A marketplace for software vulnerabilities

The July 21, 2007 issue of The Economist has an article about a Swiss company that has opened a market for software vulnerabilities: Since economics, like nature, abhors a vacuum, a small industry of “security companies” has emerged to exploit the hackers’ dilemma. These outfits buy bugs from hackers (euphemistically known as “security researchers”). They then either sell them to software companies affected by the flaws, sometimes with a corrective “patch” as a sweetener, or use them for further “research”, such as looking for more significant—and therefore more lucrative—bugs on their own account. Such firms seek to act as third parties that are trusted by hacker and target alike; the idea is that they know the market and thus know the price it will bear. Often, though, neither side trusts them. Hackers complain that, if they go to such companies to try to ascertain what represents a fair price, the value of their information plummets because too many people now know about it. Software companies, meanwhile, reckon such middlemen are offered only uninteresting information. They suspect, perhaps cynically, that the good stuff is going straight to the black market.Last week, therefore, saw the launch of a service intended to make the whole process of selling bugs more transparent while giving greater rewards to hackers who do the right thing. The company behind it, a Swiss firm called WabiSabiLabi, differs from traditional security companies in that it does not buy or sell information in its own right. Instead, it provides a marketplace for such transactions. A bug-hunter can use this marketplace in one of three ways. He can offer his discovery in a straightforward auction, with the highest bidder getting exclusive rights. He can sell the bug at a fixed price to as many buyers as want it. Or he can try to sell the bug at a fixed price exclusively to one company, without going through an auction. ...

July 29, 2007 · 3 min

Asking printer manufacturers to stop spying results in Secret Service visit?

The fact that color printers print a pattern of yellow dots on all pages that indicate which printer was used, for the purposes of being able to track the identity of who has printed any page, has been known since the EFF decrypted the codes and publicized the information in 2005. Now, however, the MIT Media Lab has started a project called “Seeing Yellow” to encourage printer owners to contact the manufacturers and complain, after it has been found that those who do so get reported to the U.S. Secret Service as subversives. (There is one known case, in which someone called to ask a printer manufacturer if there was a way to turn off the “feature.”) (Via Don Lloyd at Distributed Republic.)

July 14, 2007 · 1 min

Google thinks I'm malware

While looking through multiple pages of results from a Google query that contained some operators like negations and “site:” specifications, Google was periodically failing to give results or displaying raw HTML in my browser, then ultimately came back with: Google Error We’re sorry… … but your query looks similar to automated requests from a computer virus or spyware application. To protect our users, we can’t process your request right now. ...

July 13, 2007 · 2 min

Operation Bot Roast

Yesterday, the Washington Post reported on the FBI’s “Operation Bot Roast,” which busted several criminal users of botnets: _James C. Brewer, of Arlington, Texas. He was indicted Tuesday on charges of infecting more than 10,000 computers globally, including two Chicago-area hospitals operated by the Bureau of Health Services in Cook County, Ill. The computers at the two hospitals were linked to the health care bureau’s mainframe system. They repeatedly froze or rebooted from October to December last year, resulting in delayed medical services, according to the indictment. Brewer was released on a $4,500 bond, court records show. ...

June 14, 2007 · 2 min

Microsoft's new Turing Test

Microsoft Research has partnered with Petfinder.com to come up with a new test for determining whether there’s a live human behind the keyboard or just a computer program. It’s called Asirra, Animal Species Image Recognition for Restricting Access. The method presents twelve photographs of dogs and cats from Petfinder.com (each of which has an “adopt me” link associated with it) and asks the viewer to select all of the cats. Historical Comments Einzige (2007-06-12): I definitely prefer looking at cute pictures to deciphering those frustrating CAPTCHA thingies! ...

