|
|
Log in / Subscribe / Register

Security quotes of the week

The fisherman caught a quantum fish. "Fisherman, please let me go", begged the fish, "and I will grant you three wishes". The fisherman agreed. The fish gave the fisherman a quantum computer, three quantum signing tokens and his classical public key. The fish explained: "to sign your three wishes, use the tokenized signature scheme on this quantum computer, then show your valid signature to the king, who owes me a favor".
Shalev Ben David, Or Sattath in the abstract for "Quantum Tokens for Digital Signatures"

The market can't fix this because neither the buyer nor the seller cares. Think of all the CCTV cameras and DVRs used in the attack against Brian Krebs. The owners of those devices don't care. Their devices were cheap to buy, they still work, and they don't even know Brian. The sellers of those devices don't care: they're now selling newer and better models, and the original buyers only cared about price and features. There is no market solution because the insecurity is what economists call an externality: it's an effect of the purchasing decision that affects other people. Think of it kind of like invisible pollution.
Bruce Schneier

For a Government-mandated initiative to teach people that it is “okay” to type your credit-card numbers into random sites on the internet — in order to see “free porn” — equates to a Government-mandated boom in identity thefts and fraudulent transactions; especially given the shoddy state of implementation (XSS & CRSF vulnerabilities ) of many porn websites.
Alec Muffett

If you're a security person you're probably used to normal people not listening to you. Sometimes we know why they don't listen, but often the users get blamed for being stupid or stubborn or something else to justify their behavior. After having a conversation the other day it was noted that some of our advice could be compared to telling someone they should only trust food that has been delivered to them by a zebra.
Josh Bressers (thanks to several LWN readers).

to post comments

Security quotes of the week

Posted Oct 13, 2016 2:13 UTC (Thu) by Garak (guest, #99377) [Link] (50 responses)

The owners of those devices don't care. Their devices were cheap to buy, they still work,
Proposal: Make the devices that are victimizing someone stop working, at least to the point of stopping their part of the attack, at least until they get fixed. Standard internet abuse notification protocols. I fail to see why that isn't the preferred solution. Except perhaps if you are persuaded by ISPs preferences to expend the least amount of effort maintaining their networks, because "it's so hard to listen to complaints, investigate them, and fix the network problems both temporarily and permanently".

But yeah, go ahead with the status quo, and realize that by doing so the next generation will have the cyber-political IQ of a Trump voter. To tangent- anybody have any article references that challenge his debate assertion that Hillary's "acid" or "bleach" (he was clearly referencing bleachbit(tm) i believe) was "very expensive". I hope people can see how problematic it is that such a Trumpism gets lost in the noise of the totality of Trumpisms. Feels choreographed to me.

Security quotes of the week

Posted Oct 13, 2016 5:19 UTC (Thu) by Cyberax (✭ supporter ✭, #52523) [Link] (49 responses)

> Proposal: Make the devices that are victimizing someone stop working, at least to the point of stopping their part of the attack, at least until they get fixed. Standard internet abuse notification protocols.
May I see the RFC that describes these abuse notification protocols?

In reality ISPs simply don't care unless users make the network unstable. And a typical DDoS zombie bot only produces maybe a couple of megabits of upstream (i.e. cheap) traffic.

On the other hand, if an ISP cuts a home security device then they can likely expect a lawsuit or at the very least a very irate customer.

Security quotes of the week

Posted Oct 15, 2016 20:38 UTC (Sat) by Garak (guest, #99377) [Link] (48 responses)

May I see the RFC that describes these abuse notification protocols?
RFC Garak1: When a network administrator for one of the constituent networks of The Internet(tm) detects abusive ingress traffic, including via user complaints, they MUST investigate the complaint. If they cannot prove the complaint is illegitimate, they MUST notify the apparent directly connected source network's administrator/owner/registered-abuse-contact. If the source network does not stop the abusive traffic in a reasonable timeframe, the network administrator MUST stop peering with the abusive network, unless the local government authorities advise otherwise and assume all liability for the abusive traffic. Such interconnection blocking shall be considered "reasonable network management" for Network Neutrality considerations.
In reality ISPs simply don't care unless users make the network unstable. And a typical DDoS zombie bot only produces maybe a couple of megabits of upstream (i.e. cheap) traffic.
I agree this is plausibly true in many cases.
On the other hand, if an ISP cuts a home security device then they can likely expect a lawsuit or at the very least a very irate customer.
Lets split the problem into legitimate and non-legitimate lawsuits. Obviously non-legitimate lawsuits are a part of the legal system. I don't think we need to address that in any other way than ensuring that judges have as much information as they need availablle to help them to sufficiently understand the issues. If there is a legitimate lawsuit that would result or has resulted, please cite the precedent so that I can argue within its context.

Likewise, we can split 'irate customers' into those that are completely irrational, and those that can be persuaded by reason. I.e. persuaded to turn off or disconnect their device that is harming the network until it gets fixed, or not feel the need to file an illegitimate lawsuit if the ISP subsequently takes disconnection into their own hands. The completely irrational irate customers we can file in the same category as those who file illegitimate lawsuits.

In general though, I concede Cyberax, that I have found no RFC better than Garak1 to address this situation. About the best I came up with was-
If the address that you are inquiring about does not have contact information in one of the RIRs, is not mentioned in the explanations above, or you have further questions, please send an e-mail to abuse-filter@iana.org so that we may look into the problem further.
https://www.iana.org/help/abuse-answers

I admit, I am surprised I was not able to quickly find an RFC better than Garak1 that addresses this issue. Perhaps some other LWN reader could cite or write a better one?

