Slashdot Mirror


Japanese Man Arrested For Storing Malware

Orome1 writes "38-year-old Yasuhiro Kawaguchi is the first person in Japan to get arrested for storing malware on his computer after the upper house's Judicial Affairs Committee has confirmed the new anti-malware law passed by the Japanese parliament. The law considers the creation, distribution and storage of malware a crime punishable with up to three years in prison and a fine that could reach the sum of 500,000 yen ($6,200)."

84 comments

  1. Symantec? McAfee? by XanC · · Score: 5, Insightful

    Surely any "white hat" working against malware needs to store malware someplace, right? What a dumb law.

  2. From the article: "without a legitimate reason" by tepples · · Score: 5, Informative

    The article says the charge was "storing a computer virus without a legitimate reason". In this case, the suspect "told the MPD that he did it to punish people who use file-sharing software"; do you consider that "a legitimate reason"?

    1. Re:From the article: "without a legitimate reason" by gdshaw · · Score: 4, Insightful

      The article says the charge was "storing a computer virus without a legitimate reason". In this case, the suspect "told the MPD that he did it to punish people who use file-sharing software"; do you consider that "a legitimate reason"?

      I can think of at least two organisations that might.

    2. Re:From the article: "without a legitimate reason" by Opportunist · · Score: 2

      So what, I don't consider those organizations legitimate.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    3. Re:From the article: "without a legitimate reason" by Charliemopps · · Score: 2

      Yes.
      Information should not be illegal.
      I hate Malware as much as the next guy, but there are hundreds of ways they could have passed laws that would lead them to be able to arrest this guy without having to making certain types of code illegal.

    4. Re:From the article: "without a legitimate reason" by ChikMag777 · · Score: 0

      Information should not be illegal.

      Not trying to flame here (just inquiring), but what falls under "information"? Is child porn information? If not, where did it cross the line? Why doesn't malware cross this same line? I recognize the fact that malware that's never disseminated has no victim. As where c.p. has a victim at the time of creation.

    5. Re:From the article: "without a legitimate reason" by Anonymous Coward · · Score: 0

      Information should not be illegal.

      Okay, so I can steal credit card information as much as I want.

    6. Re:From the article: "without a legitimate reason" by tepples · · Score: 1

      As where c.p. has a victim at the time of creation.

      Not in jurisdictions that define CP to include a drawing.

    7. Re:From the article: "without a legitimate reason" by Anonymous Coward · · Score: 0

      So what? Are you a law-maker?

    8. Re:From the article: "without a legitimate reason" by Opportunist · · Score: 2

      For myself? Yes. And I never broke a single one of them, every time I was close to it I managed to change them just in time.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    9. Re:From the article: "without a legitimate reason" by perryizgr8 · · Score: 1

      imo, mere possesion of cp should not be a crime. the creation should be targeted. focusing on possession laws makes actual efforts to reduce child abuse less effective. similarly, it is stupid to punish storing malware. intentionally propagating it should be a crime.

      --
      Wealth is the gift that keeps on giving.
    10. Re:From the article: "without a legitimate reason" by perryizgr8 · · Score: 1

      you can steal as much as you want, just don't pretend to be someone else while paying for your shopping.

      --
      Wealth is the gift that keeps on giving.
    11. Re:From the article: "without a legitimate reason" by Antarius · · Score: 1

      And me without mod points. Somebody mod this up, please!

    12. Re:From the article: "without a legitimate reason" by michelcolman · · Score: 2

      Possession was declared a crime because it destroys the market for CP. Otherwise, you could download (buy) as much CP as you liked and, if you got caught, just go "I did not make it, so I'm not to blame". Now most people will stay away from these sites since just having those pics in you browser cache could be enough to send you to jail. If nobody buys CP anymore, it destroys the incentive for people to create it.

      Of course some degree of common sense must be applied. For example, I once stumbled upon a child porn picture when browsing 4chan (after hearing outrage about some ISP blocking 4chan, just checking what all the fuss was about). In some places I technically could have been arrested for that, and put in jail if any trace of that unwanted image was left in some obscure cache location on my hard drive.

      Also, I think people went a little bit overboard when arresting people for a cartoon featuring Bart and Lisa Simpson having sex. That's just ridiculous.

