CRYPTO-GRAM, August 15, 2008
Bruce Schneier <[email protected]> Fri, 15 Aug 2008 02:45:33 -0500
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
August 15, 2008
by Bruce Schneier
Chief Security Technology Officer, BT
[email protected]
http://www.schneier.com
A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0808.html>. These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>. An RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Memo to the Next President
TSA Proud of Confiscating Non-Dangerous Item
Homeland Security Cost-Benefit Analysis
News
Hacking Mifare Transport Cards
Information Security and Liabilities
Software Liabilities and Free Software
Schneier/BT News
Congratulations to Our Millionth Terrorist!
TrueCrypt's Deniable File System
The DNS Vulnerability
Comments from Readers
** *** ***** ******* *********** *************
Memo to the Next President
Obama has a cyber security plan.
It's basically what you would expect: Appoint a national cyber security=20
advisor, invest in math and science education, establish standards for=20
critical infrastructure, spend money on enforcement, establish national=20
standards for securing personal data and data-breach disclosure, and=20
work with industry and academia to develop a bunch of needed technologies=
.
I could comment on the plan, but with security the devil is always in=20
the details -- and, of course, at this point there are few details. But=20
since he brought up the topic -- McCain supposedly is "working on the=20
issues" as well -- I have three pieces of policy advice for the next=20
president, whoever he is. They're too detailed for campaign speeches or=20
even position papers, but they're essential for improving information=20
security in our society. Actually, they apply to national security in=20
general. And they're things only government can do.
One, use your immense buying power to improve the security of commercial=20
products and services. One property of technological products is that=20
most of the cost is in the development of the product rather than the=20
production. Think software: The first copy costs millions, but the=20
second copy is free.
You have to secure your own government networks, military and civilian.=20
You have to buy computers for all your government employees. Consolidate=20
those contracts, and start putting explicit security requirements into=20
the RFPs. You have the buying power to get your vendors to make serious=20
security improvements in the products and services they sell to the=20
government, and then we all benefit because they'll include those=20
improvements in the same products and services they sell to the rest of=20
us. We're all safer if information technology is more secure, even=20
though the bad guys can use it, too.
Two, legislate results and not methodologies. There are a lot of areas=20
in security where you need to pass laws, where the security=20
externalities are such that the market fails to provide adequate=20
security. For example, software companies who sell insecure products are=20
exploiting an externality just as much as chemical plants that dump=20
waste into the river. But a bad law is worse than no law. A law=20
requiring companies to secure personal data is good; a law specifying=20
what technologies they should use to do so is not. Mandating software=20
liabilities for software failures is good, detailing how is not.=20
Legislate for the results you want and implement the appropriate=20
penalties; let the market figure out how -- that's what markets are good=20
at.
Three, broadly invest in research. Basic research is risky; it doesn't=20
always pay off. That's why companies have stopped funding it. Bell Labs=20
is gone because nobody could afford it after the AT&T breakup, but the=20
root cause was a desire for higher efficiency and short-term=20
profitability -- not unreasonable in an unregulated business. Government=20
research can be used to balance that by funding long-term research.
Spread those research dollars wide. Lately, most research money has been=20
redirected through DARPA to near-term military-related projects; that's=20
not good. Keep the earmark-happy Congress from dictating how the money=20
is spent. Let the NSF, NIH and other funding agencies decide how to=20
spend the money and don't try to micromanage. Give the national=20
laboratories lots of freedom, too. Yes, some research will sound silly=20
to a layman. But you can't predict what will be useful for what, and if=20
funding is really peer-reviewed, the average results will be much=20
better. Compared to corporate tax breaks and other subsidies, this is=20
chump change.
If our research capability is to remain vibrant, we need more science=20
and math students with decent elementary and high school preparation.=20
The declining interest is partly from the perception that scientists=20
don't get rich like lawyers and dentists and stockbrokers, but also=20
because science isn't valued in a country full of creationists. One way=20
the president can help is by trusting scientific advisers and not=20
overruling them for political reasons.
Oh, and get rid of those post-9/11 restrictions on student visas that=20
are causing so many top students to do their graduate work in Canada,=20
Europe and Asia instead of in the United States. Those restrictions will=20
hurt us immensely in the long run.
Those are the three big ones; the rest is in the details. And it's the=20
details that matter. There are lots of serious issues that you're going=20
to have to tackle: data privacy, data sharing, data mining, government=20
eavesdropping, government databases, use of Social Security numbers as=20
identifiers, and so on. It's not enough to get the broad policy goals=20
right. You can have good intentions and enact a good law, and have the=20
whole thing completely gutted by two sentences sneaked in during=20
rulemaking by some lobbyist.
Security is both subtle and complex, and -- unfortunately -- doesn't=20
readily lend itself to normal legislative processes. You're used to=20
finding consensus, but security by consensus rarely works. On the=20
internet, security standards are much worse when they're developed by a=20
consensus body, and much better when someone just does them. This=20
doesn't always work -- a lot of crap security has come from companies=20
that have "just done it" -- but nothing but mediocre standards come from=20
consensus bodies. The point is that you won't get good security without=20
pissing someone off: The information broker industry, the voting machine=20
industry, the telcos. The normal legislative process makes it hard to=20
get security right, which is why I don't have much optimism about what=20
you can get done.
And if you're going to appoint a cybersecurity czar, you have to give=20
him actual budgetary authority. Otherwise he won't be able to get=20
anything done, either.
