The Security Catalyst podcast

I recommend Michael Santarcangelo’s “Security Catalyst” podcasts, which can be subscribed to at no charge via iTunes or Yahoo Podcasts. He’s got additional information and links related to the shows at the Security Catalyst website. Michael, who I met a few years back through a consulting engagement that was a “death-march project,” is a sharp, witty, and well-spoken advocate of and educator for good computer security.

February 18, 2006 · 1 min

Database error causes unbalanced budget

Bruce Schneier reports on how a house in Valparaiso, Indiana was incorrectly valued at $400 million due to a single-keystroke error by an “outside user” of Porter County’s appraisal records. This incorrect valuation led to an expectation of $8 million in property taxes due from that homeowner, which led to a erroneous increase of budgets and even distribution of funds. Now the Porter County Treasurer has had to ask 18 governmental units to return funds–the city of Valparaiso and Valparaiso Community School Corp. have been asked to return $2.7 million, which will leave the school system with a $200,000 budget shortfall. The number of errors here is huge–first of all, an external user shouldn’t have access to change budget data at all, let alone by a typo which caused the user to invoke “an assessment program written in 1995” which “is no longer in use, and technology officials did not know it could be accessed.” Second, there should have been checks on the data to identify anomalies like a house suddenly jumping in value to $400 million. Third, there should have been checks on the accuracy of budget numbers before the disbursement of funds. And I’m sure I’m only scratching the surface–it sounds like they’ve got some serious IT infrastructure issues.

February 17, 2006 · 1 min

The Secret FISA Court

Via Steve’s No Direction Home Page: Apparently presidential wiretapping is frowned upon–when it’s done by Clinton. Some of the reader comments are hilarious, viz.: “Any chance of Bush rolling some of this back?" “As quietly as possible (although it sometimes breaks out into the open, usually with the sound of gunfire and the death of innocents), a “shadow government” has been set up all around us my friend. It’s foundation is not the constitution, but Executive Orders, Presidential Procalamations, Secret Acts, and Emergency Powers." “This is wherein the danger lies in the precedent set by the Clinton criminal administration. God only knows who will be in power next, but there are no checks and balances anymore. This is exactly the SORT of thing I’ve been protesting all along. Libs just don’t see this!" ...

February 14, 2006 · 1 min · Einzige

Arizona porn spamming proxy abusers busted

The Federal Trade Commission today unsealed and announced its action in the U.S. District Court in Arizona against William Dugger (a/k/a Billy Johnson, d/b/a Net Everyone) of Hawaii (with a business address in Phoenix), Angelina Johnson (d/b/a Net Everyone) of Hawaii and/or Phoenix, and John Vitale (d/b/a Net Everyone) of Phoenix for sending CAN-SPAM-violating porn spam using compromised systems of uninvolved third parties. The Temporary Restraining Order announced today freezes their assets and requires their ISPs to disconnect all of their equipment from the Internet and deny them any access to it.

January 31, 2006 · 1 min

Congress banned from Wikipedia for abuses

Wikipedia has banned the IP blocks of U.S. Congress from the ability to make changes, due to repeated abuses by Congressional staffers who repeatedly engage in revert wars, blank content, engage in libelous behavior or violate WP:NPOV, WP:CIV [Wikipedia’s standards for neutral point of view and civility]. The editors from these IP ranges are rude and abrasive, immature, and show no understanding of Wikipedia policy. The editors also frequently try to whitewash the actions of certain politicians. They treat Wikipedia articles about politicians as though they own the articles, replacing community articles with their own sanctioned biographies and engaging in revert wars when other users dispute this sudden change. They also violate Wikipedia:Verifiability, by deleting verified reports, while adding flattering things about members of Congress that are unverified.A newspaper article has been written on this subject in the Lowell Sun by Evan Lehmann. A list of further details is in the Wikipedia entry on Congressional Staffer Edits. Kudos to Wikipedia for treating Congress the way it deserves to be treated.

January 31, 2006 · 1 min

New Internet consumer protection tool--SiteAdvisor.com

I’ve been using the Firefox plugin from SiteAdvisor.com for a few days, and I think it’s a great idea. They’ve searched the web, downloaded content, and submitted unique email addresses on signup forms everywhere they find them, to see what happens. They then rate each site for malicious content and the extent to which it generates spam in response to a signup. This database is then used by their browser plugin to display icons next to Google and Yahoo search results indicating whether that site is green, yellow, or red regarding the type of content downloaded, the amount of email you can expect to receive from signing up at the site, and whether it links to other sites that are problematic. Their privacy policy is good–they don’t keep a record of who goes to what site. One feature I’d like to see them add is the ability to not make queries for certain domains (such as Intranet web pages–their current design allows them to map out internal corporate web structures which they should not be able to get). Their advisory board includes Avi Rubin, a well-known security researcher at Johns Hopkins University (and formerly at AT&T) who has done significant work on e-voting security, and Ben Edelman, formerly of Harvard Law School’s Berkman Center for Internet & Society, who is well-known for his research on Internet subjects such as domain name usage and China’s web filtering, as well as his lawsuit against web filtering company N2H2 to defend his right to research its blocking list. SiteAdvisor has a blog, too (though as of this moment it doesn’t have a valid RSS feed, according to Thunderbird). ...

