Slashdot Mirror


Microsoft Offers A Bounty On Virus Writers

Iphtashu Fitz writes "According to news.com Microsoft will announce a bounty of $250,000 on Wednesday for information on who wrote two recent Windows viruses. The bounty is offered for information that leads to the arrest of the people who released the MSBlast worm and the SoBig virus. Microsoft will officially announce the reward in a joint press conference with the FBI and U.S. Secret Service Wednesday morning. This is the first time a company has offered money for information about the identity of the cybercriminals. Could this be the start of a new trend in going after the writers of viruses & worms?"

20 of 719 comments (clear)

  1. Not always so catchable... by the+uNF+cola · · Score: 4, Insightful

    It's not that hard to deploy a virus and not get caught. There are so many open access points and people who forget to log off of an email account after leaving.. how would you track it?

    --

    --
    "I'm not bright. Big words confuse me. But Wanda loves me and that should be enough for you." - Cosmo

    1. Re:Not always so catchable... by wizrd_nml · · Score: 3, Insightful

      1) Not getting caught is easy assuming whoever wrote the virus expected such a wide response and therefore took precautions to guard his identity. If he didn't and started bragging to all his friends, who then told their friends...

      2) I wonder if Microsoft are expecting this move to deter people from writing viruses. Maybe someone thought: that virus cost us a lot more than 1/4 million, let's spend that money and set an example even if the guy doesn't get caught.

      3) This is going to spark a new underground industry: write a virus secretly, then turn around and tell microsoft you have info about it (of course in an imaginative enough way not to get caught but still get the bounty).

    2. Re:Not always so catchable... by tanveer1979 · · Score: 5, Insightful
      Hmm not really. Given enough resources and motivation, it is not that daunting a task. With internet being taken into control everywhere and watchdogs sitting, it may not be that difficult.

      Ever read the book, "The Silicon Samurai", the cracker in that book was very clever, a master of the art. Still he got caught. Why? Because crackers, virus writers, DDoS organisers have one thing in common. They want fame. They cant sit without leaving clues. History teaches us that the greatest thieves and criminal got caught due to their hunger for fame. This will happen here also. Though i am not to sure if that is a very good thing, coz when such showdowns happen a lot of innocent people suffer.

      --
      My Aurora : http://www.youtube.com/watch?v=o91ZsGwJYyg
      FB : https://www.facebook.com/TanveersPhotography
  2. Well, there logic is (half) right... by WIAKywbfatw · · Score: 5, Insightful

    Well, ask any doctor and he'll tell you it's better to cure a disease than to treat its symptoms. No virus writers means no viruses, which means no headline news virus alerts and scares.

    Of course, the question is how much of the "disease" is the virus writers and how much is Microsoft itself with its sloppy approach to secure computing?

    --

    "Accept that some days you are the pigeon, and some days you are the statue." - David Brent, Wernham Hogg
    1. Re:Well, there logic is (half) right... by ajr_trm · · Score: 5, Insightful

      Well, ask any doctor and he'll tell you it's better to cure a disease than to treat its symptoms. No virus writers means no viruses, which means no headline news virus alerts and scares.

      The same doctor will tell you that elimination of all dangerous viruses and bacteria from our environment is impossible.
      The best way to fight the diseases is to make our constitution stronger.

      The same with software.

  3. Re:I heard they needed skilled people by studpuppy · · Score: 5, Insightful

    So.. like, is the 250K a signing bonus? Or do they get it in stock options? Of course, the real question is... is it cheaper for MS to pay 250K to jail each person that writes a virus exploiting on of their security holes than it is to pay the developers to avoid creating them in the first place?

    --
    The last time I wrote code, it was Morse
  4. Re:worms = good by Pike65 · · Score: 4, Insightful

    Well you clearly didn't get a temp job on a helpdesk a week before the shit hit the fan.

    I did >: (

    Besides, in business where the sysadmin wasn't a total retard (read: not where I was) there was no way for the worm to get in. The people who needed to patch their systems were the home users who got shafted for not using firewalls. The same people who use Windows because it's not meant to need much setting up . . .

