Archive for August, 2019

Obit watch: August 20, 2019.

Tuesday, August 20th, 2019

NYT obit for Cedric Benson.

Statement from APD.

Obit watch: August 18, 2019.

Sunday, August 18th, 2019

Cedric Benson, former UT and NFL player, was reportedly killed in a motorcycle accident last night.

Benson, a running back who played for the Longhorns from 2001 to 2004, accumulated the second-most rushing yards in program history and topped 1,000 yards in each of his four seasons. He captured the Doak Walker Award as the nation’s top running back in his senior season in 2004. The next year, the Chicago Bears took him No. 4 overall in the NFL draft. Benson went on to play eight seasons in the league and last played in 2012 with the Green Bay Packers.

He was 36. Reports are that a passenger on his motorcycle was also killed.

Obit watch: August 17, 2019.

Saturday, August 17th, 2019

Quickly, because I’m busy again: Peter Fonda. THR.

Please refrain from tasting the KNOB.

Friday, August 16th, 2019

As a Bluetooth guy, and as someone who just posted a bunch of DEFCON 27 stuff, I feel compelled to say something about the Key Negotiation of Bluetooth Attack (aka KNOB) which has been getting a lot of attention the past few days.

Here’s the actual paper from the USENIX Security Symposium.

The attack allows a third party, without knowledge of any secret material (such as link and encryption keys), to make two (or more) victims agree on an encryption key with only 1 byte (8 bits) of entropy. Such low entropy enables the attacker to easily brute force the negotiated encryption keys, decrypt the eavesdropped ciphertext, and inject valid encrypted messages (in real-time). The attack is stealthy because the encryption key negotiation is transparent to the Bluetooth users. The attack is standard-compliant because all Bluetooth BR/EDR versions require to support encryption keys with entropy between 1 and 16 bytes and do not secure the key negotiation protocol. As a result, the attacker completely breaks Bluetooth BR/EDR security without being detected. [Emphasis in the original – DB]

Here’s a higher level overview of how the attack works.

Also of interest, also from USENIX, also getting some media attention: “Please Pay Inside: Evaluating Bluetooth-based Detection of Gas Pump Skimmers“. What’s cool about this is that the authors have developed Bluetana, an Android app that scans for Bluetooth devices in the area (every five seconds), displays a list of devices it found, and highlights ones that show characteristics similar to those of Bluetooth skimmers.

First, the app checks the device’s class. All skimmers studied within this work, whether discovered by Bluetana or not, had a device class of Uncategorized. If the device class is not uncategorized, the data is saved for later analysis. The device’s MAC prefix is then compared against a “hitlist” of prefixes used in skimming devices recovered by law enforcement. If the device has a MAC that is not on this hitlist, it is unlikely to be a skimmer, and the app highlights the record yellow. Next, if the device name matches a common product using the same MAC prefix, the record highlights in orange. If all three fields (MAC prefix, Class-of-Device, and Device Name) indicate the device is likely to be a skimmer, Bluetana highlights the record in red. The highlighting procedure is the result of a year of refinements based on our experience finding skimmers in the field, and Bluetana includes a remote update procedure to account for these incremental changes.

I’m fascinated by both of these papers, just based on a preliminary skimming. I’m hoping to do a detailed reading at that mythical point in the future when I have more free time…

Black Hat/DEFCON 27 links: August 16, 2019.

Friday, August 16th, 2019

Apologies for being behind on this: I’m also working on another project that’s taking up a lot of my blogging time, but I hope to be done with that soon.

Obit watch: August 14, 2019.

Wednesday, August 14th, 2019

Dr. Carl A. Weiss Jr.

The name may ring a small bell for some of you. Others of you may be more familiar with his father…

…Dr. Carl A. Weiss, aka “The man who shot Huey Long”.

Maybe.

Carl Jr. would go on to learn a great deal about the senator and his father: that Long — who had seized near-dictatorial power to become what President Franklin D. Roosevelt branded as the most dangerous man in America — lingered 31 hours before he died of a single bullet wound, a victim, some said, of botched medical care by a patronage appointee at a Baton Rouge hospital; that his father — whose Tulane University yearbook had proclaimed that he was “bound to go out and make the world take notice” — died instantly, his body perforated with 61 bullet holes; and that his father — an antagonist of the Long regime but by most accounts an unlikely murderer — was just as rapidly convicted in the court of public opinion as the assassin.

The junior Dr. Weiss spent much of his life trying to prove that his father did not shoot Long. Some historians agree:

The counternarrative asserts that the doctor had only punched Long, that the bodyguards had overreacted and that Long was actually killed in the fusillade of their bullets. The guards were said to have then covered up their reckless response by pinning the death on Weiss.
“In his heart he knew the allegations weren’t true,” Carl III said of his father in a telephone interview. “The one-man, one-gun, one-bullet is not what occurred.”
Professor Richard D. White Jr., dean of the E. J. Ourso College of Business at Louisiana State University and the author of a more recent biography, “Kingfish: The Reign of Huey P. Long” (2006), shares those doubts.
“As a historian I cannot say either way, but deep in my heart I do not believe Carl shot Huey, but instead a stray bodyguard bullet hit him,” Professor White, who had met with Dr. Weiss Jr., said in an email this week.

