The U.S. no-fly list is a joke

Steve Kroft of 60 Minutes has obtained a copy of the no-fly list being used for airline passenger screening. The list includes people who are not a threat (like Evo Morales, president of Bolivia, Saddam Hussein, and 14 of the 19 dead 9/11 hijackers). It includes numerous common names that are useless for screening purposes–Gary Smith, John Williams, and Robert Johnson are on the list. Kroft spoke with 12 Robert Johnsons, and all of them said they are detained almost every time they try to fly. Worse yet, it doesn’t include the names of some of the most dangerous living terrorists: The 11 British suspects recently charged with plotting to blow up airliners with liquid explosives were not on it, despite the fact they were under surveillance for more than a year. The name of David Belfor who now goes by Dahud Sala Hudine, is not on the list, even though he assassinated someone in Washington, D.C., for former Iranian leader Ayatollah Khomeini. This is because the accuracy of the list meant to uphold security takes a back seat to overarching security needs: it could get into the wrong hands. “The government doesn’t want that information outside the government,” says Cathy Berrick, director of Homeland Security investigations for the General Accounting Office.I’d say that particular name is well known outside of the government now, Ms. Berrick. The TSA has allegedly been trying to fix the list for three years, spending $144 million to do so, but there is “nothing tangible yet." This is staggering incompetence. Kip Hawley is still an idiot. UPDATE (October 5, 2006): I second Tim Lee’s recommendation of Jim Harper’s commentary on what’s wrong with watch lists.

October 5, 2006 · 2 min

Kip Hawley is an idiot

Ryan Bird wrote “Kip Hawley is an idiot” on his clear plastic bag of toiletries that he was carrying through a TSA security checkpoint at Milwaukee’s General Mitchell International Airport. Kip Hawley is the head of the Transportation Security Administration. Bird writes: At the MKE “E” checkpoint I placed my laptop in one bin, and my shoes, cell phone and quart bag in a second bin. The TSA guy who was pushing bags and bins into the X-ray machine took a good hard look, and then as the bag when though the X-ray I think he told the X-ray operator to call for a bag check/explosive swab on my roller bag to slow me down. He went strait to the TSA Supervisor on duty and boy did he come marching over to the checkpoint with fire in his eyes! He grabbed the baggie as it came out of the X-ray and asked if it was mine. After responding yes, he pointed at my comment and demanded to know “What is this supposed to mean?” “It could me a lot of things, it happens to be an opinion on mine.” “You can’t write things like this” he said, “You mean my First Amendment right to freedom of speech doesn’t apply here?” “Out there (pointing pass the id checkers) not while in here (pointing down) was his response." At this point I chuckled, just looking at him wondering if he just realized how foolish that comment was, but I think my laugh pushed him over the edge as he got really angry at this point. A Milwaukee County Sheriffs deputy was summoned - I would have left at this point, but he had my quart bag with my toothpaste and hair gel. When the deputy got over the TSA supervisor showed him the bag and told him what had happened to that point. After he had finished I started to remind him he had left out his statement that my First Amendment rights didn’t apply “here” but was cut off by the deputy who demanding my ID. I asked if I was under arrest, and his response was “Right now you are not under arrest, you are being detained.” I produced my passport and he walked off with it and called in my name to see if I had any outstanding warrants, etc. The TSA supervisor picked up the phone about 20 feet away and called someone? At this point two more officers were near by and I struck up a conversation with the female officer who was making sure I kept put. I explained to her who Kip Hawley was, why I though he was an idiot, and my surprise that the TSA Supervisor felt my First Amendment rights didn’t’ apply at the TSA checkpoint. She didn’t say much. After he was assured I didn’t have any warrants out the first office came back and I had my first chance to really speak, I explained that I was just expressing my opinion and my writing should be protected my by First Amendment rights. When he didn’t respond, I then repeated that the TSA Supervisor stated my First Amendment rights didn’t apply at the TSA check point and I asked if he (the deputy) agreed that was the case. He responded by saying “You can’t yell fire in a crowed theater, there are limits to your rights. At this point I chucked again. I asked how this was even remotely like shouting “Fire” in a crowd, and his answer was “Perhaps your comments made them feel threatened." At about this point the TSA Supervisor finished up his phone call, and summoned the officer back over. They talked for about 2 minutes, and then both came back over. The officer pulled out his pad and asked for my address and I asked why he needed it. “For the report I have to file since I was summoned here” I started to give it, when I noticed the TSA Supervisor was writing it down as well, so I stopped and asked why he needed it. He said he needed to file an incident report too, and I took the opportunity to ask what the resolution of the incident was, did I do anything wrong? Are you going to ask the officer to arrest me? He said no, I was free to go, but he was going to confiscate my bag. I asked “If I did nothing wrong, why would you take my bag” He pointed to a posted sign that said something about reusing plastic bags (the MKE TSA was providing quart sized zipper bags to pax today) I let him know that I had brought my bag from home and would not be letting him take it. He then asked for permission of photograph it, which I agreed too. While he walked away to get the camera I finished giving my address to the deputy, and he told my “You’re free to go” Total time, about 25 minutes.Hat tip to Tim Lee at the Technology Liberation Front. CNN’s given coverage to the story. Also see kiphawleyisanidiot.com. ...

