CRYPTO-GRAM, February 15, 2007

Bruce Schneier <[email protected]> Thu, 15 Feb 2007 01:31:22 -0600
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

               February 15, 2007

               by Bruce Schneier
                Founder and CTO
                 BT Counterpane
              [email protected]
             http://www.schneier.com
            http://www.counterpane.com


A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0702.html>.  These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>.  An RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
      In Praise of Security Theater
      Real-ID:  Costs and Benefits
      Crypto-Gram Reprints
      Debating Full Disclosure
      Sending Photos to 911 Operators
      "Clear" Registered Traveler Program
      News
      DRM in Windows Vista
      BT Counterpane News
      Psychology of Security
      A New Secure Hash Standard
      Comments from Readers


** *** ***** ******* *********** *************

      In Praise of Security Theater



While visiting some friends and their new baby in the hospital last=20
week, I noticed an interesting bit of security. To prevent infant=20
abduction, all babies had RFID tags attached to their ankles by a=20
bracelet. There are sensors on the doors to the maternity ward, and if a=20
baby passes through, an alarm goes off.

Infant abduction is rare, but still a risk. In the last 22 years, about=20
233 such abductions have occurred in the United States. About 4 million=20
babies are born each year, which means that a baby has a 1-in-375,000=20
chance of being abducted. Compare this with the infant mortality rate in=20
the U.S. -- one in 145 -- and it becomes clear where the real risks are.

And the 1-in-375,000 chance is not today's risk. Infant abduction rates=20
have plummeted in recent years, mostly due to education programs at=20
hospitals.

So why are hospitals bothering with RFID bracelets? I think they're=20
primarily to reassure the mothers. Many times during my friends' stay at=20
the hospital the doctors had to take the baby away for this or that=20
test. Millions of years of evolution have forged a strong bond between=20
new parents and new baby; the RFID bracelets are a low-cost way to=20
ensure that the parents are more relaxed when their baby was out of=20
their sight.

Security is both a reality and a feeling. The reality of security is=20
mathematical, based on the probability of different risks and the=20
effectiveness of different countermeasures.  We know the infant=20
abduction rates and how well the bracelets reduce those rates. We also=20
know the cost of the bracelets, and can thus calculate whether they're a=20
cost-effective security measure or not.  But security is also a feeling,=20
based on individual psychological reactions to both the risks and the=20
countermeasures. And the two things are different: You can be secure=20
even though you don't feel secure, and you can feel secure even though=20
you're not really secure.

The RFID bracelets are what I've come to call security theater: security=20
primarily designed to make you *feel* more secure. I've regularly=20
maligned security theater as a waste, but it's not always, and not=20
entirely, so.

It's only a waste if you consider the reality of security exclusively.=20
There are times when people feel less secure than they actually are. In=20
those cases -- like with mothers and the threat of baby abduction -- a=20
palliative countermeasure that primarily increases the feeling of=20
security is just what the doctor ordered.

Tamper-resistant packaging for over-the-counter drugs started to appear=20
in the 1980s, in response to some highly publicized poisonings. As a=20
countermeasure, it's largely security theater. It's easy to poison many=20
foods and over-the-counter medicines right through the seal -- with a=20
syringe, for example -- or to open and replace the seal well enough that=20
an unwary consumer won't detect it. But in the 1980s, there was a=20
widespread fear of random poisonings in over-the-counter medicines, and=20
tamper-resistant packaging brought people's perceptions of the risk more=20
in line with the actual risk: minimal.

Much of the post-9/11 security can be explained by this as well. I've=20
often talked about the National Guard troops in airports right after the=20
terrorist attacks, and the fact that they had no bullets in their guns.=20
As a security countermeasure, it made little sense for them to be there.=20
  They didn't have the training necessary to improve security at the=20
checkpoints, or even to be another useful pair of eyes. But to reassure=20
a jittery public that it's OK to fly, it was probably the right thing to =
do.

Security theater also addresses the ancillary risk of lawsuits. Lawsuits=20
are ultimately decided by juries, or settled because of the threat of=20
jury trial, and juries are going to decide cases based on their feelings=20
as well as the facts. It's not enough for a hospital to point to infant=20
abduction rates and rightly claim that RFID bracelets aren't worth it;=20
the other side is going to put a weeping mother on the stand and make an=20
emotional argument. In these cases, security theater provides real=20
security against the legal threat.

Like real security, security theater has a cost. It can cost money,=20
time, concentration, freedoms, and so on.  It can come at the cost of=20
reducing the things we can do. Most of the time security theater is a=20
bad trade-off, because the costs far outweigh the benefits. But there=20
are instances when a little bit of security theater makes sense.

We make smart security trade-offs -- and by this I mean trade-offs for=20
genuine security -- when our feeling of security closely matches the=20
reality. When the two are out of alignment, we get security wrong.=20
Security theater is no substitute for security reality, but, used=20
correctly, security theater can be a way of raising our feeling of=20
security so that it more closely matches the reality of security. It=20
makes us feel more secure handing our babies off to doctors and nurses,=20
buying over-the-counter medicines, and flying on airplanes -- closer to=20
how secure we should feel if we had all the facts and did the math=20
correctly.

Of course, too much security theater and our feeling of security becomes=20
greater than the reality, which is also bad. And others -- politicians,=20
corporations and so on -- can use security theater to make us feel more=20
secure without doing the hard work of actually making us secure. That's=20
the usual way security theater is used, and why I so often malign it.

But to write off security theater completely is to ignore the feeling of=20
security. And as long as people are involved with security trade-offs,=20
that's never going to work.

This essay appeared on Wired.com, and is dedicated to my new godson,=20
Nicholas Quillen Perry.
http://www.wired.com/news/columns/0,72561-0.html

Infant abduction:
http://www.saione.com/ispletter.htm

Blog entry URL:
http://www.schneier.com/blog/archives/2007/01/in_praise_of_se.html


** *** ***** ******* *********** *************

      Real-ID:  Costs and Benefits



The argument was so obvious it hardly needed repeating. Some thought we=20
would all be safer -- =ADfrom terrorism, from crime, even from=20
inconvenience -- =ADif we had a better ID card. A good, hard-to-forge=20
national ID is a no-brainer (or so the argument goes), and it's=20
ridiculous that a modern country like the United States doesn't have one.

Still, most Americans have been and continue to be opposed to a national=20
ID card. Even just after 9/11, polls showed a bare majority (51%) in=20
favor -- and that quickly became a minority opinion again. As such, both=20
political parties came out against the card, which meant that the only=20
way it could become law was to sneak it through.

Republican Cong. F. James Sensenbrenner of Wisconsin did just that. In=20
February 2005, he attached the Real ID Act to a defense appropriations=20
bill. No one was willing to risk not supporting the troops by holding up=20
the bill, and it became law. No hearings. No floor debate. With nary a=20
whisper, the United States had a national ID.

