CRYPTO-GRAM, March 15, 2009
Bruce Schneier <[email protected]> Sat, 14 Mar 2009 23:56:29 -0500
| Newsgroups | gmane.comp.security.crypto-gram |
|---|---|
| Message-ID | <[email protected]> |
CRYPTO-GRAM
March 15, 2009
by Bruce Schneier
Chief Security Technology Officer, BT
[email protected]
http://www.schneier.com
A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0903.html>. These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>. An RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Perverse Security Incentives
Privacy in the Age of Persistence
News
Insiders
The Doghouse: Singularics
Three Security Anecdotes from the Insect World
The Kindness of Strangers
New eBay Fraud
Schneier News
IT Security: Blaming the Victim
Balancing Security and Usability in Authentication
Comments from Readers
** *** ***** ******* *********** *************
Perverse Security Incentives
An employee of Whole Foods in Ann Arbor, Michigan, was fired in 2007 for=20
apprehending a shoplifter. More specifically, he was fired for touching=20
a customer, even though that customer had a backpack filled with stolen=20
groceries and was running away with them.
I regularly see security decisions that, like the Whole Foods incident,=20
seem to make absolutely no sense. However, in every case, the decisions=20
actually make perfect sense once you understand the underlying=20
incentives driving the decision. All security decisions are trade-offs,=20
but the motivations behind them are not always obvious: They're often=20
subjective, and driven by external incentives. And often security=20
trade-offs are made for nonsecurity reasons.
Almost certainly, Whole Foods has a no-touching-the-customer policy=20
because its attorneys recommended it. "No touching" is a security=20
measure as well, but it's security against customer lawsuits. The cost=20
of these lawsuits would be much, much greater than the $346 worth of=20
groceries stolen in this instance. Even applied to suspected=20
shoplifters, the policy makes sense: The cost of a lawsuit resulting=20
from tackling an innocent shopper by mistake would be far greater than=20
the cost of letting actual shoplifters get away. As perverse it may=20
seem, the result is completely reasonable given the corporate incentives=20
-- Whole Foods wrote a corporate policy that benefited itself.
At least, it works as long as the police and other factors keep=20
society's shoplifter population down to a reasonable level.
Incentives explain much that is perplexing about security trade-offs.=20
Why does King County, Washington, require one form of ID to get a=20
concealed-carry permit, but two forms of ID to pay for the permit by=20
check? Making a mistake on a gun permit is an abstract problem, but a=20
bad check actually costs some department money.
In the decades before 9/11, why did the airlines fight every security=20
measure except the photo-ID check? Increased security annoys their=20
customers, but the photo-ID check solved a security problem of a=20
different kind: the resale of nonrefundable tickets. So the airlines=20
were on board for that one.
And why does the TSA confiscate liquids at airport security, on the off=20
chance that a terrorist will try to make a liquid explosive instead of=20
using the more common solid ones? Because the officials in charge of=20
the decision used CYA security measures to prevent specific, known=20
tactics rather than broad, general ones.
The same misplaced incentives explain the ongoing problem of innocent=20
prisoners spending years in places like Guantanamo and Abu Ghraib. The=20
solution might seem obvious: Release the innocent ones, keep the guilty=20
ones, and figure out whether the ones we aren't sure about are innocent=20
or guilty. But the incentives are more perverse than that. Who is=20
going to sign the order releasing one of those prisoners? Which=20
military officer is going to accept the risk, no matter how small, of=20
being wrong?
I read almost five years ago that prisoners were being held by the=20
United States far longer than they should, because "no one wanted to be=20
responsible for releasing the next Osama bin Laden." That incentive to=20
do nothing hasn't changed. It might have even gotten stronger, as these=20
innocents languish in prison.
In all these cases, the best way to change the trade-off is to change=20
the incentives. Look at why the Whole Foods case works. Store=20
employees don't have to apprehend shoplifters, because society created a=20
special organization specifically authorized to lay hands on people the=20
grocery store points to as shoplifters: the police. If we want more=20
rationality out of the TSA, there needs to be someone with a broader=20
perspective willing to deal with general threats rather than specific=20
targets or tactics.
For prisoners, society has created a special organization specifically=20
entrusted with the role of judging the evidence against them and=20
releasing them if appropriate: the judiciary. It's only because the=20
George W. Bush administration decided to remove the Guantanamo prisoners=20
from the legal system that we are now stuck with these perverse=20
incentives. Our country would be smart to move as many of these people=20
through the court system as we can.
This essay originally appeared on Wired.com.
http://www.wired.com/politics/security/commentary/securitymatters/2009/02=
/securitymatters_0226=20
or http://tinyurl.com/aku6bf
Whole Foods incident:
http://www.mlive.com/news/index.ssf/2007/12/grocery_worker_fired_for_stop=
p.html=20
or http://tinyurl.com/3dma49
King County ID checks:
http://www.kingcounty.gov/safety/sheriff/Services/Gun.aspx
Terrorists as liquid bombers:
http://www.schneier.com/blog/archives/2007/08/details_on_the_1.html
CYA security:
http://www.schneier.com/blog/archives/2007/02/cya_security_1.html
The perverse incentives of holding terrorist suspects in custody:
http://query.nytimes.com/gst/fullpage.html?res=3D9C00E3DF133EF934A15756C0=
A9629C8B63&sec=3D&spon=3D&pagewanted=3Dall=20
or http://tinyurl.com/cgh86n
** *** ***** ******* *********** *************
Privacy in the Age of Persistence
(Note: This isn't the first time I have written about this topic, and it=20
surely won't be the last. I think I did a particularly good job=20
summarizing the issues this time, which is why I am reprinting it.)
Welcome to the future, where everything about you is saved. A future=20
where your actions are recorded, your movements are tracked, and your=20
conversations are no longer ephemeral. A future brought to you not by=20
some 1984-like dystopia, but by the natural tendencies of computers to=20
produce data.
