"Anonymous" launches "war" against Scientology

In a press release yesterday that cites an article I co-authored in Skeptic magazine, a group referring to itself as “Anonymous” has announced that it has declared war against Scientology. The stated justification for the “war” is the Church of Scientology’s attempts to keep a video of Tom Cruise off the net. That video, which is still viewable at Gawker.com, was made for a Scientology awards ceremony. The longer video from which it was taken is also now viewable there. Gawker.com responded to a cease and desist letter with a refusal to remove the video, which it considers to be fair use for news and comment, but I’m not so sure that it has a good legal case for putting up more than short excerpts. (In case you’re wondering about all the Scientology jargon in the Tom Cruise video, MTV has done a good job of explaining it. Actor Jerry O’Connell has also put out a good parody.) The “war,” which is described at another site under the name “Project Chanology” (a reference to 4chan, a popular message board, where most posts are made by people who don’t login and are thus attributed to “Anonymous”), calls for denial of service attacks over the Internet, prank phone calls, spam emails, and personal visits involving vandalism and harassment. Apparently Scientology’s main website was down due to denial of service for at least part of the day yesterday. The press release cites a number of web pages for further information about Scientology, the second of which is the article “Scientology v. the Internet: Free Speech & Copyright Infringement on the Information Super-Highway” which Jeff Jacobsen and I wrote for Skeptic magazine in 1995 after Scientology effectively declared war on the Internet. (A much lesser-known sequel to that article, published only on the web, is “Scientology v. the Internet: An Update and Response to Leisa Goodman.") I completely disagree with the tactics being used here–Scientology has as much right to free speech and protection of their copyrights as anyone else, though I also condemn Scientology’s habitual misuse of copyright to try to suppress fair use of information. To the extent this is a prank designed to get media attention, well done. To the extent it gets taken seriously, though, it’s something that may not end well. Read the material, watch the videos, have a laugh, and tell others about the absurdity and abuses of Scientology. But please, don’t launch attacks on their websites, harass individuals, or engage in vandalism. “Anonymous” previously received coverage for attacks on MySpace accounts on Fox 11 in Los Angeles on July 26, 2007. BTW, the press release gets its facts wrong when it claims that the alt.religion.scientology Usenet newsgroup was “shut down.” Scientology attorney Helena Kobrin issued an rmgroup message, but almost all news servers ignored it. The accurate facts may be found in Jeff’s and my Skeptic article. UPDATE: Wikinews and Xenu.net have more. ...

January 23, 2008 · 12 min

Boeing 787 potentially vulnerable to passenger software-based hijacking

The Boeing 787 Dreamliner is equipped with systems to provide passengers with on-board Internet access. Unfortunately, the passenger network is also connected to the computer systems that control the plane, as well as communication and navigation systems, which the FAA has complained about in a “special conditions” document that covers issues that are a concern but are not specifically covered by regulations. Boeing says it has designed a solution that it will be testing shortly, and the FAA says that has to happen before any of these will be allowed to fly. A Boeing spokesperson claims that the FAA document criticizing the design is misleading because, as Wired reports, “the plane’s networks don’t completely connect.” She goes on in the article to say that there’s a combination of physical separation and software-based firewalls. Given the fact that software-based firewalls have themselves had vulnerabilities from time to time, I’d strongly prefer to see complete physical separation.

January 8, 2008 · 1 min

Notorious major spammer indicted

Alan Ralsky, at one time believed to be the top spammer in the world, has finally been indicted today by a federal grand jury. His home was raided back in 2005, and he’s now been charged along with ten other people in “a wide ranging international fraud scheme involving the illegal use of bulk commercial e-mailing.” Those indicted include James E. Bragg, 39, of Queen Creek, Arizona. The indictment alleges that Ralsky’s spam gang “tried to send spam” through botnets and engaged in a “pump and dump” stock scam for Chinese companies. The Detroit Free Press’s coverage reports: “Prosecutors described Ralsky, 52, of West Bloomfield, as one of the most prolific spammers in the nation. Until 2005, when federal agents raided his home and seized his computers, his operation sent tens of millions of unsolicited email messages daily to Internet subscribers, hawking everything from sexual enhancement drugs, weight loss products and worthless stock, the government said. In the summer of 2005 alone, prosecutors said, his operation generated $3 million." The DOJ press release is here. ...

