CRYPTO-GRAM

              February 15, 2012

              by Bruce Schneier
      Chief Security Technology Officer, BT
             [email protected]
            http://www.schneier.com


A free monthly newsletter providing summaries, analyses, insights, and commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit <http://www.schneier.com/crypto-gram.html>.

You can read this issue on the web at <http://www.schneier.com/crypto-gram-1202.html>. These same essays and news items appear in the "Schneier on Security" blog at <http://www.schneier.com/blog>, along with a lively comment section. An RSS feed is available.


** *** ***** ******* *********** *************

In this issue:
     "Liars and Outliers" Update
     Possibly the Most Incompetent TSA Story Yet
     News
     What Happens When the Court Demands You Decrypt a
       Document and You Forget the Key?
     Authentication by "Cognitive Footprint"
     Schneier News
     The Failure of Two-Factor Authentication


** *** ***** ******* *********** *************

     "Liars and Outliers" Update



"Liars and Outliers" is available. Amazon and Barnes & Noble have been shipping the book since the beginning of the month. Both the Kindle and the Nook versions are available for download. (Yes, Amazon's webpage claims that the book will be published on February 21, 2012, but they ship copies as soon as they get them -- this ain't Harry Potter.) I have received 250 books myself. Everyone who read and commented on a draft will get a copy in the mail. And as of today, I have shipped books to everyone who ordered a signed copy.

I've seen five more reviews. And there's one print and one audio (there's also a transcript) interview about the book.

A bunch of people on Twitter have announced that they're enjoying the book. Right now, there are only three reviews on Amazon. Please, leave a review on Amazon. (I'll write about the problem of fake reviews on these sorts of sites in another post.)

I'm not sure, but I think the Kindle price is going to increase. So if you want the book at the current $10 price, now is the time to buy it.

At the end of February, I'll be at the RSA Conference in San Francisco. In addition to my other speaking events, Davi Ottenheimer will interview me about the book at something called The Author's Studio. I'll be doing two one-hour book signings at the conference bookstore. And, and this is the best news of all, HP has bought 1,000 copies of the book and will be giving them away at their booth. I'll be doing a couple of signings there as well.

The book's webpage:
http://www.schneier.com/book-lo.html

Ordering a signed copy:
http://www.schneier.com/book-lo.html#signed

Reviews:
http://www.forbes.com/sites/adamthierer/2012/01/23/why-doesnt-society-just-fall-apart/ or http://tinyurl.com/8yfpodm http://365.rsaconference.com/blogs/securityreading/2012/01/23/liars-and-outliers-enabling-the-trust-that-society-needs-to-thrive or http://tinyurl.com/7myxe2u http://www.infoworld.com/d/security/book-review-liars-and-outliers-enabling-the-trust-society-needs-thrive-185355 or http://tinyurl.com/7uxfsqz http://www.informationweek.com/byte/reviews/personal-tech/science-tech/232600022 or http://tinyurl.com/85jdta8
http://spectrum.ieee.org/at-work/innovation/review-liars-outliers
http://www.zdnet.co.uk/blogs/zdnet-uk-book-reviews-10015295/book-review-liars-and-outliers-10025364/ or http://tinyurl.com/83xhpsb http://globalguerrillas.typepad.com/globalguerrillas/2012/02/why-the-global-system-is-killing-trust.html or http://tinyurl.com/76ed2lt

Interviews:
http://www.schneier.com/news-118.html
http://spectrum.ieee.org/podcast/telecom/internet/guarding-without-guardians or http://tinyurl.com/82lzv2q


** *** ***** ******* *********** *************

     Possibly the Most Incompetent TSA Story Yet



The storyline:

1. TSA screener finds two pipes in passenger's bags.

2. Screener determines that they're not a threat.

3. Screener confiscates them anyway, because of their "material and appearance."

4. Because they're not actually a threat, screener leaves them at the checkpoint.

5. Everyone forgets about them.

6. Six hours later, the next shift of TSA screeners notices the pipes and -- not being able to explain how they got there and, presumably, because of their "material and appearance" -- calls the police bomb squad to remove the pipes.

