Slashdot Mirror


Bruce Schneier on What He Knows Best

Over at CSO Magazine there's a wonderful interview with Bruce Schneier, where he talks about cryptography and security. He has several good points, such as the physical security industry versus the IT security camp, and how true security really boils down to people problems. There's some good commentary on post-9/11 airport security regulations as well.

110 comments

  1. Here's a link by Sir+Haxalot · · Score: 1, Informative

    to his website.

    --
    I have over 70 freaks, do you?
    1. Re:Here's a link by Anonymous Coward · · Score: 0

      Thank you, Sir Haxalot, for once again reminding us of your status as "biggest karma whore on Slashdot".

      Seriously, give it a break, man. We can use Google and Google Cache without your help. If you want karma, post something insightful - NOT A DAMN LINK.

    2. Re:Here's a link by Anonymous Coward · · Score: 1, Insightful

      If Slashdotters can use Google, then why is there an Ask Slashdot?

    3. Re:Here's a link by Anonymous Coward · · Score: 0

      Thank you, Sir Haxalot, for once again reminding us of your status as "biggest karma whore on Slashdot". Amen.

    4. Re:Here's a link by Anonymous Coward · · Score: 0

      Here's an even better link.

    5. Re:Here's a link by orthogonal · · Score: 1

      Seriously, give it a break, man. We can use Google and Google Cache without your help. If you want karma, post something insightful - NOT A DAMN LINK.

      Sir Haxalot's posts help me, becaue I have to type with a straw held in my teeth, you insensitive clod!

      --yours sincerely,
      Dr. Stephen Hawking

    6. Re:Here's a link by Anonymous Coward · · Score: 0

      That's right, the poor sod's been trying to gain karma for so long with his captain-obvious links and repost, but he still doesn't get why he hasn't gotten the +1 karma bonus after nearly 350 posts.

    7. Re:Here's a link by Anonymous Coward · · Score: 0

      Amd tou tjink thas bad? try wuth yur feet sonwday ..

      --yoirs suncerly
      Ali Ismail Abbas

    8. Re:Here's a link by Anonymous Coward · · Score: 0

      That's right, the poor sod's been trying to gain karma for so long with his captain-obvious links and repost, but he still doesn't get why he hasn't gotten the +1 karma bonus after nearly 350 posts.
      Actually... I've got the +1 karma bonus several times over, I'm 1 off it again atm.

  2. Welcome ! by Anonymous Coward · · Score: 0

    I, for one, welcome our new secret cryptographic overlords. Oops, I wasn't supposed to tell you about this.

  3. security guarantees by Anonymous Coward · · Score: 0

    If it can possibly lessen the likelihood of a terrorist attack, I'm in full support.

  4. CSO Magazine by cnb · · Score: 2, Funny

    That sounded too much like SCO Magazine :)

    1. Re:CSO Magazine by Anonymous Coward · · Score: 0

      Yes, we have found our intellectual property in obfuscated form in said publication's title. We will unveil a licensing scheme soon for any magazine that infringes on our rights.

      Sincerely, Darl

    2. Re:CSO Magazine by Joel+Carr · · Score: 1

      In related news, SCO sues the CSO Magazine for trademark infringement due the undeniable similarity between the two names and the blatent attempt by the CSO magazine to unlawfully align itself with the SCO Group by using SCO patented methods to similitaneously pump up their stock and destroy their business at the same time.

      In a seperate filing the SCO Group also sued the CSO Magazine for illegally copying SCO IP from the Linux kernel, which is the sole property of SCO. CEO of The SCO Group, Mr Darl McBride, reportedly stated that SCO's Technical Engineers had discovered 3 billion instances of IP theft of the word 'the' used in the CSO Magazine that were blatently copied letter by letter from SCO's Linux kernel. Furthermore, 699 instances of attempted obfuscation had allegedly been detected in which two of the letters of the word 'the' had been reversed in order to spell 'teh'.

      Darl McBride continued by explaining that readers of the CSO Magazine could buy temporary protection from the wrath of the SCO Group by buying a license to possess and read the CSO Magazine for the low price of $3 billion X $699. Readers were urged to take advantage of SCOs generosity now, because in 6 days time, at 6 minutes past 6, readers would be required to pay the full prices of double the amount presently required.

      At a recent SCO Forum, examples of the alleged copying were presented. When quized what relevance the presented examples of 'SCO 0wNz0r j00' and 'All your base are belong to SCO' had to the case, a SCO official stated that SCO owned the IP to both examples and all derivatives there of and that they hoped to slip these into the lawsuit without anyone noticing.

      More news at 6.

      ---

      --
      Any man who can drive safely while kissing a pretty girl is simply not giving the kiss the attention it deserves. -- AE
    3. Re:CSO Magazine by bobv-pillars-net · · Score: 1
      Furthermore, 699 instances of attempted obfuscation had allegedly been detected in which two of the letters of the word 'the' had been reversed in order to spell 'teh'.

      In a countersuit, CSO magazine accuses SCO of violating the DMCA by breaking the encryption used to obfuscate the word 'the'.

