CRYPTO-GRAM, November 15, 2006
Bruce Schneier <[email protected]> Wed, 15 Nov 2006 02:48:38 -0600
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
November 15, 2006
by Bruce Schneier
Founder and CTO
Counterpane Internet Security, Inc.
[email protected]
http://www.schneier.com
http://www.counterpane.com
A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0611.html>. These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>. An RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Voting Technology and Security
More on Electronic Voting Machines
The Inherent Inaccuracy of Voting
The Need for Professional Election Officials
Perceived Risk vs. Actual Risk
Crypto-Gram Reprints
Total Information Awareness Is Back
Forge Your Own Boarding Pass
News
The Death of Ephemeral Conversation
Airline Passenger Profiling for Profit
Counterpane News
Architecture and Security
The Doghouse: Skylark Utilities
Heathrow Tests Biometric ID
Please Stop My Car
Air Cargo Security
Cheyenne Mountain Retired
Comments from Readers
** *** ***** ******* *********** *************
Voting Technology and Security
Last week in Florida's 13th Congressional district, the victory margin=20
was only 386 votes out of 153,000. There'll be a mandatory lawyered-up=20
recount, but it won't include the almost 18,000 votes that seem to have=20
disappeared. The electronic voting machines didn't include them in their=20
final tallies, and there's no backup to use for the recount. The=20
district will pick a winner to send to Washington, but it won't be=20
because they are sure the majority voted for him. Maybe the majority=20
did, and maybe it didn't. There's no way to know.
Electronic voting machines represent a grave threat to fair and accurate=20
elections, a threat that every American -- Republican, Democrat or=20
independent -- should be concerned about. Because they're=20
computer-based, the deliberate or accidental actions of a few can swing=20
an entire election. The solution: Paper ballots, which can be verified=20
by voters and recounted if necessary.
To understand the security of electronic voting machines, you first have=20
to consider election security in general. The goal of any voting system=20
is to capture the intent of each voter and collect them all into a final=20
tally. In practice, this occurs through a series of transfer steps. When=20
I voted last week, I transferred my intent onto a paper ballot, which=20
was then transferred to a tabulation machine via an optical scan reader;=20
at the end of the night, the individual machine tallies were transferred=20
by election officials to a central facility and combined into a single=20
result I saw on television.
All election problems are errors introduced at one of these steps,=20
whether it's voter disenfranchisement, confusing ballots, broken=20
machines or ballot stuffing. Even in normal operations, each step can=20
introduce errors. Voting accuracy, therefore, is a matter of 1)=20
minimizing the number of steps, and 2) increasing the reliability of=20
each step.
Much of our election security is based on "security by competing=20
interests." Every step, with the exception of voters completing their=20
single anonymous ballots, is witnessed by someone from each major party;=20
this ensures that any partisan shenanigans -- or even honest mistakes --=20
will be caught by the other observers. This system isn't perfect, but=20
it's worked pretty well for a couple hundred years.
Electronic voting is like an iceberg; the real threats are below the=20
waterline where you can't see them. Paperless electronic voting machines=20
bypass that security process, allowing a small group of people -- or=20
even a single hacker -- to affect an election. The problem is software=20
-- programs that are hidden from view and cannot be verified by a team=20
of Republican and Democrat election judges, programs that can=20
drastically change the final tallies. And because all that's left at the=20
end of the day are those electronic tallies, there's no way to verify=20
the results or to perform a recount. Recounts are important.
This isn't theoretical. In the U.S., there have been hundreds of=20
documented cases of electronic voting machines distorting the vote to=20
the detriment of candidates from both political parties: machines losing=20
votes, machines swapping the votes for candidates, machines registering=20
more votes for a candidate than there were voters, machines not=20
registering votes at all. I would like to believe these are all mistakes=20
and not deliberate fraud, but the truth is that we can't tell the=20
difference. And these are just the problems we've caught; it's almost=20
certain that many more problems have escaped detection because no one=20
was paying attention.
This is both new and terrifying. For the most part, and throughout most=20
of history, election fraud on a massive scale has been hard; it requires=20
very public actions or a highly corrupt government -- or both. But=20
electronic voting is different: a lone hacker can affect an election. He=20
can do his work secretly before the machines are shipped to the polling=20
stations. He can affect an entire area's voting machines. And he can=20
cover his tracks completely, writing code that deletes itself after the=20
election.
And that assumes well-designed voting machines. The actual machines=20
being sold by companies like Diebold, Sequoia Voting Systems and=20
Election Systems & Software are much worse. The software is badly=20
designed. Machines are "protected" by hotel minibar keys. Vote tallies=20
are stored in easily changeable files. Machines can be infected with=20
viruses. Some voting software runs on Microsoft Windows, with all the=20
bugs and crashes and security vulnerabilities that introduces. The list=20
of inadequate security practices goes on and on.
The voting machine companies counter that such attacks are impossible=20
because the machines are never left unattended (they're not), the memory=20
cards that hold the votes are carefully controlled (they're not), and=20
everything is supervised (it isn't). Yes, they're lying, but they're=20
also missing the point.
We shouldn't -- and don't -- have to accept voting machines that might=20
someday be secure only if a long list of operational procedures are=20
followed precisely. We need voting machines that are secure regardless=20
of how they're programmed, handled and used, and that can be trusted=20
even if they're sold by a partisan company, or a company with possible=20
ties to Venezuela.
Sounds like an impossible task, but in reality, the solution is=20
surprisingly easy. The trick is to use electronic voting machines as=20
ballot-generating machines. Vote by whatever automatic touch-screen=20
system you want: a machine that keeps no records or tallies of how=20
people voted, but only generates a paper ballot. The voter can check it=20
for accuracy, then process it with an optical-scan machine. The second=20
machine provides the quick initial tally, while the paper ballot=20
provides for recounts when necessary. And absentee and backup ballots=20
can be counted the same way.
You can even do away with the electronic vote-generation machines=20
entirely and hand-mark your ballots like we do in Minnesota. Or run a=20
100% mail-in election like Oregon does. Again, paper ballots are the key.
Paper? Yes, paper. A stack of paper is harder to tamper with than a=20
number in a computer's memory. Voters can see their vote on paper,=20
regardless of what goes on inside the computer. And most important,=20
everyone understands paper. We get into hassles over our cell phone=20
bills and credit card mischarges, but when was the last time you had a=20
problem with a $20 bill? We know how to count paper. Banks count it all=20
the time. Both Canada and the U.K. count paper ballots with no problems,=20
as do the Swiss. We can do it, too. In today's world of computer=20
crashes, worms and hackers, a low-tech solution is the most secure.
Secure voting machines are just one component of a fair and honest=20
election, but they're an increasingly important part. They're where a=20
dedicated attacker can most effectively commit election fraud (and we=20
know that changing the results can be worth millions). But we shouldn't=20
forget other voter suppression tactics: telling people the wrong polling=20
place or election date, taking registered voters off the voting rolls,=20
having too few machines at polling places, or making it onerous for=20
people to register. (Oddly enough, ineligible people voting isn't a=20
problem in the U.S., despite political rhetoric to the contrary; every=20
study shows their numbers to be so small as to be insignificant. And=20
photo ID requirements actually cause more problems than they solve.)
Voting is as much a perception issue as it is a technological issue.=20
It's not enough for the result to be mathematically accurate; every=20
citizen must also be confident that it is correct. Around the world,=20
people protest or riot after an election not when their candidate loses,=20
but when they think their candidate lost unfairly. It is vital for a=20
democracy that an election both accurately determine the winner and=20
adequately convince the loser. In the U.S., we're losing the perception=20
battle.
The current crop of electronic voting machines fail on both counts. The=20
results from Florida's 13th Congressional district are neither accurate=20
nor convincing. As a democracy, we deserve better. We need to refuse to=20
vote on electronic voting machines without a voter-verifiable paper=20
ballot, and to continue to pressure our legislatures to implement voting=20
technology that works.
This essay originally appeared on Forbes.com.
http://www.forbes.com/home/security/2006/11/10/voting-fraud-security-tech=
-security-cz_bs_1113security.html
http://www.schneier.com/essay-068.html
http://www.schneier.com/blog/archives/2004/11/the_problem_wit.html
http://www.votingintegrity.org/archive/news/e-voting.html
http://www.verifiedvoting.org/article.php?id=3D997
http://www.ecotalk.org/VotingMachineErrors.htm
http://evote-mass.org/pipermail/evote-discussion_evote-mass.org/2005-Janu=
ary/000080.html=20
or http://tinyurl.com/yhvb2a
http://avirubin.com/vote/analysis/index.html
http://www.freedom-to-tinker.com/?p=3D1080
http://www.freedom-to-tinker.com/?p=3D1081
http://www.freedom-to-tinker.com/?p=3D1064
http://www.freedom-to-tinker.com/?p=3D1084
http://www.bbvforums.org/cgi-bin/forums/board-auth.cgi?file=3D/1954/15595=
.html=20
or http://tinyurl.com/9ywcn
http://itpolicy.princeton.edu/voting
http://www.ss.ca.gov/elections/voting_systems/security_analysis_of_the_di=
ebold_accubasic_interpreter.pdf=20
or http://tinyurl.com/eqpbd
http://www.blackboxvoting.org
http://www.brennancenter.org/dynamic/subpages/download_file_38150.pdf
http://avirubin.com/judge2.html
http://avirubin.com/judge.html
http://www.usatoday.com/news/washington/2006-10-29-voting-systems-probe_x=
.htm=20
or http://tinyurl.com/ylnba6
How to Steal an Election:
http://arstechnica.com/articles/culture/evoting.ars
Florida 13:
http://www.heraldtribune.com/apps/pbcs.dll/article?AID=3D/20061111/NEWS/6=
11110643=20
or http://tinyurl.com/ygo73l
http://www.heraldtribune.com/apps/pbcs.dll/article?Date=3D20061108&Catego=
ry=3DNEWS&ArtNo=3D611080506=20
or http://tinyurl.com/yahvve
http://www.heraldtribune.com/apps/pbcs.dll/article?AID=3D/20061109/NEWS/6=
11090343=20
or http://tinyurl.com/yhkwdt
http://www.nytimes.com/2006/11/10/us/politics/10florida.html
http://www.lipsio.com/SarasotaFloridaPrecinct22IncidentPhotos/
Value of stolen elections:
http://www.schneier.com/essay-046.html
Perception:
http://www.npr.org/templates/story/story.php?storyId=3D6449790
Voter suppression:
http://blackprof.com/stealingd.html
ID requirements:
http://www.lwvwi.org/cms/images/stories/PDFs/VR%20Photo%20ID.pdf
http://www.demos.org/page337.cfm
Foxtrot cartoon:
http://www.gocomics.com/foxtrot/2006/10/29
Avi Rubin wrote a good essay on voting for "Forbes" as well.
http://www.forbes.com/home/free_forbes/2006/0904/040.html
** *** ***** ******* *********** *************
More on Electronic Voting Machines
Florida 13 is turning out to be a bigger problem than I described:
"The Democrat, Christine Jennings, lost to her Republican opponent, Vern=20
Buchanan, by just 373 votes out of a total 237,861 cast -=ADone of the=20
closest House races in the nation. More than 18,000 voters in Sarasota=20
County, or 13 percent of those who went to the polls Tuesday, did not=20
seem to vote in the Congressional race when they cast ballots, a=20
discrepancy that Kathy Dent, the county elections supervisor, said she=20
could not explain.