7. TSA does not evacuate the airport, or even close the checkpoint, because -- well, we don't know why.

I don't even know where to begin.

http://www.cnn.com/2012/01/30/us/new-york-bomb-scare/index.html


** *** ***** ******* *********** *************

     News



A merchant is suing his bank, claiming that the PCI standard "force[s] merchants to sign one-sided contracts that are based on information that arbitrarily changes without notice, and that they impose random fines on merchants without providing proof of a breach or of fraudulent losses and without allowing merchants a meaningful opportunity to dispute claims before money is seized." The PCI standards are probably the biggest non-government security standard. It'll be interesting to see how this turns out.
http://www.wired.com/threatlevel/2012/01/pci-lawsuit/

Thankfully, this doesn't happen very often: "A US man who had been convicted on a second-degree murder charge will get a new trial after a computer virus destroyed transcripts of court proceedings." http://www.theregister.co.uk/2012/01/05/virus_deletes_court_transcript/ or http://tinyurl.com/6t8b7sv

Good operational security guide to Tor.
http://cryptome.org/0005/tor-opsec.htm

I wrote about the technique of using false alarms to disable security in my book, "Beyond Fear." Here it is being used to rob an art gallery. http://www.cbc.ca/news/arts/story/2012/01/09/greece-art-theft-picasso-mondrian.html or http://tinyurl.com/7pyuwfm

Funny Onion news video on Facebook and the CIA.
http://www.youtube.com/watch?v=ZJ380SHZvYU

Continuing the militarization of the U.S. police, the state of Texas gets an armed patrol boat. http://www.homelandsecuritynewswire.com/dr20120112-texas-unveils-armed-patrol-boat or http://tinyurl.com/8aydoby
I guess armed drones weren't enough for them.
http://www.democraticunderground.com/discuss/duboard.php?az=view_all&address=180x70881 or http://tinyurl.com/7rm3w5g

Turns out you can create unique signatures from plant DNA. The idea is to spray this stuff on military components in order to verify authentic items and detect counterfeits, similar to SmartWater. It's a good idea in theory, but my guess is that the security is not going to center around counterfeiting the plant DNA, but rather in subverting the systems that apply, detect, and verify the chemicals.
http://www.wired.com/dangerroom/2012/01/dna-counterfeits/
SmartWater:
http://www.schneier.com/blog/archives/2008/01/smartwater_work.html

The NSF is funding research on giving organizations information-security risk ratings, similar to credit ratings for individuals.
http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=1127185
I have no idea if this is snake oil or if it actually works, but note that this is a Phase II award. There was already a Phase I award, and the NSF must have liked the results from that.

Supreme Court rules about GPS tracking without a warrant. I originally wrote that the ruling forces the police to get a warrant before placing a GPS tracking device on a car. Actually, the ruling is much more complicated and nuanced. http://jonathanturley.org/2012/01/23/supreme-court-unanimously-rejects-obama-administrations-effort-to-conduct-warrantless-gps-searches/ or http://tinyurl.com/7gcw2mp
http://m.wired.com/threatlevel/2012/01/scotus-gps-ruling/
http://pda.physorg.com/news/2012-01-high-court-warrant-gps-tracking.html or http://tinyurl.com/7vty259 http://www.nytimes.com/2012/01/24/us/police-use-of-gps-is-ruled-unconstitutional.html or http://tinyurl.com/86xekjh http://www.networkworld.com/community/blog/supreme-court-backs-privacy-over-police-gps-case or http://tinyurl.com/6uyjeht http://www.concurringopinions.com/archives/2012/01/united-states-v-jones-the-fourth-amendment-and-gps-surveillance.html or http://tinyurl.com/7kxt6rr
http://www.scotusblog.com/2012/01/jones-confounds-the-press/
http://www.concurringopinions.com/archives/2012/01/welcoming-experts-to-discuss-the-supreme-courts-decision-in-united-states-v-jones.html or http://tinyurl.com/6vu4qkv http://www.concurringopinions.com/archives/2012/01/three-thoughts-on-u-s-v-jones.html or http://tinyurl.com/82znz2d http://www.concurringopinions.com/archives/2012/01/jones-is-a-near-optimal-result.html or http://tinyurl.com/6se6l9x http://www.concurringopinions.com/archives/2012/01/united-states-v-jones-privacy-in-public-space-piece-it-all-together-and-you-get-5.html or http://tinyurl.com/7l5xmq3 http://www.concurringopinions.com/archives/2012/01/reasonable-expectation-of-privacy.html or http://tinyurl.com/72fogkw http://www.concurringopinions.com/archives/2012/01/why-scalia-is-right-in-jones-magic-places-and-one-way-ratchets.html or http://tinyurl.com/7vkobov

Readers of Crypto-Gram will know that I like the works of Max Abrams, and regularly link to them. He has a new paper in "Defence and Peace Economics", 22:6 (2011), 583–94, "Does Terrorism Really Work? Evolution in the Conventional Wisdom since 9/11, Defence and Peace Economics".
http://dx.doi.org/10.1080/10242694.2011.635954
http://www.clas.ufl.edu/users/gesenwei/Does%20Terrorism%20Really%20Work%5B1%5D.pdf or http://tinyurl.com/78fddhj

