CRYPTO-GRAM, July 15, 2006
Bruce Schneier <[email protected]> Sat, 15 Jul 2006 01:35:21 -0500
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
July 15, 2006
by Bruce Schneier
Founder and CTO
Counterpane Internet Security, Inc.
[email protected]
http://www.schneier.com
http://www.counterpane.com
A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0607.html>. These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>. An RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Economics and Information Security
Crypto-Gram Reprints
Google and Click Fraud
A Minor Security Lesson from Mumbai Terrorist Bombings
News
Getting a Personal Unlock Code for Your O2 Cell Phone
The League of Women Voters Supports Voter-Verifiable Paper Trails
Brennan Center and Electronic Voting
Comments from Readers
** *** ***** ******* *********** *************
Economics and Information Security
I'm sitting in a conference room at Cambridge University, trying to=20
simultaneously finish this article for Wired News and pay attention to=20
the presenter onstage.
I'm in this awkward situation because 1) this article is due tomorrow,=20
and 2) I'm attending the fifth Workshop on the Economics of Information=20
Security, or: WEIS -- to my mind, the most interesting computer=20
security conference of the year.
The idea that economics has anything to do with computer security is=20
relatively new. Ross Anderson and I seem to have stumbled upon the idea=20
independently. He, in his brilliant article from 2001, "Why Information=20
Security Is Hard -- An Economic Perspective," and me in various essays=20
and presentations from that same period.
WEIS began a year later at the University of California at Berkeley and=20
has grown ever since. It's the only workshop where technologists get=20
together with economists and lawyers and try to understand the problems=20
of computer security.
And economics has a lot to teach computer security. We generally think=20
of computer security as a problem of technology, but often systems fail=20
because of misplaced economic incentives: the people who could protect=20
a system are not the ones who suffer the costs of failure.
When you start looking, economic considerations are everywhere in=20
computer security. Hospitals' medical-records systems provide=20
comprehensive billing-management features for the administrators who=20
specify them, but are not so good at protecting patients' privacy.=20
Automated teller machines suffered from fraud in countries like the=20
United Kingdom and the Netherlands, where poor regulation left banks=20
without sufficient incentive to secure their systems, and allowed them=20
to pass the cost of fraud along to their customers. And one reason the=20
internet is insecure is that liability for attacks is so diffuse.
In all of these examples, the economic considerations of security are=20
more important than the technical considerations.
More generally, many of the most basic security questions are at least=20
as much economic as technical. Do we spend enough on keeping hackers=20
out of our computer systems? Or do we spend too much? For that matter,=20
do we spend appropriate amounts on police and Army services? And are we=20
spending our security budgets on the right things? In the shadow of=20
9/11, questions like these have a heightened importance.
Economics can actually explain many of the puzzling realities of=20
internet security. Firewalls are common, e-mail encryption is rare: not=20
because of the relative effectiveness of the technologies, but because=20
of the economic pressures that drive companies to install them.=20
Corporations rarely publicize information about intrusions; that's=20
because of economic incentives against doing so. And an insecure=20
operating system is the international standard, in part, because its=20
economic effects are largely borne not by the company that builds the=20
operating system, but by the customers that buy it.
Some of the most controversial cyberpolicy issues also sit squarely=20
between information security and economics. For example, the issue of=20
digital rights management: Is copyright law too restrictive -- or not=20
restrictive enough -- to maximize society's creative output? And if it=20
needs to be more restrictive, will DRM technologies benefit the music=20
industry or the technology vendors? Is Microsoft's Trusted Computing=20
Initiative a good idea, or just another way for the company to lock its=20
customers into Windows, Media Player and Office? Any attempt to answer=20
these questions becomes rapidly entangled with both information=20
security and economic arguments.
WEIS encourages papers on these and other issues in economics and=20
computer security. We heard papers presented on the economics of=20
digital forensics of cell phones -- if you have an uncommon phone, the=20
police probably don't have the tools to perform forensic analysis --=20
and the effect of stock spam on stock prices: It actually works in the=20
short term. We learned that more-educated wireless network users are=20
not more likely to secure their access points, and that the best=20
predictor of wireless security is the default configuration of the router.
