The bots of summer

My two-part appearance on “The Security Catalyst” podcast last year has resulted in some media coverage of botnets this week at IT World Canada. The article, “The botnet menace–and what you can do about it,” by Joaquim P. Menezes, is more detailed than most media coverage of bots has been. He draws on both my Security Catalyst interview and my colleague Bob Hagen’s blog post on bots.

June 6, 2007 · 1 min

Spying on the Homefront

Tomorrow night on PBS’s Frontline is “Spying on the Homefront”: FRONTLINE addresses an issue of major consequence for all Americans: Is the Bush administration’s domestic war on terrorism jeopardizing our civil liberties? Reporter Hedrick Smith presents new material on how the National Security Agency’s domestic surveillance program works and examines clashing viewpoints on whether the president has violated the Foreign Intelligence Surveillance Act (FISA) and infringed on constitutional protections. In another dramatic story, the program shows how the FBI vacuumed up records on 250,000 ordinary Americans who chose Las Vegas as the destination for their Christmas-New Year’s holiday, and the subsequent revelation that the FBI has misused National Security Letters to gather information. Probing such projects as Total Information Awareness, and its little known successors, Smith discloses that even former government intelligence officials now worry that the combination of new security threats, advances in communications technologies, and radical interpretations of presidential authority may be threatening the privacy of Americans.(Via the Electronic Frontier Foundation.)

May 15, 2007 · 1 min

CALEA compliance day

Today’s the day that providers of VoIP and broadband Internet in the United States must comply with CALEA, mandating that they supply a way for law enforcement to eavesdrop on any communications carried over those mechanisms. I suspect many VoIP providers are in compliance but that fewer broadband Internet providers are, since the draft standard for CALEA for data over broadband Internet only came out in March. (And if you’d like to read the standard, it will cost you $164 for the PDF or $185 for a paper copy.) Bob Hagen at the Global Crossing blog points out some free tools that can be used to protect your privacy.

May 15, 2007 · 1 min

Banning the distribution of AACS keys is futile

AACS keys are used to encrypt the content of HD-DVDs (this is an oversimplification; see Ed Felten’s Freedom-to-Tinker blog for more detail). A particular “processing key” for AACS has recently been distributed on the Internet, with the AACS Licensing Authority issuing cease and desist orders to try to stop it. This has led to new and creative ways of distributing this 128-bit number, just as occurred with the DeCSS code for decrypting DVDs. When a cease-and-desist order went to digg, digg’s users proceeded to give diggs to many different sites, at one point leading to the entire front page of digg being full of nothing but links to pages with the AACS key. A couple of the more interesting methods include making the number into a song and displaying it with satellite photos of buildings that resemble hex digits. One individual appears to have had it tattooed on his chest. This is exactly what we saw with DeCSS, which is memorialized in Dave Touretzky’s Gallery of CSS Descramblers. This case is even more absurd, in that AACS LA is claiming ownership of a number–and a relatively short one–not because it encodes any content or algorithm, but because it’s one of potentially millions of keys assigned for use with its system. UPDATE (May 11, 2007): As this t-shirt makes clear, trying to protect against the distribution of a 128-bit number is futile when knowledge of the number can be easily distributed without using the number itself. I’d love to see AACS LA try to make a case against the marketing and sale of this shirt.

May 3, 2007 · 2 min

McCain's MySpace page

Whoever maintains John McCain’s MySpace page borrowed the template from another MySpace user without giving credit. That template included an image in the “Contacting ” section, which was being pulled from the original user’s page and had a list of menu items to click on. The original user, upset at his template being used without credit, changed the image, so that it said: “Dear Supporters, Today I announce that I have reversed my position and come out in full support of gay marriage… particularly marriage between passionate females. John” McCain’s MySpace page has subsequently been fixed. BTW, the Republican candidate for president with the most MySpace friends is libertarian Rep. Ron Paul, who has for some reason been removed from multiple online polls about candidate preferences (including Pajamas Media and Slate’s reporting of the online idea futures). UPDATE (March 30, 2007): Pajamas Media has re-listed Ron Paul and added Fred Thompson this week; Fred Thompson is leading and Ron Paul is in second for the Republicans; Bill Richardson is leading for the Democrats. Not that online, self-selected polling has any reflection on how an actual vote would go…

