Showing posts with label techdirt. Show all posts
Showing posts with label techdirt. Show all posts

Wednesday, March 21, 2007

more mobile malware madness

y'know, there are times when i'm not really a big fan of repeating myself (like when it comes to garbage masquerading as insight) but when a supposed top security [/straight face] influencer [straight face] takes a piece of techdirt trash at face value (what's next? will we be citing crackpot, errr, slashdot as an authoritative source?) what's a malware guy to do?

(if this is sounding angry it's because i finally had to unsub from techdirt a little while ago after discovering how inaccurate it is even outside the malware field)

taking the false claims and misrepresentations from the top:
  1. f-secure spreads mobile malware FUD - see my previous post on the subject...
  2. kaspersky spread FUD about the mobile malware threat - in the original article the kaspersky folks make it clear that you may well not be very likely to see mobile malware in your home country... the dependence on the regional market penetration of susceptible devices (smart phones) on the extent of the risk has been well established..
  3. kaspersky took a news crew into a faraday cage in order to make them understand that mobile malware was a real threat - no, they took them in the faraday cage to demonstrate how cabir works...
  4. cabir is only a threat when you intentionally ignore the warnings - this is the oft cited yes/no prompt that people consistently think should mitigate the mobile malware threat even though it has been well established that the 'no' button doesn't work (the worm just sends itself again immediately so the prompt comes back as soon as you hit 'no'... if you need to make a phone call your only real options are to hit 'yes' or get out of range of the other infected device because you can't use the phone while the prompt is there)...
  5. kaspersky has suggested that mobile malware is common - again, read the original article, you'll find they don't make that claim at all... they do say that there are certain geographic locations where it's more common than others, though...
  6. kaspersky could have just found someone with the virus instead of taking the news crew inside a faraday cage - yeah, an anti-virus company is going to demonstrate the functioning of a piece of malware that is epidemiologically equivalent to an airborne biological pathogen without the protective measures necessary to keep it from spreading beyond their control... now pull my other leg...

Monday, July 24, 2006

cutting through the mobile malware mess

techdirt, renowned for it's technical acumen (in other words it's signal to noise ratio is just slightly better than the garbage heap of the internet known as slashdot), has a post today that basically roasts f-secure for spreading mobile malware FUD... small problem - i couldn't find the FUD even after following all their links to supposed examples...

let's take a closer look, shall we?

from silicon.com:
Sal Viveros, wireless security evangelist at McAfee, said F-Secure's figures are largely in line with industry figures in terms of the total number of mobile viruses but added such viruses have largely been "proof of concept" to date and pose little threat to users.
ok, so we've got independant verification of f-secure's figures on the total number of mobile malware instances - score 1 for f-secure...

from a different article on silicon.com:
"The number of proof of concept viruses is increasing but that's not to say there has been an increase in the risk of infestation or that there is any need for panic or worry."
the person making this statement (david wood of symbian, the company holding the largest stake in the mobile phone market - aka the microsoft of the mobile phone market) clearly doesn't understand the nature of risk... the more instances of malware out there the greater the chance of a particular user encountering one of them, and therefore the greater the risk...

from the same article:
He added that these viruses will only spread with user permission and conceded that in very rare instances a user could contrive to infect their phone.
which shows that he clearly doesn't understand what's really going on in a mobile infection scenario... the no option doesn't work - you choose no and the prompt just comes back... press no again and the same thing happens... cabir and similar worms will just keep trying and effectively DoS the phone until the user chooses yes... user interaction is a non-issue if the user isn't given a real choice...

(see the video evidence here, it starts about 26 minutes in)

[edit - there's a better view of the video evidence here, starting at about 1 hour and 26 minutes]

from an article at vnunet.com:
"Phone viruses so far have been spreading over Bluetooth, so they only affect phones that are within a few metres. A MMS virus can potentially go global in minutes, just like an email worm," warned F-Secure's antivirus laboratory.
now that is a little troubling that it says minutes - because mikko hypponen, in the video referenced above, says 24 hours (both for mobile phone viruses and for email viruses) and he explains why... it's correct that it has the same potential speed as email worms but minutes seems like an error, either on the f-secure rep's side or (more likely, since they're known for botching these sorts of things) the reporter's side...

at any rate, saying a type of virus has the potential to do X is quite a bit different than saying a particular virus will do X or is likely to do X (which is the implication techdirt makes here)...

and from the a zdnet.co.uk article that triggered the current threat at techdirt:
"F-Secure is saying there's a huge risk of malcode spreading, but they've built this up," said Simon Perry, European vice president of security for CA. "If you look at their behaviour, they've consistently pushed this message. But it's a theoretical, not a real threat," he added.
i don't know where mr. perry is getting this - mikko hypponen (again in the video referenced above) made it seem pretty clear to me that mobile viruses are not anywhere near as problematic as their pc counterparts... susceptible phones are comparatively quite rare, and most of the malware can only spread to other phones that are physically nearby... that doesn't sound like a huge risk to me... he does mention some big total numbers (in the tens of thousands) but considering the law of large numbers as it applies to this situation that doesn't really raise eyebrows...

furthermore, in the same zdnet article an f-secure representative is quoted:
"I have difficulty understanding how this can be bad for [the antivirus] business. This is not a mass problem for all consumers, but our solution is available to those who need it, and there are people who need it today," Impivaara added.
it seems hard to imagine how f-secure could be making mobile malware out to be a huge risk when they're quoted in the media as saying the opposite...

still, techdirt has persisted in laying the FUD spreader charge against f-secure for some time now, not unlike many other community sources (slashdot and digg are the 2 glaring examples) have done to many other vendors... it bears a striking similarity to the reaction you get whenever you suggest there are genuine security risks in mac osx or linux... i thought at first it might just be one site or 2 sites, but the pattern that is emerging seems more widespread - it seems to have something to do with the wisdom of mobs where the wisdom of crowds fails due to the signal to noise ratio being too low... the reality is is that he who yells loudest has the most individual impact on the whole and without sufficient real wisdom to counteract that impact the whole becomes an ignorant mob...

