When the going gets weird, the weird turn pro. - Hunter S. Thompson

Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

18 October 2008

...Guns, bombs, three-ounce tubes of anthrax, Crest toothpaste, nail clippers, Snapple, and so on

If I were a terrorist, and I’m not, but if I were a terrorist—a frosty, tough-like-Chuck-Norris terrorist, say a C-title jihadist with Hezbollah or, more likely, a donkey-work operative with the Judean People’s Front—I would not do what I did in the bathroom of the Minneapolis–St. Paul International Airport, which was to place myself in front of a sink in open view of the male American flying public and ostentatiously rip up a sheaf of counterfeit boarding passes that had been created for me by a frenetic and acerbic security expert named Bruce Schnei­er. He had made these boarding passes in his sophisticated underground forgery works, which consists of a Sony Vaio laptop and an HP LaserJet printer, in order to prove that the Transportation Security Administration, which is meant to protect American aviation from al-Qaeda, represents an egregious waste of tax dollars, dollars that could otherwise be used to catch terrorists before they arrive at the Minneapolis–St. Paul International Airport, by which time it is, generally speaking, too late.

I could have ripped up these counterfeit boarding passes in the privacy of a toilet stall, but I chose not to, partly because this was the renowned Senator Larry Craig Memorial Wide-Stance Bathroom, and since the commencement of the Global War on Terror this particular bathroom has been patrolled by security officials trying to protect it from gay sex, and partly because I wanted to see whether my fellow passengers would report me to the TSA for acting suspiciously in a public bathroom. No one did, thus thwarting, yet again, my plans to get arrested, or at least be the recipient of a thorough sweating by the FBI, for dubious behavior in a large American airport. Suspicious that the measures put in place after the attacks of September 11 to prevent further such attacks are almost entirely for show—security theater is the term of art—I have for some time now been testing, in modest ways, their effectiveness. Because the TSA’s security regimen seems to be mainly thing-based—most of its 44,500 airport officers are assigned to truffle through carry-on bags for things like guns, bombs, three-ounce tubes of anthrax, Crest toothpaste, nail clippers, Snapple, and so on—I focused my efforts on bringing bad things through security in many different airports, primarily my home airport, Washington’s Reagan National, the one situated approximately 17 feet from the Pentagon, but also in Los Angeles, New York, Miami, Chicago, and at the Wilkes-Barre/Scranton International Airport (which is where I came closest to arousing at least a modest level of suspicion, receiving a symbolic pat-down—all frisks that avoid the sensitive regions are by definition symbolic—and one question about the presence of a Leatherman Multi-Tool in my pocket; said Leatherman was confiscated and is now, I hope, living with the loving family of a TSA employee).
The Things He Carried (Jeffrey Goldberg, The Atlantic, November 2008)

08 December 2007

Cheery thought for the day

“As technology becomes more complicated, society’s experts become more specialized. And in almost every area, those with the expertise to build society’s infrastructure also have the expertise to destroy it. Ask any doctor how to poison someone untraceably, and he can tell you. Ask someone who works in aircraft maintenance how to drop a 747 out of the sky without getting caught, and he’ll know. Now ask any Internet security professional how to take down the Internet, permanently. I’ve heard about half a dozen different ways, and I know I haven’t exhausted the possibilities.”

- Bruce Schneier, from Secrets and Lies

04 November 2007

Bruce Schneier: The War on the Unexpected

We've opened up a new front on the war on terror. It's an attack on the unique, the unorthodox, the unexpected; it's a war on different. If you act different, you might find yourself investigated, questioned, and even arrested -- even if you did nothing wrong, and had no intention of doing anything wrong. The problem is a combination of citizen informants and a CYA attitude among police that results in a knee-jerk escalation of reported threats.

This isn't the way counterterrorism is supposed to work, but it's happening everywhere. It's a result of our relentless campaign to convince ordinary citizens that they're the front line of terrorism defense. "If you see something, say something" is how the ads read in the New York City subways. "If you suspect something, report it" urges another ad campaign in Manchester, UK. The Michigan State Police have a seven-minute video. Administration officials from then-attorney general John Ashcroft to DHS Secretary Michael Chertoff to President Bush have asked us all to report any suspicious activity.

The problem is that ordinary citizens don't know what a real terrorist threat looks like. They can't tell the difference between a bomb and a tape dispenser, electronic name badge, CD player, bat detector, or a trash sculpture; or the difference between terrorist plotters and imams, musicians, or architects. All they know is that something makes them uneasy, usually based on fear, media hype, or just something being different.

Even worse: after someone reports a "terrorist threat," the whole system is biased towards escalation and CYA instead of a more realistic threat assessment.

Schneier on Security: The War on the Unexpected (1 November 2007)



Updated and bumped because Doc has responded (extensively) at They Rode On. Short version: "Schneier can kiss my sweet ass."

