Skip to content

Justin Mason's Weblog Posts

Monkey sense (fwd)

A funny letter from New Scientist regarding the use of monkeys to collect specimens in the field, which was pioneered by John Corner in Singapore.

The botanist noticed that local fruit-pickers trained monkeys to collect fruit, and reasoned that a monkey could similarly be trained to collect flowers, leaves and nuts for his own work. The result was the collection of hundreds of otherwise inaccessible specimens — and this gem:

Travelling with mule and monkey on a narrow path in the uplands, he spied a new and unrecognised flower on a liana hanging from the path, down a near-vertical cliff face too steep for him to climb down. So he instructed the monkey to descend and collect the flower. But the monkey just looked at him questioningly with its head on one side.

‘Go down!’ repeated the eminent botanist. At which the monkey gave an eloquent shrug, took hold of the liana and pulled it up hand over hand to collect the flower. No human being, said Corner, had ever, before or since, made him feel so much of a fool.

Comments closed

Bank of America ATMs are net-connected!

Boing Boing notes that the SQL Slammer worm ’caused service outages at tens of thousands of Bank of America ATMs and wreaked havoc at Continental Airlines. Apparently, customers at most of the #3 American bank’s 13,000 automatic teller machines were unable to process transactions for a period of time.’

Does anyone else find it very scary to contemplate an ATM network connected to the internet, with a sufficiently open set of firewalls that a semi-documented Microsoftish SQL protocol can traverse as far as the ATM servers? Sure, it probably took a few hops, compromising a couple of SQL servers along the way, but each of the firewalls in question must have had that MS-SQL port open for those servers. Yikes.

Someone should teach those guys about network compartmentalization for security; something like an ATM network, where security is hugely essential, should never have a direct IP-based connection to the internet, no matter how many firewalls and gateways are in place.

Spam: NACS: Spam Detection. Great, Catherine’s new email system at UCI uses SpamAssassin. Nothing like getting bug reports from your SO ;)

On the other side, though, they’ve written an excellent set of pages on how to detect and act on the SpamAssassin markup in various MUAs.

Comments closed

deny udp any any eq 1434

it looks like the the latest internet worm is making the rounds, and this one’s a biggie. It’s been dubbed ‘SQLSlammer’, since it hammers on the Microsoft SQL ports, attempting to exploit yet another commonly-unpatched 7-month-old MS vulnerability. The best bit: it uses UDP broadcasts to do this, so the traffic load is massive compared to previous worms, so there’s lots and lots of backbone hosage as a result. Coverage:

Quick fix: update those router filters to deny all traffic, both UDP and TCP, on port 1434. (you shouldn’t need to update the firewall filters of course, because nobody’s stupid enough to allow access to open-internet MS SQL traffic, right? ;)

Comments closed

Kim Jong Il, Giant Robot

Kim Jong Il Unfolds Into Giant Robot (Onion). Met up with Paddy Benson last night for a few drinks, and he let me into the secret that The Onion is, once again, officially funny:

‘If we add Kim Jong Il’s transformation into a giant robot to his already defiant isolationist stance and his country’s known nuclear capability, the diplomatic terrain definitely becomes more rocky,’ U.S. envoy James Kelly said. ‘Kim has made it clear that, if sufficiently threatened, he will not hesitate to use nuclear weapons or his arm-mounted HyperBazooka.’

‘We are also forced to consider the possibility that Kim may attempt to robo-meld with other members of the Axis of Evil, forming a MegaMecha-Optima-Robosoldier. Kim would make a powerful right arm — or even a torso — for such a mechanism.’

Wotcher Paddy!

Comments closed

Matt Blaze vs master keys

Matt Blaze has posted a very neat exploit against ‘weaknesses in most master-keyed lock systems, such as those used by offices, schools, and businesses as well as by some residential facilities (particularly apartment complexes, dormitories, and condominiums). These weaknesses allow anyone with access to the key to a single lock to create easily the master key that opens every lock in the entire system. Creating such a key requires no special skill, leaves behind no evidence, and does not require engaging in recognizably suspicious behavior. The only materials required are a metal file and a small number of blank keys, which are often easy to obtain.’

‘The vulnerability was discovered by applying the techniques of cryptanalysis, ordinarily used to break secret codes, to the analysis of mechanical lock design.’

