CRYPTO-GRAM, March 15, 2008
Bruce Schneier <[email protected]> Fri, 14 Mar 2008 23:02:02 -0500
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
March 15, 2008
by Bruce Schneier
Founder and CTO
BT Counterpane
[email protected]
http://www.schneier.com
http://www.counterpane.com
A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0803.html>. These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>. An RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Privacy and Power
Israel Implementing IFF System for Commercial Aircraft
News
Third Parties Controlling Information
Amtrak to Start Passenger Screening
Schneier/BT Counterpane News
The Doghouse: Drecom
Security Products: Suites vs. Best-of-Breed
Comments from Readers
** *** ***** ******* *********** *************
Privacy and Power
When I write and speak about privacy, I am regularly confronted with the=20
mutual disclosure argument. Explained in books like David Brin's "The=20
Transparent Society," the argument goes something like this: In a world=20
of ubiquitous surveillance, you'll know all about me, but I will also=20
know all about you. The government will be watching us, but we'll also=20
be watching the government. This is different than before, but it's not=20
automatically worse. And because I know your secrets, you can't use my=20
secrets as a weapon against me.
This might not be everybody's idea of utopia -- and it certainly doesn't=20
address the inherent value of privacy -- but this theory has a glossy=20
appeal, and could easily be mistaken for a way out of the problem of=20
technology's continuing erosion of privacy. Except it doesn't work,=20
because it ignores the crucial dissimilarity of power.
You cannot evaluate the value of privacy and disclosure unless you=20
account for the relative power levels of the discloser and the disclosee.
If I disclose information to you, your power with respect to me=20
increases. One way to address this power imbalance is for you to=20
similarly disclose information to me. We both have less privacy, but the=20
balance of power is maintained. But this mechanism fails utterly if you=20
and I have different power levels to begin with.
An example will make this clearer. You're stopped by a police officer,=20
who demands to see identification. Divulging your identity will give the=20
officer enormous power over you: He or she can search police databases=20
using the information on your ID; he or she can create a police record=20
attached to your name; he or she can put you on this or that secret=20
terrorist watch list. Asking to see the officer's ID in return gives you=20
no comparable power over him or her. The power imbalance is too great,=20
and mutual disclosure does not make it OK.
You can think of your existing power as the exponent in an equation that=20
determines the value, to you, of more information. The more power you=20
have, the more additional power you derive from the new data.
Another example: When your doctor says "take off your clothes," it makes=20
no sense for you to say, "You first, doc." The two of you are not=20
engaging in an interaction of equals.
This is the principle that should guide decision-makers when they=20
consider installing surveillance cameras or launching data-mining=20
programs. It's not enough to open the efforts to public scrutiny. All=20
aspects of government work best when the relative power between the=20
governors and the governed remains as small as possible -- when liberty=20
is high and control is low. Forced openness in government reduces the=20
relative power differential between the two, and is generally good.=20
Forced openness in laypeople increases the relative power, and is=20
generally bad.
Seventeen-year-old Erik Crespo was arrested in 2005 in connection with a=20
shooting in a New York City elevator. There's no question that he=20
committed the shooting; it was captured on surveillance-camera=20
videotape. But he claimed that while being interrogated, Detective=20
Christopher Perino tried to talk him out of getting a lawyer, and told=20
him that he had to sign a confession before he could see a judge.
Perino denied, under oath, that he ever questioned Crespo. But Crespo=20
had received an MP3 player as a Christmas gift, and surreptitiously=20
recorded the questioning. The defense brought a transcript and CD into=20
evidence. Shortly thereafter, the prosecution offered Crespo a better=20
deal than originally proffered (seven years rather than 15). Crespo took=20
the deal, and Perino was separately indicted on charges of perjury.
Without that recording, it was the detective's word against Crespo's.=20
And who would believe a murder suspect over a New York City detective?=20
That power imbalance was reduced only because Crespo was smart enough to=20
press the "record" button on his MP3 player. Why aren't all=20
interrogations recorded? Why don't defendants have the right to those=20
recordings, just as they have the right to an attorney? Police routinely=20
record traffic stops from their squad cars for their own protection;=20
that video record shouldn't stop once the suspect is no longer a threat.
Cameras make sense when trained on police, and in offices where=20
lawmakers meet with lobbyists, and wherever government officials wield=20
power over the people. Open-government laws, giving the public access to=20
government records and meetings of governmental bodies, also make sense.=20
These all foster liberty.