"In comparison, only 2 percent of voters in one neighboring county=20
within the same House district and 5 percent in another skipped the=20
Congressional race, according to The Herald-Tribune of Sarasota. And=20
many of those who did not seem to cast a vote in the House race did vote=20
in more obscure races, like for the hospital board."
And the absentee ballots collected for the same race show only a 2.5%=20
difference in the number of voters that voted for candidates in other=20
races but not for Congress.
There'll be a recount, and with that close a margin it's pretty random=20
who will eventually win. But because so many votes were not recorded --=20
and I don't see how anyone who has any understanding of statistics can=20
look at this data and not conclude that votes were not recorded -- we'll=20
never know who should really win this district.
In Pennsylvania, the Republican State Committee is asking the Secretary=20
of State to impound voting machines because of potential voting errors.=20
According to KDKA:
"Pennsylvania GOP officials claimed there were reports that some=20
machines were changing Republican votes to Democratic votes. They asked=20
the state to investigate and said they were not ruling out a legal=20
challenge.
"According to Santorum's camp, people are voting for Santorum, but the=20
vote either registered as invalid or a vote for Casey."
RedState.com describes some of the problems:
"RedState is getting widespread reports of an electoral nightmare=20
shaping up in Pennsylvania with certain types of electronic voting machin=
es.
"In some counties, machines are crashing. In other counties, we have=20
enough reports to treat as credible that fact that some Rendell votes=20
are being tabulated by the machines for Swann and vice versa. The same=20
is happening with Santorum and Casey. Reports have been filed with the=20
Pennsylvania Secretary of State, but nothing has happened."
I'm happy to see a Republican at the receiving end of the problems.
Actually, that's not true. I'm not happy to see anyone at the receiving=20
end of voting problems. But I am sick and tired of this being perceived=20
as a partisan issue, and I hope some high-profile Republican losses that=20
might be attributed to electronic voting-machine malfunctions (or even=20
fraud) will change that perception. This is a serious problem that=20
affects everyone, and it is in everyone's interest to fix it.
FL-13 was the big voting-machine disaster, but there were other=20
electronic voting-machine problems reported. EFF wrote: "The types of=20
machine problems reported to EFF volunteers were wide-ranging in both=20
size and scope. Polls opened late for machine-related reasons in polling=20
places throughout the country, including Ohio, Florida, Georgia,=20
Virginia, Utah, Indiana, Illinois, Tennessee, and California. In Broward=20
County, Florida, voting machines failed to start up at one polling=20
place, leaving some citizens unable to cast votes for hours. EFF and the=20
Election Protection Coalition sought to keep the polling place open late=20
to accommodate voters frustrated by the delays, but the officials=20
refused. In Utah County, Utah, more than 100 precincts opened one to two=20
hours late on Tuesday due to problems with machines. Both county and=20
state election officials refused to keep polling stations open longer to=20
make up for the lost time, and a judge also turned down a voter's plea=20
for extended hours brought by EFF."
And there's an election for mayor, where one of the candidates received=20
zero votes -- even though that candidate is sure he voted for himself.
ComputerWorld is also reporting problems across the country, as is "The=20
New York Times". Avi Rubin, whose writings on electronic voting=20
security are always worth reading, writes about a problem he witnessed=20
in Maryland:
"The voter had made his selections and pressed the "cast ballot" button=20
on the machine. The machine spit out his smartcard, as it is supposed to=20
do, but his summary screen remained, and it did not appear that his vote=20
had been cast. So, he pushed the smartcard back in, and it came out=20
saying that he had already voted. But, he was still in the screen that=20
showed he was in the process of voting. The voter then pressed the "cast=20
ballot" again, and an error message appeared on the screen that said=20
that he needs to call a judge for assistance. The voter was very=20
patient, but was clearly taking this very seriously, as one would=20
expect. After discussing the details about what happened with him very=20
carefully, I believed that there was a glitch with his machine, and that=20
it was in an unexpected state after it spit out the smartcard. The=20
question we had to figure out was whether or not his vote had been=20
recorded. The machine said that there had been 145 votes cast. So, I=20
suggested that we count the voter authority cards in the envelope=20
attached to the machine. Since we were grouping them into bundles of 25=20
throughout the day, that was pretty easy, and we found that there were=20
146 authority cards. So, this meant that either his vote had not been=20
counted, or that the count was off for some other reason. Considering=20
that the count on that machine had been perfect all day, I thought that=20
the most likely thing is that this glitch had caused his vote not to=20
count. Unfortunately, because while this was going on, all the other=20
voters had left, other election judges had taken down and put away the=20
e-poll books, and we had no way to encode a smartcard for him. We were=20
left with the possibility of having the voter vote on a provisional=20
ballot, which is what he did. He was gracious, and understood our=20
predicament.
"The thing is, that I don't know for sure now if this voter's vote will=20
be counted once or twice (or not at all if the board of election rejects=20
his provisional ballot). In fact, the purpose of counting the voter=20
authority cards is to check the counts on the machines hourly. What we=20
had done was to use the number of cards to conclude something about=20
whether a particular voter had voted, and that is not information that=20
these cards can provide. Unfortunately, I believe there are an=20
unimaginable number of problems that could crop up with these machines=20
where we would not know for sure if a voter's vote had been recorded,=20
and the machines provide no way to check on such questions. If we had=20
paper ballots that were counted by optical scanners, this kind of=20
situation could never occur."
How many hundreds of these stories do we need before we conclude that=20
electronic voting machines aren't accurate enough for elections?
On the plus side, the FL-13 problems have convinced some previous=20
naysayers in that district: "Supervisor of Elections Kathy Dent now=20
says she will comply with voters who want a new voting system -- one=20
that produces a paper trail.... Her announcement Friday marks a=20
reversal for the elections supervisor, who had promoted and adamantly=20
defended the touch-screen system the county purchased for $4.5 million=20
in 2001."
One of the dumber comments I hear about electronic voting goes something=20
like this: "If we can secure multi-million-dollar financial=20
transactions, we should be able to secure voting." Most financial=20
security comes through audit: names are attached to every transaction,=20
and transactions can be unwound if there are problems. Voting requires=20
an anonymous ballot, which means that most of our anti-fraud systems=20
from the financial world don't apply to voting. (I first explained this=20
back in 2001.)
In Minnesota, we use paper ballots counted by optical scanners, and we=20
have some of the most well-run elections in the country. To anyone=20
reading this who needs to buy new election equipment, this is what to buy=
.
On the other hand, I am increasingly of the opinion that an all mail-in=20
election -- like Oregon has -- is the right answer. Yes, there are=20
authentication issues with mail-in ballots, but these are issues we have=20
to solve anyway, as long as we allow absentee ballots. And yes, there=20
are vote-buying issues, but almost everyone considers them to be=20
secondary. The combined benefits of 1) a paper ballot, 2) no worries=20
about long lines due to malfunctioning or insufficient machines, 3)=20
increased voter turnout, and 4) a dampening of the last-minute campaign=20
frenzy make Oregon's election process very appealing.
FL-13:
http://www.nytimes.com/2006/11/10/us/politics/10florida.html
http://www.srqelections.com/results/gen2006sum.htm
http://www.srqelections.com/results/gen2006pct.htm
http://www.heraldtribune.com/apps/pbcs.dll/article?AID=3D/20061111/NEWS/6=
11110643=20
or http://tinyurl.com/ygo73l
Convincing naysayers:
http://www.heraldtribune.com/apps/pbcs.dll/article?AID=3D/20061111/NEWS/6=
11110530=20
or http://tinyurl.com/yhr6uv
Pennsylvania:
http://kdka.com/topstories/local_story_311194635.html
http://www.redstate.com/stories/elections/2006/breaking_massive_meltdown_=
in_pennsylvanian=20
or http://tinyurl.com/yjrb68
http://www.eff.org/news/archives/2006_11.php#004991
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic=
&articleId=3D9004849&source=3DNLT_SEC&nlid=3D38=20
or http://tinyurl.com/yf652b
http://www.nytimes.com/2006/11/08/us/politics/08blogs.html
http://arstechnica.com/news.ars/post/20061101-8131.html
http://www.bradblog.com/?p=3D3714
http://www.bradblog.com/?p=3D3719
E-voting state by state:
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic=
&articleId=3D9004591=20
or http://tinyurl.com/yhg3bw
E-voting vendors:
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic=
&articleId=3D9004583=20
or http://tinyurl.com/y6sxuf
HBO's "Hacking Democracy" documentary:
http://www.hbo.com/docs/programs/hackingdemocracy/index.html
http://www.nytimes.com/2006/11/02/arts/television/02hack.html
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic=
&articleId=3D9004584=20
or http://tinyurl.com/yhj8ob
Avi Rubin on voting:
http://avirubin.com/vote/
http://avi-rubin.blogspot.com/2006/11/my-day-at-polls-maryland-general.ht=
ml=20
or http://tinyurl.com/yjze8k
David Wagner and Ed Felten design a better voting machine.
http://www.wired.com/news/politics/evote/1,71957-0.html
Mayoral election:
http://abcnews.go.com/US/wireStory?id=3D2646802&CMP=3DOTC-RSSFeeds0312
My previous writings on electronic voting, as far back as 2000:
http://www.schneier.com/essay-068.html
http://www.schneier.com/essay-067.html
http://www.schneier.com/crypto-gram-0312.html#9
http://www.schneier.com/essay-101.html
http://www.schneier.com/crypto-gram-0012.html#1
Voting vs. e-commerce:
http://www.schneier.com/crypto-gram-0102.html#10
** *** ***** ******* *********** *************
The Inherent Inaccuracy of Voting
In a "New York Times" op-ed, New York University sociology professor=20
Dalton Conley points out that vote counting is inherently inaccurate:
"The rub in these cases is that we could count and recount, we could=20
examine every ballot four times over and we'd get -- you guessed it --=20
four different results. That's the nature of large numbers -- there is=20
inherent measurement error. We'd like to think that there is a "true"=20
answer out there, even if that answer is decided by a single vote. We so=20
desire the certainty of thinking that there is an objective truth in=20
elections and that a fair process will reveal it.
