how many of you reading this remember conficker? i certainly remember it, but i have a long memory, especially when it comes to regrets. you may recall an apology i posted some years ago concerning the possibility that i might have made a small contribution to the feature-set of that malware by way of giving the bad guys ideas.
well, from where i sit, that may very well have happened again, only it wasn't me this time, it was an AV vendor. now you might expect that, as a result, said vendor may become much more scrupulous about censoring themselves. it's no easy task, let me tell you, but it's certainly something that some of you (and myself included) probably expect from the people who are supposed to be protecting us.
alternatively, you might expect just an apology, under the philosophy that it's better to ask forgiveness than permission. that would certainly be easier, although accepting responsibility for negative outcomes is not generally considered good for the public image of a company. as an individual, owning up to one's mistakes and accepting responsibility is considered a mark of maturity, but the rules for companies are unfortunately very different in this regard.
which brings us to the thing you might not have expected, but probably should have - bragging about it as though it were a "prediction":
that link, by the way, points to this story on informationweek.com which in turn points back to a post on the f-secure blog where it was suggested that if the people behind the flashback malware for the mac upgraded to unpatched java vulnerabilities (it had only been using exploits for old, already patched vulnerabilities before) they might affect a lot more people.
is that a prediction or an instruction? f-secure's blog, as you might be aware, is one of the most (perhaps the most) widely read blogs in the entire anti-malware field. it stands to reason that if the people behind flashback are reading any anti-malware blogs, that one is probably on their list. even if it isn't, that particular post was about their efforts and would most likely have been forwarded by someone who was aware of their work (just as, in a small software development company, every press release, news article, and TV spot that mentions your work gets sent to everyone in the company).
would they have upgraded to unpatched vulnerabilities without that suggestion being made? perhaps, perhaps not. we'll never know. do all malware profiteers who use exploits for patched vulnerabilities inevitably upgrade to ones for unpatched vulnerabilities? that's doubtful - exploits for unpatched vulnerabilities are much harder to come by than ones for vulnerabilities that have already been patched. the transition is anything but inevitable, so there exists the very real possibility that f-secure's "prediction" was more like a self-fulfilling prophesy.
but of course, it sounds better if you call it a prediction. it sounds like something that adds value to their voice (though they have plenty already without that) and so helps to build the brand.
it seems to me that openly predicting what the bad guys are going to do next, or speculating on what they could do better, only invites them to take your advice. you might then capitalize on that with liberal amounts of spin, but at the end of the day is giving them ideas really so much more benign than giving them code? don't you tempt fate either way?
devising a framework for thinking about malware and related issues such as viruses, spyware, worms, rootkits, drm, trojans, botnets, keyloggers, droppers, downloaders, rats, adware, spam, stealth, fud, snake oil, and hype...
Showing posts with label f-secure. Show all posts
Showing posts with label f-secure. Show all posts
Monday, April 30, 2012
Sunday, February 12, 2012
is the iphone really malware free?
friday morning mikko hypponen posted a tweet about the folks behind flexispy changing the look of their site, and i took the opportunity to pose a question to him about iphone malware. you see, flexispy is (or was) a piece of mobile malware that f-secure posted about about 6 years ago. not only that, but there's a version of the software for the iphone, so i found mikko's repeated statement that there was no malware for the iphone to be a little strange in light of the fact that both he and his company have been aware of software that seems to contradict that claim for quite some time.
the resulting discussion with both mikko and his colleague sean sullivan lead in 2 separate directions, so let's look at them in turn. first mikko responded with the following:
so what people really mean when they say no malware for the iphone is that there's no malware in the app store. this is an important distinction, because the iphone ecosystem (and by extension, the threat landscape) extends beyond the app store. when chris di bona attempted to downplay the threat malware played to android devices by pointing to google's efforts to keep their android marketplace clean, a number of folks were quick to point out that the android ecosystem extended beyond google's android marketplace, so it seems strange that people would forget the same line of reasoning applies to the iphone as well.
one other thing (well, the only other thing, really) that mikko said was:
but such unqualified claims are, as mikko has revealed, not technically true. it's not that there's no malware for iphones, it's that there's no malware in the iphone app store.
but wait, is that really true? is there no malware in the app store at all? i'm not sure that's true when we've recently been made aware of apps in the app store that collect and send personal information to a remote server without the user's knowledge or consent. but it's about time i turned my attention towards the much more verbose and nuanced discussion that sean sullivan and i had on the subject. perhaps he can shed light on why these personal info stealing apps shouldn't be considered malware. while mikko didn't question the classification of flexispy as malware, sean informed me that f-secure no longer calls it malware.
why exactly that stops it from being malware in general or spyware in particular in the context of mobile device security i still can't fathom, but sean offered up two things by way of explanation. one being a concern over being sued... by malware vendors. this rationale is something i heard from dr. solomon years and years ago, but i have to admit i had hoped that the industry had become less spineless in the interim. i guess that was too much to hope for. google may stand up to the government on behalf of it's users (perhaps not always, and perhaps it doesn't always succeed, but it has tried), but apparently anti-malware vendors only stand up for their users when there's zero risk they'll be challenged.
the other thing he offered was the following definition of spyware from google:
now, sean also pointed me towards the anti-spyware coalition's risk model description document. i had hoped it would help me to learn more about this "self-install" concept that sean assured me was part of an industry agreed upon standard definition. things didn't turn out that way, since the term "self-install" doesn't appear in that document, but the topic of installation and distribution do figure prominently in the contexts of both risk factors and consent factors. unfortunately this document from 2007 appears once again to be geared to desktop computing rather than mobile computing. that's probably not too surprising considering it's 5 years old now, but it does highlight the age old problem of letting context into the classification process. mobile devices are easier to gain illicit physical access to, as well as being shared more freely (and more frequently) in social circumstances by their owners. the issue of consent at the point of install has far less significance as a risk mitigation for mobile devices. furthermore, the issue of consent at the point of install pretty clearly drops the ball in the case of trojans because it's not necessarily fully informed consent.
as the risk model description document demonstrates, somewhere along the line the industry gave up on basing it's classification system on functional definitions. sean insists that this is a "stricter process" but i think it's more correct to say that it utilizes more criteria than a functional definition system would. utilizing more criteria doesn't always lead to a stricter process because not all criteria are created equal and, at least in the case of the risk model description document, some of those criteria are used to create exceptions (which are generally not the hallmark of a strict process).
one of the last things sean wondered is how could the AV industry possibly use my (supposedly) broader definition(s) and not be accused of FUD. now, aside from the fact that the industry is already accused of FUD (and worse) pretty much regardless of what they do, i think it's important to spell out one of the key differences between a functional definition and the kind of definitions that sean sees in use. definitions that include contextual evaluation are judgements, they engender choice and leave room for agendas. a functional definition has no judgement, it is purely descriptive of the functional capabilities of what is being classified. you can no more be blamed for saying software that spies is spyware than you can for saying water is wet or the sky is blue. there's no silver bullet to make accusations go away, but if you take judgement out of the equation it should render those accusations baseless.
so why is all of this important? because it appears that we've somehow stumbled upon a way in which malware can be classified as "riskware" instead of malware. nobody hears about the riskware classification, nobody cares. they hear "No malware for iPhones" and they shut the rest out because that's all they needed to know (or at least according to traditional notions of malware that should have been all they needed to know). classifying malware as something other than malware seems to be what's enabling people to make the "No malware for iPhones" claim, like some kind of terminological shell game. "No malware for iPhones" makes people think the devices are safe and worry free, but there are risks, and not just for those who jailbreak."No malware for iPhones" is creating a false sense of security and with the revelations that have been made about apple's abject failure to lock down a particular type of personal information and the near ubiquitous exploitation of that failure by app developers, it seems like the stuff of snake-oil.
i tend to think that when people face risks they want to know about them rather than be told there's nothing to worry about, and i tend to think that when those risks come in the form of software that acts against the user's interests, informing the user is the AV industry's job. some people don't want that to happen, they want their own interests to take precedent. if the AV industry allows that to happen through inaction (or worse, facilitates it) then they don't deserve the reputation they have for protecting the user. the industry may not be able to put AV software on iphones yet, but they can certainly do a better job of raising awareness of the risks than going around telling people there's "No malware for iPhones". maybe when public awareness is raised apple will change their ways.
the resulting discussion with both mikko and his colleague sean sullivan lead in 2 separate directions, so let's look at them in turn. first mikko responded with the following:
@imaguid No malware for iPhones. If you jailbreak your phone: all bets are off. Flexispy runs on jailbroken only.now to me, this gets to one of the hearts of the matter. when people say there's no malware for the iphone, they're only talking about non-jailbroken phones. the pertinent difference between a normal iphone and a jailbroken iphone is that normal iphones can only install apps from the app store. the app store is a so-called walled garden where all the apps go through a screening process to keep out undesirable programs.
so what people really mean when they say no malware for the iphone is that there's no malware in the app store. this is an important distinction, because the iphone ecosystem (and by extension, the threat landscape) extends beyond the app store. when chris di bona attempted to downplay the threat malware played to android devices by pointing to google's efforts to keep their android marketplace clean, a number of folks were quick to point out that the android ecosystem extended beyond google's android marketplace, so it seems strange that people would forget the same line of reasoning applies to the iphone as well.
one other thing (well, the only other thing, really) that mikko said was:
@imaguid ...and to top it all: we couldn't do anything about iPhone malware anyway, as Apple won't allow Antivirus products to iPhone.and you know what? why should they allow them when there's apparently "No malware for iPhones"? whether or not there is malware for the iphone, apple doesn't want people to think there is. there is this (rather old) idea that computers can be as easy to use as an appliance (like a toaster). this idea is actually very appealing. it promises computers that just work, computers that don't get malware, computers that are easy and safe and worry free. that promise is part of the secret sauce behind apple's marketing, but if they allowed AV products in then it would dispel the illusion of the appliance computer and apple's products would lose their lustre. it's very convenient, then, that AV vendors are willing to be complicit in apple's marketing by repeating the claim that there's "No malware for iPhones".
but such unqualified claims are, as mikko has revealed, not technically true. it's not that there's no malware for iphones, it's that there's no malware in the iphone app store.
but wait, is that really true? is there no malware in the app store at all? i'm not sure that's true when we've recently been made aware of apps in the app store that collect and send personal information to a remote server without the user's knowledge or consent. but it's about time i turned my attention towards the much more verbose and nuanced discussion that sean sullivan and i had on the subject. perhaps he can shed light on why these personal info stealing apps shouldn't be considered malware. while mikko didn't question the classification of flexispy as malware, sean informed me that f-secure no longer calls it malware.
