CRYPTO-GRAM, March 15, 2008

Bruce Schneier <[email protected]> Fri, 14 Mar 2008 23:02:02 -0500
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

                 March 15, 2008

               by Bruce Schneier
                Founder and CTO
                 BT Counterpane
              [email protected]
             http://www.schneier.com
            http://www.counterpane.com


A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0803.html>.  These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>.  An RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
      Privacy and Power
      Israel Implementing IFF System for Commercial Aircraft
      News
      Third Parties Controlling Information
      Amtrak to Start Passenger Screening
      Schneier/BT Counterpane News
      The Doghouse: Drecom
      Security Products: Suites vs. Best-of-Breed
      Comments from Readers



** *** ***** ******* *********** *************

      Privacy and Power



When I write and speak about privacy, I am regularly confronted with the=20
mutual disclosure argument. Explained in books like David Brin's "The=20
Transparent Society," the argument goes something like this: In a world=20
of ubiquitous surveillance, you'll know all about me, but I will also=20
know all about you. The government will be watching us, but we'll also=20
be watching the government. This is different than before, but it's not=20
automatically worse. And because I know your secrets, you can't use my=20
secrets as a weapon against me.

This might not be everybody's idea of utopia -- and it certainly doesn't=20
address the inherent value of privacy -- but this theory has a glossy=20
appeal, and could easily be mistaken for a way out of the problem of=20
technology's continuing erosion of privacy. Except it doesn't work,=20
because it ignores the crucial dissimilarity of power.

You cannot evaluate the value of privacy and disclosure unless you=20
account for the relative power levels of the discloser and the disclosee.

If I disclose information to you, your power with respect to me=20
increases. One way to address this power imbalance is for you to=20
similarly disclose information to me. We both have less privacy, but the=20
balance of power is maintained. But this mechanism fails utterly if you=20
and I have different power levels to begin with.

An example will make this clearer. You're stopped by a police officer,=20
who demands to see identification. Divulging your identity will give the=20
officer enormous power over you: He or she can search police databases=20
using the information on your ID; he or she can create a police record=20
attached to your name; he or she can put you on this or that secret=20
terrorist watch list. Asking to see the officer's ID in return gives you=20
no comparable power over him or her. The power imbalance is too great,=20
and mutual disclosure does not make it OK.

You can think of your existing power as the exponent in an equation that=20
determines the value, to you, of more information. The more power you=20
have, the more additional power you derive from the new data.

Another example: When your doctor says "take off your clothes," it makes=20
no sense for you to say, "You first, doc." The two of you are not=20
engaging in an interaction of equals.

This is the principle that should guide decision-makers when they=20
consider installing surveillance cameras or launching data-mining=20
programs. It's not enough to open the efforts to public scrutiny. All=20
aspects of government work best when the relative power between the=20
governors and the governed remains as small as possible -- when liberty=20
is high and control is low. Forced openness in government reduces the=20
relative power differential between the two, and is generally good.=20
Forced openness in laypeople increases the relative power, and is=20
generally bad.

Seventeen-year-old Erik Crespo was arrested in 2005 in connection with a=20
shooting in a New York City elevator. There's no question that he=20
committed the shooting; it was captured on surveillance-camera=20
videotape. But he claimed that while being interrogated, Detective=20
Christopher Perino tried to talk him out of getting a lawyer, and told=20
him that he had to sign a confession before he could see a judge.

Perino denied, under oath, that he ever questioned Crespo. But Crespo=20
had received an MP3 player as a Christmas gift, and surreptitiously=20
recorded the questioning. The defense brought a transcript and CD into=20
evidence. Shortly thereafter, the prosecution offered Crespo a better=20
deal than originally proffered (seven years rather than 15). Crespo took=20
the deal, and Perino was separately indicted on charges of perjury.

Without that recording, it was the detective's word against Crespo's.=20
And who would believe a murder suspect over a New York City detective?=20
That power imbalance was reduced only because Crespo was smart enough to=20
press the "record" button on his MP3 player. Why aren't all=20
interrogations recorded? Why don't defendants have the right to those=20
recordings, just as they have the right to an attorney? Police routinely=20
record traffic stops from their squad cars for their own protection;=20
that video record shouldn't stop once the suspect is no longer a threat.

Cameras make sense when trained on police, and in offices where=20
lawmakers meet with lobbyists, and wherever government officials wield=20
power over the people. Open-government laws, giving the public access to=20
government records and meetings of governmental bodies, also make sense.=20
These all foster liberty.

