Safe Speed Forums

The campaign for genuine road safety
It is currently Fri Aug 28, 2026 05:29

All times are UTC [ DST ]




Post new topic Reply to topic  [ 76 posts ]  Go to page Previous  1, 2, 3, 4  Next
Author Message
 Post subject:
PostPosted: Sun Jun 25, 2006 12:07 
Offline
Banned
Banned

Joined: Thu Apr 15, 2004 12:47
Posts: 2291
r11co wrote:
Idealism! I know of plenty coded security systems in
everyday use that are known to be compromised but the organisation using
the system, for reasons best know to themselves and the rest of us can only
speculate on, do not implement a security upgrade - even when a solution
exists and is available.


But that backs my assertions that this is likely, whatever. Even a poor quality
solution is tolerated in the scenario you suggest. I sincerely hope that
knowledgeable people like Lum and Willcove are commissioned for this
work because they seem to have a good handle on the constraints.

_________________
I stole this .sig


Top
 Profile  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 12:08 
Offline
Site Admin
User avatar

Joined: Sat Mar 06, 2004 06:46
Posts: 16903
Location: Safe Speed
basingwerk wrote:
SafeSpeed wrote:
And no frigging benefit once we have gone through all the pain - unless you count the ability to prosecute traceable people for technical offences.


I don’t think you can see the irony of using the Internet to promote your
Luddism! Do you think that the general transfer of “batch driven record
keeping with paper notifications” to “real-time online transaction systems”
will stop because SafeSpeed thinks computers are just a fad that provide
no benefits?

There is philosophical consistency in your views - you have made
all your thoughts on road safety (and other matters?) conform to your
hatred of the surveillance society. Yet you accept materialism with ease.
What has made you able to accept certain inevitable aspects of the
current way of living, and reject others? Could it be a love affair with the
car?


It's very simple - and also highly consistent.

Technology makes a fine servant, but a vile master.

_________________
Paul Smith
Our scrap speed cameras petition got over 28,000 sigs
The Safe Speed campaign demands a return to intelligent road safety


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 12:42 
Offline
User
User avatar

Joined: Tue Apr 13, 2004 18:41
Posts: 893
basingwerk wrote:
That is not the point of my pointers! Java tries to prevent pointers from being reassigned in the way Roger described. It is not like C/C++. I’ve asked him to produce a case in Java – perhaps you know how to reassign a pointer to a corrupt stack? Let me know if you manage it - avoidance of it could go in the requirements for any system.

As I wrote previously, you are thinking at too high a level. Perhaps a Java compiler/interpreter tries to prevent this - but what do you thing the computer actually executes? (Flashback to The Matrix - do you think that's air you're breathing?) The pointer exists at a particular address and points to an executable block, complete with data, at another part of memory. All that is needed is to change the value stored at the first address - and you can do that outside Java. So, if pointers are used no language can completely prevent redirection.

Now for something that might shock you: Every language uses pointers because that's how computers work.
Code:
LDA FF EA 08 43
The above bit of pseudo assembler loads the accumulator with the address of the next piece of code to execute, or the start of a data block - seems like a pointer to me. If you're not already familiar with 6502, 8086, et al. Assembler, you might find 2GLs an eyeopener. If you don't mind the headaches, delving into 1GLs might worry you more.

So, all digital computers use pointers. Their system of registers make this inevitable. This means that your requirement cannot be met in todays systems and I can't see a way of meeting that requirement in any digital system.

basingwerk wrote:
Yes, but why do you talk of invincible computer-based systems? Do you know of invincible anything-based systems? Hm…

Now, on a practical level, is it easier to
1) Put a Guinness bottle label in the tax disc holder?

There is a huge difference. Putting a Guiness bottle lable in a tax disc holder invalidates a very small part of the system. In your brave new world, a successful attack could bring the entire system down. In extremis nobody would be allowed to travel because the road system would probably "fail safe" to the fiscal benefit of the Government - red-lighting anyone the system did not recognise until a human could "deal with" the miscreant (how else could you automatically police this). Enough "sheeple" would obey the red lights to prevent anyone from moving and people might die in the ensuing chaos.

basingwerk wrote:
As for the unknowns, they’ll come to light when they happen and be fixed, so all your comments lack relevancy in that respect.

