Slashdot Mirror


Computer Security Still Totally Inadequate

Several news sources are running articles detailing the lack of computer security on all platforms. Symantec foretells a dark future for Firefox and Mac users describing their security as a "false paradise". Kernel developer and Red Hat fellow, Allan Cox stated in his recent interview with O'Reilly that "even the best systems today are totally inadequate". He goes on to say that "We are still in a world where an attack like the Slammer worm, combined with a PC BIOS eraser or disk locking tool, could wipe out half the PCs exposed to the Internet in a few hours," Cox said. "In a sense we are fortunate that most attackers want to control and use systems they attack rather than destroy them."

21 of 452 comments (clear)

  1. Symantec, eh? by Musteval · · Score: 5, Funny

    No agenda here. Move along.

    --
    Note to mods: I'm probably being sarcastic.
    1. Re:Symantec, eh? by ackthpt · · Score: 5, Funny
      No agenda here. Move along.

      No, they have one... they found it in some book, written by some guy named Agrajag. Works much better for them than it did for him. Funny that.

      ""Do not worry, Arthur Dent. Be afraid. Be VERY afraid.""

      --

      A feeling of having made the same mistake before: Deja Foobar
  2. Re:Java. by DaHat · · Score: 5, Funny

    Quite true! If everything was programmed in Java, viruses would move so slow that they would never have a chance to infect a significant # of machines as well as those they attempt to infect would take forever to execute it's evil payload.

  3. Comment removed by account_deleted · · Score: 5, Funny

    Comment removed based on user account deletion

  4. Symantec Security Software by orangeguru · · Score: 5, Insightful

    With security suites like that you don't need any hackers or viruses. Bloated Symantic software makes your computer unusable and unstable anyway ...

  5. Duplicate Link Checker by Anonymous Coward · · Score: 5, Interesting

    One of the links appears to be new. The other was posted like a week ago. Since the 'editors' don't actually read the site, why don't they just have a short script which checks whether the same link has been posted in another story. That would really cut down on the dupes, and wouldn't take long to implement.

  6. the best systems today are totally inadequate-not by bcrowell · · Score: 5, Insightful
    I first heard this ca. 1990: if your system is connected to the internet, and it hasn't been hacked yet, it will be soon. Still hasn't happened to me.

    We are still in a world where an attack like the Slammer worm, combined with a PC BIOS eraser or disk locking tool, could wipe out half the PCs exposed to the Internet in a few hours
    Well, actually, I wonder what percentage of PCs are currently infected with malware? I'd guess way more than 50%, and the world hasn't come to an end. Actually, it would probably be a good thing if the hypothetical disk-erasing worm would come along -- it would probably prompt a lot of dumb users to make backups, take some basic security precautions, and maybe consider switching from MS-ware to more secure OSS.

  7. Allan Cox, huh? by Sheetrock · · Score: 5, Funny

    Not good enough he's a kernel developer and Red Hat fellow, now he had to go and add an l to his name?

    --

    Try not. Do or do not, there is no try.
    -- Dr. Spock, stardate 2822-3.




  8. What does this have to do with flammable gas? by bigtallmofo · · Score: 5, Insightful

    This is why having a Hydrogenous network and/or having a society where no one platform dominates.

    I'm guessing hydrogenous is not the word you were looking for. Assuming of course that you weren't proposing that we base our networks on hydrogen.

    I'm going to instead assume you meant heterogeneous which is something often proposed on Slashdot and grants the proposer instant karma as people rush to mod them up.

    The only problem is having a hetereogeneous environment increases your support costs whether you have a security incursion or not. How many people are security experts in Mac, Windows, Linux, BSD, Solaris, FreeBSD and CPM? Not many. Which means that for every environment your IT staff supports, you need additional admins.

    --
    I'm a big tall mofo.
  9. false paradise by Anonymous Coward · · Score: 5, Funny

    I think I'd rather exist in a false paradise than a certifiable hell.

  10. Re:Hydrogenous Infrastructure. by ekephart · · Score: 5, Funny

    Yes... [clears throat] ahem... The exports of Libya are numerous in amount. One thing they export is corn, or as the Indians call it, "maize". Another famous Indian was "Crazy Horse". In conclusion, Libya is a land of contrast. Thank you.

    --
    sig
  11. Mac User Buys Nortan AntiVirus by SQLz · · Score: 5, Funny

    Well, I bought Norton for mac and when I ran it, it said:

    "Updating Virii Signatures......"
    "0 Signatures updated, there are no virii for mac you idiot"

    Can I return it?