September 30, 2006 · 5 min

The ineffectiveness of TRUSTe

The TRUSTe program is supposed to certify that a website has a reasonable privacy policy. But Ben Edelman has cross-referenced TRUSTe certifications with SiteAdvisor ratings, and found that sites with TRUSTe certifications are twice as likely as those without to be listed as “untrustworthy” in SiteAdvisor’s database–meaning that they send out spam, distribute spyware, etc. Edelman calls out four particularly notorious sites that have or have had TRUSTe certification: Direct-Revenue.com, Funwebproducts.com, Maxmoolah.com, and Webhancer.com. All four are heavily involved with spyware. Direct Revenue and Maxmoolah have had their TRUSTe certifications revoked, but should never have been certified in the first place if TRUSTe was doing the validation they should have been doing. TRUSTe has long been criticized by anti-spammers for giving certifications to organizations that don’t deserve them. Ryan Singel has raised similar questions about TRUSTe’s reliability. ...

September 29, 2006 · 2 min

Hotel minibar keys open Diebold voting machines

Ed Felten points out that Diebold voting machines use a standard, commonly used key that is used for things like hotel minibars, office furniture, jukeboxes, and electronic equipment. UPDATE (January 23, 2007): Diebold helpfully displays a photograph of the key on their website–which is sufficient to make a duplicate that works.

September 18, 2006 · 1 min

More on Diebold voting machine insecurity

Ed Felten announces the release of his paper and an accompanying video about major security issues with Diebold AccuVote-TS voting machines.

September 13, 2006 · 1 min

Tech Liberation Front brings on a Discovery Institute representative

The Technology Liberation Front is a blog I’ve been reading for a few months for its quality contributions on issues involving technology, regulation, copyright, digital rights management (DRM), network neutrality, and so on. It covers a lot of the same topics as Ed Felten’s excellent Freedom-to-Tinker blog, with a strong libertarian bent. What a disappointment it was to see that the newest contributor, Hance Haney, comes from the Technology & Democracy Project at the Discovery Institute. While Haney is in Washington D.C. and is not affiliated with the intelligent design wing (the Center for Science and Culture), crackpot George Gilder is a senior fellow of the TDP. I commented to this effect at the Technology Liberation Front, which prompted a response from Lewis Baumstark: As I have no previous knowledge of Hance or the Discovery Institute, I prefer to allow him to live or die here on the merits of his debate and analysis, not on his link to a pro-ID institution.Lewis should remedy his ignorance of the Discovery Institute before coming to a conclusion about whether such an association taints Hance’s reputation and credibility–surely he would not have said the same if Hance was a representative of the (in some ways more honest) Institute for Creation Research or International Flat Earth Society. As readers of this blog know well, the Discovery Institute has a long history of dishonest and deceptive public statements and attempts to influence public opinion, public policy, and educational standards. Do a Google search for “Discovery Institute site:lippard.blogspot.com” or “Dembski site:lippard.blogspot.com” for numerous examples at this blog; many more can be found at scienceblogs.com (especially Dispatches from the Culture Wars and Pharyngula) or The Panda’s Thumb. Jim Harper of TLF responded to Lewis’s comment by writing “And the winner is . . . Lewis Baumstark! Curious. Courteous. Way to go, Lewis!” How odd that he would declare Lewis the “winner” when Lewis claimed ignorance of the Discovery Institute, or call him “curious” when his comment betrayed no interest in rectifying that ignorance. “Courteous,” I’ll grant. I agree with the comment at TLF from Cog (of the Abstract Factory blog): ...

August 26, 2006 · 5 min

AT&T sues data brokers selling phone call records

AT&T has filed a lawsuit against 25 unnamed data brokers for using “pretexting” to obtain customer call data records. These data brokers would pose as the legitimate customers in order to obtain billing records for third parties for a fee. Data brokers selling this data over the Internet got some negative public attention last summer and in January of this year, but Congress has not made pretexting illegal for phone records the way it is for financial records. It came out in June of this year that law enforcement and federal agencies were active customers of these data brokers, using them to obtain data without having to go through the process of getting warrants. The Electronic Privacy Information Center already filed an FTC complaint against one data broker, Bestpeoplesearch.com. ...

August 23, 2006 · 1 min

Is it worth shutting down botnet controllers?

Gadi Evron has now suggested, following Paul Vixie, that it’s a waste of time to fight botnets by shutting down botnet controllers. Here’s what I wrote to some colleagues when I read Vixie’s statement that stomping out botnets is not only a waste of time, but counter-productive because it causes botherders to change their behavior and find new malicious techniques: 1. If you don’t stomp them they are still going to develop new ways of doing things as a result of internal competition. It may happen more slowly, but it will still happen. There’s no getting around an arms race. Even taking his analogy seriously, he wouldn’t recommend that we stop using antibiotics. 2. Waiting on law enforcement to start effectively prosecuting will take a long time, and I don’t think I’ll be happy with what it will take for them to do it (I’m already unhappy with the new CALEA draft bill that’s circulating). Criminal prosecution will likely never target more than a minority of offenders–mostly the high-profile cases. 3. Taking action raises their costs, which applies more broadly the same economic effect as prosecution does in a narrower and stronger manner. Again, if we take the antibiotic analogy seriously, a diversity of approaches is better than relying on a single approach. 4. Our experience seems to indicate a drop in botnet controller activity when we hit them consistently. If the bulk of miscreants follow the path of least resistance, putting up a fight will tend to push them to environs where people aren’t putting up a fight.Shutting down botnet controllers does have positive effects–and it’s much quicker and reliable than law enforcement prosecution. I think a diversity of defensive actions is important, and we need to continue developing more of them–as I said above, it is a continuing arms race. Richard Bejtlich has also commented on this subject at his TaoSecurity blog, and there’s some good discussion in the comments. David Bianco has offered a suggestion at the InfoSecPotpourri blog. Bianco’s suggestion is to modify the botnet C&C traffic, which in order to be most effective would have to occur at either large consumer ISPs (where 99+% of the bots are located) or at a small number of high-volume, low-cost webhosting companies (where 75+% of the botnet controllers are located). There are a number of approaches that are being developed, which I won’t describe in any detail here, but I agree that new approaches need to go more strongly after the bots themselves rather than just the botnet controllers. Those approaches need to use Netflow, and they need to use DNS. We also need to provide incentives for consumers with old, unpatched, vulnerable systems to protect themselves and to be protected by their ISPs–that’s where the biggest bang for the buck will occur.

August 18, 2006 · 3 min

Nick Carr's bogus criticism of the blogosphere

Nick Carr writes of the blogosphere: What we tell ourselves about the blogosphere - that it’s open and democratic and egalitarian, that it stands in contrast and in opposition to the controlled and controlling mass media - is an innocent fraud.What’s the fraud? Carr claims that the top-ranked blogs have established a hierarchy of control over the entire blogosphere: The best way, by far, to get a link from an A List blogger is to provide a link to the A List blogger. As the blogophere has become more rigidly hierarchical, not by design but as a natural consequence of hyperlinking patterns, filtering algorithms, aggregation engines, and subscription and syndication technologies, not to mention human nature, it has turned into a grand system of patronage operated - with the best of intentions, mind you - by a tiny, self-perpetuating elite.But Carr is not only ignoring the facts of a comparison between the blogosphere and the mass media (the point of his initial comparison), he’s ignoring mobility of rank and the specifics of the audiences of lower-ranked blogs. I’ve seen my blog get visits from all sorts of interesting places, by people I would not ordinarily be able to speak to. John Koetsier at bizhack (who I’ve only come across because of this topic) says it very well when he points out the role of luck in getting a mass audience: ...

August 17, 2006 · 7 min

Time fountain

Here’s a gadget Harold Edgerton would have appreciated–Nate True built a little device that pumps dyed water through a tube, drops at a time, with strobe lights that illuminate individual drops as they fall. You can adjust the frequency of the strobe lights so that the drops appear to change in speed, freeze in place, or move backwards. He calls it a “time fountain."

August 11, 2006 · 1 min
Mastodon Verification