CRYPTO-GRAM, March 15, 2009

Bruce Schneier <[email protected]> Sat, 14 Mar 2009 23:56:29 -0500
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

                 March 15, 2009

               by Bruce Schneier
       Chief Security Technology Officer, BT
              [email protected]
             http://www.schneier.com


A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-0903.html>.  These same essays=20
appear in the "Schneier on Security" blog:=20
<http://www.schneier.com/blog>.  An RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
      Perverse Security Incentives
      Privacy in the Age of Persistence
      News
      Insiders
      The Doghouse: Singularics
      Three Security Anecdotes from the Insect World
      The Kindness of Strangers
      New eBay Fraud
      Schneier News
      IT Security: Blaming the Victim
      Balancing Security and Usability in Authentication
      Comments from Readers


** *** ***** ******* *********** *************

      Perverse Security Incentives



An employee of Whole Foods in Ann Arbor, Michigan, was fired in 2007 for=20
apprehending a shoplifter.  More specifically, he was fired for touching=20
a customer, even though that customer had a backpack filled with stolen=20
groceries and was running away with them.

I regularly see security decisions that, like the Whole Foods incident,=20
seem to make absolutely no sense.  However, in every case, the decisions=20
actually make perfect sense once you understand the underlying=20
incentives driving the decision. All security decisions are trade-offs,=20
but the motivations behind them are not always obvious: They're often=20
subjective, and driven by external incentives.  And often security=20
trade-offs are made for nonsecurity reasons.

Almost certainly, Whole Foods has a no-touching-the-customer policy=20
because its attorneys recommended it.  "No touching" is a security=20
measure as well, but it's security against customer lawsuits.  The cost=20
of these lawsuits would be much, much greater than the $346 worth of=20
groceries stolen in this instance.  Even applied to suspected=20
shoplifters, the policy makes sense: The cost of a lawsuit resulting=20
from tackling an innocent shopper by mistake would be far greater than=20
the cost of letting actual shoplifters get away.  As perverse it may=20
seem, the result is completely reasonable given the corporate incentives=20
-- Whole Foods wrote a corporate policy that benefited itself.

At least, it works as long as the police and other factors keep=20
society's shoplifter population down to a reasonable level.

Incentives explain much that is perplexing about security trade-offs.=20
Why does King County, Washington, require one form of ID to get a=20
concealed-carry permit, but two forms of ID to pay for the permit by=20
check?  Making a mistake on a gun permit is an abstract problem, but a=20
bad check actually costs some department money.

In the decades before 9/11, why did the airlines fight every security=20
measure except the photo-ID check?  Increased security annoys their=20
customers, but the photo-ID check solved a security problem of a=20
different kind: the resale of nonrefundable tickets. So the airlines=20
were on board for that one.

And why does the TSA confiscate liquids at airport security, on the off=20
chance that a terrorist will try to make a liquid explosive instead of=20
using the more common solid ones?  Because the officials in charge of=20
the decision used CYA security measures to prevent specific, known=20
tactics rather than broad, general ones.

The same misplaced incentives explain the ongoing problem of innocent=20
prisoners spending years in places like Guantanamo and Abu Ghraib.  The=20
solution might seem obvious: Release the innocent ones, keep the guilty=20
ones, and figure out whether the ones we aren't sure about are innocent=20
or guilty.  But the incentives are more perverse than that.  Who is=20
going to sign the order releasing one of those prisoners?  Which=20
military officer is going to accept the risk, no matter how small, of=20
being wrong?

I read almost five years ago that prisoners were being held by the=20
United States far longer than they should, because "no one wanted to be=20
responsible for releasing the next Osama bin Laden."  That incentive to=20
do nothing hasn't changed.  It might have even gotten stronger, as these=20
innocents languish in prison.

In all these cases, the best way to change the trade-off is to change=20
the incentives.  Look at why the Whole Foods case works.  Store=20
employees don't have to apprehend shoplifters, because society created a=20
special organization specifically authorized to lay hands on people the=20
grocery store points to as shoplifters: the police.  If we want more=20
rationality out of the TSA, there needs to be someone with a broader=20
perspective willing to deal with general threats rather than specific=20
targets or tactics.

For prisoners, society has created a special organization specifically=20
entrusted with the role of judging the evidence against them and=20
releasing them if appropriate: the judiciary.  It's only because the=20
George W. Bush administration decided to remove the Guantanamo prisoners=20
from the legal system that we are now stuck with these perverse=20
incentives.  Our country would be smart to move as many of these people=20
through the court system as we can.

This essay originally appeared on Wired.com.
http://www.wired.com/politics/security/commentary/securitymatters/2009/02=
/securitymatters_0226=20
or http://tinyurl.com/aku6bf

Whole Foods incident:
http://www.mlive.com/news/index.ssf/2007/12/grocery_worker_fired_for_stop=
p.html=20
or http://tinyurl.com/3dma49

King County ID checks:
http://www.kingcounty.gov/safety/sheriff/Services/Gun.aspx

Terrorists as liquid bombers:
http://www.schneier.com/blog/archives/2007/08/details_on_the_1.html

CYA security:
http://www.schneier.com/blog/archives/2007/02/cya_security_1.html

The perverse incentives of holding terrorist suspects in custody:
http://query.nytimes.com/gst/fullpage.html?res=3D9C00E3DF133EF934A15756C0=
A9629C8B63&sec=3D&spon=3D&pagewanted=3Dall=20
or http://tinyurl.com/cgh86n


** *** ***** ******* *********** *************

      Privacy in the Age of Persistence



(Note: This isn't the first time I have written about this topic, and it=20
surely won't be the last.  I think I did a particularly good job=20
summarizing the issues this time, which is why I am reprinting it.)

Welcome to the future, where everything about you is saved. A future=20
where your actions are recorded, your movements are tracked, and your=20
conversations are no longer ephemeral. A future brought to you not by=20
some 1984-like dystopia, but by the natural tendencies of computers to=20
produce data.

