones, and=20
are reporting that the devastation of the dam infrastructure is=20
complete. Seven major and five minor dams have been destroyed.=20
Re-powering the West coast will take months, as connections from the=20
Eastern grid will have to be made through the New Mexico Mountains.
"Scene 14: Worst U.S. market crash in history. America's GNP drops=20
from the top of the charts to 20th worldwide. Exports and imports cease=20
on the West coast. Martial law fails to control mass exodus from=20
Seattle, San Francisco, and L.A. as millions flee to the east. Gas=20
shortages and vigilante mentality take their toll on the panicked=20
populace. The West is 'wild' once more. The East is overrun with=20
millions seeking homes and employment."
Congratulations, Tom. I'm still trying to figure out what you win.
Contest rules and all entries:
http://www.schneier.com/blog/archives/2006/04/announcing_movi.html
Update, including selection criteria:
http://www.schneier.com/blog/archives/2006/04/movie_plot_thre.html
Winning entry:
http://www.schneier.com/blog/archives/2006/04/announcing_movi.html#c54905
** *** ***** ******* *********** *************
Crypto-Gram Reprints
Crypto-Gram is currently in its ninth year of publication. Back issues=20
cover a variety of security-related topics, and can all be found on=20
<http://www.schneier.com/crypto-gram-back.html>. These are a selection=20
of articles that appeared in this calendar month in other years.
Internet Attack Trends:
http://www.schneier.com/crypto-gram-0506.html#1
U.S. Medical Privacy Law Gutted:
http://www.schneier.com/crypto-gram-0506.html#9
Breaking Iranian Codes:
http://www.schneier.com/crypto-gram-0406.html#1
The Witty Worm:
http://www.schneier.com/crypto-gram-0406.html#9
The Risks Of Cyberterrorism:
http://www.schneier.com/crypto-gram-0306.html#1
Fixing Intelligence Failures:
http://www.schneier.com./crypto-gram-0206.html#1
Honeypots and the Honeynet Project
http://www.schneier.com/crypto-gram-0106.html#1
Microsoft SOAP:
http://www.schneier.com/crypto-gram-0006.html#SOAP
The Data Encryption Standard (DES):
http://www.schneier.com/crypto-gram-0006.html#DES
The internationalization of cryptography policy:
http://www.schneier.com/crypto-gram-9906.html#policy
and products:
http://www.schneier.com/crypto-gram-9906.html#products
The new breeds of viruses, worms, and other malware:
http://www.schneier.com/crypto-gram-9906.html#viruses
Timing attacks, power analysis, and other "side-channel" attacks=20
against cryptosystems:
http://www.schneier.com/crypto-gram-9806.html#side
** *** ***** ******* *********** *************
Diebold Doesn't Understand the Security Threat
This quote sums up nicely why Diebold should not be trusted to secure=20
election machines:
"David Bear, a spokesman for Diebold Election Systems, said the=20
potential risk existed because the company's technicians had=20
intentionally built the machines in such a way that election officials=20
would be able to update their systems in years ahead.
"'For there to be a problem here, you're basically assuming a premise=20
where you have some evil and nefarious election officials who would=20
sneak in and introduce a piece of software,' he said. 'I don't believe=20
these evil elections people exist.'"
If you can't get the threat model right, you can't hope to secure the=20
system.
http://www.nytimes.com/2006/05/12/us/12vote.html?ex=3D1305086400&en=3D5b3554=
=20
a76aad524a&ei=3D5090&partner=3Drssuserland&emc=3Drss or=
http://tinyurl.com/q7p4s
** *** ***** ******* *********** *************
News
Consumers are willing to trade privacy for convenience:
http://www.computerworld.com.au/pp.php?id=3D42605808&eid=3D-180
Two conferences:
The Workshop on Economics and Information Security, on June 26-28 in=20
Cambridge (England, not Massachusetts).
http://weis2006.econinfosec.org/
The Workshop on the Economics of Securing the Information=20
Infrastructure, on October 23-24 in Washington, DC.
http://wesii.econinfosec.org/
WEIS is currently my favorite security conference. I think that=20
economics has a lot to teach computer security, and it is very=20
interesting to get economists, lawyers, and computer security experts=20
in the same room talking about issues.
Online student exams. I'm sure this is a good idea, but I wonder when=20
the first case of cheating-by-rootkit will occur.
http://news.bbc.co.uk/go/rss/-/1/hi/scotland/4962806.stm
Bundesamt fur Sicherheit in der Informationstechnik, or Federal Office=20
for Information Security, or BSI, is Germany's equivalent of the=20
NSA. They have an English-language website that has a number of=20
English-language security publications.
http://www.bsi.bund.de/english/publications/index.htm
The National Institute of Standards and Technology has released a=20
document detailing how federal agencies should manage security=20
logs: NIST Special Publication 800-92: Guide to Computer Security Log=20
Management.
http://csrc.nist.gov/publications/drafts/DRAFT-SP800-92.pdf
Really good advice, step by step, on how to survive identity theft:
http://www.consumerist.com/consumer/top/how-to-get-through-having-your-i=20
dentity-stolen-171194.php or http://tinyurl.com/hqksb
A new report from the GAO: GAO-06-385 -- The Federal Government Needs=20
to Establish Policies and Processes for Sharing Terrorism-Related and=20
Sensitive but Unclassified Information," March 2006, lists 56 different=20
sensitive but unclassified security designations.
http://www.gao.gov/htext/d06385.html
The list is here:
http://www.schneier.com/blog/archives/2006/05/us_government_s.html
I've already written about SSI (Sensitive Security Information).
http://www.schneier.com/blog/archives/2005/03/sensitive_secur.html
The U.S. Coast Guard solicits Hollywood screenwriters to help them with=20
movie-plot threats. No, really.
http://www.signonsandiego.com/uniontrib/20060520/news_1n20ships.html
Anyone who's watched Hollywood's output in recent years knows that=20
screenwriters aren't the most creative bunch of people on the planet.
Smart profiling from the DHS and the TSA: "Select TSA employees will be=20
trained to identify suspicious individuals who raise red flags by=20
exhibiting unusual or anxious behavior, which can be as simple as=20
changes in mannerisms, excessive sweating on a cool day, or changes in=20
the pitch of a person's voice." About time.
http://www.time.com/time/nation/article/0,8599,1195330,00.html
Russian spammers have been attacking the company Blue Security, and=20
Blue Security has given up.
http://www.washingtonpost.com/wp-dyn/content/article/2006/05/16/AR200605=20
1601873.html or http://tinyurl.com/kbrwc
http://www.techweb.com/headlines_week/showArticle.jhtml?articleId=3D187900=
=20
260 or http://tinyurl.com/p9fb5
http://news.bbc.co.uk/2/hi/technology/4990622.stm
Marcus Ranum on Blue Security's idea:
http://www.ranum.com/security/computer_security/editorials/bluesecurity/=20
index.html or http://tinyurl.com/qrhcf
El Al doesn't trust the TSA, and wants to do security themselves:
http://www.haaretz.com/hasen/spages/714988.html
Great op-ed on why data mining won't find terrorists:
http://www.nytimes.com/2006/05/16/opinion/16farley.html?ex=3D1305432000&en=
=20
=3D64f96c12ae69c068&ei=3D5088&partner=3Drssnyt&emc=3Drss or=20
http://tinyurl.com/nod9s
The author is Jonathan Farley, math professor at Harvard
http://www.math.buffalo.edu/mad/PEEPS/farley_jonathan.html
Winning my award for dumb movie-plot threat of the month, here's=20
someone who thinks that counterfeit electronics are a terrorist tool.
http://spectrum.ieee.org/may06/3423/boguf4
http://www.cyberdefenseagency.com/news-20060531.php
First runner up for dumb movie-plot threat of the month, here's someone=20
who thinks that a public aviation tracking system is a "terrorist's dream."
http://dailytelegraph.news.com.au/story/0,20281,19000724-5001028,00.html=20
or http://tinyurl.com/rkytk
Under the present system, a terrorist can locate the position of an=20
aircraft by looking up. And if a terrorist is smart enough to perform=20
this intelligence-gathering exercise near an airport, he can locate the=20
position of aircraft that are low to the ground, and easier to shoot at=20
with missiles. Why are we worrying about telling terrorists where all=20
the high-altitude hard-to-hit planes are? Of course, I can invent a=20
movie plot that has the terrorists needing to shoot down a particular=20
plane because this or that famous personage is on it, but that's a bit=20
much.
A clip from the movie "Team America: World Police," was mistaken for an=20
al Qaeda video at a Congressional committee. Oops.
http://gamepolitics.livejournal.com/285129.html
Ira Winkler on why NSA spying hurts security:
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic&=
=20
articleId=3D9000515 or http://tinyurl.com/nkbam
How to cheat at writing papers for class:
http://alex.halavais.net/?p=3D1427
You too can spy on the Internet, just like the NSA.
http://www.wired.com/news/technology/0,70914-0.html
(And while we're on the topic, you really should read about the=20
equipment the NSA installed at the AT&T switches. Wow.)
http://blog.wired.com/27BStroke6/att_klein_wired.pdf
This essay makes the case that there no way to safely report a computer=20
vulnerability. Whatever you do opens you up to prosecution.
http://www.cerias.purdue.edu/weblogs/pmeunier/policies-law/post-38
Robert Lemos on "Ethics and the Eric McCarty Case."
http://www.robertlemos.com/2006/04/26/ethics-and-the-eric-mccarty-case/=20
or http://tinyurl.com/s8vyt
A robotic bill of rights:
http://www.schneier.com/blog/archives/2006/05/a_robotic_bill.html
TrueCrypt: On-the-fly encryption with plausible deniability:
http://www.truecrypt.org/
From Charlie Stross: "A report on the state of the National Identity=20
Register, May 2016." Note the date; it's fiction.
http://www.antipope.org/charlie/blog-static/2006/05/17/#id-card-3
Great quote by Alexander Solzhenitsyn (1968) on data and privacy: "As=20
every man goes through life he fills in a number of forms for the=20
record, each containing a number of questions... There are thus=20
hundreds of little threads radiating from every man, millions of=20
threads in all. If these threads were suddenly to become visible, the=20
whole sky would look like a spider's web, and if they materialized as=20
rubber bands, buses; trams and even people would all lose the ability=20
to move, and the wind would be unable to carry torn-up newspapers or=20
autumn leaves along the streets of the city. They are not visible, they=20
are not material, but every man is constantly aware of their=20
existence.... Each man, permanently aware of his own invisible threads,=20
naturally develops a respect for the people who manipulate the threads."
In the long term, corporate data mining efforts are more of a privacy=20
risk than government data mining efforts. And here's an off-the-shelf=20
product from IBM:
http://www-306.ibm.com/common/ssi/fcgi-bin/ssialias?subtype=3Dca&infotype=3D=
=20
an&appname=3DiSource&supplier=3D649&letternum=3DENUSA06-0519 or=20
http://tinyurl.com/q29er
The UK Intelligence and Security Committee has issued a report on the=20
July 7 terrorist bombings in London:
http://www.cabinetoffice.gov.uk/publications/reports/intelligence/isc_7j=20
uly_report.pdf or http://tinyurl.com/hazzn
The UK government has issued a response:
http://www.cabinetoffice.gov.uk/publications/reports/intelligence/govres=20
_7july.pdf or http://tinyurl.com/j8q5x
About the Intelligence and Security Committee:
http://www.cabinetoffice.gov.uk/intelligence/index.asp
From a list of 100,000 passwords for a German dating site, we learn=20
that "123456" works 1.4% of the time and that 2.5% of all passwords=20
begin with "1234." Interesting.
http://www.heise.de/newsticker/meldung/73396
Bank defends its bad security by saying that everyone else does it, too.
http://blogs.zdnet.com/Ou/?p=3D226
Interesting essay about how EU law would treat the NSA's collection of=20
everyone's phone records.