Ubiquitous surveillance programs that affect everyone without probable=20
cause or warrant, like the National Security Agency's warrantless=20
eavesdropping programs or various proposals to monitor everything on the=20
internet, foster control. And no one is safer in a political system of=20
control.

The inherent value of privacy:
http://www.schneier.com/essay-114.html

Erik Crespo story:
http://www.nytimes.com/2007/12/08/nyregion/08about.html
http://abcnews.go.com/TheLaw/wireStory?id=3D3968795

Cameras catch a policeman:
http://www.officer.com/web/online/Top-News-Stories/Cameras-Turn-Lens-on-P=
olice-Activities-/1$40169=20
or http://tinyurl.com/2ltqcy

Security and control:
http://www.schneier.com/essay-203.html

This essay originally appeared on Wired.com.
http://www.wired.com/politics/security/commentary/securitymatters/2008/03=
/securitymatters_0306=20
or http://tinyurl.com/2xrcnn

Commentary/rebuttal by David Brin.
http://www.wired.com/politics/security/news/2008/03/brin_rebuttal


** *** ***** ******* *********** *************

      Israel Implementing IFF System for Commercial Aircraft



Israel is implementing an IFF (identification, friend or foe) system for=20
commercial aircraft, designed to differentiate legitimate planes from=20
terrorist-controlled planes.

The news article implies that it's a basic challenge-and-response=20
system.  Ground control issues some kind of alphanumeric challenge to=20
the plane.  The pilot types the challenge into some hand-held computer=20
device, and reads back the reply.  Authentication is achieved by 1)=20
physical possession of the device, and 2) typing a legitimate PIN into=20
the device to activate it.

The article talks about a distress mode, where the pilot signals that a=20
terrorist is holding a gun to his head.  Likely, that's done by typing a=20
special distress PIN into the device, and reading back whatever the=20
screen displays.

The military has had this sort of system -- first paper-based, and=20
eventually computer-based -- for decades.  The critical issue with using=20
this on commercial aircraft is how to deal with user error.  The system=20
has to be easy enough to use, and the parts hard enough to lose, that=20
there won't be a lot of false alarms.

http://www.haaretz.com/hasen/spages/926626.html


** *** ***** ******* *********** *************

      News



A sonic blaster weapon:
http://blog.wired.com/defense/2008/02/i-was-a-puke-ra.html
Note to the TSA: The inventor has had no problems bringing this thing=20
onto airplanes.

This is a story about petty crime and identity theft, but also a=20
fascinating and impressive story about social engineering.  It works=20
even in places that take security seriously.
http://www.washingtoncitypaper.com/display.php?id=3D34552

Every few years, the stupid notion of benevolent worms shows up.  This=20
time it was a group of Microsoft researchers from the UK:
http://www.schneier.com/blog/archives/2008/02/benevolent_worm_1.html
Microsoft's response:
http://www.infoworld.com/article/08/02/19/Microsoft-scrambles-to-quash-fr=
iendly-worm-story_1.html=20
or http://tinyurl.com/34mtmb

This story is a year and a half old, but the lessons -- about spending=20
money on the wrong security threats -- are still good:
http://www.wthr.com/Global/story.asp?S=3D4934988

There are a couple of interesting things about the hijacking in New=20
Zealand last month.  First, it was a traditional hijacking.  Remember=20
after 9/11 when people said that the era of airplane hijacking was over,=20
that it would no longer be possible to hijack an airplane and demand a=20
ransom or demand passage to some exotic location?  Turns out that's just=20
not true; there still can be traditional non-terrorist hijackings.
http://www.nzherald.co.nz/section/1/story.cfm?c_id=3D1&objectid=3D1049129=
1
http://www.stuff.co.nz/4392665a11.html
http://www.stuff.co.nz/4395723a10.html
http://www.stuff.co.nz/4395846a11.html
And even more interesting, the media coverage reflected that.  Read the=20
links above.  They're calm and reasoned.  There's no mention of the=20
T-word.  We're not all cautioned that we're going to die.  If anything,=20
they're recommending that everyone not overreact.  Refreshing, really.
http://stuff.co.nz/4414911a10.html

More progress: a whole article about a bomb in Times Square without ever=20
mentioning the T-word.
http://news.yahoo.com/s/ap/20080306/ap_on_re_us/times_square_shutdown

Healthcare records are awfully insecure, and there are all sorts of=20
threats from criminals, but I think the national security angle is just=20
hyperbole.
http://www.schneier.com/blog/archives/2008/02/foreign_hackers.html

The U.S. post office is building a database that will allow people to=20
track commercial mail through the system.
http://www.washingtonpost.com/wp-dyn/content/article/2008/02/17/AR2008021=
701801.html?hpid=3Dsec-tech=20
or http://tinyurl.com/2arcjy
What the article doesn't discuss is that now the government will have a=20
database showing which businesses everyone gets mail from.

