<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: attractive]]></title>
    <link>http://www.securityratty.com/tag/attractive</link>
    <description></description>
    <pubDate>Wed, 23 Jul 2008 11:23:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[How to Clone and Modify E-Passports]]></title>
      <link>http://www.securityratty.com/article/d87db1f435de50bdfb362a781b2835de</link>
      <guid>http://www.securityratty.com/article/d87db1f435de50bdfb362a781b2835de</guid>
      <description><![CDATA[The Hackers Choice has released a tool allowing people to clone and modify electronic passports
The problem is self-signed certificates
A CA is not a great solution: Using a Certification Authority...]]></description>
      <content:encoded><![CDATA[<p>The Hackers Choice has <a href="http://blog.thc.org/index.php?/archives/4-The-Risk-of-ePassports-and-RFID.html">released</a> a tool allowing people to clone and modify electronic passports.</p>

<p>The problem is self-signed certificates.</p>

<p>A CA is not a great solution:</p>

<blockquote>Using a Certification Authority (CA) could solve the attack but at the same time introduces a new set of attack vectors:

<ol><li>The CA becomes a single point of failure. It becomes the juicy/high-value target for the attacker. Single point of failures are not good. Attractive targets are not good.

<p>Any person with access to the CA key can undetectably fake passports. Direct attacks, virus, misplacing the key by accident (the UK government is good at this!) or bribery are just a few ways of getting the CA key.</p>

<p><li>The single CA would need to be trusted by all governments. This is not practical as this means that passports would no longer be a national matter.</p>

<p><li>Multiple CA's would not work either. Any country could use its own CA to create a valid passport of any other country. Read this sentence again: Country A can create a passport data set of Country B and sign it with Country A's CA key. The terminal will validate and display the information as data from Country B.This option also multiplies the number of 'juicy' targets. It makes it also more likely for a CA key to leak.</p>

<p>Revocation lists for certificates only work when a leak/loss is detected. In most cases it will not be detected.</ol></p>

<p>So what's the solution? We know that humans are good at Border Control. In the end they protected us well for the last 120 years. We also know that humans are good at pattern matching and image recognition. Humans also do an excellent job 'assessing' the person and not just the passport. Take the human part away and passport security falls apart.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=UYU6L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=UYU6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=z7bQL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=z7bQL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 08:24:51 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/passports">passports</category>
      <category domain="http://www.securityratty.com/tag/passport">passport</category>
      <category domain="http://www.securityratty.com/tag/passport security falls">passport security falls</category>
      <category domain="http://www.securityratty.com/tag/passport data set">passport data set</category>
      <category domain="http://www.securityratty.com/tag/set">set</category>
      <category domain="http://www.securityratty.com/tag/electronic passports">electronic passports</category>
      <category domain="http://www.securityratty.com/tag/country">country</category>
      <category domain="http://www.securityratty.com/tag/key">key</category>
      <category domain="http://www.securityratty.com/tag/undetectably fake passports">undetectably fake passports</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/how_to_clone_an.html">How to Clone and Modify E-Passports</source>
    </item>
    <item>
      <title><![CDATA[Saved by SaaS: Data backup via software as a service]]></title>
      <link>http://www.securityratty.com/article/1ccc2dbc192adf243aa44f3ec3c9dd5f</link>
      <guid>http://www.securityratty.com/article/1ccc2dbc192adf243aa44f3ec3c9dd5f</guid>
      <description><![CDATA[SaaS data backup is becoming an increasingly attractive option for many companies that have difficulty with in-house backup. SaaS providers handle support and maintenance of a variety of applications...]]></description>
      <content:encoded><![CDATA[SaaS data backup is becoming an increasingly attractive option for many companies that have difficulty with in-house backup. SaaS providers handle support and maintenance of a variety of applications over the Internet without requiring their clients to invest in any servers or install software on-site.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1abdf4f18ff6dda9a90283fb7b3e8c53:m1I%2Boss1okw%2BW%2BDgsf1bSNzlQjEhC9b1cDhiTRKU4jbJWwWcmqDYHuQC6W5L3U%2BDLVtmm4r19Ftf'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:63195fa65154eb7c9f82b4058bdb73f1:lWC7pR0V0TX6w0hzjfJxjizzo%2BKZ8Z3p4Gr6EWFYVOSOkmJIlhB5An7spSPmFVx%2FTC6b9DG6u%2F1%2F8A%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ae1333c9b75150ba58ce64a4f6e62c53:74TIj0K5qYbqbfio1rcNuhZ13PBZIxvp2niPJwY%2Bie2IOoBv0R0Ft6WVGOYCPAsH7oizcxQ%2Bj13BqA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2ddbf6978d160c23c34af27f34f092db:3XcCP3DCsCqnz51pWpjHSAWzhB0VFxTSATZ4SbONSKZMvu%2F6xKB8XiyKLvRe6DS8487MZzDjJE9x4A%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=9656ce5584e9fb21da19c3d93a247f12" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=9656ce5584e9fb21da19c3d93a247f12" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/install software on-site">install software on-site</category>
      <category domain="http://www.securityratty.com/tag/saas data backup">saas data backup</category>
      <category domain="http://www.securityratty.com/tag/increasingly attractive option">increasingly attractive option</category>
      <category domain="http://www.securityratty.com/tag/in-house backup">in-house backup</category>
      <category domain="http://www.securityratty.com/tag/variety">variety</category>
      <category domain="http://www.securityratty.com/tag/internet">internet</category>
      <category domain="http://www.securityratty.com/tag/difficulty">difficulty</category>
      <category domain="http://www.securityratty.com/tag/applications">applications</category>
      <category domain="http://www.securityratty.com/tag/companies">companies</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=9656ce5584e9fb21da19c3d93a247f12">Saved by SaaS: Data backup via software as a service</source>
    </item>
    <item>
      <title><![CDATA[Identity Farming]]></title>
      <link>http://www.securityratty.com/article/b473cbd43ff87938f8034236b68d25c8</link>
      <guid>http://www.securityratty.com/article/b473cbd43ff87938f8034236b68d25c8</guid>
      <description><![CDATA[Let me start off by saying that I'm making this whole thing up
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity...]]></description>
      <content:encoded><![CDATA[<p>Let me start off by saying that I'm making this whole thing up. </p>