Paper here.

Comments closed

Tardis-noise inventor dies

Daphne Oram, one of the pioneers of electronic music, has died. (BBC)

Almost un-noticed by the wider world, one of the pioneers of electronic music has died. Without Daphne Oram, we may never had known what the Tardis sounded like. Electronic music – as much a part of today’s life as whistling a tune to yourself – grew up amid milk bottles, gravel, keys, and yards of magnetic tape and wires. These were the sort of tools typically scattered around the BBC’s Radiophonic Workshop in the 1950s and 60s, when they were used to generate wonderful and ethereal sounds for the airwaves. The mother of this great legacy was Daphne Oram. Aged 18, and armed with a passionate interest in sound, music and electronics, she started work at the BBC in 1943 as a sound engineer.
1 Comment

Lotsa SpamConf linkage and commentary

Another good trip report, from ‘babbage’ at perl.org.

  • Again, and interestingly, quite a few folks agreed with one of SA’s core tenets; no single approach (stats, RBLs, rules, distributed hashes) can filter effectively on its own, as spammers will soon figure out a way to subvert that technique. However, if you combine several techniques, they cannot all be subverted at once, so your effectiveness in the face of active attacks is much better.

  • Also interesting to note how everyone working with learning-based approaches commented on how hard it was to persuade ‘normal people’ to keep a corpus. Let’s hope SA’s auto-training will work well enough to avoid that problem.

  • in passing — babbage noted the old canard about Hotmail selling their user database to spammers. That must really piss the Hotmail folks off ;) I think it’s much more likely that, with Moore’s Law and the modern internet, a dictionary attack *will* find your account eventually.

  • Good tip on the legal angle from John Praed of The Internet Law Group: if a spam misuses the name of a trademarked product like ‘Viagra’, get a copy to Pfizer pronto. Trademark holders have a particular desire to follow up on infringements like this, as an undefended trademark loses its TM status otherwise.

  • David Berlind, ZDNet executive editor: ‘They don’t want to be involved (in developing an SMTPng)’. He might say that, but I bet their folks working on sending out their bulk-mailed email newsletters might disagree ;). Legit bulk mail senders have to be involved for it to work, and they will want to be involved, too.

  • Brightmail have a patent on spam honeypots? Must take a look for this sometime.

  • the plural of ‘corpus’ is ‘corpora’ ;)

Great report, overall.

It’s interesting to see that Infoworld notes that reps from AOL, Yahoo! and MS were all present.

Since the conf, Paul Graham has a new paper up about ‘Better Bayesian Filtering’, and lists some new tokenization techniques he’s using:

  • keep dollar signs, exclamation and most punctuation intact (we do that!)

  • prepend header names to header-mined tokens (us too!)

  • case is preserved (ditto!)

  • keep ‘degenerate’ tokens; ‘Subject:FREE!!!’ degenerates to ‘Subject:free’, to ‘FREE!!!’, and ‘free’. (ditto! well, partly. We use degeneration of tokens, but we keep the degenerate tokens in a separate, prefixed namespace from the non-degenerate ones, as he contemplates in footnote 7. It’s worth noting that case-sensitivity didn’t work well compared to the database bloat it produced; each token needs to be duplicated into the case-insensitive namespace, but that doubled the database size, and the hit-rate didn’t go up nearly enough to make it worthwhile.)

Most of these were also discovered and verified experimentally by SpamBayes, too, BTW.

When we were working on SpamAssassin‘s Bayesian-ish implementation, we took a scientific approach, and used suggestions from the SpamBayes folks and from the SpamAssassin community on tokenizer and stats-combining techniques. We then tested these experimentally on a test corpus, and posted the results. In almost all cases, our results matched up with the SpamBayes folks’ results, which is very nice, in a scientific sense.

(PS: update on the Fly UI story — ‘apis’ is not French, it’s Latin. oops! Thanks Craig…)

Comments closed

Trip Report from the SpamConf

Kaitlin Duck Sherwood writes a trip report. Good tidbits:

  • many big players in the mail-sending side want to see an SMTPng; a new protocol which is spam-resistant.

  • Jon Praed of the Internet Law Group said that ‘better spam filters make his job easier: the more contortions that a spammer goes through to make sure that the messages go through, the easier it is to convince a judge that the spammer knew it was wrong.’ Excellent!