January 26, 2006 · 2 min

Report card on the U.S. government's response to the 9/11 Commission

The U.S. government has failed to implement the recommendations of the 9/11 Commission to fix the worst problems. Shane Harris and Greta Wodele of the National Journal have written an article analyzing why this failure has occurred. Here’s the quick list of recommendations which received D or F grades: Allocate homeland-security funds based on risk: F Reform intelligence oversight: D Declassify overall intelligence budget: F Improve airline passenger prescreening: F Change incentives for information-sharing: D Improve government-wide information-sharing: D Improve checked bag and cargo screening: D Mount a maximum effort to secure weapons of mass destruction: D Strengthen the Privacy and Civil Liberties Oversight Board: D Provide adequate radio spectrum for first responders: F Support reform in Saudi Arabia: D Set coalition standards for terrorist detention: F Support secular education in Muslim countries: D Support scholarship, exchange, and library programs: D

January 20, 2006 · 1 min

FISA Court: Rubber Stamp?

In a New York Times op-ed defending the president’s warrantless wiretapping of international calls and emails, former Justice Department attorneys (under GHWB and Reagan) David Rivkin and Lee Casey write: Furthermore, the FISA court is not a rubber stamp and may well decline to issue warrants even when wartime necessity compels surveillance.It’s not? Let’s take a closer look (stats from EPIC by way of Talking Points Memo). The FISA court, established in 1978, had received 18,761 requests for warrants as of the end of 2004. How many were rejected? Four or five (sources disagree). Of the four which were definitely rejected (all from 2003), all four were partially approved upon reconsideration. And how many have been modified by the court from the original requests? 1978-1999: 0 (?) 2000: 1 2001: 2 2002: 2 (but the modifications were later reversed) 2003: 79 (of 1727 requests) 2004: 94 (of 1758 requests) It looks to me like the FISA court was a rubber stamp at least until 2003, and quite arguably still is. Rivkin and Casey go on to argue that Congress has no authority to regulate how the President exercises his wartime authority: The Constitution designates the president as commander in chief, and Congress can no more direct his exercise of that authority than he can direct Congress in the execution of its constitutional duties.Say what? Have they not read Article I, Section 8 of the U.S. Constitution, which explicitly gives Congress authority to regulate many aspects of military and wartime activity? I’ve italicized a key passage: Congress shall have the power … To declare war, grant letters of marque and reprisal, and make rules concerning captures on land and water; ...

December 28, 2005 · 4 min

Major flaw in Diebold voting machines

It is possible to preload a memory card with negative votes that are not recognized by the machine, but which affect the final outcome in an undetectible manner. In the test described in a Wired article, a mock vote was held on the question of whether Diebold machines could be hacked, with eight votes. The eight votes fed into the machines (via optically scanned paper ballots) were six “no” votes and two “yes” votes. The outcome recorded on the rigged card was one “no” and seven “yes”–the memory card was preloaded with -5 “no” votes and 5 “yes” votes. By balancing out the preloaded votes (with a sum of zero), the final record showed an accurate number of votes, but not an accurate record of what the votes were. Further flaws indicate that the Diebold machines execute code residing on the memory cards, without doing checks on the content of that code which are required by Federal Elections Commission standards. As a result of the hacking demonstrations by Finnish security expert Harri Hurst in Florida on December 13, Leon and Volusia counties in Florida have cancelled their contracts with Diebold. Much more at blackboxvoting.org.

December 23, 2005 · 1 min

Another Botnet Talk

I’m giving another talk tomorrow on botnets, this time for the Phoenix chapter of Infragard, the FBI-sponsored 501(c)(3) that is devoted to public sector/private sector partnerships to protect national infrastructures. While Infragard has primarily focused on information technology, they are broadening their focus to include things like agriculture and food distribution, energy production and transmission, chemical plants, etc. This is an update for those who attended my April 2004 Infragard talk, and includes new material that hasn’t been in any of my past botnet talks (for ASU, HTCIA, ATIC, FRnOG, and the Phoenix and Rochester, NY chapters of Infragard).

December 12, 2005 · 1 min
Mastodon Verification