cypherpunks-legacy
Threads by month
- ----- 2026 -----
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2004 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2003 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2002 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2001 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2000 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1999 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1998 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1997 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1996 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1995 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1994 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1993 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1992 -----
- December
- November
- October
- September
- 130025 discussions
"Tyler Durden" writes:
> So my newbie-style question is, is there an eGold that can be verified, but
> not accessed, until a 'release' code is sent?
>
> In other words, say I'm buying some hacker-ed code and pay in egold. I don't
> want them to be able to 'cash' the gold until I have the code. Meanwhile,
> they will want to see that the gold is at least "there", even if they can't
> cash it yet.
>
> Is there a way to send a 'release' to an eGold (or other) payment? Better
> yet, a double simultaneous release feature makes thing even more
> interesting.
I've been thinking about how to do this kind of thing with ecash.
One project I'm hoping to work on next year is a P2P gambling game (like
poker or something) using my rpow.net which is a sort of play-money ecash.
You'd like to be able to do bets and have some kind of reasonable
assurance that the other guy would pay up if he loses.
In the case of your problem there is the issue of whether the source
code you are buying is legitimate. Only once you have inspected it and
satisfied yourself that it will suit your needs would you be willing
to pay. But attaining that assurance will require examing the code in
such detail that maybe you will decide that you don't need to pay.
You could imagine a trusted third party who would inspect the code and
certify it, saying "the source code with hash XXX appears to be legitimate
Cisco source code". Then they could send you the code bit by bit and
incrementally show that it matches the specified hash, using a crypto
protocol for gradual release of secrets. You could simultaneously do
a gradual release of some payment information in the other direction.
If you don't have a TTP, one idea for using ecash is Markus Jakobsson's
"Ripping Coins for a Fair Exchange". Basically you withdraw ecash from
your account and in effect "rip it in half" and give half to the seller.
Now he gives you the product and you give him the other half of the coin.
The idea is that once you have given him the "ripped" ecash ("torn"
would be a better word because ripping means something else today),
you are out the value of the cash. You have no more incentive to cheat,
as giving him the other half won't cost you anything additional.
(Even without ecash, a service like egold could mimic this functionality.
You'd create an escrow account with two passwords, one known to each
party. Only with both passwords could data be withdrawn from the account.
Then the buyer would transfer funds into this account. After receiving
the goods, the buyer would send his password to the seller.)
The problem is that if the source code you are purchasing is bogus,
or if the other side doesn't come through, you're screwed because you've
lost the value of the torn cash. The other side doesn't gain anything
by this fraud, but they harm you, and if they are malicious that might
be enough. And likewise you might be malicious and harm them by refusing
to give them your half of the coin even after you have received the goods.
Again, this doesn't benefit you, you're still out the money, but maybe
you like causing trouble.
Another idea along these lines is gradual payment for gradual release
of the goods. You pay 10% of the amount and they give you 10% of the
source code. You pay another 10% and you get the next 10% of the source,
and so on. (Or it could be nonlinear; maybe they give out half the code
for free, but the final 10% requires a large payment.) The idea is that
you can sample and make sure they do appear to have the real thing with
a fairly small investment.
If there is some mechanism for the seller to have a reputation (like
Advogato's perhaps, with some spoofing immunity) then the problem is
easier; the seller won't want to screw buyers because it hurts his rep.
In that case it may be reasonable to ask the buyer to pay in advance,
perhaps using the partial payment system just discussed.
These various ideas all have tradeoffs, and in general this kind of
problem is hard to solve because of the complexity of what constitutes a
successful transaction. A reputation system helps a great deal to resolve
the issues, but opens up problems of its own. The betting problem I
want to work on is relatively easy because there is no ambiguity about
who wins, but even then it is hard to make sure that neither party can
maliciously harm the other.
Hal F.
4
3
<http://biz.yahoo.com/prnews/041105/sff023_1.html?printer=1>
Yahoo! Finance
Source: Cryptography Research, Inc.
Cryptography Research VP Benjamin Jun Takes Aim at Content Pirates
Friday November 5, 6:02 am ET
Discusses Technology Trends and Responses at Upcoming RSA Conference Europe
2004
SAN FRANCISCO, Nov. 5 /PRNewswire/ -- Despite piracy's high public profile
as a threat to intellectual property owners, surprisingly little has been
done to understand the range of technical solutions that are feasible,
according to security expert Benjamin Jun. With piracy plaguing deployments
of pay TV, optical media, console video games and other content, Jun, vice
president of engineering at Cryptography Research, Inc., believes content
publishers facing these issues have a number of tools and technologies at
their disposal to take aim at the pirates, and will discuss solutions and
the findings of his recent research on piracy in his seminar on Friday,
November 5 at the RSA Conference Europe 2004 being held in Barcelona, Spain.
According to Jun, pirates will grow bolder and more effective with advances
in CPU processing power, Internet bandwidth and hard drive storage.
Although piracy cannot be stopped completely, Jun believes a combination of
proactive and reactive security approaches can mitigate the risk and reduce
losses to survivable levels. Content publishers facing piracy can apply
methods for high-assurance design that anticipate attacks and employ
architectures that enable a response after attacks happen. Jun's talk
discusses recent piracy trends, describes industry techniques and presents
current research in content security.
"Although numerous products and technologies have been advertised as
solutions to the problem of piracy, most commercial security systems fail
catastrophically once an implementation is compromised, making them
inappropriate solutions for deployment as part of a major standard, said
Jun. "Piracy, like credit card fraud and computer virus security, is a
problem that cannot be solved completely, and requires a flexible solution
that combines programmable security and 'smart content' with risk
management techniques such as forensic marking and attack response
capabilities."
Proactive security combines tamper resistance with high-assurance design to
combat known security vulnerabilities. Reactive systems provide effective
tools for responding to piracy after a problem develops. These results are
findings of the Cryptography Research Content Security Initiative, a
CRI-sponsored, multi-year research effort focusing on understanding and
controlling piracy, technology trends in consumer electronics and
next-generation applied techniques for high-assurance security.
"Content providers must face next-generation pirates by selecting
technology that avoids a repeat of painful past lessons," said Carter
Laren, senior security architect at Cryptography Research. "We are proud
that results from our Content Security Research Initiative are helping
leading companies secure their most valuable content."
Benjamin Jun's talk, "Piracy: Technology Trends and Responses," part of the
Implementers Educational Track at the RSA Conference Europe 2004, will be
presented on Friday, November 5, at 11:00 a.m. at the Princesa Sofia Hotel
in Barcelona, Spain.
Benjamin Jun is a vice president of engineering at Cryptography Research,
where he heads the consulting practice and the company's Content Security
Research Initiative. He leads engineering groups in the design, evaluation
and repair of high-assurance security modules for software, ASIC and
embedded systems. Ben holds B.S. and M.S. degrees from Stanford University,
where he is a Mayfield Entrepreneurship Fellow.
About Cryptography Research, Inc.
Cryptography Research, Inc. provides consulting services and technology to
solve complex security problems. In addition to security evaluation and
applied engineering work, CRI is actively involved in long-term research in
areas including tamper resistance, content protection, network security and
financial services. The company has a broad portfolio of patents covering
countermeasures to differential power analysis and other vulnerabilities,
and is committed to helping companies produce secure smart cards and other
tamper-resistant devices.
Security systems designed by Cryptography Research engineers annually
protect more than $60 billion of commerce for wireless, telecommunications,
financial, digital television and Internet industries. For additional
information or to arrange a consultation with a member of the technical
staff, please contact Jen Craft at 415-397-0123, ext. 329 or visit
www.cryptography.com.
Source: Cryptography Research, Inc.
--
-----------------
R. A. Hettinga <mailto: rah(a)ibuc.com>
The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
44 Farquhar Street, Boston, MA 02131 USA
"... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
2
1
"A prince is a bandit who doesn't move." --Mancur Olsen
Cheers,
RAH
--------
<http://online.wsj.com/article_print/0,,SB109962052189665752,00.html>
The Wall Street Journal
November 5, 2004
COMMENTARY
A Gangster With Politics
By BRET STEPHENS
November 5, 2004; Page A12
In 1993, the British National Criminal Intelligence Service commissioned a
report on the sources of funding of the Palestine Liberation Organization.
For years, it had been Chairman Yasser Arafat's claim that he'd made a
fortune in construction as a young engineer in Kuwait in the 1950s, and
that it was this seed money, along with a 5% levy on the Palestinian
workers in Arab League countries, which kept the PLO solvent. But British
investigators took a different view: The PLO, they concluded, maintained
sidelines in "extortion, payoffs, illegal arms-dealing, drug trafficking,
money laundering and fraud," bringing its estimated fortune to $14 billion.
In retrospect, it would seem amazing that 1993 was also the year in which
the head of this criminal enterprise would be feted on the White House lawn
for agreeing peace with Israel. But then, so much about the 1990s was
amazing, which is perhaps why Arafat, of all people, thrived in that time.
The ra'is, as he is commonly spoken of among Palestinians, may basically
have been a gangster with politics, but he was also one of the 20th
century's great political illusionists. He conjured a persona, a cause, and
indeed a people virtually ex nihilo, then rallied much of the world to his
side. Now that he is dead, or nearly so -- news reports vary as of this
writing -- it will be interesting to see what becomes of his legacy.
Who was Yasser Arafat? For starters, he was not a native Palestinian,
although his parents were and he variously claimed to have been born in
Gaza or Jerusalem. In fact, he was born and schooled in Cairo, spoke Arabic
with an Egyptian accent, and took no part in the 1948 Arab-Israeli war, the
Nakba (catastrophe) which Palestinians regard as their formative national
experience. Nor did Arafat take part in the Suez War, again despite later
claims to the contrary.
But this was the period of Third World ferment -- of the "anti-colonialist"
Bandung politics of Indonesia's Sukarno, Algeria's Ben Bela, Cuba's Fidel
and Egypt's Nasser -- and at the University of Cairo Arafat became a
student activist and head of the Palestine Student Union. He also began
developing the Arafat persona -- kaffiyah, uniform, half-beard and later
the holstered pistol -- to compensate for his short stature and pudginess.
The result, as his astute biographers Judith and Barry Rubin write, "was
his embodiment of a combination of roles: fighter, traditional patriarch,
and typical Palestinian."
Around 1960, Arafat co-founded Fatah, or "conquest," the political movement
that would later come to be the dominant faction of the PLO. Aside from its
aim to obliterate Israel, the group had no particular political vision:
Islamists, nationalists, Communists and pan-Arabists were equally welcome.
Instead, the emphasis was on violence: "People aren't attracted to speeches
but to bullets," Arafat liked to say. In 1964, Fatah began training
guerrillas in Syria and Algeria; in 1965, they launched their first attack
within Israel, on a pumping station. But the bomb didn't detonate, and most
of the other Fatah raids were also duds. From this experience, Arafat took
the lesson to focus on softer targets, like civilians.
So began the era of modern terrorism: the 1972 Munich massacre, the 1973
murder of American diplomats in Khartoum, the 1974 massacre of
schoolchildren at Ma'alot, and so on. Yet as the atrocities multiplied,
Arafat's political star rose. Partly this had to do with European
cravenness in the face of the implied threat; partly with the Left's secret
love affair with the authentic man of violence. Whatever the case, by 1980
Europe had recognized the PLO, with Arafat as its leader, as the "sole
legitimate representative" of the Palestinian people. The U.S. held out for
another decade, but eventually it too caved in to international pressure
under the first Bush administration.
For the Palestinians themselves, however, this was not such a good
development. If Arafat's violence against Jews and Israelis was shocking,
his violence against fellow Palestinians was still worse. In the manner of
other would-be national liberators, he did not look kindly on dissenters
within his ranks. In 1987, for instance, Palestinian cartoonist Ali Naji
Adhami was murdered on a London street; his crime was to have insinuated in
a drawing that the ra'is was having an affair with a married woman.
Once in power in Ramallah, the abuses became much worse. Critics of his
government were routinely imprisoned and often tortured. In 1999, Muawiya
Al-Masri, a member of the Palestinian Legislative Council, gave an
interview to a Jordanian newspaper denouncing Arafat's corruption. He was
later attacked by a gang of masked men and shot three times. (He survived.)
