<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: electronic]]></title>
    <link>http://securityratty.com/tag/electronic</link>
    <description></description>
    <pubDate>Tue, 30 Sep 2008 08:24:51 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA["New Attack" Against Encrypted Images]]></title>
      <link>http://securityratty.com/article/d53a9071459b26f731fbd3ec643dbde8</link>
      <guid>http://securityratty.com/article/d53a9071459b26f731fbd3ec643dbde8</guid>
      <description><![CDATA[In a blatant attempt to get some PR : In a new paper, Bernd Roellgen of Munich-based encryption outfit PMC Ciphers, explains how it is possible to compare an encrypted backup image file made with...]]></description>
      <content:encoded><![CDATA[<p>In a blatant attempt to get some <a href="http://www.techworld.com/security/news/index.cfm?newsid=105263">PR</a>:</p>

<blockquote>In a new paper, Bernd Roellgen of Munich-based encryption outfit PMC Ciphers, explains how it is possible to compare an encrypted backup image file made with almost any commercial encryption program or algorithm to an original that has subsequently changed so that small but telling quantities of data 'leaks'.</blockquote>

<p><a href="http://www.turbocrypt.com/vpics/9a8f098c615a425eab6d17c804dd67ae/whitepapers/backup_attack.pdf">Here's</a> the paper.  Turns out that if you use a block cipher in Electronic Codebook Mode, identical plaintexts encrypt to identical ciphertexts.</p>

<p>Yeah, we already knew that.</p>

<p>And -1 point for a security company requiring the use of Javascript, and not failing gracefully for a browser that doesn't have it enabled.</p>

<p>And -- ahem -- what is it with that photograph in the paper?  Couldn't the researchers have found something a little less adolescent?</p>

<p>For the record, I <a href="http://www.schneier.com/crypto-gram-0303.html#4">doghoused</a> PMC Ciphers back in 2003:</p>

<blockquote>PMC Ciphers. The theory description is so filled with pseudo-cryptography that it's funny to read. Hypotheses are presented as conclusions. Current research is misstated or ignored. The first link is a technical paper with four references, three of them written before 1975. Who needs thirty years of cryptographic research when you have polymorphic cipher theory?</blockquote>

