Tomorrow's Transactions » PKI http://tomorrowstransactions.com Thought leadership from Consult Hyperion Wed, 10 Sep 2014 20:33:30 +0000 en-US hourly 1 http://wordpress.org/?v=4.0 And I’ve got my bronze swimming certificate http://tomorrowstransactions.com/2011/02/and-ive-got-my-bronze-swimming-certificate/ http://tomorrowstransactions.com/2011/02/and-ive-got-my-bronze-swimming-certificate/#comments Tue, 01 Feb 2011 11:05:15 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/02/and-ive-got-my-bronze-swimming-certificate/ [Dave Birch] We're a long way from having an infrastructure that can help with educational and resume credentials, although we can see how one might work, I think.

The post And I’ve got my bronze swimming certificate appeared first on Tomorrow's Transactions.

]]>
When I’m talking about identity, I sometimes joke that our ill-thought out perspectives on the topic have led to the bizarre situation that in the UK it is much easier to get a job with a bank than an account. In The Daily Telegraph for 29th January 2011, I read under the headline “False CV Fooled Bank” that:

A fraudster used a false CV [claiming degrees from Oxford and Harvard] to gain a £165,000 per annum job at a City investment bank.

I assumed that everybody made up stuff on their resumes, but it turns out that it’s against the law, so the culprit, Mr. Peter Gwinnell, was prosecuted and given a suspended sentence (I assume he’ll skip over this on his next CV). We keep being told that employers use Facebook profiles nowdays (I hope they use mine: it says that I am the most intelligent person alive today and that Nelson Mandela queued for my autograph) so perhaps CVs will soon be a thing of the past. Just out of curiosity I googled Mr. Gwinnell and found that as well as his empty LinkedIn profile, the bald fact of his departure is there on the web.

PETER GWINNELL Appointment terminated as director on 15 Feb 2010 (Document)

[From AHLI UNITED BANK (UK) PLC of W1H 6LR in LONDON UNITED KINGDOM]

To be honest, if an employer wanted proof of my A-Level in Mathematics or O-Level in British Constitution or the Degree I scraped through with in 1980, I’d be hard pressed to provide it. I don’t have the faintest idea where the relevant certificates are. I suppose I could ring the University and ask them to send me a letter, but how would the employer know I hadn’t forged the letter. And how would Southampton University know that it is me calling? Or, for that matter, how would they know that I hadn’t forged the O-Level in British Constitution certificate?

When I started my first job after university, I don’t remember being asked to provide any such proof. Come to that, I don’t remember being asked to prove who I was either. In those days, all you needed was a national insurance number. But if employers are going want proof, like the actual certificates, then there will be a bit of a premium on the certificates. Once the certificates are worth something, they will be stolen. This is what happens in China.

Local officials said the files were lost when state workers moved them from the first to the second floor of a government building. But the graduates say they believe officials stole the files and sold them to underachievers seeking new identities and better job prospects — a claim bolstered by a string of similar cases across China.

[From Files Vanished, Young Chinese Lose the Future - NYTimes.com]

How are we going to deal with this digitally? It shouldn’t be that complicated for Harvard to create a digital certificate to attest to the fact that the owner of a particular identity did, in fact, graduate. If there were some sort of device or token, perhaps some form of card, that contained my educational identity (ie, key pair) then Harvard could simply sign the public key with their private key and the whole problem is fixed (glossing over, of course, where this device or token might come from, and so on).

Something does have to be done though. The current system is simply a joke. It’s quite funny when someone cons a bank into giving them a senior position despite knowing nothing about banking (imagine!) but one of the areas that really bothers me, and probably should bother you too, is the ease with which medical credentials are forged.

A conman from Lancashire who posed as a vet and nearly killed a pony by botching its castration has been jailed for two years. Russell Oakes also masqueraded as a doctor, carried out an intimate examination and charged for false diagnoses, Liverpool Crown Court heard. The 43-year-old, of Hesketh Bank, admitted 41 charges of fraud, forgery and perverting the course of justice.

[From BBC News - Bogus Lancashire vet jailed after botched castration]

How did he do this? Was he a master forger, capable of producing an authentic-looking medical school diploma using specially-aged paper, his engraving skills and authentic ink procured from the correct German manufacturer? No, of course not: this is a post-modern crime.

He bought a fake university certificate off the internet, the court heard.

[From BBC News - Bogus Lancashire vet jailed after botched castration]

Now imagine an alternative infrastructure. I am asked to prove that I have a degree from Southampton University. I log on to the university using my OpenID id.dave.com and answer some questions, provide some data, to satisfy the university that I am, indeed, the relevant dave. My OpenID profile includes a public key, so the university creates a public key certificates, signing that key and some standard data that they provide. I can now give this certificate to anyone, and they can check it by verifying the signature using the published Southampton University public key, resolving the certificate chain in the usual way.

the BBC suffered another embarrassment today after a man interviewed on Radio 4’s World at One who claimed to be a Liberal Democrat MP was revealed to be an imposter.

