home flickr
Your Ad Here
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, August 18, 2009

How 10 digits will end privacy as we know it



Internet denizens and urban dwellers alike need to recognize that an era of anonymity is ending.

The population of the world stands at about 7 billion. So it takes only 10 digits to label each human being on the planet uniquely.

This simple arithmetic observation offers powerful insight into the limits of privacy. It dictates something we might call the 10-Digit Rule: just 10 digits or so of distinctive personal information are enough to identify you uniquely. They're enough to strip away your anonymity on the Internet or call out your name as you walk down the street. The 10-Digit Rule means that as our electronic gadgets grow chattier, and databases swell, we must accept that in most walks of life, we'll soon be wearing our names on our foreheads.

A study of 1990 U.S. Census data revealed that 87 percent of the people in the United States were uniquely identifiable with just three pieces of information (PDF): five-digit ZIP code, gender, and date of birth. Internet surfers today spew considerably more information than that. Web sites can pinpoint our geographical locations, computer models, and browser types, and they can silently track us using cookies. Banking sites even confirm our identities by verifying that our log-ins take place at consistent times of day.



Database dossiers, too, carry surprising amounts of identifying information, even when specifically anonymized for privacy. Researchers at the University of Texas at Austin last year studied a set of movie-rating profiles from about 500,000 unnamed Netflix subscribers (PDF).

Knowing just a little about a subscriber--say, six to eight movie preferences, the type of thing you might post on a social-networking site--the researchers found that they could pick out your anonymous Netflix profile, if you had one in the set. The Netflix study shows that those 10 deanonymizing digits can hide in surprising places.


Our physical belongings also betray our anonymity by silently calling out identity-betraying digits. Small wireless microchips--often called radio frequency identification, or RFID, tags--reside in car keys, credit cards, passports, building entrance badges, and transit passes. They emit unique serial numbers.

Once linked to our names--when we make credit card purchases, for instance--these microchips enable us to be tracked without our realizing it. One popular book inflames imaginations with the lurid title, "Spychips: How Major Corporations and Government Plan to Track your Every Move with RFID."
There's little point in hiding the serial numbers of chips when your mobile phone squeals on you.



But wireless microchips also highlight the futility of anonymity protections. To begin with, concerns about RFID tracking miss the forest for the trees. After all, mobile phones are ubiquitous and can be tracked at much longer ranges than standalone chips. Many people have GPS receivers in their phones and are signing up for location-based services, voluntarily (if selectively) disclosing their movements. There's little point in hiding the serial numbers of chips when your mobile phone squeals on you.

Many scientists have developed antitracking techniques for mobile phones and microchips. Instead of fixed serial numbers, wireless devices can call out changing pseudonyms, such as the rotating license plate numbers on spies' cars in the movies. The problem is that the plates may change, but the car always looks the same. In this regard, chips are like cars.


Scientists at ETH Zurich recently showed how to identify microchips uniquely using radio waves (PDF)--and consequently to see through the disguise of pseudonyms. Their experiments showed that thanks to manufacturing variations, microchips, laptop Wi-Fi cards, and other devices can't help but emit physical "fingerprints"--essentially God-given serial numbers. More digits that we radiate unknowingly.

In the end, we probably won't need to carry anything at all to see our identities betrayed in public spaces. There are already tens of millions of surveillance cameras in public spaces in the United States.



Face recognition software is crude today, but it will improve. Cameras will eventually recognize faces as well as people do. Unlike people, though, they'll have the backing of databases containing millions of faces--or the headshots that so many of us already post online.

Thankfully, despite proliferating sources of those 10 digits that are fatal to anonymity on the Internet and the sidewalk, we can still prevent the world of the film "Minority Report." There are many defensible facets to privacy beyond identity. Even if our names are blazoned forth to all and sundry, we still have the opportunity to safeguard health care and financial data, entertainment preferences, purchase histories, and social interactions.

In this battle, identity theft is a key challenge for technologists and policymakers. The only way to prevent unauthorized access to personal data is to ensure that even when criminals learn the digital constituents of your identity, they can't steal it. Strong authentication will need to fill the gap as the privacy of identities crumbles.

Perhaps the world will be friendlier when in-store advertisements greet you personally, criminals wear "Hello, My Name Is" badges, and the people you meet at parties already have your bio in hand. Facebook, Twitter, and pervasive blogging already augur a society of reflexive exhibitionism and voyeurism. But the technologies that advance us into a world of omniscience will also bring us a step backward.

For years, people aspired to escape small towns for the big city, for the fresh start of an identity without history. The Internet offered similar horizons of freedom. But the society of the small town will soon have us back in its clutches, for good and bad. And on the Internet, everyone will know if you're a dog.

Hackers break into police computer as sting backfires



An Australian Federal Police boast, on the ABC's Four Corners program last night, about officers breaking up an underground hacker forum, has backfired after hackers broke into a federal police computer system.

Security consultants say police appear to have been using the computer as a honeypot to collect information on members of the forum but the scheme came undone after the officers forgot to set a password.