    13. Re:From the article: "without a legitimate reason" by Devoidoid · · Score: 1

      And this has worked nearly as well as how making possession of drugs and alcohol illegal destroyed the markets for them.

    14. Re:From the article: "without a legitimate reason" by michelcolman · · Score: 1

      So what do you suggest then? Legalising child pornography?

  3. Re:Symantec? McAfee? by rbrausse · · Score: 2

    not dumber than cyber-crime law in other countries. politicans don't understand the whole computer/network thing

  4. So by Anonymous Coward · · Score: 0

    So... I'm guessing they don't have AOL in Japan then?

  5. Sorry, could not resist... by Robert+Zenz · · Score: 0

    So, they effectively locked Microsoft out of Japan?

  6. Re:Symantec? McAfee? by Derekloffin · · Score: 3, Informative

    The summary is pretty poor (as usual). The article says 'The revised Penal Code, which was enforced July 14, bans storage of a computer virus for the purpose of infecting other computers.' I doubt Symantec or McAfee store for the purpose of infecting other computers.

  7. Re:Symantec? McAfee? by Anonymous Coward · · Score: 0

    Read the articles before commenting.

    "the creation or distribution of a computer virus without a reasonable cause"

  8. Re:Symantec? McAfee? by Trepidity · · Score: 1

    You could consider Symantec/McAfee a sort of disorder, which is tolerated or even sometimes selected for by its host because of the protection it confers against another pathogen. Sort of the sickle-cell anemia of the computer ecosystem. But probably not a "virus", so it depends on how specific that is...

  9. 2.5 years in prison for this? by Baloroth · · Score: 3, Interesting

    FTFA:

    Kawaguchi uploaded a file containing the virus, which was titled to suggest child pornography, to the Internet via the file-sharing software Share

    Well, normally I consider people who upload viruses via file-sharing software to be scum of the earth, but this guy seems like he was actually doing it for a moderately good cause. "Think of the children" is hella over used, malware is malware, and vigilante justice it questionable, but punishing this guy seems kinda weird, especially that strongly. Also, how the hell do they define "storing" malware? Technically, that could mean anyone infected is guilty, which is really scary.

    I'm sure it won't be abused, of course. /sarcasm

    --
    "None can love freedom heartily, but good men; the rest love not freedom, but license." --John Milton
    1. Re:2.5 years in prison for this? by Baloroth · · Score: 1

      Edit: damnit, the 2.5 years appears to be for someone else. Oops.

      --
      "None can love freedom heartily, but good men; the rest love not freedom, but license." --John Milton
    2. Re:2.5 years in prison for this? by Lance+Dearnis · · Score: 2

      The problem is that if you're uploading something to infect people, there's a risk, for one, that it'll get out of control; and for second, that you might interfere with law enforcement efforts. If I pulled the same stunt here, and infected an FBI system with my virus, then who wouldn't expect them to come rip me a new one? If they wanted honeytraps set they'd do it themselves and get the laws written for it, because, they can shout "THINK OF THE CHILDREN" and get the permission to do it in a second.

      This guy might not be the best example of a conviction with the new law (It'd be nice to have one of the fake AV program writers get busted for it), but on the other hand, I'm glad to see such a law being put on the books and enforced. It's even got the exceptions for AV and anti-malware programs so that they won't get busted, or white hats. Sounds solid to me.

    3. Re:2.5 years in prison for this? by Opportunist · · Score: 1

      Where to draw the line? Let him go because he's trying to infect pedos, but impound the guy pretending to seed the latest blockbuster because he's "only" infecting copyright infringers? Or is that ok still (after all, they'd break the law, wouldn't they?) and we should only punish people that try to pretend seeding nude pics of their ex? Or is that still ok because it's "morally" wrong to show nude pics of people you don't like anymore?

      Who gets to draw the line?

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    4. Re:2.5 years in prison for this? by Baloroth · · Score: 1

      You're quite right. I posted in haste after only skimming TFA. Thought this guy got 2 and a half years for this, which seemed way too severe considering what he did. Wish Slashdot had a delete function. Turned out that was some other guy who actually made a fairly malicious virus. This guy should get a punishment, just not that bad. A hefty slap on the wrist, to discourage this kind of thing. To be followed shortly by a job offer, most likely. Still a little skeptical about how they can interpret "storing" malware, but I do understand the necessity for it. It could be impossible to prove he created it.