Data is the pollution of the information age. It's a natural byproduct=20
of every computer-mediated interaction. It stays around forever, unless=20
it's disposed of. It is valuable when reused, but it must be done=20
carefully. Otherwise, its after effects are toxic.
And just as 100 years ago people ignored pollution in our rush to build=20
the Industrial Age, today we're ignoring data in our rush to build the=20
Information Age.
Increasingly, you leave a trail of digital footprints throughout your=20
day. Once you walked into a bookstore and bought a book with cash. Now=20
you visit Amazon, and all of your browsing and purchases are recorded.=20
You used to buy a train ticket with coins; now your electronic fare card=20
is tied to your bank account. Your store affinity cards give you=20
discounts; merchants use the data on them to reveal detailed purchasing=20
patterns.
Data about you is collected when you make a phone call, send an e-mail=20
message, use a credit card, or visit a website. A national ID card will=20
only exacerbate this.
More computerized systems are watching you. Cameras are ubiquitous in=20
some cities, and eventually face recognition technology will be able to=20
identify individuals. Automatic license plate scanners track vehicles in=20
parking lots and cities. Color printers, digital cameras, and some=20
photocopy machines have embedded identification codes. Aerial=20
surveillance is used by cities to find building permit violators and by=20
marketers to learn about home and garden size.
As RFID chips become more common, they'll be tracked, too. Already you=20
can be followed by your cell phone, even if you never make a call. This=20
is wholesale surveillance; not "follow that car," but "follow every car."
Computers are mediating conversation as well. Face-to-face conversations=20
are ephemeral. Years ago, telephone companies might have known who you=20
called and how long you talked, but not what you said. Today you chat in=20
e-mail, by text message, and on social networking sites. You blog and=20
you Twitter. These conversations -- with family, friends, and colleagues=20
-- can be recorded and stored.
It used to be too expensive to save this data, but computer memory is=20
now cheaper. Computer processing power is cheaper, too; more data is=20
cross-indexed and correlated, and then used for secondary purposes. What=20
was once ephemeral is now permanent.
Who collects and uses this data depends on local laws. In the US,=20
corporations collect, then buy and sell, much of this information for=20
marketing purposes. In Europe, governments collect more of it than=20
corporations. On both continents, law enforcement wants access to as=20
much of it as possible for both investigation and data mining.
Regardless of country, more organizations are collecting, storing, and=20
sharing more of it.
More is coming. Keyboard logging programs and devices can already record=20
everything you type; recording everything you say on your cell phone is=20
only a few years away.
A "life recorder" you can clip to your lapel that'll record everything=20
you see and hear isn't far behind. It'll be sold as a security device,=20
so that no one can attack you without being recorded. When that happens,=20
will not wearing a life recorder be used as evidence that someone is up=20
to no good, just as prosecutors today use the fact that someone left his=20
cell phone at home as evidence that he didn't want to be tracked?
You're living in a unique time in history: the technology is here, but=20
it's not yet seamless. Identification checks are common, but you still=20
have to show your ID. Soon it'll happen automatically, either by=20
remotely querying a chip in your wallets or by recognizing your face on=20
camera.
And all those cameras, now visible, will shrink to the point where you=20
won't even see them. Ephemeral conversation will all but disappear, and=20
you'll think it normal. Already your children live much more of their=20
lives in public than you do. Your future has no privacy, not because of=20
some police-state governmental tendencies or corporate malfeasance, but=20
because computers naturally produce data.
Cardinal Richelieu famously said: "If one would give me six lines=20
written by the hand of the most honest man, I would find something in=20
them to have him hanged." When all your words and actions can be saved=20
for later examination, different rules have to apply.
Society works precisely because conversation is ephemeral; because=20
people forget, and because people don't have to justify every word they=20
utter.
Conversation is not the same thing as correspondence. Words uttered in=20
haste over morning coffee, whether spoken in a coffee shop or thumbed on=20
a BlackBerry, are not official correspondence. A data pattern indicating=20
"terrorist tendencies" is no substitute for a real investigation. Being=20
constantly scrutinized undermines our social norms; furthermore, it's=20
creepy. Privacy isn't just about having something to hide; it's a basic=20
right that has enormous value to democracy, liberty, and our humanity.
We're not going to stop the march of technology, just as we cannot=20
un-invent the automobile or the coal furnace. We spent the industrial=20
age relying on fossil fuels that polluted our air and transformed our=20
climate. Now we are working to address the consequences. (While still=20
using said fossil fuels, of course.) This time around, maybe we can be a=20
little more proactive.
Just as we look back at the beginning of the previous century and shake=20
our heads at how people could ignore the pollution they caused, future=20
generations will look back at us -- living in the early decades of the=20
information age -- and judge our solutions to the proliferation of data.
We must, all of us together, start discussing this major societal change=20
and what it means. And we must work out a way to create a future that=20
our grandchildren will be proud of.
This essay originally appeared on the BBC.com website.
http://news.bbc.co.uk/1/hi/technology/7897892.stm
National ID cards:
http://www.schneier.com/essay-160.html
Surveillance cameras:
http://www.schneier.com/essay-225.html
RFID chips:
http://epic.org/privacy/rfid/
Cell phone surveillance:
http://computerworld.com/action/article.do?command=3DviewArticleBasic&art=
icleId=3D9127462=20
or http://tinyurl.com/au2f4n
Wholesale surveillance:
http://www.schneier.com/essay-147.html
Data mining:
http://www.schneier.com/essay-108.html
The future of surveillance:
http://www.schneier.com/essay-109.html
Face recognition:
http://epic.org/privacy/facerecognition/
Privacy and the younger generation:
http://nymag.com/news/features/27341/
Ill effects of constant surveillance:
http://news.bbc.co.uk/1/hi/uk_politics/7872425.stm
The value of privacy:
http://www.schneier.com/essay-114.html
** *** ***** ******* *********** *************
News
Uni-ball is using fear to sell its hard-to-erase pen -- but it's the=20
wrong fear. They're confusing check-washing fraud, where someone takes=20
a check and changes the payee and maybe the amount, with identity theft.=20
And how can someone steal money from me by erasing and changing=20
information on a tax form? Are they going to cause my refund check to=20
be sent to another address? This is getting awfully Byzantine.
