Names have been omitted to protect the guilty.
[Director] and [Division Chief] were walking through [major city] Airport discussing the bill of material for [facility] the directorate was engineering. A bill of material is a detailed sheet of all the parts needed for a project. It includes unit prices, quantities, part numbers from both manufacturer and vendor, etc. Since this was a big facility, this was a very large spreadsheet. Too big to actually print out; you had to have a laptop just to keep track of the whole sheet. Near the security checkpoint, the director says to division chief (or vice versa, reports vary), "Leave your laptop out and we'll work on the BOM on the plane."
They did not make their flight. When they were next allowed to communicate, every employee in the organization received a directive email, effective immediately and punitive, to scrub all references to "bill of material" and its acronym from all publications and replace with "List of Material (LOM)."
Now this story has to be true because it's been a decade since I've seen anyone use "bill of material." It's always "list of material" now.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Friday, April 14, 2017
Wednesday, February 15, 2017
Thumb's Up
Well, I did myself a good one just the other day. Nearly took the end of my thumb clean off. A kitchen utensil called a mandolin, used for slicing vegetables, was involved.
Normally I'm much safer with blades, having been using them for so long. Guess I need to rip a corner off my Totin' Chip card.
After any injury, a patient must also be treated for shock which is characterised by a drop in blood pressure and body temperature. I laid down under a blanket and also took a pain reliever. Aspirin, being a blood-thinner, would have been a poor choice of pain reliever but pain relieving and fever reducing ibuprofen is ideal for this type of accident. Take only as directed.
![]() |
| The culprit |
Normally I'm much safer with blades, having been using them for so long. Guess I need to rip a corner off my Totin' Chip card.
On to the first aid instruction portion of this post. Remaining calm when an accident has happened is the most important thing. Panic wastes valuable time needed for the treatment and recovery of the patient. Although, if you hurt yourself, using language that would melt a pirate's ear is an understandable response. After hopping around uttering choice exclamations, I got my bleeding thumb under the faucet to clean the injury and begin assessing the damage. I lost a few tablespoons of blood which helped carry contaminants out of the wound. My girlfriend brought over the first aid kit and I directed her in applying a bandage and dressing to the cut.
![]() |
| Sharp dressed man |
I left the dressing on for 24 hours to ensure that bleeding was controlled, prevent infection, and begin healing the injury. After about 24 hours the dressing and bandage should be removed so the injury can be cleaned again, allowed air and blood circulation, and examined. The examination is to check for and treat infection and be sure the wound has begun healing. Cover the wound with a new bandage and clean dressing if it is likely to continue or resume bleeding. Otherwise, allow the wound air and full circulation to heal.
![]() |
| The result |
Friday, February 14, 2014
Hack Stack
Retail giant Target was hacked late last year in a blow to holiday shoppers across the country. Security investigators found out that the intrusion started with an HVAC contractor. A reasonable computer user, denied access to others' secure systems, could ask themselves what an outside company would be doing with access like this. Let's talk a bit about how large corporate systems are set up and how an attack can cascade like this through a supply chain.
And, no, as user of Target's extranet, Fazio's credentials should not have enabled them to upload to or in any way make contact with any part of Target's point of sale terminals.
Payment Card Industry (PCI) standards now come into play. Companies which submit credit card payments are not required to build a separate network for payment and non-payment activities. But outside users like contractors and vendors are required to use two-factor authentication to access a company's network.
Inter, Intra, and Extra
Most large companies' computer networks are set up in multiple zones. The Internet zone holds customer-facing systems like company webpages, online shopping, and contact information. These systems should only deal with low security issues like presenting product information or mailing addresses. The Intranet zone is for internal use by employees. A company's trouble ticketing system or employee computer-based training terminals are connected to this zone. Extranet is the most complicated zone to manage and secure. This is where partner companies connect to your systems for more access than the internet zone can provide without having employee level access on an intranet user.Extra, Extra, Extra
In Target's case, Fazio Mechanical Services had access credentials to Target's systems to support billing and work contracts when Fazio was hired to perform work on the HVAC systems at Target stores in the Mid-Atlantic region.And, no, as user of Target's extranet, Fazio's credentials should not have enabled them to upload to or in any way make contact with any part of Target's point of sale terminals.
Payment Card Industry (PCI) standards now come into play. Companies which submit credit card payments are not required to build a separate network for payment and non-payment activities. But outside users like contractors and vendors are required to use two-factor authentication to access a company's network.
