CRYPTO-GRAM

               January 15, 2012

              by Bruce Schneier
      Chief Security Technology Officer, BT
             [email protected]
            http://www.schneier.com


A free monthly newsletter providing summaries, analyses, insights, and commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit <http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at <http://www.schneier.com/crypto-gram-1201.html>. These same essays and news items appear in the "Schneier on Security" blog at <http://www.schneier.com/blog>, along with a lively comment section. An RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
     The TSA Proves its Own Irrelevance
     Abolishing the Department of Homeland Security
     News
     "Going Dark" vs. a "Golden Age of Surveillance"
     "Chinese Hacking" of iBahn Internet Services
     Schneier News
     Liars and Outliers News


** *** ***** ******* *********** *************

     The TSA Proves its Own Irrelevance



Have you wondered what $1.2 billion in airport security gets you? The TSA has compiled its own "Top 10 Good Catches of 2011":

    10) Snakes, turtles, and birds were found at Miami (MIA) and Los
    Angeles (LAX). I'm just happy there weren't any lions, tigers,
    and bears...

    [...]

    3) Over 1,200 firearms were discovered at TSA checkpoints across
    the nation in 2011. Many guns are found loaded with rounds in the
    chamber. Most passengers simply state they forgot they had a gun in
    their bag.

    2) A loaded .380 pistol was found strapped to passenger's ankle
    with the body scanner at Detroit (DTW). You guessed it, he forgot
    it was there...

    1) Small chunks of C4 explosives were found in passenger's
    checked luggage in Yuma (YUM). Believe it or not, he was bringing it
    home to show his family.

That's right; not a single terrorist on the list. Mostly forgetful, and entirely innocent, people. Note that they fail to point out that the firearms and knives would have been just as easily caught by pre-9/11 screening procedures. And that the C4 -- their #1 "good catch" -- was on the return flight; they missed it the first time. So only 1 for 2 on that one.

And the TSA decided not to mention its stupidest confiscations:

    TSA confiscates a butter knife from an airline pilot. TSA
    confiscates a teenage girl's purse with an embroidered handgun
    design. TSA confiscates a 4-inch plastic rifle from a GI Joe action
    doll on the grounds that it's a "replica weapon." TSA confiscates
    a liquid-filled baby rattle from airline pilot's infant daughter.
    TSA confiscates a plastic "Star Wars" lightsaber from a toddler.


The TSA's Top 10 Good Catches of 2011:
http://blog.tsa.gov/2012/01/tsa-top-10-good-catches-of-2011.html

The TSA missed the C4 the first time.
http://www.oaoa.com/articles/atwater-78425-documents-state.html

TSA stupid confiscations:
http://www.salon.com/2012/01/04/what_do_cupcakes_and_lightsabers_have_in_common/singleton/ or http://tinyurl.com/6n7487d

The Vanity Fair article:
http://www.vanityfair.com/culture/features/2011/12/tsa-insanity-201112


** *** ***** ******* *********** *************

     Abolishing the Department of Homeland Security



I have a love/hate relationship with the Cato Institute. Most of their analysis I strongly disagree with, but some of it I equally strongly agree with. Last September 11 -- the tenth anniversary of 9/11 -- Cato's David Rittgers published "Abolish the Department of Homeland Security":

    DHS has too many subdivisions in too many disparate fields to
    operate effectively. Agencies with responsibilities for
    counterfeiting investigations, border security, disaster
    preparedness, federal law enforcement training, biological warfare
    defense, and computer incident response find themselves under the
    same cabinet official. This arrangement has not enhanced the
    government's competence. Americans are not safer because the head
    of DHS is simultaneously responsible for airport security and
    governmental efforts to counter potential flu epidemics.

    National defense is a key governmental responsibility, but focusing
    too many resources on trying to defend every potential terrorist
    target is a recipe for wasteful spending. Our limited resources are
    better spent on investigating and arresting aspiring terrorists.
    DHS responsibilities for aviation security, domestic surveillance,
    and port security have made it too easy for politicians to disguise
    pork barrel spending in red, white, and blue. Politicians want to
    bring money home to their districts, and as a result, DHS
    appropriations too often differ from what ought to be DHS
    priorities.

