home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!gatech!destroyer!gumby!yale!hsdndev!news.cs.umb.edu!betsys
- From: betsys@cs.umb.edu (Elizabeth Schwartz)
- Newsgroups: comp.org.eff.talk
- Subject: Re: Virus design
- Message-ID: <BETSYS.92Dec29144112@ra.cs.umb.edu>
- Date: 29 Dec 92 19:41:12 GMT
- References: <BETSYS.92Dec27120852@ra.cs.umb.edu> <ousHwB1w165w@ruth.UUCP>
- Sender: news@cs.umb.edu (USENET News System)
- Organization: University of Massachusetts at Boston
- Lines: 50
- In-Reply-To: rat@ruth.UUCP's message of 28 Dec 92 12: 35:59 GMT
- Nntp-Posting-Host: ra.cs.umb.edu
-
- In article <ousHwB1w165w@ruth.UUCP> rat@ruth.UUCP (David Douthitt) writes:
-
- >What about a virus that showed up on your system, and said "Hi! I used
- >security hole x, but I fixed it!" Imagine what would have happened
- >(with appropriate warnings and so on) if a virus was written (very similar
- >to what rtm did), but instead it closed up the security holes that rtm
- >eventually used.
- For one thing, we wouldn't be able to beleive it; we would STILL
- have to re-load our system. Our system files would fail their
- checksums and we would have no way of knowing what had been changed.
- After all, a program which fixed hole "x" could have left its own
- surprises in hole "y" for all we know.
-
- >Those holes are the perfect example - after all, they *HAD* been fixed
- >as I understand it, but many people did not update their software to
- >fix them. See what happens when you leave it up to the admins?
- Well, that's the responsibility of the people who own and operate
- the systems. If your admin doesn't do his or her job, you need to find
- a better sysadm. It is tyrannical to force changes and improvements on
- those who do not want them. Let them live with the consequences of
- their own free choice of action.
- Perhaps 10 or 15 years ago there was an excuse for a system
- administrator to be ignorant of security issues. Nowadays, a system
- administrator who is ignorant of security is as out of place as a
- doctor who does not wash her hands before examining a patient.
- If a company pays for ignorance with failure....well, nobody dies.
- The information is available to anyone who wants to learn. Not just in
- obscure places; you can't pick up any conputer magazine or trade rag
- without seeing ads for security screaming out at you. Anyone who
- ignores all this is going to fail at something, be it security or
- development or some other part of their business.
- Those of us who DO try to keep up will have our jobs made harder by
- these viruses. If our security DOES work, on the other hand, we will
- notify the site which is the source of an attempted intrusion, so
- maybe they will get stopped up the line.
- I'm worried about another thing too. If you can have a virus come in
- to "protect" me from bad viruses, what's to stop a virus from coming
- in and doing other things....opening the door to competitors, reading
- our files for signs of political or criminal activity, or any other
- sort of monitoring?
- Nope, I want my system to run what we put on it and only what we put
- on it.
-
-
-
- --
- System Administrator Internet: betsys@cs.umb.edu
- MACS Dept, UMass/Boston Phone : 617-287-6448
- 100 Morrissey Blvd Staccato signals
- Boston, MA 02125-3393 of constant information....
-