Slashdot Mirror


Interview With an Adware Author

rye writes in to recommend a Sherri Davidoff interview with Matt Knox, a talented Ruby instructor and coder, who talks about his early days designing and writing adware for Direct Revenue. (Direct Revenue was sued by Eliot Spitzer in 2006 for surreptitiously installing adware on millions of computers.) "So we've progressed now from having just a Registry key entry, to having an executable, to having a randomly-named executable, to having an executable which is shuffled around a little bit on each machine, to one that's encrypted — really more just obfuscated — to an executable that doesn't even run as an executable. It runs merely as a series of threads. ... There was one further step that we were going to take but didn't end up doing, and that is we were going to get rid of threads entirely, and just use interrupt handlers. It turns out that in Windows, you can get access to the interrupt handler pretty easily. ... It amounted to a distributed code war on a 4-10 million-node network."

92 of 453 comments (clear)

  1. Sometimes we forget. by jellomizer · · Score: 5, Insightful

    That the people who makes IT Guys lives difficult and annoying are indeed IT guys.

    --
    If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    1. Re:Sometimes we forget. by Anonymous Coward · · Score: 5, Insightful

      Im pretty sure that the majority of cops that became criminals were the hardest to catch. They know all the tricks and what other cops/detectives will be looking for.

    2. Re:Sometimes we forget. by fph+il+quozientatore · · Score: 5, Insightful

      [Sometimes we forget t]hat the people who makes IT Guys lives difficult and annoying are indeed IT guys.

      Or lawyers.

      --
      My first program:

      Hell Segmentation fault

    3. Re:Sometimes we forget. by snl2587 · · Score: 5, Insightful

      Difficult? Maybe, but for freelancers who collect a check every time they "fix" an infected computer (read: fiddle around for a while and ultimately end up reinstalling Windows), these crapware authors are the reason they can stay in business.

    4. Re:Sometimes we forget. by Thelasko · · Score: 4, Informative

      Im pretty sure that the majority of cops that became criminals were the hardest to catch. They know all the tricks and what other cops/detectives will be looking for.

      *COUGH*

      Allegedly

      --
      One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
    5. Re:Sometimes we forget. by MobyDisk · · Score: 5, Informative

      Talented computer repair techs can stay in business just fine. But yes, the adware/spyware boom caused an explosion in the repair field too.

    6. Re:Sometimes we forget. by Anonymous Coward · · Score: 2, Insightful

      Im pretty sure that the majority of cops that became criminals were the hardest to catch. They know all the tricks and what other cops/detectives will be looking for.

      Actually, they get caught by the criminals who became cops.

    7. Re:Sometimes we forget. by Opportunist · · Score: 4, Insightful

      Without malware writers, I'd be down a few 1000 bucks and would have to do something meaningful.

      Still, you may believe me when I tell you, I'd really prefer to write software people want to have to writing software people hate to have but grudgingly accept as a necessary evil.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    8. Re:Sometimes we forget. by Holi · · Score: 4, Insightful

      if all you end up doing is reinstalling windows then maybe you should be in a different line of work.

      --
      Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
    9. Re:Sometimes we forget. by SpaceLifeForm · · Score: 3, Insightful
      Add clearcmos, reflash BIOS, zero out the entire drive, then reformat, reinstall, and you should be clean.

      Until the user screws up again.

      Most of the battle is educating the users how to keep themselves clean.

      --
      You are being MICROattacked, from various angles, in a SOFT manner.
    10. Re:Sometimes we forget. by bensafrickingenius · · Score: 4, Insightful

      "if all you end up doing is reinstalling windows then maybe you should be in a different line of work."

      Hello, I understand you have a pretty serious malware problem. Well, here are your choices: I can spend 10 hours researching all of the hundreds of different problems you have, and fix them, and maybe I'll find them all, and maybe your computer will run ok for a while after that. Of course, if I do miss something, it's your financial information that gets stolen, not mine. That'll run you $300. Or I can just back up your data, format your hard drive, reinstall Windows, secure it in its virgin state, restore your data, and have you back up and running in half the time. For half the money. Oh, and when *I'm* done with your computer, it will run faster and more reliably than the day you bought it. What would you prefer?

      And, please, don't give me the "you must not be very good at what you do if you can't make a 5 year old install of windows work better than a sparkling clean one in 20 minutes" line. Your arrogance is making my eyes water.

      --
      I am not left-handed, either!
    11. Re:Sometimes we forget. by DigiShaman · · Score: 2, Interesting

      Computers are cheap.

      A new one can be purchased for about $500 bucks these days. It simply isn't worth cleaning up a major virus infection or re-installing the OS and applications. The billable time alone would exceed the cost of the machine! Basically, computers are one-trick ponies. Once they get infected, physically throw it away and buy a new one. We live in a disposable society and computer usage is no longer an exception that it once was.

      --
      Life is not for the lazy.
    12. Re:Sometimes we forget. by DiLLeMaN · · Score: 3, Insightful

      Please tell me you're not being serious.

      --
      /var/run/twitter.sock is a twitter socket puppet.
    13. Re:Sometimes we forget. by hairyfeet · · Score: 4, Interesting

      That is why I tell customers that if they don't want it formatted and they have more than 1 virus they have to pay PER virus. Works real well and keeps them from complaining when you show them the machine has 200+ virus infections at $10 a pop. I had one customer come in and after scanning his new Toshiba laptop he had 2074 viruses RUNNING at the same time! It took nearly an hour just to see the desktop! Sadly my former boss says he had that beat, as he had a home user bring in a machine where he had managed to get over 4500 infections in the thing.

      What the earlier poster wrote is true though. Folks acted shocked that it costs so much to fix their horribly infected machines, like we should be fixing them for fun or something. Yet for some reason they don't bat an eyelash when the plumber hands them this huge itemized bill. So I have taken to handing them a nice little printout with Hijack This that shows how much crap was installed with a little mark by each infection. They don't seem to complain as much when they see that huge list of crap they managed to install.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    14. Re:Sometimes we forget. by asdfghjklqwertyuiop · · Score: 2, Insightful

      Do you really have people do that? If so where do you live? If close I'll be happy to stop by and save you guys the trouble of carrying the machine out to the trash.

    15. Re:Sometimes we forget. by symbolset · · Score: 4, Insightful

      Typically, yes, cleaning a virus infection from a windows computer costs more billable time than the replacement computer costs. I see a bunch of contrary responses, but I'm guessing they just don't know what's going on here.

      Unfortunately, the cost of replacing the machine is just the beginning. After you have the new machine, the crudware infestation it comes with must be removed and that's often a wipe and reinstall from Microsoft media anyway. Then the broken OEM drivers have to be replaced with the functional OEM drivers from the vendor's website, and the installers for those don't always work properly. Then you have to add the drivers for add-on equipment like that combo scanner/fax/printer that the drivers never quite worked for and was discontinued years ago. Then you have to find all the user data from the old machine and put it on the new machine, even the user data that's hidden in stupid places like the programs folder for the application. You'll need to install the third party antivirus, all the Windows updates, and the usual suspects: Flash, Acrobat Reader, an office suite. Then it's all got to be tested with the end user to make sure they've got everything back they need to get their work done. Then if you're going to avoid doing this again in six months, you should take the precaution of capturing a system image.

