The Schelling Game

At the Shmoocon conference, a vendor (“Breach Intelligence”) is putting a card in ever schwag bag with an “IoC”. The game works by giving everyone a different IoC, in pairs. If you find your matching IoC and come to their booth, they’ll give you a free quadcopter.

This is like the “Schelling Point“, a question in game theory. You are supposed to meet somebody New York City, but neither of you have been told where to meet. So where do you go? The trick is to estimate the most logical place that the other person, using the same information as you, would make. Most people agree that the answer is the “information booth at Grand Central Station”.
So how do you find your matching IoC to win the prize? One guy is walking around asking strangers to match cards. That’s useful, because a lot of people who don’t want to play the game simply give him their cards, so he’s got an ever expanding list of possible matches.
My solution is to tweet the IoC, and of course, blog about it:
455f8979143415b9eed0e0d6fc153c1c

— Rob Frosty Graham ❄️ (@ErrataRob) January 15, 2016

If my partner searches Twitter, they will find it. That’s because Twitter’s search engine is instantaneous. Google, on the other hand, will take a few days before they’ll find this page and index it, by which time either Shmoocon will be over, or the vendor will have run out of prizes.
At first I tweeted that number bare, because my partner has only to search it to find me. But it hides the purpose so that others don’t get on to the trick, find their matches, and exhaust the prizes. But that doesn’t work, because the logic applies to my partner as well. So instead, I want to publicize the technique widely, 
So, should my partner choose to find me, then searching on Twitter or (in time) Google should be possible. Sadly, though, I hear they’ve already run out of quadcopters.
BTW, an IoC, or “indicator of compromise” is a checksum or pattern that was retrieved in analyzing a breach, which can then maybe used to detect similar breaches elsewhere. It’s the thing that OmniCISA was designed to share. These are IoC of real attacks. If you google the number on your card, not only may you find your partner, you may also find the original virus or attack that the IoC applies to on a website.

Continue reading The Schelling Game

Posted in Uncategorized

Mythical vuln-disclosure program

In the olden days (the 1990s), we security people would try to do the “right thing” and notify companies about the security vulnerabilities we’d find. It was possible then, because the “Internet” team was a small part of the company. Contacting the “webmaster” was a straightforward process — indeed their email address was often on the webpage. Whatever the problem, you could quickly get routed to the person responsible for fixing it.

Today, the Internet suffuses everything companies do. There is no one person responsible. If companies haven’t setup a disclosure policy (such as an email account “security@example.com”), they simply cannot handle disclosure. Assuming you could tell everyone in the company about the problem, from the CEO on down to the sysadmins and developers, you still won’t have found the right person to tell — because such a person doesn’t exist. There’s simply no process for dealing with the issue.

I point this out in response to the following Twitter discussion:

@KimZetter true. hey @tactical_intel I can connect you… CC: @ErrataRob

— ❄∵ Joshua Corman ∵❄ (@joshcorman) January 5, 2016

Josh’s assertion is wrong. There is nobody at American Airlines that can handle a bug report. At some point, a product management team is going to have to prioritize fixing this bug compared to other features they want to implement, and they’ll likely convince themselves that this bug isn’t important, and it won’t get fixed.

Josh is imagining that somebody at American Airlines has both the competence and authority to handle such a bug. But if that were true, then they’d already have a vuln-disclosure program, and emails sent to “security@aa.com” would get answered. In other words, Josh is asserting that they do handle vulnerability reports — but using a super-secret process that nobody knows about.

Large companies all deal with risk the same way. It doesn’t matter if the risk is hackers, or an implosion in the housing market, or the explosion of oil refineries. The first look at “best practices”, what their peers/competitors in the industry do. The second is they’ll respond to bad things that happen to them.

In other words, the only way American Airlines will get a vuln-disclosure/bug-bounty program is (1) if many other airlines create such programs, or (2) they get bitten hard by a vulnerability.

