Slashdot Mirror


Spafford On Infrastructure Risks

nealmcb writes "In a major report from the AAAS, Eugene Spafford, director of CERIAS, summarizes the many risks to our information infrastructure (viruses, bugs, single points of failure, etc.), their causes (explosive growth, primacy of time-to-market over quality, lack of support for basic information security research, etc.), and the negative effects of the DMCA, CBDTPA, and other corporate maneuvers."

85 comments

  1. My Favorite... by Speedy8 · · Score: 2, Interesting

    My favorite are all of the P2P programs that people run that can be auto updated. Imagine the havoc that can be created with control of 1,000,000 computers with fast internet connections.

    1. Re:My Favorite... by DraconPern · · Score: 1

      You mean by combining this and this?

  2. Diversity by Anonymous Coward · · Score: 3, Funny

    How am I supposed to download my Windows ME patch if as soon as I connect with a fresh install I get infected? Microsoft should include a rescue CD that runs Linux.

    1. Re:Diversity by unoengborg · · Score: 1

      Actually there are people doing this.
      I read about it a couple of years ago.
      It was a university that provided a rescue
      diskette that booted Linux. The Linux installation
      then automagically made downloaded and installed
      windows on the hard drive.

      Sorry I can't remember what university it was
      but I think it was somewhere in South America.

      --
      God is REAL! Unless explicitly declared INTEGER
  3. This just in... by captain_craptacular · · Score: 4, Funny

    A report from the AASWEDW discussing IISDCED and UPDESCTG interrelation issues with OPWSEDSC and NMEDSE, along with EWSDICE or WEDGCDSE legislation. Film at 11.

    --
    They who would give up an essential liberty for temporary security, deserve neither liberty nor security
    1. Re:This just in... by TyZone · · Score: 1, Funny
      A report from the AASWEDW discussing IISDCED and UPDESCTG interrelation issues with OPWSEDSC and NMEDSE, along with EWSDICE or WEDGCDSE legislation. Film at 11.

      WTF?

      --
      TyZone
    2. Re:This just in... by 56ker · · Score: 0, Offtopic

      Thank God for the film at 11 - it'll give me a chance to clear my headache.

    3. Re:This just in... by Izanagi · · Score: 1

      And to think I had to go and waste all my mod points on trivial things like Micro$oft.

      --
      SCO (noun.)- A Slimy Corporate Ogre. Often seeks free money.
  4. Scientists out of touch with the economy. by DraconPern · · Score: 2, Insightful

    This comment made me think twice about how important they think security is: "After all, disruption of eBay, Amazon, Google, or online chat groups does not seem like much of a menace." -- Eugene H. Spaffor A major security breach at eBay or Amazon will surely result in millions of dollars of lost transactions and loss of investor confidence. How is that not a menace? One can argue that the US economy is more important than security because it has an global effect. And without google, most websites won't even need security. We just slashdot them until they are unavailable. :)

    1. Re:Scientists out of touch with the economy. by Anonymous Coward · · Score: 1, Insightful

      Problems with Amazon or eBay are not likely to bring people to question their faith in the US economy. Now, if one problem affected all of them more or less equally, then that would be one sector of the economy, and people would question that sector, but not the whole economy. Notice it has taken more than a few corporate bad apples and misdeeds being smoked out to bring the market into a complete funk, not one or two.

    2. Re:Scientists out of touch with the economy. by Zeinfeld · · Score: 3, Insightful
      Spaff is pretty well known in the Internet, but I am affraid I can't think of a major contribution to computer security from him since tripwire.

      Incidentally, it is somewhat disappointing that he puts out the comparisons of Windows vs Unix viruses as 'proof' that UNIX is more secure without addressing the specific features of UNIX that would make it so. It is one thing for a slashdotter to assert 'unix is more secure than windows', a university professor specialising in computer security should be able to do more than recite opinions, he should be able to explain why and how one system is more secure than another. The systemic lack of security argument does not work by the way since UNIX is the only mainstream operating system that did not originally have a security model. All the security features in modern UNIX are retrofitted - in some cases (shaddow passwords) in the face of opposition from UNIX purists.

      The principal reason why Macs, Ataris and MSDOS machines all had chronic virus problems is that they have no account based security controls. A rogue program can corrupt any system file it likes. A secondary reason is that in their original incarnation every one of the machines has supported the clueless operating mode of try to boot from removable media. The only difference since then is that the Internet has proven a far more effective vector for malicious programs than floppy disks and the clueless enabling vector has been run from email.

      He conveniently ignores fact that there are Virus building toolkits written for Windows and the vast majority of the 'dozens of new viruses a week' are no more than minor variations on the same basic cores. Nor does he tie this back to his initial theme of an O/S monoculture which is somewhat odd because the main reason why there are epidemics of Windows viruses is simply the fact that the population of Windows machines is large enough to support epidemics. For a virus to become an epidemic all that is required is for each infected host to pass on the infection to an average of more than one new host. There are two reasons an infected Linux box is less likely to do this, first 90% of the hosts an infected linux box attempts to infect are likely to be Windows boxes imune from a linux virus. Second the remaining 10% of linux boxes are likely to be considerably more heterogeneous that the average windows machine. There are likely to be a large number of different builds and even different processors, all in all a much harder target to infect.