Other researchers presented economic models to explain patch=20
management, peer-to-peer worms, investment in information security=20
technologies and opt-in versus opt-out privacy policies. There was a=20
field study that tried to estimate the cost to the U.S. economy for=20
information infrastructure failures: less than you might think. And one=20
of the most interesting papers looked at economic barriers to adopting=20
new security protocols, specifically DNS Security Extensions.
This is all heady stuff. In the early years, there was a bit of a=20
struggle as the economists and the computer security technologists=20
tried to learn each others' languages. But now it seems that there's a=20
lot more synergy, and more collaborations between the two camps.
I've long said that the fundamental problems in computer security are=20
no longer about technology; they're about applying technology.=20
Workshops like WEIS are helping us understand why good security=20
technologies fail and bad ones succeed, and that kind of insight is=20
critical if we're going to improve security in the information age.
Links to all the WEIS papers are available here.
http://weis2006.econinfosec.org
Ross Anderson's Why Information Security Is Hard -- An Economic=20
Perspective":
http://www.cl.cam.ac.uk/ftp/users/rja14/econ.pdf
** *** ***** ******* *********** *************
Crypto-Gram Reprints
Crypto-Gram is currently in its ninth year of publication. Back issues=20
cover a variety of security-related topics, and can all be found on=20
<http://www.schneier.com/crypto-gram-back.html>. These are a selection=20
of articles that appeared in this calendar month in other years.
CardSystems Exposes 40 Million Identities:
http://www.schneier.com/crypto-gram-0507.html#3
Due Process and Security:
http://www.schneier.com/crypto-gram-0407.html#1
Coca-Cola and the NSA:
http://www.schneier.com/crypto-gram-0407.html#8
How to Fight:
http://www.schneier.com/crypto-gram-0307.html#1
Crying Wolf:
http://www.schneier.com/crypto-gram-0307.html#8
Embedded Control Systems and Security:
http://www.schneier.com/crypto-gram-0207.html#1
Phone Hacking: The Next Generation:
http://www.schneier.com/crypto-gram-0107.html#1
Monitoring First:
http://www.schneier.com/crypto-gram-0107.html#5
Full Disclosure and the CIA:
http://www.schneier.com/crypto-gram-0007.html#1
Security Risks of Unicode:
http://www.schneier.com/crypto-gram-0007.html#9
The Future of Crypto-Hacking:
http://www.schneier.com/crypto-gram-9907.html#hacking
Bungled SSL:
http://www.schneier.com/crypto-gram-9907.html#doghouse
Declassifying Skipjack:
http://www.schneier.com/crypto-gram-9807.html#skip
** *** ***** ******* *********** *************
A Minor Security Lesson from Mumbai Terrorist Bombings
Two quotes. "Authorities had also severely limited the cellular=20
network for fear it could be used to trigger more attacks." And: "Some=20
of the injured were seen frantically dialing their cell phones. The=20
mobile phone network collapsed adding to the sense of panic."
Cell phones are useful to terrorists, but they're more useful to the=20
rest of us.
http://www.stuff.co.nz/stuff/0,2106,3729278a12,00.html
Note: The story was changed online, and the second quote was deleted.
** *** ***** ******* *********** *************
Google and Click Fraud
Google's $6B-a-year advertising business is at risk because it can't be=20
sure that anyone is looking at its ads. The problem is called click=20
fraud, and it comes in two basic flavors.
With network click fraud, you host GoogleAds on your own=20
website. Google pays you every time someone clicks on its ad on your=20
site. It's fraud if you sit at the computer and repeatedly click on=20
the ad or -- better yet -- write a computer program that repeatedly=20
clicks on the ad. That kind of fraud is easy for Google to spot, so=20
the clever network click fraudsters simulate different IP addresses, or=20
install Trojan horses on other people's computers to generate the fake=20
clicks.
The other kind of click fraud is competitive. You notice your business=20
competitor has bought an ad on Google, paying Google for each=20
click. So you use the above techniques to repeatedly click on his ads,=20
forcing him to spend money -- sometimes a lot of money -- on=20
nothing. Click Monkeys is a spoof site that offers to commit click=20
fraud for you.)
