<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: discover]]></title>
    <link>http://securityratty.com/tag/discover</link>
    <description></description>
    <pubDate>Tue, 05 Aug 2008 11:06:16 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Researchers discover new cross-browser exploit that affects all major desktop platforms]]></title>
      <link>http://securityratty.com/article/e2ebbad9919a340276c86f88b586578c</link>
      <guid>http://securityratty.com/article/e2ebbad9919a340276c86f88b586578c</guid>
      <description><![CDATA[Researchers are beginning to raise an alarm for what looks like a new browser security threat that affects all major desktop platforms: Microsoft Internet Explorer, Mozilla Firefox, Apple Safari,...]]></description>
      <content:encoded><![CDATA[Researchers are beginning to raise an alarm for what looks like a new browser security threat that affects all major desktop platforms: Microsoft Internet Explorer, Mozilla Firefox, Apple Safari, Opera and Adobe Flash. The threat, called Clickjacking, was to be discussed at the OWASP NYC AppSec 2008 Conference but, at the request of Adobe and [...]]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 21:11:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/major desktop platforms">major desktop platforms</category>
      <category domain="http://securityratty.com/tag/threat">threat</category>
      <category domain="http://securityratty.com/tag/browser security threat">browser security threat</category>
      <category domain="http://securityratty.com/tag/owasp nyc appsec">owasp nyc appsec</category>
      <category domain="http://securityratty.com/tag/microsoft internet explorer">microsoft internet explorer</category>
      <category domain="http://securityratty.com/tag/adobe flash">adobe flash</category>
      <category domain="http://securityratty.com/tag/adobe">adobe</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/affects">affects</category>
      <source url="http://cyberinsecure.com/researchers-discover-new-cross-browser-exploit-that-affects-all-major-desktop-platforms/">Researchers discover new cross-browser exploit that affects all major desktop platforms</source>
    </item>
    <item>
      <title><![CDATA[Hype Alert: Internet Shopping Carts Are Secure]]></title>
      <link>http://securityratty.com/article/6f0706e64d78d354492017803497a079</link>
      <guid>http://securityratty.com/article/6f0706e64d78d354492017803497a079</guid>
      <description><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled Internet Shopping Carts are Secure
OMG...really
To be fair, I realize the author is speaking from the...]]></description>
      <content:encoded><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled <a href="http://hubpages.com/hub/Internet-Shopping-Carts-Are-Secure" taget="_blank">Internet Shopping Carts are Secure</a>. <br />OMG...really?<br />To be fair, I realize the author is speaking from the eCommerce perspective, rather than that of an information security practitioner, but here's where the trouble begins:<br /><span style="font-style:italic;">"Shopping cart service providers have developed secure ecommerce shopping cart solutions for any business owner looking to enhance their current online store, or create a new one. Some ecommerce shopping cart solution providers are even receiving PABP (Payment Application Best Practice) certification which supports PCI compliance requirements for all businesses accepting credit card payments online."</span><br />This may be true in part, but it is by no means an all-inclusive claim. Shopping carts continue to be sieve-like, even when apparently reviewed per <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI</a> standards.<br />Allow me to elaborate.<br />We'll kick off our hype eliminating effort with a simple Google dork: <a href="http://www.google.com/search?hl=en&q=inurl%3A%22cart.cfm%22&btnG=Search" target="_blank"{>inurl:"cart.cfm"</a> (picking on ColdFusion again, but man, they make it easy)<br /><a href="http://www.gmpartsdirect.com/cart.cfm" target="_blank">GM Parts Direct: Your Shopping Cart</a> jumped right out at me for a number of reasons.<br />First, I sensed XSS vulns lurking like a Geiger counter senses radiation. Sound <a href="http://www.ringelkater.de/Sounds/2geraeusche_gegenst/geigerzaehler.wav" target="_blank">effect</a> for edification. :-)<br />Second, the page contained one of the growing number of aforementioned conversion-driving website <a href="http://sealserver.trustwave.com/cert.php?customerId=w6ordzctHpqOVGcB1cmBsViTpDGC2k&size=105x54&style=normal&language=en" target="_blank">security</a> seals. <br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s1600-h/GMparts.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s320/GMparts.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250473012396397122" /></a><br /><br />Tick, tick, click...the Gieger counter is getting louder. <br />Trustwave claims that the site operator "is enrolled in Trustwave's Trusted Commerce™ program to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS) mandated by all the major credit card associations including: American Express, Diners Club, Discover, JCB, MasterCard Worldwide, Visa, Inc. and Visa Europe."