Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support
Have a question?
Call us Toll-Free at:
1-877-ANTISPY
1-877-2684779
+44-207-099-2078
More contacts


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Kill Switches and Remote Control
July 1, 2008 12:48

    It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now everyone else wants to get their hooks into your gear. OnStar will soon include the ability for the police to shut off your engine remotely. Buses are getting the same capability, in case terrorists want to re-enact the movie Speed. The Pentagon wants a kill switch installed on airplanes, and is worried about potential enemies installing kill switches on their own equipment. Microsoft is doing some of the most creative thinking along these lines, with something it's calling "Digital Manners Policies." According to its patent application, DMP-enabled devices would accept broadcast "orders" limiting capabilities. Cellphones could be remotely set to vibrate mode in restaurants and concert halls, and be turned off on airplanes and in hospitals. Cameras could be prohibited from taking pictures in locker rooms and museums, and recording equipment could be disabled in theaters. Professors finally could prevent students from texting one another during class. The possibilities are endless, and very dangerous. Making this work involves building a nearly flawless hierarchical system of authority. That's a difficult security problem even in its simplest form. Distributing that system among a variety of different devices -- computers, phones, PDAs, cameras, recorders -- with different firmware and manufacturers, is even more difficult. Not to mention delegating different levels of authority to various agencies, enterprises, industries and individuals, and then enforcing the necessary safeguards. Once we go down this path -- giving one device authority over other devices -- the security problems start piling up. Who has the authority to limit functionality of my devices, and how do they get that authority? What prevents them from abusing that power? Do I get the ability to override their limitations? In what circumstances, and how? Can they override my override? How do we prevent this from being abused? Can a burglar, for example, enforce a "no photography" rule and prevent security cameras from working? Can the police enforce the same rule to avoid another Rodney King incident? Do the police get "superuser" devices that cannot be limited, and do they get "supercontroller" devices that can limit anything? How do we ensure that only they get them, and what do we do when the devices inevitably fall into the wrong hands? It's comparatively easy to make this work in closed specialized systems -- OnStar, airplane avionics, military hardware -- but much more difficult in open-ended systems. If you think Microsoft's vision could possibly be securely designed, all you have to do is look at the dismal effectiveness of the various copy-protection and digital-rights-management systems we've seen over the years. That's a similar capabilities-enforcement mechanism, albeit simpler than these more general systems. And that's the key to understanding this system. Don't be fooled by the scare stories of wireless devices on airplanes and in hospitals, or visions of a world where no one is yammering loudly on their cellphones in posh restaurants. This is really about media companies wanting to exert their control further over your electronics. They not only want to prevent you from surreptitiously recording movies and concerts, they want your new television to enforce good "manners" on your computer, and not allow it to record any programs. They want your iPod to politely refuse to copy music to a computer other than your own. They want to enforce their legislated definition of manners: to control what you do and when you do it, and to charge you repeatedly for the privilege whenever possible. "Digital Manners Policies" is a marketing term. Let's call this what it really is: Selective Device Jamming. It's not polite, it's dangerous. It won't make anyone more secure -- or more polite. This essay originally appeared in Wired.com.

All news for October 10, 2008
  22:58  Schneier on Security: Friday Squid Blogging: Natural Squid Steganography
  22:45  Martin McKeay: Recording Notice: Security Roundtable - Blogger Ethics
  18:30  Schneier on Security: The More Things Change, the More They Stay the Same
  14:39  Martin McKeay: Brute force attacks against WPA/WPA2 using Nvidia cards
  12:35  Schneier on Security: Data Mining for Terrorists Doesn't Work
  00:02  Martin McKeay: Sequoia´s helping decide the election? God help us!

All news for October 9, 2008
  23:00  MSRC: Update 1: Microsoft Security Advisory 951306
  19:07  Schneier on Security: Nonviolent Activists Are Now Terrorists
  17:51  Martin McKeay: Cisco Ooops: drug runner music on VPN CD
  16:40  MSRC: October 2008 Advanced Notification
  12:44  Schneier on Security: "New Attack" Against Encrypted Images
  12:22  Martin McKeay: Step by step guide to the DNS vulnerability
  09:28  Dancho Danchev: Cybercriminals Abusing Lycos Spain To Serve Malware
  09:00  Dancho Danchev: Commoditization of Anti Debugging Features in RATs - Part Two

All news for October 8, 2008
  14:46  Martin McKeay: NoScript protects from ClickJacking
  14:14  Martin McKeay: Big Surprise: Data mining doesn´t catch terrorists
  12:55  Schneier on Security: Chinese Monitoring Skype Messages
  02:23  Martin McKeay: Network Security Podcast, Episode 123

All news for October 7, 2008
  21:51  Schneier on Security: Do-Not-Call Lists
  18:27  Martin McKeay: Recording notice: NSP 123
  15:54  Dancho Danchev: Summarizing Zero Day's Posts for September
  14:49  Martin McKeay: Now he´s done it! Security Mike sells out
  12:21  Dancho Danchev: A Diverse Portfolio of Fake Security Software - Part Eight
  11:48  Schneier on Security: The Seven Habits of Highly Ineffective Terrorists
  07:42  Dancho Danchev: Web Based Malware Emphasizes on Anti-Debugging Features
  00:01  Dancho Danchev: Fake Windows XP Activation Trojan Wants Your CVV2 Code
Keywords: kill, switches, and, remote, control

All news for October, 2008


All news for 2008