<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: plot]]></title>
    <link>http://securityratty.com/tag/plot</link>
    <description></description>
    <pubDate>Thu, 18 Sep 2008 14:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Lessons from Mumbai]]></title>
      <link>http://securityratty.com/article/ca74a145bde98eb6902487f29715eaa3</link>
      <guid>http://securityratty.com/article/ca74a145bde98eb6902487f29715eaa3</guid>
      <description><![CDATA[I'm still reading about the Mumbai terrorist attacks, and I expect it'll be a long time before we get a lot of the details. What we know is horrific, and my sympathy goes out to the survivors of the...]]></description>
      <content:encoded><![CDATA[<p>I'm still reading about the Mumbai terrorist attacks, and I expect it'll be a long time before we get a lot of the details.  What we know is horrific, and my sympathy goes out to the survivors of the dead (and the injured, who often seem to get ignored as people focus on death tolls).  Without discounting the awfulness of the events, I have some initial observations:</p>

<ul><li>Low-tech is very effective.  <a href="http://www.schneier.com/essay-087.html">Movie-plot threats</a> -- terrorists with crop dusters, terrorists with biological agents, terrorists targeting our water supplies -- might be what people worry about, but a bunch of trained (we don't really know yet what sort of training they had, but it's clear that they <a href="http://www.news.com.au/couriermail/story/0,23739,24726093-954,00.html">had some</a>) men with guns and grenades is all they needed.

<p><li>At the same time, the attacks were surprisingly ineffective.  I can't find exact numbers, but it seems there were about 18 terrorists.  The latest toll is 195 dead, 235 wounded.  That's 11 dead, 13 wounded, per terrorist.  As horrible as the reality is, that's much less than you might have thought if you imagined the movie in your head.  Reality is <a href="http://www.pebbleandavalanche.com/weblog/2008/11/30/blog-20081130T1857">different</a> from the movies.</p>

<p><li>Even so, terrorism is rare.  If a bunch of men with guns and grenades is all they really need, then why isn't this sort of terrorism more common?  Why not in the U.S., where it's easy to get hold of weapons?  It's because terrorism is very, very rare.</p>

<p><li>Specific countermeasures don't help against these attacks.  None of the high-priced countermeasures that defend against specific tactics and specific targets made, or would have made, any difference: photo ID checks, confiscating liquids at airports, fingerprinting foreigners at the border, bag screening on public transportation, anything.  Even<a href="http://www.upi.com/Top_News/2008/11/29/Executive_says_Taj_hotel_warned_of_attack/UPI-97361228007685/">metal detectors and threat warnings</a> didn't do any good:</p>

<blockquote>"If I look at what we had, which all of us complained about, it could not have stopped what took place," he told CNN. "It's ironic that we did have such a warning, and we did have some measures."

<p>He said people were told to park away from the entrance and had to go through a metal detector. But he said the attackers came through a back entrance.</p>

<p>"They knew what they were doing, and they did not go through the front. All of our arrangements are in the front," he said.</blockquote></ul></p>

<p>If there's any lesson in these attacks, it's not to focus too much on the specifics of the attacks.  Of course, that's not the way we're programmed to think.  We <a href="http://www.schneier.com/essay-171.html">respond to stories</a> and not analysis.  I don't mean to be sympathetic; this tendency is human and these deaths are really tragic.  But eighteen armed people intent on killing lots of innocents will be able to do just that, and last-line-of-defense countermeasures won't be able to stop them.  Intelligence, investigation, and emergency response.  We have to find and stop the terrorists before they attack, and deal with the aftermath of the attacks we don't stop.  There really is no other way, and I hope that we don't let the tragedy lead us into unwise decisions about how to deal with terrorism.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=4dGOO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=4dGOO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qnl9O"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qnl9O" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 05:03:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mumbai terrorist attacks">mumbai terrorist attacks</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/armed people intent">armed people intent</category>
      <category domain="http://securityratty.com/tag/people focus">people focus</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/terrorist">terrorist</category>
      <source url="http://www.schneier.com/blog/archives/2008/12/lessons_from_mu.html">Lessons from Mumbai</source>
    </item>
    <item>
      <title><![CDATA[FBI Stoking Fear]]></title>
      <link>http://securityratty.com/article/42b3e4fb9c51c77ab790e583dada33f4</link>
      <guid>http://securityratty.com/article/42b3e4fb9c51c77ab790e583dada33f4</guid>
      <description><![CDATA[Another unsubstantiated terrorist plot: An internal memo obtained by The Associated Press says the FBI has received a &quot;plausible but unsubstantiated&quot; report that al-Qaida terrorists in late September...]]></description>
      <content:encoded><![CDATA[<p>Another <a href="http://www.google.com/hostednews/ap/article/ALeqM5j1NEBSpGCN1_9rZCXTwXBcnNXOxAD94MNT4O0">unsubstantiated</a> terrorist plot:</p>