January 4, 2008 · 2 min

"Untraceable" looks unwatchable

In January 2008 the film “Untraceable," starring Diane Lane, will be released. It looks awful. The premise is that a serial killer is killing people live on the Internet, via an “untraceable website” that is connected to contraptions that kill his victims as more people visit the site. The whole concept of an “untraceable website” or the idea that such a thing would be unstoppable by ISPs and law enforcement is absurd–the immediate upstream provider of the site would merely need to null route the IP address(es) where the website is hosted, and traffic stops. They’d also be able to quickly identify the customer who owns the server in question. Even if that server was compromised and being used to reverse proxy or redirect traffic to other servers, it would still be a relatively simple matter to track that backwards, though it would be somewhat more difficult than stopping the traffic. Even if the domain name pointed to a new server on a compromised host every second, it would still be possible to contact the domain name registrar and get the domain name shut down. If users can get to it, it can be seen how and what they’re getting to, even if that’s only the front end in a chain of successive proxies. If it has a domain name, that provides another path to shutting off access. UPDATE (January 2, 2008): I came across the script online while searching for information about the writers. Let’s just say that my opinion above is not nearly negative enough. In the first 16 pages are at least six or seven scenes that really bring on the stupid. For example, FBI Agent Jennifer Marsh, who works in the FBI’s cyber division, is monitoring machines that are being compromised by hackers (honeypots, essentially, though the script doesn’t use the word). One of her machines gets compromised and she sees that it copies her files including fake financial information. It then accesses eBay to use a stolen credit card to purchase a watch. In reality, the stolen financial information wouldn’t be likely to be used from the same machine, it would be sold to another player in the underground economy. Marsh then types commands to look for the IP address of the connecting host–but if they’ve already got honeypots or honeynets in operation, that should already be logged. She then does the usual CSI-style conversion of an IP address into a name and address without issuing a subpoena to an ISP, and discovers that it’s a home belonging to a 56-year-old woman. She immediately concludes that the actual criminal must be a neighbor using her wireless connection, despite the fact that she has no evidence that the woman has a wireless access point and isn’t just another victim with a compromised machine being used as a proxy. Without doing any more verification, she arranges to get a warrant to knock the door of the neighbor down, and it turns out to be a teenage kid. On p. 16 appears this nice quote: “She types several commands into a unix shell. Trace routing algorithms begin to run. A different screen shows possible IP addresses. The list begins growing, from ten to hundreds to thousands…. Marsh shakes her head at the futility.” There are multiple methods of performing traceroutes and even of adding fake hops to a traceroute, but traceroute is unnecessary to find out the IP address of a website–it’s only useful for finding the path traffic takes to get to that website, e.g., for finding the upstream provider. But getting a list of upstream providers is better done by looking at routing tables rather than doing traceroutes, anyway. The real investigative steps would be to look at the DNS information for the domain, get the IP address or addresses from the authoritative name server (and check to see if those are changing with a short TTL), then find the upstream providers. Funniest exchange I’ve seen so far in the script (p. 26) is this marvel of self-contradiction: [FBI agent] GRIFFIN: I traced it to a Georgetown sophomore named Andrew Kinross. But then I looked closer and saw the post didn’t actually originate from his computer. MARSH: Our guy got into his computer and posted it from there. GRIFFIN: That would be my guess. MARSH: So let’s go after the originating computer’s IP. And so far, I’ve not mentioned how the hacker mastermind hacks into the FBI agent’s car (which features the fictional “NorthStar” instead “OnStar”)–in the preview, the hacker apparently is able to control the steering of her car. I suspect drive-by-wire steering will come soon in the future of the automobile, but I don’t believe it exists today. (Turns out the preview gives a misleading impression of what the script says is happening–the hacker doesn’t actually control the steering, but remotely shuts off the car’s electrical systems and power steering.) ...

December 19, 2007 · 35 min

Multics source code released

The full source code to the last official release of the Multics operating system has been released to the general public (though full source was always made available to all customers, except for specific “unbundled” applications). Multics, the predecessor system to Unix (and in a number of ways still its superior), was a general purpose commercial operating system best known for its security. That release, Multics MR12.5 (MR = “Multics Release”), was released to customers in November 1992. The last Multics system was shut down in 2000. The software can be downloaded from a website at MIT, though it requires specialized hardware to run on, so don’t expect to be able to run it. My name appears a few times throughout the software, as I worked as a Multics software developer from 1983 to 1988. The MIT site incorrectly states that Multics development was ended by Bull in 1985–that may have been the time when Bull decided to pull the plug, but there was still development (though primarily bug fixing) going on in 1988 when I left. One of the pieces I wrote was a rewrite of the interactive message facility, in some ways a predecessor of instant messaging (except that it operated on a single timesharing host rather than over a network between hosts). Most of the software is in the “ldd” hierarchy (for library directory directory, the directory of directories of libraries). The software is in Multics “archive” format which is similar to Unix tar files. The message facility software is in /ldd/sss/source/bound_msg_facility_.s.archive. Kudos to Group Bull, the copyright holder of Multics, for making the software open source. Bull purchased Multics as part of its acquisition of Honeywell’s Large Computer Products Division in the mid-eighties. ...

