Wednesday, October 29, 2014

A lack of Infosec in the home buying process.

I often get a little edgy when people who are dealing with personal information throw around the word “secure.” Also when they say something is “100% safe” it tends to grate me as well. Nothing is secure. We’ve been trying to buy a house and during this process of applying for a mortgage and verifying income with lenders at multiple banks, it’s been a few months, I’ve noticed a few leaks or weak links in the chain of info that unnerve me in terms of my personal information security.

When we first started the process, the mortgage company asked for the usual: bank statements, tax returns, year-to-date profit-and-loss statements, IDs, and check stubs, everything to verify that we can afford the house we’re trying to buy. When I asked how do you want us to provide this information to you, their initial response was “e-mail.”

E-mail is NOT SAFE
Had the person I’m dealing with read their own email disclaimer that goes out on every email they send, they would have noticed that it states:
Do not use email to send us confidential information such as credit card numbers, PIN numbers, passwords, Social Security Numbers, Account numbers, or other important and confidential information.”

If you don’t want anyone to find out something, you definitely don’t send it through e-mail. There are typically at a minimum, 4 copies of an e-mail created for every message sent... sometimes 6.
  1. When you send the e-mail a copy is likely stored in your sent items folder, locally cached. Anyone can open this if they get ahold of your e-mail account, either by system compromise on your own terminal, but guessing your password and breaching your e-mail service provider’s system, or by getting into your e-mail through your mobile device (if you have your e-mail setup on the device). This also includes any other devices that have a copy of the e-mail or access to something like a IMAP server.
  2. The Internet is not a series of pipes. Connections to servers can take several different routes depending on the network load. In fact when you connect to your mail server, if it is offsite, there are multiple nodes on the network between your computer and the mail server itself that are rarely consistent. These nodes are not always "secure." Then the email travels from your mail server, hopefully after authentication, to your recipient’s mail server (between their networks), when it can then be stored and downloaded by your recipient to multiple devices wherever they are downloading the message. Work, Coffee Shops, Non-secure home networks, and schools on computers, tablets, Internet mail accounts, and cell phones.
  3. Not all e-mail uses SSL or TLS to connect. Some e-mail connections transmit e-mail information from point-to-point in clear text often referred to as plain text. This means anyone listening can read every word.
  4. PDF files are not inherently secure even though they require a special program to open them. While you can encrypt a PDF file by requiring a password, this is not the default. Go onto Google and do a search for any term followed by the text “filetype:pdf” and you will see thousands of results from clear text or plain text PDF files. Google knows what is in these files because their servers automatically read the PDFs and in some cases they will optically recognize the contents of the PDF to make a text version.
  5. If you provide a password to someone for the PDF, don’t send it in the same message with the PDF. In fact if you can send it a different way, either via text message or tell someone over the phone, you’re even better off. Then hope they don’t forward the message with the password to someone else, or worse decrypt the message and then forward it (as was done in our case by a county worker).

People still use fax machines?
In the `90s, fax machines were physical machines. While they might have had a buffer where a user could reprint faxes, they were essentially a modem hooked to a copy machine. You hit send and it scanned the image and sent a really low quality version over the phone line directly to another fax machine where it was almost immediately printed.

If the physical security of the fax machine was okay, you didn’t have to worry about someone tampering with the information. If the fax was sent to the wrong number, then all bets were off.

Today, fax machines are entirely different, sometimes they’re actually copy machines with a built-in computer and a hard drive. These messages can stay on these machines for a very long time. If the machines don’t have a custom password, meaning they use the default password, many of the faxes can be retrieved from the machines remotely if someone is savvy enough to go online and look for the manual for the machine itself.

If the fax machine is one of the new cheap all-in-one faxes that receives and transmits over Wifi, then the information will come into the machine, then it’s beamed as an image or an unencrypted file to the computer from the wireless fax printer to a computer. I say beamed, Wifi is not a direct connection either. Wifi transmits in all directions. If the network isn’t “secure,” anyone listening can again pull down this info with a simple network packet sifter. While it’s likely someone will not copy the fax from the airwaves when it comes in, it is a remote possibility if this entity is a potential target for information theft.

