NewsScan Daily, 1 August 2003 ("Above The Fold")
"NewsScan" <[email protected]>
| Newsgroups | gmane.culture.it.newsscan |
|---|---|
| Message-ID | <[email protected]> |
NewsScan Daily, 1 August 2003 ("Above The Fold")
***********************************************************
NewsScan Daily is underwritten by RLG, a world-class organization
making significant and sustained contributions to the effective
management and appropriate use of information technology. NSD is
written by John Gehl and Suzanne Douglas, [email protected].
***********************************************************
"ABOVE THE FOLD"
Procrastination in Patching Software Flaws
Is SMTP Ready for Retirement?
Record Labels, Colleges Seek Legitimate Music Options
Vodafone, Verizon Team Up on Roaming Laptop Data Card
Taiwanese Smart Phone Based on Windows
Malaysia to Ban Divorce Via Text Messaging
FEATURES
Flash Card
Honorary Subscriber: Grace Kelly
Safe & Sound in the Cyberage with Chey & Stephen Cobb
PROCRASTINATION IN PATCHING SOFTWARE FLAWS
A study called "Laws of Vulnerabilities" and presented at this week's Black
Hat conference of computer-security professionals indicates that critical
vulnerabilities tend to get patched fast but other vulnerabilities tend to
be overlooked -- and patched as late as two months after fixes are
released. The study was based on 1.5 million scans over a year and a half.
Gerhard Eschelbeck, the chief technology officer of Qualys, a company that
handles on-demand security audits and vulnerability management, says the
study had found that vulnerabilities such as the Code Red and Slammer worms
did not completely die out but tended to re-assert themselves, probably
because companies continue to install out-of-date software that was
susceptible to these old vulnerabilities. The study's conclusions: The
half-life of critical vulnerabilities is 30 days and doubles with lowering
degrees of severity; 50% of the most prevalent and critical vulnerabilities
are being replaced by new vulnerabilities on an annual basis; the lifespan
of some vulnerabilities is unlimited; and 80% of vulnerability exploits are
available within 60 days after the vulnerability release. (The Age,
Australia, 1 Aug 2003)
http://www.theage.com.au/articles/2003/08/01/1059480525404.html
IS SMTP READY FOR RETIREMENT?
The Simple Mail Transfer Protocol (SMTP) has served the online universe
loyally for more than two decades, but some security experts are now saying
it's time for a replacement. SMTP's flaw? It's too trusting. It makes the
assumption that an e-mail sender is who she says she is -- a characteristic
that is blamed in part for enabling more spam-mail. Suzanne Sluizer, a
co-author of SMTP's immediate predecessor, the Mail Transport Protocol,
says the e-mail environment for which SMTP was designed was very different.
"It was a trusted situation, and the protocols were developed on the basis
of that trust. So it's very surprising to me that we are using the same
protocols coming up on 25 years later, because you need different things in
a commercial environment than you need in a research environment," says
Sluizer. "I would suggest they just write a new protocol from the
beginning. In my experience in computers
trying to fix problems in the
existing thing is almost always more difficult than just sitting down and
thinking about what you want and coming up with something new." And while
some experts say rewriting SMTP from the ground up would be prohibitively
cumbersome, given the old protocol's installed user base comprising
hundreds of millions of people, Sluizer contends that problem could solved
by implementing a tandem system using two protocols -- SMTP and a new one,
with tighter authentication -- with e-mail applications supporting both
side by side. (CNet News.com 1 Aug 2003)
http://news.com.com/2100-1038_3-5058610.html?tag=fd_lede1_hed
RECORD LABELS, COLLEGES SEEK LEGITIMATE MUSIC OPTIONS
Recording industry executives are quietly working with colleges and
universities to develop new online music services that would give students
a legitimate and attractive alternative to using file-sharing sites such as
Kazaa. The discussions are still at an early stage, but music executives
are hopeful they can win over college administrators: "This is a great
opportunity to tap into this university base, show them the promise of
digital music, show them the compelling digital offerings," says Musicmatch
president Peter D. Csathy. The proposed services would provide students
with an extensive collection of songs stored on an online jukebox for a fee
of $5 or $10 a month. If they wanted to purchase songs to burn to a CD or
transfer to an MP3 player, the cost would be $1 or less per track. However,
for a legitimate service to succeed on campus, colleges would need to
curtail access to unauthorized ones, something they've so far been
reluctant to do, arguing that blocking peer-to-peer services runs counter
to the ideals of academic freedom. "Part of it was that [universities]
werent yet feeling the real heat," says Peter Fader, a market professor at
University of Pennsylvania's Wharton School. "So, unfortunately, it will
come down to when the threats are large enough, either legal or financial.