"But even in an absolutely clean recount, there is not always a sure=20
answer. Ever count out a large jar of pennies? And then do it again? And=20
then have a friend do it? Do you always converge on a single number? Or=20
do you usually just average the various results you come to? If you are=20
like me, you probably settle on an average. The underlying notion is=20
that each election, like those recounts of the penny jar, is more like a=20
poll of some underlying voting population."
He's right, but it's more complicated than that.
There are two basic types of voting errors: random errors and systemic=20
errors. Random errors are just that, random. Votes intended for A that=20
mistakenly go to B are just as likely as votes intended for B that=20
mistakenly go to A. This is why, traditionally, recounts in close=20
elections are unlikely to change things. The recount will find the few=20
percent of the errors in each direction, and they'll cancel each other=20
out. But in a very close election, a careful recount will yield a more=20
accurate -- but almost certainly not perfectly accurate -- result.
Systemic errors are more important, because they will cause votes=20
intended for A to go to B at a different rate than the reverse. Those=20
can make a dramatic difference in an election, because they can easily=20
shift thousands of votes from A to B without any counterbalancing shift=20
from B to A. These errors can either be a particular problem in the=20
system -- a badly designed ballot, for example -- or a random error that=20
only occurs in precincts where A has more supporters than B.
Here's where the problems of electronic voting machines become critical:=20
they're more likely to be systemic problems. Vote flipping, for=20
example, seems to generally affect one candidate more than another.=20
Even individual machine failures are going to affect supporters of one=20
candidate more than another, depending on where the particular machine=20
is. And if there are no paper ballots to fall back on, no recount can=20
undo these problems.
Conley proposes to nullify any election where the margin of victory is=20
less than 1%, and have everyone vote again. I agree, but I think his=20
margin is too large. In the Virginia Senate race, Allen was right not=20
to demand a recount. Even though his 7,800-vote loss was only 0.33%, in=20
the absence of systemic flaws it is unlikely that a recount would change=20
things. I think an automatic revote if the margin of victory is less=20
than 0.1% makes more sense.
Conley again:
"Yes, it costs more to run an election twice, but keep in mind that many=20
places already use runoffs when the leading candidate fails to cross a=20
particular threshold. If we are willing to go through all that trouble,=20
why not do the same for certainty in an election that teeters on a=20
razor's edge? One counter-argument is that such a plan merely shifts the=20
realm of debate and uncertainty to a new threshold -- the 99 percent=20
threshold. However, candidates who lose by the margin of error have a=20
lot less rhetorical power to argue for redress than those for whom an=20
actual majority is only a few votes away.
"It may make us existentially uncomfortable to admit that random chance=20
and sampling error play a role in our governance decisions. But in=20
reality, by requiring a margin of victory greater than one, seemingly=20
arbitrary vote, we would build in a buffer to democracy, one that offers=20
us a more bedrock sense of security that the 'winner' really did win."
This is a good idea, but it doesn't address the systemic problems with=20
voting. If there are systemic problems, there should be another election=20
day limited to only those precincts that had the problem and only those=20
people who can prove they voted -- or tried to vote and failed -- during=20
the first election day. (Although I could be persuaded that another=20
re-voting protocol would make more sense.)
But most importantly, we need better voting machines and better voting=20
procedures.
http://www.nytimes.com/2006/11/06/opinion/06conley.html
Vote flipping:
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic=
&articleId=3D9004858&source=3DNLT_SEC&nlid=3D38=20
or http://tinyurl.com/yfdhk6
** *** ***** ******* *********** *************
The Need for Professional Election Officials
In the U.S., elections are run by an army of hundreds of thousands of=20
volunteers. These are both Republicans and Democrats, and the idea is=20
that the one group watches the other: security by competing interests.=20
But at the top are state-elected or -appointed officials, and many=20
election shenanigans in the past several years have been perpetrated by=20
them.
In yet another "New York Times" op-ed, Loyola Law School professor=20
Richard Hansen argues" for professional, non-partisan election=20
officials: "The United States should join the rest of the world's=20
advanced democracies and put nonpartisan professionals in charge. We=20
need officials whose ultimate allegiance is to the fairness, integrity=20
and professionalism of the election process, not to helping one party or=20
the other gain political advantage. We don't need disputes like the=20
current one in Florida being resolved by party hacks."
And: "To improve the chances that states will choose an independent and=20
competent chief elections officer, states should enact laws making that=20
officer a long-term gubernatorial appointee who takes office only upon=20
confirmation by a 75 percent vote of the legislature -- a supermajority=20
requirement that would ensure that a candidate has true bipartisan=20
support. Nonpartisanship in election administration is no dream. It is=20
how Canada and Australia run their national elections."
To me, this is easier said than done. Where are these hundreds of=20
thousands of disinterested election officials going to come from? And=20
how do we ensure that they're disinterested and fair, and not just=20
partisans in disguise? I actually like security by competing interests.
But I do like his idea of a supermajority-confirmed chief elections=20
officer for each state. And at least he's starting the debate about=20
better election procedures in the U.S.
http://www.nytimes.com/2006/11/11/opinion/11hasen.html
** *** ***** ******* *********** *************
Perceived Risk vs. Actual Risk
I've written repeatedly about the difference between perceived and=20
actual risk, and how it explains many seemingly perverse security=20
trade-offs. Here's a "Los Angeles Times" op-ed that does the same. The=20
author is Daniel Gilbert, psychology professor at Harvard. (I just=20
recently finished his book "Stumbling on Happiness," which is not a=20
self-help book but instead about how the brain works. Strongly=20
recommended.)
The op-ed is about the public's reaction to the risks of global warming=20
and terrorism, but the points he makes are much more general. He gives=20
four reasons why some risks are perceived to be more or less serious=20
than they actually are:
1. We over-react to intentional actions, and under-react to accidents,=20
abstract events, and natural phenomena. "That's why we worry more about=20
anthrax (with an annual death toll of roughly zero) than influenza (with=20
an annual death toll of a quarter-million to a half-million people).=20
Influenza is a natural accident, anthrax is an intentional action, and=20
the smallest action captures our attention in a way that the largest=20
accident doesn't. If two airplanes had been hit by lightning and crashed=20
into a New York skyscraper, few of us would be able to name the date on=20
which it happened."
2. We over-react to things that offend our morals. "When people feel=20
insulted or disgusted, they generally do something about it, such as=20
whacking each other over the head, or voting. Moral emotions are the=20
brain's call to action."
He doesn't say it, but it's reasonable to assume that we under-react to=20
things that don't.
3. We over-react to immediate threats and under-react to long-term=20
threats. "The brain is a beautifully engineered get-out-of-the-way=20
machine that constantly scans the environment for things out of whose=20
way it should right now get. That's what brains did for several hundred=20
million years -- and then, just a few million years ago, the mammalian=20
brain learned a new trick: to predict the timing and location of dangers=20
before they actually happened. Our ability to duck that which is not=20
yet coming is one of the brain's most stunning innovations, and we=20
wouldn't have dental floss or 401(k) plans without it. But this=20
innovation is in the early stages of development. The application that=20
allows us to respond to visible baseballs is ancient and reliable, but=20
the add-on utility that allows us to respond to threats that loom in an=20
unseen future is still in beta testing."
4. We under-react to changes that occur slowly and over time. "The=20
human brain is exquisitely sensitive to changes in light, sound,=20
temperature, pressure, size, weight and just about everything else. But=20
if the rate of change is slow enough, the change will go undetected. If=20
the low hum of a refrigerator were to increase in pitch over the course=20
of several weeks, the appliance could be singing soprano by the end of=20
the month and no one would be the wiser."
It's interesting to compare this to what I wrote in "Beyond Fear" (pages=20
26-27) about perceived vs. actual risk:
" * People exaggerate spectacular but rare risks and downplay common=20
risks. They worry more about earthquakes than they do about slipping on=20
the bathroom floor, even though the latter kills far more people than=20
the former. Similarly, terrorism causes far more anxiety than common=20
street crime, even though the latter claims many more lives. Many people=20
believe that their children are at risk of being given poisoned candy by=20
strangers at Halloween, even though there has been no documented case of=20
this ever happening.
" *People have trouble estimating risks for anything not exactly like=20
their normal situation. Americans worry more about the risk of mugging=20
in a foreign city, no matter how much safer it might be than where they=20
live back home. Europeans routinely perceive the U.S. as being full of=20
guns. Men regularly underestimate how risky a situation might be for an=20
unaccompanied woman. The risks of computer crime are generally believed=20
to be greater than they are, because computers are relatively new and=20
the risks are unfamiliar. Middle-class Americans can be particularly=20
naive and complacent; their lives are incredibly secure most of the=20
time, so their instincts about the risks of many situations have been=20
dulled.
