<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: plane]]></title>
    <link>http://securityratty.com/tag/plane</link>
    <description></description>
    <pubDate>Thu, 28 Aug 2008 08:25:25 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[What would you do if you knew the Air Marshal on your plane was smuggling Drugs?]]></title>
      <link>http://securityratty.com/article/6902b40b209c72e9190f6544d2968f20</link>
      <guid>http://securityratty.com/article/6902b40b209c72e9190f6544d2968f20</guid>
      <description><![CDATA[According to a recent USA TODAY article, Federal Air Marshals have been convicted of smuggling drugs, molesting children, abducting a female escort during a layover in Washington D.C., hiring a hitman...]]></description>
      <content:encoded><![CDATA[According to a recent USA TODAY article, Federal Air Marshals have been convicted of smuggling drugs, molesting children, abducting a female escort during a layover in Washington D.C., hiring a hitman to kill a spouse and many other criminal acts. <br /><span id="fullpost"><br />The ex-Air Marshal who was convicted of smuggling drugs apparently used his position to work with a drug dealer to carry cocaine and drug money with him on flights around the country.  He was caught on tape telling an informant that he was "the man with the Golden Badge".<br /></span><br />We should remember though, that with a current force of between 3,000 - 4,000 (exact numbers are confidential), there are bound to be a few bad apples in the bunch - that is the way in every profession.  <br /><br />What makes it much more alarming when we talk about Air Marshals gone bad is the fact that at 30,000 feet in the air - their authority is absolute.  The last thing a passenger in a plane needs to be concerned about is the very person on the plane whose job it is to protect the passengers.<br /><br />The Marshal's decision making skills should be beyond reproach.  If their judgement is clouded over however, due to experimenting with the cocaine they are smuggling, the consequences could prove fatal.<br /><br />Perhaps the fact that prior to 2001, the Air Marshal service had an annual budget of $4.4 million and 33 agents which exploded to $786 million and between 3,000 to 4,000 agents today might have something to do with undesirables falling through the cracks.<br /><br />Not that rapid hiring needs are an excuse for allowing criminal behavior to go unnoticed.  The office of Inspector General or Internal Affairs needs to get actively involved and properly supervise the agency so that rogue Marshals are not allowed to remain in the service.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sat, 15 Nov 2008 20:34:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/air">air</category>
      <category domain="http://securityratty.com/tag/air marshals">air marshals</category>
      <category domain="http://securityratty.com/tag/federal air marshals">federal air marshals</category>
      <category domain="http://securityratty.com/tag/marshal">marshal</category>
      <category domain="http://securityratty.com/tag/air marshal service">air marshal service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/drugs">drugs</category>
      <category domain="http://securityratty.com/tag/ex-air marshal">ex-air marshal</category>
      <category domain="http://securityratty.com/tag/plane">plane</category>
      <source url="http://www.thebulletproofblog.com/2008/11/what-would-you-do-if-you-knew-air.html">What would you do if you knew the Air Marshal on your plane was smuggling Drugs?</source>
    </item>
    <item>
      <title><![CDATA[Kip Hawley Responds to My Airport Security Antics]]></title>
      <link>http://securityratty.com/article/2e95c109ca3f99365400804e6c31b4dd</link>
      <guid>http://securityratty.com/article/2e95c109ca3f99365400804e6c31b4dd</guid>
      <description><![CDATA[Kip Hawley, head of the TSA, has responded to my airport security penetration testing , published in The Atlantic
Unfortunately, there's not really anything to his response. It's obvious he doesn't...]]></description>
      <content:encoded><![CDATA[<p>Kip Hawley, head of the TSA, has <a href="http://www.tsa.gov/blog/2008/10/tsas-take-on-atlantic-article.html">responded</a> to my <a href="http://www.schneier.com/blog/archives/2008/10/me_helping_evad.html">airport security penetration testing</a>, published in <i>The Atlantic</i>.</p>

<p>Unfortunately, there's not really anything to his response.  It's obvious he doesn't want to admit that they've been checking ID's all this time to no purpose whatsoever, so he just emits vague generalities like a frightened squid filling the water with ink.  Yes, some of the stunts in article are silly (who cares if people fly with Hezbollah T-shirts?) so that gives him an opportunity to minimize the real issues.</p>

<blockquote>Watch-lists and identity checks are important and effective security measures. We identify dozens of terrorist-related individuals a week and stop No-Flys regularly with our watch-list process.</blockquote>

<p>It is simply impossible that the TSA catches dozens of terrorists every week. If it were true, the administration would be trumpeting this all over the press -- it would be an amazing success story in their war on terrorism.  But note that Hawley doesn't exactly say that; he calls them "terrorist-related individuals."  Which means exactly what?  People so dangerous they can't be allowed to fly for any reason, yet so innocent they can't be arrested -- even under the provisions of the Patriot Act.</p>

<p>And if Secretary Chertoff is telling the truth when he <a href="http://www.cnn.com/2008/TRAVEL/10/22/no.fly.lists/index.html">says</a> that there are only 2,500 people on the no-fly list and fewer than 16,000 people on the selectee list -- they're the ones that get extra screening -- and that most of them live outside the U.S., then it is statistically impossible that the TSA identifies "dozens" of these people every week.  The math just doesn't make sense.</p>