<p>Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity databases is making it increasingly difficult to create fake credentials. Ten years ago, someone could have just shown up in the country and gotten a driver's license, Social Security card and bank account -- possibly using the identity of someone roughly the same age who died as a young child -- but it's getting harder. And you know that trend will only continue. So you decide to grow your own identities. </p>

<p>Call it "identity farming." You invent a handful of infants. You apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them. </p>

<p>There are some complications, of course. Maybe you need people to sign their name as parents -- or, at least, mothers. Maybe you need to doctors to fill out birth certificates. Maybe you need to fill out paperwork certifying that you're home-schooling these children. You'll certainly want to exercise their financial identity: depositing money into their bank accounts and withdrawing it from ATMs, using their credit cards and paying the bills, and so on. And you'll need to establish some sort of addresses for them, even if it is just a mail drop. </p>

<p>You won't be able to get driver's licenses or photo IDs on their name. That isn't critical, though; in the U.S., more than 20 million adult citizens don't have photo IDs. But other than that, I can't think of any reason why identity farming wouldn't work. </p>

<p>Here's the real question: Do you actually have to show up for any part of your life? </p>

<p>Again, I made this all up. I have no evidence that anyone is actually doing this. It's not something a criminal organization is likely to do; twenty-five years is too distant a payoff horizon. The same logic holds true for terrorist organizations; it's not worth it. It might have been worth it to the KGB -- although perhaps harder to justify after the Soviet Union broke up in 1991 -- and might be an attractive option to existing intelligence adversaries like China. </p>

<p>Immortals could also use this trick to self-perpetuate themselves, inventing their own children and gradually assuming their identity, then killing their parents off. They could even show up for their own driver's license photos, wearing a beard as the father and blue spiked hair as the son. Iâm told this is a common idea in Highlander fan fiction. </p>

<p>The point isn't to create another movie plot threat, but to point out the central role that data has taken on in our lives. Previously, I've said that we all have a <a href="http://www.schneier.com/essay-219.html">data shadow</a> that follows us around, and that more and more institutions interact with our data shadows instead of with us. We only intersect with our data shadows once in a while -- when we apply for a driver's license or passport, for example -- and those interactions are authenticated by older, less-secure interactions. The rest of the world assumes that our photo IDs glue us to our data shadows, ignoring the rather flimsy connection between us and our plastic cards. (And, no, REAL-ID won't help.) </p>

<p>It seems to me that our data shadows are becoming increasingly distinct from us, almost with a life of their own. What's important now is our shadows; we're secondary. And as our society relies more and more on these shadows, we might even become unnecessary. </p>

<p>Our data shadows can live a perfectly normal life without us.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/09/securitymatters_0904">previously appeared<a> on Wired.com.</p>