Click fraud has become a classic security arms race. Google improves=20
its fraud detection tools, so the fraudsters get cleverer ... and the=20
cycle continues. Meanwhile, Google is facing multiple lawsuits from=20
those who claim the company isn't doing enough. My guess is that=20
everyone is right: it's in Google's interest both to solve and to=20
downplay the importance of the problem.
But the overarching problem is both hard to solve and important: how do=20
you tell if there's an actual person sitting in front of a computer=20
screen? How do you tell that the person is paying attention, hasn't=20
automated his responses, and isn't being assisted by=20
friends? Authentication systems are big business, whether based on=20
something you know (passwords), something you have (tokens), or=20
something you are (biometrics). But none of those systems can secure=20
you against someone who walks away and lets another person sit down at=20
the keyboard, or a computer that's infected with a Trojan.
This problem manifests itself in other areas, as well.
For years, online computer game companies have been battling players=20
who use computer programs to assist their play: programs that allow=20
them to shoot perfectly, or see information they normally couldn't see.
Playing is less fun if everyone else is computer assisted, but unless=20
there's a cash prize on the line, the stakes are small. Not so with=20
online poker sites, where computer-assisted players -- or even=20
computers playing without a real person at all -- have the potential to=20
drive all the human players away from the game.
Look around the internet, and you see this problem pop up again and=20
again. The whole point of captchas is to ensure that it's a real=20
person visiting a website, not just a bot on a computer. Standard=20
testing doesn't work online, because the tester can't be sure that the=20
test taker doesn't have his book open, or a friend standing over his=20
shoulder helping him. The solution in both cases is a proctor, of=20
course, but that's not always practical and obviates the benefits of=20
internet testing.
This problem has even come up in court cases. In one instance, the=20
prosecution demonstrated that the defendant's computer committed some=20
hacking offence, but the defense argued that it wasn't the defendant=20
who did it -- that someone else was controlling his computer. And in=20
another case, a defendant charged with a child porn offense argued=20
that, while it was true illegal material was on his computer, his=20
computer was in a common room of his house and he hosted a lot of=20
parties -- and it wasn't him who'd downloaded the porn.
Years ago, talking about security, I complained about the link between=20
computer and chair. The easy part is securing digital information: on=20
the desktop computer, in transit from computer to computer, or on=20
massive servers. The hard part is securing information from the=20
computer to the person. Likewise, authenticating a computer is much=20
easier than authenticating a person sitting in front of the=20
computer. And verifying the integrity of data is much easier than=20
verifying the integrity of the person looking at it -- in both senses=20
of that word.
And it's a problem that will get worse as computers get better at=20
imitating people.
Google is testing a new advertising model to deal with click fraud:=20
cost per action. Advertisers don't pay unless the customer performs a=20
certain action: buys a product, fills out a survey, whatever. It's a=20
hard model to make work -- Google would become more of a partner in the=20
final sale instead of an indifferent displayer of advertising -- but=20
it's the right security response to click fraud: change the rules of=20
the game so that click fraud doesn't matter.
That's how to solve a security problem.
Lawsuits against Google:
http://www.sfgate.com/cgi-bin/article.cgi?f=3D/c/a/2006/03/09/BUGRMHKQTR1.=
=20
DTL or http://tinyurl.com/z6gju
http://www.marketwire.com/mw/release_html_b1?release_id=3D103417
Spoof site:
http://www.clickmonkeys.com/
Captchas:
http://en.wikipedia.org/wiki/Captchas
Google cost-per-action testing:
http://www.betanews.com/article/Google_Tests_CostPerAction_Ads/115100516=20
9 or http://tinyurl.com/znvzf
** *** ***** ******* *********** *************
News
Surreal story about a person coming into the U.S. from Iraq who is held=20
up at the border because he used to sell copyrighted images on T-shirts.
http://www.latimes.com/news/opinion/commentary/la-oe-lemoine13jun13,0,15=20
07648.story or http://tinyurl.com/ourlr
Patrick Smith writes the "Ask the Pilot" column for Salon. He's=20
written two very good posts on airline security, one about how Israel's=20
system won't work in the U.S., and the other about profiling:
http://www.salon.com/tech/col/smith/2006/06/09/askthepilot189/
http://www.salon.com/tech/col/smith/2006/06/16/askthepilot190/
There are a variety of encryption technologies that allow you to=20
analyze data without knowing details of the data. Think of it as=20
privacy-enhanced data mining.
