CRYPTO-GRAM
April 15, 2012
by Bruce Schneier
Chief Security Technology Officer, BT
[email protected]
http://www.schneier.com
A free monthly newsletter providing summaries, analyses, insights, and
commentaries on security: computer and otherwise.
For back issues, or to subscribe, visit
<http://www.schneier.com/crypto-gram.html>.
You can read this issue on the web at
<http://www.schneier.com/crypto-gram-1204.html>. These same essays and
news items appear in the "Schneier on Security" blog at
<http://www.schneier.com/blog>, along with a lively comment section. An
RSS feed is available.
** *** ***** ******* *********** *************
In this issue:
Harms of Post-9/11 Airline Security
Congressional Testimony on the TSA
News
Bomb Threats As a Denial-of-Service Attack
Can the NSA Break AES?
Rare Spanish Enigma Machine
Schneier News
Buying Exploits on the Grey Market
Hacking Critical Infrastructure
** *** ***** ******* *********** *************
Harms of Post-9/11 Airline Security
I debated former TSA Administrator Kip Hawley on the "Economist"
website. I didn't bother reposting my opening statement and rebuttal,
because -- even though I thought I did a really good job with them --
they were largely things I've said before. In my closing statement, I
talked about specific harms post-9/11 airport security has caused. This
is mostly new, so here it is, British spelling and punctuation and all.
-----------------
In my previous two statements, I made two basic arguments about
post-9/11 airport security. One, we are not doing the right things: the
focus on airports at the expense of the broader threat is not making us
safer. And two, the things we are doing are wrong: the specific security
measures put in place since 9/11 do not work. Kip Hawley doesn't argue
with the specifics of my criticisms, but instead provides anecdotes and
asks us to trust that airport security -- and the Transportation
Security Administration (TSA) in particular -- knows what it's doing.
He wants us to trust that a 400-ml bottle of liquid is dangerous, but
transferring it to four 100-ml bottles magically makes it safe. He wants
us to trust that the butter knives given to first-class passengers are
nevertheless too dangerous to be taken through a security checkpoint. He
wants us to trust the no-fly list: 21,000 people so dangerous they're
not allowed to fly, yet so innocent they can't be arrested. He wants us
to trust that the deployment of expensive full-body scanners has nothing
to do with the fact that the former secretary of homeland security,
Michael Chertoff, lobbies for one of the companies that makes them. He
wants us to trust that there's a reason to confiscate a cupcake (Las
Vegas), a 3-inch plastic toy gun (London Gatwick), a purse with an
embroidered gun on it (Norfolk, VA), a T-shirt with a picture of a gun
on it (London Heathrow) and a plastic lightsaber that's really a
flashlight with a long cone on top (Dallas/Fort Worth).
At this point, we don't trust America's TSA, Britain's Department for
Transport, or airport security in general. We don't believe they're
acting in the best interests of passengers. We suspect their actions are
the result of politicians and government appointees making decisions
based on their concerns about the security of their own careers if they
don't act tough on terror, and capitulating to public demands that
"something must be done."
In this final statement, I promised to discuss the broader societal
harms of post-9/11 airport security. This loss of trust -- in both
airport security and counterterrorism policies in general -- is the
first harm. Trust is fundamental to society. There is an enormous amount
written about this; high-trust societies are simply happier and more
prosperous than low-trust societies. Trust is essential for both free
markets and democracy. This is why open-government laws are so
important; trust requires government transparency. The secret policies
implemented by airport security harm society because of their very secrecy.
The humiliation, the dehumanisation and the privacy violations are also
harms. That Mr Hawley dismisses these as mere "costs in convenience"
demonstrates how out-of-touch the TSA is from the people it claims to be
protecting. Additionally, there's actual physical harm: the radiation
from full-body scanners still not publicly tested for safety; and the
mental harm suffered by both abuse survivors and children: the things
screeners tell them as they touch their bodies are uncomfortably similar
to what child molesters say.
In 2004, the average extra waiting time due to TSA procedures was 19.5
minutes per person. That's a total economic loss -- in America -- of $10
billion per year, more than the TSA's entire budget. The increased
automobile deaths due to people deciding to drive instead of fly is 500
per year. Both of these numbers are for America only, and by themselves
demonstrate that post-9/11 airport security has done more harm than good.
