Friday, August 4, 2006


News Item 6888 Hackers Clone E-Passports.

Hackers Clone E-Passports. The United States swears RFID tags can secure travelers' documents against forgery. But German experts clone the chips at will, while another group shows how terrorists might build a passport-triggered roadside bomb. Kim Zetter reports from the Black Hat conference in Las Vegas..  [Wired News: Security Blanket]
6:12:26 PM  PermaLink   / trackback []  

News Item 6887 Technology News: Customer Service: How Much Is Customer Trust Worth?

Nearly 10 million consumers were victimized by some form of identity theft in 2004 alone. That equals 19,178 people per day, 799 per hour and 13.3 per minute. Consumers have reportedly lost over US$5 million, and businesses have lost an estimated $50 billion or more.
6:09:20 PM  PermaLink   / trackback []  

News Item 6886 CSIA Applauds Ratification of Cybercrime Treaty.

CSIA Applauds Ratification of Cybercrime Treaty. "National borders are virtually irrelevant to cybercriminals, making global cooperation absolutely critical in the battle against Internet-related crime" [GT: Security and Privacy]
6:05:38 PM  PermaLink   / trackback []  

News Item 6885 Senate approves cybercrime treaty.

Senate approves cybercrime treaty. The Senate has ratified the long-neglected Council of Europe's Convention on Cybercrime, a cybercrime treaty that supporters say would allow greater international cooperation in cybercrime investigations. Opponents, however, question its protections for privacy and human rights. [Computerworld Privacy News]
6:03:59 PM  PermaLink   / trackback []  

News Item 6884 Michigan Trains Federal, State and Local Law Enforcement in Identity Theft.

Michigan Trains Federal, State and Local Law Enforcement in Identity Theft. Helped to better prepare 476 Michigan law enforcement officers to investigate identity theft, credit fraud and counterfeiting complaints [GT: Security and Privacy]
6:02:23 PM  PermaLink   / trackback []  

News Item 6883 Voting Security Attacked In Court Again.

Voting Security Attacked In Court Again.

Here we go again. Despite all of our efforts to dispel the false dichotomy between secure voting and accessible voting, a shrinking but vocal minority of the disability rights community continues to take steps to prevent more secure voting by claiming that it will violate the rights of the disabled. They've now filed a federal lawsuit in San Francisco, called PVA v. McPherson, to try to turn back the clock -- and force Californians back into insecure, inauditable voting systems. This argument was wrong when it was rejected by a federal judge in 2004 and it's still wrong now.

[EFF: Deep Links]
5:55:55 PM  PermaLink   / trackback []  

News Item 6882 The World's Worst Internet Laws Sneaking Through the Senate.

The World's Worst Internet Laws Sneaking Through the Senate.

The Convention on Cybercrime is a sweeping treaty that has been waiting in the wings of the Senate for nearly three years. Now the administration is putting pressure on the Senate to ratify it in the next two days. If it does, it would mean the U.S. would enforce not just our own, but the rest of the world's bad Net laws. Call your Senator now, and ask them to hold its ratification.

The treaty requires that the U.S. government help enforce other countries' cybercrime laws - even if the act being prosecuted is not illegal in the United States. That means that countries that have laws limiting free speech on the Net could oblige the F.B.I. to uncover the identities of anonymous U.S. critics, or monitor their communications on behalf of foreign governments. American ISPs would be obliged to obey other jurisdiction's requests to log their users' behavior without due process, or compensation.

The treaty came into force last year on the international front, but not in the US, where it needs to be ratified by Congress first. So far, ratification has been blocked thanks to a "hold" placed by conservative lawmakers. But Republican senators this week are now being heavily pressured by the administration to drop their objections, and let it fly.

Ratifying the Cybercrime treaty would introduce not just one bad Internet law into America's lawbooks, but invite the enforcement of all the world's worst Internet laws. Call your senators now, and tell them to hold this invasive treaty at bay.

[EFF: Deep Links]
5:53:33 PM  PermaLink   / trackback []  

News Item 6881 FBI Joins With Industry to Tackle ID Theft.

FBI Joins With Industry to Tackle ID Theft. Operation Identity Shield announced at Black Hat conference in Las Vegas. [PC World: Latest Technology News]
5:49:57 PM  PermaLink   / trackback []  

News Item 6880 Is Online Free Speech In Danger?

Is Online Free Speech In Danger? Two proposed laws are threatening freedom of speech, advocacy group says. [PC World: Latest Technology News]
5:47:38 PM  PermaLink   / trackback []  

News Item 6879 NSA Suit Temporarily Halted.

NSA Suit Temporarily Halted.

The Electronic Frontier Foundation's lawsuit against AT&T for its alleged complicity in the government's warrantless wiretapping program came to a sharp, though possibly temporary halt Wednesday.

