CRYPTO-GRAM, July 15, 2007
Bruce Schneier <[email protected]> Sun, 15 Jul 2007 16:34:11 -0500
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
July 15, 2007
by Bruce Schneier
Founder and CTO
BT Counterpane
[email protected]
http://www.schneier.com
http://www.counterpane.com
A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0707.html>. These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>. An RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Correspondent Inference Theory and Terrorism
TSA and the Sippy Cup Incident
News
Ubiquity of Communication
4th Amendment Rights Extended to E-Mail
Credit Card Gas Limits
Schneier/BT Counterpane News
Designing Voting Machines to Minimize Coercion
Risks of Data Reuse
Comments from Readers
** *** ***** ******* *********** *************
Correspondent Inference Theory and Terrorism
Two people are sitting in a room together: an experimenter and a=20
subject. The experimenter gets up and closes the door, and the room=20
becomes quieter. The subject is likely to believe that the=20
experimenter's purpose in closing the door was to make the room quieter.
This is an example of correspondent inference theory. People tend to=20
infer the motives -- and also the disposition -- of someone who performs=20
an action based on the effects of his actions, and not on external or=20
situational factors. If you see someone violently hitting someone else,=20
you assume it's because he wanted to -- and is a violent person -- and=20
not because he's play-acting. If you read about someone getting into a=20
car accident, you assume it's because he's a bad driver and not because=20
he was simply unlucky. And -- more importantly for this column -- if you=20
read about a terrorist, you assume that terrorism is his ultimate goal.
It's not always this easy, of course. If someone chooses to move to=20
Seattle instead of New York, is it because of the climate, the culture=20
or his career? Edward Jones and Keith Davis, who advanced this theory in=20
the 1960s and 1970s, proposed a theory of "correspondence" to describe=20
the extent to which this effect predominates. When an action has a high=20
correspondence, people tend to infer the motives of the person directly=20
from the action: e.g., hitting someone violently. When the action has a=20
low correspondence, people tend to not to make the assumption: e.g.,=20
moving to Seattle.
Like most cognitive biases, correspondent inference theory makes=20
evolutionary sense. In a world of simple actions and base motivations,=20
it's a good rule of thumb that allows a creature to rapidly infer the=20
motivations of another creature. (He's attacking me because he wants to=20
kill me.) Even in sentient and social creatures like humans, it makes a=20
lot of sense most of the time. If you see someone violently hitting=20
someone else, it's reasonable to assume that he's a violent person.=20
Cognitive biases aren't bad; they're sensible rules of thumb.
But like all cognitive biases, correspondent inference theory fails=20
sometimes. And one place it fails pretty spectacularly is in our=20
response to terrorism. Because terrorism often results in the horrific=20
deaths of innocents, we mistakenly infer that the horrific deaths of=20
innocents is the primary motivation of the terrorist, and not the means=20
to a different end.
I found this interesting analysis in a paper by Max Abrahms in=20
"International Security." "Why Terrorism Does Not Work" analyzes the=20
political motivations of 28 terrorist groups: the complete list of=20
"foreign terrorist organizations" designated by the U.S. Department of=20
State since 2001. He lists 42 policy objectives of those groups, and=20
found that they only achieved them 7 percent of the time.
According to the data, terrorism is more likely to work if 1) the=20
terrorists attack military targets more often than civilian ones, and 2)=20
if they have minimalist goals like evicting a foreign power from their=20
country or winning control of a piece of territory, rather than=20
maximalist objectives like establishing a new political system in the=20
country or annihilating another nation. But even so, terrorism is a=20
pretty ineffective means of influencing policy.
There's a lot to quibble about in Abrahms' methodology, but he seems to=20
be erring on the side of crediting terrorist groups with success.=20
(Hezbollah's objectives of expelling both peacekeepers and Israel out of=20
Lebanon counts as a success, but so does the "limited success" by the=20
Tamil Tigers of establishing a Tamil state.) Still, he provides good=20
data to support what was until recently common knowledge: Terrorism=20
doesn't work.