Obama's plan:
http://www.barackobama.com/2008/07/16/remarks_of_senator_barack_obam_95.p=
hp=20
or http://tinyurl.com/59ted4
http://www.barackobama.com/2008/07/16/fact_sheet_obamas_new_plan_to.php=20
or http://tinyurl.com/5rcnmt
McCain:
http://www.scmagazineus.com/Cybersecurity-and-the-presidential-campaign/a=
rticle/112566=20
or http://tinyurl.com/5h3h75
Dual-use technologies:
http://www.schneier.com/blog/archives/2008/05/dualuse_technol_1.html
Good legislation:
http://www.schneier.com/essay-141.html
http://www.schneier.com/blog/archives/2007/01/information_sec_1.html
Liabilities:
http://www.schneier.com/essay-025.html
http://www.schneier.com/essay-116.html
Research redirected through DARPA:
http://query.nytimes.com/gst/fullpage.html?res=3D9F04E1DB113FF931A35757C0=
A9639C8B63=20
or http://tinyurl.com/6m6uac
Congressional earmarks:
http://www.ostp.gov/pdf/1pger_earmark.pdf
Student visa problems:
http://www7.nationalacademies.org/visas/Statement%20on%20Visa%20Problems.=
pdf=20
or http://tinyurl.com/6z7kbo
http://www.aau.edu/research/Gast.pdf
This essay originally appeared on Wired.com:
http://www.wired.com/politics/security/commentary/securitymatters/2008/08=
/securitymatters_0807=20
or http://tinyurl.com/5f6dhe
** *** ***** ******* *********** *************
TSA Proud of Confiscating Non-Dangerous Item
This is just sad. The TSA confiscated a battery pack not because it's=20
dangerous, but because other passengers might *think* it's dangerous.=20
And they're proud of the fact.
My guess is that if Kip Hawley were allowed to comment on my blog, he=20
would say something like this: "It's not just bombs that are prohibited;=20
it's things that look like bombs. This looks enough like a bomb to fool=20
the other passengers, and that in itself is a threat."
Okay, that's fair. But the average person doesn't know what a bomb looks=20
like; all he knows is what he sees on television and the movies. And=20
this rule means that all homemade electronics are confiscated, because=20
anything homemade with wires can look like a bomb to someone who doesn't=20
know better. The rule just doesn't work.
And in today's passengers-fight-back world, do you think anyone is going=20
to successfully do anything with a fake bomb?
Late Note: the TSA webpage has been updated; they admit that they=20
overreacted.
http://www.tsa.gov/press/happenings/scot_peele.shtm
** *** ***** ******* *********** *************
Homeland Security Cost-Benefit Analysis
In an excellent paper by Ohio State political science professor John=20
Mueller, "The Quixotic Quest for Invulnerability: Assessing the Costs,=20
Benefits, and Probabilities of Protecting the Homeland," there are some=20
common sense premises and policy implications.
The premises:
"1. The number of potential terrorist targets is essentially infinite.
"2. The probability that any individual target will be attacked is=20
essentially zero.
"3. If one potential target happens to enjoy a degree of protection, the=20
agile terrorist usually can readily move on to another one.
"4. Most targets are 'vulnerable' in that it is not very difficult to=20
damage them, but invulnerable in that they can be rebuilt in fairly=20
short order and at tolerable expense.
"5. It is essentially impossible to make a very wide variety of=20
potential terrorist targets invulnerable except by completely closing=20
them down."
The policy implications:
"1. Any protective policy should be compared to a "null case": do=20
nothing, and use the money saved to rebuild and to compensate any victims=
.
"2. Abandon any effort to imagine a terrorist target list.
"3. Consider negative effects of protection measures: not only direct=20
cost, but inconvenience, enhancement of fear, negative economic impacts,=20
reduction of liberties.
"4. Consider the opportunity costs, the tradeoffs, of protection measures=
."
The whole paper is worth reading.
http://psweb.sbs.ohio-state.edu/faculty/jmueller/ISA2008.pdf
** *** ***** ******* *********** *************
News
A disgruntled employee holds the San Francisco computer network hostage,=20
proving that trusted insiders can do a lot of damage.
http://www.sfgate.com/cgi-bin/article.cgi?f=3D/c/a/2008/07/14/BAOS11P1M5.=
DTL&tsp=3D1=20
or http://tinyurl.com/69r5x3
http://www.darkreading.com/blog.asp?blog_sectionid=3D342&f_src=3Ddrdaily
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic=
&articleId=3D9110520=20
or http://tinyurl.com/6cse68
Locksmiths hate computer geeks who learn lockpicking.
http://www.theglobeandmail.com/servlet/story/RTGAM.20080711.wlpicking11/E=
mailBNStory/lifeMain=20
or http://tinyurl.com/5p8jm3
http://www.crypto.com/papers/safelocks.pdf
Funny radio skit on identity theft, by Mitchell & Webb.
http://www.youtube.com/watch?v=3DCS9ptA3Ya9E
This report, "Assessing the risks, costs and benefits of United States=20
aviation security measures" by Mark Stewart and John Mueller, is=20
excellent reading. Reinforcing the cockpit door is cost effective; sky=20
marshals are not. The final paper will eventually be published in the=20
Journal of Transportation Security. I never even knew there was such a=20
thing.
http://hdl.handle.net/1959.13/28097
New York Times op-ed on the same subject:
http://www.nytimes.com/2008/07/21/opinion/21heifetz.html
Who can not feel a little chill of fear after reading this: "Britain on=20
alert for deadly new knife with exploding tip that freezes victims'=20
organs." Yes, it's real. The knife is designed for people who need to=20
drop large animals quickly: sharks, bears, etc.
http://www.dailymail.co.uk/news/article-1035729/Britain-alert-deadly-new-=
knife-exploding-tip-freezes-victims-organs.html=20
or http://tinyurl.com/6pr48c
http://www.waspknife.com/
I have no idea why Britain is on alert for it. Maybe because knife=20
crimes are on the rise.
