<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0"><id>tag:blogger.com,1999:blog-7347279</id><updated>2012-01-18T12:20:32.943-05:00</updated><category term="andrew jaquith" /><category term="grey goo" /><category term="security token" /><category term="michael santarcangelo" /><category term="flash" /><category term="email scams" /><category term="sunncomm" /><category term="hd moore" /><category term="lsp" /><category term="gene hodges" /><category term="suggestion" /><category term="infection" /><category term="flexispy" /><category term="vulnerability" /><category term="rich mogull" /><category term="strategy" /><category term="spycar" /><category term="signacert" /><category term="privacy" /><category term="compare people facebook app" /><category term="adobe" /><category term="anti-spyware coalition" /><category term="norman" /><category term="cold boot attack" /><category term="rat" /><category term="credentialed malware" /><category term="cyber command" /><category term="rsnake" /><category term="detection" /><category term="stormbringer" /><category term="scams" /><category term="lurene grenier" /><category term="f-secure" /><category term="chet wisniewski" /><category term="eset" /><category term="rich walchuck" /><category term="icontact" /><category term="variant" /><category term="junk mail" /><category term="alwil" /><category term="keylogger" /><category term="james turner" /><category term="alan shimel" /><category term="email" /><category term="authentium" /><category term="conficker" /><category term="µTorrent" /><category term="scott fulton" /><category term="patch" /><category term="google account" /><category term="jeff kephart" /><category term="facebook" /><category term="anton chuvakin" /><category term="tavis ormandy" /><category term="thunderbyte" /><category term="church-turing thesis" /><category term="ntfs" /><category term="staroffice" /><category term="wildlist" /><category term="hybrid" /><category term="sandboxie" /><category term="pharming" /><category term="matt hines" /><category term="apt" /><category term="tad heppner" /><category term="eric wilhelm" /><category term="bartpe" /><category term="rootkit unhooker" /><category term="postbag" /><category term="dvforge" /><category term="metasploit" /><category term="anti-malware" /><category term="time bomb" /><category term="gunter ollmann" /><category term="greg hoglund" /><category term="total defense inc" /><category term="dave marcus" /><category term="digital immune system" /><category term="man-in-the-middle" /><category term="adam j. o'donnell" /><category term="coseinc" /><category term="kris braun" /><category term="daniel miessler" /><category term="malware removal" /><category term="jeremiah grossman" /><category term="xss worm contest" /><category term="paul ducklin" /><category term="mac" /><category term="threatpost" /><category term="epidemiology" /><category term="statistics" /><category term="dan geer" /><category term="siteadvisor" /><category term="google" /><category term="michael st. neitzel" /><category term="commercial malware" /><category term="virtualization" /><category term="safe hex" /><category term="false positive" /><category term="behaivoural stealth" /><category term="nruns" /><category term="proactive vs reactive" /><category term="cloud-based scanning" /><category term="prevention" /><category term="osx" /><category term="DLL search path" /><category term="openoffice" /><category term="ed moyle" /><category term="sector conference" /><category term="onecare" /><category term="whitelist" /><category term="security blogger summit" /><category term="general purpose computing" /><category term="bell canada" /><category term="best practice" /><category term="hispasec" /><category term="argument switching" /><category term="cytrap labs" /><category term="amtso" /><category term="peter lindstrom" /><category term="safe web browsing" /><category term="clickjacking" /><category term="polymorphism" /><category term="andreas clementi" /><category term="malware naming" /><category term="proventsure" /><category term="george kurtz" /><category term="mandiant" /><category term="splog" /><category term="snake oil" /><category term="robert hansen" /><category term="malware experience" /><category term="hack" /><category term="vice" /><category term="fixed first order functionality" /><category term="virustotal" /><category term="mike rothman" /><category term="backdoor" /><category term="ryan naraine" /><category term="troll" /><category term="danah boyd" /><category term="kevin mcaleavey" /><category term="peter kleissner" /><category term="downloader" /><category term="luis corrons" /><category term="don c weber" /><category term="program" /><category term="hypervisor" /><category term="spyware terminator" /><category term="harry sverdlove" /><category term="dick morrell" /><category term="premier election solutions" /><category term="international space station" /><category term="joanna rutkowska" /><category term="image spam" /><category term="zero-day" /><category term="trend micro" /><category term="false authority syndrome" /><category term="toralv dirro" /><category term="3rd party patch" /><category term="phishing" /><category term="windows update" /><category term="mikko hypponen" /><category term="techdirt" /><category term="adam dodge" /><category term="blue security" /><category term="script kiddie" /><category term="ipod" /><category term="eEye" /><category term="unix" /><category term="attack vs defense asymmetry" /><category term="twitter" /><category term="boot sector virus" /><category term="mark zuckerberg" /><category term="mark russinovich" /><category term="tom kelchner" /><category term="virus" /><category term="eddy willems" /><category term="lenny zeltser" /><category term="anti-spyware" /><category term="EP_XOFF" /><category term="saber security" /><category term="gmail" /><category term="stanislav shevchenko" /><category term="sympatico" /><category term="proactive protection" /><category term="nostalgia" /><category term="cd-man" /><category term="here you have" /><category term="operation spamalot" /><category term="security failure" /><category term="dell" /><category term="remediation" /><category term="benevolent botnet" /><category term="peter norton" /><category term="amrit williams" /><category term="encryption" /><category term="vesselin bontchev" /><category term="cross-view diff" /><category term="polypack" /><category term="suggested reading" /><category term="secunia" /><category term="paul boutin" /><category term="mobile malware" /><category term="trustlayer" /><category term="marcus ranum" /><category term="anti-phishing" /><category term="bank of america" /><category term="passphrases" /><category term="mcafee" /><category term="autoplay social engineering" /><category term="department of defense" /><category term="backup" /><category term="vikram phatak" /><category term="michael santarcanjelo" /><category term="alias companion virus" /><category term="returnil" /><category term="web-based malware" /><category term="simulation" /><category term="integrity checking" /><category term="packed malware" /><category term="allysa myers" /><category term="vulnerability escrow" /><category term="authority" /><category term="defense in depth" /><category term="law enforcement" /><category term="generality of interpretation" /><category term="network security podcast" /><category term="jonathan gross" /><category term="sophos" /><category term="offensive full disclosure" /><category term="noah shiffman" /><category term="cracker" /><category term="blue frog" /><category term="poison" /><category term="winpe" /><category term="spyphone" /><category term="gary golomb" /><category term="halting problem" /><category term="jose nazario" /><category term="badware" /><category term="chris hoff" /><category term="android" /><category term="anti-malware community watch" /><category term="ed felten" /><category term="patchguard" /><category term="speech recognition" /><category term="osx/leap" /><category term="transparency" /><category term="gamma" /><category term="nss labs" /><category term="threat centric security" /><category term="persistence" /><category term="malicious software removal tool" /><category term="ssl" /><category term="accuvote ts" /><category term="auscert" /><category term="crimeware kit" /><category term="tbcheck" /><category term="grisoft" /><category term="security user" /><category term="morro" /><category term="exploit" /><category term="kai roer" /><category term="anti-malware protocols" /><category term="cme" /><category term="disposable email address" /><category term="wilders security forum" /><category term="gpcode" /><category term="obscurity" /><category term="vappware" /><category term="johannes ullrich" /><category term="HIPS" /><category term="sarah gordon" /><category term="zdnet" /><category term="vikram thakur" /><category term="failure rate" /><category term="proof of concept" /><category term="fred cohen" /><category term="posts of the week" /><category term="graham cluley" /><category term="richard bejtlich" /><category term="anti-spam" /><category term="social networking" /><category term="scareware" /><category term="application whitelist" /><category term="robert sandilands" /><category term="blacklist" /><category term="jerome segura" /><category term="windows" /><category term="thomas c. greene" /><category term="mario vuksan" /><category term="mcwresearch" /><category term="clean boot" /><category term="removal tools" /><category term="administrivia" /><category term="exploit prevention labs" /><category term="rfid" /><category term="tyler reguly" /><category term="paul wilders" /><category term="slate" /><category term="alexander gostev" /><category term="eva chen" /><category term="fud" /><category term="vervata" /><category term="social engineering" /><category term="malcon" /><category term="josh corman" /><category term="vml" /><category term="bbc" /><category term="avast" /><category term="steve white" /><category term="hbgary" /><category term="bootroot" /><category term="first4internet" /><category term="stuxnet" /><category term="execution precedence companion virus" /><category term="andreas marx" /><category term="badware busters" /><category term="blogger" /><category term="the register" /><category term="server-side polymorphism" /><category term="nishad herath" /><category term="abstraction" /><category term="tactics" /><category term="outside-the-box analysis" /><category term="history" /><category term="sandbox sprawl" /><category term="security expert" /><category term="zulfikar ramzan" /><category term="expert" /><category term="threats" /><category term="ethics" /><category term="virus spreader" /><category term="cyberwarfare" /><category term="matousec" /><category term="logic bomb" /><category term="untangle" /><category term="cellphone" /><category term="in the wild" /><category term="malware creation" /><category term="gentoo" /><category term="accountability" /><category term="pwn2own" /><category term="farhad manjoo" /><category term="blackhat" /><category term="malware" /><category term="dancho danchev" /><category term="stealthkit" /><category term="liam tung" /><category term="lonervamp" /><category term="nick harbour" /><category term="john strand" /><category term="sandi hardmeier" /><category term="komoku" /><category term="safety" /><category term="chrome" /><category term="classification" /><category term="ars technica" /><category term="password stealer" /><category term="mary landesman" /><category term="xkcd" /><category term="heuristics" /><category term="marcin  wielgoszewski" /><category term="marc maiffret" /><category term="spam" /><category term="blended threat" /><category term="gdata" /><category term="dropper" /><category term="securities exchange commission" /><category term="mal-link" /><category term="full disclosure" /><category term="roel schouwenberg" /><category term="2 factor authentication" /><category term="dennis fisher" /><category term="didier stevens" /><category term="anti-virus is dead" /><category term="carl von clausewitz" /><category term="securiteam" /><category term="definition" /><category term="credibility" /><category term="brain" /><category term="trojan" /><category term="stock spam" /><category term="user education" /><category term="virus creation" /><category term="jamie butler" /><category term="microsoft passport" /><category term="dmitry sokolov" /><category term="trustware" /><category term="single sign-on" /><category term="blue pill" /><category term="mitchell ashley" /><category term="monkey" /><category term="ralf benzmüller" /><category term="barack obama" /><category term="drm" /><category term="bacn" /><category term="cia triad" /><category term="worm" /><category term="marketing" /><category term="buckshot yankey" /><category term="clamav" /><category term="privacy software corporation" /><category term="terminology misuse" /><category term="virus writer" /><category term="anti-virus" /><category term="in-the-cloud" /><category term="linus torvalds" /><category term="malware qa" /><category term="drive-by download" /><category term="frictionless sharing" /><category term="exotic execution" /><category term="av-test.org" /><category term="offensive computing" /><category term="panda software" /><category term="david chess" /><category term="messagelabs" /><category term="renaming companion virus" /><category term="mediamax" /><category term="rob slade" /><category term="threat agents" /><category term="panacea" /><category term="risk" /><category term="total protection" /><category term="kevin townsend" /><category term="sony bmg" /><category term="rootkitdotcom" /><category term="cross platform" /><category term="sysinternals" /><category term="socketshield" /><category term="ghacks" /><category term="zeus" /><category term="peter silberman" /><category term="cyberweapon" /><category term="asarium" /><category term="spyware" /><category term="sean sullivan" /><category term="greyware" /><category term="wall of shame" /><category term="rick moy" /><category term="usability" /><category term="email worm" /><category term="frisk" /><category term="neo-call" /><category term="zone alarm" /><category term="linden labs" /><category term="voting machine" /><category term="advanced persistent threat" /><category term="bruce schneier" /><category term="okopipi" /><category term="todd woodward" /><category term="test file" /><category term="sunnet beskerming" /><category term="overwriting virus" /><category term="functional definition" /><category term="av-comparatives" /><category term="infosecsellout" /><category term="joe barr" /><category term="principle of least privilege" /><category term="comment spam" /><category term="lifehacker" /><category term="aviram" /><category term="race to zero" /><category term="michael murphy" /><category term="randy abrams" /><category term="sans" /><category term="botnet" /><category term="beastie boys" /><category term="ticker" /><category term="peter stelzhammer" /><category term="david maynor" /><category term="benny ketelslegers" /><category term="paypal" /><category term="behavioural analysis" /><category term="disclosure" /><category term="partial disclosure" /><category term="virus exchange" /><category term="alex eckelberry" /><category term="md5" /><category term="crossover" /><category term="malware kits" /><category term="raide" /><category term="drazen  drazic" /><category term="agnitum" /><category term="openid" /><category term="graham ingram" /><category term="halvar flake" /><category term="DNS" /><category term="warez" /><category term="cyberwar" /><category term="identity management" /><category term="robin bloor" /><category term="metamorphism" /><category term="john thompson" /><category term="sectheory" /><category term="bit9" /><category term="layered service provider" /><category term="securosis" /><category term="game theory" /><category term="martin overton" /><category term="multi-partite" /><category term="mara" /><category term="anti-malware testing" /><category term="digital rights malware" /><category term="ryan permeh" /><category term="xcp" /><category term="black hat conference" /><category term="derek soeder" /><category term="firefox" /><category term="sergio alvarez" /><category term="andrea lelli" /><category term="second life" /><category term="the virus alert blog" /><category term="iphone" /><category term="ethical hacker" /><category term="popup" /><category term="david harley" /><category term="sophail" /><category term="thierry zoller" /><category term="energizer" /><category term="ephemerality" /><category term="diebold" /><category term="symbian" /><category term="behaviour blocking" /><category term="zert" /><category term="responsible disclosure" /><category term="barracuda" /><category term="idg news service" /><category term="chris wysopal" /><category term="phorm" /><category term="bias" /><category term="ise" /><category term="brian krebs" /><category term="future" /><category term="bittorrent" /><category term="TOCTTOU" /><category term="extrusion" /><category term="on-demand scanning" /><category term="security" /><category term="javier guerrero díaz" /><category term="th8.us" /><category term="wince" /><category term="mebroot" /><category term="cloud" /><category term="online banking" /><category term="KHOBE" /><category term="rootkit" /><category term="adware" /><category term="short URLs" /><category term="security catalyst" /><category term="hacker" /><category term="research paper" /><category term="computer associates" /><category term="chrome os" /><category term="path precedence companion virus" /><category term="isc" /><category term="sun tzu" /><category term="checkpoint" /><category term="stealth" /><category term="digital signatures" /><category term="whitehat" /><category term="stardust" /><category term="victim" /><category term="compartmentalization" /><category term="anti-av revolt" /><category term="macro virus" /><category term="china" /><category term="companion virus" /><category term="defcon" /><category term="consumer reports" /><category term="KNOS" /><category term="chainn" /><category term="hp" /><category term="vista" /><category term="non-persistence" /><category term="cyberscrub" /><category term="sandbox" /><category term="bitdefender" /><category term="myth" /><category term="responsibility" /><category term="mark gasson" /><category term="eicar" /><category term="apple" /><category term="bufferzone" /><category term="passwords" /><category term="kaspersky" /><category term="memetics" /><category term="graphs" /><category term="maxim weinstein" /><category term="fault tolerance" /><category term="codecs" /><category term="complexity" /><category term="epsilon" /><category term="vx" /><category term="multi-media malware" /><category term="intended virus" /><category term="whole product testing" /><category term="david chartier" /><category term="green border" /><category term="viguard" /><category term="buckshot yankee" /><category term="ibm" /><category term="intrusion" /><category term="developer verification" /><category term="mikhail penkovsky" /><category term="risky business podcast" /><category term="instructables" /><category term="on-access scanning" /><category term="prevx" /><category term="andre gironda" /><category term="bud tribble" /><category term="anti-virus fight club" /><category term="martin mckeay" /><category term="hype" /><category term="updata partners" /><category term="stopbadware" /><category term="pedro bustamante" /><category term="linux" /><category term="autorun worm" /><category term="robert graham" /><category term="breach" /><category term="sunbeltblog" /><category term="copilot" /><category term="guillermito" /><category term="cult of the dead cow" /><category term="john sharp" /><category term="month of X bugs" /><category term="subvirt" /><category term="symantec" /><category term="malware writer's conference" /><category term="blog" /><category term="security awareness" /><category term="cdman83" /><category term="techworld" /><category term="software piracy" /><category term="rogue certificate" /><category term="rogue anti-malware" /><category term="correction" /><category term="mike ellison" /><category term="malware writer" /><category term="tegam" /><category term="microsoft" /><category term="unreal" /><category term="known-malware scanning" /><category term="fail" /><category term="measure-vs-countermeasure" /><category term="dan goodin" /><category term="measuring flaw finding effectiveness" /><category term="identity theft" /><category term="clay shirky" /><title type="text">anti-virus rants</title><subtitle type="html">devising a framework for thinking about malware and related issues such as viruses, spyware, worms, rootkits, drm, trojans, botnets, keyloggers, droppers, downloaders, rats, adware, spam, stealth, fud, snake oil, and hype...</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/posts/full" /><link rel="alternate" type="text/html" href="http://anti-virus-rants.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/full?start-index=26&amp;max-results=25&amp;orderby=published" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>556</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Anti-virusRants" /><feedburner:info uri="anti-virusrants" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by/2.0/" /><logo>http://creativecommons.org/images/public/somerights20.gif</logo><feedburner:emailServiceId>Anti-virusRants</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site.</feedburner:browserFriendly><entry><id>tag:blogger.com,1999:blog-7347279.post-3460802052957748546</id><published>2011-12-27T15:26:00.001-05:00</published><updated>2011-12-27T15:26:39.922-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="scams" /><category scheme="http://www.blogger.com/atom/ns#" term="ethics" /><category scheme="http://www.blogger.com/atom/ns#" term="marketing" /><category scheme="http://www.blogger.com/atom/ns#" term="randy abrams" /><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="eset" /><title type="text">the problem with the "like" trade</title><content type="html">earlier today randy abrams posted an interesting take on facebook advertising and how misleading the word "like" can be (&lt;a href="http://randy-abrams.blogspot.com/2011/12/facebook-misleading-advertising.html"&gt;http://randy-abrams.blogspot.com/2011/12/facebook-misleading-advertising.html&lt;/a&gt;). this reminded me of a beef that i've apparently had going back at least as far as may of this year (judging by the timestamp on the screenshot i took).&lt;br /&gt;&lt;br /&gt;specifically, randy said the following:&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;If I have to “like” a page to get the information I want, I don’thave a problem with that&lt;/blockquote&gt;well, with all due respect to randy, &lt;b&gt;i do have a problem with it&lt;/b&gt;. randy makes some good points about the way people's pictures get used in facebook ads when they "like" things, but a point he neglected is that forcing users to "like" or otherwise post about something before they can see the content they've been lured with is a popular tactic in facebook scams.&lt;br /&gt;&lt;br /&gt;now, i'm not trying to suggest that security companies making use of this marketing methodology are scam artists (though i am tempted to say that all marketing is in some way a scam) but they should be aware that by utilizing this sort of marketing they are effectively endorsing a marketing methodology (developed by facebook) that breeds victims. i don't expect facebook to care about such things, since such trickery is how they make their money, but i certainly expect security companies (especially ones with as strong a leaning towards empowering users as eset) to know better than to go along with facebook's questionable methods and do things like this:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-uvtD2OqMZgY/TvolFQD61NI/AAAAAAAABXA/rVPYnrZjlaE/s1600/eset-like-begging.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-uvtD2OqMZgY/TvolFQD61NI/AAAAAAAABXA/rVPYnrZjlaE/s1600/eset-like-begging.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;"like"s are not something to be bought from users in exchange for free or otherwise tempting content. they are an endorsement and as such can't be legitimate until &lt;i&gt;&lt;b&gt;after&lt;/b&gt;&lt;/i&gt; the user has sampled the content. the idea of exploiting illegitimate user endorsements should be recognized as unethical and should be understood to have consequences. by using the sort of techniques that scam artists thrive on, one is basically training people to be victims. i expect better from security companies and i think you should too.