Slashdot Mirror


Schmidt Predicts Digital Sky Is Falling

Danse writes "Former Microsoft security chief Howard Schmidt now works for the government as the vice chairman of the Critical Infrastructure Protection Board. According to this article on Security Focus, he has been touring the country, proclaiming the dangers of "zero-day viruses" and "affinity worms" that will create the kind of havoc that nothing else short of a nuclear exchange could cause. "Traffic lights, pacemakers, appliances -- all subject to outages and interruptions because in the future they're controlled via Internet, declares Schmidt. The power grid could fail catastrophically by 2005!" How do you argue with this kind of rhetoric, especially when it's being spread directly by government officials to corporate leaders?"

10 of 506 comments (clear)

  1. But.. by iONiUM · · Score: 4, Insightful

    Traffic lights, pacemakers, appliances -- all subject to outages and interruptions because in the future they're controlled via Internet

    Why would these things be controlled via the internet? We already segregate certain high security systems from the internet to avoid even the chance of them being "hacked". I don't think a pacemaker would -EVER- be hooked up to the internet -- not only is there no point, but it's just extra risk for something to go wrong.

    On the note about how to stop the rhetoric, it's simple. We need people who are educated in technology to report to the government with the TRUTH, not these fictional facts being spread to merely cause a slight fear which will (in all likely hood) raise the sales in the technology industry to "buy more secure products".

  2. Re:It's an ex Microsoft security chief... by gclef · · Score: 4, Insightful

    Well, as the article points out, what's interesting is the change of tone. While he was a Microsoftie, he was downplaying the impact of viruses & worms.

    Now that he's in the government, these things are apparently more important.

    The change of perspective and its timing is....interesting.

  3. Y2K by RobPiano · · Score: 5, Insightful

    Part of the reason Y2K happened nearly hitchless was due to the fact that so much hype was involved. By declaring "the sky is falling" they are preventing a problem through means of hype. However, this man is a microsoft ex-employee and I'll be quick to point out that most viruses and worms are not "computer" viruses specifically but *windows* viruses. By making a fuss he is trying to protect his "alma mater" as it were.

    It looks like some big goverment, "I pat your back, you pat mine" business.

    Rob

  4. I blame bad science fiction by Dark+Paladin · · Score: 5, Insightful

    And while there's some tongue in cheek in this, I really think that 90% of the reason why FUD like this is out there is because of what people see on TV/Movies.

    Law and order depicts "worm" that "takes control of your computer just be recieving an email!". Hackers: teenagers in bad oufits can crack into any system in the world (including being able to hack into a system by using phone lines taped together). Speed 2: leech loving man takes over a boat from his room with "fiber optic converter" (actually a data com port switch, I believe). The Net (another Sandra Bullock film) has a woman who's whole identity can be erased (especially when the FBI, Pentagon, and everybody else use the same anti-hacking software, which incredibly is used by evil hacker types).

    In movies, anything (microwave, blender, vacuum, whatever) can be controlled by evil computer programs. Don't ever put your computer in charge of your house, or else it will develop artificial intelligence, and try to kill you by making electric cords whip around your neck (I never figured out how that worked).

    Joe Public has no idea of how technology works - to him, it's indistinguishable from magic, so why couldn't it work? So when a man stands up and tells people a virus can circle the world 0 seconds, those who pray to the gods of technology in the hopes that their television doesn't turn off must believe.

    We don't believe in monsters or demons, so we invent them in the form of hackers and superintelligent teenagers with a vengeance. We don't believe in gods, so we invent them in a government that knows all, sees all (when it's own FBI is 10 years behind the technology curve).

    Good god, but I hate human ignorance.

  5. Re:It's an ex Microsoft security chief... by FreeUser · · Score: 5, Insightful

    Well, as the article points out, what's interesting is the change of tone. While he was a Microsoftie, he was downplaying the impact of viruses & worms.

    Now that he's in the government, these things are apparently more important.


    Hmm. I wouldn't be too certain there isn't a Microsoft agenda behind this ('Once you work for [ the CIA | Microsoft ], you always work for [ the CIA | Microsoft ]').

    With our elected leaders deep within Hollywood's pockets, and the confluence of Microsoft's Palladium agenda to extend and encode their software monopoly into the hardware itself with the media cartels' Digital Rights Management agenda, this is exactly the kind of rhetoric I would expect from someone pusing either, or both, of those agendas.

