Heathrow security confuses the map for the territory

A man wearing a Transformers t-shirt was stopped by airport security at Heathrow Terminal 5 because the cartoon character on the shirt was depicted holding a gun. This is about as idiotic as Michelle Malkin’s opposition to Rachael Ray wearing a paisley scarf that resembled a keffiyah–even after she admitted it was a paisley scarf.

June 3, 2008 · 1 min

MediaDefender launches denial of service attack against Revision3

Anti-piracy company MediaDefender, which defends its clients’ intellectual property by disrupting the content on peer-to-peer networks, launched a denial of service attack (SYN flood) against Revision3 over Memorial Day weekend. The attack was launched after Revision3 discovered that their servers were being used by MediaDefender to post spoofed BitTorrent index files and Revision3 shut off their access. Revision3, a legitimate company that distributes HD video over the Internet using BitTorrent, was not amused, and the FBI is investigating. Any legitimate Internet provider should refuse to provide services to companies that engage in illegal or immoral tactics to try to stop peer-to-peer piracy of copyrighted content, such as denial of service attacks or interference with services that are being used legitimately, even if they are also being used for piracy. If they don’t have methods which can be targeted specifically against the copyrighted content they are authorized to protect, then their methods cross the line, in my opinion. MediaDefender’s upstream network providers are Savvis (ASN 3561), Beyond the Network (ASN 3491), WV Fiber (ASN 19151), and SingTel (ASN 7473). They all should have a problem with denial of service attacks by their customer. MediaDefender was previously in the news in September 2007 when its security was breached by hackers and 700 MB of executive emails and the content of VoIP telephone calls from the company were leaked to the Internet. This seems to me like a company that should not be in business. ...

May 30, 2008 · 2 min

Pre-flight cocktails

The Washington Post reports that there have been more than 250 recent cases of the Department of Homeland Security’s Immigration and Customs Enforcement (ICE) agency giving “pre-flight cocktail” injections of psychotropic drugs to foreigners being deported. These injections of antipsychotic drugs have been given to people with no history of mental illness and for no medical justification, with the only apparent purpose to sedate them during their flights. The practice of “involuntary chemical restraint of detainees” without medical justification violates some international human rights codes, according to the Post, and is banned in several countries. Confidential documents obtained by the newspaper indicate that in some of the cases they report, detainees were not able to be given additional injections during layovers because to do so would be illegal in the countries in question. These sedations violate the government’s own rules, which only permit sedation if the individual has a mental illness which requires the drugs or if the person is aggressive to the point of creating a danger to those around them. The Post reports that during 2007, there were 67 people deported with medical escorts with no medical justification, 53 of whom were given psychiatric drugs, and 48 of whom had no documented history of violence. Most of those given drugs appear to be individuals who had previously resisted deportation. One man deported to Nigeria was still under the effects of the drugs for four days after his arrival. One drug often reported used was Haldol, which created some controversy during George H.W. Bush’s presidency when it was reported that he took the drug to avoid jet lag; some speculated that this drug was the cause of his vomiting at a dinner with (and vomiting on) the Prime Minister of Japan. A related story in the Post looks at 80 cases of deaths of immigration detainees, of which 30 were found to be “questionable,” including two in Arizona. (Via The Agitator.)