Judge Vaughn Walker, who allowed the suit to go forward despite the government's claim that the lawsuit would endanger national security, called a temporary halt to the proceedings.

AT&T, which had until Thursday to answer the allegations in the EFF's original complaint, told the judge it could not do so without revealing state secrets -- so the company wants not to have to answer until an appeals court hears the government's appeal (and possibly its own as well).

Walker granted the stay (.pdf), at least until the planned August 8 hearing, when the government and AT&T can argue to have the whole casestayedwhileboth attempt to get the Ninth Circuit to hear their appeal of Walker's decision not to toss the case.

For its part, the EFF wants the case to proceed while the appeals are pending. The civil liberties group argues that there is an ongoing and massive violation of AT&T's customers' rights and that there are portions of the case that don't involve "state secrets."

The case is Hepting vs. ATT Corp.

Photo: CarbonNYC

[27B Stroke 6]
5:43:28 PM  PermaLink   / trackback []  

News Item 6878 Last Chance for a Chipless Passport?

Last Chance for a Chipless Passport?

passport stamps

The e-passport is coming. The e-passport is coming.

After much ado, the United States has begun or will begin issuing passports with RFID chips in them.

The passports now have some anti-skimming features, including Basic Access Control and some sort of internal tin-foil hat.

But the chips are readily clonable, and some security experts still aren't sure they are a good idea. Also, it's just plain creepy to be on the same level as a pallet from WalMart.

You might still be able to get a passport without the chip and that passport will be good for 10 years -- long enough to get you to the point where new passports will be RFID chips implanted in your neck.

Travel privacy guru Edward Hasbrouckhad a good post up in May about how to maximize your chances of getting a chip-less passport, which involves a little extra money anda refundable ticket. The trick still might work.

You can also make sure your passport lasts longer by including with your application a written letter that says you need extra pages.

The government's page on getting a new passport is here, and renewals are here, but so far, the State Department hasn't returned my call asking if they are actually issuing the passports, though the last report I read was that they were starting with the Denver office.

Photo: Jesse Edwards

[27B Stroke 6]
5:35:07 PM  PermaLink   / trackback []  

News Item 6877 Intel Issues Patches to Fix Wireless Flaws.

Intel Issues Patches to Fix Wireless Flaws.

Intel has released updates to fix at least seven separate security flaws in the low-level software that powers its Centrino wireless devices. The flaws reside in Intel's wireless "device drivers," and are present at such a fundamental level of the operating system that they could be used by bad guys to spread malicious software like a computer worm wirelessly between vulnerable computers without any action on the part of the user.

The Intel Web site has more information on these flaws and includes a tool that people can use to tell whether they need to download and install software updates to fix the problems. I would strongly advise anyone using a laptop with an embedded wireless card to pay a visit to the page and run the tool, as many, many computer manufacturers embed Intel's hardware and software into their machines.

Yesterday, I wrote about a series of flaws security researchers here at Black Hat were able to find in multiple wireless device drivers. While Intel's update appears unrelated to their presentation, these vulnerabilities are quite serious and we are likely to see similar updates in the not-too-distant future from other companies that make these device drivers. Intel said it is currently working with various computer manufacturers to get their word out to their customers as well.

[Security Fix]
5:31:44 PM  PermaLink   / trackback []  

News Item 6876 Javascript Attacks on Steroids.

Javascript Attacks on Steroids.

LAS VEGAS -- Just sat through a rather disturbing presentation here at Black Hat on how bad guys can use Javascript to circumvent hardware and software firewalls and wreak havoc on a target's internal network.

Jeremiah Grossman and T.C. Niedzialkowski, both of Santa Clara, Calif.-based WhiteHat Security, showed Javascript tricks that could allow attackers to monitor which sites users have visited, change the configuration of their firewalls, and even record victims' keyboard strokes.

Javascript is a powerful programming language that works seamlessly across multiple Web browsers and operating systems, but online criminals can tap into that power to effectively force browsers that visit malicious sites to do their bidding.

Using a Web server he and Niedzialkowski had seeded with invisible code, Grossman demonstrated how he could view which sites a test browser had recently visited. The code also divulged the user's internal network address -- information that is supposed to be hidden by the firewall. Later in the demo, he showed a Javascript attack that altered the test victim's firewall settings to allow attackers to punch through directly into the internal network.

Javascript attacks have become more prevalent over the past year. Many sites that cater to people searching for "cracks" -- copy-protection hacks that make it easier to use pirated software -- routinely use scripts to silently install malware.

Grossman said an attacker who managed to compromise a large number of computers using Javascript would have no trouble forcing those victims to unknowingly participate in all kinds of illegal activities, from click fraud to downloading illegal content, or using the combined power of the affected machines to conduct denial-of-service attacks capable of knocking a targeted Web site offline.