So far, United Airlines is the leader, having created a bug-bounty program that has reward security researchers millions of frequent-flyer miles in rewards. Other airlines will eventually catch up. In the meanwhile, the only way for American Airlines to respond to a vuln is for the bug to be reported on a full-dislosure mailing list. This will either cause people in the company to panic, and therefore fix the bug before it bites them. Or, hackers will exploit the bug, and cause millions of dollars of damage. Either way, it’s how American Airlines decided to do business, how they chose to respond to risk.

…and I’m not saying this because I want to be mean to the company. I don’t even think it’s a wrong way of doing business. Sure, it sounds bad relative to the risks I understand (hacking), but it’s the only way I know how to handle other risks. Waiting to be bitten by a risk is often a better strategy than trying to anticipate all possible unknown risks. Continue reading Mythical vuln-disclosure program

Posted in Uncategorized

Trump is right about "schlong"

The reason Trump is winning is because the attacks against him are unfair. The recent schlong-gate is a great example.

Yes, “schlong” means “penis”, but is also means “rubber hose“. Getting beaten by a rubber hose has long been a severe way of beating somebody. Getting “schlonged” has long meant getting a severe beating with absolutely no sexual connotation. Sure, you may never heard of this slang, because it’s very regional, but it does exist. Fact checkers have gone back and found many uses of this word to mean just that [1] [2] [3] [4] [5], meaning “severe beating” in a non-sexual sense.

We regularly use words like hosed, shafted, stiffed, chapped, and boned to mean something similar. Sure, some of these derive from a base word for “penis”, but are commonly used these days without any sexual or derogatory connotation. The only different about “schlonged” is that most Americans were unfamiliar with the idiom. Had Trump said “shafted” instead, this controversy would not have erupted.

But those who hate Trump, and who have only known “schlong” to mean something dirty and derogatory, are unwilling to let go of their hate. They are unwilling to believe that Trump’s use of the word in relationship to Hillary is anything but sexist. No amount of citing people from that region saying “I use the word without particular sexual connotation” will ever convince them otherwise. They’ve never been to that region, never used “schlonged”, but now they are experts on exactly what connotations that word has.
And that’s why his populist demagoguery is winning. In recent years, every worker in America has been subjected to repeated rounds of sensitivity and political-correctness training, making them feel they are already guilty of racism and sexism before anything has occurred. They watch as either they, or their friends, get in trouble for transgressions just like this, innocent, yet unable to defend themselves. And women and non-whites are just as pissed off.
It’s like my friend who calls himself a “cheap Chinaman”, because he is Chinese and cheap, just like all his Chinese friends and neighbors. Off to HR he goes for re-education.
Or it’s like another co-worker, who said “fair people should only breed with their own kind”, to a black co-worker. She was talking about the Renaissance Fair, whose members (“fair people”) are hopelessly nerdy and out-of-touch like herself. But that doesn’t matter, of to HR she goes for re-education!
Or, it’s like another friend, who grew up on an Indian reservation. His first schoolyard fight was because a kid called him “white”, which was the worst possible insult. When his parents sent him up to his room without dinner as punishment, he overheard is parents say “should we tell him?”, because in fact his mother was indeed mostly white. His identity is American Indian (of the Lumbee tribe), but he looks white enough, so when he challenges his new hire indoctrination about overcoming his white privilege, off to HR for re-education he goes!
None of these three examples are white-males. Everyone feels stifled by this political correctness overreach. When they see Trump confront his bullies boldly, not backing down, he becomes a hero.
Yes, in the end, Trump is a tad racist, and his populist demagoguery borders on fascism. But if he wins, it’s not the racism of white-males that will have made it so. It will be the patently unfair hate and bigotry of the left-wing that will have made it so.


Update: Words sounding like “schlang” mean “hose” in a wide variety of European languages, such as шланг (shlang) in Russian, slang in Swedish and Dutch, slange in Danish, შლანგი (shlangi) in Georgian. European “ethnic” areas, like where Trump grew up, use the word to mean “hose”. I’m mostly ethnically German. As far back as I can remember, “schlong” has always meant penis in the same way that “hose” has meant penis.


