NewsScan Daily, 1 August 2003 ("Above The Fold")

"NewsScan" <[email protected]>
Newsgroups gmane.culture.it.newsscan
Message-ID <[email protected]>
NewsScan Daily, 1 August 2003 ("Above The Fold")
***********************************************************
NewsScan Daily is underwritten by RLG, a world-class organization
making significant and sustained contributions to the effective
management and appropriate use of information technology. NSD is
written by John Gehl and Suzanne Douglas, [email protected].
***********************************************************

"ABOVE THE FOLD"
        Procrastination in Patching Software Flaws
        Is SMTP Ready for Retirement?
        Record Labels, Colleges Seek Legitimate Music Options
        Vodafone, Verizon Team Up on Roaming Laptop Data Card
        Taiwanese Smart Phone Based on Windows
        Malaysia to Ban Divorce Via Text Messaging

FEATURES
        Flash Card
        Honorary Subscriber: Grace Kelly
        Safe & Sound in the Cyberage with Chey & Stephen Cobb

PROCRASTINATION IN PATCHING SOFTWARE FLAWS
A study called "Laws of Vulnerabilities" and presented at this week's Black 
Hat conference of computer-security professionals indicates that critical 
vulnerabilities tend to get patched fast but other vulnerabilities tend to 
be overlooked -- and patched as late as two months after fixes are 
released. The study was based on 1.5 million scans over a year and a half. 
Gerhard Eschelbeck, the chief technology officer of Qualys, a company that 
handles on-demand security audits and vulnerability management, says the 
study had found that vulnerabilities such as the Code Red and Slammer worms 
did not completely die out but tended to re-assert themselves, probably 
because companies continue to install out-of-date software that was 
susceptible to these old vulnerabilities. The study's conclusions: The 
half-life of critical vulnerabilities is 30 days and doubles with lowering 
degrees of severity; 50% of the most prevalent and critical vulnerabilities 
are being replaced by new vulnerabilities on an annual basis; the lifespan 
of some vulnerabilities is unlimited; and 80% of vulnerability exploits are 
available within 60 days after the vulnerability release. (The Age, 
Australia, 1 Aug 2003)
http://www.theage.com.au/articles/2003/08/01/1059480525404.html

IS SMTP READY FOR RETIREMENT?
The Simple Mail Transfer Protocol (SMTP) has served the online universe 
loyally for more than two decades, but some security experts are now saying 
it's time for a replacement. SMTP's flaw? It's too trusting. It makes the 
assumption that an e-mail sender is who she says she is -- a characteristic 
that is blamed in part for enabling more spam-mail. Suzanne Sluizer, a 
co-author of SMTP's immediate predecessor, the Mail Transport Protocol, 
says the e-mail environment for which SMTP was designed was very different. 
"It was a trusted situation, and the protocols were developed on the basis 
of that trust. So it's very surprising to me that we are using the same 
protocols coming up on 25 years later, because you need different things in 
a commercial environment than you need in a research environment," says 
Sluizer. "I would suggest they just write a new protocol from the 
beginning. In my experience in computers… trying to fix problems in the 
existing thing is almost always more difficult than just sitting down and 
thinking about what you want and coming up with something new." And while 
some experts say rewriting SMTP from the ground up would be prohibitively 
cumbersome, given the old protocol's installed user base comprising 
hundreds of millions of people, Sluizer contends that problem could solved 
by implementing a tandem system using two protocols -- SMTP and a new one, 
with tighter authentication -- with e-mail applications supporting both 
side by side. (CNet News.com 1 Aug 2003)
http://news.com.com/2100-1038_3-5058610.html?tag=fd_lede1_hed

RECORD LABELS, COLLEGES SEEK LEGITIMATE MUSIC OPTIONS
Recording industry executives are quietly working with colleges and 
universities to develop new online music services that would give students 
a legitimate and attractive alternative to using file-sharing sites such as 
Kazaa. The discussions are still at an early stage, but music executives 
are hopeful they can win over college administrators: "This is a great 
opportunity to tap into this university base, show them the promise of 
digital music, show them the compelling digital offerings," says Musicmatch 
president Peter D. Csathy. The proposed services would provide students 
with an extensive collection of songs stored on an online jukebox for a fee 
of $5 or $10 a month. If they wanted to purchase songs to burn to a CD or 
transfer to an MP3 player, the cost would be $1 or less per track. However, 
for a legitimate service to succeed on campus, colleges would need to 
curtail access to unauthorized ones, something they've so far been 
reluctant to do, arguing that blocking peer-to-peer services runs counter 
to the ideals of academic freedom. "Part of it was that [universities] 
weren’t yet feeling the real heat," says Peter Fader, a market professor at 
University of Pennsylvania's Wharton School. "So, unfortunately, it will 
come down to when the threats are large enough, either legal or financial. 
Then it will happen." (Los Angeles Times 1 Aug 2003)
http://www.latimes.com/technology/la-fi-music1aug01225417,1,3021446.story?coll=la-headlines-technology