This is all interesting stuff, and I recommend that you read the paper=20
for yourself. But to me, the most insightful part is when Abrahms uses=20
correspondent inference theory to explain why terrorist groups that=20
primarily attack civilians do not achieve their policy goals, even if=20
they are minimalist. Abrahms writes:
"The theory posited here is that terrorist groups that target civilians=20
are unable to coerce policy change because terrorism has an extremely=20
high correspondence. Countries believe that their civilian populations=20
are attacked not because the terrorist group is protesting unfavorable=20
external conditions such as territorial occupation or poverty. Rather,=20
target countries infer the short-term consequences of terrorism -- the=20
deaths of innocent civilians, mass fear, loss of confidence in the=20
government to offer protection, economic contraction, and the inevitable=20
erosion of civil liberties -- (are) the objects of the terrorist groups.=20
In short, target countries view the negative consequences of terrorist=20
attacks on their societies and political systems as evidence that the=20
terrorists want them destroyed. Target countries are understandably=20
skeptical that making concessions will placate terrorist groups believed=20
to be motivated by these maximalist objectives."
In other words, terrorism doesn't work, because it makes people less=20
likely to acquiesce to the terrorists' demands, no matter how limited=20
they might be. The reaction to terrorism has an effect completely=20
opposite to what the terrorists want; people simply don't believe those=20
limited demands are the actual demands.
This theory explains, with a clarity I have never seen before, why so=20
many people make the bizarre claim that al Qaeda terrorism -- or Islamic=20
terrorism in general -- is "different": that while other terrorist=20
groups might have policy objectives, al Qaeda's primary motivation is to=20
kill us all. This is something we have heard from President Bush again=20
and again -- Abrahms has a page of examples in the paper -- and is a=20
rhetorical staple in the debate.
In fact, Bin Laden's policy objectives have been surprisingly=20
consistent. Abrahms lists four; here are six from former CIA analyst=20
Michael Scheuer's book "Imperial Hubris":
* End U.S. support of Israel
* Force American troops out of the Middle East, particularly Saudi Arabia
* End the U.S. occupation of Afghanistan and (subsequently) Iraq
* End U.S. support of other countries' anti-Muslim policies
* End U.S. pressure on Arab oil companies to keep prices low
* End U.S. support for "illegitimate" (i.e. moderate) Arab governments,=20
like Pakistan
Although Bin Laden has complained that Americans have completely=20
misunderstood the reason behind the 9/11 attacks, correspondent=20
inference theory postulates that he's not going to convince people.=20
Terrorism, and 9/11 in particular, has such a high correspondence that=20
people use the effects of the attacks to infer the terrorists' motives.=20
In other words, since Bin Laden caused the death of a couple of thousand=20
people in the 9/11 attacks, people assume that must have been his actual=20
goal, and he's just giving lip service to what he *claims* are his=20
goals. Even Bin Laden's actual objectives are ignored as people focus on=20
the deaths, the destruction and the economic impact.
Perversely, Bush's misinterpretation of terrorists' motives actually=20
helps prevent them from achieving their goals.
None of this is meant to either excuse or justify terrorism. In fact, it=20
does the exact opposite, by demonstrating why terrorism doesn't work as=20
a tool of persuasion and policy change. But we're more effective at=20
fighting terrorism if we understand that it is a means to an end and not=20
an end in itself; it requires us to understand the true motivations of=20
the terrorists and not just their particular tactics. And the more our=20
own cognitive biases cloud that understanding, the more we=20
mischaracterize the threat and make bad security trade-offs.
http://www.mitpressjournals.org/doi/pdf/10.1162/isec.2006.31.2.42
http://en.wikipedia.org/wiki/Correspondent_inference_theory
Cognitive biases:
http://www.healthbolt.net/2007/02/14/26-reasons-what-you-think-is-right-i=
s-wrong/=20
or http://tinyurl.com/2oo5nk
This essay originally appeared on Wired.com:
http://www.wired.com/politics/security/commentary/securitymatters/2007/07=
/securitymatters_0712=20
or http://tinyurl.com/3y322f
** *** ***** ******* *********** *************
TSA and the Sippy Cup Incident
This story is pretty disgusting: "I demanded to speak to a TSA=20
[Transportation Security Administration] supervisor who asked me if the=20
water in the sippy cup was 'nursery water or other bottled water.' I=20
explained that the sippy cup water was filtered tap water. The sippy cup=20
was seized as my son was pointing and crying for his cup. I asked if I=20
could drink the water to get the cup back, and was advised that I would=20
have to leave security and come back through with an empty cup in order=20
to retain the cup. As I was escorted out of security by TSA and a police=20
officer, I unscrewed the cup to drink the water, which accidentally=20
spilled because I was so upset with the situation.