<p>And I also don't believe this:</p>

<blockquote>Behavior detection works and we have 2,000 trained officers at airports today. They alert us to people who may pose a threat but who may also have items that could elude other layers of physical security.</blockquote>

<p>It does work, but I don't see the TSA doing it properly.  (Fly El Al if you want to see it done properly.)  But what I think Hawley is doing is engaging in a little bit of psychological manipulation.  Like sky marshals, the real benefit of behavior detection isn't whether or not you do it but whether or not the bad guys <i>believe</i> you're doing it.  If they think you are doing behavior detection at security checkpoints, or have sky marshals on every airplane, then you don't actually have to do it.  It's the threat that's the deterrent, not the actual security system.</p>

<p>This doesn't impress me, either:</p>

<blockquote>Items carried on the person, be they a 'beer belly' or concealed objects in very private areas, are why we are buying over 100 whole body imagers in upcoming months and will deploy more over time. In the meantime, we use hand-held devices that detect hydrogen peroxide and other explosives compounds as well as targeted pat-downs that require private screening.</blockquote>

<p>Optional security measures don't work, because the bad guys will opt not to use them.  It's like those air-puff machines at some airports now.  They're probably great at detecting explosive residue off clothing, but every time I have seen the machines in operation, the passengers have the option whether to go through the lane with them or another lane.  What possible good is that?</p>

<p>The closest thing to a real response from Hawley is that the terrorists might get caught stealing credit cards.</p>

<blockquote>Using stolen credit cards and false documents as a way to get around watch-lists makes the point that forcing terrorists to use increasingly risky tactics has its own security value.</blockquote>

<p>He's right about that.  And, truth be told, that was my sloppiest answer during the original intervied.  Thinking about it afterwards, it's far more likely is that someone with a clean record and a legal credit card will buy the various plane tickets.</p>

<p>This is new:</p>

<blockquote>Boarding pass scanners and encryption are being tested in eight airports now and more will be coming.</blockquote>

<p>Ignoring for a moment that "eight airports" nonsense -- unless you do it at every airport, the bad guys will choose the airport where you don't do it to launch their attack -- this is an excellent idea.  The reason my attack works, the reason I can get through TSA checkpoints with a fake boarding pass, is that the TSA never confirms that the information on the boarding pass matches a legitimate reservation.  If all TSA checkpoints had boarding pass scanners that connected to the airlines' computers, this attack would not work.  (Interestingly enough, I noticed exactly this system at the Dublin airport earlier this month.)</p>

<blockquote>Stopping the ‘James Bond’ terrorist is truly a team effort and I whole-heartedly agree that the best way to stop those attacks is with intelligence and law enforcement working together.</blockquote>

<p>This isn't about "Stopping the 'James Bond' terrorist," it's about stopping terrorism.  And if all this focus on airports, even assuming it starts working, shifts the terrorists to other targets, we haven't gotten a whole lot of security for our money.</p>

<p>FYI:  I did a <a href="http://www.schneier.com/interview-hawley.html">long interview</a> with Kip Hawley last year. If you haven't read it, I strongly recommend you do.  I pressed him on these and many other points, and didn't get very good answers then, either.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=eD30M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=eD30M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Ih06M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Ih06M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 02:24:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/airport">airport</category>
      <category domain="http://securityratty.com/tag/effective security measures">effective security measures</category>
      <category domain="http://securityratty.com/tag/dublin airport">dublin airport</category>
      <category domain="http://securityratty.com/tag/airport security penetration">airport security penetration</category>
      <category domain="http://securityratty.com/tag/security checkpoints">security checkpoints</category>
      <category domain="http://securityratty.com/tag/kip hawley">kip hawley</category>
      <category domain="http://securityratty.com/tag/tsa">tsa</category>
      <category domain="http://securityratty.com/tag/tsa identifies">tsa identifies</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/kip_hawley_resp.html">Kip Hawley Responds to My Airport Security Antics</source>
    </item>
    <item>
      <title><![CDATA[Presentation on Application Logging, Done Wrong or Very Wrong :-)]]></title>
      <link>http://securityratty.com/article/64c60e0fd4df7a290c1a9b95390af78d</link>
      <guid>http://securityratty.com/article/64c60e0fd4df7a290c1a9b95390af78d</guid>
      <description><![CDATA[A final &quot;automated&quot; post, while I am on a plane back to California. This is a result of my work on defining what is a good log, based on looking at countless bad logs