      The heterogeneous platform argument is unfortunately one of those arguments that works fine on the individual level and fails entirely at the public policy level. The problem being that it may be logical for me to use an obscure operating system to reduce the risk of virus (or other attack) but if everyone chooses the same O/S the obscurity advantage is lost. Incidentally Linux is far too mainstream for the obscurity argument to apply, if you want to be obscure you would have to use something like the Genera (Lisp machine) system we got the Clinton administration to use to do their press release publications onto the Internet from. (The machine was not choosen for security through obscurity, however we did remark afterwards that if the machine was ever compromised we could probably write the list of suspects with the expertise to crack it for the Secret Service)

      --
      Looking for an Information Security student project suggestion?
      Try http://dotcrimeManifesto.com/
    3. Re:Scientists out of touch with the economy. by plcurechax · · Score: 2
      Spaff is pretty well known in the Internet, but I am affraid I can't think of a major contribution to computer security from him since tripwire.
      You mean other than his books (Practical UNIX and Internet Security, Web Security, Privacy and Commerce, Computer Crime: A Crime-Fighters Handbook (contrib ed.)), being the director of CERIAS and founder of Purdue CERT, chainmen of ACM U.S. Policy Committee, advisory board member of Tripwire Inc, and the winner of umpteen awards in computer security and computer science.
    4. Re:Scientists out of touch with the economy. by Anonymous Coward · · Score: 0

      You seem to have quite an inferiority complex.

      Do you possess a deep-seated desire to be noticed? Are you unpopular with women?

      It must be said, you very much remind me of Mr. Pig from this story. All blow and bluster. You want to be very sure that everybody around you knows how very important you are.

      One day, you are going to die. Will you die a decent human being? Or just a self-important prick?

      Think it over.

  5. How often do we see Windows viruses again? by BoVLB · · Score: 3, Interesting

    On page 2 he says:

    Currently we are seeing new computer viruses and worms, targetted at [Windows], reported approximately once every 75-90 minutes on average.

    which implies over a hundred per week, but on page 9 he says:

    [T]he Microsoft family of software has tens of thousands of known viruses, and new ones are being reported at the rate of dozens per week.

    which sounds somewhat lower. Which is it?

    Either way, it's a pretty horrific number.

    1. Re:How often do we see Windows viruses again? by happyclam · · Score: 2

      ... uh... at one every 75 minutes, that works out to 11.2 dozens a week. Sounds OK to me.

      (I mean the use of the term "dozens," not the fact that there's a new Windows virus introduced every 75 minutes.)

      --
      He looked at me and said, "Kid, we don't like your kind, and we're gonna send your fingerprints off to Washington."
    2. Re:How often do we see Windows viruses again? by Anonymous Coward · · Score: 0

      The first statement is likely including the re-release of older viruses. Either that, or multiple people are reporting the same "new virus", and no attempt to weed out duplicate reports.

  6. Well written, but I have some quibbles by Beryllium+Sphere(tm) · · Score: 5, Interesting

    One problem is not so much lack of basic research as it is lack of a "literature" to search. It's routine for someone to present some time-consuming research at a security conference only to have the Q&A consist of "did you know that's been done already?"

    Also, we don't know how much research is being done behind closed doors. The NSA has a lot of bright people and is big enough to do basic research *if* they choose. Their mission does include infrastructure protection.

    Spafford's comments about the pressure of time to market were on target. Bruce Schneier spoke at Microsoft once. An employee asked him what MS could do to make secure products. Schneier's response was, simply, that Microsoft shouldn't -- that security is expensive, slows development, and won't result in more sales. That last may have changed by now.

    For perspective, some of the government's cyberwarfare investigators have said that any hostile power's virus attack would get lost in the noise of daily blue screens, system "upgrades" and random viruses. On the offensive side, they recommend that if you want to stop a computer from working you should use an OS-independent attack from an F-18. Such an attack can't be fixed by downloading a patch.

    1. Re:Well written, but I have some quibbles by Anonymous Coward · · Score: 0

      i sure hope you were trolling.

      Bruce would NEVER say something like that. For him to say MS shouldnt do security and then criticize them to the degree he does makes your claim flat out fabricated.

    2. Re:Well written, but I have some quibbles by Beryllium+Sphere(tm) · · Score: 1

      I was in the audience.

      Were you? Do you remember it differently? If so please post your best recollection instead of calling me a liar.

      I was a bit startled myself. I believe he was calling attention to the difference in requirements between feature-rich, flexible, powerful commercial software and small, simple, easy-to-analyze "secure" systems.

      You may want to read "Secret and Lies", in which Bruce Schneier argues that computer security is like meatspace security -- uneconomical or impossible to do at 100%, but possible to do well enough to buy insurance.

    3. Re:Well written, but I have some quibbles by Zeinfeld · · Score: 2
      You may want to read "Secret and Lies", in which Bruce Schneier argues that computer security is like meatspace security -- uneconomical or impossible to do at 100%, but possible to do well enough to buy insurance.

      That particular idea did not start with Bruce. It has been taught in computer security 101 for twenty plus years.