      Yeah, when you're billing at a reasonable rate the cost of the machine is very little. But still, it's something and when a small business is down because the viruses make their computer unusable it's usually best to fix it now rather than wait on a replacement PC to get the doors open again.

      If you're reading this and you're a small business owner your best course is to go to EBay right now and buy another system that's the same model as yours for about $150. Then have your IT guy clone your system to it, take it home and put it in storage. Then when your system goes down, you've got a replacement to swap right in and load your data backups on (you DO make data backups, right?) so you can stay functional while your IT guy makes the dead system back into a spare for you.

      --
      Help stamp out iliturcy.
    16. Re:Sometimes we forget. by juventasone · · Score: 2, Insightful

      This debate has come up numerous times on slashdot, and I'm disturbed by the completely different paths such professionals adhere to.

      I've also been an independent technician for home/small business for 7 years, and for the vast majority of situations, I strongly believe in fix instead of reload. The reason is two-fold:

      Most of time it is a single issue (such as an infection), which I consistently remedy in an hour or so of billable time. If there are many issues it's a strong indication of hardware problems, which may appear fixed after a reload, but this is only temporary. It has nothing to do with ego--fixing requires lots of experience and competence, it is a skill worth developing.

      Secondly, and perhaps more importantly, users have lots of stuff that can't be backed up and restored. A good example would be a printer, which these days typically can't be installed without being present. The list goes on. The beginner users struggle to do these things themselves, and the advanced users who could will have an endless list of things they've setup just their way. Users appreciate having their PC back the way they're familiar with.

    17. Re:Sometimes we forget. by feepness · · Score: 5, Insightful

      Can we throw away the idea of a "throw away society"?

    18. Re:Sometimes we forget. by symbolset · · Score: 3, Insightful

      Can we throw away the idea of a "throw away society"?

      Yes. Unfortunately the baby that goes out with that bathwater is "growth economy".

      I'm for it still, but it would suck for most of you.

      --
      Help stamp out iliturcy.
    19. Re:Sometimes we forget. by symbolset · · Score: 5, Informative

      You don't "fix" a computer. You reinstall, it should only take 20 minutes tops. Of course, you should not be an idiot and not let it get that way to begin with. Regardless of your overinflated salary you are throwing away money. Dumbass.

      Look, I'm not a stranger to making an ass of myself on slashdot, but I still get to point out when other people do it. Sure, from a good image I can flash a 40GB SATA 3.0 drive in 3 minutes flat and the user is up and running. Add five minutes and I can restore today's user data from their good backup. That's not the common experience in the field because they have no good image and seldom have backups. In 20 minutes on the same drive you can install Windows if you have SP3 media. You still can't get all the updates, install the system drivers, install the accessory drivers, do a reasonable security software install and user configuration in 20 minutes. You definitely can't restore their user data, nor their critical apps. It just can't be done.

      If the typical consumer were willing to pay his tech to come out and set him up properly, and visit him and make a good image semiannually, maybe. If they bought spares, better still. But they usually won't. Usually they won't call for help until they've borked it good and don't have backups. Most people if you gave them a button that booted their computer from an "emergency backup" spare drive, would crash their main system, then the emergency backup, and then call for help.

      And some of them, oh, God I wish it were not so, utterly rely on some system running Windows 95 that hasn't been updated since because it was set up for them a decade ago and it still works and they bought into a system with no migration path.

      --
      Help stamp out iliturcy.
  2. I hate it when people venerate/elevate scumbags by elrous0 · · Score: 5, Insightful

    Some serial killer goes and and murders dozens of innocent people; and we reward him with veneration, books written about him, endless press coverage, etc. Scumbags don't deserve our respect, our veneration, or polite treatment.

    --
    SJW: Someone who has run out of real oppression, and has to fake it.
    1. Re:I hate it when people venerate/elevate scumbags by Nos. · · Score: 5, Funny

      He should be forced to forever use an unpatched Windows (9x, XP, 2000, etc) as his OS on every computer.

    2. Re:I hate it when people venerate/elevate scumbags by dave562 · · Score: 4, Insightful

      There seems to be a big stretch between a serial killer and some guy writing malicious code. My primary interest in computers initially involved all sorts of fraud and outright criminality. I now work in IT and have a completely legit lifestyle. Anyone who has any real competency or natural inclination to understand computers will mess with them and figure out how to make them do things outside of the "normal" range.

      The article talks about exploiting some incompatabilities between the Win32 and WinNT APIs. If there weren't guys like the subject of the interview, those incompatabilities would remain hidden. It takes mischevious people to come along and exploit the holes so that they get patched. By its very nature, software gets better when people push the boundries and tweak it. The person who writes code that leads to improvements in the most widely used operating system is not the same as the person who kills a bunch of people.

      If anything, Microsoft made the mistake of making the computer too friendly. They released technologies that gave people too many options. In any sort of free environment, there will be people who abuse the freedoms that they are presented with. Malware authors are those kinds of people. It is easy to blame Microsoft for looking into the future and envisioning a world where web browsers are the central application on the computer. They rushed blindly into it and unleased things like ActiveX on the world. At the core, their intention was right.. they wanted to make it easy to execute code in a distributed environment like the internet. Yet the implementation sucked and it seems like they didn't pay any attention to security.

    3. Re:I hate it when people venerate/elevate scumbags by Anonymous Coward · · Score: 5, Funny

      He should be forced to use Windows ME, at no higher than 800x600 screen mode, with a 56K modem.

      He should also be forced to eat his own testicles.

    4. Re:I hate it when people venerate/elevate scumbags by elrous0 · · Score: 4, Funny

      Given a choice between the two, I might go with the testicles.

      --
      SJW: Someone who has run out of real oppression, and has to fake it.
    5. Re:I hate it when people venerate/elevate scumbags by Anonymous Coward · · Score: 2, Funny

      Queue jokes about which one is getting more use in 3... 2... 1...

    6. Re:I hate it when people venerate/elevate scumbags by Anonymous Coward · · Score: 5, Insightful

      Damn right, dave. However, it's hard to deny that someone who writes malicious code that directly targets (ignorant) consumers may very well be treading on morally bankrupt territory.

    7. Re:I hate it when people venerate/elevate scumbags by girlintraining · · Score: 4, Insightful

      Some serial killer goes and and murders dozens of innocent people; and we reward him with veneration, books written about him, endless press coverage, etc. Scumbags don't deserve our respect, our veneration, or polite treatment.

      We're not here to discuss his moral infirmities. We're here to discuss effective ways of countering the threat the aforementioned poses. It is logical to begin by questioning those we've found engaged in such behaviors as to their motivations, goals, and methods. However, if you do not wish to dissect the frog due to moral outrage, I can give you some music to listen to but you will not pass the course.