Comments closed

Toilet Flies

Andrew McGlinchey writes about a Fly UI: ‘I have seen one of the finest instances of user interface design ever, and I saw it in the men’s room at Schipol airport in Amsterdam. In each of the urinals, there is a little printed blue fly. It looks a lot like a real fly, but it’s definitely iconic – you’re not supposed to believe it’s a real fly. It’s printed near the drain, and slightly to the left.’

I’ve heard of this one before, and yes, it is an aiming-improvement UI. It started in France around the turn of the century, if I recall correctly. One important fact: it’s not a fly — it’s a bee. You see, it’s also a visual pun — the french for ‘bee’ is ‘apis’, geddit?

(I’d have commented on the blog, itself, but it’s one of those ‘create an account to comment’ places — too much trouble!)

He’s also spot-on about why tea is big in Ireland: ‘The climate is cool, grey and damp. Steady doses of warm drink with a nice gentle caffeine push really keeps you going.’ Hey, works in the Himalayas too ;)

Comments closed

UL alert: ‘out-of-office’ autoreplies help burglars

BoingBoing, back in December, forwarded this snippet: ‘A report issued by UK-based Infrastructure Forum (‘TIF’) says spam-savvy thieves are using info from ‘out of office’ email autoresponders and cross-referencing it with publicly available personal data to target empty homes.’

Criminals are buying huge lists of email addresses over the internet and sending mass-mailings in the hope of receiving ‘out of office’ auto-responses from workers away on holiday.

By cross-reference such replies with publicly available information from online directories such as 192.com or bt.com, the burglars can often discover the name, address and telephone number of the person on holiday. Tif is advising users to warn their staff to be careful of the information they put in their ‘out of office’ messages.

“You wouldn’t go on holiday with a note pinned to your door saying who you were, how long you were away for and when you were coming back, so why would you put this in an email?” said David Roberts, chief executive at Tif. (via VNUNet)

My take on this? Bullshit.

I mean, how many house burglars (a) have the know-how to set up a fast internet connection, get hold of an addresses CD, and send a spam; and then (b) how often does a Reply-To address on a spam stay active once it’s sent — assuming it ever worked in the first place — before the ISP whacks their account? I would guess 6 hours at the most, and most spam runs wouldn’t even be halfway through by that stage (from what I hear).

Self-promoting bullshit of the highest order I reckon.

Comments closed

Six Degrees Tested

Steppe by Step (Guardian). “I started wondering if (the ‘six degrees of separation’ theory) was true today. … So 35 years on from the original experiment, I decided to test out the urban myth on a world stage: how many steps would it really take to get to someone on the other side of the planet?”

The London-based “city girl” author, Lucy Leveugle, makes it in 9 steps (hey, the world has expanded!) to Purev-Ochir Gungaa, a nomadic herdsman in the middle of the steppes of Outer Mongolia. Amazing.

Comments closed

wierd referrers

308 referrer hits from www.xxxstoryarchive.com, 282 from amateur-porn.us, 282 from nude-lesbians.us, etc. Somehow I doubt it. All the hits are 404s, looking for e.g.

nn.nn.nn.nn – – [12/Jan/2003:18:52:13 +0000] GET /pics54754-96 HTTP/1.1 404 284 http://www.celebrity-nude-pics.com/ “Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705)”

Hits from hosts at AT&T WorldNet Services and an SBC PPPoX pool. They’re all MSIE 6 on Windows, and it’s been going on for a month or so.

Theory: sounds like MSIE’s download-to-‘view’-offline functionality has bugs; when it hits a 404, maybe it requeues that request but then sends it to entirely the wrong IP.

Alternative theory: it’s a pathetically underpowered DDoS. ouch!

Anyone else seen this?

Comments closed

Still Moving

Who knew relocating with a cat could be so tricky? Well, actually, I did. He hates travel. I’m considering just putting him in a crate and handing him off to a courier to do it.

Paul Graham’s Spam Conference seems to be doing great; they’ve moved to a bigger room, and are expecting 480 (!!) attendees.

I still can’t make it due to all this movage, but thankfully there’s a few SpamAssassin folks going, so we’ll still be able to snarf some good tricks with any luck.