      If as he claims in the intro Bruce only just realised that security is risk control not risk elimination then he owes me a credit, I had a long discussion with him on that point at RSA the year before the book came out.

      The real explanation is that Bruce's interests have changed over the past ten or so years. When he wrote Applied Cryptography he was pretty much a specialist coder of crypto software, then after AP#1 he got deeper and deeper into cryptography and started proposing his own designs, mainly in the symmetric algorithm space. The point is that in that part of the security world you really can provide pretty much absolute guarantees for certain security risks.

      Since then he has pretty much moved from being a pure crypto specialist to being a computer security guru. Even so he does have something of a reputation of firing off attacks on the insecurity of systems without understanding the risks they are trying to mitigate.

      A key case in point there being his attack on the security of IPSEC. Now whatever you think about Bruce, Steve Bellovin and Jeff Schiller are by any analysis his equal technically. Whatever reputation Bruce has with the general public, Steve and Jeff have a rather higher one within the IETF.

      So yes statement to Microsoft is very much in character for Bruce, yes Bruce has an awfully high reputation, but no don't consider his word as gospel.

      --
      Looking for an Information Security student project suggestion?
      Try http://dotcrimeManifesto.com/
  7. Lord. Protect me from academics. by bons · · Score: 3, Interesting
    If anyone wants a clear understand of the disconnection between academia and the real world, feel free to download this pdf and stare in horror at Chapter 1. I don't think I can make it to chapter 2 at this point.

    So far I've read a poem that, while interesting, a quick search on google shows that the person who presented it is also the translator. Right. Can someone please find the original so we can verify this for ourselves? Thank you.

    I've seen police, fire fighters, and medical personnel compared with researchers in the social science and humanities. I've seen proposals for information to be on a "need to know" basis, with the only people who "need to know" being the government and (of course) researchers. I love it when someone welcomes a loss of freedom provided it doesn't include them.

    If you want some good music to listen to this to, I reccomend Love Me, I'm a Liberal by Phil Ochs unless you're too young, in which case you might as well listen to the Jello Biafra version

    1. Re:Lord. Protect me from academics. by chefmonkey · · Score: 4, Informative

      For those of you that find PDF a Pain In The Ass, you can grab an HTML version of this chapter from here.

    2. Re:Lord. Protect me from academics. by chefmonkey · · Score: 2, Informative
      Can someone please find the original so we can verify this for ourselves?

      Yep, it's a load of horsehockey.

      The passage he's trying to cite, I beleive, is from an essay Louis Aragon wrote in La Révolution surréaliste, n 4 (published in 1925):

      "Que les trafiquants de drogue se jettent sur nos pays terrifiés. Que l'Amérique au loin croule de ses buildings blancs."

      I'd translate this more as "That the drug traffickers throw themselves on our terrified countries. That far away, America's white buildings collapse."

      I wouldn't even interpret the first sentence as relating to America, since Aragon clearly considered America to be quite distant from himself and, consequently, any countries he would feel compelled to call "our."

      Using such a questionable quote without checking sources was extremely irresponsible on the part of Dr. Greenwood. On the other hand, Wlad Godzich should be summarily dismissed from his position at UC Santa Cruz for such academic dishonesty as daring to translate the same phrase as "The time will come, America,/When the hordes of Afghanistan/Will crash your gleaming airplanes/Into the shiny towers of Manhattan."

    3. Re:Lord. Protect me from academics. by diablovision · · Score: 1

      Uh....Spafford's name isn't even in that link.

      --
      120 characters isn't enough to explain it.
    4. Re:Lord. Protect me from academics. by zoydoid · · Score: 1

      c'mon. it's not that far off... drug traffickers -> afghanistan, i mean afghanistan is the heroin exporting capital of the world.

  8. information disclosure by reverse+flow+reactor · · Score: 1

    all that information about the infrastructure weaknesses - I guess he did not get the memo about hush on the disclosure of information. After all, if noone knows or talks about the problem, then it goes away, right? ---

    --

    The significant problems we face cannot be solved by the same level of thinking that created them. -Einstein

  9. Re:Insanely Great!!! by Anonymous Coward · · Score: 0

    Err... shouldn't that read "eighty-seven Macintosh buyers per week" instead of "millions," har, har, har?

  10. Long Ramble Time (tm) by CajunArson · · Score: 4, Insightful

    OK, as a recent Purdue Grad (Spafford heads CERIAS at Purdue) and as someone who is going into security research for a Masters degree.... I'm going to shoot my mouth off!!

    Spafford's article is somewhat of a hit & miss. I'm going to paraphrase a few sections that IMHO are good, and some that are not so good.

    The Good:
    -- UCITA: ~"This legislation will ban research into security issues with software products and even outlaw criticism of software design"~ I could'nt agree more, what kind of an idiotic company could possibly object to FREE DEBUGGING being done by University researchers, that could lead to drastically better software, instead of skipping beta, if I were a commercial developer I'd GIVE IT TO THE UNIVERSITY FIRST!! (As a rabid old-school capitalist I actually think the road to more $$$ is to put out a good product, unfortunately a bunch of short sighted schmucks thought they could cheat the system.... and look at their stocks...)

