<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss1full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:cc="http://web.resource.org/cc/" xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://www.schneier.com/blog/">
<title>Schneier on Security</title>
<link>http://www.schneier.com/blog/</link>
<description>A blog covering security and security technology.</description>
<dc:creator />
<dc:date>2009-11-06T16:13:18-06:00</dc:date>
<dc:rights>Copyright 2009 Bruce Schneier</dc:rights>
<admin:generatorAgent rdf:resource="http://www.movabletype.org/?v=4.3-en" />


<items>
<rdf:Seq>
<rdf:li rdf:resource="http://www.schneier.com/blog/archives/2009/11/friday_squid_bl_206.html" />

<rdf:li rdf:resource="http://www.schneier.com/blog/archives/2009/11/interview_with_14.html" />

<rdf:li rdf:resource="http://www.schneier.com/blog/archives/2009/11/the_doghouse_ad.html" />

<rdf:li rdf:resource="http://www.schneier.com/blog/archives/2009/11/mossad_hacked_s.html" />

<rdf:li rdf:resource="http://www.schneier.com/blog/archives/2009/11/the_problems_wi_1.html" />
</rdf:Seq>
</items>

<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/schneier/fulltext" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /></channel>


<item rdf:about="http://www.schneier.com/blog/archives/2009/11/friday_squid_bl_206.html">
<title>Friday Squid Blogging: Dentyne Ice Squid Ad</title>
<link>http://www.schneier.com/blog/archives/2009/11/friday_squid_bl_206.html</link>
<description>&lt;p&gt;&lt;a href="http://www.youtube.com/watch?v=cRKdCjAxn6Y"&gt;Weird.&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=s6JC3Zir7LM:fwNNHGF9nYI:2mJPEYqXBVI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=2mJPEYqXBVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=s6JC3Zir7LM:fwNNHGF9nYI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=s6JC3Zir7LM:fwNNHGF9nYI:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
<dc:subject />
<dc:creator>schneier</dc:creator>
<dc:date>2009-11-06T16:13:18-06:00</dc:date>
</item>

<item rdf:about="http://www.schneier.com/blog/archives/2009/11/interview_with_14.html">
<title>Interview with Me</title>
<link>http://www.schneier.com/blog/archives/2009/11/interview_with_14.html</link>
<description>&lt;p&gt;On &lt;a href="http://news.cnet.com/8301-27080_3-10381460-245.html?tag=newsLeadStoriesArea.1"&gt;CNet.com&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=hl53QjttWes:BphW75pXFXA:2mJPEYqXBVI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=2mJPEYqXBVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=hl53QjttWes:BphW75pXFXA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=hl53QjttWes:BphW75pXFXA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
<dc:subject />
<dc:creator>schneier</dc:creator>
<dc:date>2009-11-06T14:35:08-06:00</dc:date>
</item>

<item rdf:about="http://www.schneier.com/blog/archives/2009/11/the_doghouse_ad.html">
<title>The Doghouse: ADE 651</title>
<link>http://www.schneier.com/blog/archives/2009/11/the_doghouse_ad.html</link>
<description>&lt;p&gt;A &lt;a href="http://www.nytimes.com/2009/11/04/world/middleeast/04sensors.html"&gt;divining rod&lt;/a&gt; to find explosives in Iraq:&lt;/p&gt;

&lt;blockquote&gt;ATSC’s promotional material claims that its device can find guns, ammunition, drugs, truffles, human bodies and even contraband ivory at distances up to a kilometer, underground, through walls, underwater or even from airplanes three miles high. The device works on “electrostatic magnetic ion attraction,” ATSC says.

&lt;p&gt;To detect materials, the operator puts an array of plastic-coated cardboard cards with bar codes into a holder connected to the wand by a cable. “It would be laughable,” Colonel Bidlack said, “except someone down the street from you is counting on this to keep bombs off the streets.”&lt;/p&gt;

&lt;p&gt;Proponents of the wand often argue that errors stem from the human operator, who they say must be rested, with a steady pulse and body temperature, before using the device.&lt;/p&gt;

&lt;p&gt;Then the operator must walk in place a few moments to “charge” the device, since it has no battery or other power source, and walk with the wand at right angles to the body. If there are explosives or drugs to the operator’s left, the wand is supposed to swivel to the operator’s left and point at them.&lt;/p&gt;