Labels:
certifiable,
cissp,
security
Friday, January 31, 2014
Targeted
Everyone is well aware of retail runner up Target and their recent hacking. And this event couldn't have come at a worse time for them. Their systems were compromised over Thanksgiving weekend, the traditional start of the holiday shopping season, and stayed pwned for several weeks. Fortunately, they've plugged the holes and were able to continue on with their holiday sales season.
Meanwhile, banks around the country are taking steps to protect their customers' banking details. Apparently, in light of lessons learned from major breaches like Heartland Payment Systems, many found it less expensive to just reissue thousands to millions of new cards to any customers who may or even might not be affected. A major credit union here in Arizona is issuing new cards and numbers for 877 potentially compromised accounts.
While the stolen credit card information has already been put up for sale, Target insists that at least the PINs associated with debit cards were securely encrypted, specifically with Triple DES, or more properly, the Triple Data Encryption Algorithm, TDEA.
Triple DES is a block cipher, which means it encrypts blocks of data, 64 bits at a time, and does so in three passes, each with a different key based on the keying option used. Data Encryption Standard (DES), with only a 56 bit key, is too weak to protect data against brute force attacks by modern hardware and has been removed as a standard. Triple DES itself, by stacking up on the encryption with multiple keys, is considered secure enough against any practical attacks. It has, however, been replaced in most applications with Advanced Encryption Standard (AES).
Target wasn't specific as to which keying option of Triple DES was being used, though they made it clear that they never had any of the keys. Knowing which keying option was being employed could direct an attacker to a method of exploit. Since Triple DES encrypts with key one, decrypts with key two, and then encrypts again with key three, the most secure option is that all three keys are different. That usually isn't the way it's done in practice; typically the first and third key are the same. Obviously, if there's only a single key being used three times, the encryption simplifies to a single round of DES and that compatibility is, in fact, why Triple DES does encrypt-decrypt-encrypt instead of three rounds of encrypt.
So what attacks are available? Essentially a rainbow table attack. We can only hope that the payment processor who held the keys held more that one. Single key Triple DES is only DES and that could be broken in less that a day ten years ago. That's a trivial brute force attack today. Option two is the most commonly used method of implementing Triple DES and it's the one that encrypts with the first key, decrypts with a second key, then encrypts once more with the first key again. The issue is that the plaintext being encrypted, all those PINs, is such a small domain. PINs for debit cards are typically only four digits long. At best, 32 bits or half a block. Even worse, the Feistel algorithm that underpins DES and thus Triple DES operates on only a half block at a time. The fluff and random bits that fill out the block might be irrelevant when decrypting stolen debit card PINs. With such a limited domain, chosen plaintext and known plaintext attacks become available. Insanely resource intensive, but available.
As a shout-out, my cryptography professor at the University of Maryland, Lawrence C Washington, along with Wade Trappe, also a Maryland professor at the time, literally wrote the book on cryptography. I have the first edition. Maybe I should've gotten it signed by the authors; I hear signed first editions are valuable. Anyway, it's good to be a terrapin. Let's Go Maryland! Rah! Rah! Ra-ra-rah!
Meanwhile, banks around the country are taking steps to protect their customers' banking details. Apparently, in light of lessons learned from major breaches like Heartland Payment Systems, many found it less expensive to just reissue thousands to millions of new cards to any customers who may or even might not be affected. A major credit union here in Arizona is issuing new cards and numbers for 877 potentially compromised accounts.
While the stolen credit card information has already been put up for sale, Target insists that at least the PINs associated with debit cards were securely encrypted, specifically with Triple DES, or more properly, the Triple Data Encryption Algorithm, TDEA.
Triple DES is a block cipher, which means it encrypts blocks of data, 64 bits at a time, and does so in three passes, each with a different key based on the keying option used. Data Encryption Standard (DES), with only a 56 bit key, is too weak to protect data against brute force attacks by modern hardware and has been removed as a standard. Triple DES itself, by stacking up on the encryption with multiple keys, is considered secure enough against any practical attacks. It has, however, been replaced in most applications with Advanced Encryption Standard (AES).
Target wasn't specific as to which keying option of Triple DES was being used, though they made it clear that they never had any of the keys. Knowing which keying option was being employed could direct an attacker to a method of exploit. Since Triple DES encrypts with key one, decrypts with key two, and then encrypts again with key three, the most secure option is that all three keys are different. That usually isn't the way it's done in practice; typically the first and third key are the same. Obviously, if there's only a single key being used three times, the encryption simplifies to a single round of DES and that compatibility is, in fact, why Triple DES does encrypt-decrypt-encrypt instead of three rounds of encrypt.
