This is topic Sasser worm author gets slap on wrist in forum Film-Yak at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=004147

Posted by Bobby Henderson (Member # 840) on 07-09-2005, 09:46 PM:
 
The teenaged author of the Sasser worm got a slap on the wrist. And then he'll probably get a good paying job as a programmer after that. The folks running legal systems and law enforcement agencies around the world just don't get it. Crime is still crime even if it happens in the digital domain.

Perhaps it might be a bit harsh to throw this snot nosed vandal into "gen pop" within a maximum security prison for a few decades. But it would be perfectly fair for him to get sued into permanent oblivion, to the tune of at least several thousand dollars for each computer infected.

Anyway, here's a link and copy of the story text below:
http://www.cnn.com/2005/LAW/07/08/sasser.suspended/index.html

quote:

Sasser author gets suspended term
Friday, July 8, 2005; Posted: 9:19 a.m. EDT (13:19 GMT)

BERLIN, Germany (CNN) -- A German court has convicted the teenager who created the Sasser worm that snarled tens of thousands of computers last year and sentenced him to 21 months' probation.

Sven Jaschan, 19, from the northwest town of Waffensen, could have faced five years in prison as an adult but was tried as a minor because the court determined he created the virus when he was 17, said Katharina Kreutzfeldt, spokeswoman for the Verden State Court outside Bremen.

As part of the sentence, Jaschan will have to perform 30 hours of community work, either at a hospital or a retirement home, Kreutzfeldt said.

Prosecutors say Jaschan sent the computer worm on the Internet on his 18th birthday, April 29, 2004.

It was blamed for shutting down British Airways flight check-ins, hospitals and government offices in Hong Kong, part of Australia's rail network, Finnish banks, British Coast Guard stations, and millions of other computers worldwide.

The court said it was impossible to estimate the amount of damage. So far, no international civil suits have yet been filed, officials said.

Four German lawsuits were settled for under €1,000 each, said Arend Bosse, spokesman for the Rotenburg-Wuemme State Court.

Jaschan was caught last year after a tipster cashed in on a $250,000 reward offered by Microsoft, whose Windows system was prey to the virus.

Microsoft says the virus was part of a growing problem: hackers profiting from Windows vulnerabilities revealed by patches. The virus appeared 18 days after the company posted a patch to fix a flaw, and it attacked computers that hadn't downloaded the patch.

Jaschan, who reportedly spent up to 10 hours a day on his homemade computer, told Stern Magazine in an interview that he created the virus, which he called "Netzsky A," to combat two existing viruses, Mydoom and Bagle. Computer experts named Jaschan's virus "Sasser."

Jaschan, meanwhile, has taken a job at a computer company that creates anti-virus programs. After three years, Jaschan's conviction will be erased from public record if there are no new offenses, Kreutzfeldt said.

Authorities who questioned Jaschan said they believed his motive was to become a famous programmer. He was arrested at his computer at his the home of his mother, who runs a computer store.


 
Posted by Tim Reed (Member # 137) on 07-09-2005, 10:40 PM:
 
Just kill him!
 
Posted by Floyd Justin Newton (Member # 1316) on 07-10-2005, 08:29 AM:
 
Tim--

That MAY work. However there gazilions of such charaters out
there! (BTW I just spent $285.18 last week to get my computer
cleaned out.) [Eek!]
 
Posted by John Walsh (Member # 168) on 07-10-2005, 09:07 AM:
 
I mentioned this before (and I'm sure others have, too) but I think most politicians know very little about internet/computer technology. They have staff people print out their emails, perform internet searchs, etc. As a result, they rarely have to deal with the aggravation of spam, worms, virus', etc. themselves. So they still think computer problems are minor, victimless crimes.

Tim is right ... [evil]
 
Posted by Gordon McLeod (Member # 33) on 07-10-2005, 10:01 AM:
 
Also remember that not every country has the same laws in place and as such what may be a serious offence in one is not in another
 
Posted by Paul Mayer (Member # 355) on 07-10-2005, 10:04 AM:
 
Nuke 'em! [evil]
 
Posted by Louis Bornwasser (Member # 3063) on 07-10-2005, 10:19 AM:
 
Nuke 'em twice!
 
