CRYPTO-GRAM
October 15, 2011
by Bruce Schneier
Chief Security Technology Officer, BT
[email protected]
http://www.schneier.com
A free monthly newsletter providing summaries, analyses, insights, and
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at
<http://www.schneier.com/crypto-gram-1110.html>. These same essays and
news items appear in the "Schneier on Security" blog at
<http://www.schneier.com/blog>, along with a lively comment section. An
RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Three Emerging Cyber Threats
Status Report: Liars and Outliers
News
Official Malware from the German Police
Domain-in-the-Middle Attacks
Schneier News
Insider Attack Against Diebold Voting Machines
National Cybersecurity Awareness Month
** *** ***** ******* *********** *************
Three Emerging Cyber Threats
Last month, I participated in a panel at the Information Systems Forum
in Berlin. The moderator asked us what the top three emerging threats
were in cyberspace. I went last, and decided to focus on the top three
threats that are not criminal:
* The Rise of Big Data. By this I mean industries that trade on our
data. These include traditional credit bureaus and data brokers, but
also data-collection companies like Facebook and Google. They're
collecting more and more data about everyone, often without their
knowledge and explicit consent, and selling it far and wide: to both
other corporate users and to government. Big data is becoming a
powerful industry, resisting any calls to regulate its behavior.
* Ill-Conceived Regulations from Law Enforcement. We're seeing
increasing calls to regulate cyberspace in the mistaken belief that this
will fight crime. I'm thinking about data retention laws, Internet kill
switches, and calls to eliminate anonymity. None of these will work,
and they'll all make us less safe.
* The Cyberwar Arms Race. I'm not worried about cyberwar, but I am
worried about the proliferation of cyber weapons. Arms races are
fundamentally destabilizing, especially when their development can be so
easily hidden. I worry about cyberweapons being triggered by accident,
cyberweapons getting into the wrong hands and being triggered on
purpose, and the inability to reliably trace a cyberweapon leading to
increased distrust. Plus, arms races are expensive.
That's my list, and they all have the potential to be more dangerous
than cybercriminals.
Big data:
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1926431
Internet kill switches:
http://www.schneier.com/essay-224.html
Calls to eliminate anonymity:
http://www.schneier.com/blog/archives/2010/02/anonymity_and_t_3.html
Cyberwar:
http://www.schneier.com/blog/archives/2010/12/cyberwar_and_th.html
** *** ***** ******* *********** *************
Status Report: Liars and Outliers
At the beginning of the month, I completely reframed the book. I
realized that the book isn't about security. It's about trust. I'm
writing about how society induces people to behave in the group interest
instead of some competing personal interest. It's obvious that society
needs to do this; otherwise, it can never solve collective action
problems. And as a social species, we have developed both moral systems
and reputational systems that encourage people behave in the group
interest. I called these systems "societal security," along with more
recent developments: institutional (read "legal") systems and
technological systems.
That phrasing strained the definition of "security." Everything, from
the Bible to your friends treating you better if you were nice to them,
was a security system. In my reframing, those are all trust pressures.
It's a language that's more intuitive. We already know about moral
pressure, peer pressure, and legal pressure. Reputational pressure,
institutional pressure, and security pressure is much less of a stretch.
And it puts security back in a more sensible place. Security is a
mechanism; trust is the goal.
This reframing lets me more easily talk directly about the central
issues of the book: how these various pressures scale to larger
societies, and how security technologies are necessary for them to
scale. Trust changes focus as society scales, too. In smaller
societies (a family, for example), trust is more about intention and
less about actions. In larger societies, trust is all about actions.
It's more like compliance. And as things scale even further, trust
becomes less about people and more about systems. I don't need to trust
any particular banker, as long as I trust the banking system. And as we
scale up, security becomes more important.
Possibly the book's thesis statement: "Security is a set of constructed
systems that extend the naturally occurring systems that humans have
always used to induce trust and enable society. This extension became
necessary when society began to operate at a scale and complexity where
the naturally occurring mechanisms started to break down, and is more
necessary as society continues to grow in scale."