<br />Methinks that <a href="https://www.trustwave.com/" target="_blank">Trustwave's</a> Trusted Commerce program is missing a few fundamental security checks. Remember, XSS in PCI regulated sites, according to the <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI DSS</a>, indicates that a site is not compliant (see section 6.5.4) if vulnerable to XSS.<br />Uh-oh.<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s1600-h/GMparts_xss_trustwave.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s320/GMparts_xss_trustwave.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250476249048608850" /></a><br />All it takes is a fake login page, as opposed to our friends at <a href="http://xssed.com/" target="_blank">XSSED.com</a>, and...well, you get the point.<br />Simply, this is one of an endless number of shopping cart not secure, and not PCI compliant. For shame. You need only browse the <a href="http://holisticinfosec.org/content/category/6/23/45/" target="_blank">Holisticinfosec.org Advisories</a> page to find multiple ecommerce platforms and shopping carts that are missing the mark. Trust me, these are a fraction of the <a href="http://secunia.com/advisories/search/?search=shopping+cart" target="_blank">problem</a>.<br />ecommerce<>security<br />ecommerce<><a href="http://msdn.microsoft.com/en-us/library/ms995349.aspx" target="_blank">SDL</a><br />ecommerce<>PCI<br />website security seal<>security<br />Sigh.]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 11:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecommerce">ecommerce</category>
      <category domain="http://securityratty.com/tag/multiple ecommerce platforms">multiple ecommerce platforms</category>
      <category domain="http://securityratty.com/tag/ecommerce sdl">ecommerce sdl</category>
      <category domain="http://securityratty.com/tag/ecommerce perspective">ecommerce perspective</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/cart solutions">cart solutions</category>
      <category domain="http://securityratty.com/tag/cart">cart</category>
      <category domain="http://securityratty.com/tag/ecommerce security">ecommerce security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/hype-alert-internet-shopping-carts-are.html">Hype Alert: Internet Shopping Carts Are Secure</source>
    </item>
    <item>
      <title><![CDATA[NSA Snooping on Cell Phone Calls]]></title>
      <link>http://securityratty.com/article/43176b0a11dc8247b3e14685fbdf425f</link>
      <guid>http://securityratty.com/article/43176b0a11dc8247b3e14685fbdf425f</guid>
      <description><![CDATA[From CNet : A recent article in the London Review of Books revealed that a number of private companies now sell off-the-shelf data-mining solutions to government spies interested in analyzing...]]></description>
      <content:encoded><![CDATA[<p>From <a href="http://news.cnet.com/8301-13739_3-10030134-46.html">CNet</a>:</p>

<blockquote>A recent article in the <i><a href="http://www.lrb.co.uk/v30/n16/soar01_.html">London Review of Books</a></i> revealed that a number of private companies now sell off-the-shelf data-mining solutions to government spies interested in analyzing mobile-phone calling records and real-time location information. These companies include  <a href="http://www.thorpeglen.com/">ThorpeGlen</a>,  <a href="http://vastech.co.za/">VASTech</a>, <a href="http://www.kommlabs.com/">Kommlabs</a>, and <a href="http://www.aqsacomna.com/us/">Aqsacom</a>--all of which sell "passive probing" data-mining services to governments around the world.

<p>ThorpeGlen, a U.K.-based firm, offers intelligence analysts a graphical interface to the company's  mobile-phone location and call-record data-mining software.  Want to determine a suspect's "<a href="http://blog.wired.com/27bstroke6/2007/09/rogue-fbi-lette.html">community of interest</a>"? <i>Easy</i>. Want to learn if a single person is swapping SIM cards or throwing away phones (yet still hanging out in the same physical location)? <i>No problem</i>.</p>

<p>In a Web <a href="http://www.thorpeglen.com/doclib/ISS_Webinar_13_MAY_08_vb_secure.pdf">demo</a> (PDF) (<a href="http://cyber.law.harvard.edu/~csoghoian/ISS_Webinar_13_MAY_08_vb_secure.pdf">mirrored here</a>) to potential customers back in May, ThorpeGlen's vice president of global sales showed off the company's tools by mining a dataset of a single week's worth of call data from 50 million users in Indonesia, which it has crunched in order to try and discover small anti-social groups that only call each other.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=otpSL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=otpSL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=EQCBL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=EQCBL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 08:49:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/call-record">call-record</category>
      <category domain="http://securityratty.com/tag/call">call</category>
      <category domain="http://securityratty.com/tag/call data">call data</category>
      <category domain="http://securityratty.com/tag/offers intelligence analysts">offers intelligence analysts</category>
      <category domain="http://securityratty.com/tag/companies include">companies include</category>
      <category domain="http://securityratty.com/tag/real-time location information">real-time location information</category>
      <category domain="http://securityratty.com/tag/mobile-phone location">mobile-phone location</category>