Security quotes of the week

Posted Oct 15, 2016 21:00 UTC (Sat) by Garak (guest, #99377) [Link]

and for reference-

(not an RFC) - http://archive.icann.org/en/committees/security/sac004.txt
(not a spec/standard) - https://tools.ietf.org/html/rfc4732
(not a generalization) - https://tools.ietf.org/html/rfc4987

Security quotes of the week

Posted Oct 15, 2016 22:57 UTC (Sat) by Cyberax (✭ supporter ✭, #52523) [Link] (45 responses)

> RFC Garak1: When a network administrator for one of the constituent networks of The Internet(tm) detects abusive ingress traffic, including via user complaints, they MUST investigate the complaint.
我不明白你说神么。

And you can't enforce any of your wishes. ISPs are usually in a different country with a dissimilar legal system.

Security quotes of the week

Posted Oct 15, 2016 23:26 UTC (Sat) by Cyberax (✭ supporter ✭, #52523) [Link]

我不明白你说什么, to fix a typo.

Security quotes of the week

Posted Oct 15, 2016 23:45 UTC (Sat) by Garak (guest, #99377) [Link] (43 responses)

"And you can't enforce any of your wishes."

If you'd like me to consider and respond to your point, please give a complete translation. This english sentence in itself does not mean anything to me in this context. I chose my proto-RFC wording with the following in mind already and don't understand the root problem you referred to in a language I don't understand.

"ISPs are usually in a different country with a dissimilar legal system."

I presume if I researched I would discover many RFCs that don't consider this an insurmountable problem to the issues they tackled. Let me know if you think that is an incorrect presumption.

Security quotes of the week

Posted Oct 16, 2016 0:52 UTC (Sun) by Cyberax (✭ supporter ✭, #52523) [Link] (42 responses)

> If you'd like me to consider and respond to your point, please give a complete translation. This english sentence in itself does not mean anything to me in this context. I chose my proto-RFC wording with the following in mind already and don't understand the root problem you referred to in a language I don't understand.
Have you actually _tried_ to do what you preach? Go and find a job in an ISP and then try to talk to a Chinese ISP spamming you.

> I presume if I researched I would discover many RFCs that don't consider this an insurmountable problem to the issues they tackled. Let me know if you think that is an incorrect presumption.
There are no RFCs that require ISPs to cut off their paying customers. Even an extremely mild BCP38 is far from from universal adoption.

Security quotes of the week

Posted Oct 16, 2016 2:30 UTC (Sun) by Garak (guest, #99377) [Link] (41 responses)

> If you'd like me to consider and respond to your point, please give a complete translation. This english sentence in itself does not mean anything to me in this context. I chose my proto-RFC wording with the following in mind already and don't understand the root problem you referred to in a language I don't understand.

Have you actually _tried_ to do what you preach? Go and find a job in an ISP and then try to talk to a Chinese ISP spamming you.
You seem to have ignored my request for translation. Also, this has nothing to do with me being interested in working for an ISP for a living. However for instance, just because I have no interest in working for the NSA or Wells Fargo, doesn't mean that I can't justify discussing and having an interest in how they conduct their affairs. And I certainly needn't dig into the details of their entire operation to justify an interest in a slightly less detailed perspective on their operations. Of course digging as deep into the details as necessary when necessary during the discussion.

Cyberax, I will ask you again, focus on your first points until I can grasp them instead of moving on to such nonconstructive debate tactics. I'm genuinely trying to understand the point you were trying to make in a foreign language, because I think you might actually have insights that I don't that I would benefit from understanding.

Security quotes of the week

Posted Oct 16, 2016 4:05 UTC (Sun) by Cyberax (✭ supporter ✭, #52523) [Link] (40 responses)

> You seem to have ignored my request for translation.
If you speak with Chinese ISPs that's the experience you'll get (I just wrote "I don't understand what are you talking about").

> Cyberax, I will ask you again, focus on your first points until I can grasp them instead of moving on to such nonconstructive debate tactics.
Because realistically any plan that requires ISPs to work against their clients is doomed.

Security quotes of the week

Posted Oct 16, 2016 4:46 UTC (Sun) by Garak (guest, #99377) [Link] (39 responses)

> You seem to have ignored my request for translation. If you speak with Chinese ISPs that's the experience you'll get (I just wrote "I don't understand what are you talking about").
I expect international ISP business/govpolicy relationships to be very diverse, all situations relatively handled. But given that, I still think I advocate a sane policy to aim for. AFAICT you are fine with the status quo. You know that I get that already. Move on please.
> Cyberax, I will ask you again, focus on your first points until I can grasp them instead of moving on to such nonconstructive debate tactics. Because realistically any plan that requires ISPs to work against their clients is doomed.
I see it the other way around. I see the status quo as working against their legitimate clients in favor of spammers and hackers. I think you mispaint the picture that what I suggest would wreak havoc. I think it would work out much better.

Security quotes of the week

Posted Oct 16, 2016 5:42 UTC (Sun) by Cyberax (✭ supporter ✭, #52523) [Link] (38 responses)

> I expect international ISP business/govpolicy relationships to be very diverse, all situations relatively handled. But given that, I still think I advocate a sane policy to aim for. AFAICT you are fine with the status quo. You know that I get that already. Move on please.
I'm realistic about the status quo and I actually don't want to have additional layers of useless regulation.

> I see it the other way around. I see the status quo as working against their legitimate clients in favor of spammers and hackers.
Spambots run on computers of legitimate clients.

Security quotes of the week

Posted Oct 17, 2016 3:23 UTC (Mon) by Garak (guest, #99377) [Link] (37 responses)

> I expect international ISP business/govpolicy relationships to be very diverse, all situations relatively handled. But given that, I still think I advocate a sane policy to aim for. AFAICT you are fine with the status quo. You know that I get that already. Move on please.

I'm realistic about the status quo and I actually don't want to have additional layers of useless regulation.
I think the bottom line is that I'm trying to hold the FCC and early prominent cyberpolitical voices to their Free Speech on the Internet line. In a way that I don't expect you to take the time to understand and agree with.
> I see it the other way around. I see the status quo as working against their legitimate clients in favor of spammers and hackers.

Spambots run on computers of legitimate clients.
I think the key thing is that the strategy I advocate minimizes the time that spambots run on the computers of legitimate clients/people. And at the same time, minimizing far greater harms from the issue in aggregate. Although from a biological perspective, I must confess our own bodies probably found more of your-style balance in their own battles with virii/bio-malware... herd immunity...

