<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: photography]]></title>
    <link>http://securityratty.com/tag/photography</link>
    <description></description>
    <pubDate>Sun, 13 Apr 2008 21:35:30 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Coming Soon to a Movie Plot Near You]]></title>
      <link>http://securityratty.com/article/cb190ec3098a190d9aa05cdd5aa4e139</link>
      <guid>http://securityratty.com/article/cb190ec3098a190d9aa05cdd5aa4e139</guid>
      <description><![CDATA[The problem with most video surveillance is that it is not actively monitored. It is recorded so that events can be reconstructed at a later date. While this may prove to be an effective deterrent in...]]></description>
      <content:encoded><![CDATA[<p><a href="http://artofinfosec.com/wp-content/uploads/william_lamson_security_camera_hack.jpg" ><img class="size-medium wp-image-81 alignright" style="margin: 25px;" title="william_lamson_security_camera_hack" src="http://artofinfosec.com/wp-content/uploads/william_lamson_security_camera_hack-207x300.jpg" alt="" width="207" height="300" /></a>The problem with most video surveillance is that it is not actively monitored. It is recorded so that events can be reconstructed at a later date. While this may prove to be an effective deterrent in many situations, this does limit the effectiveness (and the cost of operation) of the surveillance system.</p>
<p>Of course, a major problem with that approach is that the &#8220;persons of interest&#8221; are long gone by the time the video shows that &#8220;yep, you can defiantly see some guy cutting off that lock and stealing that&#8230;&#8221;.</p>
<p>Another problem is that unless the equipment is being checked on a regular basis, it may be defeated (or just broken) for a long time before any problems are identified.</p>
<p>In the photo to the right, a <a href="http://http://www.williamlamson.com/#/work/intervention/works/1" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://http://www.williamlamson.com/#/work/intervention/works/1');" target="_blank">NYC artist  William Lamson</a>, has created an interesting photo of hacking (or blocking) a security camera with a helium balloon. This is such a simple and inexpensive attack on the video surveillance camera that I am shocked I haven&#8217;t seen this before. I am also certain that the appearance of this in a  TV or movie plot is imminent. It would have been pretty simple to use two balloons to block the camera without providing the nice tether to &#8220;fix&#8221; the problem.</p>
<p>Digital photography is a hobby of mine, and I have a mild obsession for photographing physical security faux pas (which to date has not resulted in any &#8216;Imperial Entanglements&#8217; <img src='http://artofinfosec.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ). So I am going to use Mr. Lamson&#8217;s photo to kick off a new category (and series) on Art of Information Security, called &#8220;Security faux pas&#8221; - stay tuned&#8230;</p>
<p>Cheers, Erik</p>
<p></p>
<p><a href="http://artofinfosec.com/80/coming-soon-to-a-movie-plot-near-you/" >Coming Soon to a Movie Plot Near You&#8230;</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/351945868" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 17:10:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/video surveillance camera">video surveillance camera</category>
      <category domain="http://securityratty.com/tag/camera">camera</category>
      <category domain="http://securityratty.com/tag/video surveillance">video surveillance</category>
      <category domain="http://securityratty.com/tag/movie plot">movie plot</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/photo">photo</category>
      <category domain="http://securityratty.com/tag/lamsons photo">lamsons photo</category>
      <category domain="http://securityratty.com/tag/security camera">security camera</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/351945868/">Coming Soon to a Movie Plot Near You</source>
    </item>
    <item>
      <title><![CDATA[Exploiting the War on Photography]]></title>
      <link>http://securityratty.com/article/1186ee121e916394439e8bd365cba690</link>
      <guid>http://securityratty.com/article/1186ee121e916394439e8bd365cba690</guid>
      <description><![CDATA[Petty thieves are exploiting the war on photography in Genoa: As they were walking around, Jeff saw some interesting looking produce and pulled out his Canon G-9 Point-and-Shoot and took a few...]]></description>
      <content:encoded><![CDATA[Petty thieves are <a href="http://www.scottkelby.com/blog/2008/archives/1649">exploiting</a> the <a href="http://www.schneier.com/blog/archives/2008/06/the_war_on_phot.html">war on photography</a> in Genoa:

<blockquote>As they were walking around, Jeff saw some interesting looking produce and pulled out his Canon G-9 Point-and-Shoot and took a few pictures. Within a few minutes a man came up dressed in plain clothes, flashed a badge, and told him he couldn't take photos in the store. My brother said "no problem" (after all, it's a private store, right?), but then the guy demanded my brother's memory card.