" * Personified risks are perceived to be greater than anonymous risks.=20
Joseph Stalin said, 'A single death is a tragedy, a million deaths is a=20
statistic.' He was right; large numbers have a way of blending into each=20
other. The final death toll from 9/11 was less than half of the initial=20
estimates, but that didn't make people feel less at risk. People gloss=20
over statistics of automobile deaths, but when the press writes page=20
after page about nine people trapped in a mine -- complete with=20
human-interest stories about their lives and families -- suddenly=20
everyone starts paying attention to the dangers with which miners have=20
contended for centuries. Osama bin Laden represents the face of Al=20
Qaeda, and has served as the personification of the terrorist threat.=20
Even if he were dead, it would serve the interests of some politicians=20
to keep him "alive" for his effect on public opinion.
" * People underestimate risks they willingly take and overestimate=20
risks in situations they can't control. When people voluntarily take a=20
risk, they tend to underestimate it. When they have no choice but to=20
take the risk, they tend to overestimate it. Terrorists are scary=20
because they attack arbitrarily, and from nowhere. Commercial airplanes=20
are perceived as riskier than automobiles, because the controls are in=20
someone else's hands -- even though they're much safer per passenger=20
mile. Similarly, people overestimate even more those risks that they=20
can't control but think they, or someone, should. People worry about=20
airplane crashes not because we can't stop them, but because we think as=20
a society we should be capable of stopping them (even if that is not=20
really the case). While we can't really prevent criminals like the two=20
snipers who terrorized the Washington, DC, area in the fall of 2002 from=20
killing, most people think we should be able to.
"Last, people overestimate risks that are being talked about and remain=20
an object of public scrutiny. News, by definition, is about anomalies.=20
Endless numbers of automobile crashes hardly make news like one airplane=20
crash does. The West Nile virus outbreak in 2002 killed very few people,=20
but it worried many more because it was in the news day after day. AIDS=20
kills about 3 million people per year worldwide -- about three times as=20
many people each day as died in the terrorist attacks of 9/11. If a=20
lunatic goes back to the office after being fired and kills his boss and=20
two coworkers, it's national news for days. If the same lunatic shoots=20
his ex-wife and two kids instead, it's local news...maybe not even the=20
lead story."
http://www.latimes.com/news/opinion/sunday/commentary/la-op-gilbert2jul02=
,0,4254536.story=20
or http://tinyurl.com/ydw3up
** *** ***** ******* *********** *************
Crypto-Gram Reprints
The Security of RFID Passports:
http://www.schneier.com/crypto-gram-0511.html#1
Liabilities and Software Vulnerabilities:
http://www.schneier.com/crypto-gram-0511.html#2
The Zotob Worm:
http://www.schneier.com/crypto-gram-0511.html#12
Why Election Technology is Hard:
http://www.schneier.com/crypto-gram-0411.html#1
Electronic Voting Machines:
http://www.schneier.com/crypto-gram-0411.html#2
The Security of Checks and Balances
http://www.schneier.com/crypto-gram-0411.html#10
Security Information Management Systems (SIMS):
http://www.schneier.com/crypto-gram-0411.html#12
Technology and Counterterrorism:
http://www.schneier.com/crypto-gram-0411.html#13
Airplane Hackers:
http://www.schneier.com/crypto-gram-0311.html#1
The Trojan Defense
http://www.schneier.com/crypto-gram-0311.html#8
Full Disclosure:
http://www.schneier.com/crypto-gram-0111.html#1
Why Digital Signatures are Not Signatures
http://www.schneier.com/crypto-gram-0011.html#1
Programming Satan's Computer: Why Computers Are Insecure
http://www.schneier.com/crypto-gram-9911.html#WhyComputersareInsecure or=20
http://tinyurl.com/7ldrl
Elliptic Curve Public-Key Cryptography
http://www.schneier.com/crypto-gram-9911.html#EllipticCurvePublic-KeyCryp=
tography=20
or http://tinyurl.com/a2low
The Future of Fraud: Three reasons why electronic commerce is different
http://www.schneier.com/crypto-gram-9811.html#commerce
Software Copy Protection: Why copy protection does not work
http://www.schneier.com/crypto-gram-9811.html#copy
Crypto-Gram is currently in its ninth year of publication. Back issues=20
cover a variety of security-related topics, and can all be found on=20
<http://www.schneier.com/crypto-gram-back.html>. These are a selection=20
of articles that appeared in this calendar month in other years.
** *** ***** ******* *********** *************
Total Information Awareness Is Back
Remember Total Information Awareness (TIA), the massive database on=20
everyone that was supposed to find terrorists? The public found it so=20
abhorrent, and objected so forcefully, that Congress killed funding for=20
the program in September 2003.
None of us thought that meant the end of TIA, only that it would turn=20
into a classified program and be renamed. Well, the program is now=20
called Tangram, and it is classified.
The "National Journal" writes:
"The government's top intelligence agency is building a computerized=20
system to search very large stores of information for patterns of=20
activity that look like terrorist planning. The system, which is run by=20
the Office of the Director of National Intelligence, is in the early=20
research phases and is being tested, in part, with government=20
intelligence that may contain information on U.S. citizens and other=20
people inside the country.
"It encompasses existing profiling and detection systems, including=20
those that create 'suspicion scores' for suspected terrorists by=20
analyzing very large databases of government intelligence, as well as=20
records of individuals' private communications, financial transactions,=20
and other everyday activities."
The information about Tangram comes from a government document looking=20
for contractors to help design and build the system.
DefenseTech writes: "The document, which is a description of the=20
Tangram program for potential contractors, describes other, existing=20
profiling and detection systems that haven't moved beyond so-called=20
'guilt-by-association models,' which link suspected terrorists to=20
potential associates, but apparently don't tell analysts much about why=20
those links are significant. Tangram wants to improve upon these=20
methods, as well as investigate the effectiveness of other detection=20
links such as 'collective inferencing,' which attempt to create=20
suspicion scores of entire networks of people simultaneously."
Data mining for terrorists has always been a dumb idea. And the=20
existence of Tangram illustrates the problem with Congress trying to=20
stop a program by killing its funding; it just comes back under a=20
different name.
http://nationaljournal.com/about/njweekly/stories/2006/1020nj3.htm
http://www.fbo.gov/spg/USAF/AFMC/AFRLRRS/Reference-Number-BAA-06-04-IFKA/=
SynopsisP.html=20
or http://tinyurl.com/y5sg9l
http://www.defensetech.org/archives/002875.html
My previous writings on data mining:
http://www.schneier.com/blog/archives/2006/03/data_mining_for.html
http://www.schneier.com/blog/archives/2006/05/the_problems_wi.html
** *** ***** ******* *********** *************
Forge Your Own Boarding Pass
Last week Christopher Soghoian created a Fake Boarding Pass Generator=20
website, allowing anyone to create a fake Northwest Airlines boarding=20
pass: any name, airport, date, flight. This action got him visited by=20
the FBI, who later came back, smashed open his front door, and seized=20
his computers and other belongings. It resulted in calls for his arrest=20
-- the most visible by Rep. Edward Markey (D-Massachusetts) -- who has=20
since recanted. And it's gotten him more publicity than he ever dreamed o=
f.
All for demonstrating a known and obvious vulnerability in airport=20
security involving boarding passes and IDs.
This vulnerability is nothing new. There was an article on CSOonline=20
from February 2006. There was an article on Slate from February 2005.=20
Sen. Chuck Schumer spoke about it in 2005 as well. I wrote about it in=20
the August 2003 issue of Crypto-Gram. It's possible I was the first=20
person to publish it, but I certainly wasn't the first person to think=20
of it.
It's kind of obvious, really. If you can make a fake boarding pass, you=20
can get through airport security with it. Big deal; we know.
You can also use a fake boarding pass to fly on someone else's ticket.=20
The trick is to have two boarding passes: one legitimate, in the name=20
the reservation is under, and another phony one that matches the name on=20
your photo ID. Use the fake boarding pass in your name to get through=20
airport security, and the real ticket in someone else's name to board=20
the plane.
This means that a terrorist on the no-fly list can get on a plane: He=20
buys a ticket in someone else's name, perhaps using a stolen credit=20
card, and uses his own photo ID and a fake ticket to get through airport=20
security. Since the ticket is in an innocent's name, it won't raise a=20
flag on the no-fly list.
You can also use a fake boarding pass instead of your real one if you=20
have the "SSSS" mark and want to avoid secondary screening, or if you=20
don't have a ticket but want to get into the gate area.
Historically, forging a boarding pass was difficult. It required special=20
paper and equipment. But since Alaska Airlines started the trend in=20
1999, most airlines now allow you to print your boarding pass using your=20
home computer and bring it with you to the airport. This program was=20
temporarily suspended after 9/11, but was quickly brought back because=20
of pressure from the airlines. People who print the boarding passes at=20
home can go directly to airport security, and that means fewer airline=20
agents are required.
Airline websites generate boarding passes as graphics files, which means=20
anyone with a little bit of skill can modify them in a program like=20
Photoshop. All Soghoian's website did was automate the process with a=20
single airline's boarding passes.
Soghoian claims that he wanted to demonstrate the vulnerability. You=20
could argue that he went about it in a stupid way, but I don't think=20
what he did is substantively worse than what I wrote in 2003. Or what=20
Schumer described in 2005. Why is it that the person who demonstrates=20
the vulnerability is vilified while the person who describes it is=20
ignored? Or, even worse, the organization that causes it is ignored? Why=20
are we shooting the messenger instead of discussing the problem?
As I wrote in 2005: "The vulnerability is obvious, but the general=20
concepts are subtle. There are three things to authenticate: the=20
identity of the traveler, the boarding pass and the computer record.=20
Think of them as three points on the triangle. Under the current system,=20
the boarding pass is compared to the traveler's identity document, and=20
then the boarding pass is compared with the computer record. But because=20
the identity document is never compared with the computer record -- the=20
third leg of the triangle -- it's possible to create two different=20
boarding passes and have no one notice. That's why the attack works."