So the phrase "societal security" is completely gone from the book.
(Like the phrase "dishonest minority," it only exists in old blog
posts.) There's more talk about the role of trust in society. There's
more talk about how security, real security this time, enables trust.
It felt like a major change when I embarked on it, but the fact that I
did it in three days says how this framing was always there under the
surface. And the fact that the book reads a lot more cleanly now says
this framing is the right one.
The title remains the same: "Liars and Outliers." The cover remains the
same. The table of contents is the same, although some chapters have
different names. The subtitle has changed to "How Security Enables the
Trust that Holds Society Together."
The manuscript is still due to the publisher at the end of the month,
and publication is still set for mid-February. I am enjoying writing
it, but I am also looking forward to it being done.
Previous status reports:
http://www.schneier.com/blog/archives/2011/02/societal_securi.html
http://www.schneier.com/blog/archives/2011/05/status_report_t.html
http://www.schneier.com/blog/archives/2011/08/liars_and_outli.html
http://www.schneier.com/blog/archives/2011/09/a_status_report.html
** *** ***** ******* *********** *************
News
I've already written how it is possible to detect words and phrases in
encrypted VoIP calls. Turns out it's possible to detect speakers as well.
http://www.ncfta.ca/papers/voip.pdf
The effectiveness of plagiarism detection software. As you'd expect,
it's not very good.
http://davideharrington.com/?p=594
Luis "Guicho" Mijangos, "sextortionist." It's a pretty creepy story of
cyber-stalking.
http://www.wired.com/threatlevel/2011/09/sextortionist/
The interesting thing about this electronic banking fraud from Malaysia
is how it abuses a variety of different security systems. The criminals
use a fake ID card to get a new cell phone SIM, which they then use to
authenticate a fraudulent bank transfer made with stolen credentials.
http://www.thesundaily.my/news/143839
Interesting story of shifting risk. By raising the driving age,
California just moved automobile deaths to a different age group.
http://www.latimes.com/health/la-he-teen-driver-laws-20110914,0,7056006.story
or http://tinyurl.com/5wt2fea
The long-standing U.S.-Australia ANZUS military treaty now includes
cyberspace attacks:
http://www.theregister.co.uk/2011/09/15/cyber_crime_anzus/
An interesting software liability proposal.
http://queue.acm.org/detail.cfm?id=2030258
Man-in-the-middle attack against SSL 3.0/TLS 1.0. It's the Browser
Exploit Against SSL/TLS Tool, or BEAST.
http://arstechnica.com/business/news/2011/09/new-javascript-hacking-tool-can-intercept-paypal-other-secure-sessions.ars
or http://tinyurl.com/3f3m853
http://threatpost.com/en_us/blogs/new-attack-breaks-confidentiality-model-ssl-allows-theft-encrypted-cookies-091911?utm_source=SecurityWeek
or http://tinyurl.com/436lldn
http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/
http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html
or http://tinyurl.com/3fjbq7a
Iran blocks Tor, and Tor releases a workaround on the same day.
https://blog.torproject.org/blog/iran-blocks-tor-tor-releases-same-day-fix
or http://tinyurl.com/5rc7phu
Problems with Mac OS X Lion passwords. Seems like some dumb mistakes.
http://www.defenceindepth.net/2011/09/cracking-os-x-lion-passwords.html
or http://tinyurl.com/5w3lf96
http://www.theregister.co.uk/2011/09/19/apple_password_security_exposed/
or http://tinyurl.com/6bsawem
Faking ATM fronts using 3D printers. One group stole $400K.
http://krebsonsecurity.com/2011/09/gang-used-3d-printers-for-atm-skimmers/
or http://tinyurl.com/6y7vpg5
An analysis of extensions to the Chrome browser shows that 25% of them
are insecure.
http://www.adrienneporterfelt.com/blog/?p=226
Custom HTC Android firmware breaks standard permissions and allows rogue
apps to access location, address book, and account info without
authorization.
