Category Archives: Security

Car-2-Car System Risks

I stepped out of my home the other day and saw a man laying on the ground, his new scooter a few feet away on the ground leaking oil. A small crowd had gathered around him as he described his injuries and what had happened. “A woman in a car just swerved from the far right over to the left and hit me” he said as he nursed his left shoulder and minded a scrape to his ankle. The armored jacket and helmet had clearly helped avoid further injury. He should have been wearing boots.

It seemed highly plausible that someone trying to make a last-minute left turn had decided it would make sense to abruptly cross three lanes without signaling and did not see a scooter coming. She might not have even looked at all and thought she could react in time if something appeared. After she hit the man, she apparently told a pedestrian she was going to park and then come back. Of course she never returned.

I immediately thought a vehicle sensor system could have saved this man and his scooter from injury, and perhaps even given him the identification information of the driver who swerved.

On the flip side, what if the car had some kind of positioning radar that showed another moving object within close proximity and therefore gave a warning siren when the driver tried to steer towards it? This is the same basic system as people now have in their rear bumper for backing up in tight spaces, but would be based on more sophisticated in-flight sensors.

The downside to a system like this, I simply couldn’t avoid, would be all the regular privacy concerns. In particular, should the system capture VIN and/or plate information? That would be useful in a hit-and-run scenario. Both of these could hardly be called secret information, but the ability to collect them remotely and compile them raises the risk to our privacy to a whole new level. Credit card security uses this line of reasoning; a person swiping a single card at a time is not a primary concern for data security standards, but a system that reads cards and stores the information is high risk.

I left the scene after helping move the scooter to a safe spot (it had toppled in the middle of a lane) and ensuring that the injured man was in good hands (rescue squad just pulling up).

Now I come to find out that something very similar to what I was thinking is already underway around the world:

The near-collision warning is a demonstration of technology that is expected to be rolled out to all shapes and sizes of cars in the coming years.

It is being developed by the European Car-2-Car consortium and is backed by General Motors, Audi, BMW, Fiat, Honda, Renault and a range of in-car hardware manufacturers and several universities.

The security implications of the system are absolutely stunning:

GPS tracks the position of the car while sensor data from the car – such as speed, direction, road conditions and if the windscreen wipers are on and if the brakes have been stamped on – is monitored by the on-board computer.

A wireless system similar to existing wi-fi technology – based on the 802.11p protocol – transmits and receives data to and from nearby cars, creating an ad-hoc network.

Data hops from car to car and the on-board computers can build a picture of road and traffic conditions based on information from multiple vehicles across a great distance.

Cars travelling in opposite directions can share information about where they have been and so informing each other about where they are going.

Wouldn’t you like to share all that information with a car nearby, especially someone you are trying to get away from? What about spoofed data or non-repudiation? How will this system handle people running secondary boxes to fool nearby drivers?

They say the system will rely on multiple signals, as though from multiple vehicles, but what is to stop someone from running five boxes themselves to get motorists to slow down (e.g. a cranky neighbor who wants cars in to slow while passing by)?

I suspect there will have to be a certificate system at the core of this and that begs the question of who will become the authority to all these devices? The government? Does that make them also the master repository of the information? Driving is said to be a privilege, not a right, so will someone make the case that it is ok to trace and trap the whereabouts of every vehicle at all times? Will code violations and fines be issued based on this system?

Professor Horst Wieker, from the department of telecommunications at the University of Applied Sciences, Saarbruck, said the aim was to create “foresighted driving”.

He said: “This technology allows us to build a short-range and long-range picture of road traffic conditions.

Further research brought me to a similar approach in 2004 at the University of Rutgers.

The intent sounds fine, except for the fact that there is no mention of the security implications of collecting this kind of information. Drivers tend to use and dispose of information immediately. No one at the scene of the accident could remember more than a few letters of the license plate from the car involved. Technology could certainly help, but at what level of new risk? Are people adequately assessing the security trade-offs of data generated by a peer-to-peer system? It does not appear so. I suspect the automobile manufacturers working on this do not have a strong consumer information privacy group or advocate in house. Time to propose another lower-risk way to assess traffic conditions?

Singapore seems to have a different approach that is already working, but they also apparently based their system upon reducing the environmental and economic impact of gridlock and accidents.