Last Wednesday, federal police officers in co-operation with Victoria Police executed a search warrant on premises in Brighton, Melbourne, connected to the administrator of an underground hacking forum, r00t-y0u.org, which had about 5000 members.

Many details of the investigation were revealed for the first time on Four Corners last night.

After the raid, the federal police covertly assumed control of the forum and began using it to gather evidence about members.

"We can operate in a covert activity here fairly seamlessly with no harm to our members with continual and actual significant penetration," Neil Gaughan, national manager of the federal police's High Tech Crimes Operation, told Four Corners.

However, what the federal police did not know was that hackers had already cottoned on to their plan.

Police were monitoring the forum by logging into the account of the administrator they had raided, but this aroused suspicion among members who knew the raid had taken place.

A hacker broke into the federal police's computer system and, according to a source close to the investigation, accessed both police evidence and intelligence about federal police systems such as its IP addresses.

A spokeswoman for the federal police confirmed that the hacker broke into a computer system used in its investigation but denied that any evidence was compromised, saying the computer was not connected to other federal police systems.

"The AFP has identified a person whom [sic] has attempted to access the stand-alone computer system and we are currently working with our law enforcement partners regarding this matter," the spokeswoman said.

The hacker appears to have been provoked by a message published on the r00t-y0u.org site by the federal police, warning members they were under surveillance and that "all member IP addresses have been logged", with some arrests having already been made.

In two provocative messages published on anonymous document-sharing site pastebin.com, the hacker slammed the federal police for "making it sound like they can bust 'hackers', when all they have done is busted a COUPLE script kiddies". "Script kiddies" is hacker parlance for novice hackers.

The second of these messages contained several links to screenshots allegedly proving that the writer had access to the federal police's server.

These included shots of files containing fake IDs and stolen credit card numbers, as well as the federal police's server information.

The hacker then defaced the r00t-y0u.org website with the same message it had posted on the anonymous document-sharing site.

The federal police spokeswoman said: "The information posted on the http://pastebin.com website is information contained on a stand-alone [federal police] system designed specifically to be used in investigations such as this.

"The information consists of directory file names of previously compromised credentials. No information or files exist that have, or could have, been compromised."

The hacker wrote "I couldn't stop laughing" on seeing that the federal police's server was running Windows, which is known among hacker communities for being insecure. Police had also "left the MYSQL password blank".

"These dipshits are using an automatic digital forensics and incident response tool," the hacker wrote.

"All of this [hacking] had been done within 30-40 minutes. Could of been faster if I didn't stop to laugh so much."

Shaon Diwakar, a security consultant at Hack Labs in Sydney, explained how the hack occurred.

"The attacker has discovered that the server didn't have a password for its database application and he has logged on ... and, using a technique called SQL injection, he created a PHP file on the disk and browsed through that PHP file to get complete control of that particular server," he said.

Diwakar said the hacker would have had access to anything that was stored on the computer.

"When they took this action they should have known that they would have been a big target, so they should have taken more precautions," he said.

The federal police said it had yet to charge anyone over the r00t-y0u.org forum bust, but "numerous items" were seized and the investigation was ongoing.

It declined to comment further on the case.

Tuesday, December 02, 2008

Robot soldiers to get a kinder software side


WASHINGTON: The US military is planning to build robot soldiers that would not be able to commit war crimes.

The army and the navy have hired experts in the ethics of building machines to prevent the creation of an amoral Terminator-style killing machine. By 2010 the US will have spent $4 billion ($6.1 billion) on research into "autonomous systems", the military jargon for robots, on the basis that they would not succumb to fear or the desire for vengeance that afflicts front-line soldiers.

A British robotics expert has been recruited by the navy to advise on building robots that would not violate the Geneva Conventions.

Colin Allen, a scientific philosopher at Indiana University, has just published a book summarising his views titled Moral Machines: Teaching Robots Right From Wrong.

He said: "The question they want answered is whether we can build automated weapons that would conform to the laws of war. Can we use ethical theory to help design these machines?"

Pentagon chiefs are concerned by studies of combat stress in Iraq that showed that a high proportion of front-line troops supported torture and retribution against enemy combatants. Ronald Arkin, a computer scientist at Georgia Tech university, who is working on software for the army, has written a report that concludes that robots, while not "perfectly ethical in the battlefield" can "perform more ethically than human soldiers".

He said that robots "do not need to protect themselves" and "they can be designed without emotions that cloud their judgment or result in anger and frustration with ongoing battlefield events".

Airborne drones are already used in Iraq and Afghanistan to launch air strikes and robotic vehicles are used to disable roadside bombs and other improvised explosive devices.

But this generation of robots are all remotely operated by humans. Researchers are now working on "soldier bots", which would be able to identify targets and distinguish between enemy forces and soft targets, like ambulances or civilians. Their software would be embedded with rules of engagement.

Dr Allen applauded the decision. "It's time we started thinking about the issues of how to take ethical theory and build it into the software that will ensure robots act correctly rather than wait until it's too late."

.. from smh

Monday, November 10, 2008

Sneakey

Few of us would care if our house keys appeared in a photograph of the family picnic posted on the internet.

But we should be concerned because advances in digital imaging and optics means any photograph of a key posed a potential security threat, Stefan Savage, a computer science professor at the University of California, warns.