<p>EDITED TO ADD (10/9):  I didn't realize it, but last year PMC Ciphers <a href="http://www.ciphers.de/eng/content/Backround-Info/Bruce-Schneiers-comments.html">responded</a> to my doghousing them.  Funny stuff.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=oYuwM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=oYuwM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=jkURM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=jkURM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 02:44:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pmc ciphers">pmc ciphers</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <category domain="http://securityratty.com/tag/technical paper">technical paper</category>
      <category domain="http://securityratty.com/tag/commercial encryption program">commercial encryption program</category>
      <category domain="http://securityratty.com/tag/polymorphic cipher theory">polymorphic cipher theory</category>
      <category domain="http://securityratty.com/tag/funny">funny</category>
      <category domain="http://securityratty.com/tag/backup image file">backup image file</category>
      <category domain="http://securityratty.com/tag/identical plaintexts encrypt">identical plaintexts encrypt</category>
      <category domain="http://securityratty.com/tag/funny stuff">funny stuff</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/new_attack_agai.html">"New Attack" Against Encrypted Images</source>
    </item>
    <item>
      <title><![CDATA[A Life or Death InfoSec Subversion]]></title>
      <link>http://securityratty.com/article/ce84889e3d8b870803c3f3d97330cfdd</link>
      <guid>http://securityratty.com/article/ce84889e3d8b870803c3f3d97330cfdd</guid>
      <description><![CDATA[Details about failures of complex and well-implemented information-based attacks on systems are extremely difficult to obtain. However, here the authors examine a real-life analoguean information...]]></description>
      <content:encoded><![CDATA[Details about failures of complex and well-implemented information-based attacks on systems are extremely difficult to obtain. However, here the authors examine a real-life analogue—an information attack on a highly complex security system, that of the Colombian guerrilla group FARC. This operation included a man-in-the-middle attack, targeted denial of service (DoS), and authentication subversion. The attack on FARC's communications structure is interesting not only because of its electronic and analog components, but also because it was a life or death matter. The authors examine the hostages' liberation from an information security perspective, compiling data from several Colombian newspapers and magazines and using the most accepted version of the events.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=344380c94465538d8840535190445e21"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=344380c94465538d8840535190445e21"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=344380c94465538d8840535190445e21" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/authors examine">authors examine</category>
      <category domain="http://securityratty.com/tag/information security perspective">information security perspective</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/communications structure">communications structure</category>
      <category domain="http://securityratty.com/tag/death matter">death matter</category>
      <category domain="http://securityratty.com/tag/colombian guerrilla">colombian guerrilla</category>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/colombian newspapers">colombian newspapers</category>
      <category domain="http://securityratty.com/tag/extremely difficult">extremely difficult</category>
      <source url="http://www.pheedo.com/click.phdo?i=344380c94465538d8840535190445e21">A Life or Death InfoSec Subversion</source>
    </item>
    <item>
      <title><![CDATA[Data Retention and Privacy in Electronic Communications]]></title>
      <link>http://securityratty.com/article/8c25f32527ed66213f5716af1ebfb28b</link>
      <guid>http://securityratty.com/article/8c25f32527ed66213f5716af1ebfb28b</guid>
      <description><![CDATA[The retention of communication data by network providers, often mandated by legislation, raises social and technical security concerns. A generic model combining technical, procedural, and legal...]]></description>
      <content:encoded><![CDATA[The retention of communication data by network providers, often mandated by legislation, raises social and technical security concerns. A generic model combining technical, procedural, and legal controls can help secure retained data and minimize privacy threats against users.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=2decd6847ba49454704c462f5e3e7364" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=2decd6847ba49454704c462f5e3e7364" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/technical">technical</category>
      <category domain="http://securityratty.com/tag/technical security concerns">technical security concerns</category>
      <category domain="http://securityratty.com/tag/communication data">communication data</category>
      <category domain="http://securityratty.com/tag/legal controls">legal controls</category>
      <category domain="http://securityratty.com/tag/privacy threats">privacy threats</category>
      <category domain="http://securityratty.com/tag/network providers">network providers</category>
      <category domain="http://securityratty.com/tag/raises social">raises social</category>
      <category domain="http://securityratty.com/tag/retention">retention</category>
      <source url="http://www.pheedo.com/click.phdo?i=2decd6847ba49454704c462f5e3e7364">Data Retention and Privacy in Electronic Communications</source>
    </item>
    <item>
      <title><![CDATA[Privacy groups praise bill curbing warrantless laptop searches]]></title>
      <link>http://securityratty.com/article/3e5c86703fcd723be1c09d323e7eba39</link>
      <guid>http://securityratty.com/article/3e5c86703fcd723be1c09d323e7eba39</guid>
      <description><![CDATA[Privacy and civil rights groups are welcoming legislation that proposes tough new standards for conducting searches of laptops and other electronic devices at U.S....]]></description>
      <content:encoded><![CDATA[Privacy and civil rights groups are welcoming legislation that proposes tough new standards for conducting searches of laptops and other electronic devices at U.S. borders.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d75e7e7574e820f215bcef0d3e650a14:wRVNlK0s2lTjz4UitRm7ygudfOic8tUIcj7XEGbgChJeoGiVX2W66ct33zVR4wv8zIwiRbyhc6UX'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a0d63ce0da45e5423c2e4f7697b7f8ad:ttIl5mjn5fLoRCxRCgJncx%2Fe5OADE4893%2FmUTlJ688WbK7nHBIsBIDf0EqGo%2FHGU8Np9quPs0%2B%2FCog%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:cfad8daef69c39380f7bea6b8020bdd6:dIZwcZ5PDbTf9supUSQZhmrI3O8BdTBwHsrXaZZXR4OOTg2auGFCvncZ7Ok4Kt8DHzIPaBXfSjJtnA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ed26b5c25cb776693b9c17c2bfec6fff:ADiL6RFEzLVYkwwzmei3DpZPb7uffvx2JVZPC94kdmmWLxIT7roOYLfAiVBPdOhSpct7DfId7xNP3w%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=b74bfde27100ef4a76987c5cd5a9973f" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=b74bfde27100ef4a76987c5cd5a9973f" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/electronic devices">electronic devices</category>
      <category domain="http://securityratty.com/tag/proposes tough">proposes tough</category>
      <category domain="http://securityratty.com/tag/civil rights">civil rights</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <category domain="http://securityratty.com/tag/borders">borders</category>
      <category domain="http://securityratty.com/tag/standards">standards</category>
      <category domain="http://securityratty.com/tag/legislation">legislation</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=b74bfde27100ef4a76987c5cd5a9973f">Privacy groups praise bill curbing warrantless laptop searches</source>
    </item>
    <item>
      <title><![CDATA[Data-Mining for Terrorists Not 'Feasible,' DHS-Funded Study Finds]]></title>
      <link>http://securityratty.com/article/6273d380d4e70b7ad2fefbc1bceedfea</link>
      <guid>http://securityratty.com/article/6273d380d4e70b7ad2fefbc1bceedfea</guid>
      <description><![CDATA[Searching for terrorists in masses of electronic data doesn't work and will lead to unacceptable privacy invasions, a government-funded commission reported Tuesday. Instead, the government should...]]></description>