Ubiquitous surveillance programs that affect everyone without probable=20
cause or warrant, like the National Security Agency's warrantless=20
eavesdropping programs or various proposals to monitor everything on the=20
internet, foster control. And no one is safer in a political system of=20
control.
The inherent value of privacy:
http://www.schneier.com/essay-114.html
Erik Crespo story:
http://www.nytimes.com/2007/12/08/nyregion/08about.html
http://abcnews.go.com/TheLaw/wireStory?id=3D3968795
Cameras catch a policeman:
http://www.officer.com/web/online/Top-News-Stories/Cameras-Turn-Lens-on-P=
olice-Activities-/1$40169=20
or http://tinyurl.com/2ltqcy
Security and control:
http://www.schneier.com/essay-203.html
This essay originally appeared on Wired.com.
http://www.wired.com/politics/security/commentary/securitymatters/2008/03=
/securitymatters_0306=20
or http://tinyurl.com/2xrcnn
Commentary/rebuttal by David Brin.
http://www.wired.com/politics/security/news/2008/03/brin_rebuttal
** *** ***** ******* *********** *************
Israel Implementing IFF System for Commercial Aircraft
Israel is implementing an IFF (identification, friend or foe) system for=20
commercial aircraft, designed to differentiate legitimate planes from=20
terrorist-controlled planes.
The news article implies that it's a basic challenge-and-response=20
system. Ground control issues some kind of alphanumeric challenge to=20
the plane. The pilot types the challenge into some hand-held computer=20
device, and reads back the reply. Authentication is achieved by 1)=20
physical possession of the device, and 2) typing a legitimate PIN into=20
the device to activate it.
The article talks about a distress mode, where the pilot signals that a=20
terrorist is holding a gun to his head. Likely, that's done by typing a=20
special distress PIN into the device, and reading back whatever the=20
screen displays.
The military has had this sort of system -- first paper-based, and=20
eventually computer-based -- for decades. The critical issue with using=20
this on commercial aircraft is how to deal with user error. The system=20
has to be easy enough to use, and the parts hard enough to lose, that=20
there won't be a lot of false alarms.
http://www.haaretz.com/hasen/spages/926626.html
** *** ***** ******* *********** *************
News
A sonic blaster weapon:
http://blog.wired.com/defense/2008/02/i-was-a-puke-ra.html
Note to the TSA: The inventor has had no problems bringing this thing=20
onto airplanes.
This is a story about petty crime and identity theft, but also a=20
fascinating and impressive story about social engineering. It works=20
even in places that take security seriously.
http://www.washingtoncitypaper.com/display.php?id=3D34552
Every few years, the stupid notion of benevolent worms shows up. This=20
time it was a group of Microsoft researchers from the UK:
http://www.schneier.com/blog/archives/2008/02/benevolent_worm_1.html
Microsoft's response:
http://www.infoworld.com/article/08/02/19/Microsoft-scrambles-to-quash-fr=
iendly-worm-story_1.html=20
or http://tinyurl.com/34mtmb
This story is a year and a half old, but the lessons -- about spending=20
money on the wrong security threats -- are still good:
http://www.wthr.com/Global/story.asp?S=3D4934988
There are a couple of interesting things about the hijacking in New=20
Zealand last month. First, it was a traditional hijacking. Remember=20
after 9/11 when people said that the era of airplane hijacking was over,=20
that it would no longer be possible to hijack an airplane and demand a=20
ransom or demand passage to some exotic location? Turns out that's just=20
not true; there still can be traditional non-terrorist hijackings.
http://www.nzherald.co.nz/section/1/story.cfm?c_id=3D1&objectid=3D1049129=
1
http://www.stuff.co.nz/4392665a11.html
http://www.stuff.co.nz/4395723a10.html
http://www.stuff.co.nz/4395846a11.html
And even more interesting, the media coverage reflected that. Read the=20
links above. They're calm and reasoned. There's no mention of the=20
T-word. We're not all cautioned that we're going to die. If anything,=20
they're recommending that everyone not overreact. Refreshing, really.
http://stuff.co.nz/4414911a10.html
More progress: a whole article about a bomb in Times Square without ever=20
mentioning the T-word.
http://news.yahoo.com/s/ap/20080306/ap_on_re_us/times_square_shutdown
Healthcare records are awfully insecure, and there are all sorts of=20
threats from criminals, but I think the national security angle is just=20
hyperbole.
http://www.schneier.com/blog/archives/2008/02/foreign_hackers.html
The U.S. post office is building a database that will allow people to=20
track commercial mail through the system.
http://www.washingtonpost.com/wp-dyn/content/article/2008/02/17/AR2008021=
701801.html?hpid=3Dsec-tech=20
or http://tinyurl.com/2arcjy
What the article doesn't discuss is that now the government will have a=20
database showing which businesses everyone gets mail from.
