Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, February 19, 2026

Fake People Everywhere

Soon you will only trust people you know.  



I have been learning a fun programming language called Gleam. And I wanted to read a book on it. 
The one book on it I could find was by someone called Julian Lornfield. Who has written over a dozen books in 2025 each on a different topic in computers. Theres no photo of them on the internet other then this amazon author photo. No linkedin. No youtube talks at conferences etc.



So baring some major mistake by me this is a bot churning out AI written books. It could be a real person but one without the usual trail we leave. A fake author would be odd but not something that unusual in 2025.

But to take a step up from these checks. What happens when fake reviews, linkedin accounts and these things I checked are much easier? If there was a linkedin, lots of reviews, better spacing of the release dates and even videos of talks would I have been fooled? Probably.

Making a fake account involves making photos, passing captchas, sending text back and forth between some other bots and some real people. All this is easily doable now. 

AI LLM arguments focus on the abilities at the extreme. Writing a new math proof or acing some test. But what happens when they get really good at stuff designed for normal people to easily do. Gmail wants you to get an email account. Amazon wants you to leave reviews. Emergency services want you to ring when your house is on fire. 

When LLMs get good enough at these tasks that Social media, reviews, email inboxes get flooded you will not trust anyone in the digital space you do not personally know. They pretty much are already on Twitter and facebook but other digital locations are next. The cost of an llm for the same level of intelligence decreases 10 fold per year. So if it is too expensive to build up 100 bot reviewers today it will be 1/1000th the cost in 3 years. 

For online review sites this is probably fairly obvious. But I do not think the effects on offline services are considered yet. 
999 services or dentists are not designed for 100 bots that sound like people ringing them.
Politicians and newspapers are not expecting 100 physical letters what have all been written by different bots.
If we get 100 fake ads from what looks like our bank we are likely to get one just when we are having a problem and at our most confused moment believe them.

LLMs are smart enough now to create and operate online accounts including making phone calls. The price of this will drop orders of magnitudes in a few years. The online and especially the offline world is not set up for when this happens. 



 

Monday, June 18, 2012

Baby's First Hack

Maternity hospitals put these security bracelets on your baby. The thing is because the baby loses so much weight and generally changes so much after their birth they keep falling off. The nurses get annoyed by them because they fall off so often but they generally seem not to mind them too much. My video below shows how easy they are to remove

And that is without trying to cut off the tag or shield it from the radio receiver in some way. Schneier has a good post on how these tags just because they don't actually reduce risk of harm much are still valuable. I'll quote it at length because it is so good.

'While visiting some friends and their new baby in the hospital last week, I noticed an interesting bit of security. To prevent infant abduction, all babies had RFID tags attached to their ankles by a bracelet. There are sensors on the doors to the maternity ward, and if a baby passes through, an alarm goes off.

Infant abduction is rare, but still a risk. In the last 22 years, about 233 such abductions have occurred in the United States. About 4 million babies are born each year, which means that a baby has a 1-in-375,000 chance of being abducted. Compare this with the infant mortality rate in the U.S. -- one in 145 -- and it becomes clear where the real risks are.

And the 1-in-375,000 chance is not today's risk. Infant abduction rates have plummeted in recent years, mostly due to education programs at hospitals. So why are hospitals bothering with RFID bracelets? I think they're primarily to reassure the mothers. Many times during my friends' stay at the hospital the doctors had to take the baby away for this or that test. Millions of years of evolution have forged a strong bond between new parents and new baby; the RFID bracelets are a low-cost way to ensure that the parents are more relaxed when their baby was out of their sight.

Security is both a reality and a feeling. The reality of security is mathematical, based on the probability of different risks and the effectiveness of different countermeasures. We know the infant abduction rates and how well the bracelets reduce those rates. We also know the cost of the bracelets, and can thus calculate whether they're a cost-effective security measure or not. But security is also a feeling, based on individual psychological reactions to both the risks and the countermeasures. And the two things are different: You can be secure even though you don't feel secure, and you can feel secure even though you're not really secure.

The RFID bracelets are what I've come to call security theater: security primarily designed to make you feel more secure. I've regularly maligned security theater as a waste, but it's not always, and not entirely, so.'

In Praise of Security Theater

I agree with his description. The tags from a rational measurable security point of view silly, everyone if they think about it can tell their silly. But they reassure new parents of a non rational but still present fear. And that means the tags probably are not silly.