Data is the pollution of the information age. It's a natural byproduct=20
of every computer-mediated interaction. It stays around forever, unless=20
it's disposed of. It is valuable when reused, but it must be done=20
carefully. Otherwise, its after effects are toxic.

And just as 100 years ago people ignored pollution in our rush to build=20
the Industrial Age, today we're ignoring data in our rush to build the=20
Information Age.

Increasingly, you leave a trail of digital footprints throughout your=20
day. Once you walked into a bookstore and bought a book with cash. Now=20
you visit Amazon, and all of your browsing and purchases are recorded.=20
You used to buy a train ticket with coins; now your electronic fare card=20
is tied to your bank account. Your store affinity cards give you=20
discounts; merchants use the data on them to reveal detailed purchasing=20
patterns.

Data about you is collected when you make a phone call, send an e-mail=20
message, use a credit card, or visit a website. A national ID card will=20
only exacerbate this.

More computerized systems are watching you.  Cameras are ubiquitous in=20
some cities, and eventually face recognition technology will be able to=20
identify individuals. Automatic license plate scanners track vehicles in=20
parking lots and cities. Color printers, digital cameras, and some=20
photocopy machines have embedded identification codes. Aerial=20
surveillance is used by cities to find building permit violators and by=20
marketers to learn about home and garden size.

As RFID chips become more common, they'll be tracked, too. Already you=20
can be followed by your cell phone, even if you never make a call. This=20
is wholesale surveillance; not "follow that car," but "follow every car."

Computers are mediating conversation as well. Face-to-face conversations=20
are ephemeral. Years ago, telephone companies might have known who you=20
called and how long you talked, but not what you said. Today you chat in=20
e-mail, by text message, and on social networking sites. You blog and=20
you Twitter. These conversations -- with family, friends, and colleagues=20
-- can be recorded and stored.

It used to be too expensive to save this data, but computer memory is=20
now cheaper. Computer processing power is cheaper, too; more data is=20
cross-indexed and correlated, and then used for secondary purposes. What=20
was once ephemeral is now permanent.

Who collects and uses this data depends on local laws. In the US,=20
corporations collect, then buy and sell, much of this information for=20
marketing purposes. In Europe, governments collect more of it than=20
corporations. On both continents, law enforcement wants access to as=20
much of it as possible for both investigation and data mining.

Regardless of country, more organizations are collecting, storing, and=20
sharing more of it.

More is coming. Keyboard logging programs and devices can already record=20
everything you type; recording everything you say on your cell phone is=20
only a few years away.

A "life recorder" you can clip to your lapel that'll record everything=20
you see and hear isn't far behind. It'll be sold as a security device,=20
so that no one can attack you without being recorded. When that happens,=20
will not wearing a life recorder be used as evidence that someone is up=20
to no good, just as prosecutors today use the fact that someone left his=20
cell phone at home as evidence that he didn't want to be tracked?

You're living in a unique time in history: the technology is here, but=20
it's not yet seamless. Identification checks are common, but you still=20
have to show your ID. Soon it'll happen automatically, either by=20
remotely querying a chip in your wallets or by recognizing your face on=20
camera.

And all those cameras, now visible, will shrink to the point where you=20
won't even see them. Ephemeral conversation will all but disappear, and=20
you'll think it normal. Already your children live much more of their=20
lives in public than you do. Your future has no privacy, not because of=20
some police-state governmental tendencies or corporate malfeasance, but=20
because computers naturally produce data.

Cardinal Richelieu famously said: "If one would give me six lines=20
written by the hand of the most honest man, I would find something in=20
them to have him hanged." When all your words and actions can be saved=20
for later examination, different rules have to apply.

Society works precisely because conversation is ephemeral; because=20
people forget, and because people don't have to justify every word they=20
utter.

Conversation is not the same thing as correspondence. Words uttered in=20
haste over morning coffee, whether spoken in a coffee shop or thumbed on=20
a BlackBerry, are not official correspondence. A data pattern indicating=20
"terrorist tendencies" is no substitute for a real investigation. Being=20
constantly scrutinized undermines our social norms; furthermore, it's=20
creepy. Privacy isn't just about having something to hide; it's a basic=20
right that has enormous value to democracy, liberty, and our humanity.

We're not going to stop the march of technology, just as we cannot=20
un-invent the automobile or the coal furnace. We spent the industrial=20
age relying on fossil fuels that polluted our air and transformed our=20
climate. Now we are working to address the consequences. (While still=20
using said fossil fuels, of course.) This time around, maybe we can be a=20
little more proactive.

Just as we look back at the beginning of the previous century and shake=20
our heads at how people could ignore the pollution they caused, future=20
generations will look back at us -- living in the early decades of the=20
information age -- and judge our solutions to the proliferation of data.

We must, all of us together, start discussing this major societal change=20
and what it means. And we must work out a way to create a future that=20
our grandchildren will be proud of.

This essay originally appeared on the BBC.com website.
http://news.bbc.co.uk/1/hi/technology/7897892.stm

National ID cards:
http://www.schneier.com/essay-160.html

Surveillance cameras:
http://www.schneier.com/essay-225.html

RFID chips:
http://epic.org/privacy/rfid/

Cell phone surveillance:
http://computerworld.com/action/article.do?command=3DviewArticleBasic&art=
icleId=3D9127462=20
or http://tinyurl.com/au2f4n

Wholesale surveillance:
http://www.schneier.com/essay-147.html

Data mining:
http://www.schneier.com/essay-108.html

The future of surveillance:
http://www.schneier.com/essay-109.html

Face recognition:
http://epic.org/privacy/facerecognition/

Privacy and the younger generation:
http://nymag.com/news/features/27341/

Ill effects of constant surveillance:
http://news.bbc.co.uk/1/hi/uk_politics/7872425.stm