Cold-boot attack against disk encryption: a very clever hardware attack=20
that recover keys from DRAM:
http://www.freedom-to-tinker.com/?p=3D1257
http://citp.princeton.edu.nyud.net/pub/coldboot.pdf
http://citp.princeton.edu/memory/
http://www.news.com/8301-13578_3-9876060-38.html
http://blog.wired.com/27bstroke6/2008/02/researchers-dis.html
There is a general security problem illustrated here: it is very=20
difficult to secure data when the attacker has physical control of the=20
machine the data is stored on.
http://www.schneier.com/essay-142.html
How-to, with pictures:
http://content.techrepublic.com.com/2346-1009_11-189078.html
New cryptanalysis of A5/1 (the algorithm used in GSM cell phones).=20
What's new about this attack is: 1) it's completely passive, 2) its=20
total hardware cost is around $1,000, and 3) the total time to break the=20
key is about 30 minutes. That's impressive. And it demonstrates an=20
important cryptographic maxim: attacks always get better; they never get=20
worse. This is why we tend to abandon algorithms at the first sign of=20
weakness; we know that with time, the weaknesses will be exploited more=20
effectively to yield better and faster attacks.
http://www.schneier.com/blog/archives/2008/02/cryptanalysis_o_1.html
I've already written about secret forensic codes embedded in color laser=20
printers. Seems like these codes may violate European privacy laws.
http://www.theregister.co.uk/2008/02/15/secret_printer_tracking_dots/
http://www.telegraph.co.uk/news/main.jhtml?xml=3D/news/2008/02/18/wpriv11=
8.xml=20
or http://tinyurl.com/3xqw6o
http://www.schneier.com/blog/archives/2005/10/secret_forensic.html
Interesting research on malware distribution:
http://www.schneier.com/blog/archives/2008/02/research_on_mal.html
This is no surprise: fear of Internet predators is largely unfounded.
http://www.mcclatchydc.com/homepage/story/28029.html
http://pogue.blogs.nytimes.com/2008/02/28/assessing-the-dangers-of-the-in=
ternet-for-children/=20
or http://tinyurl.com/2kqtk6
http://www.schneier.com/blog/archives/2008/02/fear_of_interne.html
More hysteria about a liquid bomb:
http://www.telegraph.co.uk/news/main.jhtml?xml=3D/news/2008/02/26/nbomb12=
6.xml=20
or http://tinyurl.com/39basa
http://www.channel4.com/video/checking-in-to-airport-chaos/series-1/episo=
de-3/explosive-combination_p_1.html=20
or http://tinyurl.com/ynrwh3
A good debunking:
http://www.theregister.co.uk/2008/02/26/gilligan_bomb_terror_liquid_again=
/=20
or http://tinyurl.com/2wffmh
http://www.theregister.co.uk/2006/08/17/flying_toilet_terror_labs/
Toy airport-security X-ray machine for kids
http://lifesinventions.com/index.cfm?fuseaction=3Dproduct.display&Product=
_ID=3D2385&CFID=3D17420493&CFTOKEN=3D53095688=20
or http://tinyurl.com/2d48ln
Reminds me of the Playmobil Security Checkpoint:
http://www.amazon.com/Playmobil-3172-Security-Check-Point/dp/B0002CYTL2=20
or http://tinyurl.com/2vz3ua
In "Underlying Reasons for Success and Failure of Terrorist Attacks:=20
Selected Case Studies" (Homeland Security Institute, June 2007), the=20
authors examine eight recent terrorist plots against commercial aviation=20
and passenger rail, and come to some interesting conclusions. I=20
especially like this quote, which echoes what I've been saying for a=20
long time now: "One phenomenon stands out: terrorists are rarely caught=20
in the act during the execution phase of an operation, other than=20
instances in which their equipment or weapons fail. Rather, plots are=20
most often foiled during the pre-execution phases." Intelligence,=20
investigation, and emergency response: that's where we should be=20
spending our counterterrorism dollar. Defending the targets is rarely=20
the right answer.