In other news, the public mass-check submission run for SpamAssassin 2.50 is about to start; with the new with-bayes and with-net-tests dimensions in the matrix, it’s going to be the biggest run yet. Should be fun.

Comments closed

The good news

Frequent drinking cuts heart attack risk (New Scientist). ‘ Half an alcoholic drink every other day, be it wine, whisky or beer, can reduce the risk of heart attacks by a third, a new study shows. The 12-year study published in The New England Journal of Medicine found that the frequency of drinking was the key to lowering the risk of heart disease, rather than the amount, the type of alcohol, or whether or not it was drunk with food.’

1 Comment

In the news

Well, looks like it’s been announced; McAfee and NAI are buying Deersoft. I wish I could comment properly, but I’m in mid-packing right now and things are a total hectic mess :(

Comments closed

minor bloglet

New Scientist: Turing tests filter spam email. “Simple tests designed to distinguish computers from humans are increasingly being used to clamp down on unsolicited, or ‘spam’, email advertising.”

The article notes that Yahoo! has imposed such a test to block automated account-signup-then-spam bots. (Thankfully — that might discourage some of the more automated 419 spammers.)

Sorry ’bout the lack of blogging — very busy ’round here, what with a new SpamAssassin release in the pipeline and a move to the US in the offing…

Comments closed

1 January 1659/60 (Lord’s Day)

Samuel Pepys has a weblog:

This morning (we living lately in the garret,) I rose, put on my suit with great skirts, having not lately worn any other, clothes but them. Went to Mr. Gunning’s chapel at Exeter House, where he made a very good sermon.

Anyway, still recovering from the holidays. Hope you all had a good one..

Comments closed

EU DMCA fails – for now

Yahoo!: Deadline Passes for European Digital Copyright Law. ‘A deadline for adopting a new EU law on copyright protection has passed with just two member countries signing up, dealing a blow to media and software companies beset by unauthorized duplication of their works across the Internet.’ The two countries are Greece and Denmark, which is odd, considering I thought Ireland had do so too.

Other actors in the private sector, such as Internet service providers, have weighed in heavily on the issue, opposing laws that could ultimately hurt consumer rights.

Yay ISPs!

Comments closed

Ireland wins the Nationalist Song Competition

BBC: An Irish republican song, A Nation Once Again, has been voted the world’s top tune according to a BBC World Service poll. ‘Following a late surge in votes, the Irish sing along crossed the finishing line ahead of a patriotic Hindi song, Vande Mataram.’

‘The poll had to deal with people trying to influence the vote through fan sites and spamming.’ No shit. The funniest thing about this poll was the way it suddenly stopped being about ‘the world’s top 10 tunes’ and suddenly became ‘how many ‘net users can each country mobilize to vote for a patriotic song’.

Still, I’m impressed the clicky fingers of the Irish net population (pop. 6 million) managed to beat those of India (pop. 1 billion)!

Comments closed

anti-drug propaganda slips up

Guardian: DrugScope, the drug charity, says that an ‘intensive media campaign against the drug ecstasy has led to an increase in cocaine use among young people’. whoops.

‘Studies show the reason they no longer use ecstasy is because of the scare stories,’ said a spokesman for the charity. ‘They haven’t seen similar stories about cocaine and their belief is that cocaine is the safer drug. The reality is that cocaine, especially crack cocaine, is a much more harmful drug – it kills more people each year and more people have dependency on it.’

They also add a few UL-busting facts:

DrugScope’s guide argues that there are no recorded examples of heroin ever being cut with ground glass … no drug is instantly addictive and that addiction generally takes several months to develop … physical withdrawal from heroin is like a bad bout of flu, not a near-death experience.
Comments closed

Aaron’s networking

Aaron’s trip to CA comes to a end in a big bang of serious meeting-up.

I read his blog using the rss2mail mail-based news aggregator he wrote (I live in e-mail, especially while I’m still on the wrong side of dialup), and I think this is the most homepage-link-laden blog entry I’ve ever read. 45 links, count ’em! Wow, I hope he can keep all those name-to-face mappings clear ;)

In other news: it seems that football (proper football, played with feet, ie. soccer) is bad for you: the World Cup penalty shoot-out caused a surge in heart attacks for England fans (New Scientist). Ban Football Now!