      <content:encoded><![CDATA[Searching for terrorists in masses of electronic data doesn't work and will lead to unacceptable privacy invasions, a government-funded commission reported Tuesday. Instead, the government should carefully evaluate how it uses the same technology as book recommendation software, and update the nation's privacy laws.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=bfaca9e109a610ab8e3b44a09be637df" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=bfaca9e109a610ab8e3b44a09be637df" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=k8GOM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=k8GOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Cvtfm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Cvtfm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=ovUNm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=ovUNm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=3H0bM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=3H0bM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=6pfmM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=6pfmM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Dmbum"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Dmbum" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=McSZm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=McSZm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=1KTkM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=1KTkM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/414257221" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/414257224" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 15:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/unacceptable privacy invasions">unacceptable privacy invasions</category>
      <category domain="http://securityratty.com/tag/book recommendation software">book recommendation software</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/electronic data">electronic data</category>
      <category domain="http://securityratty.com/tag/privacy laws">privacy laws</category>
      <category domain="http://securityratty.com/tag/nation">nation</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/lead">lead</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/414257224/data-mining-for.html">Data-Mining for Terrorists Not 'Feasible,' DHS-Funded Study Finds</source>
    </item>
    <item>
      <title><![CDATA[Anatomy of SQL injection attack]]></title>
      <link>http://securityratty.com/article/886b4b1b3c2fa196604a06176132cc4b</link>
      <guid>http://securityratty.com/article/886b4b1b3c2fa196604a06176132cc4b</guid>
      <description><![CDATA[While there are a number of security risks in the world of electronic commerce, SQL injection is one of the most common Web site attack techniques used to steal customer data such as credit card...]]></description>
      <content:encoded><![CDATA[While there are a number of security risks in the world of electronic commerce, SQL injection is one of the most common Web site attack techniques used to steal customer data such as credit card numbers, hold customer data hostage by encrypting it or destroy data outright.]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sql injection">sql injection</category>
      <category domain="http://securityratty.com/tag/destroy data outright">destroy data outright</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/customer data">customer data</category>
      <category domain="http://securityratty.com/tag/security risks">security risks</category>
      <category domain="http://securityratty.com/tag/electronic commerce">electronic commerce</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <source url="http://www.networkworld.com/news/tech/2008/100708-tech-update.html?fsrc=rss-security">Anatomy of SQL injection attack</source>
    </item>
    <item>
      <title><![CDATA[Cybersecurity, password recall, IT culture and more]]></title>
      <link>http://securityratty.com/article/53c0de20a83328a71c02b8360fb5d221</link>
      <guid>http://securityratty.com/article/53c0de20a83328a71c02b8360fb5d221</guid>
      <description><![CDATA[As part of a comprehensive cybersecurity push, the U.S. government will focus on improving its network defense capabilities and revamping acquisition rules to protect against malicious code installed...]]></description>
      <content:encoded><![CDATA[As part of a comprehensive cybersecurity push, the U.S. government will focus on improving its network defense capabilities and revamping acquisition rules to protect against malicious code installed during the manufacturing process of electronic devices.]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/comprehensive cybersecurity push">comprehensive cybersecurity push</category>
      <category domain="http://securityratty.com/tag/network defense capabilities">network defense capabilities</category>
      <category domain="http://securityratty.com/tag/malicious code">malicious code</category>
      <category domain="http://securityratty.com/tag/acquisition rules">acquisition rules</category>
      <category domain="http://securityratty.com/tag/electronic devices">electronic devices</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <source url="http://www.networkworld.com/news/2008/100708-cybersecurity-password-recall-it-culture.html?fsrc=rss-security">Cybersecurity, password recall, IT culture and more</source>
    </item>
    <item>
      <title><![CDATA[Government sends auditors to investigate Postapay fraud]]></title>
      <link>http://securityratty.com/article/c0eda9efb0ee776398a1680c5609a96e</link>
      <guid>http://securityratty.com/article/c0eda9efb0ee776398a1680c5609a96e</guid>
      <description><![CDATA[Efforts by the Postal Corporation of Kenya to embrace technology have hit a snag, with the government sending forensic auditors to probe the integrity of its electronic money transfer service,...]]></description>
      <content:encoded><![CDATA[Efforts by the Postal Corporation of Kenya to embrace technology have hit a snag, with the government sending forensic auditors to probe the integrity of its electronic money transfer service, Postapay, following reports of millions of shillings lost to fraudsters.]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/shillings lost">shillings lost</category>
      <category domain="http://securityratty.com/tag/forensic auditors">forensic auditors</category>
      <category domain="http://securityratty.com/tag/postapay">postapay</category>
      <category domain="http://securityratty.com/tag/postal corporation">postal corporation</category>
      <category domain="http://securityratty.com/tag/embrace technology">embrace technology</category>
      <category domain="http://securityratty.com/tag/fraudsters">fraudsters</category>
      <category domain="http://securityratty.com/tag/kenya">kenya</category>
      <category domain="http://securityratty.com/tag/hit">hit</category>
      <source url="http://www.networkworld.com/news/2008/100108-government-sends-auditors-to-investigate.html?fsrc=rss-security">Government sends auditors to investigate Postapay fraud</source>
    </item>
    <item>
      <title><![CDATA[IBM software bundle targets retail theft, data breaches]]></title>
      <link>http://securityratty.com/article/cb4662b93f7c290a9d035a6a5cae17ea</link>
      <guid>http://securityratty.com/article/cb4662b93f7c290a9d035a6a5cae17ea</guid>
      <description><![CDATA[IBM is targeting retail security with a package of software and services designed to prevent physical loss of merchandise, protect against electronic threats and comply with credit card industry...]]></description>
      <content:encoded><![CDATA[IBM is targeting retail security with a package of software and services designed to prevent physical loss of merchandise, protect against electronic threats and comply with credit card industry regulations.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=70698?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=70698?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/prevent physical loss">prevent physical loss</category>
      <category domain="http://securityratty.com/tag/electronic threats">electronic threats</category>
      <category domain="http://securityratty.com/tag/ibm">ibm</category>
      <category domain="http://securityratty.com/tag/retail security">retail security</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <category domain="http://securityratty.com/tag/comply">comply</category>
      <category domain="http://securityratty.com/tag/package">package</category>
      <source url="http://www.networkworld.com/news/2008/100108-ibm-retail-theft.html?fsrc=rss-security">IBM software bundle targets retail theft, data breaches</source>
    </item>
    <item>
      <title><![CDATA[How to Clone and Modify E-Passports]]></title>
      <link>http://securityratty.com/article/d87db1f435de50bdfb362a781b2835de</link>
      <guid>http://securityratty.com/article/d87db1f435de50bdfb362a781b2835de</guid>
      <description><![CDATA[The Hackers Choice has released a tool allowing people to clone and modify electronic passports
The problem is self-signed certificates
A CA is not a great solution: Using a Certification Authority...]]></description>
      <content:encoded><![CDATA[<p>The Hackers Choice has <a href="http://blog.thc.org/index.php?/archives/4-The-Risk-of-ePassports-and-RFID.html">released</a> a tool allowing people to clone and modify electronic passports.</p>