May 15, 2008 · 2 min

Bad military botnet proposal

An article by Col. Charles W. Williamson III titled “Carpet bombing in cyberspace: Why America needs a military botnet” has been published by the Armed Forces Journal. Col. Williamson, seeing that miscreants are using compromised machines all over the Internet to create botnets used for malicious purposes, has decided that the military needs to create its own, legitimate botnet. He proposes that this would be used in order to respond to online attacks from foreign countries by attacking the attackers, including both government and civilian attacking machines as necessary. He specifically proposes not using compromised machines (which would be illegal), but using machines on the af.mil (U.S. Air Force) network, including all hosts on the NIPRNet (Nonsecret IP Network). The proposal doesn’t really make any sense to me. First of all, attacks from hostile compromised machines on the Internet occur on a daily basis and are already handled by network service providers. These attacks are never likely to be initiated specifically from an individual attacking country’s systems, but rather from compromised systems all over the world–sometimes including compromised systems belonging to the U.S. military. Second, the best way to respond to attacking systems is not by launching hostile traffic back at them, but by filtering them or nullrouting them. Again, network service providers already do this today, and cooperate with each other in addressing major attacks. Thirdly, if the U.S. military sets up a botnet and uses it to launch denial of service attacks, it will be in violation of its own contracts with its network service providers–I don’t know of any network service provider that offers a military exception to its terms of service regarding denial of service attacks. Fourth, if all of the U.S. military bots are on its own network, their aggregate bandwidth still can’t exceed the bandwidth of its connections to other networks. Fifth, if there are attacks coming from another country that the U.S. is at war with, the recent subsea cable outages in the Middle East suggest that there are other effective mechanisms for disabling their ability to engage in Internet attacks. Finally, it’s not clear to me what benefit would be obtained from the military setting up its own botnet on its own network using its own IPs. Botnets offer two main benefits–(1) offering a distributed platform for computing and traffic generation and (2) creating a buffer of separation between the agent performing an action and the action itself. The second benefit occurs because the miscreant doesn’t own the machines that make up the botnet, lots of other people do. A botnet composed entirely of hosts on the military’s network is relatively easy to identify, filter, and block–the second benefit doesn’t exist. The first benefit is also mostly lost if you use your own network and hosts. The point of a distributed denial of service attack is to use up the other guy’s bandwidth, but not your own. That’s very easy to do if you’re not using your own resources, which is why distributed denial of service attacks use compromised systems and, sometimes, methods to amplify attacks using other people’s servers that send out responses that are larger than the requests that prompt them. But if you’re using your own resources on your own networks, you’re limited to the bandwidth you have at your network interconnection points, and multiplying hosts inside that perimeter gains you nothing except a guarantee that you can saturate your own internetwork connectivity and cut yourself off from the outside unless your target has less bandwidth than you do. It’s ironic that Williamson complains about a “fortress mentality,” while making a proposal to create a gigantic bot army inside the military’s own perimeter. A million-man army doesn’t help you if they’re inside a fortress with exits that restrict its ability to be deployed, except when you can win the battle with the number of men who can leave the exits at any one time. I’ve also posted a comment on the Armed Forces Journal article at the AFJ’s forum where I make a few additional points. I also agree with many of the other critical remarks that have been made in the thread there. “Crass Spektakel”’s point that “Whoever controls BGP and the backbone routers controls the internet” and that most of the control of BGP routing and the routing registries resides in the U.S. is a good one. A similar point could be made about DNS. Other posts on this subject: Kevin Poulsen at the Wired blog Jon Stokes at Ars Technica UPDATE (May 14, 2008): I may take some heat for even suggesting this, but an idea which actually takes advantage of both of the characteristic benefits of botnets I listed above and would be far, far more effective than Williamson’s proposal would be if the military produced bot software along the lines of SETI@Home and Folding@Home, which anyone could volunteer to download and run on their home or corporate machines (or better still, made available to run on XBoxes and Play Station 3s), for use by the military when needed. Some of the abuse worries could be defeated if the activation and deactivation of the software was fully under the control of the end user, and the military obtained appropriate permission from upstream ISPs for activities which would otherwise constitute AUP violations by end users. I hasten to add that this is still a terrible idea–putting such software out in public makes it a certainty that it would be reverse-engineered, and the probability of it being compromised by third parties for their own abuses would correspondingly increase. UPDATE: Looks like Paul Raven beat me to the “Milnet@Home” idea, as he dubs it. A commenter at Bruce Schneier’s blog also came up with the same idea. F-Secure’s blog also offers some good criticisms of Williamson’s proposal. ...

May 13, 2008 · 5 min

Scammers scamming scammers

Marco Cova looks in some detail at the contents of some phishing scam kits targeting particular banks that were released to the public recently. These sorts of kits, containing web code, are ordinarily sold to scammers, but these were given away free. It wasn’t out of generosity, but part of a larger scam–the code was written using a variety of obfuscation techniques so that the unwary script kiddie who modifies it to send the captured information to their own email address will not receive it. Instead, that information is sent to various email addresses presumably controlled by the distributor of the scammer-scamming phishing kits.

April 8, 2008 · 1 min

Software awards scam

Andy Brice decided to test various download sites to see which ones would give awards (and expect a banner to be posted by the developer’s website with a link back) to a piece of “software” that consisted only of a text file named “awardmestars” containing the words “this program does nothing at all” repeated several times. He submitted it to 1033 sites, of which 218 sites listed it and 421 rejected it. Of those that accepted it, 11% gave it an award (he’s currently at 23 awards): The truth is that many download sites are just electronic dung heaps, using fake awards, dubious SEO and content misappropriated from PAD files in a pathetic attempt to make a few dollars from Google Adwords. Hopefully these bottom-feeders will be put out of business by the continually improving search engines, leaving only the better sites.He notes the following sites which wrote him to say to stop wasting their time, indicating that they actually check submissions: ...