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-3460802052957748546?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=3Do4WwBmzrg:WPfV7hOTHKA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=3Do4WwBmzrg:WPfV7hOTHKA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=3Do4WwBmzrg:WPfV7hOTHKA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=3Do4WwBmzrg:WPfV7hOTHKA:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/3Do4WwBmzrg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/3460802052957748546/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=3460802052957748546" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/3460802052957748546" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/3460802052957748546" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/3Do4WwBmzrg/problem-with-like-trade.html" title="the problem with the &quot;like&quot; trade" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-uvtD2OqMZgY/TvolFQD61NI/AAAAAAAABXA/rVPYnrZjlaE/s72-c/eset-like-begging.PNG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/12/problem-with-like-trade.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-2741110754369096625</id><published>2011-12-04T20:00:00.000-05:00</published><updated>2011-12-04T20:00:00.273-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ephemerality" /><category scheme="http://www.blogger.com/atom/ns#" term="paul ducklin" /><category scheme="http://www.blogger.com/atom/ns#" term="persistence" /><category scheme="http://www.blogger.com/atom/ns#" term="danah boyd" /><category scheme="http://www.blogger.com/atom/ns#" term="f-secure" /><category scheme="http://www.blogger.com/atom/ns#" term="sean sullivan" /><category scheme="http://www.blogger.com/atom/ns#" term="sophos" /><category scheme="http://www.blogger.com/atom/ns#" term="clay shirky" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title type="text">privacy in the age of forever</title><content type="html">i've written before about &lt;a href="http://anti-virus-rants.blogspot.com/2010/02/true-nature-of-security.html"&gt;what i think privacy is&lt;/a&gt;, though classifying it as an obscurity-based strategy for satisfying a basic need for safety was very high level and abstract. it could also be taken the wrong way, since people often think about safety as only applying to their physical person (i.e. physical safety). our physical bodies aren't the only thing we want to keep safe, of course. our families, our property, our reputations, our opportunities, etc. are all things we want to keep safe, all things we want to protect, and all things for which privacy can help offer some protection.&lt;br /&gt;&lt;br /&gt;privacy is often described in terms of controlling information but on reading &lt;a href="http://www.zephoria.org/thoughts/archives/2011/11/20/debating-privacy-in-a-networked-world-for-the-wsj.html"&gt;danah boyd's thoughts on privacy&lt;/a&gt; i realized it can and should be expressed a different way. controlling information is the means by which privacy is often accomplished, but it's not what privacy is actually about. while i don't agree with the narrow scope boyd used ('asserting control over social situations'), at it's root was a kernel of truth. while the means by which privacy is achieved may be the control of information, the point is the control of outcomes related to that information, whether they be social outcomes, business outcomes, educational outcomes, housing outcomes, health outcomes, political outcomes, legal outcomes, etc.&lt;br /&gt;&lt;br /&gt;controlling outcomes is, of course, the point of any strategy. the thing about strategies, though, is that their appropriateness depends heavily on the situation, and what people largely don't realize is that there is a situation which is becoming increasingly ubiquitous under which many traditional privacy strategies don't work very well.&lt;br /&gt;&lt;br /&gt;in the online world everything is recorded and stored for consumption at a different time or in a different place. it is essentially a persistent medium through which we can interact with each other. this is a significant point because for most of human history the real world has largely been an ephemeral medium for interaction. our behaviour, the strategies that we develop as we mature in the real world take great advantage of the ephemeral nature of our interactions with others. if you weren't present the day your best friend made a hurtful comment about you to others in your peer group then you missed out, that experience is gone, "you had to be there" as it were. this ephemeral property of the event, the fact that the information only exists in a very particular point in time and space, serves to restrict access to that information to only those who were present at the same point in time and space.&lt;br /&gt;&lt;br /&gt;once we start interacting online that ephemeral property ceases to exist, so access to the information that we might have otherwise expected to be restricted due to it's ephemeral nature is no longer restricted in that way. we often don't realize that, however, because we take that 'ephemeral-ness' for granted. it's not easy adapting to a situation where that no longer applies.&lt;br /&gt;&lt;br /&gt;for example, imagine for a moment that every word you speak goes into a speech bubble above your head, like in the comic books, except unlike the comics the speech bubble doesn't go away, it stays with you and allows people to read what you said 5 minutes ago or even 5 hours ago. every swear word, every uncharitable thought uttered under your breath in the heat of the moment, everything. can you imagine how you'd adapt to that sort of situation? you'd probably censor yourself a lot more than you currently do - since your utterances have become persistent the natural adaptation that would allow you to continue to control the outcomes associated with what you say is to say far less.&lt;br /&gt;&lt;br /&gt;at first blush that might not seem unbearably bad, but let's take things a step farther because that example really only dealt with your words. this time (this is inspired by danah boyd's post, by the way), imagine you are stuck in a very large room and surrounded by everyone you ever have and ever will meet. imagine trying to live your life in this room. how do you play with your toddler in front of your business partner or a potential client? how do you woo your future wife in front of your children or your parents? how do you hang out with your high school friends in front of your future employers? how do you project an image of cool professionalism to people who saw you fall face first in a mud puddle? again, in such a situation, surrounded by people from disparate contexts of your life, the natural adaptation is to reduce the amount of information that you reveal about yourself, but think about those questions; there are certain outcomes that can't reasonably happen without revealing sensitive things about yourself.&lt;br /&gt;&lt;br /&gt;these examples may seem absurd, but this is what it means to interact in a persistent medium. anyone, anywhere, at any time can (in theory) see the footprints you've left in that medium. your interactions in a persistent medium transcend time and space, allowing people to effectively 'TiVo' your life (or at least the portion of it that's been recorded).&lt;br /&gt;&lt;br /&gt;obviously this represents an unacceptable state of affairs for online interaction. there's very little utility in it if it requires such profound self-censorship. that's the reason that technological privacy controls and privacy settings were invented - to help replace the access control that was lost when the information became recorded. unfortunately the technological controls don't operate the same way that ephemerality does, so trying to achieve a simliar outcome with them is complicated and often not intuitive.&lt;br /&gt;&lt;br /&gt;sean sullivan (at least i assume it was that sean) made &lt;a href="http://www.f-secure.com/weblog/archives/00002254.html"&gt;a post on the f-secure blog&lt;/a&gt; that highlighted a talk given by clay shirky where he said (as quoted by sean) that "managing privacy isn't natural". technically what shirky said was that managing privacy settings isn't natural. we manage privacy every day in every interaction we make with others, but managing privacy settings by definition can't be natural because the settings themselves are artificial. this has implications for the kind of privacy one can achieve though managing such settings - it is itself an artificial, man made analog to natural privacy, and prone not only to being incomplete in comparison to it's natural counterpart but also to breaking down as all man made things do. &lt;br /&gt;&lt;br /&gt;but as untrustworthy as that sounds, it will have to be good enough, because we can't turn back the hands of time or halt progress. we can't even opt out of the persistent medium. oh, we might get away with staying out of the online world ourselves, but persistence is intruding into the real world more and more. public photography, for example, is turning the public sphere (which used to represent an ephemeral medium) into a much more persistent medium than it used to be. this can be a good thing when it helps to expose things like police brutality, but it poses a not insignificant problem for us as a society.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://nakedsecurity.sophos.com/2010/06/07/public-unprivacy-googles-fault/"&gt;paul ducklin raised some concerns&lt;/a&gt; about this very problem last year on the sophos blog. at the time &lt;a href="http://anti-virus-rants.blogspot.com/2010/06/public-privacy-is-oxymoron.html"&gt;i didn't think his concept of public privacy made much sense&lt;/a&gt;, but when examined through the lens of a traditionally ephemeral medium of interaction being changed into a persistent one without people noticing or appreciating the consequences for their existing privacy strategies, it starts to be clear (to me) that this is a problem that deserves some consideration. i wouldn't consider it an invasion of privacy, per se, but perhaps it would qualify as a subversion of privacy, since it changes the environment to one where the strategies people were using to control outcomes no longer work properly, and it does so without making it clear that that had happened.&lt;br /&gt;&lt;br /&gt;are we ready for the implications of living in a world where our actions live on beyond the moment? i don't really know. certainly we can manage our privacy settings online, and maybe we can obscure our identifying features offline (though that may interact poorly with some of our cultural norms) so that public photography becomes less of an issue. i just wonder if explaining to the next generation what it was like before everything became persistent will be the last time we ever get to use the phrase "you had to be there".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-2741110754369096625?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=i9hf5MACI0g:7TByNtQOINs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=i9hf5MACI0g:7TByNtQOINs:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=i9hf5MACI0g:7TByNtQOINs:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=i9hf5MACI0g:7TByNtQOINs:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/i9hf5MACI0g" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/2741110754369096625/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=2741110754369096625" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/2741110754369096625" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/2741110754369096625" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/i9hf5MACI0g/privacy-in-age-of-forever.html" title="privacy in the age of forever" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/12/privacy-in-age-of-forever.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-6446311816178040678</id><published>2011-11-03T01:33:00.002-04:00</published><updated>2011-11-03T01:33:25.300-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="martin mckeay" /><category scheme="http://www.blogger.com/atom/ns#" term="metasploit" /><category scheme="http://www.blogger.com/atom/ns#" term="hd moore" /><category scheme="http://www.blogger.com/atom/ns#" term="josh corman" /><category scheme="http://www.blogger.com/atom/ns#" term="network security podcast" /><title type="text">thoughts on metasploit's impact</title><content type="html">i listened to the &lt;a href="http://www.mckeay.net/2011/11/01/network-security-podcast-episode-257-2/"&gt;network security podcast #257&lt;/a&gt; this afternoon, specifically because i wanted to hear what martin mckeay, josh corman, and hd moore had to say about metasploit and what josh corman calls &lt;a href="http://cognitivedissidents.wordpress.com/2011/11/01/intro-to-hdmoores-law/"&gt;HD Moore's Law&lt;/a&gt;. there were a lot of mentions of PCI and being 'this tall to ride the internet', but the comment that really caught my ear (i was listening to it rather than reading it after all) was that metasploit allows people to test their security against the attacks that are readily available.&lt;br /&gt;&lt;br /&gt;and then a voice in the back of my head said "yeah, but metasploit is what &lt;b&gt;makes&lt;/b&gt; those attacks readily available". it's essentially equivalent to saying that the readily available attacks allow people to test their security against the readily available attacks - i believe the way the internet identifies such tautologies these days is by saying "obvious statement is obvious".&lt;br /&gt;&lt;br /&gt;one of the interesting things josh corman brought to the conversation was a breakdown of adversary classes (i encourage you to read his post that i linked to above, not only for that breakdown but also a visualization of their relative success rates against a scale of defender strengths) and it occurs to me that, in the absence of metasploit, these so-called readily available attacks that are in the hands of the casual attacker wouldn't generally be in the hands of the casual attacker (and thus wouldn't be the readily available attacks) but rather in the hands of adversaries of a higher calibre.&lt;br /&gt;&lt;br /&gt;one thing that isn't really mentioned but seems fairly obvious is that the higher up you go on the scale of adversary classes, the smaller the population will be (the more skills one has the rarer one becomes) and consequently the smaller the aggregate pool of practical targets will be (since there's a limit to what any one given person can pull off in a given period of time, the manpower available to an attacker is a finite resource). that means that in the absence of metasploit, these attacks would be directly impacting fewer systems - probably more important systems, but fewer systems in total.&lt;br /&gt;&lt;br /&gt;now before i go any further, lets address an assumption i've made. i think it's an obvious one. you've probably had it on the tip of your tongue for at least the past two paragraphs. the assumption is that in the absence of metasploit nothing else would pop up to take it's place. for my purposes, that's actually not so much an assumption as it is an ideal starting point or degenerate case from which to build a more complex model.&lt;br /&gt;&lt;br /&gt;so let's say that another group of well-meaning researchers decided to pick up the gauntlet. i see no intrinsic difference between that hypothetical case and the actual case we have with metasploit right now. that makes it really not that interesting an alternative, because it's not really &lt;i&gt;alternative&lt;/i&gt; in any meaningful sense. the more interesting alternative lies in the argument that if the good guys didn't do it, if they were all too principled (for lack of a better word) to follow that path, then the bad guys certainly would.&lt;br /&gt;&lt;br /&gt;so in that case let's say a group of ne'er do wells decided to produce a similar tool. would it be the same? would it have the same properties and present the same problems? i would argue that it wouldn't - that the incentives in the underground community are different enough that what would be produced either would not be free (and therefore not available to all casual adversaries) or it would not be as capable as metasploit would have been (perhaps because the best exploits would get held back in order to give the developers a competitive or strategic advantage over the attackers they're helping for free). the motive of doing it for the benefit of everyone (that drives the excellence found in the free edition of metasploit) simply isn't compatible with financially motivated cybercrime. greed and selflessness don't mix, so a criminal-driven equivalent to metasploit wouldn't lower the bar as far as metasploit does.&lt;br /&gt;&lt;br /&gt;so what am i trying to say? what am i really getting at with all of this? the TL;DR version is that the metasploit folks are too nice to people, including the bad guys. the notion that metasploit represents the attacks that are readily available suggests to me that they lower the bar too much. no one seems to disagree that metasploit is a tool that is used by &lt;a href="http://anti-virus-rants.blogspot.com/2007/08/what-is-script-kiddie.html"&gt;script kiddies&lt;/a&gt; (among others) and so i'm left to wonder very seriously whether there's an actual legitimate use case for metasploit that involves such a completely unskilled user. leave no user behind? i think under the circumstances an exception deserves to be made.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-6446311816178040678?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=fy-wce-KSC0:5nCdSqLFbos:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=fy-wce-KSC0:5nCdSqLFbos:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=fy-wce-KSC0:5nCdSqLFbos:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=fy-wce-KSC0:5nCdSqLFbos:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/fy-wce-KSC0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/6446311816178040678/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=6446311816178040678" title="7 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/6446311816178040678" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/6446311816178040678" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/fy-wce-KSC0/thoughts-on-metasploits-impact.html" title="thoughts on metasploit's impact" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>7</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/11/thoughts-on-metasploits-impact.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-8325886375129208766</id><published>2011-10-26T10:00:00.000-04:00</published><updated>2011-10-26T10:00:04.154-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="marketing" /><category scheme="http://www.blogger.com/atom/ns#" term="george kurtz" /><category scheme="http://www.blogger.com/atom/ns#" term="mcafee" /><title type="text">marketing bullshit isn't just from marketing departments</title><content type="html">so apparently there's a conference going on right now called &lt;a href="http://www.hackerhalted.com/2011/"&gt;hacker halted&lt;/a&gt;. i heard mention of it a few days ago but paid little attention because frankly there are just too many security conferences to keep track of. what piqued my interest yesterday, however, was a retelling of something george kurtz is supposed to have said in one of the keynotes at the conference - specifically, he's quoted as saying the following (from &lt;a href="http://twitter.com/#%21/InfosecurityMag/status/128852508889190400"&gt;@InfosecurityMag's tweet&lt;/a&gt;)&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;industry has to move beyond signatures and customers need to demand this from the vendors. We need to change and adapt&lt;/blockquote&gt;now i have to admit i had no idea who george kurtz was. fact of the matter is i have no idea who most people in the security field are (so if you're wondering why i don't follow you back on twitter or add you to a circle on google+, that's a strong contender for the reason why). i thought he was just some crank talking about things he didn't really know much about (more common than you might think, unfortunately) because the AV industry hasn't been relying exclusively on signatures for quite a long time.&lt;br /&gt;&lt;br /&gt;imagine my surprise to discover george kurtz is actually the chief technology officer at mcafee, of all places. would such a highly titled representative of an AV company really say such a bizarre thing? well, if &lt;a href="http://anti-virus-rants.blogspot.com/2006/10/virus-problem-is-solved-not.html"&gt;symantec's CEO can claim the virus problem is solved&lt;/a&gt;, then i guess so, but it still begs the question "what was he thinking?"&lt;br /&gt;&lt;br /&gt;thankfully &lt;a href="http://twitter.com/#%21/rik_ferguson/status/128864524932616193"&gt;rik ferguson managed to tease&lt;/a&gt; &lt;a href="http://twitter.com/#%21/George_KurtzCTO/status/128920606929465344"&gt;a little something extra out of george&lt;/a&gt; on twitter&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;George Kurtz woke up in 2008 today "industry has to move beyond signatures". Helloooo? McFly?&lt;/blockquote&gt;&lt;blockquote class="tr_bq"&gt;@rik_ferguson maybe you missed the part about the hardware assisted security.  Opps.. forgot you don't really  have that at Trend.&lt;/blockquote&gt;and there we have it; the quote that people are fawning over (or scratching their heads over) was actually marketing bullshit. oh sure, on the the surface it looks like an AV big wig eating crow and admitting that his company isn't doing a good enough job and needs to improve; just the kind of frank confession we're all waiting for the AV industry to make. but with this added wrinkle we see that's not it at all. george's company supposedly already has improved and it's everybody else who still has the problem. &lt;i&gt;mcafee has this licked, mcafee is the solution, buy mcafee&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;no, he didn't actually say 'mcafee is the solution, buy mcafee' (to the best of my knowledge), but that is the reality distortion he's setting up - and distorting reality that way is the hallmark of marketing. all that remains is to publicly declare that deepsafe (their hardware assist technology that they announced over a month ago) is how you "move beyond signatures" and the marketing message will be complete with reality suitably distorted to mcafee's benefit and everyone else's detriment.&lt;br /&gt;&lt;br /&gt;now you might be thinking to yourself that this can't be true, that such a highly placed and well respected &lt;a href="http://anti-virus-rants.blogspot.com/2006/09/end-of-security-experts.html"&gt;security expert&lt;/a&gt; would never stoop to such base gamesmanship. the fact is that not only do most public faces of the industry practice marketing regularly in the process of representing their respective companies, but most high profile speakers rise above the rest not strictly by merit but by effectively selling themselves and building their personal brands - and if they have to stretch the truth or fuzz the facts or distort reality to make their message more palatable to the masses and give themselves more cache and influence, then so be it.&lt;br /&gt;&lt;br /&gt;and the unfortunate consequence of this is that, due to the fact that the rest of us rely on such speakers to inform us, much of what the majority of us know about the the subject matter in question is actually somewhat wrong in subtle (or not so subtle) ways. reality distortion interferes with the formation of accurate mental models and that in turn interferes with people's ability to deal with the parts of the real world those models are supposed to represent. one of the things i've tried to impress on people in the past is that they need to stop listening to marketing, but i realize now that i don't have an easy method for them to recognize it in the first place. at least not without developing much more thorough knowledge than they currently have, and to do so without relying on apparent authorities on the subject in question is no easy task.