The rsync.net warrant canary

You aren’t allowed to say if you’ve received a National Security Letter. But there’s no law that says you can’t say that you haven’t received one. Thus, rsync.net has a “warrant canary”–they periodically post a cryptographically signed statement that they have not, to date, received any PATRIOT Act warrants or had any searches and seizures. If they stop updating the statement, then you can draw your own conclusions. The second of these library signs uses the same principle: “The FBI has not been here [watch closely for removal of this sign]." (Via jwz’s blog, where some commenters question whether the recent Washington Post piece by the recipient of a National Security Letter is truthful. Note that the ACLU has a lawsuit going on about this case, which I previously noted back in 2005.) ...

March 25, 2007 · 1 min

My National Security Letter Gag Order

Yesterday’s Washington Post prints a first-hand anonymous account from the head of a small ISP who received a National Security Letter from the FBI, which was an apparent abuse of authority: Three years ago, I received a national security letter (NSL) in my capacity as the president of a small Internet access and consulting business. The letter ordered me to provide sensitive information about one of my clients. There was no indication that a judge had reviewed or approved the letter, and it turned out that none had. The letter came with a gag provision that prohibited me from telling anyone, including my client, that the FBI was seeking this information. Based on the context of the demand – a context that the FBI still won’t let me discuss publicly – I suspected that the FBI was abusing its power and that the letter sought information to which the FBI was not entitled. Rather than turn over the information, I contacted lawyers at the American Civil Liberties Union, and in April 2004 I filed a lawsuit challenging the constitutionality of the NSL power. I never released the information the FBI sought, and last November the FBI decided that it no longer needs the information anyway. But the FBI still hasn’t abandoned the gag order that prevents me from disclosing my experience and concerns with the law or the national security letter that was served on my company. In fact, the government will return to court in the next few weeks to defend the gag orders that are imposed on recipients of these letters. Living under the gag order has been stressful and surreal. Under the threat of criminal prosecution, I must hide all aspects of my involvement in the case – including the mere fact that I received an NSL – from my colleagues, my family and my friends. When I meet with my attorneys I cannot tell my girlfriend where I am going or where I have been. I hide any papers related to the case in a place where she will not look. When clients and friends ask me whether I am the one challenging the constitutionality of the NSL statute, I have no choice but to look them in the eye and lie. I resent being conscripted as a secret informer for the government and being made to mislead those who are close to me, especially because I have doubts about the legitimacy of the underlying investigation.More at the Washington Post.

March 24, 2007 · 2 min

Conservatives pile on Dinesh D'Souza

Over at Sinners in the Hands of an Angry Blog, Tim Lee points us to a dogpile of conservative criticism of Dinesh D’Souza’s book, The Enemy at Home. Some choice quotes: D’Souza has written a very bad book. If one were to take his NRO apologia seriously, his dishonesty would appear to be an issue secondary to his grandiosity. But he is not to be taken seriously and his dishonesty is the primary issue. Thus in his apologia D’Souza fails to address the thesis that frames his book. His thesis, let it be remembered, is this: “The cultural left in this country is responsible for causing 9/11.” It is a thesis, he states in the very first sentence of the book, “that will seem startling at the outset.” It is startling because he is the first writer commenting on 9/11 to have tumbled to its cause. [Scott Johnson]and “When in doubt, change the subject.” I don’t really blame Dinesh D’Souza for following that cynical bit of debater’s advice. Had I written The Enemy at Home, I would be tempted to try it, too. Alas, I fear that his 6,800-word effort to stimulate, er, “civil discussion” has failed. Why? It has nothing to do with “heresy,” as D’Souza suggests. He comes much closer when he mentions “massive errors of fact or logic.” The problem with The Enemy at Home is . . . well, everything. (I put this more politely in my original review.) What I mean is that it’s not a matter of this or that argument going astray. It’s rather that D’Souza’s major premise—that “the cultural left in this country is responsible for causing 9/11”—is wildly at odds with reality. Starting out from that mistake, D’Souza takes readers on a fantastical voyage in which white is black, day is night, and a dozen jihadists plowed jetliners into skyscrapers because of Britney Spears—or maybe it was because of Hillary Clinton, America’s high divorce-rate, or its lamentable practice of tolerating homosexuals instead of stoning them to death. [Roger Kimball]More at Sinners in the Hands of an Angry Blog, including a link to the full set of criticisms. ...

March 17, 2007 · 3 min

Are you on the TSA no-fly list?

Check it out here. I’m not on the list, but my 13-year-old nephew is, due to his common last name. (Via Bruce Schneier’s Blog.)

March 14, 2007 · 1 min

Bob Hagen on botnet evolution

Bob Hagen has put up a post on the evolution of botnets at the Global Crossing blog. (BTW, I’m hoping to have future opportunity to use titles like “Where the bots are”, “The bots from Brazil”, and “The bots of summer”.) UPDATE (August 27, 2009): I’ve replaced the above link with one to the Internet Archive, since the blog post is no longer present at its original location.

March 10, 2007 · 1 min

FBI breaking the law with National Security Letters?