This presentation &quot; Application...]]></description>
      <content:encoded><![CDATA[A final "automated" post, while I am on a plane back to California. This is a result of my work on defining what is a good log, based on looking at countless bad logs :-)<br /><br />This presentation <span style="text-decoration: underline;">"</span><a href="http://www.slideshare.net/anton_chuvakin/application-logging-good-bad-ugly-beautiful-presentation">Application Logging Good Bad Ugly ... Beautiful?</a>" would be useful to application developers who create logging functionality as well as security pros who then need to use the logs.<br /><br />Here it is, embedded below:<br /><br /><div style="width:425px;text-align:left" id="__ss_647422"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/application-logging-good-bad-ugly-beautiful-presentation?type=powerpoint" title="Application Logging Good Bad Ugly ... Beautiful?">Application Logging Good Bad Ugly ... Beautiful?</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=applicationlogginggoodbaduglymay2008rel-1223571758617993-9&stripped_title=application-logging-good-bad-ugly-beautiful-presentation" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=applicationlogginggoodbaduglymay2008rel-1223571758617993-9&stripped_title=application-logging-good-bad-ugly-beautiful-presentation" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View SlideShare <a style="text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/application-logging-good-bad-ugly-beautiful-presentation?type=powerpoint" title="View Application Logging Good Bad Ugly ... Beautiful? on SlideShare">presentation</a> or <a style="text-decoration:underline;" href="http://www.slideshare.net/upload?type=powerpoint">Upload</a> your own. (tags: <a style="text-decoration:underline;" href="http://slideshare.net/tag/logs">logs</a> <a style="text-decoration:underline;" href="http://slideshare.net/tag/logging">logging</a>)</div></div><br /><br /><br />Enjoy!<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=qaZcM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=qaZcM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=EHOqM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=EHOqM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=oc8SM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=oc8SM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/423694840" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 01:55:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/countless bad logs">countless bad logs</category>
      <category domain="http://securityratty.com/tag/bad ugly">bad ugly</category>
      <category domain="http://securityratty.com/tag/application developers">application developers</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/security pros">security pros</category>
      <category domain="http://securityratty.com/tag/beautiful">beautiful</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/423694840/presentation-on-application-logging.html">Presentation on Application Logging, Done Wrong or Very Wrong :-)</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #83: SIP and Asterisk vulnerabilities, voice biometrics, P2PSIP, Aircell blocking Skype, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/3a845f6538a2b485677d7771f5d125ce</link>
      <guid>http://securityratty.com/article/3a845f6538a2b485677d7771f5d125ce</guid>
      <description><![CDATA[Synopsis: Blue Box #83: SIP and Asterisk vulnerabilities, voice biometrics, P2PSIP , Aircell blocking Skype, VoIP security news and more
Welcome to Blue Box: The VoIP Security Podcast #83, a 39-minute...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #83: <span class="caps">SIP</span> and Asterisk vulnerabilities, voice biometrics, <span class="caps">P2PSIP</span>, Aircell blocking Skype, VoIP security news and more…</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #83, a 39-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-083-2008-09-04.mp3">Download the show here</a> (MP3, 18MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was recorded on September 4, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-083-2008-09-04.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-083-2008-09-04.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 


	<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Three-year anniversary of Blue Box coming up on October 24th - any thoughts you'd like to share with us? (Please send them to us by October 23rd.)</li>
		
	</ul>
</li>

<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-July/002702.html">Remote DoS in reSIProcate</a></li>

<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-July/002699.html">Remote root shell in Trixbox</a></li>

<li><a href="http://voipsa.org/blog/2008/06/25/avaya-cisco-and-nortel-voip-security-vulnerabilities-to-be-announced-today/">Second route of VoIPShield Cisco/Avaya/Nortel vulnerabilities</a></li>

<li><a href="http://voipsa.org/blog/2008/07/22/two-new-asterisk-security-advisories/">AST-2008-010 – <span class="caps">IAX2 </span>‘POKE’ Resource Exhaustion</a></li>

<li><a href="http://voipsa.org/blog/2008/07/22/two-new-asterisk-security-advisories/">AST-2008-011 – <span class="caps">IAX2 </span>Firmware Provisioning System</a></li>

<li>Saunderslog: <a href="http://saunderslog.com/2008/07/14/squawkbox-july-10-2008-voice-biometrics-and-voiceverifiedcom/">Squawk Box – July 10, 2008: Voice biometrics and VoiceVerified.com</a></li>

<li>Saunderslog: <a href="http://saunderslog.com/2008/07/09/squawkbox-july-9-2008-p2psip-guest-david-bryan/">Squawk Box – July 9, 2008: <span class="caps">P2PSIP</span></a></li>

<li><span class="caps">IETF</span>: <a href="http://www.ietf.org/internet-drafts/draft-matuszewski-p2psip-security-requirements-03.txt">P2PSIP Security Requirements</a></li>

<li>Voice of <span class="caps">VOIPSA</span>: “Aircell blocking VoIP on a plane” – <a href="http://voipsa.org/blog/2008/08/26/how-aircell-is-probably-blocking-voip-phone-calls-on-planes-hint-voip-whack-a-mole/">part 1</a> , <a href="http://voipsa.org/blog/2008/08/26/the-reason-why-probably-you-can-use-phweet-on-a-plane-when-skype-is-blocked/">part 2</a> and an <a href="http://voipsa.org/blog/2008/08/28/update-on-the-aircell-voip-on-a-plane-prohibition-and-an-aircell-response/">update</a></li>

<li>Voice of <span class="caps">VOIPSA</span>: Shawn Merdinger’s series on “Asking The Cisco <span class="caps">IPICS </span>Expert” – Questions <a href="http://voipsa.org/blog/2008/07/17/asking-the-cisco-systems-ipics-expert-questions-1-5/">1-5</a> – <a href="http://voipsa.org/blog/2008/07/23/asking-the-cisco-systems-ipics-expert-questions-6-10/">6-10</a> – <a href="http://voipsa.org/blog/2008/08/02/asking-the-cisco-systems-ipics-expert-questions-11-15/">11-15</a> – <a href="http://voipsa.org/blog/2008/08/18/asking-the-cisco-systems-ipics-expert-questions-16-20/">16-20</a> – <a href="http://voipsa.org/blog/2008/09/02/asking-the-cisco-systems-ipics-expert-questions-21-25/">21-25</a></li>

