McAfee Will Ignore FBI Spyware
Drew writes: "The Washington Post is reporting on the FBI's new spyware called 'Magic Lantern.' According to their article, 'At least one antivirus software company, McAfee Corp., contacted the FBI on Wednesday to ensure its software wouldn't inadvertently detect the bureau's snooping software and alert a criminal suspect.' It is ridiculous that the software companies that are supposed to help us protect computers purposefully leave in loopholes for the FBI to operate their spyware."
So I guess for linux users, the email would probably look like the following:
Dear Sir or Madam,
Please make sure you are root when you execute this file.
Thanks,
The FBI
"McAfee Will Ignore FBI Spyware"
They've been ignoring viruses for years. Why change now?
;)
Knunov
Why do users with IDs under 100,000 or over 700,000 usually have the most worthwhile comments?
This is Microsoft's wet dream... If the holes the FBI uses are unique, then the holes will be classified to protect the FBIs ability to monitor terrorists (therefore protecting national security). That means, they will have the ability to stop security exploits from being published in the interests of national security.
int func(int a);
func((b += 3, b));
I end up relying not only on you, but on the people you claim to be trusted. This is remarkably similar to trusting physically promiscuous people to not carry something transmittable to me. Yeah, and unlike in sex, in software, monogamy really isn't a feasible option (unless you believe Microsoft.)
Of course McAffee et al wanted a signature for the thing, and this was the best way to formulate the question. Besides, now they can produce a spevif Lantern-detector, and sell under the counter for a high price - and sell the names of the buyers to FBI. Ah the beauty of the free market...
In Murphy We Turst
I understand everyone's concerns about crackers exploiting the spyware to gain entry into their systems. I think this could be easily solved by the FBI providing free, convenient upgrades to the spyware product in the event that vulnerabilities are discovered.
It would also be nice if we were notified by email whenever a patch was available.