Personal blog, accepting guest commentary and links to things of interest.

August 30, 2007

Threat Level - Wired Blogs

by @ 4:59 pm. Filed under Misc

Threat Level - Wired Blogs

Computer science professor Steven Bellovin — one of the most knowledgeable outsiders on the government’s eavesdropping mandates known as CALEA, pored over recently released documents that outline the FBI’s extensive, eavesdropping architecture.

He concludes that they don’t bode well for anyone:

I don’t think the FBI really understands computer security. More precisely, while parts of the organization seem to, the overall design of the DCS-3000 system shows that when it comes to building and operating secure systems, they just don’t get it.

The most obvious example is the account management scheme described in the DCS-3000 documents: there are no unprivileged userids. In fact, there are no individual userids; rather, there are two privileged accounts. Each has diferent powers; however, as the documents themselves note, each can change the other’s permissions to restore the missing abilities. Where is the per-user accountability? Why should ordinary users run in privileged mode at all? The answers are simple and dismaying.

Leave a Reply

You must be logged in to post a comment.

internal links:

Aquarium

    PH = 8.01
    AirTemp = 74.00
    TankTemp = 78.4
    ORP = 437

Google Ads:

categories:

search blog:

archives:

other:

  • RSS 2.0
  • Comments RSS 2.0
  • Valid RSS
  • Valid XHTML
  • XFN
  • Theme copyright © 2002–2008 Mike Little.

FlickrRss: "watchmen"

    DeathGob Badges

    Watchpeanuts

    I found Rorschach!

    SOMEBODY

    IMG_3915

20 queries. 1.650 seconds