      --
      "None can love freedom heartily, but good men; the rest love not freedom, but license." --John Milton
    5. Re:2.5 years in prison for this? by Anonymous Coward · · Score: 0

      Well, normally I consider people who upload viruses via file-sharing software to be scum of the earth, but this guy seems like he was actually doing it for a moderately good cause. "Think of the children" is hella over used, malware is malware, and vigilante justice it questionable, but punishing this guy seems kinda weird, especially that strongly.

      The fact that you got up-moderated for this hate-filled rant just shows how quickly our society has been going down hill.

      When society starts condoning conservative and religious people like Anders Behring Breivik, only harm will come. Anti-child crusaders and pedophobia should not be tolerated in a civilized society.

      Of course, exceptions to good moral conduct are usually made against people who wish for children to have sexual freedom. The vigilante-ism that you propose against people who love children is no better than the vigilante-ism of the conservative zealot Anders Behring Breivik.

    6. Re:2.5 years in prison for this? by Anonymous Coward · · Score: 0

      fake AV program writers get busted for it

      Fraud & misrepresentation of product. Existing laws are more than sufficient for that.

    7. Re:2.5 years in prison for this? by Anonymous Coward · · Score: 0

      The law is and should be equal to everyone. Lenience would only encourage more abuse, especially when the supposed targets are pedophiles and other undesirables.

    8. Re:2.5 years in prison for this? by black+soap · · Score: 1

      Maybe his malware hit a police-sanctioned honey trap, impeding an actual investigation? There might be good reason for prosecuting him.

  10. * Confused * by Anonymous Coward · · Score: 0

    What the hell?? What is Japan's government's definition of "storing"?? So, if I get malware on my computer and don't detect it, I can go to prison for 3 years if the government somehow finds out??? Surely they mean that this only if you have the source code? I can't see that they would put someone in prison for having files on your machine that are infected with malware.

    1. Re:* Confused * by Opportunist · · Score: 2

      The summary leaves out the important bits like with the intent to infect others.

      And while an infected computer would possibly spread that disease, it's certainly not intended by the computer's owner.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re:* Confused * by Anonymous Coward · · Score: 0

      But if you actually do have an intent to infect others, the law doesn't stop you: you simply have to get a Windows computer without virus protection, put it on the network and let it infect others. There can be no evidence of intentional storing of malware here, since the malware gets in the natural route.

  11. Re:Symantec? McAfee? by sconeu · · Score: 2

    I doubt Symantec or McAfee store for the purpose of infecting other computers.

    No, their regular products do that quite nicely, thank you.

    --
    General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
  12. enforcable? reasonable? by rbrausse · · Score: 1

    how will they differentiate between active distribution of malware and infected machines? if some agency identifies an IP address handing out virus they will send in a SWAT team to confiscate all computers to search for installed malware or how should this work?

  13. Re:Symantec? McAfee? by Anonymous Coward · · Score: 0

    Actually they do, but they just happen to OWN those computers as well.

  14. Obligatory xkcd by Anonymous Coward · · Score: 0

    http://xkcd.com/350/

    1. Re:Obligatory xkcd by mehrotra.akash · · Score: 1

      Has anyone actually done that IRL??

  15. good thing I don't live in Japan by Anonymous Coward · · Score: 0

    For years I saved all kinds of malware - mostly email worms. I never ran them on my main PC but I felt that there was some entertainment value from attempting to run them in Wine or in a controlled environment. I don't see how that should possibly be illegal.

    1. Re:good thing I don't live in Japan by Desler · · Score: 1

      What you were doing would not be illegal. What was illegal was this guy storing malware to infect others.

  16. Re:Symantec? McAfee? by isorox · · Score: 1

    The summary is pretty poor (as usual). The article says 'The revised Penal Code, which was enforced July 14, bans storage of a computer virus for the purpose of infecting other computers.' I doubt Symantec or McAfee store for the purpose of infecting other computers.

    Ask yourself this, who has the most to gain from the continued proliferation of malware?

    If malware ceased, virus companies would go under. I'm not specifically saying that Symantec et al write malware, but it is in their business interests to do so, or to encourage it's growth.

  17. Re:Symantec? McAfee? by Opportunist · · Score: 4, Insightful

    The German law is even actually dumber.