@imaguid @mikko But they then added an installation interface, and we have since categorized it as riskware.that's right - in spite of the fact that it is designed and marketed as a tool for spying on other people, it is not classified as spyware or malware because it was given an installation interface - meaning that the attacker has to have physical control of the phone for at least as long as it takes to install an app. now, on the desktop this might be a meaningful mitigating factor, but on mobile devices where physical access is so much easier to achieve? come on...
why exactly that stops it from being malware in general or spyware in particular in the context of mobile device security i still can't fathom, but sean offered up two things by way of explanation. one being a concern over being sued... by malware vendors. this rationale is something i heard from dr. solomon years and years ago, but i have to admit i had hoped that the industry had become less spineless in the interim. i guess that was too much to hope for. google may stand up to the government on behalf of it's users (perhaps not always, and perhaps it doesn't always succeed, but it has tried), but apparently anti-malware vendors only stand up for their users when there's zero risk they'll be challenged.
the other thing he offered was the following definition of spyware from google:
Software that self-installs on a computer, enabling information to be gathered covertly about a person's Internet use, passwords, etc.apparently it's not enough that the software spies on you in order for it to be called spyware, it has to "self-install" as well. now i'm sure i must be missing something, because this definition seems to exclude anything where the victim is socially engineered into installing the software (it's hard to call it self-installing if the victim is the one installing it). it also seems to exclude anything that utilizes the particular trojan horse case where the software actually does perform the function it claims to, so the payload is additional functionality instead of strictly misrepresented functionality. a game that also steals passwords, a text editor that also sniffs network traffic, webcam software that just happens to send the video stream to a second undisclosed location in addition to the intended recipient - all of these are examples of software that ought to be called spyware but which the victim actually knowingly installs (because the undesirable functionality is unreported) and thus fails to meet the "self-install" criteria. this is precisely the type of situation users of the photo sharing iphone app called path faced.
now, sean also pointed me towards the anti-spyware coalition's risk model description document. i had hoped it would help me to learn more about this "self-install" concept that sean assured me was part of an industry agreed upon standard definition. things didn't turn out that way, since the term "self-install" doesn't appear in that document, but the topic of installation and distribution do figure prominently in the contexts of both risk factors and consent factors. unfortunately this document from 2007 appears once again to be geared to desktop computing rather than mobile computing. that's probably not too surprising considering it's 5 years old now, but it does highlight the age old problem of letting context into the classification process. mobile devices are easier to gain illicit physical access to, as well as being shared more freely (and more frequently) in social circumstances by their owners. the issue of consent at the point of install has far less significance as a risk mitigation for mobile devices. furthermore, the issue of consent at the point of install pretty clearly drops the ball in the case of trojans because it's not necessarily fully informed consent.
as the risk model description document demonstrates, somewhere along the line the industry gave up on basing it's classification system on functional definitions. sean insists that this is a "stricter process" but i think it's more correct to say that it utilizes more criteria than a functional definition system would. utilizing more criteria doesn't always lead to a stricter process because not all criteria are created equal and, at least in the case of the risk model description document, some of those criteria are used to create exceptions (which are generally not the hallmark of a strict process).
one of the last things sean wondered is how could the AV industry possibly use my (supposedly) broader definition(s) and not be accused of FUD. now, aside from the fact that the industry is already accused of FUD (and worse) pretty much regardless of what they do, i think it's important to spell out one of the key differences between a functional definition and the kind of definitions that sean sees in use. definitions that include contextual evaluation are judgements, they engender choice and leave room for agendas. a functional definition has no judgement, it is purely descriptive of the functional capabilities of what is being classified. you can no more be blamed for saying software that spies is spyware than you can for saying water is wet or the sky is blue. there's no silver bullet to make accusations go away, but if you take judgement out of the equation it should render those accusations baseless.
so why is all of this important? because it appears that we've somehow stumbled upon a way in which malware can be classified as "riskware" instead of malware. nobody hears about the riskware classification, nobody cares. they hear "No malware for iPhones" and they shut the rest out because that's all they needed to know (or at least according to traditional notions of malware that should have been all they needed to know). classifying malware as something other than malware seems to be what's enabling people to make the "No malware for iPhones" claim, like some kind of terminological shell game. "No malware for iPhones" makes people think the devices are safe and worry free, but there are risks, and not just for those who jailbreak."No malware for iPhones" is creating a false sense of security and with the revelations that have been made about apple's abject failure to lock down a particular type of personal information and the near ubiquitous exploitation of that failure by app developers, it seems like the stuff of snake-oil.
i tend to think that when people face risks they want to know about them rather than be told there's nothing to worry about, and i tend to think that when those risks come in the form of software that acts against the user's interests, informing the user is the AV industry's job. some people don't want that to happen, they want their own interests to take precedent. if the AV industry allows that to happen through inaction (or worse, facilitates it) then they don't deserve the reputation they have for protecting the user. the industry may not be able to put AV software on iphones yet, but they can certainly do a better job of raising awareness of the risks than going around telling people there's "No malware for iPhones". maybe when public awareness is raised apple will change their ways.
![]() |
| image from secmeme.com |
Sunday, December 04, 2011
privacy in the age of forever
i've written before about what i think privacy is, though classifying it as an obscurity-based strategy for satisfying a basic need for safety was very high level and abstract. it could also be taken the wrong way, since people often think about safety as only applying to their physical person (i.e. physical safety). our physical bodies aren't the only thing we want to keep safe, of course. our families, our property, our reputations, our opportunities, etc. are all things we want to keep safe, all things we want to protect, and all things for which privacy can help offer some protection.
privacy is often described in terms of controlling information but on reading danah boyd's thoughts on privacy i realized it can and should be expressed a different way. controlling information is the means by which privacy is often accomplished, but it's not what privacy is actually about. while i don't agree with the narrow scope boyd used ('asserting control over social situations'), at it's root was a kernel of truth. while the means by which privacy is achieved may be the control of information, the point is the control of outcomes related to that information, whether they be social outcomes, business outcomes, educational outcomes, housing outcomes, health outcomes, political outcomes, legal outcomes, etc.
controlling outcomes is, of course, the point of any strategy. the thing about strategies, though, is that their appropriateness depends heavily on the situation, and what people largely don't realize is that there is a situation which is becoming increasingly ubiquitous under which many traditional privacy strategies don't work very well.
in the online world everything is recorded and stored for consumption at a different time or in a different place. it is essentially a persistent medium through which we can interact with each other. this is a significant point because for most of human history the real world has largely been an ephemeral medium for interaction. our behaviour, the strategies that we develop as we mature in the real world take great advantage of the ephemeral nature of our interactions with others. if you weren't present the day your best friend made a hurtful comment about you to others in your peer group then you missed out, that experience is gone, "you had to be there" as it were. this ephemeral property of the event, the fact that the information only exists in a very particular point in time and space, serves to restrict access to that information to only those who were present at the same point in time and space.
once we start interacting online that ephemeral property ceases to exist, so access to the information that we might have otherwise expected to be restricted due to it's ephemeral nature is no longer restricted in that way. we often don't realize that, however, because we take that 'ephemeral-ness' for granted. it's not easy adapting to a situation where that no longer applies.
for example, imagine for a moment that every word you speak goes into a speech bubble above your head, like in the comic books, except unlike the comics the speech bubble doesn't go away, it stays with you and allows people to read what you said 5 minutes ago or even 5 hours ago. every swear word, every uncharitable thought uttered under your breath in the heat of the moment, everything. can you imagine how you'd adapt to that sort of situation? you'd probably censor yourself a lot more than you currently do - since your utterances have become persistent the natural adaptation that would allow you to continue to control the outcomes associated with what you say is to say far less.
at first blush that might not seem unbearably bad, but let's take things a step farther because that example really only dealt with your words. this time (this is inspired by danah boyd's post, by the way), imagine you are stuck in a very large room and surrounded by everyone you ever have and ever will meet. imagine trying to live your life in this room. how do you play with your toddler in front of your business partner or a potential client? how do you woo your future wife in front of your children or your parents? how do you hang out with your high school friends in front of your future employers? how do you project an image of cool professionalism to people who saw you fall face first in a mud puddle? again, in such a situation, surrounded by people from disparate contexts of your life, the natural adaptation is to reduce the amount of information that you reveal about yourself, but think about those questions; there are certain outcomes that can't reasonably happen without revealing sensitive things about yourself.
these examples may seem absurd, but this is what it means to interact in a persistent medium. anyone, anywhere, at any time can (in theory) see the footprints you've left in that medium. your interactions in a persistent medium transcend time and space, allowing people to effectively 'TiVo' your life (or at least the portion of it that's been recorded).
obviously this represents an unacceptable state of affairs for online interaction. there's very little utility in it if it requires such profound self-censorship. that's the reason that technological privacy controls and privacy settings were invented - to help replace the access control that was lost when the information became recorded. unfortunately the technological controls don't operate the same way that ephemerality does, so trying to achieve a simliar outcome with them is complicated and often not intuitive.
sean sullivan (at least i assume it was that sean) made a post on the f-secure blog that highlighted a talk given by clay shirky where he said (as quoted by sean) that "managing privacy isn't natural". technically what shirky said was that managing privacy settings isn't natural. we manage privacy every day in every interaction we make with others, but managing privacy settings by definition can't be natural because the settings themselves are artificial. this has implications for the kind of privacy one can achieve though managing such settings - it is itself an artificial, man made analog to natural privacy, and prone not only to being incomplete in comparison to it's natural counterpart but also to breaking down as all man made things do.
but as untrustworthy as that sounds, it will have to be good enough, because we can't turn back the hands of time or halt progress. we can't even opt out of the persistent medium. oh, we might get away with staying out of the online world ourselves, but persistence is intruding into the real world more and more. public photography, for example, is turning the public sphere (which used to represent an ephemeral medium) into a much more persistent medium than it used to be. this can be a good thing when it helps to expose things like police brutality, but it poses a not insignificant problem for us as a society.
paul ducklin raised some concerns about this very problem last year on the sophos blog. at the time i didn't think his concept of public privacy made much sense, but when examined through the lens of a traditionally ephemeral medium of interaction being changed into a persistent one without people noticing or appreciating the consequences for their existing privacy strategies, it starts to be clear (to me) that this is a problem that deserves some consideration. i wouldn't consider it an invasion of privacy, per se, but perhaps it would qualify as a subversion of privacy, since it changes the environment to one where the strategies people were using to control outcomes no longer work properly, and it does so without making it clear that that had happened.
are we ready for the implications of living in a world where our actions live on beyond the moment? i don't really know. certainly we can manage our privacy settings online, and maybe we can obscure our identifying features offline (though that may interact poorly with some of our cultural norms) so that public photography becomes less of an issue. i just wonder if explaining to the next generation what it was like before everything became persistent will be the last time we ever get to use the phrase "you had to be there".
