Showing posts with label defcon. Show all posts
Showing posts with label defcon. Show all posts

10 February 2015

DEFCON CFP submission: "The Law of Drones"

Here's the abstract for my DEFCON submission:

A decade ago, drones were mostly associated with terrorist strikes in the Middle East. Since then, the proliferation of drone technology has resulted in widespread deployment of unmanned aerial systems for law enforcement, commercial, and personal use.  The recent drone crash on the White House lawn has sparked a renewed interest in unmanned aerial systems by governments, commercial users, and hobbyists. Recent events have also put a spotlight onto the Federal Aviation Administration's renewed efforts regulate drones. This talk will review the history and development of laws, rules, and regulations regarding model aircraft, drones, and other unmanned aerial systems. Next, we will survey the legal landscape to understand current efforts by the FAA and other governmental bodies to restrict and regulate drones for personal users while expanding opportunities by governmental users. Finally, we will look at the way forward in an opportunity to evaluate the balance between the rights of drone users and the privacy expectations of citizens. If you're interested in learning more about model aircraft, drones, and other unmanned aerial systems, come check it out!

09 June 2013

The George Washington University and a small win for intellectual property

Earlier this week, I received the following email from XanEdu on behalf of The George Washington University:
XanEdu is seeking permission on behalf of [xxx] at George Washington University to include the following material in a digital CoursePack for approximately 12 students enrolled in PSSL 6246 during the Summer 2013 semester:
Title: Shodan for Presentation Testers
Author: Schearer, Michael
Page Range: 1-79
Total Pages: 79
Publisher: (author) Schearer, Michael 
If permission is granted, XanEdu will post the material on a password-protected web site. Only the instructor and students registered for this course will have access. The material will be removed at the end of the semester.   
You may grant permission by emailing or faxing this request with approval information to my attention.  Should a royalty fee apply, please include that with your email or fax.   
Thank you for your consideration. Please contact us if you have any questions or need more information.
As with most of my materials, I released this presentation under the Creative Commons License: Attribution-NonCommercial-ShareAlike 3.0 Unported (CC BY-NC-SA 3.0).

GWU gets +1 for respecting intellectual property!

23 March 2013

DEFCON CFP submission: "©opyright Gone Wrong: Our Broken System and How We Can Fix It"

Here's my DEFCON CFP submission:

Title: ©opyright Gone Wrong: Our Broken System and How We Can Fix It

Abstract: The Constitution grants the Congress the power to enact copyright laws "[t]o promote the Progress of Science and useful Arts, by securing for limited Times to Authors and Inventors the exclusive Right to their respective Writings and Discoveries." Since the founding of our country, protection of intellectual property has undergone several systematic changes that have extended the time rights are protected. Additionally, protections have gotten increasingly aggressive and oppressive. This presentation will briefly discuss the history and development of copyright law, and then focus on the more recent and onerous provisions that have become embroiled in controversy. Along the way, we'll talk about the Digital Millennium Copyright Act, copyright trolls, and other methods of intellectual property abuse. Lastly, we will take a look at some of the ways we can reform our broken system to free consumers from burdensome restraints, while at the same time protecting the intellectual property of the creators.

Bio: Michael Schearer ("theprez98") is a civil libertarian who has started numerous projects which document abuses of freedom and liberty. He is a Senior Penetration Tester at Booz Allen and a law student at UDC-DCSL. He spent nearly nine years in the Navy as an EA-6B Prowler ECMO. His military experience includes aerial combat missions over Afghanistan and Iraq and nine months on the ground doing counter-IED with the Army. He is a graduate of Georgetown’s National Security Studies Program and a speaker at ShmooCon, DEFCON, HOPE, and other conferences. Michael lives in Maryland with his wife and children.

15 March 2013

Law in Plain English: In Re National Security Letter

This is one in a series of posts designed to describe court decisions in plain English. For more detail and background on the legal issues, see the link to the case below. For similar posts, click here.

In Re National Security Letter

The FBI issued a national security letter (NSL) to an unnamed ISP for certain subscriber information. The FBI certified that disclosure of the NSL could harm national security, so the ISP was prohibited from disclosing to anyone that they had received it (a gag order). The ISP challenged the constitutionality of the  non-disclosure provision as a violation of free speech, and challenged the judicial review provisions as a violation of the separation of powers. Judge Susan Illston of the United States District Court for the Northern District of California ruled that the nondisclosure provision was a form of prior restraint which was not narrowly tailored, since the provision applied to both the content of the NSL and the fact that the ISP even received it. As a result, it violated the ISP's freedom of speech. Additionally, the judicial review provisions violated both the First Amendment and the separation of powers principle by trying to narrow the ability of courts to review the nondisclosure orders. Furthermore, she prohibited the government from issuing any NSLs or from enforcing the nondisclosure provisions in this case and in any other cases. Lastly, she stayed enforcement of the judgement pending appeal or 90 days if there is no appeal (although that seems entirely likely).

Update (8/13/2013): I missed this a few months back, but the Government did file a notice of appeal.

27 February 2013

Law in Plain English: Gabelli v. SEC

This is one in a series of posts designed to describe court decisions in plain English. For more detail and background on the legal issues, see the link to the case below. For similar posts, click here.

Gabelli v. SEC

Gabelli was charged with violating a federal law by defrauding his clients. The statute of limitations required that charges be "commenced within five years from the date when the claim first accrued." The question here was "when the claim first accrued" meant when the fraud actually occurred, or when it was discovered. In a unanimous opinion, the Supreme Court ruled that the natural reading of the law required the statute of limitations began when the fraud actually occurred. To read otherwise would violate the fairness of the statute of limitations concept. In other words, the fraud charges against Gabelli were filed too late. The practical impact of this decision is that violations of federal laws subject to the statue of limitations here will begin to run when the fraud occurred, not when it was discovered.

