CRYPTO-GRAM, May 15, 2010

Bruce Schneier <[email protected]> Sat, 15 May 2010 02:53:13 -0500
Newsgroups gmane.comp.security.crypto-gram
Message-ID <[email protected]>
                  CRYPTO-GRAM

                  May 15, 2010

               by Bruce Schneier
       Chief Security Technology Officer, BT
              [email protected]
             http://www.schneier.com


A free monthly newsletter providing summaries, analyses, insights, and=20
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit=20
<http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at=20
<http://www.schneier.com/crypto-gram-1005.html>.  These same essays and=20
news items appear in the "Schneier on Security" blog at=20
<http://www.schneier.com/blog>, along with a lively comment section.  An=20
RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
      Worst-Case Thinking
      Why Aren't There More Terrorist Attacks?
      9/11 Made us Safer?
      News
      Fifth Annual Movie-Plot Threat Contest Semi-Finalists
      Young People, Privacy, and the Internet
      The Doghouse: Lock My PC
      "If You See Something, Say Something"
      Schneier News
      Preventing Terrorist Attacks in Crowded Areas
      Punishing Security Breaches


** *** ***** ******* *********** *************

      Worst-Case Thinking



At a security conference recently, the moderator asked the panel of=20
distinguished cybersecurity leaders what their nightmare scenario was.=20
The answers were the predictable array of large-scale attacks: against=20
our communications infrastructure, against the power grid, against the=20
financial system, in combination with a physical attack.

I didn't get to give my answer until the afternoon, which was: "My=20
nightmare scenario is that people keep talking about their nightmare=20
scenarios."

There's a certain blindness that comes from worst-case thinking. An=20
extension of the precautionary principle, it involves imagining the=20
worst possible outcome and then acting as if it were a certainty. It=20
substitutes imagination for thinking, speculation for risk analysis and=20
fear for reason. It fosters powerlessness and vulnerability and=20
magnifies social paralysis. And it makes us more vulnerable to the=20
effects of terrorism.

Worst-case thinking means generally bad decision making for several=20
reasons. First, it's only half of the cost-benefit equation. Every=20
decision has costs and benefits, risks and rewards. By speculating about=20
what can possibly go wrong, and then acting as if that is likely to=20
happen, worst-case thinking focuses only on the extreme but improbable=20
risks and does a poor job at assessing outcomes.

Second, it's based on flawed logic. It begs the question by assuming=20
that a proponent of an action must prove that the nightmare scenario is=20
impossible.

Third, it can be used to support any position or its opposite. If we=20
build a nuclear power plant, it could melt down. If we don't build it,=20
we will run short of power and society will collapse into anarchy. If we=20
allow flights near Iceland's volcanic ash, planes will crash and people=20
will die. If we don't, organs won't arrive in time for transplant=20
operations and people will die. If we don't invade Iraq, Saddam Hussein=20
might use the nuclear weapons he might have. If we do, we might=20
destabilize the Middle East, leading to widespread violence and death.

Of course, not all fears are equal. Those that we tend to exaggerate are=20
more easily justified by worst-case thinking. So terrorism fears trump=20
privacy fears, and almost everything else; technology is hard to=20
understand and therefore scary; nuclear weapons are worse than=20
conventional weapons; our children need to be protected at all costs;=20
and annihilating the planet is bad. Basically, any fear that would make=20
a good movie plot is amenable to worst-case thinking.

Fourth and finally, worst-case thinking validates ignorance. Instead of=20
focusing on what we know, it focuses on what we don't know -- and what=20
we can imagine.

Remember Defense Secretary Donald Rumsfeld's quote?  "Reports that say=20
that something hasn't happened are always interesting to me, because as=20
we know, there are known knowns; there are things we know we know. We=20
also know there are known unknowns; that is to say we know there are=20
some things we do not know. But there are also unknown unknowns -- the=20
ones we don't know we don't know." And this: "the absence of evidence is=20
not evidence of absence." Ignorance isn't a cause for doubt; when you=20
can fill that ignorance with imagination, it can be a call to action.

Even worse, it can lead to hasty and dangerous acts. You can't wait for=20
a smoking gun, so you act as if the gun is about to go off. Rather than=20
making us safer, worst-case thinking has the potential to cause=20
dangerous escalation.

The new undercurrent in this is that our society no longer has the=20
ability to calculate probabilities. Risk assessment is devalued.=20
Probabilistic thinking is repudiated in favor of "possibilistic=20
thinking": Since we can't know what's likely to go wrong, let's=20
speculate about what can possibly go wrong.

Worst-case thinking leads to bad decisions, bad systems design, and bad=20
security. And we all have direct experience with its effects: airline=20
security and the TSA, which we make fun of when we're not appalled that=20
they're harassing 93-year-old women or keeping first graders off=20
airplanes.  You can't be too careful!