Tuesday, July 12, 2005

the importance of good definitions

Techdirt has an article on the recent attempts by a group of organizations to come up with an agreed upon set of definitions for spyware and adware... predictably, Techdirt gets it all horribly, horribly wrong...

the author feels that what the software does or doesn't do is immaterial - that any unwanted application that got on one's machine by unknown means should be classified as spyware... he's not the only one who feels that way but there's a BIG problem with this line of reasoning...

the problem is that classifying instances of software on the basis of how they make some nebulous real world group of users feel (which is essentially what the author's position boils down to) is ridiculously difficult on a number of levels... not only will countless millions be spent on navel-gazing exercises trying to divine whether a particular instance of software in a particular software bundle is going to be unwanted and unnoticed at install time by some fictional average computer user or one if his/her 3.2 kids, but countless millions more will be spent defending against a deluge of specious lawsuits on the grounds that each classification was arbitrary and prejudicial - ultimately leading to a system where the courts, rather than the industry decide which program is spyware and which isn't..

we're computer scientists, not mind readers - we don't deal with this eye of the beholder crap unless we absolutely have to - and in this case we don't have to... we already have an umbrella term for all bad software - it's "malware"... if we're going to classify software for anti-whatever purposes we need to do it based on functional definitions (definitions based on what functions the software performs rather than definitions based on guessing how users will react to it)... we already have one malware classification saddled with an eye of the beholder definition, it's known as the "trojan", and that non-functional catch-all definition has been the bane of anti-trojan detection for years and is probably the reason we've had to make so many other classifications because it's proven totally unworkable as a classification that people can agree upon... classification based on eye of the beholder type criteria excludes widespread agreement by definition...

functional definitions, on the other hand, are much more reasonable... no guessing is involved and legal defense is practically a non-issue - define something based on it's function and it becomes much more feasible to demonstrate that a particular thing belongs or doesn't belong in that class...

on reading the actual document that the group of organizations (the anti-spyware coalition) came up with i think that for the most part the definitions are reasonable but a little on the wordy side... adware, for example could be much more simply defined as any software that advertizes a product or service other than itself... likewise spyware can be defined as any software that surreptitiously collects information from the user's system and sends it back to a remote 3rd party...

they did miss the mark on rootkits again, but the most notable problem is their adoption of spyware as an umbrella term for just about all bad software... they justify this by saying that the public at large is calling it that but this is foolish; 2 years ago the public at large was calling all bad software viruses, 2 years in the future they'll be using yet another term... how will this system cope with that? better to ignore the foibles of the unwashed masses and simply strive for internal consistency... trying to accomodate terminology misuse by people who don't know what they're talking about will never work because the people who don't know what they're talking about will not be consistent over time - leaving those of us who do know what we're talking about having to guess what they're talking about regardless of how accomodating we try to be...

EDIT (07/19/2005): i retract what i said about their definition of rootkits - i don't know what i was looking at before but now it looks fine... turning spyware into an umbrella term is still bad though...

Monday, May 16, 2005

microsoft antivirus: the next generation

by now you've probably heard that microsoft plans to get into the anti-virus industry (again) and has already entered the anti-spyware industry... they apparently are planning to release a complete security package for a fee (see Techdirt)...

now, Techdirt makes an interesting argument for why giving away the security package might be problematic for microsoft - that they might get accused of anti-trust violations with regard to the desktop security industry...

so it would seem that they can't not charge money for their product - but here's a different angle... a big part of the problem that their product will be addressing is the insecurity of their other products... the argument has been made that anti-virus companies are the ones behind the viruses and it's an easy argument to debunk (the industry is very competitive and the companies would use that information against their competitors if it were true), but when it comes to security exploits microsoft IS behind many of the vulnerabilities being exploited... they're basically charging you to protect you from the threats posed by their other software - which sounds an aweful lot like a protection racket to me...

worse still, however, is that with their complete security package they would have less motivation to actually fix the security problems in their other software... they could say that the threat posed by vulnerability X is mitigated by Microsoft Security Suite (tm), so the severity of the problem is less than critical so fixing it will be a lesser priority... they've been trying to address security for years now and so far it's been an abject failure - we have no greater confidence in the security of their software now than we did when they started... this could mark the end of their efforts to write more secure code - it could be the sign that they're giving up... writing software to protect people from exploits when you should be fixing the vulnerabilities certainly sounds like a cop-out to me...

so really, there doesn't seem to be any moral highground for microsoft in this venture - either they kill the desktop security software industry by giving their own product away for free (like they did to netscape), or they can charge money for their product and at best admit defeat at writing secure code or at worst be guilty of protection racketeering...

maybe they should just stay out of the security industry entirely... they've tried their hand at it before (msav) and that was an abject failure too...