<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/07/23/asterisk-hack-to-show-blocked-caller-id-points-to-larger-trust-issues-with-sip/">Asterisk ‘hack’ to show blocked Caller-ID points to larger trust issues with <span class="caps">SIP</span></a> (and SpeechTEK speech)</li>

<li>NetworkWorld: <a href="http://www.networkworld.com/news/2008/072908-georgia-student-arrested-for-hacking.html">Georgia student arrested for hacking grades, VoIP</a></li>

<li><span class="caps">CRN</span>: <a href="http://www.crn.com/security/209900949">Analysis: Hacking VoIP as easy as 1-2-3</a></li>

<li><a href="http://voipsa.org/blog/2008/07/16/ari-takanen-starts-blogging-at-itworld/">Ari Takanen starts blogging at InfoWorld</a></li>

<li>InfoWorld: <a href="http://www.itworld.com/security/54688/there-motivation-voip-fuzzing" class="Is There"> Motivation for VoIP Fuzzing</a></li>

<li>TMCnet: How to keep your tech career afloat</li>

<li>New analyst report: <a href="http://www.sunherald.com/prnewswire/story/687245.html">Security Threats Loom Over Unified Communications</a> pointing to <a href="http://www.lightreading.com/entvoip/details.asp?sku_id=2230&amp;skuitem_itemid=1113&amp;promo_code=&amp;aff_code=&amp;next_url=%2Fentvoip%2Flist.asp%3Fpage_type%3Drecent_reports">Light Reading report</a> and <a href="http://www.lightreading.com/entvoip/document.asp?doc_id=159146">article</a></li>

<li><a href="http://www.callcentre.co.uk/c/portal/layout?p_l_id=259723&amp;CMPI_SHARED_articleId=551057&amp;CMPI_SHARED_CommentArticleId=551057&amp;CMPI_SHARED_ImageArticleId=551057&amp;CMPI_SHARED_ToolsArticleId=551057&amp;CMPI_SHARED_articleIdRelated=551057&amp;articleTitle=VoIP%20companies%20to%20fight%20for%20market%20share">VoIP Companies to Fight For Market Share</a></li>

<li><a href="http://www.thetechherald.com/article.php/200836/1907/IEEE-approves-802-11r-roaming-Wi-Fi-standard">IEEE approves 802.11r standard</a></li>

<li>Google Chrome – upgrading the web to be application-centric</li>

<li>Items on my <a href="http://www.disruptivetelephony.com/">DisruptiveTelephony</a> blog… Skype 5th birthday, Asterisk future, Digium/Nortel</li>

<li>No comments this week.<br />
</li>

<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list<br />
</li>

<li>Wrap-up of the show<br />
</li>

<li>39:08 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=0LabzA"><img src="http://feeds.feedburner.com/~a/BlueBox?i=0LabzA" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=uRYdM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=uRYdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=urdIM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=urdIM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=OnnxM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=OnnxM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=g0lNM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=g0lNM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=sWBIm"><img src="http://feeds.feedburner.com/~f/BlueBox?i=sWBIm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=77UtM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=77UtM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/422759142" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 06:48:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip companies">voip companies</category>
      <category domain="http://securityratty.com/tag/voice biometrics">voice biometrics</category>
      <category domain="http://securityratty.com/tag/voice">voice</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/p2psip">p2psip</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/422759142/blue-box-83-sip.html">Blue Box #83: SIP and Asterisk vulnerabilities, voice biometrics, P2PSIP, Aircell blocking Skype, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[A Few Fun Bits, While I Am Preparing for My Speech at SANS]]></title>
      <link>http://securityratty.com/article/95afa537556e21e9766eb67ee13152a8</link>
      <guid>http://securityratty.com/article/95afa537556e21e9766eb67ee13152a8</guid>
      <description><![CDATA[A few more things, that qualify as fun reads, with - hopefully just as fun! - comments