      <category domain="http://securityratty.com/tag/mobile-phone">mobile-phone</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/nsa_snooping_on.html">NSA Snooping on Cell Phone Calls</source>
    </item>
    <item>
      <title><![CDATA[Planning for a new year]]></title>
      <link>http://securityratty.com/article/53eb51a004ab3e2477c2c3559dd8fb20</link>
      <guid>http://securityratty.com/article/53eb51a004ab3e2477c2c3559dd8fb20</guid>
      <description><![CDATA[October is creeping up on us, and for most of us that means the beginning of the end of 2008, along with the nagging feeling that we should be doing some planning for 2009. This is the perfect...]]></description>
      <content:encoded><![CDATA[October is creeping up on us, and for most of us that means the beginning of the end of 2008, along with the nagging feeling that we should be doing some planning for 2009. This is the perfect opportunity to take stock of your security and compliance programs, and to develop a plan for improving things next year. If you've been following our various blogs here at RSA you probably realize by now that we espouse a security and compliance program based on three core pillars: it's information-centric, risk-driven and framework-based. Our compliance team has spoken with hundreds of customers from all over the world and in every industry segment this year, and we're finding that this approach is gaining acceptance at an ever-increasing rate. <B>Organizations are realizing that they need to discover, manage and control their information assets in order to protect them...</b>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance program based">compliance program based</category>
      <category domain="http://securityratty.com/tag/compliance team">compliance team</category>
      <category domain="http://securityratty.com/tag/industry segment">industry segment</category>
      <category domain="http://securityratty.com/tag/compliance programs">compliance programs</category>
      <category domain="http://securityratty.com/tag/information assets">information assets</category>
      <category domain="http://securityratty.com/tag/core pillars">core pillars</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/perfect opportunity">perfect opportunity</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1337">Planning for a new year</source>
    </item>
    <item>
      <title><![CDATA[File Integrity Monitoring: Secure Your Virtual and Physical IT Environments]]></title>
      <link>http://securityratty.com/article/f25697c6547acff1ffe2bf8a0039f459</link>
      <guid>http://securityratty.com/article/f25697c6547acff1ffe2bf8a0039f459</guid>
      <description><![CDATA[Source: Tripwire) Looking for a File Integrity Monitoring Solution? With the numerous servers, devices and applications organizations rely on to support their everyday business, outages and security...]]></description>
      <content:encoded><![CDATA[<b>(Source: Tripwire)</b>  Looking for a File Integrity Monitoring Solution? With the numerous servers, devices and applications organizations rely on to support their everyday business, outages and security breaches due to poor IT configurations are unacceptable. In addition, many organizations must now prove compliance with standards like PCI DSS designed to protect systems and sensitive data. File integrity monitoring solutions minimize security risk resulting from undesirable configuration change by monitoring, detecting, and reconciling changes to key files throughout the virtual and physical IT infrastructures.<p>Learn how file integrity monitoring solutions work and the capabilities you should expect your solution to have. Then review a detailed checklist you should complete before purchasing your solution. Finally, discover how Tripwire Enterprise effectively combines file integrity monitoring with configuration assessment-a single configuration control solution that proactively assesses and monitors the IT infrastructure and enables organizations to achieve and maintain compliance with standards and regulations.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=4fD2VT"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=4fD2VT" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/374621002" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/file integrity">file integrity</category>
      <category domain="http://securityratty.com/tag/applications organizations rely">applications organizations rely</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/enables organizations">enables organizations</category>
      <category domain="http://securityratty.com/tag/security breaches due">security breaches due</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/undesirable configuration change">undesirable configuration change</category>
      <category domain="http://securityratty.com/tag/maintain compliance">maintain compliance</category>
      <category domain="http://securityratty.com/tag/numerous servers">numerous servers</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/374621002/whitepapers.do">File Integrity Monitoring: Secure Your Virtual and Physical IT Environments</source>
    </item>
    <item>
      <title><![CDATA[CEP and Analytics]]></title>
      <link>http://securityratty.com/article/7167551d00ca26f4a0df8a91ba7a3054</link>
      <guid>http://securityratty.com/article/7167551d00ca26f4a0df8a91ba7a3054</guid>