Actually, you can. You can refuse to fly because of the possibility of=20
plane crashes. You can lock your children in the house because of the=20
possibility of child predators. You can eschew all contact with people=20
because of the possibility of hurt. Steven Hawking wants to avoid trying=20
to communicate with aliens because they might be hostile; does he want=20
to turn off all the planet's television broadcasts because they're=20
radiating into space? It isn't hard to parody worst-case thinking, and=20
at its extreme it's a psychological condition.

Frank Furedi, a sociology professor at the University of Kent, writes:=20
"Worst-case thinking encourages society to adopt fear as one of the=20
dominant principles around which the public, the government and=20
institutions should organize their life. It institutionalizes insecurity=20
and fosters a mood of confusion and powerlessness. Through popularizing=20
the belief that worst cases are normal, it incites people to feel=20
defenseless and vulnerable to a wide range of future threats."

Even worse, it plays directly into the hands of terrorists, creating a=20
population that is easily terrorized -- even by failed terrorist attacks=20
like the Christmas Day underwear bomber and the Times Square SUV bomber.

When someone is proposing a change, the onus should be on them to=20
justify it over the status quo. But worst case thinking is a way of=20
looking at the world that exaggerates the rare and unusual and gives the=20
rare much more credence than it deserves.

It isn't really a principle; it's a cheap trick to justify what you=20
already believe. It lets lazy or biased people make what seem to be=20
cogent arguments without understanding the whole issue. And when people=20
don't need to refute counterarguments, there's no point in listening to=20
them.

This essay was originally published on CNN.com, although they stripped=20
out all the links.
http://www.cnn.com/2010/OPINION/05/12/schneier.worst.case.thinking/

Security conference:
http://www.ewi.info/dallas

Precautionary principle:
http://en.wikipedia.org/wiki/Precautionary_principle

Iceland volcano affects organ donations:
http://www.cbsnews.com/8301-503543_162-20002792-503543.html

Areas where we tend to overestimate the threat:
http://www.schneier.com/essay-170.htm

New particle accelerator may annihilate the planet:
http://news.cnet.com/8301-10784_3-9905448-7.html

Movie plot threats:
http://www.schneier.com/essay-087.html

Rumsfeld quote:
http://www.defenselink.mil/Transcripts/Transcript.aspx?TranscriptID=3D263=
6=20
or http://tinyurl.com/2aa4rwr

Possibilistic thinking:
http://www.press.uchicago.edu/Misc/Chicago/108597in.html

Making fun of the TSA:
http://www.theatlantic.com/politics/archive/2010/05/if-the-tsa-were-runni=
ng-new-york/39839/=20
or http://tinyurl.com/2u33old

The TSA harasses a 93-year-old women:
http://www.youtube.com/watch?v=3DwHxy5GattLY

The TSA keeps a first-grader off airplanes:
http://www.bostonherald.com/news/regional/view/20100417no_fly_foul_as_gir=
l_6_put_on_list_bay_state_dad_fights_tsa_ban_on_1st-grader/srvc=3Dhome&po=
sition=3D0=20
or http://tinyurl.com/yybe2w2

Steven Hawking on communicating with aliens:
http://www.msnbc.msn.com/id/36769422/

Frank Furedi on worst-case-thinking:
http://www.frankfuredi.com/index.php/site/article/326/
http://www.frankfuredi.com/index.php/site/article/386/

How we are easily terrorized:
http://www.schneier.com/essay-124.html

Christmas Day underwear bomber:
http://www.schneier.com/essay-304.html

Times Square SUV bomber:
http://www.schneier.com/essay-315.html


** *** ***** ******* *********** *************

      Why Aren't There More Terrorist Attacks?



As the details of the Times Square car bomb attempt emerge in the wake=20
of Faisal Shahzad's arrest Monday night, one thing has already been made=20
clear: Terrorism is fairly easy. All you need is a gun or a bomb, and a=20
crowded target. Guns are easy to buy. Bombs are easy to make. Crowded=20
targets -- not only in New York, but all over the country -- are easy to=20
come by. If you're willing to die in the aftermath of your attack, you=20
could launch a pretty effective terrorist attack with a few days of=20
planning, maybe less.

But if it's so easy, why aren't there more terrorist attacks like the=20
failed car bomb in New York's Times Square? Or the terrorist shootings=20
in Mumbai? Or the Moscow subway bombings? After the enormous horror and=20
tragedy of 9/11, why have the past eight years been so safe in the U.S.?

