Here are the latest TSA guidelines for the traveling public, courtesy of The Onion, which bills itself as America's finest news source. Thanks to Schneier on Security for the link.
New TSA passenger screening guidelines, courtesy of the Onion
Story about feds visiting after request for Mao book is a hoax
From the same source that originally reported the story comes news that the story about a visit from federal agents following an interlibrary loan request for Mao's Little Red Book is a hoax. The student now admits making up the story:
Federal agents' visit was a hoax: 12/ 24/ 2005Student admits he lied about Mao book
By AARON NICODEMUS, Standard-Times staff writer
NEW BEDFORD -- The UMass Dartmouth student who claimed to have been visited by Homeland Security agents over his request for "The Little Red Book" by Mao Zedong has admitted to making up the entire story.
The 22-year-old student tearfully admitted he made the story up to his history professor, Dr. Brian Glyn Williams, and his parents, after being confronted with the inconsistencies in his account.
Had the student stuck to his original story, it might never have been proved false.
But on Thursday, when the student told his tale in the office of UMass Dartmouth professor Dr. Robert Pontbriand to Dr. Williams, Dr. Pontbriand, university spokesman John Hoey and The Standard-Times, the student added new details.
The agents had returned, the student said, just last night. The two agents, the student, his parents and the student's uncle all signed confidentiality agreements, he claimed, to put an end to the matter.
But when Dr. Williams went to the student's home yesterday and relayed that part of the story to his parents, it was the first time they had heard it. The story began to unravel, and the student, faced with the truth, broke down and cried.
It was a dramatic turnaround from the day before.
For more than an hour on Thursday, he spoke of two visits from Homeland Security over his inter-library loan request for the 1965, Peking Press version of "Quotations from Chairman Mao Tse-Tung," which is the book's official title.
His basic tale remained the same: The book was on a government watch list, and his loan request had triggered a visit from an agent who was seeking to "tame" reading of particular books. He said he saw a long list of such books.
In the days after its initial reporting on Dec. 17 in The Standard-Times, the story had become an international phenomenon on the Internet. Media outlets from around the world were requesting interviews with the students, and a number of reporters had been asking UMass Dartmouth students and professors for information....
I reported on the original story (The Canadian Privacy Law Blog: Borrow the wrong book and get it personally delivered by the feds) as did hundreds of other blogs, assuming it to be true. Well, it simply was not which shows the risk of believing what you read about on a blog, or in the conventional media (since the story originated with the South Coast Times of Massachusetts).
I tend to agree with most of what Bruce Schneier observes on this latest turn of events:
"I don't know what the moral is, here. 1) He's an idiot. 2) Don't believe everything you read. 3) We live in such an invasive political climate that such stories are easily believable. 4) He's definitely an idiot."
I won't tell which parts I agree with most ...
Korea Solves the Identity Theft Problem
Rob Hyndman is pointing to Schneier on Security: Korea Solves the Identity Theft Problem. Apparently, Korea is about to pass a law placing full responsibility for losses on the banks for identity theft and online financial fraud, even if the bank is only partially responsible. This will provide the incentive to put in place fraud-blocking measures.
The next questions are: (i) will it work? and (ii) will it only be a Korean phenomenon?
Insightful blog-post on the nature of privacy
Bruce Schneider, one of the leading thinkers on security has recently had some interesting things to say about privacy. In my experience, most IT-types usually think about privacy as being primarily a security issue: you keep information private by keeping the baddies out. But privacy is more than that. It's about giving people control over their own personal information....
Schneier on Security: The Digital Person:"Last week, I stayed at the St. Regis hotel in Washington, DC. It was my first visit, and the management gave me a questionnaire, asking me things like my birthday, my spouse's name and birthday, my anniversary, and my favorite fruits, drinks, and sweets. The purpose was clear; the hotel wanted to be able to offer me a more personalized service the next time I visited. And it was a purpose I agreed with; I wanted more personalized service. But I was very uneasy about filling out the form.
It wasn't that the information was particularly private. I make no secret of my birthday, or anniversary, or food preferences. Much of that information is even floating around the Web somewhere. Secrecy wasn't the issue.