Comments closed

Son of Star Wars leaves drivers stranded

Son of Star Wars leaves drivers stranded (Guardian). Interesting collision between military and civvie radio technology.

The upgrading of the security and surveillance systems at (RAF Fylingdales base in Yorkshire, which is planned to be used as a UK base for new US ‘Star Wars’ projects) … is knocking out the electrical systems of expensive cars. … High power radar pulses trigger the immobilising devices of many makes of cars and motorcycles – BMW, Mercedes and Jeep among them. Many have had to be towed out of range of the base before they can be restarted.

Wing Commander Chris Knapman, of RAF Fylingdales, said it was not up to the base to resolve the problem. ‘We have had the frequencies we use for a very long time,’ he said. ‘They are allocated to commercial, military and government users, and the allocation is very tightly controlled. As far as we are concerned, the radars are working on frequencies which are well known, and most car manufacturers take that into account.’

A spokesman for Jeep said: ‘The problem is that the government gives manufacturers such a narrow band to operate in – so the radio wave (sic) we use for our key fob is severely restricted.’

Comments closed

Lamest patent prior-art search ever?

AOL patents instant messaging (/.). ‘Specifically, any technology that provides ‘a network that allows multiple users to see when other users are present and then to communicate with them’ is covered.’

The CNet story which /. references points out that the patent was filed in 1997 — but that’s still 6 years after I wrote a similar perl script on the Maths Department UNIX machines in TCD. There’s a myriad of similar apps, of the same vintage, too.

The thing I find amazing is this, however — the AOL patent actually cites prior art in its References section, namely the xhtalk README file, dated 1992. There’s nothing different between xhtalk and AOL Instant Messenger apart from the protocol and the look and feel, and those aren’t key to the patent.

The US patent office really needs to start reading the patent applications before granting them.

Comments closed

Who 0wnz your government?

Danny reports “the always excellent c’t magazine analyses the hypotheticals of the Dutch IP-surveillance scandal:

According to anonymous sources within the Dutch intelligence community, all tapping equipment of the Dutch intelligence services and half the tapping equipment of the national police force, is insecure and is leaking information to Israel. …”

Yikes. You’d think they’d have learnt from Ireland’s mistakes…. this article (update: moved to here) reports that massive back-door use by a third-party government occurred before in similar circumstances, during the Anglo-Irish negotiations of 1985.

For those of you who don’t know, these discussions were between the Republic of Ireland and the UK, and took place in London.

In order to allow the negotiating team to contact their government and civil service securely, a million-pound cryptographic system had been bought in order to secure the link between the Irish Embassy in London and the government in Dublin.

Unfortunately, this equipment was thoroughly compromised.

It turns out that the Swiss company from which the equipment was bought, namely Crypto AG, had cooperated with the NSA and the BND (the NSA’s German equivalent), to allow them to decipher the traffic trivially. (Judging from the snippet from another article below, sounds like this was done using a known-plaintext attack).

The NSA routinely monitored and deciphered the Irish diplomatic messages. All it took then was for the UK’s NSA equivalent, GCHQ, to pull some strings, and the UK government had a distinct advantage in the negotiations from then on.

Another source for details on Crypto AG’s breakage is Der Spiegel, issue 36/96, pages 206-207. Here’s some snippets:

The secret man (sic) have obviously a great interest to direct the trading of encryption devices into ordered tracks. … A former employee of Crypto AG reported that he had to coordinate his developments with “people from Bad Godesberg”. This was the residence of the “central office for encryption affairs” of the BND, and the service instructed Crypto AG what algorithms to use to create the codes.

Members of the American secret service National Security Agency (NSA) also visited the Crypto AG often. The memorandum of the secret workshop of the Crypto AG in August 1975 on the occasion of the demonstration of a new prototype of an encryption device mentions as a participant the cryptographer of the NSA, Nora Mackebee. …

Depending on the projected usage area the manipulation on the cryptographic devices were more or less subtle, said Polzer. Some buyers only got simplified code technology according to the motto “for these customers that is sufficient, they don’t not need such a good stuff.”

In more delicate cases the specialists reached deeper into the cryptographic trick box: The machines prepared in this way enriched the encrypted text with “auxiliary informations” that allowed all who knew this addition to reconstruct the original key. The result was the same: What looked like inpenetrateable secret code to the users of the Crypto-machines, who acted in good faith, was readable with not more than a finger exercise for the informed listener.