Security quotes of the week

Posted Oct 17, 2016 9:52 UTC (Mon) by farnz (subscriber, #17727) [Link] (36 responses)

The easiest way to implement a "no spam" policy is to cut off anyone who's use of the Internet causes offence. Otherwise, you have to distinguish "abusive speech" from "acceptable speech" in a form that's very, very hard to automate (if it was easy, neither Facebook nor Google would ever be in the press for bad decisions around speech, and yet Facebook definitely has been recently over censoring a photo).

Thus, you're asking for conflicting goals - you want Free Speech, except where it's abusive - and it's next to impossible to sort that out. Similar limits apply to Free Speech in real life - I am restrained by the US Government from engaging in certain acts of political speech, because of the consequences of doing so.

Security quotes of the week

Posted Oct 17, 2016 12:43 UTC (Mon) by mathstuf (subscriber, #69389) [Link] (26 responses)

> restrained by the US Government from engaging in certain acts of political speech, because of the consequences of doing so.

Do you have an example?

Security quotes of the week

Posted Oct 17, 2016 12:49 UTC (Mon) by farnz (subscriber, #17727) [Link] (25 responses)

Yes - for example, I'm not allowed to give someone detailed plans for lynching a presidential candidate, including details of where said candidate will be, together with instructions to make sure that said candidate dies to remind people of how America has previously treated certain groups as "less human".

More generally, any political speech that involves violence is criminalised due to the violence; indeed, we often describe violent political speech as "terrorism". Thus, there are clear limits on "freedom of speech" in the USA; I happen to agree with those limits, but they exist, nonetheless.

Security quotes of the week

Posted Oct 17, 2016 13:00 UTC (Mon) by mathstuf (subscriber, #69389) [Link] (24 responses)

Those are really only enforcible on "true threats" which is a technical legal term. Satire, exaggeration, etc. are still allowed. I recommend following Popehat for posts describing why various cases are or are not free speech.

Security quotes of the week

Posted Oct 17, 2016 13:24 UTC (Mon) by farnz (subscriber, #17727) [Link] (23 responses)

Sure, but that does cover certain forms of political speech - for example, I can't hold an unsuspecting white Harvard student hostage at gunpoint to remind people of what it's like for ghetto-dwelling blacks when they interact with the police. I shouldn't be allowed to, either, but that is a form of political speech that's prohibited due to the clash with someone else's rights, and is banned by the US government - and no amount of crying "Freedom of Speech!" will cause my First Amendment right to speak to override your common law right (it's not constitutional) to not be held hostage.

Security quotes of the week

Posted Oct 17, 2016 13:33 UTC (Mon) by mathstuf (subscriber, #69389) [Link] (22 responses)

There wouldn't even be a first amendment question there. You'd be charged with reckless endangerment, assault with a deadly weapon, and/or kidnapping. Going in with a first amendment defense would, I imagine, get an exasperating glare from the judge while your other charges would be handed down.

Security quotes of the week

Posted Oct 17, 2016 13:36 UTC (Mon) by farnz (subscriber, #17727) [Link] (21 responses)

Exactly my point - if I engage in a particularly violent form of political speech, my freedom of speech isn't even considered as part of the court process (nor should it be - that way lies madness). Thus, there are limits to "Freedom of Speech", where you simply declare a form of speech "not speech" in order to escape the question.

Security quotes of the week

Posted Oct 17, 2016 20:38 UTC (Mon) by nybble41 (subscriber, #55106) [Link] (6 responses)

> ... if I engage in a particularly violent form of political speech, my freedom of speech isn't even considered as part of the court process ...

This is not a Freedom of Speech issue because what you are describing is assault, not speech. Any action can be viewed as self-expression, but not every form of self-expression is speech.

To an extend the government dug this hole for itself by outlawing various things which ought to be perfectly legal (victimless crimes)—things which are not speech per se, but which may be needed in some cases as a precursor to effective speech. This creates a grey area where a law about something which is not speech in its own right may be deemed unconstitutional on First Amendment grounds due to its chilling effect on actual speech. However, this only concerns things which one has a natural right to do, which obviously does not include kidnapping and assault.

The generalized and consistent version of Freedom of Speech is the Non-Aggression Principle, but no government is going to adopt the N.A.P. freely since that would make it impossible for them to continue to operate.

Security quotes of the week

Posted Oct 17, 2016 20:42 UTC (Mon) by farnz (subscriber, #17727) [Link] (5 responses)

But *why* is it not speech?

I'm doing it to make a political point; it's intended as a grand statement about the way the police are perceived in certain communities. It's assault as well, yes, and that takes priority over freedom of speech, but why is it not speech to state in an overblown fashion that the police are not trusted by all parts of American society?

Basically, this is a case where freedom of speech is (rightly) overridden by other rules (such as the one against kidnapping and assault), but there's no particular reason why it's not speech, beyond the fact that you can't claim that you have absolute freedom of speech and that other rights override it.

Security quotes of the week

Posted Oct 18, 2016 2:58 UTC (Tue) by nybble41 (subscriber, #55106) [Link] (4 responses)

> But *why* is it not speech? … I'm doing it to make a political point; it's intended as a grand statement about the way the police are perceived in certain communities.

It isn't a Freedom of Speech issue because the restriction is not about the *content* of the expression, but rather the means. It's not what you say, it's how you say it. Freedom of Speech means that the government isn't permitted to step in and prevent you from making your point, or punish you for doing so, no matter how much they would prefer your silence, but it doesn't mean that you have any special rights over others or their property. The content of the speech can be whatever you wish, but your means of expression are limited what you normally have the right to do.

