Slashdot Mirror


McAfee Will Ignore FBI Spyware

Drew writes: "The Washington Post is reporting on the FBI's new spyware called 'Magic Lantern.' According to their article, 'At least one antivirus software company, McAfee Corp., contacted the FBI on Wednesday to ensure its software wouldn't inadvertently detect the bureau's snooping software and alert a criminal suspect.' It is ridiculous that the software companies that are supposed to help us protect computers purposefully leave in loopholes for the FBI to operate their spyware."

7 of 571 comments (clear)

  1. Re:Fucking Great by DragonMagic · · Score: 3, Interesting

    I stopped bothering with virus software, mainly because its problems and prices and maintenance outweighed its benefits.

    Best thing: Download software from trusted companies and entities only, make backups of your registry and boot drive often, don't open attachments in email from those you don't fully trust not to carry viruses, and keep up to date on what new viruses are out there and how they operate.

    This doesn't affect me much. Just wish we knew how the FBI's virus would work so it could be stopped at the router or mail server level.

    --

    Human nature is the same everywhere; the modes only are different. -- Earl of Chesterfield
  2. Evidence of Cluelessness at Every Level by werdna · · Score: 3, Interesting

    There is no doubt that Macafee's mindless show of patriotism invites a new breed of free-to-do-as-they-will virii from everyone, including terrorists -- merely by attempting to appear to be the Golden Lantern.

    But moreover, it shows an economic cluelessness, inviting competitors to provide a service they do not. Even worse, it is one thing to sell a "here's some filters, we're trying to keep the buggers out," program, but another thing entirely to sell one KNOWING that it will permit viruses to go undetected. That additional scientermight even invite litigation from companies injured by their recklessness.

    In short, it is amazing what a little jingoism can do to get people to lose their minds.

  3. I'm going to vote with my dollars.... by Lawmeister · · Score: 5, Interesting

    and not purchase, nor recommend to anybody including my employer (2000+ PCs) McAfee's products. Or any other product that doesn't jive with what I want it to do.

    Will be interesting to see what the marketplace thinks of this move when their stocks start trading again on Monday.

    F-Prot isn't based in the States, and maybe they will provide the protection users want.

  4. How long will it be... by Greyfox · · Score: 3, Interesting
    Before the Mafia moves to Linux, FreeBSD or one of the commercial unices out there? I mean, come on, those guys aren't stupid. If you are in their industry, you don't tend to live long.

    You can lock a UNIX box down tighter than a virgin whore if you know what you're doing. And with the current IT job shortage, I bet Don Parcheesi can find a pet UNIX geek or three dirt cheap. Or some trustworthy ones for a bit more.

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

  5. Re:Magic Lantern benefits crackers! by hearingaid · · Score: 3, Interesting
    If McAfee is operates only on signatures, then obviously there is no need to impersonate Magic Lantern to evade it: any original code (that doesn't match existing signatures) will do.

    Correct. This is one of the major problems with virus scanners, they tend to be vulnerable to The New Virus.

    And since any code that does something more than Magic Lantern must necessarily be different from Magic Lantern, McAfee can write a signature for it after it's discovered. So, against signature-based defenses, impersonating Magic Lantern buys you exactly nothing. Is there anything I'm missing here?

    Yes. McAfee calculates the signature from the code. Presumably, the way it works around Magic Lantern is by some code that looks like this:

    if virusSignature == magicLantern then return(1);

    else doCleanVirus();

    Therefore, if an enterprising virus writer can synthesize a virus that does something different, but causes McAfee to detect the same signature, it's happycakes time.

    That said, McAfee has always sucked donkey donuts. Norton is better; however, the only PC-based antivirus product I ever really had a lot of respect for was IBM AntiVirus, partly because it was the only one that could detect virii it didn't already know about. Sigh. It's long gone though.

    --

    my old sig used to be funny, but then slashcode ate it and now it's not funny anymore

  6. Multiple abuses of Magic Lantern.(Long) by supabeast! · · Score: 3, Interesting

    Easy way to abuse the FBI's new Magic Lantern "virus."

    Do illegal stuff online, and be conspicuous about it. If you are already involved in organized crime, this will be easy. Do all your stuff using PGP on a Windows 2000 base install. Regularly talk on the phone to your buddies about those idiot FBI agents who can't read your encrypted email. Make sure to do everything with LCD montitors so that the FBI has to crack the email instead of just tapping your CRT. Get a geek to learn a lot about virus operation so that he can regularly check the system and snag the virus.

    As soon as the virus pops up, keep playing along. Send out encrypted crap messages that make no sense, and appear to be written in code words so that the FBI spends more time trying to crack THAT code after cracking the message. At the same time, decompile the virus and figure out how it works. Alter the virus to be self-propigating and extremely malicious, destroying all filesystems on infected machines and shutting them down while residing only in memory to prevent people from finding the virus on disk.

