<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>security</title>
  <link rel="alternate" type="text/html" href="http://domesticat.net/taxonomy/term/326"/>
  <link rel="self" type="application/atom+xml" href="http://domesticat.net/taxonomy/term/326/atom/feed"/>
  <id>http://domesticat.net/taxonomy/term/326/atom/feed</id>
  <updated>2007-10-28T18:57:20+00:00</updated>
  <entry>
    <title>Every tool is a weapon if you hold it right</title>
    <link rel="alternate" type="text/html" href="http://domesticat.net/2001/09/every-tool-weapon-if-you-hold-it-right" />
    <id>http://domesticat.net/2001/09/every-tool-weapon-if-you-hold-it-right</id>
    <published>2001-09-25T04:12:13+00:00</published>
    <updated>2008-01-11T21:46:11+00:00</updated>
    <author>
      <name>domesticat</name>
    </author>
    <category term="9/11" />
    <category term="extemporaneous" />
    <category term="politics" />
    <category term="rants" />
    <category term="security" />
    <summary type="html"><![CDATA[<p><em>"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."</em></p>
<p>The Fourth Amendment is not so often quoted as the fighting words of the First Amendment:  <em>"Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the government for a redress of grievances."</em></p>
<p>but it is, in its own way, as strong as the First.</p>
    ]]></summary>
    <content type="html"><![CDATA[<p><em>"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."</em></p>
<p>The Fourth Amendment is not so often quoted as the fighting words of the First Amendment:  <em>"Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the government for a redress of grievances."</em></p>
<p>but it is, in its own way, as strong as the First.</p>
<p>It's been thirteen days since Americans were reminded that they were <em>not</em> the inviolate nation they had fancied themselves to be since the ending of World War II.  It has been so many years since we understood the concept of a true, mortal, threat; so many years that, until last week, it had become a distant, happily-forgotten memory in our parents' and grandparents' minds.</p>
<p>Attacks lead to fear.  Fear leads to anger.  Anger, in its turn, leads to national determination to prevent such destruction from happening again.  Such determination, unfortunately, often leads to the suspension of civil liberties, and sometimes even to the suspension of things that our Constitution considers "rights."</p>
<p>At the beginning of the Civil War, Abraham Lincoln temporarily revoked the right of <a href="http://www.encyclopedia.com/articlesnew/05538.html">habeas corpus</a>, a decision which, rightly, angered many—yet history has forgiven him.  </p>
<p>On February 19, 1942, Franklin Roosevelt signed Executive Order 9066, interning over 100,000 people—all of them of Japanese descent, many of them American citizens—in "internment camps" <em>because they were Japanese, and therefore the enemy.</em>  Appearance meant more than innocence.  The end result: most everyone, but me, hails him as one of our greatest Presidents.</p>
<p>But that's in the past, right?</p>
<p>We'd like to believe that our elected officials are past the need to automatically revoke civil liberties when Americans are under attack or waging war.  Sadly, this does not seem to be the case, judging by actions like Attorney General John Ashcroft's recent proposal to make many computer crimes fall under the definition of "acts of terrorism."</p>
<p>The topic of "strong encryption" has been brought up many times since September 11, and the tone of the discussions I have heard in recent days bothers me greatly.  </p>
<p>Strong encryption cannot be discussed in layman's terms without discussing <a href="http://www.pgp.com/">PGP</a> and <a href="http://www.distributed.net/">distributed.net</a>.  Distributed.net arose as the answer to an RSA challenge.  A full description would defeat the point of this commentary, but suffice it to say that the RSA provides an encrypted message to anyone who wishes to attempt to decrypt it.  In an attempt to prove that encryption should be made stronger, a small program was devised that attempts to break the code using brute-force 'distributed computing' (using spare CPU cycles from computers all over the world).  PGP, on the other hand, stands for Pretty Good Privacy, and is a program, created by Phil Zimmerman, that allows anyone to strongly encrypt their email.</p>
<p>Both distributed.net and PGP are, currently, legal—but I have to wonder for how long.  The current atmosphere of American paranoia is leading our leaders down the path of overcompensating toward security at the cost of Constitutionally-guaranteed liberties.  It is all too easy to do:  their belief is that our freedom should be restricted, in order to preserve our security.  I am torn about this.  I understand why they think they are right, but I also understand that this is political knee-jerking in the guise of true protection.</p>
<p>If it can be demonstrated that terrorists and other garden-variety criminals are using strong encryption, then the government has a powerful argument toward banning strong encryption of any kind.  After all—if the government can't read their communications, then it will be much, much more difficult to find these people and bring them to justice.</p>
<p>I never thought I'd quote Ani DiFranco in a posting about cryptography, but there is a snippet of song lyric that says it better than I ever could:  <em>"Every tool is a weapon if you hold it right."</em>  It is true of physical tools—hammers, baseball bats—as it is for cryptography.</p>
<p>Don't believe me?  Think about this:  the same strong encryption that can be used by criminals is the same strong encryption you use to make sure that your online banking transactions aren't sniffed by third parties.  It's the same strong encryption you use to protect your credit card information when ordering books from <a href="http://www.amazon.com">amazon.com</a>.</p>
<p>The prevailing wisdom is that government officials support the addition of "back doors" to cryptography products.  It's for our protection, they say, but answer me this—where does the cat go when it's out of the bag?  </p>
<p>Ever seen the bumper stickers that read "<strong>When guns are outlawed, only outlaws will have guns</strong>"?  Ever seen the shirts that contain crypto code and the words, "<strong>This shirt is a munition!</strong>"  The same bit of truth applies here:  we can outlaw strong encryption in the United States, but the internet is global, and we can no more eradicate strong encryption in every country in the world than we can eradicate the memory of how to create strong encryption from the people who have already created it.</p>
<p>Take it as a given that even if strong encryption is outlawed, that it will still be available on the black market.  Do you truly believe that government agencies will use encryption systems with back doors?  Of course they won't.</p>
<p>Do you truly believe that government officials will only use the back doors for official uses?  Do you really trust them that much?  Who decides what "official use" is?  Even if they say, "We'll only use it for <em>our</em> benefit," who constitutes "our"?  Does it change with every new administration?</p>
<p>Who will be allowed to decide who "us," the good guys, are?  If the Senators and Representatives decide, it's certainly not going to be the people who spend their lives protesting the actions of Congress.  (Remember the students who protested the Vietnam War?  Some of them got <em>killed</em> for their beliefs—do you really think Congress would have given them strong encryption?)</p>
<p>After all, "we" are the good guys.  At least, from our point of view, we are.  If you look at it from other nations' point of view, the groups of people who "should" get secure cryptography change radically:  in Russia, the mafiosi will have it; in Afghanistan, the Taliban; in Iraq, Saddam Hussein…  In Ireland, it'll depend on who you're talking to at the moment.  The Palestinians and Israelis will both claim they should have it:  one group in their desperate pursuit of a homeland and another in the desperate attempt to keep theirs.</p>
<p>In the end, it matters not a whit.  The programs for strong encryption exist, and will continue to exist -if not legally, then underground.  I have no plans on making Jeff delete our copy of PGP anytime soon.  We have no compelling reason to do so and, in fact, we feel we have very compelling reasons to distribute it openly and widely to every person who will take a copy from us.</p>
<p>Even if our legislators take away programs for strong encryption, one-time pads are still unbreakable and still require no programs to make them work.  Taking away strong encryption solves no problems for us and creates myriad inconveniences in its stead—inconveniences and security risks that I cannot accept.</p>
<p>Freedom and security are a continuum; you must give up some of one to get more of the other.  I recognize that supporting strong encryption means that I cannot just use it to protect my credit card number, but that I must accept the consequences when someone uses it for a destructive or criminal reason.  It is the price I pay, and I accept that.</p>
<p><em>(The Republican Party believes I have a right to own a gun—preferably without a waiting period—but I'm a terrorist if I believe that I should be able to protect my credit card numbers and my emails.)</em></p>
<p>I had hoped our leaders would have learned from previous errors that choosing to revoke constitutional liberties in the name of national security is a grave error.  Judging by current events, I have no reason to believe that they have learned anything.  We will bomb, and we will retaliate, and they will 'temporarily' take away our liberties in the guise of national security—liberties whose restriction will not make me or my loved ones any safer.  Our politicians, I fear, cannot see the liberties of their constituents for the righteous anger that clouds their eyes.</p>
    ]]></content>
  </entry>
  <entry>
    <title>Goth night in Centennial (d*c entry #2)</title>
    <link rel="alternate" type="text/html" href="http://domesticat.net/2001/09/goth-night-centennial-dc-entry-2" />
    <id>http://domesticat.net/2001/09/goth-night-centennial-dc-entry-2</id>
    <published>2001-09-07T02:49:59+00:00</published>
    <updated>2007-10-28T18:57:20+00:00</updated>
    <author>
      <name>domesticat</name>
    </author>
    <category term="dragon*con" />
    <category term="insanity" />
    <category term="security" />
    <category term="techops" />
    <summary type="html"><![CDATA[<p>Backstage:  it's not what you'd expect.  It's more, it's less, it's completely different from what you've imagined.  The world behind the curtain is very, very different from the world that the fans see.  </p>
    ]]></summary>
    <content type="html"><![CDATA[<p>Backstage:  it's not what you'd expect.  It's more, it's less, it's completely different from what you've imagined.  The world behind the curtain is very, very different from the world that the fans see.  </p>
<p>Godhead and Clutch performed back-to-back on one of the last nights of the convention.  The setup had been bad, the soundchecks were later than scheduled, and from what we were hearing on our radios, we had a riot brewing outside.  Some all-knowing fire marshal had decided that the crowd in the lobby was exceeding safe capacity, so everyone waiting to be let in for the Godhead/Clutch concert got bullied and shepherded outside with bullhorns.By normal time, it was late in the evening&mdash;somewhere around 10 p.m.&mdash;but by convention time, the evening was just getting started.  The exhaustion was being kind enough to hold itself at bay, causing nothing more than a bit of fuzziness around the edge of my vision and a vague headache&mdash;but more pressing on my mind was the question, <em>Are we going to have a riot tonight before all this ends?</em></p>
<p>The convention had been going too well.  As Jody put it, "The Fuckup Fairy is looking for us, and she's pissed."</p>
<p>And here I was, sitting backstage in a grimy shirt and shorts that hadn't been washed in a few days, blue hair extensions clipped into my hair to identify me as tech staff, sitting backwards on the same type of chair we provided for the audience, and looking at the division between crowd area and backstage.</p>
<p>When you're wondering if there's going to be a riot outside due to pissy fire marshals shooing out a thousand semi-drunken goths from the hotel lobby, a mere cloth curtain serving as a divider doesn't look like much.</p>
<p>The bands weren't in much better moods.  Nobody had shown up with backstage passes for their friends and family, so everyone who didn't have a backstage pass was getting interrogated every ten minutes by every staffer and security person who passed backstage.  In a vague attempt to remedy the situation, I'd introduced myself to the band members of Godhead and told them if they kept having problems, to send the people to me.</p>
<p>A few minutes later, someone wearing a tech headset flinched visibly.  "Someone's throwing empty beer bottles from the seventeenth floor onto the pool deck," she said.</p>
<p>At this point, I'm wondering if I should just go to my room and hide&mdash;but no, I have work to do, so I pull up a chair.  Turn it around backwards, rest my chin on the back, stare at the curtain.  People are starting to trickle in now.  The nervousness begins to get to me&mdash;if the crowd is going to be pissy and start throwing stuff around, I really don't want to be separated from them by a few swaths of cloth.</p>
<p>A hand clamped on my shoulder.  Jody.  Oompa, we call him.  "The bands need Gatorade for after the concert."  My look&mdash;<em>where am I supposed to find that?</em>&mdash;must have been pretty plain.  He shrugged and grinned.  "Find a way.  Make it happen.  We need it in thirty minutes."</p>
<p>I run around the hotel.  Asking questions of people who don't know the answers.  Gatorade?  No, we don't have any.</p>
<p>Then it dawns on me&mdash;we're going to have to use the tech staff Gatorade stash down in Harris.  I corral Jeremy; we head downstairs to Harris.  Sean finds an empty water jug&mdash;the kind that bottled water is dispensed from&mdash;and I get directions to the hotel kitchen to fill it up with water.  Sean brings it back to the tech staff room, and we create a makeshift funnel and dump every bit of powdered Gatorade (orange) into it.  Sean shakes the bottle until it's all dissolved, and we take a taste.</p>
<p>It's terrible.  It needs more powder.  We don't have any&mdash;but &hellip; wait, we have a half-empty can of Powerade powder.  Flavor?  Fruit punch or something like that.  Either way, it's red, and it won't conflict too badly with what's already in the jug.  Makeshift funnel again, and in goes the powdered Powerade.</p>
<p>Shake again, and taste.  It's not great, and the flavor is unrecognizable, but it's all they're going to get.  I put it on a cart and take it upstairs, where the jug is set up, placed on a table, and left for the band.  I take the cart back to Harris, and rejoice over having accomplished the impossible once again.</p>
<p>The lobby has quietened down.  Most of the people milling around before have gone in to see the concert.  Security is standing around and looking nervous, and the fire marshal has laid down strips of yellow gaffer's tape to mark exit lanes from the doors that have to be kept clear, but even the drunk conventioneers seem to have calmed down.</p>
<p>I head toward the door for backstage.  Ahead of me is a surly fellow who blows off the security person and keeps walking.  I'd talked earlier in the evening with the woman who was staffing the door, and she knows I'm staff.  She points at the man's advancing back and says, "He doesn't have a backstage pass."</p>
<p>At that point, my favorite epithet comes out of my mouth:  "Jesus H. Christ in a chicken basket."  Just what we need.  I <em>hope</em> he's a band member.  If he's a gate-crasher, I'm tempted to just rip his throat out.  Either way&mdash;as a conventioneer or a band member, he should know better than to blow off security.</p>
<p>I catch up with him backstage.  I put my hand on his shoulder and turn him around.  "May I see your badge?"</p>
<p>"I don't need a goddamn badge; I'm the fucking singer for Clutch."  He's got a guest tag, but so do a ton of people at this convention.  His badge says nothing about a band, and given his current pissy attitude, I'm not terribly inclined to give him the benefit of the doubt.</p>
<p>"I wouldn't know you from God himself."  I look around frantically&mdash;thinking, can I please have some backup here? he's bigger than me!&mdash;and holler to the staff members, "Can we get some confirmation that this guy is who he says he is?"  Larger men from tech staff show up and start asking him questions.  Whoever he is&mdash;singer or not&mdash;he can get pissed and just get over it.</p>
<p>At that point, I decided I'd had it for the time being.  I went downstairs.  Kat gave me some mead.  I decided it was time to take an hour or two off, so I turned my badge around so that it looked like a regular convention attendee's, and wandered off to relax somewhere with some friends.  </p>
<p>So, if you wonder about what's going on behind the stage curtain, don't sweat it.  You're probably having more fun than they are!</p>
    ]]></content>
  </entry>
</feed>
