Schneier on Security

Syndicate content
A blog covering security and security technology.
Updated: 29 min 19 sec ago

New GAO Cybersecurity Report

Tue, 07/20/2010 - 5:43am
From the U.S. Government Accountability Office: "Cybersecurity: Key Challenges Need to Be Addressed to Improve Research and Development." Thirty-six pages; I haven't read it....

Violating Terms of Service Possibly a Crime

Mon, 07/19/2010 - 12:11pm
From Wired News: The four Wiseguy defendants, who also operated other ticket-reselling businesses, allegedly used sophisticated programming and inside information to bypass technological measures -- including CAPTCHA -- at Ticketmaster and other sites that were intended to prevent such bulk automated purchases. This violated the sites' terms of service, and according to prosecutors constituted unauthorized computer access under the anti-hacking...

Embedded Code in U.S. Cyber Command Logo

Mon, 07/19/2010 - 5:53am
This is excellent. And it's been cracked already....

Friday Squid Blogging: Hawaiian Bobtail Squid

Fri, 07/16/2010 - 3:34pm
Symbiotic relationship between the Hawaiian bobtail squid and bioluminescent bacteria, with bonus security implications....

Skype's Cryptography Reverse-Engineered

Fri, 07/16/2010 - 11:08am
Someone claims to have reverse-engineered Skype's proprietary encryption protocols, and has published pieces of it. If the crypto is good, this is less of a big deal than you might think. Good cryptography is designed to be made public; it's only for business reasons that it remains secret....

The NSA's Perfect Citizen

Fri, 07/16/2010 - 4:19am
In what creepy back room do they come up with these names? The federal government is launching an expansive program dubbed "Perfect Citizen" to detect cyber assaults on private companies and government agencies running such critical infrastructure as the electricity grid and nuclear-power plants, according to people familiar with the program. The surveillance by the National Security Agency, the government's...

How to Spot a CIA Officer

Mon, 06/07/2010 - 4:43am
How to spot a CIA officer, at least in the mid-1970s. The reason the CIA office was located in the embassy -- as it is in most of the other countries in the world -- is that by presidential order the State Department is responsible for hiding and housing the CIA. Like the intelligence services of most other countries, the...

Friday Squid Blogging: Kid vs. Squid

Fri, 06/04/2010 - 3:20pm
A book. Also, read this....

The Four Stages of Fear

Fri, 06/04/2010 - 2:30pm
Interesting: In the throes of intense fear, we suddenly find ourselves operating in a different and unexpected way. The psychological tools that we normally use to navigate the world­reasoning and planning before we act­get progressively shut down. In the grip of the brain’s subconscious fear centers, we behave in ways that to our rational mind seem nonsensical or worse. We...

World War II Sabotage Field Manual

Thu, 06/03/2010 - 5:44am
The OSS Simple Sabotage Field Manual from 1944....

Intelligence Can Never Be Perfect

Wed, 06/02/2010 - 5:39am
Go read this article -- "Setting impossible standards on intelligence" -- on laying blame for the intelligence "failure" that allowed the Underwear Bomber to board an airplane on Christmas Day. Although the CIA, FBI, and Defense, State, Treasury and Homeland Security departments have counterterrorism analytic units -- some even with information-gathering operations -- the assumption is that all of the...

Voluntary Security Inspections

Tue, 06/01/2010 - 12:00pm
What could possibly be the point of this? Cars heading to Austin-Bergstrom International Airport will see random, voluntary inspections Monday. The searches are part of an increase in security at the airport. It's a joint operation between the U.S. Department of Homeland Security, Austin Police, and airport security. The enhancements are not a response to specific threats, and the security...

Terrorizing Ourselves

Tue, 06/01/2010 - 4:54am
Who needs actual terrorists? How’s this for an ill-conceived emergency preparedness drill? An off-duty cop pretending to be a terrorist stormed into a hospital intensive care unit brandishing a handgun, which he pointed at nurses while herding them down a corridor and into a room. There, after harrowing moments, he explained that the whole caper was a training exercise. [...]...

Canada Spending $1B on Security for G8/G20 Summit in June

Mon, 05/31/2010 - 7:58am
Amazing: The Canadian government disclosed Tuesday that the total price tag to police the elite Group of Eight meeting in Muskoka, as well as the bigger-tent Group of 20 summit starting a day later in downtown Toronto, has already climbed to more than $833-million. It said it’s preparing to spend up to $930-million for the three days of meetings that...

Friday Squid Blogging: 500-Million-Year-Old Squid

Fri, 05/28/2010 - 3:52pm
Early squid: New Canadian research into 500 million-year-old carnivore fossils has revealed an early ancestor of modern-day squids and octopuses, solving the mystery surrounding a previously unclassifiable creature. "This is significant because it means that primitive cephalopods were around much earlier than we thought, and offers a reinterpretation of the long-held origins of this important group of marine animals," Martin...

Friday Squid Blogging: The Contents of Squid Stomachs

Fri, 05/28/2010 - 3:21pm
Not that interesting, really. Preliminarily, I can tell you that within my sample, cannibalism seems to be on the rise, myctophid consumption is falling, and a lot more squid may be dying hungry....

Another Scene from an Airport

Fri, 05/28/2010 - 11:00am
I've gotten to the front of the security line at a different airport, and handed a different TSA officer my ID and ticket. TSA Officer: (Looks everything over. Reads the name on my passport.) The Bruce Schneier? Me: (Nods, managing not to say: "No no, just a Bruce Schneier; didn't you hear I come in six-packs?") TSA Officer: The security...

Low-Tech Burglars to Get Lighter Sentences in Louisiana

Fri, 05/28/2010 - 5:24am
This is the kind of law that annoys me: A Senate bill to toughen penalties for crimes committed with the aid of Internet-generated "virtual maps," including acts of terrorism, won quick approval Monday in the House. [...] Adley's bill defines a "virtual street-level map" as one that is available on the Internet and can generate the location or picture of...

End-to-End Encrypted Cell Phone Calls

Thu, 05/27/2010 - 5:50am
Android app. (Slashdot thread.)...

If You See Something, Think Twice About Saying Something

Wed, 05/26/2010 - 8:16am
"If you see something, say something." Or, maybe not: The Travis County Criminal Justice Center was closed for most of the day on Friday, May 14, after a man reported that a "suspicious package" had been left in the building. The court complex was evacuated, and the APD Explosive Ordinance Disposal Unit was called in for a look-see. The package...