<p>EDITED TO ADD (9/9): Interesting <a href="http://www.examiner.com/x-536-Civil-Liberties-Examiner~y2008m9d4-Im-not-myself-today-or-manufacturing-a-new-you">commentary</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YzkGL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YzkGL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JDMVL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JDMVL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 01:42:18 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/identity">identity</category>
      <category domain="http://www.securityratty.com/tag/data">data</category>
      <category domain="http://www.securityratty.com/tag/data shadow">data shadow</category>
      <category domain="http://www.securityratty.com/tag/data shadows">data shadows</category>
      <category domain="http://www.securityratty.com/tag/shadows">shadows</category>
      <category domain="http://www.securityratty.com/tag/financial identity">financial identity</category>
      <category domain="http://www.securityratty.com/tag/photo ids glue">photo ids glue</category>
      <category domain="http://www.securityratty.com/tag/photo ids">photo ids</category>
      <category domain="http://www.securityratty.com/tag/identity databases">identity databases</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/identity_farmin.html">Identity Farming</source>
    </item>
    <item>
      <title><![CDATA[Biotech Platforms]]></title>
      <link>http://www.securityratty.com/article/45651b9a0decddecc758c652995e074f</link>
      <guid>http://www.securityratty.com/article/45651b9a0decddecc758c652995e074f</guid>
      <description><![CDATA[It is interesting to see the notion of tech platforms play out in other fields. Specifically, the biotech field is all abuzz on platforms. For example Exelixis' oncology platform built on kinase...]]></description>
      <content:encoded><![CDATA[<p>It is interesting to see the notion of tech platforms play out in other fields. Specifically, the biotech field is <a href="http://www.hammerstockblog.com/genentech’s-new-shiny-platform/">all </a><a href="http://www.hammerstockblog.com/exelixis-as-a-platform-company/">abuzz</a> on platforms. For example Exelixis&#39; oncology platform built on kinase inhibitors.</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">Having a validated drug discovery platform is the first and most important criterion for defining a good platform company. The platform is typically comprised of a combination of technology, experienced personnel and intellectual property that can generate a stream of drug candidates. Most importantly, investing should be done only after a product of the platform&#160;<span>demonstrates</span>&#160;activity&#160;<span>in clinical trials.&#160;</span>Having a clinically validated product is not a guarantee for future success of the platform nor does it mean that the specific agent will reach the market, but it does imply that one or more of the platform’s products stand a reasonable chance of becoming a commercial drug. A validated platform may increase overall success rates, yet the odds of a particular drug candidate to make it all the way to approval are still low.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Exelixis is active in the ever growing market of kinase inhibitors (KIs) for the treatment of cancer, that is, drugs that block the activity of kinases in cancer cells. Cancer cells are often described as cells that are out of control: They proliferate quickly, ignore death signals, invade nearby tissues and eventually metastasize to distant organs. These disease onset and advancement are associated with processes such as cell growth, motility and blood-vessel formation, which are governed by a complex network made of kinases. Thus, blocking these processes by inhibiting the relevant kinases has emerged as one of the most attractive approaches to fighting cancer.<br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Together with monoclonal antibodies, kinase inhibitors represent a paradigm shift in cancer treatment from cytotoxic agents to targeted therapies, a trend that is constantly growing. Like antibodies for cancer, kinase inhibitors target tumors while sparing healthy cells and consequently lead to better activity with fewer side effects. Kinase inhibitors, however, possess several advantages over antibodies. The most evident advantage is that KIs can hit targets inside the cell while antibodies can only bind targets presented on the cell surface, so internal targets are approachable only by KIs. Another advantage is the fact that KIs can be given orally, which is a major factor in terms of patient convenience, especially given the typical long treatment duration associated with targeted therapies. Another advantage, which will be later discussed in the article, is the ability to produce KIs that hit several targets at once.<br /></span></p></blockquote><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Read the whole thing </span><a href="http://www.hammerstockblog.com/exelixis-as-a-platform-company/">here</a><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">.&#160;</span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Speaking a software guy, the thing that is interesting to me here is that the platform approach allows a biotech to aggregate a large database of tests and test results to refine products across a range of targets and delivery mechanisms. Its just data. Cancer versus Moore&#39;s law? Puh-leeze.</span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 06:08:55 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/drug">drug</category>
      <category domain="http://www.securityratty.com/tag/treatment">treatment</category>
      <category domain="http://www.securityratty.com/tag/cancer treatment">cancer treatment</category>
      <category domain="http://www.securityratty.com/tag/commercial drug">commercial drug</category>
      <category domain="http://www.securityratty.com/tag/platforms">platforms</category>
      <category domain="http://www.securityratty.com/tag/drug discovery platform">drug discovery platform</category>
      <category domain="http://www.securityratty.com/tag/platform">platform</category>
      <category domain="http://www.securityratty.com/tag/cells">cells</category>
      <category domain="http://www.securityratty.com/tag/cancer cells">cancer cells</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/biotech-platforms.html">Biotech Platforms</source>
    </item>
    <item>
      <title><![CDATA[Movie Plot Threats in The Guardian ]]></title>
      <link>http://www.securityratty.com/article/44fad18176882cd40d3a3632e2971eda</link>
      <guid>http://www.securityratty.com/article/44fad18176882cd40d3a3632e2971eda</guid>
      <description><![CDATA[We spend far more effort defending our countries against specific movie-plot threats, rather than the real, broad threats. In the US during the months after the 9/11 attacks, we feared terrorists with...]]></description>
      <content:encoded><![CDATA[<p>We spend far more effort defending our countries against specific movie-plot threats, rather than the real, broad threats. In the US during the months after the 9/11 attacks, we feared terrorists with scuba gear, terrorists with crop dusters and terrorists contaminating our milk supply. Both the UK and the US fear terrorists with small bottles of liquid. Our imaginations run wild with vivid specific threats. Before long, we're envisioning an entire movie plot, without Bruce Willis saving the day. And we're scared.</p>