Then there is a likely possibility, an Internet fax. This is a web server somewhere, that receives the fax like the old fax machine, and then forwards an image of the fax to someone via unencrypted e-mail (usually). While some of these services can encrypt the image, they’ll likely use the same key for all encryptions for an account. If the user has to log into the service to download the image there is a better for security, but if the image is simply e-mailed sight-unseen, not only is this information stored in the end recipient’s e-mail, it may be stored on the Internet fax server as well: logs, cache files, buffers, and account folders. If the Internet fax service does any sort of OCR (optical character recognition) before creating the unencrypted file, the contents of the fax are again transmitted as clear text.

The "Secure" E-mail Alternative
My mortgage broker sent me a message through what she was calling a "secure e-mail service" which turned out to be a "secure" document exchange from a financial services company. Unfortunately she used "password" as the password. In this service I had no way of changing the password once I logged in.

Another possibility
Something else to consider with the rise of cloud services in information storage is that your personal information may not be in the control of the institutions which are part of the process. If they use cloud-based applications for information storage, all that can be hoped for is strong encryption and very strong passwords. Even these practices can be thwarted by bad habits.

Who gets a copy of the information? It seems like everyone known to man.
I was surprised at the number of individuals being copied on all of the back and forth communications with the Realtor: mortgage brokers, assistants, financial advisors, bosses, inspectors, banks, credit agencies, property owners; the list goes on. Any of these people who doesn’t have a “secure” system in place for any of the messages can become the weakest link in the chain. From a jail broken phone, to an unpatched copy of Windows 98 running on some back office computer, the list of potential vulnerabilities is enormous. What's worse is in my experience most of the government agencies on a local or state level lack the funds necessary to appropriately secure communications, much less look for breaches. For most of my clients I'm only called after a breach has occurred.

Why would someone target these places?
All of the entities I’ve mentioned deal in a lot of personal information. Anyone who wanted to get information on anyone in the process only has to do a little research to determine the infrastructure and shortcomings. Whether it’s intercepting a packet of information delivered by the Postal Service, or not shredding every non-pertinent piece of data, the 250 pages of detailed personal information that we’ve provided to date has been redistributed at least 6 times by my count, not including the copies my e-mail program makes itself. This doesn’t include versioning because of changed closing dates and updates to the applications.

It’s enough to make any information security professional’s head spin.

What can you do?

Get involved in Infosec as a career and change the system. Until then save enough money to pay cash. Once it's all said and done, call to lock your credit records and change all of your accounts. Also be sure to purge sensitive information from all locations where possible.

Tuesday, September 16, 2014

When mail is [potentially] tampered with and you don’t even know it.

I’ve been a fan of the buy postage online and slap it on a Priority Mail envelope for the longest time, until today. I had to send some sensitive information through the mail because I wasn’t quite ready to drive 40 miles round trip to use FedEx, because I feared my package of sensitive info setting in some FedEx box on a weekend awaiting pick-up was a bad idea. I also thought about encrypting the files and sending them digitally but I’m not entirely sure the parties on the other end would be able to deal with the procedure to access them; even passwords elude some people so two-step authentication via an online method was out of the question.

So I opted for the most “secure” method of delivery possible from the US Postal Service, selecting the “Require Adult Signature” tick box in addition to insuring the package on the USPS website. This is really ridiculous in hindsight, but at the time it felt good. I guess I can thank Seinfeld for causing my fears about mail pricing class systems and mail carrier preferential treatment in regard to extra postage or lack-thereof; that's a fallacy as well because if anything more money for "security" means the more precious the cargo.

Patiently I awaited the tracking info on the website to say “Delivered,” but it never came, even though today was the target delivery date. The reason being, the main sorting facility in the city where the package was being delivered dragged their feet on sorting my high priority package. So when it was finally sorted for its destination, it was already almost 10:00 in the morning. It’s likely sitting in the sorted stacks of mail in the sorting facility waiting for delivery in the morning, but this doesn’t keep my mind from wondering.