http://www.wired.com/news/wireservice/0,71184-0.html
"How to build a low-cost, extended-range RFID skimmer" by Ilan=20
Kirschenbaum and Avishai Wool. To appear in 15th USENIX Security=20
Symposium, Vancouver, Canada, August 2006.
http://www.eng.tau.ac.il/~yash/kw-usenix06/index.html
Fascinating paper on Xbox security. The conclusion: "The security=20
system of the Xbox has been a complete failure."
http://www.xbox-linux.org/wiki/17_Mistakes_Microsoft_Made_in_the_Xbox_Se=20
curity_System or http://tinyurl.com/blbke
This sounds like a science fiction premise: unmanned drones that=20
monitor the population for crimes.
http://www.wired.com/news/wireservice/0,71198-0.html
Random identity generator:
http://dev.allredtech.com/fakename/
I have no idea how good they are.
More information about the Greek wiretapping scandal:
http://www.schneier.com/blog/archives/2006/06/greek_wiretappi_1.html
http://www.schneier.com/blog/archives/2006/07/greek_wiretappi.html
I wrote about it previously:
http://www.schneier.com/blog/archives/2006/02/phone_tapping_i.html
AT&T rewrites its privacy policy:
http://www.sfgate.com/cgi-bin/article.cgi?file=3D/chronicle/archive/2006/0=
=20
6/21/BUG9VJHB9C1.DTL&type=3Dbusiness or http://tinyurl.com/on53q
http://ars.userfriendly.org/cartoons/?id=3D20060625
I've long known about the possible Unix date issue, but this is the=20
first I've heard of an actual bug due to the Unix time epoch rolling=20
over in 2038.
http://thedailywtf.com/forums/thread/78254.aspx
MySpace is increasing security.
http://www.cnn.com/2006/TECH/internet/06/20/myspace.safety.ap.ap/index.h=20
tml or http://tinyurl.com/rplw8
Honestly, it all sounds a lot more like cover-your-ass security than=20
real security: MySpace securing itself from lawsuits. "Safety experts"=20
seem to agree that it won't improve security much.
http://www.washingtonpost.com/wp-dyn/content/article/2006/06/25/AR200606=20
2500426.html or http://tinyurl.com/r4vkn
Digital redacting failures are getting so common that they're no longer=20
news:
http://www.mercurynews.com/mld/mercurynews/sports/special_packages/dopin=20
g_scandal/14882936.htm or http://tinyurl.com/kbyjm
You'd think a national mint would have better security against=20
insiders. But no, an employee at the Australian Mint stole $600 a day=20
over a ten-month period.
http://www.smh.com.au/news/national/mint-security-lapse-amazes-judge/200=20
6/06/21/1150845228544.html or http://tinyurl.com/hox2e
Interesting research on how to defeat China's national firewall:
http://www.lightbluetouchpaper.org/2006/06/27/ignoring-the-great-firewal=20
l-of-china/ or http://tinyurl.com/zzbt5
Congress learns how little privacy we have:
http://www.washingtonpost.com/wp-dyn/content/article/2006/06/25/AR200606=20
2500426.html
Excellent analysis on applying CALEA to VoIP: "Security Implications=20
of Applying the Communications Assistance to Law Enforcement Act to=20
Voice over IP," by Steve Bellovin, Matt Blaze, Ernie Brickell, Clint=20
Brooks, Vint Cerf, Whit Diffie, Susan Landau, Jon Peterson, and John=20
Treichler. At least read the Executive Summary.
http://www.itaa.org/news/docs/CALEAVOIPreport.pdf
Maybe I shouldn't have said this: "'I have a completely open Wi-Fi=20
network,' Schneier told ZDNet UK. 'Firstly, I don't care if my=20
neighbors are using my network. Secondly, I've protected my computers.=20
Thirdly, it's polite. When people come over they can use it.'" For the=20
record, I have an ultra-secure wireless network that automatically=20
reports all hacking attempts to unsavory men with bitey dogs.