I agree with that. In fact, in 2003, when the country was debating a single organization that would be responsible for most (not all, since the Justice Department, the State Department, and the Department of Defense were too powerful to lose any pieces of themselves) of the country's counterterrorism efforts, I wrote:

    Our nation may actually be less secure if the Department of
    Homeland Security eventually takes over the responsibilities of
    existing agencies. The last thing we want is for the Department of
    Energy, the Department of Commerce, and the Department of State to
    say: "Security; that's the responsibility of the DHS."

    Security is the responsibility of everyone in government. We won't
    defeat terrorism by finding a single thing that works all the time.
    We'll defeat terrorism when every little thing works in its own
    way, and together provides an immune system for our society. Unless
    the DHS distributes security responsibility even as it centralizes
    coordination, it won't improve our nation's security.

Back to the Cato report:

    The Department of Homeland Security should be abolished and its
    components reorganized into more practical groupings. The agencies
    tasked with immigration, border security, and customs enforcement
    belong under the same oversight agency, which could appropriately
    be called the Border Security Administration. The Transportation
    Security Administration and Federal Air Marshals Service should be
    abolished, and the federal government should end support for fusion
    centers. The remaining DHS organizations should return to their
    former parent agencies.

Hard to argue with most of that, although abolishing the TSA isn't a good idea. Airport security should be rolled back to pre-9/11 levels, but someone is going to have to be in charge of it. Putting the airlines in charge of it doesn't make sense; their incentives are going to be passenger service rather than security. Some government agency either has to hire the screeners and staff the checkpoints, or make and enforce rules for contractor-staffed checkpoints to follow.

Last November, the U.S. Congressional Republicans published a report very critical of the TSA: "A Decade Later: A Call for TSA Reform."

    This report is an examination and critical analysis of the
    development, evolution, and current status and performance of TSA
    ten years after its creation. Since its inception, TSA has lost its
    focus on transportation security. Instead, it has grown into an
    enormous, inflexible and distracted bureaucracy, more concerned
    with human resource management and consolidating power, and acting
    reactively instead of proactively. As discussed more fully in the
    "Recommendations" section on page 18, TSA must realign its
    responsibilities as a federal regulator and focus on analyzing
    intelligence, setting screening and security standards based on
    risk, auditing passenger and baggage screening operations, and
    ensuring compliance with national screening standards.

In a related link, there's a response to a petition to abolish the TSA. The response is by TSA administrator John Pistole, so it's not the most objective piece of writing on the topic, and doesn't actually respond to the petition:

    Why TSA Exists.

    TSA was created two months after the September 11 terrorist
    attacks, when Congress passed the Aviation and Transportation
    Security Act (ATSA) [.pdf] to keep the millions of Americans who
    travel each day safe and secure across numerous modes of
    transportation.

    Over the past 10 years, TSA has strengthened security by creating
    successful programs and deploying technologies that were not in
    place prior to September 11, while also taking steps whenever
    possible to enhance the passenger experience. Here are just a few
    of the many steps TSA has taken to strengthen our multi-layered
    approach to security....

    [...]

    Our Nation is safer and better prepared today because of these and
    other efforts of the Department of Homeland Security, TSA, and our
    federal, state, local and international partners. TSA is constantly
    identifying ways to continue to strengthen security and improve the
    passenger experience and appreciates the feedback of the public.

Pistole just assumes that what his organization is doing is important, and never even mentions how much it costs or whether it's worth it.


