6 ms·
Prof. Ross Anderson's response to a takedown request about security research
- barrkel 16y agoOn Google docs viewer: http://docs.google.com/viewer?url=http://www.cl.cam.ac.uk/~rja14/Papers/ukca.pdf http://docs.google.com/viewer?url=http://www.cl.cam.ac.uk/~r...
- deleted 16y ago[deleted]
- marshray 16y agoDear Jeff Bezos and Amazon: Take note of how it's done by real men. By your actions WRT Orwell and Wikileaks, you've shown that you aren't worthy to shine the shoes of a real information-bearer, and you aren't fit to host my cloud nodes either. Sincerely, Marsh Ray
- jedsmith 16y agoA service provider terminating Wikileaks for AUP violations after they began publishing classified diplomatic cables; one of the oldest educational institutions on Earth standing up for a student's MPhil thesis. Totally the same thing. How did I miss this?
- pshapiro 16y agoIt seems that the point is that Wikileaks apparently broke no laws.
- subway 16y agoYou don't have to break a law to violate an AUP.
- marshray 16y agoYou have to live up to more than your own AUP to be worthy of respect in my book. I'd go so far as to say anyone who does only the minimum required by policies they themselves wrote and defers the rest to extra-constitutional influence from the likes of Sen. Lieberman is pretty darn low. So sure, do whatever you can get away with under your AUP, just don't expect me to respect you for it (or trust you with my data).
- iwwr 16y agoDo you have some details on the background of this issue?
- dtf 16y agoHere's the original BBC Newsnight report: http://www.youtube.com/watch?v=JPAX32lgkrw http://www.youtube.com/watch?v=JPAX32lgkrw
- hermanthegerman 16y agohttp://www.lightbluetouchpaper.org/2010/12/25/a-merry-christmas-to-all-bankers/ http://www.lightbluetouchpaper.org/2010/12/25/a-merry-christ...
- latch 16y agoNo the OP, but: A news story about the initial issue: http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-is-broken/ http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i... The take down notice (pdf): http://www.cl.cam.ac.uk/~rja14/Papers/20101221110342233.pdf http://www.cl.cam.ac.uk/~rja14/Papers/20101221110342233.pdf
- alecco 16y agoLovely. The project looks very interesting. http://www.cl.cam.ac.uk/~osc22/scd/ http://www.cl.cam.ac.uk/~osc22/scd/ "Smart Card Detective"
- oiuytuikolikuhy 16y agoIf one of the smartest computer security guys was prepared to do all this work and throw lots of expensive experts (well grad students) at finding your bugs - would you: 1, Send developers to all their seminars to learn something 2, Buy them drinks 3, Sue them
- iwwr 16y agoIf anything, the banks promoting this technology should be sued for false advertising. in many cases banks refused to reimburse cardholders who reported unauthorised card use, claiming that their systems could not fail http://en.wikipedia.org/wiki/Chip_and_PIN http://en.wikipedia.org/wiki/Chip_and_PIN
- oiuytuikolikuhy 16y ago2 decades earlier they prosecuted people who reported ATM losses for fraud - because ATMs were perfectly secure.
- waqf 16y agoreference?
- oiuytuikolikuhy 16y agoNumerous paper's on ross's page http://www.cl.cam.ac.uk/~rja14/Papers/wcf.html http://www.cl.cam.ac.uk/~rja14/Papers/wcf.html
- matclayton 16y agoThey run windows95/2000 how can that ever be secure :) p.s my reference is a blue screen of death on one :)
- JCThoughtscream 16y agoTRICK QUESTION. 1 and 2 are not mutually exclusive. Exactly why is the seminar not at the local pub?
- randomwalker 16y agoSome background information. The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather than the banks. The relevant legal standard is that customers must exercise "reasonable care" with their PIN if the bank is to bear the cost of fraud. Of course, banks always insist that their systems are secure, and that it was the customer's fault. http://www.timesonline.co.uk/tol/money/consumer_affairs/article6249940.ece http://www.timesonline.co.uk/tol/money/consumer_affairs/arti... The Cambridge team has been investigating vulnerabilities in the EMV standard underlying Chip and PIN (ubiquitous in the UK) for a long time. From 2006: http://www.lightbluetouchpaper.org/2006/03/15/chip-and-skim/ http://www.lightbluetouchpaper.org/2006/03/15/chip-and-skim/ If I understand correctly they first started to find serious vulnerabilities in 2009. Blog post: http://www.lightbluetouchpaper.org/2009/08/25/defending-against-wedge-attacks/ http://www.lightbluetouchpaper.org/2009/08/25/defending-agai... Paper: "Optimised to Fail: Card Readers for Online Banking" http://www.cl.cam.ac.uk/~sd410/papers/optimised_fail.pdf http://www.cl.cam.ac.uk/~sd410/papers/optimised_fail.pdf Media: http://www.youtube.com/watch?v=U1QAnb-wnTs http://www.youtube.com/watch?v=U1QAnb-wnTs They escalated that attack in 2010. http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-is-broken/ http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i... Paper: http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.pdf http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.p... Media: http://www.youtube.com/watch?v=1pMuV2o4Lrw http://www.youtube.com/watch?v=1pMuV2o4Lrw
- oasisbob 16y agoFor the original complaint, see this PDF (via Light Blue Touch): http://www.cl.cam.ac.uk/~rja14/Papers/20101221110342233.pdf http://www.cl.cam.ac.uk/~rja14/Papers/20101221110342233.pdf
- StavrosK 16y agoI don't really understand the logic behind chip and pin cards. Do you really want me to disclose my card and my PIN to a completely untrusted machine a stranger hands to me? How do I know the vendor won't just record both and replay them, charging me for things I didn't pay?