Yet for all this, Arafat continued to ride the wave of international
goodwill. The Europeans gave him the Nobel Peace Prize. The Clinton
administration saw him as the one man who could "deliver" the Palestinians
to make peace with Israel. The peace camp in Israel, championed by the late
Yitzhak Rabin and Shimon Peres, more or less agreed: to them, Arafat was
the thug who'd keep the Palestinian street quiet. Arafat strung them along,
more or less, until his bluff was called by the Israeli peace offer at Camp
David in July 2000.
After that, there was just no point in keeping up appearances, and so came
the intifada. It was a premeditated act. As Arafat had already told an Arab
audience in Stockholm in 1996, "We plan to eliminate the State of Israel
and establish a purely Palestinian state. We will make life unbearable for
Jews by psychological warfare and population explosion . . . . We
Palestinians will take over everything, including all of Jerusalem."
It goes without saying that Arafat failed in that endeavor. The Israelis
belatedly realized that the maximum they could concede was less than the
minimum Arafat would accept, and refused to deal with him. For its part,
the Bush administration cut off the international life support. In this
sense, Arafat's illness -- so far undisclosed by his doctors -- can easily
be diagnosed: He died of political starvation.
What remains? Very little, I suspect. None of his deputies can possibly
fill his shoes, which are those of a personality cult, not a political or
national leader. There is nothing to unite Palestinians anymore, either:
their loyalties to the cause will surely dissipate in his absence. Arafat
was remarkable in that he sustained the illusion he created till the very
end. But once the magician walks off the stage, the chimera vanishes.
Mr. Stephens, former editor in chief of the Jerusalem Post, is a member of
the Journal's editorial board.
--
-----------------
R. A. Hettinga <mailto: rah(a)ibuc.com>
The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
44 Farquhar Street, Boston, MA 02131 USA
"Camels, fleas, and princes exist everywhere." -- Persian proverb
1
0
<http://www.worldtribune.com/worldtribune/breaking_10.html>
Mrs. Arafat keeps husband
on life support
Where's his money?
Special to World Tribune.com
GEOSTRATEGY-DIRECT.COMThursday, November 4, 2004
RAMALLAH - Palestinian Authority Chairman Yasser Arafat has died. He was
75 years old.
Israeli and Palestinian officials said Arafat died on Thursday in a
military hospital in Paris. They said Arafat was deemed clinically dead,
but is still attached to life support systems on the insistence of his
wife, Suha.
Palestinan Authority's Yasser Arafat: Abbas and Qurei sought to acquire
his power to allocate money as the PA chairman departed for Paris. But as
he boarded a Jordanian Air Force helicopter, Arafat refused. "I'm still
alive, thank God, so don't worry," Arafat was quoted as saying.
Reuters/Loay Abu Haykel
"He is dead, but neither Arafat's wife nor the Palestinian leadership is
ready to announce this," a PA official said. "The announcement could take
place on Friday."
The problem is that Arafat is still the only Palestinian official who can
pay the bills. And it is unclear who, if anyone, has access to the
estimated $2-3 billion in his personal Swiss bank accounts, according to a
report in the current edition of Geostrategy-Direct.com. Even his wife is
said to be unaware of how to access the funds.
Arafat continues to hold the purse strings to the Palestinian finances.
For the last decade, he has been the final, and often only word on payment
to everybody from the suicide bomber to the janitor. Not a dime was paid
without Arafat's okay.
Before he left for Paris, Arafat approved a three-member emergency
committee to operate the PA and PLO in his absence. Officials said Ahmed
Qurei was meant to run the PA's daily affairs while Mahmoud Abbas was
appointed acting chairman of the PLO.
Palestine National Council chairman Salim Zaanoun, the third member of the
committee, was said to be a symbolic figure.
Abbas and Qurei sought to acquire Arafat's power to allocate money during
the absence of the PA chairman. But as he boarded a Jordanian Air Force
helicopter for Amman, Arafat refused.
"I'm still alive, thank God, so don't worry," Arafat was quoted as saying.
Israeli officials confirmed that Arafat died on Thursday, Middle East
Newsline reported. They said Arafat was termed brain dead and physicians
have stopped attending to him.
For Palestinians, the main question is where is Arafat's money?
Issam Abu Issa knows how Arafat appropriated and concealed money. Abu Issa
was the founder and chairman of the Palestine International Bank from 1996
until he fled to Qatar in 2000.
"Rather than use donor funds for their intended purposes, Arafat regularly
diverted money to his own accounts," Abu Issa said in a report for Middle
East Quarterly. "It is amazing that some U.S. officials still see the
Palestinian Authority as a partner even after U.S. congressional records
revealed authenticated PLO papers signed by Arafat in which he instructed
his staff to divert donors' money to projects benefiting himself, his
family and his associates."
Arafat controls billions of dollars meant for the Palestinian people. In a
word, he stole it, intelligence sources said, according to the
Geostrategy-Direct report.
His personal fortune has been estimated at between $2 and $3 billion, most
of it in Swiss bank accounts.
In 1997, the PA auditor's office said in its financial report that $326
million, or 43 percent of the annual budget, was "missing."
The United States has been supporting former PA security chief Mohammed
Dahlan as Arafat's successor. To his friends in the Bush administration,
Dahlan, 43, has all the qualities for Arab leadership: a smooth talker and
brutal cop. Arafat asked Dahlan to accompany him to Paris in a move
designed to keep him out of the Gaza Strip and any coup plot.
Another challenger has been Fatah Secretary-general Marwan Barghouti,
sentenced to life in prison for a series of terrorist attacks. Barghouti,
44, has followers in the West Bank but does not appear to have the iron
will necessary to face Arafat loyalists.
Neither Israeli nor PA officials have been told much about Arafat's
condition, and the only one authorized to issue information from his
hospital bedside is the chairman's wife, Suha.
--
-----------------
R. A. Hettinga <mailto: rah(a)ibuc.com>
The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
44 Farquhar Street, Boston, MA 02131 USA
"... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
1
0
<http://www.meforum.org/article/645> ?
- Middle East Quarterly - Fall 2004
FALL 2004 * VOLUME XI: NUMBER 4
Arafat's Swiss Bank Account
by Issam Abu Issa
Yasir Arafat and the Palestinian Authority are known internationally for
the violence between Israelis and Palestinians. As ruinous as that violence
has been, another cancer permeates Arafat's administration; its name is
corruption. From firsthand experience, I understand just how deep it is.
Here is what I know.
>From Optimism to Dismay
On July 1, 1994, the Palestine Liberation Organization (PLO) chairman,
Yasir Arafat, arrived triumphant in the Gaza Strip, watched by millions on
television across the world. I was already in Ramallah, having traveled
there from my family's exile in Qatar in the weeks after Arafat, Israeli
Prime Minister Yitzhak Rabin, and President Bill Clinton had signed the
Oslo accords in September 1993. Between 1994 and 1996, I and fellow
Palestinian businessmen and intellectuals spent many days brainstorming to
see what contributions we could make to a Palestinian state. My family was
originally from Haifa, and I hoped to witness an Israeli withdrawal of
forces and the birth of a democratic Palestinian state. It was a time of
optimism among Palestinians. I gathered with friends and business partners
around the television in Ramallah and watched Arafat's arrival in the Gaza
Strip.
In 1996, I founded the Palestine International Bank (PIB). Thousands of
Palestinians in the Palestinian Authority (PA) and the diaspora supported
me financially or morally. My investors and I hoped to build a thriving
economy in the newly autonomous PA areas. The PIB was truly Palestinian.
Headquartered in Ramallah, it used mostly Palestinian capital, although it
did receive support from other Arabs. All its reserves were kept inside
Palestinian areas, and our shares traded actively on the Palestinian stock
exchange. From nothing, we expanded our customer base to more than 15,500.
Among those licensed by the newly established Palestine Monetary Authority
(PMA), we were the largest bank in the Palestinian territories.
I first met Arafat in April 1995 while trying to secure a banking license
for the PIB. This meeting at his Gaza office, though brief, was cordial and
encouraging. I thought things would go smoothly. But, as the PIB grew more
popular, Arafat's inner circle and, specifically, Muhammad Rashid, a PA
official, also known as Khalid Salam and often described as an economic
advisor to Arafat and manager of a small percentage of PIB stocks, made it
difficult for us to branch out and move forward.[1] The PA, which strictly
controls Palestinian media, launched a negative media blitz against us in a
bid to suppress our growth. The systematic effort to undermine PIB came
after I refused to cede power to Muhammad Rashid.[2]
Over the course of fifteen meetings, I became better acquainted with Arafat
and grew increasingly concerned with his leadership style. Arafat and top
PA officials did not respect the rule of law; many were corrupt. Arafat
believed neither in separation of powers nor in checks and balances. His
animosity toward accountability thwarted efforts to establish a responsible
leadership. By 1996, Palestinians in the PA were saying they had traded one
occupation for two, the one by Israel and the one by Arafat and his cronies.
Rather than use donor funds for their intended purposes, Arafat regularly
diverted money to his own accounts. It is amazing that some U.S. officials
still see the Palestinian Authority as a partner even after U.S.
congressional records revealed authenticated PLO papers signed by Arafat in
which he instructed his staff to divert donors' money to projects
benefiting himself, his family, and his associates.[3]
How did Arafat's inner circle benefit? In 1994, he instructed the
Palestinian Authority official in charge of finances, Muhammad Nashashibi,
to fund secretly-to the tune of $50,000 per month-a Jerusalem publicity
center for Raymonda Tawil, Arafat's mother-in-law, and Ibrahim Qar'in, an
associate of Arafat's family.[4] He also ordered the investment in the
computer companies of 'Ali and Mazzan Sha'ath, sons of Nabil Sha'ath, the
PA's key negotiator in talks with Israel. Amin Haddad, Arafat's designated
governor of the Palestine Monetary Authority, established several
import-export companies acting as the front man for Arafat. The Palestinian
Economic Council for Development and Reconstruction financed these
activities.[5] Thus, an organization meant to channel funds from donor
countries like France and Germany became a mechanism by which to enrich
Arafat.
Arafat's men flagrantly displayed corruption. Arriving penniless in Gaza
and the West Bank from exile in Tunisia, many PLO members amassed wealth,
built villas in Gaza, Ramallah, Amman, and other places, and sent their
children to the best schools in the United Kingdom and the United States.
Hisham Makki, former head of the Palestine Broadcasting Services,
assassinated in January 2001, earned a monthly salary of $1,500 but became
a millionaire within a few years. Immediately after his assassination,
Arafat froze Makki's personal bank accounts, estimated at $17 million.
Makki was alleged to have taken bribes and sold government-owned equipment.
However, it was rumored that he had a dispute with another PA official over
the sharing of profits gained on illegal business transactions. His
assailants, believed to be members of the Al-Aqsa Martyrs' Brigades, a
shady group affiliated with Fatah, have never been caught.[6]
Palestinians complained. The corruption of Arafat and the Palestinian
Authority were blatant, but it appeared as if their status quo policies
caused Israel and the United States to turn a blind eye. Diplomats
downplayed flagrant corruption. In August 2001, Israel seized close to a
half million documents from Palestinian offices in Jerusalem and elsewhere.
Subsequent State Department reports on Palestinian governance and terrorism
made little use or even mention of these documents.[7] European and U.S.
policymakers assumed Arafat's critics to be against the Oslo accord. That
may have been the case with members of Hamas and Palestinian Islamic Jihad,
but it was not the case among more liberal-minded Palestinians and
investors like me.
Arafat's corruption reached its peak in 1999 via the monster of "twelve
security forces that nobody could control,"[8] in addition to the
disorganized Tanzim (Fatah's militia). He played these services off each
other, never allowing a subordinate to gain power. Between 1995 and 2000,
Arafat's thugs beat up at least eleven elected members of the 88-member
Palestinian Legislative Council (PLC) because they voiced views in private
and in public that were opposed to Arafat's on how the PA is run. The
victims included PLC Human Rights Committee head Qaddoura Fares, Azmi
ash-Shoaibi, Abdul Jawad Saleh, Hatem Abdul Kader, among others. Arafat
wanted to terrorize and silence his critics. Indeed, one of his favorite
slogans was Dimuqratiyat al-Banadiq (Democracy of the Guns). Arafat
believes true power lies in force, whether directed against Israelis or
against his own people.
