Tuesday, August 17, 2004
Security Certification for PIN Entry Devices
Having been inconvenienced by card skimming, I found this Register article on Visa's PIN entry device certification program very interesting.
Friday, August 06, 2004
My complaint to Toyota, Part 3
So, having given up on Toyota Motor Sales, U.S.A., Inc. (that's the American affiliate, I gather), I turned to Toyota Canada, Inc., even though no vehicle purchase was involved:
Toyota Canada, Inc. quickly responded:
This left me puzzled... especially the
Their response was priceless:
That's right, folks: that smacking sound is me being batted back and forth between the American and Canadian arms of Toyota. :-) There's more to come, though; I'm not giving up yet.
Hi,
I'm trying to submit a complaint to Toyota Worldwide [the parent company, also referred to as Toyota Motor Corporation later on --John], but there doesn't seem to be any means of doing this through the toyota.co.jp Web site.
I filed it with toyota.com and got the following response:
Response (Michael) 08/04/2004 07:59 AM
Thank you for contacting Toyota Motor Sales, U.S.A., Inc.
We apologize, Toyota Motor Sales, U.S.A., Inc. only handles inquiries for vehicles sold in the United States and manufactured to U.S. specifications. Please contact Toyota Canada, Inc. for further assistance with your inquiry.
--
My original complaint [posted earlier --John] follows. Any assistance would be greatly appreciated.
I'm trying to submit a complaint to Toyota Worldwide [the parent company, also referred to as Toyota Motor Corporation later on --John], but there doesn't seem to be any means of doing this through the toyota.co.jp Web site.
I filed it with toyota.com and got the following response:
Response (Michael) 08/04/2004 07:59 AM
Thank you for contacting Toyota Motor Sales, U.S.A., Inc.
We apologize, Toyota Motor Sales, U.S.A., Inc. only handles inquiries for vehicles sold in the United States and manufactured to U.S. specifications. Please contact Toyota Canada, Inc. for further assistance with your inquiry.
--
My original complaint [posted earlier --John] follows. Any assistance would be greatly appreciated.
Toyota Canada, Inc. quickly responded:
Dear Mr. Jarvis,
Thank you for your recent correspondence.
We have noted your comments regarding the advertisement and have forwarded them to the appropriate departments within Toyota Canada Inc. for information purposes.
Thank you again for taking the time to write and for providing us with your feedback.
Sincerely,
Christine James
Toyota Canada Inc.
Thank you for your recent correspondence.
We have noted your comments regarding the advertisement and have forwarded them to the appropriate departments within Toyota Canada Inc. for information purposes.
Thank you again for taking the time to write and for providing us with your feedback.
Sincerely,
Christine James
Toyota Canada Inc.
This left me puzzled... especially the
information purposespart:
Thanks for the quick response, Christine. I am a little puzzled, however. First, I'd asked two questions at the end of my comments, so they weren't simply intended to inform. Second, am I to understand that Toyota Canada, Inc. was responsible for the production of the advertisement in question? I'd assumed it was produced by Toyota Motor Corporation for an international audience (dubbed in various languages, as appropriate). [I've since realized that the commercial is silent, greatly simplifying this job. --John]
If this is indeed the case, I would appreciate your help in forwarding my comments to Toyota Motor Corporation.
Cheers,
John
If this is indeed the case, I would appreciate your help in forwarding my comments to Toyota Motor Corporation.
Cheers,
John
Their response was priceless:
Thank you for your recent correspondence.
We have noted your further comments. As well, we would like to take this opportunity to explain that Toyota Canada Inc. and Toyota Motor Sales, U.S.A. (TMS) are separate business entities, as such, we suggest contacting TMS's Customer Relations directly for comment at the following:
TMS
Customer Relations
19001 South Western Ave
Torrance CA USA
90509-2991
Phone: (800) 331-4331
Fax: (310) 618-7814
We would also like to mention that TMS can be contacted through their website - www.toyota.com - select 'Contact Us' at the bottom of the main page, next select the 'FAQ page' link. You may have to create an account with TMS.
Thank you again for taking the time to write.
Sincerely,
James Mcwade
Toyota Canada Inc.
We have noted your further comments. As well, we would like to take this opportunity to explain that Toyota Canada Inc. and Toyota Motor Sales, U.S.A. (TMS) are separate business entities, as such, we suggest contacting TMS's Customer Relations directly for comment at the following:
TMS
Customer Relations
19001 South Western Ave
Torrance CA USA
90509-2991
Phone: (800) 331-4331
Fax: (310) 618-7814
We would also like to mention that TMS can be contacted through their website - www.toyota.com - select 'Contact Us' at the bottom of the main page, next select the 'FAQ page' link. You may have to create an account with TMS.
Thank you again for taking the time to write.
Sincerely,
James Mcwade
Toyota Canada Inc.
That's right, folks: that smacking sound is me being batted back and forth between the American and Canadian arms of Toyota. :-) There's more to come, though; I'm not giving up yet.
Wednesday, August 04, 2004
My complaint to Toyota, Part 2
Well, Toyota responded this morning:
An invitation to complete a customer survey followed this message. I responded to the questions about their Web site and customer service as follows:
Up next: Part 3: Toyota Canada, Inc.
Response (Michael) 08/04/2004 07:59 AM
Thank you for contacting Toyota Motor Sales, U.S.A., Inc.
We apologize, Toyota Motor Sales, U.S.A., Inc. only handles inquiries for vehicles sold in the United States and manufactured to U.S. specifications. Please contact Toyota Canada, Inc. for further assistance with your inquiry.
Toyota Canada, Inc.
1 Toyota Place
Scarborough, ON
Canada M1H 1H9
888-869-6828
If we can be of further assistance, please feel free to contact us.
Toyota Customer Experience
Thank you for contacting Toyota Motor Sales, U.S.A., Inc.
We apologize, Toyota Motor Sales, U.S.A., Inc. only handles inquiries for vehicles sold in the United States and manufactured to U.S. specifications. Please contact Toyota Canada, Inc. for further assistance with your inquiry.
Toyota Canada, Inc.
1 Toyota Place
Scarborough, ON
Canada M1H 1H9
888-869-6828
If we can be of further assistance, please feel free to contact us.
Toyota Customer Experience
An invitation to complete a customer survey followed this message. I responded to the questions about their Web site and customer service as follows:
I don't feel it's proper to expect people to create an account before they can submit questions or comments to your company. Someone (or some group) should be monitoring a feedback@toyota.com address. I felt my comments were important enough to warrant registering with your Web site; I doubt many others would bother.
As for the response I received, I was simply sluffed off to the Toyota Canada based on my location; it's obvious that the person didn't even read my complaint, since it had nothing to do with a vehicle I'd purchased (their excuse for the rebound). If anything, my complaint should've been forwarded on (by them, not me) to the appropriate department of Toyota Worldwide.
As for the response I received, I was simply sluffed off to the Toyota Canada based on my location; it's obvious that the person didn't even read my complaint, since it had nothing to do with a vehicle I'd purchased (their excuse for the rebound). If anything, my complaint should've been forwarded on (by them, not me) to the appropriate department of Toyota Worldwide.
