Thursday, March 20, 2008

Why RFID Should Never be Taken to Mean Private or Secure

I came across two interesting videos this week showing just how insecure RFID can be. I’ve linked them below. You should note that the first uses a system called Oyster that is used in many cases (including entry cards (as the video shows). The second shows an American Express card. Caveat emptor.

Note: the second video is done with a $0.99 reader off eBay (plus $7.99 in shipping). In general these cost around $50 but the prices are dropping and $50 is not much of a barrier. Tracking based on these things we carry (in this case an id or credit card) has the potential to be cheap and ubiquitous.

Oyster cards hacked and cloned by college kids

American Express cards are easily readable

Sunday, March 16, 2008

Power Corrupts; Absolute Power Corrupts; Absolutely

Hidden between the salacious headlines about a prostitute patronizing governor, the release of a report by the Department of Justice seeped out. Apparently the government we have entrusted with our security, and with the legal, and moral, requirement to protect our privacy has been playing fast and loose with the second of those obligations. According to the report, the FBI was using National Security Letters (authorized under the USA PATRIOT Act for surveillance outside of usual 4th amendment protections and requirements) to spy on subject who they were not allowed to, forbidden by courts from monitoring or simply casting their net much wider than they had approval to do.

For those wondering how this ties to our current debate about providing telecoms with immunity for prosecution (the telecoms are who the FBI delivered these NSLs to and were then given people’s private records or access to wiretaps), The Senate has already approved such immunity while the House voted this week to pass surveillance legislation without telecom immunity. Bush has threatened a veto without this clause and there has been much discussion about this issue. What is interesting here is that our government, entrusted to protect us, has asked for powers to monitor us out side of its abilities and in violation of the constitution. As in the past (think Hoover administration, Files that showed up on the Clinton White House, etc.) we see that those given the ability to secretly monitor are abusing that privilege. When we discuss the concepts of domestic spying and why that must be done out the oversight, we should also ask who watches the watchers?

Monday, March 3, 2008

IP address; Your Home on the Net

OK, so here’s a quick primer on Internet traffic. Much like the traffic on the streets, it finds its way to its destination via an address (well except for male traffic which wanders randomly around until it sees its destination, luckily for us all, Internet traffic is androgynous). The world of computer technology (especially early technology in the space) used very descriptive naming and IP (or Internet Protocol) is one of those amazingly descriptive names. Every time you communicate with another machine on the internet (e.g. every time you type in an email address, a web-site or IM someone) your IP address is communicated to that site. Don’t believe me, go to www.WhatsMyIPAddress.com and it will tell you what your IP address is. The current version of IP addresses is called IPv4 (for version 4). The problem with IPv4 is that as the number of devices that are connected to the Internet has expanded (think of every server, Internet capable cell phone, desktop, laptop, etc.) the number of available addresses is getting pretty slim (much like with telephone numbers). Also like telephone numbers (or street addresses) sections are given out in blocks (blocks of numbers or just street blocks). To deal with the lack of addresses, organizations (probably like your workplace or school) set up a set of IP addresses and then allow the traffic to get sent to addresses only it knows within its network (this is called DHCP within a reverse-proxy, don’t worry about the tech parts of this, just accept that your IP address changed periodically to allow others to use that address when you weren’t). Your Internet Service Provider (ISP) most likely does this as (just like you might have an office number at work that the post office has no idea where it is). This has all changed.

Two things are changing this system. First off is IPv6. IPv6 has much more “addressing space” which means that if this were a city, you just built a ton of new roads and everyone can easily have their own address. This means that there is no need for dynamic addressing and thus people may keep their IP addresses for long periods of time (effectively making them personally identifiable). The second change was around data aggregation.

Data aggregation has become cheap enough that storing massive amounts of data is quite cheap. Right now I can go buy a terabyte of space (that’s 1,000,000 Megabytes (MB)) for a couple hundred dollars (US $). Since storage is cheap, organizations started to store this information and associate it with other information. IP address could be linked to users (say if you logged into an online website then linking your login time and IP address would give you a user’s identity, then use that IP address on other sites and you know where the person has been). You can even use this information to get a person’s physical location (or at least the location of the machine/access point they are using). Search engines use this information to build a profile of a user and use that information to build marketing profiles. In this is where Google has found itself on the bad side of the European Union’s Privacy initiatives.

