Computer underground Digest Sun Aug 22 1993 Volume 5 : Issue 64

Computer underground Digest Sun Aug 22 1993 Volume 5 : Issue 64 ISSN 1004-042X Editors: Jim Thomas and Gordon Meyer (TK0JUT2@NIU.BITNET)

CONTENTS, #5.64 (Aug 22 1993)
File 1--Has the EFF SOLD OUT?!?
File 2--EICAR '93 conference / members' meeting
File 3--Re SKIPJACK Review (CuD 5.60)
File 4--CuNews ("Smart Kards," Comp Snooping at IRS/FBI, & more)
File 5--CuNews -- ("Hackers need not Apply" & more)
File 6--Table of Contents for Volume #1 (of P/H Msg Bases)
File 7--Graduate Paper Competition for CFP-'94 Digest contributors assume all responsibility for ensuring that articles submitted do not violate copyright protections. ---------------------------------------------------------------------- Date: Sun, 22 Aug 1993 20:23:18 CDT From: Jim Thomas Subject: File 1--Has the EFF SOLD OUT?!? The Electronic Frontier Foundation has been co-opted by the telecommunications conglomerates and has, as a consequence, lost it's integrity and credibility. Or so some critics would have us believe. Especially since the re-organization of The EFF, allegations that they have "sold out" by accepting contributions from telephone companies--or worse, that EFF now is implicitly in the employ of telephone companies--persist. This allegation seems not only unfounded, but does a disservice to the cybercommunity by falsely maligning the integrity of one of the two (CPSR being the other) most active and effective organizations working to establish and preserve the rights of the electronic realm. Because I am a dues-paying member of EFF and have recently sent my subscription fee to CPSR, I am not a dispassionate observer. Both groups are effective, and--even when in disagreement, I respect the goals and strategies chosen by each group. Therefore, as a member of EFF, I'm troubled by some of the public commentary I've read on Usenet, BBSes, and public access systems that continue to irresponsibly tarnish the integrity of EFF with false allegations. Some of the basis for criticism rests on rumors. Perhaps some derives from malice. But, the bulk may simply be a lack of information about EFF's funding sources and an imperfect understanding about the relationship between funders and recipients and the obligations that relationship entails. I see nothing *inherently* improper about EFF (or any organization) accepting funds from organizations whose goals, ideology or practices may not overlay perfectly with those of the recipients. Let's look at a few issues. 1. HOW MUCH DOES EFF RECEIVE FROM TELECOS? According to EFF sources, roughly eight percent of their $1.6 million operation budget comes from telecom sources, with no more than five percent coming from a single source. Fiscal ratios change, and whether the exact sum is seven or 11 percent matters nil. This is a useful chunk of resources, but hardly substantial. It is certainly not a sufficient amount to cause a crisis if it were withdrawn. The remainder of EFF's resources are reported to derive from private donors, membership fees, and revenue-generating activities (such as sales of t-shirts). Both in the Usenet discussion group ( and in its newsletters, EFF has been open about its funding sources and has never concealed or minimized contributions by corporate donors, including telecos. Therefore, EFF's alleged ethical malfeasance does not lie in failure to conceal its funding resources. Nor does it lie in a dependency relationship with the donors. 2. WHAT OBLIGATIONS DOES EFF OWE THE TELECOS? The broader question here centers on what obligations a donor might expect from the recipient. It is hardly unusual for organizations to accept funds from contributors whose interests overlap. Examples include contributions by R.J. Reynolds tobacco and The Playboy Foundation to the ACLU to--as a personal example--my own former funding by the National Institute of Justice. Does the ACLU support freedom of speech because it is funded in part by those with a commercial interest in protecting it? Should the ACLU abstain from taking a position on smokers'/non-smokers' rights because of funding sources? Should I have refused federal funding lest I be accused (as I once was) of being little more than a paid lackey of federal police and social control interests? Criticism of EFF for its funding sources and suspicion of the strings that might be attached extend into the lives of many of us. However, it is rare that general donations require any substantive changes in the behavior or principles of recipients. It is also common for well-endowed donors to spread their largess to a variety of groups with ends often (seemingly) antithetical to each other and even to the donor. There is no evidence whatsoever that EFF has changed its direction to satisfy donors. In fact, the recent re-organization at EFF, however much some of us might be disappointed by the emphasis, is fully consistent with their original policy statement. In fact, a careful reading of the founding EFF statement and its recent public policy formulations indicate that the re-organization was primarily structural rather than the reflection of a new philosophy. As the CPSR/EFF/ACLU coalition in the 2600 Magazine Washington Mall incident of 1992 suggest, the EFF continues to involve itself with those types of issues that led to its founding. And, as Mike Godwin's continued involvement with EFF and his willingness to help those in need of legal advice attest, EFF remains the first resource most of us think of when we seek computer-related legal assistance. Those who know Mike and EFF founders John Barlow and Mitch Kapor cannot, in their wildest fantasies, imagine even the most generous donor influencing their behavior or principles. 