Thursday, March 29, 2012

Household Charge Security Questions



The household charge website security questions pictured above are awful. This charge is a new tax the Irish government has created where most people with a house in Ireland are supposed to register online. These are questions you can use to prove your identity. But the ones they have chosen are really weak. There are three main methods to attack them.

Social Engineering: Ask someone, set up a website the user trusts "TrustyBank.com" and ask them this question again

Brute forcing or guessing via statistics: Murphy is a really common name guess that. Then Kelly, Smith, O'Sullivan, Walsh, Ryan, O'Brien, Byrne... you can guess someones surname most of the time in a low number of guesses.
Pets names are surprisingly guessable (low entropy). The names people use are not that unusual. This site has stats on the most popular ones. The most common entered place of birth will be Dublin. Similarly Companies are not based in many places. Dublin will be a correct guess in many cases. Next I'd guess America, Ireland, Home... again there are likely to be very common answers to this.

Looking at these questions I would predict 10 answers of each will cover 50% of the population.

Informed Guessing. Many of these questions can be answered by searching facebook as described in this paper Personal knowledge questions for fallback authentication: Security questions in the era of Facebook by Ariel Rabkin. Or follow the method described in the paper Messin' with Texas:Deriving Mother's Maiden Names Using Public Records by Virgil Gri th, Markus Jakobsson describes a technique for finding out the answer to this first question. These questions seem very susceptible to facebook and public record searches.

This site lists Examples of Security Questions these sorts of questions. In the Poor section they have

What is your mother's maiden name?
In what county where [sic] you born?
What is the city, state/province, and year of your birth?
What is your pet's name?

So all the questions except the where is your company based question are common and known to be poor. The questions on the household charge website are guessable, searchable and so common another website could ask you them without raising suspicions. They provide an obvious and well known vulnerability to the system.

Thursday, January 26, 2012

EULA Be Sorry

Fan handcuffs himself to goalpost during Everton and Manchester City clash
A message on his T-shirt read: "Europe's greatest training robbers. Ryanair. Lowest wages guaranteed. Stop. Recruitment scamming our children."

If people really hate airlines there are much easier ways to harm their business than this. One way is to ask people to obey their terms and conditions.

Companies are still leaving themselves open to the being moved down search engine rankings as I described in Search Engine Deoptimization? The attack is to remove links to a website using the sites own Terms and Conditions.

1. Find if a company you are annoyed with has rule against linking to them in their Terms and Conditions. Something like 'links to this website without the prior written consent'.

2. Inform all the people who link to this website of this rule. Possibly implying you are from some sort of legal enforcement organisation.

Airlines and insurance companies love having these rules. The Idea I presume is to hinder price comparison websites.

If you do not want to go to the effort of building a spider to get the list of url's that link to a site you can google (or bing)
link:http://www.aerlingus.com

Where you replace http://www.aerlingus.com with the company website you want a list of linkers to.

The last example I used was Ryanair, mainly because so many people hate them. The following companies looked to have odd T&C from a quick read. I accept the irony of linking to people T&C that say you cannot link to their T&C.

Aer Lingus: 'to link to our site(s) only through our home page. Please do not link to other pages of our site(s) without obtaining prior written permission from Aer Lingus (such consent may be withdrawn at any time at Aer Lingus's sole discretion);'

Also World Food Program, Web Check in, Vishni capital, Glasgow 7s Rugby Team and NRMA insurance

For something like the only link to the main page rules you would need to modify the "link:" search and the scary email that tries to get the links removed.

It is easy to read the terms and conditions of competitors websites. Many competitors rankings would be harmed by removal of even a small percentage of quality links to their website. I think you could boost a client above a competitor with this technique. If I was asked to bump up an insurance companies websites search rankings I would be tempted to look at the terms and conditions of their competitors and do a "Link:" search on any of them who had these linking rules websites.

A quick google and sending some emails has to be easier than handcuffing yourself to a goalpost.

Tuesday, March 29, 2011

Search Engine Deoptimization

Take a company you have a problem with

1. Imagine you hate Ryanair. I do not btw they are just an example of a company this would work on.

2. You decide you want to harm them commercially

3. You go to their terms and conditions here and see they do not allow linking to their website

"Links to this website. You may not establish and/or operate links to this website without the prior written consent of Ryanair. Such consent may be withdrawn at any time at Ryanair’s own discretion."