The current TSA measures create an even greater harm: loss of liberty.
Airports are effectively rights-free zones. Security officers have
enormous power over you as a passenger. You have limited rights to
refuse a search. Your possessions can be confiscated. You cannot make
jokes, or wear clothing, that airport security does not approve of. You
cannot travel anonymously. (Remember when we would mock Soviet-style
"show me your papers" societies? That we've become inured to the very
practice is a harm.) And if you're on a certain secret list, you cannot
fly, and you enter a Kafkaesque world where you cannot face your
accuser, protest your innocence, clear your name, or even get
confirmation from the government that someone, somewhere, has judged you
guilty. These police powers would be illegal anywhere but in an airport,
and we are all harmed -- individually and collectively -- by their
existence.
In his first statement, Mr Hawley related a quote predicting "blood
running in the aisles" if small scissors and tools were allowed on
planes. That was said by Corey Caldwell, an Association of Flight
Attendants spokesman, in 2005. It was not the statement of someone who
is thinking rationally about airport security; it was the voice of
irrational fear.
Increased fear is the final harm, and its effects are both emotional and
physical. By sowing mistrust, by stripping us of our privacy -- and in
many cases our dignity -- by taking away our rights, by subjecting us to
arbitrary and irrational rules, and by constantly reminding us that this
is the only thing between us and death by the hands of terrorists, the
TSA and its ilk are sowing fear. And by doing so, they are playing
directly into the terrorists' hands.
The goal of terrorism is not to crash planes, or even to kill people;
the goal of terrorism is to cause terror. Liquid bombs, PETN, planes as
missiles: these are all tactics designed to cause terror by killing
innocents. But terrorists can only do so much. They cannot take away our
freedoms. They cannot reduce our liberties. They cannot, by themselves,
cause that much terror. It's our reaction to terrorism that determines
whether or not their actions are ultimately successful. That we allow
governments to do these things to us -- to effectively do the
terrorists' job for them -- is the greatest harm of all.
Return airport security checkpoints to pre-9/11 levels. Get rid of
everything that isn't needed to protect against random amateur
terrorists and won't work against professional al-Qaeda plots. Take the
savings thus earned and invest them in investigation, intelligence, and
emergency response: security outside the airport, security that does not
require us to play guessing games about plots. Recognise that 100%
safety is impossible, and also that terrorism is not an "existential
threat" to our way of life. Respond to terrorism not with fear but with
indomitability. Refuse to be terrorized.
Here's the whole "Economist" debate.
http://www.economist.com/debate/days/view/824
No-fly list.:
http://www.cbsnews.com/8301-505245_162-57370298/ap-exclusive-us-no-fly-list-doubles-in-1-year/
or http://tinyurl.com/7cehxpv
Chertoff's lobbying activities.
http://www.usatoday.com/news/washington/2010-11-22-scanner-lobby_N.htm
http://www.huffingtonpost.com/2010/11/23/fear_pays_chertoff_n_787711.html or
http://tinyurl.com/2dw5kde
Cupcake incident.
http://www.thebostonchannel.com/news/30062442/detail.html
Toy gun.
http://www.huffingtonpost.com/2011/01/28/toy-firearm-gets-banned-f_n_815423.html
or http://tinyurl.com/6a4egbj
http://travel.usatoday.com/flights/post/2011/01/gatwick-toy-gun/140647/1
or http://tinyurl.com/6qh97nz
Purse incident.
http://articles.cnn.com/2011-12-02/travel/travel_air-passenger-gun-purse_1_purses-airport-security-security-risk
or http://tinyurl.com/78kvnsl
http://news.bbc.co.uk/1/hi/england/london/7431640.stm
Plastic lightsaber:
http://www.salon.com/2011/12/22/hand_over_the_fork_sir/singleton/
Demands that "something must be done."
http://www.schneier.com/essay-304.html
Trust:
http://www.schneier.com/lo.html
Full-body scanners and radiation.