So what attacks are available? Essentially a rainbow table attack. We can only hope that the payment processor who held the keys held more that one. Single key Triple DES is only DES and that could be broken in less that a day ten years ago. That's a trivial brute force attack today. Option two is the most commonly used method of implementing Triple DES and it's the one that encrypts with the first key, decrypts with a second key, then encrypts once more with the first key again. The issue is that the plaintext being encrypted, all those PINs, is such a small domain. PINs for debit cards are typically only four digits long. At best, 32 bits or half a block. Even worse, the Feistel algorithm that underpins DES and thus Triple DES operates on only a half block at a time. The fluff and random bits that fill out the block might be irrelevant when decrypting stolen debit card PINs. With such a limited domain, chosen plaintext and known plaintext attacks become available. Insanely resource intensive, but available.
As a shout-out, my cryptography professor at the University of Maryland, Lawrence C Washington, along with Wade Trappe, also a Maryland professor at the time, literally wrote the book on cryptography. I have the first edition. Maybe I should've gotten it signed by the authors; I hear signed first editions are valuable. Anyway, it's good to be a terrapin. Let's Go Maryland! Rah! Rah! Ra-ra-rah!
Labels:
certifiable,
cissp,
security
Thursday, December 19, 2013
Security Credit
Bottom line up front the way the generals like it. I take on
vulnerability, all the additional threat is against me, and I assume all
the risk. Just to have my job.
Executive summary because the bosses who wear stars on their camouflage at the office like those, too. There's a bit of utter stupidity to being a government employee. In my job I am required to hold a government travel card and government passport. That's right, I am required to increase my attack footprint [pdf] to have my job.
It isn't common, but if the government doesn't settle travel expenses in a timely manner, it hurts my credit. Just having it as an open account hurts my credit. And not just the temptation for me to use or misuse the account as that linked article is concerned about. It is yet another valid account for an attacker to break into and use for fraud. The card itself, that stupid chit of plastic, is an identity document which can be counterfeit. Speaking of misuse, done by me or anyone, it hurts my credit not my employer. If some waiter skims the card I have to dispute the fraud or it's my credit rating that gets destroyed. And yes, cards can and are misused in that very way even though they are clearly marked, "For Official Government Travel Only."
The entire program is adds vulnerability to me and I am required to assume all of the risk. I've voiced this to management as an employee and a security professional but the program and the requirement for employment remain unchanged.
Executive summary because the bosses who wear stars on their camouflage at the office like those, too. There's a bit of utter stupidity to being a government employee. In my job I am required to hold a government travel card and government passport. That's right, I am required to increase my attack footprint [pdf] to have my job.
Extra Credit
The points against the credit card are simple and straightforward enough for even a Treasury Department employee to understand. Even though this card is For Official Use Only [pdf], the government has no financial risk in this credit card. Externalities, they call it. It's open credit on my report, not theirs.It isn't common, but if the government doesn't settle travel expenses in a timely manner, it hurts my credit. Just having it as an open account hurts my credit. And not just the temptation for me to use or misuse the account as that linked article is concerned about. It is yet another valid account for an attacker to break into and use for fraud. The card itself, that stupid chit of plastic, is an identity document which can be counterfeit. Speaking of misuse, done by me or anyone, it hurts my credit not my employer. If some waiter skims the card I have to dispute the fraud or it's my credit rating that gets destroyed. And yes, cards can and are misused in that very way even though they are clearly marked, "For Official Government Travel Only."
The entire program is adds vulnerability to me and I am required to assume all of the risk. I've voiced this to management as an employee and a security professional but the program and the requirement for employment remain unchanged.
Papers, Please
Whether I travel outside the United States or not, frequently or not, I am required to hold an official government passport. An identity document which can be misplaced or stolen between trips or while traveling. And, just like with the credit cards, having a valid passport means an attacker can counterfeit a valid identity document for an attack.Bottom's Up
Bottom line at the bottom the way the generals like it. The entire pile of externalities, forcing the employee to assume all this additional risk as a condition of employment, should be redirected back to the organization.Monday, April 22, 2013
Earth Day
Today is Earth Day. This is an annual event to demonstrate support for environmental protection. Started as several different events in 1969 and 1970, it eventually coalesced into a single event and in some places is even celebrated as an entire Earth Week.