http://news.com.com/2100-1029_3-6088741.html
More true than funny, unfortunately. A template for news stories on=20
data gathering:
http://www.concurringopinions.com/archives/2006/06/template_for_ne.html
I can't believe I forgot to blog this great article about the=20
communications intercept trade show in DC:
http://www.wired.com/news/technology/0,71022-0.html?tw=3Dwn_story_page_pre=
=20
v2 or http://tinyurl.com/rsebu
Just patented: password-protected bullets:
http://www.newscientisttech.com/article.ns?id=3Ddn9412&feedId=3Donline-news_=
=20
rss20 or http://tinyurl.com/pyn4s
Does Microsoft have the ability to disable Windows remotely? Maybe.
http://blogs.zdnet.com/Bott/?p=3D84&tag=3Dnl.e622
Loading ActiveX controls on Vista without administrator privileges.
http://www.schneier.com/blog/archives/2006/07/load_activex_co.html
There's a lot of discussion as to whether this is a good idea or=20
not. I think ActiveX is a bad idea in the first place.
A song: Facial Recognition Technology Blues
http://www.eddiebandthegspots.com/Facial%20Recognition%20Technology%20Bl=20
ues.mp3 or http://tinyurl.com/hgnbm
This cell phone has a built in Breathalyzer. It alerts you if you're=20
too drunk to drive, and allows you to configure certain phone numbers=20
so you can't dial them while drunk. Think ex-lovers, and perhaps your=20
boss.
http://abcnews.go.com/Technology/story?id=3D2125709
Annual Report from the Privacy Commissioner of Canada
http://www.privcom.gc.ca/information/ar/200506/200506_pa_e.asp
This is the 2001-2002 report:
http://www.privcom.gc.ca/information/ar/02_04_10_e.asp
Excellent reading.
In this attack, you can seize control of someone's computer using his=20
WiFi interface, even if he's not connected to a network. No details=20
yet; the researchers are presenting their results at BlackHat on August=20
2nd.
http://www.infoworld.com/article/06/06/21/79536_HNwifibreach_1.html
No details yet. The researchers are presenting their results at=20
BlackHat on August 2.
http://www.blackhat.com/html/bh-usa-06/bh-usa-06-index.html
Here's a new patent issued to the U.S. Navy. It sounds like they've=20
patented the firewall.
http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=3DPTO1&Sect2=3DHITOFF&d=3DP=
G0=20
1&p=3D1&u=3D%2Fnetahtml%2FPTO%2Fsrchnum.html&r=3D1&f=3DG&l=3D50&s1=3D%222005=
0022023%=20
22.PGNR.&OS=3DDN/20050022023&RS=3DDN/20050022023 or http://tinyurl.com/khex6
Here's a chronology of data breaches since the ChoicePoint theft in=20
February 2005. Total identities stolen: 88,794,619. Although, almost=20
certainly, many names are on that list multiple times.
http://www.privacyrights.org/ar/ChronDataBreaches.htm
I have already explained why NSA-style wholesale surveillance=20
data-mining systems are useless for finding terrorists. Here's a more=20
formal explanation:
http://www.lewrockwell.com/orig7/rudmin1.html
My essay:
http://www.schneier.com/blog/archives/2006/03/data_mining_for.html
One response to software liability is to deliberately program in such a=20
way as to obscure liabilities. This blog entry on "unreliable=20
programming" is satire, but it's perceptive.
http://pestilenz.org/cgi-bin/blosxom.cgi/2005/11/11
A news article on the failure of two-factor authentication. Phishers=20
are converting to man-in-the-middle attacks, which bypass the security=20
measures.
http://blog.washingtonpost.com/securityfix/2006/07/citibank_phish_spoofs=20
_2factor_1.html or http://tinyurl.com/rbmr2
I predicted this last year.
http://www.schneier.com/crypto-gram-0503.html#2
The New York Times is running a scare story on the linkage between=20
identity theft and methamphetamine users. Supposedly meth users are=20
ideally suited to be computer hackers. I don't know if this is true or=20
not, but I worry about Congressional intervention if hacking gets=20
linked to the war on drugs.
http://www.nytimes.com/2006/07/11/us/11meth.html
The Galileo satellite codes have been cracked. Actually, the cracked=20
codes are from a prototype satellite; the final Galileo codes will be=20
different.