Up next: Part 3: Toyota Canada, Inc.
My complaint to Toyota
I saw your "splitting" Matrix ad (the one where the cars part and merge like drops of water) in the movie theatre again tonight, and, since it still offended me, I decided to write.
Specifically, I complaining about the way it opens, with the Matrix driving straight at the meridian before the tunnel. First of all, the fact that it's the first image that we're presented with tends to drill it into our minds for the length of the ad (and beyond), but, even worse in my mind, is it's being completely unnecessary; there are many other ways to introduce this idea of splitting that aren't nearly so evocative.
Just on the off chance that you have no idea what that image of driving into a meridian evokes, it is almost the exact image that was presented to the world following the death of Princess Diana in the summer of 1997. I asked two other people - keep in my mind that it's only my second time seeing the ad - about the first thought that entered their heads after seeing the image, and they both responded with Diana's death. I'm confident that more asking would elicit similar responses.
Normally, I'm all for freedom of expression in art - it's what kept me from writing this complaint after my first viewing - however, I really feel that this ad constitutes a gratuitous use of that particular image, both in its placement (i.e., at the beginning of the ad) and its relevance (i.e., it's really not referenced again; cars split and merge without any catalyst, if you will, throughout the rest of the ad).
Now, I'm not suggesting that you pull the ad - again, I'm a firm believer in letting others decide for themselves what they deem to be offensive - but I am interested in knowing whether you were aware of the striking similarities between your footage of the tunnel meridian and the shots of the wreckage where Princess Diana and Dodi Fayed died, and if so, why you decided to include them.
Thanks,
John Jarvis
Specifically, I complaining about the way it opens, with the Matrix driving straight at the meridian before the tunnel. First of all, the fact that it's the first image that we're presented with tends to drill it into our minds for the length of the ad (and beyond), but, even worse in my mind, is it's being completely unnecessary; there are many other ways to introduce this idea of splitting that aren't nearly so evocative.
Just on the off chance that you have no idea what that image of driving into a meridian evokes, it is almost the exact image that was presented to the world following the death of Princess Diana in the summer of 1997. I asked two other people - keep in my mind that it's only my second time seeing the ad - about the first thought that entered their heads after seeing the image, and they both responded with Diana's death. I'm confident that more asking would elicit similar responses.
Normally, I'm all for freedom of expression in art - it's what kept me from writing this complaint after my first viewing - however, I really feel that this ad constitutes a gratuitous use of that particular image, both in its placement (i.e., at the beginning of the ad) and its relevance (i.e., it's really not referenced again; cars split and merge without any catalyst, if you will, throughout the rest of the ad).
Now, I'm not suggesting that you pull the ad - again, I'm a firm believer in letting others decide for themselves what they deem to be offensive - but I am interested in knowing whether you were aware of the striking similarities between your footage of the tunnel meridian and the shots of the wreckage where Princess Diana and Dodi Fayed died, and if so, why you decided to include them.
Thanks,
John Jarvis
Saturday, July 24, 2004
On protection from unreasonable searches and racial profiling...
My buddy's thoughts on Phillip Henry Mann's acquittal got me started... :-)
First, I don't agree that the story begs the question: should a criminal have a reasonable expectation of privacy? If the police have reasonable grounds for suspecting that someone's a criminal, then they can take that person downtown for questioning. So, yes, if they have reasonable grounds for suspecting someone's trafficking drugs, by all means, stop the guy and bring him downtown for questioning. The key point in this story is that after the initial pat down and questioning (which I completely agree with; I don't want to see a cop wounded or killed by some scared kid any more than the next guy), they got the guy to empty his pockets because they were curious about the soft object they'd felt (as I read it). If they were surprised by what it was (i.e., they didn't suspect they'd find it when they approached the individual), and they'd convinced themselves that they weren't in any danger prior to asking to see the contents of the pocket, then there's no reasonable grounds for the search.
See, as with any aspect of the law, you've gotta go out to the boundary cases... Those improbable, and often really scary, situations. In this case, yeah, you know, I'm not saying it'd be the end of democracy as we know it if this guy lost his weed, paid a fine, etc. But what about the 911: The Road to Tyranny footage of the woman being pulled over and eventually charged with obstruction of justice? For those who haven't seen that excellent documentary, think of ticket quotas or cop surliness taken to an unreasonable extreme. Legislation is our only protection against these, thankfully rare, sorts of abuse.
Now, on racial profiling, I'll just tackle a few of its many facets. First and foremost, one should always be mindful of the biases and mind-sets of the people involved; the concept of racial profiling should never be separated from the people involved in the real-world situation, because their biases will have a huge impact on how the concept is applied. For example, if it's obviously a crutch propping up sloppy work, then we, as a society, have a problem.
But, for the sake of argument, let's say that, from a counterterrorism standpoint, some degree of racial profiling makes sense strategically (as in your example of al-Qaida). That is, it makes sense to look for people of a specific ethnicity in the search for the rest of that particular terrorist group. Now, how that appropriateness is applied tactically, in certain American and Canadian cities, for example, is another kettle of fish entirely. We must compare them very carefully (as I mentioned), keeping in mind the freedoms that we enjoy and the concept of being innocent until proven guilty in a court of law.
It's scary stuff, man. If you're on the right side of the law today, then, yeah, sure, pull over, let them search your car, your home, your pockets; you've got nothin' to hide. But, s**t, look out if you happen to be on the wrong side of things tomorrow.
First, I don't agree that the story begs the question: should a criminal have a reasonable expectation of privacy? If the police have reasonable grounds for suspecting that someone's a criminal, then they can take that person downtown for questioning. So, yes, if they have reasonable grounds for suspecting someone's trafficking drugs, by all means, stop the guy and bring him downtown for questioning. The key point in this story is that after the initial pat down and questioning (which I completely agree with; I don't want to see a cop wounded or killed by some scared kid any more than the next guy), they got the guy to empty his pockets because they were curious about the soft object they'd felt (as I read it). If they were surprised by what it was (i.e., they didn't suspect they'd find it when they approached the individual), and they'd convinced themselves that they weren't in any danger prior to asking to see the contents of the pocket, then there's no reasonable grounds for the search.
See, as with any aspect of the law, you've gotta go out to the boundary cases... Those improbable, and often really scary, situations. In this case, yeah, you know, I'm not saying it'd be the end of democracy as we know it if this guy lost his weed, paid a fine, etc. But what about the 911: The Road to Tyranny footage of the woman being pulled over and eventually charged with obstruction of justice? For those who haven't seen that excellent documentary, think of ticket quotas or cop surliness taken to an unreasonable extreme. Legislation is our only protection against these, thankfully rare, sorts of abuse.
Now, on racial profiling, I'll just tackle a few of its many facets. First and foremost, one should always be mindful of the biases and mind-sets of the people involved; the concept of racial profiling should never be separated from the people involved in the real-world situation, because their biases will have a huge impact on how the concept is applied. For example, if it's obviously a crutch propping up sloppy work, then we, as a society, have a problem.