We cannot afford that approach. How many people would you have die because the country ground to a halt as another of the "irrelevant unknowns" become known?

basingwerk wrote:
So, in the light of all that, do you doubt that new technology for will be used for establishing identity?

My fear is that it will be used and when (not if) the system fails, the "computer" rather than the truth will be believed. We've already seen some of your brave new world in the article reported here, in the Times. The victim was hounded for over two years for 52 offences he did not commit, including one motoring offence that has cost him over £30,000 to defend. At one hearing, the prosecution claimed that the defendant had been excused because he was in prison for wounding - at which point he jumped to his feet and said: “No, I am not. I’m here.” At one hearing, he was threatened with being charged with contempt of court for trying to explain that it was a case of mistaken identity.

Further reliance on technology rather than common sense to establish identity can only cause more such harm.

_________________
Will


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 13:13 
Offline
Friend of Safe Speed
Friend of Safe Speed
User avatar

Joined: Sun Sep 25, 2005 10:16
Posts: 7986
Location: Moved to London
“JAVA, buffer overflow, pointers, 2GLs…….”

This is all very clever (and TBH completely over my head) but surely other such workarounds exist? How about packet sniffing and cloning? Take the example of the MPAA and the new fangled HCDP protocols within the DVI-D and HDMI systems: this was meant to take piracy (and fair use :roll: ) beyond the common man; this system isn’t yet adopted - but HCDP stripper boxes already exist!!!!

The above isn’t intended as a catalyst for a technical discussion; my point is that we’re gonna have to accept that there are one or two very clever individuals out there who will happily sell their solutions against such security measures to whoever can afford it (those who profit from crime). Instead of being hurdles, we should be trying to make MOTs, insurance and law enforcement fair and desirable. All this high-tech RFID business will become another burden which won’t really accomplish anything except further screw the taxpayer.


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 13:19 
Offline
Friend of Safe Speed
Friend of Safe Speed

Joined: Sat Mar 06, 2004 12:01
Posts: 4815
Location: Essex
smeggy wrote:
Instead of being hurdles, we should be trying to make MOTs, insurance and law enforcement fair and desirable. All this high-tech RFID business will become another burden which won’t really accomplish anything except further screw the taxpayer.
:clap: :angel: :clap: :angel:

Exactly - technology should facilitate the good. Whilst it has a place in preventing the bad, it has never been able to, cannot now, and never will be able to replace the mark one human being. As Paul says, it makes a fine servant and a vile master.


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 13:27 
Offline
User
User avatar

Joined: Tue Apr 13, 2004 18:41
Posts: 893
Roger wrote:
As Paul says, it makes a fine servant and a vile master.

:clap:
This is the whole point - we have to be very careful not to give an artifact "the last say". Every system (computerised or otherwise) can be compromised. We need to accept that fact and properly plan for when (not if) it happens.

_________________
Will


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 13:33 
Offline
Banned
Banned

Joined: Thu Apr 15, 2004 12:47
Posts: 2291
willcove wrote:
Every language uses pointers because that's how computers work.


Here's an article about eggs, willcove -

http://en.wikipedia.org/wiki/Egg_%28food%29

Read up on it, then go and teach your grandmother how to suck them.

willcove wrote:
In extremis nobody would be allowed to travel because the road system would probably "fail safe" to the fiscal benefit of the Government - red-lighting anyone the system did not recognise until a human could "deal with" the miscreant (how else could you automatically police this). Enough "sheeple" would obey the red lights to prevent anyone from moving and people might die in the ensuing chaos.


Good - at last a requirement we can nail down - Any system must NOT
perform as willcove describes in section X1
. So that's that. We’ll test
that the system responds proportionately to emergency breakdowns and
such like, and contains a manual override, or whatever else you like. Next
please <DING>.


willcove wrote:
basingwerk wrote:
As for the unknowns, they’ll come to light when they happen and be fixed, so all your comments lack relevancy in that respect.


We cannot afford that approach. How many people would you have die
because the country ground to a halt as another of the "irrelevant
unknowns" become known?


Covered by the second requirement - Any system must NOT allow the
country to grind to a halt as willcove describes in section X2
. Next
please <DING>.


willcove wrote:
My fear is that …


Right, another requirement from willcove - we're knocking them on the
head, here. Covered by the third requirement - when the system fails,
the truth will be believed, not the computer, as willcove describes in
section X3
. Next please <DING>.