Professor Savage and two of his PhD students have developed a software program called Sneakey that can clone a key in "two to three minutes" after analysing a digital photograph.

The algorithm is so sophisticated it easily copes with the low-resolution mobile phone images routinely posted on social networking sites such as MySpace and Facebook.

"The software looks at the key, adjusts the image for any rotations or distortions, then produces a string of numbers that is appropriate for that key," Professor Savage said.

"Those numbers are fed into a key-cutting machine and it makes a perfect copy.

Professor Savage, 39, said his team at the University's Jacobs School of Engineering in San Diego found "thousands" of images of keys inadvertently posted on the photo-sharing site Flickr.

They also used a camera fitted with a telephoto lens to photograph and duplicate a set of keys on a cafe table from a distance of more than 60 metres.

Far from being unique, the bumps and valleys on a conventional key can be "completely described" using a five- or six-digit number, he said.

"The design of the keys we use today is 150 years old and the world has changed."

As a result, Professor Savage believes we should protect our keys in the same way we protect the code to our debit card.

Sneakey runs on an ordinary personal computer and uses key-cutting hardware that is readily available in Australia.

The University of California team is keeping the code secret, but Professor Savage admits anyone with a basic knowledge of programming and computer vision techniques would be able to reproduce it.

He believes the "keyless" locking systems used on modern cars will eventually become the standard for all security applications. Until then, you might think twice before posing for a happy snap with your keys dangling from your belt.


.. from smh


Sunday, June 01, 2008


What the CIA Learned From 'Get Smart'



Maxwell Smart always "missed it by that much," but some of those dopey spy shows of the '60s were right on the money. "Many of the devices first seen in movies and on TV actually came about," says Robert Wallace, former head of the CIA's covert skunk works, the Office of Technical Services.

"Remember the Cone of Silence? We built shielded enclosures that did the same thing. And the pen communicator in The Man From U.N.C.L.E.? That evolved, 10 years later, into short-range agent communication." Wallace, who was basically the agency's real-life Q, reveals these gadgets and more in his new book, Spycraft, the first comprehensive look at the technical achievements of American espionage from the 1940s to the present.

"Here's the laboratory," Wallace used to tell new recruits. "The only thing that is going to limit what you can do is your imagination." It seems they took him at his word.



1940's: Cigarette gun

Lipping this pistol disguised as a cigarette, an agent could easily release the safety pin. Rotating the filter end counterclockwise armed the gun, and a push of the thumb caused it to fire a single .22-caliber bullet. It really worked.




1940's: Combustible notebook

An ordinary-looking bound notebook contained pages of Pyrofilm and came packaged with an incendiary pencil. To prevent notes from falling into the wrong hands, an agent could simply pull the eraser out of the pencil, causing the notebook to burst into flames.



1960's: Acoustic kitty

During an hour-long procedure, techs embedded a 3/4-inch transmitter in the skull of a live cat. An antenna made of very fine wire was woven into the cat's fur, and a microphone was placed in its ear canal. After setting the kitty free, agents could listen in on nearby conversations undetected. Cats being cats, however, the system proved unreliable.



1970's: Rat concealment device

When it comes to a "dead drop" — a hiding place where spies leave messages — nothing's better (or deader) than a dead rat. Who's going to look inside unless they have to? CIA techs gutted a rat carcass, inserted secret missives wrapped in foil, and then stitched the animal back together. To ward off scavengers, the rodent was often doused in Tabasco.




1975: T-100 subminiature camera watch

A working Seiko timepiece concealed the world's smallest point-and-shoot camera. The device held a 15-inch strip of auto-advancing film and could snap about 100 crisp shots. A quick twist of the watch face revealed a 4-millimeter-diameter lens. It was a successful and widely used spy tool in its day.



1976: Insectothopter

A remotely piloted aerial vehicle disguised as a dragonfly could carry cameras and audio sensors right into the lion's den. This mobile eavesdropping bug never got off the ground.



Monday, May 19, 2008


Taking your laptop into the US?
..Be sure to hide all your data first

Last month a US court ruled that border agents can search your laptop, or any other electronic device, when you're entering the country. They can take your computer and download its entire contents, or keep it for several days. Customs and Border Patrol has not published any rules regarding this practice, and I and others have written a letter to Congress urging it to investigate and regulate this practice.

But the US is not alone. British customs agents search laptops for pornography. And there are reports on the internet of this sort of thing happening at other borders, too. You might not like it, but it's a fact. So how do you protect yourself?

Encrypting your entire hard drive, something you should certainly do for security in case your computer is lost or stolen, won't work here. The border agent is likely to start this whole process with a "please type in your password". Of course you can refuse, but the agent can search you further, detain you longer, refuse you entry into the country and otherwise ruin your day.

You're going to have to hide your data. Set a portion of your hard drive to be encrypted with a different key - even if you also encrypt your entire hard drive - and keep your sensitive data there. Lots of programs allow you to do this.



..read the rest of the article here.

.. try PGP Disk (from pgp.com) or TrueCrypt (truecrypt.org).


Odd Search