November 14, 2007 · 2 min

Macintosh security lags behind Windows and BSD

Tom Ptacek at Matasano Chargen has a rundown on the new security features in Mac OS X Leopard, which are still not quite up to snuff with what’s in Windows Vista or OpenBSD. Here’s a followup with more details.

November 8, 2007 · 1 min

Spammers and criminals for Ron Paul

From metafilter: When Ron Paul email spam started hitting inboxes in late October, UAB Computer Forensics Director Gary Warner published findings on the spam’s textual patterns and the illicit botnet used to spread it – findings which were picked up by media outlets and tech websites like Salon, Ars Technica, and Wired Magazine’s “Threat Level” blog, the latter in a set of followup posts by writer Sarah Stirland: 1, 2, 3. The Ron Paul fan response was swift and decisive: clearly the botnet was the work of anti-Ron Paul hackers trying to discredit his campaign, and Rudy Giuliani had paid Stirland (and not UAB Computer Forensics) to do a smear piece – as claimed by a YouTube video pointing to posts on RudyGiulianiForum.com. Thus proving, once again, that the Ron Paul campaign’s greatest liability is not so much his far-right conspiracy-driven antifederal libertarianism, but rather the spittle-flecked anger of his own noisiest supporters.There are definitely a lot of nuts among Ron Paul’s supporters. Meanwhile, he raised $3.8 million yesterday (apparently a number revised downward from $4.3 million) in the largest one-day online political fundraiser ever. Intrade currently shows Paul as the third most likely GOP nominee, after Giuliani and Romney. A few other Ron Paul-related blog posts that I realize I’ve neglected to mention here, from Dispatches from the Culture Wars: “Is Ron Paul a Dominionist?" Argues that Paul appears to have much in common with some theocrats. “Sandefur on Ron Paul” Doubts that Paul is a dominionist, but suggests he might be a Thomas DiLorenzo-style neo-confederate who thinks we don’t even need a federal government (in which case he wouldn’t really be the supporter of the Constitution that he seems to be) and that the U.S. Civil War wasn’t about slavery (which is pernicious nonsense). I also just came across this story, which says that Paul would like to see the U.S. Constitution amended to remove the subject of abortion from the purview of the courts, which is yet more anti-constitutional insanity. ...

November 6, 2007 · 17 min

Break-in at CI Host colo facility

The Register (UK) reports that C I Host, a webhosting provider, has now had a fourth break-in at its Chicago colocation facility. Someone cut through a wall with a saw and stole customer equipment (and the DVRs or tape recording devices for the CCTV system). C I Host apparently took days to inform its customers of the break-in, and some have voiced suspicions that it was an inside job. UPDATE (February 4, 2007): There was some followup discussion.

November 5, 2007 · 1 min

Hacker finds vulnerability in Adobe Reader

A hacker has found a flaw in Adobe’s PDF file format which can be used to exploit Adobe Reader 8.1 on Windows XP. Dave G. at the Matasano Chargen blog predicts that such attacks–targeting popular applications–will become more common. PDF in particular is a likely target due to its ubiquity and its complexity.

September 25, 2007 · 1 min

Naomi Wolf on 10 steps to a fascist America

I just saw Naomi Wolf on The Colbert Report (Wednesday night’s show), discussing her new book, The End of America: A Letter of Warning to a Young Patriot. She only had time to list a few of the ten steps on her list, but I found all ten in an article from the Guardian: 1. Invoke a terrifying internal and external enemy 2. Create a gulag 3. Develop a thug caste 4. Set up an internal surveillance system 5. Harass citizens’ groups 6. Engage in arbitrary detention and release 7. Target key individuals 8. Control the press 9. Dissent equals treason 10. Suspend the rule of law ...

September 22, 2007 · 6 min
Mastodon Verification