http://www.concurringopinions.com/archives/2006/05/the_nsa_phone_c.html=20
or http://tinyurl.com/mpv6d
Animated political cartoon on NSA eavesdropping. And a song, too.
http://www.newsday.com/news/opinion/ny-wh-nsawiretapping,0,1906650.flash=20
or http://tinyurl.com/rg57v
You can audit "Welcome to Practical Aspects of Modern Cryptography":=20
University of Washington, Winter 2006, by Josh Benaloh, Brian=20
LaMacchia, and John Manferdelli. The course materials and videos of=20
the lectures are online.
http://www.cs.washington.edu/education/courses/csep590/06wi/
http://www.cs.washington.edu/education/courses/csep590/06wi/lectures/
Fascinating interview with a debit card scammer. Moral: securing this=20
system isn't going to be easy.
http://smallworldpodcast.com/?p=3D391
And some comments from a fake ID salesman, in case you thought=20
hard-to-forge national ID cards would solve the problem:
http://www.cbsnews.com/stories/2006/06/02/ap/national/mainD8I07PHG0.shtm=20
l or http://tinyurl.com/rafve
"How to Avoid Going to Jail under 18 U.S.C. Section 1001 for Lying to=20
Government Agents."
http://library.findlaw.com/2004/May/11/147945.html
Nice article discussing the hype, and reality, over the threat of=20
homebrew chemical weapons.
http://www.theregister.co.uk/2006/06/04/chemical_bioterror_analysis/
Just hide this gadget in someone's car or briefcase -- or maybe sew it=20
into his coat -- and then track his every move using GPS. You have to=20
recover the device to play it back, but presumably the next generation=20
will be queryable remotely.
http://www.thinkgeek.com/gadgets/security/8212/?cpg=3Dcj
The U.S. government is asking ISPs to save personal data about you, in=20
case they need access to it.
http://www.latimes.com/technology/la-fi-internet2jun02,0,622125.story?co=20
ll=3Dla-home-headlines or http://tinyurl.com/zpzvz
Note that the Justice Department invoked two of the Four Horsemen of=20
the Internet Apocalypse: child pornographers and terrorists. If they=20
can figure out how to work kidnappers and drug dealers in, they can=20
probably do anything they want.
From "Assassination in the United States: An Operational Study of=20
Recent Assassins, Attackers, and Near-Lethal Approachers," (a 1999=20
article published in the "Journal of Forensic Sciences"): "Few=20
attackers or near-lethal approachers possessed the cunning or the=20
bravado of assassins in popular movies or novels. The reality of=20
American assassination is much more mundane, more banal than=20
assassinations depicted on the screen. Neither monsters nor martyrs,=20
recent American assassins, attackers, and near-lethal approachers=20
engaged in pre-incident patterns of thinking and behaviour." The quote=20
is from the last page. The whole thing is interesting reading.
http://www.secretservice.gov/ntac/ntac_jfs.pdf
Interesting law review article by Helen Nissenbaum: "Privacy as=20
Contextual Integrity."
http://crypto.stanford.edu/portia/papers/RevnissenbaumDTP31.pdf
New directions in chemical warfare: chemicals that make enemy soldiers=20
sexually irresistible to each other, attract swarms of enraged wasps,=20
or cause "severe and lasting halitosis":
http://www.newscientist.com/article.ns?id=3Dmg18524823.800
Technology always gets better; it never gets worse. There will be a=20
time, probably in our lifetimes, when weapons like these will be real.
NSA surveillance cartoon:
http://www.ibiblio.org/Dave/Dr-Fun/df200605/df20060517.jpg
Interesting paper on the security of contactless smartcards:
http://www.chi-publishing.com/samples/ISB0903HH.pdf
Wireless surveillance camera detector:
http://www.brickhousesecurity.com/dd9000.html
Great article comparing the barrier Israel is erecting to protect=20
itself from the West Bank with the hypothetical barrier the U.S. would=20
build to protect itself from Mexico: "No wonder the [Israeli] fence is=20
considered a good deal by those living on its western side. But=20
applying this model to the U.S.-Mexico border will not be easy. U.S.=20
citizens will find it hard to justify such tough measures when their=20
only goal is to stop people coming in for work -- rather than=20
preventing them from trying to commit murder. And the cost will be more=20
important. It's much easier to open your wallet when someone is=20
threatening to blow up your local cafe."