Update: The WaPo reference above is a perfect example of the left-wing bias the media aimed at Trump. It cites a previous non-sexual example of the term “schlonged”, and then insists without citing any evidence that the term must have a sexual meaning.


Update: Suppressing regional and ethnic idioms because you’ve never heard of them is, of course, a form of bigotry and racism.

Continue reading Trump is right about "schlong"

Posted in Uncategorized

Where do bitcoins go when you die? (sci-fi)

A cyberpunk writer asks this, so I thought I’d answer it:

Plotpoint query: Someone has some bitcoins, nobody knows, they die, leave no will, have no heirs, what happens to the bitcoins?

— William Gibson (@GreatDismal) December 18, 2015

Note that it’s asked in a legal framework, about “wills” and “heirs”, but law isn’t the concern. Instead, the question is:

What happens to the bitcoins if you don’t pass on the wallet and password?

Presumably, your heirs will inherit your computer, and if they scan it, they’ll find your bitcoin wallet. But the wallet is encrypted, and the password is usually not written down anywhere, but memorized by the owner. Without the password, they can do nothing with the wallet.

Now, they could “crack” the password. Half the population will choose easy-to-remember passwords, which means that anybody can crack them. Many, though, will choose complex passwords that essentially mean nobody can crack them.

As a science-fiction writer, you might make up a new technology for cracking passwords. For example, “quantum computers” are becoming scary real scary fast. But here’s the thing: any technology that makes it easy to crack this password also makes it easy to crack all of bitcoin to begin with.

But let’s go back a moment and look at how bitcoin precisely works. Sci-fi writers imagine future currency as something that exchanged between two devices, such as me holding up my phone to yours, and some data is exchanged. The “coins” are data that exist on one device, that then flow to another device.

This actually doesn’t work, because of the “double spending” problem. Unlike real coins, data can be copied. Any data I have on a device that I give to you, I can also keep, and then spend a second time to give to somebody else.

The solution is a ledger. When my phone squirts coins to your phones, both our phones contact the bank and inform it of the transfer. The bank then debits my account and credits yours. And that’s how your credit card works with the “chip and pin”. It’s actually a small computer on the credit card that verifies a transaction, and then your bank records that transaction in a ledger, debiting your account.

Bitcoin is simply that ledger, but without banks. It’s a public ledger, known as the blockchain.

The point is that you don’t have any bitcoins yourself. Instead, there is an entry in the public-ledger/blockchain that says you have bitcoins.

What’s in a bitcoin wallet is not any bitcoins, but the secret crypto keys that control the associated entries in the public ledger. Only the person with the private key can add a transaction to the public-ledger/blockchain reassigning those bitcoins to somebody else. Such a private key looks something like:

E9873D79C6D87DC0FB6A5778633389F4453213303DA61F20BD67FC233AA33262

Without this key, the associated entries in the blockchain become stale. There’s no way to create new entries passing bitcoins to somebody else. If somebody dies without passing this key to somebody else, then the bitcoins essentially die with them.

In theory, somebody can memorize their private key, but in practice, nobody does. Instead, they put this into a file, and then encrypt the file with a password that’s more easily memorized. For example, they might use as their password the first line of text from Neuromancer. It’s long and hard to guess, but yet something that is either easily memorized, of if forgotten, easily recovered. In other words, the password (or passphrase in this case) to encrypt the file containing the private key might be:

The sky above the port was the color of television, tuned to a dead channel.

So now our deceased has to pass on both the wallet file and the password that will decrypt the wallet. Presumably, though, the deceased’s heirs will find the computer and the wallet, so practically the only problem becomes cracking the password.

Cracking is an exponential problem. The trope in sci-fi is to wave aside this problem and “reroute the encryptions”, and instantly decrypt such things, but in the real world, it’s a lot harder. Passwords become exponentially harder to crack the longer they are.