There is a list of other companies that do not allow linking listed here. That where I heard of this T&C clause.

4. Now spider all the websites that do link to them. This is easy to do and you now should have a list of many websites. Either from a whois or just from scraping the website get an email address for each site.

5. Send all these linking websites official looking notices that remind them that "You may not establish and/or operate links to this website without the prior written consent of Ryanair" including a link to the official Ryanair terms and conditions. You would have to be careful here. You would not claim to be Ryanair for legal reasons. You do not want to break any laws or threaten anything. Just say you are from some official sounding company "John Smith and associates business compliance coordinators" and remind them of what the companies own policies say. It is not like you are lying.

6. Watch Ryanair drop down search rankings as people delete links to them. Search rankings are mainly based on how many (and what sort of) sites link to you. As they drop down the search engine rankings they will suffer commercially. With my google of "cheap flight dublin london" Ryanair comes up as the third site. Which implies they must get a fair amount of traffic from search engines.

I think this attack should be called Search Engine Deoptimization.

Wednesday, July 28, 2010

Evacuating the Love Parade

An important issue for crowd safety is how long it would take to evacuate a venue. Like the last article this is not to attempting to figure out the exact right answer to how large entrance/exits need to be but to try see if someone with a limited knowledge and a search engine could easily see in advance that the entrance/exit to the love parade was dangerous. Even large venues can require evacuation in the case of a natural or manmade disaster. These disasters could be weather related as happened here here and here. In the case of man made safety risks venues also are sometimes evacuated. As described here
"On December 12, 2004, the stadium Santiago Bernabeu in Madrid was evacuated because of a bomb threat.... In eight minutes, more than 70,000 people left the premises without incident."

The respected Spiegel says

"Much of the critique has centered around the fact that the tunnel where the panic took place was the only entrance to and the only exit from the party site. "
If this tunnel was the only exit available (another tunnel seems to have been reserved for emergency vehicles) how quickly should people have been able to exit?

This soccer stadium with a capacity of over 25,000 claims 'The target evacuation time for the entire Stadium at full capacity is 8 minutes.'

This document on evacuation planning states
"The maximum Emergency Evacuation Time for sports ground varies between two and a half minutes and eight minutes"

Stadiums do not have as much free space as larger venues but they still allow for moving people onto the pitch as happened at a baseball game after the 1989 San Francisco earthquake. In the case of some natural disasters or terrorist threats a site wide evacuation might be needed so even large sites probably need to be able to be evacuated reasonably quickly.

The acceptable evacuation time for a stadium seems to be under ten minutes. If Spiegel is correct and this tunnel really was the only exit any evacuation would have taken hours which is not be acceptable.

The pictures here give a very good impression of what happened. The width of the tunnel does indeed look like 16 meters. And the 'ramp' described earlier just looks like something people tried to escape up rather than a designated route.

Monday, July 26, 2010

How many people can pass through a tunnel?

A tragedy happened at the love parade when 19 people lost their lives. This will be investigated by professionals who will come out with detailed analysis on how this incident took place. I want to see what someone in half an hours worth of searching can say about how wide a tunnel you need to fit that number of people.

I worked as a volunteer at the special Olympics some years ago. The job mainly involved making sure spectators could get into and out of the events easily, that emergency services can easily gain access and that spectators and athletes were kept separate. The venues were not huge and the spectators were happy and sober. Still I got some impression of the kinds of things needed to ensure crowd safety at events.

I want to put a figure on how many people could safely fit through the tunnel that was the sole access point to the love parade venue. A 16 meter width is given by most media outlets.

But some say it is 30 meters wide. Most seem to put the number of people there at 1.4 million but others at only 500,000 'an event set up for 250,000 ended up with an estimated 500,000 to 1 million'.

How long does it take to get everyone into a venue? How many people an hour will try enter a venue? I do not think all 1.4m people try enter in an hour. But I would guess most people try to enter a venue in a three hour period. Each hour you could expect over 300,000 people to try and enter through the tunnel. People are unpredictable meaning that you would need to be able to have more than this safely in case loads turn up at the same time.