&lt;p&gt;If, as often happens, no explosives or weapons are found, the police may blame a false positive on other things found in the car, like perfume, air fresheners or gold fillings in the driver’s teeth.&lt;/blockquote&gt;&lt;/p&gt;

&lt;p&gt;Complete quackery, sold by Cumberland Industries:&lt;/p&gt;

&lt;blockquote&gt;Still, the Iraqi government has purchased more than 1,500 of the devices, known as the ADE 651, at costs from $16,500 to $60,000 each. Nearly every police checkpoint, and many Iraqi military checkpoints, have one of the devices, which are now normally used in place of physical inspections of vehicles.&lt;/blockquote&gt;

&lt;p&gt;James Randi &lt;a href="http://www.randi.org/site/index.php/swift-blog/231-a-direct-specific-challenge-from-james-randi-and-the-jref.html"&gt;says&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;This Foundation will give you our million-dollar prize upon the successful testing of the ADE651® device. Such test can be performed by anyone, anywhere, under your conditions, by you or by any appointed person or persons, in direct satisfaction of any or all of the provisions laid out above by you.

&lt;p&gt;No one will respond to this, because the ADE651® is a useless, quack, device which cannot perform any other function than separating naïve persons from their money. It’s a fake, a scam, a swindle, and a blatant fraud. The manufacturers, distributors, vendors, advertisers, and retailers of the ADE651® device are criminals, liars, and thieves who will ignore this challenge because they know the device, the theory, the described principles of operation, and the technical descriptions given, are nonsense, lies, and fraudulent.&lt;/blockquote&gt;&lt;/p&gt;

&lt;p&gt;And he quotes from the Cumberland Industries literature (not online, unfortunately):&lt;/p&gt;

&lt;blockquote&gt;Ignores All Known Concealment Methods. By programming the detection cards to specifically target a particular substance, (through the proprietary process of electro-static matching of the ionic charge and structure of the substance), the ADE651® will “by-pass” all known attempts to conceal the target substance. It has been shown to penetrate Lead, other metals, concrete, and other matter (including hiding in the body) used in attempts to block the attraction.

&lt;p&gt;No Consumables nor Maintenance Contracts Required. Unlike Trace Detectors that require the supply of sample traps, the ADE651® does not utilize any consumables (exceptions include: cotton-gloves and cleanser) thereby reducing the operational costs of the equipment. The equipment is Operator maintained and requires no ongoing maintenance service contracts. It comes with a hardware three year warranty. Since the equipment is powered electro statically, there are no batteries or conventional power supplies to change or maintain.&lt;/blockquote&gt;&lt;/p&gt;

&lt;p&gt;One interesting point is that the effectiveness of this device depends strongly on what the bad guys think about its effectiveness.  If the bad guys think it works, they have to find someone who is 1) willing to kill himself, and 2) rational enough to keep his cool while being tested by one of these things.  I'll bet that the ADE651 makes it harder to recruit suicide bombers.&lt;/p&gt;

&lt;p&gt;But what happened to the days when you could buy a &lt;a href="http://www.diviningmind.com/"&gt;divining rod&lt;/a&gt; for $100?&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=0GbRH6OcnyI:Ss5WhpohXEM:2mJPEYqXBVI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=2mJPEYqXBVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=0GbRH6OcnyI:Ss5WhpohXEM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=0GbRH6OcnyI:Ss5WhpohXEM:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
<dc:subject />
<dc:creator>schneier</dc:creator>
<dc:date>2009-11-06T06:55:14-06:00</dc:date>
</item>

<item rdf:about="http://www.schneier.com/blog/archives/2009/11/mossad_hacked_s.html">
<title>Mossad Hacked Syrian Official's Computer</title>
<link>http://www.schneier.com/blog/archives/2009/11/mossad_hacked_s.html</link>
<description>&lt;p&gt;It was &lt;a href="http://www.haaretz.com/hasen/spages/1125312.html"&gt;unattended in a hotel room&lt;/a&gt; at the time:&lt;/p&gt;

&lt;blockquote&gt;Israel's Mossad espionage agency used Trojan Horse programs to gather intelligence about a nuclear facility in Syria the Israel Defense Forces destroyed in 2007, the German magazine &lt;i&gt;Der Spiegel&lt;/i&gt; reported Monday. 