Interesting article on password sharing among American teens as a show of affection. http://www.nytimes.com/2012/01/18/us/teenagers-sharing-passwords-as-show-of-affection.html or http://tinyurl.com/8yk6ypn
Ethnologist danah boyd discusses what's happening:
http://www.zephoria.org/thoughts/archives/2012/01/23/how-parents-normalized-teen-password-sharing.html or http://tinyurl.com/7uswc43
Related: a profile of danah boyd.
http://www.nytimes.com/2012/01/22/fashion/danah-boyd-cracking-teenagers-online-codes.html or http://tinyurl.com/7ks54aa

Pretty good essay on the nature of cyberwar:
http://www.internetevolution.com/author.asp?doc_id=237983

On my blog, there was an interesting story about two British tourists detained at the U.S. border for their tweets.
http://www.schneier.com/blog/archives/2012/01/british_tourist.html

Some errors in forensic science may be the result of the biases of the examiners.
http://www.economist.com/node/21543121

The Idaho Loophole is -- if you believe the theory -- "a 50-square-mile swath of Idaho in which one can commit felonies with impunity."
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=691642

Really good article on the huge incarceration rate in the U.S., its causes, its effects, and its value. http://www.newyorker.com/arts/critics/atlarge/2012/01/30/120130crat_atlarge_gopnik?currentPage=all or http://tinyurl.com/7cbvxrs

VeriSign hacked, successfully and repeatedly, in 2010. Reuters discovered the information.
http://www.schneier.com/blog/archives/2012/02/verisign_hacked.html

The problems of too much information sharing. Yes, it's fake. But it's funny.
http://i.imgur.com/rsQ93.png
http://www.reddit.com/r/funny/comments/owx3v/so_my_little_cousin_posted_on_fb_that_he_was/ or http://tinyurl.com/6tjwbyz

The error rate for hand-counted ballots can be as high as two percent.
http://www.sciencedaily.com/releases/2012/02/120202151713.htm
All voting systems have nonzero error rates. This doesn't surprise technologists, but does surprise the general public. There's a myth out there that elections are perfectly accurate, down to the single vote. They're not. If the vote is within a few percentage points, they're likely a statistical tie. (The problem, of course, is that elections must produce a single winner.)

"Solving the Underlying Economic Problem of Internet Piracy"
http://www.forbes.com/sites/insertcoin/2012/02/03/you-will-never-kill-piracy-and-piracy-will-never-kill-you/ or http://tinyurl.com/87pakeo
This essay is definitely thinking along the correct directions.

Interesting paper about the security risks of smaller aircraft.
http://paulfreitas.com/Passenger%20Aviation%20Security%20Risk%20Management%20and%20Simple%20Physics.pdf or http://tinyurl.com/7awwecy

Interesting blog post about locking down iPads so students can take exams on them.
http://speirs.org/blog/2012/2/6/digital-exams-on-the-ipad.html

Funny essay on captchas.
http://www.nytimes.com/interactive/2012/02/05/opinion/sunday/20120205_Password.html or http://tinyurl.com/7en7tws

Adam Shostack explains to VeriSign that trust requires transparency.
http://newschoolsecurity.com/2012/02/dear-verisign-trust-requires-transparency or http://tinyurl.com/7fbupzz
This is a lesson Path should have learned.
http://mclov.in/2012/02/08/path-uploads-your-entire-address-book-to-their-servers.html or http://tinyurl.com/7ahj4pq http://www.zdnet.com/blog/apple/path-discovered-phoning-home-with-your-address-book/12182 or http://tinyurl.com/7upw5ho http://www.slashgear.com/path-privacy-blunder-could-fall-foul-of-euro-data-penalties-08212615/ or http://tinyurl.com/76jw5at http://www.wired.com/gadgetlab/2012/02/path-dave-morin-explains-data/ or http://tinyurl.com/85x8sgb

SSL traffic analysis on Google Maps.
http://blog.ioactive.com/2012/02/ssl-traffic-analysis-on-google-maps.html or http://tinyurl.com/6pnc87r

This writer wrestles with the costs and benefits of tighter controls on pseudoephedrine, a key chemical used to make methamphetamine. http://www.theatlantic.com/health/archive/2012/02/do-we-need-even-tighter-controls-on-sudafed/252637/ or http://tinyurl.com/7efdh64
I like seeing the debate framed as a security trade-off.

Dumb risk of the day: geotagged images of children:
http://machineslikeus.com/news/digital-photos-could-put-kids-risk


** *** ***** ******* *********** *************

     What Happens When the Court Demands You Decrypt a
       Document and You Forget the Key?



Last month, a U.S. court demanded that a defendant surrender the encryption key to a laptop so the police could examine it.