Then it will happen." (Los Angeles Times 1 Aug 2003)
http://www.latimes.com/technology/la-fi-music1aug01225417,1,3021446.story?coll=la-headlines-technology
VODAFONE, VERIZON TEAM UP ON ROAMING LAPTOP DATA CARD
Vodafone Group and Verizon Wireless have jointly developed a new data card
designed to give laptops wireless Internet access in the U.S. as well as in
the 27 other countries where Vodafone operates wireless networks. "This
will allow Verizon Wireless and Vodafone customers to work effectively
whilst traveling in the U.S. and Europe," says Vodafone COO Julian
Horn-Smith. The dual-branded laptop data card will be based on Vodafone's
successful Mobile Connect Card, and will be marketed by Verizon Wireless
under a licensing agreement. (Reuters 1 Aug 2003)
http://story.news.yahoo.com/news?tmpl=story&cid=581&ncid=581&e=1&u=/nm/20030801/tc_nm/telecoms_vodafone_verizon_dc
TAIWANESE SMART PHONE BASED ON WINDOWS
A new smart phone developed by Taiwan'ts Chi Mei Communications Systems and
based on Microsoft software has received regulatory approval by the U.S.
Federal Communications Commission (FCC), which is usually one of the final
stages a product goes through before commercial launch. The Chi Mei smart
phone (developed under the code name "Beethoven") has a clamshell design
and runs the Windows-powered Smartphone operating system, which is also
used in Mitac International's Mio 8380 and High Tech Computer's Qtek 7070.
Current speculation is that the phone will be sold by Motorola. (PC World
31 Jul 2003)
http://www.pcworld.com/news/article/0,aid,111839,00.asp
MALAYSIA TO BAN DIVORCE VIA TEXT MESSAGING
Malaysian men may no longer notify their wives that they're divorcing them
via e-mail or text messaging, according to an Islamic court ruling last
week. The practice had gained in popularity in some Islamic countries in
recent years, with some religious authorities sanctioning it. According to
Islamic law, a husband can divorce his wife simply by declaring his
intention to do so and then repeating that desire before a religious law
judge. (The procedure for wives is much more difficult.) Malaysian Prime
Minister Mahathir Mohamad said that while text messaging is not explicitly
prohibited under Malaysia's current laws, "it is not the way to get
divorced." Abdul Hamid Othman, the government's official religious adviser,
added, "Husbands should not be allowed to freely use SMS (text messaging)
and other easy methods such as e-mails, voicemail or even facsimile to
begin divorce proceedings. We must put a stop to it as it is morally wrong
and unacceptable to society." (AP 31 Jul 2003)
http://apnews.excite.com/article/20030731/D7SKO2FG1.html
*****
FLASH CARD
"To be wholly overlooked, and to know it, are intolerable." (John Adams)
HONORARY SUBSCRIBER: GRACE KELLY
Today's Honorary Subscriber is the American film star Grace Kelly
(1929-1982) who ended her acting career in 1956 to marry Monaco's Prince
Rainier III. The couple had three children -- Princess Caroline, Prince
Albert, and Princess Stephanie. Tragedy struck when Princess Grace died of
injuries sustained in an automobile accident. Grace and her daughter
Stephanie were driving on a winding road at Cap-d'Ail in the Côte d'Azur
region of France when Princess Grace suffered a stroke and lost control of
the car, which plunged down a steep embankment.
Grace Kelly was born into a rich Irish Catholic family in
Philadelphia and attended private schools before enrolling in the American
Academy of Dramatic Art in New York City in 1947. She made her professional
debut in summer stock in July 1949 and her Broadway debut in November 1949.
She also appeared frequently on television.
Kelly's Hollywood career spanned the six years between 1951 and 1956.
She made her screen debut in the 1951 film "Fourteen Hours," followed the
next year by playing Gary Cooper's Quaker wife in "High Noon." In 1953 she
appeared in "Mogambo," and then in 1954 she won an Academy Award for best
actress as Bing Crosby's dowdy wife in "The Country Girl." Struck by what
he called her "sexual elegance," Alfred Hitchcock considered Kelly the
perfect heroine and cast her in his films, "Dial M for Murder" (1954),
"Rear Window" (1954), and "To Catch a Thief" (1955). Her last two films
before her storybook romance and marriage were "The Swan" and "High
Society," both released in1956.
Gradually, as she became involved in Monaco life, Kelly devoted her
time to a variety of charitable works such as helping orphans. This
dedication was acknowledged in 1977 when the Cérès medal was bestowed on
her by the United Nations.
See http://www.amazon.com/exec/obidos/ASIN/B00003CXC7/newsscancom/ref=nosim
for the DVD of "Rear Window" -- or look for it in the multimedia section of
your favorite library. (We donate all revenue from our book recommendations
to adult literacy programs.)
SAFE & SOUND IN THE CYBER AGE
(This week, our security consultants, Chey and Stephen Cobb, write
about "Snake Oil, Crypto, and E-voting"):
The time has come to talk of snake oil, cryptography, and electronic
voting. Chey was already in the process of writing a couple of columns on
cryptography to highlight the work of a very worthy organization know as
the CryptoRights Foundation, which is helping human rights workers around
the world use encryption to communicate securely (see
www.cryptorights.org). And we would have felt obliged to mention that she
is currently working on a new book, "Cryptography for Dummies." But then a
NewsScan reader asked if we would comment on Internet voting, just as
researchers from Johns Hopkins University and Rice University went public
with criticism of electronic voting machines built by Diebold Election Systems.
Obviously, it was time to talk about crypto and voting, but where
does the snake oil fit into this? After all, the term was coined as a
pejorative descriptor for the mysterious elixirs sold by traveling medicine
shows as a cure for everything and anything that ails you (memorialized for
us in the song "Medicine Show" on the 1985 album "This is Big Audio
Dynamite," which features the superb line "If you've got straight trousers,
it'll give you flares").
In the world of computer security, snake oil refers a product that
oversells its security, specifically its use of cryptography, often by
refusing, like the hawker of elixirs, to say exactly what is in it. Now
this might strike you, at first glance, as illogical. After all, if the
purpose of a product is to keep things secret, doesn't it make sense to
keep the workings of the product secret? The correct answer, for a number
of reasons, is no, particularly when the product uses cryptography.
Perhaps the easiest of the reasons to convey goes like this: The role
of encryption is to garble your messages (or words or data) so that only
those who have the password (or keys or permission) can decipher what they
say. Superficially garbled output, like a miracle cure, is very hard to
distinguish from seriously garbled output, or a genuine long-term medical
recovery. Suppose our message is "Beware the Ides of March" and we encrypt
this as FIAEV IXLIM HIWSJ QEVGL. That looks, superficially, a lot like
TYWHU YHQGF ERKSD PMSVJ or even HGSDF WSEDV OPLKM NZACU. But a cryptanalyst
will quickly discern what FIAEV IXLIM HIWSJ QEVGL says because it uses a
simple substitution cipher (the aptly named Caesar Cipher, which simply
shifts the letters of the alphabet a fixed number of places to the right).
The other two examples are harder to break, or they may just be random
characters, which is why you should not trust a security claim that is
backed by nothing more than the vendor saying "Trust Us, We Know What We're
Doing."
Fortunately, genuine cryptography is not sleight of hand or a black
art. In fact, the most powerful encryption algorithms are the ones that
have been published and reviewed. In other words, they are able to encrypt
messages so well that even having the recipe of how they did it does not
help the code-breaker to break the code. For proof of this logic look no
further than the strongest encryption algorithm approved by the federal
government. This is referred to as the Advanced Encryption Standard and it
supercedes the DES or Data Encryption Standard.
