Slashdot Mirror


Future Trends of Malware

An anonymous reader writes "What are the driving forces behind the rise of malware? Who's behind it, and what tactics do they use? How are vendors responding, and what should organizations, researchers, and end users keep in mind for the upcoming future? All these questions and more are answered in the well written (MHO) Future Trends of Malware"

48 of 179 comments (clear)

  1. 56% increase in trust in AntiVirus by CrazyJim1 · · Score: 5, Insightful

    It seems like parents everywhere trust their AntiVirus to stop everything. When they get spyware, and you tell em you got to remove it, they'll retort,"Oh, just run Mcaffee". The funny part that we all know here is that there are too much malware out there for one Antivirus software to stop and they keep coming. To me, Antivirus software seems a lot like SnakeWater.

    1. Re:56% increase in trust in AntiVirus by Beatbyte · · Score: 2, Insightful

      If they run Mcaffee, they deserve it. ;)

      note: I can too make fun of all antivirus companies. I run debian.

    2. Re:56% increase in trust in AntiVirus by igb · · Score: 4, Interesting
      I'm not quite sure what `parents' has to do with it. A huge proportion of the population, with or without children, falls into one of three categories:
      • They don't know spyware or viruses from a hole in the ground, and they either re-install or buy a new computer every time their machine gets too slow
      • OR they believe their firewall and/or AV product is total protection, and they convince themselves that their machine isn't slow and isn't behaving badly, even when it it
      • OR they simply accept that computers are shit and tolerate it running badly.
      A certain sort of quasi-autistic geek then makes snotty comments and plays ``blame the victim'' by pointing out all the measures that the victim could have taken. The real solutions are:
      • For operating system vendors to sort out their problems. Oh, OK, for one particular OS vendor to sort out its problems.
      • For law enforcement to stop treating the perpetrators as cute kids, and actually do something serious about the issue.
      Blaming the victim just isn't on. `We' (ie people who provide computer and telecommunication services) sold them a machine. It's up to us to make sure it behaves reasonably. There's an ``Unsafe at Any Speed'' brewing, if but we could see it.

      ian

    3. Re:56% increase in trust in AntiVirus by dc29A · · Score: 3, Informative

      note: I can too make fun of all antivirus companies. I run debian.

      I haven't installed an anti-virus software on my home PC and laptop for over 3 years now (both running Windows). Never had any problems either. I just follow a few paranoid steps:
      - Firewall the machines router + laptop has software firewall.
      - Avoid IE like the plague.
      - Avoid Outlook Express like the plague.
      - Try as much as possible using a limited rights account instead of root. For some games and apps it doesn't work but for most mundane tasks like browsing, video, mp3 playback it works great.
      - VMware or VirtualPC is your friend if you want to run code from ugh *cough* warez sites *cough*, but as a general step, I refuse to open any email attachment that isn't an image, video or hyperlink from a trusted source (ie: someone emailing a funny image to group of friends). I treat every email attachement that I receive on my home PC as a virus. I then lower the severity of it based on file type.
      - Firefox + Adblock = golden.

      Is it perfect? Nope but paranoid surfing habits as in don't click on "OMG YOUR PC IS SLOW SPEED IT UP" flashing crap helps, or when you get to a pr0n site and it offers you a plugin.exe it might also be a bad idea to execute it.

    4. Re:56% increase in trust in AntiVirus by drsmithy · · Score: 2, Insightful
      With all that crap, isn't it time you thought about another operating system?

      Seems to me he's following the same procedures any sensible person would _regardless_ of the OS - run as a limited user, avoid buggy software and don't execute code from questionable sources.

  2. The goggles do nothing. by orthogonal · · Score: 5, Funny

    I'm sure it's a great paper. But when it's presented as black and sky blue text on a purple background, reading it is almost like having my eyes infected with malware.

    1. Re:The goggles do nothing. by wild_berry · · Score: 2, Insightful

      It's not a great paper. A great paper would have been written clearly (and not submitted by it's author: that's how I'm interpreting the Anon's "All these questions and more are answered in the well written (MHO) Future Trends of Malware").