How popular is Arafat among Palestinians? At times of crisis, television
crews show cheering Palestinians demonstrating and greeting their leader
outside his Ramallah headquarters. In better days, Palestinian television
regularly broadcasts pro-Arafat rallies across the West Bank and Gaza
Strip. But rallies aren't always what they seem. PA funds are used to buy
loyalty and drum up support.[9] The PA hires crowds, stages promotional
media campaigns, and distributes Arafat's pictures in the streets and
alleys of the Palestinian territories. Rather than build a viable state,
Arafat sought only to amass wealth and power. I myself heard his entourage
and close associates refer to him as al-Arrab, meaning "the Godfather."
At the end of 1997, when the PA Auditor's Office released its end of the
year financial report, $326 million-43 percent of the annual budget-was
"missing."[10] Only 57 percent of the budget was accounted for, spent on
security forces (35 percent), office of the president (12.5 percent), and
public allocation (9.5 percent). A special committee appointed by the PLC
conducted an investigation and released a report accusing the PA of
financial mismanagement. The findings of this panel exposed many official
misgivings and abuses such as the use of government money for personal
purposes by ministers Nabil Sha'ath, Talal Sidr, and Yasir Abd Rabboh;
excessive expenditure on rent, salaries, and cost of travel in various
ministries; receipt of bribes by ministry officials in the Ministry of
Civil Affairs; illegal and unreported collection of taxes by the Ministry
of Postal Services; granting illegal customs exemptions on cars, furniture,
and material donations entering the PA, etc. It concluded that anyone
involved in corruption should be taken to court, regardless of his position
as minister, undersecretary, or director-general. The report demanded the
ouster of at least two ministers: civil affairs minister Jamil at-Tarifi,
and planning and international cooperation minister Nabil Sha'ath.[11]
The PLC voted 51-1 in favor of dissolving Arafat's appointed 18-member
limited self-rule cabinet. Sixteen ministers gave letters to Arafat
signaling readiness to resign if asked. But Arafat confirmed the corrupt
ministers in their positions rather than firing them. Additionally, PLC
member Haider Abdel Shafi resigned due to "frustration with the performance
of the PLC and with the executive's total lack of concern for its
recommendations," and added, "The PLC is a marginal body and not a true
parliament."[12]
Even as the PLC committee was conducting its investigation, Arafat
appointed Tayeb Abd al-Rahim, general secretary of the Presidential Office,
to make a detailed inquiry into acts of corruption. His report remains
secret.
In practice the reports were meaningless. Since Arafat does not honor rule
of law, decisions by auditors or the Palestinian Legislative Council fall
by the wayside. Corruption continues. More than six years after the
report's issuance, Tarifi remains in the cabinet. Rather than face charges,
Sha'ath has won promotion.
In another case, Salam Fayyad, the official in charge of finance, again
said in August 2003 that there were many "irregularities" in the work of
the Petroleum Authority, which has been siphoning money to secret bank
accounts for years.[13] When Nablus legislator Mu'awyah al-Masri asked for
details and figures about the revenues from oil products, Fayyad shocked
the lawmakers by declaring, "Unfortunately, the documents related to the
revenues from oil products-or how the money was used-can't be found. They
have disappeared from the ministry."[14]
The bank accounts of Harbi Sarsour, head of the Petroleum Authority, were
frozen by the PA pending investigation into the scandal. But an initial
investigation by Fayyad's office and the PLC showed that much of the oil
profits had been deposited into a bank account under Arafat's name.[15]
For sheer scale, few allegations match up to a deal allegedly struck
between Muhammad Rashid, one of Arafat's economic advisors, and the late
Yossi Ginosar, a former Israeli security officer. Ginosar's company, ARC,
helped open Swiss bank accounts and deposit funds into them derived from
both PA-financed companies and Israeli tax rebates to the Palestinian
Authority.[16] Over a period of five years, approximately US$900 million
was diverted to these accounts.[17]
In early 2002, the Palestinian Center for Policy and Survey Research
conducted a poll in which they surveyed 1,320 Palestinians. Eighty-five
percent believed that there was corruption in PA institutions; only 16
percent gave a positive evaluation to democracy under the Palestinian
Authority. Eighty-four percent expressed support for fundamental reforms in
the PA.[18]
Arafat Robs the Palestine International Bank
On November 28, 1999, I became a victim of Arafat's abuse of power and
flagrant disregard for the law. That's when, in direct breach of the law,
Arafat issued a decree dissolving the Palestine International Bank's board
of directors. The state-controlled Palestine Monetary Authority took over
the bank, and with Arafat's blessing and written approval,[19] formed a new
supervisory board of directors, including at least one convicted and
Interpol-wanted felon. The unlawful takeover was a confiscation of my own,
my shareholders', and my clients' private assets for Arafat's personal use.
At the date of seizure, PIB total assets amounted to $105 million. Since
the takeover, they have neither called for a shareholders' meeting nor
disclosed the bank's balance sheet.
The PLC investigated the seizure of the bank after I lodged a complaint in
2000 about the PIB's unlawful takeover. The PMA governor then threatened
the bank's auditing firm, Talal Abu Ghazaleh International (TAGI), for
revealing facts and figures that implicated the Palestinian leadership. The
PMA governor took punitive measures against them but was unanimously
condemned by the PLC.[20] Meanwhile, the PMA altered, hid, or destroyed
bank records in their campaign to demonstrate malfeasance on my part
retroactively. They supplied false information to the
PricewaterhouseCoopers (PWC) group leading to a faulty audit. PWC seems to
have taken for granted the accuracy of material that PMA governor Amin
Haddad supplied, but he both provided some fraudulent documents and omitted
others. The Qatari government, which has remained interested in the case
because of my Qatari citizenship, rejected the PWC Report.[21]
As they seized the bank, Arafat's security services harassed me. I fled to
the Qatari mission in Gaza. Arafat's staff confiscated my private
belongings, including my car, which Arafat took for himself.[22] My brother
Issa accompanied a Qatari Foreign Ministry delegation to Gaza in order to
resolve the stalemate. But, upon his arrival, Palestinian police acting on
orders from Arafat arrested him. The PA said they would trade his freedom
for mine. Only after the State of Qatar threatened Arafat with financial
sanctions and severing of diplomatic ties did the PA give us free passage
to leave Gaza for Qatar.
In recent months, there has been some movement on my case. After months of
investigation and deliberation, the Palestinian Legislative Council ruled
all decisions taken by the PMA on the matter of PIB to be illegal, and
hence subsequent actions to be illegitimate.[23] Chiefly because of his
mismanagement of the PIB case and citing corruption, in May 2004, the PLC
fired Amin Haddad from his position in the Palestinian Monetary
Authority.[24] Hassan Khreisheh, Palestinian deputy parliament speaker,
said, "This is part of the parliament's war against corruption in the
PA."[25] He pointed out that Haddad had been pocketing unauthorized bonuses
and profiting illegally from his management of the PIB. In spite of this,
Arafat continues to back Haddad. As Khreisheh says, "Arafat resists any
change, but pressure is building against him."[26] Arafat's support for
Haddad is magnified in his August 5, 2004 letter to the PLC Reform
Committee. He stated, "Firing the governor of the PMA would serve our
enemies."[27] By "enemies," he was referring to, among others, myself and
the deputy prime minister of Qatar, Sheikh Hamad bin Jassim bin Jabor
ath-Thani, whom he mentioned more than three times before several PLC
members.
The PLC also indicted Arafat's relative, Jarrar al-Kudwa, who headed the
General Monitoring Board that functions as the PA's Controller's Office,
for corruption and misleading the investigation into the seizure of the
PIB.[28]
On June 18, 2004, the evening after the Jordanian daily Ad-Dustur published
the Khreisheh interview cited above, Arafat ordered his Special Security
Apparatus to arrest one of my sympathizers in Ramallah. Thus does Arafat
continue to use the Palestinian security forces to harass and intimidate
anyone who questions his pocketbook. It is no surprise then that he issued
clear instructions to PA officials not to discuss openly the PIB issue. To
him, the matter is an extremely important issue.[29]
I have very little faith in the Palestinian judicial system, which is fully
under Arafat's thumb. The PA disregards many court decisions unless they
serve Arafat's purposes. Chief Justice Zuhair as-Sourani usually acts on
Arafat's orders.[30] Arafat and Sourani handpicked Judge Talaat Taweel in
order to pass the civil judgment against me in absentia. Taweel has been
implicated in criminal cases.[31] Likewise, the PLC's Human Rights
Committee condemned Sourani's illegal actions. Earlier, while an attorney
general, Sourani issued an arrest warrant against me but failed to produce
any legal basis before the PLC; he merely acted on Arafat's verbal
instruction.[32] Arafat subsequently promoted him to chief justice.
The continuing decay of the judicial system prompted the Union of
Palestinian Lawyers to launch a short boycott of the Palestinian court
system on June 28, 2004.[33] Union leader Hatem Abbas remains a vocal
critical of judicial corruption. On September 26, 2004, he sent a strongly
worded letter regarding Sourani's malpractice.
And just recently, the PLC decided to suspend all sessions from September 7
to October 7, 2004, in an attempt to pressure Arafat to accelerate the
approval of a reform package that he publicly adopted on August 18, 2004,
and in protest against the Palestinian cabinet for not implementing the
decisions and bills approved by the PLC.[34] The PLC wants to stress that
the council's decisions have to be taken seriously.
The Cement Scandal
Abuse of power among Arafat's associates and Palestinian ministers is not
the exception but rather the rule, as shown by the cement scandal: PA
officials were accused of selling cement to Israel for use in constructing
the West Bank wall and for Israeli construction in the disputed
territories, then pocketing the money.
On February 11, 2004, Israel's Channel 10 television reported that the
Al-Quds Cement Factory supplied the cement for these purposes. Television
footage showed cement mixers leaving company headquarters and driving to
Maale Adumim, an Israeli settlement a few kilometers away. The family of
Prime Minister Ahmad Qureia co-owns the Al-Quds company. When confronted by
the allegations at a June 2004 press conference in Rome, Qureia denied
personal involvement.[35]
On June 9, 2004, the PLC held a debate in which some legislators accused
Maher Masri, who held the Palestinian Authority's economy portfolio, of
negligence and fraud. Council members called for an investigation on
"corruption and tax evasion" charges.[36] Despite the charges, the debate
itself was stilted. Palestinian security ejected PLC deputy and
anti-corruption campaigner Jawad Saleh from the debate after the PLC
speaker prevented nine deputies who had conducted the investigation from
participating in the debate.[37]
The scandal reportedly started with an Israeli-German businessman named
Zeev Blenski. Blenski sought to import 120,000 tons of Egyptian concrete
but, the Egyptian firms, under pressure from Egypt's anti-Israel lobby,
refused to provide it. Blenski then turned to the Tarifi Ready Mix Cement
Company, owned by Civil Affairs Minister Jamil Tarifi and his brother Jamal
and two other Palestinian cement companies, Intisar Barakeh Company for
General Trade and the Yusef Barakeh Company for General Trade.[38]
Tarifi got Masri to sign an import permit. In fact, "senior PA officials
had received bribes to issue import licenses to several importers and
businessmen working on behalf of Israelis."[39] The permits directed the
cement to be used to rebuild homes in the Rafah refugee camp, which had
been razed by Israeli troops.[40] Instead, Blenski sold the cement to build
parts of the separation fence, as well as new houses in Jewish communities
in the West Bank and Gaza.[41]
The PLC report concluded that the cement scandal went against PA objectives
by indirectly contributing to the separation barrier but also by
undermining the Palestinian treasury through the failure to collect tax on
the imported cement. Lastly, because the Palestinians still operate under
annual cement importation quotas, PA officials' greed undercut the
Palestinian construction sector.[42] The PLC passed the report to the
district attorney, but no action has yet been taken. Few Palestinians
expect that action will be taken.