_________________
I stole this .sig


Top
 Profile  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 13:34 
Offline
Banned
Banned

Joined: Thu Apr 15, 2004 12:47
Posts: 2291
Roger wrote:
Exactly - technology should facilitate the good. Whilst it has a place in preventing the bad, it has never been able to, cannot now, and never will be able to replace the mark one human being. As Paul says, it makes a fine servant and a vile master.


Then get involved with the requirements for the new system. Willcove has
been very helpful so far.

_________________
I stole this .sig


Top
 Profile  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 13:41 
Offline
Member
Member

Joined: Fri Apr 22, 2005 10:30
Posts: 2053
Location: South Wales (Roving all UK)
Bloody hell I seem to have spawned a tech fest!

I think the concesus is that there is noe not practical reason for the tax disc or VED....so therefore why does it exist?

Even before the data bases and tech stuff the disc could have been replaced by MOT and Insurance 'Discs', but there was obviously no will why?

Politics...Seriously think of the jobs. When DVLC, as it was then called, along with the stats office and other things were posted out to the regions one of the primary reasons behind this was to reallocate governement jobs to regions that needed them most....those suffereing from the effects of the decline in industry e.g south wales. VED and the 'DISC' have been overtaken by events and to my mind simply exist to maintain employment and therefore votes.

Its perfect we pay for VED, VED pays for the jobs . How many pointless jobs are we subsidising.

Not unlike another cottage industry that we pay for, doesn't come out of central taxation, but has little effect other than to provide employment....can anyone guess what I'm thinking about?


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 13:46 
Offline
User
User avatar

Joined: Tue Apr 13, 2004 18:41
Posts: 893
Basingwerk wrote a lot of stuff about how he would specify the requirements for an RFID system. However, I'm not convinced that his requirements are measureable with full confidence, or even realistic or achievable. Most importantly, I'd love to see his test plan to ensure:
Quote:
when the system fails, the truth will be believed, not the computer
Perhaps several decades in the industry, reinforced by the recently reported case of Roderick Rigby, have made me too cynical to believe that such a requirement (which is almost certainly outside the scope of the system) could ever be met!

Edited in light of civil engineer's post:

My apologies for getting sucked into a tech fest!

Bottom line: VED is unnecessary and should be replace with a fairer tax (like increased fuel duty). RFID is unnecessary and can be compromised. It offers little more than registration plates to identify a vehicle and hence deduce whether that vehicle has insurance etc. For every RFID application that I can think of, ANPR can do the job without the same security risks.

_________________
Will


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 14:21 
Offline
Gold Member
Gold Member

Joined: Sat Apr 16, 2005 14:55
Posts: 134
Location: Hérault, France
Setting aside theft of disc or being too stupid to display it, the current system is very good at being correct with respect to which vehicles are taxed and which aren't.

Moving from this to a system of harassing motorists on the basis of a database, the quality of which will only ever decrease over time, is asking for trouble.

It doesn't matter how much it costs, it will be less reliable than the current system.


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 14:24 
Offline
Friend of Safe Speed
Friend of Safe Speed
User avatar

Joined: Sun Sep 25, 2005 10:16
Posts: 7986
Location: Moved to London
basingwerk wrote:
Here's an article about eggs, willcove -

http://en.wikipedia.org/wiki/Egg_%28food%29

Read up on it, then go and teach your grandmother how to suck them.

:rotfl:

Here’s another article about eggs:

http://en.wikipedia.org/wiki/Easter_egg_(virtual)

;)

you'll need to copy and paste the whole text into your browser


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 16:11 
Offline
User

Joined: Wed Mar 10, 2004 15:05
Posts: 1225
Location: Glasgow
basingwerk wrote:
Any system must NOT
perform as willcove describes in section X1
. So that's that. We’ll test
that the system responds proportionately to emergency breakdowns and
such like, and contains a manual override, or whatever else you like. Next
please <DING>.

Any system must NOT allow the
country to grind to a halt as willcove describes in section X2
. Next
please <DING>.

when the system fails,
the truth will be believed, not the computer, as willcove describes in
section X3
. Next please <DING>.


More idealism. Do I need to explain why you can't always get what you want? Each of these requirements cannot be achieved without introducing expolitable weaknesses in the system. Back to square one.

