Homeland Insecurity

Article Tools

email E-mail Article
print Printer Format

Luckily for the victims, this digital mayhem is mostly wreaked not by the master hackers depicted in Hollywood techno-thrillers but by "script kiddies"—youths who know just enough about computers to download and run automated break-in programs. Twenty-four hours a day, seven days a week, script kiddies poke and prod at computer networks, searching for any of the thousands of known security vulnerabilities that administrators have not yet patched. A typical corporate network, Schneier says, is hit by such doorknob-rattling several times an hour. The great majority of these attacks achieve nothing, but eventually any existing security holes will be found and exploited. "It's very hard to communicate how bad the situation is," Schneier says, "because it doesn't correspond to our normal intuition of the world. To a first approximation, bank vaults are secure. Most of them don't get broken into, because it takes real skill. Computers are the opposite. Most of them get broken into all the time, and it takes practically no skill." Indeed, as automated cracking software improves, it takes ever less knowledge to mount ever more sophisticated attacks.

Given the pervasive insecurity of networked computers, it is striking that nearly every proposal for "homeland security" entails the creation of large national databases. The Moran-Davis proposal, like other biometric schemes, envisions storing smart-card information in one such database; the USA PATRIOT Act effectively creates another; the proposed Department of Homeland Security would "fuse and analyze" information from more than a hundred agencies, and would "merge under one roof" scores or hundreds of previously separate databases. (A representative of the new department told me no one had a real idea of the number. "It's a lot," he said.) Better coordination of data could have obvious utility, as was made clear by recent headlines about the failure of the FBI and the CIA to communicate. But carefully linking selected fields of data is different from creating huge national repositories of information about the citizenry, as is being proposed. Larry Ellison, the CEO of Oracle, has dismissed cautions about such databases as whiny cavils that don't take into account the existence of murderous adversaries. But murderous adversaries are exactly why we should ensure that new security measures actually make American life safer.

Any new database must be protected, which automatically entails a new layer of secrecy. As Kerckhoffs's principle suggests, the new secrecy introduces a new failure point. Government information is now scattered through scores of databases; however inadvertently, it has been compartmentalized—a basic security practice. (Following this practice, tourists divide their money between their wallets and hidden pouches; pickpockets are less likely to steal it all.) Many new proposals would change that. An example is Attorney General John Ashcroft's plan, announced in June, to fingerprint and photograph foreign visitors "who fall into categories of elevated national security concern" when they enter the United States ("approximately 100,000" will be tracked this way in the first year). The fingerprints and photographs will be compared with those of "known or suspected terrorists" and "wanted criminals." Alas, no such database of terrorist fingerprints and photographs exists. Most terrorists are outside the country, and thus hard to fingerprint, and latent fingerprints rarely survive bomb blasts. The databases of "wanted criminals" in Ashcroft's plan seem to be those maintained by the FBI and the Immigration and Naturalization Service. But using them for this purpose would presumably involve merging computer networks in these two agencies with the visa procedure in the State Department—a security nightmare, because no one entity will fully control access to the system.

Sidebar:

How Insurance Improves Security

"Eventually, the insurance industry will subsume the computer security industry...."

Equivalents of the big, centralized databases under discussion already exist in the private sector: corporate warehouses of customer information, especially credit-card numbers. The record there is not reassuring. "Millions upon millions of credit-card numbers have been stolen from computer networks," Schneier says. So many, in fact, that Schneier believes that everyone reading this article "has, in his or her wallet right now, a credit card with a number that has been stolen," even if no criminal has yet used it. Number thieves, many of whom operate out of the former Soviet Union, sell them in bulk: $1,000 for 5,000 credit-card numbers, or twenty cents apiece. In a way, the sheer volume of theft is fortunate: so many numbers are floating around that the odds are small that any one will be heavily used by bad guys.

Large-scale federal databases would undergo similar assaults. The prospect is worrying, given the government's long-standing reputation for poor information security. Since September 11 at least forty government networks have been publicly cracked by typographically challenged vandals with names like "CriminalS," "S4t4n1c S0uls," "cr1m3 0rg4n1z4d0," and "Discordian Dodgers." Summing up the problem, a House subcommittee last November awarded federal agencies a collective computer-security grade of F. According to representatives of Oracle, the federal government has been talking with the company about employing its software for the new central databases. But judging from the past, involving the private sector will not greatly improve security. In March, CERT/CC, a computer-security watchdog based at Carnegie Mellon University, warned of nineteen vulnerabilities in Oracle's database software. Meanwhile, a centerpiece of the company's international advertising is the claim that its software is "unbreakable." Other software vendors fare no better: CERT/CC issues a constant stream of vulnerability warnings about every major software firm.

Schneier, like most security experts I spoke to, does not oppose consolidating and modernizing federal databases per se. To avoid creating vast new opportunities for adversaries, the overhaul should be incremental and small-scale. Even so, it would need to be planned with extreme care—something that shows little sign of happening.

One key to the success of digital revamping will be a little-mentioned, even prosaic feature: training the users not to circumvent secure systems. The federal government already has several computer networks—INTELINK, SIPRNET, and NIPRNET among them—that are fully encrypted, accessible only from secure rooms and buildings, and never connected to the Internet. Yet despite their lack of Net access the secure networks have been infected by e-mail perils such as the Melissa and I Love You viruses, probably because some official checked e-mail on a laptop, got infected, and then plugged the same laptop into the classified network. Because secure networks are unavoidably harder to work with, people are frequently tempted to bypass them—one reason that researchers at weapons labs sometimes transfer their files to insecure but more convenient machines.

Sidebar:

Remember Pearl Harbor

"Surprise, when it happens to a government, is likely to be a complicated, diffuse, bureaucratic thing...."

Schneier has long argued that the best way to improve the very bad situation in computer security is to change software licenses. If software is blatantly unsafe, owners have no such recourse, because it is licensed rather than bought, and the licenses forbid litigation. It is unclear whether the licenses can legally do this (courts currently disagree), but as a practical matter it is next to impossible to win a lawsuit against a software firm. If some big software companies lose product-liability suits, Schneier believes, their confreres will begin to take security seriously.

Pages: <prev 1 2 3 4 5 6 7 next>

Charles C. Mann, an Atlantic correspondent, has written for the magazine since 1984. He is at work on a book based on his March 2002 Atlantic cover story, "1491".

Article Tools

email E-mail Article
Printer Format
Share

Subscribe to our e-mail newsletter.

 

From the Archives

January 2002

The Futility of "Homeland Defense"

Don't even try to close the holes in a country, and a society, designed to be porous.

January 2002

Keeping the Net Secure

September 11 demonstrated the great strength of the Internet. Now it's time to address the Internet's weaknesses.

The War on Terrorism


A collection of features from The Atlantic Monthly and Atlantic Unbound.

The Reinvention of Privacy

(March 2001)
The public fears that the last of privacy will perish in the information age. But what technology has taken away it will soon give back. By Toby Lester

From Atlantic Unbound

Flashbacks: "Technology and Security"

(August 21, 2002)
Four recent Atlantic articles consider the drawbacks of relying too heavily on technology to protect us from terrorism.

Flashbacks: "Criminal Computing"

(February 17, 2000)
Two Atlantic articles highlight the difficulties of protecting Internet users from the dangers of computer crime.

Also By

Charles C. Mann

November 2008

The Gangster In My Tub

The author finds himself in hot water at a Japanese onsen. [Web only: Slideshow: "Eternal Spring"]

July/August 2008

Personal Genomics

June 2006

How Not to Travel in Japan

Our correspondent flouts the Three Laws of Tourism there— and has a spectacular trip.


Name

Address 1

Address 2

City

State Zip

Email