  12. "Security Professionals" are Retards by Uhlek · · Score: 5, Insightful

    Yet further proof that almost all "security professionals" have about as much intelligence as a gnat.

    I'm really tired of mediocre systems guys passing a CISSP exam (thousand miles wide, quarter inch deep) and being declared experts on securing things they don't even understand to begin with.

    For one, quantative analysis of the numbers of vulnerabilities doesn't equate to determining if a system is more or less secure than another. It's also meaningless if you don't compare how the systems are configured in what kinds of environments. Even simple things like Linksys routers greatly contribute to additional security on a personal computer (Windows or otherwise).

    From the article: "Symantec chronicled 1,862 new vulnerabilities during 1H2005 - an average of 10 new flaws a day - 73 per cent of which it categorises as easily exploitable. The time between the disclosure of a vulnerability and the release of an associated exploit was just six days. Half (59 per cent) of vulnerabilities were associated with web application technologies."

    Can anyone tell me where in that statement is a shred of useful, meaningful information? Of course not. Because there is none.

    Insofar as Firefox and and OS X being "in for surprises." Sure, Firefox is an evolving application, bugs will be introduced and squashed, and later on more will be introduced. Some of those will be security vulnerabilities. Any application who's sole job is to pull data from untrusted sources and parse it will be vulnerable to security problems resulting from buggy code. Period. End of sentence.

    OS X ... please. The "it's not as popular" theory as to the lack of OS X viri and worms has been beaten to death over and over. Simple fact is the difficulty would make the first creator of an OS X virus or worm famous beyond anything another Windows worm would cause -- even if the spread wouldn't be nearly as bad. And yet, here we are, five years after the release, and not a single virus or worm that directly affects the operating system. Surprised?

    Despite that incentive, it has yet to be done. A rootkit is being touted as "proof of OS X's insecurity." Give me a break. If you can trick a user to type in their admin password with an application, it doesn't matter if you're running Windows, Linux, BSD, OS X, HP-UX, or Solaris -- you're going to get owned.

    Jesus, I hate security people. I just want to choke them.

  13. Re:Java. by andy_shepard · · Score: 5, Funny

    Saying that Java is nice because it works on all OS's is like saying that anal sex is nice because it works on all genders

    In other news, fans of anal sex everywhere protest the comparison to Java.

  14. dark future by Anonymous Coward · · Score: 5, Funny

    Symantec foretells a dark future for Firefox and Mac users...

    Whew, good thing I'm running IE 5.5 and Windows 98.

  15. Computer viruses like their biological counterpart by Yossarian45793 · · Score: 5, Insightful

    It should come as no surprise that computer viruses and worms tend to aim for control rather than destruction. This exactly parallels what happens with biological viruses and worms. A virus that destroys its host cannot propogate very far before becoming extinct. Viruses that damage their host but leave it good enough condition to continue transmitting it to other hosts are much more successful. The most successful viruses of all are those that go largely undetected and manage to spread to a majority of the population (think of sexually-transmitted diseases such as HPV).

  16. IMHO, Symantec has done more damage themselves! by King_TJ · · Score: 5, Interesting

    It makes me cringe whenever I hear Symantec making these "predictions" about potential attacks on computers.

    I have run into *countless* numbers of damaged Windows installations, directly attributable to Symantec's own products. Just last week, I struggled for hours with a customer's XP Home Edition because he was "having problems getting any streaming audio to work properly".

    Upon closer examination, the XP firewall was in a corrupt state, refusing to allow connections for his Internet radio stations. I was unable to view the advanced firewall properties, etc. After looking up event log error codes and trying several methods that repaired the problem for some people, it became obvious that I was looking at the result of a botched uninstall of a Symantec Personal Firewall or "Internet Security Suite" product.

    Not only can these things happen, but you'll often see computers with errors with the "32-bit subsystem" when going to an MS-DOS command prompt, due to Norton products screwing up system registry settings due to an improper/incomplete uninstall or installation/upgrade.

    Furthermore, when their anti-virus and "security suite" products do work properly, they still bring older, slower PCs to their knees in many cases. The "on-demand scanning" feature lags far behind the rest of the system when working with large numbers of small files (extracting a ZIP or the like), causing a window to constantly pop up, informing you to "please wait" while it scans them... And their "activation" process they now require for their AV products in Windows is every bit as bad as Microsoft's XP activation procedures! I remember purchasing a 25-pack of OEM Norton AV licenses last year, only to find that 6 or 7 of the key codes refused to work, claiming they were "used too many times" or the like. (I guess pirates with keygens hit upon them already or something?) Thiis is *not* the type of B.S. you want to fool around with when you're on a client site, getting paid by the hour to fix a virus problem for them!