http://videogum.com/archives/commercials/s-epatha-merkerson-will-terrif_0=
45001.html=20
or http://tinyurl.com/7jcful
http://www.schneier.com/blog/archives/2007/09/using_fear_to_s.html
Los Alamos has lost 80 computers: no idea if they're stolen, or just=20
misplaced. Typical story -- not even worth commenting on -- but this=20
great comment explains a lot about what was wrong with their security=20
policy: "The letter, addressed to Department of Energy security=20
officials, contends that 'cyber security issues were not engaged in a=20
timely manner' because the computer losses were treated as a 'property=20
management issue.'" The real risk in computer losses is the data, not=20
the hardware. I thought everyone knew that.
http://www.google.com/hostednews/afp/article/ALeqM5jXipyrzU1GKO4KQ3f4hhKy=
LvJvTA=20
or http://tinyurl.com/d7oxy5
Difficult-to-pronounce things are judged to be more risky than=20
easy-to-pronounce things:
http://www.ncbi.nlm.nih.gov/pubmed/19170941
New paper: "WiFi networks and malware epidemiology," by Hao Hu, Steven=20
Myers, Vittoria Colizza, and Alessandro Vespignani. Honestly, I'm not=20
sure I understood most of the article. And I don't think that their=20
model is all that great. But I like to see these sorts of methods=20
applied to malware and infection rates.
http://www.pnas.org/content/early/2009/01/26/0811973106
http://arxiv.org/abs/0706.3146
HIPAA accountability in U.S. stimulus bill:
http://www.schneier.com/blog/archives/2009/02/hipaa_accountab.html
Terrorism common sense from MI6:
http://www.theregister.co.uk/2009/02/11/mi6_spy_rubbishes_terrorism_fear/=
=20
or http://tinyurl.com/cxfl8s
Here's an analysis of 30,000 passwords from phpbb.com.
http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html
It's similar to my analysis of 34,000 MySpace passwords.
http://www.schneier.com/blog/archives/2006/12/realworld_passw.html
Seems like we still can't choose good passwords. Conficker.B exploits=20
this, trying about 200 common passwords to help spread itself.
http://www.sophos.com/blogs/gc/g/2009/01/16/passwords-conficker-worm/
Blog entry:
http://www.schneier.com/blog/archives/2009/02/another_passwor.html
Evidence of the effectiveness of the "broken windows" theory of crime=20
fighting:
http://www.boston.com/news/local/massachusetts/articles/2009/02/08/breakt=
hrough_on_broken_windows/=20
or http://tinyurl.com/cslqo5
http://www.ncjrs.gov/App/publications/Abstract.aspx?id=3D246202
The NSA wants help eavesdropping on Skype:
http://www.theregister.co.uk/2009/02/12/nsa_offers_billions_for_skype_pwn=
age/=20
or http://tinyurl.com/a9hn2n
I'm sure this is a real problem. Here's an article claiming that=20
Italian criminals are using Skype more than the telephone because of=20
eavesdropping concerns.
http://www.theregister.co.uk/2009/02/16/italian_crooks_skype/
A study from New Jersey shows that Megan's Law -- laws designed to=20
identity sex offenders to the communities they live in -- is ineffective=20
in reducing sex crimes or deterring recidivists.
http://www.nj.com/news/index.ssf/2009/02/study_finds_megans_law_fails_t_1=
.html=20
or http://tinyurl.com/b2mql2
Another Conficker variant: Conficker B++. This is one well-designed=20
piece of malware.
http://www.schneier.com/blog/archives/2009/02/new_conficker_v.html
President Obama has tasked Melissa Hathaway with conducting a 60-day=20
review of the nation's cybersecurity policies.
http://www.usatoday.com/tech/2009-02-16-cybersecurity-expert-obama_N.htm=20
or http://tinyurl.com/cx3kon
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic=
&articleId=3D9127682&intsrc=3Dnews_ts_head=20
or http://tinyurl.com/d2ygpp
This interview, conducted last year, will give you a good idea of how=20
she thinks.
http://www2.computer.org/portal/web/computingnow/1208/whatsnew/securityan=
dprivacy=20
or http://tinyurl.com/by28l7
Maine man tries to build a dirty bomb and no one cares, probably because=20
he isn't Muslim. White supremacist terrorism just isn't sexy these days.
http://jonathanstray.com/maine-man-tries-to-build-dirty-bomb
There are rumors of prototype electromagnetic pulse grenades:
http://www.theregister.co.uk/2009/02/12/electropulse_grenades/
TrapCall is a new service that reveals the caller ID on anonymous or=20
blocked calls.
http://blog.wired.com/27bstroke6/2009/02/trapcall.html
Judge orders defendant to decrypt laptop: interesting Fifth Amendment cas=
e.
http://news.cnet.com/8301-13578_3-10172866-38.html
Use this shower mirror with a hidden camera to catch the lovers of=20
cheating spouses:
http://www.dpl-surveillance-equipment.com/100611.html
The site has a wide variety of hidden cameras in common household objects=
.
http://www.dpl-surveillance-equipment.com/wireless_hidden_cameras.html
University of Miami law professor Michael Froomkin writes about ID cards=20
and society in "Identity Cards and Identity Romanticism."