http://www.nytimes.com/2008/07/17/world/europe/17knives.html
A high-level British government employee supposedly had his BlackBerry=20
stolen by Chinese intelligence. But the story doesn't make sense. If=20
you're a Chinese intelligence officer and you manage to get an aide to=20
the British Prime Minister to have sex with one of your agents, you're=20
not going to immediately burn him by stealing his BlackBerry. That's=20
just stupid. If anything, you'd clone the Blackberry and return it.=20
This is much more likely to be petty theft.
http://www.timesonline.co.uk/tol/news/politics/article4364353.ece
Clever Washington DC metro Farecard hack:
http://www.washingtonpost.com/wp-dyn/content/article/2008/07/18/AR2008071=
801912_pf.html=20
or http://tinyurl.com/6mmvpx
In this article about British speed cameras, and a trick to avoid them=20
that does not work, is this sentence: "As vehicles pass between the=20
entry and exit camera points their number plates are digitally recorded,=20
whether speeding or not." Without knowing more, I can guarantee that=20
those records are kept forever.
http://www.theregister.co.uk/2008/07/21/speed_camera_myth/
Here's someone in the UK, a passenger in a car, who moons a speeding=20
camera and gets his picture published even though the car was not=20
speeding. How did they know to look at the picture in the first place?
http://news.bbc.co.uk/1/hi/england/tyne/7378695.stm
They were confiscating sunscreen at Yankee Stadium as an anti-terrorism=20
measure. This story has a happy ending, though. A day after The New=20
York Post published this story, Yankee Stadium reversed its ban. Now, if=20
only the Post had that same effect on airport security.
http://www.nypost.com/seven/07222008/news/regionalnews/sunblockheads__at_=
the_stadium_120930.htm=20
or http://tinyurl.com/5rl2ns
http://www.schneier.com/blog/archives/2008/06/liquid_ban_gone.html
http://www.salon.com/sports/daily/?last_story=3D/sports/daily/feature/200=
8/07/23/sunblock/=20
or http://tinyurl.com/67tjn2
Adeona is an open source laptop tracking service.
http://adeona.cs.washington.edu/index.html
http://www.pcworld.com/businesscenter/article/148356/new_service_tracks_m=
issing_laptops_for_free.html=20
or http://tinyurl.com/6a8f92
From a Washington Post article on terrorist plots, comes this quote:=20
"Batiste confided, somewhat fantastically, that he wanted to blow up the=20
Sears Tower in Chicago, which would then fall into a nearby prison,=20
freeing Muslim prisoners who would become the core of his Moorish army.=20
With them, he would establish his own country." *Somewhat*=20
fantastically? What would the Washington Post consider to be truly=20
fantastic? A plan involving Godzilla? Clearly they have some very high=20
standards. I'm sick of people taking these idiots seriously. This plot=20
is beyond fantastic, it's delusional.
http://www.washingtonpost.com/wp-dyn/content/article/2008/04/20/AR2008042=
002227.html=20
or http://tinyurl.com/6pfguq
http://www.schneier.com/blog/archives/2007/06/portrait_of_the_1.html
SanDisk has introduced Write-Once Read-Many Memory (WORM) cards for=20
forensic applications.
http://www.sandisk.com/Corporate/PressRoom/PressReleases/PressRelease.asp=
x?ID=3D4353=20
or http://tinyurl.com/5zxeb2
Great World War II deception story in an obituary of former OSS agent=20
Roger Hall. Hall's book about his OSS days, "You're Stepping on My=20
Cloak and Dagger," is a must-read.
http://www.philly.com/inquirer/obituaries/20080723_Roger_Hall___Poked_fun=
_at_spies__89.html=20
or http://tinyurl.com/5apy98
Video demonstrating how easy it is to social engineer your way into=20
clubs by pretending you're the DJ.
http://www.5min.com/Video/How-to-Get-Into-Any-Club-14234755
3,000 blank British passports stolen. Looks like an inside job to me.
http://www.time.com/time/world/article/0,8599,1827501,00.html
http://www.foxnews.com/story/0,2933,393581,00.html
http://news.sky.com/skynews/Home/Politics/British-Passports-Stolen-After-=
Van-Hijacked-En-Route-From-Oldham-to-RAF-Northolt/Article/200807415058916=
?lpos=3DPolitics_1&lid=3DARTICLE_15058916_British+Passports+Stolen+After+=
Van+Hijacked+En+Ro=20
or http://tinyurl.com/6x5g2t
This is an engaging and fascinating video presentation by Professor=20
James Duane of the Regent University School of Law, explaining why -- in=20
a criminal matter -- you should never, ever, ever talk to the police or=20
any other government agent. It doesn't matter if you're guilty or=20
innocent, if you have an alibi or not -- it isn't possible for anything=20
you say to help you, and it's very possible that innocuous things you=20
say will hurt you. Definitely worth half an hour of your time.
http://video.google.com/videoplay?docid=3D-4097602514885833865
And this is a video of Virginia Beach Police Department Officer George=20
Bruch, who basically says that Duane is right.
http://video.google.com/videoplay?docid=3D6014022229458915912&q=3D&hl=3De=
n
Remember when I said that I keep my home wireless network open? Here's a=20
reason not to listen to me. "When Indian police investigating bomb=20
blasts which killed 42 people traced an email claiming responsibility to=20
a Mumbai apartment, they ordered an immediate raid. But at the address,=20
rather than seizing militants from the Islamist group which said it=20
carried out the attack, they found a group of puzzled American expats."=20
Of course, the terrorists could have sent the e-mail from anywhere.=20
But life is easier if the police don't raid *your* apartment.
http://www.guardian.co.uk/world/2008/jul/29/india.terrorism
http://www.schneier.com/blog/archives/2008/01/my_open_wireles.html
Suspect in 2001 anthrax attacks kill self. Fascinating stuff, although=20
this early story leaves me with more questions than answers.