"At this point, I was detained against my will by the police officer and=20
threatened to be arrested for endangering other passengers with the=20
spilled 3 to 4 ounces of water. I was ordered to clean the water, so I=20
got on my hands and knees while my son sat in his stroller with no shoes=20
on since they were also screened and I had no time to put them back on=20
his feet. I asked to call back my fianc=E9, who I could still see from=20
afar, waiting for us to clear security, to watch my son while I was=20
being detained, and the officer threatened to arrest me if I moved. So I=20
yelled past security to get the attention of my fianc=E9.
"I was ordered to apologize for the spilled water, and again threatened=20
arrest. I was threatened several times with arrest while detained, and=20
while three other police officers were called to the scene of the mother=20
with the 19 month old. A total of four police officers and three TSA=20
officers reported to the scene where I was being held against my will. I=20
was also told that I should not disrespect the officer and could be=20
arrested for this too. I apologized to the officer and she continued to=20
detain me despite me telling her that I would miss my flight. The=20
officer advised me that I should have thought about this before I=20
'intentionally spilled the water!'"
This story portrays the TSA as jack-booted thugs. The story hit the=20
Internet in mid-June, and quickly made the rounds. I saw it on=20
BoingBoing. But, as it turns out, it's not entirely true.
The TSA has a webpage up, with both the incident report and video.
"TSO [REDACTED] took the female to the exit lane with the stroller and=20
her bag. When she got past the exit lane podium she opened the child's=20
drink container and held her arm out and poured the contents (approx. 6=20
to 8 ounces) on the floor. MWAA Officer [REDACTED] was manning the exit=20
lane at the time and observed the entire scene and approached the female=20
passenger after observing this and stopped her when she tried to=20
re-enter the sterile area after trying to come back through after=20
spilling the fluids on the floor. The female passenger flashed her=20
badge and credentials and told the MWAA officer 'Do you know who I am?'=20
An argument then ensued between the officer and the passenger of=20
whether the spilling of the fluid was intentional or accidental.=20
Officer [REDACTED] asked the passenger to clean up the spill and she did.=
"
Watch the second video. TSO [REDACTED] is partially blocking the scene,=20
but at 2:01:00 PM it's pretty clear that Monica Emmerson -- that's the=20
female passenger -- spills the liquid on the floor on purpose, as a=20
deliberate act of defiance. What happens next is more complicated; you=20
can watch it for yourself, or you can read BoingBoing's somewhat=20
sarcastic summary.
In this instance, the TSA is clearly in the right.
But there's a larger lesson here. Remember the Princeton professor who=20
was put on the watch list for criticizing Bush? That was also untrue.=20
Why is it that we all -- myself included -- believe these stories? Why=20
are we so quick to assume that the TSA is a bunch of jack-booted thugs,=20
officious and arbitrary and drunk with power?
It's because everything seems so arbitrary, because there's no=20
accountability or transparency in the DHS. Rules and regulations change=20
all the time, without any explanation or justification. Of course this=20
kind of thing induces paranoia. It's the sort of thing you read about=20
in history books about East Germany and other police states. It's not=20
what we expect out of 21st century America.
The problem is larger than the TSA, but the TSA is the part of "homeland=20
security" that the public comes into contact with most often -- at least=20
the part of the public that writes about these things most. They're the=20
public face of the problem, so of course they're going to get the lion's=20
share of the finger pointing.
It was smart public relations on the TSA's part to get the video of the=20
incident on the Internet quickly, but it would be even smarter for the=20
government to restore basic constitutional liberties to our nation's=20
counterterrorism policy. Accountability and transparency are basic=20
building blocks of any democracy; and the more we lose sight of them,=20
the more we lose our way as a nation.
The story:
http://www.nowpublic.com/nightmare_at_reagan_national_airport_a_security_=
story_to_end_all_security_stories=20
or http://tinyurl.com/2vgvcm
http://www.boingboing.net/2007/06/14/tsa_detains_woman_ov.html
The TSA's rebuttal:
http://www.tsa.gov/approach/mythbusters/dca_incident.shtm
http://www.boingboing.net/2007/06/15/tsa_denies_sippy_cup.html
Princeton professor:
http://rawstory.com/news/2007/Professor_who_criticized_Bush_added_to_0409=
.html=20
or http://tinyurl.com/yo7ljc
http://blog.wired.com/27bstroke6/2007/04/debunking_the_p.html
** *** ***** ******* *********** *************
News
Remote sensing of meth labs, another NSF grant:
http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=3D0712406
Ridiculous "age verification" for online movie trailers: "It seems like=20
'We want to protect children' really means, We want to give the=20
appearance that we've made an effort to protect children. If they really=20
wanted to protect children, they wouldn't use the honor system as the=20
sole safeguard standing between previews filled with sex and violence=20
and Internet-savvy kids who can, in a matter of seconds, beat the=20
impotent little system."