http://www.newswise.com/articles/view/521790/
Spy gadgets you can buy. What's interesting to me is less what is=20
available commercially today, and more what we can extrapolate is=20
available to real spies.
http://darkcreek.com/detective_equipment/notebook.htm
Good article on how complexity greatly limits the effectiveness of=20
terror investigations. The stories of wasted resources are all from the=20
UK, but the morals are universal.
http://www.theregister.com/2006/07/06/90_days_terror_law_analysis/
** *** ***** ******* *********** *************
Getting a Personal Unlock Code for Your O2 Cell Phone
O2 is a UK cell phone network. The company gives you the option of=20
setting up a PIN on your phone. The idea is that if someone steals=20
your phone, they can't make calls. If they type the PIN incorrectly=20
three times, the phone is blocked. To deal with the problems of phone=20
owners mistyping their PIN -- or forgetting it -- they can contact O2=20
and get a Personal Unlock Code (PUK). Presumably, the operator goes=20
through some authentication steps to ensure that the person calling is=20
actually the legitimate owner of the phone.
So far, so good.
But O2 has decided to automate the PUK process. Now anyone on the=20
Internet can visit an O2 website type in a valid mobile telephone=20
number, and get a valid PUK to reset the PIN -- without any=20
authentication whatsoever.
This seems like a bad idea, but after I posted it on my blog a=20
representative from O2 sent me the following:
"Yes, it does seem there is a security risk by O2 supplying such a=20
service, but in fact we believe this risk is very small. The risk is=20
when a customer's phone is lost or stolen. There are two scenarios in=20
that event:
"Scenario 1 - The phone is powered off. A PIN number would be required=20
at next power on. Although the PUK code will indeed allow you to reset=20
the PIN, you need to know the telephone number of the SIM in order to=20
get it =96 there is no way to determine the telephone number from the SIM=20
or handset itself. Should the telephone number be known the risk is=20
then same as scenario 2.
"Scenario 2 - The phone remains powered on: here, the thief can use the=20
phone in any case without having to acquire PUK.
"In both scenarios we have taken the view that the principle security=20
measure is for the customer to report the loss/theft as quickly as=20
possible, so that we can remotely disable both the SIM and also the=20
handset (so that it cannot be used with any other SIM)."
The O2 website:
http://www.o2.co.uk/puk/landing/0,,555,00.html
** *** ***** ******* *********** *************
The League of Women Voters Supports Voter-Verifiable Paper Trails
For a long time, the League of Women Voters (LWV) had been on the wrong=20
side of the electronic voting machine issue. They were in favor of=20
electronic machines, and didn't see the need for voter-verifiable paper=20
trails. (They use to have a horrid and misleading Q&A about the issue=20
on their website, but it's gone now. Barbara Simons published a=20
rebuttal, which includes their original Q&A.)
The politics of the LWV are Byzantine, but basically there are local=20
leagues under state leagues, which in turn are under the national=20
(LWVUS) league. There is a national convention once every other year,=20
and all sorts of resolutions are passed by the membership. But the=20
national office can do a lot to undercut the membership and the state=20
leagues. The politics of voting machines is an example of this.
At the 2004 convention, the LWV membership passed a resolution on=20
electronic voting called "SARA," which stood for "Secure, Accurate,=20
Recountable, and Accessible." Those in favor of the resolution thought=20
that "recountable" meant auditable, which meant voter-verifiable paper=20
trails. But the national LWV office decided to spin SARA to say that=20
recountable does not imply paper. While they could no longer oppose=20
paper outright, they refused to say that paper was desirable. For=20
example, they held Georgia's system up as a model, and Georgia uses=20
paperless Diebold DRE machines. It makes you wonder if the LWVUS=20
leadership is in someone's pocket.
So at the 2006 convention, the LWV membership passed *another*=20
resolution. This one was much more clearly worded: designed to make it=20
impossible for the national office to pretend that the LWV was not in=20
favor of voter-verified paper trails.
Unfortunately, the League of Women Voters has not issued a press=20
release about this resolution. (There is a press release by=20
VerifiedVoting.org about it.) I'm sure that the national office simply=20
doesn't want to acknowledge the membership's position on the issue, and=20
wishes the issue would just go away quietly. It's a pity; the=20
resolution is a great one and worth publicizing.