My brother gave him that "Are you outta your mind" look and said, "No way!" Can you guess what happened next? The guy simply shrugged his shoulders and walked away.

My brother saw him in the store a little later, and the guy had a bag and was shopping. My brother made eye contact with him, and the guy turned away as though he didn't want Jeff looking at him. Jeff feels like this wasn't "official store security," but instead some guy collecting (and then reselling) memory cards from unsuspecting tourists (many of whom might have just surrendered that card immediately).</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=urHI1J"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=urHI1J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=W9u6kJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=W9u6kJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 02:54:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/guy simply">guy simply</category>
      <category domain="http://securityratty.com/tag/official store security">official store security</category>
      <category domain="http://securityratty.com/tag/store">store</category>
      <category domain="http://securityratty.com/tag/brother">brother</category>
      <category domain="http://securityratty.com/tag/jeff feels">jeff feels</category>
      <category domain="http://securityratty.com/tag/jeff">jeff</category>
      <category domain="http://securityratty.com/tag/canon g-9 point-and-shoot">canon g-9 point-and-shoot</category>
      <category domain="http://securityratty.com/tag/photography">photography</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/exploiting_the.html">Exploiting the War on Photography</source>
    </item>
    <item>
      <title><![CDATA[Kill Switches and Remote Control]]></title>
      <link>http://securityratty.com/article/6faff6d8aced2811984a7463136f6b3a</link>
      <guid>http://securityratty.com/article/6faff6d8aced2811984a7463136f6b3a</guid>
      <description><![CDATA[It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now...]]></description>
      <content:encoded><![CDATA[It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now everyone else wants to get their hooks into your gear.

OnStar will soon include the <a href="http://www.informationweek.com/news/mobility/showArticle.jhtml?articleID=202400922">ability</a> for the police to shut off your engine remotely. Buses are getting the <a href="http://www.nypost.com/seven/06082008/news/regionalnews/busting_terror_114567.htm">same capability</a>, in case terrorists want to re-enact the movie <cite>Speed</cite>. The Pentagon wants a kill switch <a href="http://blog.wired.com/defense/2008/06/the-pentagons-n.html">installed</a> on airplanes, and is worried about potential enemies <a href="http://spectrum.ieee.org/may08/6171">installing</a> kill switches on their own equipment. 

Microsoft is doing some of the most creative thinking along these lines, with something it's calling "<a href="http://arstechnica.com/news.ars/post/20080611-microsoft-patent-brings-miss-manners-into-the-digital-age.html">Digital Manners Policies</a>." According to its <a href="http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=HITOFF&d=PG01&p=1&u=%2Fnetahtml%2FPTO%2Fsrchnum.html&r=1&f=G&l=50&s1=%2220080125102%22.PGNR.&OS=DN/20080125102&RS=DN/20080125102">patent application</a>, DMP-enabled devices would accept broadcast "orders" limiting capabilities. Cellphones could be remotely set to vibrate mode in restaurants and concert halls, and be turned off on airplanes and in hospitals. Cameras could be prohibited from taking pictures in locker rooms and museums, and recording equipment could be disabled in theaters. Professors finally could prevent students from texting one another during class. 

The possibilities are endless, and very dangerous. Making this work involves building a nearly flawless hierarchical system of authority. That's a difficult security problem even in its simplest form. Distributing that system among a variety of different devices -- computers, phones, PDAs, cameras, recorders -- with different firmware and manufacturers, is even more difficult. Not to mention delegating different levels of authority to various agencies, enterprises, industries and individuals, and then enforcing the necessary safeguards.

Once we go down this path -- giving one device authority over other devices -- the security problems start piling up. Who has the authority to limit functionality of my devices, and how do they get that authority? What prevents them from abusing that power? Do I get the ability to override their limitations? In what circumstances, and how? Can they override my override?

How do we prevent this from being abused? Can a burglar, for example, enforce a "no photography" rule and prevent security cameras from working? Can the police enforce the same rule to avoid another Rodney King incident? Do the police get "superuser" devices that cannot be limited, and do they get "supercontroller" devices that can limit anything? How do we ensure that only they get them, and what do we do when the devices inevitably fall into the wrong hands?