http://blogs.csoonline.com/dirty_trailers_cheap_tricks
Direct marketing meets wholesale surveillance: a $100K National Science=20
Foundation grant:
http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=3D0712287
In 1748, the painter William Hogarth was arrested as a spy for sketching=20
fortifications at Calais.
http://en.wikipedia.org/wiki/The_Gate_of_Calais
Sound familiar, doesn't it?
http://www.schneier.com/blog/archives/2005/07/security_risks_3.html
http://www.schneier.com/blog/archives/2007/04/how_australian.html
http://www.flickr.com/groups/strobist/discuss/72157600359124224/
Fogshield: silly home security.
http://hardwareaisle.thisoldhouse.com/2007/06/lets_smoke_em_o.html
http://www.schneier.com/blog/archives/2007/06/silly_home_secu.html
Someone claims to have hacked the Bloomsbury Publishing network, and has=20
posted what he says is the ending to the last Harry Potter book. I=20
don't believe it, actually. Sure, it's possible -- probably even easy.=20
But the posting just doesn't read right to me. And I would expect=20
someone who really got their hands on a copy of the manuscript to post=20
the choice bits of text, not just a plot summary. It's easier, and it's=20
more proof.
http://seclists.org/fulldisclosure/2007/Jun/0380.html
The French government wants to ban BlackBerry e-mail devices, because of=20
worries of eavesdropping by U.S. intelligence.
http://www.ft.com/cms/s/dde45086-1e97-11dc-bc22-000b5df10621,_i_rssPage=3D=
61e21220-6714-11da-a650-0000779e2340.html=20
or http://tinyurl.com/yvka3p
Vulnerabilities in the DHS network:
http://blog.wired.com/27bstroke6/2007/06/dhs-security-ch.html
TSA uses Monte Carlo simulations to weigh airplane risks
http://www.gcn.com/print/26_13/44398-1.html
Good comments in the blog post:
http://www.schneier.com/blog/archives/2007/06/tsa_uses_monte.html
The Onion on terrorist cell apathy:
http://www.theonion.com/content/news/after_5_years_in_u_s_terrorist
"Cocktail condoms" are protective covers that go over your drink and=20
"protect" against someone trying to slip a Mickey Finn (or whatever=20
they're called these days). I'm sure there are many ways to defeat this=20
security device if you're so inclined: a syringe, affixing a new cover=20
after you tamper with the drink, and so on. And this is exactly the=20
sort of rare risk we're likely to overreact to. But to me, the most=20
interesting aspect of this story is the agenda. If these things become=20
common, it won't be because of security. It will be because of advertisi=
ng
http://abcnews.go.com/US/story?id=3D3302652&page=3D1&CMP=3DOTC-RSSFeeds03=
12
Does this cell phone stalking story seem real to anyone?
http://www.thenewstribune.com/front/topphoto/story/91460.html
http://consumerist.com/consumer/privacy/family-stalked-using-cellphone-sn=
oopware-271435.php?autoplay=3Dtrue=20
or http://tinyurl.com/2kklxb
There's something going on here, but I just don't believe it's entirely=20
cell phone hacking. Something else is going on.
Really good "Washington Post" article on secrecy:
http://www.washingtonpost.com/wp-dyn/content/article/2007/06/08/AR2007060=
802496.html=20
or http://tinyurl.com/yv7bjd
Back in 2002 I wrote about the relationship between secrecy and security.
http://www.schneier.com/crypto-gram-0205.html#1
Surveillance cameras that obscure faces, an interesting=20
privacy-enhancing technology.
http://www.technologyreview.com/Infotech/18617/
At the beach, sand is more deadly than sharks. And this is important=20
enough to become someone's crusade?
http://abcnews.go.com/US/wireStory?id=3D3299749
Essay: "The only thing we have to fear is the 'culture of fear' itself,"=20
by Frank Furedi.
http://www.frankfuredi.com/pdf/fearessay-20070404.pdf
Making invisible ink printer cartridges: a covert channel.