      --
      #fuckbeta #iamslashdot #dicemustdie
    8. Re:I hate it when people venerate/elevate scumbags by dylan_- · · Score: 5, Funny

      Given a choice between the two, I might go with the testicles.

      That's the trouble with browsing at +1...now I have to imagine what kind of comment that was a response to...

      --
      Igor Presnyakov stole my hat
    9. Re:I hate it when people venerate/elevate scumbags by lxs · · Score: 2, Insightful

      Scumbags don't deserve our respect, our veneration, or polite treatment.

      True, but they are interesting to watch from a distance.

    10. Re:I hate it when people venerate/elevate scumbags by 0racle · · Score: 2, Insightful

      There seems to be a big stretch between a serial killer and some guy writing malicious code

      "Not for the purpose of the point that was being made, "scum should be treated as such." It doesn't matter what they did to be labeled scum.

      If anything, Microsoft made the mistake of making the computer too friendly. They released technologies that gave people too many options

      So if I buy a door that happens to have a lock with a flaw, it's the fault of the lock maker that my stuff gets stolen? Sorry, but no, the fault lies solely on the shoulders of the thief. Windows has many problems, but all the fault for exploiting it is on the malware authors.

      --
      "I use a Mac because I'm just better than you are."
    11. Re:I hate it when people venerate/elevate scumbags by Anonymous Coward · · Score: 5, Funny

      Maybe you should click the "whoosh" button.

    12. Re:I hate it when people venerate/elevate scumbags by Ralish · · Score: 4, Interesting

      I think you're being a little harsh, not to mention very black and white.

      Firstly, he's not a serial killer, he hasn't killed anyone; he's just irritated a LOT of people by installing infuriating software that's a pain to remove; in my view, this isn't quite of the same calibre as murdering people.

      And if you read the interview, you'd see he's not really evil, like many/most/all serial killers, but a very intelligent young person.

      His actions were motivated out of being extremely poor, he needed the money, and so he got involved in dodgy software programming. This isn't a justification for what he did, but it's nevertheless important to note. Further, he removed a lot of viruses and adware through his own adware, I'm not sure if this qualifies as grey hat behaviour, but once again, it blurs the line. Most importantly, he's reformed, and persuing an honest living, as well as providing insight into his past actions. I found his explanation of the measures he took to ensure his software remained on the infected computer fascinating from a technical perspective, there were some very clever approaches there.

      I don't agree with what he did, but I'm not going to relegate him to "scumbag" status, and I wouldn't be surprised if over the coming years and decades, he makes many valuable contributions to IT and the Ruby community in particular.

    13. Re:I hate it when people venerate/elevate scumbags by girlintraining · · Score: 4, Funny

      Yes, but malware authors are a bit gamey. I suggest buying a lot of rosemary before hunting them.

      --
      #fuckbeta #iamslashdot #dicemustdie
    14. Re:I hate it when people venerate/elevate scumbags by try_anything · · Score: 4, Insightful

      Anyone who has any real competency or natural inclination to understand computers will mess with them and figure out how to make them do things outside of the "normal" range.

      "Normal?" Not "honest" or "right" or "non-dickish?" Do you really have the balls to suggest there is some kind of honest difference of opinion about the morality of what these adware guys do?

      As for what you did, we all have our shameful moments in life. We all, at some point in our lives, invented and couldn't resist using the really clever way to make fun of the retarded kid or the weak kid in class that nobody liked. We did it to show off, to take out our frustrated aggression, and to temporarily feel better than somebody else. It's called being a childish asshole and it isn't any different from a big kid beating up smaller kids because he hates his life and is desperate for any triumph, no matter how hateful it makes him feel.

      By its very nature, software gets better when people push the boundries and tweak it. The person who writes code that leads to improvements in the most widely used operating system is not the same as the person who kills a bunch of people.

      Bigger problems get more attention. The more people exploit a flaw, the bigger a problem it is. So yeah, if you go around making problems worse, they'll get patched faster. Childish, egocentric hackers use that logic to rationalize the havoc they cause. People with an honest desire to protect users act in a very different way. The difference is instructive.

    15. Re:I hate it when people venerate/elevate scumbags by hobbit · · Score: 2, Interesting

      Furthermore, he didn't steal 4 million people's credit card details. I rather think a scumbag would have done just that.

      --
      "Wise men talk because they have something to say; fools, because they have to say something" - Plato
    16. Re:I hate it when people venerate/elevate scumbags by Shakrai · · Score: 4, Funny

      I can't find it.... where is it?

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    17. Re:I hate it when people venerate/elevate scumbags by Grishnakh · · Score: 5, Insightful

      So if I buy a door that happens to have a lock with a flaw, it's the fault of the lock maker that my stuff gets stolen? Sorry, but no, the fault lies solely on the shoulders of the thief. Windows has many problems, but all the fault for exploiting it is on the malware authors.

      I disagree.

      If you buy a door that has a lock with a flaw, and the lock maker knows about this flaw and does nothing about it and continues to sell this same flawed model for many years, making billions of dollars of profit, while people like you keep getting your stuff stolen, there's two parties at fault: 1) the thieves, obviously, since they stole the stuff, and 2) the lock maker, because they sold you something they claimed to be secure and which would protect your stuff from thieves, but which really wasn't, and they knew about it.

      When assigning blame for things like this, you have to look at the big picture. For a single instance of criminality, it's usually just the criminal's fault. But when the criminals keep using the same tricks over and over to commit their crimes, you have to look at what's enabling them. In the case of MS, they shoulder a lot of blame, because they, for decades, have put features ahead of security, even though they own the lion's share of the market and any security flaw has the most potential for damage because of that. Finally, because users have known about MS's crap and keep buying it, users also share part of the blame, for continuing to purchase MS's shoddy products, although this is mitigated partially because of MS's manipulation of the market to keep themselves in a position where it's difficult to get by without their product (for instance, because many important software products like AutoCAD only work in Windows).

    18. Re:I hate it when people venerate/elevate scumbags by fuckface · · Score: 5, Funny

      Of course they're morally bankrupt. However they also play an important role in the ecosystem.

      OMG, you're right! I'll be over in 20 minutes to smash all your windows. You know, to stimulate the economy!

      All these tools are doing is saving M$ money on code audits and proper beta testing at the expense of EVERYONE else.

    19. Re:I hate it when people venerate/elevate scumbags by Thing+1 · · Score: 4, Funny

      Oh, the left, definitely the left.

      --
      I feel fantastic, and I'm still alive.
    20. Re:I hate it when people venerate/elevate scumbags by Hal_Porter · · Score: 2, Interesting

      I think you're being a little harsh, not to mention very black and white.

      Firstly, he's not a serial killer, he hasn't killed anyone; he's just irritated a LOT of people by installing infuriating software that's a pain to remove; in my view, this isn't quite of the same calibre as murdering people.