There are actually several answers to this question. One, terrorist=20
attacks are harder to pull off than popular imagination -- and the=20
movies -- lead everyone to believe. Two, there are far fewer terrorists=20
than the political rhetoric of the past eight years leads everyone to=20
believe. And three, random minor terrorist attacks don't serve Islamic=20
terrorists' interests right now.

Terrorism sounds easy, but the actual attack is the easiest part.

Putting together the people, the plot and the materials is hard. It's=20
hard to sneak terrorists into the U.S. It's hard to grow your own inside=20
the U.S. It's hard to operate; the general population, even the Muslim=20
population, is against you.

Movies and television make terrorist plots look easier than they are.=20
It's hard to hold conspiracies together. It's easy to make a mistake.=20
Even 9/11, which was planned before the climate of fear that event=20
engendered, just barely succeeded. Today, it's much harder to pull=20
something like that off without slipping up and getting arrested.

But even more important than the difficulty of executing a terrorist=20
attack, there aren't a lot of terrorists out there. Al-Qaeda isn't a=20
well-organized global organization with movie-plot-villain capabilities;=20
it's a loose collection of people using the same name. Despite the=20
post-9/11 rhetoric, there isn't a terrorist cell in every major city. If=20
you think about the major terrorist plots we've foiled in the U.S. --=20
the JFK bombers, the Fort Dix plotters -- they were mostly amateur=20
terrorist wannabes with no connection to any sort of al-Qaeda central=20
command, and mostly no ability to effectively carry out the attacks they=20
planned.

The successful terrorist attacks -- the Fort Hood shooter, the guy who=20
flew his plane into the Austin IRS office, the anthrax mailer -- were=20
largely nut cases operating alone. Even the unsuccessful shoe bomber,=20
and the equally unsuccessful Christmas Day underwear bomber, had minimal=20
organized help -- and that help originated outside the U.S.

Terrorism doesn't occur without terrorists, and they are far rarer than=20
popular opinion would have it.

Lastly, and perhaps most subtly, there's not a lot of value in=20
unspectacular terrorism anymore.

If you think about it, terrorism is essentially a PR stunt. The death of=20
innocents and the destruction of property isn't the goal of terrorism;=20
it's just the tactic used. And acts of terrorism are intended for two=20
audiences: for the victims, who are supposed to be terrorized as a=20
result, and for the allies and potential allies of the terrorists, who=20
are supposed to give them more funding and generally support their effort=
s.

An act of terrorism that doesn't instill terror in the target population=20
is a failure, even if people die. And an act of terrorism that doesn't=20
impress the terrorists' allies is not very effective, either.

Fortunately for us and unfortunately for the terrorists, 9/11 upped the=20
stakes. It's no longer enough to blow up something like the Oklahoma=20
City Federal Building. Terrorists need to blow up airplanes or the=20
Brooklyn Bridge or the Sears Tower or JFK airport -- something big to=20
impress the folks back home. Small no-name targets just don't cut it=20
anymore.

Note that this is very different than terrorism by an occupied=20
population: the IRA in Northern Ireland, Iraqis in Iraq, Palestinians in=20
Israel. Setting aside the actual politics, all of these terrorists=20
believe they are repelling foreign invaders. That's not the situation=20
here in the U.S.

So, to sum up: If you're just a loner wannabe who wants to go out with a=20
bang, terrorism is easy. You're more likely to get caught if you take a=20
long time to plan or involve a bunch of people, but you might succeed.=20
If you're a representative of al-Qaeda trying to make a statement in the=20
U.S., it's much harder. You just don't have the people, and you're=20
probably going to slip up and get caught.

This essay originally appeared on AOL News.
http://www.aolnews.com/opinion/article/opinion-why-arent-there-more-times=
-square-style-terrorist-attacks/19463843=20
or http://tinyurl.com/3xwzv7l

Amateur terrorist wannabes:
http://www.schneier.com/essay-174.html

Instilling terror:
http://www.schneier.com/essay-124.html

A similar sentiment about the economic motivations of terrorists.
http://www.theatlantic.com/business/archive/2010/05/the-market-for-terror=
ist-attacks/39842/=20
or http://tinyurl.com/266kfeh


** *** ***** ******* *********** *************

      9/11 Made us Safer?



There's an essay on the Computerworld website that claims I implied, and=20
believe, so:  "OK, so strictly-speaking, he doesn't use those exact=20
words, but the implication is certainly clear. In a discussion about why=20
there aren't more terrorist attacks, he argues that 'minor' terrorist=20
plots like the Times Square car bomb are counter-productive for=20
terrorist groups, because '9/11 upped the stakes.'"