      <description><![CDATA[Peter Lin comments in A Complex Event = Sum (Events) + Situational Knowledge ,continuingthe discussion by asking What is the definition of analytics? Is it purely a calculation, or something else
A...]]></description>
      <content:encoded><![CDATA[<p>Peter Lin <a href="http://www.thecepblog.com/2008/08/16/a-complex-event-sum-events-knowledge/#comment-1079" target="_blank">comments</a> in <a title="A Complex Event = Sum (Events) + Situational Knowledge" rel="bookmark" href="http://www.thecepblog.com/2008/08/16/a-complex-event-sum-events-knowledge/"><span style="color: #105cb6;">A Complex Event = Sum (Events) + Situational Knowledge</span></a>, continuing the discussion by asking &#8221;<em>What is the definition of analytics? Is it purely a calculation, or something else?&#8221;</em></p>
<p>A good place to being to look for clues to an answer is <a href="http://en.wikipedia.org/wiki/Analytics" target="_blank">Wikipedia</a>, where the opinion of the author there is,</p>
<blockquote><p><em> &#8221;A simple and practical definition, however, would be how an entity (i.e., business) arrives at an optimal or realistic decision based on existing data.&#8221;</em></p></blockquote>
<p>Quoting the Wikipedia author(s) further,</p>
<blockquote><p><em>&#8220;Common applications of Analytics include the study of business data using statistical analysis in order to discover and understand historical patterns with an eye to predicting and improving business performance in the future. Also, some people use the term to denote the use of mathematics in business. Others hold that field of analytics include the use of Operations Research, Statistics and Probability. However, it would be erroneous to limit the field of analytics to only statistics and mathematics.&#8221;</em></p></blockquote>
<p>The Wikipedia author(s) continue their discussion of analytics, as follows;</p>
<blockquote><p><em>&#8220;Analytics closely resembles </em><a class="mw-redirect" title="Statistical analysis" href="http://www.thecepblog.com/wiki/Statistical_analysis"><em>statistical analysis</em></a><em> and </em><a title="Data mining" href="http://www.thecepblog.com/wiki/Data_mining"><em>data mining</em></a><em>, but tends to be based on modeling involving extensive computation. Some fields within the area of analytics are </em><a class="new" title="Enterprise decision management (page does not exist)" href="http://www.thecepblog.com/w/index.php?title=Enterprise_decision_management&amp;action=edit&amp;redlink=1"><em>enterprise decision management</em></a><em>, marketing analytics, predictive science, strategy science, credit risk analysis and fraud analytics.&#8221;</em></p></blockquote>
<p>All of these topics above are CEP-related areas involving complex events and situations based on the need for optimal and reliable real-time capabilities to make meaningful (business) decisions. </p>
<p>Simple pattern matching, event mediation and routing, and basic mathematical calculations do not really fall into the realm of complex event processing.  Instead, CEP is real-time decision support based on modeling and &#8220;extensive&#8221; computation.  In a nutshell, complex events and situations require analytical models that are non-trivial and that is why without analytics, there is no true &#8220;complex event processing.&#8221;</p>
<p>See also:</p>
<p><a href="http://en.wikipedia.org/wiki/Predictive_analytics" target="_self">WIkipedia on Predictive Analytics</a></p>
<p><a href="http://en.wikipedia.org/wiki/Predictive_analytics"></a></p>
]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 10:09:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/analytics">analytics</category>
      <category domain="http://securityratty.com/tag/wikipedia author">wikipedia author</category>
      <category domain="http://securityratty.com/tag/quotingthe wikipedia author">quotingthe wikipedia author</category>
      <category domain="http://securityratty.com/tag/fraud analytics">fraud analytics</category>
      <category domain="http://securityratty.com/tag/author">author</category>
      <category domain="http://securityratty.com/tag/predictive analytics">predictive analytics</category>
      <category domain="http://securityratty.com/tag/analytics include">analytics include</category>
      <category domain="http://securityratty.com/tag/business data">business data</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <source url="http://www.thecepblog.com/2008/08/19/cep-and-analytics/">CEP and Analytics</source>
    </item>
    <item>
      <title><![CDATA[Security Researchers Embarrassed After Successful Hackers Attack]]></title>
      <link>http://securityratty.com/article/4207699a3d65e10f40cdef5233279182</link>
      <guid>http://securityratty.com/article/4207699a3d65e10f40cdef5233279182</guid>
      <description><![CDATA[Chief strategy officer for security firm StillSecure and security consultant Alan Shimel woke on Sunday morning to discover that his personal blog, which is frequently visited by readers and press,...]]></description>
      <content:encoded><![CDATA[Chief strategy officer for security firm StillSecure and security consultant Alan Shimel woke on Sunday morning to discover that his personal blog, which is frequently visited by readers and press, was pointing to a website featuring explicit gay porn. Equally disturbing, he found someone had cracked open his Yahoo! Mail account and published sensitive documents [...]]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 13:40:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/chief strategy officer">chief strategy officer</category>