    After a few days, set up an online store selling anti-virus software at $19.95 a seat licensing. Encrypt everything the program contains with the exception of an executable, so that no other virus company can figure out how it works without violating the DMCA.

    Laugh at the FBI agents who are too busy trying to figure out what all your code words are to notice you raking in millions with a foreign company selling anti-virus software, move to Zug, and retire.

    I admit, that scenario is a bit of a stretch. A more likely scheme (And what will likely happen very soon.) is a few good crackers decompile antivirus software from McAffee and Norton, both American companies that will allow the FBI virus through, and compare it with antivirus software from foreign firms, which will likely block the FBI virus to prevent the USA from spying on their companies as the USA does with echelon. Bingo, killer virus in no time flat, watch it take the world by storm. And before any of you bother to post about how the FBI will manage to keep all the details secret so that this doesn't happen, think about this; if the FBI could manage to keep a secret, we would not know about things like Magic Lantern and Carnivore to begin with.

    I want to thank the FBI for fucking over America with their inability to realize the dire consequences of their poorly-planned actions. By doing this the FBI is screwing over:
    1- All of the companies around the world, especially in the US, that will spend a ton of money dealing with the downtime caused by the first virus to exploit the Magic Lantern backdoors.
    2- All of the American antivirus software companies who will lose market share to foreign software companies who do not leave FBI backdoors in their products.
    3- Microsoft, who will likely be accused of leaving FBI backdoors in Windows, and who will lose market share when a virus sweeps the Windows world on a level that shames Code Red I and II.
    4- All the Windows admins out there who will now have to rebuild all of their compromised machines, and switch to antivirus software by companies that do not leave backdoors for the FBI.

  7. Remember the Constitution! by ZosX · · Score: 4, Interesting

    Do our constitutional rights even exist anymore?

    Owning a weapon is a priviledge, let alone owning a weapon and carrying it on your person. "The right to bear arms." You need specific reason now to carry a concealed weapon, why is that? I'm an american citizen, if I want to carry a .45 in my pocket, the constitution says I can, the government tells me I'm breaking the law......

    Sorry using an example of the breakdown of our constitutional rights.

    This really disturbs me. Between Carnivore and now Magic Lantern, we have pretty much given up all rights to privacy on the internet. I know that most of you will say that its been likely that the government has been monitoring traffic for some time anyways secretly, now we are publically accepting this as "ok in the name of our safety." Don't think they monitor your cell phone calls? Explain how they got voice recordings of the conversations of the doomed flight to Sommerset, PA.

    This is disgusting. We are just handing over our freedom and very few people are saying a word. Funny how not all that long ago, the Supreme court ruled that aquiring search warrants based upon thermal readings from a house was illegal and yet they haven't said a word about anything the FBI has been doing.

    Its really fscking sad that the alleged "war on terrorism" is really just a lame excuse to quickly remove a good deal of our rights. People in New York City are being searched randomly in Manhattan. What the hell is that? In 10 years can I expected to be searched if I walk down my street? If I have something illegal, is the search unreasonable, or does the court care more about me just having something illegal? If our phones and computers are tapped (lets assume for the moment that they are for the most part) where does the government stop? They can see what I am writing and talking about....why shouldn't they be allowed to see what I am doing in my home without a search warrant? The best part of it is, nobody would even know if they were being watched. I know this has been something people have complained about over the years (as the government has slowly crept into their privacy), but now its really in our faces. 1984 is not very far away indeed.

    Let's take Magic Lantern for instance. If one were to disassemble it, it would violate the DMCA ruling. If one were to circumvent it (which likely anyone in their right mind will), the techniques used would likely violate DMCA. (Remember Skylarov?.....)
    Can anyone think of software they might use that might possibly violate the DMCA ruling? I can think of a few, and I am not talking about cracking software. Also this makes me wonder about Windows....does DMCA make WINE illegal?

    Indeed, the whole issue is a lot like a runaway train coming down the hill. People see it from the distance and don't realize how dire their situation is and eventually the train comes pummeling down into their sleepy little town and destroys it. I wonder how long before we lose all faith in the government entirely. Too bad we decided that we are too weak and lazy to take the government back into our own hands. What's so sad is that the more disillusioned we become with our government the more likely we will feel that it is out of our control. Judging by the recent elections and the completely disgusting turnout, it seems we are just about there. What do we do in 10 years when we don't even have enough voters voting to elect an official?

    Its really time to either:

    A) Do something about the slippery path we have slid on

    or

    B) Walk away from it, buy a huge ranch/estate/tract of land, start a community of like minded individuals, and ignore what the government does. I suggest some western states that do not tax their land so you can totally live government free. :)

    Just some random infuriating thoughts I've had lately.....

    Zos/Xavius.23
    zos[@]winwood.net

    Art is the realization of truth - AOS