Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Saturday, October 30, 2010

Thoughts on UPS Suspect Packages Yesterday

Those in the know are saying it’s the work of Al Qaeda in the Arabian Peninsula (AQAP). Suspect packages are still being investigated in Newark, N.J., Philadelphia, Pa., and New York, N.Y., as well as East Midlands, England, and Dubai.

What’s worrisome is that (so far) only one of the suspect packages seems to have had real explosives, and it’s not yet clear that it’s even a viable device. Why is this of concern? Because coming from Yemen, a hotbed of Islamist terrorism and the origin of many recent AQ attacks (successful or otherwise),  they are obviously going to be under much more scrutiny. Any packages coming from Yemen with obviously visible wires, printer toner and white powder will noticed. In that it’s multiple targets simultaneously, that smacks of AQ. Yet there appear to have been no significant resources (personnel, explosives, detonators etc) involved. It’s almost like they wanted these packages to be found. This sounds to me like one of the following scenarios in play:

  • a “we’re still here” psychological operation;
  • a distraction to cover another operation elsewhere;
  • a probe to test reaction times and procedures.


If it’s the first then there’s nothing to be worried about, business as usual. The other two are much more sinister. They indicate a deeper, longer term plan coming to fruition.

So what can we do? Refuse to be terrorised. If we go about business as usual, then we win.

If we allow them to scare us into changing how we live then they win, even if nobody gets hurt.

Posted via email from John's posterous

Friday, July 23, 2010

Scaremongering And General Incoherent Nonsense in Video Piracy\Anti-Terrorism Billboard

Take a look at this:

Have you ever seen such tripe? It's idiotic and Orwellian all at the same time. So much is so wrong here, I don't even know where to start. But I'll try.

"A bomb won't go off here because weeks before the criminal pirating films was caught by monitoring his internet history"(sic)

Leaving aside the terrible punctuation (or lack thereof)*, this is a mishmash of flawed logic, non-sequitors, scaremongering and outright technological ignorance. The only thing missing is a kiddie porn reference and the scaremongering would be complete.

A bomb (not going off, mind you). Illegally copying films. Same person  involved in both. Ergo, illegal copying of films = terrorism, or aiding terrorism. 'kayyyyy......so basically what's being implied here is that anyone ripping or downloading films for personal use is a terrorist. And if they're not, we should monitor their internet usage anyway, just to be sure. And while we're at it, why not everyone else's, too?

Just in case, you know.

I'm willing to grant that there are people in the world who make and distribute illegal copies of films for profit, and that some of them may be involved in unsavoury activities. But really, how many of the people you know actually pay for illegal copies of films? Most people simply download, watch and delete.

And those who are in the illegal distribution-for-profit business will almost certainly know how to cover their tracks. They'll either use a copy bought legitimately and copy it offline (no internet history), or they'll download it using an anonymous proxy server or Tor-type network. It's VERY difficult to track what happens behind the anonymiser. Either way, internet monitoring is not very useful.

So what's going on here? Does increasing internet surveillance on the general public, aided and abetted by a TIPS -type operation REALLY help prevent terrorism? Or does this merely contribute to a paranoid, TERRORISED citizenry, where those encouraging this kind of a society are complicit in aiding the real terrorists by scaring the bejaysus out of the very people they're supposed to protect? 

At best this is a huge waste of time and resources. Bruce Schneier wrote about this a few years back. At worst, it's reminiscent of Stalinist Russia at its worst, with everyone watching everyone else, scared shitless they're going to be the next ones to hear a knock on the door at 4am. Over the top? Maybe. Then again, maybe not.

My guess is that the copyright protection crowd have taken advantage of the 9/11 7/7 paranoia to associate piracy to terrorism, and the security services have gleefully indulged. These days, if you can plant that association you're on to a sure thing. The security services are always happy to have more visibility over what happens on the internet, thank you very much, so everyone's a winner.

Except the public.

Thanks to @crntaylor for the picture on Twitter.

 

*And who wrote that awful phrase? Have they never heard of commas?

 

Posted via email from John's posterous

Thursday, January 14, 2010

Terrorism is extremely rare, so refuse to be terrorised!

