Skip to content


Apple's map "errors could prove deadly"

The Australian police have been rescuing people who become stranded after blindly following Apple devices into unfamiliar wilderness and getting lost or stuck. A public warning has been issued to try and help avoid catastrophe:

"If it was a 45-degree day, someone could actually die," Mildura's Local Area Commander Inspector Simon Clemence told state broadcaster ABC.

"It's quite a dangerous situation, so we would be calling for people not to use the new Apple iPhone mapping system if they're travelling from South Australia to Mildura."

Police said at least five vehicles had become stranded in the park after drivers followed directions on their Apple iPhones, some of them after being stranded for up to 24 hours without food or water.

It seems a bit extreme to tell people not to use the system at all. I'd have said use it with extreme caution or use it as a secondary device to local knowledge or recently verified information.

What the Australian incident news I have read fails to mention is that this is a long-standing problem. Not only are map devices prone to error but local authorities have previously warned about people relying on them too much.

I have spoken about this many times when presenting on the security risks of Big Data. Integrity issues of the data that people rely upon are a major problem. Here's the most recent version of a slide from my deck:

The tiny white URL at the bottom of the slide takes you to the story.

Three young women escaped the sinking Mercedes-Benz SUV after the vehicle's GPS directed them down a boat launch and into the Mercer Slough in Bellevue, Washington.

The driver thought she was on a road while following her GPS unit just after midnight, but she was actually heading down the boat launch.

Just last year after a conference in Las Vegas I started driving through the vast desert to the south of Death Valley. I noticed warnings both from Garmin and from law enforcement about over-reliance on any electronic map. The most common problem, they explained at that time, was taking a turn onto a road that no longer (or never) existed and becoming stuck in the sand.

It was true. As I drove down roads narrowed by soft and dangerous shoulders I could see on my map several turns where there was nothing but drifting sand.

The real story is thus that Apple is not doing enough to warn users of the risks of trusting their maps, leaving it up to small and local community budgets to carry the weight of education as well as rescue of outsiders arriving with flawed technology.

And it's not just Apple.

This point was driven home to me (pun not intended) when I watched a Google speaker last week present on the future of big data applications. The presentation painted an almost nauseatingly rosy picture of transportation entirely dependent on their service. It was one of those moments when I knew the security industry was not being integrated enough and there would be a lot of work ahead.

Is there a song called "Let's go everywhere man, only if we can get out again?"

Posted in Security.


MySQL 0-Days: CVE-2012-5611 to 5615

A set of MySQL 0-Day vulnerabilities has been posted on the full-disclosure list with CVEs already assigned, as explained by Red Hat's SRT

So normally for MySQL issues Oracle would assign the CVE #. However in this case we have a bit of a time constraint (it's a weekend and this is blowing up quickly) and the impacts are potentially quite severe. So I've spoken with some other Red Hat SRT members and we feel it is best to get CVE #'s assigned for these issues quickly so we can refer to them properly.

If Oracle security has already assigned CVE's for these please let us and the public know so we can use the correct numbers. Also if Oracle can let the public know which versions of MySQL are affected (e.g. 5.0.x, 5.1.x, 5.5.x, etc.) that would be very helpful to everyone I am sure.

So far it appears from the MariaDB response and update notice (Oracle has yet to respond) that CVE-2012-5611 will be deprecated as a duplicate of CVE-2012-5579 but 5612 and 5614 require patches. 5615, a user disclosure issue, received this response from MariaDB

hardly a 'zeroday' issue, it was known for, like, ten years

And, last but not least, 5613 is a point of configuration.

The MySQL 5.0 Reference Manual Security Guidelines clearly state "Do not grant the FILE privilege to nonadministrative users" but someone may still make that mistake, as demonstrated in this video by Eric Romang

Still no word from Oracle…but MariaDB speculates on their behalf that their next releases shouldn't be vulnerable to the CVE that they know about.

At a time when trust and transparency are more in demand than ever, security lists indicate a continuing trend in what some have described as this:

Oracle's lack of communication regarding the future…

Posted in Security.


Algorithms, DVD CSS and Haiku

My mother dropped off a book for me to read called "Coding Freedom: The Ethics and Aesthetics of Hacking" by Gabriella Coleman.

The section on poetic protest within the chapter "Code is Speech" reminded me of the haiku called

How to decrypt a
DVD, in haiku form
Thanks, Prof. D. S. T.