How could someone tamper with my mail unknowingly?
Physical tampering on a letter is fairly evident. When someone opens an end and tapes it closed you will likely notice because there are physical signs that it has been tampered with. 

I started thinking about the ubiquitous packaging used by the US Postal Service with their campaign “If it fits, it ships.” Sorting facilities likely have stacks of these preprinted boxes lying around. So if someone were to abscond with a package (for a short time while the tracking info said it was at the sorting facility, or in my case “out for delivery”), they could grab a similar package to the one that I have used (eg. Priority Mail Envelope), and go to their local office where a scanner and printer reside.

Then they could rather carelessly extract all of the documents, make copies, take pictures, or scan the items. Next they would use their new package to repackage my documents, and then scan and reprint the delivery label from my package. Place it on the new package and return the items back to the sorting facility or the waiting pile.

It’s not just mail
Then I started thinking about that expensive option of using a service like FedEx who also uses the same sort of standardized packaging. The same scenario applies. Also in regard to FedEx if someone were to notice a pattern of deliveries, they might interlope to satisfy a curiosity.

So, How Can You Really Tell?
Using simple two-step authentication (verification) is one method. The best way I thought of so far was to mark the package in a way that was nearly impossible to replicate, or in a way so that a normal onlooker for the package would not notice. Colored markers, color printout of an image from the web, but basically you mark the package.

Next you would take a picture of the markings and either text, or e-mail it to the recipient (if it is someone you can contact). Let them know that you are sending a package and send them the picture so they can verify that it is indeed the envelope or package that you initially packed.

If you have budgets for custom printing you can print your customized envelope for the internal documents and wrap the interior of your package with something that's not easily replaceable. Companies like Uline sell tape and tamper-evident bags that show indication of tampering. If the document arrives in a non-standard format you know the package was tampered with, and you can then start an investigation with the delivery service.

What companies would be the target of such an attack?
Banks, finance companies, mortgage lenders, payroll companies, Realtors, insurance companies, basically any company that receives sensitive personal information through a standardized delivery service such as FedEx or the US Postal Service in the States. Outbound mail from these companies likely isn't so much of a target in this regard for this type of attack. It's much easier to just take the letter outright if there is no tracking. Mail gets lost everyday right? The bank would assume the information was lost in transit and resubmit. If it was unexpected (like a replacement credit card), the end recipient would be clueless to the attack. Corporations only care about protection of personal information in regard to the bad press or negative media fall-out.

In regard to identity theft the corporations aren't necessarily liable if someone finds a way to game the system, so the companies will not invest money for a potential threat.

Inbound mail or packages from individuals tend to have people's personal information in them, like in instances where the senders are completing a correspondence or form. Since they have a vested interest in maintaining their identity security they will likely opt for more postage.

Final thoughts

Call it paranoia, but I notice patterns, and when I’m sending sensitive info in high profile packages to consistent recipients in a way that would normally not have a time delay or interference, the anomalies in transit do pique my interests. If anyone tells you that snail mail is safer than e-mail or encrypted files they do not know what they are talking about unless they're using a complicated verification method like I've discussed here.

Remember security is an illusion.

Thursday, September 11, 2014

CentOS: Create a Blank file or redirect the default Apache Welcome Page

When managing or hosting a CentOS box, Apache will show the CentOS welcome page. This page contains information you likely don’t want people to have, so things like the fact that you’re running Apache on CentOS. While these things can also show up in the headers, you want to remove the default page in the event someone hits the website from the IP address only or if they use a domain that resolves to the box, but there is no directory setup for that domain.



Quite a few of the online discussion forums and even the notes on the welcome screen suggest that you should visit the file at /etc/httpd/conf.d/welcome.conf on CentOS.