The value of privacy:
http://www.schneier.com/essay-114.html


** *** ***** ******* *********** *************

      News



Uni-ball is using fear to sell its hard-to-erase pen -- but it's the=20
wrong fear.  They're confusing check-washing fraud, where someone takes=20
a check and changes the payee and maybe the amount, with identity theft.=20
  And how can someone steal money from me by erasing and changing=20
information on a tax form?  Are they going to cause my refund check to=20
be sent to another address?  This is getting awfully Byzantine.
http://videogum.com/archives/commercials/s-epatha-merkerson-will-terrif_0=
45001.html=20
or http://tinyurl.com/7jcful
http://www.schneier.com/blog/archives/2007/09/using_fear_to_s.html

Los Alamos has lost 80 computers: no idea if they're stolen, or just=20
misplaced.  Typical story -- not even worth commenting on -- but this=20
great comment explains a lot about what was wrong with their security=20
policy:  "The letter, addressed to Department of Energy security=20
officials, contends that 'cyber security issues were not engaged in a=20
timely manner' because the computer losses were treated as a 'property=20
management issue.'"  The real risk in computer losses is the data, not=20
the hardware.  I thought everyone knew that.
http://www.google.com/hostednews/afp/article/ALeqM5jXipyrzU1GKO4KQ3f4hhKy=
LvJvTA=20
or http://tinyurl.com/d7oxy5

Difficult-to-pronounce things are judged to be more risky than=20
easy-to-pronounce things:
http://www.ncbi.nlm.nih.gov/pubmed/19170941

New paper: "WiFi networks and malware epidemiology," by Hao Hu, Steven=20
Myers, Vittoria Colizza, and Alessandro Vespignani.  Honestly, I'm not=20
sure I understood most of the article.  And I don't think that their=20
model is all that great.  But I like to see these sorts of methods=20
applied to malware and infection rates.
http://www.pnas.org/content/early/2009/01/26/0811973106
http://arxiv.org/abs/0706.3146

HIPAA accountability in U.S. stimulus bill:
http://www.schneier.com/blog/archives/2009/02/hipaa_accountab.html

Terrorism common sense from MI6:
http://www.theregister.co.uk/2009/02/11/mi6_spy_rubbishes_terrorism_fear/=
=20
or http://tinyurl.com/cxfl8s

Here's an analysis of 30,000 passwords from phpbb.com.
http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html
It's similar to my analysis of 34,000 MySpace passwords.
http://www.schneier.com/blog/archives/2006/12/realworld_passw.html
Seems like we still can't choose good passwords.  Conficker.B exploits=20
this, trying about 200 common passwords to help spread itself.
http://www.sophos.com/blogs/gc/g/2009/01/16/passwords-conficker-worm/
Blog entry:
http://www.schneier.com/blog/archives/2009/02/another_passwor.html

Evidence of the effectiveness of the "broken windows" theory of crime=20
fighting:
http://www.boston.com/news/local/massachusetts/articles/2009/02/08/breakt=
hrough_on_broken_windows/=20
or http://tinyurl.com/cslqo5
http://www.ncjrs.gov/App/publications/Abstract.aspx?id=3D246202

The NSA wants help eavesdropping on Skype:
http://www.theregister.co.uk/2009/02/12/nsa_offers_billions_for_skype_pwn=
age/=20
or http://tinyurl.com/a9hn2n
I'm sure this is a real problem.  Here's an article claiming that=20
Italian criminals are using Skype more than the telephone because of=20
eavesdropping concerns.
http://www.theregister.co.uk/2009/02/16/italian_crooks_skype/

A study from New Jersey shows that Megan's Law -- laws designed to=20
identity sex offenders to the communities they live in -- is ineffective=20
in reducing sex crimes or deterring recidivists.
http://www.nj.com/news/index.ssf/2009/02/study_finds_megans_law_fails_t_1=
.html=20
or http://tinyurl.com/b2mql2

Another Conficker variant: Conficker B++.  This is one well-designed=20
piece of malware.
http://www.schneier.com/blog/archives/2009/02/new_conficker_v.html

President Obama has tasked Melissa Hathaway with conducting a 60-day=20
review of the nation's cybersecurity policies.
http://www.usatoday.com/tech/2009-02-16-cybersecurity-expert-obama_N.htm=20
or http://tinyurl.com/cx3kon
http://www.computerworld.com/action/article.do?command=3DviewArticleBasic=
&articleId=3D9127682&intsrc=3Dnews_ts_head=20
or http://tinyurl.com/d2ygpp
This interview, conducted last year, will give you a good idea of how=20
she thinks.
http://www2.computer.org/portal/web/computingnow/1208/whatsnew/securityan=
dprivacy=20
or http://tinyurl.com/by28l7

Maine man tries to build a dirty bomb and no one cares, probably because=20
he isn't Muslim.  White supremacist terrorism just isn't sexy these days.
http://jonathanstray.com/maine-man-tries-to-build-dirty-bomb

There are rumors of prototype electromagnetic pulse grenades:
http://www.theregister.co.uk/2009/02/12/electropulse_grenades/

TrapCall is a new service that reveals the caller ID on anonymous or=20
blocked calls.
http://blog.wired.com/27bstroke6/2009/02/trapcall.html

Judge orders defendant to decrypt laptop: interesting Fifth Amendment cas=
e.
http://news.cnet.com/8301-13578_3-10172866-38.html

Use this shower mirror with a hidden camera to catch the lovers of=20
cheating spouses:
http://www.dpl-surveillance-equipment.com/100611.html
The site has a wide variety of hidden cameras in common household objects=
.
http://www.dpl-surveillance-equipment.com/wireless_hidden_cameras.html

University of Miami law professor Michael Froomkin writes about ID cards=20
and society in "Identity Cards and Identity Romanticism."
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=3D1309222
http://www.schneier.com/blog/archives/2009/03/michael_froomki.html

This commentary on the UK government national security strategy is=20
scary:  "Sir David Omand, the former Whitehall security and intelligence=20
co-ordinator, sets out a blueprint for the way the state will mine data=20
-- including travel information, phone records and emails -- held by=20
public and private bodies and admits: 'Finding out other people's=20
secrets is going to involve breaking everyday moral rules.'"  In short:=20
it's immoral, but we're going to do it anyway.
http://www.guardian.co.uk/uk/2009/feb/25/personal-data-terrorism-surveill=
ance=20
or http://tinyurl.com/c5ll6r

