Computer security just got harder

This has been coming for quite some time (H/T to Jeff):

Triulzi said he’s seen plenty of firmware-targeting malware in the laboratory. A client of his once infected the UEFI-based BIOS of his Mac laptop as part of an experiment. Five years ago, Triulzi himself developed proof-of-concept malware that stealthily infected the network interface controllers that sit on a computer motherboard and provide the Ethernet jack that connects the machine to a network. His research built off of work by John Heasman that demonstrated how to plant hard-to-detect malware known as a rootkit in a computer’s peripheral component interconnect, the Intel-developed connection that attaches hardware devices to a CPU.

I wrote and demonstrated to some folks in D.C. a prototype of something like this in 2004 or 2005. Even before that lots of people knew it was possible.

You can remove all hard disks from your computer, install empty ones, and as the computer is booting up for the first time infect the new hard disk before the O/S even attempts to boot off of the CD drive. Of if you wanted you could just refuse to boot.

Imagine a stealth virus that infected some large percentage of all computers then on September 11th would only perform one function—format any storage device it had control of.

Sleep well.

NSA decryption

From Leaked Slide Shows NSA Celebrated Victory Over Google’s Security With A Smiley Face:google-cloud-exploitation1383148810

That’s good to know. What that means is that either they can’t break the encrypted messages directly or that it is more work to do so. So they do it by attacking the Google servers that do the encryption and decryption.

That means encrypting my data on my computer before it hits the Internet makes it more difficult or impossible for the NSA to read. Hence:

jfFMMWu3VNTJs0iuzM/h1J9wEDojd3+34PNTyb/u/rEnedy3y9YywxRPtP8wX5nZ13xfkduP
/7+vNFbz7150wnHv8+hyEiubOLVB2D4e2Qu62jVS6E9M7q47BGCgv59S/vhV6EKhJ3GyfqK
taan8ss0V+fBjZbpsBGbhsRXaHT+A8tXSx3DpApmVbc4MIzHr9w8WG5pzCSBI/F2CXjqTE8
EMu/5zmxm+XmawdM4IAtPotIiLDTsw8IoHVJFAMdlagQDlla2z5fGJoZlDu7fsrFu7SYTso
5gEJUZF8eju5sWsqfZp1i8KvdFPYuXbzBdKJYCg/Hq0iD3/yGr4TeuW0yZ4Xrx20Wmv3nit
rOhrWZVAOsbfYB6LgoP8j2w0UkJPtzSr3d+zWk80EDMvsuPgnA93Sn5A+omipxXTimZes6Y
nz0NyXO745pZcOH3CNlddW8AFqQ0KlJC5qNVejPRs3rEQL5y+/pXyEd8JHIo0M2Qm+Elrdn
ZwZLSmNHfCeQk7aNAfD3lHTsaCQmbTZzBVWmq1YFDxiJU5ZJGNy3pXw7LT5BUVXLV9ShlSs
RGbZObCH9W8SaMrW7hu9VBJjYvpXftv0+SpbkTcxRS2IXt1Tfuqi8VgtRyJuDf7uk3wGgmI
4Pip7A/FzAwZFCqSy3zKpkVLNg/Bvos390Y5bATdDIvefJq/4QXS/gfJZkLaDUR1+bhxhBW
tRYdi2Rto3B/+hFZ8GpFCGMQpnJBXmoPsUgNtHKkfYC9PsC6dv7iP9U1NRb5KFiRzsUAutD
9blIUkogSwFvc+zyx4YX7zdY1cMLOqmLbIpep8p2TlStjSj2w6LFQddJUQxwSHSJrd3yVlo
jWtxIJU8FvopqR/LUMBjrAG7bYddOWvbuxFF6Pk/UthK12Ih138Na7OdvuTzkQQmjhXdk9z
o/zjyNyZZAVaFsZa0h/RxQjyZUEihMtEMZDXKZNHgtU3urMkQOTR9k1MZahmhbJtEydMiGJ
6ESoyejbMzD1eqzxmZkIXMrZ3VQfPf1lUxjTPwdOoLtzTbUHvuA02vpd9Gx6L0xbqgn7obb
81TAkuYb4SWn+J7gF8Fi7FVwGFZ2V692KQ05lNDP4mWkGoAGuLZmqjvlee6TqXmIaEE0YWz
HVpvRfsdvpZNQxd

One big happy family

This ought to make you feel all warm and fuzzy.