&lt;br /&gt;&lt;br /&gt;no, marketing bullshit isn't restricted to the glossy pages of a magazine or the cover of a box or an ad on tv. it's not just the product of marketing departments. it's woven into the very fabric of what we think we know, and it's hurting us.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-8325886375129208766?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=JPbmCPaImzA:q1rUGoap11w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=JPbmCPaImzA:q1rUGoap11w:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=JPbmCPaImzA:q1rUGoap11w:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=JPbmCPaImzA:q1rUGoap11w:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/JPbmCPaImzA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/8325886375129208766/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=8325886375129208766" title="14 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/8325886375129208766" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/8325886375129208766" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/JPbmCPaImzA/marketing-bullshit-isnt-just-from.html" title="marketing bullshit isn't just from marketing departments" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>14</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/10/marketing-bullshit-isnt-just-from.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-746600853721700429</id><published>2011-09-23T21:07:00.001-04:00</published><updated>2011-09-23T21:07:59.027-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="ticker" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><category scheme="http://www.blogger.com/atom/ns#" term="frictionless sharing" /><title type="text">facebook's ticker: a ticking privacy timebomb?</title><content type="html">there's a lot of pixels and bits being dedicated to the major changes that are underway at facebook, but most of the attention seems to be focused on the timeline feature. i tend to think the ticker feature deserves a lot more attention and, frankly, concern.&lt;br /&gt;&lt;br /&gt;first off, it seems clear that facebook wants to be the destination for an ever increasing number of activities - not just farmville or mafia wars, but consuming print, audio, and video media, and even purchasing goods too. fine, facebook wants to be the web portal to end all web portals - the next AOL or compuserve - it's fine to have aspirations like that; although actually being AOL or compuserve doesn't seem to have worked out that great for AOL or compuserve in the end.&lt;br /&gt;&lt;br /&gt;but with that breadth possible activities in mind, the idea that facebook will now be sharing everything you do automatically seemed really rather stupid to me at first. maybe there is too much friction inhibiting sharing right now, maybe clicking a button isn't easy enough, but truly "frictionless" sharing that happens without any action taken on the user's part takes the intent out of sharing. sharing loses all meaning that way. it no longer tells you the sharer thought this article was insightful or that video was funny, it doesn't give any hint what so ever as to whether the sharer thought something was worthwhile, it just collects everything in one big activity profile. indeed, was the person performing those activities really the sharer in that situation, or is the sharer facebook themselves?&lt;br /&gt;&lt;br /&gt;at first you might think that the resulting poor signal/noise ratio would render facebook as irrelevant as myspace and it's blinking, glittery profile pages has become. the folks at facebook seem to have realized this, though. they don't want people's main feeds to get filled with all that noise. they recognize that from a personal interaction standpoint, this data is too voluminous and unimportant. that's why they've relegated the data to a new place - the ticker.&lt;br /&gt;&lt;br /&gt;the question you should be asking yourself right now, however, is this: if this data isn't actually useful to users when they're connecting with their friends, why is facebook interested in automatically sharing it? who is interested in that data? the answer is simple - advertisers. a large profile of everything you read, watched, listened to, and did online is for all intents and purposes your web history. in this case it will be your web history as seen through the eyes of facebook. we in the security community get upset about browser vulnerabilities leaking our browser history, or tracking cookies being used to track where we've been; the data collected for ticker is not going to be inherently different than the data acquired through those other means. furthermore, it's too voluminous and granular to be useful to anything other than an automated process that looks for certain types of patterns and trends. the kind of process you'd use for the automated targeting of ads - targeting based on your activities, your behaviour.&lt;br /&gt;&lt;br /&gt;the ruse of "&lt;i&gt;frictionless sharing&lt;/i&gt;" appears to be a trojan horse (not the malware variety one might traditionally think of, though) for introducing behavioural profiling for the purposes of targeted advertisements. social spyware at it's best.&lt;br /&gt;&lt;br /&gt;but even if that's not the case, even if that data really is meant for a user's friends to see and use, there is a profound implication buried in the automated sharing of everything. you can't control your public image if the choice of what you share about yourself is taken away from you. for all the hand wringing recently about the damage that real name policies do (eliminating your ability to control the personal information that your identity represents), the elimination of your ability to control your public image means the elimination of the &lt;a href="http://en.wikipedia.org/wiki/Persona_%28psychology%29"&gt;persona&lt;/a&gt; - something that has been part of the social experience of humans since the dawn of mankind if not longer.&lt;br /&gt;&lt;br /&gt;our true selves, the nature that we keep hidden behind the masks that we each present the world, is something that we innately keep private. i simply cannot believe that our social norms are headed in the direction of completely removing those social masks. giving up &lt;i&gt;&lt;b&gt;that&lt;/b&gt;&lt;/i&gt; private information in exchange for access to a service is a privacy bargain that we have &lt;b&gt;never&lt;/b&gt; faced before.&lt;br /&gt;&lt;br /&gt;so, if you thought the ways facebook could violate our privacy couldn't get much worse, you were dead wrong.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-746600853721700429?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=DkuzdnVZDCg:Xhy58CRZqeM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=DkuzdnVZDCg:Xhy58CRZqeM:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=DkuzdnVZDCg:Xhy58CRZqeM:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=DkuzdnVZDCg:Xhy58CRZqeM:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/DkuzdnVZDCg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/746600853721700429/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=746600853721700429" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/746600853721700429" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/746600853721700429" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/DkuzdnVZDCg/facebooks-ticker-ticking-privacy.html" title="facebook's ticker: a ticking privacy timebomb?" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/09/facebooks-ticker-ticking-privacy.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-7401180231778742190</id><published>2011-08-06T11:41:00.004-04:00</published><updated>2011-08-06T11:44:54.600-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="sophail" /><category scheme="http://www.blogger.com/atom/ns#" term="tavis ormandy" /><category scheme="http://www.blogger.com/atom/ns#" term="anti-virus" /><category scheme="http://www.blogger.com/atom/ns#" term="black hat conference" /><category scheme="http://www.blogger.com/atom/ns#" term="sophos" /><title type="text">tavis ormandy's sophail presentation</title><content type="html">at the black hat security conference this year tavis ormandy presented his research into the way an &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-anti-malware-anti-virus.html"&gt;anti-virus product&lt;/a&gt;, namely sophos' product, operates in order to shine a light on something seems like it would be an important subject to consider when judging the efficacy of a product. the paper associated with the presentation can be found &lt;a href="http://t.co/6tM1wI2"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;tavis was not particularly kind in his evaluation of the code (which he apparently performed by reverse engineering the product). &lt;a href="http://nakedsecurity.sophos.com/2011/08/05/tavis-ormandy-and-sophos/"&gt;sophos' response&lt;/a&gt; is very measured and diplomatic, which is pretty much the perfect way (from a PR perspective) to respond to the kind of criticism being leveled at them. as usual, however, i don't have to be diplomatic.&lt;br /&gt;&lt;br /&gt;tavis' paper betrays a conceit that i suspect is more common in those who break things than it is in those who make things. developers, upon dealing with someone else's code, inevitably learn an important lesson: the code tells you what the software does, but it doesn't tell you why it does it that way. tavis thinks he knows all he needs to know, but he only had the code to go by. so when it comes to why certain things were done the way they were, the only thing he could reasonably do is make educated guesses. in some cases those guesses may well have been quite good, but in others they were not.&lt;br /&gt;&lt;br /&gt;i first realized this was going to be the case on the second page of the paper where he describes how weak the encryption used on the signatures was, often an XOR with an 8 bit key. if you were to guess that such encryption was to protect the signatures from an attacker, as tavis seems to have, then you'd be dead wrong. the primary purpose encrypting signatures serves is to prevent other anti-virus products from raising an alarm on the signature database (something that used to happen in the very early days). &lt;br /&gt;&lt;br /&gt;on page 3 it's mentioned that the heavy use of CRC32 in the signatures means it's easy to maliciously create false alarms by creating files that have the same CRC32 values that a particular signature is looking for and in the same places. now i ask you, the reader, if someone is maliciously planting files on your network that are designed to raise an alarm, is that alarm really false? it may be a false identification, but there really is something malicious going on that an administrator needs to investigate.&lt;br /&gt;&lt;br /&gt;also on page 3 he criticizes the quality of the signatures by stating they appear to ignore the context of the programs they come from, that they're for irrelevant, trivial, or even dead code. perhaps tavis expanded on this in his live presentation, but the paper doesn't make clear whether or not he actually looked at the malware the samples were supposed to be for. if he didn't, then the criticism about ignoring context would be particularly ironic. let's assume then that he did. how many malware samples did he examine? if only a handful then there's a not insignificant chance that he was dealing with bad examples that aren't really representative of the overall signature quality. did he ensure that his samples were actually malware? did he ensure that his samples were being identified by the right signatures? his previous criticism (on the same page!) about false identifications should highlight the fact that hey may have been looking at the wrong code when judging the quality of the signatures. but more importantly than that, there isn't a 1-to-1 relationship between signatures and samples. one signature may be intended to detect many (tens, hundreds, even thousands of) related samples - and however pointless tavis may think those sections of the malware code are, they may represent the optimal commonality between all those samples.&lt;br /&gt;&lt;br /&gt;around about page 8 or so, tavis makes a point of highlighting the fact that the emulation the product does in order to let &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-malware.html"&gt;malware&lt;/a&gt; reveal it's unencrypted/unpacked form only goes for about 500 cycles. this highlights a failure to understand one of the core problems in malware detection: the halting problem. for any other criteria the code might look for in deciding it's seen enough, there's no guarantee that criteria will ever be encountered on a particular input &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-program.html"&gt;program&lt;/a&gt;. there has to be a hardcoded cut-off point or the process runs the risk of never stopping - and that would severely impact the usability of the AV software. likewise if the hardcoded cut-off point isn't reached soon enough it also impacts the usability of the AV software. &lt;br /&gt;&lt;br /&gt;there may yet be other examples of poor guesswork that i didn't see. my own knowledge of why certain design choices might be made is limited as i've never actually built an anti-virus product. i have considered it, of course, since i am a maker of things. perhaps tavis ormandy would benefit from more experience making things rather than breaking them. perhaps this was an unorthodox expression of the oft' repeated concept that the skills needed to attack are not the same as the skills needed to defend.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-7401180231778742190?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=Ghdbx3rw0OE:l486kWC1akc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=Ghdbx3rw0OE:l486kWC1akc:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=Ghdbx3rw0OE:l486kWC1akc:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=Ghdbx3rw0OE:l486kWC1akc:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/Ghdbx3rw0OE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/7401180231778742190/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=7401180231778742190" title="6 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/7401180231778742190" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/7401180231778742190" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/Ghdbx3rw0OE/tavis-ormandys-sophail-presentation.html" title="tavis ormandy's sophail presentation" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>6</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/08/tavis-ormandys-sophail-presentation.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-6220776303292248643</id><published>2011-07-26T16:05:00.000-04:00</published><updated>2011-07-26T16:06:00.250-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="kevin mcaleavey" /><category scheme="http://www.blogger.com/atom/ns#" term="KNOS" /><category scheme="http://www.blogger.com/atom/ns#" term="anti-virus" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy software corporation" /><category scheme="http://www.blogger.com/atom/ns#" term="snake oil" /><title type="text">careful who you let write the history books</title><content type="html">over the course of the previous two weeks, kevin mcaleavey has been publishing a series of blog posts on the infosecisland site (parts &lt;a href="https://infosecisland.com/blogview/15034-Throwing-in-the-Towel-The-Sorry-State-of-Client-Security.html"&gt;one&lt;/a&gt;, &lt;a href="https://infosecisland.com/blogview/15068-The-Birth-of-the-Antivirus-Industry.html"&gt;two&lt;/a&gt;, &lt;a href="https://infosecisland.com/blogview/15106-The-Demise-of-the-Antivirus-Industry.html"&gt;three&lt;/a&gt;, &lt;a href="https://infosecisland.com/blogview/15159-The-Best-And-Most-Secure-Windows-OS-Ever.html"&gt;four&lt;/a&gt;, &lt;a href="https://infosecisland.com/blogview/15196-Seven-Security-Blankets-and-Im-Still-Short-Sheeted.html"&gt;five&lt;/a&gt;, and &lt;a href="https://www.infosecisland.com/blogview/15249-Solving-The-End-User-Problem.html"&gt;six&lt;/a&gt;) about the history of the &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-anti-malware-anti-virus.html"&gt;anti-virus&lt;/a&gt; industry. rob lewis thought this might be a subject that would interest me and he was right. unfortunately, rather than finding it mostly informative, i found with each passing part an increasing desire to post a serious critique. i'll take them one part at a time.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;part one&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;to start with i think we need to pay attention to how the author presents himself. each part refers to him as a long time industry insider, but doesn't go into anything more verifiable or specific than that. with such vague credentials (and those are meant as credentials - there's no reason to put them there except to try to convince the reader that the author is an authority on the subject he's writing about) it really feels like he's saying "trust me, i'm a &lt;a href="http://anti-virus-rants.blogspot.com/2006/09/end-of-security-experts.html"&gt;security expert&lt;/a&gt;". now i've never heard of him but that alone doesn't say that much, the anti-virus industry employs hundreds if not thousands of people and i'm really only familiar with a comparative handful of them. in part three we get to find out more specifics, but for the time being let's just say that such nebulous credentials makes me very suspicious.&lt;br /&gt;&lt;br /&gt;to be fair i should point out my own credentials, so that i'm not being a hypocrite. unlike kevin, i am not now, nor have i ever been an industry insider. i have never been employed by any company in the anti-virus industry, i have never received financial remuneration for anything i've said or done involving the anti-virus field, and frankly i've only ever met a handful of people who were part of the industry. that being said, what i am (in terms relevant to this discussion) is a long time observer of the anti-virus industry. i've always been on the outside looking in, but from about the age of 15 onwards i basically grew up interacting with security hobbyists, security professionals, security software engineers, security researchers, and even some of the big names that kevin mentions in part two.&lt;br /&gt;&lt;br /&gt;in theory, being an outsider seems like it should mean i have a more superficial view of the anti-virus industry.&amp;nbsp; we shall see.&lt;br /&gt;&lt;br /&gt;the first part of kevin's series focuses mostly on where we are today so a lot of the things he mentions should sound familiar to people following the security news. one of the things he mentions is the rustock &lt;a href="http://anti-virus-rants.blogspot.com/2006/03/what-is-botnet.html"&gt;botnet&lt;/a&gt;. he presents it as a single piece of &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-malware.html"&gt;malware&lt;/a&gt; with a 5 year half-life. this is a bit misleading for a couple of reasons, the first being that rustock is actually a family of malware - there have been many versions since 2006, in part because the anti-virus industry keeps interfering with the utility of existing versions by detecting them. additionally, the term "half life" has a very specific meaning which doesn't really apply that well to a botnet that has for all intents and purposes been killed now that microsoft controls the command and control server.&lt;br /&gt;&lt;br /&gt;subsequently he made the following quote:&lt;br /&gt;&lt;blockquote&gt;"TDL4" however has publicly caused the security industry to transition into full panic mode and literally throw in the towel&lt;/blockquote&gt;this may seem pedantic, but in order to literally throw in the towel, there has to be an actual physical towel, and someone has to throw it. an argument could be made, i suppose, for saying that they figuratively threw in the towel, or metaphorically threw in the towel. maybe even virtually threw in the towel - but if he insists that they literally threw in the towel then i have five words - pics or it didn't happen.&lt;br /&gt;&lt;br /&gt;now there was some early misinterpretation of the use of the word "indestructible" that got posted in less knowledgeable media circles, specifically that the malware was indestructible rather than the observation that malware authors were &lt;b&gt;trying&lt;/b&gt; to create an &lt;i&gt;indestructible&lt;/i&gt; or &lt;i&gt;bulletproof&lt;/i&gt; network of compromised computers, but a knowledgeable industry insider should have been able to see through that. furthermore, from my perspective the only panic i saw was the panicky feeding frenzy in the media over a statement which, like so many more purposeful scams, was simply too spectacular to be true.&lt;br /&gt;&lt;br /&gt;i got the distinct impression upon reading part one that he tends to take mainstream media as gospel when it suggests that all is lost in the fight against malware. that seems strange to me. why is an industry insider putting so much credence in what the mainstream media says? he acknowledges that the industry has called this interpretation wrong, and that they're trying to correct that misinterpretation but he seems to suggest that the "corrections" are a product of public relations rather than a genuine attempt to correct factually erroneous statements that spread fear, uncertainty, and doubt.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;another statement i'd like to draw attention to is the following:&lt;br /&gt;&lt;blockquote&gt;To see this public admission that 1980's technology has utterly failed is nothing short of breathtaking.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/blockquote&gt;admission by whom? where? what are the details? none are given and we must take him on his word that such an admission actually took place. or perhaps he thinks the misinterpretations spread by mainstream media represent that admission. could it be that he's unfamiliar with the degree to which they botch things up on a regular basis? it really makes me question his credibility if he placing his preference on the words of reporters over the words of researchers.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;part two&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;part two is where he actually starts talking about history. he starts right at the beginning but there's a problem. he mistakenly thinks &lt;a href="http://en.wikipedia.org/wiki/%28c%29Brain"&gt;the brain virus&lt;/a&gt; '&lt;i&gt;destroyed&lt;/i&gt;' many hard disks. brain came out at a time when hard disks were a rarity. moreover, brain specifically avoided infecting hard disks. the link kevin himself provided says this so i can only assume that he's not actually reading the sources he's providing to the reader.&lt;br /&gt;&lt;br /&gt;he also seems to mistakenly think brain required a reinstall to recover from. this is, of course, false. there have always been less drastic ways of restoring boot sectors. the main problem was information about doing so wasn't as easy to come by back then as it is now. still, thinking there wasn't a way to do it is essentially a form of ignorance that you wouldn't expect to find in a long time industry insider.&lt;br /&gt;&lt;br /&gt;yet another point on the brain virus; he seems to think the backlash from it forced the developers who made it out of business. i guess he never saw &lt;a href="http://www.youtube.com/watch?v=lnedOWfPKT0"&gt;this video&lt;/a&gt; by f-secure's mikko hypponen, where mikko found the developers of the virus still working at exactly the same address they were at 25 years ago when they originally wrote the virus.&lt;br /&gt;&lt;br /&gt;brain isn't the only piece of malware whose details he gets wrong, though. he mistakenly thinks popureb requires a windows reinstall to remove, much like brain. in reality what's required is to restore the MBR with the recovery console. this seems to be another example where kevin has taken mainstream media at their word instead of digging deeper and getting actual inside information, the way you'd expect an insider to do.