Posted by Bobby Henderson (Member # 840) on 07-10-2005, 12:24 PM:
 
quote:
It was blamed for shutting down British Airways flight check-ins, hospitals and government offices in Hong Kong, part of Australia's rail network, Finnish banks, British Coast Guard stations, and millions of other computers worldwide.
I just wanted to repeat that part of the news story.

Computers are controlling lots and lots of different systems where people's lives can be affected. Computers are controlling police dispatch systems, traffic control systems, medical dispatch, triage and other patient details. If a worm adversely affects those systems it could literally get someone killed.
[Mad]

And then you have the simple fact many small businesses rely on computers more than ever before to manage payroll, bill paying, organizing sales leads and more. If a piece of malware toasts a small business' main computer (likely to be a WindowsPC) it could put that business in some trouble. If the business was already struggling, such an event could be enough to finish off the business.

These are reasons why computer based crime needs to be punished much more severely. They need to be jammed with a 1st degree, federal level penalty that stays on their record permanently. These turds need to have the same hell visited on them that happens to any dumbass who robs a 7-Eleven. Such a felony conviction would automatically disqualify the convict from being able to get dozens of kinds of jobs. Offenders should be liable to extremely severe civil prosecution.

Many computer users may be dumb and reckless with their useage habits. But that removes absolutely no blame at all from the criminals who unleash malware online. It's basically the same logic behind punishing rape. It doesn't matter if some lady walks past you wearing nothing but a G-string and high heels. If she says "no" and you jump her anyway you committed rape and you need to be put away forever.
 
Posted by Gordon McLeod (Member # 33) on 07-10-2005, 12:52 PM:
 
"Such a felony conviction would automatically disqualify the convict from being able to get dozens of kinds of jobs. Offenders should be liable to extremely severe civil prosecution"
That still deosn't address that the prosecution must occur in the country of the person and there criminal codes may not recognize the crime
 
Posted by Dominic Espinosa (Member # 2122) on 07-10-2005, 01:09 PM:
 
quote: Bobby Henderson
The teenaged author of the Sasser worm got a slap on the wrist. And then he'll probably get a good paying job as a programmer after that. The folks running legal systems and law enforcement agencies around the world just don't get it. Crime is still crime even if it happens in the digital domain.
The laws are rediculously unbalanced.
Moreover, it's not really even his fault that his worm caused so many problems.
There's thousands of pieces of software that will cripple a Windows machine because Windows machines are rediculously vulnerable.
You'd think M$ would learn by now but they just don't.
They should run *Nix.
 
Posted by Tim Reed (Member # 137) on 07-10-2005, 01:59 PM:
 
quote: Dominic Espinosa
Moreover, it's not really even his fault that his worm caused so many problems.
What other purpose does a worm pgm have?
 
Posted by Bobby Henderson (Member # 840) on 07-10-2005, 02:05 PM:
 
quote: Dominic Espinosa
Moreover, it's not really even his fault that his worm caused so many problems.
That is fundamentally wrong. It is 100% his fault. He unleashed his piece of malware into the wild. It is all his fault for every computer infected.

If you just blindly fire a gun through a neighborhood, it would still be all your fault if the bullet hit someone -even if you didn't see the target down range. You pulled the trigger.

If you drove across an overpass and hurled a brick out your window at the Interstate highway below, it would be your fault if the brick went through someone else's windshield -even if you didn't see the car coming.

Sure, anyone can make arguments that Windows is crap and that all Microsoft products are vulnerable -but really that kind of argument is just bullshit. The only people that need to be blamed for computer viruses is the virus writers themselves. And it's high time they be very severely punished.

Virus writers are worthless, cowardly scum. They hide in their little cubby holes and laugh at how they screw things up for everyone else. Perhaps it might be a bit sadistic, but I think I would find it entertaining for one of these hackers to be handed over to a mob of hacking victims for one hell of an ass beating.
 
Posted by Oscar Neundorfer (Member # 458) on 07-10-2005, 02:09 PM:
 
quote: Dominic Espinosa
Moreover, it's not really even his fault that his worm caused so many problems.

If his worm crippled my computer, and I could have about 10 minutes alone with him, I think he would know at the end of 10 minutes exactly whose fault it was.
 
