Slashdot Mirror


Inside the Mind of a Virus Writer

sebFlyte writes "news.com.com is running a very interesting interview with 'Benny' (AKA Marek Strihavka), a former member of the famed 29A russian virus-writing group, about what drove the group among other things. He's now one of several ex-virus writers working for security companies."

8 of 231 comments (clear)

  1. Well, it looks like we finally have step #2... by errxn · · Score: 5, Funny

    1. Write viruses
    2. Work for antivirus company selling solutions to the viruses that you write
    3. Profit!

    --
    In Soviet Russia, Chuck Norris will still kick your ass.
  2. Let me summarize... by jmcmunn · · Score: 5, Insightful


    Q: How many viruses have you written?
    A: A lot

    Q: Why did you write them?
    A: To learn and innovate, not to harm.

    Q: Should virus writers like you work for AV companies?
    A: Yes, of course. We know security the best.

    Why is this an "interesting interview"? There is little to no content here. It's the same crap we've heard every virus writer say to every person who interviews them. While I agree that the best security people are probably the ones who used to break the system (aka virus writers and crackers) why does this need to be considered interesting news? I was more interested in the (FALSE) story about the fish from the tsunami.

  3. Truth? by PhreakinPenguin · · Score: 4, Insightful

    It amazed me the way some people think. It sounds to me like he thinks he should be free to write virii because it's expression and protected under the first amendment? So by that analogy, someone who burns down a building shouoldn't be prosecuted because they are just expresssing themselves. Come on, him saying that he didn't distribute his "code" is complete crap. He wrote it and it got distributed. Anyone who thinks differently can buy some swampland from me at a steep price.

    --


    My sig of choice is Marlboro
    1. Re:Truth? by Morganth · · Score: 4, Insightful

      "So by that analogy, someone who burns down a building shouoldn't be prosecuted because they are just expresssing themselves. Come on, him saying that he didn't distribute his "code" is complete crap. He wrote it and it got distributed."

      Nice try, but that doesn't follow. The virus writer isn't like the guy who burns down the building; he's more like the guy who came up with the formula for the molotoff cocktail your guy used to burn down the building. Coming up with the formula is a creative act, and one that is protected enough so that one has the right to actually publish the formula anywhere. One can (or at least, should) be able to publish the design for other molotoff cocktails, or bombs, or guns, or swords, or whatever harmful thing you want.

      However, the second someone takes that formula and puts together the ingredients (*ahem, compiles the source code*) and throws it at the building (*ahem, distributes the executable*), then we have our criminal.

  4. Re:That stinks... by Fjandr · · Score: 5, Interesting

    On the one hand, yes, but without any evidence that he is involved in spreading viruses (something he strongly denies) it's more likely as he says: marketing theatre.

    It's like saying that banks shouldn't pay Frank Abignail millions of dollars to help them stop check fraud because he at one time stole millions of dollars the same way. When you get someone with that much inside perspective, the good they do can far outweigh their perceived shortcomings.

  5. Re:That stinks... by shatfield · · Score: 5, Insightful

    It's not like that at all.

    Frank Abignail did steal millions of dollars. He was a criminal. This kid didn't do anything of the sort -- he simply wrote programs that exposed insecurities in operating systems.

    Sometimes those programs are called Viruses, sometimes spyware, sometimes worms.. etc. When you put them all in a pot and boil them down to their bare essentials, they all smell the same way -- programs that exploit insecurities in operating systems.

    In the end, if he indeed did NOT spread the programs that he wrote, then they weren't viruses at all -- they were just programs that exposed the insecurities of operating systems.

    I am of the mind that we absolutely need people like Benny -- someone MUST check the locks to ensure that we are indeed safe. If no-one is checking the locks, then we're just fooling ourselves that what we hold near and dear is safe.

    --
    "To make a mistake is only human; to persist in a mistake is idiotic." Cicero
  6. That stinks...Anything Goes. by Anonymous Coward · · Score: 5, Insightful

    "Frank Abignail did steal millions of dollars. He was a criminal. This kid didn't do anything of the sort -- he simply wrote programs that exposed insecurities in operating systems."

    And spam writers simply write spam that exposes weaknesses in baysian filters.

    "I am of the mind that we absolutely need people like Benny -- someone MUST check the locks to ensure that we are indeed safe. If no-one is checking the locks, then we're just fooling ourselves that what we hold near and dear is safe."

    I'll be over to check your locks. DON'T CALL THE POLICE!

  7. Close ties between virus and anti-virus industry by Animats · · Score: 5, Insightful
    I've always suspected close ties between the virus industry and the multibillion dollar anti-virus industry. Now we know they're real.

    Most viruses are designed to be friendly to the anti-virus industry.

    • They rarely do anything really destructive. "Propagate for 15 days, then erase hard drive" viruses are very rare.
    • They seldom do something that an anti-virus program can't undo. Think about that for a moment. Most viruses are uninstallable without having to reload applications or the operating system. That can't be entirely by accident.
    • They almost never attack the users data in subtle ways. We don't seem to see viruses that, say, make small changes to numbers in spreadsheets.
    • They don't even remove anti-virus programs much, which would seem to be an obvious feature.

    There's always been an implicit synergy between the virus and anti-virus companies. They need each other. But now we know there's more than that.