      I was once stuck at a client waiting for someone else to do something. This was back in the days of VBScript worms. I spent a happy few hours taking one apart to see how it worked.

      Hell, if I couldn't get a real job I'd probably be doing the same as him. Infecting a machine with UAC and IE running in protected mode is probably possible, but it sure as hell would be a challenge.

      --
      echo -e 'global _start\n _start:\n mov eax, 2\n int 80h\n jmp _start' > a.asm; nasm a.asm -f elf; ld a.o -o a;
    21. Re:I hate it when people venerate/elevate scumbags by initialE · · Score: 2, Funny

      Given a choice between the two, I might go with the testicles.

      Sometimes, the bull wins.

      --
      Starbucks, Harbuckle of Breath.
    22. Re:I hate it when people venerate/elevate scumbags by HybridJeff · · Score: 2, Insightful

      Except for the fact that salt works way better at melting ice than gravel does. It's not some kind of conspiracy to rake in more money for the repair shop, salt just works better (unfortunately it also screws with the environment more than gravel would).

    23. Re:I hate it when people venerate/elevate scumbags by XDirtypunkX · · Score: 2, Interesting

      Well, Socrates was often very rude, because rudeness promoted discourse and challenged established ideas. His teaching style was rude and aggressive, he equated those who sold access to their wisdom (sophists) with whores. Plato referred to Socrates as the "gadfly" of the state for this reason, stinging the state into action as a gadfly would sting a horse.

      Then again, Socrates was executed, so that's not to say being rude doesn't get you into trouble.

  3. Permanant Midnight by Thelasko · · Score: 3, Interesting

    It was funny. It really showed me the power of gradualism. It's hard to get people to do something bad all in one big jump, but if you can cut it up into small enough pieces, you can get people to do almost anything.

    It reminds me of the movie Permanent Midnight , where Ben Stiller starts out the movie smoking weed and at the end is hooked on crack.

    It's probably Ben Stiller's best work, by the way.

    --
    One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
    1. Re:Permanant Midnight by sanosuke001 · · Score: 2, Insightful

      Can't be much of a stretch... he plays the same bumbling, over-the-top idiot in every movie he is in.

      --
      -SaNo
    2. Re:Permanant Midnight by Hatta · · Score: 3, Insightful

      If you've watched enough Ben Stiller movies to have an opinion on which is the "best", not only do I not trust your opinion, I fear for the health and welfare of you and those around you.

      --
      Give me Classic Slashdot or give me death!
  4. Seriously by Anonymous Coward · · Score: 4, Funny

    It would be a damn shame if something bad happened to this guy.

    1. Re:Seriously by fuzzyfuzzyfungus · · Score: 5, Funny

      Do you think it would be more of a shame if he accidentally cut his throat while shaving, slipped and fell down three flights of stairs, or tripped and hit his head on a bullet?

  5. You first, buddy by Red+Flayer · · Score: 4, Interesting
    FTA:

    In particular, things involving human interactions don't have to be perfect, because groups of humans have all these self-regulations built in. If you and I have an agreement and you screwed me over badly, you've always got in the back of your mind the nagging worry that I'm going to show up on your doorstep with a club and kill you.

    Times change. In order for this to continue to be a factor, we need to make sure that occasionally, someone *does* show up on a doorstep and club someone over the head.

    I suggest we start with people who have kidded themselves that the abusive software they've written does not make them a villain.

    --
    "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
    1. Re:You first, buddy by Red+Flayer · · Score: 4, Funny

      Let me guess... You liked playing whack-a-mole when you were a kid, right?

      I grew up on a farm, where we did not have to dilute the whack-a-FOO experience with carnival games.

      Juvenile groundhogs leaving the nest to dig their own burrow were frequent targets of a well-timed shovel strike.

      Potentially-rabid raccoons, whether in the bottom of a 55-gallon drum, or in a wire mesh trap, proved no match for a well-placed pitchfork thrust.

      Voracious, ridiculously fecund rabbits proved much easier to deal when their heads were separated from their bodies via garden hoe.

      Pesky, time-wasting, crop-damaging field/woodland creatures QUIVERED before the mightiness of the farmer's kids.

      It'd be a better world if malware writers trembled before the wrath of internet users.

      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
    2. Re:You first, buddy by Red+Flayer · · Score: 2, Funny

      Hmm... On second thought, maybe I should just get some counseling.

      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
    3. Re:You first, buddy by ungulation · · Score: 2, Funny

      Dwight Schrute? Is that you?

  6. Chilling by bbbaldie · · Score: 5, Insightful

    I am now more convinced than ever that it is impossible to secure Windows.

    1. Re:Chilling by blueg3 · · Score: 2, Insightful

      Hey, *someone's* got to apply all those malware techniques to a money-making venture.

    2. Re:Chilling by El+Lobo · · Score: 5, Insightful

      The same guy says in another interview in CNET that it would be pretty easy to find ways to implement the same in OSX (where they are actually experimenting) and in many Linux distros, but nobody pays a shit for that. They can get a lot of cash for pressing their brains to find exploits for hundred of millions of computers than what they would get to find exploits for some thousands in more exotic OSs. Easy like that. A so complex thing like a OS with millions of lines of code will necessarily ALWAYS have a couple of thousand possible holes, be it BeOS, MistOs, NetBSD os whatever. You only need the will (or the cash).

      --
      It's time to realise that Abble's products are the biggest abomination these days. Just say NO to the dumb iAbble way!!
    3. Re:Chilling by nwssa · · Score: 3, Insightful

      there isn't much stopping anyone from implementing this on Linux except the payoff is a fraction. Do you go to work for 1/20th of your hourly wage?

    4. Re:Chilling by ILikeRed · · Score: 3, Interesting

      "Securing an environment of Windows platforms from abuse - external or internal - is akin to trying to install sprinklers in a fireworks factory where smoking on the job is permitted." -Gene Spafford

      --
      I have come to a conclusion that one useless man is a shame, two is a law firm, and three or more is a congress -J Adams
    5. Re:Chilling by steelfood · · Score: 4, Insightful

      In life, genetic diversity means the species has a better chance of survival. OS diversity, processor, and even instruction set diversity, is important for the same ends.

      So it's not worth much to attack Linux or OSX or one of the BSD's. If all of these OS's including Windows had the same, 20% marketshare, perhaps it wouldn't be worth it to attack any of them. Or, it might actually be worth it to go for the low hanging fruit, namely, the easier-to-use OS's (OSX, Windows, and possibly a flavor of Linux). But the returns for the amount of work needed to attack 3 or 4 different OS's definitely wouldn't be as high, and the incentive for creating malware would be much less.

      --
      "If a nation expects to be ignorant and free in a state of civilization, it expects what never was and never will be."
    6. Re:Chilling by vadim_t · · Score: 3, Insightful

      Except that for Linux, the situation is quite different.

      First, the OS is open. Which means any user of it can make and submit a patch, which would quickly spread around. Distributions engage in some competition, and the patch would get copied around. There's no need for anybody to wait for a vendor to do it.