    --
    "If being a geek means being passionate about something, then I pity those who aren't geeks." - Pike65
  5. People need to be better informed by linuxci · · Score: 3, Insightful

    The problem is not many people look further than Microsoft products because they know no better, and the mainstream press doesn't do much to help this. Microsoft throwning money into the pot to catch criminals is unlikely to solve the problem, in the UK there's a lot of schemes that offer rewards for finding criminals, but although they often catch people, it doesn't seem to deter people. I mean we can't tell people in the UK that they can install new Windows and doors in their house and not bother to lock them, and installing an MS OS (and to be fair many Linux distributions) without doing a 'lock down' is just as stupid, but most people don't know how to go about securing their PC.

    We know that other products aren't perfect but variety in software does do something to reduce the dramatic effect of these worms.

    So the more people we can educate about alternatives to Microsoft products such as Mozilla Firebird, Thunderbird and Seamonkey (the app suite) will help to restore some balance and will hopefully reduce the number of email viruses. Commercial alternatives such as Opera should also be mentioned because although I think the interface is awful, other people like it and choice is good. Many home users just use thier computers for web browsing and simple documents, so Mozilla + OpenOffice would do all they need.

    Then on the desktop you have various options as well as Windows, although unfortunately for most people they may be depending on it for certain applications. MacOS X is ok, but would require buying new hardware if you currently have an ix86 PC.

  6. Poor victimised Microsoft by amorsen · · Score: 3, Insightful

    People have been starting to see Microsoft as a vendor of poorly-written, insecure software. What this offer makes people see is that Microsoft is just the victim of evil criminals. And you can never blame the victim for the crime...

    --
    Finally! A year of moderation! Ready for 2019?
  7. Spammers by tehanu · · Score: 3, Insightful

    Given that the Sorbig virus has been linked to spammers, finding the person who wrote the virus might be a blow against spammers as well. Any trial will be well publicised and having the public connection of spammers==virus writers==evil hackers (yes I know the proper term is crackers, but this is public opinion I'm talking about here)==terrorists could be a big blow against the reputation of spamming so that it is no longer seen as just an annoyance but something potentially dangerous. This probably won't bother the spammers so much but it might help get legitimate companies who hire them give the whole email marketing process a second thought, especially if any connections come up during a trial. "Trial: Virus used to advertise for Company X." "Virus writers hack computers to advertise for X" does not sound good for Company X on the front page. At the very least it might make them more careful about who they hire and who the people they hire outsource to (as I'm sure there will be so much outsourcing something known as "plausible deniablity" will be used).

    And a connection in the public consciousness between spammers and hackers who write viruses might give a bit of impetus to the government for harsher anti-spam laws. I mean look at anti-hacking laws vs anti-spam laws. Which one has more teeth and are tougher?

  8. No, worms = bad by Moraelin · · Score: 5, Insightful

    This idea is about as retarded as saying that:

    - throwing stones through people's windows is good. It encourages them to buy bullet-proof glasses before a real thief breaks through that window.

    - lockpicking into someone's house and spray-painting their walls is good. It encourages them to buy better locks, giving a real thief less opportunity to steal stuff.

    - poisoning the neighbour's dog is good. It encourages him to get a dog which won't wag its tail when a (potential) thief throws him a piece of meat.

    - keying random people's cars is good. It encourages them to park those cars in proper park houses, where presumably a real thief would have a harder time getting away with their car.

    And so on, and so forth. I'm sure you get the idea by now.

    Basically, no, there is no proper excuse for vandalism. Neither in the proper world, nor in the IT world. And just as any judge would probably just have a laugh if someone pulled the retarded excuse "but the lock wasn't 100% secure, so it's not my fault" in a break-and-enter trial, the same should apply to breaking-and-entering someone's computer.

    And if you do go around keying cars or flooding the net with RPC exploit packets, no matter how well intentioned you are, I do hope they throw you in a nice jail cell, with two convicted anal rapists as cell-mates. Yes, that same heartfelt wish goes to whoever thought that an RPC patching worm is a good idea.

    --
    A polar bear is a cartesian bear after a coordinate transform.
  9. Clever by 0xdeadbeef · · Score: 5, Insightful

    By offering a bounty on their heads, they only serve to increase the status of worm and virus authors. What was once the loserdom of the script kiddie community is now glamorous.