Love, love, love this piece :-) Remember the &quot;robotic gun rampage&quot; stories from last year? How does this sound:...]]></description>
      <content:encoded><![CDATA[A few more things, that qualify as fun reads, with - hopefully just as fun! - comments.<br /><ul><li>Love, love, love <a href="http://www.defensetech.org/archives/004449.html">this piece</a> :-) Remember the <a href="http://chuvakin.blogspot.com/search/label/warfare">"robotic gun rampage" stories</a> from last year? How does this sound: "The gun can track 360 degress, but there is <span style="font-weight: bold;">a software-driven safety zone that makes sure rounds don't blow the rotors off.</span> If the Osprey has to maneuver away from the target and the crew chief can't hold the gun on the bad guys manually, the system slaves the gun to the point of the last shot, slewing it as the plane moves." (watch the fun video there too)<br /></li><li>"Security idiot" meme lives on - go <a href="http://duckdown.blogspot.com/2008/09/are-you-it-security-idiot.html">here</a>. BTW, the post is a follow-up to <a href="http://duckdown.blogspot.com/2008/09/how-many-fingers-are-required-to-count.html">this </a></li><li><a href="http://www.securitybalance.com/2008/09/which-compliance-pill-to-take/">A fun follow-up</a> to my post on compliance approaches titled <a href="http://chuvakin.blogspot.com/2008/09/is-pci-dss-prescriptive.html">Is PCI DSS "Too Prescriptive"?</a> </li><li>Finally, my fave post: "<a href="http://www.cutawaysecurity.com/blog/archives/342" rel="bookmark" title="Permanent Link: Increase Your Logging">Increase Your Logging</a>." I am sooooo happy that logging evangelism is spreading  far and wide! A quote from<a href="http://www.cutawaysecurity.com/blog/archives/342"> the paper</a>: ”<em>Logs are interesting, logs are fun, logs should be done by EVERYONE…..get to logging!!!</em>” (I promise that specific case was not my quote, even though I do say that very thing all the time!)<br /></li></ul>Enjoy! Time for me to run and do my preso ... about logs of course!<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=dEUWM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=dEUWM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Jdl7M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Jdl7M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=7k1zM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=7k1zM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/410521073" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 08:04:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/fun video">fun video</category>
      <category domain="http://securityratty.com/tag/fun follow-up">fun follow-up</category>
      <category domain="http://securityratty.com/tag/follow-up">follow-up</category>
      <category domain="http://securityratty.com/tag/gun">gun</category>
      <category domain="http://securityratty.com/tag/robotic gun rampage">robotic gun rampage</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/fun reads">fun reads</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/410521073/few-fun-bits-while-i-am-preparing-for.html">A Few Fun Bits, While I Am Preparing for My Speech at SANS</source>
    </item>
    <item>
      <title><![CDATA[TSA Employees Bypassing Airport Screening]]></title>
      <link>http://securityratty.com/article/435eb222ac241cb24d5a29dc4c967df3</link>
      <guid>http://securityratty.com/article/435eb222ac241cb24d5a29dc4c967df3</guid>
      <description><![CDATA[Airport screeners are now able to bypass airport screening : The Transportation Security Administration (TSA) rolled out the new uniforms and new screening policy at airports nationwide on Sept. 11...]]></description>
      <content:encoded><![CDATA[<p>Airport screeners are now able to <a href="http://www.9news.com/news/article.aspx?storyid=99941&catid=339">bypass airport screening<a>:</p>

<blockquote>The Transportation Security Administration (TSA) rolled out the new uniforms and new screening policy at airports nationwide on Sept. 11. 

<p>The new policy says screeners can arrive for work and walk behind security lines without any of their belongings examined or X-rayed. </p>

<p>"Lunch or a bomb, you can walk right through with it," said Mike Boyd, an aviation consultant in Evergreen. "This is a major security issue."</blockquote></p>

<p>Actually, it's not.  Screeners have to go in and out of security all the time as they work.  Yes, they can smuggle things in and out of the airport.  But you have to remember that the airport screeners are trusted insiders for the system: there are a zillion ways they could break airport security.</p>

<p>On the other hand, it's probably a smart idea to screen screeners when they walk through airport security when they aren't working at that checkpoint at that time.  The reason is the same reason <a href="http://www.schneier.com/essay-130.html">you should screen everyone<a>, including pilots who can crash their plane: you're not screening screeners (or pilots), you're screening people wearing screener (or pilot) uniforms and carrying screener (or pilot) IDs.  You can either train your screeners to recognize authentic uniforms and IDs, or you can just screen everybody.  The latter is just easier.</p>

<p>But this isn't a big deal.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qKcBL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qKcBL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=TjBOL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=TjBOL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 04:01:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/airport">airport</category>
      <category domain="http://securityratty.com/tag/bypass airport">bypass airport</category>
      <category domain="http://securityratty.com/tag/airport security">airport security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/transportation security administration">transportation security administration</category>
      <category domain="http://securityratty.com/tag/airport screeners">airport screeners</category>
      <category domain="http://securityratty.com/tag/security lines">security lines</category>
      <category domain="http://securityratty.com/tag/screeners">screeners</category>
      <category domain="http://securityratty.com/tag/major security issue">major security issue</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/tsa_employees_b.html">TSA Employees Bypassing Airport Screening</source>
    </item>
    <item>
      <title><![CDATA[Sorry, Qantas, No Unfettered Broadband]]></title>
      <link>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</link>
      <guid>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</guid>
      <description><![CDATA[Qantas backs off from earlier plans, changes provider for in-flight broadband: The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://www.smh.com.au/news/travel/qantas-limits-access-to-web/2008/09/17/1221330929870.html"><strong>Qantas backs off from earlier plans, changes provider for in-flight broadband:</strong></a> The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its in-flight broadband plans. Aeromobile was the provider when the service <a href="http://www.breakingtravelnews.com/article.php?story=2007081609481129&query=qantas"><strong>was tested in second quarter 2007</strong></a>, but OnAir is now described as the airline's partner. This was noted by colleague Fabio Zambelli, who emailed me the news, and <a href="http://www.setteb.it/content/view/4742"><strong>has his own account</strong></a> at 7BIT (in Italian).</p>

<p><a href="http://www.onair.aero/index.php?pid=123"><strong>OnAir</strong></a> has so far tested their calling/texting-only service on two aircraft--one operated by Air France, one by TAP Portugal--even though RyanAir announced plans that its planes would started being unwired with the service by late 2007. Still no word on that fleet progress.</p>