Recently the EU, decided that IP addresses are personal information (called PII or personally Identifiable Information in the US). Google, in particular is fighting this as they argue that IP addresses aren’t personally identifiable. If comments on that blog are any indication, the net community isn’t buying this line any more than the EU is. In fairness to Google, they really don’t care if it personally identifies you as long as it uniquely identifies a person (since that’s where their targeted ad business (the core of how they make money) makes its money). Google is trying several steps to convince people they aren’t keeping info that is personally identifiable but in reality, anyone who is storing IP addresses (even without things like search histories that invariably have PII in them) is going to have this issue. Using ISP records, IP addresses can be linked to users and from a Govt. standpoint this is the magic connection.

If you are concerned about such actions, I can recommend two actions to take. The first is to use a service like Scroogle. You can make a search plug-in for your browser for them or just go to their homepage. They proxy searches to Google but take out the ads and the tracking cookies. In this way you can access the value of a search engine (like Google) without worrying about the nasty tracking aspects of such a company. The second option is to use an anonymizing service like TOR. TOR sends all your traffic though at least three other nodes. The data is thus Anonymized from its original source but it is NOT confidential (e.g. if you log into a website that is not using SSL (the little lock icon on your browser) then the person on the end of that chain of servers could capture your login and password). This is just as true if you aren’t using TOR but just a reminder that anonymity is different than privacy.

Wednesday, February 27, 2008

RFID – What it is and Why is it Showing Up Everywhere?

So by now you’ve probably heard of RFID. If not this technology is Radio Frequency Identification. At a technological level it’s actually a pretty cool technology that could enable slick things like taking a semi-full of goods and driving it to a dock and sensors could automatically update inventory by reading the tags while the semi was pulling up to the warehouse (no clerks, no data entry errors, not time spent filling out paperwork). This is the same technology used in things like the EZ Pass for bridge tolls in certain parts of the US. Without going into a technical description of RFID, it’s easies to think of RFID as a broadcasting technology. So, when the tag is not “shielded” (think of this a quite literally putting a tinfoil hat on the device) then it is broadcasting information. Where this gets into interesting privacy issues is when this technology is integrated into things that are more personally associated. Think driver’s licenses, bus passes, clothing, pets, passports, charge cards, cell phones and even people. Since this data is remotely collectable this give people with inexpensive readers the ability to track movements as the data is aggregated. Technology like the Enhanced Drivers License also has all the data that is on your driver’s license so that data can be collected (say, like when you take it out as ID at a store).

Some organizations are pretty much against this RFID in all forms (like the folks at CASPIAN) while other folks see it as applicable for industrial use but not consumer products (as Tesco tried so that it could track consumer’s actions in their stores). Still others think this technology is fine as long as it isn’t used in humans. Finally there are those who are volunteering it be tagged. It is probably biasing but worthy of note that RFID “non-removable” bracelets are used at Guantanamo to track prisoners in much the same way that the Nazis used tattooed numbers to track prisoners in their death camps (IBM is one of the leading patenters of RFID technology as well as the folks who made the computer systems for the Nazis).

As it turns out some of this info isn’t even well secured as a German hacker proved with the e-passports. As with any technology, it can be used for good or for evil. In this case, RFID has the ability to be used for significant privacy invasion; the funny part is that there is not that much to gain for individuals when their materials are tagged. This begs the question, why adopt it?

If you want to read about how scary some of the folks patenting this technology are getting (at least in their patents) the book Spychips is a bit alarmist but quite eye opening.

Sunday, February 10, 2008

You sound familiar… Writing Style Matching in a Blogged World

So the National Science Foundation created a program called Dark Web. For those not familiar it’s a project that tries to collect all the extremist and terrorist sites on the net. For monitoring, this is probably something that seems perfectly practical. Some of the technology has interesting applications. One in particular is a writing style matching technology Writeprinting. Writeprinting looks at things like your writing style, structure and semantics to identify who you are (or more appropriately identify writings by the same individual. The benefit to be able to identify “anonymous” extremists from other writings they have done online (or other sources) is of obvious benefit which few people would deny we should be looking into in an effort to keep all people safe. Indeed, the Unibomber was caught after his manifesto was published and his brother recognized the thoughts and writing style.