      --
      The Web is like Usenet, but
      the elephants are untrained.
  5. Bruce by Anonymous Coward · · Score: 1, Funny

    Paranoia paranoia
    Everybody's coming to get me
    Just say you never met me
    I'm going underground with the moles
    Hear the voices in my head
    I swear to god it sounds like they're snoring
    But if you're bored then you're boring
    The agony and the irony , they're killing me
    I'm not sick but I'm not well
    And I'm so hot cause i'm in hell
    I'm not sick but I'm not well

    1. Re:Bruce by Anonymous Coward · · Score: 0

      That is the poem his mom used to read to him before he went to bed for the evening.

    2. Re:Bruce by Anonymous Coward · · Score: 0

      It's not paranoia when they really are out to get you.

    3. Re:Bruce by lanswitch · · Score: 1
      Just because you are paranoid
      don't mean they're not after you...

      Kurt Cobain.

    4. Re:Bruce by Anonymous Coward · · Score: 0

      Quite how you can attribute a joke my mother used to crack to Kurt Cobain is beyond me. Hero worshipping fuckwit.

    5. Re:Bruce by Anonymous Coward · · Score: 0

      I bet you still obey your mother...
      Does your mother know the meaning of irony? Then ask her to explain it to you.

  6. Post-9/11 by SunPin · · Score: 0, Offtopic

    This is a stupid term. It is now 2003 in case anyone is checking their calendars. Can we come up with a better term than something invented on Fox?

    --
    Laws are for people with no friends.
    1. Re:Post-9/11 by Anonymous Coward · · Score: 0

      How about "current" or "now"?

    2. Re:Post-9/11 by bj8rn · · Score: 1
      It may be stupid [*], but it's bloody catchy. I don't know how to measure the 'goodness' of a term, but if catchy = good, then it's really hard to come up with something better.

      [*] Come on, the day that really changed the world and you call it A NUMBER? All those other days have good names like Bloody Sunday, but a number... It sounds so empty, so devoid of emotions. Or maybe that's why it's used -- to show the world that America wasn't shaken, that the Star Spangled Banner is still waving (is that why the flag found in the ruins of WTC was shown in Salt Lake City?) and so on.

      --
      Hell is not other people; it is yourself. - Ludwig Wittgenstein
    3. Re:Post-9/11 by Anonymous Coward · · Score: 0

      "Post-9/11 is a stupid term... . It is now 2003 in case anyone is checking their calendars. Can we come up with a better term than something invented on Fox?"

      Howabout "post-9.a.m." in memory of the time of day the planes hit?

      It's not the right time for anyone outside the GMT timezone, but then 9/11 isn't the right date for anyone outside america. Middle-endian date format, anyone?

    4. Re:Post-9/11 by Anonymous Coward · · Score: 0

      Absolutely. In the grand scheme of things, 9/11/2001 wasn't that big of a deal anyways.

      -Number of civilians killed? Far more have died in Iraq since the coalition invasion.
      -An attack on the US? Been done before. Pearl Harbor comes to mind.
      Terrorist attacks on the US? Planes have been hijacked and blown up before. US terrorists have attacked their own as well.

      It's time to quit talking about the history of the entire planet as if it were split into 'before and after' a fairly minor event. Get over it folks!

    5. Re:Post-9/11 by Anonymous Coward · · Score: 0

      Yes, I agree.
      It also points out the pathetic way Americans write the date. Least significant number first!
      What kind of endian-ness is that?

    6. Re:Post-9/11 by kiltedtaco · · Score: 1

      The point is that he's refering to something that's changed since that date which I won't mention since it offends you. It doesn't matter how much time has passed since then, it changed alot of security procedures. Since he's refering to those specific changes, post-9/11 is the best term.

    7. Re:Post-9/11 by bj8rn · · Score: 1
      I think you're right, but still you're forgetting something. What was also blown up was the WTC twin towers. You hardly hear about those other buildings that were destroyed, or even the Pentagon (have they rebuilt the part that was damaged?), what everybody talks about is these two towers. Should new buildings be built in their place, or should 'ground zero' (hell, that sounds much worse than 9/11) be turned into a memorial (of what?)?

      These buildings had a great value, if not economical (was there really that big a need for office space when they were built? Right now, there certaintly isn't much need for offices, so why build new towers?) then symbolical -- why else bother attacking them? Many have called the WTC towers the symbols of capitalism, or of America(n). The history of the world may not be split into before and after it, but the history of USA is, at least for some time.

      --
      Hell is not other people; it is yourself. - Ludwig Wittgenstein
    8. Re:Post-9/11 by Anonymous Coward · · Score: 0

      Months are more significant than days. The ISO standard ordering is 2001-09-11. Everyone says "September eleventh", not "the eleventh of September", so why would anyone write 11-09?

    9. Re:Post-9/11 by MCZapf · · Score: 1

      I think people started referring to the attacks using "9/11" because they were not limited to one place, unlike, say, Pearl Harbor [Day]. It was too hard to refer to the events themselves, so they refer to the day.