A quick search for the original text of the poem brought me to an interesting backstory by its author, Seth Schoen:

A strange tradition current among programmers calls for the use of the 5-7-5 pattern — preferably cleverly — to express technology, or jokes about technology, or really anything at all, just for the fun or the challenge of writing within the constraint. I remember particularly that the UC Berkeley Computer Science Undergraduate Association has a mysterious tradition of writing haiku poems about the chemical element zinc. The tradition seemed to start with a 1995 transcript of a conversation in which CS students began to write poems about zinc, but it continued within and without the Berkeley CSUA, and I know that I personally helped spread the tradition to other forums and communities.

[...]

It's clear that the practice of writing 5-7-5 verses and calling them "haiku" seizes on only one aspect of the haiku form and entirely removes it from its original cultural context. I freely admit that my poem has no cultural continuity with the ancient Japanese haiku artform, although I think it has its own sort of literary merit.

Well, maybe if the ancient Japanese had DVD CSS to deal with…but seriously, poetry often can be revealing and controversial through indirect methods. It can be a backdoor of communication on subjects where the front door is sealed. There is perhaps more continuity than Schoen realizes.

Posted in History, Poetry, Security.


Why South Carolina's Governor wants encryption NOW

The leader of an American state is in the news advocating encryption be added to government compliance requirements. She has pointed blame for a serious breach of confidentiality, under her watch, towards her regulators.

Gov. Nikki Haley's remarks on Tuesday came after a report into the breach revealed that 74.7 GB was stolen from computers belonging to South Carolina's Department of Revenue (DOR) after an employee fell victim to a phishing email.

First, her remarks feel slightly off the mark to me. The incident response report released by her office asserts only a correlation between a phishing email and the breach.

The report very cleary states causation was not found.

The malware likely stole the user’s username and password. This theory is based on other facts discovered during the investigation; however, Mandiant was unable to conclusively determine if this is how the user’s credentials were obtained by the attacker.

The news I have seen consistently refers to a case of malware through phishing, even though the IR report warns that it is only "likely."

Beware the difference.

Why does certainty matter so much here? Because encryption has a well-known and significant weakness: an attacker who can compromise credentials needed for decryption still can steal 74.7GB of confidential data. The strength of a safe's walls are far less relevant if a front door is left open.

Second, if an executive passing the blame on to regulators sounds familiar it might be because Heartland's CEO used similar rhetoric.

In the post-Enron environment, the auditors have contracts with clients that essentially absolve them of gross negligence. The false reports we got for 6 years, we have no recourse. No grounds for litigation. That was a stunning thing to learn. In fairness to QSAs, their job is very difficult, but up until this point, we certainly didn't understand the limitations of PCI and the entire assessment process. PCI compliance doesn't mean secure. We and others were declared PCI compliant shortly before the intrusions.

Most people might think Enron was a lesson in detecting executive negligence and fraud. A CEO saying the case centers on "gross negligence" by auditors paints an interesting perspective on management responsibility as well as history.

Consider this brief definition of gross negligence for a physician:

Gross negligence evinces a reckless disregard for the rights of others or smacks of intentional wrongdoing. In other words, gross negligence is an act or omission of an aggravated character, as distinguished from the failure to exercise ordinary care.

Heartland's CEO appears to equate a breach of his systems to this kind of intentional wrongdoing, perhaps even intent to decieve, by those meant to help him assess his compliance with a regulation.

Enron, however, was a very different case. As Time magazine explained in 2002, auditors were found guilty of charges they helped executives of Enron hide risk from the regulators. Executives and auditors were thought to be in cahoots.

Said prosecutor Andrew Weissman: "This is a perfect example of Arthur Andersen sanitizing the record so the SEC would have less information."

It might be useful to also mention that Enron's auditing firm later was found not-guilty and the conviction overturned by unanimous Supreme Court decision (Andersen v. U.S., 04-368).

At trial, Andersen argued that employees who shredded tons of documents followed the policy and there was no intent to thwart the SEC investigation.
[...]
A ruling against Andersen could have had onerous consequences for businesses, whose discarding of files is an everyday occurrence. Experts say companies would have had to keep all files for fear that any disposal, however innocent, could subject them to potential prosecution.

In other words the core Enron lesson has to do with the executives intentionally misleading regulators with the help of those working for them. The Andersen case related to questions of client-independence and retention policies with oversight by regulators. The Heartland CEO characterizes the problem as executives who didn't realize they were comitting fraud rather than asking why no one blew the whistle on Enron executives.

Back to South Carolina's Governor, she was quick to throw mud at her regulators: "This is a new era in time where you can't work with 1970 equipment. You can't go with compliance standards of the federal government." See the whole mud-slinging event here:

What she says is true to some degree, you can't go with compliance standards of the federal government to be safe any more than you can take the South Carolina driving test and assume you will be safe on the road. A fair amount of driver intervention is required.

So if a driver has an accident should we expect them to say "…you can't work with 1970 vehicles. You can't just follow government driving compliance standards…?"

Third, given that (1) encryption isn't a proper solution to the loss of credentials and (2) those in charge at the time of a breach sometimes spin blame onto those who try to guide them, do I agree with a Governor's demand that encryption be added to regulation?

Actually, yes.

I'm obviously pro-regulation for a number of reasons but as I've stated for years encryption is neither difficult nor costly to implement properly. The reasons not to encrypt are fast disappearing, which begs the question of why the Governor wasn't already adopting it. Why did she think she had to wait for regulation by the federal government before she could act?

In 2005 I presented at a conference to card brands and retailers a solution that would allow end-to-end encryption of their customer data.

Although we made great technical progress I will never forget the words of a CFO who reviewed our proposal: "Davi, we don't want to be bleeding edge." That used to be a typical reaction eight years ago and one of the reasons I set out to present to people around the world how to do encryption.

Most recently I ran into this sort of reaction in China, but it seems to have started to wane in America. More and more demand for encryption is starting and regulators have already written it into state laws (e.g. Nevada's 2009 law SB 227 and Massachusetts' 2009 law 201 CMR 17).

And while some states have moved towards explicit encryption, others have implied or suggested encryption laws. Notice, for example, that the 2009 South Carolina breach law offers an encryption safe-harbor clause:

Definition of Personal Information: The first name or first initial and last name in combination with and linked to any one or more of the following data elements that relate to a resident of this State, when the data elements are neither encrypted nor redacted

We can thank California's 2003 SB 1386 for the rise in breach laws and encryption clauses over the past nine years but actually we can thank Heartland for most of the mindset shift after 2008 (more than just coincidence with the timing of encryption laws). In other words, I also will never forget (five years after my presentation on end-to-end encryption for PCI) the CEO of Heartland asking why no one had forced him to spend money on end-to-end encryption.

Heartland Payment Systems, the victim last year of a massive data breach of sensitive card data, vowed after that devastating event to develop new security gear based on end-to-end encryption between itself and its merchants to prevent such a breach from occurring again. That's now taking shape, but slowly.

The fact was no matter how I characterized encryption in terms of a long history of deployment and use (don't get me started on the Roman empire) if the regulators did not demand it now, there were always some executives I consulted with who said they didn't see the "pressure" to do it. There were those who wanted encryption to be so far behind their adoption curve that they could hold up a requirement to prove to their constituents that it was necessary (e.g. low risk to them).

So yes, I think regulators should force South Carolina's Governor to adopt the aging encryption controls because, as with Heartland, some leaders haven't been able to take that step before a breach hits the fan. I also think regulators should demand South Carolina's Governor explain how she will use encryption to protect data if keys to encryption have been stolen (e.g. as described in her incident report).

And try not to look suprised when she asks "What do the requirements say…?"


Updated to add: The IRS apparently has responded with a statement that encryption is required, as reported by WMBF news.

The governor says she's meeting with the state's congressmen to have the IRS require encryption in its standards. But the IRS says that's already on the books.

Unfortunately WMBF has a vague and diplomatic quote from the IRS — no specific requirement is cited.

We have many different systems with a variety of safeguards — including encryption — to protect taxpayer data. The IRS has in a place a robust cyber security of technology, people and processes to monitor IRS systems and networks.

We work closely with the states to ensure the protection of federal tax data. We have a long list of requirements for states to handle and protect federal tax information.

Posted in History, Security.


Aptitude kept back on Ubuntu 12.04

The occaisonal Ubuntu quirks continue. I've received a lot of positive feedback and hits on my other fix posts, and the amazing Nate Lawson said I should keep doing them, so here's another quickie.

I found aptitude failing updates in the GUI (Update Manager) patch cycle, so I switched into terminal to read the output and check what's what.

user@system:~$ sudo apt-get upgrade
Reading package lists... Done
Building dependency tree
Reading state information... Done
The following packages have been kept back:
  aptitude
0 upgraded, 0 newly installed, 0 to remove and 1 not upgraded.
user@system:

The failed package is clearly only "aptitude". More info can be gleaned by looking at the install error for just that package.

user@system:~$ sudo apt-get install aptitude

That command made the system complain about dependency in libapt-pkg4.12.

I checked the update status for libapt-pkg4.12.

The update site showed "Latest version: 0.8.16~exp12ubuntu10.5" from 2012-10-24 18:06:55 UTC. I then checked my system and I still had 0.8.16~exp12ubuntu10.2 (2012-06-15 23:06:45 UTC). Not good. Fortunately I could see 10.2 was the latest security update (CVE-2012-0954 CVSS v2 Base Score:2.6) but the expectation of 10.5 was causing the update error.

Proceed at your own risk but this was the straightforward fix.

  1. Download the latest package, based on architecture:
    wget http://security.ubuntu.com/ubuntu/pool/main/a/apt/libapt-pkg4.12_0.8.16~exp12ubuntu10.5_amd64.deb
  2. Force removal of old package:
    sudo dpkg --force-depends -r libapt-pkg4.12
  3. Install new package you just downloaded in step 1:
    sudo dpkg -i libapt-pkg4.12_0.8.16~exp12ubuntu10.5_amd64.deb

    This can be verified in /var/log/dpkg.log: "status installed libapt-pkg4.12 0.8.16~exp12ubuntu10.5"

  4. Upgrade and see if all dependencies are met:
    sudo apt-get upgrade

It's simple but annoying, especially on a LTS system.

Posted in Security.


Tweets from Gaza

Reporters are rushing into Gaza to report. Their first words are appearing real-time via Twitter. I noticed this Tweet from @erinmcunningham, for example.

I couldn't help but see the raw material perfect for a haiku. With a little editing I came up with this:

Inland from the sea
Just heard #Gaza explosion
Roar of F16s

One of the curious elements of live reporting is that much of it, on its own, is anecdotal and unverified. "I heard an explosion" is like saying "something just happened" and then we end up waiting on details that could never come. Loud unexpected noise is unnerving. Without details the report is what they are feeling more than what may be happening; it is easy to come to various conclusions. Perhaps in the near future the mobile video/audio devices will not only be Tweeting text but also incorporate real-time data on how many db was an explosion, the visual effects, etc.. Until then, poetic interpretation may be the best the public can get when we look for immediate reports.

Posted in Poetry, Security.


Karma and the Winter's Edge

With that video in mind, Fisker recently took the top design award from Fast Company.

The judges praised the design’s boldness. "The Fisker shows what you can do by taking risks in sedan design," says judge Erica Eden, a Femme Den founder at Smart Design, "and that’s really what consumers want."

Risks in sedan design? Soon after recieving their award for "innovation" many Fiskers in NY exploded (due to hurricane Sandy).

We have confidence in the Fisker Karma and safety is our primary concern. While we intend to find the cause as quickly as possible, storm damage has restricted access to the port. We will issue a further statement once the root cause has been determined.

Ooops. Perhaps not what they meant by risky? I say design fail.

I point out the award and the explosion because another finalist in the same competition was a Faraday electric bicycle that weighs only 40 lbs.

We're very excited to announce that the Faraday Porteur has been selected as a finalist for the Fast Company "Innovation By Design" awards, the winner of which will be announced October 16th in NYC.

Now imagine going backwards in time and adding resilience/survivability metrics to the design award criteria for innovation…

Here's my suggestion to Fast Company and Faraday for a new promotion that would resonate in NYC: "Bicycles. They carry you around the city faster then automobiles, they cost a small fraction, and they don't explode." Performance, reliability, affordability. What else do you want?

Porteur

I've written before about the increase in bicycle sales after disasters and the social benefits of cycling. Fast Company really missed an opportunity to recognize the future direction of transportation.

A gasoline automobile gets the award? Really? Not innovative. But giving the award to a $100K gasoline vehicle that increases the risk of failure or injury…?

At least Consumer Reports had some usability perspective in their review of the Fisker.

We buy about 80 cars a year and this is the first time in memory that we have had a car that is undriveable before it has finished our check-in process.

Fast Company should do a retraction. Or maybe that's too risky?

Posted in Energy, Poetry, Security.


Brene Brown: The power of vulnerability

Posted in Security.


Just Say No to Cyber

Bloomberg Businessweek sat down a couple months ago with five security experts including Robert Rodriguez, chairman of the Security Innovation Network and senior adviser to the Chertoff Group. The five were asked questions like "Is it important to determine who’s responsible for security? Is it the seller of the computer, the way that a seller of an automobile is responsible for a level of safety? What’s the alternative?"

An answer from Rodriguez, which built on an answer from Brvenik, recently was brought to my attention.

[SourceFire VP] Brvenik: We can make it harder, we can make it more expensive for the adversary, but they still have entry points. In order to truly solve this problem, we have to educate everybody from the start. Elementary schools should be teaching children before they’re ever online about the risks of it, and safe behaviors and how to identify bad things.

Rodriguez: I totally agree with you. Education, increasing awareness, and starting with a national ad campaign, almost like Nancy Reagan did with “Just Say No to Drugs.” It sounded silly to people in the beginning, but it was highly impactful.

While I am all for user education, I can hardly believe someone would cite Nancy Reagan's program as "highly impactful." I assume he means that in a positive way. I've always considered Reagan's slogan a complete and abject failure due to the emphasis on an inflexible and unthinking response to a complex problem. We might as well tell people to just say no to anything "cyber" because it can cause harm.

Perhaps Michael Hecht, a Penn State professor of crime, law, and justice, put it best:

Critiqued by some for reducing a complex issue to a catch phrase, Reagan's campaign is generally considered to have been unsuccessful, and the phrase "just say no" has become a pop-culture joke.

Hecht makes an interesting point about the slogans that work best and why:

…it is clear from a large body of research that students are more receptive when their peers are involved with delivering the message.

The nuance on these political issues is probably important. While I am for user education I am against a "Just Say No" program. Here's another example: while I am for passenger screening I am against the Chertoff Group lobbying to sell their millimeter wave scanner into airports. I guess I would have given Bloomberg's question a different response. I would agree with Brvenik and Rodriguez on user education but also would have disagreed with them. I would have emphasized don't blame the victim (different from Brvenik), don't be top-down and inflexible in reasoning (different from Rodriguez) and I would have said a reasonable level of liability should be put on manufacturers (more direct answer to the question).

Posted in History, Poetry, Security.


This Day in History: 1962 Cuban Missle Crisis

Two days before October 16th, 1962 an american spy plane taking photos of Cuba recorded the presence of Soviet nuclear missiles. This not only revealed a clear danger but also gaps in American intelligence operations. The missiles posed an immediate threat.

President Kennedy first saw the sobering photos on this day, 50 years ago, which started a series of events that brought the country to the brink of nuclear war. Over the next eight days the US moved towards launching its own missiles, as re-told by veterans of the incident.

"We are very near going to war, you will launch your missile to DEFCON 2," Johnson, 77, [ballistic-missile analyst technician for the 578th Strategic Missile Squadron supported by Dyess Air Force Base] recalled the sound of the alert and then the message to raise the Atlas F-series missile 185-feet to a launchpad and wait for the Defense Condition 1 (DEFCON 1) alert to push the button and send the weapon into a nuclear holocaust.

Kennedy gave a strong stance publicly during the crisis but as we know today he actually resolved the crisis peacefully through compromise; the President led a series of intense and secret diplomatic meetings with the Soviets, the United Nations and other countries. A direct phone line was installed that enabled Kennedy and Khrushchev to talk; through November they worked out how both sides would reduce their arsenal and quit the forward positions.

Foreign Policy refers to the crisis as "The Myth That Screwed Up 50 Years of U.S. Foreign Policy"

American leaders don't like to compromise, and a lingering misunderstanding of those 13 days in October 1962 has a lot to do with it.

In fact, the crisis concluded not with Moscow's unconditional diplomatic whimper, but with mutual concessions.

[...]

For too long, U.S. foreign-policy debates have lionized threats and confrontation and minimized realistic compromise. And yes, to be sure, compromise is not always the answer, and sometimes it's precisely the wrong answer. But policymakers and politicians have to be able to examine it openly and without fear, and measure it against alternatives. Compromises do fail, and presidents can then ratchet up threats or even use force. But they need to remember that the ever steely-eyed JFK found a compromise solution to the Cuban missile crisis — and the compromise worked.

Posted in History, Security.