But, for the sake of argument, let's say that, from a counterterrorism standpoint, some degree of racial profiling makes sense strategically (as in your example of al-Qaida). That is, it makes sense to look for people of a specific ethnicity in the search for the rest of that particular terrorist group. Now, how that appropriateness is applied tactically, in certain American and Canadian cities, for example, is another kettle of fish entirely. We must compare them very carefully (as I mentioned), keeping in mind the freedoms that we enjoy and the concept of being innocent until proven guilty in a court of law.
It's scary stuff, man. If you're on the right side of the law today, then, yeah, sure, pull over, let them search your car, your home, your pockets; you've got nothin' to hide. But, s**t, look out if you happen to be on the wrong side of things tomorrow.
Saturday, July 17, 2004
On wanting to believe versus believing...
I was doing my part to make Slashdot a better place, metamoderating away, when I came to a comment on Pascal's Wager: an argument for believing in God, basically. Well, in reading the context of the comment, I came to a reply by Dunbar the Inept that echoed my thoughts on belief.
My religious experiences didn't touch on this wager, or any other argument for believing or not. It's as if it was assumed that I believed because I was in Sunday school, because I was confirmed (O.K., maybe there was an argument for the assumption in that case) and because I read some of the Bible, when, in fact, I was conflicted.
And these experiences aren't limited to my United Church of Christ days: as I briefly discussed last month, I quickly became discouraged as I read the Qur'an, with its strong language against anyone who doesn't hold belief in their heart. What's amusing is that, were I able to flick belief on like a switch, I would be insane (as Dunbar pointed out).
My religious experiences didn't touch on this wager, or any other argument for believing or not. It's as if it was assumed that I believed because I was in Sunday school, because I was confirmed (O.K., maybe there was an argument for the assumption in that case) and because I read some of the Bible, when, in fact, I was conflicted.
And these experiences aren't limited to my United Church of Christ days: as I briefly discussed last month, I quickly became discouraged as I read the Qur'an, with its strong language against anyone who doesn't hold belief in their heart. What's amusing is that, were I able to flick belief on like a switch, I would be insane (as Dunbar pointed out).
Tuesday, July 13, 2004
On kids and the Web...
HaloScan's basic account restricts comments on the owner's site to 1000 characters. Who knew I'd have so much to say on this post by Deirdre?
Brian captured my thoughts on the first point; security through obscurity shouldn't be your only line of defense.
On the second point, I'll bite. From the MacCentral article on the ruling:
I disagree. If I were a parent - and I'm not, so, yes, take that into account - I wouldn't be relying on legislation or technology to assuage my fears about what's going on behind closed doors.
Depending on the age and maturity of the child, I would rely on either supervised Web time only, or my child's judgment and our open relationship. Gone are the days of unsupervised research with the children's encyclopedia or Britannica. If my kid needed to do research on tadpoles, filtering software (even the ICRA functionality in Internet Explorer seems to work well, although it requires some work on the Web site author's part) plus my supervision would be the only way to go. As they got older, some unsupervised time could be introduced... It comes down to being my responsibility.
Having the government determine what the
Tread lightly, people. We have to live with these decisions.
Brian captured my thoughts on the first point; security through obscurity shouldn't be your only line of defense.
On the second point, I'll bite. From the MacCentral article on the ruling:
If the law hadn't been challenged, a workable solution would now be in place... Parents wouldn't be afraid to leave their kids alone in the room with the computer on.
I disagree. If I were a parent - and I'm not, so, yes, take that into account - I wouldn't be relying on legislation or technology to assuage my fears about what's going on behind closed doors.
Depending on the age and maturity of the child, I would rely on either supervised Web time only, or my child's judgment and our open relationship. Gone are the days of unsupervised research with the children's encyclopedia or Britannica. If my kid needed to do research on tadpoles, filtering software (even the ICRA functionality in Internet Explorer seems to work well, although it requires some work on the Web site author's part) plus my supervision would be the only way to go. As they got older, some unsupervised time could be introduced... It comes down to being my responsibility.
Having the government determine what the
average person, applying contemporary community standards, would find obscenescares me, to be honest. We're talking about getting rid of the artistic merit defense up here in Canada too, and I just keep thinking that, yes, it sounds reasonable in many, even most, scenarios that proponents bring up. But what about the cases at the extremes of the spectrum? What about the filmmaker who shies away from the story that needs to be told for fear of going to jail?
Tread lightly, people. We have to live with these decisions.
Card Skimming
My bank disabled my banking card over the weekend; apparently, I used it at a location that's under investigation for card skimming. When I first got the call Sunday morning, I thought I'd pegged the compromised automated banking machine, but today the teller told me it could've been any location - including stores - I'd banked at in the last month. (They don't give out the location to avoid compromising the investigation.)
Now, one scheme I've heard of reads the information off the magnetic stripe on your banking card while a camera in the pamphlet holder records you entering your PIN. I learned today that a common scheme ignores the PIN, making a copy of your card and forcing a reset of the PIN with a master PIN, using the same machine you use to change your PIN at your branch. Schneier would love it! Foiled again by a global secret (in all card writers, in this case).
The good news is that so long as I notify the bank within 24 hours of learning my banking card has been lost or stolen, I'm not liable for any of the subsequent charges. Same goes for the scenario where the bank informs me of the compromise, obviously (which is why I still suspect that it was that ABM I used on Friday; the bank disabled the card right away because they knew they'd be footing any bill the skimmers or their friends racked up). Now, this all assumes that I haven't contributed to the compromise (e.g., helpfully writing my PIN on a Post-it stuck to my card, giving my card and PIN to my long-lost Uncle Bob so he can buy some smokes); should the bank be able to prove otherwise, I could be liable for even more than my account balance!
Now, one scheme I've heard of reads the information off the magnetic stripe on your banking card while a camera in the pamphlet holder records you entering your PIN. I learned today that a common scheme ignores the PIN, making a copy of your card and forcing a reset of the PIN with a master PIN, using the same machine you use to change your PIN at your branch. Schneier would love it! Foiled again by a global secret (in all card writers, in this case).
The good news is that so long as I notify the bank within 24 hours of learning my banking card has been lost or stolen, I'm not liable for any of the subsequent charges. Same goes for the scenario where the bank informs me of the compromise, obviously (which is why I still suspect that it was that ABM I used on Friday; the bank disabled the card right away because they knew they'd be footing any bill the skimmers or their friends racked up). Now, this all assumes that I haven't contributed to the compromise (e.g., helpfully writing my PIN on a Post-it stuck to my card, giving my card and PIN to my long-lost Uncle Bob so he can buy some smokes); should the bank be able to prove otherwise, I could be liable for even more than my account balance!
Saturday, July 10, 2004
On Shapiro's Understanding the Windows EAL4 Evaluation...
I should've done this a long time ago. It seems like every time a Common Criteria (CC) story hits Slashdot, some would-be expert hyperlinks to Jonathan S. Shapiro's Understanding the Windows EAL4 Evaluation, like it's the CC's Brutus. However, as often happens in discussions involving the CC, people misunderstand (and often overstate) what the CC and an EAL say about the security a product provides.