    10. Re:Post-9/11 by 2short · · Score: 1


      You're actually saying there's no great economic value to office space in lower Manhattan? No one could be that misinformed; I conclude you are entirely uninformed. That is probably the most valuable real estate on the planet.

      While we're at it, "economical" isn't the word you want, and "symbolical" is not a word at all. Try "economic" and "symbolic".

      "... the Pentagon (have they rebuilt the part that was damaged?),"

      Yes.

      "Should new buildings be built in their place..."

      "Should" is subjective. "Will" is a a certainty. I say again: most valuable real estate on the planet.

  7. true security really boils down to people problems by Anonymous Coward · · Score: 0

    it takes an "expert" to tell you this?
    man, I must be better than I thought ..

  8. Physical Security vs. Computer Security by Nerdgasm · · Score: 1

    I often wonder why it has to be this way. Wouldn't it be just as logical to make the two place nice? Perhaps if the two fields worked more closely they could actually learn something off each other.

    1. Re:Physical Security vs. Computer Security by Anonymous Coward · · Score: 0

      The problem is that there is no real way to "make" the two play nice...
      There is too much inertia in the physical-security camp which prevents them from seeing the IT-sec viewpoint...
      There is too much friction in the IT-sec world, which prevents them from making a "good role model" that the physical-sec guys might want to follow...

      It's only people like Bruce Schneier who can cast light on the rift though...

    2. Re:Physical Security vs. Computer Security by abramsh · · Score: 1

      Making physical and IT play nice is hard, but it is getting better every day. There are now even products on the market (ahm.. plug) that can help in this area such as eTrust 20/20

  9. Paranoia rules by Alien54 · · Score: 4, Interesting
    and then there is this article in the Straights Times about the latest thing in spyware on steroids.

    I can see all of the glazed eyeballs out there as you tell folks that they need to learn about firewalls and computer security, etc. Some folks just don't want to be bothered.

    Randon thought - with the decline of things like boot disk viruses, etc, best security most folks can understand is that they are safe so long as they are not on the internet.

    --
    "It is a greater offense to steal men's labor, than their clothes"
    1. Re:Paranoia rules by Scrameustache · · Score: 1

      I can see all of the glazed eyeballs out there as you tell folks that they need to learn about firewalls and computer security

      Well off course, imagine their looks if you told them they had to learn about locks and physicall security!
      All they want to do is buy the lock and not loose the key. That's the problem with computer security: You can't simply buy the lock and try not to forget your password, you need to learn security. Way too much effort for busy people who have other things on their minds.

      --

      You can't take the sky from me...

    2. Re:Paranoia rules by krymsin01 · · Score: 1

      Latest thing? That sounds like NetBus to me. *shrug*

      Face it, people have been breaking security measures since the first one was thought up, and someone is going to come up with a new security measure to try to fix the old one. LOOP.

      The only people benifiting from any of it are the people breaking the security and the people who are paid to come up with the new measures. The rest of us are just left to be vulnerable. Always.

      --
      stuff
  10. "People problems" are the LAST of your worries by JeffTL · · Score: 1

    Whereas I will be flamed into Hades for suggesting, just suggesting, that "Actually, technology usually IS the solution": Social engineering is the least of your worries. Cryptography, authentication et cetera create the need for social engineering: if you leave the computers without passwords and the serviceman's door unlocked, you can't worry about whatever-you're-protecting being unprotected from social engineering, bribery, and whatnot. Y'know why? What industrial spy (as an example) is going to bribe the guards when he can telnet?

    1. Re:"People problems" are the LAST of your worries by spitefulcrow · · Score: 1

      Exactly. Much easier to get a throwaway shell accoutn somewhere to make your accesses less traceable than it is to bribe people to get to the physical equipment. Social engineering is less of a problem because it's harder to carry out without getting caught. Amen to what Schneier says about 'cyberterrorism' hype. I think that instead of trying to prevent these vaguely defined events, people should focus on the other problems with the Net - e.g. script kiddies who get a couple hundred annoying bots set up with IRC trojans. Just a bit of education or some public service announcements to get people to stop downloading e-mail attachments from people they don't know, etc., would probably reduce the number of vulnerable machines available for hackers to compromise. In short, fighting common cybercrime seems more worthwhile to me than preventing 'cyberterrorism.'

      --
      Sorry, my karma just ran over your dogma.
    2. Re:"People problems" are the LAST of your worries by Daniel_Staal · · Score: 1

      Ah, but his point is quite often the computers have passwords, and the serviceman's door is still unlocked. Then someone walks in the door, and in reaction the security people demand blood tests instead of passwords, but still leave the door unlocked.

      What industrial spy is going to bribe the guards when he can telnet? None. But quite often he can't telnet, but he doesn't need to bribe the guards; he can walk in anyway.

      --
      'Sensible' is a curse word.
    3. Re:"People problems" are the LAST of your worries by Anonymous Coward · · Score: 0


      Exactly. Where I work, we replaced an email server with one that had more security: it forced the requirement on the users to use better ie more secure passwords. However, we are no more secure now, and may even be less secure, for two reasons:

      Instead of users being able to remember their password and keep it nowhere but their head, they now need to write it down and put it on a sticky note--usually attached to their monitor, or, if they are clever, under their keyboard. This is difficult to stop.