    If I understood the Japanese law correctly, you'd have to have some kind of intent to use that malware to infect other computers to break it. So far, so good. Personally, I don't see anything wrong with that by itself, creating, storing or distributing malware with the intent to infect should be punishable. I wonder how they want to discriminate between intentional and accidental spreading (after all, it could well be that he himself downloaded that somewhere and didn't even know it's malware), but if they find a way to actually identify the intent of someone, that law could actually do much good.

    The German "anti-hacker law" cannot. There is simply no angle or way this could possibly have any beneficial effect. Basically, what the law says is that a "hacking tool" is illegal. There may be an exception for good reason, so far nobody tested it. I actually cannot remember a case where it was used. And it's sufficiently ambiguous that a hex editor could be subject to it or a firewall that lets you configure the packets it replies with. But let's stay with nmap, hping and all the other "hacking tools" for a moment. These are very well known and quite powerful tools to check the security of a network, so they can be used to find weaknesses in it, hence they're hacking tools.

    And auditing tools. Why? Because auditors use exactly the same tools for an obvious reason: Everything you can use to find weaknesses in a network to break into it can also be used to find weaknesses in a network to fix and seal them. Unfortunately, the law makes little difference in intent. Because not the use, but the possession, is already illegal. And when I own a rifle with a scope, it doesn't make any comment yet on whether I go on a killing spree with it or whether I'm a hunter.

    Now let's ponder for a moment who gives a shit about a law that makes those tools illegal: An auditor, whose job and pretty much his career hangs on his police record being spotless, or a criminal who plans to commit a crime much more serious than "possession of hacking tools".

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  18. Re:Symantec? McAfee? by Anonymous Coward · · Score: 0

    I truly hope that includes an exception for infecting computers you own (that cannot infect other computers that you do not own). Otherwise, yes, they most definitely do.

  19. Re:Symantec? McAfee? by Anonymous Coward · · Score: 2, Funny

    it is some where alone the lines of breaking your own leg to prevent yourself from getting on a bike, because then you might have a nasty crash and hurt yourself

  20. Re:Symantec? McAfee? by Desler · · Score: 1

    Ask yourself this, who has the most to gain from the continued proliferation of malware?

    Spammers and criminals.

  21. Glad I'm not in Japan by Anonymous Coward · · Score: 0

    They've shoehorned enough malware into my Windows system to get me put away for 200 years!

  22. Re:Symantec? McAfee? by Anonymous Coward · · Score: 0

    Surely any "white hat" working against malware needs to store malware someplace, right? What a dumb law.

    You really should read the article. Pay particular attention to the wording used to describe what is illegal.

  23. Re:Symantec? McAfee? by poetmatt · · Score: 1

    You are correct. It's been known for a long time, but it's a tough issue to deal with because: no antivirus program will catch everything, even the most robust that exists today, as there will be new things tomorrow. Etc etc.

    So beyond them trying to keep it above a level of "unreliable", there's a level of "keeping out malware" they will never successfully reach anyway.

  24. 'nother article by Mashiki · · Score: 1

    Slightly better article here with some extra info:
    http://mdn.mainichi.jp/mdnnews/news/20110721p2a00m0na006000c.html

    Just a personal opinion, Yomiuri is okay. But it's pretty close to sensationalist journalism without the meat. In the future people would be better off using well just about anything else.

    --
    Om, nomnomnom...
  25. Great news! by pasv · · Score: 1

    A side effect of punishing researchers is that there will now be a deficit in that field for the next 10 years. In other words, Japan will be importing talent. Time to start learning Japanese :) Dewa, hajimemashou ka?

  26. Re:Symantec? McAfee? by realityimpaired · · Score: 2

    Technically, though, having a virus-infected PC is both storing and distributing viruses....

  27. Re:Symantec? McAfee? by realityimpaired · · Score: 1

    Both McAfee and Symantec sell products other than antivirus, though... Kaspersky may suffer a little if viruses disappeared, as may AVG and Avast!, but McAfee and Norton wouldn't be hurt at all. Microsoft certainly wouldn't suffer if they had the opportunity to drop Defender... that one's a money pit for them, and their profits would actually go up.

    But as others have pointed out, criminal syndicates who use viruses either to collect credit card info, or to launch DoS attacks for the purposes of either keeping competitors off the 'net or blackmailing companies have a *lot* more to gain than Antivirus makers. Antivirus makers are simply profiting off the need to fight back against the people who are actually writing the viruses.

