<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fiction]]></title>
    <link>http://securityratty.com/tag/fiction</link>
    <description></description>
    <pubDate>Thu, 07 Aug 2008 07:52:28 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Quantum Cryptography]]></title>
      <link>http://securityratty.com/article/665acbc2a4e65a38fe46108c2e80bb3b</link>
      <guid>http://securityratty.com/article/665acbc2a4e65a38fe46108c2e80bb3b</guid>
      <description><![CDATA[Quantum cryptography is back in the news, and the basic idea is still unbelievably cool, in theory, and nearly useless in real life
The idea behind quantum crypto is that two people communicating...]]></description>
      <content:encoded><![CDATA[<p>Quantum cryptography is back in the news, and the basic idea is still unbelievably cool, in theory, and nearly useless in real life.</p>

<p>The idea behind quantum crypto is that two people communicating using a quantum channel can be absolutely sure no one is eavesdropping.  Heisenberg's uncertainty principle requires anyone measuring a quantum system to disturb it, and that disturbance alerts legitimate users as to the eavesdropper's presence.  No disturbance, no eavesdropper -- period.</p>

<p>This month we've seen reports on a new <a href="http://news.bbc.co.uk/2/hi/science/nature/7661311.stm">working</a> quantum-key distribution <a href="http://news.cnet.com/8301-1009_3-10064219-83.html?part=rss&subj=news&tag=2547-1_3-0-5">network</a> in Vienna, and a new quantum-key distribution <a href="http://www.theregister.co.uk/2008/10/09/quantum_crypto_turbo_charged/">technique</a> out of Britain. Great stuff, but headlines like the BBC's "'Unbreakable' encryption unveiled" are a bit much.</p>

<p>The basic science behind quantum crypto was developed, and prototypes built, in the early 1980s by Charles Bennett and Giles Brassard, and there have been <a href="http://www.cs.mcgill.ca/~crepeau/CRYPTO/Biblio-QC.html">steady advances</a> in engineering since then. I describe basically how it all works in <cite>Applied Cryptography, 2nd Edition</cite> (pages 554-557). At least one company already <a href="http://www.magiqtech.com/">sells</a> quantum-key distribution products.</p>

<p>Note that this is totally separate from <a href="http://en.wikipedia.org/wiki/Quantum_computer">quantum computing</a>, which also has implications for cryptography. Several groups are working on designing and building a quantum computer, which is fundamentally different from a classical computer. If one were built -- and we're talking science fiction here -- then it could factor numbers and solve discrete-logarithm problems very quickly. In other words, it could break all of our commonly used public-key algorithms. For symmetric cryptography it's not that dire: A quantum computer would effectively halve the key length, so that a 256-bit key would be only as secure as a 128-bit key today. Pretty serious stuff, but years away from being practical. I think the best quantum computer today can factor the number 15.</p>

<p>While I like the science of quantum cryptography -- my undergraduate degree was in physics -- I don't see any commercial value in it. I don't believe it solves any security problem that needs solving. I don't believe that it's worth paying for, and I can't imagine anyone but a few technophiles buying and deploying it. Systems that use it don't magically become unbreakable, because the quantum part doesn't address the weak points of the system.</p>

<p>Security is a chain; it's as strong as the weakest link. Mathematical cryptography, as bad as it sometimes is, is the strongest link in most security chains. Our symmetric and public-key algorithms are pretty good, even though they're not based on much rigorous mathematical theory. The real problems are elsewhere: computer security, network security, user interface and so on.</p>

<p>Cryptography is the one area of security that we can get right. We already have good encryption algorithms, good authentication algorithms and good key-agreement protocols.  Maybe quantum cryptography can make that link stronger, but why would anyone bother? There are far more serious security problems to worry about, and it makes much more sense to spend effort securing those.</p>