      Second, there's much less backwards compatibility. If a library function is vulnerable, and fixing is impossible without breaking compatibility, a distribution can find all of the included software that uses it, and fix to work with the new version. You're not going to find libqt 1.0 in a modern distro either.

      Third, the open nature of the OS leads to the possibility of patching the OS to mess with the adware, making it report complete crap to the server.

      Fourth, there already are generic mechanisms such as SELinux to deal with such things. While they're not that widespread yet, a good attack or two of this sort would do a lot to help adoption.

    7. Re:Chilling by 4D6963 · · Score: 2, Informative

      Malware isn't as lame as you make it seem. I just got infected by a virus. It doesn't do much, except a few things : when you log into FTP to upload to your website, it sniffs the FTP packets so it can itself login again and deface your website by inserting malware in it (which results in a Google malware warning that I currently still have on this site (the site is still "infected")). It does one other thing, it prevents your web browsers (although not your entire system, nslookup still works) from resolving the domains of all the antivirus vendors as well as microsoft.com.

      That's discreet, subtle and cunning, and I had to boot into another copy of Windows to run an online scan. We're not in 1998 anymore, malware isn't just casino pop ups anymore, it's some very serious stuff.

      --
      You just got troll'd!
  7. Demonize him now, but when the aliens invade... by starglider29a · · Score: 4, Funny

    ...his skills to slide past security and override their computer systems may be the last hope of mankind.

    Unless the aliens AREN'T running Windows.

    1. Re:Demonize him now, but when the aliens invade... by hesaigo999ca · · Score: 3, Funny

      Keep him around once Skynet becomes self aware, we might need him!

  8. Not a complete jerk by steveha · · Score: 5, Interesting

    I'm seeing comments and tags using words like "scumbag". Well, I actually RTFA, and this guy doesn't seem to be a complete jerk.

    According to him, the adware he wrote did not crack into your system using exploits, and when you ran the uninstaller it would go away and never come back. Also, according to him, it didn't scan for really personal information like credit card numbers.

    I'm not about to start a fan club for him, but I don't hate him either.

    I was interested in the technical stuff. His software would find other adware on a system and kick the other adware off; it was also designed to be very difficult for other adware to kick off.

    The best single exchange in the interview:

    S: In your professional opinion, how can people avoid adware?

    M: Um, run UNIX.

    steveha

    --
    lf(1): it's like ls(1) but sorts filenames by extension, tersely
    1. Re:Not a complete jerk by duguk · · Score: 3, Funny

      he wrote adware. yes, he is a complete jerk. he worked for a corporation that did evil things.

      What evil things? Did you read the article, or ignore the comment you replied to?

      Are you new here? Advertising is EVIL!

  9. The new battle ground by girlintraining · · Score: 4, Interesting

    I think the Windows programming model is at fault for much of the obfusciation tactics used by malware. Entire classes of exploits have arisen due entirely to the complexities and obscurities of the interface. Modern anti-malware tactics have to monitor many different parts of the operating system, and in some cases due to architectural constraints the methods of doing so can make the entire operating system unstable. Not only that, but race conditions and the use of special trap conditions/exception handling can make safely disabling malware a frustrating experience. Even professionally designed applications can sometimes tank the Operating System. Trying disabling Symantec Anti-virus on an XP system without a reboot, for example, and then doing a reinstall of it remotely. In the field, I saw failure rates of about 6% for SAV10. On a hundred thousand systems, let's just say I was not happy on that deployment! Killing malware is even more risky.

    Windows is layers upon layers of earlier APIs that cannot be removed due to "backwards compatibility" concerns. I have some limited exposure to the .NET framework, and it has perhaps a half-dozen APIs for threading, and the documentation is riddled with exposed interfaces that have the note "Do not use. Not safe. bullet in the brain pan squish" in it. Over a third of the API is already depreciated (as far as I can tell), and there is an ever-shifting set of best practices standards. I can only imagine the hell a proper programmer endures in developing truly complex applications for .NET -- all I was doing was a few WMI calls and a database interface and I still crashed the kernel many times trying to figure out what to trap -- in many cases, error handling is mostly about creating a catch-all and then trying to break your code to see what is generated and then guessing what to trap accordingly. With an interface this complicated and unstable, it will always be a cat and mouse game between the white and black hats on this architecture, a game predicated on undocumented interfaces, obscurity, and deep knowledge of layers of the operating system that interact in unpredictable ways.

    Compare this to linux, where the interfaces haven't changed that much, and when they do, depreciated means "We're going to remove this in a year or so and we mean it." Open source has one huge advantage here -- if it's not maintained, it ceases to be relevant and there's no 20 year old code lurking about in an unused API long forgotten. At least not nearly to the degree Windows has it. If you ask me, Microsoft is complicit in allowing malware to exist because they are unwilling to modernize Windows. They need to start over from scratch on their codebase and have a good hard think about what those APIs and interfaces are going to look like and then stick to it. Or at the very least, they could start by documenting these interfaces and releasing some code so we can be more confident that our hooks into their black-boxed APIs won't tear the operating system's heart out...

    --
    #fuckbeta #iamslashdot #dicemustdie
    1. Re:The new battle ground by Shados · · Score: 3, Insightful

      Over a third of the API is already depreciated (as far as I can tell), and there is an ever-shifting set of best practices standards. I can only imagine the hell a proper programmer endures in developing truly complex applications for .NET -- all I was doing was a few WMI calls and a database interface and I still crashed the kernel many times trying to figure out what to trap -- in many cases, error handling is mostly about creating a catch-all and then trying to break your code to see what is generated and then guessing what to trap accordingly.

      Wow there cowboy... only a very small part of the API is deprecated, the best practices changed a bit once, and only had additions as new features popped, but didn't change much in years... if you crashed the -kernel-, you were using legacy APIs through .NET, not .NET itself, and error handling is very well documented for the most part, and doing a catch all is a (no offense, since .NET is obviously not your primary dev environment) noob way of doing things and is heavily warned against since version 1.

      Maybe you fell in the ONE edgecase where it doesn't work well, but 95%+ (probably more) of it works flawlessly, is clearly documented and predictable...even if you go really deep. It becomes a bit more messy when you're interacting with separate products that just happen to have APIs coded in .NET (especially if its not the only language, and thus is probably coded by programmers who have no clue wtf they're doing), and its poorly done... Happens a lot. An example is the SSIS API (thats by Microsoft too), which is in .NET, but was clearly written by C++ gurus...so its a total fucking mess.

    2. Re:The new battle ground by Samah · · Score: 3, Insightful

      If you ask me, Microsoft is complicit in allowing malware to exist because they are unwilling to modernize Windows. They need to start over from scratch on their codebase and have a good hard think about what those APIs and interfaces are going to look like and then stick to it.

      And the new version of Windows would be laughed at by non-IT consumers. "Why would I upgrade to the new Windows when all of my stuff doesn't work?" This is part of the argument against Vista, and why some people can't see past the need to break backward compatibility to do things "the right way".