  28. Storing? Malware? by Intropy · · Score: 1

    So if my grandma who doesn't know how to use a computer, clicks on and downloads Bonzai Buddy because a purple ape told her to, is she guilty?

    1. Re:Storing? Malware? by Anonymous Coward · · Score: 0

      Sure, if she manages to go back to 2005, when it still existed.

  29. Re:Symantec? McAfee? by rbrausse · · Score: 1

    If I understood the Japanese law correctly, you'd have to have some kind of intent to use that malware to infect other computers to break it. So far, so good. [..] The German "anti-hacker law" cannot. There is simply no angle or way this could possibly have any beneficial effect. Basically, what the law says is that a "hacking tool" is illegal.

    I don't know of any actual cases based on this *great* law but two criminal self-complaints - both were dismissed by the prosecutors. A constitutional complaint was not accepted because the law does not infringe any fundamental rights.

    both the Japanese and the German laws are stupid as it is impossible to enforce them with reasonable methods:

    * The literal application of the German one would forbade even "hacker tools" like telnet.
    * Japanese law enforcement agencies will have problems to distinguish between illegal distribution of malware and infected machines. Confiscate and analyse every computer of an IP distributing malware _is_ effective but not reasonable.

  30. Back in high school by Anonymous Coward · · Score: 0

    My friends and I used to collect viruses. This was before the term "Malware" was invented. We kept them on floppies and it was simply a contest to see who could collect the most.

  31. I don't know. by Anonymous Coward · · Score: 0

    Is your grandma Japanese, or living in Japan?

  32. Re:Symantec? McAfee? by Opportunist · · Score: 2

    But without intent. And someone who is clueless enough to collect active malware on his PC can credibly claim that there was no intention behind it.

    I dunno about your courts. Ours follow the logic of "don't assume malice if stupidity is enough of an explanation".

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  33. Re:Symantec? McAfee? by Opportunist · · Score: 1

    I remember those two self-reports of two malware researchers, both having been dismissed by the courts (iirc, one didn't even get so far but was threatened to get smacked for contempt if he continues to persist... draw your own conclusions), so far no verdict has been issued on the matter.

    Personally, I think it's one of those "just to have something" laws. You know, the kind where you get a shady, not-quite-fully-in-sync-with-procedures warrant, crash into the home of the "pesky" individual, find nothing and now need something to justify that warrant.

    We get a lot of those laws lately. Laws where you ponder how the heck they should be enforced since what they criminalize can only be found AFTER you had a warrant...

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  34. Re:Symantec? McAfee? by dindi · · Score: 2

    I ran servers for years and years as a sysadmin, now I run/develop for servers. From time to time this and that gets hacked, most of the time it is just attempts that leave some binaries, sources here and there. I always keep these to see what they do, how they do it and as a reference to any in-the-future attempts to see if a name, email or something pops up again from an older attack. I keep logs, hacked files packaged and usually password protected.

    This law is stupid! I 100% agree. Even writing malware is something legit if you do not distribute it. Be it a hobby, a profession, or whatever else.

  35. Re:Symantec? McAfee? by Anonymous Coward · · Score: 0

    In that case, Chrome's document inspector is an illegal hacking tool... so is notepad.exe.

  36. Define malware, define innocuous by Anonymous Coward · · Score: 0

    According to the Daily Yomiuri the malware found on his computer is capable of "copying vast amounts of graphic elements and files on a computer, causing it to freeze or malfunction."

    I have some programs with that behavior on my Windows computer. Arrest me.

    According to his own words, Kawaguchi masqueraded the malware as a innocuous file with a name that suggested it has something to do with child pornography.

    Which would be innocuous? Oh, Japan. I see.

  37. Not talking about stealing by tepples · · Score: 1

    We're not talking about "stealing" information, which involves either espionage, NDA violation, or copyright infringement. We're talking about possessing a copy of information that one already has the right to possess under copyright or trade secret law. Some people think such possession should be a crime just because the information happens to be a harmful computer program.

    1. Re:Not talking about stealing by WorBlux · · Score: 1

      So a whole new round of illegal numbers? Ick.

    2. Re:Not talking about stealing by tepples · · Score: 1

      The making available of numbers for a fraudulent use was illegal long before the Internet was made available to the public.