Surprise in New York
Pressure for reform is waning, and Palestinian democrats are caught in the
middle. On February 13, 2004, I arrived at JFK International Airport in New
York on my way to testify about PA corruption before the U.S. House
Financial Services Committee. It was not my first trip to Washington; I
have been there a half dozen times and have never faced any difficulties.
My most recent visit had been a year before when I addressed both the
Hudson Institute and The Foundation for the Defense of Democracy on
democracy and Palestinian reform.[43]
But, this trip was different. Instead of breezing through customs as I had
in the past, agents from the Department of Homeland Security's Bureau of
Immigration and Customs Enforcement kept me in custody for seventeen hours.
At some point, I was cuffed at the wrists and ankles and repeatedly
interrogated by agents who accused me of laundering $6 million from the PIB
on behalf of the Palestinian Islamic Jihad. They let me go, but I now
cannot gain entry to the United States. While dozens of academics signed
petitions in support of a visa for Tariq Ramadan, the grandson of the
founder of the Muslim Brotherhood, my case generated only silence in
American universities.[44]
Why the change? PA officials passed the charge to the State Department,
which forwarded the information uncritically to Homeland Security.[45] This
is ironic since the PIB leadership installed after my ouster was implicated
in money laundering for Saddam Hussein.[46] The U.S. embassy in Doha has
sought to rectify the matter, and I was allowed to reapply for a new visa;
the case is still pending. But splashed across the Arabic press, the
message was clear: Foggy Bottom supports Arafat and will turn a blind eye
toward the concerns of dissidents.[47] It is counterproductive for
Washington to indulge Arafat to the extent that they pull the rug out from
anyone trying to make a change. Recent chaos in Gaza reinforces that
Washington should not put all its eggs in one basket. But, how can
Palestinian administration improve if the U.S. government allows Arafat to
use its bureaucracy to do his dirty work? Accountability is key.
Conclusion
For four years, there has been violence and unmasked hostility between
Israeli and Palestinians. Palestinian security forces and Israeli soldiers,
who once jointly patrolled the streets of West Bank and Gaza towns, now
fight each other. The conflict has taken a heavy toll on human life and on
resources, both among Palestinians and Israelis. Israeli authorities and
Palestinian organizations estimate the total dead at almost 4,000 and the
wounded at more than 32,000.[48] The ailing Palestinian economy has
declined 25 percent in 2003[49] while Israel has lost billions of dollars
due to recession in the tourism sector and declining investor confidence.
When I see cars blown apart by missiles, buses and cafes on the streets of
Jerusalem and Tel Aviv destroyed, as well as destruction and death in Gaza
and the West Bank, or pictures of grieving mothers and daughters, it is
hard to believe that it has been only eleven years since the world
celebrated the promise of the Oslo accords. I have problems with Israeli
policies in the West Bank and Gaza Strip, but Arafat's leadership for too
long has used Israel as an excuse for failure to clean our own house.
Arafat's failed leadership is one factor responsible for the evolution of
Palestinian extremism and fundamentalism, as well as a culture of death and
despair among the Palestinians. While Clinton feted Arafat at the White
House as a peace partner, many of us who worked with or lived under Arafat
disagreed, seeing him instead as a man exclusively concerned with power,
money, and personal gratification. He heads a dictatorial regime staffed by
gangsters.[50] I and increasing numbers of Palestinians also blame U.S. and
Israeli officials who, in the wake of the Oslo accords, calculated that a
Palestinian dictatorship would make a better negotiating partner than a
Palestinian democracy.[51] They were very wrong. When growing pressure in
the Palestinian territories forced Arafat to find a scapegoat for his
political failure, mismanagement, and economic plunder, he turned his guns
toward the Israelis.
Reform and Arafat are like oil and water. Arafat instigates violence to
deflect blame for his own corruption. No amount of dialogue or diplomatic
dinners will change this fact.
On the positive side, there are still persons who can move the
peace-building process ahead. Many Palestinians seek change and welcome
democratization and good governance. The Palestinians have the wealth,
talent, and skills to carry out major functions for the needed
transformation. Young economic leaders could spearhead the process since
economic growth and development are fruits of peace. The Palestinian
private sector and civil society organizations can be mobilized and
empowered in order to foster the democratization process.
With the right support, the Palestinians are capable of leading a real
transformation towards a democratic state, one characterized by a
separation of powers, the rule of law, a free market economy, and a strong
civil society.
America should not be discouraged by what is going on in the Middle East
today. Signs of freedom and reform abound. But, Washington must look
forward and not revert to the formulas of the past. Palestinians want not
only to be freed from Israeli control but also, as importantly, to end the
occupation by Arafat and his cronies.
Issam Abu Issa, former chairman of the Palestine International Bank,
currently resides in Qatar. He is founder of the Palestinian National
Coalition for Democracy and Independence, a Palestinian democratic reform
movement.
[1] Interview with Palestinian deputy speaker, Ad-Dustur (Amman), June 17,
2004.
[2] Lamis Andoni, "Palestine Banking Trouble," Middle East International,
Jan. 28, 2000, p. 10.
[3] "Scandalous PLO Letters Authenticated by Congressional Task Force,"
Manfred and Anne Lehmann Foundation (New York), at
http://www.manfredlehmann.com/sieg429.html.
[4] Ibid.
[5] Ibid.
[6] Khaled Abu Toameh, "Corrupt Palestinian Officials Said Fleeing in Fear
for Their Lives," The Israel Report, Jan./Feb. 2001, at
http://www.christianactionforisrael.org/isreport.
[7] Matthew Levitt, "PLOCCA 2002: Empty Words," The Washington Institute
for Near East Policy, Peacewatch #384, May 24, 2002, at
http://www.washingtoninstitute.org/watch/Peacewatch/peacewatch2002/384.htm.
[8] Mahmoud Abbas, ex-Palestinian prime minister, quoted in Newsweek, June
21, 2004.
[9] Nathan Vardi, "Auditing Arafat," Forbes.com, Mar. 17, 2003, at
http://www.forbes.com/global/2003/0317/014.html.
[10] The Washington Post, Dec. 2, 1998.
[11] PLC Special Committee Report (The Corruption Report,) May 1997, at
http://www.jmcc.org/politics/pna/plc/plccorup.htm; Stacey Lakind and Yigal
Carmon, "The PA Economy," The Middle East Media Research Institute (MEMRI),
Inquiry and Analysis Series, no. 11, Jan. 8, 1999, at
http://www.memri.org/bin/opener.cgi?Page=archives&ID=IA1199.
[12] Arjan El Fassed, "Cement and Corruption," The Electronic Intifada,
June 11, 2004, at http://electronicintifada.net/v2/article2813.shtml.
[13] Khaled Abu Aker, "Where Has All the Oil Money Gone?" Arabic Media
Internet Network, Aug. 11, 2003, at http://www.amin.org.
[14] The Jerusalem Post, Dec. 3, 2003.
[15] Ibid.
[16] Ma'ariv (Tel Aviv), Dec. 2, 2002, Mar. 7, 2004.
[17] Press briefing, International Monetary Fund, Dubai, UAE, Sept. 20,
2003, at http://www.imf.org/external/np/tr/2003/tr030920.htm.
[18] The Palestinian Center for Policy and Survey Research, Public Opinion
Poll #5, Aug. 18-21, 2002, at
http://www.pcpsr.org/survey/polls/2002/p5a.html.
[19] Appointment letter signed by Arafat, May 24, 2003, Palestinian Court
of First Instance.
[20] PLC decision, no. 626/1/8, Oct. 25, 2003.
[21] Letter, signed by Muhammad Jeham al-Kuwari, then-director of the
Office of the Foreign Minister of Qatar, to the late Yassin Shareef,
Palestinian ambassador to the state, Ministry of Foreign Affairs, Qatar,
Aug. 30, 2000, at http://www.palestine77.net/kuwari.pdf.
[22] Focus Magazine (Munich), Dec. 16, 2002, p. 208.
[23] PLC decision, no. 642/1/8, Dec. 30, 2003.
[24] Associated Press, May 5, 2004.
[25] Ibid.
[26] Newsweek International, Aug. 30, 2004.
[27] "Report of the Special Reform Committee," PLC, Aug. 25, 2004, p. 6.
[28] The Jerusalem Post, Jan. 18, 2004.
[29] Tahseen Al Miqati, Palestinian ambassador to Qatar, quoted in Forbes
(Arabic edition), May 2004, p. 88.
[30] "Position Paper -Re: The Case of Palestine International Bank," Jan.
23, 2004, co-signed by four Palestine-based NGOs: the Mandela Institute for
Human Rights, Al-Haq, Al-Quds Human Rights Center, Al-Dustour, at
http://www.palestine77.net/ngoenglish.doc.
[31] Ad-Dustur, June 17, 2004.
[32] "Report of the Human Rights Committee," PLC, Dec. 2, 2003, p. 34.
[33] Al-Quds (Jerusalem), June 27, 2004.
[34] Palestine Media Center, Sept. 2, 2004, at
http://www.palestine-pmc.com/details.asp?cat=1&id=1422.
[35] Arjan El Fassed, "Cement and Corruption," The Electronic Intifada,
June 11, 2004, at http://electronicintifada.net/v2/article2813.shtml.
[36] Rouhi Fatouh, PLC speaker, quoted in The Jerusalem Times, June 18, 2004.
[37] The Jerusalem Post, June 21, 2004.
[38] The Jewish Tribune (Toronto), June 17, 2004.
[39] The Jerusalem Post, June 10, 2004.
[40] The Jewish Week (New York), June 25, 2004.
[41] Israel National News, June 13, 2004, at
http://www.israelnn.com/news.php3?id=63989.
[42] The Jerusalem Times, June 17, 2004.
[43] Feb. 6, 2003.
[44] "Tariq Ramadan: American and European Scholars Respond,"
Campus-Watch.org, Sept. 23, 2004.
[45] Amber Pawlik, "Exporting Freedom," May 9, 2004, at
http://www.mensnewsdaily.com/archive/p/pawlik/2004/pawlik050904.htm.
[46] The Peninsula (Doha), Apr. 13, 2003.
[47] "A Critic of Arafat Is Turned away at the U.S. Border-Reformer
Detained at Kennedy Was Headed to Meet Congress," The New York Sun, Feb.
17, 2004; "Standing up to Arafat," The Fox News, Feb. 23, 2004; Adam
Daifallah, "Arabs Who Believe in Democracy," The New York Sun, Feb. 23,
2004; "New York Authorities Detain PIB Chairman for 17 Hours at JFK
Airport," Ar-Raya (Doha), Feb. 19, 2004; "Story of the Detention of PIB
Chairman at the JFK Airport on Allegations of Financing Hamas and Jihad,"
Al-Hayat (London), Feb. 16, 2004.
[48] Casualty updates from Palestinian Red Crescent Society, at
http://www.palestinercs.org/crisistables/table_of_figures.htm, and Magen
David Adom of Israel, at
http://www.magendavidadom.org/casualtyitem.asp?Update=41.
[49] Palestine Investment Promotion Agency, at
http://www.pipa.gov.ps/economic_indicators.asp.
[50] Rafiq an-Natsheh, former PLC speaker, quoted in Asharq (Doha), July
20, 2004.
[51] Natan Sharansky, "From Helsinki to Oslo," Journal of International
Security Affairs, Summer 2001, at
http://www.jinsa.org/articles/articles.html/function/view/categoryid/1383/d…;
"Yasser Arafat: An Asset or a Burden. A Confidential Israeli Document,"
summarized by Mohammed Salah al-Attar, Nida Younis, trans., Ma'ariv, July
6, 2001, at
http://www.aljazeerah.info/News%20archives/2004%20News%20archives/Jan/13n/Y….
--
-----------------
R. A. Hettinga <mailto: rah(a)ibuc.com>
The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
44 Farquhar Street, Boston, MA 02131 USA
"... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
1
0
Click the link to see various formulae.
Cheers,
RAH
-------
<http://www.informit.com/articles/printerfriendly.asp?p=342039>
InformIT
Cryptography: Beginning with a Simple Communication Game
Date: Nov 5, 2004 By Wenbo Mao. Sample Chapter is provided courtesy of
Prentice Hall PTR.