http://gizmodo.com/gadgets/clips/how-to-make-glow+in+the+dark-printer-ink=
-269828.php=20
or http://tinyurl.com/yoszvc
Bioterrorism detection systems and false alarms:
http://www.google.com/search?q=3Dcache:sfmQXOplWaUJ:www.the-scientist.com=
/article/home/52963/+=20
or http://tinyurl.com/2tjmhy
Robotic guns:
http://defensenews.com/story.php?F=3D2803275&C=3Damerica
Airport security: Israel vs. the United States
http://www.sfgate.com/cgi-bin/article.cgi?f=3D/c/a/2007/06/17/TRGRJQF1DE1=
.DTL=20
or http://tinyurl.com/yqdt6f
Why an ATM PIN has four digits:
http://news.bbc.co.uk/2/hi/business/6230194.stm
Security cartoon: it's always a trade-off:
http://www.gocomics.com/nonsequitur/2007/06/24
Look at the last line of this article, about an Ohio town considering=20
mandatory school uniforms in lower grades: "For Edgewood, the primary=20
motivation for adopting uniforms would be to enhance school security,=20
York said." What is he talking about? Does he think that school=20
uniforms enhance security because it would be easier to spot=20
non-uniform-wearing non-students in the school building and on the=20
grounds? (Of course, non-students with uniforms would have an easier=20
time sneaking in.) Or something else? Or is security just an excuse=20
for any random thing these days?
http://news.enquirer.com/apps/pbcs.dll/article?AID=3D/20070626/NEWS01/306=
260034/1056/COL02=20
or http://tinyurl.com/2yr2z8 or http://tinyurl.com/253j8l
Good commentaries on the UK terrorist plots:
http://www.theregister.co.uk/2007/06/29/more_fear_biscuits_please/
http://www.theage.com.au/news/opinion/its-hard-to-prevent-the-hard-to-ima=
gine/2007/07/02/1183351119482.html=20
or http://tinyurl.com/2dvcyv
http://www.theregister.co.uk/2007/07/02/terror_idiocy_outbreak/
http://www.slate.com/id/2169614/nav/tap1/
http://www.atimes.com/atimes/Front_Page/IG03Aa01.html
http://www.theregister.co.uk/2007/07/04/ec_frattini_web_terror_dunce_cap/=
=20
or http://tinyurl.com/35ebmj
In former East Germany, the Stazi kept samples of people's smells.
http://www.kirchersociety.org/blog/2007/04/05/smell-jars-of-the-stasi/
The Millwall brick: an improvised weapon made out of newspaper, favored=20
by football (i.e., soccer) hooligans.
http://en.wikipedia.org/wiki/Millwall_brick
When coins are worth more as metal than as coins.
http://news.bbc.co.uk/2/hi/south_asia/6766563.stm
This guy has a bottle taken away from him, then he picks it out of the=20
trash and takes it on the plane anyway. I'm not sure whether this is=20
more gutsy or stupid. If he had been caught, the TSA would have made=20
his day pretty damn miserable. I'm not even sure bragging about it=20
online is a good idea. Too many idiots in the FBI.
http://www.zug.com/gab/index.cgi?func=3Dview_thread&head=3D1&thread_id=3D=
74827=20
or http://tinyurl.com/yuk2ky
I've written about this Greek wiretapping scandal before. A system to=20
allow the police to eavesdrop on conversations was abused (surprise,=20
surprise). There's a really good technical analysis in IEEE Spectrum=20
this month.
http://www.spectrum.ieee.org/print/5280
Commentaries:
http://www.crypto.com/blog/hellenic_eavesdropping/
http://www.cs.columbia.edu/~smb/blog/2007-07/2007-07-06.html
http://mobile.nytimes.com/blogs/bits/212
Police don't overreact to strange object. What's sad is that it feels=20
like an exception.
http://www.dallasnews.com/sharedcontent/dws/dn/latestnews/stories/071007d=
nmetrobot.5bd61405.html=20
or http://tinyurl.com/yrys8p
I'm sure glad the Australian Federal Police have their priorities=20
straight: "Technology such as cloned part-robot humans used by organised=20
crime gangs pose the greatest future challenge to police, along with=20
online scamming, Australian Federal Police (AFP) Commissioner Mick=20
Keelty says."
http://www.theage.com.au/news/national/top-cop-predicts-robot-crimewave/2=
007/07/06/1183351416078.html=20
or http://tinyurl.com/27y45n
Dan Solove comments on the recent ACLU vs. NSA decision regarding the=20
NSA's illegal wiretapping activities.