<p>Qantas will apparently launch cached Web browsing and limited Web email (probably through a proxy) along with instant messaging, with full Internet service coming "later in 2009." This is clearly due to a lack of satellite coverage that was just remediated a few weeks ago (see below). The first plane with limited service, a new A380, should be in flight 20-October-2008.</p>

<div style="float:right; margin:0px; padding-left: 10px; padding-bottom: 0px;"><p><img src="http://wifinetnews.com//images/2008/SorryQantas.jpg" alt="SorryQantas.jpg" border="0" width="100" height="152"></p><p style="font-size: 10px">I hate in-flight<br/>broadband</p></div>To Qantas' credit, note that each seat on the plane will have a laptop opower socket, a USB port, and a multimedia system that can show 100 movies and 500 TV show episodes, play the contents of 1,000 CDs and 20 radio stations, and offer 80 games. 

<p>The Morning Herald seems to overstate the importance and scope of a complaint filed by the union representing American Airlines' flight attendants. The detailed coverage in the U.S. had more to do with the potential for issues, and likely attendants lack of interest in policing yet another media on the plane. Filtering doesn't work, the attendants probably already know, and this may just be a negotiating point with the airline.</p>

<p>On why Qantas is waiting until late 2009? This requires unwinding how OnAir gets its signal.</p>

<p>Aeromobile and OnAir both rely on Inmarsat satellites for their service. Both companies had several years ago staked their futures on the fourth-generation network Inmarsat was to inaugurate with three satellites that would use beamforming to allow precise delivery of nearly 500 Kbps per receiver, with hundreds or thousands of regions being able to be targeted from a single satellite. Inmarsat's third-gen network--don't confuse this with 3G cellular ground-based networks--can deliver about 64 Kbps per channel.</p>

<p>Now, unfortunately, Inmarsat was three years late on launching its trans-Pacific bird. While the company <a href="http://www.inmarsat.com/About/Newsroom/Press/00021465.aspx?language=EN&textonly=False"><strong>claims 85 percent coverage of the earth</strong></a> and 98 percent coverage of population, there's a big gap over the Pacific that also prevents them from having good overlap between the U.S. and Japan/China/Korea, as well as the southern Pacific, covering Australia. Since the biggest market for long-haul flights would likely be Australia, Japan, and China, traveling trans-Pacific or trans-hemispheric routes, that gap is rather large.</p>

<p>Aeromobile opted to build out a service, deployed only by Emirates airline as far as I can tell, that uses the 3G service since it was available, and most necessary equipment is already installed on most over-water planes. OnAir was waiting for 4G, which has necessitated a long wait, but allowed them to launch in Europe with a seemingly next-generation service. Given that OnAir is controlled by an airline-owned integration firm, SITA, and by Airbus, they're not going anywhere.</p>

<p>Inmarsat finally <a href="http://spaceflightnow.com/proton/i4f3/"><strong>lofted its third satellite on Baikonur Cosmodrome in Kazakhstan</strong></a> on 19-August-2008, and the launch and separation was reported as successful. Previously, the company has needed up to a year to verify and deploy its 4G satellites. (You can <a href="http://forum.nasaspaceflight.com/index.php?topic=12380.105"><strong>read extremely close coverage of the launch</strong></a> at a Web site devoted to space enthusiasm.)</p>

<p>However, the dirty little secret about Inmarsat's BGAN is that it costs a fortune to heft bandwidth across it. Thus, in-flight broadband over BGAN, if it's ever available, is going to be changed on an extremely high per-MB rate. None of the providers want to say this. This is in contrast to Row 44 (and, once, Connexion by Boeing), which relies on leased Ku-band transponders where they can fix costs and they require high volumes to keep per-bit costs efffectively low.</p>

<p>OnAir's launch of calling on Air France's service involves paying a few euros per minute for calls, which might help you understand what data costs could ultimately run.</p>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 06:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/satellite coverage">satellite coverage</category>
      <category domain="http://securityratty.com/tag/coverage">coverage</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service involves">service involves</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/in-flight broadband plans">in-flight broadband plans</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/inmarsat satellites">inmarsat satellites</category>
      <category domain="http://securityratty.com/tag/inmarsat">inmarsat</category>
      <source url="http://wifinetnews.com/archives/008448.html">Sorry, Qantas, No Unfettered Broadband</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Share Cell Connections over Wi-Fi; Mile High-Fi Salaciousness; Giga-Fi; and More]]></title>
      <link>http://securityratty.com/article/457365225a8b72096232f2b375549cff</link>
      <guid>http://securityratty.com/article/457365225a8b72096232f2b375549cff</guid>
      <description><![CDATA[New version of Windows Mobile software to share cell data connections over Wi-Fi: Morose Media ships version 1.20 of WMWifiRouter, a Windows Mobile 5 and 6 application that routes cellular data...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.wmwifirouter.com/"><strong>New version of Windows Mobile software to share cell data connections over Wi-Fi:</strong></a> Morose Media ships version 1.20 of WMWifiRouter, a Windows Mobile 5 and 6 application that routes cellular data connections over Wi-Fi, turning your phone into a micro-hotspot. The software can also share a cell connection via Bluetooth or USB. The software costs $30 or &euro;20, and requires Internet (Connection) Sharing (ICS), which some providers may have removed from your phone. (The company set the price at US$30 before the euro drop, so is offering a kind of discount over their real &euro;20 price for the moment.)</p>