If you cat the file you’ll likely see something like this:

# This configuration file enables the default "Welcome"# page if there is no default index page present for# the root URL. To disable the Welcome page, comment# out all the lines below.                                                                       
<LocationMatch "^/+$">
    Options -Indexes
    ErrorDocument 403 /error/noindex.html
</LocationMatch>

Their suggestion is to comment out the lines. By doing so, you’re not presenting the visitor with a blank page, but rather a different error message. To edit the file you’ll need to be logged in as root (su -) or be a member of sudoers and use sudo.

Use the editor of your choice. I’m using emacs myself, but vi will also work. So my command looks like:

emacs /etc/httpd/conf.d/welcome.conf

So if I comment out those lines with # comment tags and save the file, then nothing happens.

#<LocationMatch "^/+$">
# Options -Indexes
#ErrorDocument 403 /error/noindex.html
#</LocationMatch>

This is because changes to configuration files in Apache require a server restart. No need to restart the box, just the Apache server; as root:

service httpd restart

You should see something similar to the following:




When you visit the page showing the welcome page before, now you’ll see a Forbidden error. This still lets savvy users know that you’re running Apache.


For me this wasn’t enough, so I took it a step further.

Since I don’t want anyone to see anything, I created a file in /var/www/error called noerror.php. Assuming you’re running PHP on your box you can do this with something like touch, so :

touch /var/www/error/noerror.php
If you want the page to blank, then you’re done with the file at this point. If you're not running PHP but only want the blank page you can call it noerror.html

For the Redirect
If you want the file to redirect somewhere else you can edit the contents to do something like this:

<?php header('Location: http://www.somedomain.com'); ?>

If you wanted this to be a permanent redirect you can add the 301 redirect declaration heard above the header line. Note if you permanently redirect you will have to flush your cache to access a directory that delivered a 403 Forbidden error.

header("HTTP/1.1 301 Moved Permanently");
header("Location: http://www.somedomain.com");


Set appropriate permissions on the file for your setup.

Edit the welcome.conf file again. (Usually you can press the up arrow on your keyboard to cycle through.)

Uncomment the lines suggested by the comments. So you should be back to this.

<LocationMatch "^/+$">
    Options -Indexes
    ErrorDocument 403 /error/noindex.html
</LocationMatch>

Change the ErrorDocument path to /error/noerror.php, so the contents should look like this:

<LocationMatch "^/+$">
    Options -Indexes
    ErrorDocument 403 /error/noerror.php
</LocationMatch>

Save the file. Restart the webserver again. Now instead of seeing the Welcome Screen you should see the domain from the redirect.

Hope this helps someone.


Note: If you don’t have an index file in the server you’re redirecting to it might create an endless loop.

Monday, December 23, 2013

Why time travel into the past is not possible

There is a simple reason for why time travel into the past isn’t possible. Everything revolves in a predictable motion from sub atomic particles all the way up to planets around their suns and galaxies. With these rotations charges are exchanged or kept at atomic and subatomic levels, and everything works in reaction causing what we see as life or existence. There is no historical record of space-time (space time is simply man’s observation), and changes and fluctuations based on subatomic inconsistencies and interactions exist; random chaos at atomic levels.

Without a record of spacetime going backward in time would mean that some reactions might reverse while others which are unpredictable would not (eg. nuclear chain reactions). If you could move at the speed of light around the sun (matter can't travel that fast) you would simply be traveling around the sun at the speed of light in whichever direction desired... sorry Star Trek fans... no whales today.

The closest thing, involving stasis… a physical recording.

If you record all of the particles in motion as an event happens in some system you might be able to recreate a representation of the scene of the event using the involved structures, but you can not recreate the event itself, you can only alter the replayed recreation or arrangement of molecules and atoms. All matter would have to be contained in a confined space, and all molecular motion would need to be stopped in that confined space, in order to accurately recreate an event and capture all involved components at a sub-atomic level; thermodynamic equilibrium would need to be achieved to insure a proper record. To record all of the particles without interfering with their structure would require disassembly for a proper mapping; a deconstruction.