Cold-boot attack against disk encryption: a very clever hardware attack=20
that recover keys from DRAM:
http://www.freedom-to-tinker.com/?p=3D1257
http://citp.princeton.edu.nyud.net/pub/coldboot.pdf
http://citp.princeton.edu/memory/
http://www.news.com/8301-13578_3-9876060-38.html
http://blog.wired.com/27bstroke6/2008/02/researchers-dis.html
There is a general security problem illustrated here: it is very=20
difficult to secure data when the attacker has physical control of the=20
machine the data is stored on.
http://www.schneier.com/essay-142.html
How-to, with pictures:
http://content.techrepublic.com.com/2346-1009_11-189078.html

New cryptanalysis of A5/1 (the algorithm used in GSM cell phones).=20
What's new about this attack is: 1) it's completely passive, 2) its=20
total hardware cost is around $1,000, and 3) the total time to break the=20
key is about 30 minutes.  That's impressive.  And it demonstrates an=20
important cryptographic maxim: attacks always get better; they never get=20
worse.  This is why we tend to abandon algorithms at the first sign of=20
weakness; we know that with time, the weaknesses will be exploited more=20
effectively to yield better and faster attacks.
http://www.schneier.com/blog/archives/2008/02/cryptanalysis_o_1.html

I've already written about secret forensic codes embedded in color laser=20
printers.  Seems like these codes may violate European privacy laws.
http://www.theregister.co.uk/2008/02/15/secret_printer_tracking_dots/
http://www.telegraph.co.uk/news/main.jhtml?xml=3D/news/2008/02/18/wpriv11=
8.xml=20
or http://tinyurl.com/3xqw6o
http://www.schneier.com/blog/archives/2005/10/secret_forensic.html

Interesting research on malware distribution:
http://www.schneier.com/blog/archives/2008/02/research_on_mal.html

This is no surprise: fear of Internet predators is largely unfounded.
http://www.mcclatchydc.com/homepage/story/28029.html
http://pogue.blogs.nytimes.com/2008/02/28/assessing-the-dangers-of-the-in=
ternet-for-children/=20
or http://tinyurl.com/2kqtk6
http://www.schneier.com/blog/archives/2008/02/fear_of_interne.html

More hysteria about a liquid bomb:
http://www.telegraph.co.uk/news/main.jhtml?xml=3D/news/2008/02/26/nbomb12=
6.xml=20
or http://tinyurl.com/39basa
http://www.channel4.com/video/checking-in-to-airport-chaos/series-1/episo=
de-3/explosive-combination_p_1.html=20
or http://tinyurl.com/ynrwh3
A good debunking:
http://www.theregister.co.uk/2008/02/26/gilligan_bomb_terror_liquid_again=
/=20
or http://tinyurl.com/2wffmh
http://www.theregister.co.uk/2006/08/17/flying_toilet_terror_labs/

Toy airport-security X-ray machine for kids
http://lifesinventions.com/index.cfm?fuseaction=3Dproduct.display&Product=
_ID=3D2385&CFID=3D17420493&CFTOKEN=3D53095688=20
or http://tinyurl.com/2d48ln
Reminds me of the Playmobil Security Checkpoint:
http://www.amazon.com/Playmobil-3172-Security-Check-Point/dp/B0002CYTL2=20
or http://tinyurl.com/2vz3ua

In "Underlying Reasons for Success and Failure of Terrorist Attacks:=20
Selected Case Studies" (Homeland Security Institute, June 2007), the=20
authors examine eight recent terrorist plots against commercial aviation=20
and passenger rail, and come to some interesting conclusions.  I=20
especially like this quote, which echoes what I've been saying for a=20
long time now:  "One phenomenon stands out: terrorists are rarely caught=20
in the act during the execution phase of an operation, other than=20
instances in which their equipment or weapons fail. Rather, plots are=20
most often foiled during the pre-execution phases."  Intelligence,=20
investigation, and emergency response: that's where we should be=20
spending our counterterrorism dollar.  Defending the targets is rarely=20
the right answer.
http://www.homelandsecurity.org/hsireports/Reasons_for_Terrorist_Success_=
Failure.pdf=20
or http://tinyurl.com/2u8ft3
http://www.schneier.com/blog/archives/2008/02/why_some_terror.html