http://www.homelandsecurity.org/hsireports/Reasons_for_Terrorist_Success_=
Failure.pdf=20
or http://tinyurl.com/2u8ft3
http://www.schneier.com/blog/archives/2008/02/why_some_terror.html
More war on the unexpected: LAX evacuated for two hours because of a=20
suspicious comment.
http://www.msnbc.msn.com/id/23216544/
http://www.knbc.com/news/15331048/detail.html
A fascinating article about how kids learn to lie. (Maybe it's a bit=20
off the security topic, but with all my reading on the psychology of=20
security, I don't think so.)
http://www.nymag.com/news/features/43893
Two good uses for RFID chips: to automatically inventory the tools a=20
truck is carrying, and to find misrouted luggage at an airport. See, no=20
technology is all bad or all good.
http://www.boston.com/cars/news/articles/2008/02/11/rfid_equipped_pickups=
_wont_let_tools_go_missing/=20
or http://tinyurl.com/37acl2
http://news.bbc.co.uk/1/hi/uk/7242620.stm
There's a new version of TrueCrypt, version 5.1, the free open-source=20
disk encryption software.
http://www.truecrypt.org/
We've all known for years that you can use Google to scan for=20
vulnerabilities. Well, now the process has been automated: Goolag=20
Scanner from the Cult of the Dead Cow. I've seen a lot of pre-release=20
scanning results from these guys, and it's pretty amazing what they've=20
found.
http://www.eweek.com/index2.php?option=3Dcontent&task=3Dview&id=3D46520&p=
op=3D1&hide_ads=3D1&page=3D0&hide_js=3D1=20
or http://tinyurl.com/2rtmkj
http://www.networkworld.com/news/2008/022208-hackers-turn-google-into-vul=
nerability.html=20
or http://tinyurl.com/346ysd
http://www.goolag.org/
When I wrote the essay "Portrait of the Modern Terrorist as an Idiot," I=20
thought a lot about the government inventing terrorist plotters and=20
entrapping them, to make the world seem scarier. Since then, it's been=20
on my list of topics to write about someday. "Rolling Stone" has his=20
excellent article on the topic, about the Joint Terrorism Task Forces in=20
the U.S.
http://www.rollingstone.com/politics/story/18137343/the_fear_factory
My essay:
http://www.schneier.com/essay-174.html
SurveillanceSaver, a screen saver that shows live images from networked=20
surveillance cameras around the world:
http://code.google.com/p/surveillancesaver/
An excellent article on the risk of knowing too much about risk. Read=20
it all:
http://www2.csoonline.com/exclusives/column.html?CID=3D33571
TSA gangsta rap. Funny.
http://www.youtube.com/watch?v=3Dz7AWw7t5zj0
A weird, weird story about TSA's ideal laptop bag. It seems that the=20
TSA thinks we're all going to redesign our lives around their security=20
checkpoints. Personally, I'd rather have a laptop bag that's useful for=20
me all the time rather than useful for the TSA when I fly -- and I go=20
through airport security about twice a week.
http://gsnmagazine.com/cms/features/news-analysis/542.html
This is video from my talk on dual-use technologies at CPSR's Technology=20
in Wartime conference.
http://www.archive.org/details/Bruce_Schneier.Dual_Use_Technologies
I don't know how big a deal it is that 122 FAA safety inspector badges=20
are missing, but I'm amused nonetheless:
http://www.nbc5i.com/travelgetaways/15508460/detail.html
So, you're sitting around the house with your buddies, playing World of=20
Warcraft. One of you wonders: "How can we get *paid* for doing this?"=20
Another says: "I know; let's pretend we're fighting terrorism, and then=20
get a government grant." "Having eliminated all terrorism in the real=20
world, the U.S. intelligence community is working to develop software=20
that will detect violent extremists infiltrating World of Warcraft and=20
other massive multiplayer games, according to a data-mining report from=20
the Director of National Intelligence." You just can't make this stuff u=
p.
http://blog.wired.com/27bstroke6/2008/02/nations-spies-w.html
http://news.bbc.co.uk/1/hi/technology/7274377.stm
http://www.crispygamer.com/comics/backward/2008-03-03.aspx
The German courts rule on the legality of the police spying in=20
cyberspace. Good stuff.