More detailed version here: Flag on the play: Schneier gets it all wrong (They Rode On)

31 August 2007

A little Quechup on your spam?

This must be some kind of new land speed record for getting spammed.

Last month, I set up a private, "secure" e-mail account, and just gave the address to friends and key business contacts. It's been working like a charm - the account works beautifully with the iPhone, and I know that every piece of mail that arrives is high-value, because I've given the address to nobody outside a tight little circle of privileged contacts.

Today, the first piece of spam arrived.

A trusted friend had included my secure e-mail in a mailshot promoting a project. No problem there; it's not a state secret, I'm just trying to keep it safe for useful communications... wish he had bcc'ed me, though.

Everyone on the mailshot who had a webmail account that autoharvests e-mail addresses for their contacts suddenly had my e-mail address. Gmail does this; Yahoo does it if asked; probably others do, too.

OK, still not a real problem there.

Then a woman I know slightly, who was on the trusted friend's mailshot (still following me?) apparently signed up for Quechup, a new social-networking site with a very underhanded modus operandi:

When you sign up, Quechup asks, as many social networking sites do, if you'd like to check your address book to see how many of your friends are already on the service (something that can be done safely at sites like LinkedIn and Facebook.)

Then guess what happens. It spams *everybody* in your freaking address book, evidently without your knowledge or consent.

Rat bastards.

I've tried to remove myself from future Quechup mailings, but with this standard of ethical behavior on their part, I'm sure my address has been sold to every Viagra spammer and Nigerian scam artist in the world by now.

27 August 2007

Vint Cerf on Internet security

Vint Cerf is vice-president and “chief internet evangelist” at Google. If the internet needs proselytisers, Mr Cerf, 64, is more than qualified – he is considered one of the architects of the worldwide web, having developed the protocols that govern it.

At the weekend the American computer scientist gave warning that poor security and poor software design were undermining the reliability of the internet. He said that he was worried about the robustness of computer software and the exposure of the network to hacks that alter the website addressing system.

Business big shot: Vint Cerf (TimesOnline, 27 August 2007)

29 June 2007

Cyberwar

China, security experts believe, has long probed United States networks. According to a 2007 Defense Department annual report to Congress, China’s military has invested heavily in electronic countermeasures and defenses against attack, and concepts like “computer network attack, computer network defense and computer network exploitation.”

According to the report, the Chinese Army sees computer network operations “as critical to achieving ‘electromagnetic dominance’ ” — whatever that is — early in a conflict.

"When Computers Attack," New York Times, 24 June 2007

In re "whatever that is," see:

30 January 2007

The online malware market

Microsoft says its new operating system, Windows Vista, is the most secure in the company’s history. Now the bounty hunters will test just how secure it is.

When its predecessor, Windows XP, was released five years ago, software bugs were typically hunted by hackers for fame and glory, not financial reward. But now software vulnerabilities — as with stolen credit-card numbers and spammable e-mail addresses — carry real financial value. They are commonly bought, sold and traded online, both by legitimate security companies, which say they are providing a service, and by nefarious hackers and thieves.
A Lively Market, Legal and Not, for Software Bugs (New York Times, 30 Jan 2007)

08 December 2006

Okay, this is downright creepy

Is your dream job "professional eavesdropper?"

Meet Snoopstick:
SnoopStick is a USB flash drive type device that allows you to monitor what your kids, employees, or anyone using your computer is doing while on the Internet. And, you can monitor them live, in real time, from anywhere in the world.

Simply plug the SnoopStick into the computer you want to monitor. Then run the setup program to install the SnoopStick monitoring components on the computer. The whole process takes less then 60 seconds.

The SnoopStick monitoring components are completely hidden, and there are no telltale signs that the computer is being monitored.

You can then unplug the SnoopStick and take it with you anywhere you go. No bigger than your thumb and less then 1/4" thick, you can carry it in your pocket, purse, or on your keychain.
I'm tempted to pick up one of these just to see whether the security measures I've set up on our machines would, as designed, lock something like this out. (The product, of course, takes advantage of the shoddy security features of Microsoft Windows; good luck getting anything like this to run on a Macintosh... heh.)

02 December 2006

Cracking the BlackBerry

...or "Hacking the CrackBerry," etc.

The security model of that BlackBerry on your hip isn't holding up very well to third-party scrutiny.

According to a white paper by John O'Connor, a researcher on Symantec's security response team, hackers can pay $100 for an API developer key that can open doors to the theft of data from Research in Motion's BlackBerry devices.

O'Connor's paper was briefly posted -- and quickly yanked -- from a blog entry discussing the future of the BlackBerry device. It is not yet clear why Symantec pulled the paper (the rumor mill says it's being saved for a conference presentation) but a quick peek at the findings suggests there might have been some external pressure involved.

eWeek Security Watch: Cracking the Blackberry with a $100 Key

Related: Symantec Weblog: Hacking the BlackBerry