More war on the unexpected:  LAX evacuated for two hours because of a=20
suspicious comment.
http://www.msnbc.msn.com/id/23216544/
http://www.knbc.com/news/15331048/detail.html

A fascinating article about how kids learn to lie.  (Maybe it's a bit=20
off the security topic, but with all my reading on the psychology of=20
security, I don't think so.)
http://www.nymag.com/news/features/43893

Two good uses for RFID chips: to automatically inventory the tools a=20
truck is carrying, and to find misrouted luggage at an airport.  See, no=20
technology is all bad or all good.
http://www.boston.com/cars/news/articles/2008/02/11/rfid_equipped_pickups=
_wont_let_tools_go_missing/=20
or http://tinyurl.com/37acl2
http://news.bbc.co.uk/1/hi/uk/7242620.stm

There's a new version of TrueCrypt, version 5.1, the free open-source=20
disk encryption software.
http://www.truecrypt.org/

We've all known for years that you can use Google to scan for=20
vulnerabilities.  Well, now the process has been automated: Goolag=20
Scanner from the Cult of the Dead Cow.  I've seen a lot of pre-release=20
scanning results from these guys, and it's pretty amazing what they've=20
found.
http://www.eweek.com/index2.php?option=3Dcontent&task=3Dview&id=3D46520&p=
op=3D1&hide_ads=3D1&page=3D0&hide_js=3D1=20
or http://tinyurl.com/2rtmkj
http://www.networkworld.com/news/2008/022208-hackers-turn-google-into-vul=
nerability.html=20
or http://tinyurl.com/346ysd
http://www.goolag.org/

When I wrote the essay "Portrait of the Modern Terrorist as an Idiot," I=20
thought a lot about the government inventing terrorist plotters and=20
entrapping them, to make the world seem scarier.  Since then, it's been=20
on my list of topics to write about someday.  "Rolling Stone" has his=20
excellent article on the topic, about the Joint Terrorism Task Forces in=20
the U.S.
http://www.rollingstone.com/politics/story/18137343/the_fear_factory
My essay:
http://www.schneier.com/essay-174.html

SurveillanceSaver, a screen saver that shows live images from networked=20
surveillance cameras around the world:
http://code.google.com/p/surveillancesaver/

An excellent article on the risk of knowing too much about risk.  Read=20
it all:
http://www2.csoonline.com/exclusives/column.html?CID=3D33571

TSA gangsta rap.  Funny.
http://www.youtube.com/watch?v=3Dz7AWw7t5zj0

A weird, weird story about TSA's ideal laptop bag.  It seems that the=20
TSA thinks we're all going to redesign our lives around their security=20
checkpoints.  Personally, I'd rather have a laptop bag that's useful for=20
me all the time rather than useful for the TSA when I fly -- and I go=20
through airport security about twice a week.
http://gsnmagazine.com/cms/features/news-analysis/542.html

This is video from my talk on dual-use technologies at CPSR's Technology=20
in Wartime conference.
http://www.archive.org/details/Bruce_Schneier.Dual_Use_Technologies

I don't know how big a deal it is that 122 FAA safety inspector badges=20
are missing, but I'm amused nonetheless:
http://www.nbc5i.com/travelgetaways/15508460/detail.html

So, you're sitting around the house with your buddies, playing World of=20
Warcraft.  One of you wonders: "How can we get *paid* for doing this?"=20
Another says: "I know; let's pretend we're fighting terrorism, and then=20
get a government grant."  "Having eliminated all terrorism in the real=20
world, the U.S. intelligence community is working to develop software=20
that will detect violent extremists infiltrating World of Warcraft and=20
other massive multiplayer games, according to a data-mining report from=20
the Director of National Intelligence."  You just can't make this stuff u=
p.
http://blog.wired.com/27bstroke6/2008/02/nations-spies-w.html
http://news.bbc.co.uk/1/hi/technology/7274377.stm
http://www.crispygamer.com/comics/backward/2008-03-03.aspx