This comes from the above essay that discusses why there have been so=20
few terrorist attacks since 9/11.  There's the primary reason -- there=20
aren't very many terrorists out there -- and the secondary reason:=20
terrorist attacks are harder to pull off than popular culture leads=20
people to believe.  What he's talking about above is the tertiary=20
reason: terrorist attacks have a secondary purpose of impressing=20
supporters back home, and 9/11 has upped the stakes in what a flashy=20
terrorist attack is supposed to look like.

 From there to 9/11 making us safer is quite a leap, and not one that I=20
expected anyone to make.  Certainly a series of events, before, during,=20
and after 9/11, contributed to an environment in which a particular=20
group of terrorists found low-budget terrorist attacks less useful --=20
and I suppose by extension we might be safer because of it.  But you'd=20
also have to factor in the risks associated with increased police=20
powers, the NSA spying on all of us without warrants, and the increased=20
disregard for the law we've seen out of the U.S. government since 9/11.=20
  And even so, that's a far cry from claiming causality that 9/11 made=20
us safer.

Not that any of this really matters.  Compared to the real risks in the=20
world, the risk of terrorism is so small that it's not worth a lot of=20
worry.  As John Mueller pointed out, the risks of terrorism "are similar=20
to the risks of using home appliances (200 deaths per year in the United=20
States) or of commercial aviation (103 deaths per year)."

http://blogs.computerworld.com/16053/9_11_made_us_safer_bruce_schneiers_s=
ign_of_the_times_square=20
or http://tinyurl.com/2g839dt

John Mueller on the risks of terrorism:
http://www.schneier.com/blog/archives/2010/04/terrorist_attac.html

A response from Computerworld.
http://blogs.computerworld.com/16079/bruce_schneier_thats_not_what_i_mean=
t=20
or http://tinyurl.com/2fb2oqx


** *** ***** ******* *********** *************

      News



Last month I was in New York, and saw posters on the subways warning=20
people about real guns painted to look like toys.  Searching, I found=20
pictures from the Baltimore police department and an article from 2006=20
New York.  They're painted bright colors to look cool -- not really to=20
fool policemen -- but I had no idea this was a thing.
http://publicintelligence.net/baltimore-police-department-guns-that-look-=
like-toys/=20
or http://tinyurl.com/y7gpzcw
http://abcnews.go.com/US/story?id=3D2045782

CCTV cameras in Moscow have been accused of streaming prerecorded video=20
instead of live images.  What I can't figure out is why?  To me, it=20
seems easier for the cameras to stream live video than prerecorded=20
images.  But it seems they were not connected at all.
http://www.theregister.co.uk/2010/01/15/moscow_cctv_fake_feed/
http://rt.com/Top_News/2010-01-13/cctv-cameras-fraud-moscow.html

In 2006, writing about future threats on privacy, I described a life=20
recorder:  "A 'life recorder' you can wear on your lapel that constantly=20
records is still a few generations off: 200 gigabytes/year for audio and=20
700 gigabytes/year for video. It'll be sold as a security device, so=20
that no one can attack you without being recorded."  I can't find a=20
quote right now, but in talks I would say that this kind of technology=20
would first be used by groups of people with diminished rights:=20
children, soldiers, prisoners, and the non-lucid elderly.  It's been=20
proposed.  Just one sentence on the security and privacy issues:=20
"Indeed, privacy concerns need to be addressed so that stalkers and=20
predators couldn't compromise the device."  Indeed.
http://www.darkreading.com/blog/archives/2010/03/is_it_time_for.html?cid=3D=
nl_DR_DAILY_2010-03-15_h=20
or http://tinyurl.com/y29q5kx http://www.schneier.com/essay-109.html

Lt. Gen. Alexander and the U.S. Cyber Command
http://www.schneier.com/blog/archives/2010/04/lt_gen_alexande.html

Research on the effectiveness of political assassinations.
http://www.schneier.com/blog/archives/2010/04/the_effectivene_1.html

Remember SmartWater: liquid imbued with a uniquely identifiable=20
DNA-style code?  Well, Mont Blanc is selling a pen with uniquely=20
identifiable ink.
http://www.schneier.com/blog/archives/2010/04/personal_code_i.html

Security Fog: an odd burglary prevention tool.
http://www.schneier.com/blog/archives/2010/04/security_fog.html

Just published by NIST: Special Publication (SP) 800-122, "Guide to=20
Protecting the Confidentiality of Personally Identifiable Information=20
(PII)."  It's 60 pages long; I haven't read it.
http://csrc.nist.gov/publications/nistpubs/800-122/sp800-122.pdf

Booby-trapping a PDF file:
http://www.theregister.co.uk/2010/03/31/pdf_insecurity/
http://www.sophos.com/blogs/sophoslabs/?p=3D9413