<blockquote>An internal memo obtained by The Associated Press says the FBI has received a "plausible but unsubstantiated" report that al-Qaida terrorists in late September may have discussed attacking the subway system.

<p>[...]</p>

<p>The internal bulletin says al-Qaida terrorists "in late September may have discussed targeting transit systems in and around New York City. These discussions reportedly involved the use of suicide bombers or explosives placed on subway/passenger rail systems," according to the document.</p>

<p>"We have no specific details to confirm that this plot has developed beyond aspirational planning, but we are issuing this warning out of concern that such an attack could possibly be conducted during the forthcoming holiday season," according to the warning dated Tuesday.</p>

<p>[...]</p>

<p>Rep. Peter King, the top Republican on the House Homeland Security Committee, said authorities "have very real specifics as to who it is and where the conversation took place and who conducted it."</p>

<p>"It certainly involves suicide bombing attacks on the mass transit system in and around New York and it's plausible, but there's no evidence yet that it's in the process of being carried out," King said.</p>

<p>Knocke, the DHS spokesman, said the warning was issued "out of an abundance of caution going into this holiday season."</blockquote></p>

<p>Got that:  "plausible but unsubstantiated," "may have discussed attacking the subway system," "specific details to confirm that this plot has developed beyond aspirational planning," "attack could possibly be conducted," "it's plausible, but there's no evidence yet that it's in the process of being carried out."</p>

<p>I have no specific details, but I want to warn everybody today that fiery rain might fall from the sky.  Terrorists may have discussed this sort of tactic, and while there is no evidence yet that it's in the process of being carried out, I want to be extra-cautious this holiday season.  Ho ho ho.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=uxqxN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=uxqxN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=hww2N"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=hww2N" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 09:27:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/holiday season">holiday season</category>
      <category domain="http://securityratty.com/tag/specific details">specific details</category>
      <category domain="http://securityratty.com/tag/al-qaida terrorists">al-qaida terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorist plot">terrorist plot</category>
      <category domain="http://securityratty.com/tag/subway system">subway system</category>
      <category domain="http://securityratty.com/tag/plausible">plausible</category>
      <category domain="http://securityratty.com/tag/plot">plot</category>
      <category domain="http://securityratty.com/tag/mass transit system">mass transit system</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/fbi_stoking_fea.html">FBI Stoking Fear</source>
    </item>
    <item>
      <title><![CDATA[Express Scripts user? Sorry.]]></title>
      <link>http://securityratty.com/article/8043f7fcbe07519e37e714d538ec6762</link>
      <guid>http://securityratty.com/article/8043f7fcbe07519e37e714d538ec6762</guid>
      <description><![CDATA[Yeah, Ive used the service a couple of time in the last few years. Sigh


