CRYPTO-GRAM
February 15, 2012
by Bruce Schneier
Chief Security Technology Officer, BT
[email protected]
http://www.schneier.com
A free monthly newsletter providing summaries, analyses, insights, and
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at
<http://www.schneier.com/crypto-gram-1202.html>. These same essays and
news items appear in the "Schneier on Security" blog at
<http://www.schneier.com/blog>, along with a lively comment section. An
RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
"Liars and Outliers" Update
Possibly the Most Incompetent TSA Story Yet
News
What Happens When the Court Demands You Decrypt a
Document and You Forget the Key?
Authentication by "Cognitive Footprint"
Schneier News
The Failure of Two-Factor Authentication
** *** ***** ******* *********** *************
"Liars and Outliers" Update
"Liars and Outliers" is available. Amazon and Barnes & Noble have been
shipping the book since the beginning of the month. Both the Kindle and
the Nook versions are available for download. (Yes, Amazon's webpage
claims that the book will be published on February 21, 2012, but they
ship copies as soon as they get them -- this ain't Harry Potter.) I
have received 250 books myself. Everyone who read and commented on a
draft will get a copy in the mail. And as of today, I have shipped
books to everyone who ordered a signed copy.
I've seen five more reviews. And there's one print and one audio
(there's also a transcript) interview about the book.
A bunch of people on Twitter have announced that they're enjoying the
book. Right now, there are only three reviews on Amazon. Please, leave
a review on Amazon. (I'll write about the problem of fake reviews on
these sorts of sites in another post.)
I'm not sure, but I think the Kindle price is going to increase. So if
you want the book at the current $10 price, now is the time to buy it.
At the end of February, I'll be at the RSA Conference in San Francisco.
In addition to my other speaking events, Davi Ottenheimer will
interview me about the book at something called The Author's Studio.
I'll be doing two one-hour book signings at the conference bookstore.
And, and this is the best news of all, HP has bought 1,000 copies of the
book and will be giving them away at their booth. I'll be doing a
couple of signings there as well.
The book's webpage:
http://www.schneier.com/book-lo.html
Ordering a signed copy:
http://www.schneier.com/book-lo.html#signed
Reviews:
http://www.forbes.com/sites/adamthierer/2012/01/23/why-doesnt-society-just-fall-apart/
or http://tinyurl.com/8yfpodm
http://365.rsaconference.com/blogs/securityreading/2012/01/23/liars-and-outliers-enabling-the-trust-that-society-needs-to-thrive
or http://tinyurl.com/7myxe2u
http://www.infoworld.com/d/security/book-review-liars-and-outliers-enabling-the-trust-society-needs-thrive-185355
or http://tinyurl.com/7uxfsqz
http://www.informationweek.com/byte/reviews/personal-tech/science-tech/232600022
or http://tinyurl.com/85jdta8
http://spectrum.ieee.org/at-work/innovation/review-liars-outliers
http://www.zdnet.co.uk/blogs/zdnet-uk-book-reviews-10015295/book-review-liars-and-outliers-10025364/
or http://tinyurl.com/83xhpsb
http://globalguerrillas.typepad.com/globalguerrillas/2012/02/why-the-global-system-is-killing-trust.html
or http://tinyurl.com/76ed2lt
Interviews:
http://www.schneier.com/news-118.html
http://spectrum.ieee.org/podcast/telecom/internet/guarding-without-guardians
or http://tinyurl.com/82lzv2q
** *** ***** ******* *********** *************
Possibly the Most Incompetent TSA Story Yet
The storyline:
1. TSA screener finds two pipes in passenger's bags.
2. Screener determines that they're not a threat.
3. Screener confiscates them anyway, because of their "material and
appearance."
4. Because they're not actually a threat, screener leaves them at the
checkpoint.
5. Everyone forgets about them.
6. Six hours later, the next shift of TSA screeners notices the pipes
and -- not being able to explain how they got there and, presumably,
because of their "material and appearance" -- calls the police bomb
squad to remove the pipes.
7. TSA does not evacuate the airport, or even close the checkpoint,
because -- well, we don't know why.