3. WHAT ARE THE ETHICAL/LEGAL OBLIGATIONS OF RECIPIENTS? Federal and state statutes, as well as various professional codes of ethics, specify obligations that might lead to a conflict of interest. The attorneys amongst us can elaborate on these. However, there is absolutely no evidence that the EFF approaches even the strictest conflict of interest threshold. Its coincidental interests with telecos involve policy and legislation affecting primarily the development of an "information highway" and the attendant technology. The EFF is not litigating on behalf of any telecos, it is not (according to EFF sources and their documents) serving in a client relationship with them, and it is engaged in no activity that--at least by any apparent logic--could be construed to place the EFF in a conflict of interest situation. EFF's initiative and perseverance in the Steve Jackson Games litigation would seem prima facie evidence that the EFF is committed to principle and not to funding expedience. There is room for considerable intellectual disagreement over the focus, goals, and organization of EFF, CPSR, and, I suppose, even CuD. But the one issue that is indisputable is the integrity, commitment, and credibility the EFF possesses. Because there is nary a soupcon of evidence to to suggest cooptation, it's time to end this unnecessary and destructive bickering about EFF's funding sources. Those who have taken the trouble to follow the public policy statements and read the EFF electronic and hardcopy newsletters, will find nothing new in my comments. Those who do not receive the newsletter and do not follow CuD's periodic summaries of the activities of groups such as the EFF and CPSR might have been influenced by rumors and misinformation. Those of us who are concerned about the future of "cyberspace" should remember our debt to these groups. Part of that debt means that we squelch false rumors that risk irreparably tarnishing the reputations and subverting the effectiveness of groups from whose actions we all benefit. ------------------------------ Date: Thu, 19 Aug 93 09:46:16 GMT From: Anthony Naggs Subject: File 2--EICAR '93 conference / members' meeting EICAR '93 Conference At a recent meeting the board of EICAR (European Institute for Computer Anti-Virus Research), decided to cancel the planned London conference this year. I understand this is due to low participation in other computer security / anti-virus events this year. However, there will instead be a Members' Meeting in Hamburg (Germany), the proposed agenda is: 25 November 1993 14:00 Working Group 3 (Legal Questions) meeting 16:00 Working Group 1 (Antivirus Technologies) meeting 18:00 Joint Dinner 26 November 1993 09:00 Discussion of the Working Groups results 11:00 Members Meeting 13:00 Lunch EICAR '94 Conference The next EICAR conference is proposed to be from 14 to 16 November 1994 in the vicinity of London. (Disclaimer; I am not an official spokesman for EICAR). +++ Anthony Naggs Email: Paper mail: Software/Electronics Engineer PO Box 1080, Peacehaven & Computer Virus Researcher East Sussex BN10 8PZ Phone: +44 273 589701 Great Britain ------------------------------ Date: Fri, 13 Aug 1993 16:15:47 CST From: roy@SENDAI.CYBRSPC.MN.ORG(Roy M. Silvernail) Subject: File 3--Re SKIPJACK Review (CuD 5.60) In #5.60: > Date: Mon, 02 Aug 1993 15:23:28 -0400 (EDT) > From: denning@CS.GEORGETOWN.EDU(Dorothy Denning) > Subject--File 5--SKIPJACK Review (Encryption Background and Assessment) > LEAF decoders that allow an authorized law enforcement official to > extract the device identifier and encrypted session key from an > intercepted LEAF. The identifier is then sent to the escrow > agents, who return the components of the corresponding device > unique key. Once obtained, the components are used to reconstruct > the device unique key, which is then used to decrypt the session > key. This is the first time I've heard anyone clarify that point. One of my main objections to the Clipper proposal was that once a legal tap had been authorized, all further communications with that Clipper chip were compromised unless the court order only released the session key. LE has NO NEED for the unique device key. They legitimately need only the session key for the lawfully intercepted communications. > 5. Secrecy of the Algorithm > > The SKIPJACK algorithm is sensitive for several reasons. Disclosure of > the algorithm would permit the construction of devices that fail to > properly implement the LEAF, while still interoperating with legitimate > SKIPJACK devices. Such devices would provide high quality > cryptographic security without preserving the law