clipped from blog.wired.com

Extortion Plot Threatens to Divulge Millions of Patients Prescriptions


Express Scripts said it...]]></description>
      <content:encoded><![CDATA[<div > Yeah, Ive used the service a couple of time in the last few years. <br/>Sigh. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/81D25E91-1C5B-4EDA-9F08-B67D3299956D/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/c0489055-8fb4-4eb3-a5c9-19e74251870d/81D25E91-1C5B-4EDA-9F08-B67D3299956D/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://blog.wired.com/27bstroke6/2008/11/extortion-plot.html" href="http://blog.wired.com/27bstroke6/2008/11/extortion-plot.html" style="font-size: 11px;">blog.wired.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://blog.wired.com/27bstroke6/2008/11/extortion-plot.html -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Extortion Plot Threatens to Divulge Millions of Patients&#8217; Prescriptions</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://blog.wired.com/27bstroke6/2008/11/extortion-plot.html --><P>Express Scripts said it has received an anonymous letter containing the names of some 75 clients that includes dates of birth, Social Security numbers and their prescriptions. The letter threatens to expose millions of patient records if Express Scripts does not pay an undisclosed amount of money.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/81D25E91-1C5B-4EDA-9F08-B67D3299956D/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_071108045615"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=071108045615&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=071108045615&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=071108045615&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_071108045615" /></a></P>]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 13:56:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/express scripts">express scripts</category>
      <category domain="http://securityratty.com/tag/extortion plot threatens">extortion plot threatens</category>
      <category domain="http://securityratty.com/tag/patients prescriptions">patients prescriptions</category>
      <category domain="http://securityratty.com/tag/prescriptions">prescriptions</category>
      <category domain="http://securityratty.com/tag/letter threatens">letter threatens</category>
      <category domain="http://securityratty.com/tag/anonymous letter">anonymous letter</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <category domain="http://securityratty.com/tag/expose millions">expose millions</category>
      <category domain="http://securityratty.com/tag/patient records">patient records</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=650">Express Scripts user? Sorry.</source>
    </item>
    <item>
      <title><![CDATA[Extortion Plot Threatens to Divulge Millions of Patients' Prescriptions]]></title>
      <link>http://securityratty.com/article/7482fa30301d89232b266687bfedef5e</link>
      <guid>http://securityratty.com/article/7482fa30301d89232b266687bfedef5e</guid>
      <description><![CDATA[A St. Louis company managing medical prescriptions of 50 million people says it has alerted the FBI of an extortion plot threatening to divulge the names and prescriptions of millions of its clients....]]></description>
      <content:encoded><![CDATA[A St. Louis company managing medical prescriptions of 50 million people says it has alerted the FBI of an extortion plot threatening to divulge the names and prescriptions of millions of its clients. Express Scripts says it received a letter announcing the plot, which seeks an undisclosed amount of money.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=80367e4ddab655ec90ba4e34e26d8764" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=80367e4ddab655ec90ba4e34e26d8764" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=18dJN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=18dJN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=DaaCn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=DaaCn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Qny1n"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Qny1n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=cqhrN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=cqhrN" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=RykfN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=RykfN" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=WjRdn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=WjRdn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=frLjn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=frLjn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=XKk1N"><img src="http://feeds.wired.com/~f/wired/politics/security?i=XKk1N" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/444932343" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/444932475" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 20:48:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/extortion plot">extortion plot</category>
      <category domain="http://securityratty.com/tag/prescriptions">prescriptions</category>
      <category domain="http://securityratty.com/tag/plot">plot</category>
      <category domain="http://securityratty.com/tag/medical prescriptions">medical prescriptions</category>
      <category domain="http://securityratty.com/tag/express scripts">express scripts</category>
      <category domain="http://securityratty.com/tag/millions">millions</category>
      <category domain="http://securityratty.com/tag/divulge">divulge</category>
      <category domain="http://securityratty.com/tag/million people">million people</category>
      <category domain="http://securityratty.com/tag/louis company">louis company</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/444932475/extortion-plot.html">Extortion Plot Threatens to Divulge Millions of Patients' Prescriptions</source>
    </item>
    <item>
      <title><![CDATA[Minority Report]]></title>
      <link>http://securityratty.com/article/b2ccffc05871404466e1badba7c3d706</link>
      <guid>http://securityratty.com/article/b2ccffc05871404466e1badba7c3d706</guid>
      <description><![CDATA[In 1956 Philip K. Dick published a short story called Minority Report which was subsequently made into a moderately successful film starring Tom Cruise. If you saw the film or read the story you may...]]></description>
      <content:encoded><![CDATA[In 1956 Philip K. Dick published a short story called Minority Report which was subsequently made into a moderately successful film starring Tom Cruise. If you saw the film or read the story you may remember that the plot revolves around a system designed to predict crimes and then arresting people in advance for crimes which they hadn't yet committed. Chilling thought, that.]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/film">film</category>
      <category domain="http://securityratty.com/tag/minority report">minority report</category>
      <category domain="http://securityratty.com/tag/moderately successful film">moderately successful film</category>
      <category domain="http://securityratty.com/tag/short story">short story</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/crimes">crimes</category>
      <category domain="http://securityratty.com/tag/predict crimes">predict crimes</category>
      <category domain="http://securityratty.com/tag/tom cruise">tom cruise</category>
      <category domain="http://securityratty.com/tag/plot revolves">plot revolves</category>
      <source url="http://www.networkworld.com/news/2008/110408-minority.html?fsrc=rss-security">Minority Report</source>
    </item>
    <item>
      <title><![CDATA[Movie-Plot Threat: Terrorists Using Twitter]]></title>
      <link>http://securityratty.com/article/31ccaa1220f62cfe9008fd043b4179f8</link>
      <guid>http://securityratty.com/article/31ccaa1220f62cfe9008fd043b4179f8</guid>
      <description><![CDATA[No , really . ( Commentary here
This is just ridiculous. Of course the bad guys will use all the communications tools available to the rest of us. They have to communicate, after all. They'll also use...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.computerweekly.com/Articles/2008/10/28/232944/terrorists-could-use-twitter-for-attacks-says-us-intelligence.htm">No<a/>, <a href="http://www.fas.org/irp/eprint/mobile.pdf"> really</a>.  (<a href="http://www.fas.org/blog/secrecy/2008/10/twitter.html">Commentary</a> <a href="http://blog.wired.com/defense/2008/10/terrorist-cell.html">here</a>.)</p>