&lt;br /&gt;&lt;br /&gt;he also seems to think that stoned was the first &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-virus.html"&gt;virus&lt;/a&gt; to go memory resident and &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-infection.html"&gt;infect&lt;/a&gt; any disk that was inserted in the drive. stoned was a &lt;a href="http://anti-virus-rants.blogspot.com/2006/10/what-is-boot-sector-virus.html"&gt;boot sector infector&lt;/a&gt;, however. all boot sector infectors infect (more or less) every disk inserted into the drive, it's kinda how they spread, and since it wasn't the first of that sort of virus i can't imagine how he got the impression it was the first one to go memory resident.&lt;br /&gt;&lt;br /&gt;more generally he seems to think the majority of viruses in the 90's were jokes and pranks and programs designed to delete files. my recollection is that most actually gave no outward indication of infection whatsoever. virus writers quickly decided they liked the notoriety that came with one of their viruses spreading far and wide, and the best way to help that to happen was to make sure it didn't make itself known by messing up people's computers. the ones that stuck out in people's memories were oftentimes jokes or pranks or had destructive payloads, however.&lt;br /&gt;&lt;br /&gt;it's not just malware he seems to get wrong, however. he appears to be under the impression that VIRUS-L was a private echomail conference available to SysOps (system operators) of BBSes that carried FidoNet. VIRUS-L was actually an internet mailing list which was gated into usenet in the form of the newsgroup comp.virus. i have no doubt it was further gated into FidoNet - i know alt.comp.virus was as my first encounter with it was through a usenet-to-FidoNet gateway. i have a feeling i encountered comp.virus the same way (without ever being a SysOp). that said, it's possible kevin could have been thinking of something else; maybe VIRUS or VIRUS_INFO (or even VIRUS_NFO) which were in fact echomail conferences on FidoNet (the first two of which have me as their most recent moderator). they also aren't private, however; i really can't seem to figure out where that part of his recollection might have come from.&lt;br /&gt;&lt;br /&gt;another curious thing i noticed is that he seems to think eugene kaspersky is the only member of the old guard of virus hunters still in the field after john mcafee, alan solomon, and peter norton (?) left. he also mentioned frisk software international but sort of as an afterthought, and somehow failed to mention frisk the person. frisk the person (and the company) are still out there, still working. they may not be attracting attention but they're still there. as such, kaspersky isn't the last so kevin's depiction of the industry as having been lobotomized seems all the more inaccurate. what's more, however, is that kevin only seems to be acknowledging a handful of the icons in the anti-virus industry. there were and are a lot more people from the old days out there. a great example would be aryeh goretsky, who was from the sounds of it like john mcafee's right hand man, and who currently is with eset. then there's the venerable vesselin bontchev, once a well respected virus expert at university of hamburg and now a well respected virus expert at FSI. then there's jimmy kuo of symantec and then mcafee and now microsoft. there are many great minds from the early days that are still with us today, so this focus on just a handful of icons and the suggestion that since most of those are gone that the industry has been lobotomized, seems like a decidedly superficial view.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;part three&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;the third part in kevin's series was about the demise of the anti-virus industry (it's not dead, it's just sleeping). it's also where we finally find out about his actual credentials. he was part of privacy software corporation, the company behind BOClean; what was apparently originally a cleanup tool for the back orifice &lt;a href="http://anti-virus-rants.blogspot.com/2006/03/what-is-rat.html#"&gt;remote access trojan&lt;/a&gt;, but was later expanded to cover more malware. apparently this company was bought by comodo in 2007, but from the sounds of things it doesn't sound like kevin stayed on with comodo for all that long, and even if he was still with them today 4 years isn't exactly "long term".&lt;br /&gt;&lt;br /&gt;he presents himself as a long term industry insider in a discussion about anti-virus vendors, but his actual first hand inside experience with the kinds of companies he talks about and criticizes in this series of posts only went on for 2 1/4 years according to his linkedin profile. that seems rather underwhelming. oh sure, before that he spent a long time in a different part of the anti-malware industry, but he spends very little time actually talking about the part of the industry where most of his actual experience is from - except to extoll the virtues of the techniques used by BOClean, of course. in any event, it's clear by this point why he was so vague about his credentials in earlier parts.&lt;br /&gt;&lt;br /&gt;back to the demise of the anti-virus industry, however. kevin focuses on the point in which &lt;a href="http://anti-virus-rants.blogspot.com/2006/02/what-is-trojan.html"&gt;trojans&lt;/a&gt; started to take off as the death knell of the industry. it was, after all, the point at which his company was forced to start dealing with malware. he seems to think that the early failures to handle trojans reflected inability on the industry's part. just to be clear, when trojans began to take off the industry &lt;b&gt;did&lt;/b&gt; hesitate, and i don't mean for a second or a minute or an hour or a day or week or a month or even a year. the anti-virus industry hesitated to redefine itself. it took a lot of doing to overcome the philosophical inertia that kept them out non-viral malware detection. trojans were not viruses, remote access 'tools' arguably had legitimate uses, and the industry was gun-shy with regards to litigation. i hope kevin can appreciate that last point as it was his revered dr solomon who explained that one to me. apparently they couldn't even add generic detection for MtE based polymorphic viruses using the existence of the MtE algorithm as an indicator because some brainiac went and put the algorithm in a 'legitimate' code obfuscation tool. the industry did eventually overcome their philosophical qualms about dealing with non-viral malware but it took the escalation of the trojan problem to make people (both inside and outside the industry) realize that the industry would be justified in going after this new kind of threat that was previously outside of their purview.&lt;br /&gt;&lt;br /&gt;a great deal of kevin's characterization of the failure of the industry seems to focus on what his company handled better. the reader is left to take his word for it that his company did a better job. he's clearly not an impartial 3rd party, his perceptions should be taken with a grain of salt. he talks about a number of techniques used by the anti-virus industry and what their failings are - a number of which are almost certainly exaggerated. i've seen my share of alternative anti-malware approaches whose proponents go on ad nauseum about how their approach is the superior one (zvi netiv stands out as a remarkable example of this). better is always subjective, there's always good and bad points.&lt;br /&gt;&lt;br /&gt;he describes BOClean's approach of only looking for the malware in memory, rather than trying to find it on disk like traditional anti-virus products do, as superior. there are benefits, of course. packers and cryptors have no effect on detection because that transformation is undone at runtime. however, there are also drawbacks. once the malware is in memory it is &lt;b&gt;active&lt;/b&gt;. it's possible for active malware to interfere with security software in any number of ways. it could use &lt;a href="http://anti-virus-rants.blogspot.com/2006/02/what-is-stealth.html"&gt;stealth&lt;/a&gt;, it could shut down the security software (which i gather was a problem for BOClean), or it could even use the security software's own filesystem enumerating behaviour to find new host programs to infect (if you're dealing with a file infecting virus). once the malware is active the security software has lost an important tactical advantage. imagine you're in a street fight - do you wait for your opponent to strike first or do you try to strike before they're even in a position to defend themselves? and remember, i'm talking about a street fight here, not some fair fight with referees and judges. you do not wait for the malware to go active in memory if you can avoid it. the code that gets control first wins, and once the malware is active in memory, it's gained control. it's only by kevin's good fortune (or BOClean's low profile) that malware creators didn't try to stomp out or otherwise interfere with BOClean. the AV industry has already faced that, going back all the way to brain (which had stealth).&lt;br /&gt;&lt;br /&gt;some of his exaggerations devolve into more factual errors. for example he calls win32/ska a simple file infector and criticises the industry for taking months to handle it. the fact is that win32/ska's infection technique was nothing like the traditional file infection technique kevin laid out elsewhere. win32/ska was not some appending file infector, it didn't simply insert itself into the winsock DLL, it carried a modified copy of the winsock DLL with it and replaced the original with the modified version. as such, recovery of the original winsock DLL was not comparable to recovering from a traditional file infector. it may have taken months to build the capabilities to recover from this type of infection into their general purpose tools, but that in part was because there were special purpose tools available to mitigate the problem and lower the priority of getting it into their general purpose products. there also happened to be manual instructions for removing win32/ska (i know because i have given those instructions to people) which also mitigated the problem and thus lowered the priority.&lt;br /&gt;&lt;br /&gt;he also points out that even now systems are still getting compromised with back orifice 12 years later and characterizes that as an example of the anti-malware industry's failure. the fact is that his BOClean is just as much a failure in that as the rest of the anti-malware industry is. that is if you can really call it a failure. stopping that trojan from ever getting used again, making it become extinct, that's just not something anyone can actually do. and it doesn't really have that much to do with whether the malware can be detected or removed by software tools, but more with the heterogeneity of the computer population and the mind-share of the malware in question amongst those who would use it. &lt;a href="http://anti-virus-rants.blogspot.com/2006/12/old-viruses-never-die.html"&gt;old viruses never die&lt;/a&gt;, and apparently old trojans don't either.&lt;br /&gt;&lt;br /&gt;he places the blame for why all windows malware works at all on microsoft. unfortunately it's not that simple. any general purpose computer is capable of supporting malware, no matter what the operating system. in this way malware can be said to be a 'feature' of general purpose computing. no matter how tightly you try to control things, there will always be the potential for software to maliciously do something you don't want it to do.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;kevin seems to think that AV industry has for the past 30 years (which is longer than the industry has actually existed) simply been coming up with signatures and not looking for patterns that could be useful for future variants. the fact that we have the concept of malware families at all invalidates this line of reasoning. it wouldn't be possible to classify new samples as belonging to an existing family without looking for such patterns. this line of reasoning also ignores heuristic alerts that say "possibly modified variant of X". it also ignores the practice of consolidating many specific signatures into a few generic signatures.&lt;br /&gt;&lt;br /&gt;he also calls automated analysis '&lt;i&gt;cheating&lt;/i&gt;' and characterizes it as simply creating an MD5 or SHA1 hash. this seems to ignore the fact that you can't logically identify that a sample is a variant of another malware family by simply creating a hash. it also clearly ignores the concept of automated classification, whereby a sample is compared with many other samples in order to determine which ones it's most similar to and thus which family it belongs to. one also has to wonder how exactly vendors are supposed to deal with 100,000 new samples a day without some kind of automation. even if you had a way to detect most of those new samples ahead of time with generic signatures, you still need to test and make sure each of those new samples is actually malware and is actually detected.&lt;br /&gt;&lt;br /&gt;rather unsurprisingly at this point, he describes &lt;a href="http://anti-virus-rants.blogspot.com/2008/04/what-are-heuristics.html"&gt;heuristics&lt;/a&gt; as bad because they emulate the malware while trying to catch it in the act of doing something bad. this is only (somewhat) true of &lt;a href="http://anti-virus-rants.blogspot.com/2008/12/what-are-dynamic-heuristics.html"&gt;dynamic heuristics&lt;/a&gt;, not &lt;a href="http://anti-virus-rants.blogspot.com/2008/12/what-are-static-heuristics.html"&gt;static heuristics&lt;/a&gt;. it's also hypocritical coming from someone championing the idea of letting the malware become active in memory before trying to do anything about it.&lt;br /&gt;&lt;br /&gt;he also referred to heuristics as creating "massive" false positive problems. in reality false positives are relatively rare. a single false positive can, of course, cause problems for many people if it's a system file, but those are rare even amongst regular false positives. those really high profile failures are something that has only happened a handful of times.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;part four&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;the fourth part of kevin's series focuses on operating systems, mostly windows, but covering mac os x and linux too. i actually agree with a lot of what kevin has to say in this part (which makes me wonder if my knowledge of OS security might be a little too shallow), but there are a few things that are worth pointing out.&lt;br /&gt;&lt;br /&gt;i tend not to agree with his suggestion that the concept of file associations based on file extensions are a bad thing and should be replaced by some kind of intelligent parsing. for one thing i think the parsing idea is logically infeasible. intelligent parsing would require windows to know about every file format, even the one i just invented yesterday, which it obviously can't. he also envisioned that the parser could generate a warning for the user to indicate what sort of action windows was about to take, but the warning could just as easily been done with file associations. the warning is based on the outcome and has little to do with how the outcome is decided upon (be it parsing or association).&lt;br /&gt;&lt;br /&gt;on the matter of unix, kevin appears to be of the opinion that pure unix was secure. this would seem to ignore the fact that the original academic treatment of computer viruses (where the term actually got coined) had a virus spreading on a professionally administered unix system without the admin's assistance. how secure is that?&lt;br /&gt;&lt;br /&gt;he also seems to believe that linux used to be secure in the beginning, but seems to forget or not care that rootkits worked on linux way back close to it's beginning. he admits that there was malicious software but contends that it got removed from distros quickly after being introduced. this ignores the fact that once end users start using such an OS, malware doesn't need to be bundled into the distro. if a user can run it, they will, and linux didn't and doesn't prevent running malware&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;part five&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;the fifth and penultimate part of the series deals the concept of defense in depth, or as kevin prefers &lt;i&gt;layered security&lt;/i&gt;. he spends an inordinate amount of time talking about firewalls and how awful they are. he sort of presented defense in depth as a caricature, focusing only on the layers that gained widespread adoption and suggesting that anything else was outside of the regular user's price range. frankly i don't think integrity checking was ever priced that way, nor behaviour blocking, nor any number of other techniques that he conveniently ignores.&lt;br /&gt;&lt;br /&gt;what's more, he criticizes each layer for being insufficient. it's as if he doesn't understand the purpose of having multiple layers. each one has flaws and weaknesses, sure, all security measures do, but in aggregate those weaknesses are diminished. they're never completely eliminated, of course, because there's no such thing as perfect security, but it's certainly something that we can approach. one might argue that one can approach that by re-engineering one particular layer instead of having many, but some of those weaknesses are inherent rather than being design or implementation flaws. such inherent weaknesses can only be braced by other additional, complementary layers.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;part six&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;the final part of keven mcaleavey's series was meant to present solutions to the problems mentioned in the previous 5 parts. when i read the final part in the series all the pieces finally clicked into place. all the confusion i previously had was gone, all the WTF moments finally made sense. i finally knew what he was on about and what the series' true purpose was. kevin's got a product to sell and the series was an extraordinarily long sales pitch.&lt;br /&gt;&lt;br /&gt;it followed a familiar pattern too, now that i think about it. first he dished out FUD about his competitors (and since he's now a secure systems provider his competitors include both the anti-malware software vendors and the operating system vendors), and then at the end hype up his own product and make it look like the blatantly obvious choice to avoid the horrible, horrible problems with everything else. he even threw in a smattering of &lt;a href="http://anti-virus-rants.blogspot.com/2006/04/what-is-snake-oil.html"&gt;snake oil&lt;/a&gt; phrases like "absolute security and protection" for good measure.&lt;br /&gt;&lt;br /&gt;the product and/or service in question (KNOS) appears to my untrained self to be similar to some sort of freeBSD-based LiveCD composed entirely out of carefully audited modules, and with the provision that you can request custom configurations from to suit your needs. the idea appears to be that the code that is allowed to run is carefully controlled and limited by them (rather than being something the user can add code to him/herself) and that exploitable vulnerabilities have supposedly been eliminated. this is supposed to keep the users safe from both malware and from them themselves.&lt;br /&gt;&lt;br /&gt;unfortunately, kevin seems to have fallen prey to the engineer's conceit - the (often mistaken) belief that a particular problem can solved through carefully engineered technology alone. KNOS does not offer absolute protection, and to say it does offers users a false sense of security. it may well stop all the malware that kevin can imagine, but (to paraphrase something that's often said in cryptographic circles) it's easy to come up with a security system so advanced that you yourself can't figure out a way around it - what's hard is figuring out one that other people can't figure out a way around either.&lt;br /&gt;&lt;br /&gt;obviously i don't know enough of the details of KNOS to suggest specific scenarios where it's security can fail, but i do know enough about computation in general to see what kevin (and others who aim to ensure only good/safe code is allowed to run) has missed. what many people don't realize, what society's conventional thinking about computers fails to hint at, is that data &lt;b&gt;is&lt;/b&gt; code. the distinction we draw between the two is little more than a mental construct that simplifies the task of building systems. it doesn't represent how computation actually works, and it isn't necessarily adhered to by the people who break systems.&lt;br /&gt;&lt;br /&gt;unless and until someone can come up with a way to control which data gets processed as scrupulously as they control which code gets executed, data will remain an open window through which systems with locked down code can be attacked. and since determining the safety of data will ultimately require the data to be processed in some way, we arrive at a catch-22.&lt;br /&gt;&lt;br /&gt;i fully expect that KNOS probably has some impressive security capabilities, but absolute security is a fantasy, and the more traditional security layers that kevin derides have managed to keep me essentially malware free (except for &lt;a href="http://anti-virus-rants.blogspot.com/2010/03/energizer-bunny-looks-more-like-rat.html"&gt;an externally non-addressable RAT installation on a sacrificial secondary system&lt;/a&gt;) for over two decades. beware security historians who are trying to sell you something - chances are they'll rewrite history to suit their sales objective.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-6220776303292248643?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=eM0ZrU1TB2w:sc1DcH-82pw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=eM0ZrU1TB2w:sc1DcH-82pw:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=eM0ZrU1TB2w:sc1DcH-82pw:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=eM0ZrU1TB2w:sc1DcH-82pw:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/eM0ZrU1TB2w" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/6220776303292248643/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=6220776303292248643" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/6220776303292248643" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/6220776303292248643" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/eM0ZrU1TB2w/careful-who-you-let-write-history-books.html" title="careful who you let write the history books" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/07/careful-who-you-let-write-history-books.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-6397247733064486202</id><published>2011-07-07T22:05:00.000-04:00</published><updated>2011-07-07T22:06:23.082-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="victim" /><category scheme="http://www.blogger.com/atom/ns#" term="jerome segura" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="maxim weinstein" /><title type="text">maybe we should blame the victim</title><content type="html">pardon my iconoclasm, but a twitter conversation with &lt;a href="http://twitter.com/jeromesegura"&gt;jerome segura&lt;/a&gt; and &lt;a href="http://twitter.com/maximweinstein"&gt;maxim weinstein&lt;/a&gt; got me thinking about this. it was sparked by maxim's blog post "&lt;a href="http://maximweinstein.com/2011/07/07/stop-blaming-the-victims/"&gt;stop blaming the victims&lt;/a&gt;" where he argued that we shouldn't be blaming people for failing to follow security best practices (such as keeping web servers up to date). personally i consider this to be a form of infantilization. i've argued against coddling users before but i want to expand on the idea here.&lt;br /&gt;&lt;br /&gt;the principle and practice of not blaming the users basically sends them the message that they're OK, they didn't do anything wrong, and they can keep doing things the way they have been. this is a marked departure from many of the other messages we send users trying to get them to be more aware of security and to make better decisions in security contexts. that makes the "don't blame the victim" dogma a substantially mixed message. have they really done nothing wrong? often times there are things they could/should have done differently, things they've been told about in the past but still failed to consider. can they be entirely free from responsibility for what happens to them in such a circumstance? i don't believe so. do we really want to send the message that they did nothing wrong and don't have to change? how will we ever get people to take better care of their security if we do that? many people are poorly adapted to the realities of the modern world and if there's no force giving them pushes in the right direction they'll never improve.