CRYPTO-GRAM
January 15, 2012
by Bruce Schneier
Chief Security Technology Officer, BT
[email protected]
http://www.schneier.com
A free monthly newsletter providing summaries, analyses, insights, and
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at
<http://www.schneier.com/crypto-gram-1201.html>. These same essays and
news items appear in the "Schneier on Security" blog at
<http://www.schneier.com/blog>, along with a lively comment section. An
RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
The TSA Proves its Own Irrelevance
Abolishing the Department of Homeland Security
News
"Going Dark" vs. a "Golden Age of Surveillance"
"Chinese Hacking" of iBahn Internet Services
Schneier News
Liars and Outliers News
** *** ***** ******* *********** *************
The TSA Proves its Own Irrelevance
Have you wondered what $1.2 billion in airport security gets you? The
TSA has compiled its own "Top 10 Good Catches of 2011":
10) Snakes, turtles, and birds were found at Miami (MIA) and Los
Angeles (LAX). I'm just happy there weren't any lions, tigers,
and bears...
[...]
3) Over 1,200 firearms were discovered at TSA checkpoints across
the nation in 2011. Many guns are found loaded with rounds in the
chamber. Most passengers simply state they forgot they had a gun in
their bag.
2) A loaded .380 pistol was found strapped to passenger's ankle
with the body scanner at Detroit (DTW). You guessed it, he forgot
it was there...
1) Small chunks of C4 explosives were found in passenger's
checked luggage in Yuma (YUM). Believe it or not, he was bringing it
home to show his family.
That's right; not a single terrorist on the list. Mostly forgetful, and
entirely innocent, people. Note that they fail to point out that the
firearms and knives would have been just as easily caught by pre-9/11
screening procedures. And that the C4 -- their #1 "good catch" -- was on
the return flight; they missed it the first time. So only 1 for 2 on
that one.
And the TSA decided not to mention its stupidest confiscations:
TSA confiscates a butter knife from an airline pilot. TSA
confiscates a teenage girl's purse with an embroidered handgun
design. TSA confiscates a 4-inch plastic rifle from a GI Joe action
doll on the grounds that it's a "replica weapon." TSA confiscates
a liquid-filled baby rattle from airline pilot's infant daughter.
TSA confiscates a plastic "Star Wars" lightsaber from a toddler.
The TSA's Top 10 Good Catches of 2011:
http://blog.tsa.gov/2012/01/tsa-top-10-good-catches-of-2011.html
The TSA missed the C4 the first time.
http://www.oaoa.com/articles/atwater-78425-documents-state.html
TSA stupid confiscations:
http://www.salon.com/2012/01/04/what_do_cupcakes_and_lightsabers_have_in_common/singleton/
or http://tinyurl.com/6n7487d
The Vanity Fair article:
http://www.vanityfair.com/culture/features/2011/12/tsa-insanity-201112
** *** ***** ******* *********** *************
Abolishing the Department of Homeland Security
I have a love/hate relationship with the Cato Institute. Most of their
analysis I strongly disagree with, but some of it I equally strongly
agree with. Last September 11 -- the tenth anniversary of 9/11 -- Cato's
David Rittgers published "Abolish the Department of Homeland Security":
DHS has too many subdivisions in too many disparate fields to
operate effectively. Agencies with responsibilities for
counterfeiting investigations, border security, disaster
preparedness, federal law enforcement training, biological warfare
defense, and computer incident response find themselves under the
same cabinet official. This arrangement has not enhanced the
government's competence. Americans are not safer because the head
of DHS is simultaneously responsible for airport security and
governmental efforts to counter potential flu epidemics.
National defense is a key governmental responsibility, but focusing
too many resources on trying to defend every potential terrorist
target is a recipe for wasteful spending. Our limited resources are
better spent on investigating and arresting aspiring terrorists.
DHS responsibilities for aviation security, domestic surveillance,
and port security have made it too easy for politicians to disguise
pork barrel spending in red, white, and blue. Politicians want to
bring money home to their districts, and as a result, DHS
appropriations too often differ from what ought to be DHS
priorities.