    3. Re:Not talking about stealing by WorBlux · · Score: 1

      But the mere possession of a number? (Any computer program can be represented as a number. If you doubt this, open up any executable on your computer with a hex editor)

  38. Harmonization by tepples · · Score: 1

    I was under the impression that Intropy's comment assumed "harmonization" of this Japanese statute into other countries' legal systems.

  39. Re:Symantec? McAfee? by Billly+Gates · · Score: 1

    Part of me wants to scream ABOUT TIME. I thought it was outrageous back in 2003 and 2004 when malware really began to infect dial up users within seconds and why no one would do anything about it? I mean what if someone tried to break into your home every 30 seconds? Or what if each time you stopped your car at a light people would dash towards your car trying every method to break in?

    Today it is a normal to shrug our shoulders while a single person has 675,000 credit card numbers and names.

    Yes, this law is stupid and I do agree, but at least it is a step in the right direction and yes many many and I mean many criminals need to be thrown in jail. It is like the wild west and for awhile when IE 6 was popular, the threat of e-commerce leaving the web was real. To this day I refuse to do online banking because I am so paranoid. If banks had authenticators like World of Warcraft I would check it but it is not worth the hasle of having my account compromised. ... I develop sites for IE and Windows so probably that is a good thing on my PC.

  40. Re:Symantec? McAfee? by Opportunist · · Score: 1

    It ain't hard to find ridiculous applications for that law, is it? :)

    Given the wording of the law, almost everything remotely dealing with networking could be twisted into being a hacking tool. Here is the original law, unfortunately I'm not good in legalese to try my hand at a sensible translation. Essentially, what it says is that somehow "dealing with" (i.e. creating, storing, acquiring, selling, forwarding...) passwords or codes to access data or programs created for the purpose of committing the crime of intercepting or illegally accessing data is illegal.

    The interesting part is that "for the purpose". And depending on how you want to read that, either the law is completely useless or insane. Either you assume that no program that can be used for such a purpose has been written with this purpose in mind, because pretty much all of them can also be used to audit and test security with the purpose of improving this security, which renders the law quite use- and toothless.

    Or you assume that every program that can be used that way was created with this purpose in mind, outlawing not only all network security tools but also technologies like rainbow tables and accessing (let alone operating) webpages listing default passwords. Given the wording, one could even construct something like outlawing the information (and of course teaching) how to test your network for security leaks, since this information could be considered a tool for "hacking" by itself.

    The danger here is that most of security is in information, teaching and learning. nmap is useless if you don't know how to read its output. hping is useless if you don't know what flags to set to get a sensible result that tells you something (again, information needed to understand that output after you know what to input). The magical "press here to find security hole" tool does not exist, even though Nessus is often abused to this end.

    My guess is they watched this video and took the crap serious. It's in German. But I think the inanity is understandable even if you have no idea of the language.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  41. Re:Symantec? McAfee? by perryizgr8 · · Score: 1

    and symantec and mcafee. also, apple.

    --
    Wealth is the gift that keeps on giving.
  42. Re:Symantec? McAfee? by rtb61 · · Score: 1

    Here's a fine line, for a network or computer systems administrator a disk of the latest malware is highly appropriate as the only means of ensuring the quality of computer systems protection software us functioning properly ie you attempt to infect the system in a controlled fashion and check to see of the various protection system are functioning correctly. Via this method I at one stage was able to ascertain a configuration fault as the system was not updating remote units by reason of a simple reference to a wrong directory (some contractors are no that competent).

    --
    Chaos - everything, everywhere, everywhen
  43. Re:Symantec? McAfee? by Anonymous Coward · · Score: 0

    Please read the law, that goes for any slashdotters, especially the poster.

    The law forbids having malware on your computer with the intend of spreading it, or rather, without the special intend of fighting it. So, you have to prove your intend to fight malware if you want to store it in your systems. Symantec, McAfee etc. have no problem in proving that (years and years of releasing products to fight this) the same with any open source guy who have ever submitted (let alone got) a patch to clam etc.

    The law is actually very clever and well thought out, unlike if it was made in America or Australia, it actually tackles the problem and not a superficial pr. stunt.