&lt;br /&gt;&lt;br /&gt;more fundamental than that is the fact that victims are victims of the word "victim". by acknowledging someone as a victim we accept and embrace the notion of powerlessness that the word engenders. recognizing people as victims gives them a license to be victims and to remain victims. when someone is taken advantage of we shouldn't be treating them as some helpless and fragile thing, we should be helping them to become empowered so that they don't get taken advantage of again and again and again. by telling them they're helpless victims we rob them of the opportunity to better master their fates and gain confidence in their abilities. perpetuating the notion of the victim keeps the lay-person down.&lt;br /&gt;&lt;br /&gt;therefore, not only do i think we should hold people at least partially responsible for the consequences of their actions or inactions (to &lt;i&gt;blame the victim&lt;/i&gt; in normal parlance), but i also think we should blame the people who say "don't blame the victim". their well-meaning but ultimately misplaced mollycoddling holds people back and stymies our collective growth and advancement. we can never adapt if we're taught that we can't change our fates.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-6397247733064486202?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=2yt1XoCVmkc:thTxRsxzoxE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=2yt1XoCVmkc:thTxRsxzoxE:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=2yt1XoCVmkc:thTxRsxzoxE:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=2yt1XoCVmkc:thTxRsxzoxE:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/2yt1XoCVmkc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/6397247733064486202/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=6397247733064486202" title="6 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/6397247733064486202" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/6397247733064486202" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/2yt1XoCVmkc/maybe-we-should-blame-victim.html" title="maybe we should blame the victim" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>6</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/07/maybe-we-should-blame-victim.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-3370833501068952701</id><published>2011-07-04T11:01:00.000-04:00</published><updated>2011-07-04T11:01:00.566-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="cloud" /><category scheme="http://www.blogger.com/atom/ns#" term="cloud-based scanning" /><category scheme="http://www.blogger.com/atom/ns#" term="anti-malware" /><title type="text">i wandered lonely as a cloud</title><content type="html">relax, i'm not about to start waxing poetic about &lt;a href="http://www.poetry-online.org/wordsworth_daffodils.htm"&gt;daffodils&lt;/a&gt;. rather i'm thinking about cloud-based &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-anti-malware-anti-virus.html"&gt;anti-malware software&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;it's something i've been thinking about for a little while now but i've finally decided to commit my thoughts to a more permanent format and share them with others.&lt;br /&gt;&lt;br /&gt;for the past couple of years the major anti-malware vendors have been deploying cloud technology to improve the effectiveness of their products. often this has been an optimization specifically for their &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-known-malware-scanning.html"&gt;known malware scanners&lt;/a&gt;, although some have also taken the opportunity to build reputation systems.&lt;br /&gt;&lt;br /&gt;it occurred to me that the cloud could be used for a great deal more than just that. think about what those reputation systems are doing. the user is faced with a complex question - is file X safe - and the cloud answers. the cloud can do this either because there are experts feeding the cloud it's answers or because there's a community feeding the cloud it's answers (or both, come to think of it). the point is that the cloud reduced the complexity for the user.&lt;br /&gt;&lt;br /&gt;now think for a moment about all those technologies that have sprung up and then fallen by the wayside over the years. how many of them fell out of favour because they required too much knowledge, because they asked too much of the user? do you see where i'm heading yet? the cloud as a complexity reducing technology (alright it technically transfers and collates that complexity, but from the user's perspective it reduces it) seems like it actually has the potential to breathe new life in virtually all of those other techniques, be they &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-sandbox.html"&gt;sandboxing&lt;/a&gt;, &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-whitelist.html"&gt;whitelisting&lt;/a&gt;, &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-behaviour-blocking.html"&gt;behaviour blocking&lt;/a&gt;, or even &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-integrity-checking.html"&gt;integrity checking&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;and of course, as i was originally coming up with that list i was reminded of the fact that many of them have actually been augmented with some kind of cloud technology to help take the complexity out of their operation. those efforts simply haven't been particularly mainstream. the biggest vendors have been slow to recognize the opportunity to augment these technologies (which can be superior in the right hands) with complexity reduction as a service. the smaller vendors that are taking a chance with this don't necessarily have the stability to keep it going. it would be nice if those other options saw more more mainstream deployment and adoption.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-3370833501068952701?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=urP9AxAE1iM:HMELozj8fu8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=urP9AxAE1iM:HMELozj8fu8:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=urP9AxAE1iM:HMELozj8fu8:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=urP9AxAE1iM:HMELozj8fu8:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/urP9AxAE1iM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/3370833501068952701/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=3370833501068952701" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/3370833501068952701" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/3370833501068952701" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/urP9AxAE1iM/i-wandered-lonely-as-cloud.html" title="i wandered lonely as a cloud" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/07/i-wandered-lonely-as-cloud.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-8013872301767655756</id><published>2011-07-04T08:21:00.000-04:00</published><updated>2011-07-04T08:21:10.874-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="cyberweapon" /><category scheme="http://www.blogger.com/atom/ns#" term="cyberwarfare" /><title type="text">quick thought on cyberwarfare</title><content type="html">one of the topics that keeps coming up in discussions of cyberwarfare is 'attribution'. that ability to know where an attack came from, who's responsible for it, etc. it keeps coming up because many of us recognize that it's very difficult to do with attacks in cyberspace.&lt;br /&gt;&lt;br /&gt;this is a source of confusion for many because our model of warfare involves things like deterrence, counter attack, and appropriate response. without attribution these things aren't possible.&lt;br /&gt;&lt;br /&gt;cyberattacks are often likened to missiles or other kinetic warfare weapons where attribution is a much more straightforward process - i think the confusion is rooted in this comparison. instead of thinking about overt warfare, cyberwarfare would be better likened to covert warfare - black ops, wet works, that sort of thing. there is no meaningful attribution with these sort of warfare and so there is no meaningful deterrence or response to such attacks. it is an area of warfare where there is attack without counter attack, where one attacks simply because it is strategically advantageous.&lt;br /&gt;&lt;br /&gt;don't picture these so-called cyberweapons as being like electronic missiles that anyone can launch simply by pressing a button, that gives entirely the wrong sort of character to the topic. if you must consider them cyberweapons at all (ie. if you must focus on the tool instead of the attack itself) think of them as guns with silencers on them. or better yet, think of them as knives, used with surgical precision and giving away no clue to those in the vicinity where the attack came from.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-8013872301767655756?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=NeaNHrpIaoQ:lKYBgAwkNBQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=NeaNHrpIaoQ:lKYBgAwkNBQ:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=NeaNHrpIaoQ:lKYBgAwkNBQ:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=NeaNHrpIaoQ:lKYBgAwkNBQ:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/NeaNHrpIaoQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/8013872301767655756/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=8013872301767655756" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/8013872301767655756" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/8013872301767655756" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/NeaNHrpIaoQ/quick-thought-on-cyberwarfare.html" title="quick thought on cyberwarfare" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/07/quick-thought-on-cyberwarfare.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-7933039097802162033</id><published>2011-06-27T23:58:00.003-04:00</published><updated>2011-06-27T23:59:13.163-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security awareness" /><category scheme="http://www.blogger.com/atom/ns#" term="michael santarcangelo" /><category scheme="http://www.blogger.com/atom/ns#" term="user education" /><title type="text">the dawn of insecurity</title><content type="html">earlier today i sent out &lt;a href="http://twitter.com/imaguid/status/85350402761048064"&gt;a tweet mentioning a security awareness initiative by the folks at eset&lt;/a&gt; and that started off a brief discussion with &lt;a href="http://twitter.com/catalyst"&gt;michael santarchangelo&lt;/a&gt; about security awareness and adoption thereof. it could have been a longer discussion, but i quickly realized i had more to say about the subject than could reasonably fit in twitter.&lt;br /&gt;&lt;br /&gt;the reason we talk about security awareness is that most people seemingly lack such awareness. but what does that mean? well one of the things it means is that people don't think about the consequences of their actions, they don't think about the possible outcomes. this isn't just some people, either. as michael pointed out, it's all people, even you and i to some degree fail to account for all the possible outcomes. it's also not just about security, but rather about virtually any kind of awareness. some of us are more aware of certain things than others are, and aware of some things more than other things, and of course the amounts are different for each person.&lt;br /&gt;&lt;br /&gt;we could, of course, think about such things more so why don't we? in a word: laziness. now i don't mean that in a judgmental way. although laziness certainly isn't well regarded in this day and age, it's not just some character flaw in humans. the argument could be made that it served a purpose, once upon a time. physical laziness, at least, serves to conserve energy, which would have been an advantageous evolutionary trait back before we started to gain mastery over our environment, when food was harder to come by. wasting energy foolishly could have hastened starvation, so the fact that we developed a tendency to conserve our strength for when we really needed it is probably a good thing, even though the adaptation doesn't serve us nearly as well now that food is (at least in developed nations) relatively plentiful.&lt;br /&gt;&lt;br /&gt;i'm not about to suggest that mental laziness shares the same lineage as physical laziness, however. it would be quite the stretch to suggest that thinking too hard could lead to starvation. mental laziness is something i've been thinking about for a while, why it's there and how to overcome it*. at some point it occurred to me that every moment a person spends thinking about outcomes is a moment that one isn't being &lt;i&gt;in the moment&lt;/i&gt;. being in the moment is one of the hallmarks of happiness. being focused on the present instead of the past or the future is something one only does when one is content. one could, then, argue that people don't think about outcomes unless they really have to because it means giving up (if only temporarily) a state of mind in which they experience happiness.&lt;br /&gt;&lt;br /&gt;that seems a little wishy washy to me, though, and while i was chatting with michael i had an idea about a possible root of mental laziness that is more like the one for physical laziness i described above. having a tendency to focus on the here and now could have been an advantageous evolutionary trait. being lost in thought when you're out in the wild and you're not the top of the food chain is a good way to become lunch for something else. those that spent too long thinking about abstract concepts got eaten while those who maintained a presence of mind lived on. the fact that contentment and happiness are linked to that mental state could be a neurological reward that evolved to reinforce what was once a beneficial behaviour (it feels good so do it more), much like our tendency to prefer sugary/fatty foods would have aided us in prioritizing energy rich foods when food was less plentiful (it tastes good so eat it more).&lt;br /&gt;&lt;br /&gt;of course, the world of today is much different than the world in which such evolutionary traits would have developed, so they don't serve us nearly as well as they once might have. those neurological rewards still reinforce the behaviours in spite of the fact that they're they're no longer advantageous. some of us have, whether through genetics or conscious effort, become better adapted to various realities of the modern world. those of use who have should count ourselves as lucky rather than looking down our noses at those who haven't adapted as quickly. fighting against millions of years of evolution can't be easy and few of us are really that much further along than anyone else.&lt;br /&gt;&lt;br /&gt;i offer these thoughts to serve as a form of perspective. it would be nice if we could just read some books or articles, or attend some classes and then magically overcome whatever it is that is holding back our security awareness. but if i'm right then at least part of what holds us back dates back to the dawn of man, if not earlier. such intrinsic aspects of humanity are not so easily changed, and yet we continue to evolve and adapt. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;(*to a certain extent i started trying to overcome others' mental laziness with respect to security with &lt;a href="http://www.secmeme.com/"&gt;http://www.secmeme.com&lt;/a&gt; long before i ever started to think in terms of mental laziness. if i were to describe it uncharitably, i'd say i was trying to trick people into thinking more about security.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-7933039097802162033?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=PsVvJ7h5IaY:k1foeZXjCec:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=PsVvJ7h5IaY:k1foeZXjCec:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=PsVvJ7h5IaY:k1foeZXjCec:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=PsVvJ7h5IaY:k1foeZXjCec:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/PsVvJ7h5IaY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/7933039097802162033/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=7933039097802162033" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/7933039097802162033" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/7933039097802162033" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/PsVvJ7h5IaY/dawn-of-insecurity.html" title="the dawn of insecurity" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/06/dawn-of-insecurity.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-1652829826266851606</id><published>2011-05-27T11:33:00.001-04:00</published><updated>2011-05-27T11:33:00.415-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="marcus ranum" /><category scheme="http://www.blogger.com/atom/ns#" term="blacklist" /><category scheme="http://www.blogger.com/atom/ns#" term="whitelist" /><title type="text">the whitelister's dilemma</title><content type="html">you remember marcus ranum's &lt;a href="http://www.ranum.com/security/computer_security/editorials/dumb/"&gt;6 dumbest ideas in computer security&lt;/a&gt;? #2 on that list was enumerating badness (aka &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-blacklist.html"&gt;blacklisting&lt;/a&gt;), which he believed should be replaced with enumerating goodness (aka &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-whitelist.html"&gt;whitelisting&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;ignoring the fact that his underlying assumptions about relative sizes of the &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-malware.html"&gt;malware&lt;/a&gt; and legitimate software populations was incredibly wrong*, there's a much more fundamental problem with turfing blacklisting in favour of whitelisting:&lt;br /&gt;&lt;blockquote&gt;the only meaningful criteria we have for deciding something is good or safe is that we haven't found anything bad in it yet.&lt;/blockquote&gt;oh sure you could &lt;b&gt;assume&lt;/b&gt; that a system is currently malware free and start your whitelisting regimen from that (potentially pre-pwned) state. you could &lt;b&gt;assume&lt;/b&gt; that software direct from the vendor is safe to add to a whitelist too (because microsoft never accidentally distributed &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-infection.html"&gt;infected&lt;/a&gt; materials, right?). you could even &lt;b&gt;assume&lt;/b&gt; that things that are digitally signed are safe (it's not like stuxnet was digitally signed or anything). &lt;br /&gt;&lt;br /&gt;of course, we know what happens when you &lt;b&gt;assume&lt;/b&gt;. the reality is that even if we do adopt whitelisting we have to continue enumerating badness for the purposes of maintaining the whitelist. whitelisting stands on the shoulders of blacklisting - it has to, our only other criteria are assumptions that have all been proven false in practice.&lt;br /&gt;&lt;br /&gt;as such, whitelisting can never replace blacklisting, it can only ever complement it.&lt;br /&gt;&lt;br /&gt;[* according to figures by whitelisting vendor bit9 that i mentioned &lt;a href="http://anti-virus-rants.blogspot.com/2008/05/bad-really-is-in-minority.html"&gt;here&lt;/a&gt;, and frankly the idea of a malicious few coders out-producing the benign many seemed silly anyways]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-1652829826266851606?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=BV-5QkklyJ8:dBQfHa2Y2sE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=BV-5QkklyJ8:dBQfHa2Y2sE:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=BV-5QkklyJ8:dBQfHa2Y2sE:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=BV-5QkklyJ8:dBQfHa2Y2sE:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/BV-5QkklyJ8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/1652829826266851606/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=1652829826266851606" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/1652829826266851606" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/1652829826266851606" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/BV-5QkklyJ8/whitelisters-dilemma.html" title="the whitelister's dilemma" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/05/whitelisters-dilemma.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-1042937001164019152</id><published>2011-05-23T13:15:00.006-04:00</published><updated>2011-05-23T13:15:00.141-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="malware" /><category scheme="http://www.blogger.com/atom/ns#" term="osx" /><category scheme="http://www.blogger.com/atom/ns#" term="mac" /><title type="text">the mac malware phenomenon</title><content type="html">i posted something to twitter earlier (which was already too big to actually fit in a normal tweet) but i think there's more to be said.&lt;br /&gt;&lt;br /&gt;those who downplay the mac threat landscape by comparing it to the pc are missing the point. the mac will never be the pc, it'll never follow the same path or be in exactly the same place, but the mac community was sold false hope and many of them are either unaware or in denial about the fact that they were lied to.&lt;br /&gt;&lt;br /&gt;one of the most crippling thing about mac security awareness is the pc comparison. people can't look past the fact that things aren't as bad for the mac. does that really matter? crime in your neighborhood likely isn't as bad as crime in a ghetto (unless you happen to be unfortunate enough to be living in a ghetto), does that mean it's safe to leave the door to your house or car unlocked? no.&lt;br /&gt;&lt;br /&gt;stop thinking about the comparison, stop thinking about the pc entirely. imagine there are no pc's. think about the things that have happened in the mac landscape over the past several years and what they mean to the various subsets of the mac user population.&lt;br /&gt;&lt;br /&gt;there are users who believe macs are immune to &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-virus.html"&gt;viruses&lt;/a&gt;. that was proven technically false five years ago (i wrote about it &lt;a href="http://anti-virus-rants.blogspot.com/2006/03/mac-computers-and-viruses.html"&gt;here&lt;/a&gt;). the viruses that have been produced may have never reached epidemic proportions, but epidemics are a poor yardstick for measuring risk. car crashes aren't exactly an epidemic, but you should still fasten your seatbelt.&lt;br /&gt;&lt;br /&gt;there are users who believe macs are inherently secure because of their *nix lineage. this, in spite of the fact that the initial academic investigation of the concept of computer viruses involved &lt;a href="http://www.all.net/books/virus/part5.html"&gt;successful experiments&lt;/a&gt; in a professionally administered unix environment. also in spite of the fact that &lt;a href="http://anti-virus-rants.blogspot.com/2006/02/what-is-rootkit.html"&gt;rootkits&lt;/a&gt; originally come from the *nix family of platforms. also in spite of the fact that a security researcher renowned for successfully attacking the platform on multiple occasions has &lt;a href="http://www.engadget.com/2010/03/19/charlie-miller-to-reveal-20-zero-day-security-holes-in-mac-os-x/"&gt;explicitly contradicted&lt;/a&gt; the notion that macs are especially secure.&lt;br /&gt;&lt;br /&gt;there are those who believe that for something to be a &lt;b&gt;real&lt;/b&gt; threat it has to activate by itself without user intervention, that something that requires the user's help is only an issue for dumb users. this despite the obvious success of &lt;a href="http://anti-virus-rants.blogspot.com/2006/02/what-is-social-engineering.html"&gt;social engineering&lt;/a&gt; attacks like &lt;a href="http://anti-virus-rants.blogspot.com/2006/11/what-is-phishing.html"&gt;phishing&lt;/a&gt; that are already platform agnostic.