http://www.propublica.org/article/scientists-cast-doubt-on-tsa-tests-of-full-body-scanners
or http://tinyurl.com/68unspe
Effects of enhanced pat downs on abuse survivors:
http://jezebel.com/5693483/what-the-tsa-screenings-mean-for-sexual-assault-survivors
or http://tinyurl.com/2358do6
http://www.csmonitor.com/USA/Society/2010/1124/For-sexual-crime-victims-TSA-pat-downs-can-be-re-traumatizing
or http://tinyurl.com/25yjqht
http://healthjournalistblog.com/tsa-manhandling-meet-criteria-for-sexual-predation/
or http://tinyurl.com/25p27bf
The TSA emulates child predators.
http://www.rawstory.com/rs/2010/12/01/airport-patdowns-grooming-children-sex-predators-abuse-expert/
or http://tinyurl.com/3vd3z8u
Extra waiting time caused by the TSA.
http://books.google.com/books?hl=en&lr=&id=tzQobMX-nNAC&oi=fnd&pg=PA48&dq=treverton+adams+dertouzous&ots=wFg0coqVoq&sig=BVKG618XzKocEHPn2KEeRCXtI6Q#v=onepage&q&f=false
or http://tinyurl.com/7be86ee
http://www.amazon.com/Terrorism-Economic-Development-Political-Openness/dp/0521887585
or http://tinyurl.com/7j4tgq5
Excess deaths caused by the TSA.
http://www.amazon.com/Terror-Security-Money-Balancing-Benefits/dp/0199795762
or http://tinyurl.com/7dtjjc7
Blalock, Garrick, Vrinda Kadiyali, and Daniel H. Simon. 2007. The Impact
of Post-9/11 Airport Security Measures on the Demand for Air Travel.
Journal of Law and Economics 50(4) November: 731755.
Personal story of someone on the no-fly list.
http://www.nytimes.com/2010/06/16/world/middleeast/16yemen.html
Quote about small knives and scissors.
http://news.bbc.co.uk/2/hi/4487162.stm
Investigation, intelligence, and emergency response:
http://www.schneier.com/essay-292.html
Terrorism is not an "existential threat."
http://www.foreignaffairs.com/articles/66186/john-mueller-and-mark-g-stewart/hardly-existential
or http://tinyurl.com/yzrjwac
Refuse to be terrorized:
http://www.schneier.com/essay-292.html
BoingBoing on the debate:
http://boingboing.net/2012/03/29/bruce-schneier-hands-former-ts.html
** *** ***** ******* *********** *************
Congressional Testimony on the TSA
I was supposed to testify on March 26 about the TSA in front of the
House Committee on Oversight and Government Reform. I was informally
invited a couple of weeks previous, and formally invited the Tuesday before.
The hearing will examine the successes and challenges associated
with Advanced Imaging Technology (AIT), the Screening of
Passengers by Observation Techniques (SPOT) program, the
Transportation Worker Credential Card (TWIC), and other security
initiatives administered by the TSA.
On the Friday before, at the request of the TSA, I was removed from the
witness list. The excuse was that I am involved in a lawsuit against
the TSA, trying to get them to suspend their full-body scanner program.
But it's pretty clear that the TSA is afraid of public testimony on
the topic, and especially of being challenged in front of Congress.
They want to control the story, and it's easier for them to do that if
I'm not sitting next to them pointing out all the holes in their
position. Unfortunately, the committee went along with them.
The committee said it would try to invite me back for another hearing,
but with my busy schedule, I don't know if I will be able to make it.
And it would be far less effective for me to testify without forcing the
TSA to respond to my points.