<p><a href="http://www.nytimes.com/2008/09/11/technology/personaltech/11smart.html?_r=1&8cir&emc=cirb1&oref=slogin"><strong>The New York Times rounds up using cell phones as hotspots:</strong></a> Though the reporter, Bob Tedeschi, mentions the issue of having to have an unlimited data plan to avoid unpleasant charges, and worries about bad drains and malicious users, he doesn't note that many carriers don't allow this kind of sharing or routing without a separate "tethering" plan, that can run $20 or more per month. Also, U.S. carriers have now all imposed a 5 GB per month reasonable use cap; some will cut you off, some charge you more, some cancel your service based on exceeding this use.</p>

<p><a href="http://www.networkworld.com/news/2008/090908-ieee-considers-gigabit.html?hpg1=bn"><strong>Gigabit Wi-Fi? Someday:</strong></a> TechWorld considers the IEEE's Very High Throughput (VHT) study group, which wants to start work on 1 Gbps or faster Wi-Fi standard for completion in 2012. With 802.11n offering raw symbol rates up to 600 Mbps--even though no devices have shipped with the radios and antennas to offer that optional high speed yet--there's interest in other frequencies that would allow faster encodings, as well as aggregating multiple links to achieve high speed rates. My experience in testing and using 2.4 GHz with Draft N would show that wide or aggregated channels doesn't work very well. The article's writer, Peter Judge, notes that ultrawideband had potential (over short distances) to approach the gigabit mark, but that UWB hasn't really reached the market in any substantive way years after it was promised to be a big technology.</p>

<p><a href="http://www.nbc5i.com/news/17435300/detail.html"><strong>Flight attendants express concerns about in-flight broadband porn:</strong></a> When I've spoken to airlines, industry experts, and service providers, I find that they all have stories about how porn is viewed on computers, through DVD players, and in convenient magazine form on planes today. Adding the Internet may provide new salacious imagery, but the problem predates Internet access, and filtering Internet service is never as good a solution as a social one. Someone idiotic enough to view porn on a plane over the Internet is also stupid enough to bring along inappropriate DVDs they watch while seated next to children. Flight attendants already have the power vested in them to take care of this. The flight attendants for American might be expressing this concern as part of a bargaining issue, where their responsibilities but not commensurate pay have increased.</p>

<p><a href="http://www.kxly.com/Global/story.asp?S=8989329"><strong>Spokane ends free Wi-Fi:</strong></a> Remember Vivato? Boy, I sure do. A company with a reach far exceeding its grasp, Vivato initially powered Spokane's downtown network. The network has continued to run on some basis--I'm not sure using what equipment--and now will move from free to fee. OneEighty Networks will charge about $10 per month to cover the costs of the network, for which local businesses at one point chipped in.</p>

<p><a href="http://www.onair.aero/"><strong>Brazilian TAM airline signs up for in-flight calling, messaging:</strong></a> OnAir has signed up the Brazilian carrier TAM, which will deploy the service on its Airbus A320 craft. Brazil hasn't yet provided regulatory approval, so no launch date is noted. TAM is the largest domestic and international carrier for Brazil.</p>]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 07:02:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/faster wi-fi standard">faster wi-fi standard</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/internet access">internet access</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/software costs">software costs</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <source url="http://wifinetnews.com/archives/008436.html">Wee-Fi: Share Cell Connections over Wi-Fi; Mile High-Fi Salaciousness; Giga-Fi; and More</source>
    </item>
    <item>
      <title><![CDATA[My LA Times Op Ed on Photo ID Checks at Airport]]></title>
      <link>http://securityratty.com/article/a6c4e0b6a9a71f79c2c06446ffd85b8a</link>
      <guid>http://securityratty.com/article/a6c4e0b6a9a71f79c2c06446ffd85b8a</guid>
      <description><![CDATA[Opinion
The TSA's useless photo ID rules
No-fly lists and photo IDs are supposed to help protect the flying public from terrorists. Except that they don't work
By Bruce Schneier
August 28, 2008
The...]]></description>
      <content:encoded><![CDATA[<p>Opinion</p>

<p><a href="http://www.latimes.com/news/opinion/la-oe-schneier28-2008aug28,0,3099808.story">The TSA's useless photo ID rules</a></p>

<p>No-fly lists and photo IDs are supposed to help protect the flying public from terrorists. Except that they don't work.</p>

<p>By Bruce Schneier </p>

<p>August 28, 2008</p>

<p>The TSA is tightening its photo ID rules at airport security. Previously, people with expired IDs or who claimed to have lost their IDs were subjected to secondary screening. Then the Transportation Security Administration realized that meant someone on the government's no-fly list -- the list that is supposed to keep our planes safe from terrorists -- could just fly with no ID. </p>

<p>Now, people without ID must also answer personal questions from their credit history to ascertain their identity. The TSA will keep records of who those ID-less people are, too, in case they're trying to probe the system.</p>

<p>This may seem like an improvement, except that the photo ID requirement is a joke. Anyone on the no-fly list can easily fly whenever he wants. Even worse, the whole concept of matching passenger names against a list of bad guys has negligible security value.</p>