&lt;br /&gt;&lt;br /&gt;there are users who believe macs aren't really a target of criminals yet. they believe that the criminals have bigger fish to go after so the mac isn't worth the effort. they believe criminals have to make an either/or decision about which platform to attack. these beliefs are in stark contrast to a nearly 4 year old reality of professional cybercriminals attacking the mac platform - specifically the zlob gang taking their already successful windows trojan and porting the important functionality over to the mac (which i mentioned &lt;a href="http://anti-virus-rants.blogspot.com/2008/04/mac-malware-reality-check.html"&gt;here&lt;/a&gt; and &lt;a href="http://anti-virus-rants.blogspot.com/2008/05/gaming-mac-malware-game-theory.html"&gt;here&lt;/a&gt;). the more recent &lt;a href="http://blogs.mcafee.com/mcafee-labs/i-smell-a-rat-java-botnet-found-in-the-wild"&gt;example of java based malware&lt;/a&gt; is an indication that the cybercriminals are trying to take the either/or question out of the equation entirely.&lt;br /&gt;&lt;br /&gt;and then there are those wonderful users who are actually security aware but somehow believe the rest of the mac user community is largely like them so the efforts to raise awareness of security issues are pointless and alarmist. this is even though it's plain to see that security aware people are a minority in any population. and as far as the mac user population goes, apple's marketing was quite clearly designed to appeal to people based on style, image, and simplicity, and told users that security was something they didn't have to worry about. to imagine such a population is somehow better at dealing with security issues than the average person seems more than unjustifiably optimistic.&lt;br /&gt;&lt;br /&gt;macs can be attacked, they have been attacked, their attackers are enjoying increasingly numerous successes, and not enough mac users know it. it's a growing threat and there has yet to be a compelling argument put forward that it won't continue to grow. knowledge is the first prerequisite for people to be able to protect themselves. stop pretending everyone knows what you know or are smart enough to make the threat a non-issue, there's just too much variety amongst humans for that to be true.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-1042937001164019152?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=voLmgZtZOYI:MKrKNU-JkxU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=voLmgZtZOYI:MKrKNU-JkxU:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=voLmgZtZOYI:MKrKNU-JkxU:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=voLmgZtZOYI:MKrKNU-JkxU:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/voLmgZtZOYI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/1042937001164019152/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=1042937001164019152" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/1042937001164019152" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/1042937001164019152" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/voLmgZtZOYI/mac-malware-phenomenon.html" title="the mac malware phenomenon" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/05/mac-malware-phenomenon.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-8600591113554145819</id><published>2011-05-19T19:18:00.000-04:00</published><updated>2011-05-19T19:18:00.117-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ethics" /><category scheme="http://www.blogger.com/atom/ns#" term="total defense inc" /><category scheme="http://www.blogger.com/atom/ns#" term="snake oil" /><category scheme="http://www.blogger.com/atom/ns#" term="updata partners" /><title type="text">Snake-Oil 'R' Us</title><content type="html">it seems that &lt;a href="http://anti-virus-rants.blogspot.com/2006/04/what-is-snake-oil.html"&gt;snake-oil&lt;/a&gt; is changing with the times, evolving and getting worse.&lt;br /&gt;&lt;br /&gt;worse? how could it possible get any worse?&lt;br /&gt;&lt;br /&gt;well, &lt;a href="http://anti-virus-rants.blogspot.com/2006/10/complete-total-full-protection-is-snake.html"&gt;i've mentioned in the past&lt;/a&gt; how certain products very names can represent snake-oil - names like &lt;a href="http://www.google.ca/search?hl=en&amp;q=mcafee%20total%20protection"&gt;"total protection"&lt;/a&gt; or &lt;a href="http://www.google.ca/search?hl=en&amp;q=bitdefender%20total%20security"&gt;"total security"&lt;/a&gt; instill in the user the false belief that they are totally protected and don't have to worry anymore.&lt;br /&gt;&lt;br /&gt;well pretty soon there's going to be &lt;a href="http://antivirus.about.com/b/2011/05/16/ca-sells-antivirus-business.htm"&gt;"total defense"&lt;/a&gt; too.&lt;br /&gt;&lt;br /&gt;how is that worse? well, "total protection" and "total security" are just product names. total defense? that's apparently going to be a company name. a company that has snake-oil running through it's veins, i suppose. probably not a surprising move for updata partners, the technology venture company running the show - a venture company's focus is on making money, they're &lt;b&gt;buying&lt;/b&gt; computer associates' internet security business unit, they aren't existing members of the security or anti-malware community/industry. but they're &lt;b&gt;going&lt;/b&gt; to be part of the anti-malware industry, they're buying they're way into it, and they're starting from a position without the established norms and ethics of either the community or industry. no wonder the ethical landscape has been eroding over time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-8600591113554145819?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=C3nLiy97PBw:PqLbDrrPmJk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=C3nLiy97PBw:PqLbDrrPmJk:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=C3nLiy97PBw:PqLbDrrPmJk:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=C3nLiy97PBw:PqLbDrrPmJk:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/C3nLiy97PBw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/8600591113554145819/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=8600591113554145819" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/8600591113554145819" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/8600591113554145819" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/C3nLiy97PBw/snake-oil-r-us.html" title="Snake-Oil 'R' Us" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/05/snake-oil-r-us.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-9016955794921707477</id><published>2011-05-09T23:34:00.000-04:00</published><updated>2011-05-09T23:34:45.824-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">security small talk</title><content type="html">[i'm republishing &lt;a href="http://www.secmeme.com/2011/05/security-small-talk.html"&gt;this secmeme post&lt;/a&gt; here because, although the topic is more fitting for secmeme, the intended audience is better addressed here - and if you're like me, you probably hate being directed to some outside site when you're going through your RSS feed.]&lt;br /&gt;&lt;br /&gt;pursuant to a brief discussion i had with @diami03 (aka michelle k.) on twitter earlier today, some thoughts popped into my head.&lt;br /&gt;&lt;br /&gt;specifically, with regards to how well known the concept of the nigerian 419 scam is, i said&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-lj0zEc8y6pI/TcgJgZ_c8hI/AAAAAAAAAko/L1LfFE0DaN0/s1600/twitter+quote.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="187" src="http://4.bp.blogspot.com/-lj0zEc8y6pI/TcgJgZ_c8hI/AAAAAAAAAko/L1LfFE0DaN0/s400/twitter+quote.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;she was not happy with that. admittedly it was a rather crass way of expressing the principles i had in mind, but i stand by them (even if i also find them disappointing).&lt;br /&gt;&lt;br /&gt;put differently there are two things in play. the first (and probably the one most are familiar with) is that people often prefer to be entertained rather than informed. if i'm being totally honest, i feel the same way sometimes. &lt;br /&gt;&lt;br /&gt;the second is that (at least to my mind) a good indicator of how well our culture has assimilated a particular piece of information is how easily/frequently that information finds it's way into everyday chatter (i.e. small talk).&lt;br /&gt;&lt;br /&gt;now normally my memetic ramblings are intended for the broadest audience i can manage, but this is a special case. injecting security into small talk logically must start with the people who are security aware. many security geeks probably already do this to a certain extent - after all, if people can talk about the weather or last night's game, why not security topics too?&lt;br /&gt;&lt;br /&gt;now i'm not the best person to advise on how to engage in small talk (far from it in fact) but there are a few things i think are self-evident. first and foremost is that this is not an opportunity to give a lecture, or to talk like you're presenting at a conference. most people don't want to go back to school and if you start sounding like a teacher they're going to tune you out. so how can you shoot the breeze about security with non-security folks? here's a few strategies:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;everybody loves a spectacle so keep your eye out for them and use them opportunistically. database breaches aren't sexy or interesting, but sony's loss of over 100 million private records breaks the boredom barrier by sheer size alone. so much so, in fact that you may well find that people have already heard about it in the mainstream media. that's a bonus, it means you can talk about something they've already heard about.&lt;/li&gt;&lt;li&gt;if they're really your friends then it stands to reason that they have at least a modicum of interest in how your day was. did you see a nigerian 419 scam in your email today? great, mention that in passing. did you see two or more of them in the same day? even better. after all, how many dead princes (or whatever) can there really be out there? if wealth and death are as strongly correlated as those scam emails suggest then i think i'd rather stay poor.&lt;/li&gt;&lt;li&gt;when you mention things that you think might directly affect them, you're showing concern about them, you're showing an interest in their well-being. everyone wants their friends to be interested in them in some way so that display of interest should make them perk up their ears and take notice. i used this strategy myself with the epsilon breach, sending links to to the list of affected merchants to some of my friends so that they could look over the list and see if the breach was likely to affect them personally.&lt;/li&gt;&lt;/ol&gt;if you're concerned about the quality of information that is passing from person to person, it's up to you to help put better information into the mix. don't be afraid to throw in a few security topics when chatting with friends. they probably already know you're a security geek so they'll understand why you're interested in it, and if you can make it even a little bit interesting for them then they might pass it along.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-9016955794921707477?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=xl3Jbl0s_Qk:ysvVyRJn_K0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=xl3Jbl0s_Qk:ysvVyRJn_K0:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=xl3Jbl0s_Qk:ysvVyRJn_K0:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=xl3Jbl0s_Qk:ysvVyRJn_K0:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/xl3Jbl0s_Qk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/9016955794921707477/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=9016955794921707477" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/9016955794921707477" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/9016955794921707477" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/xl3Jbl0s_Qk/security-small-talk.html" title="security small talk" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-lj0zEc8y6pI/TcgJgZ_c8hI/AAAAAAAAAko/L1LfFE0DaN0/s72-c/twitter+quote.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/05/security-small-talk.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-4727449899742331295</id><published>2011-05-05T00:23:00.001-04:00</published><updated>2011-05-05T00:25:10.624-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><title type="text">thoughts on viral facebook scams</title><content type="html">in response to a certain discussion on twitter, i found some ideas floating around in my head that just don't fit in a tweet, so i thought i'd share them here instead.&lt;br /&gt;&lt;br /&gt;one of the ongoing problems on facebook is the phenomenon of viral scams - scams that spread in a viral manner across the facebook userbase and trick users into doing various things (whether it be installing a rogue facebook app, clicking an invisible link, or copy-n-pasting javascript into the URL bar).&lt;br /&gt;&lt;br /&gt;there are at least 2 contentious aspects to this phenomenon. the first is whether facebook has things under control. there are certainly those who are arguing that it's not under control, that the numbers are ever increasing. there are also those who argue that, on the whole, facebook is acting in a timely manner to deal with these threats to their users. my own experience is that i rarely actually encounter these viral scams so that certainly could support the argument that they're getting killed quickly - quickly enough that they die before they make their way to me. on the other hand, though, when i do encounter these scams it doesn't appear to me that facebook is dealing with them expediently at all. a day or more to kill a viral scam campaign? really? i think they could do better - in fact, i have some specific ideas that i intend to share a little further on.&lt;br /&gt;&lt;br /&gt;the second contentious aspect is what's the best way to deal with these scams: whether it's better for facebook to police it's network more effectively or alternatively to go after the industry whose gray areas are responsible for the lions share of the scamming (ie. the cost per action / CPA marketing industry). technical defenses employed by facebook will always be a bit of a game of whack-a-mole, but they're relatively quick and easy to implement without involving a lot of other parties. investigation and enforcement of legal authority against CPA firms can certainly have some long-lasting effects but there are problems; it takes a lot of time and coordination from the law enforcement community, and CPA is only the current low-hanging fruit from a malicious business model perspective. that means, ultimately, going after CPA firms or even entire industries will also wind up being a game of whack-a-mole, it'll just much slower and it will be law enforcement playing the game instead of a technology company.&lt;br /&gt;&lt;br /&gt;i believe both technical defenses and legal authority are appropriate tactics. technical defenses are useful for dealing in the near term with that which has not yet been dealt with in the long term, while exercising legal authority tends to have more of a long term effect and creates a much bigger disruption to malicious business models (potentially requiring entirely new malicious business models to be developed to compensate). right now we don't yet have the benefits that legal authority can provide so we need to use technical defenses as a stop-gap at the same time as we pursue legal avenues. if/when legal authority manages to take out most of the CPA abuse channels that the scammers are currently exploiting, those scammers will monetize something else so we'll continue to need those technical defenses as we adjust our legal tactics to their new business models. in essence, technical defenses and legal authority represent compensating controls in a multi-layered approach to the problem.&lt;br /&gt;&lt;br /&gt;to that end, i have some specific technical ideas for facebook. &lt;br /&gt;&lt;br /&gt;all viral scams must exploit one of facebook's many communications channels. facebook needs to monitor these channels and apply some heuristics to help identify the viral scams.&lt;br /&gt;&lt;br /&gt;to start out with, they should apply a k-nearest-neighbor algorithm or some other suitable similarity measure&amp;nbsp; to the communications (do not use hashing - i hardly ever see the scams but even in the few i have seen, i've seen hash busters being used) in a sliding window of time (to limit the size of the corpus facebook would need to analyze). messages, wall posts, events, etc that cluster together as being highly similar are likely all part of the same viral campaign and should be classified as such. being part of a large cluster should cause the message (or rather the entire set of messages) to be flagged for additional review at the very least. if that review is manual, one could prioritize the review based on the size of the cluster. not all viral communications are bad, mind you - it could just be a really good joke, or a political activist campaign, or something else legitimate - that's why &lt;i&gt;virality&lt;/i&gt; alone isn't enough to classify something as bad, but it is a good start for narrowing the scope of the analysis.&lt;br /&gt;&lt;br /&gt;now, even if facebook stopped at this point, they'd still have something very useful for killing viral scams. identifying the set of nearly identical messages that a particular message belongs to means that you can aggregate data and judgments about those messages. an abuse report for one message is an abuse report for all, a flag to disable display of one message is a flag to disable display of all, a flag indicating one message was verified clean is a flag indicating all are verified clean, etc.&lt;br /&gt;&lt;br /&gt;if facebook were to go further, though, the next thing they could do as a simple static heuristic is to check to see if the message contains javascript code that is displayed to the user. most users cannot read or understand javascript. for most, the only reason they'd see that in a viral message is if they're supposed to copy and paste it in order to bypass facebook's existing defenses against malicious javascript. that makes it a pretty good indicator of malicious intent.&lt;br /&gt;&lt;br /&gt;another simple heuristic would be the presence of a link whose destination is obscured by a URL shortener. a much more contentious heuristic, of course, but i'm not really suggesting any of these on their own should be taken as proof of malice - only that they each incrementally increase the level of suspicion.&lt;br /&gt;&lt;br /&gt;a third simple heuristic would be links to facebook applications where the app developers haven't been registered very long. it's not impossible to hit it big on facebook right out of the gate, but there are nuances that aid in growing an application's popularity that you wouldn't really expect a newbie to know right off the bat. a really big viral cluster for a really new app developer should definitely raise some eyebrows.&lt;br /&gt;&lt;br /&gt;next, as an active heuristic, an automated process attached to a dummy facebook account could be sent to click it's way through the trail laid out in any message that has a link in it in order to see if any path results in the dummy account sending out a message belonging to the same viral campaign it started from. this means adding applications where requested, following links to outside pages, even pasting the contents of the clipboard into the URL bar when the trail leads back to facebook's domain.&lt;br /&gt;&lt;br /&gt;finally, recognizing that different viral clusters could be related, there needs to be a mapping between inputs and outputs of those dummy accounts so that facebook can catch the condition when an incoming message from viral campaign A leads to outgoing message from viral campaign B and which in turn goes through 0-N other viral campaigns as inputs and outputs before arriving back at campaign A.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;i don't know what methods facebook is using right now, but if they were aggregating nearly identical messages it shouldn't have taken a day or more to kill the last viral scam i encountered and it shouldn't still be possible to easily find something like this half a month later:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-HNFyDnlP1TU/TcIgBk7NZwI/AAAAAAAAAkQ/PZen4AMfcME/s1600/scammy-events.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-HNFyDnlP1TU/TcIgBk7NZwI/AAAAAAAAAkQ/PZen4AMfcME/s400/scammy-events.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;those may be neutered to the extent that they can't contribute to viral spread in facebook's environment anymore, but who knows what the pages those point to could be changed to do to people's PCs now that the main campaign is dead. those events should have been deleted a long time ago. leaving remnants of viral scams in people's accounts is a little like leaving remnants of viral code in disinfected programs.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-4727449899742331295?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=Hv7-jPeA0Jw:YLw8QCu81Us:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=Hv7-jPeA0Jw:YLw8QCu81Us:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=Hv7-jPeA0Jw:YLw8QCu81Us:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=Hv7-jPeA0Jw:YLw8QCu81Us:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/Hv7-jPeA0Jw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/4727449899742331295/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=4727449899742331295" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/4727449899742331295" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/4727449899742331295" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/Hv7-jPeA0Jw/thoughts-on-viral-facebook-scams.html" title="thoughts on viral facebook scams" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-HNFyDnlP1TU/TcIgBk7NZwI/AAAAAAAAAkQ/PZen4AMfcME/s72-c/scammy-events.PNG" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/05/thoughts-on-viral-facebook-scams.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-5859364435026118739</id><published>2011-04-21T12:48:00.003-04:00</published><updated>2011-04-21T12:48:00.529-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="fud" /><title type="text">essential FUD</title><content type="html">upon reading mike rothman's recent post on &lt;a href="http://securosis.com/blog/categorizing-fud"&gt;categorizing FUD&lt;/a&gt; i was struck with a rather surprising realization. not only has the much reviled APT suffered semantic dilution, but apparently so has the seemingly simple concept of &lt;a href="http://anti-virus-rants.blogspot.com/2006/04/what-is-fud.html"&gt;FUD&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;i say semantic dilution rather than semantic drift because, rather than taking on a new meaning, the apparent elimination of uncertainty and doubt from mike's description means that it's 2/3rds of the way to having no meaning at all. it seems that anything invoking fear is now some kind of FUD - but can that be true? are fear and FUD interchangeable? do we want to make them interchangeable? wouldn't we really only be saving a single keystroke in the process?&lt;br /&gt;&lt;br /&gt;i don't agree with mike's characterization of FUD (which seems only fitting as mike doesn't agree with much i say). although i have tried to define FUD before, i've never gone into enough depth that it would contradict interpretations like mike's. that changes today.&lt;br /&gt;&lt;br /&gt;if there is one part of &lt;u&gt;fear, uncertainty, and doubt&lt;/u&gt; that could clear this all up if it weren't so often completely overlooked - one word that held a surprising amount of meaning - it would be:&lt;br /&gt;&lt;h1 style="text-align: center;"&gt;AND&lt;/h1&gt;it's not fear, uncertainty, &lt;i&gt;OR&lt;/i&gt; doubt, boys and girls, it's &lt;b&gt;AND&lt;/b&gt;. we're talking about the intersection of the three, not the union. no single one of fear, uncertainty, or doubt qualifies as FUD on it's own. FUD requires the presence of all three. fear is only part of it. i'm tempted to say fear is only the beginning, but that's not true, something as yet unmentioned is the beginning and fear, uncertainty, and doubt are the consequences.&lt;br /&gt;&lt;br /&gt;what's going on behind the scenes with FUD, what makes it such a bad thing beyond the simple fact that it's used as a manipulation, is that it introduces an inaccurate mental model that competes with superior ones and the results are rather insidious. mental models inform our actions. they allow us to predict outcomes and consequently allow us to make plans designed to control outcomes in our favour. they are a tool which allows us to effectively formulate strategies for satisfying our basic human needs.