While Shapiro gets the general idea, you should understand that the Protection Profile (PP) hasn't caught on like most of the those involved in the project probably expected. It's optional, first of all, and requires a lot of time and effort from groups who are independent of the security product companies (e.g., consumer rights groups) to work. There are exceptions (e.g., the Smart Card Protection Profile), but, for the most part, the consumers, or their independent representatives, must define their own security needs for this step to be of some utility.
The reason is that if the consumer doesn't understand the PP - the Controlled Access Protection Profile is a good example - then they won't understand the company's security target that claims conformance to that PP, nor what the evaluation - and its associated assurance level - really means.
The Security Target (ST) is the required document that Shapiro should be referencing. It scopes the evaluation, detailing all the security requirements the product satisfies, how it satisfies them, and what assurance the consumer should have that they really are satisfied (that's the evaluation assurance level or EAL). The ST can get those security requirements from one or more PPs, but that isn't required, or, like I said, what normally happens.
Now, that all changed to some degree in January 2000, when what's now the U.S. Committee on National Security Systems issued the National Security Telecommunications and Information Systems Security Policy No. 11 (or NSTISSP #11), requiring that all products dealing with national security information (read anything sold to the U.S. government) be evaluated against the CC. Oh, and here's a bunch of PPs that you can conform to.
So, just because a lot of companies - like Microsoft - chose to conform to those PPs doesn't mean it's the only route; it doesn't even mean it's the best route. It all depends on what you, the consumer, are looking for. Concerned about what access control mechanisms are in your operating system? Well, pick up the ST (available at the CC Web site), flip to the security functional requirements section and see what it claims from the Access Control Policy family (i.e., FDP_ACC; you can find your whole shopping list in the second part of the CC).
But Shapiro's bang on when he says that the EAL, the PP (if there is one) and the ST don't mean diddly-squat if you haven't made sure that your shopping list is covered off.
Shapiro is correct in saying that the requirements in the Controlled Access Protection Profile (CAPP) aren't enough to protect an Internet-connected system; but who said they were? No one. (At least I hope Microsoft didn't say that.) To quote the Common Criteria Evaluation and Validation Scheme Web site:
1985, people! And, I would argue, it wasn't that the CAPP was the most complete validated PP. Shapiro's right when he implies that Microsoft couldn't hope to satisfy other "ported" set of requirements: the Labelled Security Protection Profile or B1 replacement; and it's those very mandatory access requirements that we need on the Internet. This is where Shapiro's going when he talks about EROS (SELinux is another example), and how it won't work well with the ubiquitous discretionary access operating systems of today.
To quote the Common Methodology for Information Technology Security Evaluation (i.e., the CEM: the document that states how to conduct CC evaluations at the various EALs):
Shapiro compares this analysis to an audit of a company's business practices. The CEM is not ISO 9001; it demands, among other things, that the product's design be sound. For example, to quote the high-level design content element ADV_HLD.2.3C:
Shapiro states that "essentially none of the code is inspected," and that such an examination isn't even required at EAL4. This is false. Notice the last input to the analysis quoted above: a subset of the implementation (i.e., some of the code). The size of this subset is left to the evaluator, with the understanding that if concerns arise while examining the initial sample, sampling should continue until the evaluator is confident in the product's ability to provide its stated security functions. To quote the implementation representation content element ADV_IMP.1.1C:
To continue the CEM quote on EAL4:
I'm not sure what Shapiro means by "no quantifiable measurements... of the software." No lines-of-code measurement? Something related to the number of system calls? While these properties certainly affect the keep-it-simple principle of security, I don't know that there are specific thresholds we could use in evaluating security products. (Well, beyond the extremes: I'm thinking of Schneier's Secrets & Lies... an estimated 60 million LOC in Windows 2000, over 3000 system calls in Windows NT 4.0!)
Certainly the CEM isn't that prescriptive. Things like the number of subsystems in the product's high-level design are left to the evaluator's judgment. Is the developer's choice of subsystems useful in understanding the product’s intended operation? Well then, whatever the number, it's served its purpose.
However, I do not believe, as Shapiro states, that an EAL4 evaluation "says absolutely nothing about the quality of the software itself;" in my opinion, the associated analysis is qualitative. I've mentioned the design requirements, but there's also ensuring that the developer has tested to that design, there's a verification of that testing and additional independent testing... And this is focused on the security functions claimed in the ST, remember. This evaluation says nothing about those functions that aren't security related. (Since they're where the money is, it's a safe bet that the developer's tested them.)
Documents related to the software development process are evaluated (e.g., configuration management and delivery), but the processes themselves are verified during a development site visit. And the quality of these processes is just as important as the quality of the software itself. If you can't guarantee that the evaluated software is what the customer is actually installing, what have you achieved?
Well, if you've made it this far, all I'm saying is that the CC is a tool; you, the consumer, can use it to specify your security needs (i.e., in a PP), and you, the developer, can use it to specify what your product secures and how (i.e., in an ST). That people compare products solely based on the EALs they were evaluated at is not the fault of the framework (use the STs, Luke!). Similarly, the levels themselves give the developer (or their sponsor) a choice in the amount of time and money they want to commit to the enterprise. How much assurance are your customers looking for? Do they simply want to know that the guidance documents you supply with the product will actually help them get it to a secure state (e.g., EAL1)? Or do they want to know that you've tested every single security function identified in your functional specification (e.g., EAL3)?
Having said all that, I would love to see a mandatory access operating system like SELinux go through a CC evaluation. If we could get that kind of security in the U.S. government, maybe, just maybe, it would get enough momentum to spill out into the U.S. population. And then? Oh, then the world, baby! :-)
How the Common Criteria Really Works
While Shapiro gets the general idea, you should understand that the Protection Profile (PP) hasn't caught on like most of the those involved in the project probably expected. It's optional, first of all, and requires a lot of time and effort from groups who are independent of the security product companies (e.g., consumer rights groups) to work. There are exceptions (e.g., the Smart Card Protection Profile), but, for the most part, the consumers, or their independent representatives, must define their own security needs for this step to be of some utility.
The reason is that if the consumer doesn't understand the PP - the Controlled Access Protection Profile is a good example - then they won't understand the company's security target that claims conformance to that PP, nor what the evaluation - and its associated assurance level - really means.
The Security Target (ST) is the required document that Shapiro should be referencing. It scopes the evaluation, detailing all the security requirements the product satisfies, how it satisfies them, and what assurance the consumer should have that they really are satisfied (that's the evaluation assurance level or EAL). The ST can get those security requirements from one or more PPs, but that isn't required, or, like I said, what normally happens.
Now, that all changed to some degree in January 2000, when what's now the U.S. Committee on National Security Systems issued the National Security Telecommunications and Information Systems Security Policy No. 11 (or NSTISSP #11), requiring that all products dealing with national security information (read anything sold to the U.S. government) be evaluated against the CC. Oh, and here's a bunch of PPs that you can conform to.
So, just because a lot of companies - like Microsoft - chose to conform to those PPs doesn't mean it's the only route; it doesn't even mean it's the best route. It all depends on what you, the consumer, are looking for. Concerned about what access control mechanisms are in your operating system? Well, pick up the ST (available at the CC Web site), flip to the security functional requirements section and see what it claims from the Access Control Policy family (i.e., FDP_ACC; you can find your whole shopping list in the second part of the CC).