22 February 2013

Law in Plain English: FTC v. Phoebe Putney Health System, Inc.

This is one in a series of posts designed to describe court decisions in plain English. For more detail and background on the legal issues, see the link to the case below. For similar posts, click here.

FTC v. Phoebe Putney Health System, Inc.

A Georgia-authorized hospital authority (Phoebe Putney Health System, PPHS) managed one hospital and then purchased the only other hospital in the same county. The Federal Trade Commission (FTC) filed an anti-trust complaint alleging that having one hospital authority owning both hospitals in the county would reduce competition. PPHS claimed that as a state-authorized entity, they were entitled to state-action immunity from the anti-trust liability. The question before the Court was whether PPHS was entitled to such immunity. The Supreme Court ruled that PPHS was not entitled to anti-trust immunity because Georgia did not make it affirmatively clear that its hospital authorities could take actions that would reduce competition. The practical impact of this decision is that states that wish to give state-action immunity to their subdivisions need to do so through a clearly articulated policy.

18 February 2013

Law in Plain English: Bloem v. Unknown Department of the Interior Employees

This is one in a series of posts designed to describe court decisions in plain English. For more detail and background on the legal issues, see the link to the case below. For similar posts, click here.

I've made a slight change to the "SCOTUS in Plain English" series to reflect the opportunity to discuss a few cases not at the Supreme Court level that are nonetheless interesting and worthy of discussion. As a result, the series is now called "Law in Plain English."

Bloem v. Unknown Department of the Interior Employees

The National Park Service distributed flyers warning Occupy protesters in McPherson Square that they would begin enforcing a prohibition on camping. Subsequently, many items of personal property (some that belonged to Bloem) were destroyed. Bloem filed a lawsuit against the unnamed Department of the Interior employees for the seizure and destruction of his property. The DoI filed a motion to dismiss, alleging that Bloem had failed to state a claim upon which relief could be granted. The District Court ruled that the tent city was expressive conduct, permitted by the First Amendment. Additionally, Bloem's allegations that the DoI had violated his Fourth and Fifth Amendment rights were sufficient, and thus Bloem had stated a plausible claim. For purposes of a motion to dismiss, which in this case is a 12(b)(6) motion, Bloem's alleged facts are presumed by the court to be true. In other words, the court looks at the case and says: even if we assume that all of his facts are true, has he made a plausible claim? This is a procedure hurdle to make sure that baseless lawsuits don't consume valuable time of the court. As a result, Bloem's claim survived the government's motion to dismiss and the case can move forward.

10 July 2012

Michael Schearer answers your questions (my #defcon rant)

Let me begin this post with the (what should be unnecessary) caveat that I love all things DEFCON. The conference and the people have been nothing but good to me over the past six years. I will be there this year, and likely years into the future.

That being said, I have a particular nitpick, which I hope will be construed as constructive criticism, concerning a couple of speaking slots that are "so-and-so answers your questions." The speakers are Bruce Schneier and Kevin Poulsen. My second caveat is that this criticism is not directed to them; I don't have a problem with either guy. And this should not be construed as directed toward any given individual associated with DEFCON, because that's really not my intent. My issue is the format (as it relates to the return for the speaker).

DEFCON has presumably gotten more popular over the years as more people attend and more people submit proposals to speak. I'm not privy to these numbers, or to the overall quality of the submissions. But given the feedback I've gotten, it would seem that there are more good talks than there are speaking slots. Legitimately good talks get turned down. It happens. I have been fortunate to have most of my talks accepted. But I've been on the rejection side, too (for DEFCON and other cons). It sucks, especially when you put a lot of work into crafting what you think is a good proposal, and especially when you get good feedback from the conference and other people.

Let's talk about when "so-and-so answers your questions." Let's say we have 45-50 minutes and 3 minutes for any given question and answer. That leaves about 15-16 people (out of hundreds or thousands) who get to ask a question; or whomever can get to the microphone faster than me. Maybe I'm in the minority here, but I just don't get a lot out of these talks. But that's really a minor criticism.

My bigger concern is that people who have put time and effort into developing legitimately good proposals are unfortunately turned down for spots that require no work. When "so-and-so answers your questions," those speakers realistically don't have to prepare anything. Show up and answer questions. I could do that (if I were popular, which I am not, but I digress).

I'd like to think that in some small way, a CFP rewards people who put time and effort into the process. That isn't to say the longest or most detailed proposal should automagically be accepted; but time and effort should mean something. When I get accepted to speak at a conference, it's a treat and reward for what is often months of prior research. It means a lot. I sense that others probably feel the same way.

I realize that this criticism might seem self-serving because I didn't get selected this year (honestly, I am and was totally bummed about it; but it happens and I am not going to let it make my experience any less awesome). I'd like to think I would have this same criticism whether or not I got accepted. But this isn't about me. Better yet, I'd love to see Bruce or Kevin (or anyone in these circumstances) give a prepared talk; it shows me they actually care about putting time and effort into rewarding the attendees with thoughtful discussion instead of showing up for a handful of Q and As, something that anyone could do.

What do you think? I am whining too much and full of shit, or is there a point somewhere here?

06 March 2012

DEFCON CFP submission: "Flex Your Rights: The Constitution & Political Activism in the Hacker Community"

I have no idea if it's a good idea or bad idea to post my DEFCON CFP submission online. For one reason or another, I have never posted my proposals. To be honest, I have never thought about it, until now. I can't see any good reason why not. On the other hand, I have been fortunate to have written a number of successful proposals for DEFCON talks in the past, so maybe this will help others in some small way.

