Showing posts with label sunbeltblog. Show all posts
Showing posts with label sunbeltblog. Show all posts

Tuesday, October 24, 2006

sunbeltblog on patchguard

this is going to be another one of those totally out of character posts where i actually say nice things so get your protective gear on because the world might just end while you read it...

i was playing around with the idea of doing my own post on patchguard, inspired by some of the crazy notions i've seen bandied about on various security blogs (mostly those without any anti-malware specialization), but now i don't have to because alex eckelberry has absolutely nailed it...

he touched on all the right things, from the inevitability of failure of any given preventative measure, to the importance of flexibility when trying to deal with new threats... he even incorporated concepts of anti-malware strategy and tactics the likes of which i rarely see discussed but often aspire to myself...

bravo, alex...

Saturday, April 08, 2006

attention visitors from subeltblog - please read this

i'm getting an influx of traffic from sunbeltblog readers over the adware comment thread to end all adware comment threads that i wrote about earlier...

i would like to ask you all, before you send me hate-mail for being an 'adware apologist' (which i'm not), please take some courses in abstract reasoning and critical analysis - because once you actually have a handle on those skills you will probably understand what i was talking about in that comment thread...

the synopsis goes like so:

an anti-spyware website criticized an anti-spyware application (labelled it rogue, actually) in part because it was bundled with adware...

the question is, does installing program B make program A bad? the answer is yes if:
1. program A (an anti-spyware app) was supposed to stop program B (an adware client)

or

2. program B can be shown to be bad itself


while many adware clients are also spyware of one form or another, the anti-spyware website in question never established that the adware in question was also spyware so number 1 above is out... that just leaves us with number 2, but again the anti-spyware website in question failed to show that program B was bad, opting instead to simply indicate who created it...

being created by bad people (in this case very bad people) doesn't make software bad (john mcafee became a pariah in the av industry for his practices, but his software was still good)... furthermore, just because most of the software made by those bad people is bad doesn't mean this one in particular is bad... you can't prove they've never made good software (because you can't prove a negative), but you can prove that this one was bad if it really was - either indicate how the program was bad or indicate that it matches a program that was previously analyzed and determined to be bad...

does just being adware make it bad? no it does not.. not all adware installs in secret (and in this case the adware's presence was fully disclosed), not all adware has pop-ups, not all adware is also spyware... none of those really bad things most people associate with adware are actually inherent to adware, they're simply present in the vast majority of cases...

was this particular instance of adware bad? probably... most (possibly all) instances of adware produced by it's creators were spyware and those creators are now paying the price for it...

was the anti-spyware app it was bundled with really rogue? definitely... aside from bundling probable spyware with an anti-spyware app, it used deceptive practices to get users to install it and there is serious question as to whether it actually detects and/or removes any spyware...

unfortunately for me, i use a functional definition for adware that is unencumbered by emotional baggage related to it's association with other types of malware and so i create contraversy and get hate-mail... but using an adware defintion that is abstracted from other forms of malware doesn't make me an adware apologist, it makes me a computer scientist and anyone who doesn't like it can stick it where the sun don't shine...

Saturday, March 25, 2006

magic at sunbeltblog.blogspot.com

so there appears to be some vanishing act going on at the sunbelt blog... in a recent article there talking about how pamela parker got it wrong i made a comment about how alex eck wasn't exactly on the money himself...

now the original url points nowhere and the original comments link has been replaced with a new one that was showing no comments...

i suspect this is nothing more than the consequences of editing the original article to remove a paragraph defending aim against being called adware (sorry, i could find no cache of the original article, you'll just have to take my word for it that said paragraph existed) combined with the vagaries of how blogspot handles edits and how haloscan (the comment service provider there) handles changes to the article's permalink... i haven't checked to see if blogspot really changes the url when you edit an already published article, but i do have some articles where the permalink has a number at the end like the new link for the sunbelt article in question...

just in case the original comment link goes on walkabout as well, here's a quote of what i posted to it:
i'm going to both agree and disagree...