http://www.cnn.com/2008/CRIME/08/01/anthrax.suicide.ap/index.html
The U.S. government has published its policy for seizing laptops at=20
borders: they can take your laptop anywhere they want, for as long as=20
they want, and share the information with anyone they want.
http://www.washingtonpost.com/wp-dyn/content/article/2008/08/01/AR2008080=
103030.html=20
or http://tinyurl.com/5w4728
http://www.cbp.gov/linkhandler/cgov/travel/admissability/search_authority=
.ctt/search_authority.pdf=20
or http://tinyurl.com/5wr7jw
http://yro.slashdot.org/yro/08/08/01/0958242.shtml
http://www.schneier.com/essay-217.html
Schneier misquote:
http://www.schneier.com/blog/archives/2008/08/schneier_misquo.html
Good perspective on Gary McKinnon's extradition to the United States.
http://www.guardian.co.uk/commentisfree/2008/aug/01/hacking.hitechcrime=20
or http://tinyurl.com/5stanr
Italians use soldiers to prevent crime. More security theater than=20
anything else.
http://www.nytimes.com/2008/08/05/world/europe/05italy.html
Laptop with Trusted Traveler identities lost, presumed stolen, and then=20
found.
http://www.orlandosentinel.com/business/orl-clear0508aug05,0,4458701.stor=
y=20
or http://tinyurl.com/6dj35c
http://cbs5.com/local/tsa.security.clear.2.788083.html
http://www.tsa.gov/press/releases/2008/0804.shtm
http://www.schneier.com/blog/archives/2007/01/clear_registere.html
http://www.schneier.com/blog/archives/2008/06/new_tsa_id_requ.html
http://www.schneier.com/blog/archives/2006/11/forge_your_own.html
http://www.sfgate.com/cgi-bin/article.cgi?f=3D/n/a/2008/08/05/financial/f=
102608D05.DTL&tsp=3D1=20
or http://tinyurl.com/6fnn8f
My essay on Trusted Traveler:
http://www.schneier.com/essay-199.html
Lots of NSA forms, obtained via the Freedom of Information Act:
http://www.thememoryhole.org/2008/07/over-400-nsa-forms/
Security idiocy story from the Dilbert blog:
http://dilbert.com/blog/entry/true_story/
These indictments against the largest ID theft ring ever were really big=20
news, but I don't think it's that much of a big deal. These crimes are=20
still easy to commit and it's still too hard to catch the criminals.=20
Catching one gang, even a large one, isn't going to make us any safer.
http://www.washingtonpost.com/wp-dyn/content/article/2008/08/05/AR2008080=
501859.html=20
or http://tinyurl.com/6oudqn
http://money.cnn.com/2008/08/05/news/companies/card_fraud/?postversion=3D=
2008080604=20
or http://tinyurl.com/6lznnr
http://technology.timesonline.co.uk/tol/news/world/us_and_americas/articl=
e4468114.ece=20
or http://tinyurl.com/5ldho6
http://www.iht.com/articles/ap/2008/08/06/business/NA-US-Retailer-Fraud-I=
ndictment.php=20
or http://tinyurl.com/6nm8yu
http://www.theregister.co.uk/2008/08/06/id_fraud_hacking_case/
http://ap.google.com/article/ALeqM5hlC-7Qgf2_9ytmu5kKBpnEf5XzeQD92D20KG0=20
or http://tinyurl.com/65392t
If we want to mitigate identity theft, we have to make it harder for=20
people to get credit, make transactions, and generally do financial=20
business remotely.
http://www.schneier.com/blog/archives/2005/04/mitigating_iden.html
The headline says it all: "'Fakeproof' e-passport is cloned in minutes."
http://www.timesonline.co.uk/tol/news/uk/crime/article4467106.ece
http://www.schneier.com/essay-125.html
DMCA does not apply to the U.S. government:
http://arstechnica.com/news.ars/post/20080804-air-force-cracks-software-c=
arpet-bombs-dmca.html=20
or http://tinyurl.com/56rb9w
Random killing on a Canadian Greyhound bus, and the predictable security=20
overreaction:
http://www.schneier.com/blog/archives/2008/08/random_killing.html
The Onion: Are the Chinese Olympics a trap?
http://www.theonion.com/content/video/the_beijing_olympics_are_they_a
Amber Alerts as security theater:
http://www.boston.com/bostonglobe/ideas/articles/2008/07/20/abducted/
Bypassing Microsoft Vista's memory protection:
http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci13243=
95,00.html=20
or http://tinyurl.com/62nqb2
http://taossa.com/archive/bh08sotirovdowd.pdf
http://arstechnica.com/news.ars/post/20080811-the-sky-isnt-falling-a-look=
-at-a-new-vista-security-bypass.html=20
or http://tinyurl.com/6an5z8
Seems like the procedure has changed for flying without ID. Now they=20
ask personal questions from your credit history.
http://philosecurity.org/2008/08/10/flying-without-a-wallet
This only works if you've lost your ID, not if you refuse to show it.
http://www.schneier.com/blog/archives/2008/06/new_tsa_id_requ.html
The UK has made public its previously classified National Risk Register.=20
Seems like the greatest threat to national security is a flu pandemic.
http://www.cabinetoffice.gov.uk/reports/national_risk_register.aspx
Interesting paper on the risk of anthrax as a terrorist weapon:
http://www.stratfor.com/weekly/busting_anthrax_myth
I don't know the details, but detecting pump and dump scams seems like a=20
really good use of data mining.
http://news.bbc.co.uk/1/hi/technology/7552009.stm
http://news.yahoo.com/s/zd/20080811/tc_zd/230711
Data mining works best when there's a well-defined profile you're=20
searching for, a reasonable number of attacks per year, and a low cost=20
of false alarms.