<p>As I've often said, it's like defending yourself against an approaching attacker by putting a huge stake in the ground. It's useless to argue about whether the stake should be 50 feet tall or 100 feet tall, because either way, the attacker is going to go around it. Even quantum cryptography doesn't "solve" all of cryptography: The keys are exchanged with photons, but a conventional mathematical algorithm takes over for the actual encryption.</p>

<p>I'm always in favor of security research, and I have enjoyed following the developments in quantum cryptography. But as a product, it has no future. It's not that quantum cryptography might be insecure; it's that cryptography is already sufficiently secure.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/10/securitymatters_1016">previously appeared</a> on Wired.com.</p>

<p>EDITED TO ADD (10/21):  It's amazing; even reporters <a href="http://www.itproportal.com/articles/2008/10/20/can-quantum-computing-be-used-tackle-payment-card-fraud/">responding to my essay</a> get it completely wrong:</p>

<blockquote>Keith Harrison, a cryptographer with HP Laboratories, is quoted by the Telegraph as saying that, as quantum computing becomes commonplace, hackers will use the technology to crack conventional encryption.

<p>"We have to be thinking about solutions to the problems that quantum computing will pose," he told the Telegraph. "The average consumer is going to want to know their own transactions and daily business is secure.</p>

<p>"One way of doing this is to use a one time pad  essentially lists of random numbers where one copy of the numbers is held by the person sending the information and an identical copy is held by the person receiving the information. These are completely unbreakable when used properly," he explained.</p>

<p>The critical feature of quantum computing is the unique fact that, if someone tampers with an information feed between two parties, then the nature of the quantum feed changes.</p>