The same company that made the healthcare.gov website (on a no-bid contract, naturally) is the same one that created the Canadian gun registry that cost roughly twenty times the original estimate and got scrapped a decade later after being found to be both useless and seriously defective.

But they want us to just trust their good intentions, ’cause they are so smart and transparent. Yeah, riiiight.

Field Ballistics bug fix

I fixed a minor bug in Field Ballistics. The new version is 1.1.1.0. It is available on the Windows Phone store now.

The bug was that under certain situations you could delete the last target. Other places in the app required that at least one target exist at all times. After deleting the last target the app would immediately crash.

As a side note: I submitted the changed version Sunday evening. It made it through Microsoft certification in less than three days.

Quote of the day—Anshel Sag

Having the ability replicate the human nervous system and some of their thought processes is a good thing to have, but I just hope that there are some very strict checks and balances within these systems. You know, to prevent a Skynet-like event where the robots become self aware and start to realize that the world is a better place without us. It’s a crazy thought, sure, but giving computers the ability to think and feel like humans is also a bit crazy too.

Anshel Sag
October 11, 2013
Qualcomm Takes Us One Step Closer to Skynet with Zeroth Neural Processing Chip*
[The propagation time of human nerves and synapses are many orders of magnitude slower than the electronic analogs because, contrary to the common misunderstanding, biological signals are transmitted via a chemical chain reaction not electrical signals. Electrical signals propagate at nearly the speed of light. IIRC it’s roughly 1 mSec per foot versus 1 nSec per foot. That’s one million times faster.

Imagine being engaged in physical combat with someone that has a OODA loop that is a million times faster than yours. The Terminator/Skynet universe of Hollywood may give you hope that wouldn’t be the reality of it. In that universe the machines were slow to observe and make decisions. In reality their actions would be, for all intents and purposes, instantaneous. If they were to use projectile weapons the compensation for all the environmental conditions, target direction and velocity, and all possible target responses would be calculated and if needed multiple projectiles would be launched to cover the responses.

At work, today, I’m working on something that writes computer code. Given a simple description in a few dozen lines it writes thousands of lines of code that compile and run without error. It completes the task almost before you can lift your finger from the “Enter” key. This same code would take a human many hours, if not days, to write.

Imagine a world with the industrial capacity of machines that not only build machines but can design them as well. There would be automated tools that build better tools and machines without human interaction. And those tools and machines could build better tools and machines than themselves.

It could be utopia. Or it could be a Terminator universe where the battle against an individual human is over in milliseconds and the battle for the entire planet is over in hours.

Sleep well.—Joe]


* See also Qualcomm Zeroth Processors official: mimicking human brain computing

Field Ballistics update

I released a new version of Field Ballistics for Windows Phone earlier this week and it made it through Microsoft’s test gauntlet this morning.

Here are the changes in version 1.1:

A crash that occurred when measuring inclines has been fixed.

Auto conditions retrieves air pressure from the weather service and allows manual input of air pressure independent from altitude for user defined conditions.

Target range can now be set in the range edit box in addition to moving the target push pin on the map.

Random thought of the day

Natural is better than artificial. Right? Man-made is bad. Right? So what could be more artificial than the way we use electricity?

The next time someone tells me how much better something is because it’s “natural” I’m going to tell them I’m sure they would be much happier and healthier if they replaced all the electric lights in their home with all natural whale oil lamps. It’s a renewal energy resource. Right?