http://www.schneier.com/blog/archives/2006/03/data_mining_for.html
Over-hyping risks against children, and the effectiveness of giving them=20
cell phones:
http://www.cnn.com/2008/TECH/ptech/08/11/cellphones.kids/index.html
The UK police seized a copy of the War on Terror board game because --=20
and it's almost too stupid to believe -- the balaclava "could be used to=20
conceal someone's identity or could be used in the course of a criminal=20
act." Don't they realize that balaclavas are for sale everywhere in the=20
UK? Or that scarves, hoods, handkerchiefs, and dark glasses could also=20
be used to conceal someone's identity?
http://www.cambridge-news.co.uk/cn%5Fnews%5Fhome/DisplayArticle.asp?ID=3D=
338658=20
or http://tinyurl.com/59ta6r
Sounds like a fun game, though:
http://www.waronterrortheboardgame.com/
** *** ***** ******* *********** *************
Hacking Mifare Transport Cards
London's Oyster card has been cracked, and the final details will become=20
public in October. NXP Semiconductors, the Philips spin-off that makes=20
the system, lost a court battle to prevent the researchers from=20
publishing. People might be able to use this information to ride for=20
free, but the sky won't be falling. And the publication of this serious=20
vulnerability actually makes us all safer in the long run.
Here's the story. Every Oyster card has a radio-frequency identification=20
chip that communicates with readers mounted on the ticket barrier. That=20
chip, the "Mifare Classic" chip, is used in hundreds of other transport=20
systems as well -- Boston, Los Angeles, Brisbane, Amsterdam, Taipei,=20
Shanghai, Rio de Janeiro -- and as an access pass in thousands of=20
companies, schools, hospitals, and government buildings around Britain=20
and the rest of the world.
The security of Mifare Classic is terrible. This is not an exaggeration;=20
it's kindergarten cryptography. Anyone with any security experience=20
would be embarrassed to put his name to the design. NXP attempted to=20
deal with this embarrassment by keeping the design secret.
The group that broke Mifare Classic is from Radboud University Nijmegen=20
in the Netherlands. They demonstrated the attack by riding the=20
Underground for free, and by breaking into a building. Their two papers=20
(one is already online) will be published at two conferences this autumn.
The second paper is the one that NXP sued over. They called disclosure=20
of the attack "irresponsible," warned that it will cause "immense=20
damages," and claimed that it "will jeopardize the security of assets=20
protected with systems incorporating the Mifare IC." The Dutch court=20
would have none of it: "Damage to NXP is not the result of the=20
publication of the article but of the production and sale of a chip that=20
appears to have shortcomings."
Exactly right. More generally, the notion that secrecy supports security=20
is inherently flawed. Whenever you see an organization claiming that=20
design secrecy is necessary for security -- in ID cards, in voting=20
machines, in airport security -- it invariably means that its security=20
is lousy and it has no choice but to hide it. Any competent=20
cryptographer would have designed Mifare's security with an open and=20
public design.
Secrecy is fragile. Mifare's security was based on the belief that no=20
one would discover how it worked; that's why NXP had to muzzle the Dutch=20
researchers. But that's just wrong. Reverse-engineering isn't hard.=20
Other researchers had already exposed Mifare's lousy security. A Chinese=20
company even sells a compatible chip. Is there any doubt that the bad=20
guys already know about this, or will soon enough?
Publication of this attack might be expensive for NXP and its customers,=20
but it's good for security overall. Companies will only design security=20
as good as their customers know to ask for. NXP's security was so bad=20
because customers didn't know how to evaluate security: either they=20
don't know what questions to ask, or didn't know enough to distrust the=20
marketing answers they were given. This court ruling encourages=20
companies to build security properly rather than relying on shoddy=20
design and secrecy, and discourages them from promising security based=20
on their ability to threaten researchers.
It's unclear how this break will affect Transport for London. Cloning=20
takes only a few seconds, and the thief only has to brush up against=20
someone carrying a legitimate Oyster card. But it requires an RFID=20
reader and a small piece of software which, while feasible for a techie,=20
are too complicated for the average fare dodger. The police are likely=20
to quickly arrest anyone who tries to sell cloned cards on any scale.=20
TfL promises to turn off any cloned cards within 24 hours, but that will=20
hurt the innocent victim who had his card cloned more than the thief.
The vulnerability is far more serious to the companies that use Mifare=20
Classic as an access pass. It would be very interesting to know how NXP=20
presented the system's security to them.
And while these attacks only pertain to the Mifare Classic chip, it=20
makes me suspicious of the entire product line. NXP sells a more secure=20
chip and has another on the way, but given the number of basic=20
cryptography mistakes NXP made with Mifare Classic, one has to wonder=20
whether the "more secure" versions will be sufficiently so.