http://www.slate.com/id/2143104/
$1M VoIP scam:
http://www.networkingpipeline.com/news/188702745
NIST has just published "Recommendation for Random Number Generation=20
Using Deterministic Random Bit Generators."
http://csrc.nist.gov/publications/nistpubs/index.html
The NSA is combing through MySpace:
http://www.newscientisttech.com/article/mg19025556.200-pentagon-sets-its=20
-sights-on-social-networking-websites.html or http://tinyurl.com/fk3z6
** *** ***** ******* *********** *************
Hacking Computers Over USB
I've previously written about the risks of small portable computing=20
devices; how more and more data can be stored on them, and then lost or=20
stolen. But there's another risk: if an attacker can convince you to=20
plug his USB device into your computer, he can take it over. From CSO=20
Magazine:
"Plug an iPod or USB stick into a PC running Windows and the device can=20
literally take over the machine and search for confidential documents,=20
copy them back to the iPod or USB's internal storage, and hide them as=20
"deleted" files. Alternatively, the device can simply plant spyware, or=20
even compromise the operating system. Two features that make this=20
possible are the Windows AutoRun facility and the ability of=20
peripherals to use something called direct memory access (DMA). The=20
first attack vector you can and should plug; the second vector is the=20
result of a design flaw that's likely to be with us for many years to=20
come."
The article has the details, but basically you can configure a file on=20
your USB device to automatically run when it's plugged into a=20
computer. That file can, of course, do anything you want it to.
Recently I've been seeing more and more written about this attack. The=20
Spring 2006 issue of 2600 Magazine, for example, contains a short=20
article called "iPod Sneakiness" (unfortunately, not online). The=20
author suggests that you can innocently ask someone at an Internet cafe=20
if you can plug your iPod into his computer to power it up -- and then=20
steal his passwords and critical files.
And about someone used this trick in a penetration test:
"We figured we would try something different by baiting the same=20
employees that were on high alert. We gathered all the worthless vendor=20
giveaway thumb drives collected over the years and imprinted them with=20
our own special piece of software. I had one of my guys write a Trojan=20
that, when run, would collect passwords, logins and machine-specific=20
information from the user's computer, and then email the findings back=20
to us.
"The next hurdle we had was getting the USB drives in the hands of the=20
credit union's internal users. I made my way to the credit union at=20
about 6 a.m. to make sure no employees saw us. I then proceeded to=20
scatter the drives in the parking lot, smoking areas, and other areas=20
employees frequented.
"Once I seeded the USB drives, I decided to grab some coffee and watch=20
the employees show up for work. Surveillance of the facility was worth=20
the time involved. It was really amusing to watch the reaction of the=20
employees who found a USB drive. You know they plugged them into their=20
computers the minute they got to their desks.
"I immediately called my guy that wrote the Trojan and asked if=20
anything was received at his end. Slowly but surely info was being=20
mailed back to him. I would have loved to be on the inside of the=20
building watching as people started plugging the USB drives in,=20
scouring through the planted image files, then unknowingly running our=20
piece of software."
There is a partial defense. From the first article:
"AutoRun is just a bad idea. People putting CD-ROMs or USB drives into=20
their computers usually want to see what's on the media, not have=20
programs automatically run. Fortunately you can turn AutoRun off. A=20
simple manual approach is to hold down the "Shift" key when a disk or=20
USB storage device is inserted into the computer. A better way is to=20
disable the feature entirely by editing the Windows Registry. There are=20
many instructions for doing this online (just search for 'disable=20
autorun') or you can download and use Microsoft's TweakUI program,=20
which is part of the Windows XP PowerToys download. With Windows XP you=20
can also disable AutoRun for CDs by right-clicking on the CD drive icon=20
in the Windows explorer, choosing the AutoPlay tab, and then selecting=20
'Take no action' for each kind of disk that's listed. Unfortunately,=20
disabling AutoPlay for CDs won't always disable AutoPlay for USB=20
devices, so the registry hack is the safest course of action."