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D1309222
http://www.schneier.com/blog/archives/2009/03/michael_froomki.html
This commentary on the UK government national security strategy is=20
scary: "Sir David Omand, the former Whitehall security and intelligence=20
co-ordinator, sets out a blueprint for the way the state will mine data=20
-- including travel information, phone records and emails -- held by=20
public and private bodies and admits: 'Finding out other people's=20
secrets is going to involve breaking everyday moral rules.'" In short:=20
it's immoral, but we're going to do it anyway.
http://www.guardian.co.uk/uk/2009/feb/25/personal-data-terrorism-surveill=
ance=20
or http://tinyurl.com/c5ll6r
Programs "staple" and "unstaple" perform all-or-nothing encryption.=20
Just demonstration code, but interesting all the same.
http://sysnet.ucsd.edu/projects/staple/
Interesting paper: "Optimised to Fail: Card Readers for Online Banking,"=20
by Saar Drimer, Steven J. Murdoch, and Ross Anderson.
http://www.cl.cam.ac.uk/~sjm217/papers/fc09optimised.pdf
http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-read=
ers-for-online-banking/=20
or http://tinyurl.com/bdnafk
I'm sure you need some skill to actually use this self-defense pen, and=20
I'm also sure it'll get through airport security checkpoints just fine.
http://www.botachtactical.com/kzxtremepen.html
This article gives an overview of U.S. military robots, and discusses=20
some of the issues regarding the ethics of their use in war.
http://www.thenewatlantis.com/publications/military-robots-and-the-laws-o=
f-war=20
or http://tinyurl.com/csoj98
The article was adapted from his book Wired for War: The Robotics=20
Revolution and Conflict in the 21st Century, published this year. I=20
bought the book, but I have not read it yet. Related is this paper on=20
the ethics of autonomous military robots.
http://www.schneier.com/blog/archives/2008/01/ethics_of_auton.html
Blog entry:
http://www.schneier.com/blog/archives/2009/03/history_and_eth.html
Secret NATO documents about the war in Afghanistan leaked due to bad=20
password:
https://secure.wikileaks.org/wiki/N1
Security theater scare mongering, in hotels and churches:
http://news.bbc.co.uk/1/hi/england/london/7933004.stm
http://www.cnn.com/2009/CRIME/03/09/church.security/index.html
http://www.schneier.com/blog/archives/2009/03/security_theate_2.html
Fascinating history of the techniques used to distribute child porn=20
throughout the world:
http://wikileaks.org/wiki/My_life_in_child_porn
http://www.schneier.com/blog/archives/2009/03/the_techniques.html#c356628=
=20
or http://tinyurl.com/asnc63
Google Maps spam:
http://www.schneier.com/blog/archives/2009/03/google_map_spam.html
This story of the world's largest diamond heist reads like a movie plot:
http://www.wired.com/politics/law/magazine/17-04/ff_diamonds?currentPage=3D=
all=20
or http://tinyurl.com/ak8hrx
Many Sentex keypads, which are used to secure doors everywhere, can be=20
opened with a default admin password:
http://www.schneier.com/blog/archives/2009/03/the_doghouse_se_1.html
** *** ***** ******* *********** *************
Insiders
Rajendrasinh Makwana was a UNIX contractor for Fannie Mae. On October=20
24, he was fired. Before he left, he slipped a logic bomb into the=20
organization's network. The bomb would have "detonated" on January 31.=20
It was programmed to disable access to the server on which it was=20
running, block any network monitoring software, systematically and=20
irretrievably erase everything -- and then replicate itself on all 4,000=20
Fannie Mae servers. Court papers claim the damage would have been in=20
the millions of dollars, a number that seems low. Fannie Mae would have=20
been shut down for at least a week.
Luckily -- and it does seem it was pure luck -- another programmer=20
discovered the script a week later, and disabled it.
Insiders are a perennial problem. They have access, and they're known=20
by the system. They know how the system and its security works, and its=20
weak points. They have opportunity. Bank heists, casino thefts,=20
large-scale corporate fraud, train robberies: many of the most=20
impressive criminal attacks involve insiders. And, like Makwana's=20
attempt at revenge, these insiders can have pretty intense motives --=20
motives that can only intensify as the economy continues to suffer and=20
layoffs increase.
Insiders are especially pernicious attackers because they're trusted.=20
They have access because they're *supposed* to have access. They have=20
opportunity, and an understanding of the system, because they use it --=20
or they designed, built, or installed it. They're already inside the=20
security system, making them much harder to defend against.
It's not possible to design a system without trusted people. They're=20
everywhere. In offices, employees are trusted people given access to=20
facilities and resources, and allowed to act -- sometimes broadly,=20
sometimes narrowly -- in the company's name. In stores, employees are=20
allowed access to the back room and the cash register; and customers are=20
trusted to walk into the store and touch the merchandise. IRS employees=20
are trusted with personal tax information; hospital employees are=20
trusted with personal health information. Banks, airports, and prisons=20
couldn't operate without trusted people.
Replacing trusted people with computers doesn't make the problem go=20
away; it just moves it around and makes it even more complex. The=20
computer, software, and network designers, implementers, coders,=20
installers, maintainers, etc. are all trusted people. See any analysis=20
of the security of electronic voting machines, or some of the frauds=20
perpetrated against computerized gambling machines, for some graphic=20
examples of the risks inherent in replacing people with computers.
Of course, this problem is much, much older than computers. And the=20
solutions haven't changed much throughout history, either. There are=20
five basic techniques to deal with trusted people:
1. Limit the number of trusted people. This one is obvious. The fewer=20
people who have root access to the computer system, know the combination=20
to the safe, or have the authority to sign checks, the more secure the=20
system is.
2. Ensure that trusted people are also trustworthy. This is the idea=20
behind background checks, lie detector tests, personality profiling,=20
prohibiting convicted felons from getting certain jobs, limiting other=20
jobs to citizens, the TSA's no-fly list, and so on, as well as behind=20
bonding employees, which means there are deep pockets standing behind=20
them if they turn out not to be trustworthy.
3. Limit the amount of trust each person has. This is=20
compartmentalization; the idea here is to limit the amount of damage a=20
person can do if he ends up not being trustworthy. This is the concept=20
behind giving people keys that only unlock their office or passwords=20
that only unlock their account, as well as "need to know" and other=20
levels of security clearance.