    I won't even go into the disk corruption their "Disk Doctor" for Macintosh did to MANY customers after they upgraded to newer versions of OS X and Symantec didn't keep up with needed changes/patches to the product!

    Their company went down the tubes ever since Peter Norton quit coding their products and started getting royalties for having his photo thrown on the front of the packages.

  17. Register.uk's publishing Symantec's adware by DECS · · Score: 5, Insightful

    Symantec is publishing a self serving press release full of intentional lies as a news item, and idiot news outlets like the Register are publishing it without criticism.

    Shame on both!

    How about reporting:

    "Symantic issued an official sensationist panic warning to Mac users who have not bought their product. It is unclear how Symantec's products will secure the Mac platform from exploits, since they do nothing to secure a system from a user with physical access. The company may also consider selling volcano insurance and eating babies"

    From the actual Register story:

    "While the number of vendor-confirmed vulnerabilities in OS X has remained relatively constant during the last two reporting periods [12 months], Symantec predicts this could change in the future. Symantec's analysis on a rootkit (OSX/Weapox) reveals it is designed to take advantage of OS X. This particular trojan demonstrates that as OS X increases in popularity, so too will the scrutiny it receives from potential attackers."

    So Symantec:
    - is shy to report that there are no exploited vulnerabilities
    - analyzed a OS X root kit and determined it ran on OS X
    - thinks the adware/malware market, driven by demand for easy to zombify PCs, is somehow poised to launch specialized attacks on inherently secured systems via non-replicating trojans that require root access to install.

    Which is worse, Symantic's bullshit misinformation, or the Register's uncritical dissemination?

  18. And that is why you'll continue to see these. by khasim · · Score: 5, Insightful
    The "experts" writing these "articles" will be out of a job as security increases.

    From TFA:
    According to the latest edition of Symantec's Internet Security Threat Report, 25 vulnerabilities were disclosed for Mozilla browsers and 13 for Microsoft Internet Explorer in the first half of 2005.
    And that statistic means absolutely nothing. Simply counting the vulnerability ANNOUNCEMENTS does not tell you anything about the vulnerabilities themselves.

    Is a vulnerability that causes FireFox to crash the same as a vulnerability that automatically installs an ActiveX control? Nope.
    Graham Pinkney, head of threat intelligence EMEA at Symantec, said that switching from IE to Firefox as a way of minimising security risks was no longer valid advice.
    Yeah. Whatever. How about you do a survey and find out how many FireFox machines have been compromised via FireFox? Huh? How about that?
    "Cross-site scripting attacks have been used to attack more vulnerabilities in Mozilla browsers over the last six months than IE," Pinkney told an IDC security conference last week ahead of the publication of Symantec's threat report today.
    And he has determined that ... how?

    Seems to me that IE's still being hit by spyware and such crap. Or didn't he mean those attacks?
    John Cheney, chief executive of email filtering firm BlackSpider, replied that the release of Firefox had "helped Microsoft to raise its game" in terms of browser security.
    "We sincerely thank the person who killed our daughter because it makes us appreciate our son so much more now." Does that make sense to anyone?
    As well as making comments that will doubtless irk Firefox fans, Symantec has renewed its assault of the perceived security advantages of Apple Macs.
    Hmmmm, Symantec sells anti-virus software and the like.

    Macs don't seem to be having massive virus/trojan/worm problems.

    Something doesn't look right.
    "Mac users may be operating under a false sense of security as a noteworthy number of vulnerabilities and attacks were detected against Apple Mac's operating system, OS X," Symantec said, reflecting comments in the previous edition of its threat report that OS X was an emerging target for attack.
    When "emerging" becomes "successfully attacked and cracked" it will become an issue. Until then, the "threat" is purely theoretical.
    "While the number of vendor-confirmed vulnerabilities in OS X has remained relatively constant during the last two reporting periods [12 months], Symantec predicts this could change in the future."
    Again, it isn't the number of vulnerabilities, it's how they can be exploited.

    Yet I keep seeing references the the NUMBER of vulnerabilities announced.
    Symantec's analysis on a rootkit (OSX/Weapox) reveals it is designed to take advantage of OS X.
    #! /bin/bash
    cd /
    rm -R

    Oh my GOD!!! It's a trojan that is designed to exploit the bash shell on LINUX!!!
    "This particular trojan demonstrates that as OS X increases in popularity, so too will the scrutiny it receives from potential attackers."
    As does my example with regards to bash and Linux.