In the 1990s, the Macintosh operating system had this feature, which=20
was removed after a virus made use of it in 1998. Microsoft needs to=20
remove this feature as well.
But it's only a partial defense. In the penetration test, they didn't=20
use AutoRun. They just created a sufficiently enticing file, and the=20
people who found the USB drives manually invoked the executable.
http://www.csoonline.com/read/050106/ipods.html
http://www.darkreading.com/document.asp?doc_id=3D95556&WT.svl=3Dcolumn1_1
http://www.darkreading.com/boards/message.asp?msg_id=3D134658
My previous essay:
http://www.schneier.com/blog/archives/2005/07/risks_of_losing.html
** *** ***** ******* *********** *************
The Doghouse: KRYPTO 2.0
The website is hysterical:
"Proof of the Krypto security !
Which would be, if one would try one of Krypto coded file unauthorized=20
to decode.
A coded file with the length of 18033 indications has therefore=20
according to computation, 256 bits highly 18033 indications =3D=20
6,184355814363201353319227173630=EB+43427
file possibilities. Each file possibility has exactly 18033 indications=20
byte.
Multiplied by the number of file possibilities then need results in the=20
memory.
Those are then: 1,1152248840041161000440562362208e+43432 byte.
Those are then: 1,038634110245961789082788150963=E8+43423 Giga byte data=20
quantity.
That is a number with 43424 places.
I can surely maintain as much memory place give it in the whole world=20
not never.
And the head problem now is, which is now the correctly decoded file.
Who it does not know can only say there. That does not know so exactly !
They can code naturally naturally also still successively several=20
times, even up to
the infinity."
Machine translated (on the website; not by me) from German into=20
English. My head hurts just trying to read that.
http://kryptochef.net/index2e.htm
** *** ***** ******* *********** *************
Counterpane News
Schneier is speaking at the FIRST Conference in Baltimore on June 30:
http://www.first.org/conference/2006/
Interview with Bruce Schneier:
http://www.sevendaysvt.com/features/2006/tales-from-the-cryptographer.html
Counterpane announced two pretty cool service agreements:
http://www.counterpane.com/pr-20060605.html
Network World wrote about Counterpane at the Gartner Security Conference:
http://www.networkworld.com/news/2006/060506-gartner-security.html
** *** ***** ******* *********** *************
Aligning Interest with Capability
Have you ever been to a retail store and seen this sign on the=20
register: "Your purchase free if you don't get a receipt"? You almost=20
certainly didn't see it in an expensive or high-end store. You saw it=20
in a convenience store, or a fast-food restaurant, or maybe a liquor=20
store. That sign is a security device, and a clever one at that. And=20
it illustrates a very important rule about security: it works best when=20
you align interests with capability.
If you're a store owner, one of your security worries is employee=20
theft. Your employees handle cash all day, and dishonest ones will=20
pocket some of it for themselves. The history of the cash register is=20
mostly a history of preventing this kind of theft. Early cash=20
registers were just boxes with a bell attached. The bell rang when an=20
employee opened the box, alerting the store owner -- who was presumably=20
elsewhere in the store -- that an employee was handling money.
The register tape was an important development in security against=20
employee theft. Every transaction is recorded in write-only media, in=20
such a way that it's impossible to insert or delete transactions. It's=20
an audit trail. Using that audit trail, the store owner can count the=20
cash in the drawer, and compare the amount with the register tape. Any=20
discrepancies can be docked from the employee's paycheck.
If you're a dishonest employee, you have to keep transactions off the=20
register. If someone hands you money for an item and walks out, you=20
can pocket that money without anyone being the wiser. And, in fact,=20
that's how employees steal cash in retail stores.
What can the store owner do? He can stand there and watch the=20
employee, of course. But that's not very efficient; the whole point of=20
having employees is so that the store owner can do other things. The=20
customer is standing there anyway, but the customer doesn't care one=20
way or another about a receipt.