Title & Abstract
Outline
Whitepaper
Bio

Title: Flex Your Rights: The Constitution & Political Activism in the Hacker Community

Abstract: Let's be clear upfront: I don't care if you're a Republican or Democrat (or another party), I don't care if you're pro-life or pro-choice. This presentation isn't about politics in the traditional sense. What we should be willing to acknowledge, however, is that public policy issues and the political process increasingly overlap with issues and interests that are important to the hacker community. Issues like free speech, privacy, and copyrights manifest themselves in legislation like SOPA, PIPA, ACTA, the Cybersecurity Act, DMCA (and many others). Surely these issues are worth our time and attention. By exploring recent legislation, court cases, and newsworthy events, it's my aim to convince you that we, the hacker community, need to flex our rights right now, more than ever. Won't you join me?

Outline: I try to write detailed outlines of my presentation that give the speaker selection folks a good idea of what I plan to talk about. By the time my slides are up on the screen, I have often changed things around, added and deleted entire sections, but that's just the way it goes. When I wrote it, this is what I planned to do. Things will change (they already have), but it paints a picture for the selectors.


I. Introduction
A. Present background: why should you listen to me? Qualifications
B. Present background: why should be skeptical! IANAL, for example
C. Explain agenda
D. Introduce topic
E. Caveats1: explain why this isn't really a "political" presentation in the traditional sense
F. Caveats2: this is not "hactivism" either, I'm asking you to become a part of the process
1. Every action has costs and benefits
2. "Hactivism" has benefits, but how high are the costs?
II. Politics in the Hacker Community
A. The status quo
1. Mostly apolitical, especially at conferences
2. Activity tends to be limited to rare issues that go viral (SOPA/PIPA)
3. A sense that things are beginning to change as more issues invade our space
B. What I am asking of you?
1. Nothing more than the EFF is already doing
2. I'm asking you to start doing it yourself, too
3. This should not be a radical change for the community
III.Issues
A. First Amendment
   1. Concepts
a. Free speech
b. Speech as it applies online/impact of technology
2. Issues of interest
a. Censorship (H5N1 research, blocking)
(1) H5N1 flu research
(2) disclosure debate comparison
(3) Paypal "legal" censorship (SmashWords)
b. SOPA/PIPA (and their inevitable follow-ups)
B. Fourth Amendment
1. Concepts
a. Reasonable expectation of privacy
b. Impact of technology on privacy (see DEFCON19)
2. Issues of interest
a. Administrative searches
b. Administrative warrants & subpoenas
c. Surveillance (cameras, GPS, cells, drones)
d. It's your fault, too (our own behavior impacts the reasonable expectation of privacy)
e. Drone technology and the ad coelum doctrine
C. Copyrights and Patents
1. Civil forfeiture abuse (US Customs, Secret Service)
2. Patent abuse/trolls
3. Digital Millennium Copyright Act
4. Golan v. Holder and public domain issues
D. Licensing laws
1. Some licensing may be desireable
2. Other serves as a high barrier to entry to protect "insiders"
a. Locksmiths
b. Private investigators
c. Digital forensics
E. Lens of Liberty
1. Potentially the most controversial, but doesn't need to be
a. Lens analogy (good? bad?)
b. process rather than substance; we can agree on process and disagree on substance
2.  Current worldview:
a. Islands of liberty in a sea of power
b. Not surprising giving massive size of govt bureacracy
c. "Red hat" analogy
3.  Proposed worldview:
a. Islands of power in a sea of liberty
b. A fundamentally different way of asking the question
c. Scepticism
(1) does the law actually accomplish its intent?
(2) short term solution or long term solution?
(3) What the consequences to all groups, not just a few (special interests/groups)
(4) or, does it benefit the whole, or just a few
d. Social contract
e. Balance of powers
f. Separation of powers
g. Federalism
4.  You may view issues through this lens and still come up with the same answers, or not
IV. Conclusions
    A. Restate argument
1. this isn't really a "political" in the traditional sense
2. this is not "hactivism" either
3. I'm asking you to become a part of the process
4. Nothing more than the EFF is already doing
    B. What can we do?
1. Vote (if you don't like the choices, do something about it)
2. Participate: in person, online, writing, calling, etc.
3. Educate
a. Yourself: read proposed legislation, don't rely on other people's work (or lack thereof)
b. Others: convince people that your rights and their rights are one in the same


Whitepaper: Even though CFP technically stands for "call for papers", I have always treated it like "call for proposals"; and in fact, I have never submitted a whitepaper before this year (to any conference). So they're certainly not required. But I felt like my subject was at least marginally controversial enough (for a hacker conference) that I wanted more space to expound upon my ideas. In reality, it's just a fleshed out version of my outline and the general direction that I want to go.


INTRODUCTION
The hacker community has mostly been an apolitical force. The Hacker Ethic lends itself to a libertarian-ish type of philosophy, but at conferences, and in general, hackers tend to stay away from overt shows of partisan politics (one notable exception: 2600/HOPE). Generally speaking, I think this is a good thing. On the few issues which do rise up and go viral (i.e., SOPA/PIPA), the hacker community will stand up and make its voice heard: not always in unison, but heard nonetheless.

The increasing role of invasive forms of technology in our everyday lives brings many issues to the forefront that the hacker community has typically left to its legal support organizations such as the Electronic Frontier Foundation. The EFF appears to be well-supported from the hacker community from a financial perspective, but support in other forms—manpower, boots on the ground, phone calls, letters and visits to legislators, in short, political activism—seems less clear.

As a growing avalanche of issues threaten to scale back our constitutionally-guaranteed freedoms, more issues begin to invade the space of the hacker. Free speech is not just for flag-burning, it increasingly manifests itself through technology—online speech and censorship are but two ways. Invasive technology has also forced the courts to interpret outdated laws on searches and seizures and the right to privacy. How these laws and rulings impact cell phones, computers, email, encryption, are all vitally important to the everyday work of the hacker community. And this is just the beginning.