I was in the District (Washington, D.C., for those of you outside the Beltway) for Earth Day 2000. That was fun, mostly for the concerts on the National Mall. I saw classics like James Taylor and Carole King, along with then-new bands like Third Eye Blind. Actor Leonardo Di Caprio was there early in the morning. He seemed like a nice guy and still does a lot of work for the environment. It was overcast and drizzly all day so I spent a lot of time under the exhibit tarps. Lots of vendors demonstrating grid-tied and off-grid solar and wind power systems, environmentally friendly building materials, and energy efficient home design and construction. Universities competed in a solar home building competition. Efficient and comfortable off-grid living spaces made of environmentally friendly building materials.
So what can a person do today to help the environment?
I'd suggest recycling if it's available but no one wants to start a new city recycling program. And it's simple economics, the margins are too low. Recycling is so widespread now that there's very little profit for a business and cities trying to run it as a business end up putting in more money than they get out of it. Expecting to make bank by selling off the products diverted from the landfill is bad budgeting. City planners need to add a line item for the increased resilience in the waste management system.
You can plant native plants like trees or grasses. Most developments during the recent housing boom were graded flat and all the existing plant life and even topsoil was scrapped away to make room for the buildings. Then, to increase the selling price, landscaping was installed but was often only possible through large quantities of water and fertilizer, more than native plants would have needed.
Enter systems like xeriscaping. Often mistaken for replacing lawns with gravel like a desert, it is actually about smart application of water. Place plants in zones with healthy water-holding soil and choose species adapted to the local climate. A xeriscaped yard has a healthy micro-biome ranging from natural forest or desert at the periphery up to water filtering marshland in the wet zone. Xeriscaping does not reduce the yard to zero water use, but uses relatively less water than the artificial environment of a lawn.
Of course, native plants provide habitat for native animals. Birds can nest in the trees and critters can forage in the undergrowth the way nature intended. This is especially important when whole ecological systems are falling apart, like what's happening with colony collapse disorder. There is growing implication that neonicotinoid pesticides are killing not only their target pest species but also native pollinators like bees. Providing a safe habitat free from the indiscriminate application of pesticides can only help.
Before any of that is available, you should start composting. It can be done at any scale, from city-wide composting programs to individual backyard projects. Start this year to have strong healthy compost to add to a raised bed garden or even small scale farming next year. Just remember, don't put in any meat, only vegetable kitchen scraps and yard waste. You'll lose the entire batch and have to start over. The real achievement, beyond cooking up healthy compost is vermiculture, compost with worms. You can add store-bought worms but healthy compost will attract native worms from the soil to move in. Plus that guarantees you aren't introducing an invasive species.
So get out there and start an Earth Day project today.
I was in the District (Washington, D.C., for those of you outside the Beltway) for Earth Day 2000. That was fun, mostly for the concerts on the National Mall. I saw classics like James Taylor and Carole King, along with then-new bands like Third Eye Blind. Actor Leonardo Di Caprio was there early in the morning. He seemed like a nice guy and still does a lot of work for the environment. It was overcast and drizzly all day so I spent a lot of time under the exhibit tarps. Lots of vendors demonstrating grid-tied and off-grid solar and wind power systems, environmentally friendly building materials, and energy efficient home design and construction. Universities competed in a solar home building competition. Efficient and comfortable off-grid living spaces made of environmentally friendly building materials.
So what can a person do today to help the environment?
I'd suggest recycling if it's available but no one wants to start a new city recycling program. And it's simple economics, the margins are too low. Recycling is so widespread now that there's very little profit for a business and cities trying to run it as a business end up putting in more money than they get out of it. Expecting to make bank by selling off the products diverted from the landfill is bad budgeting. City planners need to add a line item for the increased resilience in the waste management system.
You can plant native plants like trees or grasses. Most developments during the recent housing boom were graded flat and all the existing plant life and even topsoil was scrapped away to make room for the buildings. Then, to increase the selling price, landscaping was installed but was often only possible through large quantities of water and fertilizer, more than native plants would have needed.
Enter systems like xeriscaping. Often mistaken for replacing lawns with gravel like a desert, it is actually about smart application of water. Place plants in zones with healthy water-holding soil and choose species adapted to the local climate. A xeriscaped yard has a healthy micro-biome ranging from natural forest or desert at the periphery up to water filtering marshland in the wet zone. Xeriscaping does not reduce the yard to zero water use, but uses relatively less water than the artificial environment of a lawn.
Of course, native plants provide habitat for native animals. Birds can nest in the trees and critters can forage in the undergrowth the way nature intended. This is especially important when whole ecological systems are falling apart, like what's happening with colony collapse disorder. There is growing implication that neonicotinoid pesticides are killing not only their target pest species but also native pollinators like bees. Providing a safe habitat free from the indiscriminate application of pesticides can only help.