Here's the text of the resolution:
"Resolution Related to Program Requiring a Voter-Verifiable Paper=20
Ballot or Paper Record with Electronic Voting Machines
"Motion to adopt the following resolution related to program requiring=20
a voter-verified paper ballot or paper record with electronic voting=20
systems.
"Whereas: Some LWVs have had difficulty applying the SARA Resolution=20
(Secure, Accurate, Recountable and Accessible) passed at the last=20
Convention, and
"Whereas: Paperless electronic voting systems are not inherently=20
secure, can malfunction, and do not provide a recountable audit trail,
"Therefore be it resolved that:
"The position on the Citizens' Right to Vote be interpreted to affirm=20
that LWVUS supports only voting systems that are designed so that:
1. they employ a voter-verifiable paper ballot or other paper record,=20
said paper being the official record of the voter=B9s intent; and
2. the voter can verify, either by eye or with the aid of suitable=20
devices for those who have impaired vision, that the paper=20
ballot/record accurately reflects his or her intent; and
3. such verification takes place while the voter is still in the=20
process of voting; and
4. the paper ballot/record is used for audits and recounts; and
5. the vote totals can be verified by an independent hand count of the=20
paper ballot/record; and
6. routine audits of the paper ballot/record in randomly selected=20
precincts can be conducted in every election, and the results published=20
by the jurisdiction."
By the way, the 2006 LWV membership also voted on a resolution in favor=20
of net neutrality (the Connecticut league issued a press release,=20
because they spearheaded the issue), and one against the death=20
penalty. The national LWV office hasn't issued a press release about=20
those two issues, either.
Verified Voting press release:
http://www.verifiedvotingfoundation.org/article.php?id=3D6363
Net neutrality press release by the Connecticut LWV:
http://www.lwvct.org/issues/action/061506-release-net%20neutrality.htm
Q&A with Barbara Simons' rebuttal:
http://www.schneier.com/lwv-qa.pdf
** *** ***** ******* *********** *************
Brennan Center and Electronic Voting
I have been participating in the Brennan Center's Task Force on Voting=20
Security. Earlier this month we released a report on electronic voting.
From the executive summary:
"In 2005, the Brennan Center convened a Task Force of internationally=20
renowned government, academic, and private-sector scientists, voting=20
machine experts and security professionals to conduct the nation's=20
first systematic analysis of security vulnerabilities in the three most=20
commonly purchased electronic voting systems. The Task Force spent=20
more than a year conducting its analysis and drafting this report.=20
During this time, the methodology, analysis, and text were extensively=20
peer reviewed by the National Institute of Standards and Technology=20
("NIST")."
And:
"The Task Force examined security threats to the technologies used in=20
Direct Recording Electronic voting systems ("DREs"), DREs with a voter=20
verified auditable paper trail ("DREs w/ VVPT") and Precinct Count=20
Optical Scan ("PCOS") systems. The analysis assumes that appropriate=20
physical security and accounting procedures are all in place."
And:
"Three fundamental points emerge from the threat analysis in the=20
Security Report:
"1. All three voting systems have significant security and reliability=20
vulnerabilities, which pose a real danger to the integrity of national,=20
state, and local elections.
2. The most troubling vulnerabilities of each system can be=20
substantially remedied if proper countermeasures are implemented at the=20
state and local level.
3. Few jurisdictions have implemented any of the key countermeasures=20
that could make the least difficult attacks against voting systems much=20
more difficult to execute successfully."
And:
"There are a number of steps that jurisdictions can take to address the=20
vulnerabilities identified in the Security Report and make their voting=20
systems significantly more secure. We recommend adoption of the=20
following security measures:
"1. Conduct automatic routine audits comparing voter verified paper=20
records to the electronic record following every election. A voter=20
verified paper record accompanied by a solid automatic routine audit of=20
those records can go a long way toward making the least difficult=20
attacks much more difficult.
2. Perform "parallel testing" (selection of voting machines at random=20
and testing them as realistically as possible on Election Day.) For=20
paperless DREs, in particular, parallel testing will help jurisdictions=20
detect software-based attacks, as well as subtle software bugs that may=20
not be discovered during inspection and other testing.
3. Ban use of voting machines with wireless components. All three=20
voting systems are more vulnerable to attack if they have wireless=20
components.