Now it seems that she's forgotten the key.

What happens now? It seems as if this excuse would always be available to someone who doesn't want the police to decrypt her files. On the other hand, it might be hard to realistically forget a key. It's less credible for someone to say "I have no idea what my password is," and more likely to say something like "it was the word 'telephone' with a zero for the o and then some number following -- four digits, with a six in it -- and then a punctuation mark like a period." And then a brute-force password search could be targeted. I suppose someone could say "it was a random alphanumeric password created by an automatic program; I really have no idea," but I'm not sure a judge would believe it.

U.S ruling:
http://www.engadget.com/2012/01/24/judge-laptop-decryption-colorado-fifth-amendment/ or http://tinyurl.com/79omyvm http://news.cnet.com/8301-31921_3-57364330-281/judge-americans-can-be-forced-to-decrypt-their-laptops or http://tinyurl.com/88hhs42 http://www.wired.com/threatlevel/2012/01/judge-orders-laptop-decryption/ or http://tinyurl.com/6wrfk5b http://www.zdnet.com/blog/identity/judge-says-defendant-must-decrypt-files-fifth-amendment-not-at-issue/175 or http://tinyurl.com/7onceco
The ruling:
http://www.wired.com/images_blogs/threatlevel/2012/01/decrypt.pdf
Good analysis:
http://volokh.com/2012/01/24/encrytion-and-the-fifth-amendment-right-against-self-incrimination/ or http://tinyurl.com/7t36bm6

Forgotten key:
http://m.wired.com/threatlevel/2012/02/forgotten-password/


** *** ***** ******* *********** *************

     Authentication by "Cognitive Footprint"



DARPA is funding research into new forms of biometrics that authenticate people as they use their computer: things like keystroke patterns, eye movements, mouse behavior, reading speed, and surfing and e-mail response behavior. The idea -- and I think this is a good one -- is that the computer can continuously authenticate people, and not just authenticate them once when they first start using their computers.

I remember reading a science fiction story about a computer worm that searched for people this way: going from computer to computer, trying to identify a specific individual.

http://www.networkworld.com/community/blog/darpa-set-develop-super-secure-cognitive-fingerprint or http://tinyurl.com/7rvpvah


** *** ***** ******* *********** *************

     Schneier News


I am the Hal Clement Science Speaker at Boskone 49, Feb 17-19, in Boston.
http://www.nesfa.org/boskone/

I am speaking at the Messaging Anti-Abuse Working Group 24th General Meeting, Feb 22, in San Francisco.
http://www.maawg.org/events/upcoming_meetings

I am speaking at the RSA Conference 2012, Feb 27-Mar 2, in San Francisco.
http://www.rsaconference.com/events/2012/usa/index.htm


** *** ***** ******* *********** *************

     The Failure of Two-Factor Authentication



In 2005, I wrote an essay called "The Failure of Two-Factor Authentication," where I predicted that attackers would get around multi-factor authentication systems with tools that attack the transactions in real time: man-in-the-middle attacks and Trojan attacks against the client endpoint.

This article describes exactly that.

http://www.bbc.co.uk/news/technology-16812064
http://www.theregister.co.uk/2012/02/06/online_banking_security/

My 2005 essay:
http://www.schneier.com/blog/archives/2005/03/the_failure_of.html

The solution is to authenticate the transaction, not the person.
http://www.schneier.com/blog/archives/2006/11/fighting_fraudu.html


** *** ***** ******* *********** *************

Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing summaries, analyses, insights, and commentaries on security: computer and otherwise. You can subscribe, unsubscribe, or change your address on the Web at <http://www.schneier.com/crypto-gram.html>. Back issues are also available at that URL.

Please feel free to forward CRYPTO-GRAM, in whole or in part, to colleagues and friends who will find it valuable. Permission is also granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entirety.

CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies," and "Applied Cryptography," and an inventor of the Blowfish, Twofish, Threefish, Helix, Phelix, and Skein algorithms. He is the Chief Security Technology Officer of BT BCSG, and is on the Board of Directors of the Electronic Privacy Information Center (EPIC). He is a frequent writer and lecturer on security topics. See <http://www.schneier.com>.

Crypto-Gram is a personal newsletter. Opinions expressed are not necessarily those of BT.

Copyright (c) 2012 by Bruce Schneier.

** *** ***** ******* *********** *************

To unsubscribe, click this link:

http://listserv.modwest.com/cgi-bin/wa?TICKET=NzM0NTc4IGFyY2hpdmVATUFJTC1BUkNISVZFLkNPTSBDUllQVE8tR1JBTS1MSVNUICWkiMxFOKkM&c=SIGNOFF

Reply via email to