    2. Re:The goggles do nothing. by kent_eh · · Score: 2, Informative

      Or you could disable the stylesheet (alt-V-Y-N) to read the liked page in glorious, high-contrast, whatever your defaults are.

      --

      ---
      "I can't complain, but sometimes still do..." Joe Walsh
    3. Re:The goggles do nothing. by Ravenscall · · Score: 2, Funny

      It is well written if you are schizotypal.

      --
      You say you want a revolution....
  3. Key summary points and conclusion by millwall · · Score: 5, Insightful

    Key summary points
    --------------
    Malware authors update their multi-vendor anti virus signatures faster than most end users and enterprises do altogether

    The high pressure put on malware authors by the experienced vendors is causing them to unite efforts and assets, and realize that it's hard to compete on their own. Yet this doesn't stop them from waging a war in between

    Intellectual property theft worms have to potential to dominate in today's knowledge-driven society acting as tools for espionage

    Don't matter what you always wanted to do to ecriminals, in case of a cryptoviral extortion, you'll be the one having to initiate the contact

    The growing Internet population, E-commerce flow, and the demand for illegal/unethical services, would fuel the development of an Ecosystem, for anything, but legal

    The "Web as a platform" is a powerful medium for malware attackers understanding the new Web

    The unprecedented growth of E-commerce would always remain the main incentive for illegal activities

    7.0 Conclusion
    --------------

    I hope that the points I have raised in this research, would prove valuable to both end users, businesses and anti-virus vendors. The Internet as a growing force shaping our ways of thinking and living is as useful, as easy to exploit as well. The clear growth in E-commerce, today's open-source nature of malware, the growing penetration of the Internet in respect to insecure connected PCs, are among the main driving factors of the scene. Do your homework and stay ahead of the threats, most of all, less branding when making security decisions, but high preferences! Please, feel free to direct your opinions, remarks, or any feedback to me, at dancho.danchev AT hush.com or at ddanchev.blogspot.com where you can directly comment on my publication. Nothing is impossible, the impossible just takes a little while!

  4. Botnets and Zombie hosts by IAAP · · Score: 2, Insightful
    FTFA: Hundreds of thousands of fully controlled Internet connected hosts, with amazing bandwidth, storage and sensitive information stored within could be easily utilized to perform the majority of security attacks we are witnessing these days.

    Would it be possible, if for instance, an ISP sees a shit load of traffic from a customer's address directed at another address to start blocking that traffic? Or at the very least notifying the customer that there may something wrong. I bet just about everyone whose computer has these bots are comletely unaware. They might even bitch about how slow their connection is.

    I'm already thinking of the ethical and privacy issues involved with doing that, but it would stop some of the DOS extortion.

    1. Re:Botnets and Zombie hosts by daringone · · Score: 3, Informative

      Funny you mention that, because once they're infected, the spam barrage usually comes next. At our company, (an ISP) it takes less than a day to see the complaints from these people. They're then notified that *something* is wrong, and they need to look at it. If it isn't fixed, we usually call them then. If they continue to ignore the problem, they're disconnected until we can look at the computer. At that point, it's a willful TOS violation for spamming, even if they aren't the real spammer since the messages are coming from their machine.

    2. Re:Botnets and Zombie hosts by J.+T.+MacLeod · · Score: 2, Interesting

      At my company, when we see virus/spyware activity, we call the customer and give them instructions on how to fix it. If it recurs or doesn't get fixed--or if we can't get in touch with them and it's particularly nasty--we'll shut off service and require that we verify the computer is clean before turning their service back on.

      Which sounds pretty strict, except that we'll clean their computers for free.

    3. Re:Botnets and Zombie hosts by burnin1965 · · Score: 2, Insightful

      " if for instance, an ISP sees a shit load of traffic from a customer's address directed at another address to start blocking that traffic? Or at the very least notifying the customer "

      Notification is fine, but I would be very pissed if my ISP decided on their own to block traffic from my address based on an incorrect assumption that the traffic from my address was from an exploited host. My ISP actually did notify me once about their concern for traffic volume from my address and after I explained the situation to them I've never received another notification.