A security cartoon.
http://www.gocomics.com/chanlowe/2010/04/13/

Another security cartoon.
http://images.ucomics.com/comics/wpswi/2010/wpswi100414.gif

Nasty scam, where the user is pressured into accepting a "pre-trial=20
settlement" for ICPP copyright violations.  The level of detail is=20
impressive.
http://www.f-secure.com/weblog/archives/00001931.html

The New York Police Department removed all bicycles from President=20
Obama's route, based on the fear that they might contain pipe bombs.
http://www.schneier.com/blog/archives/2010/04/new_york_police.html

This blog entry about an attack against apache.org should serve as a=20
model for open and transparent security self-reporting.  I'm impressed.
https://blogs.apache.org/infra/entry/apache_org_04_09_2010
More news reports:
http://www.theregister.co.uk/2010/04/13/apache_website_breach_postmortem/=
=20
or http://tinyurl.com/y4fvxdf
http://www.computerworld.com/s/article/9175459/Apache_project_server_hack=
ed_passwords_compromised?taxonomyId=3D88=20
or http://tinyurl.com/y4bclwu
http://www.itpro.co.uk/622363/apache-server-suffers-hack-attack

Seat belt use and lessons for security awareness:
http://www.honeytech.com/blog/ticket-or-click-it/

Hiding your valuables in common household containers is an old trick.=20
Here are some can safes you can buy.  They're relatively inexpensive,=20
although it's cheaper to make your own.
http://www.buyasafe.com/Can-safes-s/12.htm

The U.S. is developing a hypersonic cruise missile capable of striking=20
anywhere on the planet within an hour.  The article talks about the=20
possibility of modifying Trident missiles -- problematic because they=20
would be indistinguishable from nuclear weapons -- and using the Mach=20
5-capable X-51 hypersonic cruise missile.  Interesting technology, but=20
we really need to think through the political ramifications of this sort=20
of thing better.
http://www.popularmechanics.com/technology/military/4203874
Report on the policy implications:
http://www.fas.org/sgp/crs/nuke/RL33067.pdf

Fun with secret questions.  (Be sure to read the blog comments, too.)
http://www.schneier.com/blog/archives/2010/04/fun_with_secret.html

Homeopathic bomb: this is funny.
http://www.newsbiscuit.com/2010/04/20/new-age-terrorists-develop-homeopat=
hic-bomb/=20
or http://tinyurl.com/y5f3vjl

A security analysis of India's electronic voting machines.  No surprise;=20
they're vulnerable to fraud.
http://indiaevm.org/

Good quote from Malcolm Gladwell on spies:  "The proper function of=20
spies is to remind those who rely on spies that the kinds of thing found=20
out by spies can't be trusted."  The article is about the British=20
Operation Mincemeat in World War II.
http://www.newyorker.com/arts/critics/atlarge/2010/05/10/100510crat_atlar=
ge_gladwell=20
or http://tinyurl.com/2g76dh3

Nobody encrypts phone calls.
http://blogs.forbes.com/firewall/2010/04/30/encryption-cant-stop-the-wire=
tapping-boom/=20
or http://tinyurl.com/22pv2x2

WiFi cracking kits are being sold in China.
http://www.networkworld.com/news/2010/050510-wi-fi-key-cracking-kits-sold=
-in.html=20
or http://tinyurl.com/33cdeu5

Cory Doctorow gets phished.
http://www.locusmag.com/Perspectives/2010/05/cory-doctorow-persistence-pa=
ys-parasites/=20
or http://tinyurl.com/23wwuhs

SnapScouts: a parody.
http://www.snapscouts.org/

Reflections of a former U-2 pilot.
http://www.nytimes.com/2010/05/07/opinion/07Espinoza.html

Biometric wallet: cool idea, or dumb idea?
http://geekdoctor.blogspot.com/2010/05/cool-technology-of-week.html

There's a new Windows attack.  It's only in the lab, but nothing detects =
it.
http://www.zdnet.com/blog/hardware/update-new-attack-bypasses-every-windo=
ws-security-product/8268=20
or http://tinyurl.com/28ovu5c


** *** ***** ******* *********** *************

      Fifth Annual Movie-Plot Threat Contest Semi-Finalists



On April 1, I announced the Fifth Annual Movie Plot Threat Contest:=20
"Your task, ye Weavers of Tales, is to create a fable of fairytale=20
suitable for instilling the appropriate level of fear in children so=20
they grow up appreciating all the lords do to protect them."

Submissions are in, and here are the semifinalists.