In this introductory chapter from his book, Wenbo Mao uses a simple game
to demonstrate the complexity of cryptography, and its utility for your
business.
We begin this book with a simple example of applying cryptography to solve
a simple problem. This example of cryptographic application serves three
purposes from which we will unfold the topics of this book:
*
To provide an initial demonstration on the effectiveness and practicality
of using cryptography for solving subtle problems in applications
*
To suggest an initial hint on the foundation of cryptography
*
To begin our process of establishing a required mindset for conducting the
development of cryptographic systems for information security
To begin with, we shall pose a trivially simple problem and then solve it
with an equally simple solution. The solution is a two-party game which is
very familiar to all of us. However, we will realize that our simple game
soon becomes troublesome when our game-playing parties are physically
remote from each other. The physical separation of the game-playing parties
eliminates the basis for the game to be played fairly. The trouble then
is, the game-playing parties cannot trust the other side to play the game
fairly.
The need for a fair playing of the game for remote players will "inspire"
us to strengthen our simple game by protecting it with a shield of armor.
Our strengthening method follows the long established idea for protecting
communications over open networks: hiding information using cryptography.
After having applied cryptography and reached a quality solution to our
first security problem, we shall conduct a series of discussions on the
quality criteria for cryptographic systems ('1.2). The discussions will
serve as a background and cultural introduction to the areas in which we
research and develop technologies for protecting sensitive information.
1.1 A Communication Game
Here is a simple problem. Two friends, Alice and Boba, want to spend an
evening out together, but they cannot decide whether to go to the cinema or
the opera. Nevertheless, they reach an agreement to let a coin decide:
playing a coin tossing game which is very familiar to all of us.
Alice holds a coin and says to Bob, "You pick a side then I will toss the
coin." Bob does so and then Alice tosses the coin in the air. Then they
both look to see which side of the coin landed on top. If Bob's choice is
on top, Bob may decide where they go; if the other side of the coin lands
on top, Alice makes the decision.
In the study of communication procedures, a multi-party-played game like
this one can be given a "scientific sounding" name: protocol. A protocol
is a well-defined procedure running among a plural number of participating
entities. We should note the importance of the plurality of the game
participants; if a procedure is executed entirely by one entity only then
it is a procedure and cannot be called a protocol.
1.1.1 Our First Application of Cryptography
Now imagine that the two friends are trying to run this protocol over the
telephone. Alice offers Bob, "You pick a side. Then I will toss the coin
and tell you whether or not you have won." Of course Bob will not agree,
because he cannot verify the outcome of the coin toss.
However we can add a little bit of cryptography to this protocol and turn
it into a version workable over the phone. The result will become a
cryptographic protocol, our first cryptographic protocol in this book! For
the time being, let us just consider our "cryptography" as a mathematical
function f(x) which maps over the integers and has the following magic
properties:
Property 1.1: Magic Function f
I.
For every integer x, it is easy to compute f(x) from x, while given any
value f(x) it is impossible to find any information about a pre-image x,
e.g., whether x is an odd or even number.
Protocol 1.1: Coin Flipping Over Telephone
PREMISE
Alice and Bob have agreed:
i.
a "magic function" f with properties specified in Property 1.1
ii.
an even number x in f(x) represents HEADS and the other case represents TAILS
(* Caution: due to (ii), this protocol has a weakness, see Exercise 1.2 *)
1.
Alice picks a large random integer x and computes f(x); she reads f(x) to
Bob over the phone;
2.
Bob tells Alice his guess of x as even or odd;
3.
Alice reads x to Bob;
4.
Bob verifies f(x) and sees the correctness/incorrectness of his guess.
II.
It impossible to find a pair of integers (x, y) satisfying x y and f(x)
= f(y).
In Property 1.1, the adjectives "easy" and "impossible" have meanings
which need further explanations. Also because these words are related to a
degree of difficulty, we should be clear about their quantifications.
However, since for now we view the function f as a magic one, it is safe
for us to use these words in the way they are used in the common language.
In Chapter 4 we will provide mathematical formulations for various uses of
"easy" and "impossible" in this book. One important task for this book is
to establish various quantitative meanings for "easy," "difficult" or even
"impossible." In fact, as we will eventually see in the final technical
chapter of this book (Chapter 19) that in our final realization of the
coin-flipping protocol, the two uses of "impossible" for the "magic
function" in Property 1.1 will have very different quantitative measures.
Suppose that the two friends have agreed on the magic function f. Suppose
also that they have agreed that, e.g., an even number represents HEADS and
an odd number represents TAILS. Now they are ready to run our first
cryptographic protocol, Prot 1.1, over the phone.
It is not difficult to argue that Protocol "Coin Flipping Over Telephone"
works quite well over the telephone. The following is a rudimentary
"security analysis." (Warning: the reason for us to quote "security
analysis" is because our analysis provided here is far from adequate.)
1.1.1.1 A Rudimentary "Security Analysis"
First, from "Property II" of f, Alice is unable to find two different
numbers x and y, one is odd and the other even (this can be expressed as x
y (mod 2)) such that f(x) = f(y). Thus, once having read the value f(x)
to Bob over the phone (Step 1), Alice has committed to her choice of x and
cannot change her mind. That's when Alice has completed her coin flipping.
Secondly, due to "Property I" of f, given the value f(x), Bob cannot
determine whether the pre-image used by Alice is odd or even and so has to
place his guess (in Step 2) as a real guess (i.e., an uneducated guess).
At this point, Alice can convince Bob whether he has guessed right or wrong
by revealing her pre-image x (Step 3). Indeed, Bob should be convinced if
his own evaluation of f(x) (in Step 4) matches the value told by Alice in
Step 1 and if he believes that the properties of the agreed function hold.
Also, the coin-flipping is fair if x is taken from an adequately large
space so Bob could not have a guessing advantage, that is, some strategy
that gives him a greater than 50-50 chance of winning.
We should notice that in our "security analysis" for Prot 1.1 we have made
a number of simplifications and omissions. As a result, the current version
of the protocol is far from a concrete realization. Some of these
simplifications and omissions will be discussed in this chapter. However,
necessary techniques for a proper and concrete realization of this
protocol and methodologies for analyzing its security will be the main
topics for the remainder of the whole book. We shall defer the proper and
concrete realization of Prot 1.1 (more precisely, the "magic function" f)
to the final technical chapter of this book (Chapter 19). There, we will be
technically ready to provide a formal security analysis on the concrete
realization.
1.1.2 An Initial Hint on Foundations of Cryptography
Although our first protocol is very simple, it indeed qualifies as a
cryptographic protocol because the "magic function" the protocol uses is a
fundamental ingredient for modern cryptography: one-way function. The two
magic properties listed in Property 1.1 pose two computationally
intractable problems, one for Alice, and the other for Bob.
From our rudimentary security analysis for Prot 1.1 we can claim that the
existence of one-way function implies a possibility for secure selection of
recreation venue. The following is a reasonable generalization of this
claim:
The existence of a one-way function implies the existence of a secure
cryptographic system.
It is now well understood that the converse of this claim is also true:
The existence of a secure cryptographic system implies the existence of a
one-way function.
It is widely believed that one-way function does exist. Therefore we are
optimistic on securing our information. Our optimism is often confirmed by
our everyday experience: many processes in our world, mathematical or
otherwise, have a one-way property. Consider the following phenomenon in
physics (though not an extremely precise analogy for mathematics): it is an
easy process for a glass to fall on the floor and break into pieces while
dispersing a certain amount of energy (e.g., heat, sound or even some dim
light) into the surrounding environment. The reverse process, recollecting
the dispersed energy and using it to reintegrate the broken pieces back
into a whole glass, must be a very hard problem if not impossible. (If
possible, the fully recollected energy could actually bounce the
reintegrated glass back to the height where it started to fall!)
In Chapter 4 we shall see a class of mathematical functions which provide
the needed one-way properties for modern cryptography.
1.1.3 Basis of Information Security: More than Computational Intractability
We have just claimed that information security requires certain
mathematical properties. Moreover, we have further made an optimistic
assertion in the converse direction: mathematical properties imply (i.e.,
guarantee) information security.
However, in reality, the latter statement is not unconditionally true!
Security in real world applications depends on many real world issues. Let
us explain this by continuing using our first protocol example.
We should point out that many important issues have not been considered in
our rudimentary security analysis for Prot 1.1. In fact, Prot 1.1 itself is
a much simplified specification. It has omitted some details which are
important to the security services that the protocol is designed to offer.
The omission has prevented us from asking several questions.
For instance, we may ask: has Alice really been forced to stick to her
choice of x? Likewise, has Bob really been forced to stick to his even-odd
guess of x? By "forced," we mean whether voice over telephone is sufficient
for guaranteeing the strong mathematical property to take effect. We may
also ask whether Alice has a good random number generator for her to
acquire the random number x. This quality can be crucially important in a
more serious application which requires making a fair decision.
All these details have been omitted from this simplified protocol
specification and therefore they become hidden assumptions (more on this
later). In fact, if this protocol is used for making a more serious
decision, it should include some explicit instructions. For example, both
participants may consider recording the other party's voice when the value
f(x) and the even/odd guess are pronounced over the phone, and replay the
record in case of dispute.
Often cryptographic systems and protocols, in particular, those introduced
by a textbook on cryptography, are specified with simplifications similar
to the case in Protocol "Coin Flipping Over Telephone." Simplifications can
help to achieve presentation clarity, especially when some agreement may be
thought of as obvious. But sometimes a hidden agreement or assumption may
be subtle and can be exploited to result in a surprising consequence. This
is somewhat ironic to the "presentation clarity" which is originally
intended by omitting some details. A violation of an assumption of a
security system may allow an attack to be exploited and the consequence can
be the nullification of an intended service. It is particularly difficult
to notice a violation of a hidden assumption. In '1.2.5 we shall provide a
discussion on the importance of explicit design and specification of
cryptographic systems.
A main theme of this book is to explain that security for real world
applications has many application related subtleties which must be
considered seriously.
1.1.4 Modern Role of Cryptography: Ensuring Fair Play of Games
Cryptography was once a preserve of governments. Military and diplomatic
organizations used it to keep messages secret. Nowadays, however,
cryptography has a modernized role in addition to keeping secrecy of
information: ensuring fair play of "games" by a much enlarged population
of "game players." That is part of the reasons why we have chosen to begin
this book on cryptography with a communication game.
Deciding on a recreation venue may not be seen as a serious business, and
so doing it via flipping a coin over the phone can be considered as just
playing a small communication game for fun. However, there are many
communications "games" which must be taken much more seriously. With more
and more business and e-commerce activities being and to be conducted
electronically over open communications networks, many cases of our
communications involve various kinds of "game playing." (In the Preface of
this book we have listed various business and services examples which can
be conducted or offered electronically over open networks; all of them
involve some interactive actions of the participants by following a set of
rules, which can be viewed as "playing communication games".) These
"games" can be very important!
In general, the "players" of such "games" are physically distant from each
other and they communicate over open networks which are notorious for lack
of security. The physical distance combined with the lack of security may
help and/or encourage some of the "game players" (some of whom can even be
uninvited) to try to defeat the rule of game in some clever way. The
intention for defeating the rule of game is to try to gain some unentitled
advantage, such as causing disclosure of confidential information,
modification of data without detection, forgery of false evidence,
repudiation of an obligation, damage of accountability or trust, reduction
of availability or nullification of services, and so on. The importance of
our modern communications in business, in the conduct of commerce and in
providing services (and many more others, such as securing missions of
companies, personal information, military actions and state affairs) mean
that no unentitled advantage should be gained to a player who does not
conform the rule of game.
In our development of the simple "Coin-Flipping-Over-Telephone"
cryptographic protocol, we have witnessed the process whereby an
easy-to-sabotage communication game evolves to a cryptographic protocol
and thereby offers desired security services. Our example demonstrates the
effectiveness of cryptography in maintaining the order of "game playing."
