The economics of information security

Ross Anderson and Tyler Moore have published a nice paper that gives an overview of recent research in the economics of information security and some open questions (PDF). The paper begins with an overview of the relevance of economic factors to information security and a discussion of “foundational concepts.” The concept of misaligned incentives is described with the now-standard example of how UK and U.S. regulations took opposite positions on liability for ATM fraud is given–the UK held customers liable for loss, while the U.S. held banks liable for loss. This led to U.S. banks having incentives to make their systems secure, while UK banks had no such incentives (and the UK has now reversed its position after this led to “an epidemic of fraud”). other examples are given involving anti-virus deployment (where individuals may not have incentives to purchase software if the major benefit is preventing denial of service attacks on corporations), LoJack systems (where auto theft plummets after a threshold number of auto owners in a locality install the system), and the use of peer-to-peer networks for censorship resistance. The authors examine the economics of vulnerabilities, of privacy, of the deployment of security mechanisms including digital rights management, how regulation and certification can affect system security (and sometimes have counterintuitive adverse effects, such as Ben Edelman’s finding that TRUSTe certified sites are more likely to contain malicious content than websites as a whole). They end the paper with some open issues–attempts to develop network protocols that are “strategy-proof” to prevent cheating/free-riding/bad behavior, how network topologies have different abilities to withstand different types of attacks (and differing vulnerabilities), and how the software development process has a very high failure rate for large projects, especially in public-sector organizations (e.g., as many as 30% are death-march projects). There are lots of interesting tidbits in this paper–insurance for vulnerabilities, vulnerability markets, the efficacy of spam on stock touting, the negligible effect of music downloads on music sales, and how DRM has moved power from record labels to platform owners (with Apple being the most notable beneficiary), to name a few. (Hat tip to Bruce Schneier’s blog, where you can find links to a slide presentation that covers the highlights of this paper.)

February 13, 2007 · 2 min

I've won a Thinking Blogger award!

I’ve been awarded a Thinking Blogger award, courtesy of Larry Moran at Sandwalk: Strolling with a Skeptical Biochemist. Thanks, Larry! As per the rules of this award-meme, I must tag five other blogs that make me think: 1. Glen Whitman and Tom W. Bell at Agoraphilia 2. The Technology Liberation Front 3. Martin Geddes at Telepocalypse 4. Ed Felten at Freedom-to-Tinker 5. Kevin Carson at the Mutualist blog

February 13, 2007 · 1 min

Warner Music: we'd rather go out of business than give customers what they want

After Steve Jobs said that he’d prefer to have the iTunes store sell DRM-free music, but is forced into DRM by the music labels, Edgar Bronfman of Warner Music said that his company will have nothing to do with DRM-free music: “We advocate the continued use of DRM,” Bronfman said, adding that music deserves the same anti-piracy protections as software, TV broadcasts, video games and other forms of intellectual property. “We will not abandon DRM nor services that are successfully implementing DRM for both content and consumers."This quote appeared in an article reporting Warner’s dismal results: its fiscal first-quarter profit fell 74% because of fewer album releases and soft domestic and European sales. Its shares fell nearly 6%. The New York-based recording company said net income for the period that ended Dec. 31 declined to $18 million, or 12 cents a share, from $69 million, or 46 cents, a year earlier. Revenue fell 11% to $928 million.The competition at EMI, however, feels differently: Music label EMI Group is in talks to release a large portion of its music catalog for Web sales without technological protections against piracy that are included in most music bought over the Internet now, sources said on Thursday. … One source familiar with the matter said that EMI was in talks to release a large amount of its music in an unprotected MP3 format to various online retailers.EMI’s plans apparently include talks with Shawn Fanning’s SnoCap about releasing MP3-format music through MySpace. Which company is more likely to still be in business under the same management ten years from now?

February 9, 2007 · 2 min

McCain proposes an unfunded mandate for ISPs

Declan McCullagh at News.com reports that Sen. John McCain is preparing to hold a press conference with John Walsh of America’s Most Wanted and Miss America 2007 to announce a bill that will create a new mandate for Internet Service Providers to eavesdrop on all of their customers email and web traffic in search of child porn images. The act apparently requires ISPs to implement new technology to compare all images transmitted or received by their customers to a federal database of images (presumably via some one-way hash function, so that the database is not itself distributing child pornography), and to report any that are detected to John Walsh’s National Center for Missing and Exploited Children, a nonprofit, non-governmental organization that operates as a clearinghouse/proxy for federal and state law enforcement with Congressional mandate and federal funding. The new bill is known as the Securing Adolescents From Exploitation Online or SAFE Act, and is not to be confused with the 2003 SAFE Act (Security and Freedom Ensured), the 1997 SAFE Act (Security and Freedom through Encryption), or the 1998 SAFE Act (Safety Advancement For Employees).

