Schneier On the War On the Unexpected 405
jamie found this essay by Bruce Schneier, The War on the Unexpected. (It originally appeared in Wired but this version has all the links.) "We've opened up a new front on the war on terror. It's an attack on the unique, the unorthodox, the unexpected; it's a war on different. If you act different, you might find yourself investigated, questioned, and even arrested — even if you did nothing wrong, and had no intention of doing anything wrong. The problem is a combination of citizen informants and a CYA attitude among police that results in a knee-jerk escalation of reported threats... After someone reports a 'terrorist threat,' the whole system is biased towards escalation and CYA instead of a more realistic threat assessment... If you ask amateurs to act as front-line security personnel, you shouldn't be surprised when you get amateur security."
High School Politics (Score:5, Interesting)
Humans are exceptional at detecting differences, its part of our nature, intellectually - we integrate similar concepts and differentiate between different ones. Our brains pick out differences. Thats why profiling at airports actually works.
Its nice to see someone publish something about this, but its hardly insightful.
Narrow minded. (Score:2, Interesting)
The terrorists have won... (Score:5, Interesting)
The fear is real. I hate to admit it, but it affect me.
Everyone knows that there will be further terrorist attacks on the U. S. On the one hand, we're not serious about beefing up homeland security, which is a disappointment to me--I was expecting at least a competent, good-faith effort. But we're doing all the "security theatre" stuff and none of the expensive, difficult, serious stuff. On the other hand, the Iraq war has inflamed passions in the Muslim world and created enemies where we didn't have them before. So the threat is getting worse and our defenses are not getting much better and all the "security theatre" just keeps reminding us of the issue.
On my last plane trip, the gate was near security, and my wife and I were watching as some woman got some kind of very, very extended attention from the TSA people. She was dressed in some kind of dark robe that covered her body, her head, and most of her face; it looked to me like a burkha, but I don't really know anything about such things. She also had a somewhat disfigured face, with a golf-ball-sized lump of some kind on one side of her forehead.
From our vantage point it was all pantomime. I don't know why they were searching her. But they would ask her questions, then wave those handheld metal-detector frisking things, have her sit down for a while, go away and come back with other officials who would ask her more questions and so forth. After about a half an hour she was still sitting there in the security area waiting. They announced that our flight was boarding and we got on and don't know anything more.
What I hated myself for was that I personally was creeped out by this person and her appearance. And what I particularly hated myself for was that the things creeped me out were a) her style of dress, and b) her disfigured face.
Part of me was indignant at what looked from a distance to be discriminatory treatment. And part of it was great relief that she was not on my flight.
Re:blame the media for CYA (Score:3, Interesting)
Not too long after the London bus bombings a local TV crew took it on themselves to see if they could infiltrate a local bus depot. So they get in and film themselves walking around buses and sitting in a couple of them. The go and disclose this on TV but never get brought up on charges themselves since it's such an embarrassment to the local transit authority.
So what's it going to be, folks? Police, guards and cameras on every corner to satisfy the media? How much longer can the media get away with watching everyone but having no recourse to actually being honest and fair in their offerings?
The media is, for the most part, a bunch of shitballs. It's unbelievable how much they're able to get away with and how little they're accountable for.
Sorry, Bruce, you're just wrong.... (Score:2, Interesting)
All security analysis, whether physical or electronic, starts with looking at patterns. An IDS is a perfect example, it looks for patterns and reports on them. Guess what, Bruce? IDS have false positives, a lot of them. It takes a trained security professional to analyze what the IDS thinks is an alert and determine whether it's a real threat.
Eventually someone came up with IDS systems that analyze your normal IDS traffic, and start to alert on things that aren't normal. For example, if you have a link you only see SSH connections on, and all of a sudden there are FTPs, it will alert. Again, a trained security professional looks at the alert and decides if it's a real threat.
The IDS system is analogous to the people on the street reporting strange events, except the people on the street have more intelligence than a typical IDS system (for example, I've never seen this guy (FTP) in my neighborhood, but someone just moved in across the street, ah yes he just unlocked the door there, must be the new owner). People know what is unusual, what doesn't fit into their neighborhood, more so than IDS systems.
And the police officer is analogous to the security professional. A person (IDS) reports an event to me. I take in as much information as I can, and determine whether it's a real threat. If I don't have enough information, I get it. If I can't, I continue to monitor the activity. If it looks threatening, I escalate it.