The German courts rule on the legality of the police spying in=20
cyberspace.  Good stuff.
http://www.schneier.com/blog/archives/2008/03/german_courts_r.html

Really interesting stuff about hacking implanted medical devices.  More=20
and more of them contain computers and communicate via RF.
http://www.schneier.com/blog/archives/2008/03/hacking_medical_1.html

Ross Anderson, Rainer B=F6hme, Richard Clayton, and Tyler Moore have=20
published a major report on security and economics: "Security,=20
Economics, and the Internal Market," published by the European Network=20
and Information Security Agency (ENISA).
http://www.enisa.europa.eu/doc/pdf/report_sec_econ_&_int_mark_20080131.pd=
f=20
or http://tinyurl.com/35ao58

Physically hacking Windows computers via FireWire:
http://www.darkreading.com/document.asp?doc_id=3D147713&f_src=3Ddrweekly
Full disk encryption seems like the only defense here.

Essay about stealing from bookstores:
http://www.thestranger.com/seattle/Content?oid=3D520472

The London Tube smart card is cracked.  It looks like lousy cryptography.
http://www.schneier.com/blog/archives/2008/03/london_tube_sma.html

Interesting article from Popular Mechanics on surveillance cameras --=20
I'm quoted in several places.
http://www.popularmechanics.com/technology/military_law/4236865.html
And this about watching back.
http://www.popularmechanics.com/technology/military_law/4237005.html


** *** ***** ******* *********** *************

      Third Parties Controlling Information



Wine Therapy is a web bulletin board for serious wine geeks. It's been=20
active since 2000, and its database of back posts and comments is a=20
wealth of information: tasting notes, restaurant recommendations,=20
stories and so on. Late last year, someone hacked the board software,=20
got administrative privileges and deleted the database. There was no back=
up.

Of course the board's owner should have been making backups all along,=20
but he has been very sick for the past year and wasn't able to. And the=20
Internet Archive has been only somewhat helpful.

More and more, information we rely on -- either created by us or by=20
others -- is out of our control. It's out there on the internet, on=20
someone else's website and being cared for by someone else. We use those=20
websites, sometimes daily, and don't even think about their reliability.

Bits and pieces of the web disappear all the time. It's called "link=20
rot," and we're all used to it. A friend saved 65 links in 1999 when he=20
planned a trip to Tuscany; only half of them still work today.  Here in=20
Crypto-Gram and in my own blog, essays and news articles and websites=20
that I link to regularly disappear.

It may be because of a site's policies -- some newspapers only have a=20
couple of weeks on their website -- or it may be more random: Position=20
papers disappear off a politician's website after he changes his mind on=20
an issue, corporate literature disappears from the company's website=20
after an embarrassment, etc. The ultimate link rot is "site death,"=20
where entire websites disappear: Olympic and World Cup events after the=20
games are over, political candidates' websites after the elections are=20
over, corporate websites after the funding runs out and so on.

Mostly, we ignore the issue. Sometimes I save a copy of a good recipe I=20
find, or an article relevant to my research, but mostly I trust that=20
whatever I want will be there next time. Were I planning a trip to=20
Tuscany, I would rather search for relevant articles today than rely on=20
a nine-year-old list anyway. Most of the time, link rot and site death=20
aren't really a problem.

This is changing in a Web 2.0 world, with websites that are less about=20
information and more about community. We help build these sites, with=20
our posts or our comments. We visit them regularly and get to know=20
others who also visit regularly. They become part of our socialization=20
on the internet and the loss of them affects us differently, as Greatest=20
Journal users discovered in January when their site died.

Few, if any, of the people who made Wine Therapy their home kept backup=20
copies of their own posts and comments. I'm sure they didn't even think=20
of it. I don't think of it, when I post to the various boards and blogs=20
and forums I frequent. Of course I know better, but I think of these=20
forums as extensions of my own computer -- until they disappear.

As we rely on others to maintain our writings and our relationships, we=20
lose control over their availability. Of course, we also lose control=20
over their security, as MySpace users learned last month when a 17-GB=20
file of half a million supposedly private photos was uploaded to a=20
BitTorrent site.

In the early days of the web, I remember feeling giddy over the wealth=20
of information out there and how easy it was to get to. "The Internet is=20
my hard drive," I told newbies. It's even more true today; I don't think=20
I could write without so much information so easily accessible. But it's=20
a pretty damned unreliable hard drive.

