<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss1full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:cc="http://web.resource.org/cc/" xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://www.schneier.com/blog/">
<title>Schneier on Security</title>
<link>http://www.schneier.com/blog/</link>
<description>A blog covering security and security technology.</description>
<dc:creator />
<dc:date>2010-02-09T12:09:11-06:00</dc:date>
<dc:rights>Copyright 2010 Bruce Schneier</dc:rights>
<admin:generatorAgent rdf:resource="http://www.movabletype.org/?v=4.3-en" />


<items>
<rdf:Seq>
<rdf:li rdf:resource="http://www.schneier.com/blog/archives/2010/02/all_subversive.html" />

<rdf:li rdf:resource="http://www.schneier.com/blog/archives/2010/02/outguessing_the.html" />

<rdf:li rdf:resource="http://www.schneier.com/blog/archives/2010/02/the_limits_of_v.html" />

<rdf:li rdf:resource="http://www.schneier.com/blog/archives/2010/02/more_details_on.html" />

<rdf:li rdf:resource="http://www.schneier.com/blog/archives/2010/02/new_attack_on_t.html" />
</rdf:Seq>
</items>

<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rdf+xml" href="http://feeds.feedburner.com/schneier/fulltext" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="schneier/fulltext" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /></channel>


<item rdf:about="http://www.schneier.com/blog/archives/2010/02/all_subversive.html">
<title>All Subversive Organizations Now Must Register in South Carolina</title>
<link>http://www.schneier.com/blog/archives/2010/02/all_subversive.html</link>
<description>&lt;p&gt;This appears &lt;a href="http://rawstory.com/2010/02/south-carolinas-subversive-activities-registration-act-force/"&gt;not to be a joke&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;The state's "&lt;a
href="http://www.scstatehouse.gov/code/t23c029.htm"&gt;Subversive Activities Registration Act&lt;/a&gt;," passed last year and now officially &lt;a
href="http://www.nowpublic.com/world/south-carolina-terrorist-registration-law-paperwork-al-queda-2569751.html"&gt;on the books&lt;/a&gt;, states that "every member of a subversive organization, or an organization subject to foreign control, every foreign agent and every person who advocates, teaches, advises or practices the duty, necessity or propriety of controlling, conducting, seizing or overthrowing the government of the United States ... shall register with the Secretary of State."

&lt;p&gt;There's even a $5 filing fee.&lt;/p&gt;

&lt;p&gt;By "subversive organization," the law means "every corporation, society, association, camp, group, bund, political party, assembly, body or organization, composed of two or more persons, which directly or indirectly advocates, advises, teaches or practices the duty, necessity or propriety of controlling, conducting, seizing or overthrowing the government of the United States [or] of this State."&lt;/blockquote&gt;&lt;/p&gt;

&lt;p&gt;Wow, is that idiotic or what?&lt;/p&gt;

&lt;p&gt;&lt;a href="http://fitsnews.com/wp-content/uploads/2010/02/SubversiveAgentForm.pdf"&gt;Here's&lt;/a&gt; the form.&lt;/p&gt;

&lt;p&gt;Does the Republican Party count as an organization that "directly ... advocates ... controlling ... the government"?  I think it does.  I think all political parties count under that definition.&lt;/p&gt;

&lt;p&gt;How about we all fill in a copy and send it to them.&lt;br /&gt;
&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=bl7uHJxZDF4:SRJU9kgJ-RI:2mJPEYqXBVI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=2mJPEYqXBVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=bl7uHJxZDF4:SRJU9kgJ-RI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=bl7uHJxZDF4:SRJU9kgJ-RI:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
<dc:subject />
<dc:creator>schneier</dc:creator>
<dc:date>2010-02-09T12:09:11-06:00</dc:date>
</item>

<item rdf:about="http://www.schneier.com/blog/archives/2010/02/outguessing_the.html">
<title>Outguessing the Terrorists</title>
<link>http://www.schneier.com/blog/archives/2010/02/outguessing_the.html</link>
<description>&lt;p&gt;Isn't it a bit embarrassing for an "expert on counter-terrorism" to be quoted as saying &lt;a href="http://news.bbc.co.uk/2/hi/uk_news/england/devon/8481446.stm"&gt;this&lt;/a&gt;?&lt;/p&gt;

&lt;blockquote&gt;Bill Tupman, an expert on counter-terrorism from Exeter University, told BBC News: "The problem is trying to predict the mind of the al-Qaeda planner; there are so many things they might do.