I was there in spirit, though. The title of the hearing was "TSA
Oversight Part III: Effective Security or Security Theater?"
http://oversight.house.gov/hearing/tsa-oversight-part-iii-effective-security-or-security-theater/
or http://tinyurl.com/cmy5mpj
EPIC lawsuit:
http://epic.org/privacy/body_scanners/epic_v_dhs_suspension_of_body.html
or http://tinyurl.com/28myaxv
They tried to pull the same thing last year and it failed -- video at
the 10:50 mark.
http://cnsnews.com/news/article/tsa-skips-oversight-hearing-tsa-full-body-scanners-then-shows-late
or http://tinyurl.com/6qjo5ce
http://www.youtube.com/watch?v=7jW3-mUJWpY&t=10m50s
** *** ***** ******* *********** *************
News
The U.S. military has a non-lethal heat ray. No details on what
"non-lethal" means in this context.
http://pda.physorg.com/news/2012-03-military-unveils-non-lethal-ray-weapon.html
or http://tinyurl.com/7yk9xhs
Here's an older article no the same topic.
http://www.popsci.com/scitech/article/2003-04/shoot-not-kill
Jon Callas talks about BitCoin's security model, and how susceptible it
would be to a Goldfinger-style attack (destroy everyone else's BitCoins).
http://lists.randombit.net/pipermail/cryptography/2011-July/001038.html
or http://tinyurl.com/7ft85g2
Australian security theater at airports. I like this quote: "When you
add the body scanners, the ritual humiliation of old ladies with
knitting needles and the farcical air marshals, it all adds up to
billions of dollars to prevent what? A politician being called soft on
terror, that's what," he said.
http://www.couriermail.com.au/news/airport-police-are-just-for-show/story-e6freon6-1226294310591
or http://tinyurl.com/7p9zx5z
Avi Rubin has a TEDx talk on hacking various computer devices: medical
devices, automobiles, police radios, smart phones, etc.
http://www.youtube.com/watch?feature=player_embedded&v=metkEeZvHTg
"Empirical Analysis of Data Breach Litigation," Sasha Romanosky, David
Hoffman, and Alessandro Acquisti.
http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1986461
Last month was the 2012 SHARCS (Special-Purpose Hardware for Attacking
Cryptographic Systems) conference. The presentations are online.
http://2012.sharcs.org/index.html
http://2012.sharcs.org/record.pdf
Normally I just delete these as spam, but this Summer School in
Cryptography and Software Security at Penn State for graduate students
1) looks interesting, and 2) has some scholarship money available.
http://cpss2012.cse.psu.edu
XRY forensics tool against smart phones.
http://www.schneier.com/blog/archives/2012/04/law_enforcement.html
The original news story has been debunked.
Paul Ceglia's lawsuit against Facebook is fascinating, but that's not
the point of this news entry. As part of the case, there are
allegations that documents and e-mails have been electronically forged.
I found this story about the forensics done on Ceglia's computer to be
interesting.
http://m.wired.com/threatlevel/2012/03/facebook-ownership-forensics/
Symantec deliberately "lost" a bunch of smart phones with tracking
software on them, just to see what would happen. "Some 43 percent of
finders clicked on an app labeled 'online banking.' And 53 percent
clicked on a filed named 'HR salaries.' A file named 'saved passwords'
was opened by 57 percent of finders. Social networking tools and
personal e-mail were checked by 60 percent. And a folder labeled
'private photos' tempted 72 percent."
http://digitallife.today.msnbc.msn.com/_news/2012/03/08/10595092-exclusive-the-lost-cell-phone-project-and-the-dark-things-it-says-about-us
or http://tinyurl.com/75k3j4o
http://www.symantec.com/content/en/us/about/presskits/b-symantec-smartphone-honey-stick-project.en-us.pdf
or http://tinyurl.com/7l3e99j
Good article on the current battle for Internet governance.
http://www.vanityfair.com/culture/2012/05/internet-regulation-war-sopa-pipa-defcon-hacking
or http://tinyurl.com/7268yjv
This is the most intelligent thing I've read about the JetBlue incident
where a pilot had a mental breakdown in the cockpit.
http://articles.boston.com/2012-04-02/opinion/31269352_1_jetblue-flight-attendant-steven-slater-cockpit
or http://tinyurl.com/7g7z5od
Good article on Helen Nissenbaum, privacy, and the Federal Trade Commission.
http://www.theatlantic.com/technology/archive/2012/03/the-philosopher-whose-fingerprints-are-all-over-the-ftcs-new-approach-to-privacy/254365/
or http://tinyurl.com/d23482a
James Randi talks about magicians and the security mindset. Okay, so he
doesn't use that term. But he explains how a magician's inherent
ability to detect deception can be useful to science.