By forcing all states to conform to common and more stringent rules for=20
issuing driver's licenses, the Real ID Act turns these licenses into a=20
de facto national ID. It's a massive, unfunded mandate imposed on the=20
states, and -- naturally -- the states have resisted. The detailed rules=20
and timetables are still being worked out by the Department of Homeland=20
Security, and it's the details that will determine exactly how expensive=20
and onerous the program actually is.

It is against this backdrop that the National Governors Association, the=20
National Conference of State Legislatures, and the American Association=20
of Motor Vehicle Administrators together tried to estimate the cost of=20
this initiative. "The Real ID Act: National Impact Analysis" is a=20
methodical and detailed report, and everything after the executive=20
summary is likely to bore anyone but the most dedicated bean counters.=20
But rigor is important because states want to use this document to=20
influence both the technical details and timetable of Real ID. The=20
estimates are conservative, leaving no room for problems, delays, or=20
unforeseen costs, and yet the total cost is $11 billion over the first=20
five years of the program.

If anything, it's surprisingly cheap: Only $37 each for an estimated 295=20
million people who would get a new ID under this program. But it's still=20
an enormous amount of money. The question to ask is, of course: Is the=20
security benefit we all get worth the $11 billion price tag? We have a=20
cost estimate; all we need now is a security estimate.

I'm going to take a crack at it.

When most people think of ID cards, they think of a small plastic card=20
with their name and photograph. This isn't wrong, but it's only a small=20
piece of any ID program. What starts out as a seemingly simple security=20
device -- a card that binds a photograph with a name --  becomes a=20
complex security system.

It doesn't really matter how well a Real ID works when used by the=20
hundreds of millions of honest people who would carry it. What matters=20
is how the system might fail when used by someone intent on subverting=20
that system: how it fails naturally, how it can be made to fail, and how=20
failures might be exploited.

The first problem is the card itself. No matter how unforgeable we make=20
it, it will be forged. We can raise the price of forgery, but we can't=20
make it impossible. Real IDs will be forged.

Even worse, people will get legitimate cards in fraudulent names. Two of=20
the 9/11 terrorists had valid Virginia driver's licenses in fake names.=20
And even if we could guarantee that everyone who issued national ID=20
cards couldn't be bribed, cards are issued based on other identity=20
documents -- all of which are easier to forge.

And we can't assume that everyone will always have a Real ID. Currently=20
about 20% of all identity documents are lost per year. An entirely=20
separate security system would have to be developed for people who lost=20
their card, a system that itself would be susceptible to abuse.

Additionally, any ID system involves people: people who regularly make=20
mistakes. We've all heard stories of bartenders falling for obviously=20
fake IDs, or sloppy ID checks at airports and government buildings. It's=20
not simply a matter of training; checking IDs is a mind-numbingly boring=20
task, one that is guaranteed to have failures. Biometrics such as=20
thumbprints could help, but bring with them their own set of exploitable=20
failure modes.

All of these problems demonstrate that identification checks based on=20
Real ID won't be nearly as secure as we might hope. But the main problem=20
with any strong identification system is that it requires the existence=20
of a database. In this case, it would have to be 50 linked databases of=20
private and sensitive information on every American -- one widely and=20
instantaneously accessible from airline check-in stations, police cars,=20
schools, and so on.

The security risks of this database are enormous. It would be a kludge=20
of existing databases that are incompatible, full of erroneous data, and=20
unreliable. Computer scientists don't know how to keep a database of=20
this magnitude secure, whether from outside hackers or the thousands of=20
insiders authorized to access it.

But even if we could solve all these problems, and within the putative=20
$11 billion budget, we still wouldn't be getting very much security. A=20
reliance on ID cards is based on a dangerous security myth, that if only=20
we knew who everyone was, we could pick the bad guys out of the crowd.

In an ideal world, what we would want is some kind of ID that denoted=20
intention. We'd want all terrorists to carry a card that said "evildoer"=20
and everyone else to carry a card that said "honest person who won't try=20
to hijack or blow up anything." Then security would be easy. We could=20
just look at people's IDs, and, if they were evildoers, we wouldn't let=20
them on the airplane or into the building.

This is, of course, ridiculous; so we rely on identity as a substitute.=20
In theory, if we know who you are, and if we have enough information=20
about you, we can somehow predict whether you're likely to be an=20
evildoer. But that's almost as ridiculous.

Even worse, as soon as you divide people into two categories -- more=20
trusted and less trusted people -- you create a third, and very=20
dangerous, category: untrustworthy people whom we have no reason to=20
mistrust. Oklahoma City bomber Timothy McVeigh; the Washington, DC,=20
snipers; the London subway bombers; and many of the 9/11 terrorists had=20
no previous links to terrorism. Evildoers can also steal the identity --=20
and profile -- of an honest person. Profiling can result in less=20
security by giving certain people an easy way to skirt security.

There's another, even more dangerous, failure mode for these systems:=20
honest people who fit the evildoer profile. Because evildoers are so=20
rare, almost everyone who fits the profile will turn out to be a false=20
alarm. Think of all the problems with the government's no-fly list. That=20
list, which is what Real IDs will be checked against, not only wastes=20
investigative resources that might be better spent elsewhere, but it=20
also causes grave harm to those innocents who fit the profile.

Enough of terrorism; what about more mundane concerns like identity=20
theft? Perversely, a hard-to-forge ID card can actually increase the=20
risk of identity theft. A single ubiquitous ID card will be trusted more=20
and used in more applications. Therefore, someone who does manage to=20
forge one -- or get one issued in someone else's name -- can commit much=20
more fraud with it. A centralized ID system is a far greater security=20
risk than a decentralized one with various organizations issuing ID=20
cards according to their own rules for their own purposes.

Security is always a trade-off; it must be balanced with the cost. We=20
all do this intuitively. Few of us walk around wearing bulletproof=20
vests. It's not because they're ineffective, it's because for most of us=20
the trade-off isn't worth it. It's not worth the cost, the=20
inconvenience, or the loss of fashion sense. If we were living in a=20
war-torn country like Iraq, we might make a different trade-off.

Real ID is another lousy security trade-off. It'll cost the United=20
States at least $11 billion, and we won't get much security in return.=20
The report suggests a variety of measures designed to ease the financial=20
burden on the states: extend compliance deadlines, allow manual=20
verification systems, and so on. But what it doesn't suggest is the=20
simple change that would do the most good: scrap the Real ID program=20
altogether. For the price, we're not getting anywhere near the security=20
we should.

This essay will appear in the March/April issue of "The Bulletin of=20
Atomic Scientists."