    -- The lack of research in security: yeah, Purdue churned out over 125 Seniors in Computer Engineering, and I'm the only one that I know who is doing grad work (or has a job) in security proper, and I'm only getting a Master's, so I won't help his PhD count, (not that a Master's isn't helpful, he wants to have people to take over for him when he retires).

    -- The lack of qualified people in Law Enforcement: Another *excellent* point, if we just had a competent core of cyber-crime investigators, a whole bunch of this BS about Carnivore wouldn't even be neccessary since they could do the proper investigatory work to get probable cause for warrants and nail the criminals while not violating the Constitution...
    (sometimes I think I'm the only one who wants to punish the criminals while simultaneously not punish the normal people...) The laws do need updates in some ways (NOT the DMCA), but warrants
    to look through e-mails and electronic corespondance should have clearly defined levels of evidence neccessary (just like today there are
    pretty well defined levels for searching your house).

    -- ~"That common system that runs commerce, defense, and much of the scientific establishment. It is under a constant barrage of viruses, worms, and hacker (he said hacker, not cracker BTW) attacks, this system which you use to browse the internet is also going to run an Aircraft carrier next year. What would we say if the US Airforce bought crop dusters since they are cheaper than F-16's?"~

    Another excellent point, but I don't see what he has against Linux since I use it every day!! :) OK, we all know he's attacking Windows, and he has an excellent point.... The aircraft carrier (My guess is it's the Truman or more likely the Reagan) has all kinds of reinforced bulkheads and compartments so that even if one part of the ship gets hit, the rest can keep on fighting! (here comes the analogy) So why the hell would you have one, integrated, incredibly vulnerable system running everything from a powerpoint presentation in the briefing rooms, to
    controlling the airplane elevators and ordance tracking system?? It's dangerous and completely uneccessary, I wouldn't even put Linux in charge of most of the sensitive systems, they have enough money to build custom systems (note that custom systems can still be modular and communicate with each other, they are just built to better tolerances in a restricted environment of a ship) You can run some isolated Windows boxes to do some word processing or Powerpoint slides, just don't give the ship a bluescreen!

    OK, now time for a few gripes (don't worry this list is shorter)

    -- ~"The traffic on the internet doubles every
    90 to 120 days" It looks like Spaff fell for the
    old WorldCom line too... :) He does use some hyperbole in this piece (if the worst case of everything he talks about actually happened the internet would already be fried, but he is trying to present his position trenchantly).

    -- ~"Only 12% of people in security research are women and minorities"~ OK, I could care less really, I DO discriminate... I only think the best & brightest should be doing this sort of thing, I don't care if you are a Purple-with-green-Polka dotted Female, just as long as you are the best, and I also don't care if you fill every quato imaginable, if you can't hack it, leave. He does raise a good point that too many of the security researchers aren't even from this country, but I think this means we should get more of America's best interested in security, and let the foreign exchange students learn too.

    OK, that's it, this is a topic near & dear to my heart so I just had to spout off, go ahead & flame away! :)

    --
    AntiFA: An abbreviation for Anti First Amendment.
    1. Re:Long Ramble Time (tm) by Anonymous Coward · · Score: 0

      heh, I'll be taking CS426 and 590 (Spaf usually teaches 426 and sits in 590(a seminar)) here in 2.5 weeks.

      >Purdue churned out over 125 Seniors in Computer Engineering

      wtf does CE have to do with security? ECE = basically a specialized EE major

      one more thing I should add as being a part of a government agency is seeing the complete _lack_ of security knowledge at the area or even the hq level -- I had to implement my own solution to get their crappy programs running safely without spending thousands of dollars on propreitary crap. //wolfmann

    2. Re:Long Ramble Time (tm) by CajunArson · · Score: 1

      Yeah, at Purdue at least we do everything the
      CS majors do and then some. I have done everything from transistor theory to distributed OS theory, and I've even implemented a VM from both the VLSI side in VHDL and the realspace VM
      in an OS kernel, you'd be suprised what they teach us.

      --
      AntiFA: An abbreviation for Anti First Amendment.
  11. i'll tell you what the single point of failure is by Anonymous Coward · · Score: 0

    take your picK:

    +Microsoft.
    +Government
    +Politics
    +Socialism
    +Liberals
    +National Education Association
    +Nation Endowment for the Arts
    +Medical system
    +

  12. Perpetuating the myth by Enigma2175 · · Score: 3, Informative
    From the article:
    The amount of traffic we see on the backbones of the networks has been doubling approximately every 90 to 120 days.

    I thought that myth had been debunked. It now has passed into the realm of the 'factoid'.

    --

    Enigma

  13. Therefore the proper SI standard unit is... by 2g3-598hX · · Score: 1

    ...tens of dozens ;)

  14. There Is Something Rotten in Software Engineering by Louis+Savain · · Score: 1, Flamebait

    There is something fundamentally wrong with the way we create software. The solution requires a fundamental change in the way we program our computers. Software suffers from a seminal problem. The primary reason that software is so unreliable and so hard to produce has to do with a custom that is as old as the computer: the practice of using the algorithm as the basis of software construction. Moving to a pure signal-based software model will result in at least an order of magnitude improvement in both reliability and productivity.

