TSA continues to demonstrate incompetence

A web page on the TSA’s website for travelers “who were told you are on a Federal Government Watch List” displays evidence of being a phishing site–it’s probably not, it’s just so badly done that it looks like a hacked web site that’s submitting its details to an unrelated third party. TSA responded that “We are aware there was an issue and replaced the site. The issue has been fully addressed. We take IT responsibilities seriously. There never a vulnerability; just a small glitch." The full story may be found at Wired Blogs, which points out fifteen features that make the TSA form submission site look dangerous. Also check out this comment at Christopher Soghoian’s blog: This may be surprising to hear: I am an employee at a major airline and I just recieved an e-mail that said we now have access to the TSA no-fly list, selectee list, and cleared list. I just accessed it and found it to contain thousands of names, DOB, SSN#s, drivers licesense #’s, military ID #’s, addresses, and even home phone #’s. The TSA just made this list and all of this information readily available to thousands of employees at my airline (and probably others). I think that previously this list was only available to ticket agents, but now it is available to every employee. I find it quite disturbing that any airline employee has access to this information, and that many of the ppl on the cleared list have to give up there SSN# and other information.Nice. (Hat tip to Bruce Schneier’s blog.)

February 20, 2007 · 2 min

How IPv6 is already creating security problems

Computer Associates CEO John Swainson, the keynote speaker at last week’s CA Expo ‘07 conference in Sydney, Australia, spoke about how the deployment of IPv6 will bring unavoidable and unknown security threats. He was quoted in SC Magazine: “I don’t know what they will be but I can predict with a high degree of probability that it will happen,” he said. “This is not something you can test in the lab, it’s something that emerges through practice.” Swainson’s comments on IPv6 were part of a broader theme addressing the emerging complexities in IT infrastructure and their more complex insecurities. “We’re talking about new complexities on top of existing complexities. As networks expand to include remote device types and additional applications [they] produce a wide variety of security threats,” he said.The new Apple AirPort Extreme for 802.11n wireless networks demonstrates Swainson’s point quite vividly. The device supports IPv6, and the default setting is for the device to set up an IPv6 tunnel over the IPv4 Internet and to provide IPv6 addresses to hosts on the local network with IPv6 enabled. For those using the device as their local firewall (which I’d argue is not a great idea–it’s not really adequate to the task), while it will reject most incoming IPv4 connections, it will allow all IPv6 connections through. For those not using it as a firewall, if their actual firewall allows the IPv6 tunnel (and most firewalls allow all inbound connections out, which would allow the tunnel to be established), the tunnel then becomes a path through the firewall. That is, if you put this device on your network in its default configuration, you’ve just completely opened up your internal systems to connections from any IPv6 host–your firewall may as well not be there, from an IPv6 perspective. There is no “disable IPv6” option, but if you set the device to “Link Local” mode instead of “Tunnel” mode, it will only talk IPv6 to your internal network, not to the outside world. My own home network runs IPv4 and IPv6, including wirelessly, but I have my wireless network as a separate network off my firewall, and have IPv6 firewall rules in place. It’s my firewall that provides the tunnel to the IPv6 Internet. This means that any machines connected to my wireless network that want to communicate with machines on my wired network (like servers) need to pass traffic through the firewall to get to them. Also, as my firewall is an OpenBSD machine, it will not route (for security reasons) the 6to4 packets the Apple AirPort is using to create automatic IPv6 tunneling (though this makes IPv4-to-v6 migration even more difficult). Note that in the comments on the Apple AirPort article at Ars Technica, one commenter says “The primary reason why the situation is so bad with IPv4, is that almost the entire address space is populated. Worms and virii can easily guess neighboring addresses, and since most of those are windows machines, they make great targets.” This gives a false sense of safety to IPv6, as security researchers have already pointed out numerous ways in which worms can locate other IPv6 hosts despite the sparsely populated IP space (PDF).

February 19, 2007 · 3 min

Jeff Han multitouch demo

Jeff Han (who gave a very interesting demo at the TED conference last year) has formed a company called Perceptive Pixel which makes even larger touch screens. This video is a demo of some of the interesting user interfaces that multitouch provides. Lippard (2007-02-18): Fixed. Either the default settings for BrightCove include "autostart=true" or I copied the HTML from a source that was set that way. That was annoying. ...

February 14, 2007 · 1 min

The economics of information security

Ross Anderson and Tyler Moore have published a nice paper that gives an overview of recent research in the economics of information security and some open questions (PDF). The paper begins with an overview of the relevance of economic factors to information security and a discussion of “foundational concepts.” The concept of misaligned incentives is described with the now-standard example of how UK and U.S. regulations took opposite positions on liability for ATM fraud is given–the UK held customers liable for loss, while the U.S. held banks liable for loss. This led to U.S. banks having incentives to make their systems secure, while UK banks had no such incentives (and the UK has now reversed its position after this led to “an epidemic of fraud”). other examples are given involving anti-virus deployment (where individuals may not have incentives to purchase software if the major benefit is preventing denial of service attacks on corporations), LoJack systems (where auto theft plummets after a threshold number of auto owners in a locality install the system), and the use of peer-to-peer networks for censorship resistance. The authors examine the economics of vulnerabilities, of privacy, of the deployment of security mechanisms including digital rights management, how regulation and certification can affect system security (and sometimes have counterintuitive adverse effects, such as Ben Edelman’s finding that TRUSTe certified sites are more likely to contain malicious content than websites as a whole). They end the paper with some open issues–attempts to develop network protocols that are “strategy-proof” to prevent cheating/free-riding/bad behavior, how network topologies have different abilities to withstand different types of attacks (and differing vulnerabilities), and how the software development process has a very high failure rate for large projects, especially in public-sector organizations (e.g., as many as 30% are death-march projects). There are lots of interesting tidbits in this paper–insurance for vulnerabilities, vulnerability markets, the efficacy of spam on stock touting, the negligible effect of music downloads on music sales, and how DRM has moved power from record labels to platform owners (with Apple being the most notable beneficiary), to name a few. (Hat tip to Bruce Schneier’s blog, where you can find links to a slide presentation that covers the highlights of this paper.)

February 13, 2007 · 2 min

I've won a Thinking Blogger award!

I’ve been awarded a Thinking Blogger award, courtesy of Larry Moran at Sandwalk: Strolling with a Skeptical Biochemist. Thanks, Larry! As per the rules of this award-meme, I must tag five other blogs that make me think: 1. Glen Whitman and Tom W. Bell at Agoraphilia 2. The Technology Liberation Front 3. Martin Geddes at Telepocalypse 4. Ed Felten at Freedom-to-Tinker 5. Kevin Carson at the Mutualist blog

February 13, 2007 · 1 min

What's happened to The Simple Dollar?

The Simple Dollar blog is offline, and its author is looking for a way to get back online. I’ve been reading Trent’s The Simple Dollar blog since mid-December. It’s a very well-written, professional-looking blog that gets a lot of traffic, but I was surprised to learn that he only started it about a month before I started reading it. Today, I noticed a lot of Google searches for “The Simple Dollar” were hitting my blog, all coming to my post about Robert Kiyosaki that linked to Trent’s blog. I clicked on the link to re-read his post, only to get a “Forbidden” message from his webserver. I contacted Trent to see if the problem was a legal issue, perhaps a threat from Kiyosaki, but it turns out his entire blog has been taken offline by Dreamhost, his webhosting provider. It seems that today The Simple Dollar–already in the top 2800 at Technorati–got prominent links from both digg.com and reddit.com. This generated so much traffic to the shared server hosting the blog that Dreamhost disabled the account and denied access to the blog. Not only have they denied web access, they’ve denied Trent FTP access. He does have a backup from a few days ago, but is currently looking for a way to get back online with a dedicated server. You can read his own account of his predicament at Metafilter. I’ve offered a few suggestions for possible webhosting providers, but he doesn’t think he can afford a dedicated server right now. That’s in part because, despite his huge traffic, his blog has grown in popularity so fast that he hadn’t yet acquired any major advertisers. He’s been the victim of his own too-rapid success. Are there any advertisers out there who would be willing to help finance the blog’s return on a dedicated server with sufficient bandwidth to handle the traffic? UPDATE (February 10, 2007): The Simple Dollar (or at least most of its content) is back!