Dr. Weiss ultimately cooperated with James E. Starrs, a forensic scientist at George Washington University, who tracked down Carl Sr.’s revolver (it was not unusual for Baton Rouge doctors making late-night house calls to be armed) and a single spent bullet.
They were found in a safe deposit box belonging to the daughter of Louisiana’s former top police official. Dr. Weiss joined the State Police in successfully suing to review the records and test fire the gun.
The police concluded that the bullet — if it was, indeed, the one that had killed Long — had not come from Weiss’s revolver.
Long’s clothes were also examined, and here the tearing of the material and the residue left on it indicated that Long had been shot at point-blank range. That undercut at least one theory — that Long was killed by a ricocheting bullet fired by a bodyguard.

I want to note here, for the record, that the supposed Weiss gun was not a revolver, but an FN Model 1910 pistol. As a matter of fact, it was this one.

I don’t know what to think about Long and Weiss. I’m inclined more in the direction of T. Harry Williams (who was writing close enough to the event that he could interview some first-hand witnesses, and believed that Weiss shot Long) than I am towards some of the later historians. On the other hand, the whole thing is just such a mess of botched investigations and chain of custody questions (how did the Weiss gun and the bullet end up in that guy’s safety deposit box?) that I doubt we’ll ever know anything for sure.

Quel fromage!

Tuesday, August 13th, 2019

I don’t think this qualifies for flaming hyenas status. Yet.

The Santa Clara County District Attorney’s Office served a search warrant at the Sheriff’s Office last week, as part of an apparent corruption probe into allegations of political favoritism in the agency’s issuing of concealed weapons permits, according to sources familiar with the investigation.

…sources confirmed that the investigation involves an alleged “quid pro quo” between donors to six-term Sheriff Laurie Smith’s election efforts and people who have obtained concealed-carry weapons permits from her office, which has been relatively stingy about issuing the privilege compared to neighboring counties.
The sources also said that the probe, while publicly surfacing over the past few days, had been in the works far longer and that it is focused on some of Smith’s trusted advisers in the agency.

…at least four recipients of the 13 permits either issued or renewed last year donated at least $1,000 to Smith’s re-election efforts, including to her formal campaign or to the independent Santa Clara County Public Safety Alliance that supported her.
That includes match.com founder and Santa Clara County Valley Water District board member Gary Kremen, a Los Altos resident who donated $5,000 to the safety alliance group last fall, during Smith’s re-election bid for a sixth term.

Black Hat/DEFCON 27 links: August 13, 2019.

Tuesday, August 13th, 2019

I had a lot of trouble finding this on the site, but: the DEFCON 27 media server is here.

I’ve got to wrap this up for now, as my lunch hour is almost over. I may try to do a second post tonight, if I find enough additional material to justify one. Otherwise, please share, enjoy, comment, and thank any presenters whose work you found particularly enjoyable or valuable.

Obit watch: August 13, 2019.

Tuesday, August 13th, 2019

Dorothy Olsen. She was 103 when she passed away on July 23rd.

You’ve probably never heard of her, but she was one of the WWII Women Airforce Service Pilots (WASPs). The WASPs ferried military aircraft from manufacturing plants to points where they could then be flown overseas.

Transporting and testing the latest models, towing targets and transferring captured enemy planes, the WASPs collectively flew an estimated 60 million miles from 1942 to 1944. Thirty-eight died in accidents during training or on duty.
From her base in Long Beach, Calif., Mrs. Olsen flew 61 missions for the Sixth Ferry Group in nearly two dozen models, including P-38s, P-51s and B-17s. She flew them to West Coast airfields to be deployed in the Pacific, or to Newark to be deployed in Europe.

The WASPs were initially considered to be civil service employees and not military.

The WASPs were finally recognized as veterans eligible for benefits in 1977 under President Jimmy Carter. In 2010 they received as a group the Congressional Gold Medal, one of the nation’s two highest civilian awards.

According to the paper of record, Ms. Olsen’s death leaves 38 surviving WASPs.

Henri Belolo, co-founder (with Jacques Morali) of the Village People.

I love the caption on that first photo.

TMQ Watch: August 2019.

Monday, August 12th, 2019

Looks like the NFL is getting fired up again.

Yes, the loser update will return this year. We haven’t sat down to consider which teams are likely candidates for the Owen-16 trophy, but maybe we’ll get some time to do that between now and the start of the regular season.

But we are sure everyone is asking this question: what of Gregg Easterbrook and “Tuesday Morning Quarterback”? Has he found a new home, since the “Weekly Standard” folded up their tent and headed into the long dark night? And what of “TMQ Watch”? Will that be a recurring feature next year?

To answer the last question first: sadly, no. No “TMQ Watch” in 2019. Why?

Not our choice, Easterbrook’s. We may try to keep an eye on his Twitter feed for noteworthy items relating to the NFL. But we’ve found that Easterbrook’s Twitter feed is a reliable way of pressure testing our cerebral arteries, so we don’t recommend making bets on how much and how often we’ll be doing that.

Bagatelle (#13)

Saturday, August 10th, 2019

Every now and then, I see a story in one of the papers and think to myself, “Dick Wolf’s going to get an episode of ‘Law and Order: Kinky Sex Crimes’ out of this one.”

Today is the first time I’ve ever thought “Dick Wolf’s going to get an entire season of ‘L&O:KSC’ out of this story.”

Black Hat/DEFCON 27 links: August 9, 2019.

Friday, August 9th, 2019

Some more stuff I’ve stumbled across from Black Hat:

I expect to be somewhere between slightly and highly busy this weekend, so updates will be catch as catch can. It might be Monday before I can pull more stuff together, but I’ll try as best as I can to get updates before then.