      Also, just as before, I can call the email administrator and ask to have the password for x user reset to a default. The email admin doesn't authenticate me, however, so really, I could be anybody. She may know my voice, but she gave me the same info when I was new.

      So in defiance of better IT security, we are still susceptible to social engineering.

    4. Re:"People problems" are the LAST of your worries by desitter · · Score: 0

      You are a bit off i'm afraid: technology can only be a solution if applied correctly. Which means first thinking about what problem you are going to solve. Yes is know it sounds pretty basic, but be amazed (be very amazed) at how often this simply isn't done. Of course you should apply technology to achieve some measure of security. The schneierism appropriate is then that technology doesn't magically make your computer more secure: you also have to think about how the security itself is protected: a root password is not secure if tattoed on forehead (or just written down somewhere).

      Think of terms of problems, not solutions

    5. Re:"People problems" are the LAST of your worries by michael_cain · · Score: 1

      I am always entertained by my brother-in-law's tales of the physical security around the critical machines in the Army's command-and-control bunkers in Germany in the late 1980s. He was a civilian contractor doing installation and upgrades of the software written by his company. The computers themselves were physically isolated. The room was under armed guard. The guards never knew their watch schedule more than 24 hours in advance. A small number of people entering or leaving the room were selected at random by some device (the guards could not influence it) for complete strip search. If you were out of touch for 72 hours, your security clearance was canceled (on holidays, he had to check in at a US embassy at least that often).

      As my brother-in-law said, "These people take their paranoia seriously!"

    6. Re:"People problems" are the LAST of your worries by Beryllium+Sphere(tm) · · Score: 1

      Mmm, you do have a point. What happens, though, if you follow your examples backwards through the chain of causation?

      If you have computers without passwords, that's because people didn't put passwords on them. If the serviceman's door is unlocked, it's because the administration didn't make a rule that it should be locked, or because there was a rule but nobody cared about it, or because leaving the door unlocked was the only way to get some other job done.

      In other words, people problems again.

      Thing is, you're right that technology is the solution, but only if the problem is technological. To invert your example, what industrial spy is going to telnet when he can make cold calls posing as a headhunter and get information pre-filtered by helpful humans?

  11. it should be by Alien54 · · Score: 1

    it should be Straits Times - need morning coffee. of course

    --
    "It is a greater offense to steal men's labor, than their clothes"
    1. Re:it should be by Anonymous Coward · · Score: 0

      It's okay. It's Singapore. It's an all-straights christian establishment (or on it's way of becoming one).

  12. one upt? by Anonymous Coward · · Score: 0

    Is it okay to put a "T" in one upsmanship?
    It's a serious question. I saw somebody in the comments on Bruce's article was talking about "one upt" and I'm curious whether that's an acceptable variation on "one up."

    1. Re:one upt? by kfg · · Score: 0, Offtopic

      They meant "upped."

      Relax, phonetic spellings happen.

      KFG

    2. Re:one upt? by Anonymous Coward · · Score: 0

      I've never seen that. It's probably just some clod who didn't know how to spell "one-upped".

  13. Just today ..... by losttoy · · Score: 1

    we changed the admin password of a colleague's Win2k machine who'd forgotten his password. But we also reminded ourselves just how important is physical security.

    1. Re:Just today ..... by pi+eater · · Score: 0

      win2k? people still use that?

      don't click here

  14. Cringely's view on security -- log analysis is key by GringoGoiano · · Score: 5, Interesting

    Cringely put out an article (Changing the Game: How to Save the World by Taking Back Control of Our Data) a week or so back emphasizing security through recording all activity in any given IT infrastructure. Cryptographic techniques may be great, but social engineering, cracked buffer overflows, and short-sighted or stupid actions can always leave some crucial data exposed.

    Rather than throwing your hands up when you've found you've left data exposed, or you've discovered some insider has been poking around documents they shouldn't be looking at, you should be able to track down all access to all information at all layers of your infrastructure. You hopefully can uncover traces of specific incidents, find any other similar unnoticed events that are now part of history, and find the culprits.

    So logging and log analysis are key to securing any site. You need to log:

    • web servers
    • DB access
    • app server use
    • custom applications
    • machine login sessions
    • network events
    • key card access to buildings
    • maybe even disk I/O info
    • ... and many others ...

    ... and you need to do it in a way where you can correlate information from all these disparate sources to uncover patterns of abuse. Cringely mentions that Addamark (he calls them the next "Oracle") is the first company with a viable solution for storing and analyzing the massive logs involved. I've looked at their site, does anybody know anything about this product? Sounds very useful.

  15. Audio Interview by Rabid+Penguin · · Score: 4, Informative

    He also gave an interview on Minnesota Public Radio covering similar topics on September 29. Follow the link for a RealMedia archive.

    1. Re:Audio Interview by Anonymous Coward · · Score: 0

      "How is Congress doing on security?