Freedom of Speech is a very narrow application of the Non-Aggression Principle which only covers the use of your property for the purpose of speech. Both are negative rights (non-interference) rather than positive rights (something which must be provided to you). The N.A.P. implies the freedom to use your own property (and _only_ your own property) for any purpose you wish, including speech. In both cases the old adage applies that "your right to swing your fist stops at the end of my nose". You have every right to express whatever you want using your mind, your voice, your paper, your ink—but you do not have the right to use me, or my venue, as part of your speech without my permission.

There is really too much emphasis, in my opinion, on the Freedom of Speech per se. It misses the more fundamental principle at stake and overlooks the fact that the same freedom should apply to other private and non-harmful uses of one's property. Moreover, by protecting only "speech" we open the door to restrictions on _effective_ communication methods which, while not _directly_ based on the content of the speech, still make it difficult for anyone lacking sufficient wealth and/or political connections to have their message heard by the masses. Rather than directly targeting undesirable speech, those in power can limit effective speech _in general_ to those with whom they share common interests.

> ... you can't claim that you have absolute freedom of speech and that other rights override it.

Actually you can. This is where negative and positive rights differ. Positive rights are always in conflict, because they mean that you're owed something and others are compelled to give it to you. This inevitably creates tension and a situation where everyone tries to live at the expense of everyone else. Negative rights, being grounded in non-interference, can be absolute without contradiction. You have the absolute right to freedom of speech, or more generally, the right to property—no one ever has the right to prevent you from speaking, or from otherwise using your own property. Of course, the same is true with regard to yourself—you do not have the right to prevent others from speaking, or to interfere with their own use of their property (including themselves). The only actions which are permissible are those which respect the absolute natural rights of everyone involved.

Security quotes of the week

Posted Oct 18, 2016 4:05 UTC (Tue) by mathstuf (subscriber, #69389) [Link]

I agree with this. I couldn't come up with a way to say how the kidnapping example was wrong to me, but nybble41 has done well in finding words for me at least.

Security quotes of the week

Posted Oct 18, 2016 9:38 UTC (Tue) by farnz (subscriber, #17727) [Link] (2 responses)

See, this is where my model of rights and yours differs; in my model, rights conflict, and the NAP is how you decide on the most equitable resolution of that conflict.

So, in the case of our abused Harvard student, they have a right to not be molested, which conflicts with our activist's right to speech. The NAP tells you that, in this situation, the abused student's right to not be molested is stronger than the activist's right to speech, because the activist is intruding on the student, not the other way around.

I get concerned about the "it's not about the content, it's about the means" argument, because (again taken to extremes because easy cases only make for nodding heads, not considered arguments) saying that it's unlawful to use mechanical or electrical means to amplify your speech is solely about means, not content, and yet would suggest that you can't use the Internet to exercise your right to speech.

And no, you can't. If you have absolute freedom of speech, then exercising your right to speak takes precedence over all other rights and principles; you've continued to say that you have freedom of speech conditional on the non-aggression principle. This is a reasonable position, but it does mean that my right to speak is not an absolute override on all other rights.

Security quotes of the week

Posted Oct 18, 2016 15:04 UTC (Tue) by nybble41 (subscriber, #55106) [Link] (1 responses)

> I get concerned about the "it's not about the content, it's about the means" argument, because ... saying that it's unlawful to use mechanical or electrical means to amplify your speech is solely about means, not content, and yet would suggest that you can't use the Internet to exercise your right to speech.

True, because that would not be a restriction on your Freedom of Speech, but rather on your freedom to use the Internet. This is why I said that the Non-Aggression Principle is more important than the narrow application of Freedom of Speech. Under the N.A.P. they don't have the right to deny you the use of the Internet (as an outside party with no property rights at stake), for the purpose of speech or anything else. However, as long as the prohibition is on Internet use _in general_ and not just the use of the Internet for specific types of speech, the rule would not violate the Freedom of Speech.

> ... you've continued to say that you have freedom of speech conditional on the non-aggression principle.

No, I've said that the Freedom of Speech is one application of the Non-Aggression Principle. They aren't in conflict, they're the same thing. Rights being universal, your exercise of the N.A.P. in the form of Freedom of Speech must respect the fact that others have exactly the same rights under the N.A.P. Speech is no different from any other action you might take in this regard. However, there is no profit in trying to debate this point within the self-contradictory framework of conflicting positive rights. You will not find an objective answer there to the question of which rights are "more important", only subjective opinion.

Security quotes of the week

Posted Oct 18, 2016 15:47 UTC (Tue) by farnz (subscriber, #17727) [Link]

So, as an example, if I said that you may not use electrical or mechanical means to declare your support for a political party, is that a restriction on my freedom of speech (because you've restricted content), or on my freedom to use amplification? I'd argue very strongly that it's a restriction on speech, even though it's phrased as a restriction on means too, because it's about the content, but if I'm understanding you properly, you'd say it's a restriction on means, because the key is that it's about the amplification effect that electrical or mechanical means give me?

And you're still avoiding the conflict issue - even within the NAP, there are contradictions (for example, is it illegal for you to reflect coloured photons from your clothing onto me? If not, is it illegal for you to use a perfect mirror to reflect photons from my terawatt laser pointed at my property onto me personally?)

Security quotes of the week

Posted Oct 18, 2016 19:27 UTC (Tue) by Garak (guest, #99377) [Link] (13 responses)

Exactly my point - if I engage in a particularly violent form of political speech, my freedom of speech isn't even considered as part of the court process (nor should it be - that way lies madness). Thus, there are limits to "Freedom of Speech", where you simply declare a form of speech "not speech" in order to escape the question.
Your choice of the word/phrase "_escaping_ the question" seems disingenuous to me. One could as easily and correctly characterize it as "_address_ the question". The problem I see with the status quo is that politicians and legislators and activists and speakers of all kinds would like to pretend their way out of this new equation-

A) The Internet facilitated an exponential grown in speech (via decrease in price/cost), much like the printing press did.

B) With that exponentially greater set of speech, an exponentially greater set of judicial overhead is necessary to maintain the same balance of correctly judged Free Speech versus Criminal Speech.