<p>This is just ridiculous.  Of course the bad guys will use all the communications tools available to the rest of us. They have to communicate, after all.  They'll also use cars, water faucets, and all-you-can-eat buffet lunches.  So what?</p>

<p>This commentary is dead on:</p>

<blockquote>Steven Aftergood, a veteran intelligence analyst at the Federation of the American Scientists, doesn't dismiss the Army presentation out of hand. But nor does he think it's tackling a terribly seriously threat. "Red-teaming exercises to anticipate adversary operations are fundamental. But they need to be informed by a sense of what's realistic and important and what's not," he tells Danger Room. "If we have time to worry about 'Twitter threats' then we're in good shape. I mean, it's important to keep some sense of proportion."</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=XrBFM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=XrBFM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=If9PM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=If9PM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 30 Oct 2008 04:51:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/veteran intelligence analyst">veteran intelligence analyst</category>
      <category domain="http://securityratty.com/tag/all-you-can-eat buffet lunches">all-you-can-eat buffet lunches</category>
      <category domain="http://securityratty.com/tag/bad guys">bad guys</category>
      <category domain="http://securityratty.com/tag/tells danger">tells danger</category>
      <category domain="http://securityratty.com/tag/commentary">commentary</category>
      <category domain="http://securityratty.com/tag/army presentation">army presentation</category>
      <category domain="http://securityratty.com/tag/adversary operations">adversary operations</category>
      <category domain="http://securityratty.com/tag/twitter threats">twitter threats</category>
      <category domain="http://securityratty.com/tag/water faucets">water faucets</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/movie-plot_thre_1.html">Movie-Plot Threat: Terrorists Using Twitter</source>
    </item>
    <item>
      <title><![CDATA[TSA News]]></title>
      <link>http://securityratty.com/article/5c821d386504d67e3a80de9f7e3c8408</link>
      <guid>http://securityratty.com/article/5c821d386504d67e3a80de9f7e3c8408</guid>
      <description><![CDATA[Item 1: Kip Hawley says that the TSA may reduce size restrictions on liquids. You'll still have to take them out of your bag, but they can be larger than three ounces. The reasons -- so he states --...]]></description>
      <content:encoded><![CDATA[<p>Item 1:  Kip Hawley <a href="http://www.tsa.gov/blog/2008/10/path-forward-on-liquids.html">says</a> that the TSA may reduce size restrictions on liquids.  You'll still have to take them out of your bag, but they can be larger than three ounces.  The reasons -- so he states -- are that technologies are getting better, not that the threat is reduced.</p>