http://www.schneier.com/blog/archives/2008/03/german_courts_r.html
Really interesting stuff about hacking implanted medical devices. More=20
and more of them contain computers and communicate via RF.
http://www.schneier.com/blog/archives/2008/03/hacking_medical_1.html
Ross Anderson, Rainer B=F6hme, Richard Clayton, and Tyler Moore have=20
published a major report on security and economics: "Security,=20
Economics, and the Internal Market," published by the European Network=20
and Information Security Agency (ENISA).
http://www.enisa.europa.eu/doc/pdf/report_sec_econ_&_int_mark_20080131.pd=
f=20
or http://tinyurl.com/35ao58
Physically hacking Windows computers via FireWire:
http://www.darkreading.com/document.asp?doc_id=3D147713&f_src=3Ddrweekly
Full disk encryption seems like the only defense here.
Essay about stealing from bookstores:
http://www.thestranger.com/seattle/Content?oid=3D520472
The London Tube smart card is cracked. It looks like lousy cryptography.
http://www.schneier.com/blog/archives/2008/03/london_tube_sma.html
Interesting article from Popular Mechanics on surveillance cameras --=20
I'm quoted in several places.
http://www.popularmechanics.com/technology/military_law/4236865.html
And this about watching back.
http://www.popularmechanics.com/technology/military_law/4237005.html
** *** ***** ******* *********** *************
Third Parties Controlling Information
Wine Therapy is a web bulletin board for serious wine geeks. It's been=20
active since 2000, and its database of back posts and comments is a=20
wealth of information: tasting notes, restaurant recommendations,=20
stories and so on. Late last year, someone hacked the board software,=20
got administrative privileges and deleted the database. There was no back=
up.
Of course the board's owner should have been making backups all along,=20
but he has been very sick for the past year and wasn't able to. And the=20
Internet Archive has been only somewhat helpful.
More and more, information we rely on -- either created by us or by=20
others -- is out of our control. It's out there on the internet, on=20
someone else's website and being cared for by someone else. We use those=20
websites, sometimes daily, and don't even think about their reliability.
Bits and pieces of the web disappear all the time. It's called "link=20
rot," and we're all used to it. A friend saved 65 links in 1999 when he=20
planned a trip to Tuscany; only half of them still work today. Here in=20
Crypto-Gram and in my own blog, essays and news articles and websites=20
that I link to regularly disappear.
It may be because of a site's policies -- some newspapers only have a=20
couple of weeks on their website -- or it may be more random: Position=20
papers disappear off a politician's website after he changes his mind on=20
an issue, corporate literature disappears from the company's website=20
after an embarrassment, etc. The ultimate link rot is "site death,"=20
where entire websites disappear: Olympic and World Cup events after the=20
games are over, political candidates' websites after the elections are=20
over, corporate websites after the funding runs out and so on.
Mostly, we ignore the issue. Sometimes I save a copy of a good recipe I=20
find, or an article relevant to my research, but mostly I trust that=20
whatever I want will be there next time. Were I planning a trip to=20
Tuscany, I would rather search for relevant articles today than rely on=20
a nine-year-old list anyway. Most of the time, link rot and site death=20
aren't really a problem.
This is changing in a Web 2.0 world, with websites that are less about=20
information and more about community. We help build these sites, with=20
our posts or our comments. We visit them regularly and get to know=20
others who also visit regularly. They become part of our socialization=20
on the internet and the loss of them affects us differently, as Greatest=20
Journal users discovered in January when their site died.
Few, if any, of the people who made Wine Therapy their home kept backup=20
copies of their own posts and comments. I'm sure they didn't even think=20
of it. I don't think of it, when I post to the various boards and blogs=20
and forums I frequent. Of course I know better, but I think of these=20
forums as extensions of my own computer -- until they disappear.
As we rely on others to maintain our writings and our relationships, we=20
lose control over their availability. Of course, we also lose control=20
over their security, as MySpace users learned last month when a 17-GB=20
file of half a million supposedly private photos was uploaded to a=20
BitTorrent site.
In the early days of the web, I remember feeling giddy over the wealth=20
of information out there and how easy it was to get to. "The Internet is=20
my hard drive," I told newbies. It's even more true today; I don't think=20
I could write without so much information so easily accessible. But it's=20
a pretty damned unreliable hard drive.