1. Untitled story about polar bears, by Mike Ferguson.
http://www.schneier.com/blog/archives/2010/04/fifth_annual_mo.html#c42735=
9

2. "The Gashlycrumb Terrors," by Laura.
http://www.schneier.com/blog/archives/2010/04/fifth_annual_mo.html#c42647=
7=20
or http://tinyurl.com/2fn8rjz

3.  Untitled Little Red Riding Hood parody, by Isti.
http://www.schneier.com/blog/archives/2010/04/fifth_annual_mo.html#c42640=
8=20
or http://tinyurl.com/28bze3o

4.  "The Boy who Didn't Cry Wolf," by yt.
http://www.schneier.com/blog/archives/2010/04/fifth_annual_mo.html#c42934=
5=20
or http://tinyurl.com/29t4yq9

5.  Untitled story about exploding imps, by Mister JTA.
http://www.schneier.com/blog/archives/2010/04/fifth_annual_mo.html#c42845=
7=20
or http://tinyurl.com/2cftb47

Cast your vote by number; voting closes at the end of the month.

Vote here:
http://www.schneier.com/blog/archives/2010/04/fifth_annual_mo_1.html


** *** ***** ******* *********** *************

      Young People, Privacy, and the Internet



There's a lot out there on this topic. Last week, two new papers were=20
published.

1.  "Youth, Privacy, and Reputation" is a literature review published by=20
Harvard's Berkman Center.  It's long, but an excellent summary of what's=20
out there on the topic.

2. "How Different Are Young Adults from Older Adults When it Comes to=20
Information Privacy Attitudes & Policy?" from the University of=20
California Berkeley, describes the results of a broad survey on privacy=20
attitudes.

They're both worth reading for anyone interested in this topic.

Youth, Privacy, and Reputation:
http://cyber.law.harvard.edu/publications/2010/Youth_Privacy_Reputation_L=
it_Review=20
or http://tinyurl.com/y5xjx6w

How Different Are Young Adults from Older Adults When it Comes to=20
Information Privacy Attitudes & Policy?:
http://ssrn.com/abstract=3D1589864

danah boyd on the topic:
http://www.danah.org/papers/talks/2010/SXSW2010.html
http://www.danah.org/papers/

My essay on the topic:
http://www.schneier.com/blog/archives/2010/04/privacy_and_con.html

My talk: Security, Privacy, and the Generation Gap:
http://www.schneier.com/blog/archives/2010/04/schneier_on_sec_2.html


** *** ***** ******* *********** *************

      The Doghouse: Lock My PC



Lock My PC 4 has a master password.

In blog comments, people are reporting that the master password doesn't=20
work.  Near as I can tell, those are all recent downloads.  So either=20
they took out the feature, or changed the password.

http://www.schneier.com/blog/archives/2010/04/the_doghouse_lo.html


** *** ***** ******* *********** *************

      "If You See Something, Say Something"



That slogan is owned by New York's Metropolitan Transit Authority (the=20
MTA). "Since obtaining the trademark in 2007, the authority has granted=20
permission to use the phrase in public awareness campaigns to 54=20
organizations in the United States and overseas, like Amtrak, the=20
Chicago Transit Authority, the emergency management office at Stony=20
Brook University and three states in Australia."

Of course, you're only supposed to say something if you see something=20
you think is terrorism: "Some requests have been rejected, including one=20
from a university that wanted to use it to address a series of dormitory=20
burglaries."

Not that its very effective: "The campaign urges people to call a=20
counter-terrorism hot line, 1-888-NYC-SAFE. Police officials said 16,191=20
calls were received last year, down from 27,127 in 2008."

That's a lot of wasted manpower, dealing with all those calls.

Of course, the vendors in Times Square who saw the smoking Nissan=20
Pathfinder two weeks ago didn't call that number.

And, as I've written previously, "if you ask amateurs to act as=20
front-line security personnel, you shouldn't be surprised when you get=20
amateur security." People don't need to be reminded to call the police;=20
the slogan is nothing more than an invitation to report people who are=20
different.

http://www.nytimes.com/2010/05/11/nyregion/11slogan.html

My essay on amateur security:
http://www.schneier.com/essay-195.html

Nice article  illustrating how ineffective the campaign is.
http://www.nytimes.com/2008/01/07/nyregion/07see.html


** *** ***** ******* *********** *************

      Schneier News



I wil be speaking at the 2010 World Congress on Information Technology=20
on May 26 in Amsterdam.
http://www.wcit2010.com/

I'm participating in a debate, "The Cyber War Threat Has Been Grossly=20
Exaggerated," on June 8 in Washington, DC.
http://intelligencesquaredus.org/index.php/debates/cyber-war-threat-has-b=
een-grossly-exaggerated/=20
or http://tinyurl.com/2e9uzta

I will be speaking at the CCD CoE Conference on Cyber Conflict on June=20
18 in Tallinn, Estonia.
http://www.ccdcoe.org/conference2010/