      I have some sympothy for the vast majority of the internet population who lack the knowledge or skill to lock down the crap shoot of an OS most of them run, but there are better solutions that will not impact those of us who utilize large amounts of bandwidth and are not host to malware.

      1) If you can't lock down your Windows box yourself or install and use linux, buy a Mac.

      2) If an ISP wants to help their customers with malware issues by blocking traffic, create an opt in program rather than assume all customers are clueless.

      Leave my net alone,
      burnin

  5. How do we stop it? by Reverend+Darkness · · Score: 2, Funny

    ... you know, my Uncle Jim used to say that a lot of problems in the world could be solved with a .22 to the back of the head...

    --
    ... elipses...
  6. Exclamation Replication! by digitaldc · · Score: 5, Funny

    I counted 45! exclamation points in that article!

    Now after reading it, I have become so depressed that I have decided not to connect my computer to the internet ever again!!!

    --
    He who knows best knows how little he knows. - Thomas Jefferson
    1. Re:Exclamation Replication! by geobeck · · Score: 2, Funny

      "Multiple exclamation marks are the sign of a diseased mind."
      --Terry Prattchett

      --
      Find environmentally and socially responsible products on http://buy-right.net
  7. Extremely thorough, except... by Billosaur · · Score: 2, Insightful

    ...they forgot VoIP. Amazing oversight really. How long before someone hacks Skype and manages to insert malware code into the VoIP data stream? You place a call to someone and somewhere along the way extra data is inserted and finds its way onto your machine. I'm not that knowledgeable about VoIP's inner workings, but it seems to me that anything that allows data to be moved back and forth from your computer unfettered is a doorway for malware to be lodged on your machine.

    --
    GetOuttaMySpace - The Anti-Social Network
  8. Is this a college paper? by kook44 · · Score: 4, Insightful

    Horribly written, lots of (mostly) un-referenced statistics without any analysis. Rambles on without any real point. Anything groundbreaking here?

  9. One word: Legitimization. by Caspian · · Score: 4, Insightful

    Malware meets so many of the deep desires of the marketing world (and the corporate world in general). It can provides market data in bulk, practically "for free" (from the company's perspective). It can provide a further degree of control over a user's computer. It can enforce DRM. It can force ads on people.

    Thus, I can only conclude that the future of malware is for it to go from something created by shady companies like Gator (a.k.a. "Claria") and 419WebSolutions (or whatever) to something created (or at least branded) by "household name" companies like HP, Dell, etc. A first step towards a future in which major corporations embrace malware has already occurred; just look at all the crap Dell shovels onto their much-maligned default software installations.

    --
    With spending like this, exactly what are "conservatives" conserving?
    1. Re:One word: Legitimization. by bhima · · Score: 3, Insightful

      Over the course of the past 2 years my entire extended family has switched to Apple products. I find it interesting that well over half of them have not installed a single package beyond what is on them to begin with. And *ALL* of them objected to the useless and annoying crap on their previous big name WinTel boxes.

      Why is it that Apple can figure out what regular people want and HP & Packard Bell saddle people with crap?

      --
      Nothing in the world is more dangerous than sincere ignorance and conscientious stupidity.
    2. Re:One word: Legitimization. by Caspian · · Score: 5, Insightful

      Oh yes, I almost forgot! Another word: "Sony". Their rootkit is the future. Sure, people bitch now, but in time, the companies will either find a "compromise" solution that infuriates people less (for instance, a rootkit without horrific security flaws), or simply establish rootkits and other malware as the "industry standard", critics (read: angry geeks) be damned.

      --
      With spending like this, exactly what are "conservatives" conserving?
    3. Re:One word: Legitimization. by BushCheney08 · · Score: 2, Insightful

      Why is it that Apple can figure out what regular people want and HP & Packard Bell saddle people with crap?