      I've testified before Congress on several occasions, so they're getting at least some of the right speakers."

  16. hmm.... by pi+eater · · Score: 0

    Behind every great fortune there is a crime

    1. Re:hmm.... by pi+eater · · Score: 0

      behind every great crime there's a great fortune

      don't click here

  17. Re:Cringely's view on security -- log analysis is by pi+eater · · Score: 0

    logging is a good solution, however, it can lead to a slow-down of the services your server provides.

    just a couple weeks ago i started logging our sql server.. somebody was breaking in somehow and i wanted to see if they were able to get into our db.. the entire server froze due to the huge amount of traffic.. win2k couldn't handle it.

    of course that's probably the problem; we are running win2k

    don't click here

  18. Too late is too late by repetty · · Score: 1

    Yeah, logs are good. Prison sentences are good, too. But they are all after the fact.

    For my own part, postmortems aren't nearly as important to me as preventative measures. But that's just me.

    --Richard

    1. Re:Too late is too late by Anonymous Coward · · Score: 0
      For my own part, postmortems aren't nearly as important to me as preventative measures.

      Logs are also useful for other reasons, not directly security-related. I've been asked a number of times to correlate logs to deal with some policy issue.

      For example, someone sends a threatening email using a hotmail account. Hotmail puts the client IP in a header, so I know what machine was used and when. That can then be correlated to login records. That's not enough, however, as someone could have forgot to log out or a password may have been compromised, so that has to be correlated to keycard logs to establish physical presence. This has only happened a couple times, so it's not automated, but it wouldn't have been possible without good logging.

      Or another example would be answering the question "who's the dumbass that deleted this record?" That happens often enough that I now log all DELETEs, UPDATEs and INSERTs where it doesn't hurt performance (and I design most database apps so that DELETEs never happen, but rather records are marked inactive, along with user, timestamp and IP).

      As for improving security: suppose you put all your effort into preventing breaches. When there is a breach, you may not be able to figure out the cause without good logging. This is a very serious problem as you now have a vulnerability that's been exploited and you can't fix it since you don't know what it is.

  19. An example by jjohnson · · Score: 5, Interesting

    I make a weekly trip to put our tape backups into a safety deposit box at a nearby bank. For $35/year, we get bank-level security and convenient off-site storage.

    For the two years I've been doing this, I've had a small, running battle with the president of the branch, who wants to enforce a rule that all use of safety deposit boxes must be done in the booths provided for privacy; presumably, he wants to avoid any appearance of, or liability for, the bank employee knowing what's in my safety deposit box. However, switching the tapes in the box can be done in 5 seconds right there, whereas taking a booth makes it a 2 minute affair. The tellers all know me, so they let me do it right there, except for the couple weeks after a stern policy memo has been issued.

    The reason I don't sacrifice another 1 minute, 55 seconds, is because I don't care that the tellers know--they'd figure something out with my weekly trips anyway. But the real crux is that, putting the tape backups into a safety deposit box makes it one of the strongest links in the security chain. The server room door is always locked, the servers logged off, etc. The weakest link now is that a competitor would offer one of my employees $20,000 to sneak the tape backups out one night. In comparison, the cost of breaking into a safety deposit box, removing the tapes, and returning them after copying, all undetectably, would be in the hundreds of thousands of dollars, if it could be done at all. They can't bribe a teller because the bank has only one of two keys for my box--when I've forgotten my key, I'm SOL.

    This is what Schneier means by system security. Insisting on me using a booth is like upgrading your encryption when users are writing their passwords on stickies attached to their monitors.

    --
    Anyone who loves or hates any language, platform, or manufacturer, doesn't know what they're talking about.
    1. Re:An example by asdfghjklqwertyuiop · · Score: 1

      Insisting on me using a booth is like upgrading your encryption when users are writing their passwords on stickies attached to their monitors.

      Isn't that the truth. Years ago a place I worked had a machine on the DMZ script-kiddied. One of my bosses then insisted that we set up a password policy on the win2k domain behind the firewall (which was unaffected by the incident, that's the whole point of a DMZ). The password policy required "strong" passwords - varying case, numbers, puntuation, minumum length... so now the vast majority of all users in the company keep their passwords on a sticky note on the monitor because they can't remember them.

    2. Re:An example by Anonymous Coward · · Score: 0

      I hope you're not relying on offsite storage at a "nearby bank" for disaster recovery purposes. Think about it.

    3. Re:An example by fm6 · · Score: 2, Insightful
      Insisting on me using a booth is like upgrading your encryption when users are writing their passwords on stickies attached to their monitors.
      Or like most banks' online transactions, which are encrypted by the maximum key length supported by non-export browsers, but makes no attempt to make its users use high-entropy passwords to access that encrypted data. My own bank just uses my ATM PIN, which only has 10,000 possible values!

      Most security measures serve to make people feel more secure, not make them safer. As witness the Maginot Line and the NRA.