The choice of algorithm for AES was announced at the end of 2001
after a rigorous selection process lasting several years and during which
numerous contenders were examined, line by line, by cryptographers from
around the world. In fact, anyone who wanted to test the contenders could
do so, and the winner, known as Rijndael (pronounced Rhine-doll) was
developed by two Belgian cryptographers. Rijndael is not only publicly
available for examination but the algorithm itself is free (implementing it
securely in your encryption software is not).
Which brings us to the use of computers for voting, either in voting
booths or over the Internet. After the debacle of the 2000 presidential
election, many states embraced computerized voting, at no small cost
(here's one example: in July of 2001, Maryland officials signed an
agreement with Diebold's Election Systems unit for about 11,000
touch-screen voting systems valued at up to $55.6 million).
Traditional wisdom in computer security circles is that systems such
as these should be subject to independent scrutiny, preferably before
anyone relies on their results. Why? Two reasons. First, "bad actors" will
definitely be giving them lots of scrutiny and exploiting any holes they
find. Second, if anyone disputes votes cast electronically and the system
is found to have holes, it will be very hard to prove those holes were not
exploited, even if they weren't. Then you're right back at the beginning,
minus many millions of angry taxpayers' dollars.
We will have more on encryption and the right way to go about
implementing electronic voting in the next column.
Note: In the information found below, we use the "name at name dot
name" style of email address in place in order to raise awareness of how
spammers harvest addresses.
[Chey Cobb, CISSP, the author of "Network Security for Dummies," is
an independent consultant (www.cheycobb.com) and a former senior technical
security advisor to the NRO. She can be emailed as "chey at patriot dot
net." Stephen Cobb, CISSP, helped develop SpamSquelcher, the first product
that actually stops spam. He can be emailed as "scobb at eprivacygroup dot
com."]
SUBSCRIPTION INFO FOR NEWSSCAN DAILY:
To subscribe or unsubscribe to the text, html, or handheld versions
of NewsScan Daily, send the appropriate subscribe or unsubscribe messages
(i.e., with the word 'subscribe' or 'unsubscribe' in the subject line) to
the addresses shown below:
Text version: Send message to [email protected]
HTML version: Send mail to [email protected]
NewsScan-To-Go: http://www.newsscan.com/handheld/current.html
TELL YOUR FRIENDS ABOUT NEWSSCAN DAILY! Send them our little frog:
http://www.newsscan.com/newsscan/newscup.html
***********************************************************
Please visit the site of RLG, the great organization that makes NewsScan
Daily possible. (RLG has no influence over, nor any responsibility for, our
editorial content.) Created in 1974 as the Research Libraries Group, RLG is
a not-for-profit membership corporation of more than 160 universities,
national libraries, archives, museums -- and other institutions with
remarkable collections for research and learning. Its major initiatives are
long-term retention of digital materials, resource sharing among member
institutions, and improvement of researcher access to primary source
material. RLG supplies online research resources worldwide. Visit RLG at
http://www.rlg.org.
*********
To subscribe or unsubscribe to the TEXT version of NewsScan Daily, send an
e-mail message to [email protected] with 'subscribe' or 'unsubscribe'
in the subject line. To subscribe to our HTML version of NewsScan Daily,
send mail to [email protected], with the word 'subscribe' as the
subject. (Subscribing to the HTML version won't automatically unsubscribe
you from the text version; please unsubscribe yourself as explained above.)
Please note: To unsubscribe from an account to which you no longer have
access, send mail to at [email protected].
*********
We call our news section "Above The Fold" to honor the tradition of the
great "broadsheet" newspapers in which editors must decide which news
stories are of such importance that they should be placed "above the fold"
on the front page. The NewsScan Credo: Be informative, have fun, and get to
the point! See http://www.newsscan.com/, and send us mail: John Gehl
<[email protected]> and Suzanne Douglas <[email protected]>, or call
770-704-7517.
*********
Get a free 6-week trial subscription to Innovation Weekly, an executive
summary of trends, strategies and innovations in business and technology.
Send mail to [email protected] with the word 'subscribe' in the
subject line.
What customized news and information services do you need for your company?
Get in touch with us at [email protected] or call 770-704-7517 to talk
over the possibilities.
Copyright 2003. NewsScan Daily (R) is a publication of NewsScan Inc.
***********************************************************