I agree with that. In fact, in 2003, when the country was debating a
single organization that would be responsible for most (not all, since
the Justice Department, the State Department, and the Department of
Defense were too powerful to lose any pieces of themselves) of the
country's counterterrorism efforts, I wrote:
Our nation may actually be less secure if the Department of
Homeland Security eventually takes over the responsibilities of
existing agencies. The last thing we want is for the Department of
Energy, the Department of Commerce, and the Department of State to
say: "Security; that's the responsibility of the DHS."
Security is the responsibility of everyone in government. We won't
defeat terrorism by finding a single thing that works all the time.
We'll defeat terrorism when every little thing works in its own
way, and together provides an immune system for our society. Unless
the DHS distributes security responsibility even as it centralizes
coordination, it won't improve our nation's security.
Back to the Cato report:
The Department of Homeland Security should be abolished and its
components reorganized into more practical groupings. The agencies
tasked with immigration, border security, and customs enforcement
belong under the same oversight agency, which could appropriately
be called the Border Security Administration. The Transportation
Security Administration and Federal Air Marshals Service should be
abolished, and the federal government should end support for fusion
centers. The remaining DHS organizations should return to their
former parent agencies.
Hard to argue with most of that, although abolishing the TSA isn't a
good idea. Airport security should be rolled back to pre-9/11 levels,
but someone is going to have to be in charge of it. Putting the airlines
in charge of it doesn't make sense; their incentives are going to be
passenger service rather than security. Some government agency either
has to hire the screeners and staff the checkpoints, or make and enforce
rules for contractor-staffed checkpoints to follow.
Last November, the U.S. Congressional Republicans published a report
very critical of the TSA: "A Decade Later: A Call for TSA Reform."
This report is an examination and critical analysis of the
development, evolution, and current status and performance of TSA
ten years after its creation. Since its inception, TSA has lost its
focus on transportation security. Instead, it has grown into an
enormous, inflexible and distracted bureaucracy, more concerned
with human resource management and consolidating power, and acting
reactively instead of proactively. As discussed more fully in the
"Recommendations" section on page 18, TSA must realign its
responsibilities as a federal regulator and focus on analyzing
intelligence, setting screening and security standards based on
risk, auditing passenger and baggage screening operations, and
ensuring compliance with national screening standards.
In a related link, there's a response to a petition to abolish the TSA.
The response is by TSA administrator John Pistole, so it's not the most
objective piece of writing on the topic, and doesn't actually respond to
the petition:
Why TSA Exists.
TSA was created two months after the September 11 terrorist
attacks, when Congress passed the Aviation and Transportation
Security Act (ATSA) [.pdf] to keep the millions of Americans who
travel each day safe and secure across numerous modes of
transportation.
Over the past 10 years, TSA has strengthened security by creating
successful programs and deploying technologies that were not in
place prior to September 11, while also taking steps whenever
possible to enhance the passenger experience. Here are just a few
of the many steps TSA has taken to strengthen our multi-layered
approach to security....
[...]
Our Nation is safer and better prepared today because of these and
other efforts of the Department of Homeland Security, TSA, and our
federal, state, local and international partners. TSA is constantly
identifying ways to continue to strengthen security and improve the
passenger experience and appreciates the feedback of the public.
Pistole just assumes that what his organization is doing is important,
and never even mentions how much it costs or whether it's worth it.
The Cato report:
ttp://www.cato.org/pub_display.php?pub_id=13650
My 2003 essay:
http://www.schneier.com/essay-007.html
The Congressional Republican report:
http://republicans.transportation.house.gov/Media/file/112th/Aviation/2011-11-16-TSA_Reform_Report.pdf
or http://tinyurl.com/88cxuzk
The TSA response to the petition:
https://wwws.whitehouse.gov/petitions/!/response/response-we-people-petition-abolishment-transportation-security-administration
or http://tinyurl.com/7mejgz4
** *** ***** ******* *********** *************
News
The EFF's Sovereign Key proposal.
https://www.eff.org/sovereign-keys
When you give out money based on politics, without any accounting, this
is what you get: snow cone machines for homeland security:
http://www.schneier.com/blog/archives/2011/12/snow_cone_machi.html
More on the captured U.S. drone: here's a report that Iran hacked the
drones' GPS systems.
http://www.schneier.com/blog/archives/2011/12/more_on_the_cap.html
Plasmonics anti-counterfeiting technology:
http://www.fastcompany.com/biomimicry/never-before-seen-optical-trick-creates-ultra-secure-cash
or http://tinyurl.com/77vkfdj
Anti-counterfeiting technologies have a difficult set of requirements.
They need to be cheap for legitimate currency printers, and at the same
time expensive for counterfeiters. That this technology can encode
unique serial numbers -- or even digital signatures of unique serial
numbers -- onto paper currency would be a big deal.
How to open a padlock with a soda can.
http://www.itstactical.com/skillcom/lock-picking/how-to-open-a-padlock-with-a-coke-can/
or http://tinyurl.com/bnqz37o
Human ear biometric. I have no idea how good it actually is.
http://www.csee.wvu.edu/~ross/pubs/AbazaEarSymmetry_BTAS2010.pdf
Santa hacked: a mildly amusing video.
http://vimeo.com/33402842
The TSA's cupcake problem, in several parts. Part 1: the TSA confiscates
someone's cupcake -- the frosting is a gel -- prompting widespread ridicule.
http://www.thebostonchannel.com/news/30062442/detail.html
Part 2: the TSA claims the cupcake was in a jar, which makes their
actions less obviously stupid.
http://blog.tsa.gov/2012/01/cupcakegate.html
Part 3: the cupcake lady claims that the TSA is lying.
http://consumerist.com/2012/01/the-tsa-cupcake-lady-speaks-out-im-terribly-sick-of-talking-about-cupcakes.html
The story of how Subway's point-of-sale system was hacked for $3 million.
http://arstechnica.com/business/news/2011/12/how-hackers-gave-subway-a-30-million-lesson-in-point-of-sale-security.ars
or http://tinyurl.com/7q5g42c
Really interesting story of the collar-bomb robbery -- and subsequent
investigation -- from 2003.
http://www.wired.com/magazine/2010/12/ff_collarbomb/all/1
Another new biometric: butt identification based on how you sit.
http://www.physorg.com/news/2011-12-unleash-car-seat-rear.html
Hacking Marconi's wireless in 1903: a great story.
http://www.newscientist.com/article/mg21228440.700-dotdashdiss-the-gentleman
or http://tinyurl.com/d647kt9
There's a service that can be hired to tie up target phone lines
indefinitely. The article talks about how this can be used as a
diversionary tactic to mask a cyberattack, but that seems a bit odd to
me. I'd be more concerned about how this sort of thing could be used to
disrupt the operations of a political candidate on the eve of an election.
https://krebsonsecurity.com/2011/12/busy-signal-service-targets-cyberheist-victims/
or http://tinyurl.com/c3zpq9r
In 1997, I wrote about something called a "chosen-protocol attack,"
where an attacker can use one protocol to break another. Here's an
example of the same thing in the real world: two different parking
garages that mask different digits of credit cards on their receipts.
Find two from the same car, and you can reconstruct the entire number. I
have to admit this puzzles me, because I thought there was a standard
for masking credit card numbers. I only ever see all digits except the
final four masked.
http://blog.zoller.lu/2011/12/pci-compliance-security-in-isolated.html
http://www.schneier.com/paper-chosen-protocol.html
Research paper: Alan A. Kirschenbaum, Michele Mariani, Coen Van Gulijk,
Sharon Lubasz, Carmit Rapaport, and Hinke Andriessen, "Airport Security:
An Ethnographic Study," Journal of Air Transport Management, 18 (January
2012): 68-73 (full article is behind a paywall).
http://www.sciencedirect.com/science/article/pii/S0969699711000974
Another research paper: Behzad Zare Moayedi, Mohammad Abdollahi Azgomi,
"A Game Theoretic Framework for Evaluation of the Impacts of Hackers
Diversity on Security Measures," Reliability Engineering & System
Safety, 99 (2012): 45-54 (full article behind paywall).
http://www.sciencedirect.com/science/article/pii/S0951832011002389
A third research paper: Alan T. Murray and Tony H. Grubesic, "Critical
Infrastructure Protection: The Vulnerability Conundrum," Telematics &
Informatics, 29 (February 2012): 5665 (full article behind paywall).
http://www.sciencedirect.com/science/article/pii/S0736585311000438
The history of coded messages in postage-stamp placement. I wonder how
prevalent this actually was. My guess is that it was more a clever idea
than an actual signaling system. And I notice that a lot of the code
systems don't have a placement that indicates "no message; this is just
a stamp."
http://riowang.blogspot.com/2011/12/language-of-stamps.html
These papers from NSA journals are old, but they have just been released
under FOIA.
http://cryptome.org/0006/nsa-17-docs.htm
The author of this article notices that it's often easy to guess a cell
phone PIN because of smudge marks on the screen. Those smudge marks
indicate the four PIN digits, so an attacker knows that the PIN is one
of 24 possible permutations of those digits. Then he points out that if
your PIN has only three different digits -- 1231, for example -- the PIN
can be one of 36 different possibilities. So it's more security,
although not much more secure.
http://mindyourdecisions.com/blog/2011/01/27/game-theory-and-probability-of-iphone-passwords/
or http://tinyurl.com/4rf78wj
It's time to patch your HP printers. This is a serious vulnerability.
http://www.tomsguide.com/us/Columbia-University-HP-LaserJet-Printer-Exploit,news-13671.html
or http://tinyurl.com/7pvbu6a
http://www.forbes.com/sites/alexknapp/2011/12/26/hp-releases-firmware-update-to-prevent-printer-hacking/
or http://tinyurl.com/d839pnn
http://nakedsecurity.sophos.com/2012/01/05/hp-patches-printer-firmware-flaw/
or http://tinyurl.com/6theedr
http://boingboing.net/2011/12/30/printer-malware-print-a-malic.html
Here's a list of all the printers affected.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03102449&jumpid=em_alerts_us-us_Dec11_xbu_all_all_1514802_101529_printersandmultifunctionscanners-copiers-faxes_critical_000_0
or http://tinyurl.com/7keo3h3
Note that this is the research that was mistakenly reported as allowing
hackers to set your printer on fire.
http://www.schneier.com/blog/archives/2011/12/hacking_printer.html
Hackers stole some source code to Symantec's products. We don't know
what was stolen or how recent the code is -- the company is, of course,
minimizing the story -- but it's hard to get worked up about this. Yes,
maybe the bad guys will comb the code looking for vulnerabilities, and
maybe there's some smoking gun that proves Symantec's involvement in
something sinister, but most likely Symantec's biggest problem is public
embarrassment.
http://pda.physorg.com/news/2012-01-indian-hacker-lords-symantec-antivirus.html
or http://tinyurl.com/7vg698n
http://m.wired.com/threatlevel/2012/01/symantec-source-code-leaked/
http://www.theregister.co.uk/2012/01/06/symantec_source_code_theft/
http://www.theatlanticwire.com/technology/2012/01/what-happens-when-hackers-hack-anti-hacking-software/47090/
or http://tinyurl.com/7rkskjb
http://www.infosecisland.com/blogview/19202-Symantec-Gets-Pwn3d-The-Fallout.html
Political Science professor John Mueller has been collecting predictions
about future terrorist attacks since 9/11, and -- as you'd expect --
most of them are wildly inaccurate. I've never heard this particular
quote before, and find it particularly profound: "In 2004, Russell
Seitz plausibly proposed that '9/11 could join the Trojan Horse and
Pearl Harbor among stratagems so uniquely surprising that their very
success precludes their repetition'...."
http://www.schneier.com/blog/archives/2012/01/collecting_expe.html
The EFF has published a good guide about protecting your digital devices
at international borders.
https://www.eff.org/wp/defending-privacy-us-border-guide-travelers-carrying-digital-devices
or http://tinyurl.com/7gmmewj
My own advice is here.
http://www.schneier.com/blog/archives/2008/05/crossing_border.html
http://www.schneier.com/blog/archives/2009/07/laptop_security.html
Apple has a patent on splitting a key between a portable device and its
power supply.
http://www.patentlyapple.com/patently-apple/2012/01/apple-invents-an-ingenious-security-system-for-the-iwallet-era.html
or http://tinyurl.com/897r6xb
A theory of online jihadist sites.
http://www.foreignpolicy.com/articles/2011/04/13/the_world_of_holy_warcraft?page=full
or http://tinyurl.com/3otlyxc
Long (but well-written and interesting) story of someone whose Gmail
account was hacked and erased, and eventually restored. Many interesting
lessons about the security of largely support-free cloud services.
http://www.theatlantic.com/magazine/archive/2011/11/hacked/8673/1/
** *** ***** ******* *********** *************
"Going Dark" vs. a "Golden Age of Surveillance"
It's a policy debate that's been going on since the crypto wars of the
early 1990s. The FBI, NSA, and other agencies continue to claim they're
losing their ability to engage in surveillance: that it's "going dark."
Whether the cause of the problem is encrypted e-mail, digital
telephony, or Skype, the bad guys use it to communicate, so we need to
pass laws like CALEA to force these services to be made insecure, so
that the government can eavesdrop.
The counter-argument is the "Golden Age of Surveillance" -- that the
massive increase of online data and Internet communications systems
gives the government a far greater ability to eavesdrop on our lives.
They can get your e-mail from Google, regardless of whether you use
encryption. They can install an eavesdropping program on your computer,
regardless of whether you use Skype. They can monitor your Facebook
conversations, and learn thing that just weren't online a decade ago.
Today we all carry devices that tract our locations 24/7: our cell phones.
In this essay, CDT fellows (and law professors) challenge the "going
dark" metaphor and make the case for "the golden age of surveillance."
Yes, wiretapping is harder; but so many other types of surveillance are
easier.
A simple test can help the reader decide between the "going dark"
and "golden age of surveillance" hypotheses. Suppose the agencies
had a choice of a 1990-era package or a 2011-era package. The first
package would include the wiretap authorities as they existed
pre-encryption, but would lack the new techniques for location
tracking, confederate identification, access to multiple databases,
and data mining. The second package would match current
capabilities: some encryption-related obstacles, but increased use
of wiretaps, as well as the capabilities for location tracking,
confederate tracking and data mining. The second package is clearly
superior -- the new surveillance tools assist a vast range of
investigations, whereas wiretaps apply only to a small subset of
key investigations. The new tools are used far more frequently and
provide granular data to assist investigators.
http://www.cdt.org/blogs/2811going-dark-versus-golden-age-surveillance
A longer and more detailed version of the same argument can be found in
"Encryption and Globalization," forthcoming in the Columbia Science
and Technology Law Review.
http://ssrn.com/abstract=1960602
In a related story, there's a relatively new WikiLeaks data dump of
documents related to government surveillance products.
http://wikileaks.org/the-spyfiles.html
http://m.zdnet.com/blog/london/skype-monitoring-gmail-hacks-and-fake-itunes-updates-how-governments-can-track-you/1479
or http://tinyurl.com/7569dcg
http://gadgetmix.com/articles/big-brothers-watching-you/
http://www.cultofmac.com/132782/if-you-thought-carrier-iq-scandal-was-bad-wait-till-you-see-latest-wikileaks/
or http://tinyurl.com/89vzyan
http://www.bugged.com/wikileaks-spy-files-finfly-device-targets-computer-through-apple-itunes-scam/
or http://tinyurl.com/7wwkp2e
** *** ***** ******* *********** *************
"Chinese Hacking" of iBahn Internet Services
Citing unexplained "intelligence data," an unnamed "senior intelligence
official," and an anonymous "privacy security official," Bloomberg News
claims that iBahn -- the company that runs Internet services for a bunch
of hotel chains -- has been hacked by the Chinese. The rest of the story
is pretty obvious: all sorts of private e-mails stolen, corporate
networks hacked via iBahn, China does lot of hacking, and so on. iBahn
has denied the story.