But Shapiro's bang on when he says that the EAL, the PP (if there is one) and the ST don't mean diddly-squat if you haven't made sure that your shopping list is covered off.
The Controlled Access Protection Profile
Shapiro is correct in saying that the requirements in the Controlled Access Protection Profile (CAPP) aren't enough to protect an Internet-connected system; but who said they were? No one. (At least I hope Microsoft didn't say that.) To quote the Common Criteria Evaluation and Validation Scheme Web site:
The CAPP was derived from the requirements of the C2 class of the U.S. Department of Defense (DoD) Trusted Computer System Evaluation Criteria (TCSEC), dated December, 1985...
1985, people! And, I would argue, it wasn't that the CAPP was the most complete validated PP. Shapiro's right when he implies that Microsoft couldn't hope to satisfy other "ported" set of requirements: the Labelled Security Protection Profile or B1 replacement; and it's those very mandatory access requirements that we need on the Internet. This is where Shapiro's going when he talks about EROS (SELinux is another example), and how it won't work well with the ubiquitous discretionary access operating systems of today.
Evaluation Assurance Level 4
To quote the Common Methodology for Information Technology Security Evaluation (i.e., the CEM: the document that states how to conduct CC evaluations at the various EALs):
EAL4 provides a moderate to high level of assurance. The security functions are analysed using a functional specification, guidance documentation, the high-level and low-level design of the TOE, and a subset of the implementation to understand the security behaviour...
Shapiro compares this analysis to an audit of a company's business practices. The CEM is not ISO 9001; it demands, among other things, that the product's design be sound. For example, to quote the high-level design content element ADV_HLD.2.3C:
The evaluator should make an assessment as to the appropriateness of the number of subsystems presented by the developer, and also of the choice of grouping of functions within subsystems. The evaluator should ensure that the decomposition of the [Target of Evaluation's (i.e., the product) Security Functions or TSF] into subsystems is sufficient for the evaluator to gain a high-level understanding of how the functionality of the TSF is provided.
Shapiro states that "essentially none of the code is inspected," and that such an examination isn't even required at EAL4. This is false. Notice the last input to the analysis quoted above: a subset of the implementation (i.e., some of the code). The size of this subset is left to the evaluator, with the understanding that if concerns arise while examining the initial sample, sampling should continue until the evaluator is confident in the product's ability to provide its stated security functions. To quote the implementation representation content element ADV_IMP.1.1C:
Other factors that might influence the determination of the subset include:
- the complexity of the design (if the design complexity varies across the [Target of Evaluation or TOE], the subset should include some portions with high complexity);
- the results of other design analysis sub-activities (such as work units related to the low-level or high-level design) that might indicate portions of the TOE in which there is a potential for ambiguity in the design; and
- the evaluator’s judgement as to portions of the implementation representation that might be useful for the evaluator’s independent vulnerability analysis (sub-activity AVA_VLA.2).
To continue the CEM quote on EAL4:
... The analysis is supported by independent testing of a subset of the TOE security functions, evidence of developer testing based on the functional specification and the high level design, selective confirmation of the developer test results, analysis of strengths of the functions, evidence of a developer search for vulnerabilities, and an independent vulnerability analysis demonstrating resistance to low attack potential penetration attackers. Further assurance is gained through the use of an informal model of the TOE security policy and through the use of development environment controls, automated TOE configuration management, and evidence of secure delivery procedures.
I'm not sure what Shapiro means by "no quantifiable measurements... of the software." No lines-of-code measurement? Something related to the number of system calls? While these properties certainly affect the keep-it-simple principle of security, I don't know that there are specific thresholds we could use in evaluating security products. (Well, beyond the extremes: I'm thinking of Schneier's Secrets & Lies... an estimated 60 million LOC in Windows 2000, over 3000 system calls in Windows NT 4.0!)
Certainly the CEM isn't that prescriptive. Things like the number of subsystems in the product's high-level design are left to the evaluator's judgment. Is the developer's choice of subsystems useful in understanding the product’s intended operation? Well then, whatever the number, it's served its purpose.
However, I do not believe, as Shapiro states, that an EAL4 evaluation "says absolutely nothing about the quality of the software itself;" in my opinion, the associated analysis is qualitative. I've mentioned the design requirements, but there's also ensuring that the developer has tested to that design, there's a verification of that testing and additional independent testing... And this is focused on the security functions claimed in the ST, remember. This evaluation says nothing about those functions that aren't security related. (Since they're where the money is, it's a safe bet that the developer's tested them.)
Documents related to the software development process are evaluated (e.g., configuration management and delivery), but the processes themselves are verified during a development site visit. And the quality of these processes is just as important as the quality of the software itself. If you can't guarantee that the evaluated software is what the customer is actually installing, what have you achieved?
Conclusion
Well, if you've made it this far, all I'm saying is that the CC is a tool; you, the consumer, can use it to specify your security needs (i.e., in a PP), and you, the developer, can use it to specify what your product secures and how (i.e., in an ST). That people compare products solely based on the EALs they were evaluated at is not the fault of the framework (use the STs, Luke!). Similarly, the levels themselves give the developer (or their sponsor) a choice in the amount of time and money they want to commit to the enterprise. How much assurance are your customers looking for? Do they simply want to know that the guidance documents you supply with the product will actually help them get it to a secure state (e.g., EAL1)? Or do they want to know that you've tested every single security function identified in your functional specification (e.g., EAL3)?
Having said all that, I would love to see a mandatory access operating system like SELinux go through a CC evaluation. If we could get that kind of security in the U.S. government, maybe, just maybe, it would get enough momentum to spill out into the U.S. population. And then? Oh, then the world, baby! :-)
Saturday, June 26, 2004
Toward Choice
Well, the 38th General Election is almost upon us. I've decided how I will vote, and I've decided to reveal my decision here: I'll be voting for my Green Party candidate on Monday.
So, first, why Green? I heard about - and, just recently, read about - the political campaign financing reforms that set an annual public subsidy of $1.75 per vote for parties that win over two per cent of the popular vote. I've read that the Green Party has the support of about six percent of the voting public, so I'm reasonably confident that my vote will throw another $1.75 in the Green pot for next year.
So what, you say? Well, Green Party leader Jim Harris still has a day job. With a big enough pot, he could spend more of his time thinking about, and soliciting opinions on, the country's problems. (I don't think he'll drop the day job, since he's an author as well as a management consultant.)
Too often, Canadian politics is simplified to the resources available (read money).
I've heard - CBC Radio One in the morning and evening is where I get most of my information, BTW - that the Green Party approach is frugal - fiscally conservative seems to be the vernacular - and thoughtful. That is, questioning the solutions that people take for granted, and trying to generate new ideas and discussions around them. This is obviously elusive, and it remains to be seen how it would work in practice, but I'm willing to give them the benefit of the doubt today.