The way to fix it is equally obvious: Verify the accuracy of the=20
boarding passes at the security checkpoints. If passengers had to scan=20
their boarding passes as they went through screening, the computer could=20
verify that the boarding pass already matched to the photo ID also=20
matched the data in the computer. Close the authentication triangle and=20
the vulnerability disappears.
But before we start spending time and money and Transportation Security=20
Administration agents, let's be honest with ourselves: The photo ID=20
requirement is no more than security theater. Its only security purpose=20
is to check names against the no-fly list, which would still be a joke=20
even if it weren't so easy to circumvent. Identification is not a useful=20
security measure here.
Interestingly enough, while the photo ID requirement is presented as an=20
antiterrorism security measure, it is really an airline-business=20
security measure. It was first implemented after the explosion of TWA=20
Flight 800 over the Atlantic in 1996. The government originally thought=20
a terrorist bomb was responsible, but the explosion was later shown to=20
be an accident.
Unlike every other airplane security measure -- including reinforcing=20
cockpit doors, which could have prevented 9/11 -- the airlines didn't=20
resist this one, because it solved a business problem: the resale of=20
non-refundable tickets. Before the photo ID requirement, these tickets=20
were regularly advertised in classified pages: "Round trip, New York to=20
Los Angeles, 11/21-30, male, $100." Since the airlines never checked=20
IDs, anyone of the correct gender could use the ticket. Airlines hated=20
that, and tried repeatedly to shut that market down. In 1996, the=20
airlines were finally able to solve that problem and blame it on the FAA=20
and terrorism.
So business is why we have the photo ID requirement in the first place,=20
and business is why it's so easy to circumvent it. Instead of going=20
after someone who demonstrates an obvious flaw that is already public,=20
let's focus on the organizations that are actually responsible for this=20
security failure and have failed to do anything about it for all these=20
years. Where's the TSA's response to all this?
The problem is real, and the Department of Homeland Security and TSA=20
should either fix the security or scrap the system. What we've got now=20
is the worst security system of all: one that annoys everyone who is=20
innocent while failing to catch the guilty.
This is my 30th essay for Wired.com:
http://www.wired.com/news/columns/0,72045-0.html
News:
http://j0hn4d4m5.bravehost.com
http://slightparanoia.blogspot.com/2006/10/post-fbi-visit.html
http://slightparanoia.blogspot.com/2006/10/fbi-visit-2.html
http://blog.wired.com/27bstroke6/2006/10/congressman_ed_.html
http://markey.house.gov/index.php?option=3Dcontent&task=3Dview&id=3D2336&=
Itemid=3D125=20
or http://tinyurl.com/ymjkxa
http://blog.wired.com/27bstroke6/2006/10/boarding_pass_g.html
Older mentions of the vulnerability:
http://www.csoonline.com/read/020106/caveat021706.html
http://www.slate.com/id/2113157/fr/rss/
http://www.senate.gov/~schumer/SchumerWebsite/pressroom/press_releases/20=
05/PR4123.aviationsecurity021305.html=20
or http://tinyurl.com/yzoon6
http://www.schneier.com/crypto-gram-0308.html#6
No-fly list:
http://www.schneier.com/blog/archives/2005/12/30000_people_mi.html
http://www.schneier.com/blog/archives/2005/09/secure_flight_n_1.html
http://www.schneier.com/blog/archives/2006/10/nofly_list.html
http://www.schneier.com/blog/archives/2005/08/infants_on_the.html
** *** ***** ******* *********** *************
News
This article argues that most of the $44 billion spent in the U.S. on=20
bioterrorism defense has been wasted.
http://www.newscientist.com/channel/opinion/mg19225725.000
Targeted Trojan horses are the future of malware:
http://news.com.com/The+future+of+malware+Trojan+horses/2100-7349_3-61254=
53.html=20
or http://tinyurl.com/w8hx7
FixAVote.com: a good hoax.
http://www.fixavote.com/
http://www.infoworld.com/article/06/10/26/HNfixelections_1.html
Interview with a pickpocket expert:
http://www.kiplinger.com/personalfinance/magazine/archives/2006/11/mystor=
y.html=20
or http://tinyurl.com/y3n2ap
Swiss police considering using Trojans for VoIP tapping:
http://www.pcpro.co.uk/news/95394/swiss-look-to-trojan-code-for-voip-tapp=
ing.html=20
or http://tinyurl.com/ygq43m
Lousy home security installation. (Yes, it's an advertisement. But=20
there are still important security lessons in the blog post.)
http://providentsecurity.typepad.com/community_security_the_pr/2006/10/cr=
iminal_instal.html=20
or http://tinyurl.com/ygve7r
I don't think I've ever read anyone talking about class issues as they=20
relate to security before.
http://redtape.msnbc.com/2006/10/doublestandards.html
This interesting article in "The New York Times" illustrates that the=20
problem of agricultural safety and security mirrors the security issues=20
in computer networks, especially with the monoculture in operating=20
systems and network protocols.
http://www.nytimes.com/2006/10/15/magazine/15wwln_lede.html
http://www.schneier.com/blog/archives/2006/08/security_and_mo.html
Interesting speculation: "Warning Signs for Tomorrow."
http://www.aleph.se/andart/archives/2006/10/warning_signs_for_tomorrow.ht=
ml=20
or http://tinyurl.com/yylq69
Good essay on perceived vs. actual risk. The hook is Mayor Daley of=20
Chicago demanding a no-fly-zone over Chicago in the wake of the New York=20
City airplane crash.
http://www.aopa.org/whatsnew/newsitems/2006/061013enough.html
And, on the same topic, why it doesn't make sense to ban small aircraft=20
from cities as a terrorism defense.
http://www.salon.com/tech/col/smith/2006/10/20/askthepilot205/index.html=20
or http://tinyurl.com/yh7nz6
Blog entry URL:
http://www.schneier.com/blog/archives/2006/10/perceived_risk.html
Doonesbury on terrorism and fear:
http://www.doonesbury.com/strip/dailydose/index.html?uc_full_date=3D20061=
015=20
or http://tinyurl.com/yffbq4
http://www.doonesbury.com/strip/dailydose/index.html?uc_full_date=3D20061=
016=20
or http://tinyurl.com/ylwj4j
http://www.doonesbury.com/strip/dailydose/index.html?uc_full_date=3D20061=
017=20
or http://tinyurl.com/y76864
http://www.doonesbury.com/strip/dailydose/index.html?uc_full_date=3D20061=
018=20
or http://tinyurl.com/yfq9sp
http://www.doonesbury.com/strip/dailydose/index.html?uc_full_date=3D20061=
019=20
or http://tinyurl.com/ye2km5
http://www.doonesbury.com/strip/dailydose/index.html?uc_full_date=3D20061=
020=20
or http://tinyurl.com/yfbne8
http://www.doonesbury.com/strip/dailydose/index.html?uc_full_date=3D20061=
021=20
or http://tinyurl.com/yefhz7
Really interesting article about online hacker forums, especially the=20
politics that goes on in them.
http://www.usatoday.com/tech/news/computersecurity/infotheft/2006-10-11-c=
ybercrime-hacker-forums_x.htm=20
or http://tinyurl.com/y8jqbv
Real-world social engineering crime:
http://www.theregister.co.uk/2006/10/20/easynet_brick_lane_robbery/
Here's another social-engineering story (link in Turkish). The police=20
receive an anonymous emergency call from someone claiming to have=20
planted an explosive in the Haydarpasa Numune Hospital. They evacuate=20
the hospital (100 patients plus doctors, staff, visitors, etc.) and=20
search the place for two hours. They find nothing. When patients and=20
visitors return, they realize that their valuables were stolen.
http://www.milliyet.com.tr/2006/10/25/yasam/ayas.html
Paramedic stopped at airport security for nitroglycerine residue. (At=20
least we know those chemical-residue detectors are working.)
http://dochazmat.livejournal.com/31044.html
If you have control of a network of computers -- by infecting them with=20
some sort of malware -- the hard part is controlling that network.=20
Traditionally, these computers (called zombies) are controlled via IRC.=20
But IRC can be detected and blocked, so the hackers have adapted:
http://news.com.com/Zombies+try+to+blend+in+with+the+crowd/2100-7349_3-61=
27304.html=20
or http://tinyurl.com/swhbg
The trick here is to not let the computer's legitimate owner know that=20
someone else is controlling it. It's an arms race between attacker and=20
defender.
Tamper-evident seals:
http://www.schneier.com/blog/archives/2006/10/tamperevident_s.html
http://pearl1.lanl.gov/seals/default.htm
Microsoft's Privacy Guidelines for Developing Software and Services.=20
It's actually pretty good:
http://www.microsoft.com/downloads/details.aspx?FamilyID=3Dc48cf80f-6e87-=
48f5-83ec-a18d1ad2fc1f&displaylang=3Den=20
or http://tinyurl.com/y45oge
Canadian "Guidelines for Identification and Authentication," released by=20
the Canadian Privacy Commissioner, is a good document discussing both=20
privacy risks and security threats.
http://www.privcom.gc.ca/information/guide/auth_061013_e.asp
And here's a longer document published in 2004 by Industry Canada:=20
"Principles for Electronic Authentication."
http://e-com.ic.gc.ca/epic/internet/inecic-ceac.nsf/en/h_gv00240e.html
Blog entry URL:
http://www.schneier.com/blog/archives/2006/10/canadian_guidel.html
Surveillance as performance art:
http://www.worldchanging.com/archives/005105.html
This is extreme, but the level of surveillance is likely to be the norm.=20
It won't be on a public website available to everyone, but it will be=20
available to governments and corporations.