Come on, people. I know that China hacking stories are plausible, but
the bar for actual evidence should be higher than this.
http://www.businessweek.com/news/2011-12-16/china-based-hacking-of-760-companies-shows-cyber-cold-war.html
or http://tinyurl.com/6pubxxx
http://www.networkworld.com/news/2011/121511-ibahn-supplier-of-hotel-internet-254110.html
or http://tinyurl.com/8xyb97c
** *** ***** ******* *********** *************
Schneier News
Charles Mann made me the central focus of his article on airport
security for "Vanity Fair". The article was supposed to have been in
the tenth-anniversary-of-9/11 issue, but got delayed.
http://www.vanityfair.com/culture/features/2011/12/tsa-insanity-201112
Here's a rebuttal to the piece. I agree with the two points at the end
of the post; I just don't think it changes any of my analysis.
http://www.hlswatch.com/2012/01/03/defending-the-tsa/
Mann also wrote about me in 2002 for "The Atlantic."
http://www.theatlantic.com/past/docs/issues/2002/09/mann.htm
In 1997, I spoke at the Beyond HOPE Conference in New York. (HOPE stood
for "Hackers On Planet Earth.) A video of that talk is available online.
http://blip.tv/2600magazine/beyond-hope-1997-cryptography-opportunities-threats-and-implementations-5798822#disqus_thread
or http://tinyurl.com/cnaw5vn
http://blip.tv/file/get/2600magazine-bh07999.m4v
Slides from talk:
https://www.schneier.com/schneier-talk.pdf
In this video, you'll see my first cameo appearance in a
transvestite-themed rock video at the 1:46 mark.
http://www.youtube.com/watch?v=gmPta19GSFU
** *** ***** ******* *********** *************
Liars and Outliers News
The Liars and Outliers webpage is live. On it, you can find links to
order both paper and e-book copies from a variety of online retailers,
and signed copies directly from me. I've also posted the jacket copy,
the table of contents, the first chapter, the 15 figures from the book,
an image of the full wraparound cover, and all the blurbs for the book.
Last month, I chose 10 winners from the 278 people who entered the
drawing for a free galley copy. Those copies have all been mailed, as
have copies to potential book reviewers.
Several readers suggested that I auction some copies, and I did that
last week. Two blog readers won signed galleys, with the proceeds going
to EFF and EPIC.
Book website--you can order signed copies here.
http://schneier.com/lo
** *** ***** ******* *********** *************
Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing
summaries, analyses, insights, and commentaries on security: computer
and otherwise. You can subscribe, unsubscribe, or change your address on
the Web at <http://www.schneier.com/crypto-gram.html>. Back issues are
also available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to
colleagues and friends who will find it valuable. Permission is also
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entirety.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,
Threefish, Helix, Phelix, and Skein algorithms. He is the Chief Security
Technology Officer of BT BCSG, and is on the Board of Directors of the
Electronic Privacy Information Center (EPIC). He is a frequent writer
and lecturer on security topics. See <http://www.schneier.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not
necessarily those of BT.
Copyright (c) 2012 by Bruce Schneier.
** *** ***** ******* *********** *************
To unsubscribe, click this link:
http://listserv.modwest.com/cgi-bin/wa?TICKET=NzM0NTQ2IGFyY2hpdmVATUFJTC1BUkNISVZFLkNPTSBDUllQVE8tR1JBTS1MSVNUIBb1B9q3tYsf&c=SIGNOFF