Before any of that is available, you should start composting. It can be done at any scale, from city-wide composting programs to individual backyard projects. Start this year to have strong healthy compost to add to a raised bed garden or even small scale farming next year. Just remember, don't put in any meat, only vegetable kitchen scraps and yard waste. You'll lose the entire batch and have to start over. The real achievement, beyond cooking up healthy compost is vermiculture, compost with worms. You can add store-bought worms but healthy compost will attract native worms from the soil to move in. Plus that guarantees you aren't introducing an invasive species.
So get out there and start an Earth Day project today.
Monday, May 7, 2012
Don't Push the Red Button
I have a certain level of knowledge about the issues security professionals face and the incidents they cause.
First some background on this incident. A piece of hardware was reset and the encryption keys it contained were "zeroized". Then a message was sent out to the entire section informing them not only of the exploit but also underlying vulnerabilities which carry the risk of a denial of service. Because this incident report came through internal channels, it contains too much secure information to post here. There wouldn't be enough left after redaction. I will, however, discuss the incident in generic terms as a case study. Of course, the risk has been addressed.
Up front, let's address the sender of the message. The message was sent from the Information Management Office, a higher level function than over-titled secretary but that's a distinction that's easy to be confused over. Not that the IMO is unauthorized to distribute information about incidents in the office, but as a general rule nobody should be distributing information on exploits or vulnerabilities. So that's who sent it, but where did it go? To a large office full of non-security job functions. Read that as "potential threats".
Let's move on to the content of the message. The message reveals a successful, yet inadvertent, exploit of a vulnerability with a security device in the office. It clearly describes how to "zeroize" the device and also how long to return to operation. Reading between the lines, additional indicators are revealed. There is a piece of critical equipment in an unsecured location. Anyone in the field should immediately ask what else is in that location. Keeping in mind that these devices will not pass traffic unless it's encrypted, the victim was under a complete denial of service. That operational state could be further exploited while personnel are distracted by recovery efforts.
As a security professional, how do you protect your office from this?
First, educate the threats. This incident was caused by an untrained user accidentally resetting the device. Flat out, every user needs to be properly trained to operate the equipment they have contact with. Also, educate your users about information security. Disclosing the incident could have deeper repercussions than the incident itself. An attacker should rightly assume that the risks here have been addressed and they should look for another vector. Or an attacker might just try to replicate the exploit anyway in the chance that it hasn't been addressed.
Secondly, lock up the vulnerabilities. I mean that literally. Lock up any hardware that doesn't require user contact. That's everything but the keyboard and mouse. And not just the physical hardware but also the software. Employ "least user privilege" by only giving users the amount of access they need for their jobs. An employee who's job description does not include "reset the encryption device" should not have access to that button.
Third, finish your risk assessment. Tally up the costs in dealing with your threats and vulnerabilities. Put it in real dollar amounts so you can do a quantitative comparison. In this case, a security container and user education. Now tally up the costs of a threat meeting a vulnerability to become an exploit. Again, in dollars out of the company budget. For this incident, it was one week of lost work by one office being unable to do secure business plus the cost of rekeying the encryption device. Finally, compare those dollar amounts. Assume the risk only if the cost of mitigation, in actual company money, is too high.
First some background on this incident. A piece of hardware was reset and the encryption keys it contained were "zeroized". Then a message was sent out to the entire section informing them not only of the exploit but also underlying vulnerabilities which carry the risk of a denial of service. Because this incident report came through internal channels, it contains too much secure information to post here. There wouldn't be enough left after redaction. I will, however, discuss the incident in generic terms as a case study. Of course, the risk has been addressed.
Up front, let's address the sender of the message. The message was sent from the Information Management Office, a higher level function than over-titled secretary but that's a distinction that's easy to be confused over. Not that the IMO is unauthorized to distribute information about incidents in the office, but as a general rule nobody should be distributing information on exploits or vulnerabilities. So that's who sent it, but where did it go? To a large office full of non-security job functions. Read that as "potential threats".
Let's move on to the content of the message. The message reveals a successful, yet inadvertent, exploit of a vulnerability with a security device in the office. It clearly describes how to "zeroize" the device and also how long to return to operation. Reading between the lines, additional indicators are revealed. There is a piece of critical equipment in an unsecured location. Anyone in the field should immediately ask what else is in that location. Keeping in mind that these devices will not pass traffic unless it's encrypted, the victim was under a complete denial of service. That operational state could be further exploited while personnel are distracted by recovery efforts.