"Mother Jones" article on Google and privacy:
http://www.motherjones.com/news/feature/2006/11/google.html
They may be great at keeping you from taking your bottle of water onto=20
the plane, but when it comes to catching actual bombs and guns they not=20
very good: "Screeners at Newark Liberty International Airport, one of=20
the starting points for the Sept. 11 hijackers, failed 20 of 22 security=20
tests conducted by undercover U.S. agents last week, missing concealed=20
bombs and guns at checkpoints throughout the major air hub's three=20
terminals, according to federal security officials."
http://www.rawstory.com/showoutarticle.php?src=3Dhttp%3A%2F%2Fseattletime=
s.nwsource.com%2Fhtml%2Fnationworld%2F2003327485_screeners28.html=20
or http://tinyurl.com/yfpogf
As I've written before, this is actually a very hard problem to solve:
http://www.schneier.com/blog/archives/2006/03/airport_passeng.html
Remember this truism: We can't keep weapons out of prisons. We can't=20
possibly keep them out of airports.
The Data Privacy and Integrity Advisory Committee of the Department of=20
Homeland Security recommended against putting RFID chips in identity=20
cards. It's only a draft report, but what it says is so controversial=20
that a vote on the final report is being delayed.
http://www.dhs.gov/xlibrary/assets/privacy/privacy_advcom_rpt_rfid_draft.=
pdf=20
or http://tinyurl.com/y3k2w6
http://www.wired.com/news/technology/1,72019-0.html
Online ID theft hyped, to on one's surprise:
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic=
&articleId=3D9004429=20
or http://tinyurl.com/y8mvoz
CEO arrested for stealing the identities of his employees:
http://www.varbusiness.com/sections/news/breakingnews.jhtml?articleId=3D1=
93500991=20
or http://tinyurl.com/y44w9u
This guy wants to give students bullet-proof textbooks to help in the=20
case of school shootings. You can't make this stuff up.
http://www.wbir.com/news/national/story.aspx?storyid=3D39017
New U.S. Customs database on trucks and travelers. It's yet another=20
massive government surveillance program:
http://arstechnica.com/news.ars/post/20061103-8143.html
http://edocket.access.gpo.gov/2006/06-9026.htm
http://notabob.blogspot.com/2006/11/in-crosshairs_03.html
http://www.eff.org/deeplinks/archives/004980.php
http://blog.wired.com/27bstroke6/2006/11/homeland_securi.html
http://www.washingtonpost.com/wp-dyn/content/article/2006/11/02/AR2006110=
201810.html=20
or http://tinyurl.com/yl92on
Classical crypto with lasers. I simply don't have the physics=20
background to evaluate it:
http://www.physorg.com/news80478394.html
http://authors.library.caltech.edu/5655/
On August 18 of last year, the Zotob worm badly infected computers at=20
the Department of Homeland Security, particularly the 1,300 workstations=20
running the US-VISIT application at border crossings. Wired News filed=20
a Freedom of Information Act request for details, which was denied. So=20
they sued. Eventually the government was forced to cough up the=20
documents. The details say nothing about the technical details of the=20
computer systems, and only point to the incompetence of the DHS in=20
handling the incident.
http://www.wired.com/news/technology/0,72051-0.html
Seagate has announced a product called DriveTrust, which provides=20
hardware-based encryption on the drive itself. The technology is=20
proprietary, but they use standard algorithms: AES and triple-DES, RSA,=20
and SHA-1. Details on the key management are sketchy, but the system=20
requires a pre-boot password and/or combination of biometrics to access=20
the disk. And Seagate is working on some sort of enterprise-wide key=20
management system to make it easier to deploy the technology=20
company-wide. The first target market is laptop computers. No computer=20
manufacturer has announced support for DriveTrust yet.
http://www.seagate.com/cda/newsinfo/newsroom/releases/article/0,1121,3347=
,00.html=20
or http://tinyurl.com/y7tvvd
http://www.pcworld.com/article/id,127701/article.html
http://www.theglobeandmail.com/servlet/story/RTGAM.20061030.wharddrive102=
9/BNStory/Technology/?page=3Drss&id=3DRTGAM.20061030.wharddrive1029=20
or http://tinyurl.com/y5twtg
http://news.com.com/Seagate+bakes+security+into+hard-disk+drive/2100-1029=
_3-6130824.html=20
or http://tinyurl.com/y4kzhk
http://www.cio.com/blog_view.html?CID=3D26159
http://www.sfgate.com/cgi-bin/article.cgi?f=3D/c/a/2006/10/30/BUGU2M1ETT1=
.DTL=20
or http://tinyurl.com/yjvac7
It's easy to skim personal information off an RFID credit card.
http://www.nytimes.com/2006/10/23/business/23card.html
http://www.theregister.co.uk/2006/10/24/rfid_credit_card_hack/
http://www.rfidjournal.com/article/articleview/2749/1/1/
Why management doesn't get IT security:
http://www.schneier.com/blog/archives/2006/11/why_management.html
"Keyboards and Covert Channels." Interesting research.
http://www.crypto.com/papers/jbug-Usenix06-final.pdf
"Deconstructing Information Warfare"
http://www.information-retrieval.info/PIW/deconstructing/Taipale-IW-10300=
6.pdf=20
or http://tinyurl.com/y2x9vt
The Future of Identity in the Information Society (FIDIS) hates RFID=20
passports:
http://www.fidis.net/press-events/press-releases/budapest-declaration/=20
http://it.slashdot.org/it/06/11/09/1757202.shtml or=20
http://tinyurl.com/y4eht7
Good essay on data mining.
http://www.theregister.co.uk/2006/11/08/guilty_associations/
Cryptography comic: Alice, Bob, and Eve. (I get a mention, too.)
http://xkcd.com/c177.html
UK car rentals to require fingerprints. Not optional, required.
http://www.schneier.com/blog/archives/2006/11/uk_car_rentals.html
http://news.bbc.co.uk/1/hi/magazine/6129084.stm
A classified Wikipedia for the U.S. intelligence services:
http://news.yahoo.com/s/nm/20061031/wr_nm/internet_intelligence_dc_1
** *** ***** ******* *********** *************
The Death of Ephemeral Conversation
The political firestorm over former U.S. Rep. Mark Foley's salacious=20
instant messages hides another issue, one about privacy. We are rapidly=20
turning into a society where our intimate conversations can be saved and=20
made public later. This represents an enormous loss of freedom and=20
liberty, and the only way to solve the problem is through legislation.
Everyday conversation used to be ephemeral. Whether face-to-face or by=20
phone, we could be reasonably sure that what we said disappeared as soon=20
as we said it. Of course, organized crime bosses worried about phone=20
taps and room bugs, but that was the exception. Privacy was the default=20
assumption.
This has changed. We now type our casual conversations. We chat in=20
e-mail, with instant messages on our computer and SMS messages on our=20
cell phones, and in comments on social networking Web sites like=20
Friendster, LiveJournal, and MySpace. These conversations -- with=20
friends, lovers, colleagues, fellow employees -- are not ephemeral; they=20
leave their own electronic trails.
We know this intellectually, but we haven't truly internalized it. We=20
type on, engrossed in conversation, forgetting that we're being recorded.
Foley's instant messages were saved by the young men he talked to, but=20
they could have also been saved by the instant messaging service. There=20
are tools that allow both businesses and government agencies to monitor=20
and log IM conversations. E-mail can be saved by your ISP or by the IT=20
department in your corporation. Gmail, for example, saves everything,=20
even if you delete it.
And these conversations can come back to haunt people -- in criminal=20
prosecutions, divorce proceedings or simply as embarrassing disclosures.=20
During the 1998 Microsoft anti-trust trial, the prosecution pored over=20
masses of e-mail, looking for a smoking gun. Of course they found=20
things; everyone says things in conversation that, taken out of context,=20
can prove anything.
The moral is clear: If you type it and send it, prepare to explain it in=20
public later.
And voice is no longer a refuge. Face-to-face conversations are still=20
safe, but we know that the National Security Agency is monitoring=20
everyone's international phone calls. (They said nothing about SMS=20
messages, but one can assume they were monitoring those too.) Routine=20
recording of phone conversations is still rare -- certainly the NSA has=20
the capability -- but will become more common as telephone calls=20
continue migrating to the IP network.
If you find this disturbing, you should. Fewer conversations are=20
ephemeral, and we're losing control over the data. We trust our ISPs,=20
employers and cell phone companies with our privacy, but again and again=20
they've proven they can't be trusted. Identity thieves routinely gain=20
access to these repositories of our information. Paris Hilton and other=20
celebrities have been the victims of hackers breaking into their cell=20
phone providers' networks. Google reads our Gmail and inserts=20
context-dependent ads.
Even worse, normal constitutional protections don't apply to much of=20
this. The police need a court-issued warrant to search our papers or=20
eavesdrop on our communications, but can simply issue a subpoena -- or=20
ask nicely or threateningly -- for data of ours that is held by a third=20
party, including stored copies of our communications.
The Justice Department wants to make this problem even worse, by forcing=20
ISPs and others to save our communications -- just in case we're someday=20
the target of an investigation. This is not only bad privacy and=20
security, it's a blow to our liberty as well. A world without ephemeral=20
conversation is a world without freedom.
We can't turn back technology; electronic communications are here to=20
stay. But as technology makes our conversations less ephemeral, we need=20
laws to step in and safeguard our privacy. We need a comprehensive data=20
privacy law, protecting our data and communications regardless of where=20
it is stored or how it is processed. We need laws forcing companies to=20
keep it private and to delete it as soon as it is no longer needed.
And we need to remember, whenever we type and send, we're being watched.
Foley is an anomaly. Most of us do not send instant messages in order to=20
solicit sex with minors. Law enforcement might have a legitimate need to=20
access Foley's IMs, e-mails and cell phone calling logs, but that's why=20
there are warrants supported by probable cause--they help ensure that=20
investigations are properly focused on suspected pedophiles, terrorists=20
and other criminals. We saw this in the recent UK terrorist arrests;=20
focused investigations on suspected terrorists foiled the plot, not=20
broad surveillance of everyone without probable cause.
Without legal privacy protections, the world becomes one giant airport=20
security area, where the slightest joke -- or comment made years before=20
-- lands you in hot water. The world becomes one giant market-research=20
study, where we are all life-long subjects. The world becomes a police=20
state, where we all are assumed to be Foleys and terrorists in the eyes=20
of the government.