i agree that pam's got it all wrong - adware is more than just ad-supported software... it's got to actually DISPLAY ads, not just be supported by them... there are plenty of ad supported programs out there that leave the ad serving up to a completely different program...

i disagree about aim (and others) not being adware, however... the qualifier you use to justify that distinction is that the 'primary purpose' of adware is to display ads, but i contend that trying to determine the 'primary purpose' of an application is a subjective property... it's a bad defining quality and ruins what could otherwise be a perfectly good *functional* definition...

for example, say someone comes along and makes an instant messaging service that's functionally identical to aim, but they do it not to provide the world with yet another instant messaging application but rather to deploy a platform which not only serves ads but baits users into looking at the ad serving window by putting useful functionality on it... this is still all functionally identical to aim, but it's purpose is to display ads and the instant messaging is just to keep people looking in the direction of those ads... something doesn't stop being adware just because you shoe-horn useful functionality into the ad serving client, and there's really no way to know if the functionality is there to help the ads or if the ads are there to pay for the functionality...

of course, it's not necessary to go through that convolution... aim, like most of the mainstream instant messaging clients, has at various times erected barriers to interroperability both with other im services and with 3rd party clients... the only purpose interroperability barriers serve is to guard a captive audience, which are themselves only good practicing various types of persuasion (like advertising)... so the idea that aim's primary purpose is not providing advertising is questionable at best...

moreover, if the anti-adware/anti-spyware industry persists in using such a definition (yes, i noticed that the anti-spyware coalition's definition shares the same 'feature') the adware industry could easily just port their technology into dlls and activex controls that are bundled by way of integrating them into the 3rd party's application... they'd still be capable of doing all the bad things that people hate about adware but they'd no longer be separate from the programs they're bundled with and the 'primary purpose' of the main app would then exclude such a hybrid from the adware set...


as i said before, i don't think there was any funny business going on here, i think it was probably just an edit to correct an already published article which in turn had some interesting side effects...

and now you know why i don't provide for comments on this blog - if i should happen to edit something (and there are some things i can see myself modifying on occasion, like adding citations to my definition posts) i wouldn't want to have to deal with the consequences...

Sunday, March 12, 2006

the adware comment thread to end all adware comment threads

story time folks... currently i'm embroiled quite the debate in the comments section of a posting over at sunbeltblog and in true vitalsecurity.org fashion i thought i'd offer up my observations here...

first i'll confess to making an error, i started out by misinterpreting the source material, i thought an anti-spyware app had been labelled rogue simply because it had been bundled with adware... the interesting thing is that people actually defended this interpretation - that is, if my interpretation had been what actually happened they would defend that action apparently just because the adware in question was produced by a company with a shady past...

now, i hate adware as much as the next guy and i certainly wouldn't touch this thing with a 10 foot barge pole (at least not outside of a virtual environment), but i'm honest enough with myself to admit that that is purely on suspicion alone, whereas the overwhelming opinion of the other participants seems to be that if the software is made by bad people or even people who have done bad things in the past then the software itself is bad... it's been these kinds of peculiar ideas that have kept me going back...

now i've known for a long time that the malware problem has many dimensions, it's not just the software that we need to concern ourselves with, but when we are dealing with the software part of the problem should we let things like the creator's past cloud the issue? no, of course not, that's a different part of the malware problem and it's best dealt with in a different way... when we classify malware we're concerned with whether or not the software itself poses a risk, not whether it further's some corporation's nefarious agenda... internet explorer furthered a corporation's nefarious agenda (just ask the department of justice) but that doesn't make it malware...

another peculiar idea i encountered was that if you don't deal with the question of whether the people who made the software are bad when you're deciding whether the software itself is bad then somehow you're not addressing the badness of the people at all... come on, the malware problem is a complex one, and the secret to dealing with complex problems is to break them into their component parts and deal with those parts separately... just because you aren't dealing with the people when you're dealing with the software doesn't mean you aren't dealing with the people at all, just that you've compartmentalized your efforts... is that a bad thing? no, certainly not, in fact it means you're much less likely to try and use your software solution on a people problem... and lets face it, software doesn't solve people problems - it solves problems for people, but not problems with people...