If I were a terrorist, and I’m not, but if I were a terrorist—a frosty, tough-like-Chuck-Norris terrorist, say a C-title jihadist with Hezbollah or, more likely, a donkey-work operative with the Judean People’s Front—I would not do what I did in the bathroom of the Minneapolis–St. Paul International Airport, which was to place myself in front of a sink in open view of the male American flying public and ostentatiously rip up a sheaf of counterfeit boarding passes that had been created for me by a frenetic and acerbic security expert named Bruce Schneier. He had made these boarding passes in his sophisticated underground forgery works, which consists of a Sony Vaio laptop and an HP LaserJet printer, in order to prove that the Transportation Security Administration, which is meant to protect American aviation from al-Qaeda, represents an egregious waste of tax dollars, dollars that could otherwise be used to catch terrorists before they arrive at the Minneapolis–St. Paul International Airport, by which time it is, generally speaking, too late.The Things He Carried (Jeffrey Goldberg, The Atlantic, November 2008)
I could have ripped up these counterfeit boarding passes in the privacy of a toilet stall, but I chose not to, partly because this was the renowned Senator Larry Craig Memorial Wide-Stance Bathroom, and since the commencement of the Global War on Terror this particular bathroom has been patrolled by security officials trying to protect it from gay sex, and partly because I wanted to see whether my fellow passengers would report me to the TSA for acting suspiciously in a public bathroom. No one did, thus thwarting, yet again, my plans to get arrested, or at least be the recipient of a thorough sweating by the FBI, for dubious behavior in a large American airport. Suspicious that the measures put in place after the attacks of September 11 to prevent further such attacks are almost entirely for show—security theater is the term of art—I have for some time now been testing, in modest ways, their effectiveness. Because the TSA’s security regimen seems to be mainly thing-based—most of its 44,500 airport officers are assigned to truffle through carry-on bags for things like guns, bombs, three-ounce tubes of anthrax, Crest toothpaste, nail clippers, Snapple, and so on—I focused my efforts on bringing bad things through security in many different airports, primarily my home airport, Washington’s Reagan National, the one situated approximately 17 feet from the Pentagon, but also in Los Angeles, New York, Miami, Chicago, and at the Wilkes-Barre/Scranton International Airport (which is where I came closest to arousing at least a modest level of suspicion, receiving a symbolic pat-down—all frisks that avoid the sensitive regions are by definition symbolic—and one question about the presence of a Leatherman Multi-Tool in my pocket; said Leatherman was confiscated and is now, I hope, living with the loving family of a TSA employee).
When the going gets weird, the weird turn pro. - Hunter S. Thompson
18 October 2008
...Guns, bombs, three-ounce tubes of anthrax, Crest toothpaste, nail clippers, Snapple, and so on
08 December 2007
Cheery thought for the day
- Bruce Schneier, from Secrets and Lies
04 November 2007
Bruce Schneier: The War on the Unexpected
Schneier on Security: The War on the Unexpected (1 November 2007)We've opened up a new front on the war on terror. It's an attack on the unique, the unorthodox, the unexpected; it's a war on different. If you act different, you might find yourself investigated, questioned, and even arrested -- even if you did nothing wrong, and had no intention of doing anything wrong. The problem is a combination of citizen informants and a CYA attitude among police that results in a knee-jerk escalation of reported threats.
This isn't the way counterterrorism is supposed to work, but it's happening everywhere. It's a result of our relentless campaign to convince ordinary citizens that they're the front line of terrorism defense. "If you see something, say something" is how the ads read in the New York City subways. "If you suspect something, report it" urges another ad campaign in Manchester, UK. The Michigan State Police have a seven-minute video. Administration officials from then-attorney general John Ashcroft to DHS Secretary Michael Chertoff to President Bush have asked us all to report any suspicious activity.The problem is that ordinary citizens don't know what a real terrorist threat looks like. They can't tell the difference between a bomb and a tape dispenser, electronic name badge, CD player, bat detector, or a trash sculpture; or the difference between terrorist plotters and imams, musicians, or architects. All they know is that something makes them uneasy, usually based on fear, media hype, or just something being different.
Even worse: after someone reports a "terrorist threat," the whole system is biased towards escalation and CYA instead of a more realistic threat assessment.
Updated and bumped because Doc has responded (extensively) at They Rode On. Short version: "Schneier can kiss my sweet ass."