Programs "staple" and "unstaple" perform all-or-nothing encryption.=20
Just demonstration code, but interesting all the same.
http://sysnet.ucsd.edu/projects/staple/

Interesting paper: "Optimised to Fail: Card Readers for Online Banking,"=20
by Saar Drimer, Steven J. Murdoch, and Ross Anderson.
http://www.cl.cam.ac.uk/~sjm217/papers/fc09optimised.pdf
http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-read=
ers-for-online-banking/=20
or http://tinyurl.com/bdnafk

I'm sure you need some skill to actually use this self-defense pen, and=20
I'm also sure it'll get through airport security checkpoints just fine.
http://www.botachtactical.com/kzxtremepen.html

This article gives an overview of U.S. military robots, and discusses=20
some of the issues regarding the ethics of their use in war.
http://www.thenewatlantis.com/publications/military-robots-and-the-laws-o=
f-war=20
or http://tinyurl.com/csoj98
The article was adapted from his book Wired for War: The Robotics=20
Revolution and Conflict in the 21st Century, published this year.  I=20
bought the book, but I have not read it yet.  Related is this paper on=20
the ethics of autonomous military robots.
http://www.schneier.com/blog/archives/2008/01/ethics_of_auton.html
Blog entry:
http://www.schneier.com/blog/archives/2009/03/history_and_eth.html

Secret NATO documents about the war in Afghanistan leaked due to bad=20
password:
https://secure.wikileaks.org/wiki/N1

Security theater scare mongering, in hotels and churches:
http://news.bbc.co.uk/1/hi/england/london/7933004.stm
http://www.cnn.com/2009/CRIME/03/09/church.security/index.html
http://www.schneier.com/blog/archives/2009/03/security_theate_2.html

Fascinating history of the techniques used to distribute child porn=20
throughout the world:
http://wikileaks.org/wiki/My_life_in_child_porn
http://www.schneier.com/blog/archives/2009/03/the_techniques.html#c356628=
=20
or http://tinyurl.com/asnc63

Google Maps spam:
http://www.schneier.com/blog/archives/2009/03/google_map_spam.html

This story of the world's largest diamond heist reads like a movie plot:
http://www.wired.com/politics/law/magazine/17-04/ff_diamonds?currentPage=3D=
all=20
or http://tinyurl.com/ak8hrx

Many Sentex keypads, which are used to secure doors everywhere, can be=20
opened with a default admin password:
http://www.schneier.com/blog/archives/2009/03/the_doghouse_se_1.html


** *** ***** ******* *********** *************

      Insiders



Rajendrasinh Makwana was a UNIX contractor for Fannie Mae.  On October=20
24, he was fired.  Before he left, he slipped a logic bomb into the=20
organization's network.  The bomb would have "detonated" on January 31.=20
  It was programmed to disable access to the server on which it was=20
running, block any network monitoring software, systematically and=20
irretrievably erase everything -- and then replicate itself on all 4,000=20
Fannie Mae servers.  Court papers claim the damage would have been in=20
the millions of dollars, a number that seems low.  Fannie Mae would have=20
been shut down for at least a week.

Luckily -- and it does seem it was pure luck -- another programmer=20
discovered the script a week later, and disabled it.

Insiders are a perennial problem.  They have access, and they're known=20
by the system.  They know how the system and its security works, and its=20
weak points.  They have opportunity.  Bank heists, casino thefts,=20
large-scale corporate fraud, train robberies: many of the most=20
impressive criminal attacks involve insiders.  And, like Makwana's=20
attempt at revenge, these insiders can have pretty intense motives --=20
motives that can only intensify as the economy continues to suffer and=20
layoffs increase.

Insiders are especially pernicious attackers because they're trusted.=20
They have access because they're *supposed* to have access.  They have=20
opportunity, and an understanding of the system, because they use it --=20
or they designed, built, or installed it.  They're already inside the=20
security system, making them much harder to defend against.

It's not possible to design a system without trusted people.  They're=20
everywhere.  In offices, employees are trusted people given access to=20
facilities and resources, and allowed to act -- sometimes broadly,=20
sometimes narrowly -- in the company's name.  In stores, employees are=20
allowed access to the back room and the cash register; and customers are=20
trusted to walk into the store and touch the merchandise.  IRS employees=20
are trusted with personal tax information; hospital employees are=20
trusted with personal health information.  Banks, airports, and prisons=20
couldn't operate without trusted people.

Replacing trusted people with computers doesn't make the problem go=20
away; it just moves it around and makes it even more complex.  The=20
computer, software, and network designers, implementers, coders,=20
installers, maintainers, etc. are all trusted people.  See any analysis=20
of the security of electronic voting machines, or some of the frauds=20
perpetrated against computerized gambling machines, for some graphic=20
examples of the risks inherent in replacing people with computers.

Of course, this problem is much, much older than computers.  And the=20
solutions haven't changed much throughout history, either.  There are=20
five basic techniques to deal with trusted people:

1.  Limit the number of trusted people.  This one is obvious.  The fewer=20
people who have root access to the computer system, know the combination=20
to the safe, or have the authority to sign checks, the more secure the=20
system is.

2.  Ensure that trusted people are also trustworthy.  This is the idea=20
behind background checks, lie detector tests, personality profiling,=20
prohibiting convicted felons from getting certain jobs, limiting other=20
jobs to citizens, the TSA's no-fly list, and so on, as well as behind=20
bonding employees, which means there are deep pockets standing behind=20
them if they turn out not to be trustworthy.

3.  Limit the amount of trust each person has.  This is=20
compartmentalization; the idea here is to limit the amount of damage a=20
person can do if he ends up not being trustworthy.  This is the concept=20
behind giving people keys that only unlock their office or passwords=20
that only unlock their account, as well as "need to know" and other=20
levels of security clearance.