The Internet is my hard drive, but only if my needs are immediate and my=20
requirements can be satisfied inexactly. It was easy for me to search=20
for information about the MySpace photo hack. And it will be easy to=20
look up, and respond to, comments to this essay, both on Wired.com and=20
on my own website. Wired.com is a commercial venture, so there is=20
advertising value in keeping everything accessible. My site is not at=20
all commercial, but there is personal value in keeping everything=20
accessible. By that analysis, all sites should be up on the internet=20
forever, although that's certainly not true. What is true is that=20
there's no way to predict what will disappear when.

Unfortunately, there's not much we can do about it. The security=20
measures largely aren't in our hands. We can save copies of important=20
web pages locally, and copies of anything important we post. The=20
Internet Archive is remarkably valuable in saving bits and pieces of the=20
internet. And recently, we've started seeing tools for archiving=20
information and pages from social networking sites. But what's really=20
important is the whole community, and we don't know which bits we want=20
until they're no longer there.

And about Wine Therapy? I *think* it started in 2000. It might have been=20
2001. I can't check, because someone erased the archives.

Internet Archive:
http://www.archive.org/

Greatest Journal:
http://dropbeatsnotbombs.vox.com/library/post/farewell-gj-youll-kind-of-b=
e-missed.html=20
or http://tinyurl.com/2t2yg5
http://barry095.vox.com/library/post/greatest-journal-death.html

Other hacks:
http://www.schneier.com/blog/archives/2005/02/tmobile_hack_1.html
http://www.wired.com/politics/security/news/2008/01/myspace_torrent

This essay originally appeared on Wired.com.
http://www.wired.com/politics/security/commentary/securitymatters/2008/02=
/securitymatters_0221=20
or http://tinyurl.com/2a4go3


** *** ***** ******* *********** *************

      Amtrak to Start Passenger Screening



Amtrak is going to start randomly screening passengers, in an effort to=20
close the security-theater gap between trains and airplanes.

It's kind of random:

"The teams will show up unannounced at stations and set up baggage=20
screening areas in front of boarding gates. Officers will randomly pull=20
people out of line and wipe their bags with a special swab that is then=20
put through a machine that detects explosives. If the machine detects=20
anything, officers will open the bag for visual inspection.

"Anybody who is selected for screening and refuses will not be allowed=20
to board and their ticket will be refunded.

"In addition to the screening, counterterrorism officers with=20
bomb-sniffing dogs will patrol platforms and walk through trains, and=20
sometimes will ride the trains, officials said."

This is the most telling comment:

"'There is no new or different specific threat,' [Amtrak chief executive=20
Alex] Kummant said. 'This is just the correct step to take.'"

Why is it the correct step to take?  Because it makes him feel better.=20
That's the very definition of security theater.

http://www.forbes.com/afxnewslimited/feeds/afx/2008/02/18/afx4667193.html=
=20
or http://tinyurl.com/3688xe


** *** ***** ******* *********** *************

      Schneier/BT Counterpane News



Video interview with Schneier:
http://www.builderau.com.au/news/soa/Schneir-Bad-news-is-good-news-not-so=
-for-security-/0,339028227,339285999,00.htm=20
or http://tinyurl.com/2jztv4

An interview with me from Computerworld Hong Kong:
http://www.cw.com.hk/article.php?id_article=3D1088

An article about, and a little bit by, me:
http://www.infoworld.com/article/08/02/22/08OP-security-schneier_1.html=20
or http://tinyurl.com/2qu9qq

An op-ed by me on national ID from the Minneapolis Star Tribune:
http://www.startribune.com/opinion/commentary/15891037.html
And a small Q&A from the same newspaper:
http://www.startribune.com/opinion/editorials/15891022.html

Schneier is speaking on "The Theater of Security" at the Weisman Art=20
Museum on March 27 in Minneapolis:
http://www.weisman.umn.edu/events/eventscal.php

Schneier is speaking at the Freedom to Connect conference on April 1 in=20
Washington, DC.
http://freedom-to-connect.net/

Schneier is speaking at InterSystems DEVCON2008 on April 2 in Orlando.
http://www.intersystems.com/devcon2008/

Schneier is speaking at the RSA Conference on April 8 in San Francisco.
http://www.rsaconference.com/2008/US/Home.aspx


** *** ***** ******* *********** *************

      The Doghouse: Drecom



They advertise 128-bit AES encryption, but they use XOR.