There are free tools available to help users block certain types of Javascript attacks. The NoScript extension for Firefox blocks all scripts by default, allowing the user to turn Javascript back on if they visit a trusted site and want to view content that requires it. But NoScript also remembers which sites the user has selected, and Javascript attacks are increasingly showing up on social-networking sites like Myspace.com and other places that many users implicitly trust.

Another tool I use on most of my machines is the Netcraft Toolbar, which does a pretty decent job of warning you before the browser loads sites that attempt to use known javascript attack code.

But Grossman cautioned that these tools are not a comprehensive antiscript shield. "These are all designed to spot the bad sites, not necessarily good sites doing bad things," he said.

[Security Fix]
5:29:09 PM  PermaLink   / trackback []  

News Item 6875 Net Neutrality Tool Misses the Point.

Net Neutrality Tool Misses the Point.

You may have read in the last day or two about a so called [base "]net neutrality tool[per thou] created by a hacker / tinkerer / software programmer, to detect if your send / receive packets are being discriminated against by your ISP. I think it would be a great tool to demonstrate the problem and to show that packet-shaping and discrimination is (or will be) happening.

However, what some are missing is critical to this whole net neutrality debate. It[base ']s not that we won[base ']t know or be able to detect if we[base ']re experiencing packet discrimination. Heck, we already know broadband providers are going to discriminate because they[base ']ve told us they will[~]AT&T[base ']s Whitacre even said it recently again, in case there was any question.

No the issue is this: we[base ']ll know the discrimination is happening, but the internet surfing public and web-based businesses will be unable to do anything about it. Why? Because last year the FCC gave up that discrimination complaint-process role and in Congress[base '] telecom bills (House and proposed Senate), even if the FCC changed its mind and wanted to do something, its hands will be tied.

So, go ahead, write all the discrimination-detection tools you want, but a lot of good they[base ']ll do you[~]when they start doing what they told you they would do, you[base ']ll have no recourse if we don[base ']t reinstate an enforceable net neutrality principle.

read more

[Public Knowledge - Policy Blog]
5:05:47 PM  PermaLink   / trackback []  

News Item 6874 Audit & Remove Yourself from Data-Collection Databases.

Audit & Remove Yourself from Data-Collection Databases.

Wired[base ']s 27B Stoke 6 blog has posted some helpful info on how to audit and remove yourself from of some common data-collection databases (and annoying mailing lists):

  • If you have ever applied for health, life or disability insurance on your own, it[base ']s likely the information about your health and lifestyle that you had to provide ended up in a database run by the MIB Group. The easiest way to check your record is by phone at 866.692.6901. The group will then mail you your report if they have one.
  • ChoicePoint, the folks who sold 145,000 data reports to Nigerian identity theft scammers in 2004, sells auto and home-insurance risk scores (among other things) and you can check your file for free once a year via their web page
  • ChexSystems keeps tabs individual[base ']s banking habits and sells that data to banks vetting new customers. Give them a call at 800.428.9623. They also run a system that keeps track of people who have reportedly passed a bad check. Track down that report here or make their phone jingle with this number: 800.262.7771.
  • Acxiom, another big data broker, will let you opt-out of their marketing database for free if you call 501-342-2722 and press 5. You can also ask them to send you a form that lets you check the non-marketing information they have on you. They won[base ']t let you opt-out of this, and they will charge you $5 for the privilege. Be aware it could take them months to send out the report.
  • Stop some direct mail via the Direct Marketing Association[base ']s web page. It[base ']s free if you print it out and mail it in to them for hand processing, but costs $5 if you just want to do it online. That[base ']s how much they like this opt-out list. DO NOT join the DMA[base ']s phone or email opt-out list. That[base ']s just begging for spam and telemarketing calls.
  • Stop almost all credit card and life insurance direct mail solicitations (this won[base ']t stop ones from your own bank) by calling 1-888-5-OPTOUT.
  • And of course, the ever handy Do Not Call list is here.
[michaelzimmer.org]
12:22:14 PM  PermaLink   / trackback []  

News Item 6873 Others Online: Opt-In Web Surveillance.

Others Online: Opt-In Web Surveillance.

A new service called Others Online makes obvious what Google Toolbar and other browser tools do in the background: track users web browsing activities. From their site:

Others Online is a free toolbar that shows you people relevant to your Web browsing and other interests, on every page you visit. We show you the interests you have in common, their Web pages (blog, MySpace profile, Web site, etc.) and online status, all on their terms. We[base ']ll even connect you by IM or email.

[sigma]Every time you search the Web, you[base ']ll see people that have associated themselves to those keywords, plus you[base ']ll see any other interests you share. It[base ']s like [base "]Google for people[per thou]!

In a nutshell, users sign up, create a profile like most other social networking site, download the toolbar, and then start browsing the web like usual. Others Online then collects information about the websites visited (including the URL and relevant content keywords embedded in the URL), and then shows other users who share a similar profile and browsing habits.

