Film-Tech Cinema Systems
Film-Tech Forum ARCHIVE


  
my profile | my password | search | faq & rules | forum home
  next oldest topic   next newest topic
» Film-Tech Forum ARCHIVE   » Community   » Film-Yak   » Sasser worm author gets slap on wrist (Page 2)

 
This topic comprises 2 pages: 1  2 
 
Author Topic: Sasser worm author gets slap on wrist
Carl Martin
Phenomenal Film Handler

Posts: 1424
From: Oakland, CA, USA
Registered: Feb 2002


 - posted 07-11-2005 04:15 AM      Profile for Carl Martin   Author's Homepage   Email Carl Martin   Send New Private Message       Edit/Delete Post 
i think people who run leaky software pretty much get what they deserve. hospitals got shut down by the virus? those hospitals were poorly run. just as great care is taken to ensure cleanliness during surgery, great care should be taken in securing systems on which lives depend.

setting loose the virus was unethical, to be sure, but the real problem was that the weaknesses were there to exploit in the first place.

perhaps open source software should be used more when lives are at stake or security is really really important.

carl

 |  IP: Logged

Oscar Neundorfer
Master Film Handler

Posts: 275
From: Senoia, GA
Registered: May 2000


 - posted 07-11-2005 07:19 AM      Profile for Oscar Neundorfer   Author's Homepage   Email Oscar Neundorfer   Send New Private Message       Edit/Delete Post 
quote: Carl Martin
i think people who run leaky software pretty much get what they deserve.
By that analogy, if I don't have the latest high-tech locks and security system on my house, and I get broken into and my house gets destroyed, then I got exactly what I deserve.

Oh yeah, the victim is responsible. Right. Sure. Unbelievable.

 |  IP: Logged

Leo Enticknap
Film God

Posts: 7474
From: Loma Linda, CA
Registered: Jul 2000


 - posted 07-11-2005 10:19 AM      Profile for Leo Enticknap   Author's Homepage   Email Leo Enticknap   Send New Private Message       Edit/Delete Post 
quote: Bobby Henderson
It doesn't matter if some lady walks past you wearing nothing but a G-string and high heels. If she says "no" and you jump her anyway you committed rape and you need to be put away forever.
If you rape a prostitute in a red-light area after you solicited his or her services, but who decided (s)he didn't want to go through with it at the last moment, you'll receive a lesser sentence than if you snorted a load of crack cocaine, broke into a convent and raped an 80-year old nun. Likewise, if you're caught drink-driving but did not cause any accident or hurt anyone, you'll receive a lesser sentence than if you were arrested after your car ploughed into a pavement and killed five people. In other words, the law recognises differing degrees of blame according to the circumstances of the offence. The sentence is supposed to reflect a combination of how 'badly' the offender has offended and the impact of that offence on its victim(s).

In this case there's a mismatch between the badness and the impact. This was a kid who clearly didn't think through the consequences of his actions (some would argue - though not me - that he wasn't as able to do so as an adult would be) and probably didn't intend to cause the amount of damage he did. But on the other hand, this virus did cause a lot of economic damage. And as Bobby points out, hospitals, traffic control systems and the like are now run by Windows PCs, and the consequences of them being infected could be very serious. And I certainly agree with everyone here that the owners or operators of infected systems failing to take steps to keep malware out is absolutely not a mitigating factor in determining the sentence for someone who creates and/or deliberately distributes that malware.

Personally I'd say that the most appropriate sentence would be a lifetime order banning him from touching any equipment which is connected to the Internet. That would enable him to choose a new career and move on, while protecting the public from his obvious personality flaws.

 |  IP: Logged

Louis Bornwasser
Film God

Posts: 4441
From: prospect ky usa
Registered: Mar 2005


 - posted 07-11-2005 10:25 AM      Profile for Louis Bornwasser   Author's Homepage   Email Louis Bornwasser   Send New Private Message       Edit/Delete Post 
If you are old enough and smart enough to do the crime; you should accept the time.

 |  IP: Logged

Wolff King Morrow
Master Film Handler

Posts: 490
From: Denton, TX, USA
Registered: Feb 2004


 - posted 07-11-2005 04:29 PM      Profile for Wolff King Morrow   Author's Homepage   Email Wolff King Morrow   Send New Private Message       Edit/Delete Post 
I have always believed virus makers should get 10 years in prison with no early release. Moreover, it should be considered an act of terrorism on the international scale.

 |  IP: Logged

Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001


 - posted 07-11-2005 05:38 PM      Profile for Bobby Henderson   Email Bobby Henderson   Send New Private Message       Edit/Delete Post 
Oscar already responded to the notion that people who use bad software deserve what they get. I might add this is one of the extremely lame-brained reasons virus writers choose to somehow rationalize what they're doing.

I guarantee if anyone has a relative who dies in a hospital due to some virus-caused computer malfunction they would want to track down the virus writer and split open his head with a tire iron. They would be that angry.

quote: Carl Martin
perhaps open source software should be used more when lives are at stake or security is really really important.
That argument doesn't hold. If Open Source was really the key then there would be no viruses attacking Linux or any of the open source applications designed to run under it. There's all kind of viruses made just to vandalize the Linux based Apache Web Server.