VODAFONE, VERIZON TEAM UP ON ROAMING LAPTOP DATA CARD
Vodafone Group and Verizon Wireless have jointly developed a new data card 
designed to give laptops wireless Internet access in the U.S. as well as in 
the 27 other countries where Vodafone operates wireless networks. "This 
will allow Verizon Wireless and Vodafone customers to work effectively 
whilst traveling in the U.S. and Europe," says Vodafone COO Julian 
Horn-Smith. The dual-branded laptop data card will be based on Vodafone's 
successful Mobile Connect Card, and will be marketed by Verizon Wireless 
under a licensing agreement. (Reuters 1 Aug 2003)
http://story.news.yahoo.com/news?tmpl=story&cid=581&ncid=581&e=1&u=/nm/20030801/tc_nm/telecoms_vodafone_verizon_dc

TAIWANESE SMART PHONE BASED ON WINDOWS
A new smart phone developed by Taiwan'ts Chi Mei Communications Systems and 
based on Microsoft software has received regulatory approval by the U.S. 
Federal Communications Commission (FCC), which is usually one of the final 
stages a product goes through before commercial launch. The Chi Mei smart 
phone (developed under the code name "Beethoven") has a clamshell design 
and runs the Windows-powered Smartphone operating system, which is also 
used in Mitac International's Mio 8380 and High Tech Computer's Qtek 7070. 
Current speculation is that the phone will be sold by Motorola. (PC World 
31 Jul 2003)
http://www.pcworld.com/news/article/0,aid,111839,00.asp

MALAYSIA TO BAN DIVORCE VIA TEXT MESSAGING
Malaysian men may no longer notify their wives that they're divorcing them 
via e-mail or text messaging, according to an Islamic court ruling last 
week. The practice had gained in popularity in some Islamic countries in 
recent years, with some religious authorities sanctioning it. According to 
Islamic law, a husband can divorce his wife simply by declaring his 
intention to do so and then repeating that desire before a religious law 
judge. (The procedure for wives is much more difficult.) Malaysian Prime 
Minister Mahathir Mohamad said that while text messaging is not explicitly 
prohibited under Malaysia's current laws, "it is not the way to get 
divorced." Abdul Hamid Othman, the government's official religious adviser, 
added, "Husbands should not be allowed to freely use SMS (text messaging) 
and other easy methods such as e-mails, voicemail or even facsimile to 
begin divorce proceedings. We must put a stop to it as it is morally wrong 
and unacceptable to society." (AP 31 Jul 2003)
http://apnews.excite.com/article/20030731/D7SKO2FG1.html

*****

FLASH CARD
      "To be wholly overlooked, and to know it, are intolerable." (John Adams)

HONORARY SUBSCRIBER: GRACE KELLY
      Today's Honorary Subscriber is the American film star Grace Kelly 
(1929-1982) who ended her acting career in 1956 to marry Monaco's Prince 
Rainier III. The couple had three children -- Princess Caroline, Prince 
Albert, and Princess Stephanie. Tragedy struck when Princess Grace died of 
injuries sustained in an automobile accident. Grace and her daughter 
Stephanie were driving on a winding road at Cap-d'Ail in the Côte d'Azur 
region of France when Princess Grace suffered a stroke and lost control of 
the car, which plunged down a steep embankment.
      Grace Kelly was born into a rich Irish Catholic family in 
Philadelphia and attended private schools before enrolling in the American 
Academy of Dramatic Art in New York City in 1947. She made her professional 
debut in summer stock in July 1949 and her Broadway debut in November 1949. 
She also appeared frequently on television.
      Kelly's Hollywood career spanned the six years between 1951 and 1956. 
She made her screen debut in the 1951 film "Fourteen Hours," followed the 
next year by playing Gary Cooper's Quaker wife in "High Noon." In 1953 she 
appeared in "Mogambo," and then in 1954 she won an Academy Award for best 
actress as Bing Crosby's dowdy wife in "The Country Girl." Struck by what 
he called her "sexual elegance," Alfred Hitchcock considered Kelly the 
perfect heroine and cast her in his films, "Dial M for Murder" (1954), 
"Rear Window" (1954), and "To Catch a Thief" (1955). Her last two films 
before her storybook romance and marriage were "The Swan" and "High 
Society," both released in1956.
      Gradually, as she became involved in Monaco life, Kelly devoted her 
time to a variety of charitable works such as helping orphans. This 
dedication was acknowledged in 1977 when the Cérès medal was bestowed on 
her by the United Nations.