privacy is often described in terms of controlling information but on reading danah boyd's thoughts on privacy i realized it can and should be expressed a different way. controlling information is the means by which privacy is often accomplished, but it's not what privacy is actually about. while i don't agree with the narrow scope boyd used ('asserting control over social situations'), at it's root was a kernel of truth. while the means by which privacy is achieved may be the control of information, the point is the control of outcomes related to that information, whether they be social outcomes, business outcomes, educational outcomes, housing outcomes, health outcomes, political outcomes, legal outcomes, etc.
controlling outcomes is, of course, the point of any strategy. the thing about strategies, though, is that their appropriateness depends heavily on the situation, and what people largely don't realize is that there is a situation which is becoming increasingly ubiquitous under which many traditional privacy strategies don't work very well.
in the online world everything is recorded and stored for consumption at a different time or in a different place. it is essentially a persistent medium through which we can interact with each other. this is a significant point because for most of human history the real world has largely been an ephemeral medium for interaction. our behaviour, the strategies that we develop as we mature in the real world take great advantage of the ephemeral nature of our interactions with others. if you weren't present the day your best friend made a hurtful comment about you to others in your peer group then you missed out, that experience is gone, "you had to be there" as it were. this ephemeral property of the event, the fact that the information only exists in a very particular point in time and space, serves to restrict access to that information to only those who were present at the same point in time and space.
once we start interacting online that ephemeral property ceases to exist, so access to the information that we might have otherwise expected to be restricted due to it's ephemeral nature is no longer restricted in that way. we often don't realize that, however, because we take that 'ephemeral-ness' for granted. it's not easy adapting to a situation where that no longer applies.
for example, imagine for a moment that every word you speak goes into a speech bubble above your head, like in the comic books, except unlike the comics the speech bubble doesn't go away, it stays with you and allows people to read what you said 5 minutes ago or even 5 hours ago. every swear word, every uncharitable thought uttered under your breath in the heat of the moment, everything. can you imagine how you'd adapt to that sort of situation? you'd probably censor yourself a lot more than you currently do - since your utterances have become persistent the natural adaptation that would allow you to continue to control the outcomes associated with what you say is to say far less.
at first blush that might not seem unbearably bad, but let's take things a step farther because that example really only dealt with your words. this time (this is inspired by danah boyd's post, by the way), imagine you are stuck in a very large room and surrounded by everyone you ever have and ever will meet. imagine trying to live your life in this room. how do you play with your toddler in front of your business partner or a potential client? how do you woo your future wife in front of your children or your parents? how do you hang out with your high school friends in front of your future employers? how do you project an image of cool professionalism to people who saw you fall face first in a mud puddle? again, in such a situation, surrounded by people from disparate contexts of your life, the natural adaptation is to reduce the amount of information that you reveal about yourself, but think about those questions; there are certain outcomes that can't reasonably happen without revealing sensitive things about yourself.
these examples may seem absurd, but this is what it means to interact in a persistent medium. anyone, anywhere, at any time can (in theory) see the footprints you've left in that medium. your interactions in a persistent medium transcend time and space, allowing people to effectively 'TiVo' your life (or at least the portion of it that's been recorded).
obviously this represents an unacceptable state of affairs for online interaction. there's very little utility in it if it requires such profound self-censorship. that's the reason that technological privacy controls and privacy settings were invented - to help replace the access control that was lost when the information became recorded. unfortunately the technological controls don't operate the same way that ephemerality does, so trying to achieve a simliar outcome with them is complicated and often not intuitive.
sean sullivan (at least i assume it was that sean) made a post on the f-secure blog that highlighted a talk given by clay shirky where he said (as quoted by sean) that "managing privacy isn't natural". technically what shirky said was that managing privacy settings isn't natural. we manage privacy every day in every interaction we make with others, but managing privacy settings by definition can't be natural because the settings themselves are artificial. this has implications for the kind of privacy one can achieve though managing such settings - it is itself an artificial, man made analog to natural privacy, and prone not only to being incomplete in comparison to it's natural counterpart but also to breaking down as all man made things do.
but as untrustworthy as that sounds, it will have to be good enough, because we can't turn back the hands of time or halt progress. we can't even opt out of the persistent medium. oh, we might get away with staying out of the online world ourselves, but persistence is intruding into the real world more and more. public photography, for example, is turning the public sphere (which used to represent an ephemeral medium) into a much more persistent medium than it used to be. this can be a good thing when it helps to expose things like police brutality, but it poses a not insignificant problem for us as a society.
paul ducklin raised some concerns about this very problem last year on the sophos blog. at the time i didn't think his concept of public privacy made much sense, but when examined through the lens of a traditionally ephemeral medium of interaction being changed into a persistent one without people noticing or appreciating the consequences for their existing privacy strategies, it starts to be clear (to me) that this is a problem that deserves some consideration. i wouldn't consider it an invasion of privacy, per se, but perhaps it would qualify as a subversion of privacy, since it changes the environment to one where the strategies people were using to control outcomes no longer work properly, and it does so without making it clear that that had happened.
are we ready for the implications of living in a world where our actions live on beyond the moment? i don't really know. certainly we can manage our privacy settings online, and maybe we can obscure our identifying features offline (though that may interact poorly with some of our cultural norms) so that public photography becomes less of an issue. i just wonder if explaining to the next generation what it was like before everything became persistent will be the last time we ever get to use the phrase "you had to be there".
Monday, September 13, 2010
don't be too proud of this technological terror you've created
lot's of folks have been posting about the 'here you have' mass mailing email worm that's been making the rounds. it's strange that such an old-school technique should inspire so much discussion, but it has and some of it's actually interesting.
one of the discussions comes from the enterprise application whitelisting blog, in other words, it comes from application whitelisting vendor bit9. they are, perhaps understandably, quite bullish about the fact that their technology would have stopped the threat before it could have spread while the anti-virus software vendors were supposedly left to scramble to get detection added after the fact.
while it's true that a classical blacklist or known-malware scanner would require updating after the threat becomes known, it seems that at least some of the anti-virus software vendors that harry sverdlove was taking a shot at were actually able to detect the threat heuristically (see f-secure's post or kaspersky lab's post for example).
it also deserves to be said that many anti-virus software vendors are bundling whitelisting in their suites these days, so people using that feature of those offerings would have been just as safe as if they'd been using bit9's.
most importantly, though - if social engineering can be used to get people to extract malware from a password protected archive sent as an attachment and then run that malware (and we have historical examples of successful email worms that used precisely this technique), social engineering can be used to get people to add that malware to the whitelist.
whitelists do not make you magically immune to this threat. i'm not even convinced they raise the bar a significant amount when you consider how easily people can be tricked into doing all sorts of dumb things. perhaps an enterprise would be in a better position because relatively few would (in theory) have access to modify the whitelist, but administrative users aren't above doing dumb things.
one of the discussions comes from the enterprise application whitelisting blog, in other words, it comes from application whitelisting vendor bit9. they are, perhaps understandably, quite bullish about the fact that their technology would have stopped the threat before it could have spread while the anti-virus software vendors were supposedly left to scramble to get detection added after the fact.
while it's true that a classical blacklist or known-malware scanner would require updating after the threat becomes known, it seems that at least some of the anti-virus software vendors that harry sverdlove was taking a shot at were actually able to detect the threat heuristically (see f-secure's post or kaspersky lab's post for example).
it also deserves to be said that many anti-virus software vendors are bundling whitelisting in their suites these days, so people using that feature of those offerings would have been just as safe as if they'd been using bit9's.
most importantly, though - if social engineering can be used to get people to extract malware from a password protected archive sent as an attachment and then run that malware (and we have historical examples of successful email worms that used precisely this technique), social engineering can be used to get people to add that malware to the whitelist.
whitelists do not make you magically immune to this threat. i'm not even convinced they raise the bar a significant amount when you consider how easily people can be tricked into doing all sorts of dumb things. perhaps an enterprise would be in a better position because relatively few would (in theory) have access to modify the whitelist, but administrative users aren't above doing dumb things.
Tuesday, August 24, 2010
market-speak is a tough habit to quit
on of the anti-malware marketing world's greatest victories was installing their market-speak as the lingua franca of anti-malware security, and to have done so in such a way that hardly anyone even notices. i even catch myself sometimes talking about a product offering protection instead of a product offering assistance (products don't protect you, you protect you with the product's help).
i happened upon a marketing video produced by f-secure for their safe and savvy blog not too long ago. it's possible it wasn't intended to be a marketing video, but... well... i think the video speaks for itself in that regard. it clearly tries to sell product. let's follow along and play the market-speak bingo.
so did you notice the nice big "100%"? it didn't stay for very long. the correct answer to the question "how can i be 100% sure i'm safe?" is that you can't. there is no absolute protection and anyone who says differently is trying to sell you snake-oil. offering 100% certainty you're protected is basically equivalent to claiming 100% protection - which is one of the oldest AV snake-oil tricks in the book. for shame, f-secure, for shame.
how about the references to a "solution", did everyone catch that? yeah, unfortunately the only problems these products solve are the business (or similar) problems that state 'thou must useth anti-virus'. actual security problems are not solved by these products - they don't make the problem go away, they don't make it so you don't have to worry anymore (even though they intentionally lead you into a false sense of security by suggesting you can stop worrying). security products are tools, not solutions - they don't solve real problems anymore than hammers do.
and did you happen to catch all the times when they said they "protect" you or the product protects you without qualifying that it's only partial protection? <sarcasm>yeah, that's not going to lead to a false sense of security (where people treat the product as install-and-forget security) at all</sarcasm>. why would a person continue to think about security and how to be and stay secure when vendors tell that person that they'll take care of that for them?
now i could sit here continuing to roast f-secure for their snake-oil trifecta, but as i said before even i catch myself falling into the same language patterns - early anti-malware marketing has left quite a mark on us. besides which, there's actually a lot to like in that video. the portrayal of the threat landscape and the technologies brought to bear on it are humanized and relate-able. heck, there's even someone labeled "Customer" who takes a tool offered by someone labeled "F-Secure" to chase off a 3rd person labeled "Virus" - even when the words are wrong and give the impression "we protect you", the action itself is right.
oh well, maybe their next video will feature more of what was good in this video and less of what was bad. it's not easy to break out of the pattern. we can only hope they try.
i happened upon a marketing video produced by f-secure for their safe and savvy blog not too long ago. it's possible it wasn't intended to be a marketing video, but... well... i think the video speaks for itself in that regard. it clearly tries to sell product. let's follow along and play the market-speak bingo.
so did you notice the nice big "100%"? it didn't stay for very long. the correct answer to the question "how can i be 100% sure i'm safe?" is that you can't. there is no absolute protection and anyone who says differently is trying to sell you snake-oil. offering 100% certainty you're protected is basically equivalent to claiming 100% protection - which is one of the oldest AV snake-oil tricks in the book. for shame, f-secure, for shame.
how about the references to a "solution", did everyone catch that? yeah, unfortunately the only problems these products solve are the business (or similar) problems that state 'thou must useth anti-virus'. actual security problems are not solved by these products - they don't make the problem go away, they don't make it so you don't have to worry anymore (even though they intentionally lead you into a false sense of security by suggesting you can stop worrying). security products are tools, not solutions - they don't solve real problems anymore than hammers do.
and did you happen to catch all the times when they said they "protect" you or the product protects you without qualifying that it's only partial protection? <sarcasm>yeah, that's not going to lead to a false sense of security (where people treat the product as install-and-forget security) at all</sarcasm>. why would a person continue to think about security and how to be and stay secure when vendors tell that person that they'll take care of that for them?
now i could sit here continuing to roast f-secure for their snake-oil trifecta, but as i said before even i catch myself falling into the same language patterns - early anti-malware marketing has left quite a mark on us. besides which, there's actually a lot to like in that video. the portrayal of the threat landscape and the technologies brought to bear on it are humanized and relate-able. heck, there's even someone labeled "Customer" who takes a tool offered by someone labeled "F-Secure" to chase off a 3rd person labeled "Virus" - even when the words are wrong and give the impression "we protect you", the action itself is right.
oh well, maybe their next video will feature more of what was good in this video and less of what was bad. it's not easy to break out of the pattern. we can only hope they try.
