Bruce Schneier | |||||||||
Schneier on SecurityA blog covering security and security technology. « Friday Squid Blogging: Where to Get Your Pet Squid | Main | KittenAuth » April 10, 2006No-Buy ListYou've all heard of the "No Fly List." Did you know that there's a "No-Buy List" as well? The so-called "Bad Guy List" is hardly a secret. The U.S. Treasury's Office of Foreign Assets Control maintains its "Specially Designated Nationals and Blocked Persons List" to be easily accessible on its public Web site. Posted on April 10, 2006 at 6:23 AM • 35 Comments • View Blog Reactions To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. Is this the list: http://www.ustreas.gov/offices/enforcement/ofac/sdn/index.shtml Posted by: Michael Clark at April 10, 2006 7:33 AM That's amazing. It seems that in order to comply with the law, a vending machine will have to check the identity of the customer before selling him or her a soda! Posted by: MSB at April 10, 2006 8:11 AM @Michael: yes, AFAICT. FTA: No, but they do make for a lovely soviet police state. Posted by: Jeremy Dunck at April 10, 2006 8:12 AM "it's impractical", says Hudson. Not at all! It is easy to download the list to a PDA and use it to check for suspected terrorists. All citizens should be required to carry an anti-terrorist PDA right next to their constitutionally "mandated" handgun. Of course it will not catch any terrorists, but maybe people will feel good about "doing everything possible in the war against terrorism". Posted by: Daniel at April 10, 2006 8:19 AM Bruce, think "Wire Transfers". It's the fastest and easiest way to move your ill-gotten gains. Since many of these folks [their money, not them] are in Europe (western & eastern) it's more difficult to move money around to US banks (that also have overseas operations). They can't run down to the BofA in downtown Strasburg and wire $10 million to the Caymen Islands. We have to check every wire against the OFAC list every day. [Just in case Fidel is moving his $ again :-)]. Posted by: David at April 10, 2006 8:29 AM Since when was practicality a requirement for national security measures. This has gotten even more ludicrious under the Patriot Act and the Bush government. We wouldn't need to ban cigarette lighters from airplanes if the TSA and DHS actually did their real jobs... but Bush's administration has never been about real security, just job security...usually theirs. Posted by: Dan at April 10, 2006 8:29 AM "That's amazing. It seems that in order to comply with the law, a vending machine will have to check the identity of the customer before selling him or her a soda!" You can't be too careful. Some of those soft drinks are pretty amazing. We don't want terrorists to have access to Mountain Dew, for example. Posted by: Bruce Schneier at April 10, 2006 8:39 AM "Some of those soft drinks are pretty amazing." I have read that some of these sodas have high levels of substances that can induce cancer. They are hazardous to our health, probably a greater treat than terrorism. Maybe we should ONLY sell them to terrorists. ;-) Posted by: Daniel at April 10, 2006 9:04 AM Yes, if they get soda and candy, they might do something like this... http://video.google.com/videoplay?docid=4077724936497803978 Posted by: Erik V. Olson at April 10, 2006 9:06 AM If the soft drinks cause cancer, there's no doubt that the terrorists are buying them to build some sort of biological weapon... Posted by: D at April 10, 2006 9:19 AM I worked for a mortgage banking firm a few years ago, and I can confirm that part of our checks on people who wanted to have some money for a house was to do a search on their name on that OFAC page. Seemed a little silly that part of my workflow was hitting ctrl-F on an unencrypted web page. Posted by: Ryan Forsythe at April 10, 2006 9:37 AM Seems like the perfect application for a Bloom Filter! It keeps the actual list secret, gives some false positives, and (most importantly) you can add names but can't remove them. (I wish I were joking about this) Posted by: drench at April 10, 2006 9:53 AM And of course, this Awesome Power to Screw Up People's Lives will only be used for good purposes. Posted by: Nancy Lebovitz at April 10, 2006 9:53 AM The web site appears to be unavailable. Is this the first instance of a "Schneierdotting" :-) Posted by: John Davies at April 10, 2006 10:07 AM Is this not another instance of "how to really screw over anyone with a similar name to a terrorist"? Posted by: Kieran at April 10, 2006 10:25 AM So, if a terrorist doesn't like someone, start using their name as an alias. Then their name will get added to the list. Great. Posted by: Tim Vail at April 10, 2006 10:47 AM Looks like self-advertisement for the lawyer's book... When was the last prosecution? It's relevant for banking transactions as mentioned by earlier comments. Posted by: Andy at April 10, 2006 11:26 AM "Same for Charles "Chuckie" Taylor, son of the recently arrested former president of Liberia" Thanks Bruce. You should know that you done your bit in he GWOT; since I recenently received an email from "Chuckie" with a very intriguing business proposition. These internets sure are amazing.