The Cato report:
ttp://www.cato.org/pub_display.php?pub_id=13650

My 2003 essay:
http://www.schneier.com/essay-007.html

The Congressional Republican report:
http://republicans.transportation.house.gov/Media/file/112th/Aviation/2011-11-16-TSA_Reform_Report.pdf or http://tinyurl.com/88cxuzk

The TSA response to the petition:
https://wwws.whitehouse.gov/petitions/!/response/response-we-people-petition-abolishment-transportation-security-administration or http://tinyurl.com/7mejgz4


** *** ***** ******* *********** *************

     News



The EFF's Sovereign Key proposal.
https://www.eff.org/sovereign-keys

When you give out money based on politics, without any accounting, this is what you get: snow cone machines for homeland security:
http://www.schneier.com/blog/archives/2011/12/snow_cone_machi.html

More on the captured U.S. drone: here's a report that Iran hacked the drones' GPS systems.
http://www.schneier.com/blog/archives/2011/12/more_on_the_cap.html

Plasmonics anti-counterfeiting technology:
http://www.fastcompany.com/biomimicry/never-before-seen-optical-trick-creates-ultra-secure-cash or http://tinyurl.com/77vkfdj Anti-counterfeiting technologies have a difficult set of requirements. They need to be cheap for legitimate currency printers, and at the same time expensive for counterfeiters. That this technology can encode unique serial numbers -- or even digital signatures of unique serial numbers -- onto paper currency would be a big deal.

How to open a padlock with a soda can.
http://www.itstactical.com/skillcom/lock-picking/how-to-open-a-padlock-with-a-coke-can/ or http://tinyurl.com/bnqz37o

Human ear biometric. I have no idea how good it actually is.
http://www.csee.wvu.edu/~ross/pubs/AbazaEarSymmetry_BTAS2010.pdf

Santa hacked: a mildly amusing video.
http://vimeo.com/33402842

The TSA's cupcake problem, in several parts. Part 1: the TSA confiscates someone's cupcake -- the frosting is a gel -- prompting widespread ridicule.
http://www.thebostonchannel.com/news/30062442/detail.html
Part 2: the TSA claims the cupcake was in a jar, which makes their actions less obviously stupid.
http://blog.tsa.gov/2012/01/cupcakegate.html
Part 3: the cupcake lady claims that the TSA is lying.
http://consumerist.com/2012/01/the-tsa-cupcake-lady-speaks-out-im-terribly-sick-of-talking-about-cupcakes.html

The story of how Subway's point-of-sale system was hacked for $3 million.
http://arstechnica.com/business/news/2011/12/how-hackers-gave-subway-a-30-million-lesson-in-point-of-sale-security.ars or http://tinyurl.com/7q5g42c

Really interesting story of the collar-bomb robbery -- and subsequent investigation -- from 2003.
http://www.wired.com/magazine/2010/12/ff_collarbomb/all/1

Another new biometric: butt identification based on how you sit.
http://www.physorg.com/news/2011-12-unleash-car-seat-rear.html

Hacking Marconi's wireless in 1903: a great story.
http://www.newscientist.com/article/mg21228440.700-dotdashdiss-the-gentleman or http://tinyurl.com/d647kt9

There's a service that can be hired to tie up target phone lines indefinitely. The article talks about how this can be used as a diversionary tactic to mask a cyberattack, but that seems a bit odd to me. I'd be more concerned about how this sort of thing could be used to disrupt the operations of a political candidate on the eve of an election. https://krebsonsecurity.com/2011/12/busy-signal-service-targets-cyberheist-victims/ or http://tinyurl.com/c3zpq9r

In 1997, I wrote about something called a "chosen-protocol attack," where an attacker can use one protocol to break another. Here's an example of the same thing in the real world: two different parking garages that mask different digits of credit cards on their receipts. Find two from the same car, and you can reconstruct the entire number. I have to admit this puzzles me, because I thought there was a standard for masking credit card numbers. I only ever see all digits except the final four masked.
http://blog.zoller.lu/2011/12/pci-compliance-security-in-isolated.html
http://www.schneier.com/paper-chosen-protocol.html

Research paper: Alan A. Kirschenbaum, Michele Mariani, Coen Van Gulijk, Sharon Lubasz, Carmit Rapaport, and Hinke Andriessen, "Airport Security: An Ethnographic Study," Journal of Air Transport Management, 18 (January 2012): 68-73 (full article is behind a paywall).
http://www.sciencedirect.com/science/article/pii/S0969699711000974