      Though it does occur to me that a bank might have non-security reasons for insisting that safe-deposit boxes be accessed privately. Many boxes contain contraband, "dirty" money, and other stuff the bank works very hard at not knowing about. If they get in legal hot water, they can point at their see-no-evil policies as evidence of their non-complicity.

  20. Without even reading the article ... by BillsPetMonkey · · Score: 1

    ( ... hey I never do anyway!) can I guess that Bruce says something like:

    "Technological solutions don't work for human problems. 9/11, Bush, P2P vs. RIAA are human problems. Cryptography can't help you here either, so look elsewhere. "

    Just a hunch.

    --
    "It's not your information. It's information about you" - John Ford, Vice President, Equifax
    1. Re:Without even reading the article ... by swordgeek · · Score: 1

      yep, that's about right. That's what Bruce always says.

      The thing is, he's right. And he's determined to get his point across, so he's going to keep saying it until people start listening.

      --

      "People who do stupid things with hazardous materials often die." -- Jim Davidson on alt.folklore.urban
  21. On other hand, by Anonymous Coward · · Score: 0

    After read this article, it lead me to believes that how half-life game being stolen by someone when software developer forgot to locked his door. Somehow the cleaner(who love the game), or anyone, got in and stole it.

    Or Social engineering:

    You take half-life developer to bar and hopefully he reveal his secret to those people. :)

    No wonder, Physical security problem. not computer security problem. :)

  22. Re:Cringely's view on security -- log analysis is by blibbleblobble · · Score: 2, Funny

    "You need to log:... disk I/O"

    Isn't that recursive?

    I just want to put on file that I put on file that I put on file that I put on file that I put on file that I put on file that I saw somebody read a file on disk. Damn, now I need to report myself.

  23. Well I'd just like to say... by Anonymous Coward · · Score: 0

    I thought Jaws and Seaquest DSV were pretty cool. I had no idea he was a security expert too. Wow, these Hollywood people sure keep it quiet...

  24. Forensic investigation matters more than you think by GringoGoiano · · Score: 1

    Mr. Schneier contrasts problems of physical security with IT security throughout his article and emphasizes that in both domains criminals and terrorists will, at times, hit their mark. (He also implies losses to crime are greater than losses to terror, and that society emphasizes the terror while neglecting sensible countermeasures to crime -- but that's beside the point I want to make here).

    In the physical world criminals always leaves tracks. Fingerprints, footprints, bodily fluids, DNA, personal effects, the air they breathe, traces from tools of their trade, etc. Sometimes the criminal is smart and leaves so few of these clues, or they're so undetectable or indistinguishable from the background (e.g., the air they breathe) that they get away. But at least in the physical world forensic experts can resort to physical evidence to track down the perps and extract justice or revenge.

    Mr. Schneier complains that the physical security types take ineffective measures to prevent damage in the physical world and could learn a thing or two about mitigating risk from the IT community. (Confiscating those nail clippers from grandma isn't going to prevent a hijacking!) But I think Mr. Schneier is short-sighted too, and the IT security people haven't learned yet that gathering evidence in the electronic world is key! You need to lay down the dust to track electronic footprints through the network. Your electronic gated community isn't going to keep out everyone, and logs are the dust in which cybercriminals leave their footprints! If you don't collect and analyze your logs, you're just left with 500,000 stolen credit card/social security numbers and the air they breathed.

  25. Dear 9/11 by Letter · · Score: 0
    Dear 9/11,

    It has come to our attention that your moniker is valid only in the United States. The rest of the world properly refers to September 11th as 11/9. Not quite as catchy, huh? Be glad that you exist only in the United States.

    American,
    Gladiator

    P.S. The 911 emergency response service will see you in court soon!

    1. Re:Dear 9/11 by Anonymous Coward · · Score: 0
      Wwll, don't you think it's time that all you non-Americans begin to conform?

      and what's this with the metric system. It never made any sense. I mean, the length of the king's arm is something we should standardize on! Just because you have 10 fingers (and not everyone does!) why must you insist that every measurement be a multiple of 10? Kill-a-meter? Isn't that kind of mean?

      and why do you all have to have your own time zones. The time in New York City and Washington DC *IS* the correct time. After all, it IS called Eastern STANDARD time. Why can't you standardize?? Darn Europeans (and the rest of you) are all so ego-centric and self-centered. I'm not sure if we'll ever let you become states.

  26. Re:Cringely's view on security -- log analysis is by Agent+Green · · Score: 3, Interesting

    And the best quote on the article regarding those kinds of databases:

    "Definitely. Terrorism is rare, while crime is common. Security systems that require massive databases in order to function--TIA, CAPPS 2--will make crime easier. They'll make identity theft easier. They'll make illegal government surveillance easier. They'll make it more likely that rogue employees of the governments and corporations that maintain the systems will use the data for their own purposes. In the United States, there isn't a government database that hasn't been misused by the very people entrusted with keeping its information safe. IRS employees have perused the tax records of celebrities and friends. State employees have sold driving records to private investigators. This kind of thing happens all the time."