    There is something rotten at the heart of software engineering. We are using a software technology that was introduced one hundred and sixty years ago by Lady Ada Lovelace and Charles Babbage. This was at a time when the best performance they could hope for that speed demon of theirs--the analytical engine, too bad they never got it to work--was maybe fifty cycles per second at the most. Times have changed somewhat since then. More details can be found at the links below:

    Project COSA

  15. Jive talkin' by joshsnow · · Score: 0, Troll

    In some major report from da Tripa-A-fuckin'-S, Eugene Spafford, directa' o' C-E-R-I-A-fuckin'-S, summarizes da many risks t'our 4-1-1 infrastructure (down low, viruses, bugs, single points o' aborshun, etc.), deir causes (down low, 'esplosive growt', primacy o' time-t'-market ova' quality, lack o' support 4 basic 4-1-1 security research, etc.), an' da damn negative effects o' da damn D-M-C-fuckin'-A, C-B-D-T-P-fuckin'-A, an' otha' corporate maneuva's."

  16. Re:My name is Robert by gearheadsmp · · Score: 1

    Mod this mother down! This was posted earlier today.

  17. How good is the system the vendor is running? by Jonny+Ringo · · Score: 4, Funny

    This whole report regarding "stuff rushed to market over quality" reminds of buying fire works at an indain reservation. The guy I went up to was missing 2 fingers. Like I'm going to buy some m-80's from a guy who lost 2 fingers.

    So, I wish I could see the state of the computer of the guy who's trying to sell me a computer.

  18. I have comments on COSA by tlambert · · Score: 2

    I remember your (identical) posting on July 22nd, which you claim on your web site drove 1400 hits worth of traffic to your site.

    Other than writing a thesis, and driving traffic to your web site, what have you done?

    You appear to be attempting to start an Open Source project to address the problem using your approach arrived at from your thesis materials, without a proof-of-concept.

    With respect, if your methods worked, they should be able to work manually, without having to build up a huge supprt infrastructure.

    In other words, you should be able to apply them to a demonstration problem, and have the results speak for themselves.

    You should also be aware that *declaring* an Open Source project is not the same thing as *causing* one to come into being. Merely declaring something will not cause thousands of elves to come out of the woods and solve your problems for you, Seymore Cray's claims to the contrary.

    If you want to convince people, *do something*, don't just *talk about doing something*.

    -- Terry

    1. Re:I have comments on COSA by Louis+Savain · · Score: 2

      If you want to convince people, *do something*, don't just *talk about doing something*.

      I have done a lot more than you think. These ideas did not materialize into thin air from nowhere while sitting on my ass. They've been a long time coming. You may not realize it but that is the brunt of the work. The rest is just engineering.

      I am working on a two-sided project, AI (Animal) and software reliability (COSA). I have done a tremendous amount of research in AI (see the links below) and written C++ code for a chess learning spiking neural network which can be downloaded from the site. Check it out. I am currently writing code for the COSA execution kernel.

      I think this work is too important to allow business interests to control it. I have decided to open-source all the code and research as soon as I can attract one or more sponsors.

      Temporal Intelligence

      Animal

    2. Re:I have comments on COSA by tlambert · · Score: 2

      I think you have misunderstood me.

      Yes, it's a lot of work to do the design engineering necessary for any project, including an Open Source Software project. And the design engineering is the most important part of a project -- I generally spend no less than 60% of my time on any project doing design work, and it's usually a much greater percentage than that.

      But if you want volunteers to do your coding for you, you have to be able to motivate them, and you're not handling this aspect of your project properly.

      The only thing that will motivate people to donate code to your project is if the project infrastructure already exists, and if at least a minimal set of working code exists.

      In your thesis, you describe purpose-specific objects with which other objects communicate. But you don't put up source code for the communications infrastructure that must underpin these objects, and you don't put up source code for the common function example objects themselves.

      Frankly, without example code, all it will ever be is a thesis, unless you end up finding funding and paying people to work on it, because as it stands, there is no reward equation for Open Source Software volunteers to work on an initial implementation; Open Source is really lousy at creating initial implementations.

      -- Terry

  19. The Infamous Spafford. by Tadghe · · Score: 3, Informative

    I'm sorry, but how can I take a "study" seriously when there not even citations of sources.

    Spafford is the master at soundbytes, but I'm still not convienced he knows what he's talking about.

    We could talk about the scare tactic scenario (page 4) he presents about 50% of the phones going down along with the internet (ok, anyone with half a cluepon, tell me how "the internet" can go down...portions of it yet (we saw it effectively "down" on 911) but it's pretty well impossible to take down the public 'net unless you nuked the entire planet. Ditto for the phone systems (even the legandary Blotto Box (assuming it would work) could only take down a NPA.)) but suspending reality for a moment and living in the the Spaff's world....

    His basic math does not add up (another poster has already pointed this out already) and does not agree with the data avaliable (talking about his virii numbers). even the virii whores at Mcafee don't claim there are new worms/virii ever 75-90 mins (page 4.2)

    Consider such statments he makes, such as...