      And this is one of the big reasons why Apple machines tend to cost a bit more. Bear in mind that HP and Dell and whoever else get paid to include the trialware and crippled versions of apps on their machines. They then turn around and pass the savings on to you, the consumer! They call it "adding value" to the machine. I call it loading it up with useless crap.

      --
      Be a real patriot: Question authority. Think for yourself. Formulate your own conclusions.
  10. Re:Daemon Tools by Matt2k · · Score: 2, Interesting

    Greed? You mean the selfless devotion of time to a project that no one will pay you for?

  11. P2P worms? by sczimme · · Score: 4, Insightful


    From the article:

    modular - new features are easily added to further improve its impact, want it to have P2P propagation capability, add it, want it to disseminate over IM, done.

    Okay, malware can be modular - makes sense.

    The lack of P2P worms is, I think, a logical consequence of the RIAA's busts around the U.S, and the global response towards P2P networks copyright infringement.

    How did the author manage to come to that "logical" conclusion? How is the presence (or !presence) of malware related to the "global response... copyright infringement"?

    Given today's P2P concepts, and the disruptive BitTorrent technology, it is not longer required to on purposely slow down transfers to hide the activity on a user's host.

    And where the heck is he going with this??

    Submitter, if this is your idea of "well written", I respectfully suggest you broaden your literary scope.

    --
    I want to drag this out as long as possible. Bring me my protractor.
  12. What if we sandbox major apps like browsers? by Dr.+Manhattan · · Score: 4, Insightful
    We already put servers in their own groups (e.g. an httpd running as "www-data" or something). What if we made similar limitations for user-level apps. Something like this.

    user1 is member of group "users" and "user1group", "user1Firefoxgroup", etc.

    Firefox is user "user1Firefox" and a member of "user1group" and "user1Firefoxgroup".

    Thunderbird is user "user1Thunderbird" and a member of "user1group" and "user1Thunderbirdgroup".

    In /home/user1 is a directory called "protected_applications" owned by user1:user1group with "rwxr-x---" permission. General config information common to all apps goes in here, probably only readable, not writable, by "user1group". Below it are subdirectories like "Firefox" (owned by "user1Firefox:user1Firefoxgroup" with permissions "rwxrwx---". Maybe some sticky bits set.

    This way the apps can only write to and read from their own little subdirectory tree, and not any of the others, but the main user can read and write to any of the subdirectories.

    It wouldn't solve everything, but it would help limit further the damage malware could do. It could access (and corrupt) the data for the particular application it suborned, but without exploiting secondary holes it couldn't do more. This would prevent, say, a hole in Firefox from allowing malware to get at your Gnucash data. It also doesn't require much any new permission-checking code, the kernel already does file-access checks anyway.

    --
    PHEM - party like it's 1997-2003!
    1. Re:What if we sandbox major apps like browsers? by Jasin+Natael · · Score: 2, Insightful

      Yeah. One flaw: You're assuming that the host operating system has support for UNIX-style user account restrictions. Windows could do something similar if they were to add an "Always Run As..." option, and users were smart enough to set it up, but it would be a hack at best. My guess is that as soon as support for this approach is implemented, even if the security part itself were *bug-free*, it would be a week at most before someone found an exploit to allow them to march out of the sandbox and into the system account.

      Running even the best-designed software on top of Windows is like building a nice house on a plot of land that is prone to develop sinkholes. You can keep filling in the holes, and you can keep patching up the house, but eventually the whole thing is going to cave in, or break the bank. And it won't be very comfortable to live in.

      With the above analogy, the current state of Windows is that things have gotten so bad, you're paying the crew foreman to live in your guest bedroom full-time. He (and his boss) keep telling you, "You should have used better plaster so it wouldn't crack", "You should have used steel beams in the floor slab", "You really needed stronger mortar to hold those bricks together". But what you really should have done, is put your house on a f***ing solid piece of land. It defeats the point of having an operating system when you can't depend on any of its facilities.