Another research paper: Behzad Zare Moayedi, Mohammad Abdollahi Azgomi, "A Game Theoretic Framework for Evaluation of the Impacts of Hackers Diversity on Security Measures," Reliability Engineering & System Safety, 99 (2012): 45-54 (full article behind paywall).
http://www.sciencedirect.com/science/article/pii/S0951832011002389

A third research paper: Alan T. Murray and Tony H. Grubesic, "Critical Infrastructure Protection: The Vulnerability Conundrum," Telematics & Informatics, 29 (February 2012): 56­65 (full article behind paywall).
http://www.sciencedirect.com/science/article/pii/S0736585311000438

The history of coded messages in postage-stamp placement. I wonder how prevalent this actually was. My guess is that it was more a clever idea than an actual signaling system. And I notice that a lot of the code systems don't have a placement that indicates "no message; this is just a stamp."
http://riowang.blogspot.com/2011/12/language-of-stamps.html

These papers from NSA journals are old, but they have just been released under FOIA.
http://cryptome.org/0006/nsa-17-docs.htm

The author of this article notices that it's often easy to guess a cell phone PIN because of smudge marks on the screen. Those smudge marks indicate the four PIN digits, so an attacker knows that the PIN is one of 24 possible permutations of those digits. Then he points out that if your PIN has only three different digits -- 1231, for example -- the PIN can be one of 36 different possibilities. So it's more security, although not much more secure. http://mindyourdecisions.com/blog/2011/01/27/game-theory-and-probability-of-iphone-passwords/ or http://tinyurl.com/4rf78wj

It's time to patch your HP printers. This is a serious vulnerability.
http://www.tomsguide.com/us/Columbia-University-HP-LaserJet-Printer-Exploit,news-13671.html or http://tinyurl.com/7pvbu6a http://www.forbes.com/sites/alexknapp/2011/12/26/hp-releases-firmware-update-to-prevent-printer-hacking/ or http://tinyurl.com/d839pnn http://nakedsecurity.sophos.com/2012/01/05/hp-patches-printer-firmware-flaw/ or http://tinyurl.com/6theedr
http://boingboing.net/2011/12/30/printer-malware-print-a-malic.html
Here's a list of all the printers affected.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03102449&jumpid=em_alerts_us-us_Dec11_xbu_all_all_1514802_101529_printersandmultifunctionscanners-copiers-faxes_critical_000_0 or http://tinyurl.com/7keo3h3 Note that this is the research that was mistakenly reported as allowing hackers to set your printer on fire.
http://www.schneier.com/blog/archives/2011/12/hacking_printer.html

Hackers stole some source code to Symantec's products. We don't know what was stolen or how recent the code is -- the company is, of course, minimizing the story -- but it's hard to get worked up about this. Yes, maybe the bad guys will comb the code looking for vulnerabilities, and maybe there's some smoking gun that proves Symantec's involvement in something sinister, but most likely Symantec's biggest problem is public embarrassment. http://pda.physorg.com/news/2012-01-indian-hacker-lords-symantec-antivirus.html or http://tinyurl.com/7vg698n
http://m.wired.com/threatlevel/2012/01/symantec-source-code-leaked/
http://www.theregister.co.uk/2012/01/06/symantec_source_code_theft/
http://www.theatlanticwire.com/technology/2012/01/what-happens-when-hackers-hack-anti-hacking-software/47090/ or http://tinyurl.com/7rkskjb
http://www.infosecisland.com/blogview/19202-Symantec-Gets-Pwn3d-The-Fallout.html

Political Science professor John Mueller has been collecting predictions about future terrorist attacks since 9/11, and -- as you'd expect -- most of them are wildly inaccurate. I've never heard this particular quote before, and find it particularly profound: "In 2004, Russell Seitz plausibly proposed that '9/11 could join the Trojan Horse and Pearl Harbor among stratagems so uniquely surprising that their very success precludes their repetition'...."
http://www.schneier.com/blog/archives/2012/01/collecting_expe.html