CATs from Amazon

There have been some concerns that the tourniquets I linked to on Amazon in this post might have been counterfeit. I received the ones I ordered and I am pleased to announce they appear to be the genuine article. Here is a picture:

WP_20130807_001

The way you can tell the real thing from a counterfeit, at least the ones we saw in class, was by the end. If it is stitched on the end instead of welded then it is counterfeit. See the little dots, slightly darker the rest of the material, in the red end? Those are the welds.

Threaded barrel .22s

Got a gun question: What’s the best and most readily available .22 LR pistol that comes with a threaded barrel as a standard item? It seems like there should be a lot of options, as suppressors and various barrel do-dads become more common, but I don’t see a lot of models out there. The Ruger 22/45 and Ruger Mk III both have that as an option, as does the Sig Mosquito (but I’ve not heard a lot of good things about that one). Any other options I should be looking into?

Biometric fail

From here:

Cars of the future may use the driver’s rear end as identity protection, through a system developed at Japan’s Advanced Institute of Industrial Technology. A report surfaced earlier this month that researchers there developed a system that can recognize a person by the backside when the person takes a seat. The system performs a precise measurement of the person’s posterior, its contours and the way the person applies pressure on the seat. The developers say that in lab tests, the system was able to recognize people with 98 percent accuracy.

That’s not good enough. If you can’t drive your car one time out of 50 when the chances of your car being stolen are only once out of, say, ten years you are going to disable the feature.

Also 98% accuracy number was in lab tests. I have to wonder if those lab tests included people having different things in their pockets. If you normally drive with a wallet in your rear pocket and you hop in your car after a day at the beach with your wallet in a bag thrown into the back seat what are the odds then? Or if you change your carry gun, or move the holster a little to one side or the other. And it is going to have to adapt to weight gain and loss over time.

Biometrics have a lot of problems. It’s really tough to get the accuracy needed for everyday use because characteristics of people change. And the basic concept has two fundamental, closely related, security flaws.

One is that your biometric “key” is not well hidden. You leave a set of fingerprints on the glass at the restaurant, on door knobs, and on the keyboard at the library. And image of your iris can be captured with a telephoto lens while you walk down the sidewalk.

The other flaw is that in any secure system you must have a way of repudiating a set of credentials if they have been compromised. How do you repudiate an image of your iris or your fingerprints? At most you only have two eyes and ten fingerprints. And there are lots of gummy bears.

Biometric researchers attempt to block access to these flaws by performing “liveness” tests. The guys in the black hats are keeping up and my guess is, except for some very expensive solutions, they always will.

Probable bug in Windows Phone 8

I found what appears to be a minor bug in some Windows Phone 8 devices.

It showed up in my Field Ballistics program. I have code that looks like this:

// Can we focus only on the target?
if (this.cam.IsFocusAtPointSupported)
{
    this.cam.FocusAtPoint(0.5, 0.5);
}
else
{
    this.cam.Focus();
}

On someone’s phone this raised a “System.InvalidOperationException” on the call to “FocusAtPoint”.

What appears to have happened is that the phone reports IsFocusAtPointSupported as “true” but doesn’t actually support it. It’s not all that big of deal but it does mean I’ll be releasing an update a little sooner than I had planned.

Quote of the day—Patrick J. LoPresti

When I log into my Xenix system with my 110 baud teletype, both vi *and* Emacs are just too damn slow.  They print useless messages like, ‘C-h for help’ and ‘”foo” File is read only’.  So I use the editor that doesn’t waste my VALUABLE time.

Ed, man!  !man ed

ED(1)               UNIX Programmer’s Manual                ED(1)

NAME
ed – text editor

SYNOPSIS
ed [ – ] [ -x ] [ name ]
DESCRIPTION
Ed is the standard text editor.

Computer Scientists love ed, not just because it comes first alphabetically, but because it’s the standard.  Everyone else loves ed because it’s ED!

“Ed is the standard text editor.”