It should be clear that the “traditional” political activism this presentation recommends seeks to distinguish itself from more common hacktivism often seen in the hacker community. This is not to say that hacktivism does not have its benefits; clearly, it does. It also has costs. It is my contention that, more often than not, the benefits of hacktivism (primarily awareness) are outweighed by the costs (possible jail time, the likelihood of more stringent laws). Likewise, this presentation isn’t advocating a move to transform the hacker community into a political movement—only to do (as an example) what the EFF is already doing. But financial contributions aren’t enough—hackers need be personally involved—to be the foot soldiers for freedom. And we not limit our issues to those embraced by the EFF—any issues that impact our freedom need action.

ISSUES
A. First Amendment. The First Amendment is usually analogous with the idea of free speech, and understandably so. In some ways, we have come so far in speech freedoms that we take them for granted. In other ways, small, insidious measures threaten to limit our speech—sometimes without even a peep from us.

Free speech also brings domain seizures to the forefront. Using civil forfeiture laws, the government can effectively limit speech. Worse yet, these laws flip justice on its head: the owner is now presumed guilty, and must “prove” his innocence.

Bloggers and others in other countries are under fire for their content—but that couldn’t happen here, right? Except it already does—the Department of Homeland Security has already admitted to monitoring social media. Perhaps this is not as invasive as it might be in other places, but it is chilling nonetheless.

Companies such as PayPal may deny service to organizations that produce or support content with which PayPal disagrees. This, in many ways, is a sort of legal censorship as it applies to publishers like Smash words. On that many of us can agree. The solution, on the other hand, is more perplexing. Should the government have the power to force PayPal to provide service to all businesses who want to use it? It’s not difficult to see the slippery slope here.

B. Fourth Amendment. My presentation last year was entitled “WTF Happened to the Constitution? The Right to Privacy in the Digital Age.” This presentation focused primarily on privacy issued related to the Fourth Amendment.

The Fourth Amendment is primarily based upon the concept of “reasonable expectation of privacy.” It’s a concept with variables, and our behavior can change the value of those variables. Unfortunately, to this point humans have been the weakest link. Our own behavior has weakened our reasonable expectation of privacy in many ways. Fortunately for us, the opposite is also true. If there were ever an issue that so clearly called for the involvement of the hacker community, this is it. One person opting out of an invasive airport scan may not signify a change in behavior, but 100 or 1,000 opt-outs may begin to turn the tide. Obviously, this doesn’t apply to airport opt-outs.

Recently, the Fort Worth city council decided to purchase a cell phone tracking system for the police—and with the express intent of developing probable case. This is a grave violation of the Fourth Amendment. Maybe your town is next.

Recent legislation and the explosion in drone technology promises further invasions into our homes and backyards. The ad coelum doctrine, rewritten once already last century due to the advent of air travel, is likely to see further revisions as drones become ubiquitous over our homes and businesses.
Other issues are equally important: administrative searches, administrative warrants, public surveillance.

C. Copyrights and Patents. SOPA/PIPA were the rare issues that went viral. We needed Anonymous to remind us of the history of Hollywood, that movie producers moved to California to avoid Edison’s patents. But these issues remain, and they will not give up after one loss.

There are other copyright and patent issues lurking that are important to hackers. Among them are civil forfeiture abuse (sounds boring? Kit Dotcom and others wouldn’t think so), patent abuse and patent trolls, the ever-present Digital Millennium Copyright Act, and public domain issues.

Who would have ever thought that Congress could take things out of the public domain? Yet the Supreme Court ruled that, upon signing the Uruguay Rounds, the Congress could remove works already in the public domain and restore their copyrights.

D. Licensing Laws. While most of this presentation has focused on the federal government, they have, by no means, a monopoly on actions that impact our freedoms. Some states have restrictive licensing laws for hacker-related occupations like locksmithing, private investigators, or digital forensics. While some of these licensing laws may be desirable, others serve as a barrier to entry to protect insiders.

E. Lens of Liberty.
The Lens of Liberty is a proposed worldview: potentially controversial, but need not be. It is more philosophical than political. In fact, it is an argument that suggests we can agree on issues of process while disagreeing on issues of substance.

Our current worldview is dominated by the idea that we have small islands of liberty in a sea of government power. This is not surprising given the massive size of our federal bureaucracy. I’ve asked the question in the past: Do I have the right to wear a red hat on Wednesdays? A search of the Constitution and Bill of Rights will find no such right. Can the government outlaw my hat?

The Lens of Liberty argument suggests that this question is asked in a fundamentally wrong way. In fact, the question should be: Does the government have the power to prevent me from wearing a red hat on Wednesday? Now, the answer becomes unequivocally clear: it does not.

At the core of the lens is the idea of skepticism: Does a law actually accomplish its intent? Is it a short term solution or long term solution? What are the consequences to all groups, not just a few (special interests or specific groups)? Does the law benefit the whole, or just a few at the expense of the whole?

This brings up many other issues: the social contract, the balance of powers, the separation of powers, and federalism. This presentation is not a political science lesson, but it will show how these issues are important to the hacker community.

CONCLUSIONS
It should be clear by this point that this presentation is not “political” in the traditional sense. A hacker’s position on any number of otherwise divisive issues should not prevent the community from taking a more active stand on issues of freedom that affect us all. Whether someone is a Republican or Democrat or other party should not matter that our freedoms are increasingly under attack from legislation written by representative who admit their technological shortcomings and treat it as humor.

The number one recommendation from this presentation is a simple one: vote. It is often said, and more true than not, that one cannot complain if they do not vote. It is often said in response that “I don’t like the choices.” True enough. Then do something about it. Change the choices. Why can’t you be the next candidate for school board, city council, or even state legislature and beyond?