4.  Give people overlapping spheres of trust.  This is what security=20
professionals call defense in depth.  It's why it takes two people with=20
two separate keys to launch nuclear missiles, and two signatures on=20
corporate checks over a certain value.  It's the idea behind bank=20
tellers requiring management overrides for high-value transactions,=20
double-entry bookkeeping, and all those guards and cameras at casinos.=20
It's why, when you go to a movie theater, one person sells you a ticket=20
and another person standing a few yards away tears it in half: It makes=20
it much harder for one employee to defraud the system.  It's why key=20
bank employees need to take their two-week vacations all at once -- so=20
their replacements have a chance to uncover any fraud.

5.  Detect breaches of trust after the fact and prosecute the guilty.=20
In the end, the four previous techniques can only do so well.  Trusted=20
people can subvert a system.  Most of the time, we discover the security=20
breach after the fact and then punish the perpetrator through the legal=20
system: publicly, so as to provide a deterrence effect and increase the=20
overall level of security in society.  This is why audit is so vital.

These security techniques don't only protect against fraud or sabotage;=20
they protect against the more common problem: mistakes.  Trusted people=20
aren't perfect; they can inadvertently cause damage.  They can make a=20
mistake, or they can be tricked into making a mistake through social=20
engineering.

Good security systems use multiple measures, all working together.=20
Fannie Mae certainly limits the number of people who have the ability to=20
slip malicious scripts into their computer systems, and certainly limits=20
the access that most of these people have.  It probably has a hiring=20
process that makes it less likely that malicious people come to work at=20
Fannie Mae.  It obviously doesn't have an audit process by which a=20
change one person makes on the servers is checked by someone else; I'm=20
sure that would be prohibitively expensive.  Certainly the company's IT=20
department should have terminated Makwana's network access as soon as he=20
was fired, and not at the end of the day.

In the end, systems will always have trusted people who can subvert=20
them.  It's important to keep in mind that incidents like this don't=20
happen very often; that most people are honest and honorable.  Security=20
is very much designed to protect against the dishonest minority.  And=20
often little things -- like disabling access immediately upon=20
termination -- can go a long way.

This essay originally appeared on the Wall Street Journal website.
http://online.wsj.com/article/SB123447990459779609.html

Makwana:
http://blogs.zdnet.com/BTL/?p=3D11905
http://www.theregister.co.uk/2009/01/29/fannie_mae_sabotage_averted/
http://blog.wired.com/27bstroke6/2009/01/fannie.html

Economic downturn increases insider threat:
http://news.bbc.co.uk/1/hi/technology/7875904.stm

Hospital employees illegally accessing patient data:
http://www.schneier.com/blog/archives/2007/10/27_suspended_fo.html

Insecurity in electronic voting machines:
http://www.schneier.com/blog/archives/2006/11/voting_technolo.html
http://www.nytimes.com/2008/01/06/magazine/06Vote-t.html
http://www.schneier.com/essay-101.html
http://freedom-to-tinker.com/blog/dwallach/vendor-misinformation-e-voting=
-world=20
or http://tinyurl.com/5c7kxn
http://www.schneier.com/blog/archives/2008/08/diebold_finally.html
http://blog.wired.com/27bstroke6/2009/01/diebold-audit-l.html
http://www.schneier.com/essay-068.html
http://www.crypto.com/blog/ohio_voting/
http://www.huffingtonpost.com/kirsten-anderson/an-interview-with-david-w_=
b_64063.html=20
or http://tinyurl.com/ad6rn3

Computerized gambling machine fraud:
http://www.reviewjournal.com/lvrj_home/1998/Jan-10-Sat-1998/news/6745681.=
html=20
or http://tinyurl.com/xswg

Replacing people with computers:
http://www.schneier.com/blog/archives/2008/12/comparing_the_s.html

Audit:
http://www.schneier.com/blog/archives/2008/12/audit.html


** *** ***** ******* *********** *************

      The Doghouse: Singularics



This is priceless:

"Our advances in Prime Number Theory have led to a new branch of=20
mathematics called Neutronics. Neutronic functions make possible for the=20
first time the ability to analyze regions of mathematics commonly=20
thought to be undefined, such as the point where one is divided by zero.=20
In short, we have developed a new way to analyze the undefined point at=20
the singularity which appears throughout higher mathematics.

"This new analytic technique has given us profound insight into the way=20
that prime numbers are distributed throughout the integers. According to=20
RSA's website, there are over 1 billion licensed instances of RSA=20
public-key encryption in use in the world today. Each of these instances=20
of the prime number based RSA algorithm can now be deciphered using=20
Neutronic analysis. Unlike RSA, Neutronic Encryption is not based on two=20
large prime numbers but rather on the Neutronic forces that govern the=20
distribution of the primes themselves. The encryption that results from=20
Singularic's Neutronic public-key algorithm is theoretically impossible=20
to break."

You'd think that anyone who claims to be able to decrypt RSA at the key=20
lengths in use today would, maybe, um, demonstrate that at least once.=20
Otherwise, this can all be safely ignored as snake oil.

The founder and CTO also claims to have proved the Riemann Hypothesis,=20
if you care to wade through the 63-page paper.

http://www.singularics.com/products/encryption/

Snake oil:
http://www.schneier.com/crypto-gram-9902.html#snakeoil

Riemann Hypothesis "proof":
http://www.singularics.com/science/mathematics/OnNeutronicFunctions.pdf=20
or http://tinyurl.com/agmoy9


** *** ***** ******* *********** *************

      Three Security Anecdotes from the Insect World



Beet armyworm caterpillars react to the sound of a passing wasp by=20
freezing in place, or even dropping off the plant. Unfortunately,=20
armyworm intelligence isn't good enough to tell the difference between=20
enemy aircraft (the wasps that prey on them) and harmless commercial=20
flights (bees); they react the same way to either.  So by producing=20
nectar for bees, plants not only get pollinated, but also gain some=20
protection against being eaten by caterpillars.

The small hive beetle lives by entering beehives to steal combs and=20
honey.  They home in on the hives by detecting the bees' own alarm=20
pheromones.  They also track in yeast that ferments the pollen and=20
releases chemicals that spoof the alarm pheromones, attracting more=20
beetles and more yeast.  Eventually the bees abandon the hive, leaving=20
the beetles and yeast to finish off the pollen and honey.