Who else deals with crowd volumes like this? Every few years during the Muslim Hajj there is a crowd related accident. They are building a new bridge to improve safety. There is a description of this bridge here (pdf).
the new, multi-level bridge structure which will accommodate and ease the flow of 3 million worshippers during a single daylight period. The proposed new Jamarat bridge is a superior structure formed of 4 platform levels... each of the bridge’s 4 floors is roughly 600 m-long, with variable widths (ranging from 60 m to 97 m

The engineers describe these 4 floors as at least 60 meters wide. Each 60 meters in width is supposed to handle .75 million people if scaled linearly to 16 meters that would be 200 thousand people during the day. The new Saudi bridge is designed with a much larger channel to move people than they had in Germany. Pilgrims may act differently to other crowds as they stop to perform religious ceremonies.

Another terrible crowd incident was the Hillsborough disaster where 96 people died. A quick search about football crowd safety found this document. It is a very interesting article and well worth a read

The document states
"the safety limit for crowd density is defined as 40 people in 10 square metres for a moving crowd" the tunnel at 16m wide and 100 meters long should only hold 6400 people. Walking at 38 meters per minute. 100 meters would mean it would take 156 seconds to get through the tunnel. 6400 people every 156 seconds is 147,000 in an hour. This means it would take ten hours for 1.4 million people to safely travel through.

Reuters here states
"Authorities have not yet been able to explain how exactly the tragedy happened -- near a tunnel that led to a ramp into the festival grounds. Most of the victims were found dead on the ramp and none in the tunnel, authorities said"

The football document also in Section '2.8 Wembley Complex Station' gives this equation
No. of Units of Exit Width = Number of Persons (1)
required (each width = 0.55m) Flow Rate (2) x Evacuation Time (3)

"Where number of persons (1) means the maximum number of people that could be expected to be on a platform at any time. Flow rate (2) means 40 persons per minute for escape routes incorporating stairs, and 60 persons per minute for level escape routes (without stairs). Passenger walking speeds should be assumed to be 38 metres per minute for horizontal circulation."

Using the Wembley equation above 16 meters *.55 meters means 29 people can safely span across the tunnel. 40 flow past a minute if the escape route has a stairs and 60 if it is flat. The ramp sounds like it would hinder flow in a similar way to a stairs.

Once again this is all back of the envelope and as more facts come out a much better estimate of how many people could safely negotiate the site will emerge. A reasonable estimate of the number of people who could travel through the tunnel in an hour is (tunnel width/person width)*number or people per minute * 60 minutes
which in a 16 meter wide tunnel with a stairs at the end is (16/.55)*40*60=70,000
Best case scenario with a wider tunnel and no stairs 30 meters/.55 meters *60 people *60=200,000 which is less than the expected number of people.

This calculation indicates that a cursory look at at the venue entrance would give someone grave concerns about safety for a smaller crowd than turned up on the day.

Monday, June 07, 2010

How scared should you be of nut allergies?

The wife today was selling nuts and parents kept telling her that nuts were banned in their kids school to prevent deaths from nut allergies. How many life years are saved from banning nuts in schools versus those lost through not eating nuts?

I will look at American figures as they are available and have a large sample, which are both handy. "about 150 people die annually from serious allergic food reactions" which compares with "2,000 children drown each year" according to here. So 150 people out of the 2.5 million who die each year in America die from some food allergy. Imagine all these people had 80 years left to live. You have lost 1200 human years.

Now if you happen to be the one with the allergy you would want some reasonable precautions taken. My argument here is a guesstimate on how the over anxiety about how nuts might affect us.

“We try to relieve anxiety about nut allergy by signs saying, ‘this is a nut free zone,’ which suggests that nuts are a clear and present danger,” Dr. Christakis said. “But in doing so, we increase the anxiety.” So imagine this sort of fear of nuts made everyone stop eating nuts. How many life years would be lost? "those eating nuts daily had up to 60% fewer heart attacks than those who ate nuts less than once per month". Given four hundred and fifty thousand people die each year from heart attacks. Preventing 60% of these would be 270 000 lives. Say you only saved one year off each of these that is 270000 life years as opposed to 1200 from banning nuts. This 60% figure seems really high but other studies show massive improvements here and here says '1 ounce of nuts more than 5 times/week can result in a 25 to 39 percent reduction in coronary heart disease risk among people whose characteristics match those of the general adult U.S. population'.

Now just because people who eat nuts don't get heart attacks does not mean the nuts stop the heart attacks. But the googleable studies take this correlation versus causation problem into account. Also banning nuts in schools and telling kids they might kill people wont stop all nuts being eaten. But its not hard to imagine these warnings will severely curtail nut eating.