REAL-ID:
http://thomas.loc.gov/cgi-bin/bdquerytr/z?d109:HR01268:

The REAL-ID Act: National Impact Analysis:
http://www.nga.org/Files/pdf/0609REALID.pdf

There's REAL-ID news.  Maine became the first state to reject REAL-ID.=20
This means that a Maine state driver's license will not be recognized as=20
valid for federal purposes, although I'm sure the Feds will back down=20
over this.  My guess is that Montana will become the second state to=20
reject REAL-ID, and New Mexico will be the third.
http://www.northcountrygazette.org/articles/2007/012807RealID.html
http://www.usatoday.com/news/nation/2007-01-30-realID_x.htm

More info on REAL-ID:
http://www.realnightmare.org


** *** ***** ******* *********** *************

      Crypto-Gram Reprints



Crypto-Gram is currently in its tenth year of publication.  Back issues=20
cover a variety of security-related topics, and can all be found on=20
<http://www.schneier.com/crypto-gram-back.html>.  These are a selection=20
of articles that appeared in this calendar month in other years.

Risks of Losing Portable Devices
http://www.schneier.com/crypto-gram-0602.html#1

Multi-Use ID Cards:
http://www.schneier.com/crypto-gram-0602.html#2

Countering "Trusting Trust"
http://www.schneier.com/crypto-gram-0602.html#16

TSA's Secure Flight
http://www.schneier.com/crypto-gram-0502.html#1

The Curse of the Secret Question:
http://www.schneier.com/crypto-gram-0502.html#9

Authentication and Expiration:
http://www.schneier.com/crypto-gram-0502.html#10

Toward Universal Surveillance:
http://www.schneier.com/crypto-gram-0402.html#1

The Politicization of Security:
http://www.schneier.com/crypto-gram-0402.html#2

Identification and Security:
http://www.schneier.com/crypto-gram-0402.html#6

The Economics of Spam:
http://www.schneier.com/crypto-gram-0402.html#9

Militaries and Cyber-War:
http://www.schneier.com/crypto-gram-0301.html#1

The RMAC Authentication Mode:
http://www.schneier.com/crypto-gram-0301.html#7

Microsoft and "Trustworthy Computing":
http://www.schneier.com./crypto-gram-0202.html#1

Judging Microsoft:
http://www.schneier.com./crypto-gram-0202.html#2

Hard-drive-embedded copy protection:
http://www.schneier.com/crypto-gram-0102.html#1

A semantic attack on URLs:
http://www.schneier.com/crypto-gram-0102.html#7

E-mail filter idiocy:
http://www.schneier.com/crypto-gram-0102.html#8

Air gaps:
http://www.schneier.com/crypto-gram-0102.html#9

Internet voting vs. large-value e-commerce:
http://www.schneier.com/crypto-gram-0102.html#10

Distributed denial-of-service attacks:
http://www.schneier.com/crypto-gram-0002.html#ddos

Recognizing crypto snake-oil:
http://www.schneier.com/crypto-gram-9902.html#snakeoil


** *** ***** ******* *********** *************

      Debating Full Disclosure



Full disclosure -- the practice of making the details of security=20
vulnerabilities public -- is a damned good idea. Public scrutiny is the=20
only reliable way to improve security, while secrecy only makes us less=20
secure.

Unfortunately, secrecy *sounds* like a good idea. Keeping software=20
vulnerabilities secret, the argument goes, keeps them out of the hands=20
of the hackers.  The problem, according to this position, is less the=20
vulnerability itself and more the information about the vulnerability.

But that assumes that hackers can't discover vulnerabilities on their=20
own, and that software companies will spend time and money fixing secret=20
vulnerabilities. Both of those assumptions are false. Hackers have=20
proven to be quite adept at discovering secret vulnerabilities, and full=20
disclosure is the only reason vendors routinely patch their systems.

To understand why the second assumption isn't true, you need to=20
understand the underlying economics. To a software company,=20
vulnerabilities are largely an externality. That is, they affect you --=20
the user -- much more than they affect it. A smart vendor treats=20
vulnerabilities less as a software problem, and more as a PR problem. So=20
if we, the user community, want software vendors to patch=20
vulnerabilities, we need to make the PR problem more acute.

Full disclosure does this. Before full disclosure was the norm,=20
researchers would discover vulnerabilities in software and send details=20
to the software companies -- who would ignore them, trusting in the=20
security of secrecy. Some would go so far as to threaten the researchers=20
with legal action if they disclosed the vulnerabilities.

Later on, researchers announced that particular vulnerabilities existed,=20
but did not publish details. Software companies would then call the=20
vulnerabilities "theoretical" and deny they actually existed. Of course,=20
they would still ignore the problems, and occasionally threaten the=20
researcher with legal action. Then, of course, some hacker would create=20
an exploit using the vulnerability -- and the company would release a=20
really quick patch, apologize profusely, and go on to explain that the=20
whole thing was entirely the fault of the evil, vile hackers.

It wasn't until researchers published complete details of the=20
vulnerabilities that the software companies started fixing them.

Of course, the software companies hated this. They received bad PR every=20
time a vulnerability was made public, and the only way to get some good=20
PR was to quickly release a patch. For a large company like Microsoft,=20
this was very expensive.

So a bunch of software companies, and some security researchers, banded=20
together and invented "responsible disclosure."  The basic idea was that=20
the threat of publishing the vulnerability is almost as good as actually=20
publishing it. A responsible researcher would quietly give the software=20
vendor a head start on patching its software, before releasing the=20
vulnerability to the public.

This was a good idea -- and these days it's normal procedure -- but one=20
that was possible only because full disclosure was the norm. And it=20
remains a good idea only as long as full disclosure is the threat.

The moral here doesn't just apply to software; it's very general. Public=20
scrutiny is how security improves, whether we're talking about software=20
or airport security or government counterterrorism measures. Yes, there=20
are trade-offs. Full disclosure means that the bad guys learn about the=20
vulnerability at the same time as the rest of us -- unless, of course,=20
they knew about it beforehand -- but most of the time the benefits far=20
outweigh the disadvantages.

Secrecy prevents people from accurately assessing their own risk.=20
Secrecy precludes public debate about security, and inhibits security=20
education that leads to improvements. Secrecy doesn't improve security;=20
it stifles it.

I'd rather have as much information as I can to make an informed=20
decision about security, whether it's a buying decision about a software=20
product or an election decision about two political parties. I'd rather=20
have the information I need to pressure vendors to improve security.

I don't want to live in a world where companies can sell me software=20
they know is full of holes or where the government can implement=20
security measures without accountability. I much prefer a world where I=20
have all the information I need to assess and protect my own security.