It's comparatively easy to make this work in closed specialized systems -- OnStar, airplane avionics, military hardware -- but much more difficult in open-ended systems. If you think Microsoft's vision could possibly be securely designed, all you have to do is look at the dismal effectiveness of the various copy-protection and digital-rights-management systems we've seen over the years. That's a similar capabilities-enforcement mechanism, albeit simpler than these more general systems.

And that's the key to understanding this system. Don't be fooled by the scare stories of wireless devices on airplanes and in hospitals, or visions of a world where no one is yammering loudly on their cellphones in posh restaurants. This is really about media companies wanting to exert their control further over your electronics. They not only want to prevent you from surreptitiously recording movies and concerts, they want your new television to enforce good "manners" on your computer, and not allow it to record any programs. They want your iPod to politely refuse to copy music to a computer other than your own. They want to enforce <em>their</em> legislated definition of manners: to control what you do and when you do it, and to charge you repeatedly for the privilege whenever possible. 

"Digital Manners Policies" is a marketing term. Let's call this what it really is: Selective Device Jamming. It's not polite, it's dangerous. It won't make anyone more secure -- or more polite.

This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/06/securitymatters_0626">originally appeared</a> in Wired.com.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JiKwGJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JiKwGJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=aXm5MJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=aXm5MJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 02:48:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wireless devices">wireless devices</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/devices inevitably">devices inevitably</category>
      <category domain="http://securityratty.com/tag/digital manners policies">digital manners policies</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/prevent security cameras">prevent security cameras</category>
      <category domain="http://securityratty.com/tag/difficult security">difficult security</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/prevent students">prevent students</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/kill_switches_a.html">Kill Switches and Remote Control</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: I've Seen the Future, and It Has a Kill Switch]]></title>
      <link>http://securityratty.com/article/b9aa8529e116abf92778a4755495e63d</link>
      <guid>http://securityratty.com/article/b9aa8529e116abf92778a4755495e63d</guid>
      <description><![CDATA[It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now...]]></description>
      <content:encoded><![CDATA[<p>It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now everyone else wants to get their hooks into your gear.
</p><p>
OnStar will soon include the <a href="http://www.informationweek.com/news/mobility/showArticle.jhtml?articleID=202400922">ability</a> for the police to shut off your engine remotely. Buses are getting the <a href="http://www.nypost.com/seven/06082008/news/regionalnews/busting_terror_114567.htm">same capability</a>, in case terrorists want to re-enact the movie <cite>Speed</cite>. The Pentagon wants a kill switch <a href="http://blog.wired.com/defense/2008/06/the-pentagons-n.html">installed</a> on airplanes, and is worried about potential enemies <a href="http://spectrum.ieee.org/may08/6171">installing</a> kill switches on their own equipment. 
</p><p>
Microsoft is doing some of the most creative thinking along these lines, with something it's calling "<a href="http://arstechnica.com/news.ars/post/20080611-microsoft-patent-brings-miss-manners-into-the-digital-age.html">Digital Manners Policies</a>." According to its <a href="http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=HITOFF&d=PG01&p=1&u=%2Fnetahtml%2FPTO%2Fsrchnum.html&r=1&f=G&l=50&s1=%2220080125102%22.PGNR.&OS=DN/20080125102&RS=DN/20080125102">patent application</a>, DMP-enabled devices would accept broadcast "orders" limiting capabilities. Cellphones could be remotely set to vibrate mode in restaurants and concert halls, and be turned off on airplanes and in hospitals. Cameras could be prohibited from taking pictures in locker rooms and museums, and recording equipment could be disabled in theaters. Professors finally could prevent students from texting one another during class. 
</p><p>
The possibilities are endless, and very dangerous. Making this work involves building a nearly flawless hierarchical system of authority. That's a difficult security problem even in its simplest form. Distributing that system among a variety of different devices -- computers, phones, PDAs, cameras, recorders -- with different firmware and manufacturers, is even more difficult. Not to mention delegating different levels of authority to various agencies, enterprises, industries and individuals, and then enforcing the necessary safeguards.
