Back of the Book — May 18, 2019

It's Friday afternoon, May 31, 2019, 13:05, and I am declaring this Web page finished. I have updated this Web page again, this time with more about the Trump tariff shenanigans, and possible criminal acts. I had previously added the location of the next WBAI LSB meeting. I'd previously updated this page with some of what Pickles of the North did on the program, and more about the SHA-1 security issues we talked about. I've also noted that we were unable to get to the topic of the Alabama anti-choice legislation.

Did you know that I've got a brief synopsis of some of the WBAI LSB meetings?

I have also posted a whole lot of the minutes of the Pacifica National Finance Committee. I'm a member of that committee because I'm the WBAI LSB Treasurer.

The next WBAI LSB meeting is scheduled to be held on June 12, 2019, at the First Unitarian Church chapel 119 Pierrepont St, corner of Monroe Place, in Brooklyn, NY 11201, Brooklyn, NY 11201. These meetings are usually supposed to start at 7:00 PM.

The WBAI LSB met on Wednesday, May 8, 2019, at 7:10 PM at the First Unitarian Church chapel 119 Pierrepont St, corner of Monroe Place, in Brooklyn, NY 11201.

The LSB had to populate some PNB committees at this meeting. This is all happening later than usual because the 2018, Pacifica elections were so delayed. Luckily, the LSB didn't have to venture into the potential quagmire of multiple Single Transferable Voting (STV) elections, as happened at the previous meeting.

Each year the LSB has to elect two members, who are not Directors, to each of four PNB committees. And at this meeting each side put forth a single candidate for each committee, so there was no need for STV elections. In addition there were task forces that didn't require elections, and the Committee of Inclusion which has some elected members from the LSB. It all got done pretty efficiently. The LSB, meeting as a Delegates Assembly, also considered one and a half bylaws amendments from the PNB. I say one and a half because the LSB really only got to a vote on one, and just broached the second one without voting on it. There are actually three bylaws amendments that have to go before the LSBs. At this meeting one bylaws amendment failed to get the required number of votes to pass, the other never got to a vote and the third was never even brought up.

At this meeting the LSB actually got to a Treasurer's Report. Unfortunately one of the JUC operatives decided to disrupt it. He didn't understand the acronyms used during the report, he claimed, and so he started shouting out about it. I told him that he could ask his questions after the report proper was finished, but he insisted on shouting and disrupting the meeting. Typical JUC. I got the oral report done, the first in 11 months, and there were questions and answers after it. The JUC disrupter never said exactly what he'd wanted clarified. He did state his opinion that there shouldn't be oral Treasurer's Reports the the LSB meetings. An amazingly stupid proposal. I put out a written Treasurer's Report for all to read.

Some years ago the WBAI LSB voted to hold its regular meetings on the second Wednesday of every month, subject to change by the LSB, which gives us the following schedule:

All of these meetings are set to begin at 7:00 PM.

The Pacifica elections are over, for now. This past fortnight I've gotten an E-mail from the National Elections Supervisor that nominations for, WBAI's local board will open on June 1, 2019, and will close on June 30.

With the elections around Pacifica having gone well the PNB may be poised to help WBAI survive, rather than being a detriment as has happened some years ago.

Our friend, fellow WBAI producer and Saddle Pal Uncle Sidney Smith has been banned from WBAI by General Manager Berthold Reimers. The General Manager will not say why. He won't even tell Sidney why he's banned! This is grossly unfair to Sidney and constitutes abuse of Staff. Why did Berthold ban Sidney?

Official Apollo Program logo

Pickles of the North talked about the Apollo program, and how in 1969 there were actually three missions to the Moon — one in May, which was a dry run for the mission that landed in July, and then another Moon landing that November! And with no bathrooms on the moon, she discovered one small legacy those astronauts left mankind at Tranquility Base!

It is so hard to get to the science related and other topics these days with the politics in America, and the world, getting so bad.

United States International Trade Commission seal
What Are They Doing?

On this program we talked about the probably illegal shenanigans of Donnie Bonespur Trump. He's gotten his trade war going. And he's running off at the mouth about how China will be paying the price of the trade war through the tariffs that Trump is imposing on goods coming in from the so-called People's Republic of China. Of course that's not true. When Trump was in elementary school kids were still being taught about tariffs. The effect of a tariff is that it make goods imported from the targeted country more expensive. And of course the vendors pass the added expense of the tariffs on to the customers. Apparently Trump is just too stupid to understand this basic fact. Trump is claiming that America well make hundreds of millions of dollars by raising the tariffs. The reality is that the American Consumer will be the one paying out those hundreds of millions of dollars. How can we have a President who doesn't understand the basics of tariffs, while imposing them? The world is a strange place, all right.

And we also wondered on the air if one aspect of this stupid tariff action is really aimed at manipulating the Stock Market. The crime of insider trading occurs when someone has inside information about how a particular stock will perform in the near term. The inside trader will know ahead of time to buy a stock that's about to go up or dump a stock that about to go down. We,, wouldn't it be the ultimate in insider trading to be able to actually force stocks to go up or down. One wonders if Trump leaks some information to the people who are handling his finances while he's occupying the Presidency and giving them the chance to sell before he does something stupid that's calculated to depress the markets?

And of course Trump wants to prevent any oversight of his finances. Maybe New York State's investigations of his, and his family's, business activities will unearth some more information on this topic.

We'd rather be talking about gravitational waves, where gold comes from and the effects of global warming/climate change than about the antics of a moron in power who repeatedly claims that he's a genius. But we feel compelled to talk about the things that are causing turmoil in society.