There are very few, if any, organisations who have the wherewithal or the means to win or at least maintain the advantage in the cat-and-mouse game that is digital security (ever heard of NDS?!).

Governments with fixed budgets and who are entirely at the mercy of private organisations who sell them their solutions will never be in a position to do it.


Last edited by r11co on Sun Jun 25, 2006 16:16, edited 1 time in total.

Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 16:12 
Offline
Gold Member
Gold Member

Joined: Fri Sep 24, 2004 23:26
Posts: 9268
Location: Treacletown ( just north of M6 J3),A MILE OR TWO PAST BEDROCK
Tax on fuel , we've got -alongside VED. Being cynical ,HMG can increase both slightly and make a tidy sum , with the apathy in force by the UK motoring public. Group them into one and the increase could break the apathy .

Apart from that - how many people in DVLA depend on VED for a job. Could HMG live with the reaction of redundancies ??. But then these people might just be moved sidesways, making for a higher rate of tax to fund the move ?? :lol:

_________________
lets bring sanity back to speed limits.
Drivers are like donkeys -they respond best to a carrot, not a stick .Road safety experts are like Asses - best kept covered up ,or sat on


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 16:53 
Offline
Banned
Banned

Joined: Thu Apr 15, 2004 12:47
Posts: 2291
willcove wrote:
Most importantly, I'd love to see his test plan to ensure:
Quote:
when the system fails, the truth will be believed, not the computer
Perhaps several decades in the industry, reinforced by the recently reported case of Roderick Rigby, have made me too cynical to believe that such a requirement (which is almost certainly outside the scope of the system) could ever be met!


Yes, you are right - you were thinking at a "TechFest" level when
you implied that justice is “outside the scope” of the requirements for
changes to the road system – we would not dispense with it so lightly.

I’m heartened that you concede the system we have is too poor and that
methods to establish identity must be hardened to stop more “Roderick
Rigby” cases. That's a start, at least.

But the requirements you specified are mandatory, for any
acceptable system, which counts the current system out, doesn’t it? You
quote the case of case of Roderick Rigby's cloned plates, then imply ANPR
is fine. I don't get it, willcove - are plates reliable for ID purposes, or not?
If not, why support them, and if they are, why quote “Roderick Rigby”?
Straighten this out, can’t you?

PS - what side is the match on, and what time?

_________________
I stole this .sig


Top
 Profile  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 17:02 
Offline
Banned
Banned

Joined: Thu Apr 15, 2004 12:47
Posts: 2291
r11co wrote:
basingwerk wrote:
blah blah blah - Next
please <DING>.


More idealism. Do I need to explain why you can't always get what you want?


Another good point from r11co - the common case of the conflicting
requirement. And the solution must be to make the system consistent, so
something has to give. To decide, we ask what is important and what will
it cost.

If identity is not important, then ANPR is fine. So is identity important in a
road system? If it turns out that it is, the system will go in. And coppers,
politicians, and many members of the public think it is important to know
who is at the site when crimes occur. It’s just the way it is, old bean.

When is this football on the tele? What channel? Should I drink Danish or
Dutch lager?

PS: these are just my opinons, anway - who really knows - gosh, the footies on. Tara!

_________________
I stole this .sig


Last edited by basingwerk on Sun Jun 25, 2006 17:05, edited 1 time in total.

Top
 Profile  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 17:05 
Offline
Gold Member
Gold Member

Joined: Fri Sep 24, 2004 23:26
Posts: 9268
Location: Treacletown ( just north of M6 J3),A MILE OR TWO PAST BEDROCK
[quote="basingwerk


When is this football on the tele? What channel? Should I drink Danish or
Dutch lager?[/quote]

Footie is on now - lager - your choice - suggest waffles might ( in your case ) be a good accompanyment.

_________________
lets bring sanity back to speed limits.
Drivers are like donkeys -they respond best to a carrot, not a stick .Road safety experts are like Asses - best kept covered up ,or sat on


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 17:11 
Offline
User
User avatar

Joined: Tue Apr 13, 2004 18:41
Posts: 893
basingwerk wrote:
You quote the case of case of Roderick Rigby's cloned plates, then imply ANPR is fine. I don't get it, willcove - are plates reliable for ID purposes, or not? If not, why support them, and if they are, why quote “Roderick Rigby”? Straighten this out, can’t you?