Not many kids have nut allergies. So a blanket ban without good reason wont save many lives. There is good evidence eating nuts is very good for your health. It is reasonable to assume telling kids nuts could kill them wont encourage them to eat them.

I think this nut fear illustrates a problem many of us have with comparing sudden risks with long term risks. For example when schools ban running by kids because they might be sued but they ignore the long term health effects of kids not exercising. There are risks everywhere but when someone wants to minimise one it is worth asking how dangerous that risk is and what consequences minimising it will have.

Friday, March 27, 2009

What have a panzer tank and a Dublin taxi got in common?


You can use statistical methods to estimate their numbers boom boom

How many taxis are there in Dublin? I'm going to try guess without looking it up then see if I'm right. And I'm going to use Panzers to do it.

During WW2 the allies had to try guess how many tanks the germans had. From the Guardian
"The statisticians had one key piece of information, which was the serial numbers on captured mark V tanks. The statisticians believed that the Germans, being Germans, had logically numbered their tanks in the order in which they were produced"

People are always trying to guess how many of something there is. Iphones, kindles, computer worms, all sorts of man made objects. Mainly though it is important for military reasons.

Lancasters square law says that the power of a modern military force is proportional not to the number of units it has, but to the square of the number of units. This means that relatively small changes in the number of units an enemy has can have big changes in their effectiveness. Play around with the graph of x^2-x; here if you want to see for yourself. This is also important in computer game simulations of military operations.

Anyway I'll get some data on the Dublin Taxi driver licence numbers and get back with the calculation. The estimation problem should make more sense with an example.

Thursday, March 05, 2009

Malware News 2012

Turing Bots Are Coming
Autonomous IM bots with near human appearance have become an increasing source of malware infection in the last few months. Early attempt at such IM "Turing bots" first occurred in 2007. However recent improvements in the technology have lead to increased success in these infection methods. The bots attempt to appear human in instant messenger communications. This is generally to attempt to learn bank account information.

Eliezer Yedkawsky who has for years pointed out the security threat of artificial intelligence warned yesterday "Why does a dog wag its tail? Because the dog is smarter than the tail. If the tail was smarter, it would wag the dog."

A security expert dismissed as preposterous the idea that smarter then human AI coming from IM bots represents an existential threat to humanity.

NamScan closes

In related news a Vietnamese Anti Virus company NamScan closed yesterday. The Buddhist workers at the company refused to create software that would destroy intelligent AI bots. A company spokesman said "this is a strange cult that has grown up in our company. The engineers believed that if a program a collection of bits could pass the Turing test then it was in some way "human" and destroying it would be immoral".

The ruling on the court case between the antivirus industry and PETAI (people for the ethical treatment of AI) is due next week. A spokesman for the antivirus industry said "without the ability to stop these programs the whole internet will collapse".

Friday, February 27, 2009

Carrying stolen money

There was a bank raid this morning where an bank employee was made carry 7 million euro out of a bank. The story is here

"The official, who is in his 20s, was then forced to drive his car to the bank. After withdrawing the money, he handed it over to the gang at Clontarf DART station."

I am ignoring the horror of the attack and just asking what would 7 million euro weigh? In 2 euro coins it would weigh 29750kg


A bank note is around 1 gram according to here.
So 7 million euro is
14000 500 euro notes (1.1g) or 14.4kg.
100 euro notes (1g) are about 5 times that 70kg which a normal man could not carry nonchalantly out of a building.
50 euro notes (.9g) would weigh 126kg which most people could not lift.

So how did the employee carry this money? You would think there would be restrictions on employees carting large bags of money around.

There is also the size issue. 500 notes are Size: 160 x 82 x 0.12 mm so 14000 would be a pile 168 cm high. So say you want to put these into a duffel bag. This is roughly 600 mm long by 300 mm wide by 300 mm high

So you can fit three pile lengthways, three sideways and 2500 notes upwards. So in a duffel bag you can have a bit more then (there is left over room at the top and sides) 3*3*2500= 22500 500 euro notes. This is 11250000 euro weighing about 25 kilos.

How many 100 note (1g) of Size: 147 x 82 x 0.12 mm, 50 note (.9g) of Size: 140 x 77 x 0.12 mm could be carried?