    "[...] on average over 1 million each year from computer misuses and computer crime [lost each year]. Worldwide, as much as 1 trillion may be lost in downtime and damages each year. Not only is poor security costing us real money, it is also harming our national competiveness."

    The FBI study is not cited only mentioned. The numbers he mentions are not backed up with facts, neither are there facts to back up the "national competiveness" loss he cites (surely it's not because our economy is in the tanker no?).

    He goes on to say that only "100 (maybe 60)". people in higher Ed have training in Security (as he defines it I might add). But again, no facts to back that up, only conjecture.

    I loved the paragraph.
    "As best I as I can tell, the total amount of money available this most recent fiscal year for *basic* research in information security was about $2 million (through the National Science Foundation); a great dealof the money is being spent on acquisition and development of technology for security, but rather that is money spent on extentions of known methods rather than basic reasearch"

    Ok, from a basic logical thinking point of view...either the 2 mill was avaliable for basic research or not (he says both, he says at the begining it is, but then says that most of the money was spent on "extentions of known methods")

    after this he goes on to say that comp sci as a discpline was created at Purdue (where he works).

    Finally for some WorldCom quotes...
    "The amount of traffic that we see on the backbones of the networks has been doubling ever 90 to 120 days" That's pretty much a direct quote from some of the FUD that the WorldCom guys were pitching back in 99-2000.

    He goes on to bitch about people intering the Comp Sec field without a degree and tries to pitch those folks as having no real level of depth or expertise. I can only point out that the great and powerful Spaff has been personally hacked by those selfsame people....

    My point being in this that you gentle reader, need to take Spafford with a very large grain. Always ask for the proof.

    If you wish to learn more about spafford simply browse some of his old Usenet posts.
    in particular you may find such threads as "CERT as told by Spafford" entertaining. Spafford used to be one of the honchos that kept general security info from the hands of the unwashed masses....

    You can also read his "the sky is falling" report to the Whitehouse a few years ago, again it makes interesting reading.

    Mark this as a troll if you must, but don't accept every blind statment by somone with a PHD as gospel.

    --
    Bugs Bunny was right.
    1. Re:The Infamous Spafford. by Anonymous Coward · · Score: 0
      There is some truth to your arguments but I believe there are misconceptions and mistruths in your post as well.
      I'm sorry, but how can I take a "study" seriously when there not even citations of sources.
      This really isn't a 'study', its based off a presentation according to the paper. As such I don't find it terribly unusual that references aren't quoted. You can be sure there are references (academics are notoriously fickle with regards to such), although whether they are reliable is of course a different matter (as shown by the WorldCom figures and the virii numbers.)
      "As best I as I can tell, the total amount of money available this most recent fiscal year for *basic* research in information security was about $2 million (through the National Science Foundation); a great dealof the money is being spent on acquisition and development of technology for security, but rather that is money spent on extentions of known methods rather than basic reasearch"

      Ok, from a basic logical thinking point of view...either the 2 mill was avaliable for basic research or not (he says both, he says at the begining it is, but then says that most of the money was spent on "extentions of known methods")
      Hmm.. Sounds to me like there was 2 million that was positioned in such a way that it could be used for basic research. Instead, however, this money was spent on extensions of known methods, rather than on said research. Thus of the money NSF put forward into the security arena (2 million supposedly), the majority of it was not spent on advancing the state of knowledge.
      after this he goes on to say that comp sci as a discpline was created at Purdue (where he works).
      This one has some basis in reality. Purdue had one of the, and perhaps the, first Computer Science department (1962.) Thus one could say that it did have a founding role in that aspect.
      You can also read his "the sky is falling" report to the Whitehouse a few years ago, again it makes interesting reading.
      If you were attempting to pitch major changes to politicians you too would probably be attempting to make your case as powerful as possible. If you don't make the threat seem large enough you will just get ignored. Personally I don't mind a bit of alarmism when its purpose is to get more funding into security research. The area desperately needs more funding and effort.

      Just my thoughts, felt someone should post a slightly less biased view to counterpoint your own obviously biased one.. not that anyone reads the AC.
    2. Re:The Infamous Spafford. by craw · · Score: 1

      I have to agree that a bit (a lot?) of what Spafford wrote was a bit over the top. My favorite could have been written by somebody on /.

      "The next generation of Navy aircraft carriers is going to have all weapons systems, propulsion, and command and control run by the very same system that you use at home to browse the Internet and play computer games. This is the same one that keeps coming up with "blue screens of death," which take on new, grim meaning in a military environment."

      If Spafford had been a bit more toned down, he could have still made the same points without introducing vulnerabilies in his arguments that would make one cringe. OTOH, his points should be contemplated and analyzed. Computer/network security is pathetic if one considers the worse case scenario. A design error that is inherent in a commonly used protocol used by network routers could potentiall create havoc. Hmmm, didn't we come close to this one?

    3. Re:The Infamous Spafford. by Tadghe · · Score: 2

      "not that anyone read the AC."

      I do. and I agree with at least one of your points (the NSF one). But my point was really to point out that people need to *think* about what the so called "experts" (did you know that Spafford once said that taking a lead pipe to somones knees was worse than hacking thier systems (he was referring to Bank and the like I would add in all fairness) but I still find that amazing. Again though. my point was really not to diss Spafford, but rather to get people to ask if the people telling them the sky is falling (or that the 'Net the end to all human suffering (not that the Spaz has said that), and consider what they are saying and critically evaluate it.