This is why evaluating security products is hard: the devil is in the=20
details.

http://www.heise-online.co.uk/security/Enclosed-but-not-encrypted--/featu=
res/110136/0=20
or http://tinyurl.com/2xqv5r

http://www.easy-nova.de/index.php?siteID=3D18&productID=3D28

Blog entry URL:
http://www.schneier.com/blog/archives/2008/02/the_doghouse_dr.html


** *** ***** ******* *********** *************

      Security Products: Suites vs. Best-of-Breed



We know what we don't like about buying consolidated product suites: one=20
great product and a bunch of mediocre ones. And we know what we don't=20
like about buying best-of-breed: multiple vendors, multiple interfaces,=20
and multiple products that don't work well together. The security=20
industry has gone back and forth between the two, as a new generation of=20
IT security professionals rediscovers the downsides of each solution.

The real problem is that neither solution really works, and we=20
continually fool ourselves into believing whatever we don't have is=20
better than what we have at the time. And the real solution is to buy=20
results, not products.

Honestly, no one wants to buy IT security. People want to buy whatever=20
they want -- connectivity, a Web presence, email, networked=20
applications, whatever -- and they want it to be secure. That they're=20
forced to spend money on IT security is an artifact of the youth of the=20
computer industry. And sooner or later the need to buy security will=20
disappear.

It will disappear because IT vendors are starting to realize they have=20
to provide security as part of whatever they're selling. It will=20
disappear because organizations are starting to buy services instead of=20
products, and demanding security as part of those services. It will=20
disappear because the security industry will disappear as a consumer=20
category, and will instead market to the IT industry.

The critical driver here is outsourcing. Outsourcing is the ultimate=20
consolidator, because the customer no longer cares about the details. If=20
I buy my network services from a large IT infrastructure company, I=20
don't care if it secures things by installing the hot new intrusion=20
prevention systems, by configuring the routers and servers so as to=20
obviate the need for network-based security, or if it uses magic=20
security dust given to it by elven kings. I just want a contract that=20
specifies a level and quality of service, and my vendor can figure it out=
.

IT is infrastructure. Infrastructure is always outsourced. And the=20
details of how the infrastructure works are left to the companies that=20
provide it.

This is the future of IT, and when that happens we're going to start to=20
see a type of consolidation we haven't seen before. Instead of large=20
security companies gobbling up small security companies, both large and=20
small security companies will be gobbled up by non-security companies.=20
It's already starting to happen. In 2006, IBM bought ISS. The same year=20
BT bought my company, Counterpane, and last year it bought INS. These=20
aren't large security companies buying small security companies; these=20
are non-security companies buying large and small security companies.

If I were Symantec and McAfee, I would be preparing myself for a buyer.

This is good consolidation. Instead of having to choose between a single=20
product suite that isn't very good or a best-of-breed set of products=20
that don't work well together, we can ignore the issue completely. We=20
can just find an infrastructure provider that will figure it out and=20
make it work -- who cares how?

This essay originally appeared as the second half of a=20
point/counterpoint with Marcus Ranum in "Information Security."
http://searchsecurity.techtarget.com/magazineFeature/0,296894,sid14_gci13=
03850_idx2,00.html

Marcus's half:
http://searchsecurity.techtarget.com/magazineFeature/0,296894,sid14_gci13=
03850,00.html=20
or http://tinyurl.com/36zhml


** *** ***** ******* *********** *************

      Comments from Readers



There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and join=20
in.

http://www.schneier.com/blog


** *** ***** ******* *********** *************

CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise.  You can=20
subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>.  Back issues are also=20
available at that URL.

Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable.  Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is the author of the=20
best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography," and an inventor of the Blowfish and Twofish algorithms.=20
He is founder and CTO of BT Counterpane, and is a member of the Board of=20
Directors of the Electronic Privacy Information Center (EPIC).  He is a=20
frequent writer and lecturer on security topics.  See=20
<http://www.schneier.com>.

BT Counterpane is the world's leading protector of networked information=20
- the inventor of outsourced security monitoring and the foremost=20
authority on effective mitigation of emerging IT threats.  BT=20
Counterpane protects networks for Fortune 1000 companies and governments=20
world-wide.  See <http://www.counterpane.com>.

Crypto-Gram is a personal newsletter.  Opinions expressed are not=20
necessarily those of BT or BT Counterpane.

Copyright (c) 2008 by Bruce Schneier.