However, Bruce, when you say that police shouldn't rely on the individuals on the street to help with security, you're like saying I should take down my IDS systems. It's a ridiculous statement. You say it's amateurish? Well, without individuals on the street calling in things they think is unusual, then police don't know someone is unusual. Just like an IDS system, if it doesn't tell me something is anomalous, I don't know whether to go in and check it.
The simple fact is that because people didn't report the unusual behavior of many of the 9/11 attackers, e.g. taking flight lessons that only focused on flying, getting pulled over without licenses, getting pulled over with illegal immigration statuses.... BECAUSE no one reported that activity, they went and hijacked 4 aircraft and killed 3000 people.
Specifically, Bruce... when you say we've opened up the war on the unusual, this is EXACTLY what more modern IDS/IPS systems do, they don't look at signatures, they look at UNUSUAL TRAFFIC. When it finds UNUSUAL TRAFFIC it REPORTS IT to you, then you INVESTIGATE IT, you QUESTION THE PEOPLE INVOLVED, and if they did something against policy you REMOVE THEM FROM THEIR JOBS. YES BRUCE, THIS IS WHAT YOU DO.
Also, on another rant. What's YOUR solution, Bruce? You tell us how NOT to do it, but you have no solutions yourself. Oh wait, you do... you tell us we should do EXACTLY what you rant against:
Yes, I can agree that some people blow shit out of proportion, this happens everyday and is part of the human nature (especially for those that love drama). But that doesn't mean we should stop this activity, law enforcement just needs to become better at detecting the actual threats and escalating incidents at the same time fine-tuning their "IDS" systems to what is real threats. This isn't something that will happen overnight, but doesn't mean we should stop it completely!
I tip my hat to your sarcasm... (Score:2, Interesting)
Hiding in plain sight (Score:3, Interesting)
Re:Dejavu (Score:5, Interesting)
"The tools of conquest do not necessarily come with bombs and explosions and fallout. There are weapons that are simply thoughts, attitudes, prejudices, to be found only in the minds of men. For the record: prejudices can kill, and suspicion can destroy, and the thoughtless, frightened search for a scapegoat has a fallout all of its own, for the children and the children yet unborn. And the pity of it is that such things cannot be confined... to The Twilight Zone."
Re:Dejavu (Score:5, Interesting)
Basically, the problem of getting the bomb to the useful place has just changed the place: it used to be the plane. Now it can be the airport check in queues. Next would be the airport entrances. There will always be a mass of people checking in somewhere, at least until the damn flying cars are finally here.
Re:Dejavu (Score:3, Interesting)
No. Frankly, you should not. Not unless, you're calling out to the person who left the bag by accident, out of genuine concern that they get their bag back.
Here's the thing: Let me make some new common sense: Attitude and mindset matter. Attitude and mindset determine how people think, how they relate with others, and so on.
If everybody is looking out for suspicious behavior, thinking to call the cops, and making the kinds of arguments you are, then we're headed in totally the wrong direction. We need a world of care, goodwill, freedom, and love, not one of fear, paranoia, reporting, and the panopticon. You're right, it does sound ominous, and we don't need that kind of thing here.
We need clarity of intent: Community, care, heart, cooperation, generosity.
We can't hold that, while thinking, "I've got to be on the lookout for anything that might be suspicious."
So I say: "No." Even looking out for suspicious behavior, it's not going to work. The person who wants to kill you or destroy the bridge will find a way. They will just not walk away, before using the bomb. They'll have someone else deliver the bomb.
There is no security, save security in the social fabric itself.
Boston Police Stopped Me (Score:3, Interesting)
The police were firm but polite in their in-park ten-minute interrogation. They said things like "maybe you shouldn't walk around in public parks." and "don't you think it's a bad idea to say 'good morning' to a complete stranger?". They believed me when I said I was Canadian -- after seeing my passport and driver's licence. (yeah, passport wasn't enough for them. I have no clue how they were able to authenticate an Ontario driver's licence, Massacheusets has something that looks like it's off a 1985 inkjet.)
It was really just one crazy woman -- I greeted many people during the week, and others, notably injured Kelly, and also fishing Steve, were exceptionally nice.
All the same, I was glad when they let me leave the country five days later.