Posted by Brad Miller (Member # 2) on 07-10-2005, 02:25 PM:
 
There really ought to be a $1 million fine for every person caught like this, plus 5 years in jail with no possibility for early release AND MOST IMPORTANTLY that person is banished FOR LIFE by the government to work in any capacity, a job that has ANYTHING to do with a computer, short of punching an order up at a fast food place. The fine for that should be $5 million and the employer should be slapped with $20 million fine for hiring him.
 
Posted by Adam Wilbert (Member # 1184) on 07-10-2005, 07:02 PM:
 
I bet Microsoft is pleased with their $250,000 return on investment. [Roll Eyes]
 
Posted by Carl Martin (Member # 1146) on 07-11-2005, 04:15 AM:
 
i think people who run leaky software pretty much get what they deserve. hospitals got shut down by the virus? those hospitals were poorly run. just as great care is taken to ensure cleanliness during surgery, great care should be taken in securing systems on which lives depend.

setting loose the virus was unethical, to be sure, but the real problem was that the weaknesses were there to exploit in the first place.

perhaps open source software should be used more when lives are at stake or security is really really important.

carl
 
Posted by Oscar Neundorfer (Member # 458) on 07-11-2005, 07:19 AM:
 
quote: Carl Martin
i think people who run leaky software pretty much get what they deserve.
By that analogy, if I don't have the latest high-tech locks and security system on my house, and I get broken into and my house gets destroyed, then I got exactly what I deserve.

Oh yeah, the victim is responsible. Right. Sure. Unbelievable.
 
Posted by Leo Enticknap (Member # 534) on 07-11-2005, 10:19 AM:
 
quote: Bobby Henderson
It doesn't matter if some lady walks past you wearing nothing but a G-string and high heels. If she says "no" and you jump her anyway you committed rape and you need to be put away forever.
If you rape a prostitute in a red-light area after you solicited his or her services, but who decided (s)he didn't want to go through with it at the last moment, you'll receive a lesser sentence than if you snorted a load of crack cocaine, broke into a convent and raped an 80-year old nun. Likewise, if you're caught drink-driving but did not cause any accident or hurt anyone, you'll receive a lesser sentence than if you were arrested after your car ploughed into a pavement and killed five people. In other words, the law recognises differing degrees of blame according to the circumstances of the offence. The sentence is supposed to reflect a combination of how 'badly' the offender has offended and the impact of that offence on its victim(s).

In this case there's a mismatch between the badness and the impact. This was a kid who clearly didn't think through the consequences of his actions (some would argue - though not me - that he wasn't as able to do so as an adult would be) and probably didn't intend to cause the amount of damage he did. But on the other hand, this virus did cause a lot of economic damage. And as Bobby points out, hospitals, traffic control systems and the like are now run by Windows PCs, and the consequences of them being infected could be very serious. And I certainly agree with everyone here that the owners or operators of infected systems failing to take steps to keep malware out is absolutely not a mitigating factor in determining the sentence for someone who creates and/or deliberately distributes that malware.

Personally I'd say that the most appropriate sentence would be a lifetime order banning him from touching any equipment which is connected to the Internet. That would enable him to choose a new career and move on, while protecting the public from his obvious personality flaws.
 
Posted by Louis Bornwasser (Member # 3063) on 07-11-2005, 10:25 AM:
 
If you are old enough and smart enough to do the crime; you should accept the time.
 
Posted by Wolff King Morrow (Member # 2226) on 07-11-2005, 04:29 PM:
 
I have always believed virus makers should get 10 years in prison with no early release. Moreover, it should be considered an act of terrorism on the international scale.
 
Posted by Bobby Henderson (Member # 840) on 07-11-2005, 05:38 PM:
 
Oscar already responded to the notion that people who use bad software deserve what they get. I might add this is one of the extremely lame-brained reasons virus writers choose to somehow rationalize what they're doing.

I guarantee if anyone has a relative who dies in a hospital due to some virus-caused computer malfunction they would want to track down the virus writer and split open his head with a tire iron. They would be that angry.

quote: Carl Martin
perhaps open source software should be used more when lives are at stake or security is really really important.
That argument doesn't hold. If Open Source was really the key then there would be no viruses attacking Linux or any of the open source applications designed to run under it. There's all kind of viruses made just to vandalize the Linux based Apache Web Server.

The simple truth is virus writers are vandalous scum and need to be put away for a long time when they unleash their shit into the wild.
 