A Justice Department review of 293 National Security Letters issued by the FBI found 22 instances (7.5%) of apparent violations of FBI and Justice Department regulations. The FBI issued more than 19,000 National Security Letters in 2005. UPDATE: This story has now hit CNN, which has more details. The Justice Department’s inspector general says the FBI is guilty of “serious misuse” of National Security Letters and that use of them may be underreported by as much as 20%. The audit found that more than half of NSLs were used to get information about U.S. citizens. CNN reports 26 violations, of which 22 were the FBI’s fault and 4 were caused by errors by the recipients of the National Security Letters. UPDATE (March 10, 2007): FBI Director Robert Mueller and Attorney General Alberto Gonzales have acknowledged that the FBI broke the law, apologized, and promised to stop further such intrusions. Gonzales left open the possibility of criminal prosecutions against FBI agents or lawyers who misused their PATRIOT Act powers. UPDATE (June 14, 2007): An audit has discovered that the above-reported 26 violations were the tip of the iceberg. 10% of National Security Letters have been reviewed, and the total number of violations is now over 1,000. UPDATE (March 7, 2008): This year’s audit has shown that the NSL abuses continued through 2006 and that the FBI underreported to Congress the number of NSLs by more than 4,600. UPDATE (January 20, 2010): Yet further evidence of FBI abuses in collecting telephone records has been uncovered.

March 9, 2007 · 2 min

Windows, Mac, and BSD security

March 9, 2007 · 0 min

Inside the TSA

Barbara Peterson took a job as a TSA screener and has written an interesting description of her experience for Conde Nast Traveler. She blames TSA’s incompetence not on the individual screeners (who are generally doing as well as they could be hoped to under the demands of the job) but on Congress.

March 5, 2007 · 1 min

TSA continues to demonstrate incompetence

A web page on the TSA’s website for travelers “who were told you are on a Federal Government Watch List” displays evidence of being a phishing site–it’s probably not, it’s just so badly done that it looks like a hacked web site that’s submitting its details to an unrelated third party. TSA responded that “We are aware there was an issue and replaced the site. The issue has been fully addressed. We take IT responsibilities seriously. There never a vulnerability; just a small glitch." The full story may be found at Wired Blogs, which points out fifteen features that make the TSA form submission site look dangerous. Also check out this comment at Christopher Soghoian’s blog: This may be surprising to hear: I am an employee at a major airline and I just recieved an e-mail that said we now have access to the TSA no-fly list, selectee list, and cleared list. I just accessed it and found it to contain thousands of names, DOB, SSN#s, drivers licesense #’s, military ID #’s, addresses, and even home phone #’s. The TSA just made this list and all of this information readily available to thousands of employees at my airline (and probably others). I think that previously this list was only available to ticket agents, but now it is available to every employee. I find it quite disturbing that any airline employee has access to this information, and that many of the ppl on the cleared list have to give up there SSN# and other information.Nice. (Hat tip to Bruce Schneier’s blog.)

February 20, 2007 · 2 min

How IPv6 is already creating security problems

Computer Associates CEO John Swainson, the keynote speaker at last week’s CA Expo ‘07 conference in Sydney, Australia, spoke about how the deployment of IPv6 will bring unavoidable and unknown security threats. He was quoted in SC Magazine: “I don’t know what they will be but I can predict with a high degree of probability that it will happen,” he said. “This is not something you can test in the lab, it’s something that emerges through practice.” Swainson’s comments on IPv6 were part of a broader theme addressing the emerging complexities in IT infrastructure and their more complex insecurities. “We’re talking about new complexities on top of existing complexities. As networks expand to include remote device types and additional applications [they] produce a wide variety of security threats,” he said.The new Apple AirPort Extreme for 802.11n wireless networks demonstrates Swainson’s point quite vividly. The device supports IPv6, and the default setting is for the device to set up an IPv6 tunnel over the IPv4 Internet and to provide IPv6 addresses to hosts on the local network with IPv6 enabled. For those using the device as their local firewall (which I’d argue is not a great idea–it’s not really adequate to the task), while it will reject most incoming IPv4 connections, it will allow all IPv6 connections through. For those not using it as a firewall, if their actual firewall allows the IPv6 tunnel (and most firewalls allow all inbound connections out, which would allow the tunnel to be established), the tunnel then becomes a path through the firewall. That is, if you put this device on your network in its default configuration, you’ve just completely opened up your internal systems to connections from any IPv6 host–your firewall may as well not be there, from an IPv6 perspective. There is no “disable IPv6” option, but if you set the device to “Link Local” mode instead of “Tunnel” mode, it will only talk IPv6 to your internal network, not to the outside world. My own home network runs IPv4 and IPv6, including wirelessly, but I have my wireless network as a separate network off my firewall, and have IPv6 firewall rules in place. It’s my firewall that provides the tunnel to the IPv6 Internet. This means that any machines connected to my wireless network that want to communicate with machines on my wired network (like servers) need to pass traffic through the firewall to get to them. Also, as my firewall is an OpenBSD machine, it will not route (for security reasons) the 6to4 packets the Apple AirPort is using to create automatic IPv6 tunneling (though this makes IPv4-to-v6 migration even more difficult). Note that in the comments on the Apple AirPort article at Ars Technica, one commenter says “The primary reason why the situation is so bad with IPv4, is that almost the entire address space is populated. Worms and virii can easily guess neighboring addresses, and since most of those are windows machines, they make great targets.” This gives a false sense of safety to IPv6, as security researchers have already pointed out numerous ways in which worms can locate other IPv6 hosts despite the sparsely populated IP space (PDF).

February 19, 2007 · 3 min
Mastodon Verification