</p><p>
Once we go down this path -- giving one device authority over other devices -- the security problems start piling up. Who has the authority to limit functionality of my devices, and how do they get that authority? What prevents them from abusing that power? Do I get the ability to override their limitations? In what circumstances, and how? Can they override my override?
</p><p>
How do we prevent this from being abused? Can a burglar, for example, enforce a "no photography" rule and prevent security cameras from working? Can the police enforce the same rule to avoid another Rodney King incident? Do the police get "superuser" devices that cannot be limited, and do they get "supercontroller" devices that can limit anything? How do we ensure that only they get them, and what do we do when the devices inevitably fall into the wrong hands?
</p><p>
It's comparatively easy to make this work in closed specialized systems -- OnStar, airplane avionics, military hardware -- but much more difficult in open-ended systems. If you think Microsoft's vision could possibly be securely designed, all you have to do is look at the dismal effectiveness of the various copy-protection and digital-rights-management systems we've seen over the years. That's a similar capabilities-enforcement mechanism, albeit simpler than these more general systems.
</p><p>
And that's the key to understanding this system. Don't be fooled by the scare stories of wireless devices on airplanes and in hospitals, or visions of a world where no one is yammering loudly on their cellphones in posh restaurants. This is really about media companies wanting to exert their control further over your electronics. They not only want to prevent you from surreptitiously recording movies and concerts, they want your new television to enforce good "manners" on your computer, and not allow it to record any programs. They want your iPod to politely refuse to copy music a computer other than your own. They want to enforce <em>their</em> legislated definition of manners: to control what you do and when you do it, and to charge you repeatedly for the privilege whenever possible. 
</p><p>
"Digital Manners Policies" is a marketing term. Let's call this what it really is: Selective Device Jamming. It's not polite, it's dangerous. It won't make anyone more secure -- or more polite.
</p>
<p>
---
</p>
<p><em>Bruce Schneier is chief security technology officer of BT, and author of</em> Beyond Fear: Thinking Sensibly About Security in an Uncertain World<em>.</em>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=2e7004605a2cfdb2dff6647568035341" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=2e7004605a2cfdb2dff6647568035341" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=TdV5GI"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=TdV5GI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=hCKWyi"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=hCKWyi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=P6GE7i"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=P6GE7i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=YY5ZlI"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=YY5ZlI" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=rAla0I"><img src="http://feeds.wired.com/~f/wired/politics/security?i=rAla0I" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=DKXIgi"><img src="http://feeds.wired.com/~f/wired/politics/security?i=DKXIgi" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=IE7M8i"><img src="http://feeds.wired.com/~f/wired/politics/security?i=IE7M8i" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=swX5hI"><img src="http://feeds.wired.com/~f/wired/politics/security?i=swX5hI" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/320220918" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/320220920" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/wireless devices">wireless devices</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/prevent security cameras">prevent security cameras</category>
      <category domain="http://securityratty.com/tag/difficult security">difficult security</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/prevent students">prevent students</category>
      <category domain="http://securityratty.com/tag/difficult">difficult</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/320220920/securitymatters_0626">Security Matters: I've Seen the Future, and It Has a Kill Switch</source>
    </item>
    <item>
      <title><![CDATA[The War on Photography]]></title>
      <link>http://securityratty.com/article/e6f171eea9c9a93417a3d9104f855e8e</link>
      <guid>http://securityratty.com/article/e6f171eea9c9a93417a3d9104f855e8e</guid>
      <description><![CDATA[What is it with photographers these days? Are they really all terrorists, or does everyone just think they are
Since 9/11, there has been an increasing war on photography. Photographers have been...]]></description>
      <content:encoded><![CDATA[<p>What is it with photographers these days?  Are they really all terrorists, or does everyone just think they are?</p>