      --
      Homonyms are fun!
      You're driving your car, but they're riding their bikes there.
    3. Re:The new battle ground by Shados · · Score: 2, Insightful

      But I don't think you'll argue with me that Windows programming is helluva more complicated than Linux/Unix, and unnecessarily so.

      Oh yes I will argue with you over that :) You just have to get the parallels right. You can't go and compare the entirety of the API of Windows to a subset of Linux's...if you take all of the GUI APIs, the management APIs, .NET, Win32, etc, then just go and compare to the stuff the Linux kernel exposes... that doesn't work. Add the primary linux GUI environments, the various librairies, all of the integration issues, and you end up being in a fairly similar mess. Gnome alone is such a mess...

      "But Gnome isn't part of Linux, you don't have to use it to code in Linux!", well, you don't have to use Win32, and while it tends to hide under many APIs, it is possible to dodge it, for example. The documentation is some of the best on the market (it has to be: if you have an MSDN subscription, and there's an issue with the API, they have to help you out fix your issue, debug your code, and give you patches if a supported API doesn't work as it should... so while part of the API isn't as well documented as others, they're pretty careful that its only the rare edge cases, because it will cost them if you fall on it and have a support subscription...

      The old stuff isn't as good as the new, but its similar to what you said of Linux... some stuff gets forgotten and no one uses it anymore. Usually, if you still have to interface with it, its because of legacy code within the company, and that would be true regardless of OS.

      Seriously though... .NET isn't cross platform, and it costs to deploy on the server side (unless you use MONO, but thats uncommon). The top notch documentation and API is the ONLY reason it catches on at all. When it came out, it was "new", and very very different (especially C#), and broke a lot of stuff... people would have ditched it faster than you can say "Vista" if you couldn't pick it up in days with MSDN at your side.

      You probably just didn't have time to get all of the tools that are standard in a Windows dev environment, while on Linux/Unix, as soon as you sit down in front of a box, you make sure everything you need is there, which is the same thing I do when I sit in front of a Windows box.

    4. Re:The new battle ground by Lonewolf666 · · Score: 2, Informative

      True, and even some corporate users would not want it if their old applications won't run. On the other hand, the old cruft will continue to give them trouble until they DO a redesign.

      Apple went the other way with OS X, see http://en.wikipedia.org/wiki/History_of_Mac_OS_X. It took them four years to develop it, and backwards compatibility was limited.
      For a while, I'm sure that cost them customers. But by now, it seems they got past that problem and the new, shiny OS helps them to gain market share from Microsoft.

      --
      C - the footgun of programming languages
    5. Re:The new battle ground by camperdave · · Score: 2, Insightful

      Virtualization. Microsoft should put out a proper version of windows with a sandbox area for old software.

      --
      When our name is on the back of your car, we're behind you all the way!
  10. Persistance is the problem by FrostDust · · Score: 2, Insightful

    Theoretically, I'm not opposed to ad-supported programs. If someone is willing to put up with an advertisement in order to use a program for free, go ahead and let them. It's worked for television, radios, and web sites for quite a while (Tivos and Ad-Block aside).

    The problem, obviously, is when uninstalling the adware becomes a major hassle. For example, the author described in the interview how you would have to download a special uninstaller from the net, fill out a survey, and allow them to keep a registry key installed permanently. That is bullshit. Uninstalling shouldn't force any remains of the program to be left behind, period. Yes, in this situation it prevents unintentional (or intentional) reinstalls, but that wouldn't be an issue if adware didn't rely on drive-by downloads and was more upfront in what was being installed with the main program.

    To maintain some sense of legitimacy, uninstalling shouldn't be more complicated than a few clicks from using the Add/Remove Programs dialog, and not leave behind any of the program's code.

  11. Sadly, no. by lucas_picador · · Score: 5, Insightful

    From the article:

    In their licensing terms, the EULA people agree to, they would say "in addition, we get to install any other software we feel like putting on." Of course, nobody reads EULAs, so a lot of people agreed to that. If they had, say, 4 million machines, which was a pretty good sized adware network, they would just go up to every other adware distributor and say "Hey! I've got 4 million machines. Do you want to pay 20 cents a machine? I'll put you on all of them." At the time there was basically no law around this. EULAs were recognized as contracts and all, so that's pretty much how distribution happened.

    Um, no. Unconscionability is a pretty ancient principle of contract law. People joke about signing away their first-born child in an unread EULA, but they understand that it's a joke: that term would never be enforced by a court, because allowing contracts of adhesion (like EULAs) signed by non-lawyers in casual circumstances to extract those kinds of concessions from the parties would result in the complete breakdown of society.

    So when this guy (and his bosses) talk about how there was "no law around this", they're not fooling anyone, least of all themselves. If I buy a bus ticket and on the back there's some fine print stating that by riding the bus I've agreed to let the driver break into my house and take anything he wants, guess where the bus driver ends up if he tried to exercise his contractual "rights"? In prison. Which is where this guy belongs.

  12. Why Windows Registry is a bad idea by whoever57 · · Score: 5, Interesting
    From the interview:

    We did create unwritable registry keys and file names, by exploiting an "impedance mismatch" between the Win32 API and the NT API. Windows, ever since XP, is fundamentally built on top of the NT kernel. NT is fundamentally a Unicode system, so all the strings internally are 16-bit counter Unicode. The Win32 API is fundamentally Ascii. There are strings that you can express in 16-bit counted Unicode that you can't express in ASCII. Most notably, you can have things with a Null in the middle of it.

    That meant that we could, for instance, write a Registry key that had a Null in the middle of it. Since the user interface is based on the Win32 API, people would be able to see the key, but they wouldn't be able to interact with it because when they asked for the key by name, they would be asking for the Null-terminated one. Because of that, we were able to make registry keys that were invisible or immutable to anyone using the Win32 API. Interestingly enough, this was not only all civilians and pretty much all of our competitors, but even most of the antivirus people.

    --
    The real "Libtards" are the Libertarians!
    1. Re:Why Windows Registry is a bad idea by Johnno74 · · Score: 4, Interesting

      The differences in the way the NT api and Win32 api handle registry strings has been very well documented by Mark Russinovich and others.

      Rootkit Revealer (written by mark) uses this difference to try and detect rootkits - read the registry using both APIs, and see what comes back different.

      Hence Rootkit Revealer would put a huge flashing neon sign above malware that uses this technique

  13. Yes, he is a jerk by sirwired · · Score: 4, Insightful

    To get that oh-so-useful uninstaller you had to go to a website, answer a survey, and only then could you download it. If they genuinely wanted to make it easy, they would have put it in Add/Remove Programs, and stuck their survey in there.

    I don't know about you, but after getting sketchy software on my machine, the LAST thing I want to do is go to some random website and download even MORE crap. I wouldn't trust that download one bit.

    And the bit about "it was also designed to be very difficult for other adware to kick off" is complete hand-waving B.S. It was designed to be very difficult for anti-virus packages and anti-spyware packages too. In fact, anti-malware packages were probably the primary target of the persistence code.