The Measles virus
The Measles Virus
photo credit:CDC/Cynthia S. Goldsmith

Pickles here. For the program I read through a list of diseases that can be prevented through vaccination. Vaccination helps prevent kids from experiencing unnecessary suffering and exposure to further complications of a disease, one of which, in the case of measles, is pneumonia.

Ten years ago, before my mother was able to get that season's influenza vaccination, which included inoculation against the H1N1 virus (also called the swine flu) that had become pandemic, she contracted H1N1 and her immune system was so compromised she also ended up with pneumonia and a case of herpes zoster (shingles), which itself is a complication of chicken pox that lies dormant for years in the affected nerves. My mother had an extremely rough time recovering.

We also had a cousin who decades ago contracted rubella (German measles) while pregnant. Rubella can severely affect the growing fetus. Her daughter was born with some of the most severe complications due to Congenital Rubella Syndrome, one of which is intellectual disability. This was the risk pregnant women were exposed to prior to the development of the rubella vaccine.

The world is a better place with vaccination in it. We need less willful ignorance and more scientific thinking.

SHA-1 no good

On this program we talked about the recent breakthrough where academics Thomas Peyrin from Singapore and Gaëtan Leurent from France have figured out how to make a successful, real world attack on the SHA-1 hashing algorithm. This is a milestone for digital security, for the understanding of cryptographic technique and for relatively affordable computing power. It may be a disaster for ordinary people trying to keep things secure in their on-line transactions.

SHA-1 is referred to as a cryptographic hash. Using the SHA-1 protocols you can perform a set of arithmetical operations on bytes and you'll end up with a hexadecimal number that's 40 digits long. This number is called the hash of the data. The entire process for creating SHA-1 hashes is here. An important property of this hash is that it cannot be reversed to yield the data that it acted on. This is important for a variety of reasons.

Software that generates a cryptographic hash can be used on any set of characters, whether they're a string that you type into the hashing software or a computer file. Here's an example where I show the SHA-1 hash of the string WBAI as I've type it in.

String to be hashedThe Hash

A typical use of cryptographic hashes is to make it hard to steal people's passwords. If you subscribe to an on-line forum, or if you're doing on-line banking, or just about anything else that requires you to put in a password, a cryptographic hash is used. What happens is that you put in your password and it is then hashed with some form of cryptographic hash function by the site you're logging into. The site then stores only the hash, not the password. When you log in the site hashes the password and if that hash matches the hash that's stored on the site you're in. With this method if the site is hacked the hackers only get the hashes, not the passwords, and since the hashes can't be reversed to discover the password the damage from the intrusion is lessened. I'll note that many sites add a salt to the end of the password that you register with and make a cryptographic hash of the combined password and salt. The salt is usually a small, hexadecimal number.

When you go to a site that wants to keep your interactions with it secure a cryptographic protocol is used. And here's where the hashes come in again. These days the TLS certificate security protocol is used. Various cryptographic hash protocols are used for creating the TLS certificate. SHA-1 was used a lot in the past, and it's still getting used now on some sites.

What Peyrin and Leurent have done is show how to force a chosen-prefix collision attack on SHA-1 hashes. In this case collision means that you get the same SHA-1 hash for two different files or strings of data. If an attacker can now forge a document and create a SHA-1 hash for it or create a forged TLS certificate for a bogus Web site and if you're using SHA-1 as the cryptographic hash for that document or Web site you'll never know the difference. You could be giving your bank password or your credit card details to some crook.

Mathematicians, and others, have been challenging the SHA-1 protocol for years trying to compromise it; this is called cryptanalysis. In 2005, they came up with a theory of how a SHA-1 collision could be done. In 2017, a group of cryptanalysts from Google and the Dutch National Research Institute for Mathematics and Computer Science (CWI) created two files for which there was a SHA-1 collision. Now Peyrin and Leurent have found a way to do it for any file. So now if a site you log into still uses SHA-1 as its cryptographic hash for passwords, or in order to secure the connection, there is a potential vulnerability where attackers could forge any SHA-1 signed documents they want, ranging from business documents to TLS certificates.

A part of this current breakthrough has been the fact that it can be achieved relatively inexpensively. In an interview with ZDNET Peyrin said that an effort to create a collision, or two files that have the same SHA-1 hash, could be accomplished, With a budget of less than $100,000, which is really practical. It sure is practical. Any state actor could easily fund such an effort, and hackers with funding could put that much money against an effort too. If you can steal millions of dollars for an investment of $100,000 that's a damned good return on that investment.

The good news is that there are still some cryptographic has protocols around that have not been compromised. Included among those are SHA-256 and, even better, SHA-512. There are also the Blake 2 algorithms, which may not be that well tested yet, and the SHA-3 algorithms, which some do not trust because they are alleged to have been weakened by the NSA. The world is getting dicier.

map credit=Wikimedia Commons/TUBS

We had really intended to talk on this program about the Alabama anti-choice legislation that the Alabama Republicans have even said is unenforceable and is just calculated to get the Supreme Court involved. Unfortunately, we ran out of time; pitching programs are notoriously difficult to manage. We have to pitch and we have to do radio. Unfortunately, we couldn't cram in what we'd wanted to say about the Alabama legislation. I'm sure that we'll be talking about it in the future, however.

In the past fortnight I have updated the following program Web pages:

The Web page for the March 23, 2019 program.

The Web page for the May 4, 2019 program.

The contents of this Web page are copyright © 2019, R. Paul Martin.