<p>Since 9/11, there has been an increasing war on photography.  <a href="http://nycphotorights.com/wordpress/?p=110">Photographers</a> <a href="http://news.bbc.co.uk/2/hi/technology/7351252.stm">have</a> <a href="http://www.allensphotoblog.com/blog1/2007/09/photography_terrorism.html">been</a> <a href="http://flash.popphoto.com/blog/2007/06/the-crime-of-ph.html">harrassed</a>, <a href="http://flash.popphoto.com/blog/2007/10/the-crime-of-ph.html">questioned</a>, <a href="http://flash.popphoto.com/blog/2007/09/the-crime-of-ph.html">detained</a>, <a href="http://flash.popphoto.com/blog/2007/11/the-crime-of-ph.html">arrested</a> or <a href="http://www.episcopalcafe.com/daily/war_and_peace/every_day_diplomacy.php">worse</a>, and <a href="http://blog.myspace.com/index.cfm?fuseaction=blog.view&amp;friendID=71473815&amp;blogID=394235689">declared</a> <a href="http://www.boingboing.net/2008/05/14/bb-reader-two-fbi-ag.html">to</a> <a href="http://www.andycarvin.com/archives/2008/05/almost_arrested_for_taking_photos_at_uni.html">be</a> <a href="http://blog.washingtonpost.com/rawfisher/2008/05/union_station_photo_follies.html">unwelcome</a>. We've been repeatedly told to <a href="http://www.amateurphotographer.co.uk/news/Antiterror_police_defend_campaign_targeting_suspicious_behaviour_of_people_with_cameras_news_195594.html">watch</a> <a href="http://www.news.com.au/couriermail/story/0,23739,23553587-952,00.html">out</a> <a href="http://www.salon.com/tech/col/smith/2006/02/10/askthepilot173/index.html">for</a> <a href="http://www.nytimes.com/2008/01/20/arts/design/20shat.html?_r=1&amp;adxnnl=1&amp;oref=slogin&amp;adxnnlx=1210125984-qrPPfpI/kDlEi+wMrOvtEA">photographers</a>, especially <a href="http://lightchasersphotography.com/blog/how-to-shoot-photographs-like-a-terrorist/">suspicious</a> <a href="http://www.memphisflyer.com/memphis/Content?oid=oid%3A41348">ones</a>.  Clearly any terrorist is going to first photograph his target, so vigilance is required.</p>

<p>Except that it's <a href="http://blog.wired.com/gadgets/2008/03/uk-politician-c.html">nonsense</a>.  The 9/11 terrorists didn't photograph anything.  Nor did the London transport bombers, the Madrid subway bombers, or the liquid bombers arrested in 2006.  Timothy McVeigh didn't photograph the Oklahoma City Federal Building.  The Unabomber didn't photograph anything; neither did shoe-bomber Richard Reid.  Photographs aren't being found amongst the papers of Palestinian suicide bombers.  The IRA wasn't known for its photography.  Even those <a href="http://www.schneier.com/essay-174.html">manufactured terrorist plots</a> that the US government likes to talk about -- the Ft. Dix terrorists, the JFK airport bombers, the Miami 7, the Lackawanna 6 -- no photography.</p>

<p>Given that real terrorists, and even wannabe terrorists, don't seem to photograph anything, why is it such pervasive conventional wisdom that terrorists photograph their targets?  Why are our fears so great that we have no choice but to be suspicious of any photographer?</p>

<p>Because it's a <a href="http://www.schneier.com/essay-087.html">movie-plot threat</a>.</p>

<p>A movie-plot threat is a specific threat, vivid in our minds like the plot of a movie.  You remember them from the months after the 9/11 attacks: anthrax spread from crop dusters, a contaminated milk supply, terrorist scuba divers armed with almanacs.  Our imaginations run wild with detailed and specific threats, from the news, and from actual movies and television shows.  These movie plots resonate in our minds and in the minds of others we talk to.  And many of us get scared.</p>

<p>Terrorists taking pictures is a quintessential detail in any good movie.  Of course it makes sense that terrorists will take pictures of their targets.  They have to do reconnaissance, don't they?  We need 45 minutes of television action before the actual terrorist attack -- 90 minutes if it's a movie -- and a photography scene is just perfect.  It's our movie-plot terrorists that are photographers, even if the real-world ones are not.</p>

<p>The problem with movie-plot security is it only works if we guess the plot correctly.  If we spend a zillion dollars defending Wimbledon and terrorists blow up a different sporting event, that's money wasted.  If we post guards all over the Underground and terrorists bomb a crowded shopping area, that's also a waste.  If we teach everyone to be alert for photographers, and terrorists don't take photographs, we've wasted money and effort, and taught people to fear something they shouldn't.</p>

<p>And even if terrorists did photograph their targets, the math doesn't make sense.  Billions of photographs are taken by honest people every year, <a href="http://www.nytimes.com/2005/05/05/fashion/thursdaystyles/05photos.html">50 billion</a> by amateurs alone in the US  And the national monuments you imagine terrorists taking photographs of are the same ones tourists like to take pictures of.  If you see someone taking one of those photographs, the odds are infinitesimal that he's a terrorist.</p>

<p>Of course, it's far easier to explain the problem than it is to fix it.  Because we're a species of storytellers, we find movie-plot threats <a href="http://www.schneier.com/essay-171.html">uniquely compelling</a>.  A single vivid scenario will do more to convince people that photographers might be terrorists than all the data I can muster to demonstrate that they're not.</p>