      Jasin Natael
      --
      True science means that when you re-evaluate the evidence, you re-evaluate your faith.
    2. Re:What if we sandbox major apps like browsers? by IntlHarvester · · Score: 2, Insightful

      (A) You are trying to kludge Unix Permissions onto a siutation where a new model is required. Unix Groups are already a nightmare and this sort of thing would just makes it worse. How would you save a file from your web browser without a nightmare of permission settings?

      Furthermore it doesn't do what you want: Exploiting "user1Firefox:user1Firefoxgroup" is good enough to send spam and DoS attacks.

      Check "Capabilities"-based systems that do what you really want. They've been around for a while.

      (B) Users want Data Exchange between applications. Firefox need to talk to plugins like Java and RealPlayer. People want to embed spreadsheets into word processor documents. You need rich-copy-paste. You need to be able to script apps and pipe output. All of these Data Exchange vectors would undermine your permission system.

      --
      Business. Numbers. Money. People. Computer World.
    3. Re:What if we sandbox major apps like browsers? by Kadin2048 · · Score: 2, Interesting

      Well put -- I like the analogy.

      Actually I think what people are doing today, is practically building another guest house out back for the foreman and the rest of his work crew to live in while they're patching up your house. Remember the discussion a few months ago here on Slashdot about why the average joe needed a dual-core or multiprocessor Windows box? It was so one processor could run his actual application, and the other one could run all the anti-virus/spyware/adware/intrusion programs.

      The situation has really become ridiculous, but because it's happened so slowly and because so many people are highly invested in it, nobody with any authority wants to take a step back and call it for what it is.

      --
      "Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
  13. Seems kind of pointless... by Nephroth · · Score: 4, Insightful
    They put an an awful lot of effort into saying something that could be summed up in just a few words:

    Malicious software can make money now, that which makes money attracts sellers.

    It's that simple, whereas in the past malware was mostly out of a quest for fame or percieved revenge, the malware of today is business malware, the nasty programs of old all dressed up in suit and tie and making someone filthy rich.

    This problem is exacerbated by the fact that nearly everyone runs Windows XP these days and Microsoft wasn't very attentive to security when they designed it. The sheer number of critical vulnerabilities that the operating system has is mind boggling. Recently, it was stated by some firm or another that Linux had released more patches than any other OS this year. Now, aside from the obvious problem with that statement (the patches weren't patches for Linux itself but for software in common Linux distributions, which is vastly greater in number than that of a Windows installation) if you look at the things patched, they aren't terribly dangerous. They are things like "potentially vulnerable to DNS attack" or "Local user can gain partial root privileges" and such, they are not like "Someone on the other side of a planet can send you a magic packet that makes your computer their bitch permanently," which is what the vast majority of Windows vulnerabilities allow.

    In short, malware has grown because malware is like any pathogen, it lies in wait until conditions are optimal for its growth and when they are it takes over quite rapidly. Remove one of its primary growth factors, and you'll slow it down. Remove more, and you'll potentially kill it.

    --
    Our greatest enemy is neither a single man, nor is it a nation, it is, as it has always been, our own greed.
  14. Well written? by Caspian · · Score: 3, Funny

    My God, the grammatical errors in that paper are painful. Is a paper displaying such an appalling lack of quality really worthy of the attention of hundreds of thousands of SlashDot geeks?

    --
    With spending like this, exactly what are "conservatives" conserving?
  15. simple solution by g-to-the-o-to-the-g · · Score: 3, Insightful

    Its really easy to fix: don't use winders

  16. Malware is becoming dangerous by Mr.Fork · · Score: 4, Insightful

    From my point of view, a security specialist, is that only 20-30% of the attacks on businesses and corporations are done electronicly from the outside, the rest (70-80%) are inside, mostly disgrunted employees. With the current trend of money/public focused companies treating employees like crap, all it would take is a vicious malware application to take them down.