http://www.concurringopinions.com/archives/2007/07/aclu_v_nsa.html
http://www.concurringopinions.com/archives/2007/07/aclu_v_nsa_and.html
Dan Solove on privacy and the "nothing to hide" argument:
http://ssrn.com/abstract=3D998565
Funny airport-security photo:
http://www.flickr.com/photos/9831094@N02/755509753/
** *** ***** ******* *********** *************
Ubiquity of Communication
In an essay by Randy Farmer, a pioneer of virtual online worlds, he=20
describes communication in something called Disney's ToonTown.=20
Designers of online worlds for children wanted to severely restrict the=20
communication that users could have with each other, lest somebody say=20
something that's inappropriate for children to hear.
Randy discusses various approaches to this problem that were tried over=20
the years. The ToonTown solution was to restrict users to something=20
called "Speedchat," a menu of pre-constructed sentences, all innocuous.=20
They also gave users the ability to conduct unrestricted conversations=20
with each other, provided they both knew a secret code string. The=20
designers presumed the code strings would be passed only to people a=20
user knew in real life, perhaps on a school playground or among neighbors=
.
Users found ways to pass code strings to strangers anyway. Users=20
invented several protocols, using gestures, canned sentences, or=20
movement of objects in the game.
Randy writes: "By hook, or by crook, customers will always find a way=20
to connect with each other."
http://www.fudco.com/habitat/archives/000058.html
http://www.disneyonlineworlds.com/index.php/Becoming_Secret_Friends_with_=
someone_you_don%27t_know=20
or http://tinyurl.com/2gkdlx
** *** ***** ******* *********** *************
4th Amendment Rights Extended to E-Mail
This is a great piece of news in the U.S. For the first time, e-mail has=20
been granted the same constitutional protections as telephone calls and=20
personal papers: the police need a warrant to get at it. Now it's only=20
a circuit court decision -- the Sixth U.S. Circuit Court of Appeals in=20
Ohio -- it's pretty narrowly defined based on the attributes of the=20
e-mail system, and it has a good chance of being overturned by the=20
Supreme Court...but it's still great news.
The way to think of the warrant system is as a security device. The=20
police still have the ability to get access to e-mail in order to=20
investigate a crime. But in order to prevent abuse, they have to=20
convince a neutral third party -- a judge -- that accessing someone's=20
e-mail is necessary to investigate that crime. That judge, at least in=20
theory, protects our interests.
Clearly e-mail deserves the same protection as our other personal=20
papers, but -- like phone calls -- it might take the courts decades to=20
figure that out. But we'll get there eventually.
http://blog.wired.com/27bstroke6/2007/06/appeals_court_s.html
http://arstechnica.com/news.ars/post/20070619-appeals-court-feds-cant-sei=
ze-secretly-seize-e-mail-without-a-warrant.html=20
or http://tinyurl.com/26maek
http://www.freedom-to-tinker.com/?p=3D1170
http://www.volokh.com/archives/archive_2007_06_17-2007_06_23.shtml#118220=
8168=20
or http://tinyurl.com/yqb4uz
http://www.ca6.uscourts.gov/opinions.pdf/07a0225p-06.pdf
** *** ***** ******* *********** *************
Credit Card Gas Limits
Here's an interesting phenomenon: rising gas costs have pushed up a lot=20
of legitimate transactions to the "anti-fraud" ceiling.
Security is a trade-off, and now the ceiling is annoying more and more=20
legitimate gas purchasers. But to me the real question is: does this=20
ceiling have any actual security purpose?
In general, credit card fraudsters like making gas purchases because the=20
system is automated: no signature is required, and there's no need to=20
interact with any other person. In fact, buying gas is the most common=20
way a fraudster tests that a recently stolen card is valid. The=20
anti-fraud ceiling doesn't actually prevent any of this, but limits the=20
amount of money at risk.
But so what? How many perps are actually trying to get more gas than is=20
permitted? Are credit-card-stealing miscreants also swiping cars with=20
enormous gas tanks, or merely filling up the passenger cars they=20
regularly drive? I'd love to know how many times, prior to the run-up=20
in gas prices, a triggered cutoff actually coincided with a subsequent=20
report of a stolen card. And what's the effect of a ceiling, apart from=20
a gas shut-off? Surely the smart criminals know about smurfing, if they=20
need more gas than the ceiling will allow.