The EFF has published a good guide about protecting your digital devices at international borders. https://www.eff.org/wp/defending-privacy-us-border-guide-travelers-carrying-digital-devices or http://tinyurl.com/7gmmewj
My own advice is here.
http://www.schneier.com/blog/archives/2008/05/crossing_border.html
http://www.schneier.com/blog/archives/2009/07/laptop_security.html

Apple has a patent on splitting a key between a portable device and its power supply. http://www.patentlyapple.com/patently-apple/2012/01/apple-invents-an-ingenious-security-system-for-the-iwallet-era.html or http://tinyurl.com/897r6xb

A theory of online jihadist sites.
http://www.foreignpolicy.com/articles/2011/04/13/the_world_of_holy_warcraft?page=full or http://tinyurl.com/3otlyxc

Long (but well-written and interesting) story of someone whose Gmail account was hacked and erased, and eventually restored. Many interesting lessons about the security of largely support-free cloud services.
http://www.theatlantic.com/magazine/archive/2011/11/hacked/8673/1/


** *** ***** ******* *********** *************

     "Going Dark" vs. a "Golden Age of Surveillance"



It's a policy debate that's been going on since the crypto wars of the early 1990s. The FBI, NSA, and other agencies continue to claim they're losing their ability to engage in surveillance: that it's "going dark." Whether the cause of the problem is encrypted e-mail, digital telephony, or Skype, the bad guys use it to communicate, so we need to pass laws like CALEA to force these services to be made insecure, so that the government can eavesdrop.

The counter-argument is the "Golden Age of Surveillance" -- that the massive increase of online data and Internet communications systems gives the government a far greater ability to eavesdrop on our lives. They can get your e-mail from Google, regardless of whether you use encryption. They can install an eavesdropping program on your computer, regardless of whether you use Skype. They can monitor your Facebook conversations, and learn thing that just weren't online a decade ago. Today we all carry devices that tract our locations 24/7: our cell phones.

In this essay, CDT fellows (and law professors) challenge the "going dark" metaphor and make the case for "the golden age of surveillance." Yes, wiretapping is harder; but so many other types of surveillance are easier.

    A simple test can help the reader decide between the "going dark"
    and "golden age of surveillance" hypotheses. Suppose the agencies
    had a choice of a 1990-era package or a 2011-era package. The first
    package would include the wiretap authorities as they existed
    pre-encryption, but would lack the new techniques for location
    tracking, confederate identification, access to multiple databases,
    and data mining. The second package would match current
    capabilities: some encryption-related obstacles, but increased use
    of wiretaps, as well as the capabilities for location tracking,
    confederate tracking and data mining. The second package is clearly
    superior -- the new surveillance tools assist a vast range of
    investigations, whereas wiretaps apply only to a small subset of
    key investigations. The new tools are used far more frequently and
    provide granular data to assist investigators.


http://www.cdt.org/blogs/2811going-dark-versus-golden-age-surveillance

A longer and more detailed version of the same argument can be found in "Encryption and Globalization," forthcoming in the Columbia Science and Technology Law Review.
http://ssrn.com/abstract=1960602

In a related story, there's a relatively new WikiLeaks data dump of documents related to government surveillance products.
http://wikileaks.org/the-spyfiles.html
http://m.zdnet.com/blog/london/skype-monitoring-gmail-hacks-and-fake-itunes-updates-how-governments-can-track-you/1479 or http://tinyurl.com/7569dcg
http://gadgetmix.com/articles/big-brothers-watching-you/
http://www.cultofmac.com/132782/if-you-thought-carrier-iq-scandal-was-bad-wait-till-you-see-latest-wikileaks/ or http://tinyurl.com/89vzyan http://www.bugged.com/wikileaks-spy-files-finfly-device-targets-computer-through-apple-itunes-scam/ or http://tinyurl.com/7wwkp2e


** *** ***** ******* *********** *************

     "Chinese Hacking" of iBahn Internet Services



Citing unexplained "intelligence data," an unnamed "senior intelligence official," and an anonymous "privacy security official," Bloomberg News claims that iBahn -- the company that runs Internet services for a bunch of hotel chains -- has been hacked by the Chinese. The rest of the story is pretty obvious: all sorts of private e-mails stolen, corporate networks hacked via iBahn, China does lot of hacking, and so on. iBahn has denied the story.