<p>This makes eavesdropping impossible.</blockquote></p>

<p>No, it wouldn't make eavesdropping impossible.  It would make eavesdropping <i>on the communications channel</i> impossible unless someone made an implementation error.  (In the 80s, the NSA broke Soviet one-time-pad systems because the Soviets reused the pad.)  Eavesdropping via spyware or Trojan or TEMPEST would still be possible.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=NpW5M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=NpW5M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=NzQ5M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=NzQ5M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 02:48:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cryptography">cryptography</category>
      <category domain="http://securityratty.com/tag/quantum cryptography">quantum cryptography</category>
      <category domain="http://securityratty.com/tag/quantum">quantum</category>
      <category domain="http://securityratty.com/tag/quantum-key distribution network">quantum-key distribution network</category>
      <category domain="http://securityratty.com/tag/quantum channel">quantum channel</category>
      <category domain="http://securityratty.com/tag/quantum system">quantum system</category>
      <category domain="http://securityratty.com/tag/quantum-key distribution technique">quantum-key distribution technique</category>
      <category domain="http://securityratty.com/tag/quantum feed">quantum feed</category>
      <category domain="http://securityratty.com/tag/quantum crypto">quantum crypto</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/quantum_cryptog.html">Quantum Cryptography</source>
    </item>
    <item>
      <title><![CDATA[Quantum Cryptography: As Awesome As It Is Pointless]]></title>
      <link>http://securityratty.com/article/02906355879678e055ed7a962ad11336</link>
      <guid>http://securityratty.com/article/02906355879678e055ed7a962ad11336</guid>
      <description><![CDATA[Quantum cryptography is back in the news, and the basic idea is still unbelievably cool, in theory, and nearly useless in real life
The idea behind quantum crypto is that two people communicating...]]></description>
      <content:encoded><![CDATA[<p>
Quantum cryptography is back in the news, and the basic idea is still unbelievably cool, in theory, and nearly useless in real life.
</p><p>
The idea behind quantum crypto is that two people communicating using a quantum channel can be absolutely sure no one is eavesdropping.  Heisenberg's uncertainty principle requires anyone measuring a quantum system to disturb it, and that disturbance alerts legitimate users as to the eavesdropper's presence.  No disturbance, no eavesdropper — period.
</p><p>
This month we've seen reports on a new <a href="http://news.bbc.co.uk/2/hi/science/nature/7661311.stm">working</a> quantum-key distribution <a href="http://news.cnet.com/8301-1009_3-10064219-83.html?part=rss&subj=news&tag=2547-1_3-0-5">network</a> in Vienna, and a new quantum-key distribution <a href="http://www.theregister.co.uk/2008/10/09/quantum_crypto_turbo_charged/">technique</a> out of Britain. Great stuff, but headlines like the BBC's "'Unbreakable' encryption unveiled" are a bit much.
 </p><p>
The basic science behind quantum crypto was developed, and prototypes built, in the early 1980s by Charles Bennett and Giles Brassard, and there have been <a href="http://www.cs.mcgill.ca/~crepeau/CRYPTO/Biblio-QC.html">steady advances</a> in engineering since then. I describe basically how it all works in <cite>Applied Cryptography, 2nd Edition</cite> (pages 554-557). At least one company already <a href="http://www.magiqtech.com/">sells</a> quantum-key distribution products.
</p><p>
Note that this is totally separate from <a href="http://en.wikipedia.org/wiki/Quantum_computer">quantum computing</a>, which also has implications for cryptography. Several groups are working on designing and building a quantum computer, which is fundamentally different from a classical computer. If one were built — and we're talking science fiction here — then it could factor numbers and solve discrete-logarithm problems very quickly. In other words, it could break all of our commonly used public-key algorithms. For symmetric cryptography it's not that dire: A quantum computer would effectively halve the key length, so that a 256-bit key would be only as secure as a 128-bit key today. Pretty serious stuff, but years away from being practical. I think the best quantum computer today can factor the number 15.
</p><p>
While I like the science of quantum cryptography — my undergraduate degree was in physics — I don't see any commercial value in it. I don't believe it solves any security problem that needs solving. I don't believe that it's worth paying for, and I can't imagine anyone but a few technophiles buying and deploying it. Systems that use it don't magically become unbreakable, because the quantum part doesn't address the weak points of the system.
</p><p>
Security is a chain; it's as strong as the weakest link. Mathematical cryptography, as bad as it sometimes is, is the strongest link in most security chains. Our symmetric and public-key algorithms are pretty good, even though they're not based on much rigorous mathematical theory. The real problems are elsewhere: computer security, network security, user interface and so on.
</p><p>
Cryptography is the one area of security that we can get right. We already have good encryption algorithms, good authentication algorithms and good key-agreement protocols.  Maybe quantum cryptography can make that link stronger, but why would anyone bother? There are far more serious security problems to worry about, and it makes much more sense to spend effort securing those. 
</p><p>
As I've often said, it's like defending yourself against an approaching attacker by putting a huge stake in the ground. It's useless to argue about whether the stake should be 50 feet tall or 100 feet tall, because either way, the attacker is going to go around it. Even quantum cryptography doesn't "solve" all of cryptography: The keys are exchanged with photons, but a conventional mathematical algorithm takes over for the actual encryption. 
</p><p>
I'm always in favor of security research, and I have enjoyed following the developments in quantum cryptography. But as a product, it has no future. It's not that quantum cryptography might be insecure; it's that cryptography is already sufficiently secure.
</p>
<p> 
---
</p> 
<p><em>Bruce Schneier is chief security technology officer of BT. His new book is </em>Schneier on Security<em>.</em> 
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=c1b0ca00ac0f95597bf221ad5e5c5153" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=c1b0ca00ac0f95597bf221ad5e5c5153" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=UswCM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=UswCM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=wtl5m"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=wtl5m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Lo9gm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Lo9gm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=TTT2M"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=TTT2M" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=FO1rM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=FO1rM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=gniBm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=gniBm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=XHBrm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=XHBrm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=nRLbM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nRLbM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/422243670" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/422243671" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/quantum">quantum</category>
      <category domain="http://securityratty.com/tag/quantum cryptography">quantum cryptography</category>
      <category domain="http://securityratty.com/tag/cryptography">cryptography</category>
      <category domain="http://securityratty.com/tag/quantum-key distribution technique">quantum-key distribution technique</category>
      <category domain="http://securityratty.com/tag/quantum-key distribution network">quantum-key distribution network</category>
      <category domain="http://securityratty.com/tag/quantum crypto">quantum crypto</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/quantum channel">quantum channel</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/422243671/securitymatters_1016">Quantum Cryptography: As Awesome As It Is Pointless</source>
    </item>
    <item>
      <title><![CDATA[Just what color is a security hole?]]></title>
      <link>http://securityratty.com/article/c8ee6671bca09e0abe96c10e625cc445</link>
      <guid>http://securityratty.com/article/c8ee6671bca09e0abe96c10e625cc445</guid>
      <description><![CDATA[Computer attacks in space are no longer the stuff of science fiction: Recently, laptops on the International Space Station turned out to have computer viruses. NASA believes that the malware--a...]]></description>
      <content:encoded><![CDATA[Computer attacks in space are no longer the stuff of science fiction: Recently, laptops on the International Space Station turned out to have computer viruses. NASA believes that the malware--a password stealer that targets online games--may have infected the laptops via a USB thumb drive that one of the astronauts carried aboard. While it wasn't much of a threat, it just goes to show that the little buggers are everywhere.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=89488?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=89488?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/space">space</category>
      <category domain="http://securityratty.com/tag/targets online games">targets online games</category>
      <category domain="http://securityratty.com/tag/usb thumb drive">usb thumb drive</category>
      <category domain="http://securityratty.com/tag/computer viruses">computer viruses</category>
      <category domain="http://securityratty.com/tag/computer attacks">computer attacks</category>
      <category domain="http://securityratty.com/tag/password stealer">password stealer</category>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <category domain="http://securityratty.com/tag/science fiction">science fiction</category>
      <source url="http://www.networkworld.com/news/2008/093008-bugs--fixes-just-what.html?fsrc=rss-security">Just what color is a security hole?</source>
    </item>
    <item>
      <title><![CDATA[Identity Farming]]></title>
      <link>http://securityratty.com/article/b473cbd43ff87938f8034236b68d25c8</link>
      <guid>http://securityratty.com/article/b473cbd43ff87938f8034236b68d25c8</guid>
      <description><![CDATA[Let me start off by saying that I'm making this whole thing up
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity...]]></description>
      <content:encoded><![CDATA[<p>Let me start off by saying that I'm making this whole thing up. </p>