<p>I'm skeptical, of course.  But read his post; it's interesting.</p>

<p>Item 2:  Hawley <a href="http://www.schneier.com/blog/archives/2008/10/kip_hawley_resp.html#c321445">responded</a> to my <a href="http://www.schneier.com/blog/archives/2008/10/kip_hawley_resp.html">response</a> to his <a href="http://www.tsa.gov/blog/2008/10/tsas-take-on-atlantic-article.html">blog post</a> about an <a href="http://www.theatlantic.com/doc/200811/airport-security/3">article about me</a> in <i>The Atlantic</i>.</p>

<p>Item 3: <i>The Atlantic</i> is holding a <a href="http://jeffreygoldberg.theatlantic.com/archives/2008/10/new_contest_can_you_outlame_th.php">contest</a>, based on Hawley's comment that the TSA is basically there to catch stupid terrorists:</p>

<blockquote>And so, a contest: How would the Hawley Principle of Federally-Endorsed Mediocrity apply to other government endeavors?</blockquote>

<p>Not the same as my <a href="http://www.schneier.com/blog/archives/2006/06/movieplot_threa_1.html">movie-plot threat contest</a>, but fun all the same.</p>

<p><br />
Item 4: What would the TSA make of <a href="http://www.boingboing.net/2008/10/24/chanel-gun-heel.html">this</a>?</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=RJc1M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=RJc1M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=q9CVM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=q9CVM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 11:27:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tsa">tsa</category>
      <category domain="http://securityratty.com/tag/hawley principle">hawley principle</category>
      <category domain="http://securityratty.com/tag/hawley">hawley</category>
      <category domain="http://securityratty.com/tag/item">item</category>
      <category domain="http://securityratty.com/tag/kip hawley">kip hawley</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/movie-plot threat">movie-plot threat</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/threat">threat</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/tsa_news.html">TSA News</source>
    </item>
    <item>
      <title><![CDATA[Terrorists and Child Porn, Oh My!]]></title>
      <link>http://securityratty.com/article/9aba933602066f28498b9028fb513efc</link>
      <guid>http://securityratty.com/article/9aba933602066f28498b9028fb513efc</guid>
      <description><![CDATA[It's the ultimate movie-plot threat: terrorists using child porn : It is thought Islamist extremists are concealing messages in digital images and audio, video or other files
Police are now...]]></description>
      <content:encoded><![CDATA[<p>It's the ultimate movie-plot threat: <a href="http://www.telegraph.co.uk/news/uknews/3215115/Terrorists-use-child-porn-to-exchange-information.html">terrorists</a> <a href="http://www.timesonline.co.uk/tol/news/uk/crime/article4959002.ece">using</a> <a href="http://www.foxnews.com/story/0,2933,439641,00.html">child porn</a>:</p>

<blockquote>It is thought Islamist extremists are concealing messages in digital images and audio, video or other files.

<p>Police are now investigating the link between terrorists and paedophilia in an attempt to unravel the system.</p>

<p>It could lead to the training of child welfare experts to identify signs of terrorist involvement as they monitor pornographic websites.</blockquote></p>

<p>Of course, terrorists and strangers preying on our children are two of the things that cause the most fear in people.  Put them together, and there's no limit to what sorts of laws you can get passed.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=NHbHM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=NHbHM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=i9l7M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=i9l7M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 22 Oct 2008 08:57:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/child porn">child porn</category>
      <category domain="http://securityratty.com/tag/child welfare experts">child welfare experts</category>
      <category domain="http://securityratty.com/tag/monitor pornographic websites">monitor pornographic websites</category>
      <category domain="http://securityratty.com/tag/islamist extremists">islamist extremists</category>
      <category domain="http://securityratty.com/tag/movie-plot threat">movie-plot threat</category>
      <category domain="http://securityratty.com/tag/digital images">digital images</category>
      <category domain="http://securityratty.com/tag/terrorist involvement">terrorist involvement</category>
      <category domain="http://securityratty.com/tag/signs">signs</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/terrorists_and_2.html">Terrorists and Child Porn, Oh My!</source>
    </item>
    <item>
      <title><![CDATA[The Two Classes of Airport Contraband]]></title>
      <link>http://securityratty.com/article/9add41f24cfea6a99d21547a04d8fdaf</link>
      <guid>http://securityratty.com/article/9add41f24cfea6a99d21547a04d8fdaf</guid>
      <description><![CDATA[Airport security found a jar of pasta sauce in my luggage last month. It was a 6-ounce jar, above the limit; the official confiscated it, because allowing it on the airplane with me would have been...]]></description>
      <content:encoded><![CDATA[<p>Airport security found a jar of pasta sauce in my luggage last month. It was a 6-ounce jar, above the limit; the official confiscated it, because allowing it on the airplane with me would have been too dangerous. And to demonstrate how dangerous he really thought that jar was, he blithely tossed it in a nearby bin of similar liquid bottles and sent me on my way.</p>