&lt;br /&gt;&lt;br /&gt;unfortunately, mental models are never 100% complete. there are always holes, always missing pieces and weak points. these are what FUD models exploit in order to compete with existing mental models. obviously if someone's mental model is more complete and internally consistent they are less susceptible to FUD because they "know better" than to fall for it, but unfortunately many people have mental models that are largely incomplete so a FUD mental model has a good chance of taking hold and effectively competing with the model the person had.&lt;br /&gt;&lt;br /&gt;that competition is a problem. it causes a person to be confused, to question what they thought they knew. this is the uncertainty - the U in FUD. subsequent to that a person would then logically start to distrust the sources that had informed them and helped them form their previous mental model. this makes it difficult for those or similar/consistent sources to fill in blanks in the original mental model and thus interferes with a person's ability to build a better mental model. this is the doubt - the D in FUD. finally comes the logical conclusion that if what one thought one knew was wrong then the steps one took based on that knowledge could also be wrong. the consequence of that being that the person is no longer prepared or capable of handling something they needed to handle and the emotional reaction to that is fear - the F in FUD.&lt;br /&gt;&lt;br /&gt;recapping then, a more in-depth account of FUD is that it is a communicated inaccurate mental model that causes:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;uncertainty about what you know&lt;/li&gt;&lt;li&gt;doubt in those whom you learned from or could learn from in the future&lt;/li&gt;&lt;li&gt;fear that you're no longer going to be able to satisfy some need that you have&lt;/li&gt;&lt;/ul&gt;it should be noted that that same fear can result when you fill in some of the blanks of an incomplete mental model. what differentiates that from FUD, however, is that although fear can result in the short term, there's no uncertainty or doubt. building a better, more complete mental model results in a person being better able develop strategies to satisfy their needs in the long run and is thus beneficial, as compared with FUD which stymies a person's ability to develop effective strategies.&lt;br /&gt;&lt;br /&gt;now the argument could be made that mike himself was spreading FUD about FUD (meta-FUD). a model of FUD that seemingly allowed for anything involving fear to be called FUD would certainly make people uncertain about what they previously knew about FUD and doubt the people that had previously informed their opinions about FUD. and since mike also opened the door for the possibility of good FUD and suggested that FUD was more widespread than one would have otherwise thought (as a consequence of dropping 2/3rd's of the requirements), there would certainly be room for people to be concerned that they no longer knew how to navigate the sea of FUD mike was depicting and thus be afraid of getting duped.&lt;br /&gt;&lt;br /&gt;on the other hand, however, the argument could also be made that mike's model of FUD is simply incomplete (seemingly missing uncertainty and doubt) and that what might appear to be meta-FUD is actually inaccurate conclusions drawn as a result of missing pieces of that model.&lt;br /&gt;&lt;br /&gt;i'm not going to accuse mike of spreading meta-FUD, primarily because i feel accusations of FUD spreading should be reserved for those who should know better than to believe the model they're communicating. those spreading inaccurate or inferior mental models unwittingly should certainly be notified, however.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-5859364435026118739?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=iy37_58ToFU:ZLbjyhy0ZTk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=iy37_58ToFU:ZLbjyhy0ZTk:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=iy37_58ToFU:ZLbjyhy0ZTk:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=iy37_58ToFU:ZLbjyhy0ZTk:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/iy37_58ToFU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/5859364435026118739/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=5859364435026118739" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/5859364435026118739" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/5859364435026118739" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/iy37_58ToFU/essential-fud.html" title="essential FUD" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/04/essential-fud.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-7576112814495629247</id><published>2011-04-12T10:38:00.003-04:00</published><updated>2011-04-12T10:38:00.130-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="virustotal" /><title type="text">it's not a detection rate</title><content type="html">(this has been stewing for a little while now)&lt;br /&gt;&lt;br /&gt;look, i realize that &lt;a href="http://www.virustotal.com/"&gt;virustotal&lt;/a&gt; performs a series of detection tests in order to get it's results. i also know that it expresses those results as something that looks a lot like a rate. but as much as you may want to, as much intuitive sense as it may make, don't mistake those results for a detection rate.&lt;br /&gt;&lt;br /&gt;first, let's deal with the elephant in the room. in the anti-malware world, the term "detection rate" has already been used for something else. traditionally a detection rate is arrived at by testing an anti-malware product against many malware samples in order to see how good the product is at detecting malware. this is what detection rate has meant for somewhere on the order of two decades, and it bares little relation to what virustotal does.&lt;br /&gt;&lt;br /&gt;the inverse of that method, to test a single sample against many anti-malware products in order to see how bad anti-malware technology is, is in theory similar to what virustotal does but it differs in two very important ways:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;the purpose of virustotal's test is to give the user an indication of whether the submitted sample is likely to be malware rather than to determine how bad anti-malware technology is&lt;/li&gt;&lt;li&gt;the way virustotal uses anti-malware products in it's testing does not lend itself to an accurate determination of whether a particular product can detect a particular sample (as i've discussed &lt;a href="http://anti-virus-rants.blogspot.com/2009/01/virustotal-usage-fail.html"&gt;over&lt;/a&gt; and &lt;a href="http://anti-virus-rants.blogspot.com/2008/12/why-perform-virustotal-based-av-tests.html"&gt;over again&lt;/a&gt;, and &lt;a href="http://blog.hispasec.com/virustotal/22"&gt;as hispasec themselves mention&lt;/a&gt;)&lt;/li&gt;&lt;/ol&gt;i mulled over the idea that even though it's not a detection rate, and it's not even an inverse detection rate, maybe it could at least represent the lower bound of an inverse detection rate since the most obvious methodological problems (if we were trying to interpret virustotal results the way some people seem to want) would lead to detection capabilities being under-reported. even if it could be called that, however, an inverse detection rate lower bound is so abstract that there's little benefit in using the term with the general population. &lt;br /&gt;&lt;br /&gt;i'm tempted to suggest people just call the results a &lt;u&gt;&lt;i&gt;&lt;b&gt;score&lt;/b&gt;&lt;/i&gt;&lt;/u&gt;, but when you compare "virustotal results" with "virustotal score" you realize you're not really saving much more than 2 keystrokes by using that term. there's no intuitive meaning to be had in either of them. it seems the kind of intuitive meaning that people hope to convey by calling it a detection rate simply can't be had.&lt;br /&gt;&lt;br /&gt;as such, whether you're an recognized and well regarded expert like &lt;a href="http://twitter.com/danchodanchev/status/53085667890176001"&gt;dancho danchev who explicitly calls it a detection rate&lt;/a&gt;, or &lt;a href="http://twitter.com/briankrebs/status/57533617613705216"&gt;brian krebs who tries to infer meaning about&lt;/a&gt; &lt;a href="http://twitter.com/briankrebs/status/57534166706831360"&gt;anti-malware technology by looking at the results&lt;/a&gt;, or even if you just someone who relies on such experts for their accurate analyses and informed opinions - remember that virustotal is for testing samples not anti-malware products. don't try to infer meaning from virustotal test results about something virustotal isn't meant to test. you will most likely fail.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-7576112814495629247?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=MZAi1U_6tok:mpHW45hKoQw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=MZAi1U_6tok:mpHW45hKoQw:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=MZAi1U_6tok:mpHW45hKoQw:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=MZAi1U_6tok:mpHW45hKoQw:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/MZAi1U_6tok" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/7576112814495629247/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=7576112814495629247" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/7576112814495629247" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/7576112814495629247" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/MZAi1U_6tok/its-not-detection-rate.html" title="it's not a detection rate" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/04/its-not-detection-rate.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-2881924533212263351</id><published>2011-04-06T10:14:00.003-04:00</published><updated>2011-04-06T10:14:00.138-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="epsilon" /><category scheme="http://www.blogger.com/atom/ns#" term="email" /><category scheme="http://www.blogger.com/atom/ns#" term="disposable email address" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">why the epsilon breach shouldn't be an issue</title><content type="html">the epsilon breach (&lt;a href="http://krebsonsecurity.com/2011/04/epsilon-breach-raises-specter-of-spear-phishing/"&gt;where an email marketing company that does business with a veritable who's who of big name corporate brands and financial institutions lost the names and email addresses of the customers of those companies&lt;/a&gt;) seems to be on everyone's mind recently, and to tell the truth i find that kind of strange. &lt;br /&gt;&lt;br /&gt;it's not as though i'm under any illusion about it not being able to affect me. a colleague of mine at work got a notification about the breach affecting him so while i haven't received one yet myself, the possibility of receiving one certainly exists. yet i find myself completely unconcerned about the possibility. why? because i took steps to protect myself proactively (steps my colleague knew he should have taken such that now wishes he'd been more vigilant).&lt;br /&gt;&lt;br /&gt;i have been using disposable email addresses since the fall of 2004. with them &lt;a href="http://anti-virus-rants.blogspot.com/2006/12/how-to-avoid-email-spam.html"&gt;i've managed to keep any email accounts i created after that point completely spam free&lt;/a&gt; for the past 6 1/2 years, i've come up with &lt;a href="http://anti-virus-rants.blogspot.com/2006/12/how-to-recognize-phishing-emails-easy.html"&gt;a sender authentication protocol to foil phishing&lt;/a&gt;, and as it happens &lt;a href="http://anti-virus-rants.blogspot.com/2008/12/unexpected-spam.html"&gt;i've recovered from email breaches in the past&lt;/a&gt; in mere moments.&lt;br /&gt;&lt;br /&gt;and that's the reason a breach like epsilon is a non-issue to me. not only is it old hat, recovering is as simple as logging into the disposable email provider and clicking disable or delete (depending on the provider) for each compromised address, and then going on about the rest of your day.&lt;br /&gt;&lt;br /&gt;it's dead simple to recover from the breach of something when that something happens to be disposable - you simply dispose of it. what i don't understand is, why aren't more people and especially more security practitioners doing the same thing? why hand out your real personal contact information like candy on halloween if you don't have to (and believe me, you don't have to)?&amp;nbsp; even if you decide you still want to do business with these companies who saw fit to hand your contact information over to a marketing company (hey, you're already their customer, why do they need to keep trying so hard to sell to you), it's a heck of a lot easier to make a replacement disposable email address than it is to make a replacement real email address. just a couple of clicks and some random typing (or just mash keys if you prefer); no captcha, no verifcation, no profile info, you filled that all out when you created an account at the disposable email provider in the first place.&lt;br /&gt;&lt;br /&gt;cory doctorow gave a short talk about &lt;a href="http://www.youtube.com/watch?v=RAGjNe1YhMA"&gt;kids and privacy&lt;/a&gt; and he mentioned that they're being trained to not value their privacy, in part by over protective parents who prevent them from learning how to protect themselves. i don't think kids are the only ones who've been so trained. one of the most regrettable schools of thought that i've seen displayed from users all the way up to security pros is the one that says '&lt;i&gt;they&lt;/i&gt; are (or are supposed to be) protecting me'. there is a profound absence of self-reliance in favour of letting protection be the responsibility of someone else.&lt;br /&gt;&lt;br /&gt;most people wouldn't hand their phone number out to every tom, dick, or harry they meet on the street, but when it comes to email addresses somehow people think the rules are different. they trust everyone who asks for it and expect everyone to protect it for them instead of protecting it themselves. this is an absurd position to take, but &lt;i&gt;authorities&lt;/i&gt; (ie. people who are supposed to know better) have groomed the masses to systematically take just that position when it comes to anything that has to do with online protection.&lt;br /&gt;&lt;br /&gt;i'm not holding my breath but, considering the scope of the epsilon breach, maybe some people will start to think&lt;br /&gt;&lt;blockquote&gt;well if you're going to protect me from the bad guys, who's going to protect me from you?&lt;/blockquote&gt;i know, i'm probably being too optimistic, but surely some people out there will see this incident and realize how truly pervasive the mishandling of personal information is by the people we entrust it to. dozens of companies handed that data over to one completely unnecessary entity which then became a single point of failure, and because most people weren't protecting themselves from those companies (either their intentional bad acts or their ineptitude) many people are now at much greater risk of falling victim to targeted phishing and other related attacks.&lt;br /&gt;&lt;br /&gt;a clever reader would probably realize that entrusting your real email address to a disposable email provider is still expecting that provider to protect it for you. the thing is, instead of trusting many entities with your data, under this model you're only trusting one. you also don't have to trust them with the same address you use for personal correspondence (which would be the hardest kind of address to change); i certainly don't.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-2881924533212263351?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=HHTlMzPDQac:oXYpeLnrctk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=HHTlMzPDQac:oXYpeLnrctk:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=HHTlMzPDQac:oXYpeLnrctk:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=HHTlMzPDQac:oXYpeLnrctk:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/HHTlMzPDQac" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/2881924533212263351/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=2881924533212263351" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/2881924533212263351" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/2881924533212263351" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/HHTlMzPDQac/why-epsilon-breach-shouldnt-be-issue.html" title="why the epsilon breach shouldn't be an issue" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/04/why-epsilon-breach-shouldnt-be-issue.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-8330379085289477006</id><published>2011-03-31T12:50:00.000-04:00</published><updated>2011-03-31T12:50:33.404-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="anti-malware community watch" /><category scheme="http://www.blogger.com/atom/ns#" term="mcafee" /><title type="text">community watch experiment</title><content type="html">this is just a heads up about an experiment i'm trying out. i have no idea if it will prove useful; but if you were at all interested in the discovery that mcafee had partnered with a malware vendor, especially if you wanted to say something about it but felt like you couldn't, &lt;a href="http://anti-malware-community-watch.blogspot.com/p/about.html"&gt;this experiment&lt;/a&gt; was cooked up with you in mind.&lt;br /&gt;&lt;br /&gt;basically, if the industry can't police itself then it seems like the next logical group to shoulder that burden is the anti-malware community. i'm proposing something like a neighborhood watch, and if one of you sees something then please try and find a way to say something - i'm willing to help if i can.&lt;br /&gt;&amp;nbsp;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-8330379085289477006?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=k6lSG0rjj-s:ljL8ophLHj8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=k6lSG0rjj-s:ljL8ophLHj8:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=k6lSG0rjj-s:ljL8ophLHj8:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=k6lSG0rjj-s:ljL8ophLHj8:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/k6lSG0rjj-s" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/8330379085289477006/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=8330379085289477006" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/8330379085289477006" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/8330379085289477006" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/k6lSG0rjj-s/community-watch-experiment.html" title="community watch experiment" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/03/community-watch-experiment.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-915634432099972419</id><published>2011-03-20T22:42:00.005-04:00</published><updated>2011-03-20T22:42:00.119-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="credibility" /><category scheme="http://www.blogger.com/atom/ns#" term="ethics" /><category scheme="http://www.blogger.com/atom/ns#" term="anti-malware" /><category scheme="http://www.blogger.com/atom/ns#" term="accountability" /><category scheme="http://www.blogger.com/atom/ns#" term="malware creation" /><title type="text">the covenant is broken</title><content type="html">one month ago i published &lt;a href="http://anti-virus-rants.blogspot.com/2011/02/ethical-conflict-in-anti-malware-domain.html"&gt;a blog post excoriating mcafee&lt;/a&gt; for being involved with a firm that creates and sells &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-malware.html"&gt;malware&lt;/a&gt;. for one month i've been waiting - not for a reaction to my own post, but a parallel reaction from the industry to the revelation that mcafee was involved with malware creators. i have been underwhelmed by the response (or lack thereof), and somewhat overwhelmed by the implications.&lt;br /&gt;&lt;br /&gt;take a moment to let the &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-anti-malware-anti-virus.html"&gt;AV&lt;/a&gt; industry's silence on this matter sink in. what does it mean? does it mean that they can't say anything because they've all got similar skeletons in their closet? or does it mean they're just not interested in capitalizing on that sort of thing anymore?&lt;br /&gt;&lt;br /&gt;you see, for a long time there's been a persistent rumour that AV vendors don't just partner with malware writing companies, they hire &lt;a href="http://anti-virus-rants.blogspot.com/2010/08/what-is-malware-writer.html"&gt;malware writers&lt;/a&gt; outright. the AV vendors, of course, claim that that doesn't happen - they claim to have a policy against hiring malware writers &lt;i&gt;and&lt;/i&gt; they say not to just take their word for it because their competition would take advantage of such ethical lapses if they were ever to occur.&lt;br /&gt;&lt;br /&gt;they weren't just blowing hot air, either. making an example of an anti-malware company that hired a virus writer has happened in the past (thank you &lt;a href="http://www.f-secure.com/weblog/archives/00000346.html"&gt;f-secure&lt;/a&gt;), so we know that such self-correcting controls have previously been in place. we were supposed to trust AV companies because they were financially motivated to do the right thing. every company had something to lose if they misbehaved and every other company had something to gain if they caught someone misbehaving.&lt;br /&gt;&lt;br /&gt;but now the revelation that mcafee works with a malware writing company comes along and nobody has anything to say. well, to be specific, no company has anything to say (since i know there are individuals who felt strongly about this but may not have been able to speak for their employers). it was the job, the duty, of every member company in the anti-malware industry to act as a watchdog for the industry in case things like this happened, and you all &lt;b&gt;failed&lt;/b&gt;. each and every one. one month later is too late to strike - the opportunity has passed - the iron is no longer hot.&lt;br /&gt;&lt;br /&gt;the industry was supposed to be policing itself, but that no longer seems to be happening. without that, all we have is their word that they should be trusted, but those are just words. nothing but sweet, sweet words that turn into bitter orange wax in my ears (to quote futurama's philip j. fry). without &lt;b&gt;action&lt;/b&gt; it means nothing. &lt;br /&gt;&lt;br /&gt;the industry's accountability is gone. we can't honestly believe they're still policing themselves now. they used to adhere to and enforce the anti-malware community's standard of ethical behaviour. it's important to draw a distinction between the anti-malware community and the anti-malware industry at this point. although there has always been significant overlap, there has also always been those who were part of one set but not the other. obviously i'm not in the anti-malware industry, and i can think of a number of people who were members of the community long before they became part of the industry. on the other side, do you think HR is staffed by anti-malware community members? the legal department? upper management may have a few here or there, but for the most part they're just ordinary business folks. increasingly, the anti-malware industry is representing business interests instead of the values and ideals of the anti-malware community. the community's influence in the industry has been gradually waning up to this point where there's no one left who can realistically hold them accountable for violations of the community's standard of ethical behaviour.&lt;br /&gt;&lt;br /&gt;they can still be held accountable on technical grounds, i suppose, but for how long? &lt;a href="http://anti-virus-rants.blogspot.com/2010/09/what-is-anti-malware-testing.html"&gt;anti-malware testing&lt;/a&gt; was in a bad state for a while - AMTSO has been helping to elevate the quality of testing, but does the anti-malware industry (which is increasingly losing touch with the anti-malware community) have too much influence over the goings-on there? ideally the inclusion of both the anti-malware industry and anti-malware testing industry should create a balance. the testing industry has an understandable bias towards the more practicable approaches to testing (they have limited resources, after all) and a strong motivation to not appear to be going to easy on the vendors. the vendors, on the other hand, have insights into the inner workings of their products which are sometimes necessary to understanding and eliminating certain sources of testing bias and a strong motivation to perform well on tests. this should create a balance that forces both sides to take harder but ultimately superior paths. as the industry moves away from ethical accountability in favour of business concerns, it stands to reason that they may start to move away from embracing technical accountability as well - and realizing their input in AMTSO feeds back into a system that enables technical accountability, they may try to game the system for their own ends.