So, finally, why reveal all this to the world? Well, to be honest, I still have a lot to learn about our political system and the problems that our "open society" is up against. (Dare I say I'm green?) :-) If you see flaws in my logic, have relevant information I'm not considering, or just want to share your point of view, add your comments at the end of this entry. (That goes for any entry, BTW, although I only just set up commenting this month. E-mail me about older entries; I'll probably create an new one based on your comment.)
So, first, why Green? I heard about - and, just recently, read about - the political campaign financing reforms that set an annual public subsidy of $1.75 per vote for parties that win over two per cent of the popular vote. I've read that the Green Party has the support of about six percent of the voting public, so I'm reasonably confident that my vote will throw another $1.75 in the Green pot for next year.
So what, you say? Well, Green Party leader Jim Harris still has a day job. With a big enough pot, he could spend more of his time thinking about, and soliciting opinions on, the country's problems. (I don't think he'll drop the day job, since he's an author as well as a management consultant.)
Too often, Canadian politics is simplified to the resources available (read money).
Oh, you have a problem? How much money do you need? Well, that'll force cutbacks elsewhere.I think the voters assume that solutions (but not money) grow on trees, and that with enough resources, we could solve all of Canada's problems. The fact is that we've thrown a lot of money at some problems for years, and they're still staring us in the face.
I've heard - CBC Radio One in the morning and evening is where I get most of my information, BTW - that the Green Party approach is frugal - fiscally conservative seems to be the vernacular - and thoughtful. That is, questioning the solutions that people take for granted, and trying to generate new ideas and discussions around them. This is obviously elusive, and it remains to be seen how it would work in practice, but I'm willing to give them the benefit of the doubt today.
So, finally, why reveal all this to the world? Well, to be honest, I still have a lot to learn about our political system and the problems that our "open society" is up against. (Dare I say I'm green?) :-) If you see flaws in my logic, have relevant information I'm not considering, or just want to share your point of view, add your comments at the end of this entry. (That goes for any entry, BTW, although I only just set up commenting this month. E-mail me about older entries; I'll probably create an new one based on your comment.)
Sunday, June 13, 2004
The Fruits of the Immoral
The creators of The WB's Superstar USA were obviously part of the popular crowd growing up; either that, or they're acting out a perverted cycle of abuse. This show is as cruel and immoral as the school-yard to high-school game of letting the pariah hang out with the popular crowd to protract said loner's humiliation when their true status is finally revealed. It is heartless, and runs diametric to the spirit of the golden rule.
Close to a month ago, CBC's Ontario Today ran a phone-in on raising moral children. Unfortunately, I couldn't listen to the whole program - having to work in the afternoon 'n' all :-) - but what I heard got me thinking. What are the consequences of raising children who don't question why Sally is never invited to any birthday parties, or why Paul gets the snot beaten out of him every school day at 3:00 p.m.? What happens when the movers and shakers believe that that's life, and that those who are affected should suck it up and watch their backs so they're on the winning side next time?
Today, I think the answer is that shows like Superstar USA are produced, promoted and watched by millions of people. Is this a big deal? Not really, but I think it's a sign of things to come. One can only hope that the people behind the scenes don't see how this message feeds the fear of humiliation, putting the preservation of one's status - and one's self, ultimately - above all other considerations. The consequences of this are truly horrific when these people are asked to act morally, when many other lives hang in the balance. What will be going through their heads? Which outcome makes them look the best? It's scary... really scary.
Close to a month ago, CBC's Ontario Today ran a phone-in on raising moral children. Unfortunately, I couldn't listen to the whole program - having to work in the afternoon 'n' all :-) - but what I heard got me thinking. What are the consequences of raising children who don't question why Sally is never invited to any birthday parties, or why Paul gets the snot beaten out of him every school day at 3:00 p.m.? What happens when the movers and shakers believe that that's life, and that those who are affected should suck it up and watch their backs so they're on the winning side next time?
Today, I think the answer is that shows like Superstar USA are produced, promoted and watched by millions of people. Is this a big deal? Not really, but I think it's a sign of things to come. One can only hope that the people behind the scenes don't see how this message feeds the fear of humiliation, putting the preservation of one's status - and one's self, ultimately - above all other considerations. The consequences of this are truly horrific when these people are asked to act morally, when many other lives hang in the balance. What will be going through their heads? Which outcome makes them look the best? It's scary... really scary.
Saturday, June 12, 2004
The perfectly-legal, all-seeing eye
"We're at war," [Dennis R. Schrader, director of homeland security for Gov. Robert L. Ehrlich Jr.,] said.
This blanket justification for building a regional, closed-circuit, video surveillance system in Baltimore raised my blogging brow, but it was Schrader's flawed logic that pushed me over the edge:
Cameras will only observe and record that which a police officer or private citizen could legally see.
Each camera will only observe and record what could be legally seen! The aggregate of every camera's observation is something that no one could physically see, and it is such a limitation that is taken into account when laws are written. Remove this limitation, and we can no longer talk about what is legal or illegal until the effected laws have been revisited.
This is one of the few things that's scarier than the huge databases of information being compiled these days: decision-makers who are oblivious to the power of data. (What else is scarier? Corporations owning these databases, but that's another entry.) What may seem innocuous to one person (e.g., seeing Joe walk out of some apartment complex), may be a critical piece in someone else's puzzle: the final correlation in a list of evidence that means Joe's screwin' around, or he's an alcoholic, or a homosexual, or suffering from Parkinson's disease... The list is endless, as is the list of what people could do with that information, including nothing. The point is, it's out of Joe's hands. His privacy is in jeopardy.
Saturday, June 05, 2004
Thursday, May 27, 2004
Canadian Pentecostal... Terrorists?
I wish I could find the sound bite I heard on CBC this morning; I don't know if it was the same FBI agent (Ahearn), but someone from the FBI said something like,
This kind of thinking starts us down a very slippery slope; the problem is that the public buys it wholesale, feeding the fear that words and thoughts are dangerous, regardless of their context. I'm not saying that the FBI were wrong to investigate this complaint; all I'm saying is that this was their opportunity to put things in perspective, say that it's good to be vigilant, but we must also be rational. In what context were the words spoken? Are you responding to other indicators? What are they? The right to speak one's mind is so fragile in the face of all this fear.
This snowball of public opinion has another cost: no one questions the security trade-off - security is always a trade-off (to quote Schneier). In this case, we're trading the right to speak about a broad range of ideas for what? Security theatre (another Schneier phrase). It's irresponsible to let people believe that they're safer when they don't hear about terrorist acts, or bombs, when we're on the bus, in line at Wendy's, or on an airplane.
Yes, be vigilant (because, no, Pollyanna, the whole world isn't in love with Canada), but don't start looking for the gestapo every time someone says "bomb" or "anthrax."
This sort of thing reflects the climate change since September 11, 2001.Yes, absolutely. The Western hemisphere will never be the same. Then he went on to say, "... and people need to watch what they say around these security measures." Uh... What?
This kind of thinking starts us down a very slippery slope; the problem is that the public buys it wholesale, feeding the fear that words and thoughts are dangerous, regardless of their context. I'm not saying that the FBI were wrong to investigate this complaint; all I'm saying is that this was their opportunity to put things in perspective, say that it's good to be vigilant, but we must also be rational. In what context were the words spoken? Are you responding to other indicators? What are they? The right to speak one's mind is so fragile in the face of all this fear.