News:
http://www.guardian.co.uk/technology/2008/jun/26/hitechcrime.oystercards=20
or http://tinyurl.com/6zby6c
http://www.ru.nl/ds/research/rfid/
http://technology.timesonline.co.uk/tol/news/tech_and_web/article4184481.=
ece=20
or http://tinyurl.com/64svrc
http://www.youtube.com/watch?v=3DNW3RGbQTLhE
http://news.cnet.com/8301-10784_3-9985886-7.html?hhTest=3D1
http://www.secureidnews.com/news/2008/07/10/nxp-sues-to-prevent-hackers-f=
rom-releasing-mifare-flaws/=20
or http://tinyurl.com/5brcxr
http://news.cnet.co.uk/software/0,39029694,49297810,00.htm
http://www.techradar.com/news/world-of-tech/tfl-responds-to-oyster-hack-r=
unling-428238=20
or http://tinyurl.com/6cc2ou
One of the papers:
http://www.cs.ru.nl/~flaviog/publications/Attack.MIFARE.pdf
Dutch court ruling:
http://zoeken.rechtspraak.nl/resultpage.aspx?snelzoeken=3Dtrue&search=
type=3Dljn&ljn=3DBD7578&u_ljn=3DBD7578=20
or http://tinyurl.com/5a5e3h
Secrecy and security:
http://www.schneier.com/crypto-gram-0205.html#1
Other research on Mifare:
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic=
&articleId=3D9078038=20
or http://tinyurl.com/6n42p4
http://www.cs.virginia.edu/~evans/pubs/usenix08/
http://eprint.iacr.org/2008/166
http://staff.science.uva.nl/~delaat/sne-2006-2007/p41/Report.pdf
http://www.translink.nl/media/bijlagen/nieuws/TNO_ICT_-_Security_Analysis=
_OV-Chipkaart_-_public_report.pdf=20
or http://tinyurl.com/66ptjy
Chinese compatible chip:
http://www.fmsh.com/english/product_chipcard.php?product=3DFM11RF32
http://www.fmsh.com/english/products/FM11RF32_FS_ENG.pdf
This essay originally appeared in the Guardian.
http://www.guardian.co.uk/technology/2008/aug/07/hacking.security
** *** ***** ******* *********** *************
Information Security and Liabilities
A recent study of Internet browsers worldwide discovered that over half=20
-- 52% -- of Internet Explorer users weren't using the current version=20
of the software. For other browsers the numbers were better, but not=20
much: 17% of Firefox users, 35% of Safari users, and 44% of Opera users=20
were using an old version.
This is particularly important because browsers are an increasingly=20
common vector for internet attacks, and old versions of browsers don't=20
have all their security patches up to date. They're open to attack=20
through vulnerabilities the vendors have already fixed.
Security professionals are quick to blame users who don't use the latest=20
update and install every patch. "Keeping up is critical for security,"=20
they say, and "if someone doesn't update their system, it's their own=20
fault that they get hacked." This sounds a lot like blaming the victim:=20
"He should have known not to walk down that deserted street; it's his=20
own fault he was mugged." Of course the victim could have =96and quite=20
possibly should have =96 taken further precautions, but the real blame=20
lies elsewhere.
It's not as if patching is easy. Even in a corporate setting, systems=20
administrators have trouble keeping up with the never-ending flow of=20
software patches. There could easily be dozens per week across all=20
operating systems and applications, and far too often they break things.=20
Microsoft's Automatic Update feature has automated the process, but=20
that's the exception. Patching is triage, and administrators are=20
constantly prioritizing it along with everything else they're doing.
It's the system that's broken. There's no other industry where shoddy=20
products are sold to a public that expects regular problems, and where=20
consumers are the ones who have to learn how to fix them. If an=20
automobile manufacturer has a problem with a car and issues a recall=20
notice, it's a rare occurrence and a big deal =96 and you can take you ca=
r=20
in and get it fixed for free. Computers are the only mass-market=20
consumer item that pushes this burden onto the consumer, requiring him=20
to have a high level of technical sophistication just to survive.
It doesn't have to be this way. It is possible to write quality=20
software. It is possible to sell software products that work properly,=20
and don't need to be constantly patched. The problem is that it's=20
expensive and time consuming. Software vendors won't do it, of course,=20
because the marketplace won't reward it.
The key to fixing this is software liabilities. Computers are also the=20
only mass-market consumer item where the vendors accept no liability for=20
faults. The reason automobiles are so well designed is that=20
manufacturers face liabilities if they screw up. A lack of software=20
liability is effectively a vast government subsidy of the computer=20
industry. It allows them to produce more products faster, with less=20
concern about safety, security, and quality.
Last summer, the House of Lords Science and Technology Committee issued=20
a report on "Personal Internet Security." I was invited to give=20
testimony for that report, and one of my recommendations was that=20
software vendors be held liable when they are at fault. Their final=20
report included that recommendation. The government rejected the=20
recommendations in that report last autumn, and last week the committee=20
issued a report on their follow-up inquiry, which still recommends=20
software liabilities.
Good for them.
I'm not implying that liabilities are easy, or that all the liability=20
for security vulnerabilities should fall on the vendor. But the courts=20
are good at partial liability. Any automobile liability suit has many=20
potential responsible parties: the car, the driver, the road, the=20
weather, possibly another driver and another car, and so on. Similarly,=20
a computer failure has several parties who may be partially responsible:=20
the software vendor, the computer vendor, the network vendor, the user,=20
possibly another hacker, and so on. But we're never going to get there=20
until we start. Software liability is the market force that will=20
incentivise companies to improve their software quality -- and=20
everyone's security.
This essay was previously published in the Guardian:
http://www.guardian.co.uk/technology/2008/jul/17/internet.security
House of Lords documents
http://www.publications.parliament.uk/pa/ld200607/ldselect/ldsctech/165/1=
65i.pdf=20
or http://tinyurl.com/27ca43
http://www.official-documents.gov.uk/document/cm72/7234/7234.pdf
http://www.publications.parliament.uk/pa/ld200708/ldselect/ldsctech/131/1=
31.pdf=20
or http://tinyurl.com/58ka8f
Liability as a way to fix externalities:
http://www.schneier.com/blog/archives/2007/01/information_sec_1.html
** *** ***** ******* *********** *************
Software Liabilities and Free Software
Whenever I write about software liabilities, many people ask about free=20
and open source software. If people who write free software, like=20
Password Safe, are forced to assume liabilities, they will simply not be=20
able to and free software would disappear.
Don't worry, they won't be.