Of course, like most technologies, it can be used for good or evil as machines and algorithms are apathetic to purpose by definition. This means that the same technology we rely on to keep us safe from terrorists may also be the same technology that keeps us from expressing our thoughts and feelings about what is happening in our communities, country or world. Anonymous speech was important to our founding fathers (as much of what they were doing was treasonous under English rule) and this technology could easily be used for other “well meaning” though totally unintended purposes such as catching students who write other’s papers or unmasking anonymous whistle blowing bloggers.

Of course, not making any public writings available would thwart such a technology but it also has a down side. Right now public shows of dissent are the ways that people form movements against programs, policies, organizations and governments that they don’t agree with. This form of association allows a safety valve for people to express their concerns and help make change if their views are shared by enough individuals. If such speech is tracked and the authors found and punished (like those that have protested President Bush in the United States or were thrown out of the US Capital for shirts relating to the Iraq occupation). In individual cases this leads to motivating those who believe in the cause being suppressed. In extreme cases it leads people to go directly to much more drastic means such as subversion and terrorism.

The point here is that freedom of speech is as much about having a voice as it is about maintaining a civil society. The creation of technologies that remove that anonymity may have the ironic result of actually making things less safe in the long run as those who feel that they are being oppressed and don’t feel free to express their grievances (free from reprisal) move to more extreme tactics.

Will technology meant to make us safer actually have the opposite affect? I certainly hope not. But as we develop such technologies we should bear such possible outcomes in mind.

Of course, people also may just start to come up with obfuscation programs (such as used in computer code) to mask their identities; only time will tell.

Sunday, February 3, 2008

RFID: Tag Your Kids For More Efficient Busses… Hu?

The Associated Press is reporting that a Rhode Island town is going to implement a “test” program where they will RFID (Radio Frequency Identification) children’s backpacks to see where they get on and off the bus. They will also use a GPS system to track the busses location. The ACLU of RI is fighting this action as unnecessary. I’ll avoid the obvious question of why they need this at all since they could just GPS the bus and then have the driver record the number of kids that get on the bus without needing to identify each individual student. The school dismisses concerns that others could use this information to track children since they say it is “just a number”. If this sounds familiar, it might be the ghosts of the debates over the Social Security Number program (and we see how that number has remained just a number and not a personal identifier, right?). The push for RFID stalled some time ago over the debacle with Tesco and its hidden tracking of UK shoppers (and Gillette razors at Wal-Mart here in the US). It appears this is back in the news. There is no question that RFID (Radio Frequency Identification) has many uses, but tracking people is one that many folks are rightfully skeptical of (see www.spychips.com). I’ve not covered RFID yet in this blog (I will some time in the future) but there is good reason to be skeptical about technology that makes its carrier remotely traceable if we believe that people should have personal privacy). At least in the US, privacy is a balance; even in the case of the 4th amendment, there are weighing factors that have been used to determine the limits of privacy protections v govt. intrusions. In this case, all I can wonder is who thinks this is an appropriate trade off?

Monday, January 28, 2008

AT&T reborn, Former Death Star now Net Nanny

This is a great article about what AT and T is going to do; monitor every bit of information that goes across its network. Oh sure, we’ve known for a while that they do this for the government, but apparently now they are doing it for the RIAA (recording industry) and MPAA (film industry). If this feels a little strange, maybe it’s because it reverses the idea of innocent until proven guilty (granted that is for govt. and no such principal necessarily applies to private industry). The article does a great job of pointing out that the telecoms pushed for (and got) a protection from liability for providing material (as opposed to what happened to Napster or Grokster) assuming that they had no part in deciding what it was. This would seem to contravene that. This also brings in an interesting question about which is more important as a service provider; serving your customers, or helping another industry. If free enterprise is correct, then this knowledge should mean terrible impacts on AT and T’s financial (as the article predicts). If not, then we have a profound example of user’s naïveté about privacy and control measures that is destined to play itself out with potentially unfortunate consequences in the future (the TIA program’s plant to use letter carriers as agents for the govt. and then later firefighters comes to mind as such things in the govt. sector). As for how the public will react, and if AT and T will suffer any measurable financial impact, only the future will tell.