The Pig

by Roald Dahl

In England once there lived a big
And wonderfully clever pig.
To everybody it was plain
That Piggy had a massive brain.
He worked out sums inside his head,
There was no book he hadn’t read.
He knew what made an airplane fly,
He knew how engines worked and why.
He knew all this, but in the end
One question drove him round the bend:
He simply couldn’t puzzle out
What LIFE was really all about.
What was the reason for his birth?
Why was he placed upon this earth?
His giant brain went round and round.
Alas, no answer could be found.
Till suddenly one wondrous night.
All in a flash he saw the light.
He jumped up like a ballet dancer
And yelled, “By gum, I’ve got the answer!”
“They want my bacon slice by slice
“To sell at a tremendous price!
“They want my tender juicy chops
“To put in all the butcher’s shops!
“They want my pork to make a roast
“And that’s the part’ll cost the most!
“They want my sausages in strings!
“They even want my chitterlings!
“The butcher’s shop! The carving knife!
“That is the reason for my life!”
Such thoughts as these are not designed
To give a pig great piece of mind.
Next morning, in comes Farmer Bland,
A pail of pigswill in his hand,
And piggy with a mighty roar,
Bashes the farmer to the floor…
Now comes the rather grizzly bit
So let’s not make too much of it,
Except that you must understand
That Piggy did eat Farmer Bland,
He ate him up from head to toe,
Chewing the pieces nice and slow.
It took an hour to reach the feet,
Because there was so much to eat,
And when he finished, Pig, of course,
Felt absolutely no remorse.
Slowly he scratched his brainy head
And with a little smile he said,
“I had a fairly powerful hunch
“That he might have me for his lunch.
“And so, because I feared the worst,
“I thought I’d better eat him first. “

The pig clearly thought negotiation of terms, or finding common values, was out of the question.

Testing the One Child Rule

China’s rule for couples was to have only one child or face a financial penalty. This meant couples with more money could treat the law as a tax and simply pay their way to a larger family. That seems like an expected outcome. However, I just read the news about a more drastic evasive technique:

Some of the breaches of the one-child policy only came to light during corruption investigations.

One legislator had four children by four different mistresses.

The official Xinhua news agency said some officials had not been adequately punished for their birth-control crimes.

It argued that this failure to enforce the law within its own ranks had led to the decrease in the government’s ability to enforce its birth-control policy.

Step one, attain an official position. This is similar to the Bush administration’s philosophy of rule. Once in office, some leaders clearly think they rise above the law. For example, Bush sent out a clear “click-it or ticket” warning to all motorists, and then drove around in front of reporters without his seatbelt on. Minor nit, but it makes the point nicely. There are dozens of examples, all of which say Bush and his cabal would probably go out of their way to have many more children if a law was passed in America that forbid large families.

Step two, closely examine the terms of the regulation. Does an official with four mistresses count as four couples, each entitled to a single child, or is there a patriarchal subtext — a man can only have one offspring? Here too the Bush administration has shown it uses highly creative interpretations. Cheney might say he is in the executive branch when he wants its protection, but that he is not in the executive branch when he want to avoid its regulations. Clever fellow, some might say in the US, as the Bush games come to light and are argued out in public.

China says they are holding “corruption investigations”. In America…?

BioWillie, Foreign Policy, and the Evidence of Organics

Good news from the singer/songwriter about his support of the domestic production of fuel. Regulation has helped spur his efforts in the northwestern state:

Earlier this year Oregon lawmakers passed a series of bills aimed at kick-starting the state’s biofuels industry, including a requirement that all gasoline sold in Oregon be mixed with 10 percent ethanol after in-state production of ethanol reaches 40 million gallons per year.

A similar production target for biodiesel crops used for biofuel production will trigger a mandatory 2 percent blend in all diesel fuels sold in Oregon.

Naturally, the article includes the usual criticism about converting cropland into fuel and the risk of impacting the food markets. Unfortunately it does not provide any counter-points from folks who know this line of reasoning is poorly founded. Here are a few pointers:

  1. Oil for biodiesel is everywhere, not just crops, and so the plant can operate as a recycling plant to reduce landfill and waste
  2. Crops generally run in surplus with vast amounts of over-production leading to government subsidies to support produce that will never reach the market. This allows a shift of subsidies into innovation and research for fuel alternatives, without impacting availability of food.
  3. America has a long-standing claim that its giant surplus of food should be used for “humanitarian” missions overseas. The reality is that this aid was often leveraged for economic and military interests rather than pure humanitarian US foreign policy aims and can be traced to more global instability, not less.