<p>How to fly, even if you are on the no-fly list: Buy a ticket in some innocent person's name. At home, before your flight, check in online and print out your boarding pass. Then, save that web page as a PDF and use Adobe Acrobat to change the name on the boarding pass to your own. Print it again. At the airport, use the fake boarding pass and your valid ID to get through security. At the gate, use the real boarding pass in the fake name to board your flight.</p>

<p>The problem is that it is unverified passenger names that get checked against the no-fly list. At security checkpoints, the TSA just matches IDs to whatever is printed on the boarding passes. The airline checks boarding passes against tickets when people board the plane. But because no one checks ticketed names against IDs, the security breaks down.</p>

<p>This vulnerability isn't new. It isn't even subtle. I first wrote about it in 2006. I asked Kip Hawley, who runs the TSA, about it in 2007. Today, any terrorist smart enough to Google "print your own boarding pass" can bypass the no-fly list.</p>

<p>This gaping security hole would bother me more if the very idea of a no-fly list weren't so ineffective. The system is based on the faulty notion that the feds have this master list of terrorists, and all we have to do is keep the people on the list off the planes. </p>

<p>That's just not true. The no-fly list -- a list of people so dangerous they are not allowed to fly yet so innocent we can't arrest them -- and the less dangerous "watch list" contain a combined 1 million names representing the identities and aliases of an estimated 400,000 people. There aren't that many terrorists out there; if there were, we would be feeling their effects. </p>

<p>Almost all of the people stopped by the no-fly list are false positives. It catches innocents such as Ted Kennedy, whose name is similar to someone's on the list, and Islam Yusuf (formerly Cat Stevens), who was on the list but no one knew why.</p>

<p>The no-fly list is a Kafkaesque nightmare for the thousands of innocent Americans who are harassed and detained every time they fly. Put on the list by unidentified government officials, they can't get off. They can't challenge the TSA about their status or prove their innocence. (The U.S. 9th Circuit Court of Appeals decided this month that no-fly passengers can sue the FBI, but that strategy hasn't been tried yet.) </p>

<p>But even if these lists were complete and accurate, they wouldn't work. Timothy McVeigh, the Unabomber, the D.C. snipers, the London subway bombers and most of the 9/11 terrorists weren't on any list before they committed their terrorist acts. And if a terrorist wants to know if he's on a list, the TSA has approved a convenient, $100 service that allows him to figure it out: the Clear program, which issues IDs to "trusted travelers" to speed them through security lines. Just apply for a Clear card; if you get one, you're not on the list.</p>

<p>In the end, the photo ID requirement is based on the myth that we can somehow correlate identity with intent. We can't. And instead of wasting money trying, we would be far safer as a nation if we invested in intelligence, investigation and emergency response -- security measures that aren't based on a guess about a terrorist target or tactic.</p>

<p>That's the TSA: Not doing the right things. Not even doing right the things it does.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=0Nd83L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=0Nd83L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Uz4JRL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Uz4JRL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 01:15:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/no-fly list">no-fly list</category>
      <category domain="http://securityratty.com/tag/airport">airport</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security hole">security hole</category>
      <category domain="http://securityratty.com/tag/transportation security administration">transportation security administration</category>
      <category domain="http://securityratty.com/tag/photo">photo</category>
      <category domain="http://securityratty.com/tag/ids">ids</category>
      <category domain="http://securityratty.com/tag/matches ids">matches ids</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/my_la_times_op.html">My LA Times Op Ed on Photo ID Checks at Airport</source>
    </item>
    <item>
      <title><![CDATA[The TSA Told You That Liquids Are Dangerous]]></title>
      <link>http://securityratty.com/article/1f7d3372e8bdb16a7b2823651bbe6350</link>
      <guid>http://securityratty.com/article/1f7d3372e8bdb16a7b2823651bbe6350</guid>
      <description><![CDATA[So weird : A plane was forced to land when a passenger had an extreme allergic reaction to a leaking jar of mushroom soup, it was revealed today
The soup fell on the man from an overhead locker on a...]]></description>
      <content:encoded><![CDATA[<p>So <a href="http://www.examiner.ie/breaking/ireland/mhqlojkfidql/">weird</a>:</p>

<blockquote>A plane was forced to land when a passenger had an extreme allergic reaction to a leaking jar of mushroom soup, it was revealed today.

<p>The soup fell on the man from an overhead locker on a Ryanair flight to Dublin from Budapest.</p>

<p>He reportedly suffered allergic swelling in his neck and struggled to breathe, forcing staff to seek emergency medical treatment.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=95xjGK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=95xjGK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=J8p2FK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=J8p2FK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 08:25:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/allergic">allergic</category>
      <category domain="http://securityratty.com/tag/extreme allergic reaction">extreme allergic reaction</category>
      <category domain="http://securityratty.com/tag/mushroom soup">mushroom soup</category>
      <category domain="http://securityratty.com/tag/soup">soup</category>
      <category domain="http://securityratty.com/tag/ryanair flight">ryanair flight</category>
      <category domain="http://securityratty.com/tag/overhead locker">overhead locker</category>
      <category domain="http://securityratty.com/tag/dublin">dublin</category>
      <category domain="http://securityratty.com/tag/neck">neck</category>
      <category domain="http://securityratty.com/tag/passenger">passenger</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/the_tsa_told_yo.html">The TSA Told You That Liquids Are Dangerous</source>
    </item>
  </channel>
</rss>