4. Give people overlapping spheres of trust. This is what security=20
professionals call defense in depth. It's why it takes two people with=20
two separate keys to launch nuclear missiles, and two signatures on=20
corporate checks over a certain value. It's the idea behind bank=20
tellers requiring management overrides for high-value transactions,=20
double-entry bookkeeping, and all those guards and cameras at casinos.=20
It's why, when you go to a movie theater, one person sells you a ticket=20
and another person standing a few yards away tears it in half: It makes=20
it much harder for one employee to defraud the system. It's why key=20
bank employees need to take their two-week vacations all at once -- so=20
their replacements have a chance to uncover any fraud.
5. Detect breaches of trust after the fact and prosecute the guilty.=20
In the end, the four previous techniques can only do so well. Trusted=20
people can subvert a system. Most of the time, we discover the security=20
breach after the fact and then punish the perpetrator through the legal=20
system: publicly, so as to provide a deterrence effect and increase the=20
overall level of security in society. This is why audit is so vital.
These security techniques don't only protect against fraud or sabotage;=20
they protect against the more common problem: mistakes. Trusted people=20
aren't perfect; they can inadvertently cause damage. They can make a=20
mistake, or they can be tricked into making a mistake through social=20
engineering.
Good security systems use multiple measures, all working together.=20
Fannie Mae certainly limits the number of people who have the ability to=20
slip malicious scripts into their computer systems, and certainly limits=20
the access that most of these people have. It probably has a hiring=20
process that makes it less likely that malicious people come to work at=20
Fannie Mae. It obviously doesn't have an audit process by which a=20
change one person makes on the servers is checked by someone else; I'm=20
sure that would be prohibitively expensive. Certainly the company's IT=20
department should have terminated Makwana's network access as soon as he=20
was fired, and not at the end of the day.
In the end, systems will always have trusted people who can subvert=20
them. It's important to keep in mind that incidents like this don't=20
happen very often; that most people are honest and honorable. Security=20
is very much designed to protect against the dishonest minority. And=20
often little things -- like disabling access immediately upon=20
termination -- can go a long way.
This essay originally appeared on the Wall Street Journal website.
http://online.wsj.com/article/SB123447990459779609.html
Makwana:
http://blogs.zdnet.com/BTL/?p=3D11905
http://www.theregister.co.uk/2009/01/29/fannie_mae_sabotage_averted/
http://blog.wired.com/27bstroke6/2009/01/fannie.html
Economic downturn increases insider threat:
http://news.bbc.co.uk/1/hi/technology/7875904.stm
Hospital employees illegally accessing patient data:
http://www.schneier.com/blog/archives/2007/10/27_suspended_fo.html
Insecurity in electronic voting machines:
http://www.schneier.com/blog/archives/2006/11/voting_technolo.html
http://www.nytimes.com/2008/01/06/magazine/06Vote-t.html
http://www.schneier.com/essay-101.html
http://freedom-to-tinker.com/blog/dwallach/vendor-misinformation-e-voting=
-world=20
or http://tinyurl.com/5c7kxn
http://www.schneier.com/blog/archives/2008/08/diebold_finally.html
http://blog.wired.com/27bstroke6/2009/01/diebold-audit-l.html
http://www.schneier.com/essay-068.html
http://www.crypto.com/blog/ohio_voting/
http://www.huffingtonpost.com/kirsten-anderson/an-interview-with-david-w_=
b_64063.html=20
or http://tinyurl.com/ad6rn3
Computerized gambling machine fraud:
http://www.reviewjournal.com/lvrj_home/1998/Jan-10-Sat-1998/news/6745681.=
html=20
or http://tinyurl.com/xswg
Replacing people with computers:
http://www.schneier.com/blog/archives/2008/12/comparing_the_s.html
Audit:
http://www.schneier.com/blog/archives/2008/12/audit.html
** *** ***** ******* *********** *************
The Doghouse: Singularics
This is priceless:
"Our advances in Prime Number Theory have led to a new branch of=20
mathematics called Neutronics. Neutronic functions make possible for the=20
first time the ability to analyze regions of mathematics commonly=20
thought to be undefined, such as the point where one is divided by zero.=20
In short, we have developed a new way to analyze the undefined point at=20
the singularity which appears throughout higher mathematics.
"This new analytic technique has given us profound insight into the way=20
that prime numbers are distributed throughout the integers. According to=20
RSA's website, there are over 1 billion licensed instances of RSA=20
public-key encryption in use in the world today. Each of these instances=20
of the prime number based RSA algorithm can now be deciphered using=20
Neutronic analysis. Unlike RSA, Neutronic Encryption is not based on two=20
large prime numbers but rather on the Neutronic forces that govern the=20
distribution of the primes themselves. The encryption that results from=20
Singularic's Neutronic public-key algorithm is theoretically impossible=20
to break."
You'd think that anyone who claims to be able to decrypt RSA at the key=20
lengths in use today would, maybe, um, demonstrate that at least once.=20
Otherwise, this can all be safely ignored as snake oil.
The founder and CTO also claims to have proved the Riemann Hypothesis,=20
if you care to wade through the 63-page paper.
http://www.singularics.com/products/encryption/
Snake oil:
http://www.schneier.com/crypto-gram-9902.html#snakeoil
Riemann Hypothesis "proof":
http://www.singularics.com/science/mathematics/OnNeutronicFunctions.pdf=20
or http://tinyurl.com/agmoy9
** *** ***** ******* *********** *************
Three Security Anecdotes from the Insect World
Beet armyworm caterpillars react to the sound of a passing wasp by=20
freezing in place, or even dropping off the plant. Unfortunately,=20
armyworm intelligence isn't good enough to tell the difference between=20
enemy aircraft (the wasps that prey on them) and harmless commercial=20
flights (bees); they react the same way to either. So by producing=20
nectar for bees, plants not only get pollinated, but also gain some=20
protection against being eaten by caterpillars.
