Boston police arrest MIT student for blinking nametag

Boston authorities have filed another set of bogus “hoax device” charges, against Star Simpson, a 19-year-old MIT student who was wearing a sweatshirt with a homemade electronic nametag stuck to the front of it. The device was made of a breadboard with LEDs and a 9V battery, and Simpson was also holding “a lump of putty” in her hands, as she was waiting at Logan airport for a friend’s flight to arrive. She explained that she made the device for career day because she wanted to stand out. She was released on $750 bail and will have to appear in court on October 29 on charges of “possessing a hoax device." The Boston Globe’s article says: ...

September 21, 2007 · 16 min

British bands banned from U.S. visits

It’s becoming a problem for newly popular British bands to tour in the United States, because they are being denied P-1 visas unless they can prove that they have been “internationally recognized” for a “sustained and substantial” amount of time. Recently the band New Model Army, which has actually been around for decades, were denied visas to perform in San Francisco at the DNA Lounge.

September 21, 2007 · 1 min

Lessons for information security from Multics

Bruce Schneier brings attention to a 2002 paper by Paul Karger and Roger Schell (PDF) about lessons learned from Multics security that are still relevant today, and Multicians come out of the woodwork in the comments. Karger and Schell were part of the Air Force “tiger team” that ran penetration attacks against Multics in the 1970s. They were successful, which ultimately led to a Multics security enhancement project, the result of which was that Multics was the first commercial operating system to obtain a B2 security rating from the National Computer Security Center. I played a small part in that project, fixing some bugs and helping to run tests of Multics’ Trusted Computing Base (TCB).

September 19, 2007 · 1 min

Microsoft updates Windows XP and Vista without user permission or notification

Microsoft has admitted that it has updated nine executable files in XP and Windows on users’ machines even when they have turned off automatic updates. These files are part of the Windows update feature itself. Corporate users who use SMS rather than Windows update for OS patches are not affected. Bruce Schneier raises the question of whether this ability to force updates could be exploited by a third party. I would hope that such updates are digitally signed, so that they can only come from Microsoft, but a commenter at Schneier’s blog notes that even if that is the case there is a potential vulnerability created: There may be an attack vector, even if the updates are signed by Microsoft. The signed updates would always be silently accepted. If Microsoft ever signs an update which later turns out to be vulnerable to some attack (this has happened before with signed activeX components), an attacker could re-push this vulnerable update and introduce a known vulnerability into the target system.Another commenter notes that this feature could be used by law enforcement to install a keylogger on a machine, if Microsoft agreed to do it.

September 17, 2007 · 1 min

Anti-P2P company suffers major security breach

MediaDefender, a company that attempts to disrupt the sharing of copyrighted material owned by its clients on peer-to-peer filesharing networks, has suffered an embarassing security breach–the leaking of 700 MB of emails from senior employees in the company. The leak allegedly occurred because one senior employee was forwarding company email to his Gmail account, and he used the same password for his Gmail account that he used to register for a P2P service of some kind. This breach demonstrates the importance of adhering to corporate policies about use of external mail providers and using good password security–anything really important should have a unique password, not the same one used for accessing a variety of online websites and services. UPDATE: It’s now being claimed that MediaDefender’s phone systems have also been compromised for the last nine months, and a 25-minute phone call between MediaDefender and the New York Attorney General’s office is circulating, as well as a transcript. The transcript indicates that the AG’s office was concerned (rightly so, apparently) about a possible mail server compromise at MediaDefender; the MediaDefender representative states at one point that he is speaking over a VoIP connection. UPDATE: It seems the record companies are using information about P2P downloads collected by MediaDefender to make marketing decisions. Here’s a quote from one of the leaked emails (quoted from SlashDot): Subject: Nicole Scherzinger Date: Fri, 24 Aug 2007 15:14:31 -0700 Nicole from pussy cat dolls has a single called “whatever u like”. It’s not selling well on itunes or playing that great on radio. A song called “Baby Love” just leaked (I don’t know how long ago). Interscope wants to know if Baby Love is picking up steam on p2p. They need to make a decision by early next week on whether they should switch to this song as the single. Please get me a score comparison on Monday for these two tracks. Also, please put beyonces, fergie, gwen, and nelly furtado singles as comparisons.UPDATE (September 17, 2007): Ars Technica has a good summary of the breach and what the leaked information shows about what MediaDefender has been up to with its video upload service (apparently designed to encourage the upload of copyrighted content as a sort of sting operation), MiiVi. MediaDefender says it was an “internal project” that was supposed to be password protected but was inadvertently made public. CNet has a story on MediaDefender which notes: ...

September 16, 2007 · 3 min

Another Sony rootkit

F-Secure announced yesterday that it has found another Sony product that installs a rootkit and hidden directory on Windows machines. Last time it was the copy protection associated with music CDs, this time it’s software associated with a fingerprint reader for the Sony MicroVault USM-F memory stick, which Sony says is now no longer for sale. The use of the memory stick causes files to be installed into a hidden directory on your hard drive which is hidden from the operating system, including antivirus scanning. This means that, like the hidden directory created by the CD copy protection scheme, the directory can be used by other malicious software to hide itself.