I did not say that ANPR is fine! Certainly. ANPR is flawed and allowing data collected from ANPR to override the truth is wrong. What I said was "for every RFID application that I can think of, ANPR can do the job without the same security risks." This doesn't mean that I support ANPR or consider it to be fine - just that it is less prone to the security risks present in RFID.

_________________
Will


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 17:16 
Offline
User
User avatar

Joined: Thu Apr 28, 2005 00:01
Posts: 2258
Location: South Wales
I can't be bothered to go back and find the posts I'm replying to since there's been about 20 new ones in the last 12 hours but..

Basingwerk wrote about how the government will be implementing each phase of the project in small leaps quietly, eg. photo ID, ANPR etc. etc.

This I agree with, in as much as I agree that this is exactly what the government are doing, bringing in a new system completely by stealth under the guise of lots of smaller less significant changes that people aren't going to get too riled up about because it's not that different. It's just when you put them all together that you have something monstrous.


On security, any system worth cracking will get cracked eventually, systems not worth cracking will generally get left alone or just become the target of bored script kiddies who will relish the opportunity to call the system's owner a fag or other childish insults. This is how Microsoft got away with such poor security for so long. When everyone was on dial-up, Windows boxes wern't worth compromising, now we have broadband, an individual windows box makes a great spam relay and now we need to secure our Windows boxes.

My problem with any new system is not that it will be widely exploited by the general public, when that happens it will almost certainly be fixed, but that the criminals who have most to benefit will find ways to abuse or circumvent the system and will do so quietly, will keep their exploits to themselves without telling anyone else how to do it and will remain undetected, meanwhile the innocent victims who have had their identity stolen will have a much harder time proving their innocence (Computar says no *cough*) as the system is perceived to be secure. We are already seeing this with chip&pin (see other thread) and I see no reason wy this will be any better.


Basingwerk pointed out that the internet was a government IT project, therefore my assertation that government IT projects usually fail is wrong.

Actually that was the US government.. or rather it was the US military. The internet in the UK was a university thing, not a government thing.


Basingwerk seems to think that me and others are luddites and that it is ironic to promote luddism on the internet.

No, just concerned that any computer system is insecure if there is sufficient motive to break into it. At least with a physical break-in it's usually pretty obvious that something has happened, wheras with computer systems it's often not the case.
As for using the internet to do it. If the safespeed forums are hacked it's ultimately not a big deal (though Paul may disagree), the worst that will happpen is my e-mail address will end up on someone's spam list and I will have to block all email to the address I gave to this forum, also I'll lose the ability to come here and argue with trolls :)

If the government's new motoring database is hacked, then some mafia drug baron could be driving around broadcasting my car details to the RFID readers landing me with parking fines, congestion charges and a visit from the police who suspect me of drug trafficking.

The only way to make a system work correctly all the time is to disconnect it from any network, have perfect physical security and don't let the users anywhere near it. Anything else is vulnerable.

And being a government IT project, it'll probably go to a bunch of muppets who will write half of it in PHP or something stupid.


Top
 Profile Send private message  
 
 Post subject:
PostPosted: Sun Jun 25, 2006 18:30 
Offline
Gold Member
Gold Member

Joined: Fri Sep 24, 2004 23:26
Posts: 9268
Location: Treacletown ( just north of M6 J3),A MILE OR TWO PAST BEDROCK
As i mentioned - where would all the DVLA staff go - but from this

http://driving.timesonline.co.uk/articl ... 51,00.html

Thats £6M for little work.If they scrapped the tax disk, the DVLA staff would not be needed and a new department would be needed to bring in the bacon from the sale of data on registrations.

However the last line in this is good news--
"The Department for Transport expressed concern about the “number and breadth” of companies accessing information after an earlier Sunday Times exposé last August. It is expected to conclude a review of the practice before the end of the year. "

_________________
lets bring sanity back to speed limits.
Drivers are like donkeys -they respond best to a carrot, not a stick .Road safety experts are like Asses - best kept covered up ,or sat on


Top
 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 76 posts ]  Go to page Previous  1, 2, 3, 4  Next

All times are UTC [ DST ]


Who is online

Users browsing this forum: No registered users and 206 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You can post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
[ Time : 0.112s | 11 Queries | GZIP : Off ]