    --
    // Agent Green (Ian / IU7 / KB1JQO)
    // IEEE 802.3: All 10base Are Belong To Us
  27. MOD PARENT DOWN!!!!! by Anonymous Coward · · Score: 0

    Parent is a known troll who uses his karma to post trolls and flamebait at +2.

  28. Ummm by Neon_Mango · · Score: 2, Insightful

    Ok so lots of valuable company data is moved from your facility to a bank by an employee on a weekly basis? I think the weakest link in the chain is you. I'm just saying what's to stop someone from taking the tapes from you in transit? Sure the bank has good security (cameras, security guards, a vault), and your company most likely has good security too but when your in transit couldn't someone stop you and take the tapes from you (by force if needed)? Just out of curiosity are there any backup software packages (like something made by Veritas or Computer Associates) that will not only compress data before backup but also encrypt it?

    1. Re:Ummm by tyen · · Score: 1

      ...but when your in transit couldn't someone stop you and take the tapes from you (by force if needed)?

      My associates Mr. Smith and Mr. Wesson will be pleased to make the acquaintance of that someone. Actually, I conceal carry a .45 ACP manufactured by a company called Kimber, but few Slashdotter's would recognize that name. I'm one of the principals of the company, so carrying concealed at the office is condoned.

    2. Re:Ummm by jjohnson · · Score: 1

      I'm the one who makes the switch every week, unless I'm unavailabe, in which case it's the sysadmin.

      You're sort of right, but not really due to the particular circumstances. The bank is a ten minute drive through a semi-rural/industrial setting, down major roads with lots of cops who don't have much to do. A carjacking is unlikely in the extreme.

      Also, there's just the fact that, since we're a manufacturer of commodity housewares, where industrial espionage itself isn't terribly useful, the risk of an attempt is pretty low. If the tapes I was carrying were for Dow Chemical, it would seem more likely.

      I'm not aware of any encrypting backup packages.

      --
      Anyone who loves or hates any language, platform, or manufacturer, doesn't know what they're talking about.
    3. Re:Ummm by 2short · · Score: 1


      So, someone wanting your data badly enough to take it by force can still take it. But you've ensured that they have to kill you in the bargain. Good thinking.

    4. Re:Ummm by Anonymous Coward · · Score: 0

      Isn't it an offence to carry a concealed weapon?

    5. Re:Ummm by tyen · · Score: 1

      If your data is that sensitive that you can conceive of someone killing to get at it, you hire pros to transport it. There are professional courier services that work with this kind of risk, though they are expensive. Otherwise, life is full of risk, deal with it and move on or continue to cower and whimper on your knees.

    6. Re:Ummm by tyen · · Score: 1

      Carrying concealed is allowed in select states in the United States, provided an individual goes through a licensing process that is renewed every few years. Very irritating that we have to ask the Leviathan Government permission to defend ourselves, but a minor nit compared with some of the grosser violations of our freedoms that are more important to roll back.

    7. Re:Ummm by 2short · · Score: 1

      I quite agree. The point I was trying to make was this:
      Without disputing your right to have a loaded firearm about your person, I don't think it's a very smart way to mitigate the risk of someone stealing your data; or a very smart way to mitigate almost any risk for that matter. Unless you're in law enforcement or the army, the risk from being armed (accident, escalation of otherwise non-fatal assault, etc.) far outweighs the very small chance that being armed will actually be helpful.
      I understand that life is full of risks, and I don't cower in fear. I go where I want and do what I want. But I don't increase my risk in order to feel a false sense of security or machismo by carrying a firearm. I've never been in a situation where, in hindsight, I've wished I had a gun. Nor do I expect to ever be in such a situation. I have been in a couple situations where, in hindsight, I'm quite thankful I didn't have a gun.

  29. CSO has a magazine? by HiggsBison · · Score: 1
    And why would the Chicago Symphony Orchestra be interested in Bruce Schneier's views on security and such? A better way to keep a Stradavarius safe?

    (No, I didn't RTFA. Why do you ask?)

    --
    My other car is a 1984 Nark Avenger.
  30. stupidsecurity.com has been slashdotted! by Anonymous Coward · · Score: 0

    Stupidsecurity.com, linked to from within the article, has been slashdotted. This proves that slashdotters *do* read articles after all!

    1. Re:stupidsecurity.com has been slashdotted! by hugesmile · · Score: 1

      I wouldn't assume that a misbehaving system is due to slashdotting. My buddy's hard drive HAPPENED to crash on 1/1/2000 (hey, someone's had to). He blamed it on Y2K. Maybe it was slashdotted too. Sorry, non-Americans, when I referred to 1/1, to y'all, that would be reversed... 1/1, that is.

  31. SCO Magazine by Anonymous Coward · · Score: 0

    SCO magazine - your impartial word of reason in the world of Linux/Unix controversy. Subscribe today!

  32. This is the guy.... by Anonymous Coward · · Score: 0

    This is the guy who, after the last Windows worm, said that maybe it's time that internet users should have to have a license. Was he joking? The journalists certainly wasn't.

  33. You are only as secure as your weakest link. by Anonymous Coward · · Score: 0

    You are only as secure as your weakest link.
    and your weakest link is normally a human being.

    Some cryptography can't be cracked in a reasonable time-frame.

    Humans can be.
    and some, quite easily.

  34. vested interests by Anonymous Coward · · Score: 0

    these people make a living off bugs and flaws. if they say "security in Windows 2023 is tight" then thats symantec and friends out of work. this guy wont be selling books to anyone - yeah there will always be bugs but if they stop being headline news budgets and thinking moves to other things. its in their interest to create percieved problems and / or hype things, make sure security stays a headline.

    how many times was 9/11 mentioned in that article, what has crashing planes into a building got specifically todo with *computer security* ? nothing. it makes a great headline and great headlines mean companies get scared, idiot ctos follow the hype and the same people making a living off complaining and saying they can fix security make big money. catch 22.

    The classic is Verisign and root servers. "Imagine cyberterrorists knocking them all over !!!" (cyberterrorists aka 13 yr old kid but it doesnt sound "cool"). Are they a charity who are really concerned or rather want control and the money and power that comes with it ? Take a wild frickin guess. Of course the usual idiots jump on board predicting world ending disasters and link it to 9/11. Oh and the "experts" who make the comments and predictions also work for a . always.

  35. Bruce at CIS by Anonymous Coward · · Score: 0

    Bruce Schneier will be speaking (along with many other security experts) at the Stanford Center for Internet and Society's CyberSecurity conference this Nov. 22nd.

    More info here.

  36. FleshNet by TooTechy · · Score: 1

    It just popped into my head. It has to be...

    FLESHNET

  37. But, Slashdot always says... by t0ny · · Score: 1
    People are the biggest problem? Everyone on Slashdot always says its Microsoft...

    Does this mean they arent really the experts they pretend to be? Im confused.

    --

    Manipulate the moderator system! Mod someone as "overrated" today.

  38. What about Bruce Schneier's thoughts on by Anonymous Coward · · Score: 0

    dog grooming? Is he for it or against it?
    Or what about that 300,000,000 year old purple donut frog they just found recently?

  39. CSO? by IGnatius+T+Foobar · · Score: 1

    CSO?

    Aren't they the people who are trying to stamp out Lniux with a bunch of frivolous lwasuits?

    Dyslexic lawyers of the world, untie!

    --
    Tired of FB/Google censorship? Visit UNCENSORED!
  40. This is the greatest post ever: by Anonymous Coward · · Score: 0

    Lovely anchorage and the Schneier generally doesn't have the wherewithall to enforce the no slashdot linkage laws.
    And finally to some lot somewhere concluding our very gay tour please exit through the gift shop you fat stupid cocksucker.

  41. Re:Cringely's view on security -- log analysis is by Anonymous Coward · · Score: 0

    I've looked at their site, does anybody know anything about this product? Sounds very useful. Yes they have an excellent product and I haven't seen a single other company that can scale to the huge logging levels this one can, or for as cheaply. After learning about Addmark, it seems obvious that any log solution that uses a traditional RDBMS as a backend cannot possibly be as cheap or fast as their solution.

  42. Okay.. but you are getting off topic. by mindstrm · · Score: 1

    You started by saying that your secuurity is pretty good, and giving us a breakdown.. now you claim you aren't the weak link, because who would want the tapes?

    That doesn't change the fact that you are the weak link.

    Also, the bank manager has a very good, and valid, point. Wheras you see convenience, he sees the possibility of a complaint down the road, and heck, bank protocol wasn't followed; the employees had information they should not have, which makes them more suspect.

    1. Re:Okay.. but you are getting off topic. by jjohnson · · Score: 1

      I think that the weakest link is one of the employees in the I.S. department (myself included) being bribed to sneak the tapes out. What I was disagreeing with was your characterization of my transporting the tapes as being the weak link. While I can see a competitor laying out for a bribe, I can't see one organizing a carjacking, which would be much more expensive, more risky, and less useful, since we'd know the tapes were gone. What I was disagreeing with was the attack vector you proposed.

      My point about the tapes being less than valuable to our competitors is part of my assessment of our security risks. If we were developing weapons systems for the military, it would be plausible for one of our competitors to kidnap me en route. As a manufacturer of commodity housewares, though, I think that the tapes have a limited value that serves to discount certain scenarios. Bribery to make a secret copy of the tapes is plausible. Killing me (or risking it) to get the tapes isn't.

      --
      Anyone who loves or hates any language, platform, or manufacturer, doesn't know what they're talking about.
  43. PIn is safe. by mindstrm · · Score: 1

    You are mixing up two things here. Yes, a PIN is easy to brute-force, if the system will allow you to do it. Most will not; after a few wrong attempts, your account is locked. What are the odds of guessing the right 4 digit pin if you only get five attempts?

    You don't need a high entropy password if it's not possible to brute-force against the system.

    Many banks insist that they KNOW what is in a safe deposit box, so you don't put, say, things that could explode, or start a fire, in them. That's not to say they know the exact contents, but they often supervise. I think maybe you watch too much TV if you think banks have safe deposit boxes full of "dirty" money. (though no doubt there is some out there)