Wednesday, August 04, 2010
digital signatures are not a poor man's whitelist
back when mcafee had their catastrophic false positive i made the suggestion that av vendors in general (and mcafee in particular) could use a whitelist of critical system files to avoid false alarms that render systems unbootable/unusable. basically the idea being that known trusted files could be ignored by anti-malware components prone to false alarm. in the comments of that post didier stevens suggested checking digital signatures of files could be used as an alternative. at first i thought that was an OK compromise to developing a proper whitelist of critical files, but recent events have made me rethink that.
as kaspersky's alexander gostev described, a digital signature will cause a file to be regarded as trusted by security software, much like didier suggested in his comment, and if it's malware that means it will be effectively hidden from the anti-malware software.
i think that's a pretty glaring problem and underscores the fact that digital signatures are a poor substitute for a proper whitelist. a proper whitelist is constructed of items that are known and trusted, but with digital signatures it's neither the anti-malware vendor nor the user who's constructing this implied whitelist. instead, the implicit whitelist is constructed jointly by every tom, dick, and harry who happens by hook or by crook to get his/her hands on a valid digital certificate. that means the people who make the determination of whether a file is safe and/or trustworthy are (generally) the same ones who created it. however, those people could lie, they could fail to actually check the safety/integrity of the file they're signing, or they might not even be qualified to check the safety/integrity of the file they're signing. even if the owner of the digital certificate used to sign the file is a trustworthy entity, that doesn't mean the file is also trustworthy. first and foremost, trust is not commutative. besides that, though, as the stuxnet example shows us, the certificate can fall into the wrong hands. treating digital signatures as whitelist entries creates a situation where altogether too many entities have influence over what is considered trusted and safe.
thus digital signatures can not tell us what we need a whitelist to tell us, namely that the file is trusted and safe. the presence of a valid digital signature only tells us two things: that the file was signed with certificate X (which may or may not be under the exclusive control of the party it was issued to), and that the file hasn't changed since it was signed. whether it's safe, whether it's fit for use, is entirely outside the scope of what a digital signature can tell us.
i think the idea of using a whitelist to avoid false alarms is a good one, but using digital signatures in it's place is a shortcut. av vendors need to stop cutting corners and implement proper whitelists for this particular application. there are already tens of thousands of digitally signed malware samples in f-secure's collection so i'm at a loss trying to figure out why this technique of false positive avoidance hasn't been abandoned already. now that news that detections of stuxnet didn't start until after the digital signature expired, malware authors will surely be looking to exploit this behaviour more and more.
as kaspersky's alexander gostev described, a digital signature will cause a file to be regarded as trusted by security software, much like didier suggested in his comment, and if it's malware that means it will be effectively hidden from the anti-malware software.
i think that's a pretty glaring problem and underscores the fact that digital signatures are a poor substitute for a proper whitelist. a proper whitelist is constructed of items that are known and trusted, but with digital signatures it's neither the anti-malware vendor nor the user who's constructing this implied whitelist. instead, the implicit whitelist is constructed jointly by every tom, dick, and harry who happens by hook or by crook to get his/her hands on a valid digital certificate. that means the people who make the determination of whether a file is safe and/or trustworthy are (generally) the same ones who created it. however, those people could lie, they could fail to actually check the safety/integrity of the file they're signing, or they might not even be qualified to check the safety/integrity of the file they're signing. even if the owner of the digital certificate used to sign the file is a trustworthy entity, that doesn't mean the file is also trustworthy. first and foremost, trust is not commutative. besides that, though, as the stuxnet example shows us, the certificate can fall into the wrong hands. treating digital signatures as whitelist entries creates a situation where altogether too many entities have influence over what is considered trusted and safe.
thus digital signatures can not tell us what we need a whitelist to tell us, namely that the file is trusted and safe. the presence of a valid digital signature only tells us two things: that the file was signed with certificate X (which may or may not be under the exclusive control of the party it was issued to), and that the file hasn't changed since it was signed. whether it's safe, whether it's fit for use, is entirely outside the scope of what a digital signature can tell us.
i think the idea of using a whitelist to avoid false alarms is a good one, but using digital signatures in it's place is a shortcut. av vendors need to stop cutting corners and implement proper whitelists for this particular application. there are already tens of thousands of digitally signed malware samples in f-secure's collection so i'm at a loss trying to figure out why this technique of false positive avoidance hasn't been abandoned already. now that news that detections of stuxnet didn't start until after the digital signature expired, malware authors will surely be looking to exploit this behaviour more and more.
Thursday, June 14, 2007
when misunderstanding hurts you
today's post by tyler reguly about a revelation he found in f-secure's marketing message caught my eye because i think it exhibits some misunderstandings that i suspect are probably not unique to him so i'm going to try and clear up some of the confusion...
the statement that triggered all of this was that f-secure ships out around 6 updates per day... in tyler's words:
the key misunderstanding here is what exactly those threat write-ups represent... they are not the only pieces of malware that the respective av companies encounter, far from it, they are just the ones that have distinguished themselves enough from the background noise of hundreds of pieces of malware being processed per day to warrant a write-up... nobody maintains a repository of malware write-ups equal in quantity to the amount of malware their product detects, that's just too much work for too little return, so they pick out the ones that are significant in some way such as ones that do something genuinely new, or ones that have in hindsight proven to be a slightly more significant threat than the vast majority...
notice the word hindsight... it is, unfortunately, not possible to predict which pieces of malware will make it big and which won't so it's not possible to use that as a criteria for issuing an update... technically sophisticated viruses have gone nowhere while barely functioning frankenstein creations have run amok... as such, all the anti-virus companies can do is try to minimize (within reason) the window of opportunity that a potentially significant threat will have... in fact, sometimes the failure to become a significant threat (certainly a desirable outcome) hinges on the rapid and widespread deployment of detection capabilities for it...
f-secure accomplishes this with around 6 updates per day... some companies ship updates hourly (and have been doing so for years now)... these aren't fixes (at least not generally), it's not a QA problem, there genuinely are sufficiently many pieces of malware being processed each day to warrant this update frequency... does that mean they're sweating the small stuff? maybe so but it's only because there's no way to know what's going to become big...
the statement that triggered all of this was that f-secure ships out around 6 updates per day... in tyler's words:
When you are pushing out that many updates it tells me one of two things. i) You are “sweatin’ the small stuff” or ii) You have a bad QA process and need to push out fixes.he goes on to investigate whether there is enough malware to justify that many updates and finds that no-one is producing write-ups of new threats at anywhere near that rate...
the key misunderstanding here is what exactly those threat write-ups represent... they are not the only pieces of malware that the respective av companies encounter, far from it, they are just the ones that have distinguished themselves enough from the background noise of hundreds of pieces of malware being processed per day to warrant a write-up... nobody maintains a repository of malware write-ups equal in quantity to the amount of malware their product detects, that's just too much work for too little return, so they pick out the ones that are significant in some way such as ones that do something genuinely new, or ones that have in hindsight proven to be a slightly more significant threat than the vast majority...
notice the word hindsight... it is, unfortunately, not possible to predict which pieces of malware will make it big and which won't so it's not possible to use that as a criteria for issuing an update... technically sophisticated viruses have gone nowhere while barely functioning frankenstein creations have run amok... as such, all the anti-virus companies can do is try to minimize (within reason) the window of opportunity that a potentially significant threat will have... in fact, sometimes the failure to become a significant threat (certainly a desirable outcome) hinges on the rapid and widespread deployment of detection capabilities for it...
f-secure accomplishes this with around 6 updates per day... some companies ship updates hourly (and have been doing so for years now)... these aren't fixes (at least not generally), it's not a QA problem, there genuinely are sufficiently many pieces of malware being processed each day to warrant this update frequency... does that mean they're sweating the small stuff? maybe so but it's only because there's no way to know what's going to become big...
Tags:
anti-malware,
anti-virus,
f-secure,
malware,
tyler reguly
Tuesday, October 10, 2006
complete / total / full protection is snake oil
it's been a while since i last held a vendor's feet to the fire over advertising meant to instill a false sense of security - otherwise known as snake oil... well, i'm about to make up for that...
now, i want to make it clear that i generally don't go looking for anti-virus ad copy or marketing material, i grew out of that complete and utter bullshit a long time ago and as a result rarely ever see actual anti-virus advertisements (actually, i do my best to avoid advertisements in general because really it's all bullshit, but anyways)... i knew that misleading claims occasionally slipped into a vendors marketing material from time to time but clay (of claymania fame) brought to my attention the disturbing fact that snake-oil in the anti-virus industry is actually much more common than i had been aware or wanted to believe... on further investigation it seems to be fairly ubiquitous...
but before i really lay into them, let's start with the title of this post... we've know for a long time that 100% protection was snake oil, it was an impossible claim that obvious snake oil peddlars pushed on an unsuspecting public years ago until the community woke up and said we weren't going to accept that anymore... so then ask yourself does complete, total, or full protection represent a significantly different meaning than 100% protection? not as far as i can tell - they're the same thing just with different words in order to avoid the old snake oil alarm bells... it's not like we're talking about almost full, nearly complete, or just about total protection; these folks aren't saying that if you use their product you'll be 99 and 44 100ths percent protected, no it's complete/total/full/100 percent protection all the way...
so when mcafee creates a product whose very name is mcafee total protection they're lying to the public and their brochure that states "It offers comprehensive security that’s always on and always up to date—and the confidence that you are completely protected." is promoting a false sense of security - you are never completely or totally protected...