As a security professional, how do you protect your office from this?
First, educate the threats. This incident was caused by an untrained user accidentally resetting the device. Flat out, every user needs to be properly trained to operate the equipment they have contact with. Also, educate your users about information security. Disclosing the incident could have deeper repercussions than the incident itself. An attacker should rightly assume that the risks here have been addressed and they should look for another vector. Or an attacker might just try to replicate the exploit anyway in the chance that it hasn't been addressed.
Secondly, lock up the vulnerabilities. I mean that literally. Lock up any hardware that doesn't require user contact. That's everything but the keyboard and mouse. And not just the physical hardware but also the software. Employ "least user privilege" by only giving users the amount of access they need for their jobs. An employee who's job description does not include "reset the encryption device" should not have access to that button.
Third, finish your risk assessment. Tally up the costs in dealing with your threats and vulnerabilities. Put it in real dollar amounts so you can do a quantitative comparison. In this case, a security container and user education. Now tally up the costs of a threat meeting a vulnerability to become an exploit. Again, in dollars out of the company budget. For this incident, it was one week of lost work by one office being unable to do secure business plus the cost of rekeying the encryption device. Finally, compare those dollar amounts. Assume the risk only if the cost of mitigation, in actual company money, is too high.
Labels:
certifiable,
cissp,
security
Thursday, December 8, 2011
Fight for the Future
The fight against Stopping Online Piracy Act (H.R. 3261 a.k.a. SOPA) is not over yet. And there is so much to go over now. Protect IP (S.968 a.k.a. PIPA) is often put forward as a compromise to SOPA but both bills are not acceptable to a free internet and are not needed in a competitive business market.
This situation is developing so fast that I can't keep up with it. All I can do is direct readers to one of my favorite sites on the internet, Techdirt. Floor64, the consulting company which hosts Techdirt, is biased strongly in favor of internet freedom.
Some of the recent developments include many Senators distancing themselves from this bill, at least until after their re-election is secured. Supporters of these bills have offered to not enforce the DNS blocking until after the technical issues are sorted out. As an aside, these DNS provisions are not viable in conjunction with a secure name resolution system. DNSSEC rejects the various versions of DNS modification proposed by these bills' supporters. Additionally, a domain name system that can lie on government orders can lie on anyone's orders.
Another major development in the news is that many sites including this one are voluntarily blacking out tomorrow, January 18, 2012, as a preview of what the internet could look like when it's censored by hostile business interests.
Many interested parties in both the House and Senate will ask for these bills to be tabled until "the issues can be studied". Meaning in this case after the election cycle is complete and representatives are secure in their jobs. This requires a renewed call to action from all interested parties. Push for these bills to be defeated on the floor of both the House and Senate. And hold their remaining supporters accountable.
This situation is developing so fast that I can't keep up with it. All I can do is direct readers to one of my favorite sites on the internet, Techdirt. Floor64, the consulting company which hosts Techdirt, is biased strongly in favor of internet freedom.
Some of the recent developments include many Senators distancing themselves from this bill, at least until after their re-election is secured. Supporters of these bills have offered to not enforce the DNS blocking until after the technical issues are sorted out. As an aside, these DNS provisions are not viable in conjunction with a secure name resolution system. DNSSEC rejects the various versions of DNS modification proposed by these bills' supporters. Additionally, a domain name system that can lie on government orders can lie on anyone's orders.
Another major development in the news is that many sites including this one are voluntarily blacking out tomorrow, January 18, 2012, as a preview of what the internet could look like when it's censored by hostile business interests.
Many interested parties in both the House and Senate will ask for these bills to be tabled until "the issues can be studied". Meaning in this case after the election cycle is complete and representatives are secure in their jobs. This requires a renewed call to action from all interested parties. Push for these bills to be defeated on the floor of both the House and Senate. And hold their remaining supporters accountable.
Labels:
censorship,
security
Wednesday, November 16, 2011
American Censorship Day
Today, the House of Representatives is debating HR 3261, Stop Online Piracy Act or SOPA. This debate is attended by representatives of the content and entertainment lobbies. There are no representatives from technology companies in attendance. This is a concern because SOPA is a bill to add third-party liability on internet services like payment processors and DNS providers for content online as if they were hosting it themselves. It also directly eliminates the safe-harbors provision of the Digital Millennium Copyright Act, which would otherwise force the content industry to apply liability for infringement to the actual infringer.