Mountain alcon blue caterpillars get ants to feed them by spoofing a=20
biometric: the sounds made by the queen ant.

http://scienceblogs.com/notrocketscience/2008/12/buzzing_bees_scare_cater=
pillars_away_from_plants.php=20
or http://tinyurl.com/b2fp7m

http://scienceblogs.com/notrocketscience/2009/01/beetle_and_yeast_team_up=
_against_bees.php=20
or http://tinyurl.com/96kdea

http://scienceblogs.com/notrocketscience/2009/02/butterflies_scrounge_off=
_ants_by_mimicking_the_music_of_quee.php=20
or http://tinyurl.com/cxu8cm


** *** ***** ******* *********** *************

      The Kindness of Strangers



When I was growing up, children were commonly taught: "don't talk to=20
strangers." Strangers might be bad, we were told, so it's prudent to=20
steer clear of them.

And yet most people are honest, kind, and generous, especially when=20
someone asks them for help.  If a small child is in trouble, the=20
smartest thing he can do is find a nice-looking stranger and talk to him.

These two pieces of advice may seem to contradict each other, but they=20
don't. The difference is that in the second instance, the child is=20
choosing which stranger to talk to. Given that the overwhelming majority=20
of people will help, the child is likely to get help if he chooses a=20
random stranger. But if a stranger comes up to a child and talks to him=20
or her, it's not a random choice. It's more likely, although still=20
unlikely, that the stranger is up to no good.

As a species, we tend help each other, and a surprising amount of our=20
security and safety comes from the kindness of strangers. During=20
disasters: floods, earthquakes, hurricanes, bridge collapses. In times=20
of personal tragedy. And even in normal times.

If you're sitting in a caf=E9 working on your laptop and need to get up=20
for a minute, ask the person sitting next to you to watch your stuff.=20
He's very unlikely to steal anything. Or, if you're nervous about that,=20
ask the three people sitting around you. Those three people don't know=20
each other, and will not only watch your stuff, but they'll also watch=20
each other to make sure no one steals anything.

Again, this works because you're selecting the people. If three people=20
walk up to you in the cafe and offer to watch your computer while you go=20
to the bathroom, don't take them up on that offer. Your odds of getting=20
three honest people are much lower.

Some computer systems rely on the kindness of strangers, too. The=20
Internet works because nodes benevolently forward packets to each other=20
without any recompense from either the sender or receiver of those=20
packets. Wikipedia works because strangers are willing to write for, and=20
edit, an encyclopedia =AD with no recompense.

Collaborative spam filtering is another example. Basically, once someone=20
notices a particular e-mail is spam, he marks it, and everyone else in=20
the network is alerted that it's spam. Marking the e-mail is a=20
completely altruistic task; the person doing it gets no benefit from the=20
action. But he receives benefit from everyone else doing it for other=20
e-mails.

Tor is a system for anonymous Web browsing. The details are complicated,=20
but basically, a network of Tor servers passes Web traffic among each=20
other in such a way as to anonymize where it came from. Think of it as a=20
giant shell game. As a Web surfer, I put my Web query inside a shell and=20
send it to a random Tor server. That server knows who I am but not what=20
I am doing. It passes that shell to another Tor server, which passes it=20
to a third. That third server -- which knows what I am doing but not who=20
I am -- processes the Web query. When the Web page comes back to that=20
third server, the process reverses itself and I get my Web page.=20
Assuming enough Web surfers are sending enough shells through the=20
system, even someone eavesdropping on the entire network can't figure=20
out what I'm doing.

It's a very clever system, and it protects a lot of people, including=20
journalists, human rights activists, whistleblowers, and ordinary people=20
living in repressive regimes around the world. But it only works because=20
of the kindness of strangers. No one gets any benefit from being a Tor=20
server; it uses up bandwidth to forward other people's packets around.=20
It's more efficient to be a Tor client and use the forwarding=20
capabilities of others. But if there are no Tor servers, then there's no=20
Tor. Tor works because people are willing to set themselves up as=20
servers, at no benefit to them.

Alibi clubs work along similar lines. You can find them on the Internet,=20
and they're loose collections of people willing to help each other out=20
with alibis. Sign up, and you're in. You can ask someone to pretend to=20
be your doctor and call your boss. Or someone to pretend to be your boss=20
and call your spouse. Or maybe someone to pretend to be your spouse and=20
call your boss. Whatever you want, just ask and some anonymous stranger=20
will come to your rescue. And because your accomplice is an anonymous=20
stranger, it's safer than asking a friend to participate in your ruse.

There are risks in these sorts of systems. Regularly, marketers and=20
other people with agendas try to manipulate Wikipedia entries to suit=20
their interests. Intelligence agencies can, and almost certainly have,=20
set themselves up as Tor servers to better eavesdrop on traffic. And a=20
do-gooder could join an alibi club just to expose other members. But for=20
the most part, strangers are willing to help each other, and systems=20
that harvest this kindness work very well on the Internet.

This essay originally appeared on the Wall Street Journal website.
http://online.wsj.com/article/SB123567809587886053.html

Tor:
http://www.torproject.org/torusers.html.en
http://www.torproject.org

Alibi clubs:
http://www.nytimes.com/2004/06/26/technology/26ALIB.html?hp
http://www.alibinetwork.com/index.jsp


** *** ***** ******* *********** *************

      New eBay Fraud



Here's a clever fraud, exploiting relative delays in eBay, PayPal, and=20
UPS shipping.

"The buyer reported the item as 'destroyed' and demanded and got a=20
refund from Paypal. When the buyer shipped it back to Chad and he opened=20
it, he found there was nothing wrong with it -- except that the scammer=20
had removed the memory, processor and hard drive. Now Chad is out $500=20
and left with a shell of a computer, and since the item was 'received'=20
Paypal won't do anything."