Number two: participate. Sending money to the EFF every year is a great first step, but we have to move beyond that. The city council will probably buy a nice new shiny cell phone monitoring system for the police without thinking twice about it—unless you’re there to raise legitimate concerns. Participation means in person, online, on the phone, in the mail.

Number three: education. First, yourself. Don’t rely on other people to tell you what’s in a proposed bill—in many cases, they’re pushing a particular vision or they may have not done their homework!—go read it yourself (it’s shocking how few people actually do this). Second, educate others. Convince people that your rights and their rights are one in the same. Your free speech online is the same as their free speech at the Occupy movement, or wherever. We don’t have to agree on policy to share belief in the same freedom.

Biography: I typically have a generic biography and then customize it to the talk. So, for example, since this talk is about the Constitution, I included a few items that would be relevant.

Michael Schearer ("theprez98") is the founder of MyFreeState, the Freedom Report, and the Assault on Privacy, projects which document abuses of our freedom and liberty.  Michael is the owner of Leverage Consulting & Associates, a computer security business. He spent nearly nine years in the United States Navy as an EA-6B Prowler Electronic Countermeasures Officer. His military experience includes aerial combat missions over both Afghanistan and Iraq and nine months on the ground doing counter-IED work with the U.S. Army. He is a graduate of Georgetown University's National Security Studies Program and a speaker at ShmooCon, DEFCON, HOPE, and other conferences. Michael lives in Maryland with his wife and four children.

21 January 2012

Five Ways We’re Killing Our Own Privacy

That's the title for ShmooCon FireTalks. Here's the abstract:
At DEFCON, I talked about how our privacy rights are under attack. Our sea of liberty is drying up due to the ever-encroaching power of the government. A litany of abuses continue to chip away at the historical foundations of privacy: administrative searches as pretexts to avoid search warrants, national security letter, andsuffocating public surveillance just to name a few. Yet the government alone is not the only source of our ever-diminishing privacy. In this talk, I turn my attention…to you. Yes, believe it or not, you (and me) and the other 310 million of us in this country are also responsible for our diminished expectation of privacy. Why are we responsible? Who wants our information, and why is it so valuable? Is there anything we can do to stem the tide?
See you there!

31 December 2011

2011 predictions update

Everyone makes predictions for the upcoming year, but how many people go back and actually score themselves?

1. The Supreme Court will reverse the Ninth Circuit in Wal-Mart v. Dukes.
TRUE

2. Judge Roger Vinson of the U.S. District Court for the Northern District of Florida will find the health care reform law to be unconstitutional.
TRUE

3. The FCC will approve new net neutrality rules (that will probably happen in the next week or so), but the federal courts will find that this oversteps their authority (again).
PARTIALLY TRUE (case is still pending)

4. At least one politician (state legislator or above) will resign when a video of their misconduct goes viral.
Thankfully, we didn't get video of Weiner's weiner, but he did resign. PARTIALLY TRUE

5. North Korea's Kim Jong-il will die and his son, Kim Jong-un, will take over.
TRUE and TRUE

6. At least one Philadelphia sports team will make it to the Super Bowl, NHL Finals, or World Series.
FALSE (unfortunately)

7. Patriots' QB Tom Brady will win the NFL MVP and Eagles' QB Michael Vick will finish second.
TRUE (Note: Brady was unanimous; there was no second place)

8. Baltimore (BWI) will record less than 30 inches of snowfall this winter (please)
TRUE (I think the official number was 18-19 inches)

9. I will get accepted to law school (please) and actually go this time!
FALSE (long story)

10. Stuxnet's creator(s) will be revealed (total guess).
FALSE

And one more for the road that I am most certain of:

DEFCON19 will be canceled.
Always TRUE

09 August 2011

DEFCON thank you!

A very gracious "thank you!" to everyone who came out to my privacy presentation at DEFCON, as well as to those of you who or tweeted about it afterwards.

I spoke to some media and also contributed to several documentaries (I hope they turn out well!).  I'll keep track of the media and blog interest here:

threatpost: DEFCON Round Up: The Good, The Bad and The Underage:
Another interesting presentation on Web privacy that’s getting a lot of attention on news aggregation and social media sites is Michael "theprez98" Schearer’s “WTF Happened to the Constitution?”
Network World: Privacy and Technology: WTF Happened to Your Constitutional Rights? (this article got aggregated everywhere):

An interesting presentation dealing with privacy and the Constitution was given at DefCon. In "WTF Happened to the Constitution?! The Right to Privacy in the Digital Age," there were six reasons given as "things that should p*ss you off."
In the abstract for the talk, Michael "theprez98" Schearer states, "There is no explicit right to privacy in the Constitution, but some aspects of privacy are protected by the first, Third, Fourth and Fifth Amendments." It lists several ways in which we must deal with "technologically invasive searches" such as at airports or searches and seizures of laptops. Schearer added, "It becomes evident very quickly that searches and seizures are not so clear when it comes to bits and bytes...so where do we go from here?"
I'd like to share with you the six things Schearer said should tick you off.
1.  Administrative searches
2.  Administrative warrants and subpoenas
3.  Public surveillance
4.  School and students' rights
5.  Legislators, judges and technology
6.  It's your fault, too
For each reason, Schearer lists why it's a problem and what we can do about it. For example, he suggests that we should demonstrate that administrative searches are "increasingly intrusive in light of current technology." Since there is very little oversight on National Security Letters, a form of administrative warrants and subpoenas, we should continue to support efforts to publicize abuse.
Regarding surveillance cameras and GPS tracking, Schearer said the technology is "amassing data without suspicion" and we should continue to shout known and obvious abuses from the rooftops. He used the example of the Justice Department saying people have no reasonable expectation of privacy when it comes to warrantless GPS tracking. Depending on if the Supreme Court decides such tracking is Constitutional, may also let us know if we are "too far down the slippery slope" when it comes to surveillance.
Schearer said students are "often denied the same basic rights as other citizens." He added that some concerns about "disrupting an education environment" are legitimate but that reasoning is often used "as a pretext to invade students' civil rights." One example he quoted was a creepy "calorie camera" in Texas that is being used to track how much students eat.
According to Schearer, we have way too many legislators and judges who are incompetent. They write poor laws and make poor decisions because they simply do not have the "aptitude for understanding technology." Possible fixes to this problem could be a bunch of totally geeky folks who do grasp tech to run for public office, or just like there are Bankruptcy Courts, there could be specialty Technology Courts.
But also according to Schearer, the problem with privacy is "your fault, too." We share too much information voluntarily like on social networks which then lowers society's expectation of privacy and subjects us to more government intrusion. Schearer says we might be too far down the slippery slope on this one, but "just because we can share, doesn't mean we have to."
In conclusion, Schearer said, privacy isn't dead yet but it is dying fast. "We can reclaim privacy by protecting our information and refusing to share so much voluntarily, and in turn increasing society's expectation of privacy." He added that we should "increase awareness by shining the light on governmental intrusions into privacy rights."
Check out theprez98's slides on Scribd to see more of his talk, "WTF Happened to the Constitution?! The Right to Privacy in the Digital Age."