Full text here.

So what’s the bottom line? Use GPG! ;)

From: Julian Assange (spam-protected)

To: (spam-protected) (spam-protected)
Date: Mon, 14 Oct 1996 13:24:31 +1000 (EST)

Approved: (spam-protected)

Subject: BoS: Crypto AG = Crypto NSA/BNG ?

Thanks to Anonymous for this English translation of the German original.


secret services undermine cryptographic devices


Archive of “DER SPIEGEL” issue 36/96 pages 206-207


“Who is the authorized fourth”

Secret services undermine the protection of cryptographic devices.

Switzerland is a discreet place. Uncounted millions of illegal money find an asylum in the discreet banks of the republic. Here another business can prosper, which does not need any publicity: the production of cryptographic devices.

A top address for tools of secrecy was for several decades the company Crypto AG in Zug. It was founded in 1952 by the legendary Swedish cryptographer Boris Hagelin. Hundreds of thousands of his “Hagelin-machines”, pendants of the German “Enigma” devices, were used in World War II on the side of the Allies.

A prospectus of the company states: “In the meantime, the Crypto AG has built up long standing cooperative relations with customers in 130 countries.” Crypto AG delivers enciphering devices applicable to voice as well as data networks.

But behind this solid facade the most impudent secret service feint of the century has been staged: German and American services are under suspicion of manipulation of the cryptographic devices of Crypto AG in a way that makes the codes crackable within a very short time, and this allegedly happened until the end of the eighties.

Customers of Crypto AG are many honorable institutions, like the Vatican, as well as countries like Iraq, Iran, Libya, that are at the top of the priority list of U.S. services. At the beginning of the nineties the discreet company was suspected to play an unfair game. What was the source of the “direct precise and undeniable proofs” U.S. president Reagan referred to when he ordered the bombardment of Libya, the country he called the wire puller of the attack against the disco La Belle? Obviously the U.S services were able to read encrypted radio transmissions between Tripoli and its embassy in East Berlin.

Hans Buehler, a sales engineer of Crypto AG, got between the fronts of the secret service war. On March 18, 1992, the unsuspecting tradesman was arrested in Teheran. During the nine and a half months of solitary confinement in a military prison he had to answer over and over again, to whom he leaked the codes of Teheran and the keys of Libya.

In the end Crypto AG paid generously the requested bail of about one million German marks (DM), but dismissed the released Buehler a few weeks later. The reason: Buehlers publicity, “especially during and after his return” was harmful for the company. But Buehler started to ask inconvenient questions and got surprising answers.

Already the ownership of the Crypto AG was diffuse. A “foundation”, established by Hagelin, provides according to the company “the best preconditions for the independence of the company”.

But a big part of the shares are owned by German owners in changing constellations. Eugen Freiberger, who is the head of the managing board in 1982 and resides in Munich, owns all but 6 of the 6,000 shares of Crypto AG. Josef Bauer, who was elected into managing board in 1970, now states that he, as an authorized tax agent of the Muenchner Treuhandgesellschaft KPMG [Munich trust company], worked due to a “mandate of the Siemens AG”. When the Crypto AG could no longer escape the news headlines, an insider said, the German shareholders parted with the high-explosive share.

Some of the changing managers of Crypto AG did work for Siemens before. Rumors, saying that the German secret service BND was hiding behind this engagement, were strongly denied by Crypto AG.

But on the other hand it appeared like the German service had an suspiciously great interest in the prosperity of the Swiss company. In October 1970 a secret meeting of the BND discussed, “how the Swiss company Graettner could be guided nearer to the Crypto AG or could even be incorporated with the Crypto AG.” Additionally the service considered, how “the Swedish company Ericsson could be influenced through Siemens to terminate its own cryptographic business.”

The secret man have obviously a great interest to direct the trading of encryption devices into ordered tracks. Ernst Polzer*, a former employee of Crypto AG, reported that he had to coordinate his developments with “people from Bad Godesberg”. This was the residence of the “central office for encryption affairs” of the BND, and the service instructed Crypto AG what algorithms to use to create the codes. (* name changed by the editor)

Members of the American secret service National Security Agency (NSA) also visited the Crypto AG often. The memorandum of the secret workshop of the Crypto AG in August 1975 on the occasion of the demonstration of a new prototype of an encryption device mentions as a participant the cryptographer of the NSA, Nora Mackebee.