Posted by Dominic Espinosa (Member # 2122) on 07-12-2005, 01:36 AM:
 
What I meant is that if you tell someone "hey, your emergency exit is cracked open" and they do nothing about it for YEARS AND YEARS AND YEARS and some jerk comes along and throws a half stick of dynamite in there, yes the kid with the matches is a vandal but the idiot who didn't close the door is also at fault.

What I mean is that Microsoft should secure their opperating systems against attacks that exploit holes in the software they write.

As with any system, the *nix's must be hardened but the quantity of malware out there than can even touch such a system is very low.
Servers running nix get brought down via DoS attacks more than software exploits.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 07-12-2005, 01:57 AM:
 
quote: Dominic Espinosa
What I mean is that Microsoft should secure their opperating systems against attacks that exploit holes in the software they write.
Exactly how would you like them to do this? Remember you only get to choose one of the following two options:

(a) Don't tell people about it, do nothing and hope no one discovers and exploits a particular bug.

(b) Respond to reports (from internal and external sources) of possible bugs in the software, develop patches, and deliver them in a timely manner with one of the most advanced content distribution systems in the world.

If you picked (b) then your argument doesn't apply to Sasser or the vast majority of the exploits of Microsoft operating systems in at least the past five years. Microsoft didn't even need to "secure their opperating systems against attacks that exploit holes in the software they write" since they had already "secured" their software two weeks prior to the fact. The exploit was in response to Microsoft securing their software.

I could go on for pages / hours about reasons for and against Microsoft releasing software that they later find flaws in. Everyone does it because at the time they believe there are no known flaws in the software. I won't criticize them for fixing a bug in a matter of days and then having some loser use that patch to develop an exploit. If I was going to criticize them for that I might as well choose (a) above.
 
Posted by Carl Martin (Member # 1146) on 07-12-2005, 05:18 AM:
 
quote: Oscar Neundorfer
By that analogy, if I don't have the latest high-tech locks and security system on my house, and I get broken into and my house gets destroyed, then I got exactly what I deserve.

Oh yeah, the victim is responsible. Right. Sure. Unbelievable.

i think in this instance, and in general, one has to be careful about making analogies between the computer world and the "real" world. if you network your computer, that's tantamount to accepting the consequences of whatever comes down the pipeline. if you have a bug that can be exploited to compromise your system, that is equivalent to an invitation in a sense. not in the sense that that is what you want, or that you're "asking for it", of course, but those notions just don't have much purchase in the computer world. i suppose the law says different, i don't know.

why would a hospital or air traffic control or whatever critical system not be isolated from the internet? why would the microsoft patch not be implemented super-fast on these systems as a matter of course? they should have been.

okay, feel free to refute. just feeling these things out a bit. i do think this scenario is distinct from rape and burglary.

carl
 
Posted by Oscar Neundorfer (Member # 458) on 07-12-2005, 07:22 AM:
 
quote: Carl Martin
if you network your computer, that's tantamount to accepting the consequences of whatever comes down the pipeline. if you have a bug that can be exploited to compromise your system, that is equivalent to an invitation in a sense. not in the sense that that is what you want, or that you're "asking for it", of course
Well, I can't agree that connecting to the internet is tantamount to "accepting" the consequences. Yes, I realize there are risks involved, but the risks come from people with no moral character who see nothing wrong with taking from others in terms of time, money, and other property. Regardless of the law, if someone does that to anyone else, it is wrong.

If the temptation to commit a crime, destroy property (whether real or intellectual), or cause whatever damage one can do, is to be considered an invitation, then there are plenty of "invitations" out there in ALL forms, whether in the computer world or the real world. That does NOT mean that I issued the "invitation".

When I was a child in the 1950's, we rarely locked the doors on our house. On many occasions during the summer here in the hot South, with no air conditioning, we slept with the doors open. We did not have to worry then as we would now because the moral character of people in general was far better. Sure, there were people who would do wrong things, but not nearly to the extent there is now. Now, I always make sure ALL my locks are locked and the security system is on. I try hard to keep my family and property safe from the scumbags out there.

As to my analogy, both my computer(and its data) and my house are my property. The public internet is the path to my computer just as the public road system is the path to my house. Both my computer and my house are moderately secure but not impenetrable. Both have security vulnerabilities that could be exploited. Criminals could make efforts to break and enter either my computer or my house, and once in, cause damage in some form. There is the potential to lose something valuable that I have worked hard for due to this criminal activity.