<p>The problem is self-signed certificates.</p>

<p>A CA is not a great solution:</p>

<blockquote>Using a Certification Authority (CA) could solve the attack but at the same time introduces a new set of attack vectors:

<ol><li>The CA becomes a single point of failure. It becomes the juicy/high-value target for the attacker. Single point of failures are not good. Attractive targets are not good.

<p>Any person with access to the CA key can undetectably fake passports. Direct attacks, virus, misplacing the key by accident (the UK government is good at this!) or bribery are just a few ways of getting the CA key.</p>

<p><li>The single CA would need to be trusted by all governments. This is not practical as this means that passports would no longer be a national matter.</p>

<p><li>Multiple CA's would not work either. Any country could use its own CA to create a valid passport of any other country. Read this sentence again: Country A can create a passport data set of Country B and sign it with Country A's CA key. The terminal will validate and display the information as data from Country B.This option also multiplies the number of 'juicy' targets. It makes it also more likely for a CA key to leak.</p>

<p>Revocation lists for certificates only work when a leak/loss is detected. In most cases it will not be detected.</ol></p>

<p>So what's the solution? We know that humans are good at Border Control. In the end they protected us well for the last 120 years. We also know that humans are good at pattern matching and image recognition. Humans also do an excellent job 'assessing' the person and not just the passport. Take the human part away and passport security falls apart.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=UYU6L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=UYU6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=z7bQL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=z7bQL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 08:24:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passports">passports</category>
      <category domain="http://securityratty.com/tag/passport">passport</category>
      <category domain="http://securityratty.com/tag/passport security falls">passport security falls</category>
      <category domain="http://securityratty.com/tag/passport data set">passport data set</category>
      <category domain="http://securityratty.com/tag/set">set</category>
      <category domain="http://securityratty.com/tag/electronic passports">electronic passports</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/undetectably fake passports">undetectably fake passports</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/how_to_clone_an.html">How to Clone and Modify E-Passports</source>
    </item>
  </channel>
</rss>