The process of structural recording should never, ethically be done on a living sentient thing which would also prevent things such as teleportation or exact atomic cloning of living organisms. The reason for this is because stopping all atoms in their present state would cause their [natural] interactions to fail and their atomic structures would be disrupted. If the matter was not stopped prior to recording, the speed of the atomic breakdown could prove extremely painful and the instantaneous reactions between cells in the organism would make the recorded position of the future recorded cells in a state of reaction. Imagine burning every cell off of your body one cell at a time, the reassembled image of the original (yourself) would contain evidence of the trauma because you couldn’t record all of the cells in their paused molecular subatomic state at the same time. This is all of course based on the organism itself surviving the pause or deceleration to maximum entropy.


Furthermore upon reassembly if the recorded cells were to be rearranged there would be a chance of accidentally creating an excited nucleus causing a fission reaction.

I would like to state that I've not studied these things at any level at all and this is simply my uneducated hypothesis based on my observation.

Sunday, December 22, 2013

The universe isn't a hologram, but it looks that way... here's why.

I read a headline on the Nature site stating “Simulations back up theory that Universe is a hologram.” I was surprised this was news or that they had taken a time to create a computer model to discern this bit of information. A hologram, according to Wikipedia, is a representation of an image in space (not outer space) made from an apparently random structure or representation of either varying intensity, density, or profile. According to the article:
“A team of physicists has provided some of the clearest evidence yet that our Universe could be just one big projection.”
Maybe I’m the only one who sees the universe this way, but I was thinking, in a more modern parlance, “duh.” Then they go on to talk about Quantum Physics and a 10-Dimensional Theory of Gravity and how the universe will be hopefully more easily explained in the future in terms of Quantum Theory. Okay, so there we have a problem.

Everything we see from Earth and near space is indeed a projection on whatever surface we’re using to view it (technically)… either it’s the lenses in our eyes, a camera lens, or the output of a computer model based on data that we’re gleaned from observation. No two eyes are alike, no two people are alike, and while we may see things similarly we do not see the exact same things.

Heavenly bodies beyond our solar system as we see them in the sky are but a historical representation of something that once was in time. The distance of the stars, each multiple light years away means that the light we see varies in age (it takes a really long time to get here). It takes longer for light from a star much further away to reach us. Any calculation in the movement of these stars has to be based on fallible things such as time and the amount of light and waves being measured, because there is not enough historical data for us to accurately predict how far away an object outside our solar system really is. We as a people with our present intellects have not existed long enough to gather enough information about the movement of all of the stars using the latest technology. We still get excited about landing remote controlled vehicles successfully in our own solar system... billions of dollars have been spent on this very act.

Additionally because objects can vary in size and because we have no way of discerning the size accurately in three dimensions here on Earth from our vantage point, parallax is a major issue and prevents us from actually appropriately gauging distance. We would have to map every star and object in the sky at all times from more than one vantage point. Add in assumptions for constants such as the speed of light in a vacuum (unbent by gravity), and because we can not measure all of the factors acting on the minute amounts of light that make it to our instruments we can make no solid theories as to anything remotely substantial, only calculations of the subset of data required to properly model our perceptions which contain very small amounts of data in the grand scheme of things. We can theorize about what atoms exist on other planets in our solar system but we still don't know.

Furthermore, this is all unprovable (in terms of their scientific research) because we will not exist long enough to determine whether the experiments are true, therefore we should stop wasting efforts on any sort of scientific rational relating to Quantum Physics, Quantum Mechanics, and Quantum Theory and focus on making life of today and tomorrow better for the people who exist now. There are so many more things that matter in life. What's next, interstellar space travel? Leave Sci-fi as a hobby. Don't make the rest of society pay for actual real science fiction through failed experimentation. We are not in The Matrix, we are not in a simulation, don't get your hopes up. Life will be just as cruel tomorrow.

Tuesday, December 17, 2013

Allstate Drivewise. A huge failure in potential.