&lt;p&gt;"And it is also necessary to reassure the public that we are trying to outguess the al-Qaeda planner and we are in the process of protecting them from any threat."&lt;/blockquote&gt;&lt;/p&gt;

&lt;p&gt;I think it's necessary to convince the public to &lt;a href="http://www.schneier.com/essay-124.html"&gt;refuse to be terrorized&lt;/a&gt;.  What frustrates me most about Abdulmutallab is that he caused terror even though his plot failed.  I want us to be indomitable enough for the next attack to fail to cause terror, even if it succeeds.  Remember: terrorism can't destroy our country's way of life; only our reaction to terrorism can.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=mE4Q9HT_TKQ:cMJV9xOf7BU:2mJPEYqXBVI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=2mJPEYqXBVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=mE4Q9HT_TKQ:cMJV9xOf7BU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=mE4Q9HT_TKQ:cMJV9xOf7BU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
<dc:subject />
<dc:creator>schneier</dc:creator>
<dc:date>2010-02-09T06:07:48-06:00</dc:date>
</item>

<item rdf:about="http://www.schneier.com/blog/archives/2010/02/the_limits_of_v.html">
<title>The Limits of Visual Inspection</title>
<link>http://www.schneier.com/blog/archives/2010/02/the_limits_of_v.html</link>
<description>&lt;p&gt;Interesting &lt;a href="http://www.cell.com/current-biology/abstract/S0960-9822(09)02122-8"&gt;research&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;Target prevalence powerfully influences visual search behavior. In most visual search experiments, targets appear on at least 50% of trials. However, when targets are rare (as in medical or airport screening), observers shift response criteria, leading to elevated miss error rates. Observers also speed target-absent responses and may make more motor errors. This could be a speed/accuracy tradeoff with fast, frequent absent responses producing more miss errors. Disproving this hypothesis, our experiment one shows that very high target prevalence (98%) shifts response criteria in the opposite direction, leading to elevated false alarms in a simulated baggage search. However, the very frequent target-present responses are not speeded. Rather, rare target-absent responses are greatly slowed. In experiment two, prevalence was varied sinusoidally over 1000 trials as observers' accuracy and reaction times (RTs) were measured. Observers' criterion and target-absent RTs tracked prevalence. Sensitivity (d') and target-present RTs did not vary with prevalence. These results support a model in which prevalence influences two parameters: a decision criterion governing the series of perceptual decisions about each attended item, and a quitting threshold that governs the timing of target-absent responses. Models in which target prevalence only influences an overall decision criterion are not supported.&lt;/blockquote&gt;

&lt;p&gt;This has &lt;a href="http://www.npr.org/templates/story/story.php?storyId=122561355"&gt;implications&lt;/a&gt; for searching for contraband at airports.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=d7egl6uAg0w:PL3kjCJmTz0:2mJPEYqXBVI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=2mJPEYqXBVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=d7egl6uAg0w:PL3kjCJmTz0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=d7egl6uAg0w:PL3kjCJmTz0:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
<dc:subject />
<dc:creator>schneier</dc:creator>
<dc:date>2010-02-08T13:54:20-06:00</dc:date>
</item>

<item rdf:about="http://www.schneier.com/blog/archives/2010/02/more_details_on.html">
<title>More Details on the Chinese Attack Against Google</title>
<link>http://www.schneier.com/blog/archives/2010/02/more_details_on.html</link>
<description>&lt;p&gt;Three weeks ago, Google announced a &lt;a href="http://www.schneier.com/blog/archives/2010/01/google_vs_china.html"&gt;sophisticated attack&lt;/a&gt; against them from China.  There have been some &lt;a href="http://www.wired.com/threatlevel/2010/02/apt-hacks/"&gt;interesting technical details&lt;/a&gt; since then.  And the &lt;a href="http://www.schneier.com/blog/archives/2010/02/worlds_largest.html"&gt;NSA is helping Google&lt;/a&gt; analyze the attack.&lt;/p&gt;