Posted by: Barry Freed at April 10, 2006 11:34 AM These names are a joke, right? Just how many folks called "Ahmed Mohammed" can you imagine there are? Or does the block only apply if he signs his order "a.k.a. Ahmed the Egyptian"? (assuming he chooses to write in latin script with this form of letters). Pity any other Egyptians called Ahmed. Posted by: erasmus at April 10, 2006 11:54 AM @ John > The web site appears to be unavailable. No, that's happened before (last time in December if I recall). Schneierdotting is less frequent, but it still occurs (usually with destination hosts with *really* small bandwidth allocations). Of course, usually Bruce posts papers (which are on university nets with "fat pipes") or articles from some newspaper (ditto). Posted by: Pat Cahalan at April 10, 2006 12:24 PM And for anyone who wants to join the terrorists, or to help them out in any way, its a perfect list of contacts, advisors, suppliers, etc. It's probably a best seller in some parts of the Middle East... Mr W Posted by: Mr W at April 10, 2006 12:34 PM You'll be surprised, but when I recently visited the branch of Citibank in Moscow, Russia (in a rather out-of-the-way location) in order to exchange $100 into local russian currency, i was, sure, asked for a passport and printed a receipt. The receipt was stamped by the nice red "Sanctions/SDN Verified". It was a routine street level operation, and it made me laughing, imagining somebody like Mira Milosevic going to Citi to change the bill to buy some bread :) Posted by: Tacci at April 10, 2006 12:35 PM The NYT obviously does not check the list, they have a Charles Taylor doing book and film reviews. Posted by: Mo at April 10, 2006 1:02 PM "The OFAC requirements apply to all U.S. citizens. " I just found myself a market niche: "Having trouble buying your vegetables? My business will flourish and prosper, until Posted by: Gerd at April 10, 2006 1:42 PM okay, i found the list, is there any angle i can play to sell goods and services to these people, maybe as part of an affinity program? Posted by: another_bruce at April 10, 2006 2:06 PM "You can't be too careful. Some of those soft drinks are pretty amazing. We don't want terrorists to have access to Mountain Dew, for example." If Osama does the Dew, it's all over..... Posted by: anonymousy at April 10, 2006 2:24 PM This law is only impractical if you think its purpose is to stop people selling to the "Bad Guys." If, instead, you realize that this law, like so many others, is meant to make it easier to prosecute as wide a number of people as possible, then you see that it is a very effective law. A famous example of this "type" of law is our tax code being used to prosecute mobsters, prostitutes, drug dealers, and other "Bad Guys." Another example is the use of data recovery professionals to find out if you ever had anything illegal on your computer. Even if it was in temp files, and even if you said, "eeewww! I don't want to be seeing crap like that! I'd better delete that right now and never go back!" These "types" of laws allow them to go after you if they wish. It's purely to make life easier for the prosecutors. Posted by: Mac at April 10, 2006 4:18 PM Greetings, I am Enid Taylor, wife of former President of Liberia, Charles Taylor. I need your assistence for a business transaction. There will be NO RISK to you. Currently I have 50000 (FIFTY THOUSAND) humvees in a car lot in Texas, but I am unable to access them due to the OFAC list. I propose to transfer them to your name so you can collect, and then you transfer 60% of the humvees to me, keeping the remainder as your profit. Posted by: Enid Taylor at April 10, 2006 5:07 PM Greetings, I am Bob, whose name just happens to resemble that of an alias of a cousin of a suspected terrorist sympathisers mother in law. I currently have $50 in my account but find myself unable to buy milk and bread at the local shop. In return for your assistance you can keep 3 slices of bread (white or wholemeal, your choice) and a glass of milk. Posted by: Bob the Innocent at April 10, 2006 6:15 PM Wow - what a great resource for matching SSN, passport and DOB records! ;) Posted by: Orthopteroid at April 10, 2006 9:57 PM I know most (if not all?) banks in france have an "OFAC filter" running with their SWIFT installations. As one poster guessed, it does generate many false positives. One large institution I worked for had a dedicated team to handle these. Posted by: Alex at April 11, 2006 1:47 AM Hah. This WP reporter just heard about OFAC? He doesn't know from stuff. This bad guy list has been in place for years and years. What's more, your great country has a wonderful set of sanctions against bad countries including, of course, that island in the Caribbean which is such a danger to US freedom and democracy. Check out http://www.treas.gov/offices/enforcement/ofac/programs/ Posted by: JakeS at April 11, 2006 8:15 AM Here is an interesting recount of a no-fly experience. http://www.capitolhillblue.com/artman/publish/article_8045.shtml If it is to believed, no-fly is becoming a tool for political retaliation. Posted by: NoFly1 at April 15, 2006 12:46 PM It is not quite as daft as it looks. For example, if you wanted to donate money to help the Palestinian people, but not terrorists, you would be well advised to check the organisation you donated to was not on the list. If you fail to do so, and donate to "RELIEF COMMITTEE FOR SOLIDARITY WITH Posted by: Ben Liddicott at April 16, 2006 2:48 PM Bruce, I wrote the SDNcompliance.com website to help alleviate the burden people face in checking their client lists against the SDN. This tool parses the SDN list nightly, indexes it and allows you to export your outlook contacts and match them against the list. It's all free and advertising driven and the solutions I looked at that are out there now by Attus and Bridger Insight are ungodly expensive and horrible interfaces. Sean Posted by: Sean Tierney at April 18, 2006 5:47 PM Post a comment
Powered by Movable Type 3.36. Photo at top by Steve Woit.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT. |
|
Comments