September 5, 2007 · 1 min

Lying at the Weekly Standard

Julian Sanchez points out the staggering misrepresentation by those arguing that the recent increase in wiretapping power amounts to nothing more than an update of FISA procedures to reflect current technology. (Hat tip to Tim Lee at the Technology Liberation Front.)

August 17, 2007 · 1 min

Bruce Schneier interviews Kip Hawley

Bruce Schneier has posted all five parts of his interview with Transportation Security Administration head Kip Hawley: Part 1, Part 2, Part 3, Part 4, Part 5.

August 16, 2007 · 1 min

Congress approves expansion of presidential wiretapping powers

Both houses of Congress have passed a bill that updates the Foreign Intelligence Surveillance Act (FISA) to allow warrantless wiretapping when at least one party is a foreigner, without any requirement that the foreigner be suspected of having connections to terrorists. Wiretaps in such cases do not require approval of the FISA court, only of the attorney general and the director of national intelligence. As Tim Lee at Technology Liberation Front observes: So let me get this straight: the White House says “we think we should be able to eavesdrop on virtually any domestic-to-foreign phone call without court oversight, based on the say-so of one of the president’s subordinates.” And the Democrats response was “Hell no! Warrantless spying should require the say-so of two of the president’s subordinates!”Arizona’s Congressmen voted along party lines except for Harry Mitchell, who sided with the Republicans in favor of the bill, which provides for this expansion of powers for the next six months. (UPDATE, August 8, 2007: Actually, McCain didn’t vote on this bill at all, it’s another of his no-shows.) Kudos to Pastor, Grijalva, and Giffords for voting against this. (Hat tip to Technology Liberation Front and Stranger Fruit.) UPDATE (August 7, 2007): Ed Brayton at Dispatches from the Culture Wars has more on how this bill has gutted any oversight of what the Executive branch is doing. ...

August 5, 2007 · 2 min

Abolish the CIA

I’m currently reading Pulitzer Prize winning author Tim Weiner’s 20-years-in-the-making history of the Central Intelligence Agency, Legacy of Ashes: A History of the CIA (2007, Doubleday). All of Weiner’s facts are sourced and on-the-record, including numerous recently declassified sources (some of which the government is attempting to re-classify). This review of the book by Chalmers Johnson, a former outside consultant for the CIA, does a good job of pointing out some of the highlights and arguing at the conclusion for the abolition of the CIA and letting the State Department’s Bureau of Intelligence and Research fill in for the foreign intelligence function. Weiner’s book points out how the CIA has been mismanaged since its creation from the ashes of the Office of Strategic Services, failing to come up with accurate information about major events of significance and leaving a wake of damage from failed covert ops designed to stop the spread of communism even where there was none. And it has regularly deceived presidents, massaged or fabricated intelligence information, and violated the laws of the United States. Johnson writes: Nothing has done more to undercut the reputation of the United States than the CIA’s “clandestine” (only in terms of the American people) murders of the presidents of South Vietnam and the Congo, its ravishing of the governments of Iran, Indonesia (three times), South Korea (twice), all of the Indochinese states, virtually every government in Latin America, and Lebanon, Afghanistan, and Iraq. The deaths from these armed assaults run into the millions. After 9/11, President Bush asked “Why do they hate us?” From Iran (1953) to Iraq (2003), the better question would be, “Who does not?"This paragraph understates the case–Johnson goes on to describe how the CIA provided funding for Japanese and Italian politicians. Weiner’s book observes that the CIA helped a convicted war criminal become prime minister of Japan in 1957 and bribed the leading officials of the Liberal Democratic Party, which it helped maintain in power until the 1990s. CIA broadcasts from Radio Free Europe called for uprisings. To their surprise, former Hungarian prime minister Imre Nagy, who had been expelled from the Communist Party, announced on state radio a break with Russia, and within days formed a new coalition government in October 1956, but CIA Director Allen Dulles rejected him because he had been a communist and RFE attacked him. RFE broadcasts as much as promised U.S. assistance to Hungarian rebels, only to leave them to die on their own in November 1956 when the Soviets crushed the rebellion. Tens of thousands of people were killed and thousands shipped off to Siberia. Dulles lied to Eisenhower about the content of the broadcasts, transcripts of which only became available in English in 1996, and claimed the U.S. had done nothing to encourage the Hungarians. I’ve still got much to read in the book (I’m only up to 1958), but so far it is eye-opening and appalling. UPDATE (August 11, 2007): The CIA has issued a press release taking issue with Weiner’s book for its bias. UPDATE (December 16, 2009): The CIA has published a review critiquing the accuracy and reliability of Weiner’s book. ...

August 1, 2007 · 6 min
Mastodon Verification