Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, December 05, 2007

Stop forwarding me those stupid e-mails

Forwarding Emails
This post addresses the age-old question of "what you have to lose" when you forward one of those e-mails that asks that question, as in "Maybe Bill Gates will share his fortune. What do you have to lose?" My brother really really is an attorney too, but even he knows better than to forward these emails. As a matter of fact, this post will describe why you shouldn't forward ANY e-mails "to all of your friends", even at the threat of instant death for breaking the curse or instant millions for doing Bill Gates some unspecified favor.

Old news
First, let me say that this should be old news to anyone who has been on the internet for more than a week. It surprises me that people still don't know to go to snopes and check whether the story they are spreading is even true. Generally, the answer is no. Nevertheless, we all still have that one aunt or cousin who just now got the internet, and they will forward these things until they are given a compelling reason not to. Here is that compelling reason.

All spam is spam
So, the risk of forwarding any compelling e-mail is that you are essentially participating willingly as a human part of a very effective spam operation. As you may know, sometimes spammers create viruses which download to your machine and secretly take it over to attack other machines or send commercial e-mails on behalf of the spammer. This allows the spammer to get around certain restrictions that might be imposed by their ISP against sending bulk e-mails. Instead the e-mails are from everyone, to everyone.

Exponential growth
One reason not to forward any e-mail, no matter how compelling, is that we've all already seen it. This is a mathematical certainty when you think about it. Let's take a compelling factor, call it x. If you are compelled to x degree to forward an e-mail, then you will forward it to x people, let's say. However, those x people will presumably find it just as compelling, and each x people will forward it to x people. That's x*x people so far. Now if that goes to a third generation, it is x to the third, and even if x is just 4, the message has been forwarded to a million people in ten generations. So, we've all seen it by the time you are sending it. The problem is even worse with more compelling e-mails. There is an easy test to see if an e-mail is subject to this problem. If you are thinking of forwarding it to more than two people, it is too compelling, and we have already seen it. This applies to virus warnings, gold speculation, "secret" recipes, free money, etc.

But I didn't forward any commercial e-mail
You may think that you can filter out commercial messages yourself, and just pare your forward list to those who do not complain about it, and those who have already seen it will just ignore it. You may be able to do that, though I question whether your e-mail was just a covert advertisement for MicroSoft and AOL, because after all, these are good impressions of those companies if they are being all charitable to you, the customer. None of this matters. The real, valuable content of those e-mails is not the "compelling" message. It is the forwarding lists of validated e-mail addresses. These lists are gold to a spammer. After a number of generations of sending one of these e-mails, it will have hundreds of e-mail addresses in it. At some point, someone will forward it to one of their active online friends, who is really a spammer. Now that spammer has MY e-mail address, and I didn't even want the mail in the first place, never mind forward it. I'm just on it because you sent it to me at some point. So stop it. Thanks for your time.

Wednesday, September 12, 2007

Security Exploit for your Car

Car security
I have talked a bit about cars and technology here before, particularly security. I think this is an issue which deserves some attention, but nonetheless I will post about it here rather than forward an e-mail to everyone I know telling them to forward it in turn. That has its own security risks, which I will explain in a later post. This article explains how I discovered a security hole for the automatic remote for some cars, and how to avoid it. This is on a slightly older car, but this exploit can be gleaned from a simple reading of the car owner's manual without any special technical knowledge or equipment, just a sneaky mind like mine, and one's own keyless entry. Your mileage may vary, as they say. You should read your own owner's manual with a mind toward something similar. More on that later.

Security attempts
Over time, car manufacturers have taken on the issue of keyless entry security. Early transmitters simply sent a digital sequence to the receiver in the car, matched to that receiver. The problem with this was that criminals could simply sit in a parking lot and record the sequences on their own receiver, and play them back to open the doors. This particular exploit required special equipment, and so was a specialized type of threat, but a real one nonetheless. To correct for this, manufacturers began coding the transmitters to the receivers but with special encryption algorithms built into both, with two-way communication, so that a different code was sent each time.

The exploit
In the particular case of my car, a Chrysler Sebring, this fix for a relatively rare problem created a much more common and exploitable problem. The transmitter is matched to the car at the factory, but it has some kind of internal limitation on how many new unique codes can be generated without communication. According to the owner's manual, if the keyless entry is keyed "more than 250 times" when not within range of the car, this pairing is lost. I suspect they really mean more than 255 times, but that's a nit. Anyway, since there is a way the customer can lose the pairing, there has to be a way to resync. The way to resync, on my car, is simply this: Lock the doors (using the door-lock switch on the door, of course, because your remote doesn't work), then press the buttons on the remote in a particular way (which I will skip here to maintain a little security through obscurity). The remote resyncs and then can be used to unlock the door again.

Oops
If you haven't figured out the exploit by now, it is simply that if the owner of the car has locked his doors with the door-lock switch, any schmoe with the same remote can then press the appropriate sequence on his remote and get into the car. The key will still not fit, so they can't steal your car, but at least they can steal all your CD's and sunglasses. Up until I realized this, I locked my door this way all the time, because it's easier to flip the lever on the door than to fiddle around with the remote. Luckily, I discovered this exploit not by being victimized but because I had a remote that didn't work even after replacing the batteries, and it said on the remote "consult the owner's manual." I tried it on my dad's car, which is the same but a newer year, and sure enough it works.

Keeping out interlopers
The solution is simple, of course. Just lock your doors with the keyless remote always. This will also ensure that you don't lock your keys in the car, which is good.

Other cars
Your car may differ in the way that it resets the keyless entry. For example, some require that the key is in the ignition to initiate the sequence. In this case you are safe from this exploit, but there may be other ones depending on your car. Read your owner's manual, and if you find another exploit for your car, post it below.