Come on, people. I know that China hacking stories are plausible, but the bar for actual evidence should be higher than this.


http://www.businessweek.com/news/2011-12-16/china-based-hacking-of-760-companies-shows-cyber-cold-war.html or http://tinyurl.com/6pubxxx http://www.networkworld.com/news/2011/121511-ibahn-supplier-of-hotel-internet-254110.html or http://tinyurl.com/8xyb97c


** *** ***** ******* *********** *************

     Schneier News



Charles Mann made me the central focus of his article on airport security for "Vanity Fair". The article was supposed to have been in the tenth-anniversary-of-9/11 issue, but got delayed.
http://www.vanityfair.com/culture/features/2011/12/tsa-insanity-201112
Here's a rebuttal to the piece. I agree with the two points at the end of the post; I just don't think it changes any of my analysis.
http://www.hlswatch.com/2012/01/03/defending-the-tsa/
Mann also wrote about me in 2002 for "The Atlantic."
http://www.theatlantic.com/past/docs/issues/2002/09/mann.htm

In 1997, I spoke at the Beyond HOPE Conference in New York. (HOPE stood for "Hackers On Planet Earth.) A video of that talk is available online. http://blip.tv/2600magazine/beyond-hope-1997-cryptography-opportunities-threats-and-implementations-5798822#disqus_thread or http://tinyurl.com/cnaw5vn
http://blip.tv/file/get/2600magazine-bh07999.m4v
Slides from talk:
https://www.schneier.com/schneier-talk.pdf

In this video, you'll see my first cameo appearance in a transvestite-themed rock video at the 1:46 mark.
http://www.youtube.com/watch?v=gmPta19GSFU


** *** ***** ******* *********** *************

     Liars and Outliers News



The Liars and Outliers webpage is live. On it, you can find links to order both paper and e-book copies from a variety of online retailers, and signed copies directly from me. I've also posted the jacket copy, the table of contents, the first chapter, the 15 figures from the book, an image of the full wraparound cover, and all the blurbs for the book.

Last month, I chose 10 winners from the 278 people who entered the drawing for a free galley copy. Those copies have all been mailed, as have copies to potential book reviewers.

Several readers suggested that I auction some copies, and I did that last week. Two blog readers won signed galleys, with the proceeds going to EFF and EPIC.


Book website--you can order signed copies here.
http://schneier.com/lo


** *** ***** ******* *********** *************

Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing summaries, analyses, insights, and commentaries on security: computer and otherwise. You can subscribe, unsubscribe, or change your address on the Web at <http://www.schneier.com/crypto-gram.html>. Back issues are also available at that URL.

Please feel free to forward CRYPTO-GRAM, in whole or in part, to colleagues and friends who will find it valuable. Permission is also granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entirety.

CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies," and "Applied Cryptography," and an inventor of the Blowfish, Twofish, Threefish, Helix, Phelix, and Skein algorithms. He is the Chief Security Technology Officer of BT BCSG, and is on the Board of Directors of the Electronic Privacy Information Center (EPIC). He is a frequent writer and lecturer on security topics. See <http://www.schneier.com>.

Crypto-Gram is a personal newsletter. Opinions expressed are not necessarily those of BT.

Copyright (c) 2012 by Bruce Schneier.

** *** ***** ******* *********** *************

To unsubscribe, click this link:

http://listserv.modwest.com/cgi-bin/wa?TICKET=NzM0NTQ2IGFyY2hpdmVATUFJTC1BUkNISVZFLkNPTSBDUllQVE8tR1JBTS1MSVNUIBb1B9q3tYsf&c=SIGNOFF

Reply via email to