The key to understanding this is that this sort of contractual liability=20
is part of a contract, and with free software -- or free anything --=20
there's no contract. Free software wouldn't fall under a liability=20
regime because the writer and the user have no business relationship;=20
they are not seller and buyer. I would hope the courts would realize=20
this without any prompting, but we could always pass a Good=20
Samaritan-like law that would protect people who distribute free=20
software. (The opposite would be an Attractive Nuisance-like law -- that=20
would be bad.)
There would be an industry of companies who provide liabilities for free=20
software. If Red Hat, for example, sold free Linux, they would have to=20
provide some liability protection. Yes, this would mean that they would=20
charge more for Linux; that extra would go to the insurance premiums.=20
That same sort of insurance protection would be available to companies=20
who use other free software packages.
The insurance industry is key to making this work. Luckily, they're good=20
at protecting people against liabilities. There's no reason to think=20
they won't be able to do it here.
** *** ***** ******* *********** *************
Schneier/BT News
Schneier interviewed by RU Sirius, in April:
http://www.rusiriusradio.com/2007/04/02/show-98-everything-the-us-governm=
ent-is-doing-about-security-is-wrong/=20
or http://tinyurl.com/yuvum2
http://www.10zenmonkeys.com/2007/04/10/homeland-security-follies/
** *** ***** ******* *********** *************
Congratulations to Our Millionth Terrorist!
The U.S terrorist watch list has hit one million names. I sure hope=20
we're giving our millionth terrorist a prize of some sort.
Who knew that a million people are terrorists. Why, there are only twice=20
as many burglars in the U.S. And fifteen times more terrorists than=20
arsonists.
Is this idiotic, or what?
Some people are saying fix it, but there seems to be no motivation to do=20
so. I'm sure the career incentives aren't aligned that way. You probably=20
get promoted by putting people on the list. But taking someone off the=20
list...if you're wrong, no matter how remote that possibility is, you=20
can probably lose your career. This is why in civilized societies we=20
have a judicial system, to be an impartial arbiter between law=20
enforcement and the accused. But that system doesn't apply here.
Kafka would be proud.
Okay, so it's not a million people. Seems to be about 400,000 people,=20
only 5% of Americans. Not that 400,000 terrorists is any less absurd.
"Screening and law enforcement agencies encountered the actual people on=20
the watch list (not false matches) more than 53,000 times from December=20
2003 to May 2007, according to a Government Accountability Office report=20
last fall."
Okay, so I have a question. How many of those 53,000 were arrested? Of=20
those who were not, why not? How many have we taken off the list after=20
we've investigated them?
http://www.aclu.org/privacy/35968prs20080714.html
http://www.fbi.gov/ucr/cius_04/offenses_reported/property_crime/burglary.=
html=20
or http://tinyurl.com/5wchf5
http://www.fbi.gov/ucr/cius_04/offenses_reported/property_crime/arson.htm=
l=20
or http://tinyurl.com/5qs5f7
http://www.cnn.com/2008/US/07/16/watch.list/index.html
http://www.propublica.org/article/aclu-million-on-terrorist-watch-list-71=
4=20
or http://tinyurl.com/5fbsxr
Bob Blakely runs the numbers.
http://notabob.blogspot.com/2008/07/round-up-usual-suspects.html
Jon Stewart makes fun of the list, too:
http://www.thedailyshow.com/video/index.jhtml?videoId=3D176627
** *** ***** ******* *********** *************
TrueCrypt's Deniable File System
Together with Tadayoshi Kohno, Steve Gribble, and three of their=20
students at the University of Washington, I have a new paper that breaks=20
the deniable encryption feature of TrueCrypt version 5.1a. Basically,=20
modern operating systems leak information like mad, making deniability a=20
very difficult requirement to satisfy.
The students did most of the actual work. I helped with the basic ideas,=20
and contributed the threat model. Deniability is a very hard feature to=20
achieve.
"There are several threat models against which a DFS could potentially=20
be secure:
"* One-Time Access. The attacker has a single snapshot of the disk=20
image. An example would be when the secret police seize Alice's computer.
"* Intermittent Access. The attacker has several snapshots of the disk=20
image, taken at different times. An example would be border guards who=20
make a copy of Alice's hard drive every time she enters or leaves the=20
country.
"* Regular Access. The attacker has many snapshots of the disk image,=20
taken in short intervals. An example would be if the secret police break=20
into Alice's apartment every day when she is away, and make a copy of=20
the disk each time."
Since we wrote our paper, TrueCrypt released version 6.0 of its=20
software, which claims to have addressed many of the issues we've=20
uncovered. We did not have time to analyze version 6.0. But, honestly,=20
I wouldn't trust it.
http://www.schneier.com/paper-truecrypt-dfs.html
http://www.truecrypt.org/docs/?s=3Dhidden-operating-system
http://www.truecrypt.org/docs/?s=3Dhidden-volume-precautions
Articles:
http://www.darkreading.com/document.asp?doc_id=3D159192&WT.svl=3Dnews2_1
http://www.pcworld.com/businesscenter/article/148513/data_can_leak_from_p=
artially_encrypted_disks.html=20
or http://tinyurl.com/57ek8x
http://yro.slashdot.org/article.pl?sid=3D08/07/17/2043248
** *** ***** ******* *********** *************
The DNS Vulnerability
Despite the best efforts of the security community, the details of a=20
critical Internet vulnerability discovered by Dan Kaminsky about six=20
months ago have leaked. Hackers are racing to produce exploit code, and=20
network operators who haven't already patched the hole are scrambling to=20
catch up. The whole mess is a good illustration of the problems with=20
researching and disclosing flaws like this.