&lt;br /&gt;&lt;br /&gt;this highlights yet another problem. not only does the industry itself become suspect, so does everything it touches. it's not just accountability that's gone, it's credibility as well, and that lack of credibility can be toxic to others. &lt;br /&gt;&lt;br /&gt;when the anti-malware industry no longer represents the values and ideals of the anti-malware community, when the bottom line takes priority over everything else, the result is bad for everyone. it's bad for the users because they will eventually have little left but to choose between crappy products in pretty boxes. it's bad for the anti-malware community within the industry because their jobs will cease to be fulfilling and they will be increasingly disturbed by the actions of their employers. it's even bad for the anti-malware community outside the industry simply because of association and the failure of most people to recognize any distinction between the industry and community. this isn't something that happens overnight. this isn't something that started one month ago. it's been going on for a while and you community members in the industry are all &lt;a href="http://en.wikipedia.org/wiki/Boiling_frog"&gt;frogs in a pot that is being slowly brought to a boil&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;i don't know how to correct this. i don't even know if it can be corrected (damage has already been done, and you can't always go back to the way things were). i don't pretend to have those kinds of answers. if i had to guess, i would guess that turning the industry around and getting back on course would take as much influence as the community can muster. full recovery may not be possible, but is not trying really an option? an alternative may be to restore accountability through external sources, but given the particulars in play (a company that sells malware to a nation state), that would involve scrutiny from other nation states and being investigated by scores of foreign nations on an ongoing basis doesn't sound appealing.&lt;br /&gt;&lt;br /&gt;there can be no credibility without accountability and there can be no accountability without consequences. that house of cards depends on consequences and as near as i can tell there have been none.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-915634432099972419?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=thHjmFXj7EU:On4nM5bYDeU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=thHjmFXj7EU:On4nM5bYDeU:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=thHjmFXj7EU:On4nM5bYDeU:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=thHjmFXj7EU:On4nM5bYDeU:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/thHjmFXj7EU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/915634432099972419/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=915634432099972419" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/915634432099972419" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/915634432099972419" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/thHjmFXj7EU/covenant-is-broken.html" title="the covenant is broken" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/03/covenant-is-broken.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-3460639205487462190</id><published>2011-02-20T19:34:00.011-05:00</published><updated>2011-02-20T19:34:00.807-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="symantec" /><category scheme="http://www.blogger.com/atom/ns#" term="commercial malware" /><category scheme="http://www.blogger.com/atom/ns#" term="hbgary" /><category scheme="http://www.blogger.com/atom/ns#" term="stealthkit" /><category scheme="http://www.blogger.com/atom/ns#" term="ethics" /><category scheme="http://www.blogger.com/atom/ns#" term="peter silberman" /><category scheme="http://www.blogger.com/atom/ns#" term="mandiant" /><category scheme="http://www.blogger.com/atom/ns#" term="greg hoglund" /><category scheme="http://www.blogger.com/atom/ns#" term="malware writer" /><category scheme="http://www.blogger.com/atom/ns#" term="komoku" /><category scheme="http://www.blogger.com/atom/ns#" term="mcafee" /><category scheme="http://www.blogger.com/atom/ns#" term="jamie butler" /><title type="text">ethical conflict in the anti-malware domain</title><content type="html">&lt;i&gt;forgive my silence over the last little while. motivation to blog sometimes isn't easy to find. as time wears on, fewer and fewer things get under my skin enough to drive me to rant (is that what it means to mellow with age?). but since you're reading this i think you can guess what this post infers.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;five years ago i wrote a post about what i perceived as an &lt;a href="http://anti-virus-rants.blogspot.com/2006/04/ethical-conflict-in-anti-rootkit.html"&gt;ethical conflict in the anti-'rootkit' domain&lt;/a&gt;. it detailed the actions of two of the most notorious names in &lt;a href="http://anti-virus-rants.blogspot.com/2006/04/whats-stealthkit.html"&gt;stealthkit&lt;/a&gt; research, jamie butler and greg hoglund, and how they were profiting from making a particular niche of the &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-malware.html"&gt;malware&lt;/a&gt; problem more popular (and thus, inevitably a bigger problem).&lt;br /&gt;&lt;br /&gt;one of the things i pointed out was that symantec was working with a start-up company (komoku) that had jamie butler (author of what was at one time one of the most widely deployed stealthkits around) as it's chief technology officer. i thought the fact that an &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-anti-malware-anti-virus.html"&gt;anti-malware&lt;/a&gt; company was in bed with a company that hired such a high profile &lt;a href="http://anti-virus-rants.blogspot.com/2010/08/what-is-malware-writer.html"&gt;malware writer&lt;/a&gt; deserved at least a moment of reflection, considering the hard-line stance anti-malware companies take on hiring malware writers themselves. at the end of the day, mind you, that start-up was focused on prevention so maybe the argument could be made that mr. butler had or was trying to reform in some way. (mr. butler has since moved on to mandiant, along with his disciple {the FU2 to butler's FU} peter silberman)&lt;br /&gt;&lt;br /&gt;when i &lt;a href="http://arstechnica.com/tech-policy/news/2011/02/anonymous-speaks-the-inside-story-of-the-hbgary-hack.ars"&gt;read earlier this past week&lt;/a&gt; that another anti-malware company (mcafee) had been working with greg hoglund's company (hbgary) i thought it an interesting historical footnote but paid little attention to it beyond that (though, if i had remembered that &lt;a href="http://anti-virus-rants.blogspot.com/2006/04/mcafees-rootkit-report-alternative.html"&gt;mcafee had once been pointing fingers at rootkitDOTcom&lt;/a&gt;, maybe the hypocrisy would have stood out more). after all, little attention seemed to be paid to such connections five years ago so why should this time be any different? well, that was before i knew what hbgary was in to.&lt;br /&gt;&lt;br /&gt;apparently, on top of the legitimate work that one can find out about by visiting the hbgary website (which of course &lt;a href="http://anti-virus-rants.blogspot.com/2006/04/anti-malware-linking-policy.html"&gt;i won't link to&lt;/a&gt;), it &lt;i&gt;appears&lt;/i&gt; that hbgary also &lt;a href="http://arstechnica.com/tech-policy/news/2011/02/black-ops-how-hbgary-wrote-backdoors-and-rootkits-for-the-government.ars/"&gt;writes and sells malware for fairly large sums of money&lt;/a&gt;. the customers for their malware include the government/military but might not stop there. even if that set of customers does stop there, hbgary appears to be in the high-end commercial malware business.&lt;br /&gt;&lt;br /&gt;so where does that leave mcafee? it leaves them in bed with commercial malware writers. while AV companies have been proclaiming for decades that they don't and won't hire malware writers, apparently they don't have to. they can simply partner with the boutique security shops that do. clearly they are not picking their business associates as carefully as they are their actual employees. &lt;br /&gt;&lt;br /&gt;and then there's the claim that surfaces from time to time that AV companies won't make special provisions to keep malware deployed by the authorities from getting detected. what's the point of making such a claim if you're just going to turn around and do business with the company that may very well be making said malware?&lt;br /&gt;&lt;br /&gt;how many other AV companies, besides mcafee, were or are in bed with hbgary? how many are in bed with companies &lt;b&gt;&lt;i&gt;LIKE&lt;/i&gt;&lt;/b&gt; hbgary? where's their ethical high horse when it comes to partnerships? why wasn't the "malware writers need not apply" policy updated when commercial malware became the norm and presented the loophole we see before us today?&lt;br /&gt;&lt;br /&gt;&lt;i&gt;some&lt;/i&gt; AV companies are rewarding malware writers financially. it may not be in the ways we traditionally thought of, but with the #2 company in the industry involved in this practice (and arguably the #1 company as well, depending on where you want to draw the line), the end result is AV companies contributing to the commercial success of malware writers, and &lt;b&gt;that is not ok at all&lt;/b&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-3460639205487462190?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=mxAmKTwmt4A:4W_WunGEzKk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=mxAmKTwmt4A:4W_WunGEzKk:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=mxAmKTwmt4A:4W_WunGEzKk:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=mxAmKTwmt4A:4W_WunGEzKk:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/mxAmKTwmt4A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/3460639205487462190/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=3460639205487462190" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/3460639205487462190" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/3460639205487462190" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/mxAmKTwmt4A/ethical-conflict-in-anti-malware-domain.html" title="ethical conflict in the anti-malware domain" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>3</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/02/ethical-conflict-in-anti-malware-domain.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-3542759333690114589</id><published>2011-01-20T00:17:00.000-05:00</published><updated>2011-01-20T00:17:52.469-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="commercial malware" /><category scheme="http://www.blogger.com/atom/ns#" term="virus" /><category scheme="http://www.blogger.com/atom/ns#" term="stealth" /><category scheme="http://www.blogger.com/atom/ns#" term="boot sector virus" /><category scheme="http://www.blogger.com/atom/ns#" term="brain" /><title type="text">brain - a first in so many ways</title><content type="html">i've seen &lt;a href="http://www.news.com.au/technology/the-birth-of-the-first-personal-computer-virus-brain/story-e6frfro0-1225990906387"&gt;a couple&lt;/a&gt; &lt;a href="http://techland.time.com/2011/01/19/happy-birthday-jerk-first-pc-virus-born-25-years-ago/"&gt;of articles&lt;/a&gt; now about this being the 25th anniversary of the &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-virus.html"&gt;computer virus&lt;/a&gt; known as &lt;a href="http://www.f-secure.com/v-descs/brain.shtml"&gt;brain&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;brain was the first PC virus in the wild. it was the first &lt;a href="http://anti-virus-rants.blogspot.com/2006/10/what-is-boot-sector-virus.html"&gt;bootsector infector&lt;/a&gt;. it was the first &lt;a href="http://anti-virus-rants.blogspot.com/2006/02/what-is-stealth.html"&gt;stealth&lt;/a&gt; virus.&lt;br /&gt;&lt;br /&gt;supposedly it was created in the (somewhat hypocritical) hopes of attacking software piracy, so the history of intellectual property maximalism has a particularly odious chapter to add.&lt;br /&gt;&lt;br /&gt;the thought occurred to me, however (and i'm probably not the first but i haven't seen this said anywhere that i can remember), that if the stated motivation behind the virus is correct then brain is, on top of everything else, the first commercially motivated &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-malware.html"&gt;malware&lt;/a&gt;. before &lt;a href="http://www.f-secure.com/v-descs/trojan-spy_w32_zbot.shtml"&gt;zeus&lt;/a&gt;, before &lt;a href="http://www.f-secure.com/v-descs/gpcode.shtml"&gt;gpcode&lt;/a&gt;, before &lt;a href="http://anti-virus-rants.blogspot.com/2006/03/what-is-adware.html"&gt;adware&lt;/a&gt;, before the porn dialers there was the brain virus intended to get people to contact the virus' manufacturer for &lt;i&gt;support&lt;/i&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-3542759333690114589?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=VehIvK2mhiQ:-ymuc6LoHYA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=VehIvK2mhiQ:-ymuc6LoHYA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=VehIvK2mhiQ:-ymuc6LoHYA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=VehIvK2mhiQ:-ymuc6LoHYA:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/VehIvK2mhiQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/3542759333690114589/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=3542759333690114589" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/3542759333690114589" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/3542759333690114589" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/VehIvK2mhiQ/brain-first-in-so-many-ways.html" title="brain - a first in so many ways" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/01/brain-first-in-so-many-ways.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-7490742187485430479</id><published>2011-01-17T07:39:00.001-05:00</published><updated>2011-01-17T07:39:00.715-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="symantec" /><category scheme="http://www.blogger.com/atom/ns#" term="marketing" /><category scheme="http://www.blogger.com/atom/ns#" term="terminology misuse" /><title type="text">how do you get to the top?</title><content type="html">so how do you get to the top? well, if you're an &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-anti-malware-anti-virus.html"&gt;anti-virus&lt;/a&gt; company it stands to reason you get there through technical excellence (yes, i can hear you snickering from here). of course if you have technical excellence then it also stands to reason that your people know what it is they're talking about when they go and say something about &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-malware.html"&gt;malware&lt;/a&gt; in public.&lt;br /&gt;&lt;br /&gt;specifically, what i and many other people expect is that people working for the #1 anti-virus company to at the very least know the difference between &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-virus.html"&gt;viral&lt;/a&gt; and non-viral malware. those kinds of basics seem like they should be prerequisites for achieving technical excellence in the anti-virus industry.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.symantec.com/connect/node/1618951"&gt;apparently that is expecting too much&lt;/a&gt;, since some people (in the industry, no less) are still using the term 'virus' as the umbrella term instead of the more accurate term 'malware'. i'm not sure exactly when it happened, but at some point i started hearing more terminology misuse from media sources within the industry than i hear from general media sources in the world at large.&lt;br /&gt;&lt;br /&gt;to say that cancels out any willingness i might have had to suspend disbelief about the question of technical excellence is an understatement.&lt;br /&gt;&lt;br /&gt;now one explanation i could entertain is that this is actually part of a very clever plot to keep the public confused and disoriented. governments long ago figured out that it was easier to control their subjects if they kept them stupid and uneducated. it doesn't seem unreasonable to suppose that corporations might make use of similar tactics. the foundation upon which greater understanding and ultimately greater self-reliance is built on is an accurate and consistent body of knowledge about the topic at hand. authoritatively using terms where they don't belong unquestionably undermines the process of developing that body of knowledge. it is precisely the type of tactic i would expect if corporations were trying to keep the masses easily manipulated.&lt;br /&gt;&lt;br /&gt;that being said, i'm still prone to give the benefit of the doubt. never attribute to malice that which can easily be explained by incompetence. of course, since that reflects poorly on the possibility of technical excellence, that still leaves open the question of how one can get to the top and stay there.&lt;br /&gt;&lt;br /&gt;without technical excellence being the driving force to keep the top players on top, we eliminate the possibility that the system is a meritocracy - or at least if there is a meritocracy, it's not the merits of the technology that are important but rather the merits of the efforts to manipulate people into thinking their technology has the most merit. that's called marketing. in essence, it's the best manipulator, not the best technology, that wins.&lt;br /&gt;&lt;br /&gt;(though a system that rewards manipulation seems like it should eventually evolve into one that actively tries to keep people stupid in order to manipulate them more easily)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-7490742187485430479?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=_83AZHuGJkk:MCgGmHN69u8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=_83AZHuGJkk:MCgGmHN69u8:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=_83AZHuGJkk:MCgGmHN69u8:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=_83AZHuGJkk:MCgGmHN69u8:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/_83AZHuGJkk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/7490742187485430479/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=7490742187485430479" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/7490742187485430479" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/7490742187485430479" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/_83AZHuGJkk/how-do-you-get-to-top.html" title="how do you get to the top?" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/01/how-do-you-get-to-top.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-7347279.post-723076572448768323</id><published>2011-01-03T18:45:00.014-05:00</published><updated>2011-01-03T18:45:00.449-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="prevention" /><title type="text">revisiting the 3 preventative paradigms</title><content type="html">i've been thinking about the 3 preventative paradigms lately [actually i found this languishing in my drafts pile since jan '09].&lt;br /&gt;&lt;br /&gt;&lt;b&gt;framing the 3 preventative paradigms&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;in the ideal case:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;a &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-blacklist.html"&gt;blacklist&lt;/a&gt; blocks access to a protected resource for things/actions that are bad&lt;/li&gt;&lt;li&gt;a &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-whitelist.html"&gt;whitelist&lt;/a&gt; blocks access to a protected resource for those things/actions that are not good&lt;/li&gt;&lt;li&gt;a &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-sandbox.html"&gt;sandbox&lt;/a&gt; blocks access to a protected resource unconditionally, offering a comparable low-value alternative resource as a surrogate&lt;/li&gt;&lt;/ol&gt;as you can see, this covers all conceivable options except the degenerate case of no prevention where access to the protected resource is not blocked under any circumstance (though realistically we can ignore this case when we're talking about prevention).&lt;br /&gt;&lt;br /&gt;&lt;b&gt;balancing the 3 preventative paradigms&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;the world is not an ideal place, however, and those cases cannot be implemented perfectly:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;the halting problem prevents us from implementing a perfect blacklist and limits us to only blocking things/actions that are known to be bad, thus leading to the so-called reactive nature of blacklists&lt;/li&gt;&lt;li&gt;while the halting problem does affect whitelists in the same way, whitelists actually benefit in a way from being limited to only known things/actions. however the generality of interpretation prevents us from implementing perfect whitelists (as the security world is bound to discover when whitelisting finally crosses the chasm) because we will only ever be able to apply &lt;a href="http://anti-virus-rants.blogspot.com/2008/02/what-is-application-whitelisting.html"&gt;application whitelisting&lt;/a&gt; to known &lt;a href="http://anti-virus-rants.blogspot.com/2006/01/what-is-program.html"&gt;program&lt;/a&gt; types and thus will have to &lt;b&gt;&lt;i&gt;react&lt;/i&gt;&lt;/b&gt; whenever we discover a new program type being abused.&lt;/li&gt;&lt;li&gt;while the generality of interpretation may make it difficult to know when a sandbox needs to be used, what prevents sandboxes from being perfect when they &lt;b&gt;are&lt;/b&gt; used (baring implementation failures that lead to unaided sandbox escape) is the need to share data (across the barrier erected by the sandbox) that is inherent to the division of labour, not to mention a variety of other useful and interesting things we do with computers.&lt;/li&gt;&lt;/ol&gt;thus with blacklists handling everything known to be bad, whitelists handling everything known to be good, and sandboxes handling everything in between, one might naively consider prevention to be a done deal; but with each one having problems that the others can't fully compensate for there will always be those edge cases that slip through and demonstrate that prevention is only the beginning of what a defender must consider. &lt;br /&gt;&lt;ol&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7347279-723076572448768323?l=anti-virus-rants.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=0sEmAdzxYlg:u4aDpRp2wmE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=0sEmAdzxYlg:u4aDpRp2wmE:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?i=0sEmAdzxYlg:u4aDpRp2wmE:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Anti-virusRants?a=0sEmAdzxYlg:u4aDpRp2wmE:bcOpcFrp8Mo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Anti-virusRants?d=bcOpcFrp8Mo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Anti-virusRants/~4/0sEmAdzxYlg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://anti-virus-rants.blogspot.com/feeds/723076572448768323/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7347279&amp;postID=723076572448768323" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/723076572448768323" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7347279/posts/default/723076572448768323" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Anti-virusRants/~3/0sEmAdzxYlg/revisiting-3-preventative-paradigms.html" title="revisiting the 3 preventative paradigms" /><author><name>kurt wismer</name><uri>http://www.blogger.com/profile/03810635947269551517</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="27" src="http://photos1.blogger.com/img/193/1227/1024/kurt.1.jpg" /></author><thr:total>3</thr:total><feedburner:origLink>http://anti-virus-rants.blogspot.com/2011/01/revisiting-3-preventative-paradigms.html</feedburner:origLink></entry></feed>