    The Digital Sky is falling, but not because of any foreign terrorists or script kiddiez. It is falling because several powerful cartels, a software monopolist, and our government are joining forces to eradicate the free wheeling internet as we know it in order to replace it with a medium they can better control, something that will resemble Just Another Media Outlet far more than it will the internet as we know it today.

    If this steamroller isn't stopped it will be the end of Free Software, the end of the peer-to-peer nature that is inherent in the design of today's internet, and the end to free exchange of information via digital media. In short, it will be the end of freedom as we have come to know it.

    And you know what. By the time anyone notices, much less cares, it will be far too late. We are the most affected here on /., and even we cannot be bothered to get off our asses and become politically involved. How can we expect those whose livlihoods are less directly affected to cast aside their apathy and conditioned reluctance to get actively involved when we can't be bothered to do it ourselves?

    The change of perspective and its timing is....interesting.

    You said it! Interesting ... and profoundly depressing.

    --
    The Future of Human Evolution: Autonomy
  6. Re:It's an ex Microsoft security chief... by BWJones · · Score: 5, Insightful

    Exactly. But what I think you are missing is some of the other potential conflicts of interest that still might remain with George Schmidt. Does he own Microsoft stock? With this new FUD tone and Microsoft's new focus on security, is he trying to drum up new business for the company thus boosting their stock price/performance?

    --
    Visit Jonesblog and say hello.
  7. Re:Pacemaker... by colmore · · Score: 4, Insightful

    Anyone who engineers anything as critical as the controls to a pacemaker or a traffic light to be remotely configurable or writable is just asking for trouble.

    Just because something has an IP adress and can be remotely monitored, does not mean that it needs to have ANY remote access to any functionality that could cause a problem.

    Yes, we can (and will) design things stupidly enough so that this will be a problem, but that's more our fault than anything else. Like leaving your car unlocked with the keys in the ignition at 3 AM downtown. It's just not smart.

    Now the more serious issue here, though, is that an uninformed government employee is scaremongering for power. Nothing new. But with the stock market doing as it is (buy at 6000, I say) this kind of talk is doing direct harm to the country.

    This guy needs to shut the hell up.

    --
    In Capitalist America, bank robs you!
  8. Re:I didn't know all IP = Internet by mborland · · Score: 5, Insightful
    While I could imagine a worm moving through the internet fairly quickly, I can't imagine it doing too much serious harm. I mean, nothing could be much more serious that code red or Melissa or something.

    I think I agree with your general points, but actually the worms could have been a lot worse. Had Code Red, for example, performed destructive actions on the target servers, it would have been an absolute disaster, and everyone would have remembered The Day Code Red Hit. As it was, most people disabled the exploited feature or applied hotfixes, and were back on their feet again.

    Imagine if it had just deleted the boot.ini, and/or perhaps several megabytes of critical files (critical enough to fail on reboot but not to halt current operation)? It would continue to scan, and if the admin rebooted (that is the first line of defense, after all!) they would be hosed. Perhaps it would actually be worse to delete the 'non-standard' files, like user files...destroying web sites and forcing admins to go to back ups (Windows admins do keep backups, don't they?). Imagine 300,000 boxes being hosed within a short period!

    Be fearless, build firewalls, and update your software, and ignore this moron

    Amen!

  9. Re:Not bloody Likely by rnturn · · Score: 4, Insightful
    ``When nimbda came out it was windows boxes. This did not effect apache/*nix boxen.''

    While Apache servers didn't get rooted by Nimbda, or by its cousin Code Red, they were still affected. Of course, it was more of a DOS attack since the Apache daemons were attempting to respond to the bogus requests but it was an attack nonetheless. I've seen the load shoot through the roof on Apache servers the had been targeted by nimbda/code-red infected system. I should note that this was a strange case where someone fired up an NT system (for testing) that they were unaware had become infected and both systems were inside a firewall. Makes a good case for having another layer of firewalls (and, perhaps, an IDS) inside the LAN just to protect your servers from goofy situations like this.

    --
    CUR ALLOC 20195.....5804M
  10. You overly deride people by SuperKendall · · Score: 4, Insightful

    Oh really? "Sheeple" want fridges that print out grocerly lists? Fuuny, I don't remember any of the "Sheeple" I've talked to wanting those things. Where did I hear about stuff like that... oh yeah, it was here on /.!! Seems like either Microsoft or people here would want stuff like that, but people who are happy watching a 20" TV with mono sound are unlikely to want such things.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley