CRYPTO-GRAM, June 15, 2007
Bruce Schneier <[email protected]> Fri, 15 Jun 2007 03:11:02 -0500
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
June 15, 2007
by Bruce Schneier
Founder and CTO
BT Counterpane
[email protected]
http://www.schneier.com
http://www.counterpane.com
A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0706.html>. These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>. An RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Rare Risk and Overreactions
Tactics, Targets, and Objectives
News
Portrait of the Modern Terrorist as an Idiot
Teaching Viruses
Bush's Watch Stolen?
Schneier/BT Counterpane News
Second Movie-Plot Threat Contest Winner
Perpetual Doghouse: Meganet
Non-Security Considerations in Security Decisions
Comments from Readers
** *** ***** ******* *********** *************
Rare Risk and Overreactions
Everyone had a reaction to the horrific events of the Virginia Tech=20
shootings. Some of those reactions were rational. Others were not.
A high school student was suspended for customizing a first-person=20
shooter game with a map of his school. A contractor was fired from his=20
government job for talking about a gun, and then visited by the police=20
when he created a comic about the incident. A dean at Yale banned=20
realistic stage weapons from the university theaters -- a policy that=20
was reversed within a day. And some teachers terrorized a sixth-grade=20
class by staging a fake gunman attack, without telling them that it was=20
a drill.
These things all happened, even though shootings like this are=20
incredibly rare; even though -- for all the press -- less than one=20
percent of homicides and suicides of children ages 5 to 19 occur in=20
schools. In fact, these overreactions occurred, not despite these facts,=20
but *because* of them.
The Virginia Tech massacre is precisely the sort of event we humans tend=20
to overreact to. Our brains aren't very good at probability and risk=20
analysis, especially when it comes to rare occurrences. We tend to=20
exaggerate spectacular, strange and rare events, and downplay ordinary,=20
familiar and common ones. There's a lot of research in the=20
psychological community about how the brain responds to risk -- some of=20
it I have already written about -- but the gist is this: Our brains are=20
much better at processing the simple risks we've had to deal with=20
throughout most of our species' existence, and much poorer at evaluating=20
the complex risks society forces us to face today.
Novelty plus dread equals overreaction.
We can see the effects of this all the time. We fear being murdered,=20
kidnapped, raped and assaulted by strangers, when it's far more likely=20
that the perpetrator of such offenses is a relative or a friend. We=20
worry about airplane crashes and rampaging shooters instead of=20
automobile crashes and domestic violence -- both far more common.
In the United States, dogs, snakes, bees and pigs each kill more people=20
per year than sharks. In fact, dogs kill more humans than any animal=20
except for other humans. Sharks are more dangerous than dogs, yes, but=20
we're far more likely to encounter dogs than sharks.
Our greatest recent overreaction to a rare event was our response to the=20
terrorist attacks of 9/11. I remember then-Attorney General John=20
Ashcroft giving a speech in Minnesota -- where I live -- in 2003, and=20
claiming that the fact there were no new terrorist attacks since 9/11=20
was proof that his policies were working. I thought: "There were no=20
terrorist attacks in the two years preceding 9/11, and you didn't have=20
any policies. What does that prove?"
What it proves is that terrorist attacks are very rare, and maybe our=20
reaction wasn't worth the enormous expense, loss of liberty, attacks on=20
our Constitution and damage to our credibility on the world stage.=20
Still, overreacting was the natural thing for us to do. Yes, it's=20
security theater, but it makes us feel safer.
People tend to base risk analysis more on personal story than on data,=20
despite the old joke that "the plural of anecdote is not data." If a=20
friend gets mugged in a foreign country, that story is more likely to=20
affect how safe you feel traveling to that country than abstract crime=20
statistics.
We give storytellers we have a relationship with more credibility than=20
strangers, and stories that are close to us more weight than stories=20
from foreign lands. In other words, proximity of relationship affects=20
our risk assessment. And who is everyone's major storyteller these=20
days? Television. (Nassim Nicholas Taleb's great book, "The Black=20
Swan: The Impact of the Highly Improbable," discusses this.)
Consider the reaction to another event from last month: professional=20
baseball player Josh Hancock got drunk and died in a car crash. As a=20
result, several baseball teams are banning alcohol in their clubhouses=20
after games. Aside from this being a ridiculous reaction to an=20
incredibly rare event (2,430 baseball games per season, 35 people per=20
clubhouse, two clubhouses per game. And how often has this happened?),=20
it makes no sense as a solution. Hancock didn't get drunk in the=20
clubhouse; he got drunk at a bar. But Major League Baseball needs to be=20
seen as doing *something*, even if that something doesn't make sense --=20
even if that something actually increases risk by forcing players to=20
drink at bars instead of at the clubhouse, where there's more control=20
over the practice.
I tell people that if it's in the news, don't worry about it. The very=20
definition of "news" is "something that hardly ever happens." It's when=20
something isn't in the news, when it's so common that it's no longer=20
news -- car crashes, domestic violence -- that you should start worrying.
But that's not the way we think. Psychologist Scott Plous said it well=20
in "The Psychology of Judgment and Decision Making": "In very general=20
terms: (1) The more *available* an event is, the more frequent or=20
probable it will seem; (2) the more *vivid* a piece of information is,=20
the more easily recalled and convincing it will be; and (3) the more=20
*salient* something is, the more likely it will be to appear causal."
So, when faced with a very available and highly vivid event like 9/11 or=20
the Virginia Tech shootings, we overreact. And when faced with all the=20
salient related events, we assume causality. We pass the Patriot Act.=20
We think if we give guns out to students, or maybe make it harder for=20
students to get guns, we'll have solved the problem. We don't let our=20
children go to playgrounds unsupervised. We stay out of the ocean=20
because we read about a shark attack somewhere.
It's our brains again. We need to "do something," even if that=20
something doesn't make sense; even if it is ineffective. And we need to=20
do something directly related to the details of the actual event. So=20
instead of implementing effective, but more general, security measures=20
to reduce the risk of terrorism, we ban box cutters on airplanes. And=20
we look back on the Virginia Tech massacre with 20-20 hindsight and=20
recriminate ourselves about the things we *should have done.
Lastly, our brains need to find someone or something to blame. (Jon=20
Stewart has an excellent bit on the Virginia Tech scapegoat search, and=20
media coverage in general.) But sometimes there is no scapegoat to be=20
found; sometimes we did everything right, but just got unlucky. We=20
simply can't prevent a lone nutcase from shooting people at random;=20
there's no security measure that would work.
As circular as it sounds, rare events are rare primarily because they=20
don't occur very often, and not because of any preventive security=20
measures. And implementing security measures to make these rare events=20
even rarer is like the joke about the guy who stomps around his house to=20
keep the elephants away.
"Elephants? There are no elephants in this neighborhood," says a neighbo=
r.
"See how well it works!"
If you want to do something that makes security sense, figure out what's=20
common among a bunch of rare events, and concentrate your=20
countermeasures there. Focus on the general risk of terrorism, and not=20
the specific threat of airplane bombings using liquid explosives. Focus=20
on the general risk of troubled young adults, and not the specific=20
threat of a lone gunman wandering around a college campus. Ignore the=20
movie-plot threats, and concentrate on the real risks.
Irrational reactions:
http://arstechnica.com/news.ars/post/20070502-student-creates-counter-str=
ike-map-gets-kicked-out-of-school.html=20
or http://tinyurl.com/2dbl67
http://www.boingboing.net/2007/05/03/webcomic_artist_fire.html
http://www.yaledailynews.com/articles/view/20843
http://yaledailynews.com/articles/view/20913
http://www.msnbc.msn.com/id/18645623/
Risks of school shootings (from 2000):
http://www.cdc.gov/HealthyYouth/injury/pdf/violenceactivities.pdf
Crime statistics -- strangers vs. acquaintances:
http://www.fbi.gov/ucr/05cius/offenses/expanded_information/data/shrtable=
_09.html=20
or http://tinyurl.com/2qbtae
Me on the psychology of risk and security:
http://www.schneier.com/essay-155.html
Risk of shark attacks:
http://www.oceanconservancy.org/site/DocServer/fsSharks.pdf
Ashcroft speech:
http://www.highbeam.com/doc/1G1-107985887.html
Me on security theater:
http://www.schneier.com/essay-154.html
Baseball beer ban:
http://blogs.csoonline.com/baseballs_big_beer_ban
Nicholas Taub essay:
http://www.fooledbyrandomness.com/nyt2.htm
http://www.telegraph.co.uk/opinion/main.jhtml?xml=3D/opinion/2007/04/22/d=
o2201.xml=20
or http://tinyurl.com/3bewfy
VA Tech and gun control:
http://abcnews.go.com/International/wireStory?id=3D3050071&CMP=3DOTC-RSSF=
eeds0312=20
or http://tinyurl.com/25js4o
http://www.cnn.com/2007/US/04/19/commentary.nugent/index.html
VA Tech hindsight:
http://news.independent.co.uk/world/americas/article2465962.ece
http://www.mercurynews.com/charliemccollum/ci_5701552
Jon Stewart video:
http://www.comedycentral.com/motherload/player.jhtml?ml_video=3D85992
Me on movie-plot threats:
http://www.schneier.com/essay-087.html
Another opinion:
http://www.socialaffairsunit.org.uk/blog/archives/000512.php
This essay originally appeared on Wired.com, my 42nd essay on that site.
http://www.wired.com/politics/security/commentary/securitymatters/2007/05=
/securitymatters_0517=20
or http://tinyurl.com/26cxcs
French translation:
http://archiloque.net/spip.php?rubriques2&periode=3D2007-06#
** *** ***** ******* *********** *************
Tactics, Targets, and Objectives
If you encounter an aggressive lion, stare him down. But not a leopard;=20
avoid his gaze at all costs. In both cases, back away slowly; don't run.=20
If you stumble on a pack of hyenas, run and climb a tree; hyenas can't=20
climb trees. But don't do that if you're being chased by an elephant;=20
he'll just knock the tree down. Stand still until he forgets about you.
I spent the last few days on safari in a South African game park, and=20
this was just some of the security advice we were all given. What's=20
interesting about this advice is how well-defined it is. The defenses=20
might not be terribly effective -- you still might get eaten, gored or=20
trampled -- but they're your best hope. Doing something else isn't=20
advised, because animals do the same things over and over again. These=20
are security countermeasures against specific tactics.
Lions and leopards learn tactics that work for them, and I was taught=20
tactics to defend myself. Humans are intelligent, and that means we are=20
more adaptable than animals. But we're also, generally speaking, lazy=20
and stupid; and, like a lion or hyena, we will repeat tactics that work.=20
Pickpockets use the same tricks over and over again. So do phishers, and=20
school shooters. If improvised explosive devices didn't work often=20
enough, Iraqi insurgents would do something else.
So security against people generally focuses on tactics as well.
A friend of mine recently asked me where she should hide her jewelry in=20
her apartment, so that burglars wouldn't find it. Burglars tend to look=20
in the same places all the time -- dresser tops, night tables, dresser=20
drawers, bathroom counters -- so hiding valuables somewhere else is more=20
likely to be effective, especially against a burglar who is pressed for=20
time. Leave decoy cash and jewelry in an obvious place so a burglar will=20
think he's found your stash and then leave. Again, there's no guarantee=20
of success, but it's your best hope.
The key to these countermeasures is to find the pattern: the common=20
attack tactic that is worth defending against. That takes data. A single=20
instance of an attack that didn't work -- liquid bombs, shoe bombs -- or=20
one instance that did -- 9/11 -- is not a pattern. Implementing=20
defensive tactics against them is the same as my safari guide saying:=20
"We've only ever heard of one tourist encountering a lion. He stared it=20
down and survived. Another tourist tried the same thing with a leopard,=20
and he got eaten. So when you see a lion...." The advice I was given was=20
based on thousands of years of collective wisdom from people=20
encountering African animals again and again.
Compare this with the Transportation Security Administration's approach.=20
With every unique threat, TSA implements a countermeasure with no basis=20
to say that it helps, or that the threat will ever recur.
Furthermore, human attackers can adapt more quickly than lions. A lion=20
won't learn that he should ignore people who stare him down, and eat=20
them anyway. But people will learn. Burglars now know the common=20
"secret" places people hide their valuables -- the toilet, cereal boxes,=20
the refrigerator and freezer, the medicine cabinet, under the bed -- and=20
look there. I told my friend to find a different secret place, and to=20
put decoy valuables in a more obvious place.
This is the arms race of security. Common attack tactics result in=20
common countermeasures. Eventually, those countermeasures will be evaded=20
and new attack tactics developed. These, in turn, require new=20
countermeasures. You can easily see this in the constant arms race that=20
is credit card fraud, ATM fraud or automobile theft.
The result of these tactic-specific security countermeasures is to make=20
the attacker go elsewhere. For the most part, the attacker doesn't=20
particularly care about the target. Lions don't care who or what they=20
eat; to a lion, you're just a conveniently packaged bag of protein.=20
Burglars don't care which house they rob, and terrorists don't care who=20
they kill. If your countermeasure makes the lion attack an impala=20
instead of you, or if your burglar alarm makes the burglar rob the house=20
next door instead of yours, that's a win for you.
Tactics matter less if the attacker is after you personally. If, for=20
example, you have a priceless painting hanging in your living room and=20
the burglar knows it, he's not going to rob the house next door instead=20
-- even if you have a burglar alarm. He's going to figure out how to=20
defeat your system. Or he'll stop you at gunpoint and force you to open=20
the door. Or he'll pose as an air-conditioner repairman. What matters is=20
the target, and a good attacker will consider a variety of tactics to=20
reach his target.
This approach requires a different kind of countermeasure, but it's=20
still well-understood in the security world. For people, it's what alarm=20
companies, insurance companies and bodyguards specialize in. President=20
Bush needs a different level of protection against targeted attacks than=20
Bill Gates does, and I need a different level of protection than either=20
of them. It would be foolish of me to hire bodyguards in case someone=20
was targeting me for robbery or kidnapping. Yes, I would be more secure,=20
but it's not a good security trade-off.
Al-Qaeda terrorism is different yet again. The goal is to terrorize. It=20
doesn't care about the target, but it doesn't have any pattern of=20
tactic, either. Given that, the best way to spend our counterterrorism=20
dollar is on intelligence, investigation and emergency response. And to=20
refuse to be terrorized.
These measures are effective because they don't assume any particular=20
tactic, and they don't assume any particular target. We should only=20
apply specific countermeasures when the cost-benefit ratio makes sense=20
(reinforcing airplane cockpit doors) or when a specific tactic is=20
repeatedly observed (lions attacking people who don't stare them down).=20
Otherwise, general countermeasures are far more effective a defense.
Safari security advice:
http://www.cybertracker.co.za/DangerousAnimals.html
School shooter security advice:
http://www.ucpd.ucla.edu/ucpd/zippdf/2007/Active%20Shooter%20Safety%20Tip=
s.pdf=20
or http://tinyurl.com/2qvgyg
Burglar security advice:
http://www.pfadvice.com/2007/02/05/the-best-place-to-hide-money-conversat=
ion-with-a-burglar/=20
or http://tinyurl.com/ywdoy9
http://www.pfadvice.com/2007/03/06/dont-hide-money-in-the-toilet-more-con=
versation-with-a-burglar/=20
or http://tinyurl.com/236wbs
Me on terrorism:
http://www.schneier.com/essay-096.html
http://www.schneier.com/blog/archives/2006/08/terrorism_secur.html
http://www.schneier.com/blog/archives/2005/09/katrina_and_sec.html
http://www.schneier.com/blog/archives/2006/08/what_the_terror.html
Learning behavior in tigers:
http://www.cptigers.org/animals/species.asp?speciesID=3D9
This essay originally appeared on Wired.com.
http://www.wired.com/print/politics/security/commentary/securitymatters/2=
007/05/securitymatters_0531=20
or http://tinyurl.com/2zdghw
** *** ***** ******* *********** *************
News
In an effort to prevent terrorism, parts of the mobile phone network=20
will be disabled when President Bush visits Australia. I've written=20
about this kind of thing before; it's a perfect example of security=20
theater: a countermeasure that works if you happen to guess the specific=20
details of the plot correctly, and completely useless otherwise. On the=20
plus side, it's only a small area that's blocked.
http://www.smh.com.au/news/NATIONAL/Mobiles-to-drop-out-during-Bush-visit=
/2007/05/16/1178995171116.html=20
or http://tinyurl.com/2e8nbo
http://www.schneier.com/blog/archives/2007/04/triggering_bomb.html
http://it.slashdot.org/it/07/05/17/1221255.shtml
http://www.theregister.co.uk/2007/05/18/black_helicopter_george_bush_down=
_under/=20
or http://tinyurl.com/2p266j
Dan Geer writes about security trade-offs, monoculture, and genetic=20
diversity in honeybees:
http://geer.tinho.net/acm.geer.0704.pdf
The e-mail EPIC Alert comes out twice a week from the Electronic Privacy=20
Information Center. It's a great resource for information on privacy=20
and policy, both in the U.S. and abroad.
http://www.epic.org/alert/
WEP attack researchers explain how their attack on the 802.11 wireless=20
security protocol works.
http://www.theregister.co.uk/2007/05/15/wep_crack_interview/
http://www.schneier.com/blog/archives/2007/05/interview_with_5.html
Airline security cartoon -- literal CYA security:
http://www.clarionledger.com/misc/blogs/mramsey/uploaded_images/bilde-2-7=
80665.jpg=20
or http://tinyurl.com/2as767
Funny "Saturday Night Live" TSA skit:
http://www.youtube.com/watch?v=3DykzqFz_nHZE
Here's a joke that'll get you arrested:
http://www.schneier.com/blog/archives/2007/05/joke_thatll_get_1.html
London is running a dirty-bomb drill. Mostly a movie-plot threat, but=20
these sorts of drills are useful, regardless of the scenario. Honestly,=20
though, plain old explosives are much more of a risk than these exotic=20
bombs. Although with a dirty bomb, the media-inspired panic would=20
certainly be a huge factor.
http://www.theregister.co.uk/2007/05/18/dirty_bomb_test_in_marylebone/
We have a new factoring record: 307 digits (1023 bits). It's a special=20
number -- 2^1039 - 1 -- but the techniques can be generalized. Expect=20
regular 1024-bit numbers to be factored soon. I hope RSA application=20
users would have moved away from 1024-bit security years ago, but for=20
those who haven't yet: wake up.
http://www.physorg.com/news98962171.html
On the futility of fighting online pirates:
http://www.forbes.com/2007/05/04/youtube-piratesbay-piracy-tech-cx_ag_050=
7pirates.htmlhttp://yro.slashdot.org/yro/07/05/17/1749259.shtml=20
or http://tinyurl.com/28rwnm
Good article on image spam:
http://csoonline.com/read/040107/fea_spam.html
Definitely look at the interactive graphics page.
http://csoonline.com/read/040107/fea_spam_by_the_numbers.html
>From the U.S. GAO: "Aviation Security: Efforts to Strengthen=20
International Prescreening are Under Way, but Planning and=20
Implementations Remain," May 2007. Worth reading the summary, at least.
http://www.gao.gov/new.items/d07346.pdf
The TSA airport security screeners caught a guy in a fake uniform. It=20
reads like a joke. We spend billions on airport security, and we have=20
so little to show for it that the TSA has to make a big deal about the=20
crime of impersonating a member of the military?
http://www.tsa.gov/press/happenings/florida_uniform.shtm
UK police using military drones: yet another step in the militarization=20
of the police.
http://news.bbc.co.uk/1/hi/england/merseyside/6676809.stm
Criminals hijack large web hosting firm. "The company claims to have=20
more than 700,000 customers. If we assume for the moment the small=20
segment of IPOWER servers Security Fix analyzed is fairly representative=20
of a larger trend, IPOWER may well be home to nearly a quarter-million=20
malicious Web sites."
http://blog.washingtonpost.com/securityfix/2007/05/cyber_crooks_hijack_ac=
tivities_1.html=20
or http://tinyurl.com/ysbalr
The FBI has lousy security against insider attacks, according to a GAO=20
report.
http://www.pcworld.com/article/id,132250-c,privacysecurity/article.html=20
or http://tinyurl.com/yt86mg
Interesting spoofing attack:
http://www.theregister.co.uk/2007/05/25/strange_spoofing_technique/
I thought terrorism is why we have a DHS, but they've been preoccupied=20
with other things: "Of the 814,073 people charged by DHS in immigration=20
courts during the past three years, 12 faced charges of terrorism, TRAC=20
said." TRAC is a great group, and I recommend wandering around their=20
site if you're interested in what the U.S. government is actually doing.
http://www.cnn.com/2007/POLITICS/05/27/homeland.security.record/index.htm=
l=20
or http://tinyurl.com/3xre8e
http://trac.syr.edu/
Last November, the Data Privacy and Integrity Advisory Committee of the=20
Department of Homeland Security recommended against putting RFID chips=20
in identity cards. DHS ignored them, and went ahead with the project=20
anyway. Now, the Smart Card Alliance is criticizing the DHS's RFID=20
program for cross-border identification -- the People Access Security=20
Services (PASS) cards -- basically saying that it is making the very=20
mistakes the Data Privacy and Integrity Advisory Committee warned about.
http://www.gcn.com/online/vol1_no1/44338-1.html
http://www.schneier.com/blog/archives/2006/11/dhs_privacy_com.html
http://www.schneier.com/blog/archives/2007/05/rfid_in_people.html
This is a surreal story from 2005 of someone who was chained up for=20
hours for trying to spend $2 bills. Clerks at Best Buy thought the=20
bills were counterfeit, and had him arrested. The most surreal quote of=20
the article is the last sentence: "Commenting on the incident,=20
Baltimore County police spokesman Bill Toohey told the Sun: 'It's a sign=20
that we're all a little nervous in the post-9/11 world.'" What in the=20
world do the terrorist attacks of 9/11 have to do with counterfeiting?=20
How does being "a little nervous in the post-9/11 world" have anything=20
to do with this incident? Counterfeiting is not terrorism; it isn't=20
even a little bit like terrorism.
http://www.worldnetdaily.com/news/article.asp?ARTICLE_ID=3D43685
Port defense against swimming terrorists: cool science and engineering,=20
but definitely a movie-plot threat.
http://blog.wired.com/defense/2007/05/how_to_stop_a_s.html
DHS uses actual science-fiction writers to help develop movie-plot=20
threats. At least they're honest about it this time.
http://www.usatoday.com/tech/science/2007-05-29-deviant-thinkers-security=
_N.htm=20
or http://tinyurl.com/3cys5h
Head-mounted police cameras in the UK:
http://www.manchestereveningnews.co.uk/news/s/1007/1007600_super_wardens_=
go_on_patrol.html=20
or http://tinyurl.com/29tdzr
I haven't written anything about the cyberwar between Russia and Estonia=20
because, well, because I didn't think there was anything new to say. We=20
know that this kind of thing is possible. We don't have any definitive=20
proof that Russia was behind it. But it would be foolish to think that=20
the various world's militaries don't have capabilities like this. And=20
anyway, I wrote about cyberwar back in January 2005.
http://www.schneier.com/crypto-gram-0501.html#10
Information leakage in the Slingbox:
http://www.freedom-to-tinker.com/?p=3D1163
http://www.cs.washington.edu/research/security/usenix07devices.html
Outfitting moths with sensors:
http://government.zdnet.com/?p=3D3189
Teaching computers how to forget: an article on the huge amount of data=20
that now follows us through life, and whether we'd be better off it=20
computers "forgot" things after a set amount of time:
http://arstechnica.com/news.ars/post/20070509-escaping-the-data-panoptico=
n-teaching-computers-to-forget.html=20
or http://tinyurl.com/272629
http://ksgnotes1.harvard.edu/Research/wpaper.nsf/rwp/RWP07-022/$File/rwp_=
07_022_mayer-schoenberger.pdf=20
or http://tinyurl.com/yq8llf
More about this issue:
http://www.concurringopinions.com/archives/2007/05/the_right_to_de.html=20
or http://tinyurl.com/2fhlgb
http://www.harvardlawreview.org/forum/issues/119/dec05/ohm.shtml
http://www.lcs.gov.bc.ca/privacyaccess/Conferences/Feb2007/ConfPresentati=
ons/Perlman-Radia-keynote.pdf=20
or http://tinyurl.com/345rte
http://www.washingtonpost.com/wp-dyn/content/article/2007/05/15/AR2007051=
501873.html=20
or http://tinyurl.com/2o9kw5
I've written about this, too:
http://www.schneier.com/essay-109.html
http://www.schneier.com/essay-129.html
There have been some interesting court cases in the U.S. about computer=20
searches and third-party consent:
http://www.law.com/jsp/article.jsp?id=3D1179092588804
http://www.wired.com/politics/law/commentary/circuitcourt/2007/05/circuit=
court_0523=20
or http://tinyurl.com/2gr7om
Interesting terrorism statistics: "The majority of terrorist attacks=20
result in no fatalities, with just 1 percent of such attacks causing the=20
deaths of 25 or more people.... The database identifies more than=20
30,000 bombings, 13,400 assassinations and 3,200 kidnappings. Also, it=20
details more than 1,200 terrorist attacks within the United States." A=20
lot of this depends on your definition of "terrorism," but it's=20
interesting stuff.
http://www.livescience.com/history/070524_terrorism_database.html
http://www.start.umd.edu/data/gtd/
The Department of Homeland Security is soliciting research proposals in=20
computer and network security. There are nine research areas: Botnets=20
and Other Malware: Detection and Mitigation, Composable and Scalable=20
Secure Systems, Cyber Security Metrics, Network Data Visualization for=20
Information Assurance, Internet Tomography/Topography, Routing Security=20
Management Tool, Process Control System Security, Data Anonymization=20
Tools and Techniques, and Insider Threat Detection and Mitigation.
http://www.hsarpabaa.com/Solicitations/BAA07-09_CyberSecurityRD_Posted_05=
162007.pdf=20
or http://tinyurl.com/yv85ne
Remote metal sensors used to detect poachers. I'm sure this technology=20
has more value on the battlefield.
http://www.technologyreview.com/Biotech/18722/
The Data Privacy and Integrity Advisory Committee of the Department of=20
Homeland Security has issued an excellent report on REAL ID:
http://www.dhs.gov/xlibrary/assets/privacy/privacy_advcom_05-2007_realid.=
pdf=20
or http://tinyurl.com/2bbyqv
Great article on perceived vs. actual risks to children, and how overly=20
protecting them can actually cause harm.
http://news.bbc.co.uk/1/hi/education/6720661.stm
Commentary:
http://www.timesonline.co.uk/tol/comment/columnists/alice_miles/article18=
90234.ece=20
or http://tinyurl.com/3bthca
Two shielding stories:
Special underwear protects wearers from infrared photographers.
http://inventorspot.com/new_shot_guard_underwear_infrared_protection_phot=
ographers=20
or http://tinyurl.com/2mjap4
And a window film that blocks electromagnetic radiation but lets in light=
.
http://www.stltoday.com/stltoday/business/stories.nsf/0/F1B4A7E978173C108=
62572E7000AA32B?OpenDocument=20
or http://tinyurl.com/2ax9gd
Somehow, I don't see either becoming a mass-market consumer item,=20
although I can certainly imagine military facilities installing the latte=
r.
The DHS wants universities to inventory a long list of chemicals.=20
Interesting stuff about specific chemicals in the article.
http://www.theregister.co.uk/2007/06/02/dhs_dud_interesting_chemicals/
DNA-based watermarks. It's not cryptography -- despite the name -- but=20
it's interesting.
http://www.biomedcentral.com/1471-2105/8/176/abstract
New directions in malware: evasive malicious code. Just another step in=20
the never-ending arms race of network security.
http://news.zdnet.co.uk/security/0,1000000189,39287357,00.htm
More on Kish's encryption scheme:
http://www.arxiv.org/abs/physics/0612153
And a paper claiming this is totally insecure:
http://www.lightbluetouchpaper.org/2006/10/08/kishs-totally-secure-system=
-is-insecure/=20
or http://tinyurl.com/2y87wx
Again, I don't have the EE background to know who's right. But this is=20
exactly the sort of back-and-forth I want to see. My previous article=20
on the topic:
http://www.schneier.com/essay-099.html
The growing problem of license plate cloning:
http://news.bbc.co.uk/1/hi/uk/6707367.stm
Interesting paper: "Data Mining and the Security-Liberty Debate," by=20
Daniel J. Solove.
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D990030
Dorky real-life/Second-Life security awareness video:
http://www.youtube.com/watch?v=3DWMe3gbC-dXc
According to the Kennedy Space Center website, "stand alone GPS=20
equipment is not permitted on property." It's okay if they're embedded=20
in your phone or computer, though.
http://www.kennedyspacecenter.com/visitKSC/NASAtours/security.asp
** *** ***** ******* *********** *************
Portrait of the Modern Terrorist as an Idiot
The recently publicized terrorist plot to blow up John F. Kennedy=20
International Airport, like so many of the terrorist plots over the past=20
few years, is a study in alarmism and incompetence: on the part of the=20
terrorists, our government and the press.
Terrorism is a real threat, and one that needs to be addressed by=20
appropriate means. But allowing ourselves to be terrorized by wannabe=20
terrorists and unrealistic plots -- and worse, allowing our essential=20
freedoms to be lost by using them as an excuse -- is wrong.
The alleged plan, to blow up JFK's fuel tanks and a small segment of the=20
40-mile petroleum pipeline that supplies the airport, was ridiculous.=20
The fuel tanks are thick-walled, making them hard to damage. The airport=20
tanks are separated from the pipelines by cutoff valves, so even if a=20
fire broke out at the tanks, it would not back up into the pipelines.=20
And the pipeline couldn't blow up in any case, since there's no oxygen=20
to aid combustion. Not that the terrorists ever got to the stage -- or=20
demonstrated that they could get there -- where they actually obtained=20
explosives. Or even a current map of the airport's infrastructure.
But read what Russell Defreitas, the lead terrorist, had to say:=20
"Anytime you hit Kennedy, it is the most hurtful thing to the United=20
States. To hit John F. Kennedy, wow.... They love JFK -- he's like the=20
man. If you hit that, the whole country will be in mourning. It's like=20
you can kill the man twice."
If these are the terrorists we're fighting, we've got a pretty=20
incompetent enemy.
You couldn't tell that from the press reports, though. "The devastation=20
that would be caused had this plot succeeded is just unthinkable," U.S.=20
Attorney Roslynn R. Mauskopf said at a news conference, calling it "one=20
of the most chilling plots imaginable." Sen. Arlen Specter=20
(R-Pennsylvania) added, "It had the potential to be another 9/11."
These people are just as deluded as Defreitas.
The only voice of reason out there seemed to be New York's Mayor Michael=20
Bloomberg, who said: "There are lots of threats to you in the world.=20
There's the threat of a heart attack for genetic reasons. You can't sit=20
there and worry about everything. Get a life.... You have a much greater=20
danger of being hit by lightning than being struck by a terrorist."
And he was widely excoriated for it.
This isn't the first time a bunch of incompetent terrorists with an=20
infeasible plot have been painted by the media as poised to do all sorts=20
of damage to America. In May we learned about a six-man plan to stage an=20
attack on Fort Dix by getting in disguised as pizza deliverymen and=20
shooting as many soldiers and Humvees as they could, then retreating=20
without losses to fight again another day. Their plan, such as it was,=20
went awry when they took a videotape of themselves at weapons practice=20
to a store for duplication and transfer to DVD. The store clerk=20
contacted the police, who in turn contacted the FBI. (Thank you to the=20
video store clerk for not overreacting, and to the FBI agent for=20
infiltrating the group.)
The "Miami 7," caught last year for plotting -- among other things -- to=20
blow up the Sears Tower, were another incompetent group: no weapons, no=20
bombs, no expertise, no money and no operational skill. And don't forget=20
Iyman Faris, the Ohio trucker who was convicted in 2003 for the=20
laughable plot to take out the Brooklyn Bridge with a blowtorch. At=20
least he eventually decided that the plan was unlikely to succeed.
I don't think these nut jobs, with their movie-plot threats, even=20
deserve the moniker "terrorist." But in this country, while you have to=20
be competent to pull off a terrorist attack, you don't have to be=20
competent to cause terror. All you need to do is start plotting an=20
attack and -- regardless of whether or not you have a viable plan,=20
weapons or even the faintest clue -- the media will aid you in=20
terrorizing the entire population.
The most ridiculous JFK Airport-related story goes to the New York Daily=20
News, with its interview with a waitress who served Defreitas salmon;=20
the front-page headline blared, "Evil Ate at Table Eight."
Following one of these abortive terror misadventures, the administration=20
invariably jumps on the news to trumpet whatever ineffective "security"=20
measure they're trying to push, whether it be national ID cards,=20
wholesale National Security Agency eavesdropping or massive data mining.=20
Never mind that in all these cases, what caught the bad guys was=20
old-fashioned police work -- the kind of thing you'd see in decades-old=20
spy movies.
The administration repeatedly credited the apprehension of Faris to the=20
NSA's warrantless eavesdropping programs, even though it's just not=20
true. The 9/11 terrorists were no different; they succeeded partly=20
because the FBI and CIA didn't follow the leads before the attacks.
Even the London liquid bombers were caught through traditional=20
investigation and intelligence, but this doesn't stop Secretary of=20
Homeland Security Michael Chertoff from using them to justify access to=20
airline passenger data.
Of course, even incompetent terrorists can cause damage. This has been=20
repeatedly proven in Israel, and if shoe-bomber Richard Reid had been=20
just a little less stupid and ignited his shoes in the lavatory, he=20
might have taken out an airplane.
So these people should be locked up ... assuming they are actually=20
guilty, that is. Despite the initial press frenzies, the actual details=20
of the cases frequently turn out to be far less damning. Too often it's=20
unclear whether the defendants are actually guilty, or if the police=20
created a crime where none existed before.
The JFK Airport plotters seem to have been egged on by an informant, a=20
twice-convicted drug dealer. An FBI informant almost certainly pushed=20
the Fort Dix plotters to do things they wouldn't have ordinarily done.=20
The Miami gang's Sears Tower plot was suggested by an FBI undercover=20
agent who infiltrated the group. And in 2003, it took an elaborate sting=20
operation involving three countries to arrest an arms dealer for selling=20
a surface-to-air missile to an ostensible Muslim extremist. Entrapment=20
is a very real possibility in all of these cases.
The rest of them stink of exaggeration. Jose Padilla was not actually=20
prepared to detonate a dirty bomb in the United States, despite=20
histrionic administration claims to the contrary. Now that the trial is=20
proceeding, the best the government can charge him with is conspiracy to=20
murder, kidnap and maim, and it seems unlikely that the charges will=20
stick. An alleged ringleader of the U.K. liquid bombers, Rashid Rauf,=20
had charges of terrorism dropped for lack of evidence (of the 25=20
arrested, only 16 were charged). And now it seems like the JFK=20
mastermind was more talk than action, too.
Remember the "Lackawanna Six," those terrorists from upstate New York=20
who pleaded guilty in 2003 to "providing support or resources to a=20
foreign terrorist organization"? They entered their plea because they=20
were threatened with being removed from the legal system altogether. We=20
have no idea if they were actually guilty, or of what.
Even under the best of circumstances, these are difficult prosecutions.=20
Arresting people before they've carried out their plans means trying to=20
prove intent, which rapidly slips into the province of thought crime.=20
Regularly the prosecution uses obtuse religious literature in the=20
defendants' homes to prove what they believe, and this can result in=20
courtroom debates on Islamic theology. And then there's the issue of=20
demonstrating a connection between a book on a shelf and an idea in the=20
defendant's head, as if your reading of this article -- or purchasing of=20
my book -- proves that you agree with everything I say. (The Atlantic=20
recently published a fascinating article on this.)
I'll be the first to admit that I don't have all the facts in any of=20
these cases. None of us do. So let's have some healthy skepticism.=20
Skepticism when we read about these terrorist masterminds who were=20
poised to kill thousands of people and do incalculable damage.=20
Skepticism when we're told that their arrest proves that we need to give=20
away our own freedoms and liberties. And skepticism that those arrested=20
are even guilty in the first place.
There is a real threat of terrorism. And while I'm all in favor of the=20
terrorists' continuing incompetence, I know that some will prove more=20
capable. We need real security that doesn't require us to guess the=20
tactic or the target: intelligence and investigation -- the very things=20
that caught all these terrorist wannabes -- and emergency response. But=20
the "war on terror" rhetoric is more politics than rationality. We=20
shouldn't let the politics of fear make us less safe.
There a zillion links associated with this essay. You can find them on=20
the online version:
http://www.schneier.com/blog/archives/2007/06/portrait_of_the.html
This essay originally appeared on Wired.com:
http://www.wired.com/politics/security/commentary/securitymatters/2007/06=
/securitymatters_0614=20
or http://tinyurl.com/29mxc5
** *** ***** ******* *********** *************
Teaching Viruses
Over two years ago, George Ledin wrote an essay in "Communications of=20
the ACM," where he advocated teaching worms and viruses to computer=20
science majors: "Computer science students should learn to recognize,=20
analyze, disable, and remove malware. To do so, they must study=20
currently circulating viruses and worms, and program their own.=20
Programming is to computer science what field training is to police work=20
and clinical experience is to surgery. Reading a book is not enough. Why=20
does industry hire convicted hackers as security consultants? Because we=20
have failed to educate our majors."
This spring semester, he taught the course at Sonoma State University.=20
It got a lot of press coverage. No one wrote a virus for a class=20
project. No new malware got into the wild. No new breed of=20
supervillain graduated.
Teaching this stuff is just plain smart.
Essay:
http://www.csl.sri.com/neumann/insiderisks05.html#175
http://www.sonoma.edu/pubs/newsrelease/archives/001090.html
http://www1.pressdemocrat.com/apps/pbcs.dll/article?AID=3D/20070522/NEWS/=
705220312/1033/NEWS01=20
or http://tinyurl.com/ytrbzs
http://blogs.pcworld.com/staffblog/archives/004452.html
http://www1.pressdemocrat.com/apps/pbcs.dll/article?AID=3D/20070526/NEWS/=
705260309/1043/OPINION01=20
or http://tinyurl.com/2e2anv
http://www.hardocp.com/news.html?news=3DMjU5NzgsLCxoZW50aHVzaWFzdCwsLDE
http://technews.acm.org/archives.cfm?fo=3D2007-05-may/may-25-2007.html#31=
3412=20
or http://tinyurl.com/yuur5l
http://www.calstate.edu/pa/clips2007/may/22may/virus.shtml
** *** ***** ******* *********** *************
Bush's Watch Stolen?
Watch the video very carefully; it's President Bush working the crowds=20
in Albania. 0.50 seconds into the clip, Bush has a watch. 1.04 seconds=20
into the clip, he had a watch.
The U.S. is denying that his watch was stolen: "Photographs showed=20
Bush, surrounded by five bodyguards, putting his hands behind his back=20
so one of the bodyguards could remove his watch."
I simply don't see that in the video. Bush's arm is out in front of him=20
during the entire nine seconds between those stills.
Another denial: "An Albanian bodyguard who accompanied Bush in the town=20
told The Associated Press he had seen one of his U.S. colleagues close=20
to Bush bend down and pick up the watch."
That's certainly possible; it may have fallen off.
But possibly the pickpocket of the century. (Although would anyone=20
actually be stupid enough to try? There must be a zillion=20
easier-to-steal watches in that crowd, many of them nicer than Bush's.)
Video clip:
http://www.youtube.com/watch?v=3DPKDdF6vfjoo
Denials:
http://uk.reuters.com/article/oddlyEnoughNews/idUKL1285325620070612
http://www.guardian.co.uk/worldlatest/story/0,,-6703190,00.html
** *** ***** ******* *********** *************
Schneier/BT Counterpane News
Interview with me from "Infosecurity Magazine":
http://www.infosecurity-magazine.com/features/mayjune07/interview_schneie=
r.html=20
or http://tinyurl.com/2cvs45
Interview with me from IT Security:
http://www.itsecurity.com/interviews/interview-bruice-schneier-051607/
At the kickoff reception for the IT Security Summit in Johannesburg,=20
there was a bit of industrial theater about identity theft. Someone=20
tried to pretend he was me; it was pretty funny, really. Someone=20
captured my discussion after on video.
http://blogs.zdnet.com/threatchaos/?p=3D458
Two interviews with me in Norwegian:
http://www.dagensit.no/bedrifts-it/article1104925.ece
http://www.digi.no/php/art.php?id=3D384118
Schneier is speaking at the I-4 Conference on June 25th in Milan.
https://i4online.com/
Schneier is speaking at Secure 2007 on June 26th in Bad Homburg, Germany.
http://www.secure2007.de/
** *** ***** ******* *********** *************
Second Movie-Plot Threat Contest Winner
On April 1, I announced the Second Annual Movie-Plot Threat Contest:
"Your goal: invent a terrorist plot to hijack or blow up an airplane=20
with a commonly carried item as a key component. The component should be=20
so critical to the plot that the TSA will have no choice but to ban the=20
item once the plot is uncovered. I want to see a plot horrific and=20
ridiculous, but just plausible enough to take seriously.
"Make the TSA ban wristwatches. Or laptop computers. Or polyester. Or=20
zippers over three inches long. You get the idea.
"Your entry will be judged on the common item that the TSA has no choice=20
but to ban, as well as the cleverness of the plot. It has to be=20
realistic; no science fiction, please. And the write-up is critical;=20
last year the best entries were the most entertaining to read."
On June 5, I posted three semi-finalists out of the 334 comments:
* Butterflies and beverages; water must be banned.
* Dimethylmercury; security checkpoints must be banned, but of course=20
they can't be. Oh, what to do!
* Oxy-hydrogen bomb; wires -- earphones, power cables, etc. -- must be=20
banned.
Well, we have a winner. I can't divulge the exact formula -- because=20
you'll all hack the system next year -- but it was a combination of my=20
opinion, popular acclaim in blog comments, and the opinion of Tom Grant=20
(the previous year's winner -- not his real name).
The winner is: "Butterflies and Beverages," posted by Ron. (Ron gets=20
signed copies of my books, a $50 Amazon gift certificate contributed by=20
a reader, and -- if I can find one -- an interview with a real-live=20
movie director. (Does anyone know one?) We hope that one of his prizes=20
isn't a visit by the FBI.)
Here is the winning entry:
It must have been a pretty meadow, Wilkes thought, just a day before. He=20
tried to picture how it looked then: without the long, wide wound in the=20
earth, without the charred and broken fuselage of the jet that gouged it=20
out, before the rolling ground was strewn with papers and cushions and=20
random bits of plastic and fabric and all the things inside the plane=20
that lay like the confetti from a brief, fiery parade.
Yes, a nice little spot, just far enough from the airport's runways to=20
be not too noisy, but close enough to watch the planes going in and out,=20
fortunately just a bit too close to have been developed. When the plane=20
rolled over and angled downward, not even a mile past the end of the=20
runway, at least the only people at risk were the ones on the plane. For=20
them, it was mercifully quick, the impact breaking their necks before=20
the breaking wing tanks ignited in sheets of flame, the charred bodies=20
still in their seats.
He spotted the NTSB guy, standing by the forward half of the fuselage,=20
easy to spot among the FAA and local airport people -- they were always=20
the only suits in the crowd. Heading over, Wilkes saw this one wasn't=20
going to be too hard: when planes came down intact like this, breaking=20
in to just a few pieces on impact, the cause was always easier to find.=20
This one looked to be no exception.
He muttered to the suit, "Wilkes," gesturing at the badge clipped to his=20
shirt. No need to get too friendly, they'd file separate reports anyway.=20
As long as they were remotely on the same page, there wasn't much need=20
to actually talk to the guy. "What's this little gem?" he wondered=20
aloud, looking at the hole in the side of the downed jet.
"Explosion," drawled the NTSB guy; he had that Chuck Yeager slow-play=20
sound, Wilkes thought, like someone who could sound calm describing=20
Armageddon. "Looks like it was from the inside, something just big=20
enough to rip a few square feet out of the side. Enough to throw it on=20
its side"
"And if the plane is low enough, still taking off, with the engines near=20
full thrust, it rolls over and down too fast=85" he trailed off, picturin=
g=20
the result.
"Yep, all in a couple of seconds. Too quick for the flight crew to have=20
time to get it back." The NTSB guy shook his head, the id clipped to his=20
suit jacket swaying back and forth with the motion. "Always the best=20
time if you're going to take a bird down: takeoff or landing, guess=20
whoever did this one wanted to get it over with sooner rather than=20
later." He snorted in derision, "Somebody snuck in an explosive, must=20
have been a screener havin' an off day."
"Maybe," said Wilkes, not ready to write it off as just a screener's=20
error. The NTSB guys were always quick to find a bad decision, one human=20
error, and explain the whole thing away. But Wilkes' job was to find the=20
flaws in the systems, the procedures, the way to come up with=20
prophylactic precautions. Maybe there was nothing more than a screener=20
who didn't spot a grenade or a stick of dynamite, something so obvious=20
that there was nothing to do but chalk up a hundred and eighty three=20
dead lives to one madman and one very bad TSA employee.
But maybe not. That's when Wilkes spotted the first two of the=20
butterflies. Bright yellow against the charred black of the burned=20
wreckage, they seemed like the most incongruous things -- and as he=20
thought this, another appeared.
As they took photos and made measurements, more showed up -- by ones and=20
twos, a few flying away, but gradually building up to dozens over the=20
course of the morning. Odd, the NTSB rep agreed, but nothing that tells=20
us anything about the terrorist who brought down that plane.
Wilkes wasn't so sure. Nature was handing out a big fat clue here, he=20
was sure of that. What he wasn't sure of was what in the hell it could=20
possibly mean.
He leaned in close with the camera on his phone, getting some good close=20
images of the colorful insects, emailing back to the office with a=20
request to reach out to an expert. He needed a phone consult, someone=20
who knew the behavior of this particular butterfly, someone who could=20
put him on the right track.
Within minutes, his phone was buzzing, with a conference call already=20
set up with a professor of entomology, and even better one local to the=20
area; a local might know this bug better than an academic from a more=20
prestigious, but distant university.
He was half-listening during the introductions, Wilkes wasn't interested=20
in this guy's particulars, the regional team would have that all=20
available if he needed it later. He just wanted answers.
"Pieridae," the professor offered, "and all males, I'd bet."
"Okay," Wilkes answered, wondering if he this really would tell him=20
anything. "Why are they all over my bomb hole?"
"I can't be sure, but it must be something attracting them. These are=20
commonly called 'sulfur butterflies', could there be sulfur on your=20
wreckage?"
Yeah, Wilkes thought, this is looking like a wild goose chase. "No=20
sulfur, we already did a quick chem test for it. Anything else these=20
little fellas like?"
"Sure, but not something you'd be likely to find in a bomb -- just=20
sodium. They package it up with their sperm and deliver it to the female=20
as an extra little bonus -- sort of the flowers and candy of the=20
butterfly world."
"Okay, that's=85wow, the things I learn in this job. Sorry to bother you,=
=20
sir, I guess it's just=85yeah, thanks."
Butterfly sperm -- now this might set a new record for useless trivia=20
learned in a crash investigation. Unbelievable.
The NTSB guy wandered over, seeing Wilkes was off the phone. "Get=20
anything from your expert?" he queried, trying and failing to suppress a=20
grin. Wilkes suspected there would soon be a story going around the NTSB=20
office about the FAA "butterfly guy"; ah well, better to be infamous=20
than anonymous.
"Nah, not much. The little guys like sulfur," Wilkes offered, seeing his=20
counterpart give a cynical chuckle at that, "and sodium. Unless there=20
was a whole lot of salt packed around the perp's explosive, our little=20
yellow friends are just a mystery."
The NTSB rep got a funny look on his face, a faraway look. "Sodium. An=20
explosive that leaves behind sodium. Well, that could be=85"
They looked at each other, both heading to the same conclusion, both=20
reluctant to get there. Wilkes said it first: "Sodium metal. Cheap, easy=20
to get, it would have to be: sodium metal."
"And easy," the NTSB rep drawled, "to sneak on the plane. The stuff is=20
soft, but you could fashion it in to any simple things: eyeglass frames,=20
belt buckles, buttons, simple things the screeners would never be=20
lookin' at."
"Wouldn't take much," Wilkes offered, an old college chemistry-class=20
prank coming to mind. "An couple of ounces, that would be enough to blow=20
out the side of a plane, enough for what we're seeing here."
"With the easiest trigger in the world," the NTSB man added, putting=20
words to the picture forming in Wilkes mind. A cup of water would be=20
enough, just drop the sodium metal in to it and the chemical reaction=20
would quickly release hydrogen gas, with enough heat generated as a=20
byproduct of the reaction to ignite the gas. In just a second or two,=20
you'd have an explosion strong enough to knock the side out of a plane.
"Sounds like a problem for you FAA boys," his counterpart teased. "What=20
ya gonna do, ban passengers from carrying more than a few grams of=20
anything made of metal? "
"No," Wilkes shot back, "we can't ban everything that could be made of=20
sodium metal. Or all the other water-reactives," he mused aloud,=20
thinking of all the carbides, anhydrides, and alkali metals that would=20
cover. "Too many ways to hide them, too many types to test for them all.=20
No, it isn't the metals we'll have to ban."
"Naw, you don't mean," the NTSB man stared in disbelief, his eyes=20
growing wide. "You couldn't, I mean, it's the only other way but it's=20
ridiculous."
"No, it's not so ridiculous, it's really the only way. We're going to=20
have to ban water, and anything containing a significant amount of=20
water, from all passenger flights. It's the only way, otherwise we could=20
have planes dropping out of the sky every time someone is served a=20
beverage."
Contest and entries:
http://www.schneier.com/blog/archives/2007/04/announcing_seco.html
Winning entry:
http://www.schneier.com/blog/archives/2007/04/announcing_seco.html#c16117=
8=20
or http://tinyurl.com/2hravr
Other semi-finalists:
http://www.schneier.com/blog/archives/2007/04/announcing_seco.html#c16227=
2=20
or http://tinyurl.com/2f5qao
http://www.schneier.com/blog/archives/2007/04/announcing_seco.html#c16168=
2=20
or http://tinyurl.com/ywjhzr
Ron's home page:
http://www.ronaldphillips.com/
** *** ***** ******* *********** *************
Perpetual Doghouse: Meganet
I first wrote about Meganet in 1999, in a larger article on=20
cryptographic snake-oil, and formally put them in the doghouse in 2003:
"They build an alternate reality where every cryptographic algorithm has=20
been broken, and the only thing left is their own system. 'The weakening=20
of public crypto systems commenced in 1997. First it was the 40-bit key,=20
a few months later the 48-bit key, followed by the 56-bit key, and later=20
the 512 bit has been broken...' What are they talking about? Would you=20
trust a cryptographer who didn't know the difference between symmetric=20
and public-key cryptography? 'Our technology... is the only unbreakable=20
encryption commercially available.' The company's founder quoted in a=20
news article: 'All other encryption methods have been compromised in the=20
last five to six years.' Maybe in their alternate reality, but not in=20
the one we live in.
"Their solution is to not encrypt data at all. 'We believe there is one=20
very simple rule in encryption: if someone can encrypt data, someone=20
else will be able to decrypt it. The idea behind VME is that the data is=20
not being encrypted nor transferred. And if it's not encrypted and not=20
transferred, there is nothing to break. And if there's nothing to break,=20
it's unbreakable.' Ha ha; that's a joke. They really do encrypt data,=20
but they call it something else."
Read the whole thing; it's pretty funny.
They're still around, and they're still touting their snake-oil "virtual=20
matrix encryption." (The patent is finally public, and if someone can=20
reverse-engineer the combination of patentese and gobbledygook into an=20
algorithm, we can finally see how actually awful it really is.) The=20
tech on their website is better than it was in 2003, but it's still=20
pretty hokey.
Back in 2005, they got their product FIPS 140-1 certified. The=20
certification was for their AES implementation, but they're sneakily=20
implying that VME was certified. From their website: "The Strength of a=20
Megabit Encryption (VME). The Assurance of a 256 Bit Standard (AES).=20
Both Technologies Combined in One Certified Module! FIPS 140-2=20
CERTIFICATE # 505."
Just goes to show that with a bit of sleight-of-hand you can get=20
anything FIPS 140 certified.
http://www.meganet.com/
http://www.meganet.com/Technology/intro.asp
http://www.meganet.com/Technology/explain.asp
http://www.meganet.com/challenges/default.asp
My doghouse article:
http://www.schneier.com/crypto-gram-0302.html#4
My snake oil article:
http://www.schneier.com/crypto-gram-9902.html#snakeoil
Patent:
http://patft.uspto.gov/netacgi/nph-Parser?Sect1=3DPTO1&Sect2=3DHITOFF&d=3D=
PALL&p=3D1&u=3D%2Fnetahtml%2FPTO%2Fsrchnum.htm&r=3D1&f=3DG&l=3D50&s1=3D62=
19421.PN.&OS=3DPN/6219421&RS=3DPN/6219421=20
or http://tinyurl.com/28stql
FIPS certification (#505 on this page):
http://csrc.nist.gov/cryptval/140-1/1401val2005.htm
** *** ***** ******* *********** *************
Non-Security Considerations in Security Decisions
(This essay has an accompanying diagram that's necessary to understand=20
what I'm saying. You can find it here:=20
http://www.schneier.com/blog/archives/2007/06/nonsecurity_con_1.html.)
Security decisions are generally made for nonsecurity reasons. For=20
security professionals and technologists, this can be a hard lesson. We=20
like to think that security is vitally important. But anyone who has=20
tried to convince the sales VP to give up her department's Blackberries=20
or the CFO to stop sharing his password with his secretary knows=20
security is often viewed as a minor consideration in a larger decision.=20
This issue's articles on managing organizational security make this=20
point clear.
Below is a diagram of a security decision. At its core are assets, which=20
a security system protects. Security can fail in two ways: either=20
attackers can successfully bypass it, or it can mistakenly block=20
legitimate users. There are, of course, more users than attackers, so=20
the second kind of failure is often more important. There's also a=20
feedback mechanism with respect to security countermeasures: both users=20
and attackers learn about the security and its failings. Sometimes they=20
learn how to bypass security, and sometimes they learn not to bother=20
with the asset at all.
Threats are complicated: attackers have certain goals, and they=20
implement specific attacks to achieve them. Attackers can be legitimate=20
users of assets, as well (imagine a terrorist who needs to travel by=20
air, but eventually wants to blow up a plane). And a perfectly=20
reasonable outcome of defense is attack diversion: the attacker goes=20
after someone else's asset instead.
Asset owners control the security system, but not directly. They=20
implement security through some sort of policy -- either formal or=20
informal -- that some combination of trusted people and trusted systems=20
carries out. Owners make their judgments based on risks ... but really,=20
only by perceived risks. They're also affected by a host of other=20
considerations, including those legitimate users mentioned previously,=20
and the trusted people needed to implement the security policy.
Looking over the diagram, it's obvious that the effectiveness of=20
security is only a minor consideration in an asset owner's security=20
decision. And that's how it should be.
This essay originally appeared in "IEEE Computers and Security."
** *** ***** ******* *********** *************
Comments from Readers
There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and join=20
in.
http://www.schneier.com/blog
** *** ***** ******* *********** *************
CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise. You can=20
subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>. Back issues are also=20
available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable. Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the=20
best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography," and an inventor of the Blowfish and Twofish algorithms.=20
He is founder and CTO of BT Counterpane, and is a member of the Board of=20
Directors of the Electronic Privacy Information Center (EPIC). He is a=20
frequent writer and lecturer on security topics. See=20
<http://www.schneier.com>.
BT Counterpane is the world's leading protector of networked information=20
- the inventor of outsourced security monitoring and the foremost=20
authority on effective mitigation of emerging IT threats. BT=20
Counterpane protects networks for Fortune 1000 companies and governments=20
world-wide. See <http://www.counterpane.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not=20
necessarily those of BT or BT Counterpane.
Copyright (c) 2007 by Bruce Schneier.