&lt;p&gt;According to the magazine, Mossad agents in London planted the malware on the computer of a Syrian official who was staying in the British capital; he was at a hotel in the upscale neighborhood of Kensington at the time. &lt;/p&gt;

&lt;p&gt;The program copied the details of Syria's illicit nuclear program and sent them directly to the Mossad agents' computers, the report said.&lt;/blockquote&gt;&lt;/p&gt;

&lt;p&gt;Remember the &lt;a href="http://www.schneier.com/blog/archives/2009/10/evil_maid_attac.html"&gt;evil maid&lt;/a&gt; attack: if an attacker gets hold of your computer temporarily, he can bypass your encryption software.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=rb9uAmhH85w:FSg-pDjmy3s:2mJPEYqXBVI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=2mJPEYqXBVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=rb9uAmhH85w:FSg-pDjmy3s:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=rb9uAmhH85w:FSg-pDjmy3s:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
<dc:subject />
<dc:creator>schneier</dc:creator>
<dc:date>2009-11-05T12:48:51-06:00</dc:date>
</item>

<item rdf:about="http://www.schneier.com/blog/archives/2009/11/the_problems_wi_1.html">
<title>The Problems with Unscientific Security</title>
<link>http://www.schneier.com/blog/archives/2009/11/the_problems_wi_1.html</link>
<description>&lt;p&gt;From the &lt;i&gt;Open Access Journal of Forensic Psychology&lt;/i&gt;, by a whole list of authors:  "&lt;a href="http://web.me.com/gregdeclue/Site/Volume_1__2009_files/Meijer%202009.pdf"&gt;A Call for Evidence-Based Security Tools&lt;/a&gt;":&lt;/p&gt;

&lt;blockquote&gt;&lt;b&gt;Abstract&lt;/b&gt;:  Since the 2001 attacks on the twin towers, policies on security have changed drastically, bringing about an increased need for tools that allow for the detection of deception. Many of the solutions offered today, however, lack scientific underpinning.

&lt;p&gt;We recommend two important changes to improve the (cost) effectiveness of security policy. To begin with, the emphasis of deception research should shift from technological to behavioural sciences. Secondly, the burden of proof should lie with the manufacturers of the security tools. Governments should not rely on  ecurity tools that have not passed scientific scrutiny, and should only employ those methods that have been proven effective. After all, the use of tools that do not work will only get us further from the truth.&lt;/blockquote&gt;&lt;/p&gt;

&lt;p&gt;One excerpt:&lt;/p&gt;

&lt;blockquote&gt;In absence of systematic research, users will base their evaluation on data generated by field use. Because people tend to follow heuristics rather than the rules of probability theory, perceived effectiveness can substantially differ from true effectiveness (Tversky &amp; Kahneman, 1973). For example, one well-known problem associated with field studies is that of selective feedback. Investigative authorities are unlikely to receive feedback from liars who are erroneously considered truthful. They will occasionally receive feedback when correctly detecting deception, for example through confessions (Patrick &amp; Iacono, 1991; Vrij, 2008).  The perceived effectiveness that follows from this can be further reinforced through confirmation bias: Evidence confirming one's preconception is weighted more heavily than evidence contradicting it (Lord, Ross, &amp; Lepper, 1979). As a result, even techniques that perform at chance level may be perceived as highly effective (Iacono, 1991). This unwarranted confidence can have profound effects on citizens' safety and civil liberty: Criminals may escape detection while innocents may be falsely accused. The Innocence Project (Unvalidated or improper science, no date) demonstrates that unvalidated or improper forensic science can indeed lead to wrongful convictions (see also Saks &amp; Koehler, 2005).&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="http://www.sciencedaily.com/releases/2009/10/091031003540.htm"&gt;Article&lt;/a&gt; on the paper. &lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=JxW5uUAxdyk:5hyThuJkgSw:2mJPEYqXBVI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=2mJPEYqXBVI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=JxW5uUAxdyk:5hyThuJkgSw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/schneier/fulltext?a=JxW5uUAxdyk:5hyThuJkgSw:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/schneier/fulltext?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description>
<dc:subject />
<dc:creator>schneier</dc:creator>
<dc:date>2009-11-05T06:11:27-06:00</dc:date>
</item>


</rdf:RDF>