More detailed version here: Flag on the play: Schneier gets it all wrong (They Rode On)
31 August 2007
A little Quechup on your spam?
Last month, I set up a private, "secure" e-mail account, and just gave the address to friends and key business contacts. It's been working like a charm - the account works beautifully with the iPhone, and I know that every piece of mail that arrives is high-value, because I've given the address to nobody outside a tight little circle of privileged contacts.
Today, the first piece of spam arrived.
A trusted friend had included my secure e-mail in a mailshot promoting a project. No problem there; it's not a state secret, I'm just trying to keep it safe for useful communications... wish he had bcc'ed me, though.
Everyone on the mailshot who had a webmail account that autoharvests e-mail addresses for their contacts suddenly had my e-mail address. Gmail does this; Yahoo does it if asked; probably others do, too.
OK, still not a real problem there.
Then a woman I know slightly, who was on the trusted friend's mailshot (still following me?) apparently signed up for Quechup, a new social-networking site with a very underhanded modus operandi:
Then guess what happens. It spams *everybody* in your freaking address book, evidently without your knowledge or consent.
27 August 2007
Vint Cerf on Internet security
Business big shot: Vint Cerf (TimesOnline, 27 August 2007)Vint Cerf is vice-president and “chief internet evangelist” at Google. If the internet needs proselytisers, Mr Cerf, 64, is more than qualified – he is considered one of the architects of the worldwide web, having developed the protocols that govern it.
At the weekend the American computer scientist gave warning that poor security and poor software design were undermining the reliability of the internet. He said that he was worried about the robustness of computer software and the exposure of the network to hacks that alter the website addressing system.
29 June 2007
Cyberwar
China, security experts believe, has long probed United States networks. According to a 2007 Defense Department annual report to Congress, China’s military has invested heavily in electronic countermeasures and defenses against attack, and concepts like “computer network attack, computer network defense and computer network exploitation.”
According to the report, the Chinese Army sees computer network operations “as critical to achieving ‘electromagnetic dominance’ ” — whatever that is — early in a conflict.
"When Computers Attack," New York Times, 24 June 2007
In re "whatever that is," see:
30 January 2007
The online malware market
Microsoft says its new operating system, Windows Vista, is the most secure in the company’s history. Now the bounty hunters will test just how secure it is.A Lively Market, Legal and Not, for Software Bugs (New York Times, 30 Jan 2007)
When its predecessor, Windows XP, was released five years ago, software bugs were typically hunted by hackers for fame and glory, not financial reward. But now software vulnerabilities — as with stolen credit-card numbers and spammable e-mail addresses — carry real financial value. They are commonly bought, sold and traded online, both by legitimate security companies, which say they are providing a service, and by nefarious hackers and thieves.
08 December 2006
Okay, this is downright creepy
Meet Snoopstick:
SnoopStick is a USB flash drive type device that allows you to monitor what your kids, employees, or anyone using your computer is doing while on the Internet. And, you can monitor them live, in real time, from anywhere in the world.I'm tempted to pick up one of these just to see whether the security measures I've set up on our machines would, as designed, lock something like this out. (The product, of course, takes advantage of the shoddy security features of Microsoft Windows; good luck getting anything like this to run on a Macintosh... heh.)
Simply plug the SnoopStick into the computer you want to monitor. Then run the setup program to install the SnoopStick monitoring components on the computer. The whole process takes less then 60 seconds.
The SnoopStick monitoring components are completely hidden, and there are no telltale signs that the computer is being monitored.
You can then unplug the SnoopStick and take it with you anywhere you go. No bigger than your thumb and less then 1/4" thick, you can carry it in your pocket, purse, or on your keychain.
02 December 2006
Cracking the BlackBerry
eWeek Security Watch: Cracking the Blackberry with a $100 KeyThe security model of that BlackBerry on your hip isn't holding up very well to third-party scrutiny.
According to a white paper by John O'Connor, a researcher on Symantec's security response team, hackers can pay $100 for an API developer key that can open doors to the theft of data from Research in Motion's BlackBerry devices.
O'Connor's paper was briefly posted -- and quickly yanked -- from a blog entry discussing the future of the BlackBerry device. It is not yet clear why Symantec pulled the paper (the rumor mill says it's being saved for a conference presentation) but a quick peek at the findings suggests there might have been some external pressure involved.
Related: Symantec Weblog: Hacking the BlackBerry