http://www.wired.com/wiredscience/2012/03/opinion-randi-magic-scientists/ or
http://tinyurl.com/7g4ka6b
Here's my essay on the security mindset.
http://www.schneier.com/blog/archives/2008/03/the_security_mi_1.html
The National Academies Press has published "Crisis Standards of Care: A
Systems Framework for Catastrophic Disaster Response."
http://www.schneier.com/blog/archives/2012/04/a_systems_frame.html
The "New York Times" tries to make sense of the TSA's policies on
computers. Why do you have to take your tiny laptop out of your bag,
but not your iPad? Their conclusion: security theater.
http://travel.nytimes.com/2012/04/08/travel/the-mystery-of-the-flying-laptop.html
or http://tinyurl.com/8ymw8yz
Good article debunking the myth that young people don't care about
privacy on the Internet.
http://www.pbs.org/mediashift/2012/04/online-privacy-kids-know-more-than-you-think-093.html
or http://tinyurl.com/ceab6t8
Usually I don't bother posting random stories about dumb or inconsistent
airport security measures. But this one -- a Heathrow Airport security
story about trousers -- is particularly interesting:
http://jackofkent.com/2012/04/my-trousers-and-airport-security/
I read "Raise the Crime Rate" a couple of months ago, and I'm still not
sure what I think about it. It's definitely one of the most
thought-provoking essays I've read this year. The author argues that
the only moral thing for the U.S. to do is to accept a slight rise in
the crime rate while vastly reducing the number of people incarcerated.
While I might not agree with his conclusion -- as I said above, I'm
not sure whether I do or I don't -- it's very much the sort of trade-off
I talk about in "Liars and Outliers." And Steven Pinker has an
extensive argument about violent crime in modern society that he makes
in "The Better Angels of our Nature."
http://nplusonemag.com/raise-the-crime-rate
Interesting video of Brian Snow speaking from last November. (Brian
used to be the Technical Director of NSA's Information Assurance
Directorate.) About a year and a half ago, I complained that his words
were being used to sow cyber-fear. This talk -- about 30 minutes -- is
a better reflection of what he really thinks.
http://www.synaptic-labs.com/resources/streaming-videos/synaptic-labs-2012-annual-reports-video-series.html#a
or http://tinyurl.com/75fyozc
My original complaint.
http://www.schneier.com/blog/archives/2010/12/brian_snow_sows.html
Disguising Tor traffic as Skype video calls, to prevent national
firewalls from blocking it.
http://www.schneier.com/blog/archives/2012/04/disguising_tor.html
** *** ***** ******* *********** *************
Bomb Threats As a Denial-of-Service Attack
The University of Pittsburgh has been the recipient of over 80 bomb
threats in the past two months (over 30 during the last week). Each
time, the university evacuates the threatened building, searches it top
to bottom -- one of the threatened buildings is the 42-story Cathedral
of Learning -- finds nothing, and eventually resumes classes. This
seems to be nothing more than a very effective denial-of-service attack.
Police have no leads. The threats started out as handwritten messages
on bathroom walls, but are now being sent via e-mail and anonymous
remailers.
The University is implementing some pretty annoying security theater in
response:
To enter secured buildings, we all will need to present a
University of Pittsburgh ID card. It is important to understand
that book bags, backpacks and packages will not be allowed. There
will be single entrances to buildings so there will be longer
waiting times to get into the buildings. In addition,
non-University of Pittsburgh residents will not be allowed in the
residence halls.
I can't see how this will help, but what else can the University do?
Their incentives are such that they're stuck overreacting. If they
ignore the threats and they're wrong, people will be fired. If they
overreact to the threats and they're wrong, they'll be forgiven.
There's no incentive to do an actual cost-benefit analysis of the
security measures.
For the attacker, though, the cost-benefit payoff is enormous. E-mails
are cheap, and the response they induce is very expensive.
If you have any information about the bomb threatener, contact the FBI.