      --
      Bugs Bunny was right.
    4. Re:The Infamous Spafford. by Anonymous Coward · · Score: 0

      Indeed.. too many people blindly accept what they are given. Actually knowing Spaf and other "experts" in the field has certainly opened my eyes to how fallible and biased they can be, just like everyone else. Taking things with a grain of salt is definetly a good idea.

      Enough Slashdot for one evening, have a good one.

    5. Re:The Infamous Spafford. by Anonymous Coward · · Score: 0

      Hmm, if half the phone service goes out, you think somehow the Internet will be mysteriously immune?

      Perhaps you weren't around the day AT&T was out for a number of hours. Things didn't work.

      Spaff's right on the money...

    6. Re:The Infamous Spafford. by Anonymous Coward · · Score: 0

      after this he goes on to say that comp sci as a discpline was created at Purdue (where he works).

      Purdue has the oldest (first) school of computer science in the nation. Look it up.

    7. Re:The Infamous Spafford. by Tadghe · · Score: 2

      But it was *not* where Comp Sci was first developed into a discpline...to quote you..."look it up". Hint: take a look at Stanford's comp sci history...or shit, just google for it.

      --
      Bugs Bunny was right.
  20. Yeah, sure... but... by SquireCD · · Score: 0

    It's probably true that the system, as a whole, is pretty weak. But, this isn't really news. I remember, the group L0pth, speaking at the US Congress a few years ago and they said the exact same thing. See the artical(s) here:
    here and here

  21. Well reasoned arguments... by cosmicpossum · · Score: 1
    Are always better than hand ringing and chicken littling. This article would be improved manyfold if the tone were more scientific and less OH MY GOD.

    If you ask most fuds they will tell you that only another fud knows anything useful:

    "We have a number of policy decisions that are being made by low level technical people"

    I think that the whole point of this diatribe is to get more money for his research program. It would help if he cited his sources and gave examples.

    Of course, it has already been pointed out that the doubling of internet traffic every 100 days was debunked just days ago. Errors like quoting bogus statistics just servers to further discredit this piece.

    --
    (This sig intentionally left blank)
  22. The wrong approach. by Restil · · Score: 3, Informative

    Constantly, the money that companies are forced to spend on recovering from various infrastructure attacks are should not always be referred to as "losses". Certainly, if someone broke into your building and stole something, that is a loss. But if your entire corporate network is down for two days while your IT department is working overtime and the rest of the company is not, while getting paid, this is not a loss. This is an operating expense. This is part of the expected cost of using software that has well known vulnerabilities. This is part of that "total cost of ownership" that Microsoft is only so proud to bring up when discussing their software prices when compared with those of competitors.

    So for now on, don't suggest that companies LOSE this money whenever they're attacked. This is just part of the total cost of ownership when you run insecure software, and when you hire substandard IT personel, and when you don't have reasonable company policies regarding non-business related applictions.

    Companies can take the cheap way out. They can put Windows boxes in front of every employee of the company, content that everyone can quickly figure out what to do with minimal expense. Hire some just out of college whackjobs with no useful experience to run the network. They're cheap afterall. Nobody to train, nobody to waste money on. No need to spend money on security audits. That's just wasted money. Of course, you'll "lose" all of it the first time someone hits you, but that's the way you've decided to budget your technical department. You get what you pay for.

    -Restil

    --
    Play with my webcams and lights here
  23. excuse my poor, uneducated soul, but... by prisen · · Score: 0

    from the other-kings-said-i-was-daft-to-build-a-castle-on-a -swamp dept. where the @)$(*@ did that come from?

  24. This guy's forecast is way out. by Dthoma · · Score: 1
    "...the many risks to our information infrastructure (viruses, bugs, single points of failure, etc.)"

    And these risks to the Internet have been around for HOW long now? About 30 years, from the very moment of its creation? And has it ever gone completely down the tube?

    Didn't think so.

    --

    Note to M1-ers: a curt but otherwise insightful message is not "Flamebait" or "Troll".

  25. Your link is to ch. 1, not ch. 4; Gene's is ch. 4 by tlambert · · Score: 2

    See the subject line.

    The provided link is to an HTML version of chapter 1 of the book of which Gene Spafford's comments being cited in theis Slashdot article are in chapter 4.

    -- Terry

  26. consumers to blame by jadavis · · Score: 1

    I think this guy puts too much blame on the vendors. Vendors supply what people want, and people, in general, want bad software fast rather than good software a little slower. I don't buy into that, I get software based primarily on it's technical merit (which includes security, of course).

    Sometimes vendors imply that "everyone writes crappy software". I think that's bad because the consumers might not understand the idea of an application or OS that works consistantly.

    However, I don't see any clear way around that kind of marketing. And I certainly don't see any productive (as opposed to counterproductive) way of *forcing* people to write good software without public demand. After all, liability would decrease the number of free software developers. Not only that, what about software developed outside the US? Import laws? That just sounds like a bad idea.