    The guy arrested and if the facts are as stated in the article, will be the first convicted, was storing malware on his system with the intend of spreading it via p2p systems, allegedly because he himself see this as an evil piracy service that needs his personal punishment. It might convince others that this is not the way to go.

  44. Re:Symantec? McAfee? by Anonymous Coward · · Score: 0

    I ran servers for years and years as a sysadmin, now I run/develop for servers. From time to time this and that gets hacked [...]

    Are you working for Sony ? :)

    Seriously, you should reconsider your security policies if it happens from time to time. Subscribe to security lists, upgrade software more often, change your OS/distribution for a better one, improve your firewall(s) configuration and/or whatever else you think might be improved. "From time to time" sounds too often to me.

  45. RLY? by Artem+S.+Tashkinov · · Score: 1

    What about 20% or so Windows PCs infected with malware? Does this law means their owners should be indicted immediately?

  46. Re:Symantec? McAfee? by wrook · · Score: 1

    The Japanese legal system is complicated somewhat. It doesn't work the way many other legal systems work. The police have a fair number of freedoms when interrogating suspects, such that getting confessions is easier than it might otherwise be. So to prove intent is not so difficult if you can convince the suspect to confess (as seems to have been this case here).

    You might notice that I'm choosing my words carefully. Like I said, things in Japan are different. I'm not an expert on these matters, and there is no lack of people who will jump all over the Japanese legal system. I'll just say that the prosecutor's conviction rates are 95% and a great deal of those convictions come from confessions -- far more so than any other country in which I've lived. But the prosecutor is supposed to be impartial and acts to protect innocent people as well as go after guilty people (and to a certain extent, I really believe that happens).

    So the upshot of laws like this in Japan is that you have to be very careful *ahead of time* to make sure that what you are doing will be interpreted in the right light. If you do that, you're probably OK.

  47. Re:Symantec? McAfee? by Opportunist · · Score: 1

    Erh... no. Not necessarily. Having a trojan to test the security of a computer system is like having a single sample of e coli and using it to see whether a patient's immune system is up to speed. It works, but only if the patient just happens to be not immune. What if he is against this sample but not against the billion others?

    Also, given the heuristics getting better in contemporary malware scanners, you might be surprised how many they find even if the sig file they use never had any exposure to the current flavor of the attacker. You might see a scanner detecting something while still lacking current updates. Be careful when relying on that kind of security audit!

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  48. Re:Symantec? McAfee? by Opportunist · · Score: 1

    I'd rather think that this has more to do with Japanese culture and the general "I vs. we" difference to Western cultures. I have noticed that the Japanese people I had to deal with put a lot of emphasis on the way they're being viewed and how they affect others, compared to people from Europe or the US who are far more egocentric and more concerned about their personal gain. That's not to say that Japanese are altruistic (far from it...), rather that they seem actually concerned how their actions affect others and how they want to atone even for only perceived transgressions rather than having people think they act selfish.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  49. ouch.... by hesaigo999ca · · Score: 1

    should have a bypass, such as a white hat or security company or employee studying it.....just like diseases for labs etc...

  50. Re:Symantec? McAfee? by sjames · · Score: 1

    I don't know where you're from, but in the U.S. there are far too many DAs who will attempt to indict nearly anyone for nearly anything on the thinnest of pretexts and without regard for the clear intent of the law.

  51. Re:Symantec? McAfee? by Opportunist · · Score: 1

    They usually get shot down quickly by our judges. I guess that's the result when you have a system where judges for superior courts are chosen by their peers instead of being appointed by an administration. They tend to follow the spirit of the law since they want to be considered for higher "honors" and it's general consensus amongst our judges that attorneys who try to bend, stretch or otherwise mutilate the law should be shown their limits.

    The drawback is that judges try to weasel out of controversial cases since they know that, no matter how they cast their verdict, it will reflect badly on them. Some judge will certainly disagree.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  52. Re:The funny thing is... by Anonymous Coward · · Score: 0

    No, the funny thing is that you're wrong about that.

  53. Re:Symantec? McAfee? by dindi · · Score: 1

    High risk businesses have a lot of attacks. Throw-away servers get some malware here and there. These are next-next-next install boxes with default LAMP and wordpress/joomla/etc .... Most of the attacks are unsuccessful, but they leave traces, sometimes binaries uploaded here and there.

    BTW I program full time now and let the network people deal with this kind of stuff. :)