And so forth…

On the last point, here is an example of the type of propaganda still available from the US Government:

To help consume surplus crops, which were depressing prices and costing taxpayers money, Congress in 1954 created a Food for Peace program that exported U.S. farm goods to needy countries. Policy-makers reasoned that food shipments could promote the economic growth of developing countries. Humanitarians saw the program as a way for America to share its abundance.

In the 1960s, the government decided to use surplus food to feed America’s own poor as well. During President Lyndon Johnson’s War on Poverty, the government launched the federal Food Stamp program, giving low-income persons coupons that could be accepted as payment for food by grocery stores. Other programs using surplus goods, such as for school meals for needy children, followed. These food programs helped sustain urban support for farm subsidies for many years, and the programs remain an important form of public welfare — for the poor and, in a sense, for farmers as well.

But as farm production climbed higher and higher through the 1950s, 1960s, and 1970s, the cost of the government price support system rose dramatically. Politicians from non-farm states questioned the wisdom of encouraging farmers to produce more when there was already enough — especially when surpluses were depressing prices and thereby requiring greater government assistance.

Apparently US farmers reached such levels of efficiency that the US government has been trying different methods of holding back production for over thirty years. Fast forward through the export-crises of the 1980s, when foreign buyers caused farmers in the US to cringe over a lack of demand, and you see even more reason why a jump in domestic demand for crop production makes economic sense.

This is further supported by the issue of farming for food-grade versus fuel-grade crops. Consumers love their perfect looking fruit and vegetables, don’t they. I’ll never forget when I heard Sir John Krebs, the head of the UK Food Standards Agency, suggest that this is why organics are popular:

The organic industry relies on image. […] Sir John said the only people who got value for money from organic food were those who wanted producers to adopt more holistic farming methods. He told the BBC: “They’re not getting value for money, in my opinion and in the opinion of the Food Standards Agency, if they think they’re buying food with extra nutritional quality or extra safety.

“We don’t have the evidence to support those claims.”

Duh. How sad is that?

First of all, people generally allow pesticides and non-holistic farming methods for the same reason that Sir John notes — consumers seek a particular image. Who wants a worm in their apple? Ick. That was the old image. The difference now is that a “holistic” image includes a measure of broad health risks that were previously ignored or understated. Who would rather have a brain tumor or kids with cancer than find a silly worm and cut it out of an apple? Yeah, that’s the new “image” consciousness about health and security that is far more realistic, in my experience.

Second, I really do not understand how the “don’t have evidence” argument creeps into the public representations of so many of these upper management types. If there is insufficient proof of harm or benefit, should a leader state that there is no risk or reward ahead? On the contrary, more intelligence is needed, not less. They should be calling for research, open dialog and a proper determination.

Here is one example of research results from 2007:

A ten-year study comparing organic tomatoes with standard produce found almost double the level of flavonoids – a type of antioxidant.

Flavonoids have been shown to reduce high blood pressure, lowering the risk of heart disease and stroke.

Here is another from 2005:

Drinking organic milk has more health benefits than drinking non-organic, a study has suggested.

[…]

It showed organic milk has higher levels of vitamin E, omega 3 essential fatty acids and antioxidants, which help beat infections.

The latter example is really good because it has this little nugget from the British Nutrition Foundation:

Even if regular milk is slightly lower in some nutrients than organic milk, chances are you will be already be meeting your dietary needs for these nutrients by consuming other foods.

Or maybe they’ll be sending out pills and injections to help compensate for the lack of nutrition? I’m sure the pharmaceutical companies love that line of reasoning. Why have family farms with useful produce when you can generate tons of tasteless, nutrition-less objects and create a whole industry for supplements? Wonder if they say the same thing about taste: don’t worry about the bland cardboard-like tomatoes, each one will be shipped with a lozenge to compensate by releasing simulated tomato flavor. And a smell market too…the possibilities are endless, in a non-holistic way if you see what I mean.

Rather than feed these substandard food-stuffs to people and try to supplement them with useful additives, perhaps it should be sent to the fuel supply and replaced with more substantive organics? One might argue the price of food could increase, but we should be realistic about actual consumer price index rates, and the greater cost-benefit of food in terms of health risk and nutrition. We should also remember cheap does not always mean the least expensive.

Let the facts roll in, and it should become clear that a domestic source of fuel made from recycled waste as well as holistically grown crops makes a lot of security sense.