Wednesday, May 28, 2008

Logic attack

Reasoning with First order logic can be hard
Unfortunately, a more complex algorithm can get caught in infinite loops that are known to be impossible to guard against completely. (to be more precise, it is NP complete)”

This means that is someone creates a new web app. “Do I really think this?” where you input your beliefs. “Grass is green” “cows eat grass”->output “Cows eat something that is green” you can attack it.
Denial of Service via Algorithmic Complexity describes Attacks“. Where by sending data that they know has worst case analysis time (eg. a sort in exactly the wrong order, entries that hash to the same bucket) an attacker can massively slow down your system.

First order logic decisions are NP-complete. In the same way as hash tables can be attacked if a system reasons about first order logic maliciously crafted inputs could be used to tie up the systems resources.

Monday, April 14, 2008

Medical Phishing

There has recently been a reported attack targeted GP’s login information.
“A number of NHSmail users have recently received an email fraudulently claiming to be from the NHSmail team. The email asks users to send their name and password to an email address. Under no circumstances should you respond to any email or other form of communication requesting your password.”

This attack targeted GP’s and it is unclear how much patient data could be compromised from a successfully phished GP account.
Phishing for medical records is likely to become much more common as computerized access to medical records become more common. Google have announced plans to store medical information.
“Google Health aims to solve an urgent need that dovetails with our overall mission of organizing patient information and making it accessible and useful. Through our health offering, our users will be empowered to collect, store, and manage their own medical records online.”

Not that Google health has been targeted by phishers but being aware it is a potential target is important. Increasing patients access to their medical records also presents opportunities to phishers. The market for phishing bank details is obvious, who will buy medical records is less clear. But any information private that has value will be phished for and we should anticipate this when new information is made computer accessible.

Sunday, March 30, 2008

Physical Computer Attack

Turns out the idea I had for a computer virus that physically attacks people has happened.
An epilepsy support forum has been targeted with flashing javascript. The whole attack is very sick. Still I think I was right for pointing out the threat. The warning could have lead the epilepsy forum to turn scripting off. I do not know how a migraine forum could prevent trigger images though.

Tuesday, January 29, 2008

How to catch Kerviel

I know nothing about finance and my sole knowledge of the Kerviel case is based on this excellent article.

I am now going to shout my mouth off about how this fraud could have been avoided.

1. The bank broke rule one of fraud detection. “He never took holidays and when he left the office he refused to let other traders take over his positions". Everyone must take their holidays.

2.“Every two or three days he was changing his position. He would input a transaction that would trigger a control in three days and before that happened he would replace it with a different one.” These sorts of checks need to be randomised. If the checks are this deterministic they can be easily circumvented.

3. Benford's law. I bet a shiny Euro coin that Kerviel straight made up some of the data he entered into the company system. I double that bet that this fake data he entered looks entirely random. And thus if this data was checked to see if it obeyed Benford's law it would have been detected as fraudulent.

4. Knowing nothing about finance this is where I run out of ideas. What I would do next is obey the advice of this book
p66 "one of the best ways of analysing an organisational problem is to ask not "What can we improve?" but "what can we change?". It could be that something as simple as randomly changing the seating occasionally could discourage nefarious activity.

So any other ideas for simple checks and balances that could prevent such frauds?

Monday, January 28, 2008

Spam Excuses

Why not use spam to help you? After years of penis enlargement emails and confidential business propositions from Nigeria you deserve some payback.
So why not use spam to cover your misdeeds? Send an email admitting to some heinous crime. But modify it so that the email gets sent to the spam folder and is ignored.
Then when your boss asks about the defrauded 5 billion or your wife finds you in bed with her sister you can say "But i sent you an email telling you" and that way lose some of the blame.
Think of it this way Spam filtering is an immune system that prevents useless emails from getting into your email body. What I am trying to do is create a false positive auto-immune email response.

Spam filters use a number of techniques to judge that an email is spam.
1. The user email. Someone who emails you all the time is unlikely to suddenly become a spammer. Because of this when sending your confession you need to use an email the recipient does not recognise. You can use an anonymous remailer or even just a web email account.
2. If you are sending to a web email if your email has sent spam previously your address is likely to be blacklisted. So before sending to recipient@mail from spammer@mail send some purely spam email from this address before you send the email with the confession you want to be junked.
3. The message content. Email filters generally use Bayesian filtering where words are ranked by their frequency.
You can take a collection of spam emails and extract random words out of them. This might fool a Bayesian filter but you could not later argue that you really meant for the email to be read.