March 26, 2008 · 2 min

Ex-terrorists turned Christian evangelists

It was only a matter of time. Where John Todd, Mike Warnke, “Lauren Stratford,” and others found that they could get attention and money by claiming to be ex-Satanists/witches/Illuminati converted to Christian evangelists, we now see “ex-Islamic terrorists” turned born-again Christians and hitting the lecture circuit, and getting paid for appearances at the U.S. Air Force Academy, as the New York Times reports. The Times article ends with the most obvious question: Arab-American civil rights organizations question why, at a time when the United States government has vigorously moved to jail or at least deport anyone with a known terrorist connection, the three men, if they are telling the truth, are allowed to circulate freely. A spokesman for the F.B.I. said there were no warrants for their arrest.Of the three speakers, Zak Anani, Kamal Saleem, and Walid Shoebat, Anani is described as the most explicitly preaching born-again Christianity rather than providing information about Islamic terrorism. He also seems to be the one with the clearest record of making false claims about his own background: Anani, now an evangelical Christian, claims to be an expert on the topic because he killed 223 people in Allah’s name, “two-thirds of them by daggers.” He even claims to have killed a man for waking him up at 3 a.m. to pray. Anani, born in Lebanon, said he joined a militant Muslim group in the early 1970s at age 13, and made his first kill shortly after. … He said he was soon promoted to troop leader and formed his own regiment, but later met a Christian missionary and converted. ...

March 23, 2008 · 5 min

Most antiterrorism spending is wasteful

The March 6, 2008 issue of The Economist features lots of interesting articles (it includes one of the quarterly technology reviews), one of which is “Feel safer now?" This is a report on a study by economists in Texas and Alabama commissioned by the Copenhagen Consensus, which looks at the effects of increased spending on counterterrorism efforts and “homeland security” globally since 2001, and the effects. They calculate that while such spending has increased by somewhere between $65 billion and $200 billion a year, the benefits are far smaller than the costs of terrorism, which were about $17 billion in 2005. While the spending may have prevented some incidents, even if this extra spending prevented 30 attacks like the July 2005 London bombings every year, it would still be more expensive than the damage from terrorism. The authors suggest that the benefits from increased counterterrorism spending have been about 5-8 cents per each dollar of spending, whereas if instead money was spent specifically on disrupting terrorist finances, $5-$15 of benefits could be obtained for each dollar spent.

March 20, 2008 · 1 min

Terrorist watch list grows past 700,000 names

The ACLU reports that the Terrorist Screening Center’s watch list reached 700,000 names in September 2007, and is adding 20,000 new names per month. “At that rate, our list will have a million names on it by July. If there were really that many terrorists running around, we’d all be dead." Names on the list include: Robert Johnson Alexandra Hay Evo Morales (president of Bolivia) Saddam Hussein (dead former dictator of Iraq) the 9/11 hijackers (all still dead) Gary Smith John Williams Edward Kennedy (Massachusetts Senator) John Lewis (U.S. Rep. from Georgia) Daniel Brown (U.S. soldier detained on way home from Iraq) James Moore (author of book critical of Bush administration) Catherine (“Cat”) Stevens (wife of Sen. Ted Stevens) Yusuf Islam (formerly known as Cat Stevens) Vernon Lewis (retired Major General, U.S. Army) Robert Campbell (U.S. Navy, retired) David Nelson John William Anderson Don Young (U.S. Rep. from Alaska) The whole idea of checking names for flight screening is nearly pointless, since terrorists are capable of getting fake ID. It’s absolutely idiotic to have extremely common names on the list and subject everyone who happens to have a common name to extra screening every time they fly. The right way to do screening is to use mechanisms like randomly subjecting people to extra screening and to have people undercover trained to identify suspicious behavior in the terminal–and to use multiple mechanisms that are randomly changed from day to day, so that security measures tested on one day will not be the exact measures in place on a later day. UPDATE (March 18, 2008): Note that the no-fly list is a subset of the terrorist watch list. The former is what I criticize in the last paragraph. An FBI audit has stated that the information the FBI supplies for the terrorist watch list is “outdated and inaccurate." ...

March 15, 2008 · 3 min

Homeland Security threat

The Miami Herald has uncovered a new Homeland Security threat–and it’s U.S. Customs and Border Protection agents that are committing crimes. Bribery, drug trafficking, migrant smuggling, embezzlement, and other crimes have become so prevalent that a senior manager has issued a memo pointing out that agents are supposed to uphold, not break the law: U.S. Customs and Border Protection is supposed to stop these types of crimes. Instead, so many of its officers have been charged with committing those crimes themselves that their boss in Washington recently issued an alert about the ‘‘disturbing events’’ and the ``increase in the number of employee arrests.’’ ...

March 15, 2008 · 1 min
Mastodon Verification