    Now consider what this means to their "secure computing" initiative, how the frustrations from dealing with this shit can make people more accepting of their draconian security measures. Consider the financial benefits of "digital rights management" that they can only realize after the hardware and software is locked down.

    You can imagine the conversation that lead to this, like something out of "24" or the Bush administration: Lets allow, no, lets *encourage* a virus 911 so they'll let us lead them to safety!

  10. Smoke and Mirrors - Windows not ready for Internet by Anonymous Coward · · Score: 5, Insightful
    If that were even remotely true then Apache would be swimming in remote exploits, which it is not. Not only that, Microsoft's products just aren't designed for security, even by the admission of their own executives. In fact, Windows is insecure by design. Microsoft has worked hard to earn the shoddy reputation it has among technology experts and is focusing all the more on marketing efforts. But face it, Windows is not ready for the Internet and is not likely to be. Even Joe Sixpack is starting to figure that out.

    This bounty is just a PR game to distract from anti-trust, patent violations, anti-competitive fines, security fines. Microsoft's executives and other investors have had enough time now to dump their stock. Game over.

  11. We Need to Stop Equating All Conspiracy Theories by FreeUser · · Score: 5, Insightful

    Mind you, some conspiracy theorists also claim that the world is ruled by alien lizards, so I think it's fair to take what they say with a pinch of salt.

    Yes, but they aren't the same conspiracy theorists. :-)

    On a serious note, folks on slashdot (and indeed, people in general) tend to equate all types of conspiracies (and conspiracy theories) and lump them together...somehow equating Enron with the X-Files, at least until Enron is exposed publicly (then, for some reason, people are able to grasp the difference). This is a real problem, because it means that people will live in denial of real-world conspiracies that are taking place (e.g. Monsanto's conspiracy to dump toxic waste into the rural groundwater of the deep American south in the 1990s, or the current SCO conspiracy to defraud their investors and steal the copyright of thousands of software developers around the world) by dismissing them in their minds as no more likely than alien invasion, UFOs in storage at area 51, or silent black helicopters hovering overhead.

    We do know conspiracies exist, therefor, it logically follows that some conspiracy theories are likely to be not out in left field, but rather quite correct.

    We know as a matter of historical record that the Nazis conspired to stage a "terrorist" act against the Reichstag as a prelude to a coup d'tate, however, listening to the "conspiracy theorists" of the time would have been like listening to a conspiracy theorist today claiming that 9/11 was staged by Baby Bush (it obviously wasn't ... but it has certainly been exploited in analogous ways by the FBI and the secret service to grab unprecidented power in the United States).

    Microsoft has a history of conspiring to do dishonest and disingenuous things that directly (and illegally) harm and coerce their customers and their competitors, indeed, they have been convicted of doing so on numerous occasions (the DOJ anti-trust trial and subsequent sell-out being only the latest example). A conspiracy theorist pointing out a economic or tactical political advantage Microsoft might gain through ill-behavior toward its customers is not out in left field ... their theory, while quite possibly false, is certainly worthy of consideration, particularly given the amount of historical fact that illuminates similiar behavior by Microsoft in the past.

    So IMHO it is a mistake (and disingenuous) to equate actions by Microsoft and the copyright cartels that directly threaten our digital freedoms, and the conspiracies that do in fact drive these agendas (even if said conspiracies have the most banal of motivations: greed for cold, hard cash), with tin-foil hats, ghosts, and UFO sightings, as is so often done by the apologists of such groups.

    Expressing concern about corporate or government malfeasance (conspired or not) isn't even remotely analogous to X-Files-like nonsense, and it is time we stopped allowing sceptics to use dishonest means (equating suspicion of the Reichstag burning ^H^H^H Microsoft's exploitation of their woeful security record to political advantage, with suspicion of Alien Lizard ruling the earth) to denigrate those who do express such concerns.

    --
    The Future of Human Evolution: Autonomy
  12. I'm looking for a virus writer... by clickety6 · · Score: 3, Insightful

    ...who is willing to spend a few years out of circulation for $125,000...!

    Contact me on 555-EASYCASH.

    --
    ----------------------------------- My Other Sig Is Hilarious -----------------------------------
  13. Re:Why People Bash Microsoft by TopShelf · · Score: 3, Insightful

    That is one the silliest things I've read in a looooong time.