[From Radio 4 follows Jeremy Hunt gaffe by interviewing fake MP | Media | guardian.co.uk]

How would the proposed infrastructure help here? The system has to be so easy to use that a harassed BBC researcher can use it. Come to that it has to be so easy that military installations, the police and other can use it too.

During the period of January to June 2010, undercover investigators utilized fraudulent badges and credentials of the DoD’s military criminal investigative organizations to penetrate the security at: 6 military installations; 2 federal courthouses; and 3 state buildings in the New York and New Jersey area

[From Schneier on Security: The Security Threat of Forged Law-Enforcement Credentials]

Step forward the mobile phone. Every single one of the people who were “verifying” IDs in these stories has a mobile phone, so there’s no need to look any further. The military policeman’s mobile phone should be able to check your ID. And your mobile phone should be able to check his ID. And if you’re both using mobile phones, both IDs can be checked simultaneously. We already know that symmetry is an important property of an identity infrastructure: the bank needs to be able to check it’s me, but I need to be able check it’s the bank. And the mobile phone can do both. So next time Peter shows up for an interview, the interviewer can simply tap Peter’s NFC phone against their NFC phone and see a full list of his credentials.

(Law enforcement has special additional issue though: sometimes, the policeman doesn’t want to reveal that he’s a policeman, but that’s a topic for another day.)

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post And I’ve got my bronze swimming certificate appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2011/02/and-ive-got-my-bronze-swimming-certificate/feed/ 3
Red army http://tomorrowstransactions.com/2010/12/red-army/ http://tomorrowstransactions.com/2010/12/red-army/#respond Mon, 13 Dec 2010 23:00:47 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/12/red-army/ Wikileaks is going to force the debate about anonymity and the Internet. Pretty soon, as many have anticipated, there's going to be a blue internet and a red internet, an authenticated internet with a digital identity infrastructure and a barbarian (alluding to the original sense of the word) internet.

The post Red army appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Oh no! According to tonight’s news reports, the UK is bracing itself for cyberattack from the “hackers” supporting Julian Assange and Wikileaks. Apparently vital government services are at risk from the group called “Anonymous” launching distributed denial-of-service (DDOS) attacks. A bit like this guy, from the group “Not Anonymous At All”:

A 17-year-old from Manchester has been arrested by the Metropolitan Police’s e-crime unit (PCeU) on suspicion of being behind a denial of service attack against the online game Call of Duty.

[From Call of Duty DDoS attack police arrest teen • The Register]

He was, of course, traced from his IP address. I thought it was funny, in a way, that journalists and politicians refer to the LOIC kids as “hackers” when they are anything but. What’s more, as I said when Charles Arthur was kind enough to invite me on to The Guardian’s Technology Podcast, they have chosen a particularly funny way to join the Anonymous group of internet vigilantes: software that isn’t anonymous in the least and that delivers their IP addresses to their intended victims, thus making it easy for them to be traced and arrested. This is, in fact, precisely what has happened.

A 16-year-old boy was arrested in the Netherlands in connection with a series of cyber attacks on Visa, MasterCard

[From Dutch teen arrested over cyber attacks on Visa, MasterCard]

My personal views about Wikileaks and the “Cable Gate” DDOS attacks are irrelevant. (I will say this: that if you don’t like MasterCard then cancel your card and leave mine out of it). But they will certainly have an impact on thinking and the calls for “something to be done” mean change. Since there’s no way to stop people from copying data (as the music industry has discovered), that’s probably not a fruitful line of thinking. So what will happen?

What technology may lead to are “red” and “blue” internets. (Note that “blue and red” are here allusions to the military labelling of secure and insecure networks, they are nothing to do with blue and red pills in The Matrix.) Essentially, there will be secure and insecure internets both running over the same IP networks.

On the red, open, internet people and organisations will exchange encrypted data across an untrusted network. Some people may choose not to connect to the red internet at all and only crazy people (and organisations) will send unencrypted data to unauthenticated counterparties.

On the blue, closed, internet you will need to authenticate yourself before you are allowed to access anything and a digital identity infrastructure will deliver privacy (and in some cases anonymity) through cryptography, not through data protection registrars or privacy ombudsmen. In order to connect to the government, or Facebook, or Amazon, you will have to use the blue internet: they simply won’t be connected to the red internet any more. At home, I will probably set my internet connection to blue only.