I've been meaning to get this one up for some time. For a short time I had signed up for Allstate's Drivewise program. Driving very few miles as compared to most other drivers and the fact that I don't drive like an idiot, I figured it was safe (nothing to lose). The problem is the data set that they've created their perfect driver rating system around are likely based on their payouts for accidents by type of braking, time of day, mileage, and excessive speed (80+ mph). Okay sounds good so far. I kind of figured this going in.

Overwhelmingly statistics apparently aren't on my side when they're being applied by Allstate.

When you dig into the Drivewise data after receiving your first set of "grades" you'll see 4 nice looking graphics in the interface. One for mileage, one for braking, one for time of day, one for speed in excess of 80mph.

Mileage

They go on to tell you that the mileage is a calculated projection of how many miles they think you'll drive based on your daily driving. If you're sticking to what they expect this shouldn't be a problem. I don't have a problem with mileage from the device because it coincides with the mileage from my odometer (which they already had on file). Spoiler, if you tell them you only drive 7,000 miles a year, and you really drive 50,000 the program will not give you a discount and the agent will have access to your actual mileage and will likely raise your premiums accordingly.

Braking

The braking section of the graphics show two things. "Hard Braking" and "Extreme Braking" are the two categories. According to Drivewise, hard braking is when you decelerate by 8mph in less than 1 second. If you're following a bus that makes frequent stops and you can not change lanes, depending on the bus driver's performance and lack of indication you will have a hard braking event (or two or four), someone walks out in front of you, a dog in the road, you get the idea. Extreme braking is when you decelerate by 10mph in less than 1 second. So if you come up to a short traffic light that has a 3 second yellow (these do exist) from 50mph and begin decelerating, you will likely have an extreme braking event. When you have 4 hard braking events and 1 extreme braking event over the course of 3 weeks this erodes any discount you would expect to receive from the program. I do mean ANY and ALL discounts.

Time of day

The time of day expectations for the program are really optimistic for Allstate. They have 4 categories. They've said that the "Lowest Risk" for accidents is on weekends between 5am and 11pm. The same time that most teens are out driving to work or shopping, etc. The "Low Risk" time is from 4am-12pm on weekdays (When teens are driving to school.). "Moderate Risk" is from 12pm to 11pm on Weekdays (When teens are on their way home from school or on their way to work at night). If you're out past 11pm you are driving at the "High Risk" time which is from 11pm-4am on weekdays and from 11pm-5am on weekends (Drunk people dodging, but luckily most teens are at home curiously enough).

Speed >=80

This one is pretty straight forward however they give a whole range of grading here where you basically stay below 80 or you don't. I don't understand this one at all because if you go above 80 you should be in the very high-risk category for drivers. Go get a racing license and take it out on the track. Now if you're in a state like Florida or Montana where you may encounter a 75mph speed limit, then it's understandable that this may need to be changed, but they're not trying to hide anything from you here.

My Suggestions

If Allstate really wanted their Drivewise program to be highly successful for them and to actually reward people who are definitely driving safely they would look at a different set of parameters.

Speed

Since the device already knows how fast the driver is going, it should be able to tell whether they are one of those people who can't maintain a constant speed. If the driver accelerates extremely rapidly (0-60 in 10 seconds) then they should have a record of drag racing on file. This could be road rage (extremely risky) or someone not paying attention to their lane ending... this might also obviously be drag racing, but the risks are the same. If the driver is running 65 and catches someone doing 45 and does not overtake or switch lanes, then they are not paying attention. Also if they decelerate by this much and maintain the speed it means that they either entered a construction zone, or they slowed down to the flow of traffic. If the device sees people accelerating and decelerating regularly it should know that the person is in a stop and start traffic jam. It already knows the time of day, so if the person is in rush hour stop and start traffic then it should know and place them in a higher risk category (for a low impact collision).

Location vs Speed

The device already has the ability to track vehicle location because it's transmitting on a cellular signal. If Google and most GPS systems can tell how long it will take to get to a destination, the device should be able to do this as well. This means if the driver is speeding and the device knows it, then they are risky and should not receive the discount. Something like 65 in-town in a school zone and they should put the driver into the high-risk category as well (for a high impact collision).