The first part of this bill tasks the Attorney General with the requirement to censor foreign websites on the accusations of the content industry. The procedures that the Attorney General would be required to initiate do not involve contacted the accused infringer directly. Instead, the payment processors, search engines, ad networks, and domain name service providers across the internet with knowledge of or business relationships with the accused foreign website will be forced to cease operations with the accused. Search engines will have to remove the accused from their results, ad networks will not be allowed to disburse revenue to sites accused of infringing, and DNS providers will be prohibited from resolving domain names to IP addresses for accused sites. The second title of HR 3261 increases penalties for web site operators accused of copyright infringement.
Now that we've outlined what this bill is supposed to do, let's discuss why it won't do any of that and why it is a horrid piece of legislation.
First off, this bill is clearly just fellating the entertainment industry as a reward for their failure to adapt to changing market conditions. Copyright infringement is a result of a poorly implemented business model which does not monetize the audience to the level of the copyright holder's expectations. SOPA has no provision for removing infringing content. It only adds liability, and thus expense, to third-party service providers. These costs will be passed along to customers or used to raise the barriers to entry for innovative new companies entering the market. Nor are there penalties for false accusations or claims against non-infringing content.
Also, foreign governments will find themselves pressured to "meet their international obligations" in expanding protectionist copyright policies. And, as this bill is written to target foreign websites, so will it be used as the basis for laws used against American business interests.
Third, whenever the ability to censor is available there is always a desire to expand this ability and this bill will not stay in scope. SOPA has already been used to legitimize censorship by foreign regimes and the bill hasn't even passed yet.
If you believe your elected Congressperson still represents you, call them and ask them to oppose HR 3261.
The first part of this bill tasks the Attorney General with the requirement to censor foreign websites on the accusations of the content industry. The procedures that the Attorney General would be required to initiate do not involve contacted the accused infringer directly. Instead, the payment processors, search engines, ad networks, and domain name service providers across the internet with knowledge of or business relationships with the accused foreign website will be forced to cease operations with the accused. Search engines will have to remove the accused from their results, ad networks will not be allowed to disburse revenue to sites accused of infringing, and DNS providers will be prohibited from resolving domain names to IP addresses for accused sites. The second title of HR 3261 increases penalties for web site operators accused of copyright infringement.
Now that we've outlined what this bill is supposed to do, let's discuss why it won't do any of that and why it is a horrid piece of legislation.
First off, this bill is clearly just fellating the entertainment industry as a reward for their failure to adapt to changing market conditions. Copyright infringement is a result of a poorly implemented business model which does not monetize the audience to the level of the copyright holder's expectations. SOPA has no provision for removing infringing content. It only adds liability, and thus expense, to third-party service providers. These costs will be passed along to customers or used to raise the barriers to entry for innovative new companies entering the market. Nor are there penalties for false accusations or claims against non-infringing content.
Also, foreign governments will find themselves pressured to "meet their international obligations" in expanding protectionist copyright policies. And, as this bill is written to target foreign websites, so will it be used as the basis for laws used against American business interests.
Third, whenever the ability to censor is available there is always a desire to expand this ability and this bill will not stay in scope. SOPA has already been used to legitimize censorship by foreign regimes and the bill hasn't even passed yet.
If you believe your elected Congressperson still represents you, call them and ask them to oppose HR 3261.
Labels:
censorship,
security
Sunday, September 18, 2011
Decade-old memories
I passed up writing about a supposedly important anniversary last week. I didn't write about it because, honestly, it didn't really affect me.
I was in college at the University of Maryland, College Park, in the 2001 Fall semester. Since 11 September, 2001, was a Tuesday morning, I was in an early lab class. After lab I had the whole rest of the day open so I went back to the IEEE lounge in the basement of the engineering building. That's when another student, well known for being a bit of a cut-up, said a plane had crashed into the World Trade Center.
Of course I said, "That's a really bad joke, James."
But I still walked to the computer lab down the hall to find out the story. I sat down at an open computer and thought about where to find the information I was looking for. You had to do that in those days. Remember that Google was only a few years old and hadn't overthrown the top search engines of the day, Lycos and Alta Vista. As this story was supposedly happening in New York, my first stop was the New York Times, the first New York-based newspaper I could think of. Their site wasn't available that day, my first indication that there might be something to this story. So I tried the Washington Post, our hometown paper there inside the Beltway. Also unavailable that morning. Now I'm thinking I need to try for a server well outside the supposed area. The LA Times was showing news from the night before. They hadn't even woken up yet to update their website. I finally hit upon the Tampa Tribune, who was both awake and online. That's when the towers started falling.
In the following years, many whitepapers would be written about dealing with surge capacity for news websites and many more about continuity of operations. The University's administration was castigated for not evacuating the school to which their response was, "Where are the students supposed to go? All the flights have been grounded and anywhere could have been a target." There was a campus-wide memorial on the 12th and classes were cancelled that day. Looking up and seeing military fighter jets on patrol instead of the normal passenger jet contrails was the eeriest part. We were concerned about reopening the world's oldest continuously operating airport.
I was in college at the University of Maryland, College Park, in the 2001 Fall semester. Since 11 September, 2001, was a Tuesday morning, I was in an early lab class. After lab I had the whole rest of the day open so I went back to the IEEE lounge in the basement of the engineering building. That's when another student, well known for being a bit of a cut-up, said a plane had crashed into the World Trade Center.
Of course I said, "That's a really bad joke, James."
But I still walked to the computer lab down the hall to find out the story. I sat down at an open computer and thought about where to find the information I was looking for. You had to do that in those days. Remember that Google was only a few years old and hadn't overthrown the top search engines of the day, Lycos and Alta Vista. As this story was supposedly happening in New York, my first stop was the New York Times, the first New York-based newspaper I could think of. Their site wasn't available that day, my first indication that there might be something to this story. So I tried the Washington Post, our hometown paper there inside the Beltway. Also unavailable that morning. Now I'm thinking I need to try for a server well outside the supposed area. The LA Times was showing news from the night before. They hadn't even woken up yet to update their website. I finally hit upon the Tampa Tribune, who was both awake and online. That's when the towers started falling.
In the following years, many whitepapers would be written about dealing with surge capacity for news websites and many more about continuity of operations. The University's administration was castigated for not evacuating the school to which their response was, "Where are the students supposed to go? All the flights have been grounded and anywhere could have been a target." There was a campus-wide memorial on the 12th and classes were cancelled that day. Looking up and seeing military fighter jets on patrol instead of the normal passenger jet contrails was the eeriest part. We were concerned about reopening the world's oldest continuously operating airport.
Labels:
80s music,
forgotten realms,
hidden places,
security,
September 11 2001
Tuesday, April 26, 2011
Security -
I successfully completed the certification exam for CompTIA Security+. Then I saw this in the building.
I'll give you a hint. That's one of those magnetic door sensors you see inside the door frames in some places. The problem? I'm out in the hall.
Yes, this sensor is installed on the wrong side of the door. Poorly, I might add; that's double-sided foam tape barely holding the sensor on the door jamb.
This may not seem like much of an issue but as an example, let's walk through a couple of ways I would, er, a malicious intruder could exploit this.
Speaking of breaching that door, looking at the handle reveals a standard-issue cipher lock. That's the one with a keypad. You'll note both a keyed deadbolt and a keyhole on the lock itself. Very convenient that the keypad can be bypassed with a regular key. Or a pick set. Or a bump key.
So how would you protect your facility against this sort of vulnerability? First, obviously, install your door sensors on the correct side of the door. Second, establish a security presence inside the building with guards patrolling the hallways and a camera on that door. Also, train the building tenants to approach unidentified personnel and confirm their identity. Third, standardize the appearance of all the doorways. If all the doors look equally secured, an intruder won't be able to pick out the high value targets easily.
![]() |
| View from outside the security door. |
Yes, this sensor is installed on the wrong side of the door. Poorly, I might add; that's double-sided foam tape barely holding the sensor on the door jamb.
This may not seem like much of an issue but as an example, let's walk through a couple of ways I would, er, a malicious intruder could exploit this.
- Hold onto the information. If you learned anything from Indiana Jones and the Last Crusade, it's that the wired door is the important one.
- Simply cut the wire. The false alarm would tie up responders here at this door while an intruder was left free to operate at another location.
- Hack the sensor. The signal coming off that sensor probably isn't complex. It could be trivial to rig up a device to replicate it. Install the signal generator on a tap then cut the wire. The intruder is now free to breach the door while the "sensor" continues to report nothing wrong.
![]() |
| Standard issue cipher lock |
So how would you protect your facility against this sort of vulnerability? First, obviously, install your door sensors on the correct side of the door. Second, establish a security presence inside the building with guards patrolling the hallways and a camera on that door. Also, train the building tenants to approach unidentified personnel and confirm their identity. Third, standardize the appearance of all the doorways. If all the doors look equally secured, an intruder won't be able to pick out the high value targets easily.
Labels:
security
Subscribe to:
Posts (Atom)