Now, some of you may be concerned that, as The Daily Telegraph told us, the Chinese government have a master key that can decrypt everything on the Internet, in which case the entire Internet will be — very literally indeed — red forever.

While sensitive data such as emails are generally encrypted before being transmitted, the Chinese government holds a copy of an encryption master key which could be used to break into redirected traffic.

[From China 'hijacks' 15 per cent of world's internet traffic - Telegraph]

But look on the bright side: since the Chinese have “a copy” of this mythical master key, someone else must have the original, and they will be able to read all of the Chinese government’s e-mail and put that on Wikileaks too.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Red army appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/12/red-army/feed/ 0
Stux on you http://tomorrowstransactions.com/2010/11/stux-on-you/ http://tomorrowstransactions.com/2010/11/stux-on-you/#comments Mon, 29 Nov 2010 20:58:52 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2010/11/stux-on-you/ So whoever wanted to stop the Iranians from enriching uranium (the Americans, the Saudis, the Israelis etc) found a cheaper and more efficient way to do it than launching cruise missiles or dropping bunker busting bombs.
...MC7 is the assembly language that runs on PLCs and is often originally written in STL... only CPUs 6ES7-417 and 6ES7-315-2 are infected [From Exploring Stuxnet’s PLC Infection Process | Symantec Connect ] OK.
...O'Murchu noted that researchers had uncovered the reference to an obscure date in the worm's code, May 9, 1979, which, he noted, was the date on which a prominent Iranian Jew, Habib Elghanian, who was executed by the new Islamic government shortly after the revolution.
...I does make you wonder though: if there was a proper digital identity infrastructure in place, which managed M2M transactions as well as P2M transactions, then how would this kind of attack work?

The post Stux on you appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] The media are full of cyberwar at the moment. I’m sleeping safely in my bed knowing that we now have a cyberwar strategy. But there does appear to have been one cyberwar attack that has already succeeded. The story about Stuxnet is fascinating, especially now that the Iranians have admitted that it worked.

President Mahmoud Ahmadinejad admitted Monday that “several” uranium enrichment centrifuges were damaged by “software installed in electronic equipment,” amid speculation Iran’s nuclear activities had come under cyberattack.

[From France24 - Iran admits uranium enrichment hit by malware]

So whoever wanted to stop the Iranians from enriching uranium (the Americans, the Saudis, the Israelis etc) found a cheaper and more efficient way to do it than launching cruise missiles or dropping bunker busting bombs.

Here are the bare bones.

the malicious code that Stuxnet aims to run on the industrial control system execute on the PLC and are written in MC7 bytecode. MC7 is the assembly language that runs on PLCs and is often originally written in STL… only CPUs 6ES7-417 and 6ES7-315-2 are infected

[From Exploring Stuxnet’s PLC Infection Process | Symantec Connect]

OK. So this seems reasonable. A clever virus writer has put together something that propagates across PCs and when it finds a particular CPU attached (for industrial control) is sends its “payload” to that CPU. It’s very specific.

Stuxnet searches for frequency converter drives made by Fararo Paya of Iran and Vacon of Finland. In addition, Stuxnet is only interested in frequency converter drives that operate at very high speeds, between 807 Hz and 1210 Hz. The malware is designed to change the output frequencies of drives, and therefore the speed of associated motors, for short intervals over periods of months. This would effectively sabotage the operation of infected devices while creating intermittent problems that are that much harder to diagnose.

[From Missing piece completes Stuxnet jigsaw • The Register]

Pretty dastardly.

O’Murchu noted that researchers had uncovered the reference to an obscure date in the worm’s code, May 9, 1979, which, he noted, was the date on which a prominent Iranian Jew, Habib Elghanian, who was executed by the new Islamic government shortly after the revolution.

[From Stuxnet Analysis Supports Iran-Israel Connections | threatpost]

On the other hand, it was also the day that the Unabomber struck at Northwestern, so maybe it’s got something to do with that? Or what if it is related to the famous Pierre Trudeau rally on that day and BC separatists are behind the hack, actually targeted at the Canadian oil industry? Of course, none of us has any idea whether any of this is true or not. I does make you wonder though: if there was a proper digital identity infrastructure in place, which managed M2M transactions as well as P2M transactions, then how would this kind of attack work? Suppose, for example, that the kind of digital identity infrastructure that uses digital signatures was in place that how would sneaky foreign viruses get their payload on board?

It turns out that the Stux story does involve digital signatures. Having followed the links from a few stories to try and find out what actually happened, I’m none the wiser. Perhaps journalists aren’t reporting it properly, or perhaps bits of the story are missing.

Q: How can it install its own driver? Shouldn’t drivers be signed for them to work in Windows?
A: Stuxnet driver was signed with a certificate stolen from Realtek Semiconductor Corp.