<p>Fear aside, there aren't many legal restrictions on what you can photograph from a public place that's already in public view.  If you're harassed, it's almost certainly a law enforcement official, public or private, acting way beyond his authority.  There's nothing in any post-9/11 law that restricts your right to photograph.</p>

<p>This is worth fighting.  Search "photographer rights" on Google and download one of the several wallet documents that can help you if you get harassed; I found one for the <a href="http://www.sirimo.co.uk/ukpr.php">UK</a>, <a href="http://www.krages.com/phoright.htm">US</a>, and <a href="http://www.artslaw.com.au/_documents/files/StreetPhotographersRights.pdf">Australia</a>.  Don't cede your right to photograph in public.  Don't propagate the terrorist photographer story.  Remind them that prohibiting photography was something we used to ridicule about the USSR.  Eventually sanity will be restored, but it may take a while.</p>

<p>This essay <a href="http://www.guardian.co.uk/technology/2008/jun/05/news.terrorism">originally appeared</a> in <i>The Guardian</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=7inlUI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=7inlUI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=vkX7JI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=vkX7JI" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 02:44:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/movie">movie</category>
      <category domain="http://securityratty.com/tag/movie-plot security">movie-plot security</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/imagine terrorists">imagine terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists bomb">terrorists bomb</category>
      <category domain="http://securityratty.com/tag/movie-plot terrorists">movie-plot terrorists</category>
      <category domain="http://securityratty.com/tag/dix terrorists">dix terrorists</category>
      <category domain="http://securityratty.com/tag/movie-plot threats uniquely">movie-plot threats uniquely</category>
      <category domain="http://securityratty.com/tag/wannabe terrorists">wannabe terrorists</category>
      <source url="http://www.schneier.com/blog/archives/2008/06/the_war_on_phot.html">The War on Photography</source>
    </item>
    <item>
      <title><![CDATA[Filming in DC's Union Station]]></title>
      <link>http://securityratty.com/article/a9cf6fdf3badd6c22f7cd9f107b5fd12</link>
      <guid>http://securityratty.com/article/a9cf6fdf3badd6c22f7cd9f107b5fd12</guid>
      <description><![CDATA[This video is priceless. A Washington DC news crew goes down to Union Station to interview someone from Amtrak about people who have been stopped from taking pictures even though there's no policy...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.myfoxdc.com/myfox/pages/Home/Detail?contentId=6664418&version=1&locale=EN-US&layoutCode=VSTY&pageId=1.1.1">This video</a> is priceless.  A Washington DC news crew goes down to Union Station to interview someone from Amtrak about people who have been stopped from taking pictures even though there's no policy against it.  As the Amtrack spokesperson is explaining that there is no policy against photography, a guard comes up and tries to stop them from filming, saying it is against the rules.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=8GmFlI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=8GmFlI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=0fJAzI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=0fJAzI" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 03 Jun 2008 09:57:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/union station">union station</category>
      <category domain="http://securityratty.com/tag/news crew">news crew</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <category domain="http://securityratty.com/tag/amtrack spokesperson">amtrack spokesperson</category>
      <category domain="http://securityratty.com/tag/photography">photography</category>
      <category domain="http://securityratty.com/tag/priceless">priceless</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/amtrak">amtrak</category>
      <source url="http://www.schneier.com/blog/archives/2008/06/filming_in_dcs.html">Filming in DC's Union Station</source>
    </item>
    <item>
      <title><![CDATA[Google takes Street View snaps in Paris; lawsuits may follow]]></title>
      <link>http://securityratty.com/article/4c88dfe6c250ed3eb259ea52170fb3ec</link>
      <guid>http://securityratty.com/article/4c88dfe6c250ed3eb259ea52170fb3ec</guid>
      <description><![CDATA[Google has begun scanning the streets of Paris, gathering data for its Street View service, which adds street-level photography to the satellite views offered by Google Maps. The search company will...]]></description>
      <content:encoded><![CDATA[Google has begun scanning the streets of Paris, gathering data for its Street View service, which adds street-level photography to the satellite views offered by Google Maps. The search company will gather a wealth of data from the project but, thanks to France's strict privacy laws, it may also pick up a few lawsuits on the way if it chooses to publish the photos unedited.]]></content:encoded>
      <pubDate>Thu, 08 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/google maps">google maps</category>
      <category domain="http://securityratty.com/tag/street view service">street view service</category>
      <category domain="http://securityratty.com/tag/strict privacy laws">strict privacy laws</category>
      <category domain="http://securityratty.com/tag/satellite views">satellite views</category>
      <category domain="http://securityratty.com/tag/lawsuits">lawsuits</category>
      <category domain="http://securityratty.com/tag/paris">paris</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/street-level photography">street-level photography</category>
      <source url="http://www.networkworld.com/news/2008/050908-google-takes-street-view-snaps.html?fsrc=rss-security">Google takes Street View snaps in Paris; lawsuits may follow</source>
    </item>
    <item>
      <title><![CDATA[RSA Day 2: Wednesday with JJ & the Engima]]></title>
      <link>http://securityratty.com/article/3b6a2b76bdadf65037a7c7a51ded2473</link>
      <guid>http://securityratty.com/article/3b6a2b76bdadf65037a7c7a51ded2473</guid>
      <description><![CDATA[RSA Conference, San Francisco
Day 2: Wednesday, April 9th
I know, I know- its late- but better late than never, right
I really tried my best to take photos as much as possible. A quick note on the...]]></description>
      <content:encoded><![CDATA[<p><strong>RSA Conference, San Francisco<br />Day 2: Wednesday, April 9th</strong></p><p>I know, I know- it&#8217;s late- but better late than never, right?</p><p>I really tried my best to take photos as much as possible.&nbsp;A quick note on the photography- because of the size of the rooms, it didn&#8217;t make sense to have the flash on, unfortunately it slowed the shutter speed, making some images blurry (sorry). </p><p>So Day 2 already felt like day 5 somehow. I had flown in early to be a tourist for a day or so but caught up with partners and other event-goers early, making it an especially long week. Wednesday was an eventful day. I have a great&nbsp; <strong>Sins of Our Fathers</strong> session to share with you, a day with the <strong>Enigmas</strong>, and the <strong>Security Bloggers Party</strong>. </p><p><strong>The highlight of the day&#8217;s sessions had to be the</strong> <strong>&#8216;Sins of Our Fathers&#8217;</strong> breakout with an amazingly hilarious geek-filled panel including <a class="offsite-link-inline" href="http://www.linkedin.com/in/danhouser" target="_blank">Daniel Houser</a>, <a class="offsite-link-inline" href="http://www.cryptography.com/company/Benjamin-Jun.html" target="_blank">Ben Jun </a>and <a class="offsite-link-inline" href="http://www.linkedin.com/pub/2/1bb/3b5" target="_blank">Hugh Thompson</a>. (Hugh unquestionably won the <em>Most Entertaining Geek Award</em> for the day). I was <a class="offsite-link-inline" href="http://tweetscan.com/index.php?s=SoOF&u=jjx&p=0" target="_blank">tweeting live</a> from the session and took some photos of the interactive polls they intertwined in the discussion. They drew some interesting correlations between current security issues, such as SQL injections an &#8216;previous sins&#8217;, likening it to&nbsp;phone whistling. There were random notes about the&nbsp;inherent security risk of&nbsp;mixing data and coding together. <a class="offsite-link-inline" href="http://www.flickr.com/photos/42618430@N00/tags/soof/" target="_blank">View photos from session.</a></p><p><span class="full-image-float-right"><img style="width: 256px; height: 192px" alt="DSC01791.JPG" src="http://www.securityuncorked.com/storage/DSC01791.JPG?__SQUARESPACE_CACHEVERSION=1208144360449" /></span>Then they talked about using good technology in a way that made it vulnerable. Examples, the Enigma code machines from WWII. (It was&nbsp;actually broken by the known plain-text gathered from repetition in contact initiation, and the mis-use of one-time-pads). They drew the line from Enigma to WEP and other algorithms that were okay, but mis-implemented. </p><p>There were a variety of other anecdotes, accompanied by audience-wide snickers, snorts and laughter. One story of tape backups, encrypted, with the key dutifully stick-noted to the case. Another of the secretary who type-writered all the 5.25&#8221; floppies. The story of the unmanned Predator aircraft flying unattended for about 5 minutes during a PC reboot. They were all tied into the topic nicely, and the guys did an outstanding job interacting and playing off one another. </p><p>One a more serious note- well, sorta- Hugh showed a clip from his participation in the documentary &#8220;<a class="offsite-link-inline" href="http://www.hbo.com/docs/programs/hackingdemocracy/" target="_blank">Hacking Democracy&#8221;</a> about the lack of security of electronic voting. </p><blockquote><p>Here was&nbsp;something amusing&#8230; Their crypto&nbsp;list of <br /><strong>If you hear&nbsp;any of these, RUN!</strong></p><ol><li><div>Cryptography is expensive. </div></li><li><div>We have this guy that&#8217;s reallllly smart&#8230;</div></li><li><div>Wired EQUIVALENT encryption&#8230; .&nbsp;</div></li><li><div>It&#8217;s &#8220;proprietary&#8221; security</div></li><li><div>It&#8217;s revolutionary NEW cryptography technology!</div></li><li><div>It uses DES- so its FIPS 140 compliant&nbsp;</div></li></ol></blockquote><blockquote><p><strong>Some of the sins from the session&#8230;</strong></p><ul><li><div>Engineering, Development &amp; Management sins </div></li><li><div>Using a good technology in a bad implementation</div></li><li><div>Lack of metrics to indicate misuse</div></li><li><div>Feature/mission creep - using item A for solution B</div></li><li><div>Not teaching people how to use security</div></li><li><div>Teaching them, but teaching bad habits </div></li><li><div>Normalization of deviancy </div></li></ul></blockquote><p>I&#8217;ve spent long enough on that, there&#8217;s plenty more to share, but that session was so good, I thought it deserved some special attention. I did stay for the <strong>Cyber Storm II</strong> Panel, but that left more than <em>&#8216;a little&#8217;</em> to be desired. I would have liked more anecdotal stories and a little more personality. The panel participants were knowledgeable, and I&#8217;m sure they were doing what they had been told, but it made for a very dry session, little content of interest, and much repetition. There&#8217;s a little <a class="offsite-link-inline" href="http://tweetscan.com/index.php?s=CSII&u=jjx" target="_blank">live Tweeting </a>from that session too. </p><p>&nbsp;</p><p><strong>Playing with the Enigma<span class="full-image-float-right"><img style="width: 256px; height: 192px" alt="DSC01797.JPG" src="http://www.securityuncorked.com/storage/DSC01797.JPG?__SQUARESPACE_CACHEVERSION=1208144122189" /></span></strong><br />At the Sins of Our Fathers sessions, I believe it was Ben that mentioned we had at our disposal not one- but TWO Enigma machines on the expo floor here are RSA. And BOTH were for our playing! They had it set so we could set the key and encode a message at the NSA booth, then take the encrypted message to the Cryptographic Research booth and use that Enigma to decypher the message. <em>HOLY COW!!!!!!</em> If their session hadn&#8217;t been so great I would have left right then. The only time I&#8217;ve seen these beautiful little pieces of crypto history, they&#8217;ve been fully encased in glass, and not for the touching. They actually let you set the rotors and punch the code in yourself so my buddy Eric and I ran right over to take full geek advantage of the situation.&nbsp;</p><p>YES, that&#8217;s me with an Enigma, and I have <a class="offsite-link-inline" href="http://www.flickr.com/photos/42618430@N00/tags/enigma/" target="_blank">more photos </a>of the two Engimas.</p><p>&nbsp;</p><p><strong>The big highlight of the evening? The Security Bloggers Party</strong> of course! You get a whole post just for this topic, so stay tuned for that. I didn&#8217;t take photos here, because I felt pretty sure someone would be walking around with a camera. I need to find @ajolly (Apneet Jolly) and see if he has any- he&#8217;s usually fully equipped with a very nice camera&#8230; </p><p># # #</p>
]]></content:encoded>
      <pubDate>Sun, 13 Apr 2008 21:35:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/inherent security risk">inherent security risk</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/security bloggers party">security bloggers party</category>
      <category domain="http://securityratty.com/tag/dry session">dry session</category>
      <category domain="http://securityratty.com/tag/session">session</category>
      <category domain="http://securityratty.com/tag/enigma">enigma</category>
      <category domain="http://securityratty.com/tag/enigma machines">enigma machines</category>
      <category domain="http://securityratty.com/tag/fathers session">fathers session</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/4/14/rsa-day-2-wednesday-with-jj-the-engima.html">RSA Day 2: Wednesday with JJ &amp; the Engima</source>
    </item>
  </channel>
</rss>