when sophos claims that "Sophos Anti-Virus Small Business Edition detects and disinfects viruses, spyware, Trojans and worms at every potential point of infection, ensuring networks and remote users are fully protected." they're telling you 'porkies' - you're never fully protected either...
when computer associates tells you they are "Providing Complete PC Protection from Internet Threats" they are full of hot air (or maybe something else - once again, you can't have complete protection...
when eset informs you "That means you’re purchasing more than antispyware software, you’re purchasing total-protection software. And peace of mind." they're totally full of it - because they certainly aren't giving you total protection...
when grisoft pronounces that they provide "Complete security protection against all of the most serious Internet threats, including viruses, worms, trojans, spyware, adware, hackers and spam." it is complete bunk - once again, there can be no complete protection...
when f-secure states that "F-Secure® Internet Security 2007TM provides a complete and easy-to-use protection against all Internet threats, whether they are known or previously unidentified." they're going completely overboard - complete protection against known and unidentified/unknown threats is nothing short of fantasy...
when panda software asserts that "The new Panda Internet Security 2007 offers the most complete protection so you can use the Internet with absolute peace of mind." they're actually setting you up with a double-whammy - complete protection is impossible so absolute peace of mind is entirely unwarranted... that brings up another type of misleading claim - the worry free protection... panda software really likes 'worry free' ("Browse the Internet, download any file you want, play online for hours... without any worries")...
they aren't the only ones, as trend micro clearly shows with "Trend Micro Antivirus can effectively remove viruses, email worms and Trojans that can destroy your data and files. You can use the Internet worry-free, knowing you’re protected from viruses in email messages, Internet downloads, instant messages, and removable disks."...
and norman gets into the act too with "This product combines the award winning Norman Virus Control and Norman Personal Firewall in one package to offer customers complete peace of mind while using the Internet." - no security program catches everything therefore no security program should be giving you complete peace of mind...
worry free protection that gives you peace of mind just another form of the install and forget snake oil that we've seen before and that bitdefender is proudly displaying here when they say "Ease of use and automatic updating make BitDefender Client Standard an "install and forget" antivirus product." - isn't it great how they even knew to highlight the offending phrase with quotation marks?
this isn't even all of them... i'm sure if i looked harder/longer i'd find even more vendors doing these (and similar) things... it's bad enough that the words protect and protection all by themselves suggest they're complete - you normally have to qualify their use in order to suggest anything less that complete protection - but to so blatantly do the opposite, making false claims and giving the public a false sense of security, and on such a large scale . . . . . words fail me... it makes me ashamed to admit to knowing anyone in the industry, and very glad i'm not one of them...
[edit - thanks for pointing out that the last paragraph was borked, clay... hopefully it no longer looks like the product of someone who was up way too late...]
now, i want to make it clear that i generally don't go looking for anti-virus ad copy or marketing material, i grew out of that complete and utter bullshit a long time ago and as a result rarely ever see actual anti-virus advertisements (actually, i do my best to avoid advertisements in general because really it's all bullshit, but anyways)... i knew that misleading claims occasionally slipped into a vendors marketing material from time to time but clay (of claymania fame) brought to my attention the disturbing fact that snake-oil in the anti-virus industry is actually much more common than i had been aware or wanted to believe... on further investigation it seems to be fairly ubiquitous...
but before i really lay into them, let's start with the title of this post... we've know for a long time that 100% protection was snake oil, it was an impossible claim that obvious snake oil peddlars pushed on an unsuspecting public years ago until the community woke up and said we weren't going to accept that anymore... so then ask yourself does complete, total, or full protection represent a significantly different meaning than 100% protection? not as far as i can tell - they're the same thing just with different words in order to avoid the old snake oil alarm bells... it's not like we're talking about almost full, nearly complete, or just about total protection; these folks aren't saying that if you use their product you'll be 99 and 44 100ths percent protected, no it's complete/total/full/100 percent protection all the way...
so when mcafee creates a product whose very name is mcafee total protection they're lying to the public and their brochure that states "It offers comprehensive security that’s always on and always up to date—and the confidence that you are completely protected." is promoting a false sense of security - you are never completely or totally protected...
when sophos claims that "Sophos Anti-Virus Small Business Edition detects and disinfects viruses, spyware, Trojans and worms at every potential point of infection, ensuring networks and remote users are fully protected." they're telling you 'porkies' - you're never fully protected either...
when computer associates tells you they are "Providing Complete PC Protection from Internet Threats" they are full of hot air (or maybe something else - once again, you can't have complete protection...
when eset informs you "That means you’re purchasing more than antispyware software, you’re purchasing total-protection software. And peace of mind." they're totally full of it - because they certainly aren't giving you total protection...
when grisoft pronounces that they provide "Complete security protection against all of the most serious Internet threats, including viruses, worms, trojans, spyware, adware, hackers and spam." it is complete bunk - once again, there can be no complete protection...
when f-secure states that "F-Secure® Internet Security 2007TM provides a complete and easy-to-use protection against all Internet threats, whether they are known or previously unidentified." they're going completely overboard - complete protection against known and unidentified/unknown threats is nothing short of fantasy...
when panda software asserts that "The new Panda Internet Security 2007 offers the most complete protection so you can use the Internet with absolute peace of mind." they're actually setting you up with a double-whammy - complete protection is impossible so absolute peace of mind is entirely unwarranted... that brings up another type of misleading claim - the worry free protection... panda software really likes 'worry free' ("Browse the Internet, download any file you want, play online for hours... without any worries")...
they aren't the only ones, as trend micro clearly shows with "Trend Micro Antivirus can effectively remove viruses, email worms and Trojans that can destroy your data and files. You can use the Internet worry-free, knowing you’re protected from viruses in email messages, Internet downloads, instant messages, and removable disks."...
and norman gets into the act too with "This product combines the award winning Norman Virus Control and Norman Personal Firewall in one package to offer customers complete peace of mind while using the Internet." - no security program catches everything therefore no security program should be giving you complete peace of mind...
worry free protection that gives you peace of mind just another form of the install and forget snake oil that we've seen before and that bitdefender is proudly displaying here when they say "Ease of use and automatic updating make BitDefender Client Standard an "install and forget" antivirus product." - isn't it great how they even knew to highlight the offending phrase with quotation marks?
this isn't even all of them... i'm sure if i looked harder/longer i'd find even more vendors doing these (and similar) things... it's bad enough that the words protect and protection all by themselves suggest they're complete - you normally have to qualify their use in order to suggest anything less that complete protection - but to so blatantly do the opposite, making false claims and giving the public a false sense of security, and on such a large scale . . . . . words fail me... it makes me ashamed to admit to knowing anyone in the industry, and very glad i'm not one of them...
[edit - thanks for pointing out that the last paragraph was borked, clay... hopefully it no longer looks like the product of someone who was up way too late...]
Tags:
anti-virus,
bitdefender,
computer associates,
eset,
f-secure,
grisoft,
mcafee,
norman,
panda software,
snake oil,
sophos,
trend micro
Monday, July 24, 2006
cutting through the mobile malware mess
techdirt, renowned for it's technical acumen (in other words it's signal to noise ratio is just slightly better than the garbage heap of the internet known as slashdot), has a post today that basically roasts f-secure for spreading mobile malware FUD... small problem - i couldn't find the FUD even after following all their links to supposed examples...
let's take a closer look, shall we?
from silicon.com:
from a different article on silicon.com:
from the same article:
(see the video evidence here, it starts about 26 minutes in)
[edit - there's a better view of the video evidence here, starting at about 1 hour and 26 minutes]
from an article at vnunet.com:
at any rate, saying a type of virus has the potential to do X is quite a bit different than saying a particular virus will do X or is likely to do X (which is the implication techdirt makes here)...
and from the a zdnet.co.uk article that triggered the current threat at techdirt:
furthermore, in the same zdnet article an f-secure representative is quoted:
still, techdirt has persisted in laying the FUD spreader charge against f-secure for some time now, not unlike many other community sources (slashdot and digg are the 2 glaring examples) have done to many other vendors... it bears a striking similarity to the reaction you get whenever you suggest there are genuine security risks in mac osx or linux... i thought at first it might just be one site or 2 sites, but the pattern that is emerging seems more widespread - it seems to have something to do with the wisdom of mobs where the wisdom of crowds fails due to the signal to noise ratio being too low... the reality is is that he who yells loudest has the most individual impact on the whole and without sufficient real wisdom to counteract that impact the whole becomes an ignorant mob...
let's take a closer look, shall we?
from silicon.com:
Sal Viveros, wireless security evangelist at McAfee, said F-Secure's figures are largely in line with industry figures in terms of the total number of mobile viruses but added such viruses have largely been "proof of concept" to date and pose little threat to users.ok, so we've got independant verification of f-secure's figures on the total number of mobile malware instances - score 1 for f-secure...
from a different article on silicon.com:
"The number of proof of concept viruses is increasing but that's not to say there has been an increase in the risk of infestation or that there is any need for panic or worry."the person making this statement (david wood of symbian, the company holding the largest stake in the mobile phone market - aka the microsoft of the mobile phone market) clearly doesn't understand the nature of risk... the more instances of malware out there the greater the chance of a particular user encountering one of them, and therefore the greater the risk...
from the same article:
He added that these viruses will only spread with user permission and conceded that in very rare instances a user could contrive to infect their phone.which shows that he clearly doesn't understand what's really going on in a mobile infection scenario... the no option doesn't work - you choose no and the prompt just comes back... press no again and the same thing happens... cabir and similar worms will just keep trying and effectively DoS the phone until the user chooses yes... user interaction is a non-issue if the user isn't given a real choice...
