Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, June 24, 2009

This is Totally Cool


New York Times rolls a piece on the hyper-secretive, security-obsessed culture at Apple. My guess is that it's unlikely to change after Jobs leaves.

Money graph:
Secrecy at Apple is not just the prevailing communications strategy; it is baked into the corporate culture. Employees working on top-secret projects must pass through a maze of security doors, swiping their badges again and again and finally entering a numeric code to reach their offices, according to one former employee who worked in such areas.

Work spaces are typically monitored by security cameras, this employee said. Some Apple workers in the most critical product-testing rooms must cover up devices with black cloaks when they are working on them, and turn on a red warning light when devices are unmasked so that everyone knows to be extra-careful, he said.


To me, this by itself is almost reason to avoid Apple's stock -- I'm not a fan of the black-box approach -- but cool nonetheless, no?

Wednesday, April 15, 2009

And Kentucky's Election Thieves Win the Prize


... for being the first, presumably, to commit documented voting-machine fraud. Congratulations!

The fraud is actually kinda slick and exploits two key points of weakness: a difference between what the printed instructions say and what the system actually does, and people's unfamiliarity with a system they use maybe once or twice a year, a system of which they have no real under-the-hood understanding. The gist of the attack was this:

1) There are different types of voting machines used by the same vendor. Some of the machines, manufactured by Omaha-based Election Systems & Software, use the "cast vote" button as the last step in the process. Other machines of the same model family (the "iVotronic") use "cast vote" as the second to last step in the process. In these machines, which were used in the fraud, the cast-vote button prompts the user to confirm.

2) The documented instructions for the second group of machines was written for the first group. The written instructions voters saw told them that cast-vote was the final step, even though it wasn't.

3) It was an inside job. After the voter pressed the cast-vote button -- which they were explicitly told by both the machine's written instructions and by in-on-the-scam polling-place officials was the last thing they needed to do -- but left before pressing confirm, a polling-place worker slipped into the booth, "corrected", shall we say, the ballot, and then confirmed, making the worker's vote the official vote recorded by the system.

There is one way, and only one way to do electronic-voting right: The voter MUST leave with a hard-copy receipt of their vote. That, of course, doesn't matter if voters are told by corrupt officials that they don't need receipts or that the machine doesn't give them. But keeping people inside the system from subverting the system is the eternal challenge of security, and the receipt system requires that *all* workers of a given polling place be in on it. If only one non-rogue worker tells voters to not leave without their receipt, then this fraud cannot take place.

Fourth Annual Movie-Plot Threat Contest


Security guru Bruce Schneier is hosting his annual contest for people to submit their best "movie plot" terrorism threats. It is Schneier's belief that security measures built to defend against very specific threats (say, a bomb in a shoe) are destined to fail and are often used only to scare people. I'll let him explain the contest. From his newsletter:

Let's face it, the War on Terror is a tired brand. There just isn't enough action out there to scare people. If this keeps up, people will forget to be scared. And then both the terrorists and the terror-industrial complex lose. We can't have that.

We're going to help revive the fear. There's plenty to be scared about, if only people would just think about it in the right way. In this Fourth Movie-Plot Threat Contest, the object is to find an existing event somewhere in the industrialized world -- Third World events are just too easy -- and provide a conspiracy theory to explain how the terrorists were really responsible.

The goal here is to be outlandish but plausible, ridiculous but possible, and -- if it were only true -- terrifying. Entries should be formatted as a news story, and are limited to 150 words (I'm going to check this time) because fear needs to be instilled in a population with short attention spans.

Well, we can't very well have people walking around in states of non-fear. That just won't do at all.

If you're of an imaginative and scary mind, submit your entry here. Tips on how to write a good terrorism story can be found here