    Malware is also becoming intelligently designed, no longer the 'see-this-famous-tennis-star-naked so-I-can-use-built-in-vbs-code to-email-everyone-in-your-addressbook' stupid-is-as-stupid-does tricks. They're pointed, direct, and very very scary.

    Here's to paying and treating your geek employee well!

    --
    Management is doing things right; leadership is doing the right things. - Peter F. Drucker
    1. Re:Malware is becoming dangerous by WhiteWolf666 · · Score: 4, Funny

      Malware is also becoming intelligently designed

      Are you sure its not evolving?

      Ba-duh-chick!

      --
      WhiteWolf666 an exBush supporter. All you new-school,compassionate,save the children Republicans can rot in hell
  17. WTF does this mean? by gkuz · · Score: 3, Insightful
    FTFA: "Do your homework and stay ahead of the threats, most of all, less branding when making security decisions, but high preferences!"

    Could the person who called this article "well-written" be so kind as to tell me what this means? The article is filled with crap like this; I'd give it a C-, at best, as a freshman paper.

  18. Categories by goal by G4from128k · · Score: 4, Interesting
    Malware can be categorized by the goal of the creator. This can include:
    1. Marketing: Redirecting browser windows or overlaying pop-ups to promote a product or service
    2. Phishing: attacking an individual to extract passwords that let a criminal access the victim's accounts or identity
    3. Vandalism: Wanton destruction of a PC or network
    4. Spam Broadcasting: creating and controlling a botnet for spamming
    5. Extortion: Forcing a company to pay a ransom to avoid a DDoS or the triggering of an embedded bit of malware.
    6. Vilgilantism: Attacking P2P, spamming, or phishing networks to forestall perceived illegal activity
    7. Espionage: Illegally accessing company or country's secrets
    8. Military: Damaging an opponent country's IT infrastructure

    Note that some of these goals target individuals and their PCs whereas other target larger organizations. One key commonality of nearly all of the goals is that they target large numbers of PCs or require large numbers of infected machines to achieve the goal. Thus immunological approaches that look for the spread of unusual code or data packet patterns can help address this problem. On the other hand, immunological approaches won't work if the malware attack targets a single individual or company -- e.g. implanting a unique virus in one computer in a company for purposes of espionage or extortion.

    Note that half of the goals are very different from the stereotypical destructive virus or worm of yesteryear. With the exception of vandalism, extortion, vigilantism, and military, the other goals are essentially non-destructive. The malware creator's goals are not achieved if the malware crashes the target machine.
    --
    Two wrongs don't make a right, but three lefts do.
  19. Biometrics & RFID by TFGeditor · · Score: 2, Insightful

    I think the ultimate future of malware will encompass biometric and RFID. Rather than key loggers, we will see biometric image capture (e.g. a scan/image capture of the user's thumbprint). Or capturing RFID patterns.

    I still say purveyors and criminal users of malware should be subject to life prison sentences if not death.

    --
    Ignorance is curable, stupid is forever.
  20. Wrong approach altogether by h_benderson · · Score: 2, Insightful

    Anti Virus companies will always be slower than malware writers. The whole signature-based antivirus approach is fundamentally flawed. The solution? Either by using heuristics (could get pretty difficult), or don't allow the malware to get onto your machine in the first place. That shouldn't be too difficult, if you think about it.

    With a multiuser system that actually enforces permissions, it's your fault if you click on that attachment. And the only thing that happens is you lose your home dir. I agree that using your personal data this way is much worse than losing system data, but it is also much more educating. If it happens to you once, you'll remember when you get the next suspiciously looking email. On the other hand, if your system slowly goes down due to the number of malware you have installed, you curse the vendor (M$), but you don't realise it's your own fault.

  21. Re:Daemon Tools by badfish99 · · Score: 2, Interesting
    Absolutely no right?

    So (for example) did nobody have any right to say that Sony should not include a rootkit in the software on their CDs? Does nobody have the right to say that Microsoft Windows should be better quality? If some software destroyed your hard disk, would you just say "it's a blessing that I could have chosen not to install it"?