Bob Newman, an engineer of the chip producer Motorola, which cooperated with Crypto AG in the seventies to develop a new generation of electronic encryption machines, knows Mackebee. She was introduced to him as a “counselor”.

“The people knew Zug very good and gave travel tips to the Motorola people for the visit at Crypto AG”, Newman reported. Polzer also remembers the American “watcher”, who strongly demanded the use of certain encryption methods.

Depending on the projected usage area the manipulation on the cryptographic devices were more or less subtle, said Polzer. Some buyers only got simplified code technology according to the motto “for these customers that is sufficient, they don’t not need such a good stuff.”

In more delicate cases the specialists reached deeper into the cryptographic trick box: The machines prepared in this way enriched the encrypted text with “auxiliary informations” that allowed all who knew this addition to reconstruct the original key. The result was the same: What looked like inpenetrateable secret code to the users of the
Crypto-machines, who acted in good faith, was readable with not more than a finger exercise for the informed listener.

The Crypto AG called such reports “old hearsay” and “pure invention”. But the process, that was started by the company against the former employee Buehler, on the grounds that he had said that there might be some truth in the suspicions of the Iranian investigators, surprisingly ended in November of last year.

After the trial, that could have brought embarrassing details to the light, the company agreed to an settlement outside the court. Since that time Buehler is very silent with regard to this case. “He made his fortune financially,” presumed an insider of the scene.

“In the industry everybody knows how such affairs will be dealed with,” said Polzer, a former colleague of Buehler. “Of course such devices protect against interception by unauthorized third parties, as stated in the prospectus. But the interesting question is: Who is the authorized fourth?”

— “Of all tyrannies a tyranny sincerely exercised for the good of its victims may be the most oppressive. It may be better to live under robber barons than under omnipotent moral busybodies, The robber baron’s cruelty may sometimes sleep, his cupidity may at some point be satiated; but those who torment us for own good will torment us without end, for they do so with the approval of their own conscience.” – C.S. Lewis, _God in the Dock_ +———————+——————–+———————————-+ |Julian Assange RSO | PO Box 2031 BARKER | Secret Analytic Guy Union | (spam-protected) | VIC 3122 AUSTRALIA | finger for PGP key hash ID = | (spam-protected) | FAX +61-3-98199066 | 0619737CCC143F6DEA73E27378933690 | +———————+——————–+———————————-+

Comments closed

Bullshitty keynotes: not as easy as they used to be

thanks to blogs, wifi and the web, bullshitting a keynote at a conference isn’t quite as easy to pull off as it used to be! From Dan Gillmor’s keynote at Supernova, via BoingBoing:

At PCForum, Joe Nacchio, the CEO of Qwest was on-stage, doing a Q and A. Joe was whining about how hard it is to run a phone company these days. Dan (Gillmor) blogged, “Joe’s whining.” A few moments later, he got an email from someone who wasn’t at the conference, someone in Florida, with a link to a page that showed that Joe took $300MM out of the company and has another $4MM to go — gutting the company as he goes.

Esther Dyson described this as the turning point. The mood turned ugly. The room was full of people reading the blog and everyone stopped being willing to cut Joe any slack.

Comments closed

some spam quickies

I’ve just found Gary Robinson’s blog, which is a bit silly, as boasts the primary source after Paul Graham’s‘A Plan For Spam’ paper for modern Bayesian spamfiltering techniques. I’d only read Gary’s page describing the Robinson-combining technique, but he’s been doing a good job of blogging the anti-spam world in general recently. Hence, he’s made the blogroll ;)

Some choice links from his blog:

First off — Jon Udell points out why reply-to-whitelist systems are Bad:

The email thread that provoked this message will soon dissolve. Including [email protected] might have been useful, but the moment has passed. If I urgently need to contact [email protected] , I may have to grit my teeth and register to do so. But no ad-hoc communication is going to make it over that activation threshold.