(see the video evidence here, it starts about 26 minutes in)
[edit - there's a better view of the video evidence here, starting at about 1 hour and 26 minutes]
from an article at vnunet.com:
"Phone viruses so far have been spreading over Bluetooth, so they only affect phones that are within a few metres. A MMS virus can potentially go global in minutes, just like an email worm," warned F-Secure's antivirus laboratory.now that is a little troubling that it says minutes - because mikko hypponen, in the video referenced above, says 24 hours (both for mobile phone viruses and for email viruses) and he explains why... it's correct that it has the same potential speed as email worms but minutes seems like an error, either on the f-secure rep's side or (more likely, since they're known for botching these sorts of things) the reporter's side...
at any rate, saying a type of virus has the potential to do X is quite a bit different than saying a particular virus will do X or is likely to do X (which is the implication techdirt makes here)...
and from the a zdnet.co.uk article that triggered the current threat at techdirt:
"F-Secure is saying there's a huge risk of malcode spreading, but they've built this up," said Simon Perry, European vice president of security for CA. "If you look at their behaviour, they've consistently pushed this message. But it's a theoretical, not a real threat," he added.i don't know where mr. perry is getting this - mikko hypponen (again in the video referenced above) made it seem pretty clear to me that mobile viruses are not anywhere near as problematic as their pc counterparts... susceptible phones are comparatively quite rare, and most of the malware can only spread to other phones that are physically nearby... that doesn't sound like a huge risk to me... he does mention some big total numbers (in the tens of thousands) but considering the law of large numbers as it applies to this situation that doesn't really raise eyebrows...
furthermore, in the same zdnet article an f-secure representative is quoted:
"I have difficulty understanding how this can be bad for [the antivirus] business. This is not a mass problem for all consumers, but our solution is available to those who need it, and there are people who need it today," Impivaara added.it seems hard to imagine how f-secure could be making mobile malware out to be a huge risk when they're quoted in the media as saying the opposite...
still, techdirt has persisted in laying the FUD spreader charge against f-secure for some time now, not unlike many other community sources (slashdot and digg are the 2 glaring examples) have done to many other vendors... it bears a striking similarity to the reaction you get whenever you suggest there are genuine security risks in mac osx or linux... i thought at first it might just be one site or 2 sites, but the pattern that is emerging seems more widespread - it seems to have something to do with the wisdom of mobs where the wisdom of crowds fails due to the signal to noise ratio being too low... the reality is is that he who yells loudest has the most individual impact on the whole and without sufficient real wisdom to counteract that impact the whole becomes an ignorant mob...
Tags:
cellphone,
f-secure,
fud,
mobile malware,
techdirt
Friday, July 07, 2006
"mine's bigger"
yeah, i know it's a pretty provocative statement, but that's pretty much what authentium are saying in this blog post...
mcafee lets everyone know their product is about to reach the 200,000 threats detected milestone and authentium pipes and and says 'well we're about to reach 300,000'... classic - no really, i'm surprised there are anti-virus companies still playing this particular numbers game... i thought it went out of style years ago...
now let me ask you something, do you really think there are 100,000 pieces of malware being missed by mcafee's product? you can't trust the raw numbers reported by vendors, unfortunately, and not just because some of them have apparent inferiority complexes...
this is old news for some of us but for those who don't know yet, here's how it works... say you have 2 malware samples that are related to each other (they belong to the same malware family) - scanner-A detects both pieces of malware using 2 separate signatures and scanner-B detects both pieces of malware using only 1 signature... now both detect the same number of real world threats, but the way they count is by counting the number of distinct malware definitions in the scanner's database so scanner-A will say it detects 2 pieces of malware where scanner-B will only say it detects 1 piece of malware because they're similar enough that they look the same to scanner-B...
now whether a scanner needs 1 or 2 signatures in the scenario above doesn't really have any bearing on which scanner is better, there are benefits and drawbacks for on both sides and it's not always scanner-A that requires more signatures... that said, you should be able to easily see how one scanner's numbers can be very different from those of another... now a 50% difference is considerable and i find that very suspicious, especially when f-secure pegged the number at 185,000 earlier this year which is much more in line with mcafee's 200,000 figure...
regardless, the numbers that vendors report just do not mean what they otherwise seem to mean... comparing the number of signatures between different products is a pointless exercise and it ultimately misleads the reader into thinking that one product is better than another when it may not be true... and if you're detecting the scent of snake oil in that practise, well me too...
mcafee lets everyone know their product is about to reach the 200,000 threats detected milestone and authentium pipes and and says 'well we're about to reach 300,000'... classic - no really, i'm surprised there are anti-virus companies still playing this particular numbers game... i thought it went out of style years ago...
now let me ask you something, do you really think there are 100,000 pieces of malware being missed by mcafee's product? you can't trust the raw numbers reported by vendors, unfortunately, and not just because some of them have apparent inferiority complexes...
this is old news for some of us but for those who don't know yet, here's how it works... say you have 2 malware samples that are related to each other (they belong to the same malware family) - scanner-A detects both pieces of malware using 2 separate signatures and scanner-B detects both pieces of malware using only 1 signature... now both detect the same number of real world threats, but the way they count is by counting the number of distinct malware definitions in the scanner's database so scanner-A will say it detects 2 pieces of malware where scanner-B will only say it detects 1 piece of malware because they're similar enough that they look the same to scanner-B...
now whether a scanner needs 1 or 2 signatures in the scenario above doesn't really have any bearing on which scanner is better, there are benefits and drawbacks for on both sides and it's not always scanner-A that requires more signatures... that said, you should be able to easily see how one scanner's numbers can be very different from those of another... now a 50% difference is considerable and i find that very suspicious, especially when f-secure pegged the number at 185,000 earlier this year which is much more in line with mcafee's 200,000 figure...
regardless, the numbers that vendors report just do not mean what they otherwise seem to mean... comparing the number of signatures between different products is a pointless exercise and it ultimately misleads the reader into thinking that one product is better than another when it may not be true... and if you're detecting the scent of snake oil in that practise, well me too...
Tags:
anti-virus,
authentium,
f-secure,
malware,
mcafee,
snake oil
Tuesday, April 04, 2006
cellphone spyware part deux
so my last posting about cellphone spyware (flexispy) apparently was interesting enough to someone for them to send me my very first non-spam feedback... specifically, someone claiming to be affiliated with neo-call sent me a nice little email with their views on the flexispy story...
this is actually pretty amazing, because apparently the neo-call folks (being industry leaders) developed superior cellphone spying technology months ago and nobody paid any attention to them or talked about them (awwwww)... the email goes on to say that it's very interesting that f-secure picked up on the flexispy story a day after the software was released - and i agree... if it really was only a day after the software was released it would appear that vervata decided that getting a examined by anti-virus vendors would make for a good publicity stunt, and i suppose they may be right... on the other hand, f-secure now detects their product as a spyware trojan so i guess that kinda backfired on them since that detection is going to limit the marketability product (who wants to pay for spyware that an anti-virus product can already detect?)...
finally, the email finished off with a lament about how neo-call is an industry leader (in the field of cellphone spyware, apparently) and how it's a shame that nobody is paying any attention to them or talking about them at all.. clearly they're jealous of all the special lovin' the boys and girls and f-secure have been giving flexispy and they want in on some of that action - and it appears they may be deserving... their product forwards sms messages, lo-jack's the phone through GSM localization, and i gather there's even a bonus add-on for listening in on calls - definitely sounds spyware to me... oh, and get this, the FAQ clearly states that you can't tell the product is installed by examining the phone - yup, it fails to disclose it's true nature just like flexispy, isn't that wonderfully up-front of them to admit to it's trojan nature?
mikko and the rest of the gang at f-secure - these guys are obviously looking for some of your special attention, so go ahead and hook 'em up..
[edit april 7 2006: i don't know what i was thinking posting links to a malware distributor, i guess i must have been laughing too hard to realize what i was doing]
this is actually pretty amazing, because apparently the neo-call folks (being industry leaders) developed superior cellphone spying technology months ago and nobody paid any attention to them or talked about them (awwwww)... the email goes on to say that it's very interesting that f-secure picked up on the flexispy story a day after the software was released - and i agree... if it really was only a day after the software was released it would appear that vervata decided that getting a examined by anti-virus vendors would make for a good publicity stunt, and i suppose they may be right... on the other hand, f-secure now detects their product as a spyware trojan so i guess that kinda backfired on them since that detection is going to limit the marketability product (who wants to pay for spyware that an anti-virus product can already detect?)...
finally, the email finished off with a lament about how neo-call is an industry leader (in the field of cellphone spyware, apparently) and how it's a shame that nobody is paying any attention to them or talking about them at all.. clearly they're jealous of all the special lovin' the boys and girls and f-secure have been giving flexispy and they want in on some of that action - and it appears they may be deserving... their product forwards sms messages, lo-jack's the phone through GSM localization, and i gather there's even a bonus add-on for listening in on calls - definitely sounds spyware to me... oh, and get this, the FAQ clearly states that you can't tell the product is installed by examining the phone - yup, it fails to disclose it's true nature just like flexispy, isn't that wonderfully up-front of them to admit to it's trojan nature?
mikko and the rest of the gang at f-secure - these guys are obviously looking for some of your special attention, so go ahead and hook 'em up..
[edit april 7 2006: i don't know what i was thinking posting links to a malware distributor, i guess i must have been laughing too hard to realize what i was doing]
Thursday, March 30, 2006
flexispy vs. the anti-malware industry
if you haven't heard about flexispy (the first spyware trojan for symbian cell phones) then i'd suggest reading about it here and here...
i don't really think it's all that interesting that someone has finally made spyware for cellphones - what i think is amazing, however, is that a member of the commercial spyware industry (vervata) seems to actually not understand why their product (flexispy) is being called a spyware trojan by f-secure...
imagine, you make software that you yourself call a "spy application" and then don't understand why people call it spyware... hello!?!? it's software that spies on you, what do you think people are going to call it?... are these guys for real? well, either they really don't get it, or they think that there are enough other people who don't get it that it's worth it to bother making such a ridiculous argument...
but why is that? well, i think it serves as a stong indication that the anti-malware industry/community in general, and the anti-spyware industry/community in particular, have failed the public in an important way... they've failed to make the threats understandable to ordinary people... look at the anti-spyware coalition's glossary, is their definition of spyware as straight forward as 'software that spys on you'? no, in fact they have 2 separate and contradictory definitions, one of which makes spyware an umbrella term... i've already blogged about stopbadware.org's use of a colloquialism from wikipedia as their definition for spyware, and then there's sunbelt's listing criteria that i was recently made aware of and which is about as easy to read as an end user license agreement unless you already have some familiarity with the malware field...
how are people suppose to get this stuff with literature like that? if it were common knowledge that spyware is software that spies on you then vervata would have no reasonable way to claim ignorance, much less argue the fact... and if it were common knowledge that trojans were programs that do bad things that you thought they didn't do then vervata also should have known that their product (which fails to disclose it's true nature) can be made into a trojan simply by saying it's something good or by installing it on someone's phone and leading (or leaving) them to believe that everying on the phone is normal...
of course, i'm not all about pointing the finger at other people here... while writing this i've realized that even my own definitions could stand some improvement in this area... as much as i try to make the definitions themselves short and sweet (with explanations afterwards for those interested in more detail) they could still be simpler and retain their correctness at the same time... i think we need to compose our definitions like we were talking to 4 year olds, not because people are stupid but because most simply don't have enough of a foundation here to grasp our meaning when we write for other people people in the anti-malware field... i think if we really understand what we're talking about then that shouldn't be too difficult a task... so i guess i'll be tweaking some existing blog entries in the not too distant future..
i don't really think it's all that interesting that someone has finally made spyware for cellphones - what i think is amazing, however, is that a member of the commercial spyware industry (vervata) seems to actually not understand why their product (flexispy) is being called a spyware trojan by f-secure...