Indeed, the use of cryptography is an effective and the only practical way
to ensure secure communications over open computers and communications
networks. Cryptographic protocols are just communication procedures
armored with the use of cryptography and thereby have protective functions
designed to keep communications in good order. The endless need for
securing communications for electronic commerce, business and services
coupled with another need for anticipating the ceaseless temptation of
"breaking the rules of the game" have resulted in the existence of many
cryptographic systems and protocols, which form the subject matter of this
book.
1.2 Criteria for Desirable Cryptographic Systems and Protocols
We should start by asking a fundamental question:
What is a good cryptographic system/protocol?
Undoubtedly this question is not easy to answer! One reason is that there
are many answers to it depending on various meanings the word good may
have. It is a main task for this book to provide comprehensive answers to
this fundamental question. However, here in this first chapter we should
provide a few initial answers.
1.2.1 Stringency of Protection Tuned to Application Needs
Let us begin with considering our first cryptographic protocol we designed
in '1.1.1.
We can say that Protocol "Coin Flipping Over Telephone" is good in the
sense that it is conceptually very simple. Some readers who may already be
familiar with many practical one-way hash functions, such as SHA-1 (see
'10.3.1), might further consider that the function f(x) is also easy to
implement even in a pocket calculator. For example, an output from SHA-1 is
a bit string of length of 160 bits, or 20 bytes (1 byte = 8 bits); using
the hexadecimal encoding scheme (see Example 5.17) such an output can be
encoded into 40 hexadecimal charactersb and so it is just not too tedious
for Alice (Bob) to read (and jot down) over the phone. Such an
implementation should also be considered sufficiently secure for Alice and
Bob to decide their recreation venue: if Alice wants to cheat, she faces a
non-trivial difficulty in order to find x y (mod 2) with f(x) = f(y);
likewise, Bob will also have to face a non-trivial difficulty, that is,
given f(x), to determine whether x is even or odd.
However, our judgement on the quality of Protocol "Coin Flipping Over
Telephone" realized using SHA-1 is based on a level of non-seriousness that
the game players expect on the consequence of the game. In many more
serious applications (e.g., one which we shall discuss in '1.2.4), a fair
coin-flipping primitive for cryptographic use will in general require much
stronger one-way and commitment-binding properties than a practical
one-way hash function, such as SHA-1, can offer. We should notice that a
function with the properties specified in Property 1.1, if we take the
word "impossible" literally, is a completely secure one-way function. Such
a function is not easily implementable. Worse, even its very existence
remains an open question (even though we are optimistic about the
existence, see our optimistic view in '1.1.2, we shall further discuss the
condition for the existence of a one-way function in Chapter 4). Therefore,
for more serious applications of fair coin-flipping, practical hash
functions won't be considered good; much more stringent cryptographic
techniques are necessary. On the other hand, for deciding a recreation
venue, use of heavyweight cryptography is clearly unnecessary or overkill.
We should point out that there are applications where a too-strong
protection will even prevent an intended security service from functioning
properly. For example, Rivest and Shamir propose a micropayment scheme,
called MicroMint [242], which works by making use of a known deficiency in
an encryption algorithm to their advantage. That payment system exploits a
reasonable assumption that only a resourceful service provider (e.g., a
large bank or financial institute) is able to prepare a large number of
"collisions" under a practical one-way function, and do so economically.
This is to say that the service provider can compute k distinct numbers
(x1, x2, . . ., xk) satisfying
The numbers x1, x2, . . ., xk, are called collision under the one-way
function f. A pair of collisions can be checked efficiently since the
one-way function can be evaluated efficiently, they can be considered to
have been issued by the resourceful service provider and hence can
represent a certified value. The Data Encryption Standard (DES, see '7.6)
is suggested as a suitable algorithm for implementing such a one-way
function ([242]) and so to achieve a relatively small output space (64
binary bits). Thus, unlike in the normal cryptographic use of one-way
functions where a collision almost certainly constitutes a successful
attack on the system (for example, in the case of Protocol "Coin Flipping
Over Telephone"), in MicroMint, collisions are used in order to enable a
fancy micropayment service! Clearly, a strong one-way function with a
significantly larger output space (i.e., 64 bits, such as SHA-1 with 160
bits) will nullify this service even for a resourceful service provider
(in '3.6 we will study the computational complexity for finding collisions
under a hash function).
Although it is understandable that using heavyweight cryptographic
technologies in the design of security systems (for example, wrapping with
layers of encryption, arbitrarily using digital signatures, calling for
online services from a trusted third party or even from a large number of
them) may provide a better feeling that a stronger security may have been
achieved (it may also ease the design job), often this feeling only
provides a false sense of assurance. Reaching the point of overkill with
unnecessary armor is undesirable because in so doing it is more likely to
require stronger security assumptions and to result in a more complex
system. A complex system can also mean an increased difficulty for security
analysis (hence more likelihood to be error-prone) and secure
implementation, a poorer performance, and a higher overhead cost for
running and maintenance.
It is more interesting and a more challenging job to design cryptographic
or security systems which use only necessary techniques while achieving
adequate security protection. This is an important element for
cryptographic and security systems to qualify as good.
1.2.2 Confidence in Security Based on Established "Pedigree"
How can we be confident that a cryptographic algorithm or a protocol is
secure? Is it valid to say that an algorithm is secure because nobody has
broken it? The answer is, unfortunately, no. In general, what we can say
about an unbroken algorithm is merely that we do not know how to break it
yet. Because in cryptography, the meaning of a broken algorithm sometimes
has quantitative measures; if such a measure is missing from an unbroken
algorithm, then we cannot even assert whether or not an unbroken algorithm
is more secure than a known broken one.
Nevertheless, there are a few exceptions. In most cases, the task of
breaking a cryptographic algorithm or a scheme boils down to solving some
mathematical problems, such as to find a solution to an equation or to
invert a function. These mathematical problems are considered "hard" or
"intractable." A formal definition for "hard" or "intractable" will be
given in Chapter 4. Here we can informally, yet safely, say that a
mathematical problem is intractable if it cannot be solved by any known
methods within a reasonable length of time.
There are a number of well-known intractable problems that have been
frequently used as standard ingredients in modern cryptography, in
particular, in public-key or asymmetric cryptography (see '8.3-'8.14). For
example, in public-key cryptography, intractable problems include the
integer factorization problem, the discrete logarithm problem, the
Diffie-Hellman problem, and a few associated problems (we will define and
discuss these problems in Chapter 8). These problems can be referred to as
established "pedigree" ones because they have sustained a long history of
study by generations of mathematicians and as a result, they are now
trusted as really hard with a high degree of confidence.
Today, a standard technique for establishing a high degree of confidence
in security of a cryptographic algorithm is to conduct a formal proof
which demonstrates that an attack on the algorithm can lead to a solution
to one of the accepted "pedigree" hard problems. Such a proof is an
efficient mathematical transformation, or a sequence of such
transformations, leading from an attack on an algorithm to a solution to a
hard problem. Such an efficient transformation is called a reduction which
"reduces" an attack to a solution to a hard problem. Since we are highly
confident that the resultant solution to the hard problem is unlikely to
exist (especially under the time cost measured by the attack and the
reduction transformation), we will be able to derive a measurable
confidence that the alleged attack should not exist. This way of security
proof is therefore named "reduction to contradiction:" an easy solution to
a hard problem.
Formally provable security, in particular under various powerful attacking
model called adaptive attacks, forms an important criterion for
cryptographic algorithms and protocols to be regarded as good. We shall use
fit-for-application security to name security qualities which are
established through formal and reduction-to-contradiction approach under
powerful attacking models.
As an important topic of this book, we shall study fit-for-application
security for many cryptographic algorithms and protocols.
1.2.3 Practical Efficiency
When we say that a mathematical problem is efficient or is efficiently
solvable, we basically assert that the problem is solvable in time which
can be measured by a polynomial in the size of the problem. A formal
definition for efficiency, which will let us provide precise measures of
this assertion, will be provided in Chapter 4.
Without looking into quantitative details of this assertion for the time
being, we can roughly say that this assertion divides all the problems
into two classes: tractable and intractable. This division plays a
fundamental role in the foundations for modern cryptography: a
complexity-theoretically based one. Clearly, a cryptographic algorithm must
be designed such that it is tractable on the one hand and so is usable by
a legitimate user, but is intractable on the other hand and so constitutes
a difficult problem for a non-user or an attacker to solve.
We should however note that this assertion for solubility covers a vast
span of quantitative measures. If a problem's computing time for a
legitimate user is measured by a huge polynomial, then the "efficiency" is
in general impractical, i.e., can have no value for a practical use. Thus,
an important criterion for a cryptographic algorithm being good is that it
should be practically efficient for a legitimate user. In specific, the
polynomial that measures the resource cost for the user should be small
(i.e., have a small degree, the degree of a polynomial will be introduced
in Chapter 4).
In Chapter 14 we will discuss several pioneering works on provably strong
public-key cryptosystems. These works propose public-key encryption
algorithms under a common motivation that many basic versions of public-key
encryption algorithms are insecure (we name those insecure schemes
"textbook crypto" because most textbooks in cryptography introduce them up
to their basic and primitive versions; they will be introduced in Part III
of this book). However, most pioneering works on provably strong public-key
cryptosystems resort to a bit-by-bit encryption method, [125, 210, 241],
some even take extraordinary steps of adding proofs of knowledge on the
correct encryption of each individual bit [210] plus using public-key
authentication framework [241]. While these early pioneering works are
important in providing insights to achieve strong security, the systems
they propose are in general too inefficient for applications. After
Chapter 14, we will further study a series of subsequent works following
the pioneering ones on probably strongly secure public-key cryptosystems
and digital signature schemes. The cryptographic schemes proposed by these
latter works propose have not only strong security, but also practical
efficiency. They are indeed very good cryptographic schemes.
A cryptographic protocol is not only an algorithm, it is also a
communication procedure which involves transmitting of messages over
computer networks between different protocol participants under a set of
agreed rules. So a protocol has a further dimension for efficiency
measure: the number of communication interactions which are often called
communication rounds. Usually a step of communication is regarded to be
more costly than a step of local computation (typically an execution of a
set of computer instructions, e.g. a multiplication of two numbers on a
computing device). Therefore it is desirable that a cryptographic protocol
should have few communication rounds. The standard efficiency criterion for
declaring an algorithm as being efficient is if its running time is
bounded by a small polynomial in the size of the problem. If we apply this
efficiency criterion to a protocol, then an efficient protocol should have
its number of communication rounds bounded by a polynomial of an extremely
small degree: a constant (degree 0) or at most a linear (degree 1)
function. A protocol with communication rounds exceeding a linear function
should not be regarded as practically efficient, that is, no good for any
practical use.
In '18.2.3 we will discuss some zero-knowledge proof protocols which have
communication rounds measured by non-linear polynomials. We should note
that those protocols were not proposed for real applications; instead, they
have importance in the theory of cryptography and computational
complexity. In Chapter 18 we will witness much research effort for
designing practically efficient zero-knowledge protocols.
1.2.4 Use of Practical and Available Primitives and Services
A level of security which is good for one application needn't be good
enough for another. Again, let us use our coin-flipping protocol as an
example. In '1.2.1 we have agreed that, if implemented with the use of a
practical one-way hash function, Protocol "Coin Flipping Over Telephone" is
good enough for Alice and Bob to decide their recreation venue over the
phone. However, in many cryptographic applications of a fair coin-flipping
primitive, security services against cheating and/or for fairness are at
much more stringent levels; in some applications the stringency must be in
an absolute sense.
For example, in Chapter 18 we will discuss a zero-knowledge proof protocol
which needs random bit string input and such random input must be mutually
trusted by both proving/verification parties, or else serious damages will
occur to one or both parties. In such zero-knowledge proof protocols, if
the two communication parties do not have access to, or do not trust, a
third-party-based service for supplying random numbers (such a service is
usually nicknamed "random numbers from the sky" to imply its
impracticality) then they have to generate their mutually trusted random
numbers, bit-by-bit via a fair coin-flipping protocol. Notice that here
the need for the randomness to be generated in a bit-by-bit (i.e., via fair
coin-flipping) manner is in order to satisfy certain requirements, such as
the correctness and zero-knowledge-ness of the protocol. In such a
situation, a level of practically good (e.g., in the sense of using a
practical hash function in Protocol "Coin Flipping Over Telephone") is most
likely to be inadequate.