The details of the vulnerability aren't important, but basically it's a=20
form of DNS cache poisoning. The DNS system is what translates domain=20
names people understand, like www.schneier.com, to IP addresses=20
computers understand: 204.11.246.1. There is a whole family of=20
vulnerabilities where the DNS system on your computer is fooled into=20
thinking that the IP address for www.badsite.com is really the IP=20
address for www.goodsite.com -- there's no way for you to tell the=20
difference -- and that allows the criminals at www.badsite.com to trick=20
you into doing all sorts of things, like giving up your bank account=20
details. Kaminsky discovered a particularly nasty variant of this=20
cache-poisoning attack.
Here's the way the timeline was supposed to work: Kaminsky discovered=20
the vulnerability about six months ago, and quietly worked with vendors=20
to patch it. (There's a fairly straightforward fix, although the=20
implementation nuances are complicated.) Of course, this meant=20
describing the vulnerability to them; why would companies like Microsoft=20
and Cisco believe him otherwise? On July 8, he held a press conference=20
to announce the vulnerability -- but not the details -- and reveal that=20
a patch was available from a long list of vendors. We would all have a=20
month to patch, and Kaminsky would release details of the vulnerability=20
at the Black Hat conference early next month.
Of course, the details leaked. How isn't important; it could have leaked=20
a zillion different ways. Too many people knew about it for it to remain=20
secret. Others who knew the general idea were too smart not to speculate=20
on the details. I'm kind of amazed the details remained secret for this=20
long; undoubtedly it had leaked into the underground community before=20
the public leak two days ago. So now everyone who back-burnered the=20
problem is rushing to patch, while the hacker community is racing to=20
produce working exploits.
What's the moral here? It's easy to condemn Kaminsky: If he had shut up=20
about the problem, we wouldn't be in this mess. But that's just wrong.=20
Kaminsky found the vulnerability by accident. There's no reason to=20
believe he was the first one to find it, and it's ridiculous to believe=20
he would be the last. Don't shoot the messenger. The problem is with the=20
DNS protocol; it's insecure.
The real lesson is that the patch treadmill doesn't work, and it hasn't=20
for years. This cycle of finding security holes and rushing to patch=20
them before the bad guys exploit those vulnerabilities is expensive,=20
inefficient and incomplete. We need to design security into our systems=20
right from the beginning. We need assurance. We need security engineers=20
involved in system design. This process won't prevent every=20
vulnerability, but it's much more secure -- and cheaper -- than the=20
patch treadmill we're all on now.
What a security engineer brings to the problem is a particular mindset.=20
He thinks about systems from a security perspective. It's not that he=20
discovers all possible attacks before the bad guys do; it's more that he=20
anticipates potential types of attacks, and defends against them even if=20
he doesn't know their details. I see this all the time in good=20
cryptographic designs. It's over-engineering based on intuition, but if=20
the security engineer has good intuition, it generally works.
Kaminsky's vulnerability is a perfect example of this. Years ago,=20
cryptographer Daniel J. Bernstein looked at DNS security and decided=20
that Source Port Randomization was a smart design choice. That's exactly=20
the work-around being rolled out now following Kaminsky's discovery.=20
Bernstein didn't discover Kaminsky's attack; instead, he saw a general=20
class of attacks and realized that this enhancement could protect=20
against them. Consequently, the DNS program he wrote in 2000, djbdns,=20
doesn't need to be patched; it's already immune to Kaminsky's attack.
That's what a good design looks like. It's not just secure against known=20
attacks; it's also secure against unknown attacks. We need more of this,=20
not just on the internet but in voting machines, ID cards,=20
transportation payment cards ... everywhere. Stop assuming that systems=20
are secure unless demonstrated insecure; start assuming that systems are=20
insecure unless designed securely.
Details of the attack:
http://darkoz.com/?p=3D15
http://blog.invisibledenizen.org/2008/07/kaminskys-dns-issue-accidentally=
-leaked.html=20
or http://tinyurl.com/6axgcu
News articles:
http://news.bbc.co.uk/2/hi/technology/7496735.stm
http://www.doxpara.com/?p=3D1162
http://www.kb.cert.org/vuls/id/800113
http://www.blackhat.com/html/bh-usa-08/bh-us-08-main.html
http://it.slashdot.org/it/08/07/21/2212227.shtml
http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html
http://addxorrol.blogspot.com/2008/07/on-dans-request-for-no-speculation.=
html=20
or http://tinyurl.com/5gp7vm
http://blog.wired.com/27bstroke6/2008/08/dns-flaw-much-w.html
Patch treadmill:
http://www.schneier.com/crypto-gram-0103.html#1
Assurance:
http://www.schneier.com/blog/archives/2007/08/assurance.html
The security mindset:
http://www.schneier.com/blog/archives/2008/03/the_security_mi.html
Dan Bernstein's work:
http://cr.yp.to/djbdns/forgery.html
http://cr.yp.to/djbdns/dnscache.html
This essay previously appeared on Wired.com:
http://www.wired.com/politics/security/commentary/securitymatters/2008/07=
/securitymatters_0723=20
or http://tinyurl.com/5d2kke
** *** ***** ******* *********** *************
Comments from Readers
There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and join =
in.
http://www.schneier.com/blog
** *** ***** ******* *********** *************
CRYPTO-GRAM is a free monthly newsletter providing summaries, analyses,=20
insights, and commentaries on security: computer and otherwise. You can=20
subscribe, unsubscribe, or change your address on the Web at=20
<http://www.schneier.com/crypto-gram.html>. Back issues are also=20
available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable. Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the=20
best sellers "Beyond Fear," "Secrets and Lies," and "Applied=20
Cryptography," and an inventor of the Blowfish and Twofish algorithms.=20
He is the Chief Security Technology Officer of BT (BT acquired=20
Counterpane in 2006), and is on the Board of Directors of the Electronic=20
Privacy Information Center (EPIC). He is a frequent writer and lecturer=20
on security topics. See <http://www.schneier.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not=20
necessarily those of BT.
Copyright (c) 2008 by Bruce Schneier.