The small hive beetle lives by entering beehives to steal combs and=20
honey. They home in on the hives by detecting the bees' own alarm=20
pheromones. They also track in yeast that ferments the pollen and=20
releases chemicals that spoof the alarm pheromones, attracting more=20
beetles and more yeast. Eventually the bees abandon the hive, leaving=20
the beetles and yeast to finish off the pollen and honey.
Mountain alcon blue caterpillars get ants to feed them by spoofing a=20
biometric: the sounds made by the queen ant.
http://scienceblogs.com/notrocketscience/2008/12/buzzing_bees_scare_cater=
pillars_away_from_plants.php=20
or http://tinyurl.com/b2fp7m
http://scienceblogs.com/notrocketscience/2009/01/beetle_and_yeast_team_up=
_against_bees.php=20
or http://tinyurl.com/96kdea
http://scienceblogs.com/notrocketscience/2009/02/butterflies_scrounge_off=
_ants_by_mimicking_the_music_of_quee.php=20
or http://tinyurl.com/cxu8cm
** *** ***** ******* *********** *************
The Kindness of Strangers
When I was growing up, children were commonly taught: "don't talk to=20
strangers." Strangers might be bad, we were told, so it's prudent to=20
steer clear of them.
And yet most people are honest, kind, and generous, especially when=20
someone asks them for help. If a small child is in trouble, the=20
smartest thing he can do is find a nice-looking stranger and talk to him.
These two pieces of advice may seem to contradict each other, but they=20
don't. The difference is that in the second instance, the child is=20
choosing which stranger to talk to. Given that the overwhelming majority=20
of people will help, the child is likely to get help if he chooses a=20
random stranger. But if a stranger comes up to a child and talks to him=20
or her, it's not a random choice. It's more likely, although still=20
unlikely, that the stranger is up to no good.
As a species, we tend help each other, and a surprising amount of our=20
security and safety comes from the kindness of strangers. During=20
disasters: floods, earthquakes, hurricanes, bridge collapses. In times=20
of personal tragedy. And even in normal times.
If you're sitting in a caf=E9 working on your laptop and need to get up=20
for a minute, ask the person sitting next to you to watch your stuff.=20
He's very unlikely to steal anything. Or, if you're nervous about that,=20
ask the three people sitting around you. Those three people don't know=20
each other, and will not only watch your stuff, but they'll also watch=20
each other to make sure no one steals anything.
Again, this works because you're selecting the people. If three people=20
walk up to you in the cafe and offer to watch your computer while you go=20
to the bathroom, don't take them up on that offer. Your odds of getting=20
three honest people are much lower.
Some computer systems rely on the kindness of strangers, too. The=20
Internet works because nodes benevolently forward packets to each other=20
without any recompense from either the sender or receiver of those=20
packets. Wikipedia works because strangers are willing to write for, and=20
edit, an encyclopedia =AD with no recompense.
Collaborative spam filtering is another example. Basically, once someone=20
notices a particular e-mail is spam, he marks it, and everyone else in=20
the network is alerted that it's spam. Marking the e-mail is a=20
completely altruistic task; the person doing it gets no benefit from the=20
action. But he receives benefit from everyone else doing it for other=20
e-mails.
Tor is a system for anonymous Web browsing. The details are complicated,=20
but basically, a network of Tor servers passes Web traffic among each=20
other in such a way as to anonymize where it came from. Think of it as a=20
giant shell game. As a Web surfer, I put my Web query inside a shell and=20
send it to a random Tor server. That server knows who I am but not what=20
I am doing. It passes that shell to another Tor server, which passes it=20
to a third. That third server -- which knows what I am doing but not who=20
I am -- processes the Web query. When the Web page comes back to that=20
third server, the process reverses itself and I get my Web page.=20
Assuming enough Web surfers are sending enough shells through the=20
system, even someone eavesdropping on the entire network can't figure=20
out what I'm doing.
It's a very clever system, and it protects a lot of people, including=20
journalists, human rights activists, whistleblowers, and ordinary people=20
living in repressive regimes around the world. But it only works because=20
of the kindness of strangers. No one gets any benefit from being a Tor=20
server; it uses up bandwidth to forward other people's packets around.=20
It's more efficient to be a Tor client and use the forwarding=20
capabilities of others. But if there are no Tor servers, then there's no=20
Tor. Tor works because people are willing to set themselves up as=20
servers, at no benefit to them.
Alibi clubs work along similar lines. You can find them on the Internet,=20
and they're loose collections of people willing to help each other out=20
with alibis. Sign up, and you're in. You can ask someone to pretend to=20
be your doctor and call your boss. Or someone to pretend to be your boss=20
and call your spouse. Or maybe someone to pretend to be your spouse and=20
call your boss. Whatever you want, just ask and some anonymous stranger=20
will come to your rescue. And because your accomplice is an anonymous=20
stranger, it's safer than asking a friend to participate in your ruse.
There are risks in these sorts of systems. Regularly, marketers and=20
other people with agendas try to manipulate Wikipedia entries to suit=20
their interests. Intelligence agencies can, and almost certainly have,=20
set themselves up as Tor servers to better eavesdrop on traffic. And a=20
do-gooder could join an alibi club just to expose other members. But for=20
the most part, strangers are willing to help each other, and systems=20
that harvest this kindness work very well on the Internet.
This essay originally appeared on the Wall Street Journal website.
http://online.wsj.com/article/SB123567809587886053.html
Tor:
http://www.torproject.org/torusers.html.en
http://www.torproject.org
Alibi clubs:
http://www.nytimes.com/2004/06/26/technology/26ALIB.html?hp
http://www.alibinetwork.com/index.jsp
** *** ***** ******* *********** *************
New eBay Fraud
Here's a clever fraud, exploiting relative delays in eBay, PayPal, and=20
UPS shipping.
"The buyer reported the item as 'destroyed' and demanded and got a=20
refund from Paypal. When the buyer shipped it back to Chad and he opened=20
it, he found there was nothing wrong with it -- except that the scammer=20
had removed the memory, processor and hard drive. Now Chad is out $500=20
and left with a shell of a computer, and since the item was 'received'=20
Paypal won't do anything."