    It isn't whether someone can write a virus/worm/trojan. It's whether they can get such onto your box.
    Away from the desktop, Microsoft enterprise applications remain the top hacker target.
    Why "away from"?

    Aren't they also the top target on the desktop?

    How about "As well as the desktop, Microsoft's enterprise apps are targets for attack"?

    Nothing but more crap from a vendor who's seeing their gravy train getting ready to leave the station on its last run.
  19. Opt-In ActiveX is the best IE feature, ever by quazee · · Score: 5, Informative

    This, in fact, should reduce the IE's attack surface several-fold.

    MS has made a huge mistake when IE 4.x-6.x relied on CATID_SafeForScripting/CATID_SafeForInitializing COM component categories to make decisions whether it's safe to use the COM component from a JavaScript/VBScript.

    CATID_SafeForScripting is not needed when the COM component is accessed from a stand-alone .VBS/.JS script stored on the local machine (which is trusted to do anything anyway), yet a lot of MS and third-party components is in CATID_SafeForScripting for no reason at all.

    IE has a kill bit feature which allows disabling certain scriptable COM components based on their GUIDs. And most IE security fixes are, in fact, just registry updates adding more of those "kill bits".

    Examples: http://www.microsoft.com/technet/security/bulletin /fq99-032.mspx
    http://www.microsoft.com/technet/security/bulletin /fq99-037.mspx
    http://www.microsoft.com/technet/security/Bulletin /MS02-055.mspx
    http://www.microsoft.com/technet/security/Bulletin /MS02-065.mspx
    http://www.microsoft.com/technet/security/bulletin /ms02-055.asp
    http://www.microsoft.com/technet/security/bulletin /ms03-038.asp
    http://www.microsoft.com/technet/security/Bulletin /MS03-038.mspx
    http://www.microsoft.com/technet/treeview/?url=/te chnet/security/bulletin/MS03-038.asp
    ... and many-many-many more of these holes (just search for "kill bit" with the quotes)

    --
    throw new SuccessException("Sig read successfully");
  20. McAffee is even worse by Moraelin · · Score: 5, Interesting

    Well, I won't disaggree with you on the whole. It in fact mirrors my own thoughts and observations.

    I once got a computer virused intentionally. (That was the only Windows virus I ever got, btw, so if anyone wants to start with the canned "Windows has viruses, use Linux instead" answers, spare your breath.) I was installing Windows 2000, had no firewall handy, and thought I'm too lazy to go buy a firewall or go burn Zone Alarm on a CD on someone else's computer. Also, I didn't know yet that I could just activate the built-in poor-man's firewall (yes, you can tell Windows 2000 to not allow incoming connections) to stay safe until I download the updates and a firewall. So, anyway, I thought I'd let it get virused while I download the firewall, then format and reinstall. It's not like 20 minutes extra are a major catastrophe.

    So predictably it does catch an RPC buffer-overflow virus while downloading Sygate Personal Firewall. Then I block it from connecting to the network and play with it a little. It got me curious.

    You know what was sad? It actually slowed the computer a lot less than Norton. You know what's sadder? Installing Norton and running a full scan didn't catch it anyway. It just slowed down the computer some more.

    But still, Symantec isn't _the_ worst. Try McAffee sometime if you're masochistic. Not only it was even less efficient and slower, but also had such gems as:

    - needed IE to download its updates, because it used some ActiveX crap, but it was too stupid to just launch IE, then. It launched the default browser, in this case Opera, and then couldn't get itself updated. That sad.

    - it was installed on D: but the updates proceeded to install themselves in the default directory on C:. Worse yet, I wasn't just left with just an extra copy on the hard drive, but had two versions running in RAM at the same time.

    - this got even funnier later when I uninstalled it, because one of the two versions remained installed and auto-loaded. I had to edit the registry to stop it. (If you thought only spyware has to be removed that way, McAffee is obviously the counter-example.)

    - their "privacy" protection basically did nothing but try to protect me from cookies, including temporary login cookies on web sites. I suddenly couldn't use any sites that required login. Not even in a consistent and predictable way. E.g., Gamespy's Fileplanet got terminally confused and different pages thought that I was logged in and not logged in at the same time.

    And so on and so forth. That was a rather non-funny experience.

    --
    A polar bear is a cartesian bear after a coordinate transform.