- 16y ago
- ig1 16y agoAn important but often overlooked fact is that while there's no universal freedom of speech in British Law (although the UK is a member of the European convention on human rights which has such a protection), universities specifically are required to act to protect freedom of speech of their members. The University of Cambridge is legally obliged to stand behind this research under the 1986 Education Act which states: (2) The duty imposed by subsection (1) above includes (in particular) the duty to ensure, so far as is reasonably practicable, that the use of any premises of the establishment is not denied to any individual or body of persons on any ground connected with— (a)the beliefs or views of that individual or of any member of that body; or (b)the policy or objectives of that body. Full text: http://www.legislation.gov.uk/ukpga/1986/61/section/43 http://www.legislation.gov.uk/ukpga/1986/61/section/43
- cperciva 16y agowhile there's no universal freedom of speech in British Law... Perhaps not in written law, but I think you'd have a hard time convincing a judge that the British constitution does not guarantee freedom of speech. As my legal friends as fond of pointing out, an unwritten constitution has the important advantage that its words can't be twisted the way that a written constitution can.
- pyre 16y agoBut an unwritten constitution is easier to change, because there is nothing written down to refer to as a 'base.'
- cperciva 16y agoCanadian constitutional law has something called the 'living tree doctrine', which states that the constitution can grow and evolve over time, being reinterpreted in new contexts. To push the metaphor a bit further, I'd point out that a living tree is considerably more resilient than a dead tree, and is likely to adapt to conditions which might otherwise destroy it. I don't think anyone can seriously claim that the commerce clause of the US constitution was intended to grant the vast powers which it has been used to uphold; but because the US constitution is -- theoretically -- not subject to growth and reinterpretation the way that the Canadian or British constitutions are, a legal fiction has been adopted instead. If the commerce clause had been interpreted within the context of the Canadian or British constitutions, it would probably have been handled as "we're going to read one new power into this" on a number of occasions, rather than the "yes, this clause gives you the power to do everything" which seems to have occurred in the US.
- alimoeeny 16y agoI really enjoyed the language!
- StavrosK 16y agoIndeed, that was a burn of academic proportions.
- viraptor 16y agoSame here. After the first page, I was laughing aloud. The whole letter reads like a two page, very official statement claiming "You sir, are an idiot." Then again - he's British :) I love it, especially that my course this year included exactly that paper and we spent considerable time on it for comparison to many other types of attacks.
- socratees 16y agoEvery university, scientific and social community, and research organization that think they have to pander to the requests of corporations and those in power, must make note of this. We have had enough "Dark Ages" in the past. Let's learn something from history.
- Eliezer 16y agoCambridge is the University of Erasmus, of Newton, and of Darwin CMOA
- patrickdc 16y agoBaller!
- mjac 16y agoReading that letter makes me proud of the Security Group at Cambridge University. Ross Anderson took us for a couple of Security courses in second/third year Computer Science and was interesting, direct and completely no-nonsense. He emphasised that policy and ignorance were often the main causes of failures, especially with LAS, NHS centralisation (UK government projects). I find strong individuals like Anderson inspiring when they take on organisations who attack knowledge rather than being hands-on and fixing their systems. The Security II course is especially relevant. I am not sure that everyone can access these resources but the lecture notes cover a variety of modern hardware approaches to security (including chip-and-pin). Try: http://www.cl.cam.ac.uk/teaching/1011/SecurityII/ http://www.cl.cam.ac.uk/teaching/1011/SecurityII/ I highly recommend Anderson's Security Engineering, the first edition is available online: http://www.cl.cam.ac.uk/~rja14/book.html http://www.cl.cam.ac.uk/~rja14/book.html