4. Use a transparent and random selection process for all auditing=20
procedures. For any auditing to be effective (and to ensure that the=20
public is confident in such procedures), jurisdictions must develop and=20
implement transparent and random selection procedures.
5. Ensure decentralized programming and voting system administration.=20
Where a single entity, such as a vendor or state or national=20
consultant, performs key tasks for multiple jurisdictions, attacks=20
against statewide elections become easier.
6. Institute clear and effective procedures for addressing evidence of=20
fraud or error. Both automatic routine audits and parallel testing are=20
of questionable security value without effective procedures for action=20
where evidence of machine malfunction and/or fraud is discovered.=20
Detection of fraud without an appropriate response will not prevent=20
attacks from succeeding."
The report is long, but I think it's worth reading. If you're short on=20
time, though, at least read the Executive Summary.
The report has generated some press. Unfortunately, the news articles=20
recycle some of the lame points that Diebold continues to make in the=20
face of this kind of analysis. From The Washington Post article:
"Voting machine vendors have dismissed many of the concerns, saying=20
they are theoretical and do not reflect the real-life experience of=20
running elections, such as how machines are kept in a secure environment.
"'It just isn't the piece of equipment, ' said David Bear, a spokesman=20
for Diebold Election Systems, one of the country's largest vendors.=20
'It's all the elements of an election environment that make for a=20
secure election.'
"'This report is based on speculation rather than an examination of the=20
record. To date, voting systems have not been successfully attacked in=20
a live election,' said Bob Cohen, a spokesman for the Election=20
Technology Council, a voting machine vendors' trade group. 'The=20
purported vulnerabilities presented in this study, while interesting in=20
theory, would be extremely difficult to exploit.'"
I wish The Washington Post found someone to point out that there have=20
been many, many irregularities with electronic voting machines over the=20
years, and the lack of convincing evidence of fraud is exactly the=20
problem with their no-audit-possible systems. Or that the "it's all=20
theoretical" argument is the same one that software vendors used to use=20
to discredit security vulnerabilities before the full-disclosure=20
movement forced them to admit that their software had problems.
The report:
http://www.brennancenter.org/presscenter/releases_2006/pressrelease_2006=20
_0627.html or http://tinyurl.com/mwzy8
http://www.brennancenter.org/programs/downloads/Full%20Report.pdf
http://www.brennancenter.org/programs/downloads/Executive%20Summary.pdf
News articles:
http://today.reuters.com/news/newsArticle.aspx?type=3DdomesticNews&storyID=
=20
=3D2006-06-27T130232Z_01_N26181575_RTRUKOC_0_US-VOTINGMACHINES.xml or=20
http://tinyurl.com/kca69
http://business.bostonherald.com/technologyNews/view.bg?articleid=3D145981=
=20
or http://tinyurl.com/gdx7l
http://www.usatoday.com/news/washington/2006-06-26-e-voting_x.htm
http://www.washingtonpost.com/wp-dyn/content/article/2006/06/27/AR200606=20
2701451_pf.html or http://tinyurl.com/oudom
** *** ***** ******* *********** *************
Comments from Readers
There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and=20
join in.
http://www.schneier.com/blog
** *** ***** ******* *********** *************
CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise. You=20
can subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>. Back issues are also=20
available at that URL.
Comments on CRYPTO-GRAM should be sent to=20
[email protected]. Permission to print comments is assumed=20
unless otherwise stated. Comments may be edited for length and clarity.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable. Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entirety.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of=20
the best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography," and an inventor of the Blowfish and Twofish=20
algorithms. He is founder and CTO of Counterpane Internet Security=20
Inc., and is a member of the Advisory Board of the Electronic Privacy=20
Information Center (EPIC). He is a frequent writer and lecturer on=20
security topics. See <http://www.schneier.com>.
Counterpane is the world's leading protector of networked information -=20
the inventor of outsourced security monitoring and the foremost=20
authority on effective mitigation of emerging IT threats. Counterpane=20
protects networks for Fortune 1000 companies and governments=20
world-wide. See <http://www.counterpane.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not=20
necessarily those of Counterpane Internet Security, Inc.
Copyright (c) 2006 by Bruce Schneier.