    And their distributors were complete scum that Direct Revenue did very little to police. Yeah, they suspended any that were complained about (if the hapless users even had any clue how they got the software), but those rogue distributors would just sign up under a new name.

    I can't believe he thought this job was a "net positive" simply because he wiped out the other guys' malware more than he installed. That just means he is a very sneaky coder... That's like a embezzeling salesman saying he was a "net positive" because he generated more profits than he stole. It may be true, but it doesn't make him any less of a scumbag.

    SirWired

  14. there are comments here threatening violence by circletimessquare · · Score: 5, Insightful

    so let's educate some of you:

    we capture someone like frank abagnale, and we go all sharia law on him, as a lot of you propose, and leave him as a bloody stump

    then what?

    well, there are other frank abagnales out there. how do we detect them and capture them? well, the frank abagnale you just beat to a pulp: he would have made a good tool to do that, ya think?

    luckily, in real life, this is exactly what the feds and the banks did. in real life, you capture and use highly intelligent crooks to... drum roll please... capture more highly intelligent crooks. get it?

    law enforcement is hard grinding work, it doesn't happen like "death wish" or "dirty harry". i know in some of your justice league of america fantasy lives, delivering justice with a fist and a gun is the way to go. but we'd like to talk about reality, ok?

    so to review:

    1. we can have justice your way, and beat adware authors to a pulp, or
    2. we can have smart justice, and listen carefully to mr. adware author's words, and use those words to catch more adware authors

    get it? see the difference? do you want to pursue justice? or do you want to beat people up?

    these are mutually exclusive activities, despite your dimwitted fantasy lives

    now go crawl back under your rocks mouth breathers. nobody who is actually going to catch and punish cybercriminals in this world is going to think like you do

    even the most vile amoral serial killer is useful to keep alive and listen to. simply for matters of brain analysis and psychological study. or, we could put a bullet in his head, scrambling the abnormal brains, and having nothing useful to catch more vile amoral serial killers

    dumb violent justice leaves a dumb violent society that knows nothing about the smart and truly vicious criminals in their midst

    smart justice is about studying smart criminals, and using them against each other

    --
    intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
    1. Re:there are comments here threatening violence by Red+Flayer · · Score: 2, Insightful
      You make a good point, but there is a huge flaw to your system.

      There is no disincentive to do wrong.

      I know there's a big philosophical issue with deterrence as a reason for punishment, but the truth of the matter is that people will tend to not commit crimes when the

      [risk of getting caught]*[punishment when caught] is greater than [benefit from committing crime]

      I think your philosophy tries to tip the balance by increasing the risk of getting caught for potential criminals... but that doesn't help when the punishment is minimal and the potential gains so large. Let's see... a life of luxury vs. a short stint in country club prison and a consulting gig with a three-letter-agency.

      The key is to increase the chances of catching criminals, while having punishment severe enough to factor into the potential criminal's decision-making process.

      I'd also note... the interviewee mentions that it was a gradual change to intentionally writing malware, and the incremental decisions to do what he did were easy to make. He valued pleasing his employer over not doing wrong, even if he didn't consciously realize it. If there is a risk of severe punishment for his actions, maybe those incremental decisions would have been made differently (note that at the time, legality was not an issue, however).

      To sum up, increased success at catching criminals solves nothing if it does not come with punishment for those criminals. As you point out, there will always be more brilliant people who will fulfill the role of criminal... we need to ensure that they don't *want* to commit those crimes.

      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
  15. The Ethics of CoreWars by ewhac · · Score: 4, Insightful
    My initial gut reaction was to denounce this guy as a $SCOUNDREL (substitute your preferred profane term). But a little voice told me to go read the article, and now I'm not as sure as I was previously.

    Just for fun, consider the following actions a Unitary Programmer might do to your machine. Where would you rate them on the $SCOUNDREL scale, and why?

    • Deletes viruses from your machine.
    • Deletes competing adware from your machine.
    • Rebuffs attempts by competing viruses and adware to be deleted.
    • Reconfigures IE to be more secure.
    • Reconfigures Outlook to send plaintext only, fixed-width font, no top-posting, do not load or display remote images.
    • Disables using MSWord as an email editor.
    • Deletes IE; replaces it with Firefox, preserving all your bookmarks.
    • Deletes Outlook; replaces it with Thunderbird, converting all your mail archives.
    • Deletes all BitTorrent clients; replaces it with a RIAA/MPAA/FBI warning.
    • Deletes the scary warning about installing device drivers not digitally signed by Microsoft.
    • Converts HDCP to a system security setting, and flags all unprivileged applications that attempt to mess with it.
    • Deletes Windows; replaces it with Linux+Wine.
    • Deletes Windows; replaces it with Linux+KDE, with a message on the desktop reading, "Learn to use a real computer, kid..."

    Playing "CoreWars" is tricky business, and people with even a dim sense of ethics are loathe to try it. But there's one case where none of the above actions are ethically questionable: When the machine's owner does it themselves.

    I think the adware author lost sight of that for a while...

    Schwab

  16. Re:Executable that's not an executable? by Rycross · · Score: 2

    According to the article, deleting the registry entries mean that the program would re-install itself, while leaving them in-place would cause the software to avoid that computer (registry entries were used as an opt-out marker).

  17. or the cops still on the force... by SuperBanana · · Score: 5, Insightful

    Im pretty sure that the majority of cops that became criminals were the hardest to catch. They know all the tricks and what other cops/detectives will be looking for.

    What about those that use color of law? It's not terribly surprising that the FBI only receives about 200 complaints of color-of-law, and doesn't investigate, much less prosecute, a single one.

    Simply being a police officer offers enormous immunity from the general public accusing you of crimes, and further means that most of your fellow officers won't "rat" on you (instead of being disgusted at your behavior and bringing disrepute to the supposed "profession.")

  18. Distributed crime by onkelonkel · · Score: 2, Insightful
    "a big stretch between a serial killer and some guy writing malicious code"

    I sometimes wonder if there is a way to estimate aggregate "harm" caused by a widely distributed crime. Is it the same to steal 1 minute of time from 1 million people with an automated telemarketing robocall as it is to lock 1 guy in your basement for 2 years (1 million minutes)?

    --
    None of them can see the clouds; The polished wings don't care.
  19. Re:No wonder by Lonewolf666 · · Score: 2, Informative

    Maybe even that won't get rid of the adware.
    It will, if you do it right. That means
    1) Don't try to "repair" the installation, format C: and do it really from scratch.
    2) Don't install from a "recovery CD" from the hardware vendor, it might have the adware pre-installed. Use an unmodified Microsoft CD. Install from that.