So here's what the employer does: he hires the customer. By putting up=20
a sign saying "Your purchase free if you don't get a receipt," the=20
employer is getting the customer to guard the employee. The customer=20
makes sure the employee gives him a receipt, and employee theft is=20
reduced accordingly.
There is a general rule in security to align interest with=20
capability. The customer has the capability of watching the employee;=20
the sign gives him the interest.
In Beyond Fear, I wrote about ATM fraud; you can see the same mechanism=20
at work:
"When ATM cardholders in the US complained about phantom withdrawals=20
from their accounts, the courts generally held that the banks had to=20
prove fraud. Hence, the banks' agenda was to improve security and keep=20
fraud low, because they paid the costs of any fraud. In the UK, the=20
reverse was true: The courts generally sided with the banks and assumed=20
that any attempts to repudiate withdrawals were cardholder fraud, and=20
the cardholder had to prove otherwise. This caused the banks to have=20
the opposite agenda; they didn't care about improving security, because=20
they were content to blame the problems on the customers and send them=20
to jail for complaining. The result was that in the US, the banks=20
improved ATM security to forestall additional losses--most of the fraud=20
actually was not the cardholder's fault -- while in the UK, the banks=20
did nothing."
The banks had the capability to improve security. In the US, they also=20
had the interest. But in the UK, only the customer had the=20
interest. It wasn't until the UK courts reversed themselves and=20
aligned interest with capability that ATM security improved.
Computer security is no different. For years I have argued in favor of=20
software liabilities. Software vendors are in the best position to=20
improve software security; they have the capability. But,=20
unfortunately, they don't have much interest. Features, schedule, and=20
profitability are far more important. Software liabilities will change=20
that. They'll align interest with capability, and they'll improve=20
software security.
One last story. In Italy, tax fraud used to be a national hobby. (It=20
may still be; I don't know.) The government was tired of retail stores=20
not reporting sales and paying taxes, so they passed a law regulating=20
the customers. Any customer having just purchased an item and stopped=20
within a certain distance of a retail store, had to produce a receipt=20
or they would be fined. Just as in the "Your purchase free if you=20
don't get a receipt" story, the law turned the customers into tax=20
inspectors. They demanded receipts from merchants, which in turn=20
forced the merchants to create a paper audit trail for the purchase and=20
pay the required tax.
This was a great idea, but it didn't work very well. Customers,=20
especially tourists, didn't like to be stopped by police. People=20
started demanding that the police prove they just purchased the=20
item. Threatening people with fines if they didn't guard merchants=20
wasn't as effective an enticement as offering people a reward if they=20
didn't get a receipt.
Interest must be aligned with capability, but you need to be careful=20
how you generate interest.
This essay originally appeared on Wired.com.
http://www.wired.com/news/columns/0,71032-0.html
** *** ***** ******* *********** *************
Comments from Readers
There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and=20
join in.
http://www.schneier.com/blog
** *** ***** ******* *********** *************
CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise. You=20
can subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>. Back issues are also=20
available at that URL.
Comments on CRYPTO-GRAM should be sent to=20
[email protected]. Permission to print comments is assumed=20
unless otherwise stated. Comments may be edited for length and clarity.
Please feel free to forward CRYPTO-GRAM to colleagues and friends who=20
will find it valuable. Permission is granted to reprint CRYPTO-GRAM,=20
as long as it is reprinted in its entirety.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of=20
the best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography," and an inventor of the Blowfish and Twofish=20
algorithms. He is founder and CTO of Counterpane Internet Security=20
Inc., and is a member of the Advisory Board of the Electronic Privacy=20
Information Center (EPIC). He is a frequent writer and lecturer on=20
security topics. See <http://www.schneier.com>.
Counterpane is the world's leading protector of networked information -=20
the inventor of outsourced security monitoring and the foremost=20
authority on effective mitigation of emerging IT threats. Counterpane=20
protects networks for Fortune 1000 companies and governments=20
world-wide. See <http://www.counterpane.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not=20
necessarily those of Counterpane Internet Security, Inc.
Copyright (c) 2006 by Bruce Schneier.