<p>There are two classes of contraband at airport security checkpoints: the class that will get you in trouble if you try to bring it on an airplane, and the class that will cheerily be taken away from you if you try to bring it on an airplane. This difference is important: Making security screeners confiscate anything from that second class is a waste of time. All it does is harm innocents; it doesn't stop terrorists at all.</p>

<p>Let me explain. If you're caught at airport security with a bomb or a gun, the screeners aren't just going to take it away from you. They're going to call the police, and you're going to be stuck for a few hours answering a lot of awkward questions. You may be arrested, and you'll almost certainly miss your flight. At best, you're going to have a very unpleasant day.</p>

<p>This is why articles about how screeners don't catch <a href="http://www.cnn.com/2008/US/01/28/tsa.bombtest/index.html">every</a> -- or even <a href="http://www.homelandstupidity.us/2007/10/25/tsa-screeners-fail-most-bomb-tests/">a</a> <a href="http://www.homelandstupidity.us/2006/10/31/tsa-screeners-still-fail-to-find-guns-bombs/">majority</a> -- of guns and bombs that <a href="http://www.boston.com/news/local/articles/2003/10/16/logan_screeners_fail_weapons_tests/">go through the checkpoints</a> don't bother me. The screeners don't have to be perfect; they just have to be good enough. No terrorist is going to base his plot on getting a gun through airport security if there's decent chance of getting caught, because the consequences of getting caught are too great.</p>

<p>Contrast that with a terrorist plot that requires a 12-ounce bottle of liquid. There's no evidence that the London liquid bombers actually had a workable plot, but assume for the moment they did. If some copycat terrorists try to bring their liquid bomb through airport security and the screeners catch them -- like they caught me with my bottle of pasta sauce -- the terrorists can simply try again. They can try again and again. They can keep trying until they succeed. Because there are no consequences to trying and failing, the screeners have to be 100 percent effective. Even if they slip up one in a hundred times, the plot can succeed.</p>

<p>The same is true for knitting needles, pocketknives, scissors, corkscrews, cigarette lighters and whatever else the airport screeners are confiscating this week. If there's no consequence to getting caught with it, then confiscating it only hurts innocent people. At best, it mildly annoys the terrorists.</p>