<p>Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity databases is making it increasingly difficult to create fake credentials. Ten years ago, someone could have just shown up in the country and gotten a driver's license, Social Security card and bank account -- possibly using the identity of someone roughly the same age who died as a young child -- but it's getting harder. And you know that trend will only continue. So you decide to grow your own identities. </p>

<p>Call it "identity farming." You invent a handful of infants. You apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them. </p>

<p>There are some complications, of course. Maybe you need people to sign their name as parents -- or, at least, mothers. Maybe you need to doctors to fill out birth certificates. Maybe you need to fill out paperwork certifying that you're home-schooling these children. You'll certainly want to exercise their financial identity: depositing money into their bank accounts and withdrawing it from ATMs, using their credit cards and paying the bills, and so on. And you'll need to establish some sort of addresses for them, even if it is just a mail drop. </p>

<p>You won't be able to get driver's licenses or photo IDs on their name. That isn't critical, though; in the U.S., more than 20 million adult citizens don't have photo IDs. But other than that, I can't think of any reason why identity farming wouldn't work. </p>

<p>Here's the real question: Do you actually have to show up for any part of your life? </p>

<p>Again, I made this all up. I have no evidence that anyone is actually doing this. It's not something a criminal organization is likely to do; twenty-five years is too distant a payoff horizon. The same logic holds true for terrorist organizations; it's not worth it. It might have been worth it to the KGB -- although perhaps harder to justify after the Soviet Union broke up in 1991 -- and might be an attractive option to existing intelligence adversaries like China. </p>

