Thursday, March 05, 2009

The end of Surveillance State

For the last year and a half, I have published a blog over at CNET, focusing on security, privacy and technology policy. Well, as of March 4, that business relationship is now over.

As my regular readers will know, for the past few months, I have been hammering the Obama Administration for its close ties to Google/YouTube. Starting back in November of 2008, I called for the "separation of Google and State," and urged the then President-elect to find a more pro-privacy way to deliver his video messages.

Looking back through the posts I have published in the past few months, nearly every single one is focused on this issue. These include:

Why Obama should ditch YouTube
Dear Obama: Use BitTorrent for your Fireside podcasts
White House exempts YouTube from privacy rules
White House acts to limit YouTube cookie tracking
White House yanks 'YouTube' from privacy policy.

While this might seem like an insane obsession, I strongly believe that my writing helped to bring a significant amount of attention to this issue, and thus lead to real change. Consider the following:

  • In the first five days of the Obama Presidency, his web-team changed their privacy policy three times, addressing issues first highlighted on my blog.


  • Before Obama had even moved in the White House, his lawyers had written up a waiver for the YouTube cookie issue (although they still refuse to release it), addressing concerns that I had raised in November of 2008. YouTube was similarly used by several agencies during the Bush Administration, although no such waiver was felt to be necessary.


  • Within days of Obama's inauguration, his web-team rushed out a partial fix to the cookie issue for people who didn't click "play", and then shortly after, a link to the White House privacy policy was added below each embedded video on the White House Web site.


In the past six weeks, the White House web team has devoted a significant amount of time towards fixing privacy problems on the site. If the issue wasn't a priority for them when they started in late January, it certainly is now.

"The White House Dumps YouTube"

On Monday, I published a story documenting the fact that the White House had, with its latest weekly video address, opted to not use an embedded YouTube video on the official White House Web site.

The story set off a minor shit-storm in the blogosphere, which eventually lead to a New York Times story, and official denials by both the White House and YouTube.

Feeling the pressure, my editors at CNET rewrote the headline on my blog post, and then added a comment to the top stating that my story "significantly misconstrued the White House's policy on and use of YouTube."

The next day, I was notified that our business relationship had been terminated, and that CNET would no longer be requiring my blogging services.

Ouch.

Looking at the denials in depth

It is clear that Google (and to a lesser extent) the White House needed to issue denials, if just to save face. However, rather than addressing the specific statements in my blog post, they denied things that I never actually claimed.

Rather than actually comparing the denials to the text of my blog post, the media willingly published Google's spin-heavy version of the story.

In an effort to set the record straight, particularly with regard to CNET's statement that I "significantly misconstrued" the facts, consider the following:

Writing on the Google Policy Blog, Steve Grove wrote:

[Chris's] report is wrong. The White House decision does not mean that the White House has stopped using YouTube. The White House continues to post videos to its YouTube channel, as do other agencies like the U.S. Department of Education and the State Department.


However, my original story never claimed otherwise:

The White House is still posting copies of the videos to its official YouTube channel.


Likewise, consider the statements made by the White House to the New York Times:

Now the White House is denying that it has changed its policy on videos from YouTube, which is owned by Google, or other third parties. While it chose to host President Obama’s weekly radio and video address on WhiteHouse.gov, rather than embed a video from YouTube on its site, the change was simply an experiment, said Nick Shapiro, a White House spokesman.

“As the president continues his goal of making government more accessible and transparent, this week we tested a new way of presenting the president’s weekly address by using a player developed in-house,” Mr. Shapiro said in a statement. “This decision is more about better understanding our internal capabilities than it is a position on third-party solutions or a policy. The weekly address was also published in third-party video hosting communities and we will likely continue to embed videos from these services on WhiteHouse.gov in the future.”


Again, back to my original blog post:

It is unclear whether this switch away from YouTube marks a permanent shift in policy for the White House, or whether the Oval Office geek squad is merely testing an alternate video provider. While the latest video is served using Akamai's servers, the older videos remain as embedded YouTube files.