A serious problem is one of trust. No one is going to accept "but I told you I was going to defraud the bank of billions" if you make such an obvious attempt to stop your mail getting seen no one will believe you made a sincere attempt to confess.

So rather then adding random spamy words altering your email to look spamy in a more natural way is preferable. Markov models are a good way of producing realistic text.

I gathered together some spams to train this ruby program on it on and the result is below.

"an alpha blocker (other than tamsulosin (Flomax) 0.4 mg once a day) such as doxazosin (Minipress),
TRY IS TODAY TO GAIN THE LONGEST AND LIVE LARGE TODAY! from 20$ 4 or more mood-killing premature ej@culation. Just try VPXL and more effective is an idea of the world is an idea of Feed Blaster is faster, easier to use,"

So how do you tell your boss that you are defrauding your bank out of a possible 5 billion euro? Say the message is
I am engaged in an illegal rogue trading activity.

Ok now give an explanation for the use of the weird email account. Make the explanation kind of spammy.

sorry for using this weird account I thought you might want to join me in this confidential business proposition.

add some more spam sounding text also

(I know this sounds like one of these confidential business propositions but do not worry i am not trying to Increase Your pen!s size.)
(If we join together in this we will Enjoy all the action of Las Vegas with 24 hour customer services,)


Now when you send this mail it will be cause a false positive be sent to the junk folder ignored and only brought up when you need to blame someone else during your trial.

Thursday, January 03, 2008

Natural Selection in War

This tasteless cartoon reminded me of a weird security glitch that could have effected the evolution of mankind.

In Vietnam a faulty random number generator meant that people born in certain months were more likely to get drafted



If you follow the logic of this article this could have resulted in a skewed evolutionary selection where people whose parents were romantic (feb 14th-> November) or Irish (March 17-> December) had less chance of getting killed.

So check your random number generators are accurate if you do not want a future infested with romantic Irish people.

Tuesday, August 14, 2007

Why do banks never prove their identity to you?

I Just had the following phone conversation. My bank phoned me up and then asked me to confirm I was me

Bank: We will just need your address there
Me: Sorry I cannot give you that unless you confirm you are my bank
Bank: Well if you give us your address we will confirm it here
Me: Well if you give me my address I will believe you are my bank
Bank: Did you get the letter we sent you last week saying we would be calling?
Me: No I didn’t but that letter would not prove you are the bank calling now anyway
Bank: Ok then it must be in the post we will ring you back later when it arrives

Unless the bank proves to you who they are, or that the ATM you are using belongs to them, how are you supposed to have trust?

Tuesday, March 27, 2007

Hummer Drivers are Wankers

Managed to scratch one off the list of "100 things to do before you die" yesterday. There was a guy driving a Hummer beside me at the traffic light. Got out pointed at him and shouted "wanker". In retrospect he was clearly Russian mafia but it still had to be done.

For all the talk of friendliness it is actually massive black cynacism and begrudgery that defines the Irish. We seemed to have lost the ability to point at obvious wankers and point out their wankertuide to them.

I have heard many arguments as to why Hummers are awful. If you want to shout wanker at them becuase of their lack of social conscience that is fine. However my main reason is that they are clearly driven by wankers.

The great Irish icons, Michael Collins, John F Kennedy and Pope John Paul II all had the balls to get shot in open topped cars. Now we have these wankers driving round in armored personnel carriers? How much risk are they really in? Have they invented modern urban guerrilla warfare, lead a side in a civil war, broke up the mafia, invaded cuba or attempted to topple communism? Until you can prove you have done something to piss off lots of angry people with guns you should grow a pair and not drive round in a tank

Security as a status symbol

This article is about how a lot of security equipment is to advertise "hey I have things that are worth stealing".

This is like Eminem wearing a bullet proof vest to show that he annoys people enough that they would be willing to shoot him. Or how dodgy Russian mafiosas drive hummers around Dublin like they are in a war zone.

It is slightly different from "security theatre" as Schneier calls it as it is not designed to provide the illusion of security just the illusion of a need for security.
There are many similar things to this in computer security,
Symantec have a response unit housed in a nuclear bunker. This is a good way for the DR Strangelove cachet to rub off on people checking for botnets.