The simple truth is virus writers are vandalous scum and need to be put away for a long time when they unleash their shit into the wild.

 |  IP: Logged

Dominic Espinosa
Phenomenal Film Handler

Posts: 1172
From: California, U.S.A.
Registered: Jan 2004


 - posted 07-12-2005 01:36 AM      Profile for Dominic Espinosa   Email Dominic Espinosa   Send New Private Message       Edit/Delete Post 
What I meant is that if you tell someone "hey, your emergency exit is cracked open" and they do nothing about it for YEARS AND YEARS AND YEARS and some jerk comes along and throws a half stick of dynamite in there, yes the kid with the matches is a vandal but the idiot who didn't close the door is also at fault.

What I mean is that Microsoft should secure their opperating systems against attacks that exploit holes in the software they write.

As with any system, the *nix's must be hardened but the quantity of malware out there than can even touch such a system is very low.
Servers running nix get brought down via DoS attacks more than software exploits.

 |  IP: Logged

Daryl C. W. O'Shea
Film God

Posts: 3977
From: Midland Ontario Canada (where Panavision & IMAX lenses come from)
Registered: Jun 2002


 - posted 07-12-2005 01:57 AM      Profile for Daryl C. W. O'Shea   Author's Homepage   Email Daryl C. W. O'Shea   Send New Private Message       Edit/Delete Post 
quote: Dominic Espinosa
What I mean is that Microsoft should secure their opperating systems against attacks that exploit holes in the software they write.
Exactly how would you like them to do this? Remember you only get to choose one of the following two options:

(a) Don't tell people about it, do nothing and hope no one discovers and exploits a particular bug.

(b) Respond to reports (from internal and external sources) of possible bugs in the software, develop patches, and deliver them in a timely manner with one of the most advanced content distribution systems in the world.

If you picked (b) then your argument doesn't apply to Sasser or the vast majority of the exploits of Microsoft operating systems in at least the past five years. Microsoft didn't even need to "secure their opperating systems against attacks that exploit holes in the software they write" since they had already "secured" their software two weeks prior to the fact. The exploit was in response to Microsoft securing their software.

I could go on for pages / hours about reasons for and against Microsoft releasing software that they later find flaws in. Everyone does it because at the time they believe there are no known flaws in the software. I won't criticize them for fixing a bug in a matter of days and then having some loser use that patch to develop an exploit. If I was going to criticize them for that I might as well choose (a) above.

 |  IP: Logged

Carl Martin
Phenomenal Film Handler

Posts: 1424
From: Oakland, CA, USA
Registered: Feb 2002


 - posted 07-12-2005 05:18 AM      Profile for Carl Martin   Author's Homepage   Email Carl Martin   Send New Private Message       Edit/Delete Post 
quote: Oscar Neundorfer
By that analogy, if I don't have the latest high-tech locks and security system on my house, and I get broken into and my house gets destroyed, then I got exactly what I deserve.

Oh yeah, the victim is responsible. Right. Sure. Unbelievable.

i think in this instance, and in general, one has to be careful about making analogies between the computer world and the "real" world. if you network your computer, that's tantamount to accepting the consequences of whatever comes down the pipeline. if you have a bug that can be exploited to compromise your system, that is equivalent to an invitation in a sense. not in the sense that that is what you want, or that you're "asking for it", of course, but those notions just don't have much purchase in the computer world. i suppose the law says different, i don't know.

why would a hospital or air traffic control or whatever critical system not be isolated from the internet? why would the microsoft patch not be implemented super-fast on these systems as a matter of course? they should have been.

okay, feel free to refute. just feeling these things out a bit. i do think this scenario is distinct from rape and burglary.

carl

 |  IP: Logged

Oscar Neundorfer
Master Film Handler

Posts: 275
From: Senoia, GA
Registered: May 2000


 - posted 07-12-2005 07:22 AM      Profile for Oscar Neundorfer   Author's Homepage   Email Oscar Neundorfer   Send New Private Message       Edit/Delete Post 
quote: Carl Martin
if you network your computer, that's tantamount to accepting the consequences of whatever comes down the pipeline. if you have a bug that can be exploited to compromise your system, that is equivalent to an invitation in a sense. not in the sense that that is what you want, or that you're "asking for it", of course
Well, I can't agree that connecting to the internet is tantamount to "accepting" the consequences. Yes, I realize there are risks involved, but the risks come from people with no moral character who see nothing wrong with taking from others in terms of time, money, and other property. Regardless of the law, if someone does that to anyone else, it is wrong.

If the temptation to commit a crime, destroy property (whether real or intellectual), or cause whatever damage one can do, is to be considered an invitation, then there are plenty of "invitations" out there in ALL forms, whether in the computer world or the real world. That does NOT mean that I issued the "invitation".

When I was a child in the 1950's, we rarely locked the doors on our house. On many occasions during the summer here in the hot South, with no air conditioning, we slept with the doors open. We did not have to worry then as we would now because the moral character of people in general was far better. Sure, there were people who would do wrong things, but not nearly to the extent there is now. Now, I always make sure ALL my locks are locked and the security system is on. I try hard to keep my family and property safe from the scumbags out there.