    Now you have a clean installation. To make it stay clean (not only from adware), do the following:
    3) Before you connect to the internet again, install the latest service pack AND the post-SP4 hotfixes. Here a utility that collects all the updates into an offline update CD is helpful. I use the offline updater from heise, a German IT publishing house.
    You can download the current version from http://www.heise.de/ct/projekte/offlineupdate/download/ctupdate50.zip
    The UK site of heise has an article in English that explains the system (for an older version, but I think the principle still applies): http://www.heise-online.co.uk/security/Do-it-yourself-Service-Pack--/features/80682
    4) It is usually a good idea to use something else than Internet Explorer for surfing ;-)

    --
    C - the footgun of programming languages
  20. Yes, law by Wrexs0ul · · Score: 5, Funny

    Lol, the only "other" profession where it can take 4 million lines of code and a dozen libraries to effectively state "Hello World".

    -Matt

    --
    --- Need web hosting?
  21. Re:Outsource by Lotana · · Score: 3, Insightful

    As an Out-sourced IT consultant I don't forget. I thank them.

    Everyone wins.

    Have a look at broken window fallacy.

    Not everyone wins. Just someone else is paying the price

  22. "Ecosystem"??? by DesScorp · · Score: 4, Insightful

    Of course they're morally bankrupt. However they also play an important role in the ecosystem.

    What? How in the hell are malware writers an "important part of the ecosystem"?

    This is the Internet, not Wild Kingdom. In nature, real virus infections do indeed serve a natural purpose. On a computer, it serves nothing but the ends of assholes and criminals. There's no justification... none whatsoever... for what these guys do. And don't give me that farcical security argument, either. They're not doing the world any favors by violating other people's computers.

    --
    Life is hard, and the world is cruel
  23. Why did you buy a door with a lock on it? by Valdrax · · Score: 2, Insightful

    So if I buy a door that happens to have a lock with a flaw, it's the fault of the lock maker that my stuff gets stolen? Sorry, but no, the fault lies solely on the shoulders of the thief.

    I'm sorry, but why did you buy a door with a lock on it if not to protect against thieves? If someone sells a product that purports to protect you against criminals, and it fails to do as advertised, then that seller has sold a defective product and partially to blame for your loss. To follow your line of logic would absolve locksmiths of any responsibility to make a product that isn't slipshod.

    Microsoft thumps its own chest about the safety and security of its system. Their failure to live up to their claims makes them part of the problem and not an innocent bystander.

    --
    If it's for-profit but free, you're not the customer -- you're the product (e.g., the Slashdot Beta's "audience").
  24. "Not evil?" by Valdrax · · Score: 3, Insightful

    And if you read the interview, you'd see he's not really evil, like many/most/all serial killers, but a very intelligent young person.

    First, what exactly is "evil?" Some people think that one has to cackle and twirl your moustache with glee at being evil for its own sake, but most people who do horrible and evil things to other people have a good justification for their acts: "I was desperate and I needed the money," "I was just following orders," "I'm protecting my family and my country," "Everybody else gets away with doing it," "My evil rids the world of other evils," "If I didn't, then someone else would," "It was just a job," "It's nothing personal," "Stupid people get what they deserve," "It's just survival of the fittest," etc., etc.

    Doing something wrong just because you were in a tight spot and put your own needs over others is no more just than doing it just because you enjoyed it. Evil is evil. While I feel sympathy for his poverty and think that we as a society should focus our government's attention more on preventing the root causes of crime than just "deterrence," I feel no real qualms about stringing someone up if they've crossed the line. He had a choice whether to do right and struggle or to do wrong and prosper. He chose the easier of the two paths.

    And second, I'd like to point out that most serial killers were "very intelligent young people." Unlike them, he wasn't mentally ill -- just greedy, ethically bankrupt, and too enthralled by the shiny programming challenge.

    --
    If it's for-profit but free, you're not the customer -- you're the product (e.g., the Slashdot Beta's "audience").
    1. Re:"Not evil?" by Ralish · · Score: 2, Interesting

      For me your post illustrates the over usage of the word "evil", or maybe I just have a different idea of what really qualifies for evil.

      If someone was to ask me to provide an example of someone who is just plain evil, I'd reply with someone like Robert Mugabe. Completely and utterly corrupt, inhumane, starves his people, an absolute disgrace with no redeeming features.

      For someone like the subject of this article, I prefer "unethical". What he did was undoubtedly wrong, but he also did things that immediately illustrate that he DOES have a conscience, examples:
      a) Provided an uninstaller
      b) Removed viruses (and to a far lesser extent, competing adware)
      c) Didn't take it to the next level (capturing credit cards and personal data)

      You call him greedy. Well, yes, he was to the extent that his motivation was money. But (do correct me if I'm wrong), I don't get the impression he got rich off what he did. He made some money, but not lots.
      You call him ethically bankrupt, but if he truly was bankrupt in the ethics department, why did he do the above?
      Why would you provide people a means to remove your software, take the time to remove viruses, and not steal their personal data?

      If he has no ethical boundaries, fuck it, just do it. But he didn't, even though by his own admission, he easily could have. For me, this indicates that he's definitely not ethically bankrupt, he has ethical limits, and by extension, he's certainly not evil. Society at times can be far too quick to condemn someone as "evil", "scumbag", whatever. Rarely is it that clear cut, and in this case, it's far more grey.

  25. Disposable computers? Can I have them? by zooblethorpe · · Score: 3, Insightful

    Can you get me in touch with these people you're advising? I could certainly use some free IT equipment.

    No really, I'm serious -- if you know of folks throwing out perfectly functional computers solely because of virus infections, I'd love to have a few of their machines. Heck, they're worth something just for hobbyist spare parts, if nothing else. :)

    Cheers,

    --
    "What in the name of Fats Waller is that?"
    "A four-foot prune."
  26. Re:No wonder by symbolset · · Score: 2, Insightful

    3.b. Make a clone image of the system to an external hard drive so that next time you can be done in 20 minutes. I recommend clonezilla for this because it's free, boots from a pen drive, supports Windows and Linux, and will save to a USB drive or open Windows share on the network.

    4) It is usually a good idea to use something else than Internet Explorer for surfing ;-)

    Another good tip is to load a good hosts file. You would be amazed how much it helps. There's no host like localhost. It's cheezy, it's retro, it's cheating. But it doesn't cause cancer.*

    *This statement has not been evaluated by the AMA. Void where prohibited. Your mileage may vary. Everything causes cancer.

    --
    Help stamp out iliturcy.
  27. Mod "Insightful", not "Troll" by zooblethorpe · · Score: 2, Informative

    Mods, while I might not personally agree with the rationale of throwing away computers because of infections, Digishaman's argument certainly makes sense, at least on an economic level, for the vast legions of the clueless. If they have browsing habits that habitually get their machines so glommed up with muckware as to be unusable, they're going to have to shell out major buckage to get their machines un-mucked -- and at that point, it *does* indeed begin to make more sense for them to just buy a newer low-end machine -- at least the OEM OS should be more up-to-date than their older machine, and might therefore last a bit longer before being rendered unusable again.

    Cheers,

    --
    "What in the name of Fats Waller is that?"
    "A four-foot prune."