Tech Republic: Deb does DEFCON: Hacking conference tackles cyberwar and civil liberties:
The second session I attended was titled, in the true spirit of Defcon, “WTF Happened to the Constitution?” Michael Schearer, aka “theprez98,” took us through the history of privacy law and how the U.S. Constitution, legislation, and case law protect our rights to privacy — and how they increasingly don’t.
A short editorial comment: I totally appreciate how she said my title was "in the true spirit of Defcon..." I will admit that was totally my intent.

SANS blog: Hostile Forensics (a mention!):
Seeing a few great presentations today here at DefCon, namely by Christopher Cleary, Michael "theprez98" Schearer, and Wesley McGrew motivated me to get off my duff and finish this thing.
WXPNews: Lowering (and Raising) the Bar for Expectations of Privacy in Technology:
At Defcon, which tends to be a little less formal and a lot more "in your face," Michael Schearer (known in the hacker community as "theprez98") got right to the point in his presentation titled "WTF Happened to the Constitution?" with the unpleasant but oh-so-true statement that we, the people, are at least partially responsible for the erosion of our privacy rights. This was reinforced by the panel of attorneys from the Electronic Frontier Foundation (EFF) who fielded questions later in the day at Defcon. A key factor in determining whether a search or seizure is legal under the fourth amendment hinges on whether you have a reasonable expectation of privacy, and by accepting without question or protest ever more intrusive behaviors, we change the definition of what's considered by society to be "reasonable."
The Network World article also got Digg'd.

If you know of other articles or media coverage would you please let me know? Thank you!

11 July 2011

My BSidesLV / DEFCON schedule

No BlackHat for me this year, for a couple of reasons. First, I am working for myself and I simply can't afford it. Second, I have come to believe that BSides events are simply better time spent.

So yes, I'll be arriving in Las Vegas on Tuesday night and attending BSidesLV on Wednesday and Thursday at the Artisan Hotel. I was fortunate enough to be involved in evaluating the proposals this year and I can say you won't be disappointed.

On Friday, August 5 at 1100 I'll be giving my DEFCON talk entitled "WTF Happened to the Constitution?! The Right to Privacy in the Digital Age." Here is my abstract:
There is no explicit right to privacy in the Constitution, but some aspects of privacy are protected by the First, Third, Fourth and Fifth Amendments. This presentation will discuss the historical development of the right to privacy, and in particular, the development of the Fourth Amendment; and then compares this historical development to the current digital age. The development of the right to privacy (especially given the historical context of the Fourth Amendment) to our current age requires us to deal with technologically invasive personal searches as airports, searches and seizures of laptops and other computing devices, and how to handle stored communications. It becomes evident very quickly that searches and seizures are not so clear when it comes to bits and bytes...so where do we go from here?
At 1300 on Friday I'll be moderating a Net Neutrality panel. Here is the abstract:
Over the last five years, network neutrality has moved from an abstract buzzword to FCC-enacted policy. Supporters and detractors both contend that their opponents position means "the end of the Internet as we know it!" This panel discussion will present a reasoned discussion of the issue from multiple viewpoints. Among the issues to answer: What is network neutrality and can we even agree on a definition? Does the FCC have the authority to enact net neutrality rules? What is the role of Congress in net neutrality? Lastly, what are the future implications for the Internet? This panel discussion will cover the basics of net neutrality, the role of Congress and the FCC in regulating the Internet, and the future legal and policy implications of the FCC's neutrality rules. Is the future of the Internet really at risk?
Finally, I'll be speaking again at DEFCON Skytalks. My talk is entitled, "Clearances and Chaos: Tales from the Crypt." Here is the abstract:
I spent the last six months looking for a new job. Along the way, I was invited to a ton of interviews, actually attended some of them, was surprised at the lack of technical questions in most of them, received some offers, and came away even more impressed with the value of a security clearance (if that is even possible). In the end, I decided to go out on my own as self-employed independent contractor. This is the story of my job search, but even more, it is a small story of the cleared infosec world: the stars are contractors, clearances and the chaos that ensues.
Unless things change at the last minute, no Toxic BBQ this year, and that's a shame. Otherwise, you can probably catch me at the DEFCON Forums meet. Most of the rest of the time, I tend to just wander from talk to talk and event to event. If you're interested in meeting up anytime that week, let me know!

Finally, since I've already had more than one such inquiry, if you're press and you'll interested in talking to me about any of my talks, please contact me at theprez98-at-verizon-dot-net. Thanks and see you in Vegas!