Sorta cool to be able to find other people searching for the same stuff I am, such as [base "]web surfing surveillance[per thou]. But my concern is that products like this, even though opt-in, work to normalize web surveillance, playing into the [base "]I[base ']ve got nothing to hide[per thou] meme that justifies wholesale surveillance of our daily activities. The more users become comfortable with the surveillance of their online activities, the less likely they will be able to identify abuses of that surveillance.

A couple of other points on this particular service:

  • Their privacy policy states that [base "]When you sign up for an Others Online Account, we ask you for personal information (such as your birth date, gender, email address, country, post code and an account password)[sigma].[per thou] But that the [base "]service is anonymous [base ']Äì we do not request your name or your physical address.[per thou] This isn[base ']t entirely true, since research (such as Latanya Sweeney[base ']s amazing work) has shown that 87 percent of Americans can be personally identified by records listing only their birth date, gender and ZIP code. Anonymity is not guaranteed simply by not collecting one[base ']s name and address.
  • Another note in the privacy policy states that [base "]We may combine the information you submit under your account with information from third parties in order to provide you with a better experience and to improve the quality of our services.[per thou] Who knows what kind of [base "]information from third parties[per thou] they[base ']re talking about, but this is just the kind of data mining and data aggregation practices that Sweeney (and folks like Dan Solove) warn us about.
  • While you can clear your entire search history, it doesn[base ']t seem to be possible to selectively delete certain searches or browsing activities from their database. Users must remember to logoff the service is they don[base ']t want others to know they[base ']ve been watching Pat Benetar videos on YouTube.

[via John Battelle]

[michaelzimmer.org]
12:20:12 PM  PermaLink   / trackback []  

News Item 6872 Walt Handelsman: N.S.A. Wiretapping

A Flash based cartoon :-)

12:17:31 PM  PermaLink   / trackback []  

News Item 6871 The spy suit wars. A nation divided

The spy suit wars.

A nation divided

Valley Justice  Two United States District Court judges recently handed down decisions in high-profile cases involving wiretapping and alleged records aggregation on behalf of the National Security Agency (NSA). The suits were brought against AT&T by plaintiffs in the Northern District of California with the legal 'expertise'� of the Electronic Frontier Foundation (EFF), and in the Northern District of Illinois with the help of the American Civil Liberties Union (ACLU.) The suits allege that AT&T violated constitutional and statutory protections against the disclosure of private information by providing telephone communications and subscriber information to the federal government.

[The Register - Internet and Law: Digital Rights/Digital Wrongs]
12:15:09 PM  PermaLink   / trackback []  

News Item 6870 Feds dip their snouts back in EFF vs. AT&T wiretap case.

Feds dip their snouts back in EFF vs. AT&T wiretap case.

Cracking the 'classified mosaic'

Valley Justice Surprise, surprise. The US government has asked a California court to take a second look at a recent decision that allowed the EFFâo[dot accent]s wiretap case to proceed against AT&T.

[The Register - Internet and Law: Digital Rights/Digital Wrongs]
12:11:11 PM  PermaLink   / trackback []  

News Item 6869 UK gov spoiler for critical ID report?

UK gov spoiler for critical ID report?

Wait for the indi view tomorrow

The Home Office has published the long-awaited results of its consultation with the IT industry over identity cards, on the eve of the publication of an independent report that is expected to criticise the government for failing to adequately consult industry and other stakeholders about its plans.

[The Register - Internet and Law: Digital Rights/Digital Wrongs]
12:09:25 PM  PermaLink   / trackback []  

News Item 6868 MPs want to postpone ID.

MPs want to postpone ID.

Better late than never, they say

The government has been advised to further postpone the introduction of ID Cards until it can be sure the scheme will work.

[The Register - Internet and Law: Digital Rights/Digital Wrongs]
12:07:34 PM  PermaLink   / trackback []  

News Item 6867 How to clone the copy-friendly biometric passport.

How to clone the copy-friendly biometric passport.

So easy the manual tells you that you can do it

Analysis At Black Hat yesterday, security consultant Lukas Grunwald of German company DN-Systems demonstrated the cloning of a biometric passport, observing beforehand to Wired that the "whole passport design is totally brain damaged." But should we be surprised? Not exactly, because that's precisely what it says on the tin.

[The Register - Internet and Law: Digital Rights/Digital Wrongs]
12:06:17 PM  PermaLink   / trackback []  

News Item 6866 e-passport cloning risks exposed.

e-passport cloning risks exposed.

RFID hack attack

A security consultant has shown how to clone electronic passports based on internationally agreed designs due to begin distribution this year.

[The Register - Internet and Law: Digital Rights/Digital Wrongs]
12:04:18 PM  PermaLink   / trackback []