My perception is that a lot of politicians and businesspeople have been riding the wave of (A), while doing their best to ignore (B). Same basic equation as the (BS buzzword) IoT manufacturers trying to sell new forms of utility without bothering to consider the resulting new forms of (in)security. However I think that in an Ayn Randian sense, reality will continue to confront this problem in the form of unpleasant side effects.

Security quotes of the week

Posted Oct 19, 2016 8:13 UTC (Wed) by farnz (subscriber, #17727) [Link] (12 responses)

I've taken an extreme case, because extremes force you to think about your reasoning. However, once you've said that something I do is enough to convert my speech into not-speech (in this case violence pushes that line), what else is an acceptable reason to convert my free speech into not-speech?

While I disagree fundamentally with mathstuf, he's espousing a consistent libertarian position, where the NAP is the core principle, and freedom of speech is merely one way in which the NAP manifests; thus, for him, there is no contradiction - there is no core belief in freedom of speech, it's just something that naturally falls out, complete with the common sense limits, as a consequence of following a much more important principle.

However, if you're trying to say that freedom of speech is a right, and then having to define things as "not-speech" in order to avoid invoking that right, then you get into a thorny mess - who gets to define what is and is not speech, and why them?

Security quotes of the week

Posted Oct 19, 2016 19:46 UTC (Wed) by Garak (guest, #99377) [Link] (4 responses)

However, if you're trying to say that freedom of speech is a right, and then having to define things as "not-speech" in order to avoid invoking that right, then you get into a thorny mess - who gets to define what is and is not speech, and why them?
Judges. Because that is their job.

Security quotes of the week

Posted Oct 19, 2016 19:54 UTC (Wed) by farnz (subscriber, #17727) [Link] (2 responses)

OK, and then what legal guidance does a judge have such that they aren't just making decisions from the seat of their pants? Is it "not-speech" if it offends a thin-skinned person to the point of tears? Is it "not-speech" if your contract with your communications provider does not explicitly say it's speech? Is it "not-speech" if I'm richer than you and offended by your statements? Worse, is it "not-speech" if you're complaining to an ISP's abuse desk, but "speech" if an ISP's customer sends you data that you don't want?

The normal job of a judge is to take the law, and the situation before them, and to twist the two together such that any reasonable person would agree that they've correctly applied the law to the situation; however, if you have a right to freedom of speech, but things that are "bad" are not-speech, what stops the judge deciding that as a matter of law, running a server on a "residential" Internet link is "not-speech"?

Security quotes of the week

Posted Oct 19, 2016 20:28 UTC (Wed) by Garak (guest, #99377) [Link] (1 responses)

OK, and then what legal guidance does a judge have such that they aren't just making decisions from the seat of their pants? Is it "not-speech" if it offends a thin-skinned person to the point of tears?
I hate having to try to explain things as if to a small child in their first government/civics class, but... The obvious general answer is that most societies have fairly well laid out sets of guidance that judges must demonstrate a sufficient knowledge of before they are allowed to become judges. Law schools and so forth.

Each country and society has its own. In some societies, you'll get crucified for saying certain things. In other societies, you'll get beheaded for not saying certain things. In many societies, you will be punished for burning the local flag, but not a foreign flag. In some societies, you will be punished for burning certain books, but not punished for burning other books.

RFC-Garak1 was about forcing the automation to happen, with local official judicial settings being the ultimate bottom line of that automation. Because there just is no better way to go about it that I see. I will continue to spend as much effort as I can muster, to convince those around me, focusing on the local, extending to the global, galactic, and universal, that nobody should be punished for burning any book or flag that they own. And I won't accomplish that mission tomorrow, or next year, or in my own lifetime. That's just how I see it. $0.02...

Security quotes of the week

Posted Oct 19, 2016 20:34 UTC (Wed) by farnz (subscriber, #17727) [Link]

It's clear that you didn't pay attention in civics. The point of law school and the like is to make it easier for the judge to correctly apply law to the cases in front of them, such that (in general) it doesn't matter which judge you end up in front of, they'll all make the same decisions given the same set of facts. Then, for the cases where a mistake is made by a judge, you have an appeals process, which (ultimately) compares the law to the decision, and either confirms that the judge was right in their application of law to the case, or that they made a human mistake.

If you're saying "free speech, but only speech, not speech-like things", you need a legal definition of "speech" that judges around the country can apply. Otherwise, there's a simple way to define it for RFC-Garak1 - "speech" is spoken words transmitted by sound waves, while anything electronic is not speech; et voilà! we have today's situation unchanged.

Security quotes of the week

Posted Oct 20, 2016 12:48 UTC (Thu) by Wol (subscriber, #4433) [Link]

> Judges. Because that is their job.

And what freedom do Judges have to JUDGE?

I don't know if or how the case has been resolved, but I gather it's very recent - a man who everyone KNEW COULDN'T HAVE DONE THE CRIME was due to be executed, and nobody would step in and do anything about it, because as far as the American system was concerned, "he had had due process". The fact that it was a clear and blatant miscarriage of justice didn't enter in to the equation.

For all his faults, that was one thing that was admirable about our Judge Denning - if he thought something was wrong, he would do something about it, law or no law. As the bible says, the job of the Judge is to protect the weak and powerless!

Cheers,
Wol

Security quotes of the week

Posted Oct 19, 2016 20:19 UTC (Wed) by Garak (guest, #99377) [Link] (6 responses)

While I disagree fundamentally with mathstuf, he's espousing a consistent libertarian position, where the NAP is the core principle, and freedom of speech is merely one way in which the NAP manifests; thus, for him, there is no contradiction - there is no core belief in freedom of speech, it's just something that naturally falls out, complete with the common sense limits, as a consequence of following a much more important principle.

However, if you're trying to say that freedom of speech is a right,
I think you misconstrue the debate. Nobody is arguing for freedom of speech as so much of a right that mobs can form and rule the countryside via a sufficient number of death threats. Nobody is arguing for that. That necessary and pedantic debate is very, very old. I'll admit that it would be legitimate to throw that same sentiment at RFC-Garak1, except that there, the debate I'm trying to have is only very very old in Internet Years. In human years, it's still fairly young IMHO.