20 June 2011

Top ten update

With the news this morning that Wal-Mart succeeded at the Supreme Court in having the Dukes class action suit dismissed, it's time to update the top ten predictions for 2011. Here's a look back at the predictions with updates:


1. The Supreme Court will reverse the Ninth Circuit in Wal-Mart v. Dukes. YES

2. Judge Roger Vinson of the U.S. District Court for the Northern District of Florida will find the health care reform law to be unconstitutional. YES

3. The FCC will approve new net neutrality rules (that will probably happen in the next week or so), but the federal courts will find that this oversteps their authority (again). YES and NO

4. At least one politician (state legislator or above) will resign when a video of their misconduct goes viral.  YES and NO (Chris Lee and Anthony Weiner have both resigned, but over pictures and not video)

5. North Korea's Kim Jong-il will die and his son, Kim Jong-un, will take over. NO

6. At least one Philadelphia sports team will make it to the Super Bowl, NHL Finals, or World Series. NO (only the Phillies are left)

7. Patriots' QB Tom Brady will win the NFL MVP and Eagles' QB Michael Vick will finish second. YES (Brady was unanimous)

8. Baltimore (BWI) will record less than 30 inches of snowfall this winter (please) YES (14.4 inches)

9. I will get accepted to law school (please) and actually go this time! NO (wait-listed, blah!)

10. Stuxnet's creator(s) will be revealed (total guess). NO


And of course, the bonus prediction: DEFCON19 will be canceled. YES :-)

27 May 2011

The new job

Almost four years ago, my time in the Navy was quickly coming to a close and I was anxious to find a job.  I gave my first-ever talk at DEFCON about my counter-IED work in Iraq, and in the small crowd of people asking questions, a man flashed his Navy ID card, handed me his contact information, and told me that we needed to talk.

I have to admit at the time I was slightly frightened that somehow my talk had attracted the wrong sort of attention (I was still on active duty at the time, and my talk, while unclassified, was nonetheless pretty aggressive). Ultimately, my apprehension was misplaced; he was in the Navy Reserves but more importantly, he worked for Booz Allen and he was offering me an interview.  I went through a couple of interviews (my first one didn't go so well, but they saw potential and invited me back for a second), and by December I was thrilled to get (and accept) a job with Booz Allen.

Over the past three plus years I have worked with an amazing team of analysts that would be difficult to top. Through the highs and lows, this team has done amazing work and I am proud to have been a small part of it.  Over the course of barely two years, our six member team grew by leaps and bounds (we're about to pass 40 by next month), and it has been a remarkable run. That being said, it was time for a change.

Today, I am happy to announce that I've accepted a new challenge. Effective June 20, I will be working as a Security Engineer and Penetration Tester with TDI Security, a computer security consulting firm based in Washington, DC. I'm working not as an employee of TDI, but as a independent contractor.  Going out on my own and being self-employed is a step I've been looking to make for some time now. While my business (Leverage Consulting & Associates) has been around for over a year now, this move effectively marks the beginning of full-scale operations.

For a while now, I have been looking for the right opportunity to move into more direct full-scope penetration testing work, and I believe that this is that opportunity. Additionally, I already know some of the people I will be working with and I am extremely excited for this new direction.

I've very much enjoyed my time at Booz Allen, and I hope to be able stay in touch with those of you who I've met during that time. I am especially looking forward to meeting new folks through this new role.

See you in Vegas!

10 January 2011

NYT article on "secret subpoenas" misses the issue entirely

This article in the New York Times is, frankly speaking, terrible (emphases are mine):
THE news that federal prosecutors have demanded that the microblogging site Twitter provide the account details of people connected to the WikiLeaks case, including its founder, Julian Assange, isn’t noteworthy because the government’s request was unusual or intrusive. It is noteworthy because it became public.
For the Twitter request, the government obtained a secret subpoena from a federal court. Twitter challenged the secrecy, not the subpoena itself, and won the right to inform the people whose records the government was seeking. WikiLeaks says it suspects that other large sites like Google and Facebook have received similar requests and simply went along with the government.
This kind of order is far more common than one may think, and in the case of terrorism and espionage investigations the government can issue them without a court order. The government says more than 50,000 of these requests, known as national security letters, are sent each year, but they come with gag orders that prevent those contacted from revealing what the agency has been seeking or even the existence of the gag orders.
Let me rephrase the relevant parts into an explanation:
The government issued or obtained a secret subpoena (without a court order), known as a national security letter, to compel Twitter to provide the details of people connected to the Wikileaks case.
Uh, no. Not even close.

First, as both Christopher Soghoian and I have noted, it is not a subpoena, but a court order, and it makes a difference.

Second, as you can see below, the order is authorized by Title 18, United States Code, Section 2703(d).  National Security Letters are authorized by Title 18, U.S.C., Section 2709.  The difference is huge.  The Twitter court order (see below) is authorized by 2703(d) and signed by a federal magistrate.  Section 2709 National Security Letters are administrative subpoenas by the FBI and not signed by a magistrate or judge.

Third, there are distinct words in the order below:
...the Court finds that the applicant has offered specific and articulable facts showing that there are reasonable grounds to believe that the records or other information sought are relevant and material to an ongoing criminal investigation.
This is not just legal mumbo jumbo.  These words are carefully selected because they represent the legal standard required to issue a court order.  In fact, the "specific and articulable facts" standard of 2703(d) derives from the Supreme Court's decision in Terry v. Ohio, 392 U.S. 1.  A subpoena, even under 2703(d), would require a lower legal standard called reasonableness.

The entire article is based on the misunderstood claim that the Twitter court order is a National Security Letter administrative subpoena.  I am neither a lawyer, nor a journalist, but it doesn't take a genius to figure out that the New York Times misses the issue entirely.