A challenging task in applied research on cryptography and cryptographic
protocols is to build high quality security services from practical and
available cryptographic primitives. Once more, let us use a coin-flipping
protocol to make this point clear. The protocol is a remote coin-flipping
protocol proposed by Blum [43]. Blum's protocol employs a practically
secure and easily implementable "one-way" function but achieves a
high-quality security in a very strong fashion which can be expressed as:
*
First, it achieves a quantitative measure on the difficulty against the
coin flipping party (e.g., Alice) for cheating, i.e., for preparing a pair
of collision x y satisfying f(x) = f(y). Here, the difficulty is
quantified by that for factoring a large composite integer, i.e., that for
solving a "pedigree" hard problem.
*
Second, there is absolutely no way for the guessing party to have a
guessing strategy biased away from the 50-50 chance. This is in terms of a
complete security.
Thus, Blum's coin-flipping protocol is particularly good in the sense of
having achieved a strong security while using only practical cryptographic
primitives. As a strengthening and concrete realization for our first
cryptographic protocol, we will describe Blum's coin-flipping protocol as
the final cryptographic protocol of this book.
Several years after the discovery of public-key cryptography [97, 98,
246], it became gradually apparent that several basic and best-known
public-key encryption algorithms (we will refer to them as "textbook
crypto") generally have two kinds of weakness: (i) they leak partial
information about the message encrypted; (ii) they are extremely
vulnerable to active attacks (see Chapter 14). These weaknesses mean that
"textbook crypto" are not fit for applications. Early approaches to a
general fix for the weaknesses in "textbook crypto" invariantly apply
bit-by-bit style of encryption and even apply zero-knowledge proof
technique at bit-by-bit level as a means to prevent active attacks, plus
authentication framework. These results, while valuable in the development
of provably secure public-key encryption algorithms, are not suitable for
most encryption applications since the need for zero-knowledge proof or
for authentication framework is not practical for the case of encryption
algorithms.
Since the successful initial work of using a randomized padding scheme in
the strengthening of a public key encryption algorithm [24], a general
approach emerges which strengthens popular textbook public-key encryption
algorithms into ones with provable security by using popular primitives
such as hash functions and pseudorandom number generators. These
strengthened encryption schemes are practical since they use practical
primitives such as hash functions, and consequently their efficiency is
similar to the underlying "textbook crypto" counterparts. Due to this
important quality element, some of these algorithms enhanced from using
practical and popular primitives become public-key encryption and digital
signature standards. We shall study several such schemes in Chapters 15
and 16.
Designing cryptographic schemes, protocols and security systems using
available and popular techniques and primitives is also desirable in the
sense that such results are more likely to be secure as they attract a
wider interest for public scrutiny.
1.2.5 Explicitness
In the late 1960's, software systems grew very large and complex. Computer
programmers began to experience a crisis, the so-called "software crisis."
Large and complex software systems were getting more and more error prone,
and the cost of debugging a program became far in excess of the cost of
the program design and development. Soon computer scientists discovered a
few perpetrators who helped to set-up the crisis which resulted from bad
programming practice. Bad programming practice includes:
*
Arbitrary use of the GOTO statement (jumping up and down seems very
convenient)
*
Abundant use of global variables (causing uncontrolled change of their
values, e.g., in an unexpected execution of a subroutine)
*
The use of variables without declaration of their types (implicit types can
be used in Fortran, so, for example, a real value may be truncated to an
integer one without being noticed by the programmer)
*
Unstructured and unorganized large chunk of codes for many tasks (can be
thousands of lines a piece)
*
Few commentary lines (since they don't execute!)
These were a few "convenient" things for a programmer to do, but had proved
to be capable of causing great difficulties in program debugging,
maintenance and further development. Software codes designed with these
"convenient" features can be just too obscure to be comprehensible and
maintained. Back then it was not uncommon that a programmer would not be
able to to understand a piece of code s/he had written merely a couple of
months or even weeks ago.
Once the disastrous consequences resulting from the bad programming
practice were being gradually understood, Program Design Methodology became
a subject of study in which being explicit became an important principle
for programming. Being explicit includes limiting the use of GOTO and
global variables (better not to use them at all), explicit (via mandatory)
type declaration for any variables, which permits a compiler to check type
flaws systematically and automatically, modularizing programming (dividing
a large program into many smaller parts, each for one task), and using
abundant (as clear as possible) commentary material which are texts inside
a program and documentation outside.
A security system (cryptographic algorithm or protocol) includes program
parts implemented in software and/or hardware, and in the case of
protocol, the program parts run on a number of separate hosts (or a number
of programs concurrently and interactively running on these hosts). The
explicitness principle for software engineering applies to a security
system's design by default (this is true in particular for protocols).
However, because a security system is assumed to run in a hostile
environment in which even a legitimate user may be malicious, a designer
of such systems must also be explicit about many additional things. Here
we list three important aspects to serve as general guidelines for security
system designers and implementors. (In the rest of the book we will see
many attacks on algorithms and protocols due to being implicit in design or
specification of these systems.)
1.
Be explicit about all assumptions needed.
A security system operates by interacting with an environment and
therefore it has a set of requirements which must be satisfied by that
environment. These requirements are called assumptions (or premises) for a
system to run. A violation of an assumption of a protocol may allow the
possibility of exploiting an attack on the system and the consequence can
be the nullification of some intended services. It is particularly
difficult to notice a violation of an assumption which has not been clearly
specified (a hidden assumption). Therefore all assumptions of a security
system should be made explicit.
For example, it is quite common that a protocol has an implicit assumption
or expectation that a computer host upon which the protocol runs can
supply good random numbers, but in reality few desktop machines or
hand-held devices are capable of satisfying this assumption. A so-called
low-entropy attack is applicable to protocols using a poor random source. A
widely publicized attack on an early implementation of the Secure Sockets
Layer (SSL) Protocol (an authentication protocol for World Wide Web browser
and server, see '12.5) is a well-known example of the low-entropy attack
[123].
Explicit identification and specification of assumptions can also help the
analysis of complex systems. DeMillo et al. (Chapter 4 of [91]), DeMillo
and Merritt [92] suggest a two-step approach to cryptographic protocol
design and analysis, which are listed below (after a modification by Moore
[204, 205]):
i.
Identify all assumptions made in the protocol.
ii.
For each assumption in step (i), determine the effect on the security of
the protocol if that assumption were violated.
2.
Be explicit about exact security services to be offered.
A cryptographic algorithm/protocol provides certain security services.
Examples of some important security services include: confidentiality (a
message cannot be comprehended by a non-recipient), authentication (a
message can be recognized to confirm its integrity or its origin),
non-repudiation (impossibility for one to deny a connection to a message),
proof of knowledge (demonstration of evidence without disclosing it), and
commitment (e.g., a service offered to our first cryptographic protocol
"Coin Flipping Over Telephone" in which Alice is forced to stick to a
string without being able to change).
When designing a cryptographic protocol, the designer should be very clear
regarding exactly what services the protocol intends to serve and should
explicitly specify them as well. The explicit identification and
specification will not only help the designer to choose correct
cryptographic primitives or algorithms, but also help an implementor to
correctly implement the protocol. Often, an identification of services to
the refinement level of the general services given in these examples is
not adequate, and further refinement of them is necessary. Here are a few
possible ways to further refine some of them:
Confidentiality
privacy, anonymity, invisibility, indistinguishability
Authentication
data-origin, data-integrity, peer-entity
Non-repudiation
message-issuance, message-receipt
Proof of knowledge
knowledge possession, knowledge structure
A misidentification of services in a protocol design can cause misuse of
cryptographic primitives, and the consequence can be a security flaw in
the protocol. In Chapter 2 and Chapter 11 we will see disastrous examples
of security flaws in authentication protocols due to misidentification of
security services between confidentiality and authentication.
There can be many more kinds of security services with more ad hoc names
(e.g., message freshness, non-malleability, forward secrecy, perfect
zero-knowledge, fairness, binding, deniability, receipt freeness, and so
on). These may be considered as derivatives or further refinement from the
general services that we have listed earlier (a derivative can be in terms
of negation, e.g., deniability is a negative derivative from
non-repudiation). Nevertheless, explicit identification of them is often
necessary in order to avoid design flaws.
3.
Be explicit about special cases in mathematics.
As we have discussed in '1.2.2, some hard problems in computational
complexity theory can provide a high confidence in the security of a
cryptographic algorithm or protocol. However, often a hard problem has some
special cases which are not hard at all. For example, we know that the
problem of factorization of a large composite integer is in general very
hard. However the factorization of a large composite integer N = PQ where Q
is the next prime number of a large prime number P is not a hard problem at
all! One can do so efficiently by computing (? is called the floor function
and denotes the integer part of 7) and followed by a few trial divisions
around that number to pinpoint P and Q.
Usual algebraic structures upon which cryptographic algorithms work (such
as groups, rings and fields, to be studied in Chapter 5) contain special
cases which produce exceptionally easy problems. Elements of small
multiplicative orders (also defined in Chapter 5) in a multiplicative
group or a finite field provide such an example; an extreme case of this is
when the base for the Diffie-Hellman key exchange protocol (see '8.3) is
the unity element in these algebraic structures. Weak cases of elliptic
curves, e.g., "supersingular curves" and "anomalous curves," form another
example. The discrete logarithm problem on "supersingular curves" can be
reduced to the discrete logarithm problem on a finite field, known as the
Menezes-Okamoto-Vanstone attack [197] (see '13.3.4.1). An "anomalous curve"
is one with the number of points on it being equal to the size of the
underlying field, which allows a polynomial time solution to the discrete
logarithm problem on the curve, known as the attack of Satoh-Araki [252],
Semaev [258] and Smart [278].
An easy special case, if not understood by an algorithm/protocol designer
and/or not clearly specified in an algorithm/protocol specification, may
easily go into an implementation and can thus be exploited by an attacker.
So an algorithm/protocol designer must be aware of the special cases in
mathematics, and should explicitly specify the procedures for the
implementor to eliminate such cases.
It is not difficult to list many more items for explicitness (for example,
a key-management protocol should stipulate explicitly the key-management
rules, such as separation of keys for different usages, and the procedures
for proper key disposal, etc.). Due to the specific nature of these items
we cannot list all of them here. However, explicitness as a general
principle for cryptographic algorithm/protocol design and specification
will be frequently raised in the rest of the book. In general, the more
explicitly an algorithm/protocol is designed and specified, the easier it
is for the algorithm/protocol to be analyzed; therefore the more likely it
is for the algorithm/protocol to be correctly implemented, and the less
likely it is for the algorithm/protocol to suffer an unexpected attack.
1.2.6 Openness
Cryptography was once a preserve of governments. Military and diplomatic
organizations used it to keep messages secret. In those days, most
cryptographic research was conducted behind closed doors; algorithms and
protocols were secrets. Indeed, governments did, and they still do, have a
valid point in keeping their cryptographic research activities secret. Let
us imagine that a government agency publishes a cipher. We should only
consider the case that the cipher published is provably secure; otherwise
the publication can be too dangerous and may actually end up causing
embarrassment to the government. Then other governments may use the
provably secure cipher and consequently undermine the effectiveness of the
code-breakers of the government which published the cipher.
Nowadays, however, cryptographic mechanisms have been incorporated in a
wide range of civilian systems (we have provided a non-exhaustive list of
applications in the very beginning of this chapter). Cryptographic research
for civilian use should take an open approach. Cryptographic algorithms do
use secrets, but these secrets should be confined to the cryptographic
keys or keying material (such as passwords or PINs); the algorithms
themselves should be made public. Let's explore the reasons for this
stipulation.
In any area of study, quality research depends on the open exchange of
ideas via conference presentations and publications in scholarly journals.