 

Great article by the Register concerning the rarity of terrorism and why you shouldn't be terrorised.

http://www.theregister.co.uk/2010/01/08/mutallab_comment/

If we react to any incident with fear and panic, then the instigators will have achieved their aims.Their goals are to disrupt of our way of life, actually killing people is just a means to that end and is a very secondary goal. So even if their attempts to commit mass-murder fail, they still achieve their goals if we overreact, which we inevitably do - every single time. We close the stable door after the horse has bolted, we crank up the colour coded alerts and a hysterical media frenzy whips everyone into a state of, um, well, TERROR! We, (the media, governments and public at large) collectively, are doing their work for them! They must be laughing their arses off when they see how we react on the extremely rare occasion that one of them tries to blow up a plane, even when he screws it up royally.

Via Bruce Schneier

 

Posted via web from John's posterous

Tuesday, January 5, 2010

Update on previous post

Bruce Schneier has a great take on my (and, it seems, every other person's out there) El-Al thinking - it doesn't scale.


http://www.schneier.com/blog/archives/2010/01/adopting_the_is.html

I wonder if there isn't a happy medium between the two, though? Hmm.

My original post:
http://jmahony.posterous.com/attempted-airline-bombing-security-theatre-fr

Posted via email from John's posterous

Monday, December 28, 2009

Attempted airline bombing: Security Theatre, front and centre

Dear oh dear.  So now, in addition to no liquids (unless you bought them in duty free, of course, which is another whole mess), taking your shoes off, no nail clippers, no wrapped packages, no cutlery, no glass (that soda can makes a nice little knife, though), you have to stay seated with no ipod, laptop, camera, or book for the last hour of the flight. Cue hundreds of bored, irate passengers. It seems that the bad guys will only do their bad guy thing at the end of the flight. Silly terrorists, how predictable - they must be really stumped now !

And eventually, someone's going to get stabbed with a pencil (come on, it's gotta happen sometime) and that's it, no more inflight writing materials. Someone gets angry and throws his iphone at a crewmember? No more cellphones on board. Seriously, the way this is going, within five years there'll be no more carry-on luggage, and we'll all be forced to change into jumpsuits before boarding, handcuffed to our seats from gate to gate.These reactive "security" measures are bordering on absurd.

So what to do?

Here's a radical idea: what about observing passenger behaviour before they get on the plane? Look at El-al: probably the biggest target there is for terrorists , and only one successful hijacking since 1968. Is it magic? Hi-tech wizardry? Nope: it's plain ol' police work and human observation, supported by good training. They have a layered approach to security that starts even before check-in. See here for some of their practices:

http://en.wikipedia.org/wiki/El_Al#El_Al_security

So enough with the theatrics already. Put trained observers on the ground both inside and outside the secure area. If this guy Umar Farouk Abdulmutallab had undergone any kind of screening at all by competent persons, he'd have been pulled aside for further questions, and unless he's a highly skilled liar, he'd have been detected, or at least prevented from boarding.

Bruce Schneier's been saying this for years:

http://www.schneier.com/blog/archives/2009/12/separating_expl.html

Posted via web from John's posterous

Friday, December 18, 2009

Twitter Offline, Apparently Due to Compromised DNS records

A group calling itself the Iranian Cyber Army has apparently taken Twitter offline. At the moment it's not clear what happened, but Twitter says it's a DNS attack. From what's been reported so far, Twitter's DNS provider (http://dyn.com) may have been compromised, but seems only to affect twitter for now. It sounds like the perpetrators pointed the name twitter.com to a non-existent IP address. As of now, twitter is still inaccessible (I'm in France).

DNS is the service that associates the name of a computer on the Internet to an IP address so that we humans don't have to remember a long string of numbers to access a website, just its name.


For more information:

http://www.pcworld.com/businesscenter/article/185058/hackers_take_twitter_offline.html
http://status.twitter.com/

Posted via email from John's posterous

Wednesday, December 2, 2009

Computer Laboratory – Technical reports: UCAM-CL-TR-754

A great study on the psychology of being conned, blagged, swindled and scammed and how to avoid it. It was done as a part of a study to investigate the weak link of any security system, the human element. Fascinating reading, and also quite entertaining!

Computer Laboratory – Technical reports: UCAM-CL-TR-754