This essay originally appeared on CSOOnline:
http://www2.csoonline.com/exclusives/column.html?CID=3D28073

It was part of a series of essays on the topic.  Marcus Ranum wrote=20
against the practice of disclosing vulnerabilities:
http://www2.csoonline.com/exclusives/column.html?CID=3D28072
Mark Miller of Microsoft wrote in favor of responsible disclosure.
http://www2.csoonline.com/exclusives/column.html?CID=3D28071

These are sidebars to a very interesting article in "CSO Magazine," "The=20
Chilling Effect," about the confluence of forces that are making it=20
harder to research and disclose vulnerabilities in web-based software:
http://www.csoonline.com/read/010107/fea_vuln.html
All the links are worth reading in full.

A Simplified Chinese translation by Xin Li:
http://blog.delphij.net/archives/001694.html


** *** ***** ******* *********** *************

      Sending Photos to 911 Operators



Last month, Mayor Bloomberg announced that New York will be the first=20
city with 911 call centers able to receive images and videos from cell=20
phones and computers. If you witness a crime, you can not only call in=20
-- you can send in a picture or video as well.

This is a great idea that can make us all safer. Often the biggest=20
problem a 911 operator has is getting enough good information from the=20
caller. Sometimes the caller is emotionally distraught. Sometimes=20
there's confusion and background noise. Sometimes there's a language=20
barrier. Giving callers the opportunity to use all the communications=20
tools at their disposal will help operators dispatch the right help faste=
r.

Still Images and videos can also help identify and prosecute criminals.=20
Memories are notoriously inaccurate. Photos aren't perfect, but they=20
provide a different sort of evidence -- one that, with the right=20
safeguards, can be used in court.

The worry is that New York will become a city of amateur sleuths and=20
snitches, turning each other in to settle personal scores or because of=20
cultural misunderstandings. But the 911 service has long avoided such=20
hazards. Falsely reporting a crime is itself a serious crime, which=20
discourages people from using 911 for anything other than a true emergenc=
y.

Since 1968, the 911 system has evolved smartly with the times. Calls are=20
now automatically recorded. Callers are now automatically located by=20
phone number or cell phone location.

Bloomberg's plan is the next logical evolution -- one that all of us=20
should welcome. Smile, suspected criminals: you're on candid camphone.

http://www.newsday.com/news/local/newyork/ny-nycell185056789jan18,0,72389=
79.story=20
or http://tinyurl.com/23hguc
http://www.nyc.gov/portal/site/nycgov/menuitem.c0935b9a57bb4ef3daf2f1c701=
c789a0/index.jsp?pageID=3Dmayor_press_release&catID=3D1194&doc_name=3Dhtt=
p%3A%2F%2Fwww.nyc.gov%2Fhtml%2Fom%2Fhtml%2F2007a%2Fpr014-07.html&cc=3Dunu=
sed1978&rc=3D1194&ndi=3D1=20
or http://tinyurl.com/2ut2f2
http://suitablyflip.blogs.com/suitably_flip/2007/01/smile_youre_on_.html=20
or http://tinyurl.com/ywhx8e

This essay originally appeared in "The New York Daily News."
http://www.nydailynews.com/news/ideas_opinions/story/489855p-412569c.html=
=20
or http://tinyurl.com/36axrq


** *** ***** ******* *********** *************

      "Clear" Registered Traveler Program



CLEAR, a private service that prescreens travelers for a $100 annual=20
fee, has come to Kennedy International Airport. To benefit from the=20
Clear Registered Traveler program, which is run by Verified Identity=20
Pass, a person must fill out an application, let the service capture his=20
fingerprints and iris pattern, and present two forms of identification.=20
If the traveler passes a federal background check, he will be given a=20
card that allows him to pass quickly through airport security.

Sounds great, but it's actually two ideas rolled into one: one clever=20
and one very stupid.

The clever idea is allowing people to pay for better service. Clear has=20
been in operation at the Orlando International Airport since July 2005,=20
and members have passed through security checkpoints faster simply=20
because they are segregated from less experienced fliers who don't know=20
the drill.

Now, at Kennedy and other airports, Clear is purchasing and installing=20
federally approved technology that will further speed up the screening=20
process: scanners that will eliminate the need for cardholders to remove=20
their shoes, and explosives detection machines that will eliminate the=20
need for them to remove their coats and jackets. There are also Clear=20
employees at the checkpoints who, although they can't screen=20
cardholders, can guide members through the security process. Clear has=20
not yet paid airports for an extra security lane or the Transportation=20
Security Administration for extra screening personnel, but both of those=20
enhancements are on the table if enough people sign up.

I fly more than 200,000 miles per year and would gladly pay $100 a year=20
to get through airport security faster.

But the stupid idea is the background check. When first conceived,=20
traveler programs focused on prescreening. Pre-approved travelers would=20
pass through security checkpoints with less screening, and resources=20
would be focused on everyone else. Sounds reasonable, but it would leave=20
us all less safe.

Background checks are based on the dangerous myth that we can somehow=20
pick terrorists out of a crowd if we could identify everyone.=20
Unfortunately, there isn't any terrorist profile that prescreening can=20
uncover. Timothy McVeigh could probably have gotten one of these cards.=20
So could have Eric Rudolph, the pipe bomber at the 1996 Olympic Games in=20
Atlanta. There isn't even a good list of known terrorists to check=20
people against; the government list used by the airlines has been the=20
butt of jokes for years.

And have we forgotten how prevalent identity theft is these days? If you=20
think having a criminal impersonating you to your bank is bad, wait=20
until they start impersonating you to the Transportation Security=20
Administration.

The truth is that whenever you create two paths through security -- a=20
high-security path and a low-security path -- you have to assume that=20
the bad guys will find a way to exploit the low-security path. It may be=20
counterintuitive, but we are all safer if the people chosen for more=20
thorough screening are truly random and not based on an error-filled=20
database or a cursory background check.

I think of Clear as a $100 service that tells terrorists if the FBI is=20
on to them or not. Why in the world would we provide terrorists with=20
this ability?

We don't have to. Clear cardholders are not scrutinized less when they=20
go through checkpoints, they're scrutinized more efficiently. So why not=20
get rid of the background checks altogether? We should all be able to=20
walk into the airport, pay $10, and use the Clear lanes when it's worth=20
it to us.

This essay originally appeared in "The New York Times."
http://www.nytimes.com/2007/01/21/opinion/nyregionopinions/21LIschneier.h=
tml=20
or http://tinyurl.com/35l4mh

Clear:
http://www.flyclear.com/

Verified Identity Pass, Inc.
http://www.verifiedidpass.com/

My 2004 essays on Trusted Traveler Programs and Verified Identity Card, I=
nc.
http://www.schneier.com/essay-051.html
http://www.schneier.com/crypto-gram-0403.html#10


** *** ***** ******* *********** *************

      News



Non-terrorist embarrassment in Boston.  I wrote about it in my blog the=20
day after it happened.
http://www.schneier.com/blog/archives/2007/02/nonterrorist_em.html
I am writing something new for Wired.com; it should appear next week.