However, in the areas of cryptographic algorithms, protocols and security
systems, open research is more than just a common means to acquire and
advance knowledge. An important function of open research is public expert
examination. Cryptographic algorithms, protocols and security systems have
been notoriously error prone. Once a cryptographic research result is made
public it can be examined by a large number of experts. Then the
opportunity for finding errors (in design or maybe in security analysis)
which may have been overlooked by the designers will be greatly increased.
In contrast, if an algorithm is designed and developed in secret, then in
order to keep the secret, only few, if any, experts can have access to and
examine the details. As a result the chance for finding errors is
decreased. A worse scenario can be that a designer may know an error and
may exploit it secretly.
It is now an established principle that cryptographic algorithms,
protocols, and security systems for civilian use must be made public, and
must go through a lengthy public examination process. Peer review of a
security system should be conducted by a hostile expert.
1.3 Chapter Summary
In this chapter we began with an easy example of applied cryptography. The
three purposes served by the example are:
i.
Showing the effectiveness of cryptography in problem solving
ii.
Aiming for a fundamental understanding of cryptography
iii.
Emphasizing the importance of non-textbook aspects of security
They form the main topics to be developed in the rest of this book.
We then conducted a series of discussions which served the purpose for an
initial background and cultural introduction to the areas of study. Our
discussions in these directions are by no means of complete. Several other
authors have also conducted extensive study on principles, guidelines and
culture for the areas of cryptography and information security. The
following books form good further reading material: Schneier [254],
Gollmann [129] and Anderson [14]. Schneier's monthly distributed
"Crypto-Gram Newsletters" are also good reading material. To subscribe for
receiving the newsletters, send an email to schneier(a)counterpane.com.
Exercises
1.1
What is the difference between a protocol and an algorithm?
1.2
In Prot 1.1 Alice can decide HEADS or TAILS. This may be an unfair
advantage for some applications. Modify the protocol so that Alice can no
longer have this advantage.
Hint: let a correct guess decide the side.
1.3
Let function f map from the space of 200-bit integers to that of 100-bit
ones with the following mapping rule:
here "?" denotes bit-by-bit XOR operation, i.e.,
i. Is f efficient?
ii.
Does f have the "Magic Property I"?
iii.
Does f have the "Magic Property II"?
iv.
Can this function be used in Prot 1.1?
1.4
Is an unbroken cryptographic algorithm more secure than a known broken one?
If not, why?
1.5
Complex systems are error-prone. Give an additional reason for a complex
security system to be even more error-prone.
) 2004 Pearson Education, Inc. InformIT. All rights reserved.
800 East 96th Street Indianapolis, Indiana 46240
--
-----------------
R. A. Hettinga <mailto: rah(a)ibuc.com>
The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
44 Farquhar Street, Boston, MA 02131 USA
"... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
1
0
Hum.
So my newbie-style question is, is there an eGold that can be verified, but
not accessed, until a 'release' code is sent?
In other words, say I'm buying some hacker-ed code and pay in egold. I don't
want them to be able to 'cash' the gold until I have the code. Meanwhile,
they will want to see that the gold is at least "there", even if they can't
cash it yet.
Is there a way to send a 'release' to an eGold (or other) payment? Better
yet, a double simultaneous release feature makes thing even more
interesting.
-TD
>From: "R.A. Hettinga" <rah(a)shipwright.com>
>To: cryptography(a)metzdowd.com, cypherpunks(a)al-qaeda.net
>Subject: Your source code, for sale
>Date: Wed, 3 Nov 2004 19:24:43 -0500
>
><http://www.adtmag.com/print.asp?id=10225>
>
> - ADTmag.com
>
>Your source code, for sale
>
>By Mike Gunderloy
>
>Well, maybe not yet. But what does the future hold for those who consider
>their source code an important proprietary asset?
>
>Halloween this year featured more scary stuff than just ghosts and ghouls.
>It was also the day (at least in the Pacific time zone) when the Source
>Code Club posted their second Newsletter in a public Usenet group. Despite
>their innocent-sounding name, the Source Code Club is a group of hackers
>who are offering to sell the source to commercial products. Their current
>menu of source code for sale looks like this:
> * Cisco Pix 6.3.1 - $24,000
> * Enterasys Dragon IDS - $19.200
> * Napster - $12,000
>
>They also claim to have the source code for many other packages that they
>haven't announced publicly. "If you are requesting something from a Fortune
>100 company, there is a good chance that we might already have it, they
>say. Now, you might think this business is blatantly illegal, and no doubt
>it is. But that doesn't necessarily mean it's impossible. They're posting
>their newsletter to Usenet, probably from an Internet cafe somewhere, so
>that's not traceable. They'll take orders the same way, and require orders
>to be encrypted using their PGP key, which is at least reasonably
>unbreakable at the moment. (As of this writing, I don't see any encrypted
>messages posted to the newsgroup they use, though). For payment, they're
>using e-gold, which claims to protect the anonymity of its account holders.
>
>Now, it seems reasonably likely that the Source Code Club folks will
>eventually get caught; going up against Cisco's resources displays at least
>a strong conviction of invulnerability. But even if these guys get caught,
>there are deeper issues here. Ten years ago, no one could have dreamed of
>trying to set up such a business. Ten years from now, advances in
>cryptography, more forms of currency circulating on the Internet, and
>improvements in anonymity software are likely to make it impossible to
>catch a similar operation.
>
>What will it mean when hacker groups can in fact do business this way with
>impunity? First, it's important to note that the ability to sell wares
>anonymously won't necessarily imply the ability to get inventory. Your best
>defense against having your own source code leaked is to pay careful
>attention to its physical security. These days, if I were developing an
>important commercial product, I'd make sure there was no path between my
>development or build machines and the public Internet. Hackers can do lots
>of things, but they still can't leap over physical disconnections. Second,
>I'd use software that prevents temporary storage devices (like USB sticks)
>from connecting to the network, and keep CD and DVD burners out of the
>development boxes as well.
>
>It's also worth making sure that your business doesn't depend entirely on
>source code. While the intellectual property that goes into making software
>is certainly a valuable asset, it shouldn't be your only asset. Think about
>ancillary services like training, support, and customization in addition to
>simply selling software.
>
>Finally, note that the Source Code Club business model is based on taking
>advantage of people wanting to know what's in the software that they
>purchase. About the pix code, they say "Many intelligence
>agencies/government organizations will want to know if those 1's and 0's in
>the pix image really are doing what was advertised. You must ask yourself
>how well you trust the pix images you download to your appliance from
>cisco.com." Microsoft (among other companies) has demonstrated how to
>remove this particular fear factor from customers: share your source code
>under controlled circumstances. That doesn't mean that you need to adapt an
>open source model, but when a big customer comes calling, why not walk
>their engineers through how things work and let them audit their own areas
>of concern?
>
>Given the shifting landscape of intellectual property, and the threat from
>groups such as the Source Code Club, these are matters you need to think
>about sooner rather than later. Otherwise you may wake up some morning and
>find that your major asset has vanished without your even knowing it was in
>danger.
>
>
>Mike Gunderloy, MCSE, MCSD .NET, MCDBA is an independent software
>consultant and author working in eastern Washington. He's the editor of
>ADT's Developer Central newsletter and author of numerous books and
>articles. You can reach him at MikeG1(a)larkfarm.com.
>
>This article originally appeared in the
>November 2004 issue of Application Development Trends.
>
>
>--
>-----------------
>R. A. Hettinga <mailto: rah(a)ibuc.com>
>The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
>44 Farquhar Street, Boston, MA 02131 USA
>"... however it may deserve respect for its usefulness and antiquity,
>[predicting the end of the world] has not been found agreeable to
>experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today - it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/
2
1
So, it's the night of the day of the morning after, and all around us are
masses milling in despair over the destruction of freedom that has
occurred here over the last four years.
Given that the US was the "Gulch" to the brain drain of the Soviet Union,
where does a true capitalist, or even just a closet objectivist flee
today? France? Spain? The "EU"?
Where does one go today, if they are unwilling to participate in the
Failed Experiment? (BTW: No, Lichtenstein does not accept immigrants, and
yes, I have reverified this recently).
--
Yours,
J.A. Terranson
sysadmin(a)mfn.org
0xBD4A95BF
"An ill wind is stalking
while evil stars whir
and all the gold apples
go bad to the core"
S. Plath, Temper of Time
2
1
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
James A. Donald:
> You are quite right, it is unjust that people like Bin Laden are so
> immensely rich with oil wealth. To remedy this problem, Bush
> should confiscate the Middle Eastern oil reserves.
>
> You are using stale old communist rhetoric - but today's terrorists
> no longer not even pretend to fight on behalf of the poor and
> oppressed.
This was quite lame and doesn't really deserve a response.
To label any argument that points out the obvious circumstance
that injustice feeds hatred as communist propaganda, is really only
ridiculous, even if it's also dangerously incompetent and as such no
real laughing matter.
Why do you mention Bin Laden anyway? There are thousands of
bigger and smaller groups around the world (they exists in every
country more or less) that we'd label as terrorists in the western
part of the world. You think every one of these hundreds of thousands
or perhaps millions of recruits and followers are millionaires?
Fantastically lame comment to a real and important issue.
Should we take you seriously when you write these childish rants?
I don't know what to fear the most, the dangerous ignorance of
those of your kind or what dictatorial rulers may accomplish using
your ignorant kind as followers who do not question the truths from
the authorities. Hitler did it in the 30's election where some 37%
voted for the nazis, in a democratic multi-party election I might
add. Some of the ingrediences present then in Hitler's rhetoric are
also present today in Bush's rhetoric, even though I don't mean to
make the comparison .
We just cannot afford to be this naive.
I can't help thinking about the fact that we usually portray
Americans as a religious and church going people. Perhaps some 25%
attend church on a somewhat regular basis. To make matters worse
those people seem to vote for Bush(?). One can't help wonder if
they're literate and if they actually read the bible and it's message
of love, understanding, forgiveness and compassion for their fellow
man.
May god bless the world, we may need it.
Johnny Doelittle
Men willingly believe what they wish.
(Julius Caesar)
There is nothing worse than aggressive stupidity.
(von Goethe)
-----BEGIN PGP SIGNATURE-----
Version: Tom Ridge Special v1.01
iQA/AwUBQYoO4jVaKWz2Ji/mEQKzWACfTEUN6ENT9/kbzMEOQVuvM4txtpIAnRI2
pU5RbBMeBggUCWf2ZW4rBQYG
=EiIW
-----END PGP SIGNATURE-----
2
1
<http://www.thesun.co.uk/article/0,,2-2004512410,00.html>
The Sun Newspaper Online - UK's biggest selling newspaper
Thursday, November 4, 2004
By DEREK BROWN
Deputy Showbiz Editor
RAPPER Eminem's new album Encore has been leaked on to the internet.
The Real Slim Shady star's hotly-anticipated fourth album was stolen
nearly two weeks before its release date.
The theft has sparked panic at his record label Interscope who have
brought forward the worldwide release date.
An illegal website called RNS put the entire album on the net two days ago.
Thousands of fans instantly downloaded it and could pass it on to
countless others.
It could lose the 32-year-old rapper MILLIONS of pounds in royalties from
CD sales.
Interscope bosses were locked in meetings all day yesterday.
They decided to bring forward Encore's release date by three days to next
Friday November 12.
Unveiling the album on a Friday rather than a Monday is virtually
unprecedented - and a sign of how panicked bosses are.
An insider at the label said: "This is catastrophic news. Security has
been so tight on this album nobody can figure out how the album has got out
there.
"We now think thousands of people around the world are downloading it.
"This is a very, very serious issue for us."
Encore features 20 tracks with titles including Mosh, Puke and Big Weenie.
Eighties star Martika features on Like Toy Soldiers.
Despite the theft, experts still predict Encore - the follow up to The
Eminem Show - will be the biggest selling album in the world this year.
--
-----------------
R. A. Hettinga <mailto: rah(a)ibuc.com>
The Internet Bearer Underwriting Corporation <http://www.ibuc.com/>
44 Farquhar Street, Boston, MA 02131 USA
"... however it may deserve respect for its usefulness and antiquity,
[predicting the end of the world] has not been found agreeable to
experience." -- Edward Gibbon, 'Decline and Fall of the Roman Empire'
1
0