      <category domain="http://securityratty.com/tag/explicit gay porn">explicit gay porn</category>
      <category domain="http://securityratty.com/tag/security firm stillsecure">security firm stillsecure</category>
      <category domain="http://securityratty.com/tag/personal blog">personal blog</category>
      <category domain="http://securityratty.com/tag/mail account">mail account</category>
      <category domain="http://securityratty.com/tag/sensitive documents">sensitive documents</category>
      <category domain="http://securityratty.com/tag/sunday">sunday</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/discover">discover</category>
      <source url="http://cyberinsecure.com/security-researchers-embarrassed-after-successful-hackers-attack/">Security Researchers Embarrassed After Successful Hackers Attack</source>
    </item>
    <item>
      <title><![CDATA[Listening to the evidence]]></title>
      <link>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</link>
      <guid>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</guid>
      <description><![CDATA[Last week the House of Commons Culture, Media and Sport Select Committee published a report of their inquiry into Harmful content on the Internet and in video games . They make a number of...]]></description>
      <content:encoded><![CDATA[<p>Last week the <a href="http://www.parliament.uk/parliamentary_committees/culture__media_and_sport.cfm">House of Commons Culture, Media and Sport Select Committee</a> published a report of their inquiry into &#8220;<a href="http://www.publications.parliament.uk/pa/cm200708/cmselect/cmcumeds/353/353.pdf">Harmful content on the Internet and in video games</a>&#8220;. They make a number of recommendations including a self-regulatory body to set rules for Internet companies to force them to protect users; that sites should provide a &#8220;watershed&#8221; so that grown-up material cannot be viewed before 9pm; that YouTube should screen material for forbidden content; that &#8220;<a href="http://www.spiked-online.com/index.php?/site/article/4633/">suicide websites</a>&#8221; should be blocked; that ISPs should be forced to block child sexual abuse image websites whatever the cost, and that blocking of bad content was generally desirable.</p>
<p>You will discern a certain amount of enthusiasm for blocking, and for a &#8220;<a href="http://www.yes-minister.com/polterms.htm#Politicians">something must be done</a>&#8221; approach. However, in coming to their conclusions, they do not, in my view, seem to have listened too hard to the evidence, or sought out expertise elsewhere in the world&#8230;<br />
<span id="more-351"></span><br />
Google/YouTube told them that 10 hours of video was posted every minute, and the amount is increasing. In the oral evidence session an MP helpfully suggested: &#8220;That video content is tagged. You do not need to look at every single minute of video content. Surely you could have people who would look at the video content which is tagged with labels which suggest it could be inappropriate.&#8221; Of course &#8220;<a href="http://lostria.blogspot.com/2008/01/fertility-slaps.html">happy_slapping.wmv</a>&#8221; or &#8220;<a href="http://www.phrases.org.uk/meanings/bunny-boiler.html">fluffy_bunnies.avi</a>&#8221; must always contain exactly what it says on the tin (<a href="http://en.wikipedia.org/wiki/Not%21">not!</a>) but unaccountably Google said it was a &#8220;fair suggestion&#8221;, so perhaps my cynicism is misplaced.</p>
<p>However, back to blocking.</p>
<p>I submitted <a href="http://www.cl.cam.ac.uk/~rnc1/080129-cms.pdf">some evidence of my own</a>, which the committee summarised, reasonably accurately:</p>
<blockquote><p>Dr Richard Clayton, a researcher in the Security Group of the Computer Laboratory at Cambridge University and author of several academic papers on methods for blocking access to Internet content, pointed out that there was no single blocking method which was both inexpensive and discerning enough to block access to only one part of a large website (such as FaceBook). In his view, the fatal flaw of all network-level blocking schemes was the ease with which they could be overcome, either by encrypting content or by the use of proxy services hosted outside the UK.</p></blockquote>
<p>The committee&#8217;s conclusion, having read this was:</p>
<blockquote><p>At a time of rapid technological change, it is difficult to judge whether blocking access to Internet content at network level by Internet service providers is likely to become ineffective in the near future. However, this is not a reason for not doing so while it is still effective for the overwhelming majority of users.</p></blockquote>
<p>which I suppose logically means that the committee thinks that blocking should now be discarded as a policy option &#8212; but somehow I think that isn&#8217;t their intended meaning.</p>