<p>It's not just terrorism; it's any rare risk in the news. The big fear in Canada right now, following a particularly gruesome incident, is random decapitations on intercity buses. In the US, fears of school shootings are much greater than the actual risks. In the UK, it's child predators. And people all over the world mistakenly fear flying more than driving. But the very definition of news is something that hardly ever happens. If an incident is in the news, we shouldn't worry about it. It's when something is so common that its no longer news - car crashes, domestic violence - that we should worry. But that's not the way people think.</p>

<p>Psychologically, this makes sense. We are a species of storytellers. We have good imaginations and we respond more emotionally to stories than to data. We also judge the probability of something by how easy it is to imagine, so stories that are in the news feel more probable - and ominous - than stories that are not. As a result, we overreact to the rare risks we hear stories about, and fear specific plots more than general threats.</p>

<p>The problem with building security around specific targets and tactics is that its only effective if we happen to guess the plot correctly. If we spend billions defending the Underground and terrorists bomb a school instead, we've wasted our money. If we focus on the World Cup and terrorists attack Wimbledon, we've wasted our money.</p>

<p>It's this fetish-like focus on tactics that results in the security follies at airports. We ban guns and knives, and terrorists use box-cutters. We take away box-cutters and corkscrews, so they put explosives in their shoes. We screen shoes, so they use liquids. We take away liquids, and they're going to do something else. Or they'll ignore airplanes entirely and attack a school, church, theatre, stadium, shopping mall, airport terminal outside the security area, or any of the other places where people pack together tightly.</p>

<p>These are stupid games, so let's stop playing. Some high-profile targets deserve special attention and some tactics are worse than others. Airplanes are particularly important targets because they are national symbols and because a small bomb can kill everyone aboard. Seats of government are also symbolic, and therefore attractive, targets. But targets and tactics are interchangeable.</p>

<p>The following three things are true about terrorism. One, the number of potential terrorist targets is infinite. Two, the odds of the terrorists going after any one target is zero. And three, the cost to the terrorist of switching targets is zero.</p>

<p>We need to defend against the broad threat of terrorism, not against specific movie plots. Security is most effective when it doesn't require us to guess. We need to focus resources on intelligence and investigation: identifying terrorists, cutting off their funding and stopping them regardless of what their plans are. We need to focus resources on emergency response: lessening the impact of a terrorist attack, regardless of what it is. And we need to face the geopolitical consequences of our foreign policy.</p>

<p>In 2006, UK police arrested the liquid bombers not through diligent airport security, but through intelligence and investigation. It didn't matter what the bombers' target was. It didn't matter what their tactic was. They would have been arrested regardless. That's smart security. Now we confiscate liquids at airports, just in case another group happens to attack the exact same target in exactly the same way. That's just illogical.</p>

<p>This essay <a href="http://www.guardian.co.uk/technology/2008/sep/04/terrorism.terrorismandtravel">originally appeared</a> in <i>The Guardian</i>.  Nothing I haven't already said elsewhere.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=BZifEL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=BZifEL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YYA7cL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YYA7cL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 01:56:57 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/terrorists bomb">terrorists bomb</category>
      <category domain="http://www.securityratty.com/tag/bomb">bomb</category>
      <category domain="http://www.securityratty.com/tag/threats">threats</category>
      <category domain="http://www.securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://www.securityratty.com/tag/terrorists attack wimbledon">terrorists attack wimbledon</category>
      <category domain="http://www.securityratty.com/tag/specific targets">specific targets</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/targets">targets</category>
      <category domain="http://www.securityratty.com/tag/security follies">security follies</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/movie_plot_thre_2.html">Movie Plot Threats in The Guardian </source>
    </item>
    <item>
      <title><![CDATA[Security Matters: How to Create the Perfect Fake Identity]]></title>
      <link>http://www.securityratty.com/article/978beddfbfcfa8c96d83a85e27f028f6</link>
      <guid>http://www.securityratty.com/article/978beddfbfcfa8c96d83a85e27f028f6</guid>
      <description><![CDATA[Let me start off by saying that I'm making this whole thing up
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity...]]></description>
      <content:encoded><![CDATA[<p>Let me start off by saying that I'm making this whole thing up.
</p>

<p>
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity databases is making it increasingly difficult to create fake credentials. Ten years ago, someone could have just shown up in the country and gotten a driver's license, Social Security card and bank account -- possibly using the identity of someone roughly the same age who died as a young child -- but it's getting harder. And you know that trend will only continue. So you decide to grow your own identities.
</p>

<p>
Call it "identity farming." You invent a handful of infants. You apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them.
</p>

<p>
There are some complications, of course. Maybe you need people to sign their name as parents -- or, at least, mothers. Maybe you need to doctors to fill out birth certificates. Maybe you need to fill out paperwork certifying that you're home-schooling these children. You'll certainly want to exercise their financial identity: depositing money into their bank accounts and withdrawing it from ATMs, using their credit cards and paying the bills, and so on. And you'll need to establish some sort of addresses for them, even if it is just a mail drop.
</p>

<p>
You won't be able to get driver's licenses or photo IDs on their name. That isn't critical, though; in the U.S., more than 20 million adult citizens don't have photo IDs. But other than that, I can't think of any reason why identity farming wouldn't work.  
</p>