    Jeff
    --
    Social scientists are inspired by theories; scientists are humbled by facts.
  27. Re:Well written, but I have some quibbles-has not by linuxislandsucks · · Score: 1

    it Has not changed as far as MS's concern about writing secure code..

    MR Blox(MS Employee) in his comments recently about whether the new C++ library to prevent buffer overflows should be required to be used by MS programmers listed as optional!

    But here is the kicker we poor open source coders seem to be able to write code without buffer overflows..maybe MS programmers are just plain fucking stupid!

    --
    Don't Tread on OpenSource
  28. Typical Spaf by Anonymous Coward · · Score: 0

    A lowbrow contribution that doesn't say much, but what it does say is stuff everyone else has been saying for a long time.

    We need a pompous dick in a three-piece suit to tell us what we already know?

  29. Spafford has done other things by cide1 · · Score: 2

    Gene Spafford was instrumental in blocking the installation of Carnivore onto Purdue University's network. Many other schools folded, but he was adament about users rights.

    --
    -- the computer doesn't want any beer, no matter how much you think it does. NEVER, EVER feed your computer beer.
    1. Re:Spafford has done other things by Anonymous Coward · · Score: 0

      Get your facts straight. No schools "folded" -- they all rejected Carnivore (except some matchbook-cover Institute of OnlyInItForTheMoney in Chicago). As usual, Spaf followed the crowd on this one.

  30. PDF Is Viral? by Anonymous Coward · · Score: 0

    What idiot allows a security doc to be published in a viralent format?

  31. Re:Well written, but I have some quibbles-has not by GGardner · · Score: 2
    But here is the kicker: we poor open source coders seem to be able to write code without buffer overflows

    Two words: sendmail

  32. Crypto-Gram: Recommended Interview with Spafford by securitas · · Score: 2


    This interview with Gene Spafford was recommended by Bruce Schneier in his Crypto-Gram newsletter some months back.

    Bruce says:

    Long and interesting interview with Gene Spafford, about the infosec threat landscape; privacy; the challenges of digital certificates, CRLs, public key infrastructure standards and interoperability; key escrow, backup and recovery; identity fraud; trust on the Internet; and the problems of security education today. Sample quote: "Security doesn't work as an add-on. It really needs to be built-in from the beginning."

    I skipped over the intro page but if you really want to see it it's here.

  33. Meetup was fun. by snoozebutton · · Score: 1

    Meetup in Toronto was fun last night.

    1. Re:Meetup was fun. by Anonymous Coward · · Score: 0

      Especially the goatse strippers and that chainsaw up your ass. It was great... we must do it again!

  34. Good read by Anonymous Coward · · Score: 0

    It's a very interesting and true read, however Spafford displays his ignorance over the global IT market which I find a little disturbing as it's been highlighted all too well recently.

  35. Re:Well written, but I have some quibbles-has not by theCoder · · Score: 2

    Well, that's only one word :)

    But, yes, there's nothing about OSS that prevents buffer overflows. It just has a greater change of being caught and fixed IMO than CSS. Not that the buffer overflows will be caught immediately. Sendmail's problems went for years without being noticed. But many of them are now fixed.

    You are absolutely right though -- OSS is not immune to things like security holes, viruses, worms, or othre bugs. It stands a slightly better chance, and I use it all the time, but people who think it's the holy grail are just deluding themselves.

    --
    "Save the whales, feed the hungry, free the mallocs" -- author unknown
  36. Re:Well written, but I have some quibbles-has not by Anonymous Coward · · Score: 0
    How about this:

    Two words: Red Hat

  37. If he's missing fingers... by SaDan · · Score: 1

    ...then you know the product is good, right? The vendor might be a moron, though.

  38. Spaff published the piece before the myth popped. by Ungrounded+Lightning · · Score: 2

    I thought that myth had been debunked. It now has passed into the realm of the 'factoid'.

    Spaff published the piece a week before it was debunked. The file is dated Jul 19, the article you cite follows from an Economist article dated Jul 26.

    Now looks like what we had was:
    2 years of tenfold growth
    3 years of twofold growth.
    (dotcom bubble pop)
    2 more years where numbers aren't in (though DSL connects were about doubling per year).

    Substituting "doubles every year" in Spaff's article makes it a bit less gee-whiz, but no less valid.

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  39. Phew!!! by Pig+Hogger · · Score: 2
    Phew!!! It's Spafford!!!

    I thought for a moment it was SpaMfford Wallace...

  40. Re: USS Yorktown by plcurechax · · Score: 2
    I have to agree that a bit (a lot?) of what Spafford wrote was a bit over the top. My favorite could have been written by somebody on /.

    "The next generation of Navy aircraft carriers is going to have all weapons systems, propulsion, and command and control run by the very same system that you use at home to browse the Internet and play computer games. This is the same one that keeps coming up with "blue screens of death," which take on new, grim meaning in a military environment."

    If Spafford had been a bit more toned down, he could have still made the same points without introducing vulnerabilies in his arguments that would make one cringe
    Well, he isn't really over the top, the difference between say Windows XP and Windows NT/2000 is minor. Perhaps you should read about the USS Yorktown.
    RISKS digest 19.88 (1998): USS Yorktown dead in water after divide by zero.