<p>The Committee should perhaps have a look at <a href="http://www.acma.gov.au/webwr/_assets/main/lib310554/isp-level_internet_content_filtering_trial-report.pdf">this Australian report</a>, which found that ISP level content filtering (and in Australia the politicians want to use ISP level filtering to provide a child-friendly Internet) did work (up to a point) at Tier 3 (the smallest) ISPs. The <a href="http://en.wikiquote.org/wiki/Evelyn_Waugh#Scoop_.281938.29">up-to-a-point</a> is that unlike previous tests the systems didn&#8217;t completely wreck the browsing experience by slowing it down. However, the systems blocked only 85-98% of illegal material and similar percentages of material suitable for adults but not for younger children. Interestingly some products were better at different categories.</p>
<p>Getting that many sites wrong is really quite significant, so it&#8217;s difficult to see this as a ringing endorsement for blocking the web. Additionally, the Australian report found that the blocking was useless on &#8220;non-web&#8221; protocols (such as peer-to-peer) and their report specifically didn&#8217;t consider cost, or ease of circumvention &#8212; so it&#8217;s not just UK politicians not wanting to consider evidence on that topic!</p>
<p>Finally, I should note that the Culture Media and Sport Committee has also ignored some rather more recent academic work. The MPs have put into their report that they were horrified to discover that child sexual abuse images took 24 hours to remove in the UK. What (should they ever learn of it) will they make of the recent discovery by <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and myself that shows that if the website is hosted abroad then <a href="http://www.lightbluetouchpaper.org/2008/06/11/slow-removal-of-child-sexual-abuse-image-websites/">a month is more to be expected</a>?</p>
]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 20:24:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/isp level content">isp level content</category>
      <category domain="http://securityratty.com/tag/video games">video games</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/bad content">bad content</category>
      <category domain="http://securityratty.com/tag/video content">video content</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/evidence">evidence</category>
      <category domain="http://securityratty.com/tag/child-friendly internet">child-friendly internet</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/08/listening-to-the-evidence/">Listening to the evidence</source>
    </item>
    <item>
      <title><![CDATA[Hacking Mifare Transport Cards]]></title>
      <link>http://securityratty.com/article/3a7dba1bb2685c0c225ca69eddd304c7</link>
      <guid>http://securityratty.com/article/3a7dba1bb2685c0c225ca69eddd304c7</guid>
      <description><![CDATA[London's Oyster card has been cracked , and the final details will become public in October. NXP Semiconductors, the Philips spin-off that makes the system, lost a court battle to prevent the...]]></description>
      <content:encoded><![CDATA[<p>London's Oyster card has been <a href="http://www.guardian.co.uk/technology/2008/jun/26/hitechcrime.oystercards">cracked</a>, and the final details will become public in October. NXP Semiconductors, the Philips spin-off that makes the system, lost a court battle to prevent the researchers from publishing. People might be able to use this information to ride for free, but the sky won't be falling. And the publication of this serious vulnerability actually makes us all safer in the long run.</p>

<p>Here's the story. Every Oyster card has a radio-frequency identification chip that communicates with readers mounted on the ticket barrier. That chip, the "Mifare Classic" chip, is used in hundreds of other transport systems as well — Boston, Los Angeles, Brisbane, Oslo, Amsterdam, Taipei, Shanghai, Rio de Janeiro — and as an access pass in thousands of companies, schools, hospitals, and government buildings around Britain and the rest of the world.</p>

<p>The security of Mifare Classic is terrible. This is not an exaggeration; it's kindergarten cryptography. Anyone with any security experience would be embarrassed to put his name to the design. NXP attempted to deal with this embarrassment by keeping the design secret.</p>

<p>The group that <a href="http://www.ru.nl/ds/research/rfid/">broke</a> Mifare Classic is from Radboud University Nijmegen in the Netherlands. They <a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/article4184481.ece">demonstrated the attack</a> by riding the Underground for free, and by <a href="http://www.youtube.com/watch?v=NW3RGbQTLhE">breaking into</a> a building. Their two papers (one is already <a href="http://www.cs.ru.nl/~flaviog/publications/Attack.MIFARE.pdf">online</a>) will be published at <a href="http://www.scc.rhul.ac.uk/CARDIS/">two</a> <a href="http://www.isac.uma.es/esorics08/">conferences</a> this autumn.</p>

<p>The second paper is the one that NXP <a href="http://news.cnet.com/8301-10784_3-9985886-7.html?hhTest=1">sued</a> <a href="http://www.secureidnews.com/news/2008/07/10/nxp-sues-to-prevent-hackers-from-releasing-mifare-flaws/">over</a>. They called disclosure of the attack "irresponsible," warned that it will cause "immense damages," and claimed that it "will jeopardize the security of assets protected with systems incorporating the Mifare IC." The <a href="http://zoeken.rechtspraak.nl/resultpage.aspx?snelzoeken=true&amp;searchtype=ljn&amp;ljn=BD7578&amp;u_ljn=BD7578">Dutch court</a> would have none of it:  "Damage to NXP is not the result of the publication of the article but of the production and sale of a chip that appears to have shortcomings."</p>