Security theater and a secure data center:
http://ask.slashdot.org/comments.pl?sid=3D214948&threshold=3D4&commentsor=
t=3D0&mode=3Dflat&cid=3D17458652=20
or http://tinyurl.com/wzfyz

PC World has found a do-it-yourself phishing kit for sale on the=20
Internet.  Of course, because they're a fine, upstanding magazine, they=20
don't include any information about how to buy it or how much it costs.
http://www.pcworld.com/article/id,128524-c,cybercrime/article.html

Terrorists might bomb airplanes, take and kill hostages, and otherwise=20
terrorize innocents.  But there's one thing they just won't do: lie on=20
government forms.  And that's why the State of Ohio requires certain=20
license (including private pilot license) applicants to certify that=20
they're not terrorists.  Because if we can't lock them up long enough=20
for terrorism, we've got the additional charge of lying on a government=20
form to throw at them.
http://www.schneier.com/blog/archives/2007/01/do_terrorists_l.html

FedEx refuses to ship empty containers: security theater at its finest.
http://putative.typepad.com/putative/2007/01/fedex_refuses_s.html

The "Washington Post" on ubiquitous surveillance
http://www.washingtonpost.com/wp-dyn/content/article/2007/01/15/AR2007011=
501304.html=20
or http://tinyurl.com/y86fyl

After over five years of harassing innocents and not catching any=20
terrorists, the no-fly list is finally being checked for accuracy, and=20
probably cut in half.
http://www.breitbart.com/news/2007/01/17/D8MNE7DG0.html
It's not enough, though.  The no-fly list doesn't work and is easy to=20
bypass.
http://www.schneier.com/essay-052.html
http://www.schneier.com/blog/archives/2006/11/forge_your_own.html
http://www.cs.berkeley.edu/~daw/faa/noid.html
http://www.schneier.com/essay-008.html
http://www.schneier.com/blog/archives/2006/10/nofly_list.html

RFID tattoos.  Great idea for livestock.  Dumb idea for soldiers:
http://www.industrialcontroldesignline.com/showArticle.jhtml?articleID=3D=
196900052=20
or http://tinyurl.com/2mk9g3

Huge online bank heist.  This is my favorite line:  "Ehlin blamed=20
successful social engineering for the heist, rather than any=20
deficiencies in Nordea security procedures."  Um...hello?   Are you an=20
idiot, or what?
http://news.zdnet.co.uk/security/0,1000000189,39285547,00.htm

Second in our series of stupid comments to the press, here's Kansas=20
City's assistant city manager commenting on the fact that they lost 26=20
computer tapes containing personal information:  "It's not a situation=20
that if you had a laptop you could access....  You would need some=20
specialized equipment and some specialized knowledge in order to read=20
these tapes."
http://www.myfoxkc.com/myfox/pages/News/Detail?contentId=3D2113498&versio=
n=3D4&locale=3DEN-US&layoutCode=3DTSTY&pageId=3D3.1.1=20
or http://tinyurl.com/2a35bh

The NSA is hiring data miners:
http://www.issa-balt.org/html/ctc_opportunity.html

Dogbert's Password Recovery Service for Morons
http://www.unitedmedia.com/comics/dilbert/archive/dilbert-20070117.html=20
or http://tinyurl.com/32c33p
http://www.unitedmedia.com/comics/dilbert/archive/dilbert-20070118.html=20
or http://tinyurl.com/ywrvb2

SAS troops stationed in London:
http://www.timesonline.co.uk/article/0,,2-2559186,00.html
While I agree that the British police completely screwed up the Menezes=20
shooting, I'm not at all convinced the SAS can do better.  The police=20
are trained to work within a lawful society; military units are=20
primarily trained for military combat operations.  Which group do you=20
think will be more restrained?  This kind of thing is a result of the=20
"war on terror" rhetoric.  We don't need military operations, we need=20
police protection.  I think people have been watching too many seasons=20
of "24."

Sir Ken Macdonald -- the UK's "director of public prosecutions" =96 has=20
spoken out against the "war on terror" rhetoric:
http://politics.guardian.co.uk/terrorism/story/0,,1997247,00.html

The Blu-ray DRM system has been broken, although details are scant.=20
It's the same person who broke the HD DVD system in December.  (Both use=20
AACS.)  As I've written previously, both of these systems are supposed=20
to be designed in such a way as to recover from hacks like this.  We're=20
going to find out if the recovery feature works.
http://www.theregister.co.uk/2007/01/23/blu-ray_drm_cracked/
You should read this seven-part series by Ed Felten on the topic:
http://www.freedom-to-tinker.com/?p=3D1104
http://www.freedom-to-tinker.com/?p=3D1106
http://www.freedom-to-tinker.com/?p=3D1107
http://www.freedom-to-tinker.com/?p=3D1108
http://www.freedom-to-tinker.com/?p=3D1109
http://www.freedom-to-tinker.com/?p=3D1110
http://www.freedom-to-tinker.com/?p=3D1111

"Prophetic Justice" by Amy Waldman ("The Atlantic Monthly," Oct 2006) is=20
a fascinating article about terrorism trials in the U.S. where the=20
prosecution attempts to prove that the defendant was planning on=20
committing an act of terrorism.  Very often, the trials hinge on=20
different interpretations of Islam, Islamic scripture, and Islamic=20
belief -- and often we are essentially putting the religion on trial.=20
Reading it, I was struck with some of the more extremist religious=20
rhetoric in the U.S. today, and how it would fare under the same level=20
of scrutiny.  It's a long article, but well worth reading.  There are=20
many problems with prosecuting people for thoughtcrimes, and the article=20
discusses some of them.
http://www.theatlantic.com/doc/200610/waldman-islam

I've previously written about how official uniforms are inherent=20
authentication tokens, even though they can be easy to forge.
Now we see this tactic being used by insurgents in Baghdad:
http://www.washingtonpost.com/wp-dyn/content/article/2007/01/21/AR2007012=
100227.html=20
or http://tinyurl.com/yv6hcd
http://www.schneier.com/blog/archives/2007/01/iraqi_gunmen_dr.html

Airport security game:  Play online, and see if you can keep up with the=20
ever-changing arbitrary rules.
http://www.addictinggames.com/airportsecurity.html

"Internet Explorer Unsafe for 284 Days in 2006."
http://blog.washingtonpost.com/securityfix/2007/01/internet_explorer_unsa=
fe_for_2.html=20
or http://tinyurl.com/y4qnyt
http://www.washingtonpost.com/wp-srv/technology/daily/graphics/index20070=
104.html=20
or http://tinyurl.com/ysbhym

There is a proposal in Scotland to protect automatic speed-trap cameras=20
from vandals by monitoring them with other cameras.  Then, I suppose we=20
need still other cameras to protect the camera-watching cameras.  When=20
will it end?
http://news.bbc.co.uk/2/hi/uk_news/scotland/south_of_scotland/6293823.stm=
=20
or http://tinyurl.com/2ql8rs