Crazy Driving

Add a couple of accelerometers to the device and now you can actually find the people who are weaving at risky times (drunks) and the people who are weaving on their daily commute (food-eating, texting, doing their make-up, you know... people who are exhibiting risky behavior). Also you can find the people who are insanely driving and weaving in and out of traffic with fast bursts of acceleration. Like the yellow semi truck that didn't like my Chicago Black Hawks tag.

Time of day

The Allstate Drivewise program needs to get a realistic idea of when people drive and when people don't drive in order to be successful. If I'm driving safely at a time of day when there is nobody on the road but me, then I shouldn't be in the high-risk category. If I'm driving when there are fewer people who are on the road like an afternoon after rush hour, I shouldn't be in a moderate risk category. If I'm driving when EVERYONE is off of work at the same time as they are on a Weekend, then I should be in a very high risk category (more people on the road=greater chance of an accident). If I'm driving when people are trying to get to work on time or they're trying to rush home after a bad day at work those are risky times as well.

I think if Allstate had actually taken the time to utilize the system instead of cutting corners, they could actually reward the people who are indeed safe drivers and profit from the people who aren't.

Suggested Upgrades

Add a couple of wireless cameras to the device. Let's put one in the front and in the back. Let's actually get some documentation on why someone is stopping abruptly. Don't outsource the research to a country overseas. Now you can have people in the US work from home and analyze the footage. It would help keep people off of the streets and off of the roads and it would also help with those fender benders that don't get reported. Not to mention auto theft, erratic driving and whether someone's towing a trailer at high speed. Yeah I'm talking about the people in the fast lane running 80mph towing the trailer that's rated for 45mph max.

Make the device aware on its surroundings. Add a hygrometer. Let's see if people are driving in the rain or driving when it's dry. Let's take some barometric pressure readings on the Drivewise device. Zero visibility thunderstorm, do you slow down? They should know. Let's add a thermometer. Driving on ice? The device should know. If you drive excellent on ice, then you should be rewarded. If you're more like a skating star doing twirls, whirls, and 720 degree spins, you should be penalized.

Make it driver aware, add something to the keychain so when a certain driver is in a closer proximity it knows who is driving the car. Sure you could swap keys, but this would definitely help if you had teens driving the car. That way they could tell who was a safe driver and who wasn't. Want the discount back, don't let junior drive your car.

All-in-all I'm 100% positive about making the roads a safer place.

What is the Allstate Drivewise really about?

The Allstate Drivewise device is not out to make the roads safer. In actuality if we look at the device from a completely different approach, it's a now a gimmick that invades the privacy of the driver. Allstate isn't interested in whether someone is a safe driver. They're interested in finding ways to make you pay high premiums. The higher risk they can make you in their book, the better off they are (monetarily). My agent seemed disappointed that I was healthy when applying for Life Insurance... gee, I wonder why that is? The same logic applies to car insurance. If you're a truly bad driver, the system will punish you, but if you're a good driver, then it's up to the insurance company to make up for the loss.

Realistically if we look at the stats from the US National Transportation Safety Board, most people aren't at risk of getting into a major accident on the road statistically. Only the select few. If we can keep those people off of the street, then sign me up. Until then, I'm keeping the Allstate Drivewise out of my vehicle because it makes me think about something when I'm behind the wheel that isn't related to my driving performance at all, and that's whether or not I'm going to be financially penalized about something out of my control. And when they do penalize me for something which is not a risk at all, I appear to them to be an "unsafe" driver, which helps them to justify charging more.

Get Wise Allstate.


A note on the edits
Originally I had mentioned that it might have been up to the device programmers, but that's not really fair. Once a product like this passes enough scrutiny panels in the production phase, good intentions of the designers are left in a pile for the sake of a little bit of savings. As long as the device gives a plausible illusion of savings, then the company will proceed.