This snowball of public opinion has another cost: no one questions the security trade-off - security is always a trade-off (to quote Schneier). In this case, we're trading the right to speak about a broad range of ideas for what? Security theatre (another Schneier phrase). It's irresponsible to let people believe that they're safer when they don't hear about terrorist acts, or bombs, when we're on the bus, in line at Wendy's, or on an airplane.
Yes, be vigilant (because, no, Pollyanna, the whole world isn't in love with Canada), but don't start looking for the gestapo every time someone says "bomb" or "anthrax."
May 27, 8:45 AM EDT
Plane Turned Around After 9/11 Discussion
BUFFALO, N.Y. (AP) -- A plane was turned around on the runway and returned to the gate after three men were overheard praying and discussing the Sept. 11 terror attacks.
The men - two ministers from Toronto and one of their cousins from the United States - were on a Continental flight Wednesday headed to Newark, N.J.
The pilot taxied back to Buffalo-Niagara International Airport, where members of the joint terrorism task force in Buffalo interviewed the men and fellow passengers.
The ministers were identified as the Rev. Komal Singh and the Rev. Yohan Heenatigala. The third man was not identified.
Singh was on his way to an evangelical crusade in Baltimore when he told another passenger that the passenger's last breath on Earth would be his first breath in heaven if he became a born-again Christian.
"My first reaction was someone was just talking and someone got nervous and that's exactly what it turned out to be, but it has to be checked out," said Peter Ahearn, FBI special agent in charge.
The men were released and the flight took off.
Copyright: 2004 Associated Press
Publication: AP Custom News
Personal Use: You may make a single copy of any portion of the content, or use this content online, solely for your personal, non-commercial use, provided you do not remove any trademark, copyright or other notice from such content.
Thursday, April 01, 2004
The responsibility of artists
Today, the Independent Filmmakers Cooperative of Ottawa (IFCO) denied Ken Takahashi's grant application for his film Last Night with Jesse. The grounds for this verdict - fear of the film's running afoul of proposed law Bill C-12 and its lack of an artistic merit defence - while troubling, are not the subject of this entry.
What concerns me is City Councillor Jan Harder's position on the matter. Her self-proclaimed threat to pull the city's contribution to arts funding (about one third of the total amount) was particularly distasteful, and unprofessional. (Unfortunately, I heard the sound bite on CBC Radio One, and haven't been able to find it in print.)
Takahashi's position echoes my thoughts on the role of artists:
I feel strongly that challenging the status quo - with or without taxpayer dollars - is key to preserving the liberties that make this country great, in much the same way as Sherman Kent urged intelligence analysts to avoid analytic or cognitive biases:
Just the fact that there's such an outcry against this film should give us pause. Will it send the message that
In forcing us to reconsider our knee-jerk reactions, artists have a big responsibility. By acknowledging the importance of this role - in the form of arts funding - citizens are really "electing" artists and their approving bodies, trusting in their judgment. By insisting that city council have a say in how arts funding is granted, Jan Harder is implying that she too is an artist who knows how the status quo must be challenged (and how it must not, in this case). I don't know about you, but the films that really challenged what I thought I knew often horrified me, certainly coming out of left field. Would you trust the average joe on the street to judge the merits of that sort of art as it sits in the mind of an artist, an unrealized vision?
It reminds me of Former Prime Minister Pierre Elliott Trudeau's thoughts on democracy:
Similarly, I feel that Jan Harder's, or any other city councillor's, point of view inappropriately biases her judgment of how the status quo should be challenged. To a lesser extent, I feel the same way about the IFCO, which is why I'm glad that their denial was based on legal grounds. (Whether that law is right and just is another, equally important, matter.) This responsibility rests with the artists, in my mind, and it is the grandeur of their calling.
What concerns me is City Councillor Jan Harder's position on the matter. Her self-proclaimed threat to pull the city's contribution to arts funding (about one third of the total amount) was particularly distasteful, and unprofessional. (Unfortunately, I heard the sound bite on CBC Radio One, and haven't been able to find it in print.)
Takahashi's position echoes my thoughts on the role of artists:
I think it's important for artists to push the envelope, to challenge the status quo. And the city council getting involved and dictating what forms of art should be concentrated on - I think that's a bad thing to do and a dangerous precedent. If art is going to be dictated by the government, then we've lost an important voice, and I'm very concerned about that.
I feel strongly that challenging the status quo - with or without taxpayer dollars - is key to preserving the liberties that make this country great, in much the same way as Sherman Kent urged intelligence analysts to avoid analytic or cognitive biases:
[Kent] urged special caution when a whole team of analysts immediately agrees on an interpretation of yesterday’s development or a prediction about tomorrow’s. Especially regarding Vietnam, he also cautioned against a “been-to” bias; field exposure can be valuable, but a quick trip doesn’t necessarily provide revealed truths. One path he recommended for coping with cognitive bias was to make working assumptions explicit and to challenge them vigorously.
Just the fact that there's such an outcry against this film should give us pause. Will it send the message that
aberrant sexual behaviour against children is acceptableas Ottawa resident A. Charles King suggests? The film is in pre-production, folks! It isn't saying anything yet!
In forcing us to reconsider our knee-jerk reactions, artists have a big responsibility. By acknowledging the importance of this role - in the form of arts funding - citizens are really "electing" artists and their approving bodies, trusting in their judgment. By insisting that city council have a say in how arts funding is granted, Jan Harder is implying that she too is an artist who knows how the status quo must be challenged (and how it must not, in this case). I don't know about you, but the films that really challenged what I thought I knew often horrified me, certainly coming out of left field. Would you trust the average joe on the street to judge the merits of that sort of art as it sits in the mind of an artist, an unrealized vision?
It reminds me of Former Prime Minister Pierre Elliott Trudeau's thoughts on democracy:
Nor do I believe that elected representatives should abdicate their responsibility by being nothing but the mouthpieces for their constituencies. In its extreme form this ceases to be representative democracy and becomes direct democracy. Though it may look more democratic, it's really tantamount to saying that policies and laws must be decided by the people themselves... It's a misunderstanding of parliamentary democracy, and it cannot be made to work in large societies, because small groups meeting to deal with very important problems from their regional or local point of view cannot have in mind the legalistic, administrative, constitutional functions of government that are the fabric society must have to function in an orderly way.
Similarly, I feel that Jan Harder's, or any other city councillor's, point of view inappropriately biases her judgment of how the status quo should be challenged. To a lesser extent, I feel the same way about the IFCO, which is why I'm glad that their denial was based on legal grounds. (Whether that law is right and just is another, equally important, matter.) This responsibility rests with the artists, in my mind, and it is the grandeur of their calling.
Monday, March 22, 2004
Netiquette Guidelines
Request For Comments: 1855 - Netiquette Guidelines was published in 1995, but it is still very relevant today. Granted, many Internet users are paying a flat rate for their bandwidth these days - taking some of the sting out of the argument that quoting whole messages costs your recipients, for example - but goodness knows a thought to brevity wouldn't hurt Internet traffic levels.