The issue was control. In the United States, information about a person is owned by the person who collects it, not by the person it is about. There are specific exceptions in the law, but they're few and far between. There are no broad data protection laws, as you find in the European Union. There are no Privacy Commissioners, as you find in Canada. Privacy law in the United States is largely about secrecy: if the information is not secret, there's little you can do to control its dissemination...."
If you aren't a regular reader of Schneider on Security, I highly recommend adding it to your blogroll.
Entertainment industry accused of 'trying to hijack data retention directive'
Many people are willing to sacrifice some privacy to gain increased security. In this "age of terrorism", initiatives such as the European Data Retention Directive and the Canadian Lawful Access proposals seem more palatable when we are told they are essential to protecting against serious crimes such as terrorism. The European Data Protection Directive has consistenly been "sold" as being limited to protecting the continent against terrorism. Now, representatives of the entertainment industry are making the request that the retained information be available for investigations of copyright and other IP violations. Critics are saying that the entertainment industry is trying to hijack the directive. See: Entertainment industry 'trying to hijack data retention directive' - ZDNet UK News.
Also, check out the discussion on Slashdot: Slashdot | Music Industry 'trying to hijack EU data laws'.
Update (20051127) from Schneier on Security: European Terrorism Law and Music Downloaders:
"Our society definitely needs a serious conversation about the fundamental freedoms we are sacrificing in a misguided attempt to keep us safe from terrorism. It feels both surreal and sickening to have to defend out fundamental freedoms against those who want to stop people from sharing music. How is possible that we can contemplate so much damage to our society simply to protect the business model of a handful of companies."
Cartoon: False sense of security
Thanks to Bruce Schneier for pointing to this great cartoon: False sense of security.
Schneier on Security: ChoicePoint Says "Please Regulate Me"
Wired News: Fatal Flaw Weakens RFID Passports
Bruce Schneier has a great article at Wired News on the new RFID enabled passports that the US Government is introducing. It chronicles the security problems and the (half way) solutions offered by the US State Department. It is very interesting reading, both for those interested in the actual project and those interested in problems that can arise in projects with privacy issues that require a high level of technical expertise:
Wired News: Fatal Flaw Weakens RFID Passports"...The State Department has done a great job addressing specific security and privacy concerns, but its lack of technical skills is hurting it. The collision-avoidance ID is just one example of where, apparently, the State Department didn't have enough of the expertise it needed to do this right.
Of course it can fix the problem, but the real issue is how many other problems like this are lurking in the details of its design? We don't know, and I doubt the State Department knows either. The only way to vet its design, and to convince us that RFID is necessary, would be to open it up to public scrutiny.
The State Department's plan to issue RFID passports by October 2006 is both precipitous and risky. It made a mistake designing this behind closed doors. There needs to be some pretty serious quality assurance and testing before deploying this system, and this includes careful security evaluations by independent security experts. Right now the State Department has no intention of doing that; it's already committed to a scheme before knowing if it even works or if it protects privacy."
Schneier on Security: Choicepoint's CISO Speaks
Bruce Schneier has some interesting comments flowing from an interview with the CISO of ChoicePoint that appeared in SearchSecurity.com:
Schneier on Security: Choicepoint's CISO Speaks: "Choicepoint's CISO Speaks
Richard Baich, Choicepoint's CISO, is interviewed on SearchSecurity.com:This is not an information security issue. My biggest concern is the impact this has on the industry from the standpoint that people are saying ChoicePoint was hacked. No we weren't. This type of fraud happens every day.Nice spin job, but it just doesn't make sense. This isn't a computer hack in the traditional sense, but it's a social engineering hack of their system. Information security controls were compromised, and confidential information was leaked.
It's created a media frenzy; this has been mislabeled a hack and a security breach. That's such a negative impression that suggests we failed to provide adequate protection. Fraud happens every day. Hacks don't.So, Choicepoint believes that providing adequate protection doesn't include preventing this kind of attack.
I'm sure he's exaggerating when he says that 'this type of fraud happens every day' and 'frauds happens every day,' but if it's true then Choicepoint has a huge information security problem."
The article and interview are worth reading on their own, as well.
Through-the-wall audio surveillance
Thanks to Bruce Schneier (Schneier on Security: Eavesdropping Through a Wall) for directing me to an interesting US patent application for through-the-wall audio surveillance technology that was developed in association with NASA: United States Patent Application: 0050220310.