The Visa spokesperson said, "We get more calls, questions, when gas=20
prices increase." He/she didn't say: "We *make* more calls to see if=20
fraud is occurring." So the only inquiries made may be in the cases=20
where fraud isn't occurring.
http://www.sfgate.com/cgi-bin/article.cgi?f=3D/n/a/2007/06/15/financial/f=
110628D50.DTL=20
or http://tinyurl.com/ywfqdj
Smurfing:
http://en.wikipedia.org/wiki/Smurfing_%28crime%29
** *** ***** ******* *********** *************
Schneier/BT Counterpane News
Slate wrote an article on my movie-plot threat contest.
http://www.slate.com/id/2169232/
** *** ***** ******* *********** *************
Designing Voting Machines to Minimize Coercion
If someone wants to buy your vote, he'd like some proof that you've=20
delivered the goods. Camera phones are one way for you to prove to your=20
buyer that you voted the way he wants. Belgian voting machines have=20
been designed to minimize that risk.
"Once you have confirmed your vote, the next screen doesn't display how=20
you voted. So if one is coerced and has to deliver proof, one just has=20
to take a picture of the vote one was coerced into, and then back out=20
from the screen and change ones vote. The only workaround I see is for=20
the coercer to demand a video of the complete voting process, instead of=20
a picture of the ballot."
The author is wrong that this is an advantage electronic ballots have=20
over paper ballots. Paper voting systems can be designed with the same=20
security features.
http://didierstevens.wordpress.com/2007/06/11/some-e-voting-observations/=
=20
or http://tinyurl.com/24k5l6
** *** ***** ******* *********** *************
Risks of Data Reuse
We learned the news in March: Contrary to decades of denials, the U.S.=20
Census Bureau used individual records to round up Japanese-Americans=20
during World War II.
The Census Bureau normally is prohibited by law from revealing data that=20
could be linked to specific individuals; the law exists to encourage=20
people to answer census questions accurately and without fear. And while=20
the Second War Powers Act of 1942 temporarily suspended that protection=20
in order to locate Japanese-Americans, the Census Bureau had maintained=20
that it only provided general information about neighborhoods.
New research proves they were lying.
The whole incident serves as a poignant illustration of one of the=20
thorniest problems of the information age: data collected for one=20
purpose and then used for another, or "data reuse."
When we think about our personal data, what bothers us most is generally=20
not the initial collection and use, but the secondary uses. I personally=20
appreciate it when Amazon.com suggests books that might interest me,=20
based on books I have already bought. I like it that my airline knows=20
what type of seat and meal I prefer, and my hotel chain keeps records of=20
my room preferences. I don't mind that my automatic road-toll collection=20
tag is tied to my credit card, and that I get billed automatically. I=20
even like the detailed summary of my purchases that my credit card=20
company sends me at the end of every year. What I don't want, though, is=20
any of these companies selling that data to brokers, or for law=20
enforcement to be allowed to paw through those records without a warrant.
There are two bothersome issues about data reuse. First, we lose control=20
of our data. In all of the examples above, there is an implied agreement=20
between the data collector and me: It gets the data in order to provide=20
me with some sort of service. Once the data collector sells it to a=20
broker, though, it's out of my hands. It might show up on some=20
telemarketer's screen, or in a detailed report to a potential employer,=20
or as part of a data-mining system to evaluate my personal terrorism=20
risk. It becomes part of my data shadow, which always follows me around=20
but I can never see.
This, of course, affects our willingness to give up personal data in the=20
first place. The reason U.S. census data was declared off-limits for=20
other uses was to placate Americans' fears and assure them that they=20
could answer questions truthfully. How accurate would you be in filling=20
out your census forms if you knew the FBI would be mining the data,=20
looking for terrorists? How would it affect your supermarket purchases=20
if you knew people were examining them and making judgments about your=20
lifestyle? I know many people who engage in data poisoning: deliberately=20
lying on forms in order to propagate erroneous data. I'm sure many of=20
them would stop that practice if they could be sure that the data was=20
only used for the purpose for which it was collected.
The second issue about data reuse is error rates. All data has errors,=20
and different uses can tolerate different amounts of error. The sorts of=20
marketing databases you can buy on the web, for example, are notoriously=20
error-filled. That's OK; if the database of ultra-affluent Americans of=20
a particular ethnicity you just bought has a 10 percent error rate, you=20
can factor that cost into your marketing campaign. But that same=20
database, with that same error rate, might be useless for law=20
enforcement purposes.