February 10, 2007 · 2 min

Warner Music: we'd rather go out of business than give customers what they want

After Steve Jobs said that he’d prefer to have the iTunes store sell DRM-free music, but is forced into DRM by the music labels, Edgar Bronfman of Warner Music said that his company will have nothing to do with DRM-free music: “We advocate the continued use of DRM,” Bronfman said, adding that music deserves the same anti-piracy protections as software, TV broadcasts, video games and other forms of intellectual property. “We will not abandon DRM nor services that are successfully implementing DRM for both content and consumers."This quote appeared in an article reporting Warner’s dismal results: its fiscal first-quarter profit fell 74% because of fewer album releases and soft domestic and European sales. Its shares fell nearly 6%. The New York-based recording company said net income for the period that ended Dec. 31 declined to $18 million, or 12 cents a share, from $69 million, or 46 cents, a year earlier. Revenue fell 11% to $928 million.The competition at EMI, however, feels differently: Music label EMI Group is in talks to release a large portion of its music catalog for Web sales without technological protections against piracy that are included in most music bought over the Internet now, sources said on Thursday. … One source familiar with the matter said that EMI was in talks to release a large amount of its music in an unprotected MP3 format to various online retailers.EMI’s plans apparently include talks with Shawn Fanning’s SnoCap about releasing MP3-format music through MySpace. Which company is more likely to still be in business under the same management ten years from now?

February 9, 2007 · 2 min

The RIAA doesn't understand economics

The Recording Industry Association of America has a web page arguing that we’re all getting a fantastic deal on compact discs because, if they had gone up in price along with the Consumer Price Index, they’d be over $33 each. As Ben Woods points out, by that same argument Texas Instruments calculators that cost $20 in the mid-1980s should have cost over $300. In fact, the recording labels engaged in price fixing, by setting “minimum advertised pricing” on CD retailers, which caused prices to stop their downward trend in 1996–and causing a decline in sales as prices increased. If you want to sell more CDs, lower the price. (Via Techdirt.) UPDATE (February 9, 2007): This post at kuro5hin from January 2003 on “RIAA vs. MP3 vs. Adam Smith” addresses compact disc pricing and demand. UPDATE (February 10, 2007): And this post at Techdirt reports on a study that shows no measurable effect on CD sales from online downloads (as opposed to, say, CD prices).

February 9, 2007 · 1 min

Selling nothing for something

Long or Short Capital reports that: [Conceptual] artist Jonathon Keats has digitally generated a span of silence, four minutes and thirty-three seconds in length, portable enough to be carried on a cellphone. His silent ringtone… is expected to bring quiet to the lives of millions of cellphone users, as well as those close to them.Given the duration of the ringtone, Keats should expect to get sued by the estate of John Cage for copyright infringement.

February 8, 2007 · 1 min

McCain proposes an unfunded mandate for ISPs

Declan McCullagh at News.com reports that Sen. John McCain is preparing to hold a press conference with John Walsh of America’s Most Wanted and Miss America 2007 to announce a bill that will create a new mandate for Internet Service Providers to eavesdrop on all of their customers email and web traffic in search of child porn images. The act apparently requires ISPs to implement new technology to compare all images transmitted or received by their customers to a federal database of images (presumably via some one-way hash function, so that the database is not itself distributing child pornography), and to report any that are detected to John Walsh’s National Center for Missing and Exploited Children, a nonprofit, non-governmental organization that operates as a clearinghouse/proxy for federal and state law enforcement with Congressional mandate and federal funding. The new bill is known as the Securing Adolescents From Exploitation Online or SAFE Act, and is not to be confused with the 2003 SAFE Act (Security and Freedom Ensured), the 1997 SAFE Act (Security and Freedom through Encryption), or the 1998 SAFE Act (Safety Advancement For Employees).

February 8, 2007 · 1 min
Mastodon Verification