imagine, you make software that you yourself call a "spy application" and then don't understand why people call it spyware... hello!?!? it's software that spies on you, what do you think people are going to call it?... are these guys for real? well, either they really don't get it, or they think that there are enough other people who don't get it that it's worth it to bother making such a ridiculous argument...
but why is that? well, i think it serves as a stong indication that the anti-malware industry/community in general, and the anti-spyware industry/community in particular, have failed the public in an important way... they've failed to make the threats understandable to ordinary people... look at the anti-spyware coalition's glossary, is their definition of spyware as straight forward as 'software that spys on you'? no, in fact they have 2 separate and contradictory definitions, one of which makes spyware an umbrella term... i've already blogged about stopbadware.org's use of a colloquialism from wikipedia as their definition for spyware, and then there's sunbelt's listing criteria that i was recently made aware of and which is about as easy to read as an end user license agreement unless you already have some familiarity with the malware field...
how are people suppose to get this stuff with literature like that? if it were common knowledge that spyware is software that spies on you then vervata would have no reasonable way to claim ignorance, much less argue the fact... and if it were common knowledge that trojans were programs that do bad things that you thought they didn't do then vervata also should have known that their product (which fails to disclose it's true nature) can be made into a trojan simply by saying it's something good or by installing it on someone's phone and leading (or leaving) them to believe that everying on the phone is normal...
of course, i'm not all about pointing the finger at other people here... while writing this i've realized that even my own definitions could stand some improvement in this area... as much as i try to make the definitions themselves short and sweet (with explanations afterwards for those interested in more detail) they could still be simpler and retain their correctness at the same time... i think we need to compose our definitions like we were talking to 4 year olds, not because people are stupid but because most simply don't have enough of a foundation here to grasp our meaning when we write for other people people in the anti-malware field... i think if we really understand what we're talking about then that shouldn't be too difficult a task... so i guess i'll be tweaking some existing blog entries in the not too distant future..
Tuesday, March 14, 2006
why virtual machine based 'rootkits' won't be the next big problem
ok, ignoring the issue of what rootkits really are for the moment, let's examine this idea of rootkits that are so low level they're even below the OS...
first, as greg hoglund points out you're pretty much guaranteed to notice the performance hit when your entire OS gets dropped into a virtual machine...
second, as pointed out on the f-secure blog it's actually been done before over a decade ago, back when stealth was still called stealth...
but really, i think i'm going to go them both one better (at least) and say that we solved the full stealth problem over a decade ago... that solution was called booting from a known clean bootable floppy disk and scanning with a known virus scanner...
"but kurt, how are we supposed to use our generic rootkit detection technology if the rootkit isn't active?" - simple, you aren't... those sorts of generics require the malware to be active, which gives it a tactical advantage (it's able to actively defend itself then)... it also allows the malware to know more about the security application than the security application knows about the malware, which is another tactical advantage for the malware... if you're unfamiliar with what sun tsu had to say about engaging the enemy when you're at a disadvantage then i suggest you go do your homework right now... you can't rely solely on generics that way - known-malware techniques (know your enemy) must be employed in an environment and under conditions of your choosing in order to maximize your tactical advantage, and the generics are then used in a supporting role to partially cover what that strategy can't...
now, those of you who've been following things for a few years now you probably know that microsoft screwed that option up with the advent of NTFS... no version of MSDOS is capable of parsing an NTFS partition natively and microsoft seems unwilling to do much about that - probably because so far there really hasn't been that great a need these days... however, should the need arise a fair amount of effort has gone into correcting microsoft's oversight... things like bart's pe disk, NTFS4DOS, or any one of the many recovery oriented live-cd linux distributions can give you access to an NTFS partition after booting from a known clean bootable medium...
all in all, the majority of what's being said out there about microsoft's subvirt and the technology it represents is just hype... in the very unlikely event that anyone ever actually bothers trying to deploy it in the wild, it's an old problem that we've had a solution for for some time now...
[obligatory terminology rant]
of course all of this is one of the consequences of the rootkit redefinition... it clouds the issues in both the rootkit problem-space and the stealth problem-space... we wouldn't be forgetting this history if stealth was still called stealth, and then maybe the brain-trust at microsoft wouldn't have to spend untold millions reinventing the wheel that we already know how to deal with...
[/obligatory terminology rant]
first, as greg hoglund points out you're pretty much guaranteed to notice the performance hit when your entire OS gets dropped into a virtual machine...
second, as pointed out on the f-secure blog it's actually been done before over a decade ago, back when stealth was still called stealth...
but really, i think i'm going to go them both one better (at least) and say that we solved the full stealth problem over a decade ago... that solution was called booting from a known clean bootable floppy disk and scanning with a known virus scanner...
"but kurt, how are we supposed to use our generic rootkit detection technology if the rootkit isn't active?" - simple, you aren't... those sorts of generics require the malware to be active, which gives it a tactical advantage (it's able to actively defend itself then)... it also allows the malware to know more about the security application than the security application knows about the malware, which is another tactical advantage for the malware... if you're unfamiliar with what sun tsu had to say about engaging the enemy when you're at a disadvantage then i suggest you go do your homework right now... you can't rely solely on generics that way - known-malware techniques (know your enemy) must be employed in an environment and under conditions of your choosing in order to maximize your tactical advantage, and the generics are then used in a supporting role to partially cover what that strategy can't...
now, those of you who've been following things for a few years now you probably know that microsoft screwed that option up with the advent of NTFS... no version of MSDOS is capable of parsing an NTFS partition natively and microsoft seems unwilling to do much about that - probably because so far there really hasn't been that great a need these days... however, should the need arise a fair amount of effort has gone into correcting microsoft's oversight... things like bart's pe disk, NTFS4DOS, or any one of the many recovery oriented live-cd linux distributions can give you access to an NTFS partition after booting from a known clean bootable medium...
all in all, the majority of what's being said out there about microsoft's subvirt and the technology it represents is just hype... in the very unlikely event that anyone ever actually bothers trying to deploy it in the wild, it's an old problem that we've had a solution for for some time now...
[obligatory terminology rant]
of course all of this is one of the consequences of the rootkit redefinition... it clouds the issues in both the rootkit problem-space and the stealth problem-space... we wouldn't be forgetting this history if stealth was still called stealth, and then maybe the brain-trust at microsoft wouldn't have to spend untold millions reinventing the wheel that we already know how to deal with...
[/obligatory terminology rant]
Tags:
bartpe,
clean boot,
f-secure,
greg hoglund,
malware,
microsoft,
ntfs,
rootkit,
stealth,
stealthkit,
subvirt,
sun tzu,
terminology misuse
Monday, February 20, 2006
the descent of rootkits
i think it's about time to get to the root of the rootkit terminology shift...
i've blogged before about what i think a rootkit is, and about how the anti-spyware coalition's definition is basically in line with my own...
and yet somehow the definition currently in use is all about hiding processes and/or activities from the user rather than about root/administrative privileges...
as i observed before; f-secure, despite acknowledging that the original unix meaning was basically in line with the one i use in this little blurb:
but my first clue about where this new definition came from was in mark russinovich's blog entry where he gives his definition:
a rootkit developer community? well, a community of developers of cloaking technology at any rate... but lets think about this for a sec... by and large, these developers are not going to be a malicious bunch (there are far more good people in the world than there are bad) so when they look at rootkits, even the original unix-style rootkits, they aren't going to really be all that interested in the more blatantly malware type features - the thing that's going to interest them is the cloaking because it has applications outside of malware...
it has been suggested that terminology changes with frequent misuse and that is most likely what happened here... the developer community in question, lacking any significant influence from malware experts (since malware issues were outside the scope of their interests, and because malware expertise is a lot harder to come by than you might think), used and reused the term rootkit (since rootkits represented examples of the kinds of sophisticated stealth techniques they were interested in) so much outside of it's original meaning that they gave it a new meaning...
so what? you might well think that language changes in just this way so there's nothing wrong here, but consider this:
while upcoming concepts like 'stealth by design' indicate that the current terminological misstep may be in the process of correcting itself, there will be purists who will resist the change in terminology on the basis that the proposed new definition of rootkit is not what a rootkit was supposed to be... they'll simply have to be reminded that their rootkit definition was not the original one either and if the correction does take place it will simply be a reversion to the original state of things...
i've blogged before about what i think a rootkit is, and about how the anti-spyware coalition's definition is basically in line with my own...
and yet somehow the definition currently in use is all about hiding processes and/or activities from the user rather than about root/administrative privileges...
as i observed before; f-secure, despite acknowledging that the original unix meaning was basically in line with the one i use in this little blurb:
The term rootkit is very old and is dated back to the days when UNIX ruled the world. Rootkits for the UNIX operating system were typically used to elevate the privileges of a user to the root level (=administrator). This explains the name of this category of tools.still insists on using the new hiding-related definition...
but my first clue about where this new definition came from was in mark russinovich's blog entry where he gives his definition:
Software that hides itself or other objects, such as files, processes, and Registry keys, from view of standard diagnostic, administrative, and security software.which he says he derived from what the rootkit developer community was using as a definition and which happens to basically mirror the definition proposed by greg hoglund, founder of rootkit.com (a hub of the aforementioned developer community) and author of a book on these so-called rootkits (not that registering a domain and/or writing a book actually makes anyone a credible authority, but for the sake of argument lets say he is one), which states:
A rootkit is a tool that is designed to hide itself and other processes, data, and/or activity on a system.
a rootkit developer community? well, a community of developers of cloaking technology at any rate... but lets think about this for a sec... by and large, these developers are not going to be a malicious bunch (there are far more good people in the world than there are bad) so when they look at rootkits, even the original unix-style rootkits, they aren't going to really be all that interested in the more blatantly malware type features - the thing that's going to interest them is the cloaking because it has applications outside of malware...
it has been suggested that terminology changes with frequent misuse and that is most likely what happened here... the developer community in question, lacking any significant influence from malware experts (since malware issues were outside the scope of their interests, and because malware expertise is a lot harder to come by than you might think), used and reused the term rootkit (since rootkits represented examples of the kinds of sophisticated stealth techniques they were interested in) so much outside of it's original meaning that they gave it a new meaning...
so what? you might well think that language changes in just this way so there's nothing wrong here, but consider this:
- technical jargon does not evolve the same way that conversational language does... imagine if people started using the term 'telescope' to refer to something completely different...