Security quotes of the week

Posted Oct 19, 2016 20:23 UTC (Wed) by farnz (subscriber, #17727) [Link] (5 responses)

In which case, please define which definition of freedom of speech you're working to - under the NAP derived version, you don't have freedom of speech on the Internet, full-stop, as to do so would require that you forced someone else to carry your bits.

Security quotes of the week

Posted Oct 19, 2016 20:35 UTC (Wed) by Garak (guest, #99377) [Link] (4 responses)

please stop pretending like you are debating my points with me in good faith. You are trying to derail the debate down pedantic rabbit holes. I clearly have an above ground goal (to be able to run my own email server like Hillary Clinton without paying a lexus lane 'business class / server allowed' tax to my ISP)

Security quotes of the week

Posted Oct 19, 2016 21:29 UTC (Wed) by Cyberax (✭ supporter ✭, #52523) [Link] (2 responses)

You have a strange fixation on email servers, that's for sure. Never mind that you can get a month of VPS subscription for less than the cost of a latte.

But anyway, you seem to be under impression that freedom of speech entitles you to get heard. That's simply not true.

Security quotes of the week

Posted Oct 19, 2016 23:01 UTC (Wed) by pizza (subscriber, #46) [Link] (1 responses)

> Never mind that you can get a month of VPS subscription for less than the cost of a latte.

In all fairness, a VPS beefy enough to handle proper spam filtering will cost about two lattes per month.

(Which in turn is costs less than the single static IP added on my "business-class" connection)

Meh. Comcast.

Security quotes of the week

Posted Oct 20, 2016 13:26 UTC (Thu) by Wol (subscriber, #4433) [Link]

And how much did it cost for the hardware to defeat the DoS on Krebs's post?

My thing about rights is nice and simple - THERE AREN'T ANY. It's my DUTY to protect free speech for others, so I can get to enjoy it too.

So all these IoT botnets and stuff clearly fall foul :-)

At the end of the day we have a DUTY not to be malicious or negligent - everything else can flow from that.

Cheers,
Wol

Security quotes of the week

Posted Oct 20, 2016 9:41 UTC (Thu) by farnz (subscriber, #17727) [Link]

I am debating in good faith - if all you're after is a fully Neutral Network, where you're not restricted from operating "servers" on your home line just because it's "residential" service, not "business" service, then say so. You've brought in a whole pile of deeply difficult issues (freedom of speech, abuse handling in the face of malicious actors) that I've got experience of from the hard side of the problem, and I'm discussing those in good faith.

I agree that "server" restrictions on "residential" lines are nonsense; not least because I have bought consumer devices that act in some senses as a server (games consoles can, as can my VoIP handset and my Slingbox), but which no residential provider would restrict due to the consumer blowback of restricting devices. However, that's entirely orthogonal to the issues you've brought into play of abuse handling and freedom of speech, which apply whether you run "servers" or not.

Security quotes of the week

Posted Oct 18, 2016 18:39 UTC (Tue) by Garak (guest, #99377) [Link] (8 responses)

The easiest way to implement a "no spam" policy is to cut off anyone who's use of the Internet causes offence. Otherwise, you have to distinguish "abusive speech" from "acceptable speech" in a form that's very, very hard to automate (if it was easy, neither Facebook nor Google would ever be in the press for bad decisions around speech, and yet Facebook definitely has been recently over censoring a photo).
That is an important key point, though my stance is that it absolutely can and should be automated, with the logical caveat that the real issue is that such automation requires plenty of person-hours of work. Work which those who advocate the status quo are happy with not getting done. Work which I believe is worth doing and getting done.
Thus, you're asking for conflicting goals - you want Free Speech, except where it's abusive - and it's next to impossible to sort that out. Similar limits apply to Free Speech in real life - I am restrained by the US Government from engaging in certain acts of political speech, because of the consequences of doing so.
That sounds nonsensical. I would respond that what I am asking for is not conflicting goals, but your next sentence would be the explanation of that point.

Unfortunately, for most of the Internet's relatively brief history, and probably still, most legislators and others have taken the path of least resistance. Pretending that they can eat their cake and have it too. The cake being the idea that the Internet(tm) is a magical place where Free Speech is possible, without the work expenditure mentioned above to tackle the important point you made. (which clearly has a long history outside the internet as one of many speech mediums)

RFC-Garak1 is basically about forcing the automation to happen, ultimately with homosapiens in official judicial settings being the ultimate bottom line of the automated system to separate legal Free Speech from criminal Free Speech (death threats, etc).

I want the cake to not be a lie.

Security quotes of the week

Posted Oct 18, 2016 18:44 UTC (Tue) by farnz (subscriber, #17727) [Link] (2 responses)

Sure, and both Google and Facebook would agree with you - but right now, automation of "abuse" detection is an active area of research, and is somewhere that ends up being seen as a competitive advantage (because, in general, it is - it's hard AI, since it needs to correctly predict the outcome of any court case that would be raised over a given bit of speech).

Security quotes of the week

Posted Oct 18, 2016 19:38 UTC (Tue) by Garak (guest, #99377) [Link] (1 responses)

Both Google and Facebook seem to profit from the overall situation. They seem to have become defacto Gatekeepers of speech on the internet. RFC-Garak1 is about empowering all internet users in the way the internet was evangelized early on. The real problem is that, in a Trump-43% world I foresee Google and Facebook's attempt to do precisely what you stated as further entrenching their status as "too big to fail". If I could compete with GMail, starting with linux and squirrelmail and a home server, combined with the ability for that solution to be distributed and used by any other internet user, without some 'business class / server allowed' lexus lane tax... Maybe someday.

Security quotes of the week

Posted Oct 19, 2016 8:20 UTC (Wed) by farnz (subscriber, #17727) [Link]

Facebook and Google are defacto gatekeepers because (a) the cost of handling abuse, even with automation on their scale, is high, and (b) people prefer an Internet free of other people's abuse (although not their own).