Very clever.  The seller accepted the return from UPS after a visual=20
inspection, so UPS considered the matter closed.  PayPal and eBay both=20
considered the matter closed.  if the amount was large enough, the=20
seller could sue, but how could he prove that the computer was=20
functional when he sold it?

It seems to me that the only way to solve this is for PayPal to not=20
process refunds until the seller confirms what he received back is the=20
same as what he shipped.  Yes, then the seller could commit similar=20
fraud, but sellers (certainly professional ones) have a greater=20
reputational risk.

http://consumerist.com/5159479/ebay-scammer-says-pc-destroyed-in-mail-tak=
es-500-sends-back-destroyed-pc-minus-parts=20
or http://tinyurl.com/czj2bu


** *** ***** ******* *********** *************

      Schneier News



Schneier is speaking at MinneWebCon on April 6 in Minneapolis.
http://minnewebcon.umn.edu/

Schneier is speaking at the 3rd Annual Asia-Pacific Programme for Senior=20
National Security Officers (APPSNO) on April 14 in Singapore.
http://www.rsis.edu.sg/cens/events/upcoming_events.html


** *** ***** ******* *********** *************

      IT Security: Blaming the Victim



Blaming the victim is common in IT: users are to blame because they=20
don't patch their systems, choose lousy passwords, fall for phishing=20
attacks, and  so on. But, while users are, and will continue to be, a=20
major source of security problems, focusing on them is an unhelpful way=20
to think.

People regularly don't do things they are supposed to: changing the oil=20
in their cars, going to the dentist, replacing the batteries in their=20
smoke detectors. Why? Because people learn from experience. If something=20
is immediately harmful, e.g., touching a hot stove or petting a live=20
tiger, they quickly learn not to do it. But if someone skips an oil=20
change, ignores a computer patch, or chooses a lousy password, it's=20
unlikely to matter. No feedback, no learning.

We've tried to solve this in several ways. We give people rules of=20
thumb: oil change every 5,000 miles; secure password guidelines. Or we=20
send notifications: smoke alarms beep at us, dentists send postcards,=20
Google warns us if we are about to visit a website suspected of hosting=20
malware. But, again, the effects of ignoring these aren't generally felt=20
immediately.

This makes security primarily a hindrance to the user. It's a recurring=20
obstacle: something that interferes with the seamless performance of the=20
user's task. And it's human nature, wired into our reasoning skills, to=20
remove recurring obstacles. So, if the consequences of bypassing=20
security aren't obvious, then people will naturally do it.

This is the problem with Microsoft's User Account Control (UAC).=20
Introduced in Vista, the idea is to improve security by limiting the=20
privileges applications have when they're running. But the security=20
prompts pop up too frequently, and there's rarely any ill-effect from=20
ignoring them. So people do ignore them.

This doesn't mean user education is worthless. On the contrary, user=20
education is an important part of any corporate security program. And at=20
home, the more users understand security threats and hacker tactics, the=20
more secure their systems are likely to be. But we should also recognise=20
the limitations of education.

The solution is to better design security systems that assume uneducated=20
users: to prevent them from changing security settings that would leave=20
them exposed to undue risk, or even better to take security out of their=20
hands entirely.

For example, we all know that backups are a good thing. But if you=20
forget to do a backup this week, nothing terrible happens. In fact,=20
nothing terrible happens for years on end when you forget. So, despite=20
what you know, you start believing that backups aren't really that=20
important. Apple got the solution right with its backup utility Time=20
Machine. Install it, plug in an external hard drive, and you are=20
automatically backed up against hardware failure and human error. It's=20
easier to use it than not.

For its part, Microsoft has made great strides in securing its operating=20
system, providing default security settings in Windows XP and even more=20
in Windows Vista to ensure that, when a naive user plugs a computer in,=20
it's not defenceless.

Unfortunately, blaming the user can be good business. Mobile phone=20
companies save money if they can bill their customers when a calling=20
card number is stolen and used fraudulently. British banks save money by=20
blaming users when they are victims of chip-and-pin fraud. This is=20
continuing, with some banks going so far as to accuse the victim of=20
perpetrating the fraud, despite evidence of large-scale fraud by=20
organised crime syndicates.

The legal system needs to fix the business problems, but system=20
designers need to work on the technical problems. They must accept that=20
security systems that require the user to do the right thing are doomed=20
to fail. And then they must design resilient security nevertheless.

This essay originally appeared in The Guardian.
http://www.guardian.co.uk/technology/2009/mar/12/read-me-first

Users are a problem:
http://www.informationweek.com/news/security/client/showArticle.jhtml?art=
icleID=3D213002007=20
or http://tinyurl.com/ab8pux
http://www.informationweek.com/news/security/attacks/showArticle.jhtml?ar=
ticleID=3D212700890=20
or http://tinyurl.com/b2s2ep

Lousy passwords:
http://www.schneier.com/essay-144.html

Choosing good passwords:
http://www.schneier.com/essay-148.html

Microsoft's UAC problems:
http://arstechnica.com/security/news/2008/04/vistas-uac-security-prompt-w=
as-designed-to-annoy-you.ars=20
or http://tinyurl.com/cxazee

The limits of education:
http://www.schneier.com/essay-139.html

Blaming the user:
http://www.schneier.com/blog/archives/2005/12/cell_phone_comp.html
http://news.bbc.co.uk/1/hi/programmes/newsnight/7265437.stm

Large-scale chip-and-pin fraud:
http://www.telegraph.co.uk/news/newstopics/politics/lawandorder/3173346/C=
hip-and-pin-scam-has-netted-millions-from-British-shoppers.html=20
or http://tinyurl.com/4xuk69


** *** ***** ******* *********** *************

      Balancing Security and Usability in Authentication



Since January, the Conficker.B worm has been spreading like wildfire=20
across the Internet: infecting the French Navy, hospitals in Sheffield,=20
the court system in Houston, and millions of computers worldwide.  One=20
of the ways it spreads is by cracking administrator passwords on=20
networks.  Which leads to the important question: Why in the world are=20
IT administrators still using easy-to-guess passwords?

