Re: Keep it secret, stupid!

2003-01-28 Thread geer

>   This is why I have so much disdain for "corporate information
>   security" departments.  They seem so busy plugging the mouse holes
>   in the barn walls, they forget that the door is wide open.

not necessary but so often true, especially when policy
prescribes procedure rather than measurable goal state

here's my own list (in the "eat your own dogfood" sense)

  * can lose laptop and suffer only embarassment
  * can work from any location however hostile
  * in-building network drops vulnerable only to vandalism

obcrypto: all of the above require it...

--dan


-
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]



Re: Keep it secret, stupid!

2003-01-28 Thread Adam Shostack
On Mon, Jan 27, 2003 at 07:42:25PM -0600, Neil Johnson wrote:
| 
| My favorite lock is the electronic lock I saw in a data center. To make  it 
| easier to leave the room, they installed a motion detector near the door to 
| unlock the door when you walked toward the door. That way you didn't need to 
| badge out (why they considered this a bad thing, I don't know).

Probably fire or safety codes, it seems pretty standard.

| Which is all well and good until you notice that there is a 1/2" gap along the 
| bottom of the door.  Take a dowel rod, tape a piece of cardboard to the edge 
| (like a flag), stick it under the door, rotate the dowel a couple of times to 
| trigger the motion sensor, and  ta-da! you are in.

This is also standard.  Best way is paper under the door, and the best
cheap fix I've seen involves weather striping bottom of the door so
you can't get the paper through easily. (the frame needs to be
staggered, so that paper doesn't go through at all, but that would
lead to a risk of tripping people at the floor.)

Adam


-- 
"It is seldom that liberty of any kind is lost all at once."
   -Hume



-
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]



Re: Keep it secret, stupid!

2003-01-28 Thread Neil Johnson

My favorite lock is the electronic lock I saw in a data center. To make  it 
easier to leave the room, they installed a motion detector near the door to 
unlock the door when you walked toward the door. That way you didn't need to 
badge out (why they considered this a bad thing, I don't know).

Which is all well and good until you notice that there is a 1/2" gap along the 
bottom of the door.  Take a dowel rod, tape a piece of cardboard to the edge 
(like a flag), stick it under the door, rotate the dowel a couple of times to 
trigger the motion sensor, and  ta-da! you are in.

Of course during the security audit, the auditors' biggest concern was that 
the data center's walls didn't go all the way to the ceiling, so some one 
could sneak in over the suspended ceilings (There were no private offices or 
closets on adjoining walls of the data center).

My other favorite was a company's policy banning "all company confidential 
information" from being stored on PDA's.  Of course they said nothing about 
all the "company confidential information" being stored in Day-Timer's, 
Filo-Faxes, and other paper based personal organizers. I suggested that they 
require these users to use secret decoder rings or Pig-Latin to secure the 
data and require them to photocopy their organizer's daily (to provide 
backups for "disaster recovery"). 

This is why I have so much disdain for "corporate information security" 
departments.  They seem so busy plugging the mouse holes in the barn walls, 
they forget that the door is wide open.

-- 
Neil Johnson

-
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]



Re: Keep it secret, stupid!

2003-01-27 Thread Matt Blaze
> 
> > The tragic part is that there are alternatives.  There are several
> > lock designs that turn out to resist this threat, including master
> > rings and bicentric locks.  While these designs aren't perfect, they
> 
> I think it is worth pointing out that, while master ring systems (and
> master-keyed systems with false steps added) resist the attack Matt
> describes, they often make the task of picking the lock (on a case by case
> basis) easier.

Actually, master ring systems make it considerably harder to pick
a lock.  Sometimes a pin will set at the master shear line and sometimes
it will set at the change shear line, but unless all pin stacks catch
at the same one, the lock won't operate.  (This phenomenon is also why
it is difficult to pick a SFIC core with conventional torque tools).

Adding false cuts does increase picking vulnerability, of course.

Personally, I think it's a shame that master ring designs have all but
disappeared. They're still listed as an option in the Corbin-Russwin
catalog for a few commercial cylinders, and are also used in some prison
locks as I understand it.

-matt


> 
> That needs to be considered when designing a physical security plan. One
> may wish to key locks of particular importance separately from the master
> ring system if entry by picking is a concern.
> 
> (There are some master-key systems, like the one made by Corbin, that
> require pin rotation at the proper time to unlock the secondary sheer
> line. And, as Matt mentioned, bicentric cylinders avoid this problem
> completely. Cost may be a major concern with these solutions, though.)
> 
> 



-
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]



Re: Keep it secret, stupid!

2003-01-26 Thread Len Sassaman
On Sun, 26 Jan 2003, Matt Blaze wrote:

> The tragic part is that there are alternatives.  There are several
> lock designs that turn out to resist this threat, including master
> rings and bicentric locks.  While these designs aren't perfect, they

I think it is worth pointing out that, while master ring systems (and
master-keyed systems with false steps added) resist the attack Matt
describes, they often make the task of picking the lock (on a case by case
basis) easier.

That needs to be considered when designing a physical security plan. One
may wish to key locks of particular importance separately from the master
ring system if entry by picking is a concern.

(There are some master-key systems, like the one made by Corbin, that
require pin rotation at the proper time to unlock the secondary sheer
line. And, as Matt mentioned, bicentric cylinders avoid this problem
completely. Cost may be a major concern with these solutions, though.)



-
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]



Re: Keep it secret, stupid!