February 8, 2007 · 1 min

Schoolteacher convicted on bogus charges due to malware

Connecticut substitute teacher Julie Amero faces up to 40 years in prison for “risk of injury to a minor or impairing the morals of a child” because a seventh-grade classroom computer was infected with malware. While browsing the web for information about hair styles, the browser hit a website that caused pop-ups ads for pornographic sites to pop up. Because Amero’s attorney failed to raise the issue of malware, most of a defense expert witness’s testimony was excluded from presentation to the jury, which unanimously voted for conviction. There are so many things wrong here: * The school district had let its filtering software expire, so the machine didn’t have adequate protection (and was likely unpatched for major vulnerabilities). * The police did an incompetent investigation, failing to check for malware. * The police testified, falsely, that Amero would have had to physically click on a pornographic link to get those sites to pop up. * Amero’s attorney did an incompetent job of defending her, by failing to bring up the critically important issue of malware. * And the law itself is absurd–Amero shouldn’t get 40 years in prison even if she had intentionally shown pornography to seventh graders. Lindsay Beyerstein has a good summary of the case at the Huffington Post, including links to the expert testimony that shows conclusively that malware, not Amero, was at fault. P.Z. Myers criticizes the “insane anti-porn hysteria” aspect of the case at Pharyngula. UPDATE (June 7, 2007): Julie Amero has been granted a retrial! She will get a new trial sometime in 2007. UPDATE (November 26, 2008): The state of Connecticut has finally decided to drop the charges against Amero. UPDATE (December 4, 2008): But Amero still loses her teacher’s license! ...

February 4, 2007 · 2 min

More comments on Boston lite brite fiasco

Bruce Schneier has commented on the Aqua Teen Hunger Force nonsense in Boston: Now the police look stupid, but they’re trying really not hard not to act humiliated: Governor Deval Patrick told the Associated Press: “It’s a hoax – and it’s not funny." Unfortunately, it is funny. What isn’t funny is now the Boston government is trying to prosecute the artist and the network instead of owning up to their own stupidity. The police now claim that they were “hoax” explosive devices. I don’t think you can claim they are hoax explosive devices unless they were intended to look like explosive devices, which merely a cursory look at any of them shows that they weren’t. ...

February 2, 2007 · 3 min

Boston completely losing it on Aqua Teen marketing campaign

Boston authorities have now escalated their response to the “Aqua Teen Hunger Force” movie publicity campaign, by arresting two of the men who put up magnetic lights showing the Mooninite characters Ignignokt and Err, on charges of “placing a hoax device in a way that results in panic." But this is absurd–it wasn’t a “hoax device”–they were lighted pictures of characters from a movie. It was not designed to look like anything remotely dangerous. Massachusetts Attorney General Martha Coakley said, “It had a very sinister appearance. … It had a battery behind it, and wires.” So anything with a battery and wires (like, say, an iPod) is now a threatening, sinister appearing device? Massachusetts is trying to cover its stupidity with more stupidity. Nine other cities didn’t find this remotely threatening, and nobody saw the ones in Boston as threatening for the first 2-3 weeks they were up. (For photos and my initial report, see here.)

February 1, 2007 · 1 min

Marketing campaign for Aqua Teen Hunger Force causes security scare

The strange objects that set off a scare in Boston and caused at least one of them to be blown up were magnetic lights set up by Turner Broadcasting to promote the Aqua Teen Hunger Force movie. They had been in place for weeks before being mistaken for something dangerous and causing authorities to shut down bridges and access into the Charles River. Aqua Teen Hunger Force is a usually entertaining short cartoon that appears on the Cartoon Network’s adult swim. This isn’t the first time that a movie marketing campaign has resulted in this kind of hysterical over-reaction. In April of last year, a device that played the “Mission: Impossible” theme was placed into Los Angeles Times newspaper vending machines. One of the devices in Santa Clarita had exposed wires, was mistaken for a bomb, and the L.A. County Sheriff’s Office arson squad blew it up. UPDATE: CNN has a photo of one of the Aqua Teen light boards, which depicts the Mooninite named Err (the smaller one), extending his middle finger. (Correction–it’s the bigger one, Ignignokt, in the picture above, though there are some of Err as well.) UPDATE (February 1, 2007): Here’s how an Associated Press story in the Arizona Republic described these devices: “The exact nature of the objects was not disclosed. But authorities said some looked like circuit boards or had wires hanging from them." That sounds a lot scarier than the reality, doesn’t it? It conveniently omits the fact that there’s a clear pattern of lights depicting a cartoon character. That article goes on to say “At least some of the devices resemble one of the villains on “Aqua Teen,” part of Cartoon Network’s late-night Adult Swim lineup.” Is there any evidence that any of them did not? Nine of ten cities where these devices were put in place did not have a panicked overreaction, and the one that did waited two to three weeks before jumping into a panic. Had they been actual malicious devices, their reaction would have been too late. One word of advice for future marketeers: put a label on your devices with a phone number that can be called so you can explain what you’re doing before the authorities blow up your equipment. Here’s another picture of one of the devices in place. ...

January 31, 2007 · 3 min

Nice airport security game

Here’s a nice flash game that requires you to screen airport passengers on the basis of an ever-changing set of arbitrary rules. (Via Bruce Schneier’s blog.)

January 31, 2007 · 1 min

Skeptical information and security information links sites

I’ve got a couple of websites of hierarchically organized links that I’ve maintained for quite some time, though I haven’t really worked on them much lately. I currently get more spam link submissions than genuine link submissions to each, so I’d like to request contributions of legitimate entries. One is my skeptical links site, which is fairly extensive, especially on a few topics such as Scientology, creationism, the websites of skeptical groups, and critiques of organized skepticism. The other is my security links site, which is much less extensive, but still has some useful links, mostly on security and hacking tools and security standards. Contributions are welcome–just go to the appropriate area and click the “add a site” link at the top of the page. ...

January 24, 2007 · 1 min
Mastodon Verification