I won a CSO Compass Award:
http://www.csoonline.com/article/593063/CSO_Compass_Award_Bruce_Schneier=20
or http://tinyurl.com/24yfscz

Someone named me as one of the top 10 science and technology writers of=20
all time.  Flattering though it is, I don't think I belong in the=20
company of Einstein, Newton, Darwin, and Asimov.
http://www.pcauthority.com.au/News/173552,top-10-science-and-technology-w=
riters.aspx=20
or http://tinyurl.com/2ck4xkm

Mike Mimoso interviewed me at the RSA Conference last month.
http://searchsecurity.techtarget.com/video/0,297151,sid14_gci1508484,00.h=
tml=20
or http://tinyurl.com/2caloxr
http://searchsecurity.techtarget.com/video/0,297151,sid14_gci1508486,00.h=
tml=20
or http://tinyurl.com/28fb2bf


** *** ***** ******* *********** *************

      Preventing Terrorist Attacks in Crowded Areas



In the wake of the failed Times Square car bombing, it's natural to ask=20
how we can prevent this sort of thing from happening again. The answer=20
is stop focusing on the specifics of what actually happened, and instead=20
think about the threat in general.

Think about the security measures commonly proposed. Cameras won't help.=20
They don't prevent terrorist attacks, and their forensic value after the=20
fact is minimal. In the Times Square case, surely there's enough other=20
evidence -- the car's identification number, the auto body shop the=20
stolen license plates came from, the name of the fertilizer store -- to=20
identify the guy. We will almost certainly not need the camera footage.=20
The images released so far, like the images in so many other terrorist=20
attacks, may make for exciting television, but their value to law=20
enforcement officers is limited.

Check points won't help, either. You can't check everybody and=20
everything. There are too many people to check, and too many train=20
stations, buses, theaters, department stores and other places where=20
people congregate. Patrolling guards, bomb-sniffing dogs, chemical and=20
biological weapons detectors: they all suffer from similar problems. In=20
general, focusing on specific tactics or defending specific targets=20
doesn't make sense. They're inflexible; possibly effective if you guess=20
the plot correctly, but completely ineffective if you don't. At best,=20
the countermeasures just force the terrorists to make minor changes in=20
their tactic and target.

It's much smarter to spend our limited counterterrorism resources on=20
measures that don't focus on the specific. It's more efficient to spend=20
money on investigating and stopping terrorist attacks before they=20
happen, and responding effectively to any that occur.  This approach=20
works because it's flexible and adaptive; it's effective regardless of=20
what the bad guys are planning for next time.

After the Christmas Day airplane bombing attempt, I was asked how we can=20
better protect our airplanes from terrorist attacks. I pointed out that=20
the event was a security success -- the plane landed safely, nobody was=20
hurt, a terrorist was in custody -- and that the next attack would=20
probably have nothing to do with explosive underwear. After the Moscow=20
subway bombing, I wrote that overly specific security countermeasures=20
like subway cameras and sensors were a waste of money.

Now we have a failed car bombing in Times Square. We can't protect=20
against the next imagined movie-plot threat. Isn't it time to recognize=20
that the bad guys are flexible and adaptive, and that we need the same=20
quality in our countermeasures?

This essay originally appeared on the New York Times "Room for Debate"=20
blog.  I know, it's nothing I haven't said before.
http://roomfordebate.blogs.nytimes.com/2010/05/03/times-square-bombs-and-=
big-crowds/?src=3Dtptw#bruce=20
or http://tinyurl.com/283dnwv

http://www.schneier.com/essay-309.html
http://www.schneier.com/essay-304.html
http://www.schneier.com/essay-312.html

Steven Simon likes cameras, although his arguments are more movie-plot=20
than real.
http://roomfordebate.blogs.nytimes.com/2010/05/03/times-square-bombs-and-=
big-crowds/?src=3Dtptw#steven=20
or http://tinyurl.com/25hhkzy

Michael Black, Noah Shachtman,  Michael Tarr, and Jeffrey Rosen all=20
wrote about the limitations of security cameras.=20
http://roomfordebate.blogs.nytimes.com/2010/05/03/times-square-bombs-and-=
big-crowds/?src=3Dtptw#black=20
or http://tinyurl.com/26qw5pg
http://roomfordebate.blogs.nytimes.com/2010/05/03/times-square-bombs-and-=
big-crowds/?src=3Dtptw#noah=20
or http://tinyurl.com/22mqo9r
http://roomfordebate.blogs.nytimes.com/2010/05/03/times-square-bombs-and-=
big-crowds/?src=3Dtptw#tarr=20
or http://tinyurl.com/23z3eeq
http://roomfordebate.blogs.nytimes.com/2010/05/03/times-square-bombs-and-=
big-crowds/?src=3Dtptw#jeffrey=20
or http://tinyurl.com/23ocm5c