Very clever. The seller accepted the return from UPS after a visual=20
inspection, so UPS considered the matter closed. PayPal and eBay both=20
considered the matter closed. if the amount was large enough, the=20
seller could sue, but how could he prove that the computer was=20
functional when he sold it?
It seems to me that the only way to solve this is for PayPal to not=20
process refunds until the seller confirms what he received back is the=20
same as what he shipped. Yes, then the seller could commit similar=20
fraud, but sellers (certainly professional ones) have a greater=20
reputational risk.
http://consumerist.com/5159479/ebay-scammer-says-pc-destroyed-in-mail-tak=
es-500-sends-back-destroyed-pc-minus-parts=20
or http://tinyurl.com/czj2bu
** *** ***** ******* *********** *************
Schneier News
Schneier is speaking at MinneWebCon on April 6 in Minneapolis.
http://minnewebcon.umn.edu/
Schneier is speaking at the 3rd Annual Asia-Pacific Programme for Senior=20
National Security Officers (APPSNO) on April 14 in Singapore.
http://www.rsis.edu.sg/cens/events/upcoming_events.html
** *** ***** ******* *********** *************
IT Security: Blaming the Victim
Blaming the victim is common in IT: users are to blame because they=20
don't patch their systems, choose lousy passwords, fall for phishing=20
attacks, and so on. But, while users are, and will continue to be, a=20
major source of security problems, focusing on them is an unhelpful way=20
to think.
People regularly don't do things they are supposed to: changing the oil=20
in their cars, going to the dentist, replacing the batteries in their=20
smoke detectors. Why? Because people learn from experience. If something=20
is immediately harmful, e.g., touching a hot stove or petting a live=20
tiger, they quickly learn not to do it. But if someone skips an oil=20
change, ignores a computer patch, or chooses a lousy password, it's=20
unlikely to matter. No feedback, no learning.
We've tried to solve this in several ways. We give people rules of=20
thumb: oil change every 5,000 miles; secure password guidelines. Or we=20
send notifications: smoke alarms beep at us, dentists send postcards,=20
Google warns us if we are about to visit a website suspected of hosting=20
malware. But, again, the effects of ignoring these aren't generally felt=20
immediately.
This makes security primarily a hindrance to the user. It's a recurring=20
obstacle: something that interferes with the seamless performance of the=20
user's task. And it's human nature, wired into our reasoning skills, to=20
remove recurring obstacles. So, if the consequences of bypassing=20
security aren't obvious, then people will naturally do it.
This is the problem with Microsoft's User Account Control (UAC).=20
Introduced in Vista, the idea is to improve security by limiting the=20
privileges applications have when they're running. But the security=20
prompts pop up too frequently, and there's rarely any ill-effect from=20
ignoring them. So people do ignore them.
This doesn't mean user education is worthless. On the contrary, user=20
education is an important part of any corporate security program. And at=20
home, the more users understand security threats and hacker tactics, the=20
more secure their systems are likely to be. But we should also recognise=20
the limitations of education.
The solution is to better design security systems that assume uneducated=20
users: to prevent them from changing security settings that would leave=20
them exposed to undue risk, or even better to take security out of their=20
hands entirely.
For example, we all know that backups are a good thing. But if you=20
forget to do a backup this week, nothing terrible happens. In fact,=20
nothing terrible happens for years on end when you forget. So, despite=20
what you know, you start believing that backups aren't really that=20
important. Apple got the solution right with its backup utility Time=20
Machine. Install it, plug in an external hard drive, and you are=20
automatically backed up against hardware failure and human error. It's=20
easier to use it than not.
For its part, Microsoft has made great strides in securing its operating=20
system, providing default security settings in Windows XP and even more=20
in Windows Vista to ensure that, when a naive user plugs a computer in,=20
it's not defenceless.
Unfortunately, blaming the user can be good business. Mobile phone=20
companies save money if they can bill their customers when a calling=20
card number is stolen and used fraudulently. British banks save money by=20
blaming users when they are victims of chip-and-pin fraud. This is=20
continuing, with some banks going so far as to accuse the victim of=20
perpetrating the fraud, despite evidence of large-scale fraud by=20
organised crime syndicates.
The legal system needs to fix the business problems, but system=20
designers need to work on the technical problems. They must accept that=20
security systems that require the user to do the right thing are doomed=20
to fail. And then they must design resilient security nevertheless.
This essay originally appeared in The Guardian.
http://www.guardian.co.uk/technology/2009/mar/12/read-me-first
Users are a problem:
http://www.informationweek.com/news/security/client/showArticle.jhtml?art=
icleID=3D213002007=20
or http://tinyurl.com/ab8pux
http://www.informationweek.com/news/security/attacks/showArticle.jhtml?ar=
ticleID=3D212700890=20
or http://tinyurl.com/b2s2ep
Lousy passwords:
http://www.schneier.com/essay-144.html
Choosing good passwords:
http://www.schneier.com/essay-148.html
Microsoft's UAC problems:
http://arstechnica.com/security/news/2008/04/vistas-uac-security-prompt-w=
as-designed-to-annoy-you.ars=20
or http://tinyurl.com/cxazee
The limits of education:
http://www.schneier.com/essay-139.html
Blaming the user:
http://www.schneier.com/blog/archives/2005/12/cell_phone_comp.html
http://news.bbc.co.uk/1/hi/programmes/newsnight/7265437.stm
Large-scale chip-and-pin fraud:
http://www.telegraph.co.uk/news/newstopics/politics/lawandorder/3173346/C=
hip-and-pin-scam-has-netted-millions-from-British-shoppers.html=20
or http://tinyurl.com/4xuk69
** *** ***** ******* *********** *************
Balancing Security and Usability in Authentication
Since January, the Conficker.B worm has been spreading like wildfire=20
across the Internet: infecting the French Navy, hospitals in Sheffield,=20
the court system in Houston, and millions of computers worldwide. One=20
of the ways it spreads is by cracking administrator passwords on=20
networks. Which leads to the important question: Why in the world are=20
IT administrators still using easy-to-guess passwords?