<p>
Here's the real question: Do you actually have to show up for any part of your life?
</p>

<p>
Again, I made this all up. I have no evidence that anyone is actually doing this. It's not something a criminal organization is likely to do; twenty-five years is too distant a payoff horizon. The same logic holds true for terrorist organizations; it's not worth it. It might have been worth it to the KGB -- although perhaps harder to justify after the Soviet Union broke up in 1991 -- and might be an attractive option to existing intelligence adversaries like China.
</p>

<p>
Immortals could also use this trick to self-perpetuate themselves, inventing their own children and gradually assuming their identity, then killing their parents off. They could even show up for their own driver's license photos, wearing a beard as the father and blue spiked hair as the son. I’m told this is a common idea in <a href="http://www.highlander.org/"><cite>Highlander</cite></a> fan fiction.
</p>

<p>
The point isn't to create another movie plot threat, but to point out the central role that data has taken on in our lives. Previously, I've said that we all have a <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/05/securitymatters_0515">data shadow</a> that follows us around, and that more and more institutions interact with our data shadows instead of with us. We only intersect with our data shadows once in a while -- when we apply for a driver's license or passport, for example -- and those interactions are authenticated by older, less-secure interactions. The rest of the world assumes that our photo IDs glue us to our data shadows, ignoring the rather flimsy connection between us and our plastic cards. (And, no, REAL-ID won't help.)
</p>

<p>
It seems to me that our data shadows are becoming increasingly distinct from us, almost with a life of their own. What's important now is our shadows; we're secondary. And as our society relies more and more on these shadows, we might even become unnecessary.
</p>

<p>
Our data shadows can live a perfectly normal life without us.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is Chief Security Technology Officer of BT, and author of </cite>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<cite>.</cite>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=8c450d9a9d0030ff631259b1803cae6a" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=8c450d9a9d0030ff631259b1803cae6a" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=snUd9L"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=snUd9L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=uzqRkl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=uzqRkl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=zVASIl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=zVASIl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=itvpML"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=itvpML" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=XRzLgL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=XRzLgL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=hSbcKl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=hSbcKl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Rk785l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Rk785l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=qjRx3L"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qjRx3L" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/382935195" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/382935196" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/identity">identity</category>
      <category domain="http://www.securityratty.com/tag/data">data</category>
      <category domain="http://www.securityratty.com/tag/data shadow">data shadow</category>
      <category domain="http://www.securityratty.com/tag/data shadows">data shadows</category>
      <category domain="http://www.securityratty.com/tag/shadows">shadows</category>
      <category domain="http://www.securityratty.com/tag/social security card">social security card</category>
      <category domain="http://www.securityratty.com/tag/financial identity">financial identity</category>
      <category domain="http://www.securityratty.com/tag/photo ids glue">photo ids glue</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/382935196/securitymatters_0904">Security Matters: How to Create the Perfect Fake Identity</source>
    </item>
    <item>
      <title><![CDATA[Microsoft and BearingPoint see space to play in the Enterprise GRC market]]></title>
      <link>http://www.securityratty.com/article/36af1d0bb845709d797550944d74b9e3</link>
      <guid>http://www.securityratty.com/article/36af1d0bb845709d797550944d74b9e3</guid>
      <description><![CDATA[Earlier this week in a joint press release, Microsoft and BearingPoint announced the new BearingPoint Enterprise Governance, Risk, and Compliance product offering. Ok... it will be a while before the...]]></description>
      <content:encoded><![CDATA[<p><img border="0" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Chris-McClean.gif" alt="Chris McClean" title="Chris McClean" style="margin: 0px 5px 5px 0px; float: left;" /></p>

<p>Earlier this week in a joint press release, Microsoft and BearingPoint announced the new <a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&amp;newsId=20080805005278&amp;newsLang=en">BearingPoint Enterprise Governance, Risk, and Compliance</a> product offering. Ok... it will be a while before the more veteran enterprise GRC vendors start really losing sleep over this deal. But BearingPoint continues to be a <a href="http://www.forrester.com/Research/Document/0,,40476,00.html">top risk consulting firm</a>, and Microsoft’s reach through the business user community will be an attractive benefit for compliance and risk professionals trying to get hundreds or thousands of staff members to contribute to the GRC program. There’s potential here for sure.</p>