Looking back

While CNET goes to great lengths to state that the people writing in its Blog Network are not CNET employees, that detail often gets lost on members of the public. As a result, when I would blog something, it would be written up by other media outlets as "CNET reported that."

As an activist, this gives you a very powerful tool, since you effectively get to speak with the voice of the mainstream media. My blog gave me a soapbox which hugely amplified my voice, and permitted me to pillory companies and the government whenever I thought they were doing something they shouldn't.

In several cases, I was able to use the CNET blog to significantly shape the public debate on various issues -- such as with Google's so called "anonymization" of search log data, TSA's policies towards flying with no ID and the disclosure of identifying customer information by Internet Service Providers.

I suppose that what surprises me the most is that CNET let me editorialize on their site and with their brand for as long as they did.

Moving on

While I am clearly a bit sad about the loss of my soapbox, there is probably a silver lining in this. I am a PhD student in my third year, and I really need to start working on my dissertation soon. Blogging, even once or twice a week, takes a significant amount of time, at least when you are trying to write detailed and original analysis. It'll be nice to be able to refocus those 10 hours a week or so back on my studies.

It's likely that I'll still blog here once and a while, but now that I'm no longer contractually obligated nor paid to do so, it is likely that I'll be writing far less frequently.

Those of you who had subscribed to the CNET RSS, please re-subscribe here. And those PR hacks who keep pitching stories in the hope that I'll post your press release to CNET, please stop.

Wednesday, September 05, 2007

My Blog Has Moved!

I'm happy to announce that my blog has moved to CNET, where I've joined their Blog Network.

Due to the terms of my contract, I've had to change the name of my blog (so that they can own the new name) - and so the new blog is named Surveillance State. The new blog is located at:
http://www.cnet.com/surveillance-state/

For the most part, the blog will remain the same - still a focus on security and privacy, with a bit of amateur legal analysis thrown in for fun - although expect slightly more frequent posting (3x per week or so).

I've already posted a couple articles this week - while we were still getting all the kinks worked out of the system: An analysis of Comcast's BitTorrent filtering (and the laws they may be breaking in doing so), and today a post on Apple's iPod Touch (and the fact Steve Jobs won't be able to blame AT&T for keeping the platform closed).

I hope you'll all follow me over to CNET.

Thursday, July 19, 2007

Airport Security x 3


This blog post is likely to be the last until September, as I'll be leaving Munich next week, and will spend the entire month of August backpacking in India. I expect to have email access in Ladakh, and I doubt if there will be decent Internet in the remote villages in the Parvati Valley - at least, there wasn't any when I visited last year.

Today's blog post is in three parts, all related to airport security: The end of my legal troubles, the successful publication of my airport security research paper, and a brief writeup of my recent experience going through British airport security.



I received word from my awesome pro-bono legal counsel, Jennifer Granick, that TSA has wrapped up their investigation, and will not be filing civil charges against me. The FBI dropped their investigation in November last year. It looks like the entire affair is now over.

Ten months after the FBI strong-armed my ISP into taking down my website (as well as ransacking my home, and making off with my computers and passports), the flaws that I highlighted are still exploitable, and have not been fixed. The reimplementation of my boarding pass generator by "John Adams" (that was first released on November 1 2006) also remains online.

In addition to the help of super-lawyers Jennifer Granick and Steve Braga, I received an outpouring of support from around the world, from the students, faculty and staff at Indiana University, and from my friends, family and loved ones.

One particular friend provided me with a place to stay the night the FBI visited, and had it not been for their instance that I come with them, I would have been at home when the G-Men broke in at 2AM, guns drawn. To this person in particular as well as everyone else who helped out, I am eternally grateful.



Security research is typically a two part process: You break something, and then you fix it. My boarding pass generator and numerous blog-posts highlighting the no-id + no-fly list problem were the first part of the research process. A newly released academic paper fixing the flaws is the second part.

I am proud to announce that my paper "Insecure Flight: Broken Boarding Passes and Ineffective Terrorist Watch Lists" has been accepted for publication by the IDMAN 07 working conference, where I'll also be presenting it in Rotterdam, Netherlands in October.