As to my analogy, both my computer(and its data) and my house are my property. The public internet is the path to my computer just as the public road system is the path to my house. Both my computer and my house are moderately secure but not impenetrable. Both have security vulnerabilities that could be exploited. Criminals could make efforts to break and enter either my computer or my house, and once in, cause damage in some form. There is the potential to lose something valuable that I have worked hard for due to this criminal activity.

Today, there is little respect on the part of many people for the property rights of others. Not to get political, but even our Supreme Court recently made a major ruling against legitimate individual property rights. Kids, which make up a good many of the virus writers out there if I am informed correctly, are especially inconsiderate of property rights, as evidenced by the number of kids making attacks on computer systems.

The bottom line is this: if someone breaks into my computer and destroys my work, wastes my time and money, and causes me much grief, that person is to blame, not me. I did not deserve it, I did not ask for it, and in my opinion they should be held to at least as high a degree of responsibility and as great a punishment as anyone breaking into my house and doing similar damage.

quote: Dominic Espinosa
yes the kid with the matches is a vandal but the idiot who didn't close the door is also at fault.

Once again, the victim is somehow responsible. I submit that your so called "idiot" should be able to leave the door wide open 24/7 and not have to worry about such things. It is ENTIRELY the fault of the vandal. Yes, I know this is the real world, but if it weren't for the vandals, we could do exactly as I suggested.

 |  IP: Logged

Bobby Henderson
"Ask me about Trajan."

Posts: 10973
From: Lawton, OK, USA
Registered: Apr 2001


 - posted 07-12-2005 11:13 AM      Profile for Bobby Henderson   Email Bobby Henderson   Send New Private Message       Edit/Delete Post 
quote: Carl Martin
i think in this instance, and in general, one has to be careful about making analogies between the computer world and the "real" world.
If you have your "real" money and "real" identity getting stolen via some criminal using a computer, the "real" world analogies definitely apply 100%. The hacker should have his real world butt thrown into the clink. Perhaps after a few years of getting his poo pushed in by a few thugs he might think twice about screwing with the lives of ordinary people.

Lots of computer hackers wrongly think they're providing some kind of Robin Hood style service for the world. Our perverted popular culture, of course, eats up that crap since they love all sorts of negative anti-heroes. But hackers aren't hurting anyone other than regular people. They may think they're sticking it to Microsoft when in reality they're making companies like Microsoft lots more money. Big corporations don't get hurt at all by this stuff. Those vandalistic bastards need to wake up and realize that sore truth.

quote: Carl Martin
if you have a bug that can be exploited to compromise your system, that is equivalent to an invitation in a sense.
Again, I completely disagree with that. And I think another real world analogy would be appropriate. If you walk through a neighborhood and notice the front door ajar on a house, that gives you absolutely no right at all to enter. If you choose to enter anway, you can be charged for breaking and entering.

The same rules should apply on computer crime. Just because you see an open door into a network that doesn't give you any right to enter it.

I'm sure some fellow Film-Tech members have seen this story:
http://www.cnn.com/2005/LAW/07/07/wi.fi.theft.ap/
quote:
ST. PETERSBURG, Florida (AP) -- Police have arrested a man for using someone else's wireless Internet network in one of the first criminal cases involving this fairly common practice.

Benjamin Smith III, 41, faces a pretrial hearing this month following his April arrest on charges of unauthorized access to a computer network, a third-degree felony.

Police say Smith admitted using the Wi-Fi signal from the home of Richard Dinon, who had noticed Smith sitting in an SUV outside Dinon's house using a laptop computer.

The practice is so new that the Florida Department of Law Enforcement doesn't even keep statistics, according to the St. Petersburg Times, which reported Smith's arrest this week.

Innocuous use of other people's unsecured Wi-Fi networks is common. But experts say that illegal use often goes undetected, such as people sneaking on others' networks to traffic in child pornography, steal credit card information and send death threats.

Security experts say people can prevent such access by turning on encryption or requiring passwords, but few bother or even know how to do so.

Wi-Fi, short for Wireless Fidelity, has enjoyed prolific growth since 2000. Millions of households have set up wireless home networks that allow people to use the Web from their backyards but also reach the house next door or down the street.

Prosecutors declined to comment, and a working phone number could not be located for Smith.

Copyright 2005 The Associated Press. All rights reserved.This material may not be published, broadcast, rewritten, or redistributed.

Wardriving into private home networks, even if you're just using it to jump onto the Internet for free is illegal. I have lots of criticism for people who leave their home Wi-Fi hotspots unsecured. They open themselves up to all sorts of trouble. But they're still not the ones committing the crime. The people choosing to enter are the only ones breaking the law.

 |  IP: Logged



All times are Central (GMT -6:00)
This topic comprises 2 pages: 1  2 
 
   Close Topic    Move Topic    Delete Topic    next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:



Powered by Infopop Corporation
UBB.classicTM 6.3.1.2

The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion and agrees to release the authors from any and all liability.

© 1999-2020 Film-Tech Cinema Systems, LLC. All rights reserved.