See http://www.amazon.com/exec/obidos/ASIN/B00003CXC7/newsscancom/ref=nosim 
for the DVD of "Rear Window" -- or look for it in the multimedia section of 
your favorite library. (We donate all revenue from our book recommendations 
to adult literacy programs.)

SAFE & SOUND IN THE CYBER AGE
      (This week, our security consultants, Chey and Stephen Cobb, write 
about "Snake Oil, Crypto, and E-voting"):
      The time has come to talk of snake oil, cryptography, and electronic 
voting. Chey was already in the process of writing a couple of columns on 
cryptography to highlight the work of a very worthy organization know as 
the CryptoRights Foundation, which is helping human rights workers around 
the world use encryption to communicate securely (see 
www.cryptorights.org). And we would have felt obliged to mention that she 
is currently working on a new book, "Cryptography for Dummies." But then a 
NewsScan reader asked if we would comment on Internet voting, just as 
researchers from Johns Hopkins University and Rice University went public 
with criticism of electronic voting machines built by Diebold Election Systems.
      Obviously, it was time to talk about crypto and voting, but where 
does the snake oil fit into this? After all, the term was coined as a 
pejorative descriptor for the mysterious elixirs sold by traveling medicine 
shows as a cure for everything and anything that ails you (memorialized for 
us in the song "Medicine Show" on the 1985 album "This is Big Audio 
Dynamite," which features the superb line "If you've got straight trousers, 
it'll give you flares").
      In the world of computer security, snake oil refers a product that 
oversells its security, specifically its use of cryptography, often by 
refusing, like the hawker of elixirs, to say exactly what is in it. Now 
this might strike you, at first glance, as illogical. After all, if the 
purpose of a product is to keep things secret, doesn't it make sense to 
keep the workings of the product secret? The correct answer, for a number 
of reasons, is no, particularly when the product uses cryptography.
      Perhaps the easiest of the reasons to convey goes like this: The role 
of encryption is to garble your messages (or words or data) so that only 
those who have the password (or keys or permission) can decipher what they 
say. Superficially garbled output, like a miracle cure, is very hard to 
distinguish from seriously garbled output, or a genuine long-term medical 
recovery. Suppose our message is "Beware the Ides of March" and we encrypt 
this as FIAEV IXLIM HIWSJ QEVGL. That looks, superficially, a lot like 
TYWHU YHQGF ERKSD PMSVJ or even HGSDF WSEDV OPLKM NZACU. But a cryptanalyst 
will quickly discern what FIAEV IXLIM HIWSJ QEVGL says because it uses a 
simple substitution cipher (the aptly named Caesar Cipher, which simply 
shifts the letters of the alphabet a fixed number of places to the right). 
The other two examples are harder to break, or they may just be random 
characters, which is why you should not trust a security claim that is 
backed by nothing more than the vendor saying "Trust Us, We Know What We're 
Doing."
      Fortunately, genuine cryptography is not sleight of hand or a black 
art. In fact, the most powerful encryption algorithms are the ones that 
have been published and reviewed. In other words, they are able to encrypt 
messages so well that even having the recipe of how they did it does not 
help the code-breaker to break the code. For proof of this logic look no 
further than the strongest encryption algorithm approved by the federal 
government. This is referred to as the Advanced Encryption Standard and it 
supercedes the DES or Data Encryption Standard.
      The choice of algorithm for AES was announced at the end of 2001 
after a rigorous selection process lasting several years and during which 
numerous contenders were examined, line by line, by cryptographers from 
around the world. In fact, anyone who wanted to test the contenders could 
do so, and the winner, known as Rijndael (pronounced Rhine-doll) was 
developed by two Belgian cryptographers. Rijndael is not only publicly 
available for examination but the algorithm itself is free (implementing it 
securely in your encryption software is not).
      Which brings us to the use of computers for voting, either in voting 
booths or over the Internet. After the debacle of the 2000 presidential 
election, many states embraced computerized voting, at no small cost 
(here's one example: in July of 2001, Maryland officials signed an 
agreement with Diebold's Election Systems unit for about 11,000 
touch-screen voting systems valued at up to $55.6 million).
      Traditional wisdom in computer security circles is that systems such 
as these should be subject to independent scrutiny, preferably before 
anyone relies on their results. Why? Two reasons. First, "bad actors" will 
definitely be giving them lots of scrutiny and exploiting any holes they 
find. Second, if anyone disputes votes cast electronically and the system 
is found to have holes, it will be very hard to prove those holes were not 
exploited, even if they weren't. Then you're right back at the beginning, 
minus many millions of angry taxpayers' dollars.
      We will have more on encryption and the right way to go about 
implementing electronic voting in the next column.
      Note: In the information found below, we use the "name at name dot 
name" style of email address in place in order to raise awareness of how 
spammers harvest addresses.
      [Chey Cobb, CISSP, the author of "Network Security for Dummies," is 
an independent consultant (www.cheycobb.com) and a former senior technical 
security advisor to the NRO. She can be emailed as "chey at patriot dot 
net." Stephen Cobb, CISSP, helped develop SpamSquelcher, the first product 
that actually stops spam. He can be emailed as "scobb at eprivacygroup dot 
com."]

SUBSCRIPTION INFO FOR NEWSSCAN DAILY:
      To subscribe or unsubscribe to the text, html, or handheld versions 
of NewsScan Daily, send the appropriate subscribe or unsubscribe messages 
(i.e., with the word 'subscribe' or 'unsubscribe' in the subject line) to 
the addresses shown below:
      Text version: Send message to [email protected]
      HTML version: Send mail to [email protected]
      NewsScan-To-Go: http://www.newsscan.com/handheld/current.html

TELL YOUR FRIENDS ABOUT NEWSSCAN DAILY! Send them our little frog: 
http://www.newsscan.com/newsscan/newscup.html

***********************************************************
Please visit the site of RLG, the great organization that makes NewsScan 
Daily possible. (RLG has no influence over, nor any responsibility for, our 
editorial content.) Created in 1974 as the Research Libraries Group, RLG is 
a not-for-profit membership corporation of more than 160 universities, 
national libraries, archives, museums -- and other institutions with 
remarkable collections for research and learning. Its major initiatives are 
long-term retention of digital materials, resource sharing among member 
institutions, and improvement of researcher access to primary source 
material. RLG supplies online research resources worldwide. Visit RLG at 
http://www.rlg.org.

*********

To subscribe or unsubscribe to the TEXT version of NewsScan Daily, send an 
e-mail message to [email protected] with 'subscribe' or 'unsubscribe' 
in the subject line. To subscribe to our HTML version of NewsScan Daily, 
send mail to [email protected], with the word 'subscribe' as the 
subject. (Subscribing to the HTML version won't automatically unsubscribe 
you from the text version; please unsubscribe yourself as explained above.) 
Please note: To unsubscribe from an account to which you no longer have 
access, send mail to at [email protected].

*********

We call our news section "Above The Fold" to honor the tradition of the 
great "broadsheet" newspapers in which editors must decide which news 
stories are of such importance that they should be placed "above the fold" 
on the front page. The NewsScan Credo: Be informative, have fun, and get to 
the point! See http://www.newsscan.com/, and send us mail: John Gehl 
<[email protected]> and Suzanne Douglas <[email protected]>, or call 
770-704-7517.

*********

Get a free 6-week trial subscription to Innovation Weekly, an executive 
summary of trends, strategies and innovations in business and technology. 
Send mail to [email protected] with the word 'subscribe' in the 
subject line.

What customized news and information services do you need for your company? 
Get in touch with us at [email protected] or call 770-704-7517 to talk 
over the possibilities.

Copyright 2003. NewsScan Daily (R) is a publication of NewsScan Inc.
***********************************************************
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.