There's a $50,000 reward waiting for you. For the university, paying
that would be a bargain.
http://www.npr.org/2012/04/11/150439648/spate-of-bomb-threats-annoys-pittsburgh-students?ft=1&f=1001
or http://tinyurl.com/7yxresd
http://www.post-gazette.com/stories/local/neighborhoods-city/experts-say-threatening-emails-are-virtually-impossible-to-trace-630118/
or http://tinyurl.com/86cnpyf
The individual threats:
http://stopthepittbombthreats.blogspot.com/
https://docs.google.com/spreadsheet/lv?key=0AlvhxmKEu6UpdGZURVFqRTc2NENqVGp3QWxUZ1hOU3c&toomany=true#gid=2
or http://tinyurl.com/77xtbu6
University and police reactions:
http://www.police.pitt.edu/
http://www.pitt.edu/news2012/hickton.pdf
** *** ***** ******* *********** *************
Can the NSA Break AES?
In an excellent article in "Wired," James Bamford talks about the NSA's
codebreaking capability.
According to another top official also involved with the program,
the NSA made an enormous breakthrough several years ago in its
ability to cryptanalyze, or break, unfathomably complex encryption
systems employed by not only governments around the world but also
many average computer users in the US. The upshot, according to
this official: "Everybody's a target; everybody with communication
is a target."
Bamford has been writing about the NSA for decades, and people tell him
all sorts of confidential things. Reading the above, the obvious
question to ask is: can the NSA break AES?
My guess is that they can't. That is, they don't have a cryptanalytic
attack against the AES algorithm that allows them to recover a key from
known or chosen ciphertext with a reasonable time and memory complexity.
I believe that what the "top official" was referring to is attacks
that focus on the implementation and bypass the encryption algorithm:
side-channel attacks, attacks against the key generation systems (either
exploiting bad random number generators or sloppy password creation
habits), attacks that target the endpoints of the communication system
and not the wire, attacks that exploit key leakage, attacks against
buggy implementations of the algorithm, and so on. These attacks are
likely to be much more effective against computer encryption.
Another option is that the NSA has built dedicated hardware capable of
factoring 1024-bit numbers. There's quite a lot of RSA-1024 out there,
so that would be a fruitful project. So, maybe.
http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/all/1
The NSA denies everything.
http://www.wired.com/threatlevel/2012/03/nsa-denies-wired/
** *** ***** ******* *********** *************
Rare Spanish Enigma Machine
This is a neat story:
A pair of rare Enigma machines used in the Spanish Civil War have
been given to the head of GCHQ, Britain's communications
intelligence agency. The machines -- only recently discovered in
Spain -- fill in a missing chapter in the history of British
code-breaking, paving the way for crucial successes in World War
II.
Fun paragraphs:
A non-commissioned officer found the machines almost by chance,
only a few years ago, in a secret room at the Spanish Ministry of
Defence in Madrid.
"Nobody entered there because it was very secret," says Felix
Sanz, the director of Spain's intelligence service.
"And one day somebody said 'Well if it is so secret, perhaps there
is something secret inside.' They entered and saw a small office
where all the encryption was produced during not only the civil
war but in the years right afterwards."
http://www.bbc.co.uk/news/magazine-17486464
Blog comments from someone actually involved in the process:
http://www.schneier.com/blog/archives/2012/03/rare_spanish_en.html#c729877
or http://tinyurl.com/78yqovp
http://www.schneier.com/blog/archives/2012/03/rare_spanish_en.html#c730641
or http://tinyurl.com/7hgyfke
** *** ***** ******* *********** *************
Schneier News
Liars and Outliers: IT World published an excerpt from Chapter 4.
http://www.itworld.com/it-managementstrategy/259124/securitys-hidden-tax-takes-big-cut
or http://tinyurl.com/85flhrd
The link below is not a video of my talk at the RSA Conference earlier
this year. This is a 16-minute version of that talk -- TED-like -- that
the conference filmed the day after for the purpose of putting it on the
Internet.
http://www.youtube.com/watch?v=SrjgXHAYvxk
I'll be speaking at InfoShare in Gdansk, Poland, April 19-20.
http://infoshare.pl/
I'll be speaking to the New Zealand Internet Task Force in Wellington,
New Zealand, on May 1.
