I've been reading Bruce Schneier's blog and his books for years because I think he intrinsically understands the psychology of security and the difference between actual and perceived risk.
Check out this clip from the Rachel Maddow Show where the discussion revolves around the recent underwear bomber and our government's subsequent reaction.
Showing posts with label Schneier. Show all posts
Showing posts with label Schneier. Show all posts
Wednesday, December 30, 2009
Friday, August 7, 2009
Overheard at Airport
From Greg Laden's blog, courtesy of Bruce Schneier:
"Here," dad to girl, "Get your ID out and have it with your ticket."
"Excuse me, sir," said the TSA officer, pointing to the young female, "She does not need to have her ID out, she's a minor."
Dad: "How do you know she's a minor if you don't look at her ID?"
.... (silence as everyone waits for answer)....
Dad again: "Kind of a hole in the system, isn't it?"
TSA Officer, voice lowered ... "There are a LOT of holes in the system, sir." ... walks away.
Young girl, "Good one, dad. Now tell her our name is LADEN and see what happens!"
"Here," dad to girl, "Get your ID out and have it with your ticket."
"Excuse me, sir," said the TSA officer, pointing to the young female, "She does not need to have her ID out, she's a minor."
Dad: "How do you know she's a minor if you don't look at her ID?"
.... (silence as everyone waits for answer)....
Dad again: "Kind of a hole in the system, isn't it?"
TSA Officer, voice lowered ... "There are a LOT of holes in the system, sir." ... walks away.
Young girl, "Good one, dad. Now tell her our name is LADEN and see what happens!"
Thursday, June 18, 2009
Easy Computer Snooping Tool
This is good news for people who are engaged in forensic examination of computers, but bad news when you consider that bad people will also have access to it, which means losing your data could happen more quickly and easily than before. Via his Schneier on Security blog, Bruce Schneier links to a press release for EnCase Portable, which "runs on a USB drive, rather than a laptop, and enables the user to easily and rapidly boot a target computer to the USB drive, and run a pre-configured data search and collection job."
So essentially, someone could walk calmly into your home or office, or up to your computer in a conference room or left unattended in a coffee shop, plug in a discreet USB drive, reboot you, and proceed to suck all of your data back into the thumb drive. Depending on how long you are gone, this could go entirely unnoticed, with the only evidence being a computer that has rebooted.
There's not much additional information in the press release about whether controls such as full-disk encryption or bios password protection can be defeated by this tool, so it will be interesting to participate in the chatting within security circles to get the scoop.
This is just my gentle reminder to you that leaving your PC unattended, even for short periods of time, introduces risk, and to make sure you follow some simple security controls to keep data leakage to a minimum.
Tuesday, June 16, 2009
Prairie Dogs Pull Ocean 11 Caper
The Maryland Zoo spent a cool half-million dollars constructing an escape-proof habitat for a group of prairie dogs, and the ungrateful land rodents broke out in less than 10 minutes, leaving the zoo's Terry Benedict fuming."They find all the weak spots and exploit them," said Karl Kranz, the zoo's vice president for animal programs and chief operating officer.I post this not because I'm fascinated by prairie dogs - meerkats have more personality - but because I'm a security geek, and it's a point I've been trying to make for years about stasis and complacency when designing and implementing a security infrastructure.
While you're laying the last row of virtual bricks on your perimeter, the forces of evil are already probing and prodding to find ways around your defenses. It's important that you do, too.
Five hundred grand is a lot of cash for a system that doesn't work, but anyone who has been in the corporate infosec world can quote much larger pricetags for enormous technology white elephants that either failed to provide the level of security and control that was promised, or became such a nightmare to implement that the system was either scaled back or discarded.
So take a lessen from the Maryland Zoo. Anytime you build a security system, spend some time determining what holes open up with the introduction of this new system, and have plans to fix them before you start building. And once you've remediated those gaps, move on to the next set of weaknesses. Then the next.