Fascinating story of an Israeli driver who picked up a suicide bomber.=20
What's interesting to me is how the driver comes to realize his=20
passenger is a suicide bomber.  It wasn't anything that comes up on a=20
profile, but a feeling that something is wrong.
http://news.bbc.co.uk/1/hi/world/middle_east/6312657.stm

Excessive secrecy and security helps terrorists.  I've said it, and now=20
so has the director of the Canadian Security Intelligence Service:
http://www.canada.com/ottawacitizen/news/story.html?id=3D5f848011-0a8c-43=
48-90df-f6656d0281d9=20
or http://tinyurl.com/2koeb9

"Knowing the Enemy" by George Packer ("The New Yorker," Dec 18, 2006),=20
is a fascinating article about the social science needed to prevail=20
against Islamic terrorism, which the author argues is best characterized=20
as a counterinsurgency.
http://www.newyorker.com/fact/content/articles/061218fa_fact2

Business models for discovering security vulnerabilities, both legal and=20
illegal.  There's a lot of FUD in this article, but also some good stuff.
http://www.iht.com/articles/2007/01/29/business/bugs.php

Dave Barry on Super Bowl security:
http://www.miami.com/mld/miamiherald/living/columnists/dave_barry/1660159=
9.htm?source=3Drss&channel=3Dmiamiherald_dave_barry=20
or http://tinyurl.com/yoxd73

According to an older article, "Mistaken eyewitness identification is=20
the leading cause of wrongful convictions."  Given what I've been=20
reading recently about memory and the brain, this does not surprise me=20
at all.  New Mexico is currently debating a bill reforming eyewitness=20
identification procedures.  I don't have access to any of the=20
psychological or criminology studies that back these reforms up, but the=20
bill is being supported by the right sorts of people.
http://www.lcsun-news.com/ci_5164992

Fascinating article on the Corsham bunker, the secret underground UK=20
site the government was to retreat to in the event of a nuclear war.
http://politics.guardian.co.uk/politicspast/story/0,,2006099,00.html

Interesting data from New York.  The number of people stopped and=20
searched has gone up fivefold since 2002, but the number of arrests due=20
to these stops has only doubled.  (The number of "summonses" has also=20
gone up fivefold.)
http://www.prisonplanet.com/articles/february2007/030207Stopped.htm

Three pipe bombs were found in the town of Pearblossom, California, and=20
-- it seems -- disposed of without causing hysteria.  Boston, are you=20
paying attention?
http://www.dailynews.com/ci_5180780

Ross Anderson and Tyler Moore just published "The Economics of=20
Information Security: A Survey and Open Questions."  Excellent reading.
http://www.cl.cam.ac.uk/~rja14/Papers/toulouse-summary.pdf
http://www.cl.cam.ac.uk/~rja14/Presentations/econsec_toulouse.ppt
http://www.cl.cam.ac.uk/~twm29/science-econ.pdf

This article is a perfect illustrating of the wasteful, pork-barrel,=20
political spending that we like to call "homeland security."  And to=20
think we could actually be spending this money on something useful.
http://www.boston.com/news/local/articles/2007/02/09/firefighters_windfal=
l_comes_with_a_catch/=20
or http://tinyurl.com/yw4lew

"Information Security and Externalities."  I updated a 2004 essay of=20
mine for the European Network and Information Security Agency quarterly=20
newsletter:
http://www.enisa.europa.eu/doc/pdf/publications/enisa_quarterly_01_07.pdf=
=20
or http://tinyurl.com/2bcktu

This is a good summary of the European SWIFT privacy case:
http://www.newswireless.net/index.cfm/article/3057

We've all seen those anti-counterfeiting holograms: on credit cards, on=20
software, on expensive apparel.  Turns out they're getting easier to=20
counterfeit.
http://www.wired.com/news/technology/0,72664-0.html

BitFrost, the security system for the One Laptop Per Child project, is=20
very interesting.  At least read the design principles and design goals.
http://wiki.laptop.org/go/Bitfrost
www.wired.com/news/technology/0,72669-0.html
http://it.slashdot.org/article.pl?sid=3D07/02/07/2137233

Here's an article on a brain scanning technique that reads people's=20
intentions.  There's not a lot of detail, but my guess is that it=20
doesn't work very well.  But that's not really the point.  If it doesn't=20
work today, it will in five, ten, twenty years; it will work eventually.=20
  What we need to do, today, is debate the legality and ethics of these=20
sorts of interrogations.
http://www.guardian.co.uk/science/story/0,,2009217,00.html
I wrote about this sort of thing in 2005, in the context of Judge=20
Roberts' confirmation hearings.
http://www.wired.com/news/politics/0,1283,68911,00.html

Random number humor:
http://xkcd.com/c221.html


** *** ***** ******* *********** *************

      DRM in Windows Vista



Windows Vista includes an array of "features" that you don't want. These=20
features will make your computer less reliable and less secure. They'll=20
make your computer less stable and run slower. They will cause technical=20
support problems. They may even require you to upgrade some of your=20
peripheral hardware and existing software. And these features won't do=20
anything useful. In fact, they're working against you. They're digital=20
rights management (DRM) features built into Vista at the behest of the=20
entertainment industry.

And you don't get to refuse them.

The details are pretty geeky, but basically Microsoft has reworked a lot=20
of the core operating system to add copy protection technology for new=20
media formats like HD DVD and Blu-ray disks. Certain high-quality output=20
paths -- audio and video -- are reserved for protected peripheral=20
devices. Sometimes output quality is artificially degraded; sometimes=20
output is prevented entirely. And Vista continuously spends CPU time=20
monitoring itself, trying to figure out if you're doing something that=20
it thinks you shouldn't. If it does, it limits functionality and in=20
extreme cases restarts just the video subsystem. We still don't know the=20
exact details of all this, and how far-reaching it is, but it doesn't=20
look good.

Microsoft put all those functionality-crippling features into Vista=20
because it wants to own the entertainment industry. This isn't how=20
Microsoft spins it, of course. It maintains that it has no choice, that=20
it's Hollywood that is demanding DRM in Windows in order to allow=20
"premium content"--meaning, new movies that are still earning=20
revenue--onto your computer. If Microsoft didn't play along, it'd be=20
relegated to second-class status as Hollywood pulled its support for the=20
platform.

It's all complete nonsense. Microsoft could have easily told the=20
entertainment industry that it was not going to deliberately cripple its=20
operating system, take it or leave it. With 95% of the operating system=20
market, where else would Hollywood go? Sure, Big Media has been pushing=20
DRM, but recently some -- Sony after their 2005 debacle and now EMI=20
Group -- are having second thoughts.