- hoglund's definition describes what is more properly known as stealth in the malware field... the concept of stealth has enjoyed wide use in the malware field for at least the past 20 years (back in 1986, the brain virus wasn't just the first pc virus in the wild, it was the first stealth virus) and has been applied to virtually all forms of malware, not just rootkits
- stealth is actually a more natural and intuitive label for what hoglund's definition describes; so much so that the term is creeping back into the vocabulary of the rootkit community at rootkit.com to cover new types of cloaking that 'rootkit' is no longer felt to encompass
- under hoglund's definition, the term 'rootkit' has no etymological basis - that is the word doesn't appear to come from anywhere or be rooted in any underlying details... by comparison, a collection of programs (-> a collection of software tools -> a toolkit -> a kit) that aids in gaining or maintaining root/administator (administrator is called 'root' in unix) access is fairly clear about where the term 'rootkit' comes from
while upcoming concepts like 'stealth by design' indicate that the current terminological misstep may be in the process of correcting itself, there will be purists who will resist the change in terminology on the basis that the proposed new definition of rootkit is not what a rootkit was supposed to be... they'll simply have to be reminded that their rootkit definition was not the original one either and if the correction does take place it will simply be a reversion to the original state of things...
Friday, November 18, 2005
what's that so-called real story again?
bruce schneier spins a yarn quite well in his recent article on the sony DRM scandal so i'm not goint to bother making any kind of 'story' here...
read it... see if you can see what i see...
no, no, not the terminology misuse (that his own readers picked up on - in the industry it's that pesky cloaking business that makes something a rootkit, regardless of how bizarre that sounds)... no, he blames anti-virus companies for not detecting the rootkit sooner...
hello?!?! where was bruce almighty during that period, hmm?? where was his company counterpane and their managed security solution? didn't they detect anything??? we're talking managed security here, with actual people at the helm rather than the automatons that anti-virus software represents... i don't recall bruce raising the initial alarm, do you?
anti-virus software detects what it knows... how does it get to know something? by the people who make it being given samples or at least pointed in the right general direction as f-secure was...
how exactly were they going to get that information sooner than they did? ('chance' is the only way i can see that happening) and without that how were they supposed to detect it? are anti-virus companies supposed to sift through and analyze every line of code on the planet, and if so are we to believe audio CDs should have been high on their priority list?
and then, to go on and make the disingenious statement that that kind of protection is exactly what we pay anti-virus companies for when he knows damn well (writes about it, talks about it, made a business model out of it) that real security isn't as simple as installing software and expecting it to protect you, that it's a process, that it requires real people making intelligent and informed security decisions - i'm sure that made for good copy but it's still hipocrisy... people protect computers, the software is just a tool to help them do the job... and of course no security, no matter how good, is perfect...
anti-virus software cannot protect you from everything all the time... many of them have no anti-rootkit technology yet, and detection of phoning home is generally relegated to the software firewalls...
bruce appears to be too far removed from the anti-virus community (note, i'm not specifying the industry) to get it... i've been part of the community for well over a decade and the only person i know who even mentions his name is me... i suspect the security guru simply considers viruses to be a small niche in the overall security landscape, and that may be true but the devil's in the details and those are something he isn't displaying a firm grasp of here...
i'm no anti-virus apologist here, though... he did get one thing right, any av company that wasn't all over this when the new broke deserves a swift boot in the ass... f-secure shouldn't have been the only av company denouncing sony's move from the get-go...
read it... see if you can see what i see...
no, no, not the terminology misuse (that his own readers picked up on - in the industry it's that pesky cloaking business that makes something a rootkit, regardless of how bizarre that sounds)... no, he blames anti-virus companies for not detecting the rootkit sooner...
hello?!?! where was bruce almighty during that period, hmm?? where was his company counterpane and their managed security solution? didn't they detect anything??? we're talking managed security here, with actual people at the helm rather than the automatons that anti-virus software represents... i don't recall bruce raising the initial alarm, do you?
anti-virus software detects what it knows... how does it get to know something? by the people who make it being given samples or at least pointed in the right general direction as f-secure was...
how exactly were they going to get that information sooner than they did? ('chance' is the only way i can see that happening) and without that how were they supposed to detect it? are anti-virus companies supposed to sift through and analyze every line of code on the planet, and if so are we to believe audio CDs should have been high on their priority list?
and then, to go on and make the disingenious statement that that kind of protection is exactly what we pay anti-virus companies for when he knows damn well (writes about it, talks about it, made a business model out of it) that real security isn't as simple as installing software and expecting it to protect you, that it's a process, that it requires real people making intelligent and informed security decisions - i'm sure that made for good copy but it's still hipocrisy... people protect computers, the software is just a tool to help them do the job... and of course no security, no matter how good, is perfect...
anti-virus software cannot protect you from everything all the time... many of them have no anti-rootkit technology yet, and detection of phoning home is generally relegated to the software firewalls...
bruce appears to be too far removed from the anti-virus community (note, i'm not specifying the industry) to get it... i've been part of the community for well over a decade and the only person i know who even mentions his name is me... i suspect the security guru simply considers viruses to be a small niche in the overall security landscape, and that may be true but the devil's in the details and those are something he isn't displaying a firm grasp of here...
i'm no anti-virus apologist here, though... he did get one thing right, any av company that wasn't all over this when the new broke deserves a swift boot in the ass... f-secure shouldn't have been the only av company denouncing sony's move from the get-go...
Tags:
anti-virus,
bruce schneier,
drm,
f-secure,
first4internet,
fud,
rootkit,
sony bmg,
stealthkit,
terminology misuse,
xcp
Sunday, March 13, 2005
rootkits for windows
this page tries to explain what rootkits are and the emerging threat they pose for the windows platform...
that's all well and good but there's something that just doesn't sit well with me... let's take a closer look:
i like this explanation... it's simple, it's consistent, it makes sense.... a rootkit is a tool used to gain root (*nix speak for administrator) privileges...
now this is not so good... apparently rootkits for windows don't really have anything to do with giving a principle administrative privileges... it does a bunch of the other things it's unix counterpart does (i.e. it uses sophisticated techniques to hide) but no elevation of privilege...
does that make sense to you?
if i take the self-replication out of a virus, regardless of the fact that it can still do all the other things it used to be able to do, it is no longer a virus...
why then if i take the root granting functionality out of a rootkit does it remain a rootkit?
it doesn't seem to make a lot of sense, it is not logically consistent... by rights, what they're calling rootkits for windows should be called (in keeping with the spirit of the rootkit name) stealthkits...
now, this was an f-secure description so you may well be thinking that maybe those f-secure folks are a little confused... but no, if that were the case then why does sophos also seem to think that rootkits are more about hiding than they are about privilege elevation (which they don't even mention)... and then there's sysinternal's explanation of rootkits which also focuses on hiding rather than privilege elevation...
this seems like it might actually be industry wide, in which case i can just site here in awe and wonder because the industry appears to be from a completely different planet than you and me...
that's all well and good but there's something that just doesn't sit well with me... let's take a closer look:
The term rootkit is very old and is dated back to the days when UNIX ruled the world. Rootkits for the UNIX operating system were typically used to elevate the privileges of a user to the root level (=administrator). This explains the name of this category of tools.
i like this explanation... it's simple, it's consistent, it makes sense.... a rootkit is a tool used to gain root (*nix speak for administrator) privileges...
Rootkits for Windows work in a different way and are typically used to hide malicious software from for example an antivirus scanner. Rootkits are typically not malicious by themselves but are used for malicious purposes by viruses, worms, backdoors and spyware. A virus combined with a rootkit produces what was known as full stealth viruses in the MS-DOS environment.
now this is not so good... apparently rootkits for windows don't really have anything to do with giving a principle administrative privileges... it does a bunch of the other things it's unix counterpart does (i.e. it uses sophisticated techniques to hide) but no elevation of privilege...
does that make sense to you?
if i take the self-replication out of a virus, regardless of the fact that it can still do all the other things it used to be able to do, it is no longer a virus...
why then if i take the root granting functionality out of a rootkit does it remain a rootkit?
it doesn't seem to make a lot of sense, it is not logically consistent... by rights, what they're calling rootkits for windows should be called (in keeping with the spirit of the rootkit name) stealthkits...
now, this was an f-secure description so you may well be thinking that maybe those f-secure folks are a little confused... but no, if that were the case then why does sophos also seem to think that rootkits are more about hiding than they are about privilege elevation (which they don't even mention)... and then there's sysinternal's explanation of rootkits which also focuses on hiding rather than privilege elevation...
this seems like it might actually be industry wide, in which case i can just site here in awe and wonder because the industry appears to be from a completely different planet than you and me...
Tags:
f-secure,
malware,
rootkit,
sophos,
stealth,
stealthkit,
sysinternals,
trojan,
unix,
windows
Wednesday, March 09, 2005
legality of virus writing
someone at f-secure is clearly frustrated...
how many times have i seen someone say that virus writing should be illegal? i don't know, i've lost count it's been said so many times... i'm sure it probably seems entirely reasonable too... except wait, oh my goodness, it's not!...
huh? what am i talking about? i'm talking about the fact that enforcing such a law would be an unprecedented contravention of fundamental human rights...
let's face facts - abstracted from all other related activities, simply writing a virus is analogous to writing in a personal journal... it's a matter of freedom of thought and as such one of the most fundamental freedoms there is... it doesn't affect anyone until the writer tries to communicate his/her idea with others... if i write a virus and no one else ever sees it, have i contributed to the virus problem? if i utter a racial slur and no one's around to hear it, have i offended a minority group? no on both counts... what i do in the privacy of my own home or the privacy of my own computer should be of no concern to anyone else...
if you're going to outlaw something, outlaw something that actually causes a problem... outlaw spreading viruses, maybe even outlaw publishing viruses (see here for why full disclosure shouldn't be usable as a valid argument against such free speech limitations), but keep the thought police out of the picture...
that's important so i'll repeat it - outlawing virus writing would be a contravention of a person's freedom of thought, keep the thought police out of the picture...
how many times have i seen someone say that virus writing should be illegal? i don't know, i've lost count it's been said so many times... i'm sure it probably seems entirely reasonable too... except wait, oh my goodness, it's not!...
huh? what am i talking about? i'm talking about the fact that enforcing such a law would be an unprecedented contravention of fundamental human rights...
let's face facts - abstracted from all other related activities, simply writing a virus is analogous to writing in a personal journal... it's a matter of freedom of thought and as such one of the most fundamental freedoms there is... it doesn't affect anyone until the writer tries to communicate his/her idea with others... if i write a virus and no one else ever sees it, have i contributed to the virus problem? if i utter a racial slur and no one's around to hear it, have i offended a minority group? no on both counts... what i do in the privacy of my own home or the privacy of my own computer should be of no concern to anyone else...
if you're going to outlaw something, outlaw something that actually causes a problem... outlaw spreading viruses, maybe even outlaw publishing viruses (see here for why full disclosure shouldn't be usable as a valid argument against such free speech limitations), but keep the thought police out of the picture...
that's important so i'll repeat it - outlawing virus writing would be a contravention of a person's freedom of thought, keep the thought police out of the picture...
Tags:
ethics,
f-secure,
law enforcement,
virus,
virus writer,
vx
Subscribe to:
Posts (Atom)