March 29, 2007 · 1 min

The rsync.net warrant canary

You aren’t allowed to say if you’ve received a National Security Letter. But there’s no law that says you can’t say that you haven’t received one. Thus, rsync.net has a “warrant canary”–they periodically post a cryptographically signed statement that they have not, to date, received any PATRIOT Act warrants or had any searches and seizures. If they stop updating the statement, then you can draw your own conclusions. The second of these library signs uses the same principle: “The FBI has not been here [watch closely for removal of this sign]." (Via jwz’s blog, where some commenters question whether the recent Washington Post piece by the recipient of a National Security Letter is truthful. Note that the ACLU has a lawsuit going on about this case, which I previously noted back in 2005.) ...

March 25, 2007 · 1 min

Bob Hagen on botnet evolution

Bob Hagen has put up a post on the evolution of botnets at the Global Crossing blog. (BTW, I’m hoping to have future opportunity to use titles like “Where the bots are”, “The bots from Brazil”, and “The bots of summer”.) UPDATE (August 27, 2009): I’ve replaced the above link with one to the Internet Archive, since the blog post is no longer present at its original location.

March 10, 2007 · 1 min

Why Arizona doesn't go on daylight savings time

The Arizona Republic has a story on why Arizona doesn’t go on daylight savings time–it was attempted in 1967 and reversed by the state legislature in 1968, when Sandra Day O’Connor was Senate Majority Leader. The feds gave Arizona an exemption from daylight savings time on January 4, 1974, two days before a mandate for states to go on daylight savings time. As I like to say, Arizona has so much daylight we don’t bother to save any. One positive side-effect–no issues over this year’s DST changes in Arizona (except for companies that operate across multiple states). UPDATE (March 13, 2007): Long or Short Capital offers some funny additional speculation on why Arizona doesn’t go on Daylight Savings Time. ...

March 10, 2007 · 1 min

Windows, Mac, and BSD security

March 9, 2007 · 0 min

Where the wisdom of crowds fails

Richard Bennett has an interesting post about Wikipedia and the decentralization of knowledge collection titled “Teaching the hive mind to discriminate." He argues that while Wikipedia is good at accumulating the knowledge of a large number of individuals, it also collects their “prejudice, mistaken beliefs, wishful thinking, and conformance to tradition.” It is unrealistic to expect that these erroneous beliefs will automatically be weeded out because “expertise is not as widely dispersed as participation”: So the real question about information and group scaling is this: are there procedures for separating good information from false information (”discrimination”) that are effective enough to allow groups to be scaled indefinitely without a loss of information quality? It’s an article of faith in the Wikipedia “community” that such procedures exist, and that they’re essentially self-operative. That’s the mythos of “emergence”, that systems, including human systems, automatically self-organize in such a way as to reward good behavior and information and purge bad information. This seems to be based on the underlying assumption that people being basically good, the good will always prevail in any group.Readers of this blog know that I would argue that many religious and political beliefs are examples that support Bennett’s position. On a related point, Ed Felten has a recent post about how reputation systems on the Internet can be manipulated, referencing a pair of articles at Wired by Annalee Newitz. A common flaw is that the reputations of the raters themselves is either not taken into account or is easily manipulated. If there were a way of reliably weighting expertise of raters within appropriate knowledge domains, that could provide a method of discrimination to sort out the good from the bad information. This is a subject that my planned (but never completed) Ph.D. dissertation in epistemology (on social epistemology, specifically on obtaining knowledge based on the knowledge of others) at the University of Arizona should have touched upon. One philosopher who had touched on this subject at the time I was working on my Ph.D. (back in the early 1990s) was Philip Kitcher, whose book The Advancement of Science: Science without Legend, Objectivity without Illusions (1993, Oxford University Press) contains a chapter titled “The Organization of Cognitive Labor” (originally published as “The Division of Cognitive Labor” in the Journal of Philosophy, 87(1990):5-21). ...

March 3, 2007 · 5 min
Mastodon Verification