Twitter 2703d Court Order

17 December 2010

Some thoughts about 2011

I'm not big on predictions, mostly because people make ambiguous ones that are difficult to judge.  So here's my attempt at a handful of predictions for 2011 that should be easily distinguishable with a yes or no answer:

1. The Supreme Court will reverse the Ninth Circuit in Wal-Mart v. Dukes.

2. Judge Roger Vinson of the U.S. District Court for the Northern District of Florida will find the health care reform law to be unconstitutional.

3. The FCC will approve new net neutrality rules (that will probably happen in the next week or so), but the federal courts will find that this oversteps their authority (again).

4. At least one politician (state legislator or above) will resign when a video of their misconduct goes viral.

5. North Korea's Kim Jong-il will die and his son, Kim Jong-un, will take over.

6. At least one Philadelphia sports team will make it to the Super Bowl, NHL Finals, or World Series.

7. Patriots' QB Tom Brady will win the NFL MVP and Eagles' QB Michael Vick will finish second.

8. Baltimore (BWI) will record less than 30 inches of snowfall this winter (please)

9. I will get accepted to law school (please) and actually go this time!

10. Stuxnet's creator(s) will be revealed (total guess).

And one more for the road that I am most certain of:

DEFCON19 will be canceled.

09 December 2010

Why the Pentagon Papers case doesn't apply to Wikileaks

In deciding whether Wikileaks or the New York Times (or anyone else) can or should be prosecuted for publishing the leaked diplomatic cables, many people have made reference to the "Pentagon Papers" case regarding the New York Times attempt to publish the documents that Daniel Ellsberg leaked to the press regarding the Vietnam War.

The case in question is New York Times Co. v. United States, 403 U.S. 713 (1971).  The government cited 18 U.S.C. § 793-794 (otherwise known as the Espionage Act), in particular, section 793(e):
(e) Whoever having unauthorized possession of, access to, or control over any document, writing, code book, signal book, sketch, photograph, photographic negative, blueprint, plan, map, model, instrument, appliance, or note relating to the national defense, or information relating to the national defense which information the possessor has reason to believe could be used to the injury of the United States or to the advantage of any foreign nation, willfully communicates, delivers, transmits or causes to be communicated, delivered, or transmitted, or attempts to communicate, deliver, transmit or cause to be communicated, delivered, or transmitted the same to any person not entitled to receive it, or willfully retains the same and fails to deliver it to the officer or employee of the United States entitled to receive it...
The key here is that the government sought to prevent publishing of the documents before it occurred.  This is an extraordinary rare restriction of the First Amendment called prior restraint.  In Bantam Books, Inc. v. Sullivan, 372 U.S. 58, the Supreme Court said: "Any system of prior restraints of expression comes to this Court bearing a heavy presumption against its constitutional validity."  Likewise, the Government "thus carries a heavy burden of showing justification for the imposition of such a restraint." Organization for a Better Austin v. Keefe, 402 U.S. 415 (1971).

The Court in Near v. Minnesota, 283 U.S. 697 (1931) did leave open some exceptions when prior restraint might be acceptable--among them cases involving national security.  And this is precisely what the government relied upon in the Pentagon Papers case.  However, the Court found in New York Times Co. v. United States that the government ultimately failed to meet this burden, and publication was allowed to continue.

New York Times Co. v. United States was about prior restraint of free speech, not an open invitation to publish any material without regard for any outcomes.  Publishers are still subject to issues like libel; and realistically could still be subject to the Espionage Act or other similar laws.  Indeed, Justice White's concurrence (jointed by Justice Stewart) said:
[t]hat the Government mistakenly chose to proceed by injunction does not mean that it could not successfully proceed in another way...If any of the material here at issue is of this [classified] nature, the newspapers are presumably now on full notice of the position of the United States and must face the consequences if they publish. I would have no difficulty in sustaining convictions under these sections on facts that would not justify the intervention of equity and the imposition of a prior restraint.
Exactly! The burden of the government in these situations would clearly be less than those in a case of prior restraint.  On the other hand, this isn't to suggest that the government would inevitably prevail in such a circumstance.  Rather, the free-wheeling citations of this case in defense of Wikileaks are misguided precisely because they mistake the holding to be much broader than it truly is.

07 November 2010

SHODAN weekend roundup

Since the ICS-CERT Alert came out about SHODAN and SCADA systems, I posted some links to a bunch of my previous SHODAN material here.

There have been a couple of articles and blog posts that discussed this issue, and also mentioned some of my previous work:
I also gave a presentation about SHODAN at Security B-Sides Delaware entitled "How to Pwn an ISP in 10 Minutes or Less (Without Really Trying);" the video is here.  I posted the slides from my previous presentations here, but I neglected to include the video links, so here they are: The Next HOPE and DEFCON18.  There is also audio for my QuahogCon presentation here.

Finally, here is the full ICS-CERT Alert:

ICS-Alert-10-301-01

03 November 2010

ICS-CERT Alert; SHODAN roundup

With the recent ICS-CERT Alert (PDF) going out about SHODAN (and in particular, in regards to SCADA systems), I thought I would collect the links for all or most of my SHODAN-related material since I have a bunch since last year:

My SHODAN-related blog posts are here.

I have also presented a lot about SHODAN over the last year.  Many of these presentations are similar in nature although the newer ones have some updated material.  There's not really any SCADA-specific material here, but in all reality the concepts are all the same if you use SCADA-related search terms.

SHODAN for Penetration Testers (ShmooCon Firetalks)
Pentesting the Web with Firefox: SHODAN
SHODAN for Penetration Testers (QuahogCon)
SHODAN for Penetration Testers (The Next HOPE)
SHODAN for Penetration Testers (DEFCON18)

I've talked with a couple of friends about advancing some of this research so hopefully we have something else coming out in the near future.