And ed doesn’t waste space on my Timex Sinclair.  Just look:

-rwxr-xr-x  1 root          24 Oct 29  1929 /bin/ed
-rwxr-xr-t  4 root     1310720 Jan  1  1970 /usr/ucb/vi
-rwxr-xr-x  1 root  5.89824e37 Oct 22  1990 /usr/bin/emacs

Of course, on the system *I* administrate, vi is symlinked to ed. Emacs has been replaced by a shell script which 1) Generates a syslog message at level LOG_EMERG; 2) reduces the user’s disk quota by 100K; and 3) RUNS ED!!!!!!

“Ed is the standard text editor.”

Let’s look at a typical novice’s session with the mighty ed:

golem> ed

?
help
?
?
?
quit
?
exit
?
bye
?
hello?
?
eat flaming death
?
^C
?
^C
?
^D
?


Note the consistent user interface and error reportage.  Ed is
generous enough to flag errors, yet prudent enough not to overwhelm
the novice with verbosity.

Patrick J. LoPresti
July 11, 1991
The True Path in alt.religion.emacs
[There is more but this should give you enough of a hint to get you to read the whole thing—assuming you GET OFF OF MY LAWN!

This remarkable piece of enlightenment is just as valid today as it was when it was originally posted 22 years ago today.

And as I was telling Ry the other day, not only would I rather not be running Windows 8, I still harbor some resentment DOS was replaced with Windows 95.—Joe]

And you still use Android?

Via a Tweet from Ry we have still more info on the security issues with Android (emphasis in the original):

The Bluebox Security research team – Bluebox Labs – recently discovered a vulnerability in Android’s security model that allows a hacker to modify APK code without breaking an application’s cryptographic signature, to turn any legitimate application into a malicious Trojan, completely unnoticed by the app store, the phone, or the end user. The implications are huge! This vulnerability, around at least since the release of Android 1.6 (codename: “Donut” ), could affect any Android phone released in the last 4 years1 – or nearly 900 million devices2– and depending on the type of application, a hacker can exploit the vulnerability for anything from data theft to creation of a mobile botnet.

While the risk to the individual and the enterprise is great (a malicious app can access individual data, or gain entry into an enterprise), this risk is compounded when you consider applications developed by the device manufacturers (e.g. HTC, Samsung, Motorola, LG) or third-parties that work in cooperation with the device manufacturer (e.g. Cisco with AnyConnect VPN) – that are granted special elevated privileges within Android – specifically System UID access.

Installation of a Trojan application from the device manufacturer can grant the application full access to Android system and all applications (and their data) currently installed. The application then not only has the ability to read arbitrary application data on the device (email, SMS messages, documents, etc.), retrieve all stored account & service passwords, it can essentially take over the normal functioning of the phone and control any function thereof (make arbitrary phone calls, send arbitrary SMS messages, turn on the camera, and record calls). Finally, and most unsettling, is the potential for a hacker to take advantage of the always-on, always-connected, and always-moving (therefore hard-to-detect) nature of these “zombie” mobile devices to create a botnet.

I’ve known there were lots of security issues with Android but this is much bigger than I imagined. If you were concerned about various three letter agencies sucking up data about you (or even your snail mail) then you should be even more concerned that just about anyone that is technologically competent can take complete control of your Android phone.

A little over two years ago I purchased a Android phone with thought of developing apps for it. I never got around to it and after releasing Field Ballistics for Windows Phone I gave it further consideration. I decided not do pursue Android as an alternate platform. I’m glad I made that decision. Would you want everyone and their brother looking at the map on your phone showing your location and the location of your next target? At Boomershoot that would be an invitation to have “your” target poached.

Random thought of the day

In my hand I have a computer with nearly the human computational power of an entire planet of people. It has proximity, light, sound, acceleration, magnetic field, and location sensors. It is in near constant contact with a network of hundreds of millions of other computers most of which are far more powerful than it. You can buy one for about a day’s pay.

With all that power, data, and sensor input available what appears one of the easiest paths to fame and fortune with it is to program it to make fart sounds*.