If you don't, someone else will.
Prairie Dogs Hack Baltimore Zoo , via Schneier on Security
Thursday, May 14, 2009
Detecting Liars
Back in my former career, it was often said that it must have really sucked to be one of my kids when it came to trying to tell a lie. I spent 15 years as a fraud investigator, and had attended both basic and advance interview and interrogation schools, so I could spot an untruth walking down 5th Avenue.Bruce Schneier, writing in his Schneier on Security blog, weighs in on comments made by psychologist Kevin Colwell, from Southern Connecticut State University, who has advised parents, police departments, Pentagon flunkies, and scores of others on lie detecting based on the amount of detail presented by the person in question.
In several studies, Dr. Colwell and Dr. Hiscock-Anisman have reported one consistent difference: People telling the truth tend to add 20 to 30 percent more external detail than do those who are lying. "This is how memory works, by association," Dr. Hiscock-Anisman said. "If you're telling the truth, this mental reinstatement of contexts triggers more and more external details."
There's a measure of truth (!) to this approach, but it's just one piece to an enormously complex puzzle. Does the speaker use significant detail in non-threatening conversations but resorts to a lack of detail when pressed on the topic in question? What about their non-verbal communication mechanisms, mannerisms, posture, and so on?
Here's an example - having been trained as an interrogator, if someone asks me if I know what time it is, my answer is either "yes" or "no", and that's it. 98% of the population will respond with, "Yes, it's 5:15" because that's the customary response. In an interview / interrogation scenario, I want to give up as little information as possible, while the interrogator wants me to spill my guts, metaphorically (and if you're Dick Cheney, literally) speaking.
Does this mean I'm being dishonest in my responses? Not at all. When did it become my job to answer the interrogator in the manner that he or she wants? My responsibility is to me, and anything that puts that at risk is a no-go.
If you think I've committed a crime, charge me. If you don't have enough to charge me, don't expect me to give you the evidence you need. Talk to the hand, buddy.
Schneier on Security: Detecting Liars by Content
Tuesday, April 28, 2009
Spot a Fake Census Taker?
Originally linked from Bruce Schneier's blog, this video about how to spot a fake census taker is pretty ridiculous.
Bruce comments: This apparently non-ironic video warns that people might impersonate census workers in an effort to rob you. But while you shouldn't trust the ID of a stranger, you should trust that same stranger to give you a phone number where you can verify that ID. This, of course, makes no sense.
Bruce comments: This apparently non-ironic video warns that people might impersonate census workers in an effort to rob you. But while you shouldn't trust the ID of a stranger, you should trust that same stranger to give you a phone number where you can verify that ID. This, of course, makes no sense.
Tuesday, April 7, 2009
Identifying People using Anonymous Social Networking Data
Bruce Schneier, writing in his Schneier on Security blog, details the work of two University of Texas at Austin scientists who have developed an algorithm that allows them to take anonymous social networking data and use it to pull out actual names and addresses.
So much for the anonymity.
Social graphs from Twitter, Flickr and Live Journal were used in the research.
The pair found that one third of those who are on both Flickr and Twitter can be identified from the completely anonymous Twitter graph. This is despite the fact that the overlap of members between the two services is thought to be about 15%.
The researchers suggest that as social network sites become more heavily used, then people will find it increasingly difficult to maintain a veil of anonymity.
You've been warned.
Identifying People using Anonymous Social Networking Data
So much for the anonymity.
Social graphs from Twitter, Flickr and Live Journal were used in the research.
The pair found that one third of those who are on both Flickr and Twitter can be identified from the completely anonymous Twitter graph. This is despite the fact that the overlap of members between the two services is thought to be about 15%.
The researchers suggest that as social network sites become more heavily used, then people will find it increasingly difficult to maintain a veil of anonymity.
You've been warned.
Identifying People using Anonymous Social Networking Data
Subscribe to:
Posts (Atom)