What the entertainment companies are finally realizing is that DRM=20
doesn't work, and just annoys their customers. Like every other DRM=20
system ever invented, Microsoft's won't keep the professional pirates=20
from making copies of whatever they want. The DRM security in Vista was=20
broken the day it was released. Sure, Microsoft will patch it, but the=20
patched system will get broken as well. It's an arms race, and the=20
defenders can't possibly win.

I believe that Microsoft knows this and also knows that it doesn't=20
matter. This isn't about stopping pirates and the small percentage of=20
people who download free movies from the Internet. This isn't even about=20
Microsoft satisfying its Hollywood customers at the expense of those of=20
us paying for the privilege of using Vista. This is about the=20
overwhelming majority of honest users and who owns the distribution=20
channels to them. And while it may have started as a partnership, in the=20
end Microsoft is going to end up locking the movie companies into=20
selling content in its proprietary formats.

We saw this trick before; Apple pulled it on the recording industry.=20
First iTunes worked in partnership with the major record labels to=20
distribute content, but soon Warner Music's CEO Edgar Bronfman Jr. found=20
that he wasn't able to dictate a pricing model to Steve Jobs. The same=20
thing will happen here; after Vista is firmly entrenched in the=20
marketplace, Sony's Howard Stringer won't be able to dictate pricing or=20
terms to Bill Gates. This is a war for 21st-century movie distribution=20
and, when the dust settles, Hollywood won't know what hit them.

To be fair, just last week Steve Jobs publicly came out against DRM for=20
music. It's a reasonable business position, now that Apple controls the=20
online music distribution market. But Jobs never mentioned movies, and=20
he is the largest single shareholder in Disney. Talk is cheap. The real=20
question is would he actually allow iTunes Music Store purchases to play=20
on Microsoft or Sony players, or is this just a clever way of deflecting=20
blame to the--already hated--music labels.

Microsoft is reaching for a much bigger prize than Apple: not just=20
Hollywood, but also peripheral hardware vendors. Vista's DRM will=20
require driver developers to comply with all kinds of rules and be=20
certified; otherwise, they won't work. And Microsoft talks about=20
expanding this to independent software vendors as well. It's another war=20
for control of the computer market.

Unfortunately, we users are caught in the crossfire. We are not only=20
stuck with DRM systems that interfere with our legitimate fair-use=20
rights for the content we buy, we're stuck with DRM systems that=20
interfere with all of our computer use--even the uses that have nothing=20
to do with copyright.

I don't see the market righting this wrong, because Microsoft's monopoly=20
position gives it much more power than we consumers can hope to have. It=20
might not be as obvious as Microsoft using its operating system monopoly=20
to kill Netscape and own the browser market, but it's really no=20
different. Microsoft's entertainment market grab might further entrench=20
its monopoly position, but it will cause serious damage to both the=20
computer and entertainment industries. DRM is bad, both for consumers=20
and for the entertainment industry: something the entertainment industry=20
is just starting to realize, but Microsoft is still fighting. Some=20
researchers think that this is the final straw that will drive Windows=20
users to the competition, but I think the courts are necessary.
In the meantime, the only advice I can offer you is to not upgrade to=20
Vista. It will be hard. Microsoft's bundling deals with computer=20
manufacturers mean that it will be increasingly hard not to get the new=20
operating system with new computers. And Microsoft has some pretty deep=20
pockets and can wait us all out if it wants to. Yes, some people will=20
shift to Macintosh and some fewer number to Linux, but most of us are=20
stuck on Windows. Still, if enough customers say no to Vista, the=20
company might actually listen.

http://www.cs.auckland.ac.nz/~pgut001/pubs/vista_cost.html
http://www.theinquirer.net/default.aspx?article=3D37091
http://www.miraesoft.com/karel/2007/01/23/microsoft-on-content-protection=
-in-vista/=20
or http://tinyurl.com/yvb8e7

Sony debacle:
http://www.schneier.com/essay-094.html

EMI:
http://www.forbes.com/home/digitalentertainment/2007/02/08/emi-drm-music-=
tech-media-cx_lh_pk_0207drm.html=20
or http://tinyurl.com/269sbg

Schneier on DRM:
http://www.schneier.com/crypto-gram-0105.html#3

Vista DRM hacked:
http://www.theregister.com/2007/01/31/vista_drm_hacked/

Steve Jobs on DRM:
http://www.apple.com/hotnews/thoughtsonmusic/

This essay originally appeared on Forbes.com.
http://www.forbes.com/security/2007/02/10/microsoft-vista-drm-tech-securi=
ty-cz_bs_0212vista.html=20
or http://tinyurl.com/242amw


** *** ***** ******* *********** *************

      BT Counterpane News



Rebecca Blood interviewed me for her "Bloggers on Blogging" series.
http://www.rebeccablood.net/bloggerson/bruceschneier.html

On June 10, 2006, I gave a talk at the ACLU New Jersey Membership=20
Conference: "Counterterrorism in America: Security Theater Against=20
Movie-Plot Threats."  Here's the video (a little over an hour long).
http://www.schneier.com/news-023.html

Here's an interview I did with LinuxWorld.  It was a verbal interview=20
that they transcribed.
http://www.linuxworld.com/news/2007/020807-qa-schneier.html

And a short interview with me for Information Week:
http://www.informationweek.com/showArticle.jhtml;jsessionid=3D53O1Q0CX4NL=
YIQSNDLPCKH0CJUNN2JVN?articleID=3D197004884=20
or http://tinyurl.com/33vmrz

I will host one of BT's "Big Thinkers" series on February 21, 10:00hr=20
GMT.  The topic is: "Security: Not Just a Technical Problem"
http://www.networked.bt.com/bigthinkers_security.php

BT has bought INS.  This is good for Counterpane, as our two companies=20
have been partners for years.  And, like all BT's private acquisitions,=20
the purchase price is not public.
http://www.btplc.com/News/Articles/ShowArticle.cfm?ArticleID=3D7466d6b2-b=
13c-4c02-ad0f-cfd8ec7988ec=20
or http://tinyurl.com/2yzxsn


** *** ***** ******* *********** *************

      Psychology of Security



I just posted a long essay on my website, exploring how psychology can=20
help explain the difference between the feeling of security and the=20
reality of security.

It's too long to include in this issue, and I will be sending it out to=20
everyone in a special issue of Crypto-Gram on February 28.  In the=20
meantime, you can read an earlier draft of the essay by following the=20
link below.

http://www.schneier.com/essay-155.html
http://www.schneier.com/essay-155.pdf

Other articles and commentary:
http://www.darkreading.com/document.asp?doc_id=3D116153
http://it.slashdot.org/it/07/02/01/2343212.shtml
http://www.csoonline.com/podcasts/Schneier_security020207.html
http://www.networkworld.com/news/2007/020707-rsa-schneier.html
http://it.slashdot.org/it/07/02/07/1656215.shtml


** *** ***** ******* *********** *************

      A New Secure Hash Standard



The U.S. National Institute of Standards and Technology is having a=20
competition for a new cryptographic hash function.