&lt;p&gt;The rumor that China used a system Google put in place to enable lawful intercepts, which I used as a news hook for &lt;a href="http://www.schneier.com/essay-306.html"&gt;this essay&lt;/a&gt;, has not been confirmed.  At this point, I doubt that it's true.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=-y-qqrenv0A:oGAi9wN8Lxs:2mJPEYqXBVI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=2mJPEYqXBVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=-y-qqrenv0A:oGAi9wN8Lxs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=-y-qqrenv0A:oGAi9wN8Lxs:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
<dc:subject />
<dc:creator>schneier</dc:creator>
<dc:date>2010-02-08T06:03:05-06:00</dc:date>
</item>

<item rdf:about="http://www.schneier.com/blog/archives/2010/02/new_attack_on_t.html">
<title>New Attack on Threefish</title>
<link>http://www.schneier.com/blog/archives/2010/02/new_attack_on_t.html</link>
<description>&lt;p&gt;At &lt;a href="http://cist.korea.ac.kr/~fse2010/index.php"&gt;FSE 2010&lt;/a&gt; this week, Dmitry Khovratovich and Ivica Nikolic presented a paper where they cryptanalyze ARX algorithms (algorithms that use only addition, rotation, and exclusive-OR operations): "&lt;a href="http://www.skein-hash.info/sites/default/files/axr.pdf"&gt;Rotational Cryptanalysis of ARX&lt;/a&gt;."  In the paper, they demonstrate their attack against &lt;a href="http://www.schneier.com/threefish.html"&gt;Threefish&lt;/a&gt;.  Their attack breaks 39 (out of 72) rounds of Threefish-256 with a complexity of 2&lt;sup&gt;252.4&lt;/sup&gt;, 42 (out of 72) rounds of Threefish-512 with a complexity of 2&lt;sup&gt;507&lt;/sup&gt;, and 43.5 (out of 80) rounds of Threefish-1024  with a complexity of 2&lt;sup&gt;1014.5&lt;/sup&gt;.  (Yes, that's over 2&lt;sup&gt;1000&lt;/sup&gt;.  Don't laugh; it really is a valid attack, even though it -- or any of these others -- will never be practical.)&lt;/p&gt;

&lt;p&gt;This is excellent work, and represents the best attacks against Threefish to date.  (I suspect that the attacks can be extended a few more rounds with some clever cryptanalytic tricks, but no further.)  The security of full Threefish isn't at risk, of course; there's still plenty of security margin.&lt;/p&gt;

&lt;p&gt;We have always stood by the security of Threefish with any set of non-obviously-bad constants.  Still, a trivial modification -- changing a single constant in the key schedule -- dramatically reduces the number of rounds through which this attack can penetrate.  If NIST allows another round of tweaks to the &lt;a href="http://csrc.nist.gov/groups/ST/hash/sha-3/index.html"&gt;SHA-3 candidate algorithms&lt;/a&gt;, we will almost certainly take the opportunity to improve &lt;a href="http://www.skein-hash.info/"&gt;Skein's&lt;/a&gt; security; we'll change this constant to a value that removes the rotational symmetries that this technique exploits.  If they don't, we're still confident of the security of Threefish and Skein.&lt;/p&gt;

&lt;p&gt;And we're always pleased to see more cryptanalysis against Threefish and Skein.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=iaWnSNUZO_8:wqnxzwW4iEU:2mJPEYqXBVI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=2mJPEYqXBVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=iaWnSNUZO_8:wqnxzwW4iEU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=iaWnSNUZO_8:wqnxzwW4iEU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
<dc:subject />
<dc:creator>schneier</dc:creator>
<dc:date>2010-02-07T08:06:59-06:00</dc:date>
</item>


</rdf:RDF>