enforcement access > capability that distinguishes this cryptographic initiative. > However, while full exposure of the internal details of SKIPJACK would > jeopardize law enforcement and national security objectives, it would > not jeopardize the security of encrypted communications. This is > because a shortcut attack is not feasible even with full knowledge of > the algorithm. Indeed, our analysis of the susceptibility of SKIPJACK > to a brute force or shortcut attack was based on the assumption that > the algorithm was known. These sections actually makes me feel better about SKIPJACK in general. I kind of suspected that the real reason for secrecy was to protect LE access. (I'd still prefer the algorithm be made public) Now, anyone care to speculate about the security of the LEAF itself? This whole discussion centered upon SKIPJACK security, but I don't recall whether the LEAF is _actually_ encrypted by SKIPJACK. A SKIPJACK key and a Clipper key are both 80 bits, but that doesn't mean you have to crypt them the same way. ------------------------------ Date: Wed, 18 Aug 93 12:19:00 BST From: grmeyer@GENIE.GEIS.COM Subject: File 4--CuNews ("Smart Kards," Comp Snooping at IRS/FBI, & more) Smart Kards Are Coming ====================== A group of corporations, including MasterCard, Visa, Citicorp, Amex, IBM, AT&T, Microsoft, and Apple, have formed the Smart Card Forum. The cross-industry group will promote the use of smart-card technology for payment, transit, health care, identification, and security applications. (Information Week August 9, 1993 pg 10) Computer Snooping at the IRS and FBI ==================================== The Internal Revenue Service is implementing a $23 billion computer modernization project that will give it online access to taxpayer information. In the midst of this, the GAO has revealed that as many as 350 employees in the IRS's Southeast Region (Atlanta) have been snooping into taxpayer records. So far, 154 have been disciplined. The GAO (Government Accounting Office) has also said that access to the FBI's National Crime Information Center (NCIC) databases has been systematically abused by law enforcement workers and associates. Cases cited as examples include an officer using NCIC to track down his ex-girlfriend (he later killed her), a terminal operator checking customers for her drug-dealing boyfriend...just to be sure they weren't undercover agents, and a dispatcher running background checks on her fiance's political opponents. The FBI declines comment, but the GAO has recommended that Congress make it a criminal offense to access the network for private use. (Information Week. August 9, 1993. pg 13) Wipe Before Discarding ====================== A Canadian citizen, who purchased a used hard drive from a local computer store, found himself in possession of a goldmine of personal data and information. The used drive contained the personnel records of every employee in the Alberta land title offices in Edmonton and Calgary. It included salaries, social security numbers [presumably the Canadian equivalent], and performance evaluations. It also held lengthy, confidential memos about plans to turn over the land title department to a private agency. (Information Week August 9, 1993 pg 60) Pay Your Rent ============= Speaking of Edmonton, Alberta... A landlord's association there has formed a group to share information about tenants. The online database can be searched with little more than a name or driver's license number. The landlords say the primary purpose is to keep track of people who skip out on rent payments, or damage property. They answer concerns about discrimination by saying that anyone caught abusing the system will be forbidden from using it in the future. (Information Week August 9, 1993 pg 66) ------------------------------ From: grmeyer@GENIE.GEIS.COM Date: Fri, 20 Aug 93 00:23:00 BST Subject: File 5--CuNews -- ("Hackers need not Apply" & more) If It's Blurry You Shouldn't Be Watching ======================================== A patented digital technology from VideoFreedom Systems (San Diego, CA) may be the key to getting an intrusive Congress off their censorship bandwagon. The technology would allow television (and movie theatres!) to blur objectionable scenes and sounds. Much the same way the news programs can distort the voice and image of a confidential source who wishes to remain that way. The technology would allow those viewers who want to see "the good parts" to clean-up the image to their tastes. (Information Week August 16, 1993 pg 10) Hackers Need Not Apply ====================== Information Week magazine recently conducted a "fax vote" self-selected survey of readers. The questions asked about policies, thoughts, and practices regarding hiring ex-hackers to help out with computer security. Of the those who choose to respond, 15% said they had been approached for a job by a hacker. Only 6% said they had ever hired a hacker to test security. Of their concerns about doing so, over half said "they might compromise security". About 35% expressed concerns over "legal problems". Some of the write-in comments included: "Their crimes are difficult to prove and almost impossible to prosecute. Not only do they go unpunished, but hiring them makes crime pay." "What happened to our idea of ethics and morality? I don't believe only felon hackers are smart enough to foolproof our computer systems." "They could sell ideas back to your competitor. These people will do anything for a buck". Refer to Information Week, August 16, 1993 pg 29 for full details. This Tag Line Meets Corporate Standards ======================================= Duke Power Company (Charlotte, NC) has issued a memo to supervisors and managers that forbids employees from expressing their religious or political opinions over the company's Email, voice mail, or fax machines. The company says the memo arises out of problems with people using 'tag lines' (short sentences at the end of messages) on the company's Profs mail system. The company did not forbid tag lines, but issued guidelines for their content. According to the company few of its 18,000 employees see the rules as a restriction of free speech. (Information Week. August 16, 1993 pg 60) Woodstock for Hackers and Phreaks ================================= Newsweek magazine (Aug 16, 1993 pg 47) features a story on the End of The Universe conference in the Netherlands. According the Information Week's summary, the Newsweek article reports that attendees had at least one thing in common with the Woodstock guests....they believe that rules were meant to be broken. (IW's summary is on pg. 64, August 16, 1993) Don't Copy That (Microsoft) Floppy! =================================== Information Week reports that an article in the San Francisco paper THE REVOLVER (Aug 9, pg 1) says some lawyers claim that Microsoft might enjoy too much influence over federal prosecutors. It seems that an unusually high number of cases against software pirates are launched on Microsoft's behalf. The number is higher compared with Lotus or WordPerfect for example. (Information Week. August 1, 1993. pg 64) ------------------------------ Date: Tue, 10 Aug 93 22:48:47 EDT From: lodcom (LOD Communications) Subject: File 6--Table of Contents for Volume #1 (of P/H Msg Bases) ((MODERATORS' NOTE: In CuD #5.39, we reviewed the BBS Message Base File Archive Project compiled by LODCOM. We were impressed by the comprehensiveness of the project and favorably reviewed it as a valuable set of documents for scholars and curious readers who are interested in BBS "underground" culture of the 1980s. The collection has been expanded, and the current offerings are described below)). ++++ Volume I of the Hack/Phreak BBS Message Base File Archive Project has been completed. This file is 19 KB in length and contains the Table's of Contents for each of the 20 Message Base Files. Volume II is being compiled and is expected to be completed and sent out to those who have ordered the Set sometime in September. Volume III is expected to be completed in November 1993. Should any additional material come our way, a fourth and final Volume will be made. The newest version of the Order Form File will be sent to you sometime in the next week. Should you find the following TOC's interesting and you want to order the files do so with the NEW order form. If you have already ordered using the old order form that is fine, as the price change is retroactive since it is to YOUR benefit. As you will note when you see the new order form and information file, ALL the volumes created will cost $39.00 personal, $99.00 commercial. That is, for the above price you receive ALL the volumes, not just one volume. The price change was made due to the good response to the initial order form. When Volume #2 is completed a file similar to this one with its TOC's will be mailed to you. If you wish to be taken off this mailing list just say so. If not, Lodcom will continue to keep you up to date on the projects' progress. Disseminate this File as you see fit. If you have any questions feel free to email us anytime. LOD Communications: Leaders in Engineering, Social and Otherwise ;) Email: Voice Mail: 512-448-5098 Snail Mail: LOD Communications 603 W. 13th Suite 1A-278 Austin, Texas USA 78701 ------------------------------ Date: Fri, 20 Aug 1993 18;21:43 EDT From: Subject: File 7--Graduate Paper Competition for CFP-'94 STUDENT PAPER COMPETITION Full time college or graduate students are invited to enter the student paper competition. Papers must not exceed 2500 words and should address the impact of computer and telecommunications technologies on freedom and privacy in society. Winners will receive a scholarship to attend the conference and present their papers. All papers should be submitted by November 1, 1993 (either as straight text via e-mail or 6 printed copies) to: Prof. Eugene Spafford Department of Computer Science Purdue University West Lafayette, IN 47907-2004 E-Mail:; Voice: 317-494-7825 REGISTRATION Registration information and fee schedules will be announced by September 1, 1993. Inquiries regarding registration should be directed to RoseMarie Knight, Registration Chair, at the JMLS address above; her voice number is 312-987-1420. ------------------------------ End of Computer Underground Digest #5.64 ************************************