<p>With software giants IBM, Oracle, SAP, and now Microsoft increasing their level of commitment in the enterprise GRC space, the 2-3 year market outlook continues to change. The risk and regulatory landscape is only going to get tougher to handle, and the more GRC programs can run seamlessly with existing business processes and applications, the better. The vendors focused solely on GRC still have the advantage for now, but market consolidation is on its way... and it’s coming maybe just a tiny bit faster than it was at the start of this week.</p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 12:12:55 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/grc">grc</category>
      <category domain="http://www.securityratty.com/tag/bearingpoint">bearingpoint</category>
      <category domain="http://www.securityratty.com/tag/grc programs">grc programs</category>
      <category domain="http://www.securityratty.com/tag/risk">risk</category>
      <category domain="http://www.securityratty.com/tag/bearingpoint continues">bearingpoint continues</category>
      <category domain="http://www.securityratty.com/tag/grc program">grc program</category>
      <category domain="http://www.securityratty.com/tag/top risk">top risk</category>
      <category domain="http://www.securityratty.com/tag/bearingpoint enterprise governance">bearingpoint enterprise governance</category>
      <category domain="http://www.securityratty.com/tag/enterprise grc space">enterprise grc space</category>
      <source url="http://blogs.forrester.com/srm/2008/08/microsoft-and-b.html">Microsoft and BearingPoint see space to play in the Enterprise GRC market</source>
    </item>
    <item>
      <title><![CDATA[Traditional Disaster Recovery Services Are Dead]]></title>
      <link>http://www.securityratty.com/article/91a8e062482df48ac9d61748458d67d9</link>
      <guid>http://www.securityratty.com/article/91a8e062482df48ac9d61748458d67d9</guid>
      <description><![CDATA[If you still subscribe to fixed site recovery services using shared IT infrastructure from the likes of HP, IBM BCRS, or SunGard, among others, you will quickly become a dinosaur in the next 1 to 2...]]></description>
      <content:encoded><![CDATA[<p><img border="0" title="Stephanie Balaouras" alt="Stephanie Balaouras" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Stephanie-Balaouras.gif" style="margin: 0px 5px 5px 0px; float: left;" /></p>

<p><span style="font-size: 10pt; font-family: Arial;">If you still subscribe to fixed site recovery services using shared IT infrastructure from the likes of HP, IBM BCRS, or SunGard, among others, you will quickly become a dinosaur in the next 1 to 2 years. </span></p>

<p><span style="font-size: 10pt; font-family: Arial;">These types of shared infrastructure services involve lengthy restores from tape and a recovery time objective of 72 hours, at best. Plus, you'll be lucky if you recover at all because chances are, you've had trouble scheduling a test with your service provider and it's been a LONG time since the last one, if indeed you’ve ever tested. </span></p>

<p><span style="font-size: 10pt; font-family: Arial;"><a href="http://www.forrester.com/go?docid=46270">72 hours recovery just doesn't cut it anymore</a>. And frankly, understanding your provider's oversubscription ratio to shared infrastructure to determine the risk of multiple invocations, or attempting to negotiate exclusions zones and availability guarantees is a time suck. Most companies are either taking DR back in-house or, if they still rely on a DR service provider, they are using dedicated infrastructure.</span></p>

<p><span style="font-size: 10pt; font-family: Arial;">A dedicated infrastructure is attractive as it enables replication to improve recovery objectives. But it’s expensive, and puts advanced IT recovery out of the reach of many companies who can't measure downtime in millions of dollars.</span></p>



<p><span style="font-size: 10pt; font-family: Arial;">But, there are new services on the horizon that will make advanced IT recovery affordable for the masses. This month SunGard announced the availability of its new Virtual Server Replication Service. As I discussed in my most recent <a href="http://www.forrester.com/go?docid=44878">Forrester Wave™ of DR Service Providers</a> and <a href="http://www.forrester.com/go?docid=42944">other reports</a>, server virtualization is transforming IT recovery. With replication to a virtualized server infrastructure and shared storage infrastructure, customers can enjoy improved recovery-time and recovery-point objectives without the cost of dedicated and custom IT recovery solutions from the <span class="hilite">DR</span> services provider.SunGard is the first DR service provider to productize these virtual services. I expect other DR service providers to follow suit. <br /></span></p>

<p><span style="font-size: 10pt; font-family: Arial;">So, the next time your contract is up for renewal, you need to completely rethink your approach to IT recovery. Get off tape and move to these new virtual services. It will improve your recovery capabilities and you don't have to worry about the oversubscription issue with shared virtual infrastructure -- the DR provider can manage capacity much more easily in this environment. In fact, SunGard is offering an RTO SLA of 6 hours as part of the offering. To my knowledge, this is the first time a DR service provider is offering this as part of a standard contract. I'm looking forward to the day when vendors will offer most services with transparent, subscription-based pricing, and standard contract terms that don't take a team of procurement professionals to negotiate.<span face="Times New Roman">&nbsp;</span><span style="font-size: 10pt; font-family: Arial;"><street w:st="on"></street></span></span></p>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 13:06:37 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/recovery">recovery</category>
      <category domain="http://www.securityratty.com/tag/recovery time objective">recovery time objective</category>
      <category domain="http://www.securityratty.com/tag/recovery-time">recovery-time</category>
      <category domain="http://www.securityratty.com/tag/services">services</category>
      <category domain="http://www.securityratty.com/tag/recovery affordable">recovery affordable</category>
      <category domain="http://www.securityratty.com/tag/recovery capabilities">recovery capabilities</category>
      <category domain="http://www.securityratty.com/tag/recovery solutions">recovery solutions</category>
      <category domain="http://www.securityratty.com/tag/provider">provider</category>
      <category domain="http://www.securityratty.com/tag/recovery-point objectives">recovery-point objectives</category>
      <source url="http://blogs.forrester.com/srm/2008/08/traditional-dis.html">Traditional Disaster Recovery Services Are Dead</source>
    </item>
    <item>
      <title><![CDATA[Software Liabilities and Free Software]]></title>
      <link>http://www.securityratty.com/article/dd4800aaf10918236391882307e39b57</link>
      <guid>http://www.securityratty.com/article/dd4800aaf10918236391882307e39b57</guid>
      <description><![CDATA[Whenever I write about software liabilities , many people ask about free and open source software. If people who write free software, like PasswordSafe , are forced to assume liabilities, they will...]]></description>
      <content:encoded><![CDATA[<p>Whenever I <a href="http://www.guardian.co.uk/technology/2008/jul/17/internet.security">write</a> <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">about</a> <a href="http://www.schneier.com/essay-116.html">software</a> <a href="http://www.schneier.com/essay-025.html">liabilities</a>, many people ask about free and open source software.  If people who write free software, like <a href="http://www.schneier.com/passsafe.html">PasswordSafe</a>, are forced to assume liabilities, they will simply not be able to and free software would disappear.</p>