Privacy Risks of Used Cell Phones
A few months ago, I used a loaner Blackberry for a week or so. When I was bored and fiddling around with it, I discovered the "saved messages" folder on the device had about a dozen e-mails in it from a previous user. Not good. I deleted them all and then did a bit of research to make sure that I didn't leave any data behind when I returned it.
This has just happened on a massive scale, according to Schneier on Security. He's blogging about a recent incident that has more than a few cellular customers hopping mad. When trading up, customers of a certain cellular provider were asked if they wanted to donate their older phones to charities, such as local women's shelters. The phones ended up on e-bay and the company didn't even bother purging the phones of data. Not good in more ways than one. See Schneier on Security: Privacy Risks of Used Cell Phones.
NYT: Some Sympathy for Paris Hilton
The most recent Sunday New York Times has an article on the past week in privacy. Both the Paris Hilton and ChoicePoint incidents are discussed. The Times also quotes Bruce Schneier, the author of Schneier on Security.
The New York Times > Week in Review > Some Sympathy for Paris Hilton:"...But the implications of the problem at ChoicePoint are enormous, said Daniel J. Solove, an associate professor of law at George Washington University and author of 'The Digital Person: Technology And Privacy in The Information Age.' The company, he noted, has collected information on practically every adult American, and 'these are dossiers that J. Edgar Hoover would be envious of.' Government has looked into ways to mine commercial data to detect patterns of suspicious activity, he noted, and it will continue to do so. But who watches the watchers? Lawmakers like Senators Charles Schumer of New York and Dianne Feinstein of California are calling for tighter regulation of data brokers. That would be a good idea, said Marc Rotenberg, executive director of the Electronic Privacy Information Center in Washington. 'It's a big, largely unregulated industry that doesn't bear consequences when things go wrong.' Even those who pursue fame, he noted, deserve a measure of privacy...."
Bruce Schneider on RFID passports
Most followers of computer security and privacy news know about Bruce Schneier. (He is the author and editor of the Crypto-Gram newsletter and of Beyond Fear: Thinking Sensibly about Security in an Uncertain World.) In his recent blog entry about the security and privacy issues related to the reports that RFID will be added to American passports (see Wired News: American Passports to Get Chipped), he very clearly articlates the perceived privacy risks of adding this technology to passports. I would only add that the same risks are inherent in adding RFID to any identity document.
Schneier on Security: RFID Passports:"October 04, 2004
RFID Passports... But the Bush administration is advocating radio frequency identification (RFID) chips for both U.S. and foreign passports, and that's a very bad thing.
These chips are like smart cards, but they can be read from a distance. A receiving device can "talk" to the chip remotely, without any need for physical contact, and get whatever information is on it. Passport officials envision being able to download the information on the chip simply by bringing it within a few centimeters of an electronic reader.
Unfortunately, RFID chips can be read by any reader, not just the ones at passport control. The upshot of this is that travelers carrying around RFID passports are broadcasting their identity.
Think about what that means for a minute. It means that passport holders are continuously broadcasting their name, nationality, age, address and whatever else is on the RFID chip. It means that anyone with a reader can learn that information, without the passport holder's knowledge or consent. It means that pickpockets, kidnappers and terrorists can easily--and surreptitiously--pick Americans or nationals of other participating countries out of a crowd.
...
The Bush administration is deliberately choosing a less secure technology without justification. If there were a good offsetting reason to choose that technology over a contact chip, then the choice might make sense.
Unfortunately, there is only one possible reason: The administration wants surreptitious access themselves. It wants to be able to identify people in crowds. It wants to surreptitiously pick out the Americans, and pick out the foreigners. It wants to do the very thing that it insists, despite demonstrations to the contrary, can't be done.
Normally I am very careful before I ascribe such sinister motives to a government agency. Incompetence is the norm, and malevolence is much rarer. But this seems like a clear case of the Bush administration putting its own interests above the security and privacy of its citizens, and then lying about it."