June 12, 2007 · 1 min

The bots of summer

My two-part appearance on “The Security Catalyst” podcast last year has resulted in some media coverage of botnets this week at IT World Canada. The article, “The botnet menace–and what you can do about it,” by Joaquim P. Menezes, is more detailed than most media coverage of bots has been. He draws on both my Security Catalyst interview and my colleague Bob Hagen’s blog post on bots.

June 6, 2007 · 1 min

Spying on the Homefront

Tomorrow night on PBS’s Frontline is “Spying on the Homefront”: FRONTLINE addresses an issue of major consequence for all Americans: Is the Bush administration’s domestic war on terrorism jeopardizing our civil liberties? Reporter Hedrick Smith presents new material on how the National Security Agency’s domestic surveillance program works and examines clashing viewpoints on whether the president has violated the Foreign Intelligence Surveillance Act (FISA) and infringed on constitutional protections. In another dramatic story, the program shows how the FBI vacuumed up records on 250,000 ordinary Americans who chose Las Vegas as the destination for their Christmas-New Year’s holiday, and the subsequent revelation that the FBI has misused National Security Letters to gather information. Probing such projects as Total Information Awareness, and its little known successors, Smith discloses that even former government intelligence officials now worry that the combination of new security threats, advances in communications technologies, and radical interpretations of presidential authority may be threatening the privacy of Americans.(Via the Electronic Frontier Foundation.)

May 15, 2007 · 1 min

CALEA compliance day

Today’s the day that providers of VoIP and broadband Internet in the United States must comply with CALEA, mandating that they supply a way for law enforcement to eavesdrop on any communications carried over those mechanisms. I suspect many VoIP providers are in compliance but that fewer broadband Internet providers are, since the draft standard for CALEA for data over broadband Internet only came out in March. (And if you’d like to read the standard, it will cost you $164 for the PDF or $185 for a paper copy.) Bob Hagen at the Global Crossing blog points out some free tools that can be used to protect your privacy.

May 15, 2007 · 1 min

Banning the distribution of AACS keys is futile

AACS keys are used to encrypt the content of HD-DVDs (this is an oversimplification; see Ed Felten’s Freedom-to-Tinker blog for more detail). A particular “processing key” for AACS has recently been distributed on the Internet, with the AACS Licensing Authority issuing cease and desist orders to try to stop it. This has led to new and creative ways of distributing this 128-bit number, just as occurred with the DeCSS code for decrypting DVDs. When a cease-and-desist order went to digg, digg’s users proceeded to give diggs to many different sites, at one point leading to the entire front page of digg being full of nothing but links to pages with the AACS key. A couple of the more interesting methods include making the number into a song and displaying it with satellite photos of buildings that resemble hex digits. One individual appears to have had it tattooed on his chest. This is exactly what we saw with DeCSS, which is memorialized in Dave Touretzky’s Gallery of CSS Descramblers. This case is even more absurd, in that AACS LA is claiming ownership of a number–and a relatively short one–not because it encodes any content or algorithm, but because it’s one of potentially millions of keys assigned for use with its system. UPDATE (May 11, 2007): As this t-shirt makes clear, trying to protect against the distribution of a 128-bit number is futile when knowledge of the number can be easily distributed without using the number itself. I’d love to see AACS LA try to make a case against the marketing and sale of this shirt.

May 3, 2007 · 2 min

FBI focus on counterterrorism leads to increase in unprosecuted fraud and identity theft

With the FBI being directed to focus its attention on counterterrorism, its investigations of fraud, identity theft, civil rights violations, and crime in general have plummeted: – Overall, the number of criminal cases investigated by the FBI nationally has steadily declined. In 2005, the bureau brought slightly more than 20,000 cases to federal prosecutors, compared with about 31,000 in 2000 – a 34 percent drop. – White-collar crime investigations by the bureau have plummeted in recent years. In 2005, the FBI sent prosecutors 3,500 cases – a fraction of the more than 10,000 cases assigned to agents in 2000…. ...

April 12, 2007 · 2 min
Mastodon Verification