Computer authentication systems have two basic requirements. They need=20
to keep the bad guys from accessing your account, and they need to allow=20
you to access your account. Both are important, and every=20
authentication system is a balancing act between the two. Too little=20
security, and the bad guys will get in too easily. But if the=20
authentication system is too complicated, restrictive, or hard to use,=20
you won't be able to -- or won't bother to -- use it.
Passwords are the most common authentication system, and a good place to=20
start. They're very easy to implement and use, which is why they're so=20
popular. But as computers have become faster, password guessing has=20
become easier. Most people don't choose passwords that are complicated=20
enough to remain secure against modern password-guessing attacks.=20
Conficker.B is even less clever; it just tries a list of about 200=20
common passwords.
To combat password guessing, many systems force users to choose=20
harder-to-guess passwords -- requiring minimum lengths, non=20
alpha-numeric characters, etc. -- and change their passwords more=20
frequently. The first makes guessing harder, and the second makes a=20
guessed password less valuable. This, of course, makes the system more=20
annoying, so users respond by writing their passwords down and taping=20
them to their monitors, or simply forgetting them more often. Smarter=20
users write them down and put them in their wallets, or use a secure=20
password database like Password Safe.
Users forgetting their passwords can be expensive -- sysadmins or=20
customer service reps have to field phone calls and reset password -- so=20
some systems include a backup authentication system: a secret question.=20
The idea is that if you forget your password, you can authenticate=20
yourself with some personal information that only you know. Your=20
mother's maiden name was traditional, but these days there are all sorts=20
of secret questions: your favourite schoolteacher, favourite colour,=20
street you grew up on, name of your first pet, and so on. This might=20
make the system more usable, but it also makes it much less secure:=20
answers can be easily guessable, and are often known by people close to y=
ou.
A common enhancement is a one-time password generator, like a SecurID=20
token. This is a small device with a screen that displays a password=20
that changes automatically once a minute. Adding this is called=20
two-factor authentication, and is much more secure, because this token=20
-- "something you have" -- is combined with a password -- "something you=20
know." But it's less usable, because the tokens have to be purchased=20
and distributed to all users, and far too often it's "something you lost=20
or forgot." And it costs money. Tokens are far more frequently used in=20
corporate environments, but banks and some online gaming worlds have=20
taken to using them -- sometimes only as an option, because people don't=20
like them.
In most cases, how an authentication system works when a legitimate user=20
tries to log on is much more important than how it works when an=20
impostor tries to log on. No security system is perfect, and there is=20
some level of fraud associated with any of these authentication methods.=20
But the instances of fraud are rare compared to the number of times=20
someone tries to log on legitimately. If a given authentication system=20
let the bad guys in one in a hundred times, a bank could decide to live=20
with the problem -- or try to solve it in some other way. But if the=20
same authentication system prevented legitimate customers from logging=20
on even one in a thousand times, the number of complaints would be=20
enormous and the system wouldn't survive one week.
Balancing security and usability is hard, and many organizations get it=20
wrong. But it's also evolving; organizations needing to tighten their=20
security continue to push more involved authentication methods, and more=20
savvy Internet users are willing to accept them. And certainly IT=20
administrators need to be leading that evolutionary change.
A version of this essay was originally published in The Guardian.
http://www.guardian.co.uk/technology/2009/feb/19/insecure-passwords-confl=
ickerb-worm=20
or http://tinyurl.com/awd5np
Conficker.B:
http://www.crn.com/security/212902319
http://www.telegraph.co.uk/news/worldnews/europe/france/4547649/French-fi=
ghter-planes-grounded-by-computer-virus.html=20
or http://tinyurl.com/bbku57
http://www.smarthealthcare.com/sheffield-conficker
http://www.theregister.co.uk/2009/02/09/houston_malware_infection/
http://arstechnica.com/security/news/2009/01/conficker-worm-spikes-infect=
s-1-1-million-pcs-in-24-hours.ars=20
or http://tinyurl.com/dmvd8d
http://securitywatch.eweek.com/virus_and_spyware/experts_-_conficker_usb_=
worm_spreading_quickly.html=20
or http://tinyurl.com/bk5fs9
http://voices.washingtonpost.com/securityfix/2009/01/tricky_windows_worm_=
wallops_mi.html=20
or http://tinyurl.com/8e8fbg
http://bt.counterpane.com/Risk_Assessment_W32.Conficker_Worm_Update2.pdf=20
or http://tinyurl.com/detvm5
http://www.microsoft.com/security/portal/Entry.aspx?Name=3DWorm:Win32/Con=
ficker.B=20
or http://tinyurl.com/9vpbxs
http://www.sophos.com/blogs/gc/g/2009/01/16/passwords-conficker-worm/
Guessing passwords:
http://www.schneier.com/essay-246.html
http://www.schneier.com/essay-148.html
Password Safe:
http://www.schneier.com/passsafe.html
Security problems with secret questions:
http://www.schneier.com/blog/archives/2005/02/the_curse_of_th.html
** *** ***** ******* *********** *************
Comments from Readers
There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and join =
in.
http://www.schneier.com/blog
** *** ***** ******* *********** *************
Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing=20
summaries, analyses, insights, and commentaries on security: computer=20
and otherwise. You can subscribe, unsubscribe, or change your address=20
on the Web at <http://www.schneier.com/crypto-gram.html>. Back issues=20
are also available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable. Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the=20
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"=20
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,=20
Phelix, and Skein algorithms. He is the Chief Security Technology=20
Officer of BT BCSG, and is on the Board of Directors of the Electronic=20
Privacy Information Center (EPIC). He is a frequent writer and lecturer=20
on security topics. See <http://www.schneier.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not=20
necessarily those of BT.
Copyright (c) 2009 by Bruce Schneier.