Computer authentication systems have two basic requirements.  They need=20
to keep the bad guys from accessing your account, and they need to allow=20
you to access your account.  Both are important, and every=20
authentication system is a balancing act between the two.  Too little=20
security, and the bad guys will get in too easily.  But if the=20
authentication system is too complicated, restrictive, or hard to use,=20
you won't be able to -- or won't bother to -- use it.

Passwords are the most common authentication system, and a good place to=20
start.  They're very easy to implement and use, which is why they're so=20
popular.  But as computers have become faster, password guessing has=20
become easier.  Most people don't choose passwords that are complicated=20
enough to remain secure against modern password-guessing attacks.=20
Conficker.B is even less clever; it just tries a list of about 200=20
common passwords.

To combat password guessing, many systems force users to choose=20
harder-to-guess passwords -- requiring minimum lengths, non=20
alpha-numeric characters, etc. -- and change their passwords more=20
frequently.  The first makes guessing harder, and the second makes a=20
guessed password less valuable.  This, of course, makes the system more=20
annoying, so users respond by writing their passwords down and taping=20
them to their monitors, or simply forgetting them more often.  Smarter=20
users write them down and put them in their wallets, or use a secure=20
password database like Password Safe.

Users forgetting their passwords can be expensive -- sysadmins or=20
customer service reps have to field phone calls and reset password -- so=20
some systems include a backup authentication system: a secret question.=20
  The idea is that if you forget your password, you can authenticate=20
yourself with some personal information that only you know.  Your=20
mother's maiden name was traditional, but these days there are all sorts=20
of secret questions: your favourite schoolteacher, favourite colour,=20
street you grew up on, name of your first pet, and so on.  This might=20
make the system more usable, but it also makes it much less secure:=20
answers can be easily guessable, and are often known by people close to y=
ou.

A common enhancement is a one-time password generator, like a SecurID=20
token.  This is a small device with a screen that displays a password=20
that changes automatically once a minute.  Adding this is called=20
two-factor authentication, and is much more secure, because this token=20
-- "something you have" -- is combined with a password -- "something you=20
know."  But it's less usable, because the tokens have to be purchased=20
and distributed to all users, and far too often it's "something you lost=20
or forgot."  And it costs money.  Tokens are far more frequently used in=20
corporate environments, but banks and some online gaming worlds have=20
taken to using them -- sometimes only as an option, because people don't=20
like them.

In most cases, how an authentication system works when a legitimate user=20
tries to log on is much more important than how it works when an=20
impostor tries to log on.  No security system is perfect, and there is=20
some level of fraud associated with any of these authentication methods.=20
  But the instances of fraud are rare compared to the number of times=20
someone tries to log on legitimately.  If a given authentication system=20
let the bad guys in one in a hundred times, a bank could decide to live=20
with the problem -- or try to solve it in some other way. But if the=20
same authentication system prevented legitimate customers from logging=20
on even one in a thousand times, the number of complaints would be=20
enormous and the system wouldn't survive one week.

Balancing security and usability is hard, and many organizations get it=20
wrong.  But it's also evolving; organizations needing to tighten their=20
security continue to push more involved authentication methods, and more=20
savvy Internet users are willing to accept them.  And certainly IT=20
administrators need to be leading that evolutionary change.

A version of this essay was originally published in The Guardian.
http://www.guardian.co.uk/technology/2009/feb/19/insecure-passwords-confl=
ickerb-worm=20
or http://tinyurl.com/awd5np

Conficker.B:
http://www.crn.com/security/212902319
http://www.telegraph.co.uk/news/worldnews/europe/france/4547649/French-fi=
ghter-planes-grounded-by-computer-virus.html=20
or http://tinyurl.com/bbku57
http://www.smarthealthcare.com/sheffield-conficker
http://www.theregister.co.uk/2009/02/09/houston_malware_infection/
http://arstechnica.com/security/news/2009/01/conficker-worm-spikes-infect=
s-1-1-million-pcs-in-24-hours.ars=20
or http://tinyurl.com/dmvd8d
http://securitywatch.eweek.com/virus_and_spyware/experts_-_conficker_usb_=
worm_spreading_quickly.html=20
or http://tinyurl.com/bk5fs9
http://voices.washingtonpost.com/securityfix/2009/01/tricky_windows_worm_=
wallops_mi.html=20
or http://tinyurl.com/8e8fbg
http://bt.counterpane.com/Risk_Assessment_W32.Conficker_Worm_Update2.pdf=20
or http://tinyurl.com/detvm5
http://www.microsoft.com/security/portal/Entry.aspx?Name=3DWorm:Win32/Con=
ficker.B=20
or http://tinyurl.com/9vpbxs
http://www.sophos.com/blogs/gc/g/2009/01/16/passwords-conficker-worm/

Guessing passwords:
http://www.schneier.com/essay-246.html
http://www.schneier.com/essay-148.html

Password Safe:
http://www.schneier.com/passsafe.html

Security problems with secret questions:
http://www.schneier.com/blog/archives/2005/02/the_curse_of_th.html


** *** ***** ******* *********** *************

      Comments from Readers



There are hundreds of comments -- many of them interesting -- on these=20
topics on my blog. Search for the story you want to comment on, and join =
in.

http://www.schneier.com/blog


** *** ***** ******* *********** *************

Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing=20
summaries, analyses, insights, and commentaries on security: computer=20
and otherwise.  You can subscribe, unsubscribe, or change your address=20
on the Web at <http://www.schneier.com/crypto-gram.html>.  Back issues=20
are also available at that URL.

Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable.  Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is the author of the=20
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"=20
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,=20
Phelix, and Skein algorithms.  He is the Chief Security Technology=20
Officer of BT BCSG, and is on the Board of Directors of the Electronic=20
Privacy Information Center (EPIC).  He is a frequent writer and lecturer=20
on security topics.  See <http://www.schneier.com>.

Crypto-Gram is a personal newsletter.  Opinions expressed are not=20
necessarily those of BT.

Copyright (c) 2009 by Bruce Schneier.