Bruce Schneier, Senator Schumer, and others did a great job in highlighting the fake/modifiable boarding pass problem years before I built my hullabaloo causing website. However, no academic has yet written about this. My paper fully explores the interesting combination of the ability to fly without ID, and the government's insistence on maintaining a no-fly list. I have personally flown without ID over 12 times, and I do not believe that anyone else has really written about the fact that this essentially neutralizes the no-fly list. I also present a new physical denial of service attack against the TSA passenger screening system.

It is important to note that I do not take a position on the no-fly list in the paper. The US government has spent over $250 million dollars on implementing the list. The paper thus explores methods to effectively enforce it. The paper presents a technical solution to the problem (digitally signed boarding passes), which will enable TSA staff to instantly learn if a pass is valid or not, or if it has been tampered with, as well as stopping all other known attacks.

Were the airlines in the US willing to check the ID of each passenger before they board a flight - something they did right after 9/11 - my technical solution wouldn't be necessary. 100% effective enforcement of the no-fly list is only possible when airlines check all IDs at the gate, and when the US government takes away our right to fly without ID.

A pre-publication copy of my paper can be downloaded here.


I was in London two weeks ago to see family. I flew in a few hours after the failed bomb attack, and was watching TV in east London when the idiots tried to drive a flaming jeep into Glasgow airport.

I flew back to Germany a couple days later, and in spite of the fact that I had to get up at 4AM for my flight, I paid close attention to the security procedures in place at Stansted Airport.
  • There is now an unwritten but enforced rule banning large umbrellas. If it can't fit in a carry on bag, you're forbidden to take it through security. British airport security staff thus seized my golf-umbrella.


  • Just as in the US, the British consider hummus to be a liquid. I took the top off the container, held it upside down, thus demonstrating that it would not pour out, but the screener insisted that I give it up. The supervisor on duty did at least let me sit on one of the bag-searching tables, with people's bags being searched on both sides of me. Thus, under the watchful corner-of-the-eye of her security staff, I ate all the hummus and pita bread I had brought with me as my lunch. The supervisor even went out of her way to bring me an unrequested cup of water . I can't imagine TSA staff doing this.

  • Print at home boarding passes with the airline Easyjet contain a computer-readable barcode. This barcode is read by airport security screening staff, before you even enter the metal detector/x-ray line. I'm not sure what happens if the barcode doesn't find a match - but I did observe that my name came up on the screen, which the security staff member then compared to my ID. This means that if your name is not associated with a paid ticket in the reservation system, you will not even gain access to the security screening area. Quite impressive.


  • Once Easyjet staff began boarding, they looked up every passenger's name in the reservation system and checked it against an ID before letting the passenger onto the airplane. No passport, no entry.



Comparing US domestic flight security to European flight is not 100% fair. You do not need to show ID to travel within the US, and except for a few select situations, you cannot be forced to show ID in the US. Europeans do not have this right, and as the individual European countries are much smaller than the US, you are essentially always crossing some international border when you fly.

US airlines somehow managed to get the government to let them stop asking for ID at the gate - after they complained about the labor costs and delays the process introduced to the flight-boarding process.

Nonsense.

If Easyjet, a no-frills airline that won't even give you a free glass of water, can ask passengers for ID and somehow manage to turn a profit, as well as get their flights off in a reasonable amount of time, then the US airlines are not telling the truth.

I lived in the UK when the IRA, through the use of bombs placed in train-station rubbish bins, forced the authorities to remove every trash can from train and tube-stations in London.

While the Israelis get a lot of credit for their airport security skills - as others have pointed out before me, Israel is small, and doesn't have many flights in or out. London's Heathrow is one of, if not the the busiest airport in the world. The British have had this airport security thing figured out for years. If the US government is serious about enforcing the no-fly list, they should learn a thing or two from the Brits, and force all airlines to check passengers' ID against a computerized reservation system record at the gate.

The flip side of course, is that if the US government finally accepts that the no-fly list is a pointless waste of money, then that money can be spent on more important things - like training TSA staff to actually find the weapons and bombs that currently seem to miss, again and again.