<p>Exactly right. More generally, the notion that secrecy supports security is <a href="http://www.schneier.com/crypto-gram-0205.html#1">inherently flawed</a>. Whenever you see an organization claiming that design secrecy is necessary for security — in ID cards, in voting machines, in airport security — it invariably means that its security is lousy and it has no choice but to hide it. Any competent cryptographer would have designed Mifare's security with an open and public design.</p>

<p>Secrecy is fragile. Mifare's security was based on the belief that no one would discover how it worked; that's why NXP had to muzzle the Dutch researchers. But that's just wrong. Reverse-engineering isn't hard. <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=spam__malware_and_vulnerabilities&amp;articleId=9078038&amp;taxonomyId=85">Other</a> <a href="http://www.cs.virginia.edu/~evans/pubs/usenix08/">researchers</a> <a href="http://eprint.iacr.org/2008/166">had</a> <a href="http://staff.science.uva.nl/~delaat/sne-2006-2007/p41/Report.pdf">already</a> <a href="http://www.translink.nl/media/bijlagen/nieuws/TNO_ICT_-_Security_Analysis_OV-Chipkaart_-_public_report.pdf">exposed</a> Mifare's lousy security. A Chinese company even <a href="http://www.fmsh.com/english/product_chipcard.php?product=FM11RF32">sells</a> a <a href="http://www.fmsh.com/english/products/FM11RF32_FS_ENG.pdf">compatible chip</a>. Is there any doubt that the bad guys already know about this, or will soon enough?</p>

<p>Publication of this attack might be expensive for NXP and its customers, but it's good for security overall. Companies will only design security as good as their customers know to ask for. NXP's security was so bad because customers didn't know how to evaluate security: either they don't know what questions to ask, or didn't know enough to distrust the marketing answers they were given. This court ruling encourages companies to build security properly rather than relying on shoddy design and secrecy, and discourages them from promising security based on their ability to threaten researchers.</p>

<p>It's unclear how this break will affect <a href="http://www.tfl.gov.uk/">Transport for London</a>. Cloning takes only a few seconds, and the thief only has to brush up against someone carrying a legitimate Oyster card. But it requires an RFID reader and a small piece of software which, while feasible for a techie, are too complicated for the average fare dodger. The police are likely to quickly arrest anyone who tries to sell cloned cards on any scale. TfL <a href="http://news.cnet.co.uk/software/0,39029694,49297810,00.htm">promises</a> <a href="http://www.techradar.com/news/world-of-tech/tfl-responds-to-oyster-hack-runling-428238">to</a> turn off any cloned cards within 24 hours, but that will hurt the innocent victim who had his card cloned more than the thief.</p>

<p>The vulnerability is far more serious to the companies that use Mifare Classic as an access pass. It would be very interesting to know how NXP presented the system's security to them.</p>

<p>And while these attacks only pertain to the Mifare Classic chip, it makes me suspicious of the entire product line. NXP sells a more secure chip and has another on the way, but given the number of basic cryptography mistakes NXP made with Mifare Classic, one has to wonder whether the "more secure" versions will be sufficiently so.</p>

<p>This essay <a href="http://www.guardian.co.uk/technology/2008/aug/07/hacking.security">originally appeared</a> in the <i>Guardian</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=lyT29K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=lyT29K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=3HhhnK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=3HhhnK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 02:07:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mifare">mifare</category>
      <category domain="http://securityratty.com/tag/design">design</category>
      <category domain="http://securityratty.com/tag/design secrecy">design secrecy</category>
      <category domain="http://securityratty.com/tag/mifare classic chip">mifare classic chip</category>
      <category domain="http://securityratty.com/tag/secrecy">secrecy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/secrecy supports security">secrecy supports security</category>
      <category domain="http://securityratty.com/tag/security properly">security properly</category>
      <category domain="http://securityratty.com/tag/chip">chip</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/hacking_mifare.html">Hacking Mifare Transport Cards</source>
    </item>
    <item>
      <title><![CDATA[Card Wars: The Phantom Menace]]></title>
      <link>http://securityratty.com/article/9d5b71fcb64161e1a88ba8844117af51</link>
      <guid>http://securityratty.com/article/9d5b71fcb64161e1a88ba8844117af51</guid>
      <description><![CDATA[Just like George Lucas cant help but return to his old projects , I have been returning to mine. After three years of stagnation, I am pleased to announce the re-launch of phantomwithdrawals.com ,...]]></description>