Schneier on Security: ChoicePoint
Bruce Scheier has a good comment on the ChoicePoint fiasco and the lessons to be learned about incident response:
Schneier on Security: ChoicePoint:"...This story would have never been made public if it were not for SB 1386, a California law requiring companies to notify California residents if any of a specific set of personal information is leaked.
ChoicePoint's behavior is a textbook example of how to be a bad corporate citizen. The information leakage occurred in October, and it didn't tell any victims until February. First, ChoicePoint notified 30,000 Californians and said that it would not notify anyone who lived outside California (since the law didn't require it). Finally, after public outcry, it announced that it would notify everyone affected...."
You too can be hacked when the answer to your secret question is the name of your famous, book-writing dog
How secret is your "secret question" when you are famous for being famous and your life is an open book. It is looking more and more like Paris Hilton's Sidekick II was hacked into thanks to really, really bad password protection. Or, as MacDevCenter points out, a really obvious "secret question" to make it really easy for users who have fogotten their passwords.
"Like many online service providers, T-Mobile.com requires users to answer a 'secret question' if they forget their passwords. For Hilton's account, the secret question was 'What is your favorite pet's name?' By correctly providing the answer, any internet user could change Hilton's password and freely access her account. "
Apparently her dog, Tinkerbell, is almost as famous as her. He is an author (The Tinkerbell Hilton Diaries: My Life Tailing Paris Hilton), a fashion accessory and a dog-about-town. Anybody with more interest in inane celebrities than I would have been able to get her secret question and log into the T-Mobile system.
For a good review of the inherent weakness of these systems, see Schneier on Security: The Curse of the Secret Question.
Paris Hilton's Sidekick gets hacked
The Internet is abuzz this morning with the exciting contents of Paris Hilton's T-Mobile Sidekick. It appears that someone hacked into the T-Mobile system and was able to get the contents of her address book, notepad and the photos she had take with the gadget. Most of the links earlier today were to the photos themselves, which are not "safe for work".
Most of the discussion about it suggests that it may be related to the recent hacking of T-Mobile's systems (see PIPEDA and Canadian Privacy Law: Incident(s): Hacker breaches T-Mobile systems, reads US Secret Service email), but it could just have easily been a result of someone guessing her password and accessing the system via the T-Mobile login page. I wouldn't be surprised if her password was "password".
This incident does, however, highlight the vulnerability of personal information when it is in possession of third parties. Our e-mail and address books are held by Yahoo! or Hotmail or whoever. Our voice mail resides on some telco server and our instant messages are archived. It used to be that the bad guys had to break into our homes and offices for this stuff. Now they just have to hack into one of dozens of systems. (See Schneier on Security: T-Mobile Hack).
For (safe for work) coverage of the incident, see Paris Hilton's Sidekick gets hacked. What is T-Mobile going to do about it? - Engadget - www.engadget.com and Hackers post Paris Hilton's address book online - Computerworld:
"Hackers post Paris Hilton's address book onlineA copy of her T-Mobile USA cell phone address book appeared on the Web
News Story by Paul Roberts
FEBRUARY 21, 2005 (IDG NEWS SERVICE) - Hackers penetrated the crystalline ranks of Hollywood celebrity Saturday, posting the cellular phone address book of hotel heiress and celebrity Paris Hilton on a Web page and passing the phone numbers and e-mail addresses of some of Tinsel Town's hottest stars into the public realm.
A copy of Hilton's T-Mobile USA Inc. cell phone address book appeared on the Web site of a group calling itself 'illmob.' The address book contains information on over 500 of Hilton's acquaintances, including super celebrities such as Eminem and Christina Aguilera. It is not known how the information was obtained, but the release of the contact book may be further fallout from a hack of T-Mobile's servers that came to light in January...."
Schneier on Private Webcams and the Police
Since the Conrona (Southern California) Chamber of Commerce and the local police have begun asking local businesses to provide law enforcement with access to the feeds from local businesses' web-enabled security cameras, Bruce Schneier asks how long it will be before a law is passed requiring a backdoor for police?: Schneier on Security: Private Webcams and the Police.
"Lawful access" to the next level? "We're just keeping up with technology. In the olden days, we'd be able to post a cop in front of your store so this is no different ..."
RFID Cartoon
Thanks to Bruce Schneier for leading me to this great RFID Cartoon.
It's funny because it's true.