Today, there is little respect on the part of many people for the property rights of others. Not to get political, but even our Supreme Court recently made a major ruling against legitimate individual property rights. Kids, which make up a good many of the virus writers out there if I am informed correctly, are especially inconsiderate of property rights, as evidenced by the number of kids making attacks on computer systems.

The bottom line is this: if someone breaks into my computer and destroys my work, wastes my time and money, and causes me much grief, that person is to blame, not me. I did not deserve it, I did not ask for it, and in my opinion they should be held to at least as high a degree of responsibility and as great a punishment as anyone breaking into my house and doing similar damage.

quote: Dominic Espinosa
yes the kid with the matches is a vandal but the idiot who didn't close the door is also at fault.

Once again, the victim is somehow responsible. I submit that your so called "idiot" should be able to leave the door wide open 24/7 and not have to worry about such things. It is ENTIRELY the fault of the vandal. Yes, I know this is the real world, but if it weren't for the vandals, we could do exactly as I suggested.
 
Posted by Bobby Henderson (Member # 840) on 07-12-2005, 11:13 AM:
 
quote: Carl Martin
i think in this instance, and in general, one has to be careful about making analogies between the computer world and the "real" world.
If you have your "real" money and "real" identity getting stolen via some criminal using a computer, the "real" world analogies definitely apply 100%. The hacker should have his real world butt thrown into the clink. Perhaps after a few years of getting his poo pushed in by a few thugs he might think twice about screwing with the lives of ordinary people.

Lots of computer hackers wrongly think they're providing some kind of Robin Hood style service for the world. Our perverted popular culture, of course, eats up that crap since they love all sorts of negative anti-heroes. But hackers aren't hurting anyone other than regular people. They may think they're sticking it to Microsoft when in reality they're making companies like Microsoft lots more money. Big corporations don't get hurt at all by this stuff. Those vandalistic bastards need to wake up and realize that sore truth.

quote: Carl Martin
if you have a bug that can be exploited to compromise your system, that is equivalent to an invitation in a sense.
Again, I completely disagree with that. And I think another real world analogy would be appropriate. If you walk through a neighborhood and notice the front door ajar on a house, that gives you absolutely no right at all to enter. If you choose to enter anway, you can be charged for breaking and entering.

The same rules should apply on computer crime. Just because you see an open door into a network that doesn't give you any right to enter it.

I'm sure some fellow Film-Tech members have seen this story:
http://www.cnn.com/2005/LAW/07/07/wi.fi.theft.ap/
quote:
ST. PETERSBURG, Florida (AP) -- Police have arrested a man for using someone else's wireless Internet network in one of the first criminal cases involving this fairly common practice.

Benjamin Smith III, 41, faces a pretrial hearing this month following his April arrest on charges of unauthorized access to a computer network, a third-degree felony.

Police say Smith admitted using the Wi-Fi signal from the home of Richard Dinon, who had noticed Smith sitting in an SUV outside Dinon's house using a laptop computer.

The practice is so new that the Florida Department of Law Enforcement doesn't even keep statistics, according to the St. Petersburg Times, which reported Smith's arrest this week.

Innocuous use of other people's unsecured Wi-Fi networks is common. But experts say that illegal use often goes undetected, such as people sneaking on others' networks to traffic in child pornography, steal credit card information and send death threats.

Security experts say people can prevent such access by turning on encryption or requiring passwords, but few bother or even know how to do so.

Wi-Fi, short for Wireless Fidelity, has enjoyed prolific growth since 2000. Millions of households have set up wireless home networks that allow people to use the Web from their backyards but also reach the house next door or down the street.

Prosecutors declined to comment, and a working phone number could not be located for Smith.

Copyright 2005 The Associated Press. All rights reserved.This material may not be published, broadcast, rewritten, or redistributed.

Wardriving into private home networks, even if you're just using it to jump onto the Internet for free is illegal. I have lots of criticism for people who leave their home Wi-Fi hotspots unsecured. They open themselves up to all sorts of trouble. But they're still not the ones committing the crime. The people choosing to enter are the only ones breaking the law.
 




Powered by Infopop Corporation
UBB.classicTM 6.3.1.2