Both Marvin and I have good cause to be depressed.


*Ry pointed this out to me last week. “Thank you” Ry.

What gets prosecuted

Next time someone says they are OK with the NSA spying because they are “keeping us safe” and “if you do nothing wrong, you have nothing to fear” or some such fantasy, here’s something to consider. According to this, the most commonly crime prosecuted in the former East Germany in the five years before the unification was failure to report a crime you knew about. When the state knows everything, then NOT being a rat becomes more dangerous than being a criminal giving the police a cut of the action for protection, because you have no leverage. That thought should terrify folks when they realize what it really means.

(BTW – I think the Judge likely believes what he says when he reports that, but I do not have an independent verification of his reported fact- anyone know for sure the stats on that? Even if it’s not the number one “crime,” if it’s anywhere in the top hundred it is bad.)

(Later Edit: How big a step is it from “see something, say something” to “see something, you are required to say something” with some sort of nebulous protections that may, or may not, protect you if you do say something?)

Quote of the day—Gregory Morris

I played with it some… took me a minute to figure out how to position the shooter/target spots on the map… but then I found the elevation tool, and… whoa, totally cool.

Top notch stuff here.

Gregory Morris
June 28, 2013
Comment to the blog post Field Ballistic about my app for Windows Phone.
[I have nothing to add.—Joe]

Field Ballistics is “Top Paid”

I found this surprising*. Very pleasing, but surprising:

WindowsPhoneTopPaidSports

Field Ballistics on Windows Phone is in the list of “Top paid” sports apps after being out for only a week.

See my announcement here. Purchase it (or get a free trial version) here.


*Assuming no inflation, sales remain constant, and I saved and invested every penny then in another 1000 years I might be able to retire on the proceeds.

In my other life I am also a mechanic

I started repairing musical instruments in the 1970s. My hippie days. Started a business doing that when I was 19. Taxes and red tape slowly turned me, or helped turn me, into a conservative, if by conservative we mean someone who believes that people should stay the hell out of other people’s business.

Anyway it’s difficult to get away from the musical instruments completely. Below is a Yamaha 894– solid silver body and keys, and this one has a custom headjoint made by Drelinger in White Plains, NY. The Japanese have been making some fine instruments and this one is no exception. Each key is like a piece of jewelry, not in the sense that certain guns are said to be “jewelry” but literally.

Every key is fit to its pivots or shaft to perfection. Any tighter and it would bind with temperature changes. One key can have a half dozen or more parts, silver soldered together in a jig and hand polished. The soft pad each key holds must produce an air-tight seal with a light touch to the tone hole, it must do it quietly, and it must usually do it in mechanical combination with one or more other keys, so there is a fair amount of regulation of each key, and more regulation between keys.

image

The soft pads are leveled to the tone holes by use of paper shims of various thicknesses. I work with .001″, .002″ and .003″ shims mostly. Mark, remove the pad, cut a shim, paste it on the back of the pad, reinsert the pad, and try. Repeat as necessary, which can be many times per pad. You can see the punches, of which I’ve made several to fit various pad cup sizes, and bits of round shims, and a razor blade for cutting them into pieces. Sometimes you use whole shims to increase the effective thickness of the pad.

If you’re not already crazy it can drive you there. Many, many attempts, by many people (myself included) have been made over the decades to come up with a pad that’s more or less self-leveling and that can still hold up to moisture and all the rest, without sticking or making more noise, and so far it’s still the old felt and bladder skin pad that’s generally preferred.

It takes hours and hours, but I love it when it all comes together and the instrument finally becomes a “single thing” again, rather than the many parts I’ve been working on separately. You could even say it’s music to the ears. Lately though I’m given pause, wondering what good any of this does for anyone.

This flute is one of several owned by the principal flutist in a Northwestern U.S. orchestra, and yes; she knows that her flute is being worked on by a gun accessory corporation president. We’ve known each other for decades. She’s also a university professor and so it is safe to say that our world views differ somewhat. Two worlds. We get along very well all the same.