<p>Immortals could also use this trick to self-perpetuate themselves, inventing their own children and gradually assuming their identity, then killing their parents off. They could even show up for their own driver's license photos, wearing a beard as the father and blue spiked hair as the son. Iâm told this is a common idea in Highlander fan fiction. </p>

<p>The point isn't to create another movie plot threat, but to point out the central role that data has taken on in our lives. Previously, I've said that we all have a <a href="http://www.schneier.com/essay-219.html">data shadow</a> that follows us around, and that more and more institutions interact with our data shadows instead of with us. We only intersect with our data shadows once in a while -- when we apply for a driver's license or passport, for example -- and those interactions are authenticated by older, less-secure interactions. The rest of the world assumes that our photo IDs glue us to our data shadows, ignoring the rather flimsy connection between us and our plastic cards. (And, no, REAL-ID won't help.) </p>

<p>It seems to me that our data shadows are becoming increasingly distinct from us, almost with a life of their own. What's important now is our shadows; we're secondary. And as our society relies more and more on these shadows, we might even become unnecessary. </p>

<p>Our data shadows can live a perfectly normal life without us.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/09/securitymatters_0904">previously appeared<a> on Wired.com.</p>

<p>EDITED TO ADD (9/9): Interesting <a href="http://www.examiner.com/x-536-Civil-Liberties-Examiner~y2008m9d4-Im-not-myself-today-or-manufacturing-a-new-you">commentary</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YzkGL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YzkGL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JDMVL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JDMVL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 01:42:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data shadow">data shadow</category>
      <category domain="http://securityratty.com/tag/data shadows">data shadows</category>
      <category domain="http://securityratty.com/tag/shadows">shadows</category>
      <category domain="http://securityratty.com/tag/financial identity">financial identity</category>
      <category domain="http://securityratty.com/tag/photo ids glue">photo ids glue</category>
      <category domain="http://securityratty.com/tag/photo ids">photo ids</category>
      <category domain="http://securityratty.com/tag/identity databases">identity databases</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/identity_farmin.html">Identity Farming</source>
    </item>
    <item>
      <title><![CDATA[Security ROI: Fact or fiction?]]></title>
      <link>http://securityratty.com/article/fbf6bc81005b78cbc57848cbb082e371</link>
      <guid>http://securityratty.com/article/fbf6bc81005b78cbc57848cbb082e371</guid>
      <description><![CDATA[When it comes to cyber security, all the ROI models fall apart. Here's why, and what you should do to make the most of your security...]]></description>
      <content:encoded><![CDATA[When it comes to cyber security, all the ROI models fall apart. Here's why, and what you should do to make the most of your security dollars.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:499c2a3a4d1aa61439cbe62d4cd721a1:DJCjreRdpg2uL56Ovb%2FBaJMlxgrCAICnp%2BpHMVcDOMW2qd0UmX%2FLmE6xi455fMF1bkYG8ZFHx7ijHPofzFyNyOx0g%2F4gk9Pz3%2BCYW71HLKE%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:25b7a76cb8b61875b7cad53dccd49786:4cBhwYjUhxbtyp86FDvu3GtGJ0SFJoghVp2ggud5SD18yTJxDTNackKCEWNZxEtZIlkoBLcNa8Vd1sPdw%2FTk%2B%2F5IImLOvUVo8ASLPntPExA%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:ee3c45171e1eb9f561a02aea8ad1ed21:S7FhDHaUgjuQw%2B6cPqZ4mFe68gBextIupfhRc5FD1pF8%2BnSlyAPSvqOM1Rzh2Zy%2F%2B%2BW5qtJ3KyEPoLfKFIEDmBtGfwdd86KFmX3qho%2FHhGs%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:4570f11122724a774ae63a17d336e012:7ZU5nlEZE5tx7LYSOApmnG32QQG5r4kKGWr6uZPBaD6Ji9RZIcnKdE%2FNBzu%2BaeEB9AdNi4TL4RsEbpq5PawTHx7ZoyzcLOlftPfjUBn1I1Y%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=a0cc86654df97d21104738409cff9a63" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a0cc86654df97d21104738409cff9a63" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security dollars">security dollars</category>
      <category domain="http://securityratty.com/tag/roi models">roi models</category>
      <category domain="http://securityratty.com/tag/cyber security">cyber security</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=a0cc86654df97d21104738409cff9a63">Security ROI: Fact or fiction?</source>
    </item>
    <item>
      <title><![CDATA[Security ROI: Fact or fiction?]]></title>
      <link>http://securityratty.com/article/f275ab680afeb5adde96e6c738593c89</link>
      <guid>http://securityratty.com/article/f275ab680afeb5adde96e6c738593c89</guid>
      <description><![CDATA[When it comes to cyber security, all the ROI models fall apart. Here's why, and what you should do to make the most of your security...]]></description>
      <content:encoded><![CDATA[When it comes to cyber security, all the ROI models fall apart. Here's why, and what you should do to make the most of your security dollars.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=QTRpQE"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=QTRpQE" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/382919644" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 00:36:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security dollars">security dollars</category>
      <category domain="http://securityratty.com/tag/roi models">roi models</category>
      <category domain="http://securityratty.com/tag/cyber security">cyber security</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/382919644/article.do">Security ROI: Fact or fiction?</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: How to Create the Perfect Fake Identity]]></title>
      <link>http://securityratty.com/article/978beddfbfcfa8c96d83a85e27f028f6</link>
      <guid>http://securityratty.com/article/978beddfbfcfa8c96d83a85e27f028f6</guid>
      <description><![CDATA[Let me start off by saying that I'm making this whole thing up
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity...]]></description>
      <content:encoded><![CDATA[<p>Let me start off by saying that I'm making this whole thing up.
</p>