    1) Freedom of the press is only truly open to those who can afford to publish? Uh, hello, communication channels are more wide open today then they have ever been, thanks to blogs, email, newsgroups, P2P, desktop publishing, etc. Of course big corporations have more options available to them, but that is (and has always been) the case just about everywhere in the world.

    2) "What will hopefully emerge from this process is a totally new form of government, a meritocracy. In my opinion, music will be the greatest power." Have you taken your meds today, or are we looking at 50 Cent as the new Director of Homeland Security?

    3) "the company with the greatest financial clout in the world right now is Microsoft." A software company, no matter how large, hardly wields "financial clout" like a GE, which spans the globe and gobbles up companies in a variety of industries by the handful, or a huge bank like Citigroup, which brokers deals and provides the financing that makes business projects possible. Microsoft is a giant in the software business, but in terms of the overall business picture, they aren't the biggest kid on the block by far.

    4) Gates can direct the "full power of the press" to back candidates of his choosing? While Microsoft has a partnership with NBC, I doubt that he spends his time telling Katie & Matt which candidates to pump up.

    5) "If my thesis is right, and this is a plutocratic system, then Gates is nominally the king, with no hereditary right of succession as such, unless he can prolong his wealth into the next generation. Well, your "thesis" is dead wrong from the start, and is certainly finished off by the fact that Gates plans to give all his fortune away.

    There are plenty of reasons to bash or admire Microsoft, but paranoid fantasies are another thing entirely...

    --
    Stop by my site where I write about ERP systems & more
  14. Re:Brilliant move by lone_marauder · · Score: 3, Insightful

    To some degree a virus wrecking havoc amongst computer using their software can be seen like if somebody was vandalizing your property.

    Oops! Be careful with that. Compare the MS business process with real life, and you might raise the specter of product liability.

    --
    who are those slashdot people? they swept over like Mongol-Tartars.
  15. Re:I heard they needed skilled people by Daniel+Dvorkin · · Score: 4, Insightful
    You know damn well that if Linux enjoyed the sort of desktop ubiquity that M$ has right now, we'd all be bitching about the latest exploit/virus/worm and complaining about how it takes so long to get them patched and why in $#%^&$%@#&* couldn't it have been written correctly in the first place!
    Right. Which is why I'm bitching all the time about hbow insecure Apache is, and how long it takes to get it patched, and why the $#%^&$%@#&* it couldn't have been written right in the first place ...

    ... oh, wait a minute, I'm not.
    --
    The correlation between ignorance of statistics and using "correlation is not causation" as an argument is close to 1.
  16. Re:I heard they needed skilled people by WhiteWolf666 · · Score: 3, Insightful

    Perhaps I'm barking up the wrong tree...But....

    Its not JUST that MS makes the default user---

    It is also that Windows runs a ton of stupid, random crap in kernel space.

    Like Windows Media Player. Like Internet Explorer. Like Outlook. Like a ton of office stuff.

    None of that belongs in kernel space.

    --
    WhiteWolf666 an exBush supporter. All you new-school,compassionate,save the children Republicans can rot in hell
  17. Microsoft is doing something at least... by gone.fishing · · Score: 3, Insightful

    Gee, I knew what most of these posts were going to say before I even read them. Most of them say that this is just a marketing ploy by Microsoft to deflect criticism, that Microsoft's poorly written code is what is really the cause, and Microsoft this and Microsoft that and oh, by the way Linux rules.

    Let's put all of that aside for a minute. I'm not going to be pro-Microsoft or Pro-anything here. I am going to be Anti-virus writer though.

    Cyber-crime be it scams, viruses, trojans, worms, password/identity theft, carding or whatever affects all of us personally. It does because it casts things like the internet, ecommerce, and technology in a poor light. It causes "big money" to think twice before they invest in technology, it causes things like e-voting to come more slowly to the forefront and, it forces companies to take sometimes extreme security measures.

    In a sense, the 'net hasn't matured yet. It can be compared to the Wild West where crooks didn't have to run very far or hide very long or even worry very much about getting caught. I have no doubt that over time we will see the net change and cyber-criminals and other scumbags will have more to fear. But right now, a wanted poster with a reward is appropriate. It is what Wells-Fargo did to catch outlaws way back when and it will work as well today.