http://www.androidpolice.com/2011/10/01/massive-security-vulnerability-in-htc-android-devices-evo-3d-4g-thunderbolt-others-exposes-phone-numbers-gps-sms-emails-addresses-much-more/
or http://tinyurl.com/68z8lse
Isaac Asimov on security theater:
http://www.schneier.com/blog/archives/2011/10/isaac_asimov_on.html
Nice cartoon on the problems of content filtering.
http://onefte.com/2011/10/01/we-are-not-bad-people-2/
FBI-sponsored backdoors.
http://www.schneier.com/blog/archives/2011/10/fbi-sponsored_b.html
Dilbert on security standards.
http://dilbert.com/fast/2011-08-02/
The previous day's cartoon:
http://dilbert.com/fast/2011-08-01/
XKCD makes the same point:
http://xkcd.com/927/
Security seals on voting machines.
http://www.cs.princeton.edu/~appel/voting/SealsOnVotingMachines.pdf
http://dl.acm.org/citation.cfm?id=2019603&dl=ACM&coll=DL&CFID=46593735&CFTOKEN=91913758
or http://tinyurl.com/3ftg8fy
U.S. drones have a computer virus. You'd think we would be more careful
than this.
http://www.wired.com/dangerroom/2011/10/virus-hits-drone-fleet/
http://arstechnica.com/business/news/2011/10/exclusive-computer-virus-hits-drone-fleet.ars
or http://tinyurl.com/6gcso9o
http://www.reuters.com/article/2011/10/07/us-usa-drones-idUSTRE7966FQ20111007
or http://tinyurl.com/6bakf3m
No one bothered to tell the Air Force's IT department for two weeks:
http://arstechnica.com/tech-policy/news/2011/10/get-hacked-dont-tell-drone-base-didnt-report-virus.ars
or http://tinyurl.com/6fp9pep
New attacks on CAPTCHAs.
http://homepages.cs.ncl.ac.uk/jeff.yan/google.pdf
Weird World War II security puzzle.
http://www.schneier.com/blog/archives/2011/10/weird_world_war.html
Two California burglars tip off the police after they find child porn on
CDs they stole from someone's house.
http://www.cnn.com/2011/10/06/us/california-robbery-porn-bust/index.html
or http://tinyurl.com/3sph8gm
** *** ***** ******* *********** *************
Official Malware from the German Police
The Chaos Computer Club has disassembled and analyzed the Trojan used by
the German police for legal intercept. In its default mode, it takes
regular screenshots of the active window and sends it to the police. It
encrypts data in AES Electronic Codebook mode with -- are you ready? --
a fixed key across all versions. There's no authentication built in, so
it's easy to spoof. It sends data to a command-and-control server in
the U.S., which is almost certainly against German law. There's code to
allow the controller to install additional software onto the target
machine, but that's not authenticated either, so it would be easy to
fool the Trojan into installing anything.
F-Secure has announced it will treat the Trojan as malware. I hope all
the other anti-virus companies will do the same.
EDITED TO ADD (10/12): Another story. And some good information on the
malware. Germany's Justice Minister is calling for an investigation.
http://www.ccc.de/en/updates/2011/staatstrojaner
http://www.ccc.de/system/uploads/76/original/staatstrojaner-report23.pdf
or http://tinyurl.com/3t5g2lb
F-Secure:
http://www.f-secure.com/weblog/archives/00002249.html
http://www.f-secure.com/weblog/archives/00002250.html
Analyses:
http://nakedsecurity.sophos.com/2011/10/09/government-backdoor-trojan-chaos/
or http://tinyurl.com/6gg3wb3
http://nakedsecurity.sophos.com/2011/10/10/german-government-r2d2-trojan-faq/
or http://tinyurl.com/65gtnhn
Calls for an investigation:
http://www.bbc.co.uk/go/em/fr/-/news/world-europe-15253259
** *** ***** ******* *********** *************
Domain-in-the-Middle Attacks
It's an easy attack. Register a domain that's like your target except
for a typo. So it would be countrpane.com instead of counterpane.com,
or mailcounterpane.com instead of mail.counterpane.com. Then, when
someone mistypes an e-mail address to someone at that company and you
receive it, just forward it on as if nothing happened. These are called
"doppelganger domains," and they're already being used to spy on companies.