The Internet is my hard drive, but only if my needs are immediate and my=20
requirements can be satisfied inexactly. It was easy for me to search=20
for information about the MySpace photo hack. And it will be easy to=20
look up, and respond to, comments to this essay, both on Wired.com and=20
on my own website. Wired.com is a commercial venture, so there is=20
advertising value in keeping everything accessible. My site is not at=20
all commercial, but there is personal value in keeping everything=20
accessible. By that analysis, all sites should be up on the internet=20
forever, although that's certainly not true. What is true is that=20
there's no way to predict what will disappear when.
Unfortunately, there's not much we can do about it. The security=20
measures largely aren't in our hands. We can save copies of important=20
web pages locally, and copies of anything important we post. The=20
Internet Archive is remarkably valuable in saving bits and pieces of the=20
internet. And recently, we've started seeing tools for archiving=20
information and pages from social networking sites. But what's really=20
important is the whole community, and we don't know which bits we want=20
until they're no longer there.
And about Wine Therapy? I *think* it started in 2000. It might have been=20
2001. I can't check, because someone erased the archives.
Internet Archive:
http://www.archive.org/
Greatest Journal:
http://dropbeatsnotbombs.vox.com/library/post/farewell-gj-youll-kind-of-b=
e-missed.html=20
or http://tinyurl.com/2t2yg5
http://barry095.vox.com/library/post/greatest-journal-death.html
Other hacks:
http://www.schneier.com/blog/archives/2005/02/tmobile_hack_1.html
http://www.wired.com/politics/security/news/2008/01/myspace_torrent
This essay originally appeared on Wired.com.
http://www.wired.com/politics/security/commentary/securitymatters/2008/02=
/securitymatters_0221=20
or http://tinyurl.com/2a4go3
** *** ***** ******* *********** *************
Amtrak to Start Passenger Screening
Amtrak is going to start randomly screening passengers, in an effort to=20
close the security-theater gap between trains and airplanes.
It's kind of random:
"The teams will show up unannounced at stations and set up baggage=20
screening areas in front of boarding gates. Officers will randomly pull=20
people out of line and wipe their bags with a special swab that is then=20
put through a machine that detects explosives. If the machine detects=20
anything, officers will open the bag for visual inspection.
"Anybody who is selected for screening and refuses will not be allowed=20
to board and their ticket will be refunded.
"In addition to the screening, counterterrorism officers with=20
bomb-sniffing dogs will patrol platforms and walk through trains, and=20
sometimes will ride the trains, officials said."
This is the most telling comment:
"'There is no new or different specific threat,' [Amtrak chief executive=20
Alex] Kummant said. 'This is just the correct step to take.'"
Why is it the correct step to take? Because it makes him feel better.=20
That's the very definition of security theater.
http://www.forbes.com/afxnewslimited/feeds/afx/2008/02/18/afx4667193.html=
=20
or http://tinyurl.com/3688xe
** *** ***** ******* *********** *************
Schneier/BT Counterpane News
Video interview with Schneier:
http://www.builderau.com.au/news/soa/Schneir-Bad-news-is-good-news-not-so=
-for-security-/0,339028227,339285999,00.htm=20
or http://tinyurl.com/2jztv4
An interview with me from Computerworld Hong Kong:
http://www.cw.com.hk/article.php?id_article=3D1088
An article about, and a little bit by, me:
http://www.infoworld.com/article/08/02/22/08OP-security-schneier_1.html=20
or http://tinyurl.com/2qu9qq
An op-ed by me on national ID from the Minneapolis Star Tribune:
http://www.startribune.com/opinion/commentary/15891037.html
And a small Q&A from the same newspaper:
http://www.startribune.com/opinion/editorials/15891022.html
Schneier is speaking on "The Theater of Security" at the Weisman Art=20
Museum on March 27 in Minneapolis:
http://www.weisman.umn.edu/events/eventscal.php
Schneier is speaking at the Freedom to Connect conference on April 1 in=20
Washington, DC.
http://freedom-to-connect.net/
Schneier is speaking at InterSystems DEVCON2008 on April 2 in Orlando.
http://www.intersystems.com/devcon2008/
Schneier is speaking at the RSA Conference on April 8 in San Francisco.
http://www.rsaconference.com/2008/US/Home.aspx
** *** ***** ******* *********** *************
The Doghouse: Drecom
They advertise 128-bit AES encryption, but they use XOR.