2003-01-26 Thread Bram Cohen
Matt Blaze wrote:

> Once I understood the basics, I quickly discovered, or more accurately
> re-discovered, a simple and practical rights amplification (or
> privilege escalation) attack to which most master-keyed locks are
> vulnerable.
> http://www.crypto.com/masterkey.html

Matt, is there some reason why you didn't bother asking a single locksmith
if they knew about this attack already before claiming it was 'new' in
your paper? Have you looked into the differences in actual costs of
production of the various ways of making locks more secure? Do you have
any information on how common various ways of breaking into locks are done
in practice?

I'm not arguing that security through obscurity is a good thing, just
pointing out that your claims of the importance of your publication are
being made mostly in ignorance.

-Bram Cohen

"Markets can remain irrational longer than you can remain solvent"
-- John Maynard Keynes


-
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]



Re: Keep it secret, stupid!

2003-01-26 Thread Matt Blaze
> Matt Blaze wrote:
> 
> > Once I understood the basics, I quickly discovered, or more accurately
> > re-discovered, a simple and practical rights amplification (or
> > privilege escalation) attack to which most master-keyed locks are
> > vulnerable.
> > http://www.crypto.com/masterkey.html
> 
> Matt, is there some reason why you didn't bother asking a single locksmith
> if they knew about this attack already before claiming it was 'new' in
> your paper? Have you looked into the differences in actual costs of
> production of the various ways of making locks more secure? Do you have
> any information on how common various ways of breaking into locks are done
> in practice?

Of course I did.  What gave you the idea that I didn't?

> 
> I'm not arguing that security through obscurity is a good thing, just
> pointing out that your claims of the importance of your publication are
> being made mostly in ignorance.
> 
> -Bram Cohen
> 
> "Markets can remain irrational longer than you can remain solvent"
> -- John Maynard Keynes
> 



-
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]



Keep it secret, stupid!

2003-01-26 Thread Matt Blaze
Here's a note I sent to PGN and Farber's respective lists that might be
of interest to those here.  I think the issues go well beyond my attack
against locks, reflecting a deep cultural clash that perhaps goes a long
way toward explaining things like the DMCA.

-matt



Keep it secret, stupid!

Last year, I started wondering whether cryptologic approaches might be
useful for the analysis of things that don't use computers.
Mechanical locks seemed like a natural place to start, since they
provided many of the metaphors we used to think about computer
security in the first place.

So I read everything I could get my hands on about locks, which
included most of the available open literature and at least some of
the "closed" literature of that field.  Once I understood the basics,
I quickly discovered, or more accurately re-discovered, a simple and
practical rights amplification (or privilege escalation) attack to
which most master-keyed locks are vulnerable.  The attack uses access
to a single lock and key to get the master key to the entire system,
and is very easy to perform.  For details, see
http://www.crypto.com/masterkey.html

I wrote up the attack, in a paper aimed more at convincing computer
scientists that locks are worth our attention than anything else (I
called it "Rights amplification in master-keyed mechanical locks").
As I pointed out in the paper, surely I could not have been the first
to discover this -- locksmiths, criminals, and college students must
have figured this out long ago.  Indeed, several colleagues mentioned
that my paper reminded them of their college days.  There is
considerable evidence that similar methods for master key decoding
have been discovered and rediscovered over the years, used illicitly
and passed along as folklore (several people have unearthed Internet
postings dating back as much as 15 years describing how to make master
keys).  Curious college students -- and professional burglars -- have
long been able to get their hands on master keys to the places that
interest them.

But the method does not seem to appear in the literature of locks and
security, and certainly users of master keyed locks did not seem to
know about this risk.  I submitted the paper to a journal and
circulated it to colleagues in the security community.  Eventually,
the paper reached the attention of a reporter at the New York Times,
who wrote it up in a story on the front page of the business section
last week.

The response surprised me.  For a few days, my e-mail inbox was full
of angry letters from locksmiths, the majority of which made both the
point that I'm a moron, because everyone knew about this already, as
well as the point that I'm irresponsible, because this method is much
too dangerous to publish.  A few managed to also work in a third
point, which is that the method couldn't possibly work because
obviously I'm just some egghead who doesn't know anything about locks.

Those letters, with their self-canceling inconsistency, are easy
enough to brush aside, but there seems to be a more serious problem
here, one that has led to a significant real-world vulnerability for
lock users but that is sadly all too familiar to contemporary
observers of computer security.

The existence of this method, and the reaction of the locksmithing
profession to it, strikes me as a classic instance of the complete
failure of the "keep vulnerabilities secret" security model.  I'm told
that the industry has known about this vulnerability and chosen to do
nothing -- not even warn their customers -- for over a century.
Instead it was kept secret and passed along as folklore, sometimes
used as a shortcut for recovering lost master keys for paying
customers.  If at some point in the last hundred years this method had
been documented properly, surely the threat could have been addressed
and lock customers allowed to make informed decisions about their own
security.

The tragic part is that there are alternatives.  There are several
lock designs that turn out to resist this threat, including master
rings and bicentric locks.  While these designs aren't perfect, they
resist completely the adaptive oracle attack described in my paper.
It's a pity that stronger alternative designs have been allowed to die
a quiet death in the marketplace while customers, ignorant of the
risks, have spent over a hundred years investing in inferior systems.

Although a few people have confused my reporting of the vulnerability
with causing the vulnerability itself, I can take comfort in a story
that Richard Feynman famously told about his days on the Manhattan
project.  Some simple vulnerabilities (and user interface problems)
made it easy to open most of the safes in use at Los Alamos.  He
eventually demonstrated the problem to the Army officials in charge.
Horrified, they promised to do something about it.  The response?  A
memo