This matters. The phrase "one-way hash function" might sound arcane and=20
geeky, but hash functions are the workhorses of modern cryptography.=20
They provide web security in SSL. They help with key management in=20
e-mail and voice encryption: PGP, Skype, all the others. They help make=20
it harder to guess passwords. They're used in virtual private networks,=20
help provide DNS security, and ensure that your automatic software=20
updates are legitimate. They provide all sorts of security functions in=20
your operating system. Every time you do something with security on the=20
Internet, a hash function is involved somewhere.

Basically, a hash function is a fingerprint function. It takes a=20
variable-length input -- anywhere from a single byte to a file terabytes=20
in length -- and converts it to a fixed-length string: 20 bytes, for=20
example.

One-way hash functions are supposed to have two properties. First,=20
they're one-way. This means that it is easy to take an input and compute=20
the hash value, but it's impossible to take a hash value and recreate=20
the original input. By "impossible" I mean "can't be done in any=20
reasonable amount of time."

Second, they're collision-free. This means that even though there are an=20
infinite number of inputs for every hash value, you're never going to=20
find two of them. Again, "never" is defined as above. The cryptographic=20
reasoning behind these two properties is subtle, but any cryptographic=20
text talks about them.

The hash function you're most likely to use routinely is SHA-1. Invented=20
by the National Security Agency, it's been around since 1995. Recently,=20
though, there have been some pretty impressive cryptanalytic attacks=20
against the algorithm. The best attack is barely on the edge of=20
feasibility, and not effective against all applications of SHA-1. But=20
there's an old saying inside the NSA: "Attacks always get better; they=20
never get worse." It's past time to abandon SHA-1.

There are near-term alternatives -- a related algorithm called SHA-256=20
is the most obvious -- but they're all based on the family of hash=20
functions first developed in 1992. We've learned a lot more about the=20
topic in the past 15 years, and can certainly do better.

Why the National Institute of Standards and Technology, or NIST, though?=20
Because it has exactly the experience and reputation we want. We were in=20
the same position with encryption functions in 1997. We needed to=20
replace the Data Encryption Standard, but it wasn't obvious what should=20
replace it. NIST decided to orchestrate a worldwide competition for a=20
new encryption algorithm. There were 15 submissions from 10 countries --=20
I was part of the group that submitted Twofish -- and after four years=20
of analysis and cryptanalysis, NIST chose the algorithm Rijndael to=20
become the Advanced Encryption Standard, or AES.

The AES competition was the most fun I've ever had in cryptography.=20
Think of it as a giant cryptographic demolition derby: A bunch of us put=20
our best work into the ring, and then we beat on each other until there=20
was only one standing. It was really more academic and structured than=20
that, but the process stimulated a lot of research in block-cipher=20
design and cryptanalysis. I personally learned an enormous amount about=20
those topics from the AES competition, and we as a community benefited=20
immeasurably.

NIST did a great job managing the AES process, so it's the perfect=20
choice to do the same thing with hash functions. And it's doing just=20
that. Last year and the year before, NIST sponsored two workshops to=20
discuss the requirements for a new hash function, and last month it=20
announced a competition to choose a replacement for SHA-1. Submissions=20
will be due in fall 2008, and a single standard is scheduled to be=20
chosen by the end of 2011.

Yes, this is a reasonable schedule. Designing a secure hash function=20
seems harder than designing a secure encryption algorithm, although we=20
don't know whether this is inherently true of the mathematics or simply=20
a result of our imperfect knowledge. Producing a new secure hash=20
standard is going to take a while. Luckily, we have an interim solution=20
in SHA-256.

Now, if you'll excuse me, the Twofish team needs to reconstitute and get=20
to work on an Advanced Hash Standard submission.

http://en.wikipedia.org/wiki/One-way_hash_function
http://csrc.nist.gov/publications/fips/fips180-2/fips180-2withchangenotic=
e.pdf=20
or http://tinyurl.com/yrxah

SHA-1 Cryptanalysis:
http://www.schneier.com/blog/archives/2005/02/cryptanalysis_o.html
http://www.schneier.com/blog/archives/2005/08/new_cryptanalyt.html

AES:
http://www.csrc.nist.gov/publications/fips/fips197/fips-197.pdf

Twofish:
http://www.schneier.com/twofish.html

NIST Hash Competition:
http://www.csrc.nist.gov/pki/HashWorkshop/index.html
http://www.csrc.nist.gov/pki/HashWorkshop//FederalRegister/Federal%20Regi=
ster%20Notice%20for%20Requirements%20&%20Criteria%20-%20E7-927.pdf=20
or http://tinyurl.com/25mtrj
http://csrc.nist.gov/pki/HashWorkshop/timeline.html
http://www.csrc.nist.gov/pki/HashWorkshop/2005/program.htm
http://www.csrc.nist.gov/pki/HashWorkshop/2006/program_2006.htm

This essay originally appeared on Wired.com.
http://www.wired.com/news/columns/0,72657-0.html

Every time I write about one-way hash functions, I get responses from=20
people claiming they can't possibly be secure because an infinite number=20
of texts hash to the same short (160-bit, in the case of SHA-1) hash=20
value.  Yes, of course an infinite number of texts hash to the same=20
value; that's the way the function works.  But the odds of it happening=20
naturally are less than the odds of all the air molecules bunching up in=20
the corner of the room and suffocating you, and you can't force it to=20
happen, either.  Right now, several groups are trying to implement=20
Xiaoyun Wang's attack against SHA-1.  I predict one of them will find=20
two texts that hash to the same value this year -- it will demonstrate=20
that the hash function is broken and be really big news.


** *** ***** ******* *********** *************

      Comments from Readers



There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and join=20
in.

http://www.schneier.com/blog


** *** ***** ******* *********** *************

CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise.  You can=20
subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>.  Back issues are also=20
available at that URL.

Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable.  Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is the author of the=20
best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography," and an inventor of the Blowfish and Twofish algorithms.=20
He is founder and CTO of BT Counterpane, and is a member of the Board of=20
Directors of the Electronic Privacy Information Center (EPIC).  He is a=20
frequent writer and lecturer on security topics.  See=20
<http://www.schneier.com>.

BT Counterpane is the world's leading protector of networked information=20
- the inventor of outsourced security monitoring and the foremost=20
authority on effective mitigation of emerging IT threats.  BT=20
Counterpane protects networks for Fortune 1000 companies and governments=20
world-wide.  See <http://www.counterpane.com>.

Crypto-Gram is a personal newsletter.  Opinions expressed are not=20
necessarily those of BT or BT Counterpane.

Copyright (c) 2007 by Bruce Schneier.