<p>Don't worry, they won't be.</p>

<p>The key to understanding this is that this sort of contractual liability is part of a contract, and with free software -- or free anything -- there's no contract.  Free software wouldn't fall under a liability regime because the writer and the user have no business relationship; they are not seller and buyer.  I would hope the courts would realize this without any prompting, but we could always pass a Good Samaritan-like law that would protect people who distribute free software.  (The opposite would be an Attractive Nuisance-like law -- that would be bad.)</p>

<p>There would be an industry of companies who provide liabilities for free software.  If Red Hat, for example, sold free Linux, they would have to provide some liability protection.  Yes, this would mean that they would charge more for Linux; that extra would go to the insurance premiums.  That same sort of insurance protection would be available to companies who use other free software packages.</p>

<p>The insurance industry is key to making this work.  Luckily, they're good at protecting people against liabilities.  There's no reason to think they won't be able to do it here.</p>

<p>I've written more about liabilities and the insurance industry <a href="http://www.schneier.com/crypto-gram-0204.html#6">here</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=eikXNJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=eikXNJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=znVSvJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=znVSvJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 10:42:33 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/free software">free software</category>
      <category domain="http://www.securityratty.com/tag/free">free</category>
      <category domain="http://www.securityratty.com/tag/free software packages">free software packages</category>
      <category domain="http://www.securityratty.com/tag/distribute free software">distribute free software</category>
      <category domain="http://www.securityratty.com/tag/software liabilities">software liabilities</category>
      <category domain="http://www.securityratty.com/tag/liabilities">liabilities</category>
      <category domain="http://www.securityratty.com/tag/assume liabilities">assume liabilities</category>
      <category domain="http://www.securityratty.com/tag/free linux">free linux</category>
      <category domain="http://www.securityratty.com/tag/people">people</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/software_liabil.html">Software Liabilities and Free Software</source>
    </item>
    <item>
      <title><![CDATA[The Not-So-Sweet Life of Supplicants]]></title>
      <link>http://www.securityratty.com/article/a7513e6c4a71a61081c2aa1aef143439</link>
      <guid>http://www.securityratty.com/article/a7513e6c4a71a61081c2aa1aef143439</guid>
      <description><![CDATA[There are plenty of integration and configuration challenges when we look at 802.1X , but one of the most notable issues is choosing the right supplicant to best serve your end users
Some of the major...]]></description>
      <content:encoded><![CDATA[<P>There are plenty of integration and configuration challenges when we look at <A title="802.1X Primer" href="http://securityuncorked.squarespace.com/security-uncorked/2008/4/2/what-is-8021x-heres-a-technology-primer-for-you.html">802.1X</A>, but one of the most notable issues is <strong>choosing the right <A title="What is a supplicant?" href="http://securityuncorked.squarespace.com/security-uncorked/2008/6/5/know-the-difference-between-a-nac-client-and-a-1x-supplicant.html">supplicant</A> to best serve your end users</strong>. </P>
<P>Some of the major obstacles we face with 802.1X center around creating a smooth end user experience.&nbsp; We, as integrators, have the distinct ability to make &#8216;whatever&#8217; work- we find a way. But, what I hear most from my customers is &#8220;<em>it has to be easy for the end user.&#8221;</em>&nbsp; (Sometimes they go on a little further, but I&#8217;ll leave it at that.)</P>
<P><strong>Why does it matter?</strong> </P>
<P>Wireless, wireless, wireless. Although&nbsp;wired 1X is&nbsp;popular&nbsp;with our customer-base, the world isn&#8217;t quite flocking to it yet. However, 802.1X is certainly the best way to increase security and ease management of wireless networks. It&#8217;s standard, it&#8217;s flexible, it&#8217;s widely-supported by devices and endpoints and it eliminates the need for pre-shared keys or secondary passwords. It&#8217;s what most enterprises, government&nbsp;and educational organizations are implementing now, so it&#8217;s important. </P>
<P><strong>What are some of the problems?</strong> </P>
<P>The end user will have some adjustments to make, and network admins and support desks aren&#8217;t always thrilled with the propect of re-training users for these expectations.</P><span>
<ul>
<li>First of all, the <span style="TEXT-DECORATION: underline">time to authenticate</span> and connect to the network is going to drastically increase. I say drastically- it&#8217;s only a few seconds- but I&#8217;m sure it feels like minutes to a new 1X end user. 