  22. Re:Daemon Tools by The+Ultimate+Fartkno · · Score: 2, Funny

    > when the author suddenly decides that free doesn't pay the bills

    I don't think he decided it as much as he *realised* it.

  23. It's not just a technical problem by FishandChips · · Score: 2, Interesting

    So far, malware has been treated as an IT/commercial problem (which is what this article does), but it has become so pervasive and costly that it is also now a political problem. The barely fettered growth of malware - its sheer scale, organization and the amounts of money involved - raises a lot of questions about privacy, international cooperation and what to do about the internet itself. I don't think it's something that the IT industry can tackle on its own. You can have as much protection as you like, but so long as malware outfits can slip through 1001 transnational loopholes and exploit safe-haven jurisdictions there will always be a serious problem.

    I don't pretend to know the answers, but waving a copy of Norton Internet Security at the bad boys isn't it, for sure. Perhaps there is an element of deliberate wimping out going on here. The IT industry doesn't want to admit it cannot solve things alone, because it doesn't want politicians and regulators muscling in. And politicians like to pretend that malware is purely an IT problem because they don't want the headache of involvement in sorting out the mess.

    As one result, perhaps, domains ending in letters like .ru or .ro can apparently do what they like, and some notorious spammers and phishers remain on Top 50 lists for years without anyone so much as slapping their wrist. In previous centuries, the whole thing was called "piracy" and states tackled it with, erm, "extreme prejudice". Sometimes, I feel they may have been on to something.

    --
    Las qué passoun
    tournoun pas maï
  24. Re:Daemon Tools by HappyDrgn · · Score: 3, Insightful

    "did nobody have any right to say that Sony should not include a rootkit in the software"

    You're comparing apples to oranges here. The difference with Daemon Tools is that it gives you an option to not install additional software and when you tell it no thanks that is the end of it. In the case of Sony's rootkit however there was no option to not install this extra software. The problem most people have with this is not that the software was there in the first place, but that the installer used vague wording to conceal what will actually be installed and if you told it not to install the software it did it anyway.

    "Does nobody have the right to say that Microsoft Windows should be better quality?"

    Yes. With your pocket book. You may be able to do the same with Daemon Tools. The author is obviously looking for some kind of compensation for untold hours of hard labor. Why not make a donation for the days, weeks, years of use you got out of it? Alternatively, as someone else suggested, why not ask the author to make a paid version instead of including extra software? Just because it's free does not make it afraid of money.

  25. Two Words: Titan Rain by mosel-saar-ruwer · · Score: 2, Interesting

    money

    Look, money is a perfectly fine motivation for script kiddies and Nigerian scam artists and ex-KGB Russian/Ukrainian mafiosi.

    But there's an outfit sitting behind a router in the PRC that has a different motivation; something along the lines of "Geopolitical World Dominance":

    The Invasion of the Chinese Cyberspies
    (And the Man Who Tried to Stop Them)

    ...The hackers he was stalking, part of a cyberespionage ring that federal investigators code-named Titan Rain, first caught Carpenter's eye a year earlier when he helped investigate a network break-in at Lockheed Martin in September 2003. A strikingly similar attack hit Sandia several months later, but it wasn't until Carpenter compared notes with a counterpart in Army cyberintelligence that he suspected the scope of the threat...

    http://www.securityteam.us/article.php/20050829200 849601/print

    http://it.slashdot.org/article.pl?sid=05/08/28/174 5245

    It's kinda like the board game "Risk", only this is the real McCoy.

  26. Re:Daemon Tools by baadger · · Score: 2, Insightful
    Installing Daemon Tools and then being given the option to opt out of crapware is not the same as, nor does it even compare to:

    • Sony BMG's rootkit installing itself without user intervention
    • The software being of a poor quality. You're Windows analogy suggests essentially that Daemon Tools is now a totally useless or inferior, or somehow less valuable, product just because it is now bundled with some optional junkware. If the software was of a poor quality you wouldn't be installing it, crapware or not.
    • Something 'wrecking' my hard drive. Daemon Tools doesn't, and even if I installed it's crapware it still wouldn't.