Defenses are few. I suppose you can buy up the most common typos, but
there will always be ones you didn't think about -- especially if you
use a lot of subdomains.
http://www.wired.com/threatlevel/2011/09/doppelganger-domains/
** *** ***** ******* *********** *************
Schneier News
I will be speaking at the Hacker Halted conference on October 25 in Miami.
http://www.hackerhalted.com/2011/
I will be speaking at the Pennsylvania I.T. and Security Conference in
King of Prussia, PA, on November 2.
http://www.pasecurityconference.com/2011/index.shtml
I will be speaking at the AISA National Conference on November 9 in Sydney.
http://www.aisa.org.au/national-conference/
I will be speaking at the American Society of Consultant Pharmacists
Technology Summit on November 15, in Phoenix.
http://www.ascpannual.com/technology-summit
** *** ***** ******* *********** *************
Insider Attack Against Diebold Voting Machines
This is both news and not news:
Indeed, the Argonne team's attack required no modification,
reprogramming, or even knowledge, of the voting machine's
proprietary source code. It was carried out by inserting a piece
of inexpensive "alien electronics" into the machine.
It's not news because we already know that if you have access to the
internals of a voting machine, you can make it do whatever you want.
It is news because it's so easy. The entire hack took two hours, start
to finish. The attacker doesn't have to know how the machine works, he
just needs physical access. (And we know that voting machines are
routinely left unguarded, and have locks that are easily bypassed.)
I find this all so frustrating because there are a gazillion ways to
hack electronic voting machines. Specific attacks get the headlines,
and the voting machine companies counter with reasons why those attacks
are not "valid." And in the noise and counter-noise, no one hears the
general truth: these systems are insecure, and should not be used in
elections.
http://politics.salon.com/2011/09/27/votinghack/
Unguarded voting machines:
https://freedom-to-tinker.com/blog/felten/election-day-more-unguarded-voting-machines
or http://tinyurl.com/449l7xq
Easily bypassed voting-machine locks:
https://freedom-to-tinker.com/blog/felten/hotel-minibar-keys-open-diebold-voting-machines
or http://tinyurl.com/3pc5uza
** *** ***** ******* *********** *************
National Cybersecurity Awareness Month
October is National Cybersecurity Awareness Month, sponsored by the
Department of Homeland Security. The website has some sample things you
can do to celebrate, but they're all pretty boring. Surely we can do
better. Post your suggestions in the comments section of the blog post.
Blog entry URL:
http://www.schneier.com/blog/archives/2011/10/national_cybers.html
National Cybersecurity Awareness Month:
http://www.dhs.gov/files/programs/gc_1158611596104.shtm
** *** ***** ******* *********** *************
Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing
summaries, analyses, insights, and commentaries on security: computer
and otherwise. You can subscribe, unsubscribe, or change your address
on the Web at <http://www.schneier.com/crypto-gram.html>. Back issues
are also available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to
colleagues and friends who will find it valuable. Permission is also
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entirety.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,
Threefish, Helix, Phelix, and Skein algorithms. He is the Chief
Security Technology Officer of BT BCSG, and is on the Board of Directors
of the Electronic Privacy Information Center (EPIC). He is a frequent
writer and lecturer on security topics. See <http://www.schneier.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not
necessarily those of BT.
Copyright (c) 2011 by Bruce Schneier.
** *** ***** ******* *********** *************
To unsubscribe, click this link:
http://listserv.modwest.com/cgi-bin/wa?TICKET=NzM0NDU0IGFyY2hpdmVATUFJTC1BUkNISVZFLkNPTSBDUllQVE8tR1JBTS1MSVNUIOs1dt0LNdYz&c=SIGNOFF