<p>
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity databases is making it increasingly difficult to create fake credentials. Ten years ago, someone could have just shown up in the country and gotten a driver's license, Social Security card and bank account -- possibly using the identity of someone roughly the same age who died as a young child -- but it's getting harder. And you know that trend will only continue. So you decide to grow your own identities.
</p>

<p>
Call it "identity farming." You invent a handful of infants. You apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them.
</p>

<p>
There are some complications, of course. Maybe you need people to sign their name as parents -- or, at least, mothers. Maybe you need to doctors to fill out birth certificates. Maybe you need to fill out paperwork certifying that you're home-schooling these children. You'll certainly want to exercise their financial identity: depositing money into their bank accounts and withdrawing it from ATMs, using their credit cards and paying the bills, and so on. And you'll need to establish some sort of addresses for them, even if it is just a mail drop.
</p>

<p>
You won't be able to get driver's licenses or photo IDs on their name. That isn't critical, though; in the U.S., more than 20 million adult citizens don't have photo IDs. But other than that, I can't think of any reason why identity farming wouldn't work.  
</p>

<p>
Here's the real question: Do you actually have to show up for any part of your life?
</p>

<p>
Again, I made this all up. I have no evidence that anyone is actually doing this. It's not something a criminal organization is likely to do; twenty-five years is too distant a payoff horizon. The same logic holds true for terrorist organizations; it's not worth it. It might have been worth it to the KGB -- although perhaps harder to justify after the Soviet Union broke up in 1991 -- and might be an attractive option to existing intelligence adversaries like China.
</p>

<p>
Immortals could also use this trick to self-perpetuate themselves, inventing their own children and gradually assuming their identity, then killing their parents off. They could even show up for their own driver's license photos, wearing a beard as the father and blue spiked hair as the son. I’m told this is a common idea in <a href="http://www.highlander.org/"><cite>Highlander</cite></a> fan fiction.
</p>

<p>
The point isn't to create another movie plot threat, but to point out the central role that data has taken on in our lives. Previously, I've said that we all have a <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/05/securitymatters_0515">data shadow</a> that follows us around, and that more and more institutions interact with our data shadows instead of with us. We only intersect with our data shadows once in a while -- when we apply for a driver's license or passport, for example -- and those interactions are authenticated by older, less-secure interactions. The rest of the world assumes that our photo IDs glue us to our data shadows, ignoring the rather flimsy connection between us and our plastic cards. (And, no, REAL-ID won't help.)
</p>

<p>
It seems to me that our data shadows are becoming increasingly distinct from us, almost with a life of their own. What's important now is our shadows; we're secondary. And as our society relies more and more on these shadows, we might even become unnecessary.
</p>

<p>
Our data shadows can live a perfectly normal life without us.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is Chief Security Technology Officer of BT, and author of </cite>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<cite>.</cite>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=8c450d9a9d0030ff631259b1803cae6a" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=8c450d9a9d0030ff631259b1803cae6a" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=snUd9L"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=snUd9L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=uzqRkl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=uzqRkl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=zVASIl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=zVASIl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=itvpML"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=itvpML" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=XRzLgL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=XRzLgL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=hSbcKl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=hSbcKl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Rk785l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Rk785l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=qjRx3L"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qjRx3L" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/382935195" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/382935196" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data shadow">data shadow</category>
      <category domain="http://securityratty.com/tag/data shadows">data shadows</category>
      <category domain="http://securityratty.com/tag/shadows">shadows</category>
      <category domain="http://securityratty.com/tag/social security card">social security card</category>
      <category domain="http://securityratty.com/tag/financial identity">financial identity</category>
      <category domain="http://securityratty.com/tag/photo ids glue">photo ids glue</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/382935196/securitymatters_0904">Security Matters: How to Create the Perfect Fake Identity</source>
    </item>
    <item>
      <title><![CDATA[In the News: Hacking the T, Georgia on Their Mind and Cyberbullying]]></title>
      <link>http://securityratty.com/article/6842e0c51946c54dd8a65c699b7b4943</link>
      <guid>http://securityratty.com/article/6842e0c51946c54dd8a65c699b7b4943</guid>
      <description><![CDATA[Cyberwarfare Against GeorgiaCyberwarfare has moved from science fiction to hard military fact. Do you need proof? Last week, computer experts from Estonia traveled to Georgia to keep the...]]></description>
      <content:encoded><![CDATA[Cyberwarfare Against GeorgiaCyberwarfare has moved from science fiction to hard military fact. Do you need proof? Last week, computer experts from Estonia traveled to Georgia to keep the country's...]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 06:20:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hard military">hard military</category>
      <category domain="http://securityratty.com/tag/computer experts">computer experts</category>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/science fiction">science fiction</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/moved">moved</category>
      <category domain="http://securityratty.com/tag/cyberwarfare">cyberwarfare</category>
      <category domain="http://securityratty.com/tag/proof">proof</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/382697984/">In the News: Hacking the T, Georgia on Their Mind and Cyberbullying</source>
    </item>
    <item>
      <title><![CDATA[Friday Squid Blogging: Talking Squids in Outer Space]]></title>
      <link>http://securityratty.com/article/87f5c6b689b960e5f179a191af6bc43b</link>
      <guid>http://securityratty.com/article/87f5c6b689b960e5f179a191af6bc43b</guid>
      <description><![CDATA[An index of fiction
The site was inspired by Margaret Atwood's infamous comment that Oryx and Crake isn't really science fiction, because science fiction is &quot;talking squids in outer space.&quot; This...]]></description>
      <content:encoded><![CDATA[<p>An index of <a href="http://talkingsquidsinouterspace.com/">fiction</a>.</p>

<p>The site was inspired by Margaret Atwood's infamous comment that <i>Oryx and Crake</i> isn't really science fiction, because science fiction is "talking squids in outer space." This prompted a hunt for science fiction which actually did feature talking squids in outer space.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=q2EugK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=q2EugK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=V8N3JK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=V8N3JK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 12:57:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/outer space">outer space</category>
      <category domain="http://securityratty.com/tag/fiction">fiction</category>
      <category domain="http://securityratty.com/tag/science fiction">science fiction</category>
      <category domain="http://securityratty.com/tag/squids">squids</category>
      <category domain="http://securityratty.com/tag/margaret atwood">margaret atwood</category>
      <category domain="http://securityratty.com/tag/infamous comment">infamous comment</category>
      <category domain="http://securityratty.com/tag/hunt">hunt</category>
      <category domain="http://securityratty.com/tag/feature">feature</category>
      <category domain="http://securityratty.com/tag/index">index</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/friday_squid_bl_63.html">Friday Squid Blogging: Talking Squids in Outer Space</source>
    </item>
    <item>
      <title><![CDATA[Where Computers and Biology Intersect What is Life?]]></title>
      <link>http://securityratty.com/article/b18143e16ebb7dcbc61eec5d7d657fa7</link>
      <guid>http://securityratty.com/article/b18143e16ebb7dcbc61eec5d7d657fa7</guid>
      <description><![CDATA[Scientists have recently discovered a biological virus called Sputnik that can infect another virus (a Giant Virus, known as mamavirus), and hijack its machinery for self-replication and theyre using...]]></description>
      <content:encoded><![CDATA[<p>Scientists have recently discovered a biological virus called Sputnik that can infect another virus (a Giant Virus, known as mamavirus), and hijack its machinery for self-replication &#8212; and they&#8217;re using this new discovery as evidence that a virus is alive.</p>
<p>The question whether biological viruses are forms of life has been debated, since they lack the respiratory and metabolic process of other accepted life forms. Naturally, different scientists have different reasons for opinions either way.</p>
<p>So how does <a rel="nofollow" target="_blank" href="http://www.nature.com/news/2008/080806/full/454677a.html">the new virus</a>-infecting-virus work?</p>
<blockquote><p>With just 21 genes, Sputnik is tiny compared with its mama — but insidious. When the giant mamavirus infects an amoeba, it uses its large array of genes to build a ‘viral factory’, a hub where new viral particles are made. Sputnik infects this viral factory and seems to hijack its machinery in order to replicate. The team found that cells co-infected with Sputnik produce fewer and often deformed mamavirus particles, making the virus less infective. This suggests that Sputnik is effectively a viral parasite that sickens its host — seemingly the first such example.</p>
<p>&#8230;</p>
<p>“It was the cause of great excitement in virology,” says Eugene Koonin at the National Center for Biotechnology Information in Bethesda, Maryland. “It crossed the imaginary boundary between viruses and cellular organisms.”</p></blockquote>
<p>Science fiction, fantasy and the popular imagination have been fueled in recent decades by the concept of the cyborg, that fusion of machine and creature &#8212; but under the scientists&#8217; new definition, even your laptop might be evidence of life&#8230;provided it&#8217;s infected by a computer virus.</p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 07:52:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/giant virus">giant virus</category>
      <category domain="http://securityratty.com/tag/virus">virus</category>
      <category domain="http://securityratty.com/tag/biological virus">biological virus</category>
      <category domain="http://securityratty.com/tag/sputnik">sputnik</category>
      <category domain="http://securityratty.com/tag/sputnik produce fewer">sputnik produce fewer</category>
      <category domain="http://securityratty.com/tag/computer virus">computer virus</category>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/mamavirus">mamavirus</category>
      <category domain="http://securityratty.com/tag/mamavirus particles">mamavirus particles</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/358696064/">Where Computers and Biology Intersect What is Life?</source>
    </item>
  </channel>
</rss>