Field Ballistics is available on Windows Phone

I just received notification that Field Ballistics for Windows Phone has passed the Microsoft certification tests and is now available in the store. It may take a day or two before you can search for it in the store but you can install it now using this link.

Some of the cool features are illustrated with the following screen shots:

ScreenShotMap

The shooter and targets are placed on a map. The program automatically computes the range to the targets. It also automatically computes the direction of the wind relative to the bullet flight path. This means that if the wind is from the west and you are shooting at a target to the south you will get the correction the full value of wind drift. But if you then choose a target directly east (or west) of you the wind correction will be zero. Of course all the trigonometry is done to correct for shooting in all directions.

At the bottom of the screen are two columns. The left column is the ballistics solution to make the shot at the selected target. In the right column is data about the target and the bullet when it arrives at that target. Of particular note is that in the case above the bullet velocity is in red (the theme color of the phone). This means the bullet velocity is below the minimum you have specified in the settings. This is particularly important for Boomershooters because the targets won’t detonate if the bullets are going too slow.

Tapping the ‘S’ or ‘T’ icons at the bottom of the screen moves the center of the map to the shooter or the selected target. The down arrow icon moves the selected target (or the shooter if it was selected) to the location of the phone using the phone GPS. This means that you can set up multiple targets on the map, then the shooter can “run and gun” and get ballistic solutions quickly. By using the GPS to get the current location of the shooter the distances and wind corrections are automatically update for each position the shooter wishes to shoot from.

ScreenShotTargets

You can add as many targets as you wish* and give them user friendly names. If you tap the “Measure” button you can use the phone camera and accelerometer to determine the incline to the target from your current location.

ScreenShotIncline

This is the incline measurement screen using the camera. You put the crosshairs on the target and tap “Done” to capture the incline of the phone for this target. You can also zoom in or out and refocus the camera.

[Please note this is only to illustrate the incline measurement feature, not to advocate shooting in cities.]

ScreenShotConditions

The automatic weather conditions are obtained from the current location of the shooter. This doesn’t mean the physical location of the phone. You can position the shooter in another state and the nearest weather station to the designated shooter location will be used. When you define your own conditions you can even use the phone GPS to capture your altitude.

ScreenShotCartridges

Black Hills and Federal match ammo are predefined. Add as many of your own cartridges* as you desire.

ScreenShotRifles

Some predefined rifles are included but you can add as many of your own rifles* as desired.

ScreenShotHelp

There are pages and pages of easily accessible help on the phone.


*The trial version only allows one target and one each of user defined conditions, cartridges, and rifles.

Field Ballistics failed certification testing

This afternoon I received an email from Microsoft telling me my new phone app failed the certification testing.

There were two errors. In the first case I didn’t have a clue I was violating the policy. In the second case I was careless. Both are easily fixed.

Test failure 1:

Test: Content that is offensive in any country/region to which your app is targeted is not allowed. Content may be considered offensive in certain countries/regions because of local laws or cultural norms. Examples of potentially offensive content in certain countries/regions include, but are not limited to, the following:

Group 1: China
Prohibited Sexual Content
Disputed territory or region references
Providing or enabling access to content or services that are illegal under applicable local law

Comments: Result: Fail
Your application uses the Bing Maps Silverlight Control for Windows Phone. Bing Maps is not supported for Group 1 countries at this time. You may resubmit your application and deselect the Group 1 countries.

Test failure 2:

Test: Screenshots must only contain app graphics, and must not include any emulator chrome, frame rate counters or debug information.

Comments: The application screenshots contain frame rate counters and debug information.

Three out of the eight screenshots had the frame rate counters and debug information in them. I knew better and just wasn’t paying close enough attention in my rush to get the app submitted.

It will take 30 minutes or so to fix it and resubmit. I’ll get to that sometime tonight after visiting my son and his family.