http://internetnz.net.nz/news/media-releases/2012/World-renowned-security-technologist-bound-New-Zealand
I'll be speaking at Identity Conference 2012 in Wellington, New Zealand,
also on May 1.
http://www.identityconference.victoria.ac.nz/
I'll be speaking at the Privacy Forum in Wellington, New Zealand on May 2.
http://privacy.org.nz/assets/Files/Privacy-forum/Privacy-Forum-Programme-2012-FINAL.pdf
** *** ***** ******* *********** *************
Buying Exploits on the Grey Market
A Forbes article talks about legitimate companies buying zero-day
exploits, including the fact that "an undisclosed U.S. government
contractor recently paid $250,000 for an iOS exploit."
The price goes up if the hack is exclusive, works on the latest
version of the software, and is unknown to the developer of that
particular software. Also, more popular software results in a
higher payout. Sometimes, the money is paid in installments, which
keep coming as long as the hack does not get patched by the
original software developer.
Yes, I know that vendors will pay bounties for exploits. And I'm sure
there are a lot of government agencies around the world who want
zero-day exploits for both espionage and cyber-weapons. But I just
don't see that much value in buying an exploit from random hackers
around the world.
These things only have value until they're patched, and a known exploit
-- even if it is just known by the seller -- is much more likely to get
patched. I can much more easily see a criminal organization deciding
that the exploit has significant value before that happens. Government
agencies are playing a much longer game.
And I would expect that most governments have their own hackers who are
finding their own exploits. One, cheaper. And two, only known within
that government.
http://www.forbes.com/sites/andygreenberg/2012/03/23/shopping-for-zero-days-an-price-list-for-hackers-secret-software-exploits/
or http://tinyurl.com/87cldtg
http://www.zdnet.com/blog/security/us-government-pays-250000-for-ios-exploit/11044
or http://tinyurl.com/854qawl
** *** ***** ******* *********** *************
Hacking Critical Infrastructure
An otherwise uninteresting article on Internet threats to public
infrastructure contains this paragraph:
At a closed-door briefing, the senators were shown how a power
company employee could derail the New York City electrical grid by
clicking on an e-mail attachment sent by a hacker, and how an
attack during a heat wave could have a cascading impact that would
lead to deaths and cost the nation billions of dollars.
Why isn't the obvious solution to this to take those critical electrical
grid computers off the public Internet?
http://www.nytimes.com/2012/03/14/us/new-interest-in-hacking-as-threat-to-us-security.html
or http://tinyurl.com/85g677y
** *** ***** ******* *********** *************
Since 1998, CRYPTO-GRAM has been a free monthly newsletter providing
summaries, analyses, insights, and commentaries on security: computer
and otherwise. You can subscribe, unsubscribe, or change your address on
the Web at <http://www.schneier.com/crypto-gram.html>. Back issues are
also available at that URL.
Please feel free to forward CRYPTO-GRAM, in whole or in part, to
colleagues and friends who will find it valuable. Permission is also
granted to reprint CRYPTO-GRAM, as long as it is reprinted in its entirety.
CRYPTO-GRAM is written by Bruce Schneier. Schneier is the author of the
best sellers "Schneier on Security," "Beyond Fear," "Secrets and Lies,"
and "Applied Cryptography," and an inventor of the Blowfish, Twofish,
Threefish, Helix, Phelix, and Skein algorithms. He is the Chief Security
Technology Officer of BT BCSG, and is on the Board of Directors of the
Electronic Privacy Information Center (EPIC). He is a frequent writer
and lecturer on security topics. See <http://www.schneier.com>.
Crypto-Gram is a personal newsletter. Opinions expressed are not
necessarily those of BT.
Copyright (c) 2012 by Bruce Schneier.
** *** ***** ******* *********** *************
To unsubscribe, click this link:
http://listserv.modwest.com/cgi-bin/wa?TICKET=NzM0NjM3IGFyY2hpdmVATUFJTC1BUkNISVZFLkNPTSBDUllQVE8tR1JBTS1MSVNUIAEwUkGm6V9e&c=SIGNOFF