And a different kind of whitelist — the IronPort Bonded Sender type, from Whitelists: the weapon of choice against spam (ZDNet):

After a one and half months of testing, IronPort identified hundreds of thousands of false-positives. At that rate, the mail generated by IronPort’s customers alone, which make up a small percentage of the total amount of e-mail that traverses the Internet, is resulting in over one million false-positives per year.

Hmm. Well, I’m not 100% convinced here — I did see Amazon.FR, who are apparently Bonded Sender customers, send a promotional mail to a mailing list. I also saw several reports from other places regarding the same mail. How often does a mailing list order goods from an e-commerce site? (But, having said that, that’s the only Bonded Sender issue I’ve seen in about 6 months — so let’s put that down to teething issues, or someone on the list who decided to act up when ordering some goods.)

Spamland.org, a new Wiki for spamfiltering.

Debra Bowen, a California State Senator, is proposing a hardcore new anti-spam bill. “It would bar unsolicited e-mail advertising and allow people who receive it to sue the senders for $500 per transmission. A judge could triple the penalty if he or she decided the violation was intentional. … ‘The ($500) fine’s really intended to get a whole generation of computer-savvy folks to help us do the enforcement,’ Bowen says. ‘Getting rid of spam is never going to be the district attorney’s first priority and it shouldn’t be.”‘ She notes also that she’s “seen estimates that it could grow to 50 percent in the next five years.” Too late — it’s already there, as far as I can tell.

FWIW, I like the sound of this — she’s requiring that commercial e-mail senders have an existing verified-opt-in relationship beforehand. Sounds good to me.

And finally, a very interesting set of tests on Robinson-combining strategies. Very interesting, that is, if you’re implementing a Bayesian spam filter. Otherwise quite boring. ;)

Comments closed

Cisco file ludicrously lame patent on regexps

from Slashdot: Cisco patents ‘Intrusion detection signature analysis using regular expressions and logical operators’.

That is so, so sad. Filed January 15, 1999. There’s got to be a stack of prior art.

A google search throws up this trivial example first off — the use of snoop | egrep 'PATTERN1|PATTERN2|PATTERN3'. More searching reveals Lance Spitzner’s page on Intrusion Detection for Checkpoint FW-1, which looks like it was originally written in 1997. The alert.sh script there uses grep(1) plentifully.

Comments closed

wheel re-invention

AT&T reinvent the wheel (via New Scientist). “a user could safely sign up for a monthly email newsletter by specifying the source of the newsletter and limiting it to 12 messages over the next year. If the address fell into the hands of spammers, their messages would be blocked by the software before it reached the user’s inbox. ‘The ‘Single Purpose’ address system reduces spam by stopping it right before the user sees it,’ says John Ioannidis, at AT&T’s research laboratory in New Jersey, US. The software is currently at the prototype stage.”

In other words, they’ve re-written TMDA, The Tagged Message Delivery Agent. Nice one.

Comments closed

Toxic darkness

BBC – the Great Smog of 1952 recalled. “Fifty years ago, a choking cloud enveloped much of London and the Home Counties – a toxic fog which killed at least 4,000 people. Here, Barbara Fewster, 74, recalls the Great Smog of 1952.” A very Ballardian tale of this environmental disaster:

After a long time we arrived at Kew Bridge – that’s at least 10 miles from Hampstead – when my fiancé called out to me, ‘I’ve lost you, where have you got to?’ I must have veered off out of range of the sidelights.

At that point, a milk float passed by and my fiancé told me to get in so we could follow its taillights. He put his foot down. Well, then the milkman disappeared and we could hear the float bouncing over the grass on Kew Green. All I could do was get out of the car and continue walking. We later came across a car that had overtaken us earlier on in the journey – it was up a tree, crashed, and no sign of the occupant.

Comments closed

Spam Never Ends

‘Spam’ Likely to Clutter E-Mail for Some Time, says Jupiter Research (via Reuters).

“It’s getting easier to send spam messages. You can buy a CD-ROM with millions of e-mail addresses for next to nothing and send it out for next to nothing,” said Jared Blank, senior analyst at Jupiter.

“Spammers are clever people and there is clearly an arms race between spammers and people trying to prevent spam that just constantly escalates,” said Forrester analyst Jim Nail. “Having simple lists of spammers and domains — that’s not enough because spammers change domains or addresses to stay ahead.”

So, good news: I have a job. Bad news: well, I think that side is obvious ;)

Comments closed