I run my own mailserver on a cheap VPS, and I've run my own blog before now. The issue is that you get three grades of "abuse":

  1. The obvious and easy to block - "BUY ILLEGAL DRUGS NOW FROM https://not-the-fbi.example.com/". This level of abuse is easy to fix in an automated fashion - simple pattern matching does it.
  2. The hidden pattern abuse; the text itself looks reasonable, as do the links at first glance (because they'll be changed later to redirect to somewhere malicious). However, the clue is visible when you see large numbers of comments or mails, as there's a concerted campaign of similar human-like text pointing to the same set of links.
  3. The semi-intelligent abuse; there's no obvious pattern here, beyond the fact that the text is not "an advance in the state of knowledge" but a rehash of what you should already know if you got to this point on the page. Sometimes there are links, but if there are, they're randomly selected between dangerous links under attacker control, and reasonable links like Wikipedia. This one needs AI to detect - it's very much a "I'll know it when I see it" situation.
  4. Sites that currently post good and valuable content that people link to, that later get changed to point to junk. This covers both things like "a nasty unexpected situation means that lwn.net is taken over by a spammer", and "I'm paying people to produce interesting articles that I can later redirect".

Large scale, like Facebook or Google, makes the second type of abuse trivial to automatically detect - they see so much data that the hidden pattern is obvious. It also makes the third type of abuse easier to spot - you can pull out common "non-human" mistakes across a very large corpus, and thus find accounts that never engage in "human" content creation, only "non-human". The fourth type is actively researched, and a reason for both Google and Facebook to invest in AI.

And you can cheaply compete with GMail - VPSes good enough for mail use start at about $5 per month; that this is not a commonly taken option suggests that people aren't willing to pay for mail service. Further, my ISP in the UK has no restrictions on servers, and yet lots of their customers use Office 365, GMail etc for mail, suggesting that the "server allowed" term isn't a big influencer in people's mail system choice.

Security quotes of the week

Posted Oct 19, 2016 10:10 UTC (Wed) by micka (subscriber, #38720) [Link] (4 responses)

Automation in this case is absolutely excluded. You want humans to be in the discussion before any decision is taken.
You want a human to make sure this is not a false positive (or you end up with the equivalent of DMCA take down on your own video/audio/text).

Do you want your ISP to do DPI on all your traffic? I don't, so they can't cut access for only one device, they must cut access for all the traffic for the user.
I don't know how it is where you live but I think in most of the place the ISP can't decide to cut access without first trying to solve the problem with the user (except in urgent cases, which _this is not_).
And I think I remember ECHR lean towards considering internet access is a right (as a consequence of more fundamental rights). So mandating this kind of thing would be awkward.

Then you have the question that this problem will be _not actionable_ for a majority of the population. How do I secure my device? What "device", what do you call a device? Ah that thing? It goes on Google? Ah you call it internet...

I don't think anybody would want to go that way.

Security quotes of the week

Posted Oct 19, 2016 10:31 UTC (Wed) by farnz (subscriber, #17727) [Link]

But if you don't have automation, your ISP's abuse desk is overloaded, and is best off ignoring abuse unless it affects their own customers, by and large - in other words, the status quo.

Automation can act as a simple pre-filter; an automaton with high precision (precision is the ratio of true positives to total positive flags, so high precision means a very low rate of false positives, but says nothing about false negatives) triggers an automatic cut-off with the user having the right to refer the situation to a human. You can also use a high recall (recall is the ratio of true positives to the sum of false negatives and true positives, so a high recall automaton has a very low rate of false negatives, but says nothing about false positives) automaton to determine what gets put in front of the humans. Between the two, the human doesn't deal with the obvious cases (the high precision automaton has dealt with those), nor do they deal with false triggers (the high recall automaton has dealt with those), leaving them with the difficult cases to handle only.

Security quotes of the week

Posted Oct 19, 2016 19:52 UTC (Wed) by Garak (guest, #99377) [Link] (2 responses)

Automation in this case is absolutely excluded. You want humans to be in the discussion before any decision is taken.
For important pedantic reasons I'll reiterate that when I've used the word 'automation' I've been implying that humans are part of that system, and in fact, the primary 'judgement' agents. The idea of Google or Facebook having an algorithm that in any way judges the legitimacy (versus criminality) of my speech is unacceptable to me. Pretty much what you are saying. Clearly Google and Facebook are welcome to cease allowing me to use their service if they disagree with me politically. If however they excercise that liberty, that is precisely why I need Real Free Speech on the internet in the form of hosting/operating my own server, such that Google and Facebook have no power of censorship over me.

Security quotes of the week

Posted Oct 19, 2016 20:06 UTC (Wed) by Garak (guest, #99377) [Link]

and to clarify, I doubt that unless I went out of my way, I could get Facebook or Google to censor me for political or illegitimate legal reasons. However I still feel that the overall situation has effectively censored a(n estimated) majority of Free Speech on the internet. I believe that Google and Facebook and other Gatekeeper's dangling of broad censorship powers in their Terms Of Service, prevent a vast amount of speech because of the psychological effect of the presence of the Gatekeepers, including their long-winded mandatory finely printed legal contracts (Terms Of Service / Acceptable Use Policy / etc).

Not to mention the more technical aspects of presentation of text-string speech. Clearly Facebook and Google box you in to expressing yourself in the visual formats that they offer to their users. Wheras the FOSS home server operator has no such limitations on forming the wider aesthetics of their expressions (to the extent their software development and artistic skills allow)

Security quotes of the week

Posted Oct 19, 2016 20:25 UTC (Wed) by farnz (subscriber, #17727) [Link]

You absolutely do not want humans to be the primary judgement agents for the majority of cases; final arbiters, yes, but the error rate of a human is relatively high compared to a system designed to have high precision. Indeed, a good spam filter tuned for high precision has an error rate lower than a 5 human chain can manage.

In the ideal world, you have a system with 100% precision handle the obvious cases (no human involvement). You then have a system with 100% recall decide which of the remaining cases get put before a human; these are the hard ones. A system with 100% precision cannot have a false positive (by definition); it has a mix of false negatives, true negatives, and true positives. Similarly, a system with 100% recall cannot have a false negative - it throws out a mix of true positives, false positives and true negatives. The pairing isn't perfect, because something that a 100% precision system correctly classifies as a negative can be misclassifed by a 100% recall system as a false positive - there's then no way to tell which of the two systems is correct, bar bringing in human judgement.

Security quotes of the week

Posted Oct 16, 2016 8:54 UTC (Sun) by farnz (subscriber, #17727) [Link]

I've investigated, and the abusive traffic is not intentional - it's a result of a bug in the operating system my user is running, which is an American export.

As it's not our responsibility, and the originator of the bug is in the USA (out of reach of our judicial system), I'm closing the ticket - please get your countrymen to fix all the bugs in their code as shipped over to us.

Security quotes of the week

Posted Oct 13, 2016 9:21 UTC (Thu) by epa (subscriber, #39769) [Link] (2 responses)

Isn't relying on users not to enter their credit-card number almost as doomed as relying on them not to plug in USB devices or to view documents attached to email messages?

The number is printed in big writing on the front of every card. Surely any system that requires keeping it a secret needs a rethink.

Security quotes of the week

Posted Oct 13, 2016 10:30 UTC (Thu) by eru (subscriber, #2753) [Link]

The number is printed in big writing on the front of every card. Surely any system that requires keeping it a secret needs a rethink.

But the number isn't online (until the user enters it manually). These days, crooks are not interested in information that isn't downloadable, it is just too much trouble to obtain.

Security quotes of the week

Posted Oct 13, 2016 11:02 UTC (Thu) by farnz (subscriber, #17727) [Link]

A system that relies on users not entering their credit card number unless they intend to spend money is not doomed - people are trained that they shouldn't give you access to their cards unless they want you to spend money.

What dooms card-based age verification systems (beyond the practicalities of the card networks not wanting to get involved) is that to make them work, you have to train people to give access to their cards without any intention of spending money. Once you've established that giving out your card number is a requirement for access, not just payment, you've trained people to be phished.

Security quotes of the week

Posted Oct 14, 2016 11:56 UTC (Fri) by ksandstr (guest, #60862) [Link]

>(...) some of our advice could be compared to telling someone they should only trust food that has been delivered to them by a zebra.

But this is literally true. Many "security people" argue things from a black-and-white perspective, where either there's absolute security or there's none at all; and this leads them to suggest an implicit threat model where a supposed poison might be proximity-lethal to any zebra but require ingestion to kill a human. All with a straight face, expensive marketing materials, and the full rehearsed gravitas of a Serious Professional.

Ever notice how "security people" tend to have eccentric solutions to their personal infosec? Such as running every application in a dedicated, transient VM, and nothing on the host. Yet no two of them agree what the threat model is which they're responding to: presumably all of them are chased by the all the world's TLAs at the same time, electronic preppers hugging air-gaps in their respective e-bunkers. That's for those who'll describe their solutions in the first place -- security by obscurity being a cherry on top, just in case, can't hurt you know.

Security quotes of the week

Posted Oct 20, 2016 10:39 UTC (Thu) by eduperez (guest, #11232) [Link] (2 responses)

> The market can't fix this because neither the buyer nor the seller cares. Think of all the CCTV cameras and DVRs used in the attack against Brian Krebs. The owners of those devices don't care. Their devices were cheap to buy, they still work, and they don't even know Brian. The sellers of those devices don't care: they're now selling newer and better models, and the original buyers only cared about price and features. There is no market solution because the insecurity is what economists call an externality: it's an effect of the purchasing decision that affects other people. Think of it kind of like invisible pollution.

This reminds me how the FCC deals with radio interference: there are rules about what radio signal a device may or may not emit, and the FCC enforces such rules; I think a similar scheme could be applied here.

littering on the internet

Posted Oct 23, 2016 19:01 UTC (Sun) by Garak (guest, #99377) [Link] (1 responses)

This reminds me how the FCC deals with radio interference: there are rules about what radio signal a device may or may not emit, and the FCC enforces such rules; I think a similar scheme could be applied here.
In a sense, the goal of RFC-Garak1 above was an attempt to codify legal enforcement authority in this area. Unfortunately I get the impression there are too many voices here arguing the old non-regulation line on environmental pollution. I.e, my (business's) pollution is so small it isn't hurting anyone, therefore it is a horrible violation of my liberty to point the government's gun at my head making me a slave to their overbearing cleanup/prevention plan. However at some point, the aggregate harms to society increase until the point that the imposition on liberty becomes less onerous than having years shaved off the average human lifespan because of the aggregate effect.

I'm guessing things play out similarly here, as the harms from the aggregate of compromised devices polluting the internet increase. At some point the inconveniencing of device manufacturers and users with reasonable regulation and enforcement becomes less unpleasant than choking on the pollution on the internet. Pollution that also is used as a virtual smokescreen for more insidious malicious and criminal profit-motive based activity. (and *cough* unethical state surveillance *cough*)

littering on the internet

Posted Oct 25, 2016 9:36 UTC (Tue) by micka (subscriber, #38720) [Link]

Not at all. I actually would support regulation, I mean regulation of the devices that are allowed to be sold.
I don't think some rule that say users should fix they misbehaving devices they may not even know they have or how they work would change anything to the problem. That's more magical thinking in my opinion.
But don't grant conformity marking to devices that don't provide some minimal security properties (of course, a certified device in year X would probably not pass certification in year X+1 and yet still exist, but that's the same thing with cars without airbags).
And fine and/or refuse to certify new devices from a company that fails to update their devices or fail to do product returns.

That's how other kinds of devices (cars, electric saws) got less dangerous.


Copyright © 2016, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds