UK passport RFID “gotcha”?

The Guardian has a “gotcha” piece about how easy it is to crack the security on the RFID tags in the new UK passports. Bruce Schneier and Bruce Sterling have both commented favorably on the piece, but personally I don’t see what all the fuss is about. The RFID chip contains a cryptographically signed digital copy of the main page of your passport, including a digital copy of your photograph. The idea is that this way you can’t modify the name or paste your own photo into a stolen passport because the digital data won’t match, and you can’t modify the digital data because it has to be signed by the issuing country. After people expressed concerns that someone nearby could eavesdrop on the conversation between the passport and the RFID reader, they decided to encrypt the passport using your passport number, expiration date and date of birth, which is encoded using a barcode (or maybe a magnetic stripe). That way the customs official swiping your card can read the photo but someone eavesdropping on the RFID conversation can’t.

There’s only one concern the story mentions that makes even vague sense to me:

This means that each time you hand over your passport at, say, a hotel reception or car-rental office abroad to be “photocopied”, it could be cloned with equipment like ours. This could have been done with an old passport, but since the new biometric passports are supposed to be secure they are more likely to be accepted without question at borders.

Certainly people trust computers a little too much, but this sounds like something proper training would solve. The idea that the RFID chip can be cloned doesn’t seem like that difficult a concept to teach.

So what am I missing here?

UK passport RFID “gotcha”? Read More »

Rush Limbaugh on last week’s election

Rush Limbaugh, on the results of last week’s election:

The way I feel is this: I feel liberated, and I’m gonna – I’m just gonna tell you as plainly as I can why. I no longer am going to have to carry the water for people who I don’t think deserve having their water carried.

Now, you might say, well, why have you been doing it? Because the stakes are high. Even though the Republican Party let us down, to me, they represent a far better future for my beliefs, and therefore the country’s, than the Democrat [sic] Party does, and liberalism. And I believe my side is worthy of victory. And I believe it’s much easier to reform things that are going wrong on my side from a position of strength.

Now, I’m liberated from having to constantly come in here every day and try to buck up a bunch of people who don’t deserve it.

It’s not often I complement Limbaugh, but good on him (and about damn time). I think Limbaugh is a buffoon, but I also think the country is a lot better off with a cacophony of buffoons all speaking their minds than a bunch of ditto-head water-bearers all marching in lock-step. It’s something citizens of all political leanings need to keep in mind.

(Limbaugh quote via On The Media… in case you were wondering whether my radio taste had changed recently.)

Rush Limbaugh on last week’s election Read More »

EFF Patent Busting

EFF has a call out for prior art to help bust two broad patents:

The Patent Busting Project fights back against bogus patents by filing requests for reexamination against the worst offenders. We’ve successfully pushed the Patent and Trademark Office to reexamine patents held by Clear Channel and Test.com, and now we need your help to bust a few more.

A company called NeoMedia has a patent on reading an ‘index’ (e.g, a bar code) off a product, matching it with information in a database, and then connecting to a remote computer (e.g., a website). In other words, NeoMedia claims to have invented the basic concept of any technology that could, say, scan a product on a supermarket shelf and then connect you to a price-comparison website. To bust this overly broad patent, we need to find prior art that describes a product made before 1995 that might be something like a UPC scanner, but which also connects the user to a remote computer or database. Take a look at the description and please forward it to anyone you know who might have special knowledge in this area. You can submit your tips here.

Also in our sights is a patent on personalized subdomains from Ideaflood. For example, a student named Alice might have personalized URL ‘http://alice.university.edu/’ that redirects to a personal directory at ‘http://www.university.edu/~alice/.’ Ideaflood says that it has a patent on a key mechanism that makes this possible. We need prior art that describes such a method being used before 1999, specifically using DNS wildcards, html frames, and virtual hosting. Prior art systems might have existed in foreign ISPs, universities, or other ISPs with web-hosting services. You can submit tips here.

I’ll betcha there’s prior art in the augmented reality field that reads on the first patent, either from Steve Feiner’s group at Columbia or maybe even the stuff we were playing with at the Media Lab. (I’ll go rooting around once I meet a different deadline I’m spending my evenings on…)

EFF Patent Busting Read More »

Bill Buxton prediction on cheap ubiquitous displays

Bill Buxton gave the closing plenary talk at this year’s Computer Supported Collaborative Work conference this year, and bet everyone a drink that in seven years:

…it will be as cheap to buy, per square foot, to buy 100 dpi full-color displays as the same square-footage of whiteboard today. In 7 years, displays with on the order of 20 times more pixels than are on that screen right now [pointing to a 15′ x 15′ projector screen] but the same size will be cheaper than that screen is right now without the projector. It’s going to be about one to ten dollars a square foot for a 100 dpi full-color display that’s 6mm thick. And the only question is which of the six or so competing technologies is gonna get there first.

And now, what does that mean? That’s a technological affordance, it doesn’t mean anything except that it’s interesting because I’m a technologist. But as a designer, as a citizen, as a father, I care because now I can’t think about watches, mobile phones, or any of these other devices out of the context of these portable wearable types of things moving around in space collectively and relating to those things there on the wall. What’s that mean for education, what’s it mean for business, how do we conduct our meetings? And that is CSCW, or a different branch of it. And the amount of effort put to that, to me, is still really low.

Personally I think he’s being a little optimistic the time scale, but not by a lot, and he’s certainly right that researchers need to be thinking about how that changes the environments in which we work and live. And he has a little built-in slack in his prediction: CSCW only meets every other year, so even if he’s wrong we won’t be able to collect on our drink until 2014.

Bill Buxton prediction on cheap ubiquitous displays Read More »

The Group Noun

To start your weekends out on a humorous note, I came across this joke in my digital photo shoebox. My Dad cut it out of a magazine several decades ago, and I’ve always loved it:

The Group Noun

Perhaps the story was old, but it was sweeping through academic circles:

Four dons were walking down an Oxford street one evening. All were philologists and members of the English department. They were discussing group nouns: a covey of quail, a pride of lions, an exaltation of larks.

As they talked, they passed four ladies of the evening. The dons did not exactly ignore the hussies — in a literary way, that is. One of them asked: “How would you describe a group like that?”

Suggested the first: “A jam of tarts?”

The second: “A flourish of strumpets?”

The third: “An essay of Trollope’s?”

Then the dean of the dons, the eldest and most scholarly of them all, closed the discussion: “I wish that you gentlemen would consider ‘An anthology of pros.'”

A Google search indicates it was originally printed in the Sept. 19, 1955 issue of Time Magazine, but I think Dad’s copy was a reprint from a few decades later. That or he was a very erudite 10 year old!

Update 11/4/06: An update from my Dad: “Interesting bit of sleuthing you’ve done. In fact, at age 12 (at least approximately), I had to rely on others for my erudition, in this case coming from my father. He was absolutely ecstatic about this particular joke when he came upon it during his reading of Time, and after some explanation, I quickly became appreciative myself and clipped it out of the magazine.”

The Group Noun Read More »

Today’s news from Iraq

In today’s news, US soldiers lifted their cordon around Sadr City after an order from Prime Minister Maliki, essentially accepting that their search for a captured American soldier had failed and was not tenable given the increasing backlash from Moktada al-Sadr supporters. We also just ended the fourth deadliest month for American soldiers in Iraq, with 101 105 U.S. service members killed. Meanwhile, security company Kroll and engineering company Bechtel both announced they were pulling out of Iraq due to deteriorating security, and a briefing prepared by the US Central Command indicates Iraq has been rapidly sliding into chaos since the bombing of a Shiite shrine in Samarra in February.

So with all that and the mid-term elections less than a week away, I guess there’s no question why the President hopes we’ll just forget the past two years and think it’s still election 2004, huh?

Today’s news from Iraq Read More »

Finally a patent that admits to bogus claims!

There are so many bogus claims in patent applications these days it’s kind of nice to see an application that comes right out and admits it (via The Volokh Conspiracy):

9. The method of providing user interface displays in an image forming apparatus which is really a bogus claim included amongst real claims, and which should be removed before filing; wherein the claim is included to determine if the inventor actually read the claims and the inventor should instruct the attorneys to remove the claim.

Finally a patent that admits to bogus claims! Read More »

Snooping search terms from the browser cache with JavaScript

SPI Dynamics has an interesting proof-of-concept page that can snoop your browser’s cache of visited URLs and figure out whether you’ve searched for specific terms on Google. Or rather, I assume it can on some people’s computers… for some reason it always returns “yup, you searched for that” on both Firefox and Safari on my Mac.

Regardless, it’s an interesting attack. It’s based on the fact that your browser changes the color of links you’ve already visited, and sites can determine which style the browser has applied to a link using JavaScript and CSS, thus determining whether a particular URL has been visited or not. This basic concept was described by Jeremiah Grossman’s history extractor at Black Hat his year. SPI Dynamics takes it one step further by probing for the URL corresponding to a set of query terms on the popular search sites. They can’t just get a list of all your searches, but they could in theory troll for a list of interesting search terms, be they names of competing products, porn sites, common illnesses, etc. and then modify the page being displayed based on that information. (Via Google Blogoscoped.)

Snooping search terms from the browser cache with JavaScript Read More »