<li>In addition, we&#8217;re in a transition and growing period where we&#8217;re trying to integrate and authenticate multiple pieces- the machine and/or user as well as any other clients residing on the endpoint, so there can be <span style="TEXT-DECORATION: underline">single-sign-on issues</span>. Not SSO in the traditional sense, but single-1X-sign-on vs logging in to authenticate and open the port, logging in again to get to network resources (such as Novell). 
<li>There may also be issues supporting <span style="TEXT-DECORATION: underline">multiple profiles</span>, so end users may need to understand the concept of enabling 802.1X on an interface at their office, then disabling it when they go home. 
<li>Or perhaps, in a shared or lab-type environment, we may have multiple unique users logging in to the same endpoint device, so we have to make it easy for end users to <span style="TEXT-DECORATION: underline">log off so there&#8217;s a forced re-auth</span> for the next user. </li>
</ul>
<P>There are plenty more, but this hits on the major concerns of most organizations planning to implement 802.1X (wired or wireless).</span></P>
<P><strong>How do we address the issues?</strong></P>
<P>There are different ways to deal with the complexity of supplicant and end-user interactions. First and foremost, a good <span style="TEXT-DECORATION: underline">end user training</span> program will be needed. There&#8217;s a learning curve, but eventually end users will get it- we just have to make sure the transition for &#8216;now&#8217; to &#8216;got it&#8217; is smooth and doesn&#8217;t overwhelm help desk resources. </P>
<P>As the operating systems and clients progress, we&#8217;re seeing <span style="TEXT-DECORATION: underline">more integration</span> and the ability to share 802.1X information between disparate pieces of the endpoint. </P>
<P>In the meantime, there are also <span style="TEXT-DECORATION: underline">3rd-party supplicants</span> that can ease several of the pains. <A class=offsite-link-inline title="Cisco SSC" href="http://www.cisco.com/en/US/products/ps7034/index.html" target=_blank>Cisco&#8217;s&nbsp;Secure Services&nbsp;Client</A>&nbsp; (acquired from Meetinghouse&#8217;s Aegis supplicant) and <A class=offsite-link-inline title="Juniper OAC" href="http://www.juniper.net/products_and_services/aaa_and_802_1x/odyssey/index.html" target=_blank>Juniper&#8217;s Odyssey Access Client</A>&nbsp; (acquired from Funk) both offer options and configurations not currently available in native OS supplicants. (For example, both offer the GINA shim for integrating Windows 1X login with Novell as well as multiple profile support.) Although I haven&#8217;t tried it, my understanding is you can still operate both of these clients independent of the controllers provided from the same vendor. </P>
<P><strong>Is it a deal-killer?</strong> </P>
<P>It can be. The struggle to provide a smooth transition for end users is often a deal-killer for organizations looking at deploying 802.1X. Although there are ways to combat most of these obstacles; often the time, planning and money required to&nbsp;proceed make it unattractive enough to abandon the project. In most cases, the more heterogeneous the endpoint environment is, the less attractive the solution becomes. In an all-Microsoft environment, you can have an 802.1X framework up in a matter of hours. With a mix of authentication directories, endpoint OSs and user expectations, you could spend weeks or&nbsp;months ironing out the details.</P>
<P><strong>The good news.</strong></P>
<P>Yes, there&#8217;s some good news here. The increased adoption of 802.1X is continually leading to increased integration of the software, operating systems and clients on endpoints. While 802.1X may never reach &#8216;plug-and-play&#8217; status, pretty soon the integration will reach a point where configuration is simplified enough for more wide-spread adoption, even in the most diverse environments. </P>
<P>Just hang tight, we&#8217;ll get there!</P>
<P># # #</P>
]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 11:23:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/user">user</category>
      <category domain="http://www.securityratty.com/tag/end-user interactions">end-user interactions</category>
      <category domain="http://www.securityratty.com/tag/user experience">user experience</category>
      <category domain="http://www.securityratty.com/tag/machine andor user">machine andor user</category>
      <category domain="http://www.securityratty.com/tag/users">users</category>
      <category domain="http://www.securityratty.com/tag/multiple unique users">multiple unique users</category>
      <category domain="http://www.securityratty.com/tag/user expectations">user expectations</category>
      <category domain="http://www.securityratty.com/tag/endpoint">endpoint</category>
      <category domain="http://www.securityratty.com/tag/expectations">expectations</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/7/23/the-not-so-sweet-life-of-supplicants.html">The Not-So-Sweet Life of Supplicants</source>
    </item>
  </channel>
</rss>