This essay originally appeared on Forbes.com:
http://www.forbes.com/security/2006/10/18/nsa-im-foley-tech-security-cx_b=
s_1018security.html=20
or http://tinyurl.com/ymmnee
** *** ***** ******* *********** *************
Airline Passenger Profiling for Profit
I have previously written and spoken about the privacy threats that come=20
from the confluence of government and corporate interests. It's not the=20
deliberate police-state privacy invasions from governments that worry=20
me, but the normal-business privacy invasions by corporations -- and how=20
corporate privacy invasions pave the way for government privacy=20
invasions and vice versa.
The U.S. government's airline passenger profiling system was called=20
Secure Flight, and I've written about it extensively. At one point, the=20
system was going to perform automatic background checks on all=20
passengers based on both government and commercial databases -- credit=20
card databases, phone records, whatever -- and assign everyone a "risk=20
score" based on the data. Those with a higher risk score would be=20
searched more thoroughly than those with a lower risk score. It's a=20
complete waste of time, and a huge invasion of privacy, and the last=20
time I paid attention it had been scrapped.
But the very same system that is useless at picking terrorists out of=20
passenger lists is probably very good at identifying consumers. So what=20
the government rightly decided not to do, the start-up corporation=20
Jetera is doing instead:
"Jetera would start with an airline's information on individual=20
passengers on board a given flight, drawing the name, address, credit=20
card number and loyalty club status from reservations data. Through a=20
process, for which it seeks a patent, the company would match the=20
passenger's identification data with the mountains of information about=20
him or her available at one of the mammoth credit bureaus, which=20
maintain separately managed marketing as well as credit information.=20
Jetera would tap into the marketing side, showing consumer demographics,=20
purchases, interests, attitudes and the like.
"Jetera's data manipulation would shape the entertainment made available=20
to each passenger during a flight. The passenger who subscribes to a=20
do-it-yourself magazine might be offered a video on woodworking. Catalog=20
purchase records would boost some offerings and downplay others. Sports=20
fans, known through their subscriptions, credit card ticket-buying or=20
booster club memberships, would get 'The Natural' instead of 'Pretty=20
Woman.'"
The article is dated August 21, 2006 and is subscriber-only. Most of it=20
talks about the revenue potential of the model, the funding the company=20
received, and the talks it has had with anonymous airlines. No airline=20
has signed up for the service yet, which would not only include=20
in-flight personalization but pre- and post-flight mailings and other=20
personalized services. Privacy is dealt with at the end of the article:
"Jetera sees two legal issues regarding privacy and resolves both in its=20
favor. Nothing Jetera intends to do would violate federal law or airline=20
privacy policies as expressed on their websites. In terms of customer=20
perceptions, Jetera doesn't intend to abuse anyone's privacy and will=20
have an 'opt-out' opportunity at the point where passengers make=20
inflight entertainment choices.
"If an airline wants an opt-out feature at some other point in the=20
process, Jetera will work to provide one, McChesney says. Privacy and=20
customer service will be an issue for each airline, and Jetera will=20
adapt specifically to each."
The U.S. government already collects data from the phone company, from=20
hotels and rental-car companies, and from airlines. How long before it=20
piggy backs onto this system?
The other side to this is in the news, too: commercial databases using=20
government data:
"Records once held only in paper form by law enforcement agencies,=20
courts and corrections departments are now routinely digitized and sold=20
in bulk to the private sector. Some commercial databases now contain=20
more than 100 million criminal records. They are updated only fitfully,=20
and expunged records now often turn up in criminal background checks=20
ordered by employers and landlords."
http://www.aviationnow.com/search/AvnowSearchResult.do?reference=3Dxml/aw=
st_xml/2006/08/21/AW_08_21_2006_P55-56-01.xml&query=3Djetera=20
or http://tinyurl.com/tt59x
http://www.nytimes.com/2006/10/17/us/17expunge.html
My previous writings:
http://www.schneier.com/blog/archives/2006/03/the_future_of_p.html
http://www.schneier.com/blog/archives/2005/09/secure_flight_n_1.html
** *** ***** ******* *********** *************
Counterpane News
BT Acquires Counterpane:
On October 25, British Telecom announced that it acquired Counterpane=20
Internet Security, Inc.
This is something I've been working on for about a year, and I'm=20
thrilled that it has finally come to pass.
http://www.btplc.com/News/Articles/Showarticle.cfm?ArticleID=3D386c1b2f-0=
860-4afc-8f4a-26a066c12d10=20
or http://tinyurl.com/yzmtn3
Newspapers:
http://today.reuters.com/news/articleinvesting.aspx?view=3DCN&storyID=3D2=
006-10-25T071554Z_01_L25202546_RTRIDST_0_TELECOMS-COUNTERPANE-BT-UPDATE-1=
.XML&rpc=3D66&type=3Dqcna=20
or http://tinyurl.com/y28vr3
http://news.bbc.co.uk/1/hi/business/6083818.stm
http://www.businessweek.com/ap/financialnews/D8KVRV6O1.htm or=20
http://tinyurl.com/ylmw5f
http://business.timesonline.co.uk/article/0,,13129-2422003,00.html
http://business.guardian.co.uk/story/0,,1930942,00.html
http://www.iht.com/articles/ap/2006/10/25/business/EU_FIN_COM_Britain_BT_=
Group.php=20
or http://tinyurl.com/vxhvp
http://www.mercurynews.com/mld/mercurynews/business/technology/15847133.h=
tm=20
or http://tinyurl.com/wba9a
http://www.smh.com.au/news/TECHNOLOGY/BT-buys-security-specialist-Counter=
pane-cofounded-by-cryptologistSchneier/2006/10/26/1161749214324.html=20
or http://tinyurl.com/y8632k
http://www.twincities.com/mld/twincities/15848925.htm
Trade and news media:
http://news.com.com/BT+snaps+up+Counterpane+Internet+Security/2100-1002_3=
-6129284.html=20
or http://tinyurl.com/y5hzeh
http://news.zdnet.com/2100-1009_22-6129284.html
http://www.redherring.com/Article.aspx?a=3D19374&hed=3DBT+Snags+Counterpa=
ne§or=3DIndustries&subsector=3DCommunications=20
or http://tinyurl.com/yxx6ej
http://www.scmagazine.com/uk/news/article/600346/bt-acquires-counterpane-=
security/=20
or http://tinyurl.com/v7rmh
http://www.itweek.co.uk/vnunet/news/2167238/bt-buys-security-outsourcer=20
or http://tinyurl.com/uq88x
http://www.networkworld.com/news/2006/102506-bt-buys.html
http://www.techworld.com/security/news/index.cfm?newsID=3D7188&pagtype=3D=
all=20
or http://tinyurl.com/y7dzzf
http://www.eetimes.com/news/latest/showArticle.jhtml?articleID=3D19340218=
8=20
or http://tinyurl.com/smvda
http://www.ovum.com/news/euronews.asp?id=3D5014
http://news.moneycentral.msn.com/provider/providerarticle.asp?feed=3DOBR&=
Date=3D20061025&ID=3D6133629=20
or http://tinyurl.com/y3lzaj
Foreign press:
http://www.theage.com.au/news/Technology/BT-buys-security-specialist-Coun=
terpane-cofounded-by-cryptologistSchneier/2006/10/26/1161749214324.html=20
or http://tinyurl.com/y36vt2
http://press-releases.techwhack.com/5016/counterpane-bt/
http://www.metimes.com/storyview.php?StoryID=3D20061025-074107-7311r
http://www.canada.com/topics/technology/news/gizmos/story.html?id=3Da177c=
27c-b5c6-4eb9-be30-a96cf83b8ed0&k=3D50643=20
or http://tinyurl.com/y4wal4
http://www.breakingnews.ie/2006/10/25/story282489.html
http://www.euro2day.gr/articlesfna/22917952/
http://www.net-security.org/secworld.php?id=3D4334
British tabloids:
http://www.thesun.co.uk/article/0,,11039-2006490511,00.html
http://www.mirror.co.uk/news/tm_headline=3Dbt-in-code-war-&method=3Dfull&=
objectid=3D17992435&siteid=3D94762-name_page.html=20
or http://tinyurl.com/y2aqxy
Best blog comment ever:
http://www.schneier.com/blog/archives/2006/10/bt_acquires_cou.html#c12182=
1=20
or http://tinyurl.com/ug2oo
Commentary from one of our investors:
http://whohastimeforthis.blogspot.com/2006/11/british-telecom-dials-up-da=
-vinci-code.html=20
or http://tinyurl.com/y6rdm3
Blog entry URL:
http://www.schneier.com/blog/archives/2006/10/bt_acquires_cou.html
** *** ***** ******* *********** *************
Architecture and Security
You've seen them: those large concrete blocks in front of skyscrapers,=20
monuments and government buildings, designed to protect against car and=20
truck bombs. They sprang up like weeds in the months after 9/11, but the=20
idea is much older. The prettier ones doubled as planters; the uglier=20
ones just stood there.
Form follows function. From medieval castles to modern airports,=20
security concerns have always influenced architecture. Castles appeared=20
during the reign of King Stephen of England because they were the best=20
way to defend the land and there wasn't a strong king to put any limits=20
on castle-building. But castle design changed over the centuries in=20
response to both innovations in warfare and politics, from=20
motte-and-bailey to concentric design in the late medieval period to=20
entirely decorative castles in the 19th century.
These changes were expensive. The problem is that architecture tends=20
toward permanence, while security threats change much faster. Something=20
that seemed a good idea when a building was designed might make little=20
sense a century -- or even a decade -- later. But by then it's hard to=20
undo those architectural decisions.
When Syracuse University built a new campus in the mid-1970s, the=20
student protests of the late 1960s were fresh on everybody's mind. So=20
the architects designed a college without the open greens of traditional=20
college campuses. It's now 30 years later, but Syracuse University is=20
stuck defending itself against an obsolete threat.
Similarly, hotel entries in Montreal were elevated above street level in=20
the 1970s, in response to security worries about Quebecois separatists.=20
Today the threat is gone, but those older hotels continue to be=20
maddeningly difficult to navigate.