Q: Has the stolen certificate been revoked?
A: Yes. Verisign revoked it on 16th of July. A modified variant signed with a certificate stolen from JMicron Technology Corporation was found on 17th of July.

[From Stuxnet Questions and Answers -]

I don’t understand this. A stolen certificate wouldn’t allow you to forge a signature, since it contains the public key, whereas you need the private key to form a signature. Is there anyone out there who can point me in the right direction to find out what has actually been going on? Or is this more evidence that someone has the master key to the internet that The Daily Telegraph told us about.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Stux on you appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2010/11/stux-on-you/feed/ 2
Vote “no” to yesterday’s technology http://tomorrowstransactions.com/2008/12/vote-no-to-yesterdays-technology/ http://tomorrowstransactions.com/2008/12/vote-no-to-yesterdays-technology/#respond Tue, 16 Dec 2008 14:32:52 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/12/vote-no-to-yesterdays-technology/ [Dave Birch] There's infrastructure dddjd xxx bank. These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

The post Vote “no” to yesterday’s technology appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] The recent Pew report on the Future of the Internet makes the same point that I have been droning on about for ages. Looking at PCs and the web doesn’t tell you anything about the future, because the future is mobile.

“Clearly, in the long run, mobile wins,” says Consult Hyperion’s Birch. “For most people, in most of the world, most of the time, the mobile phone is the most important device.”

[From FST]

Now, in some advanced countries, it is seen as natural to being to transfer applications that hinge on identity over to the most personal interweb interface, the mobile phone. An interesting case study is Estonia. We’ve looked before at Estonia’s use of new technology and they are back at the forefront this month:

Lawmakers approved a measure Thursday allowing citizens to vote by mobile phone in the next parliamentary elections in 2011… The mobile-voting system, which has already been tested, requires that voters obtain free, authorized chips for their phones, said Raul Kaidro, spokesman of the SK Certification Center, which issues personal ID cards in Estonia.

[From Estonia to vote by mobile phone in 2011 - International Herald Tribune]

This is a similar architecture to that being deployed in Turkey, where the key pair at the heart of scheme is stored in the SIM and the on-board application uses it for digital signatures.

So if the future — in fact, the present — is mobile, wouldn’t people developing major new IT systems — with a strong identity component — have mobile technology at the heart of the vision and make the mobile exploitation of the infrastructure a key element in the public proposition?

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Vote “no” to yesterday’s technology appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/12/vote-no-to-yesterdays-technology/feed/ 0
Population-scale PKI http://tomorrowstransactions.com/2008/02/population-scal/ http://tomorrowstransactions.com/2008/02/population-scal/#comments Fri, 01 Feb 2008 12:38:58 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/02/population-scal/ Summary

The post Population-scale PKI appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] The Land Registry, the government agency that records who owns Britain’s land and buildings, has spent the past decade developing an e-conveyancing system to make buying and selling houses easier and more certain. It’s going to be using PKI to secure the system. Authorised parties will be able to exchange information quickly, securely and reliably with each other and the Land Registry. Documents will be encrypted and “signed” with a digital certificate, and people will require a secure token, username and password to produce and read the documents. Final testing is underway and when it goes live, expected in early summer, it will be able to process up to 300,000 documents a day and support up to half a million security “certificates” from property professionals such as conveyance attorneys.


It sounds like a great system. Let’s hope that it’s designed and implemented to a high standard, because systems like this one have no margin for error. Even when bad implementation leads to errors that aren’t serious, as with the UK Passport Office, it can have a very bad impact on confidence. Look at the impact of yesterday’s HMRC failure: no data was lost or compromised, yet public faith in government ID has been seriously undermined.

Of course, when bad implementation or an incomplete understanding of PKI leads to errors that are that serious, the results can be disastrous. India has a PKI-based digital signature system managed through digital certificates issued by licensed CAs. The CAs are authenticated by the Controller of Certifying Authorities (CCA) who is the root certifying authority in India. Every digital certificate owner therefore needs to download the digital certificate of the certifying authority as well as the digital certificate of the Controller when he has to install or verify the end user certificate in his system. In October 2007, this CCA site (which is supposed to be 24/7) went down. This meant that no-one could authenticate certificate chains. I’ve no idea how much this actually cost businesses, but in a future society where all sorts of transactions are conducted digitally and demand authentication, this kind of centralised solution is an obvious weakness. Surely an intelligent terrorist would want to cripple this kind of root rather than waste time blowing up the odd building here and there.

Still, I’m sure it’s now well understood that building a large identity management system with a single central point-of-failure is, essentially, designing-in failure.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Population-scale PKI appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/02/population-scal/feed/ 1