<p>To fix this, airport security has to make a choice. If something is dangerous, treat it as dangerous and treat anyone who tries to bring it on as potentially dangerous. If it's not dangerous, then stop trying to keep it off airplanes. Trying to have it both ways just distracts the screeners from actually making us safer.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=bB1FL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=bB1FL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Uc79L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Uc79L" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 01:47:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/airport security checkpoints">airport security checkpoints</category>
      <category domain="http://securityratty.com/tag/checkpoints">checkpoints</category>
      <category domain="http://securityratty.com/tag/airport security">airport security</category>
      <category domain="http://securityratty.com/tag/screeners">screeners</category>
      <category domain="http://securityratty.com/tag/security screeners">security screeners</category>
      <category domain="http://securityratty.com/tag/liquid">liquid</category>
      <category domain="http://securityratty.com/tag/london liquid bombers">london liquid bombers</category>
      <category domain="http://securityratty.com/tag/airport screeners">airport screeners</category>
      <category domain="http://securityratty.com/tag/plot">plot</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/the_two_classes.html">The Two Classes of Airport Contraband</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: Airport Pasta-Sauce Interdiction Considered Harmful]]></title>
      <link>http://securityratty.com/article/9b6db0f25f815641ea3655ef3cb29af5</link>
      <guid>http://securityratty.com/article/9b6db0f25f815641ea3655ef3cb29af5</guid>
      <description><![CDATA[Airport security found a jar of pasta sauce in my luggage last month. It was a 6-ounce jar, above the limit; the official confiscated it, because allowing it on the airplane with me would have been...]]></description>
      <content:encoded><![CDATA[<p>
Airport security found a jar of pasta sauce in my luggage last month. It was a 6-ounce jar, above the limit; the official confiscated it, because allowing it on the airplane with me would have been too dangerous. And to demonstrate how dangerous he really thought that jar was, he blithely tossed it in a nearby bin of similar liquid bottles and sent me on my way.
</p><p>
There are two classes of contraband at airport security checkpoints: the class that will get you in trouble if you try to bring it on an airplane, and the class that will cheerily be taken away from you if you try to bring it on an airplane. This difference is important: Making security screeners confiscate anything from that second class is a waste of time. All it does is harm innocents; it doesn't stop terrorists at all.
</p><p>
Let me explain. If you're caught at airport security with a bomb or a gun, the screeners aren't just going to take it away from you. They're going to call the police, and you're going to be stuck for a few hours answering a lot of awkward questions. You may be arrested, and you'll almost certainly miss your flight. At best, you're going to have a very unpleasant day.
</p><p>
This is why articles about how screeners don't catch <a href="http://www.cnn.com/2008/US/01/28/tsa.bombtest/index.html">every</a> -- or even <a href="http://www.homelandstupidity.us/2007/10/25/tsa-screeners-fail-most-bomb-tests/">a</a> <a href="http://www.homelandstupidity.us/2006/10/31/tsa-screeners-still-fail-to-find-guns-bombs/">majority</a> -- of guns and bombs that <a href="http://www.boston.com/news/local/articles/2003/10/16/logan_screeners_fail_weapons_tests/">go through the checkpoints</a> don't bother me. The screeners don't have to be perfect; they just have to be good enough. No terrorist is going to base his plot on getting a gun through airport security if there's decent chance of getting caught, because the consequences of getting caught are too great.
</p><p>
Contrast that with a terrorist plot that requires a 12-ounce bottle of liquid. There's no evidence that the London liquid bombers actually had a workable plot, but assume for the moment they did. If some copycat terrorists try to bring their liquid bomb through airport security and the screeners catch them -- like they caught me with my bottle of pasta sauce -- the terrorists can simply try again. They can try again and again. They can keep trying until they succeed. Because there are no consequences to trying and failing, the screeners have to be 100 percent effective. Even if they slip up one in a hundred times, the plot can succeed.
</p><p>
The same is true for knitting needles, pocketknives, scissors, corkscrews, cigarette lighters and whatever else the airport screeners are confiscating this week. If there's no consequence to getting caught with it, then confiscating it only hurts innocent people. At best, it mildly annoys the terrorists.
</p><p>
To fix this, airport security has to make a choice. If something is dangerous, treat it as dangerous and treat anyone who tries to bring it on as potentially dangerous. If it's not dangerous, then stop trying to keep it off airplanes. Trying to have it both ways just distracts the screeners from actually making us safer.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is chief security technology officer of BT. His new book is </cite>Schneier on Security<cite>.

</p><br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=aefd56c11b2eee64280f816001ed44dc"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=aefd56c11b2eee64280f816001ed44dc"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=aefd56c11b2eee64280f816001ed44dc" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=K4hTL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=K4hTL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=gnANl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=gnANl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=7cfHl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=7cfHl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=lizGL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=lizGL" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=4j0mL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=4j0mL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=McKUl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=McKUl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=F517l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=F517l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=FIJtL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=FIJtL" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/396484059" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/396484061" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 14:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security screeners">security screeners</category>
      <category domain="http://securityratty.com/tag/airport security checkpoints">airport security checkpoints</category>
      <category domain="http://securityratty.com/tag/checkpoints">checkpoints</category>
      <category domain="http://securityratty.com/tag/airport security">airport security</category>
      <category domain="http://securityratty.com/tag/screeners">screeners</category>
      <category domain="http://securityratty.com/tag/liquid">liquid</category>
      <category domain="http://securityratty.com/tag/london liquid bombers">london liquid bombers</category>
      <category domain="http://securityratty.com/tag/airport screeners">airport screeners</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/396484061/securitymatters_0918">Security Matters: Airport Pasta-Sauce Interdiction Considered Harmful</source>
    </item>
  </channel>
</rss>