I don't even know where to begin.
http://www.cnn.com/2012/01/30/us/new-york-bomb-scare/index.html
** *** ***** ******* *********** *************
News
A merchant is suing his bank, claiming that the PCI standard "force[s]
merchants to sign one-sided contracts that are based on information that
arbitrarily changes without notice, and that they impose random fines on
merchants without providing proof of a breach or of fraudulent losses
and without allowing merchants a meaningful opportunity to dispute
claims before money is seized." The PCI standards are probably the
biggest non-government security standard. It'll be interesting to see
how this turns out.
http://www.wired.com/threatlevel/2012/01/pci-lawsuit/
Thankfully, this doesn't happen very often: "A US man who had been
convicted on a second-degree murder charge will get a new trial after a
computer virus destroyed transcripts of court proceedings."
http://www.theregister.co.uk/2012/01/05/virus_deletes_court_transcript/
or http://tinyurl.com/6t8b7sv
Good operational security guide to Tor.
http://cryptome.org/0005/tor-opsec.htm
I wrote about the technique of using false alarms to disable security in
my book, "Beyond Fear." Here it is being used to rob an art gallery.
http://www.cbc.ca/news/arts/story/2012/01/09/greece-art-theft-picasso-mondrian.html
or http://tinyurl.com/7pyuwfm
Funny Onion news video on Facebook and the CIA.
http://www.youtube.com/watch?v=ZJ380SHZvYU
Continuing the militarization of the U.S. police, the state of Texas
gets an armed patrol boat.
http://www.homelandsecuritynewswire.com/dr20120112-texas-unveils-armed-patrol-boat
or http://tinyurl.com/8aydoby
I guess armed drones weren't enough for them.
http://www.democraticunderground.com/discuss/duboard.php?az=view_all&address=180x70881
or http://tinyurl.com/7rm3w5g
Turns out you can create unique signatures from plant DNA. The idea is
to spray this stuff on military components in order to verify authentic
items and detect counterfeits, similar to SmartWater. It's a good idea
in theory, but my guess is that the security is not going to center
around counterfeiting the plant DNA, but rather in subverting the
systems that apply, detect, and verify the chemicals.
http://www.wired.com/dangerroom/2012/01/dna-counterfeits/
SmartWater:
http://www.schneier.com/blog/archives/2008/01/smartwater_work.html
The NSF is funding research on giving organizations information-security
risk ratings, similar to credit ratings for individuals.
http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=1127185
I have no idea if this is snake oil or if it actually works, but note
that this is a Phase II award. There was already a Phase I award, and
the NSF must have liked the results from that.
Supreme Court rules about GPS tracking without a warrant. I originally
wrote that the ruling forces the police to get a warrant before placing
a GPS tracking device on a car. Actually, the ruling is much more
complicated and nuanced.
http://jonathanturley.org/2012/01/23/supreme-court-unanimously-rejects-obama-administrations-effort-to-conduct-warrantless-gps-searches/
or http://tinyurl.com/7gcw2mp
http://m.wired.com/threatlevel/2012/01/scotus-gps-ruling/
http://pda.physorg.com/news/2012-01-high-court-warrant-gps-tracking.html
or http://tinyurl.com/7vty259
http://www.nytimes.com/2012/01/24/us/police-use-of-gps-is-ruled-unconstitutional.html
or http://tinyurl.com/86xekjh
http://www.networkworld.com/community/blog/supreme-court-backs-privacy-over-police-gps-case
or http://tinyurl.com/6uyjeht
http://www.concurringopinions.com/archives/2012/01/united-states-v-jones-the-fourth-amendment-and-gps-surveillance.html
or http://tinyurl.com/7kxt6rr
http://www.scotusblog.com/2012/01/jones-confounds-the-press/
http://www.concurringopinions.com/archives/2012/01/welcoming-experts-to-discuss-the-supreme-courts-decision-in-united-states-v-jones.html
or http://tinyurl.com/6vu4qkv
http://www.concurringopinions.com/archives/2012/01/three-thoughts-on-u-s-v-jones.html
or http://tinyurl.com/82znz2d
http://www.concurringopinions.com/archives/2012/01/jones-is-a-near-optimal-result.html
or http://tinyurl.com/6se6l9x
http://www.concurringopinions.com/archives/2012/01/united-states-v-jones-privacy-in-public-space-piece-it-all-together-and-you-get-5.html
or http://tinyurl.com/7l5xmq3
http://www.concurringopinions.com/archives/2012/01/reasonable-expectation-of-privacy.html
or http://tinyurl.com/72fogkw
http://www.concurringopinions.com/archives/2012/01/why-scalia-is-right-in-jones-magic-places-and-one-way-ratchets.html
or http://tinyurl.com/7vkobov
Readers of Crypto-Gram will know that I like the works of Max Abrams,
and regularly link to them. He has a new paper in "Defence and Peace
Economics", 22:6 (2011), 583–94, "Does Terrorism Really Work? Evolution
in the Conventional Wisdom since 9/11, Defence and Peace Economics".
http://dx.doi.org/10.1080/10242694.2011.635954
http://www.clas.ufl.edu/users/gesenwei/Does%20Terrorism%20Really%20Work%5B1%5D.pdf
or http://tinyurl.com/78fddhj
Interesting article on password sharing among American teens as a show
of affection.
http://www.nytimes.com/2012/01/18/us/teenagers-sharing-passwords-as-show-of-affection.html
or http://tinyurl.com/8yk6ypn
Ethnologist danah boyd discusses what's happening:
http://www.zephoria.org/thoughts/archives/2012/01/23/how-parents-normalized-teen-password-sharing.html
or http://tinyurl.com/7uswc43
Related: a profile of danah boyd.
http://www.nytimes.com/2012/01/22/fashion/danah-boyd-cracking-teenagers-online-codes.html
or http://tinyurl.com/7ks54aa
Pretty good essay on the nature of cyberwar:
http://www.internetevolution.com/author.asp?doc_id=237983
On my blog, there was an interesting story about two British tourists
detained at the U.S. border for their tweets.
http://www.schneier.com/blog/archives/2012/01/british_tourist.html
Some errors in forensic science may be the result of the biases of the
examiners.
http://www.economist.com/node/21543121
The Idaho Loophole is -- if you believe the theory -- "a 50-square-mile
swath of Idaho in which one can commit felonies with impunity."
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=691642
Really good article on the huge incarceration rate in the U.S., its
causes, its effects, and its value.
http://www.newyorker.com/arts/critics/atlarge/2012/01/30/120130crat_atlarge_gopnik?currentPage=all
or http://tinyurl.com/7cbvxrs
VeriSign hacked, successfully and repeatedly, in 2010. Reuters
discovered the information.
http://www.schneier.com/blog/archives/2012/02/verisign_hacked.html
The problems of too much information sharing. Yes, it's fake. But it's
funny.
http://i.imgur.com/rsQ93.png
http://www.reddit.com/r/funny/comments/owx3v/so_my_little_cousin_posted_on_fb_that_he_was/
or http://tinyurl.com/6tjwbyz
The error rate for hand-counted ballots can be as high as two percent.
http://www.sciencedaily.com/releases/2012/02/120202151713.htm
All voting systems have nonzero error rates. This doesn't surprise
technologists, but does surprise the general public. There's a myth out
there that elections are perfectly accurate, down to the single vote.
They're not. If the vote is within a few percentage points, they're
likely a statistical tie. (The problem, of course, is that elections
must produce a single winner.)
"Solving the Underlying Economic Problem of Internet Piracy"
http://www.forbes.com/sites/insertcoin/2012/02/03/you-will-never-kill-piracy-and-piracy-will-never-kill-you/
or http://tinyurl.com/87pakeo
This essay is definitely thinking along the correct directions.
Interesting paper about the security risks of smaller aircraft.
http://paulfreitas.com/Passenger%20Aviation%20Security%20Risk%20Management%20and%20Simple%20Physics.pdf
or http://tinyurl.com/7awwecy
Interesting blog post about locking down iPads so students can take
exams on them.
http://speirs.org/blog/2012/2/6/digital-exams-on-the-ipad.html
Funny essay on captchas.
http://www.nytimes.com/interactive/2012/02/05/opinion/sunday/20120205_Password.html
or http://tinyurl.com/7en7tws
Adam Shostack explains to VeriSign that trust requires transparency.
http://newschoolsecurity.com/2012/02/dear-verisign-trust-requires-transparency
or http://tinyurl.com/7fbupzz
This is a lesson Path should have learned.
http://mclov.in/2012/02/08/path-uploads-your-entire-address-book-to-their-servers.html
or http://tinyurl.com/7ahj4pq
http://www.zdnet.com/blog/apple/path-discovered-phoning-home-with-your-address-book/12182
or http://tinyurl.com/7upw5ho
http://www.slashgear.com/path-privacy-blunder-could-fall-foul-of-euro-data-penalties-08212615/
or http://tinyurl.com/76jw5at
http://www.wired.com/gadgetlab/2012/02/path-dave-morin-explains-data/ or
http://tinyurl.com/85x8sgb
SSL traffic analysis on Google Maps.
http://blog.ioactive.com/2012/02/ssl-traffic-analysis-on-google-maps.html or
http://tinyurl.com/6pnc87r
This writer wrestles with the costs and benefits of tighter controls on
pseudoephedrine, a key chemical used to make methamphetamine.
http://www.theatlantic.com/health/archive/2012/02/do-we-need-even-tighter-controls-on-sudafed/252637/
or http://tinyurl.com/7efdh64
I like seeing the debate framed as a security trade-off.
Dumb risk of the day: geotagged images of children:
http://machineslikeus.com/news/digital-photos-could-put-kids-risk
** *** ***** ******* *********** *************
What Happens When the Court Demands You Decrypt a
Document and You Forget the Key?
Last month, a U.S. court demanded that a defendant surrender the
encryption key to a laptop so the police could examine it.
Now it seems that she's forgotten the key.
What happens now? It seems as if this excuse would always be available
to someone who doesn't want the police to decrypt her files. On the
other hand, it might be hard to realistically forget a key. It's less
credible for someone to say "I have no idea what my password is," and
more likely to say something like "it was the word 'telephone' with a
zero for the o and then some number following -- four digits, with a six
in it -- and then a punctuation mark like a period." And then a
brute-force password search could be targeted. I suppose someone could
say "it was a random alphanumeric password created by an automatic
program; I really have no idea," but I'm not sure a judge would believe it.
U.S ruling:
http://www.engadget.com/2012/01/24/judge-laptop-decryption-colorado-fifth-amendment/
or http://tinyurl.com/79omyvm
http://news.cnet.com/8301-31921_3-57364330-281/judge-americans-can-be-forced-to-decrypt-their-laptops
or http://tinyurl.com/88hhs42
http://www.wired.com/threatlevel/2012/01/judge-orders-laptop-decryption/
or http://tinyurl.com/6wrfk5b
http://www.zdnet.com/blog/identity/judge-says-defendant-must-decrypt-files-fifth-amendment-not-at-issue/175
or http://tinyurl.com/7onceco
The ruling:
http://www.wired.com/images_blogs/threatlevel/2012/01/decrypt.pdf
Good analysis:
http://volokh.com/2012/01/24/encrytion-and-the-fifth-amendment-right-against-self-incrimination/
or http://tinyurl.com/7t36bm6
Forgotten key:
http://m.wired.com/threatlevel/2012/02/forgotten-password/
** *** ***** ******* *********** *************
Authentication by "Cognitive Footprint"
DARPA is funding research into new forms of biometrics that authenticate
people as they use their computer: things like keystroke patterns, eye
movements, mouse behavior, reading speed, and surfing and e-mail
response behavior. The idea -- and I think this is a good one -- is
that the computer can continuously authenticate people, and not just
authenticate them once when they first start using their computers.
I remember reading a science fiction story about a computer worm that
searched for people this way: going from computer to computer, trying to
identify a specific individual.
http://www.networkworld.com/community/blog/darpa-set-develop-super-secure-cognitive-fingerprint
or http://tinyurl.com/7rvpvah
** *** ***** ******* *********** *************
Schneier News
I am the Hal Clement Science Speaker at Boskone 49, Feb 17-19, in Boston.
http://www.nesfa.org/boskone/
I am speaking at the Messaging Anti-Abuse Working Group 24th General
Meeting, Feb 22, in San Francisco.
http://www.maawg.org/events/upcoming_meetings
I am speaking at the RSA Conference 2012, Feb 27-Mar 2, in San Francisco.
http://www.rsaconference.com/events/2012/usa/index.htm
** *** ***** ******* *********** *************
The Failure of Two-Factor Authentication
In 2005, I wrote an essay called "The Failure of Two-Factor
Authentication," where I predicted that attackers would get around
multi-factor authentication systems with tools that attack the
transactions in real time: man-in-the-middle attacks and Trojan attacks
against the client endpoint.
This article describes exactly that.
http://www.bbc.co.uk/news/technology-16812064
http://www.theregister.co.uk/2012/02/06/online_banking_security/
My 2005 essay:
http://www.schneier.com/blog/archives/2005/03/the_failure_of.html
The solution is to authenticate the transaction, not the person.
http://www.schneier.com/blog/archives/2006/11/fighting_fraudu.html
** *** ***** ******* *********** *************
Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing
summaries, analyses, insights, and commentaries on security: computer
and otherwise. You can subscribe, unsubscribe, or change your address on
the Web at <http://www.schneier.com/crypto-gram.html>. Back issues are
also available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to
colleagues and friends who will find it valuable. Permission is also
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entirety.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,
Threefish, Helix, Phelix, and Skein algorithms. He is the Chief Security
Technology Officer of BT BCSG, and is on the Board of Directors of the
Electronic Privacy Information Center (EPIC). He is a frequent writer
and lecturer on security topics. See <http://www.schneier.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not
necessarily those of BT.
Copyright (c) 2012 by Bruce Schneier.
** *** ***** ******* *********** *************
To unsubscribe, click this link:
http://listserv.modwest.com/cgi-bin/wa?TICKET=NzM0NTc4IGFyY2hpdmVATUFJTC1BUkNISVZFLkNPTSBDUllQVE8tR1JBTS1MSVNUICWkiMxFOKkM&c=SIGNOFF