Paul Ekman wants more people.=20
http://roomfordebate.blogs.nytimes.com/2010/05/03/times-square-bombs-and-=
big-crowds/?src=3Dtptw#paul=20
or http://tinyurl.com/2fz78zc

Richard Clarke has a nice essay about how we shouldn't panic.
http://roomfordebate.blogs.nytimes.com/2010/05/03/times-square-bombs-and-=
big-crowds/?src=3Dtptw#richard=20
or http://tinyurl.com/24rhwm8


** *** ***** ******* *********** *************

      Punishing Security Breaches



(The editor of the Freakonomics blog asked me to write about this topic.=20
  The idea was that they would get several opinions, and publish them=20
all.  They spiked the story, but I already wrote my piece.  So here it is=
.)

In deciding what to do with Gray Powell, the Apple employee who=20
accidentally left a secret prototype 4G iPhone in a California bar,=20
Apple needs to figure out how much of the problem is due to an employee=20
not following the rules, and how much of the problem is due to unclear,=20
unrealistic, or just plain bad rules.

If Powell sneaked the phone out of the Apple building in a flagrant=20
violation of the rules -- maybe he wanted to show it to a friend -- he=20
should be disciplined, perhaps even fired.  Some military installations=20
have rules like that.  If someone wants to take something classified out=20
of a top secret military compound, he might have to secrete it on his=20
person and deliberately sneak it past a guard who searches briefcases=20
and purses.  He might be committing a crime by doing so, by the way.=20
Apple isn't the military, of course, but if their corporate security=20
policy is that strict, it may very well have rules like that.  And the=20
only way to ensure rules are followed is by enforcing them, and that=20
means severe disciplinary action against those who bypass the rules.

Even if Powell had authorization to take the phone out of Apple's labs=20
-- presumably someone has to test drive the new toys sooner or later --=20
the corporate rules might have required him to pay attention to it at=20
all times.  We've all heard of military attach=E9s who carry briefcases=20
chained to their wrists.  It's an extreme example, but demonstrates how=20
a security policy can allow for objects to move around town -- or around=20
the world -- without getting lost.  Apple almost certainly doesn't have=20
a policy as rigid as that, but its policy might explicitly prohibit=20
Powell from taking that phone into a bar, putting it down on a counter,=20
and participating in a beer tasting.  Again, if Apple's rules and=20
Powell's violation were both that clear, Apple should enforce them.

On the other hand, if Apple doesn't have clear-cut rules, if Powell=20
wasn't prohibited from taking the phone out of his office, if engineers=20
routinely ignore or bypass security rules and -- as long as nothing bad=20
happens -- no one complains, then Apple needs to understand that the=20
system is more to blame than the individual.  Most corporate security=20
policies have this sort of problem.  Security is important, but it's=20
quickly jettisoned when there's an important job to be done.  A common=20
example is passwords: people aren't supposed to share them, unless it's=20
really important and they have to.  Another example is guest accounts.=20
And doors that are supposed to remain locked but rarely are.  People=20
routinely bypass security policies if they get in the way, and if no one=20
complains, those policies are effectively meaningless.

Apple's unfortunately public security breach has given the company an=20
opportunity to examine its policies and figure out how much of the=20
problem is Powell and how much of it is the system he's a part of.=20
Apple needs to fix its security problem, but only after it figures out=20
where the problem is.

http://www.telegraph.co.uk/technology/apple/7611045/Engineer-leaves-new-g=
eneration-Apple-iPhone-on-bar-stool.html=20
or http://tinyurl.com/y5kaxl6


** *** ***** ******* *********** *************

Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing=20
summaries, analyses, insights, and commentaries on security: computer=20
and otherwise.  You can subscribe, unsubscribe, or change your address=20
on the Web at <http://www.schneier.com/crypto-gram.html>.  Back issues=20
are also available at that URL.

Please feel free to forward CRYPTO-GRAM, in whole or in part, to=20
colleagues and friends who will find it valuable.  Permission is also=20
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entiret=
y.

CRYPTO-GRAM is written by Bruce Schneier.  Schneier is the author of the=20
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"=20
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,=20
Threefish, Helix, Phelix, and Skein algorithms.  He is the Chief=20
Security Technology Officer of BT BCSG, and is on the Board of Directors=20
of the Electronic Privacy Information Center (EPIC).  He is a frequent=20
writer and lecturer on security topics.  See <http://www.schneier.com>.

Crypto-Gram is a personal newsletter.  Opinions expressed are not=20
necessarily those of BT.

Copyright (c) 2010 by Bruce Schneier.