Understanding error rates and how they propagate is vital when=20
evaluating any system that reuses data, especially for law enforcement=20
purposes. A few years ago, the Transportation Security Administration's=20
follow-on watch list system, Secure Flight, was going to use commercial=20
data to give people a terrorism risk score and determine how much they=20
were going to be questioned or searched at the airport. People rightly=20
rebelled against the thought of being judged in secret, but there was=20
much less discussion about whether the commercial data from credit=20
bureaus was accurate enough for this application.
An even more egregious example of error-rate problems occurred in 2000,=20
when the Florida Division of Elections contracted with Database=20
Technologies (since merged with ChoicePoint) to remove convicted felons=20
from the voting rolls. The databases used were filled with errors and=20
the matching procedures were sloppy, which resulted in thousands of=20
disenfranchised voters -- mostly black -- and almost certainly changed a=20
presidential election result.
Of course, there are beneficial uses of secondary data. Take, for=20
example, personal medical data. It's personal and intimate, yet valuable=20
to society in aggregate. Think of what we could do with a database of=20
everyone's health information: massive studies examining the long-term=20
effects of different drugs and treatment options, different=20
environmental factors, different lifestyle choices. There's an enormous=20
amount of important research potential hidden in that data, and it's=20
worth figuring out how to get at it without compromising individual priva=
cy.
This is largely a matter of legislation. Technology alone can never=20
protect our rights. There are just too many reasons not to trust it, and=20
too many ways to subvert it. Data privacy ultimately stems from our=20
laws, and strong legal protections are fundamental to protecting our=20
information against abuse. But at the same time, technology is still vita=
l.
Both the Japanese internment and the Florida voting-roll purge=20
demonstrate that laws can change -- and sometimes change quickly. We=20
need to build systems with privacy-enhancing technologies that limit=20
data collection wherever possible. Data that is never collected cannot=20
be reused. Data that is collected anonymously, or deleted immediately=20
after it is used, is much harder to reuse. It's easy to build systems=20
that collect data on everything -- it's what computers naturally do --=20
but it's far better to take the time to understand what data is needed=20
and why, and only collect that.
History will record what we, here in the early decades of the=20
information age, did to foster freedom, liberty and democracy. Did we=20
build information technologies that protected people's freedoms even=20
during times when society tried to subvert them? Or did we build=20
technologies that could easily be modified to watch and control? It's=20
bad civic hygiene to build an infrastructure that can be used to=20
facilitate a police state.
Individual data and the Japanese internment:
http://www.sciam.com/article.cfm?articleID=3DA4F4DED6-E7F2-99DF-32E46B0AC=
1FDE0FE&sc=3DI100322=20
or http://tinyurl.com/33kcy3
http://www.usatoday.com/news/nation/2007-03-30-census-role_N.htm
http://www.homelandstupidity.us/2007/04/05/census-bureau-gave-up-wwii-int=
ernment-camp-evaders/=20
or http://tinyurl.com/2haky8
http://rawstory.com/news/afp/Census_identified_Japanese_American_03302007=
.html=20
or http://tinyurl.com/2ctnl3
Marketing databases:
http://www.wholesalelists.net
http://www.usdatacorporation.com/pages/specialtylists.html
Secure Flight:
http://www.epic.org/privacy/airtravel/secureflight.html
Florida disenfranchisement in 2000:
http://www.thenation.com/doc/20010430/lantigua
This article originally appeared on Wired.com:
http://www.wired.com/politics/onlinerights/commentary/securitymatters/200=
7/06/securitymatters_0628=20
or http://tinyurl.com/34mr2g
** *** ***** ******* *********** *************
Comments from Readers
There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and join=20
in.
http://www.schneier.com/blog
** *** ***** ******* *********** *************
CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise. You can=20
subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>. Back issues are also=20
available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable. Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the=20
best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography," and an inventor of the Blowfish and Twofish algorithms.=20
He is founder and CTO of BT Counterpane, and is a member of the Board of=20
Directors of the Electronic Privacy Information Center (EPIC). He is a=20
frequent writer and lecturer on security topics. See=20
<http://www.schneier.com>.
BT Counterpane is the world's leading protector of networked information=20
- the inventor of outsourced security monitoring and the foremost=20
authority on effective mitigation of emerging IT threats. BT=20
Counterpane protects networks for Fortune 1000 companies and governments=20
world-wide. See <http://www.counterpane.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not=20
necessarily those of BT or BT Counterpane.
Copyright (c) 2007 by Bruce Schneier.