    All the examples you give, and infact your entire reply, are about the right and individual has to bitch about something bad that has happened to them. And you can bitch if you're so inclined, I never said grandparent couldn't say it's a damn shame, and that he now has a different opinion of D-Tools or it's author. I was merely pointing out in my first post that Barik should be bloody grateful Daemon Tools is not as bad as any of the examples you give.

    On a tangent, your Windows/OS analogy could be better served by Linux. You pay for Windows one way or another, therefore you expect, have some kind of mediocre right to receive, or atleast can acceptably demand, a level of service, maintenance or warrenty with the product. The Linux kernel on the other hand, I believe, is explicitly distributed with "absolutely no warranty, whatsoever". The quality of the product, in reality, is irrelevent to your point.
  27. Re:Daemon Tools by barik · · Score: 2, Interesting

    Yes, it does annoy me that much. If an author is willing to include spyware in the first place, what else are they willing to do with their software? When you download a piece of software, you expect that software, and not random bundles of non-related software.

    You are correct that I have no right to say what the author can and cannot do. I can simply choose not to use the software anymore, which I have done. And in this case, since it for corporate use, I can vote with my wallet as well.

  28. Yawn. by TheLink · · Score: 2, Insightful

    That's what they call future trends? If that's right we're pretty safe then.

    What would be interesting would be malware written in popular high level scripting or bytecode languages - e.g. perl, python, lisp. These do and will run on windows - with broadband becoming widespread it doesn't take long to download and run the relevant packed perl/python/lisp executable, and such executables do have legitimate uses anyway.

    You can very easily write games/utils in such languages to help them spread as trojans.

    It'll be interesting to see how the AV people will cope with these.

    An attacker should be able to rapidly generate multiple versions of the malware faster than the AV people can generate signatures.

    The malware can search for updates and download them with the help of search engines like google (google groups) and various blog/discussion sites. They might even be able to communicate with each other via spam email.

    I'm not even sure if the code signing stuff will help.

    After all the initial code could be innocuous with perhaps one or two really terrible "bugs". But subsequent code could be totally different. Because with such languages once the first bit is in, fetching and executing new code isn't as hard as downloading a new executable binary (which may require passing checks by the O/S and AV software), it's just downloading/finding the correctly identified/tagged string and running the equivalent of "eval" on it. Heck, one could just blindly run a string and catch the resulting exceptions if it's not proper code.

    I'm not a malware author, but I think most malware is rather primitive (esp those on windows[1]). I'm wondering how advanced the malware detection and prevention stuff really is.

    [1] I guess they don't need to be very sophisticated when the users actually do stuff like help enter the right passwords to unzip the malware and then voluntarily run the payload! Even better those users usually run as admin.

    --
  29. lack of security intentional? by fdisk3hs · · Score: 2, Interesting

    Has anybody looked into the idea that companies (such as pharmaceutical marketers) are paying Microsoft to not fix vulnerabilities? This is something that I've wondered about often, but never read anything about. A "Halloween Document" on this would be very interesting...
    A lot of users have asked me over the years if Microsoft is paid by antivirus companies not to fix vulnerabilities. This is apparently an easy leap of logic for the most untechnical folks. We know that pharmaceutical marketers are using bots to crawl and reap email addresses, as the Perl developer that tried to blow the whistle on them last year had his computers confiscated by the cops, who were sent by his employer to ensure a cover-up (stop their ex-employee from publishing company secrets using some kind of Industrial Espionage legislation). Sigh.

  30. No! by Belial6 · · Score: 2, Interesting

    If fingerprints ever start being widely used, muggers will just hit you over the head and cut off your fingers. They can check to see if you have a bank account later. If you think that there are not plenty of people that would cut your fingers off for the chance of a couple of hundred dollars, you are sadly mistaken, and a danger to the rest of society.