I got to thinking about this RFC after I received what I considered to be a rude e-mail at work. The subject was in uppercase, and there was no salutation or complimentary closing. Worse still, it included the question: how did you figure that one?
Now, the tone of that question makes all the difference in the world. Friends, or even acquaintances, could admonish one another easily by putting a teasing spin on it; that spin would force a leap of faith between strangers, but it could still fly, depending on the personalities involved. But take the facial expressions and tone out of the equation, and it will fall hard 9 times out of 10, in my opinion.
I had never met the woman who sent this e-mail. (I'd also done nothing wrong - she had made an incorrect assumption - but that's beside the point.) My response directed her to the proper person, but I'm wondering if I should follow it with a copy of Netiquette Guidelines... Seems like I'd be violating some other etiquette though, and that would defeat the purpose of the whole exchange, no?
I got to thinking about this RFC after I received what I considered to be a rude e-mail at work. The subject was in uppercase, and there was no salutation or complimentary closing. Worse still, it included the question: how did you figure that one?
Now, the tone of that question makes all the difference in the world. Friends, or even acquaintances, could admonish one another easily by putting a teasing spin on it; that spin would force a leap of faith between strangers, but it could still fly, depending on the personalities involved. But take the facial expressions and tone out of the equation, and it will fall hard 9 times out of 10, in my opinion.
I had never met the woman who sent this e-mail. (I'd also done nothing wrong - she had made an incorrect assumption - but that's beside the point.) My response directed her to the proper person, but I'm wondering if I should follow it with a copy of Netiquette Guidelines... Seems like I'd be violating some other etiquette though, and that would defeat the purpose of the whole exchange, no?
Sunday, February 08, 2004
Muhammet Kalem and me
This is a picture of a street corner in Konya, Turkey; the city where the 11-storey apartment building (according to the CBC; Reuters has it as a 10-storey building) collapsed on February 2, 2004.
Muhammet Kalem was pulled from the wreckage today, having indicated his position to rescuers by moving a piece of plastic tubing. As I look at pictures of Konya, I'm stunned by how much it resembles many Canadian cities. I lived in four apartment buildings over a six-year span of my life, and not once did I doubt, or even consider, their structural integrity. Strict building codes are yet another luxury I enjoy without thought.
I understand that Muhammet's father (who had gone out earlier and avoided the collapse) had already arranged his burial plot. What mixed emotions he must be dealing with today: his son alive beyond all hope, his wife (and second child?) still missing.
Wednesday, January 21, 2004
Still on the subject of trademark infringement, HaidaBucks legal battle ended well last summer. (I like that name a lot, actually.) It looks like Mike Rowe's will also. Here's to the power of public opinion!
Uzi Nissan's Plight
I was reading about Mike Rowe's recent run-in with Microsoft when I found comments comparing it to Uzi Nissan's problems. Up until then, I'd been unaware of Mr. Nissan's legal battle with Nissan Motor Co., Ltd. The car maker has been trying to wrest the nissan.com domain name from Mr. Nissan since 1999, despite his every right to it. Unbelievably, as it stands right now, Mr. Nissan still owns the domain name and nissan.net (what used to be the home of his Internet service company), but he can't use them for commercial purposes. Talk about stripping ownership of its value! Now that his appeal has been rejected, he waits. What I can't believe is that the judge ruled that Mr. Nissan's critique of this lawsuit on ncchelp.org proved the actual dilution of the Nissan Motors trademark, as required by the Federal Trademark Dilution Act. I sure hope this ruling is sent back for review. The man has a right to express his opinion!
Friday, January 16, 2004
The US-VISIT Program
Bruce Schneier wrote a great piece on the US-VISIT program for the current Crypto-Gram. My first thought, upon reading about the program on Slashdot about a week ago, was: where does Canada fit in it? This came up in answering one of the frequently asked US-VISIT questions on the U.S. Department of Homeland Security Web site: while Canada is not part of the U.S. Visa Waiver Program, existing agreements with the U.S. exempt most Canadians from having to submit their biometric data. Of course, this can change based on national need.
My second thought was retention. It's easy to collect data, but keeping track of what you've collected, throwing it out when you're done with it, that's tougher. To their credit, the U.S. DHS conducted a privacy impact assessment on the US-VISIT program that addressed many of the fair information practices, including limited collection, accuracy and individual access:
What's interesting is that this quote is taken from the section entitled Retention and Destruction. At no point does it discuss the destruction or deletion of the biometric data. And, again, it's easy to keep data around just in case. The scary part is, though, when new systems are being developed and those involved are looking for ways to save money, to avoid reinventing the wheel, these piles of data are pretty enticing. What happens if I'm separated from my biometric data? Oh, that's John because he sent us this biometric data electronically, and look! It matches. No, actually it's just the person who has access to that data; it's been sitting on this decommissioned kiosk for the last two years, but hey, no worries, because you know what? John's fingerprints don't change a whole heck of a lot.
Yes, I know most sensible systems will only use stored biometric data in comparisons with what they get from me, right there, but convenience, assumptions, time constraints... System designers, project managers... They make mistakes. I'd just prefer that my data trail wasn't there, ready to be mucked with.
My second thought was retention. It's easy to collect data, but keeping track of what you've collected, throwing it out when you're done with it, that's tougher. To their credit, the U.S. DHS conducted a privacy impact assessment on the US-VISIT program that addressed many of the fair information practices, including limited collection, accuracy and individual access:
There is also some duplication in the types of data collected by each system. These inconsistencies and duplication result in some heightened degree of risk with respect to integrity/security of the data, and to access and redress principles, because personal information could persist on one or more component systems beyond its period of use or disappear from one or more component systems while still in use. These risks are mitigated, however, by having a Privacy Officer for US-VISIT to handle specific issues that may arise, by providing review of the Privacy Officer’s decision by the DHS Chief Privacy Officer, and, to the extent permitted by existing law, regulations, and policy, by allowing covered individuals access to their information and permitting them to challenge its completeness. Additionally, as an overarching mechanism to ensure appropriate privacy protections, US-VISIT operators will conduct periodic strategic reviews of the data to ensure that what is collected is limited to that which is necessary for US-VISIT purposes.
What's interesting is that this quote is taken from the section entitled Retention and Destruction. At no point does it discuss the destruction or deletion of the biometric data. And, again, it's easy to keep data around just in case. The scary part is, though, when new systems are being developed and those involved are looking for ways to save money, to avoid reinventing the wheel, these piles of data are pretty enticing. What happens if I'm separated from my biometric data? Oh, that's John because he sent us this biometric data electronically, and look! It matches. No, actually it's just the person who has access to that data; it's been sitting on this decommissioned kiosk for the last two years, but hey, no worries, because you know what? John's fingerprints don't change a whole heck of a lot.
Yes, I know most sensible systems will only use stored biometric data in comparisons with what they get from me, right there, but convenience, assumptions, time constraints... System designers, project managers... They make mistakes. I'd just prefer that my data trail wasn't there, ready to be mucked with.
Subscribe to:
Posts (Atom)