The classic story here is that of a knave who plays chess with a king. The king tells his opponent that he can have anything he wants within reason should he win. The knave chooses this as his prize: one grain of rice for the first square, two for the second, four grains of rice for the third square, and so on, doubling each time for all 64 squares on the chessboard. The king, thinking this to be a minor amount, agrees. When the knave wins, the king finds he cannot payoff the winnings — because of exponential growth.

The first ten squares have the following number of rice grains:

1 2 4 8 16 32 64 128 256 512

This is 1024 grains of rice in total. Using ‘k’ to mean ‘a thousand’ (kilo-grains), the next 10 squares look like this:

1k 2k 4k 8k 16k 32k 64k 128k 256k 512k

This is about a million grains of rice. Using ‘m’ to mean ‘a million’ (mega-grains of rice), the next 10 squares look like this:

1m 2m 4m 8m 16m 32m 64m 128m 256k 512m

This is about a billion grains of rice. The next 10 squares becomes a trillion gains of rice, and we are only 40 out of 64 squares.

As the Wikipedia article discusses, filling the chessboard requires a heap of rice larger than Mt. Everest in rice, or a thousand years at the current rate of growing rice.

One ending of this story is that the knave gets the daughter in marriage and half the kingdom. In the other version of this story, the king beheads the knave for his impudence.

The same applies to password cracking. Short passwords are easily cracked. Because of exponential growth, long passwords becoming impossible to track, even at sci-fi levels of imagined technology. If such a magic technology existed, then it would defeat the underlying cryptography of the blockchain as well — if you could crack the password encrypting the key, you could just crack the key. If you could do that, then you could steal everyone’s bitcoins, not just the deceased’s.

In the above example, the sci-fi writer in question imagines an artificial intelligence that, in order to make money, tracks down dead people and harvests all the bitcoins they haven’t passed on. This can’t be done by harvesting the blockchain — it’d need the private keys.

One way that this might happen is that for the AI to own a company that recycles computers. Before recycling, it automatically scans them for such files. While it can’t break the encryption normally, some large percentage of people choose weak passwords. Also, the AI might know some tricks that make it smarter at figuring out how people choose passwords. It still won’t crack everything, but even cracking half the possible coins would lead to a good amount of income.

Or, let’s tackle this problem from another angle, a legal angle. One of the hot topics these days is something known as “crypto backdoors”. The police claim (erroneously in my opinion) that such unbreakable encryption prevents them from investigating some crimes, because even when they have a warrant to get computers, phones, and files, they can’t possibly decrypt them. Thus, they claim, technology needs a “backdoor” that only the police can access with a warrant.

In it’s simplest form, this is technically easy. Indeed, it’s often a feature for corporations, so that they can get at the encrypted files and message when employees leave the firm, or more often, when stupid employees forget their password but need to have the IT department recover their data.

In a practical form, it’s unreasonable, because it means outlawing any software that doesn’t have a backdoor. Since crypto is just math, and software is something anybody can write, this means a drastic police-state measure. But, if you are a cyberpunk writer about future dystopias, well then, this would be perfectly reasonable.

Thus, in this case, the police, using their secret backdoor key, would be able to decrypt the wallet, and recover any secret key.

But then at the same time, the police could in theory impose this rule on the blockchain itself. Instead of simply trusting a single person’s key, it can trust multiple keys, so that any of them can transfer bitcoins to somebody else. One of those keys could be a secret backdoor police held by the police, so they could step in and grab bitcoins any time they want.

This would, of course, largely defeat the purpose of the bitcoin blockchain, because now you had a central control. But things can go halfway. Bitcoin is transnational, so it really can’t be controlled by even a dystopic government, which is why it’s currently popular in places like Russia. However, a government can still force the citizens of their own country to backdoor their transactions with that county’s public backdoor key (which matches a secret police key). Thus, the American police would be able to grab bitcoins from any law-abiding American to chose to sign their transactions with the FBI’s key.

The point I’m making here is that if you are a sci-fi writer, while a naive approach to the topic might not have a good answer, something thinking and discussing it with a bunch of people might yield something fruitful.

Continue reading Where do bitcoins go when you die? (sci-fi)

Posted in Uncategorized