      <content:encoded><![CDATA[<p>Just like George Lucas can&#8217;t help but <a href="http://www.cinematical.com/2005/05/25/lucas-idea-for-new-star-wars-prequel/">return to his old projects</a>, I have been returning to mine. After three years of stagnation, I am pleased to announce the re-launch of <a href="http://www.phantomwithdrawals.com">phantomwithdrawals.com</a>, freshly re-vamped, updated and turned into a Wiki editable by the general public.</p>
<p>In fact, it&#8217;s not just great artists like Mr. Lucas and I starting up old projects, our honourable colleagues wearing the black hats have got the same idea. We have new victims reporting in, <a href="http://www.newsvine.com/_news/2008/07/01/1629600-citibank-atm-breach-reveals-pin-security-problems">rumours</a>&nbsp;<a href="http://blog.wired.com/27bstroke6/2008/06/citibank-issues.html">abound</a> of an auth system compromise at Citi, the Ombudsman is backlogged with months of disputed withdrawal cases, and some like <a href="http://www.guardian.co.uk/technology/2008/jan/03/hitechcrime.news">Alain Job</a> are even going to court.</p>
<p>One original contributor to the phantom case histories has just been hit by a second phantom withdrawal five years on and is chalking up another case in the files. While her new phantom is a bread-and-butter skim incident (a magstripe clone used in the far east), amongst this mass, true phantoms &#8212; the real mystery cases &#8212; are on the rise too. Two new victims with whom I have been corresponding very kindly offered to fund the hosting for the revamped site.</p>
<p>Let&#8217;s consider one of these mysteries. The McGaughey case has been reported in the media in Northern Ireland: dozens of withdrawals taking place over four weeks, totaling almost five thousand pounds, all within a ten mile radius of the McGaughey&#8217;s home. Summarised that way it looks like a classic first party fraud (couple short on cash withdraw money, then deny it later). But no-one in the family is short on cash, the McGaugheys look after their card details carefully, and have solid <a href="http://www.bridgewebs.com/derryvolgie/">alibis</a> at the time of many of the withdrawals, and the interlocking pattern of real and disputed withdrawals is such that any third party would have a hard time taking and returning the card (whether covertly or in collusion with the McGaugheys). No-one appears to have either the means or the motive.</p>
<p>Unusually the bank has been very cooperative, providing logs from their authorisation system (<A href="http://www.aciworldwide.com/products/detail.aspx?product_id=236">BASE24</a>), including all of the cryptograms, input data and transaction parameters covering the affected transactions. Everything turns on the Application Transaction Counter (ATC), an on-card counter which increments with every transaction initiated. If an EMV chip can be fully cloned (secret keys and all), then it will have to submit an ATC value when transacting, and if used in parallel with the real card, it won&#8217;t be long before the same number pops up twice in the auth system, or large gaps in the sequence appear. The McGaughey&#8217;s ATC sequence appears to interlock perfectly: clearly the original card was used?</p>
<p>Of course logs can be misinterpreted (<a href="http://news.bbc.co.uk/1/hi/programmes/newsnight/7265437.stm">Badger</a>) or even faked, auth systems may not work as expected, and customers may lie and cheat following all sorts of agendas; just around the corner the missing piece of the jigsaw may lie, which reveals the truth behind the case. And there is the totally separate matter of who should suffer the loss in the interim, whilst the truth remains unclear. <a href="http://www.lightbluetouchpaper.org/2008/04/09/new-banking-code-shifts-more-liability-to-customers/">Liability for disputed withdrawals</a> is the most hotly contested issue of all.</p>
<p><a href="http://www.phantomwithdrawals.com">phantomwithdrawals.com</a> can&#8217;t do much more for the McGaugheys, but it can bear witness. Documenting the incidence of phantoms and the experiences of customers disputing them adds much needed transparency to the process, and helps researchers and experts seek out the really interesting cases.</p>
<p>Maybe we can lift the lid and discover the truth behind the &#8220;phantom menace&#8221; &#8212; everyone is united in that goal at least &#8212; but let&#8217;s also hope that Episode 2: <a href="http://www.epaynews.com/index.cgi?survey=&#038;ref=browse&#038;f=view&#038;id=11497625028614136145&#038;block=">Attack of the Clones</a> has not yet started shooting!</p>
<p>Mike.</p>
]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 11:06:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/phantom">phantom</category>
      <category domain="http://securityratty.com/tag/real">real</category>
      <category domain="http://securityratty.com/tag/real card">real card</category>
      <category domain="http://securityratty.com/tag/card details">card details</category>
      <category domain="http://securityratty.com/tag/phantom menace">phantom menace</category>
      <category domain="http://securityratty.com/tag/phantom withdrawal">phantom withdrawal</category>
      <category domain="http://securityratty.com/tag/transaction">transaction</category>
      <category domain="http://securityratty.com/tag/application transaction counter">application transaction counter</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/05/card-wars-the-phantom-menace/">Card Wars: The Phantom Menace</source>
    </item>
  </channel>
</rss>