Also in the 1970s, the Israeli consulate in New York built a unique=20
security system: a two-door vestibule that allowed guards to identify=20
visitors and control building access. Now this kind of entryway is=20
widespread, and buildings with it will remain unwelcoming long after the=20
threat is gone.
The same thing can be seen in cyberspace as well. In his book, "Code and=20
Other Laws of Cyberspace," Lawrence Lessig describes how decisions about=20
technological infrastructure -- the architecture of the internet --=20
become embedded and then impracticable to change. Whether it's=20
technologies to prevent file copying, limit anonymity, record our=20
digital habits for later investigation or reduce interoperability and=20
strengthen monopoly positions, once technologies based on these security=20
concerns become standard it will take decades to undo them.
It's dangerously shortsighted to make architectural decisions based on=20
the threat of the moment without regard to the long-term consequences of=20
those decisions.
Concrete building barriers are an exception: They're removable. They=20
started appearing in Washington, D.C., in 1983, after the truck bombing=20
of the Marines barracks in Beirut. After 9/11, they were a sort of=20
bizarre status symbol: They proved your building was important enough to=20
deserve protection. In New York City alone, more than 50 buildings were=20
protected in this fashion.
Today, they're slowly coming down. Studies have found they impede=20
traffic flow, turn into giant ashtrays and can pose a security risk by=20
becoming flying shrapnel if exploded.
We should be thankful they can be removed, and did not end up as=20
permanent aspects of our cities' architecture. We won't be so lucky with=20
some of the design decisions we're seeing about internet architecture.
This essay originally appeared in Wired.com.
http://www.wired.com/news/columns/0,71968-0.html
Concrete barriers coming down in New York:
http://www.nytimes.com/2006/10/07/nyregion/nyregionspecial3/07bollard.htm=
l=20
or http://tinyurl.com/y6v2xw
Activism-restricting architecture at the University of Texas:
http://www.utwatch.org/archives/polemicist/utarchitectureandactivism_may1=
990.html=20
or http://tinyurl.com/stby3
Commentary from the Architectures of Control in Design Blog.
http://architectures.danlockton.co.uk/?p=3D145
** *** ***** ******* *********** *************
The Doghouse: Skylark Utilities
I'll just quote this bit: "Files are encrypted in place using the=20
524,288 Bit cipher SCC, better know [sic] as the king of ciphers."
http://www.skylarkutilities.com/encode-it/home.html
For reference, here's my snake oil guide from 1999.
http://www.schneier.com/crypto-gram-9902.html#snakeoil
** *** ***** ******* *********** *************
Heathrow Tests Biometric ID
Heathrow airport is testing an iris scan biometric machine to identify=20
passengers at customs.
I've written previously about biometrics: when they work and when they=20
fail: "Biometrics are powerful and useful, but they are not keys. They=20
are useful in situations where there is a trusted path from the reader=20
to the verifier; in those cases all you need is a unique identifier.=20
They are not useful when you need the characteristics of a key: secrecy,=20
randomness, the ability to update or destroy. Biometrics are unique=20
identifiers, but they are not secrets."
The system under trial at Heathrow is a good use of biometrics. There's=20
a trusted path from the person through the reader to the verifier;=20
attempts to use fake eyeballs will be immediately obvious and=20
suspicious. The verifier is being asked to match a biometric with a=20
specific reference, and not to figure out who the person is from his or=20
her biometric. There's no need for secrecy or randomness; it's not=20
being used as a key. And it has the potential to really speed up=20
customs lines.
http://news.bbc.co.uk/1/hi/uk/1808187.stm
http://www.schneier.com/crypto-gram-9808.html#biometrics
** *** ***** ******* *********** *************
Please Stop My Car
Residents of Prescott Valley are being invited to register their car if=20
they don't drive in the middle of the night. Police will then stop=20
those cars if they are on the road at that time, under the assumption=20
that they're stolen:
"The Watch Your Car decal program is a voluntary program whereby vehicle=20
owners enroll their vehicles with the AATA. The vehicle is then entered=20
into a special database, developed and maintained by the AATA, which is=20
directly linked to the Motor Vehicle Division (MVD).
"Participants then display the Watch Your Car decals in the front and=20
rear windows of their vehicle. By displaying the decals, vehicle owners=20
convey to law enforcement officials that their vehicle is not usually in=20
use between the hours of 1:00 AM and 5:00 AM, when the majority of=20
thefts occur.
"If a police officer witnesses the vehicle in operation between these=20
hours, they have the authority to pull it over and question the driver.=20
With access to the MVD database, the officer will be able to determine=20
if the vehicle has been stolen, or not. The program also allows law=20
enforcement officials to notify the vehicle's owner immediately upon=20
determination that it is being illegally operated."
This program is entirely optional, but there's a serious externality.=20
If the police spend time chasing false alarms, they're not available for=20
other police business. If the town charged car owners a fine for each=20
false alarm, I would have no problems with this program. It doesn't=20
have to be a large fine, but it has to be enough to offset the cost to=20
the town. It's no different than police departments charging homeowners=20
for false burglar alarms, when the alarm systems are automatically=20
hooked into the police stations.
http://www.pvaz.net/Services/police/watchyourcar.htm
** *** ***** ******* *********** *************
Air Cargo Security
BBC is reported a "major" hole in air cargo security. Basically, cargo=20
is being flown on passenger planes without being screened. A would-be=20
terrorist could therefore blow up a passenger plane by shipping a bomb=20
via FedEx.
In general, cargo deserves much less security scrutiny than passengers.=20
Here's the reasoning:
Cargo planes are much less of a terrorist risk than passenger planes,=20
because terrorism is about innocents dying. Blowing up a planeload of=20
FedEx packages is annoying, but not nearly as terrorizing as blowing up=20
a planeload of tourists. Hence, the security around air cargo doesn't=20
have to be as strict.
Given that, if most air cargo flies around on cargo planes, then it's=20
okay for some small amount -- assuming it's random and assuming the=20
shipper doesn't know which packages beforehand -- of cargo to fly as=20
baggage on passenger planes. A would-be terrorist would be better off=20
taking his bomb and blowing up a bus than shipping it and hoping it=20
might possibly be put on a passenger plane.
At least, that's the theory. But theory and practice are different.
The British system involves "known shippers":
"Under a system called "known shipper" or "known consignor" companies=20
which have been security vetted by government appointed agents can send=20
parcels by air, which do not have to be subjected to any further=20
security checks.
"Unless a package from a known shipper arouses suspicion or is subject=20
to a random search it is taken on trust that its contents are safe."
But:
"Captain Gary Boettcher, president of the US Coalition Of Airline Pilots=20
Associations, says the 'known shipper' system 'is probably the weakest=20
part of the cargo security today.'
"'There are approx 1.5 million known shippers in the US. There are=20
thousands of freight forwarders. Anywhere down the line packages can be=20
intercepted at these organisations,' he said.
"'Even reliable respectable organisations, you really don't know who is=20
in the warehouse, who is tampering with packages, putting parcels=20
together.'"
This system has already been exploited by drug smugglers:
"Mr Adeyemi brought pounds of cocaine into Britain unchecked by air=20
cargo, transported from the US by the Federal Express courier company.=20
He did not have to pay the postage.
"This was made possible because he managed to illegally buy the=20
confidential Fed Ex account numbers of reputable and security cleared=20
companies from a former employee.
"An accomplice in the US was able to put the account numbers on drugs=20
parcels which, as they appeared to have been sent by known shippers,=20
arrived unchecked at Stansted Airport.
"When police later contacted the companies whose accounts and security=20
clearance had been so abused they discovered they had suspected nothing."
And it's not clear that a terrorist can't figure out which shipments are=20
likely to be put on passenger aircraft:
"However several large companies such as FedEx and UPS offer clients the=20
chance to follow the progress of their parcels online.
"This is a facility that Chris Yates, an expert on airline security for=20
Jane's Transport, says could be exploited by terrorists.
"'From these you can get a fair indication when that package is in the=20
air, if you are looking to get a package into New York from Heathrow at=20
a given time of day.'"
And BBC reports that 70% of cargo is shipped on passenger planes. That=20
seems like too high a number.
If we had infinite budget, of course we'd screen all air cargo. But we=20
don't, and it's a reasonable trade-off to ignore cargo planes and=20
concentrate on passenger planes. But there are some awfully big holes=20
in this system.
http://news.bbc.co.uk/2/hi/americas/6059742.stm
** *** ***** ******* *********** *************
Cheyenne Mountain Retired
Cheyenne Mountain was the United States' underground command post,=20
designed to survive a direct hit from a nuclear warhead. It's a Cold=20
War relic -- built in the 1960s -- and retiring the site is probably a=20
good idea. But this paragraph gives me pause:
"Keating said the new control room, in contrast, could be damaged if a=20
terrorist commandeered a jumbo jet and somehow knew exactly where to=20
crash it. But 'how unlikely is that? We think very,' Keating said."
I agree that this is an unlikely terrorist target, but still.
http://apnews.myway.com//article/20061016/D8KPU1C02.html
** *** ***** ******* *********** *************
Comments from Readers
There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and join=20
in.
http://www.schneier.com/blog
** *** ***** ******* *********** *************
CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise. You can=20
subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>. Back issues are also=20
available at that URL.
Comments on CRYPTO-GRAM should be sent to [email protected].=20
Permission to print comments is assumed unless otherwise stated.=20
Comments may be edited for length and clarity.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable. Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the=20
best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography," and an inventor of the Blowfish and Twofish algorithms.=20
He is founder and CTO of Counterpane Internet Security Inc., and is a=20
member of the Advisory Board of the Electronic Privacy Information=20
Center (EPIC). He is a frequent writer and lecturer on security topics.=20
See <http://www.schneier.com>.
Counterpane is the world's leading protector of networked information -=20
the inventor of outsourced security monitoring and the foremost=20
authority on effective mitigation of emerging IT threats. Counterpane=20
protects networks for Fortune 1000 companies and governments world-wide.=20
See <http://www.counterpane.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not=20
necessarily those of Counterpane Internet Security, Inc.
Copyright (c) 2006 by Bruce Schneier.