This is why evaluating security products is hard: the devil is in the=20
details.
http://www.heise-online.co.uk/security/Enclosed-but-not-encrypted--/featu=
res/110136/0=20
or http://tinyurl.com/2xqv5r
http://www.easy-nova.de/index.php?siteID=3D18&productID=3D28
Blog entry URL:
http://www.schneier.com/blog/archives/2008/02/the_doghouse_dr.html
** *** ***** ******* *********** *************
Security Products: Suites vs. Best-of-Breed
We know what we don't like about buying consolidated product suites: one=20
great product and a bunch of mediocre ones. And we know what we don't=20
like about buying best-of-breed: multiple vendors, multiple interfaces,=20
and multiple products that don't work well together. The security=20
industry has gone back and forth between the two, as a new generation of=20
IT security professionals rediscovers the downsides of each solution.
The real problem is that neither solution really works, and we=20
continually fool ourselves into believing whatever we don't have is=20
better than what we have at the time. And the real solution is to buy=20
results, not products.
Honestly, no one wants to buy IT security. People want to buy whatever=20
they want -- connectivity, a Web presence, email, networked=20
applications, whatever -- and they want it to be secure. That they're=20
forced to spend money on IT security is an artifact of the youth of the=20
computer industry. And sooner or later the need to buy security will=20
disappear.
It will disappear because IT vendors are starting to realize they have=20
to provide security as part of whatever they're selling. It will=20
disappear because organizations are starting to buy services instead of=20
products, and demanding security as part of those services. It will=20
disappear because the security industry will disappear as a consumer=20
category, and will instead market to the IT industry.
The critical driver here is outsourcing. Outsourcing is the ultimate=20
consolidator, because the customer no longer cares about the details. If=20
I buy my network services from a large IT infrastructure company, I=20
don't care if it secures things by installing the hot new intrusion=20
prevention systems, by configuring the routers and servers so as to=20
obviate the need for network-based security, or if it uses magic=20
security dust given to it by elven kings. I just want a contract that=20
specifies a level and quality of service, and my vendor can figure it out=
.
IT is infrastructure. Infrastructure is always outsourced. And the=20
details of how the infrastructure works are left to the companies that=20
provide it.
This is the future of IT, and when that happens we're going to start to=20
see a type of consolidation we haven't seen before. Instead of large=20
security companies gobbling up small security companies, both large and=20
small security companies will be gobbled up by non-security companies.=20
It's already starting to happen. In 2006, IBM bought ISS. The same year=20
BT bought my company, Counterpane, and last year it bought INS. These=20
aren't large security companies buying small security companies; these=20
are non-security companies buying large and small security companies.
If I were Symantec and McAfee, I would be preparing myself for a buyer.
This is good consolidation. Instead of having to choose between a single=20
product suite that isn't very good or a best-of-breed set of products=20
that don't work well together, we can ignore the issue completely. We=20
can just find an infrastructure provider that will figure it out and=20
make it work -- who cares how?
This essay originally appeared as the second half of a=20
point/counterpoint with Marcus Ranum in "Information Security."
http://searchsecurity.techtarget.com/magazineFeature/0,296894,sid14_gci13=
03850_idx2,00.html
Marcus's half:
http://searchsecurity.techtarget.com/magazineFeature/0,296894,sid14_gci13=
03850,00.html=20
or http://tinyurl.com/36zhml
** *** ***** ******* *********** *************
Comments from Readers
There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and join=20
in.
http://www.schneier.com/blog
** *** ***** ******* *********** *************
CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise. You can=20
subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>. Back issues are also=20
available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable. Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the=20
best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography," and an inventor of the Blowfish and Twofish algorithms.=20
He is founder and CTO of BT Counterpane, and is a member of the Board of=20
Directors of the Electronic Privacy Information Center (EPIC). He is a=20
frequent writer and lecturer on security topics. See=20
<http://www.schneier.com>.
BT Counterpane is the world's leading protector of networked information=20
- the inventor of outsourced security monitoring and the foremost=20
authority on effective mitigation of emerging IT threats. BT=20
Counterpane protects networks for Fortune 1000 companies and governments=20
world-wide. See <http://www.counterpane.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not=20
necessarily those of BT or BT Counterpane.
Copyright (c) 2008 by Bruce Schneier.