<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; Commentary</title>
	<atom:link href="http://www.spamchronicles.com/category/commentary/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Chronicling My Spam Explorations</description>
	<lastBuildDate>Wed, 12 Sep 2007 02:11:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>U.S. AntiSpyware Legislation: Oh-oh</title>
		<link>http://www.spamchronicles.com/2007/05/02/us-antispyware-legislation-oh-oh/</link>
		<comments>http://www.spamchronicles.com/2007/05/02/us-antispyware-legislation-oh-oh/#comments</comments>
		<pubDate>Thu, 03 May 2007 02:46:46 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[law]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/news/us-antispyware-legislation-oh-oh/</guid>
		<description><![CDATA[A U.S. House of Representatives subcommittee approved a bill known as the Internet Spyware Prevention Act which was given the catchy name &#8220;I-Spy&#8221;. As a CNet News article points out, this has been tried before and hasn&#8217;t passed. While outlawing spam seems like a good idea in theory I suspect it will fail in practice. [...]]]></description>
			<content:encoded><![CDATA[<p>A U.S. House of Representatives subcommittee approved a bill known as the <a href="http://thomas.loc.gov/cgi-bin/bdquery/z?d110:h.r.01525:" title="Jump to the Library of Congress Thomas entry on the bill">Internet Spyware Prevention Act</a> which was given the catchy name &#8220;I-Spy&#8221;. As a <a href="http://news.com.com/House+tries+again+for+antispyware+bill/2100-7348-6180708.html?part=dht&amp;tag=nl.e703" title="Jump to the news.com story about the I-Spy act">CNet News</a> article points out, this has been tried before and hasn&#8217;t passed.</p>
<p>While outlawing spam seems like a good idea in theory I suspect it will fail in practice. Instead of preventing and reducing spyware it will provide a roadmap and protection for some while not really outlawing anything new. The FTC says they already have the <a href="http://news.com.com/FTC+officials+blast+spyware+measures/2100-1023_3-5202016.html" title="Jump to the news.com article about the FTC's view">ability to go after</a> the worst offenders and in fact have <a href="http://news.com.com/FTC+sues+company+over+spyware/2110-7348_3-5889202.html" title="Jump to a news.com article about ftc lawsuits against spyware distributors">sued some</a>. <a href="http://www.cdt.org/privacy/spyware/20060626spyware-enforcement-federal.php" title="Jump to nformation about criminal charges against spyware distributors">Criminal charges</a> have been brought against others under current law.</p>
<p>While I&#8217;m not sure the FTC always has the consumers best interests in mind, the bill doesn&#8217;t seem to have any real teeth. Most of what the bill seems to outlaw (taking personal information &#8211; which is defined) seems to be already illegal. The bill also links the act of installing the spyware with the intent of committing another crime, defrauding someone, or damaging the computer.</p>
<p>Software companies are supporting this version of the bill because it&#8217;s less onerous than other versions. To me that means this bill could open the floodgates and give cover to a lot of people. Would the Sony rootkit be illegal? While stupid and damaging their was no &#8220;intent&#8221; to damage. Would this law have given cover to Sony in their civil suits?</p>
<p>On the other hand, a badly written law could hurt legitimate software companies and developers without actually improving anything.</p>
<p>With the Can-Spam act as a role model, I don&#8217;t expect this to make a difference one way or another. (Even though I-Spy is as catchy as Can-Spam) The botnet operators are already breaking laws, this won&#8217;t make them stop. A bad law could hurt legitimate developers. All that is sure to happen if the law passes is that some Representatives and Senators can use their support of he bill to get votes.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/04/23/viruses-spam-and-software-updates-2/" rel="bookmark" class="crp_title">Viruses, Spam and Software Updates</a></li><li><a href="http://www.spamchronicles.com/2007/06/12/rootkit-revealer/" rel="bookmark" class="crp_title">Rootkit Revealer</a></li><li><a href="http://www.spamchronicles.com/2007/06/03/spam-counts-for-week-ending-june-3-2007/" rel="bookmark" class="crp_title">Spam Counts for Week Ending June 3, 2007</a></li><li><a href="http://www.spamchronicles.com/2007/04/15/viruses-spam-and-software-updates/" rel="bookmark" class="crp_title">Viruses, Spam and Software Updates</a></li><li><a href="http://www.spamchronicles.com/2007/08/08/spam-news-from-around-the-web/" rel="bookmark" class="crp_title">Spam News From Around The Web</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/05/02/us-antispyware-legislation-oh-oh/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac Hacked &#8211; Both Sides Miss the Point</title>
		<link>http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/</link>
		<comments>http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/#comments</comments>
		<pubDate>Wed, 25 Apr 2007 23:38:17 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[mac]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/commentary/mac-hacked-both-sides-miss-the-point/</guid>
		<description><![CDATA[One of two MacBooks was hacked at the CanWestSec conference is Vancouver, Canada. Both Macbooks were part of the &#8220;hack-a-Mac-contest&#8221; at the show. A successful hacker got the Macbook. The Macbooks were set up with OS X and all the latest security updates (including 2007-004) but no additional security software or special settings. One of [...]]]></description>
			<content:encoded><![CDATA[<p>One of two MacBooks was hacked at the CanWestSec conference is Vancouver, Canada. Both Macbooks were part of the &#8220;hack-a-Mac-contest&#8221; at the show. A successful hacker got the Macbook. The Macbooks were set up with OS X and all the latest security updates (including 2007-004) but no additional security software or special settings.</p>
<p>One of the Macs was hacked on the second day, which made headlines (in the types of publications that care about such things). The headlines tended to be slanted in one of two directions. Some emphasized that Mac security was breached and equated it to the worst windows vulnerabilities. They left out the details. On the other side the articles were slanted towards the fact that the breach only occurred after the rules were relaxed and that the breach didn&#8217;t get root access. This was true and more detailed than the sensational headlines in the first category, but they tended to imply the breach was meaningless.</p>
<p>The facts are:</p>
<ul>
<li>The Mac was breached when it visited a malicious website</li>
<li>The vulnerability is in Quicktime (Initial reports that it was a vulnerability in Safari were wrong.)</li>
<li>Both Firefox and Safari could be used to deliver the vulnerability</li>
<li>Windows is also considered vulnerable (if it has Quicktime)</li>
<li>The vulnerability was found by a security researcher and the exploit was actually delivered by a friend of his. The friend is keeping the MacBook, the researcher is applying for the $10,000 bounty offered by TippingPoint.</li>
<li>A second Mac, which required a hacker to get root/administrator level access and did not surf the web was not breached.</li>
</ul>
<p>What does this all mean, if anything?</p>
<p><span id="more-35"></span></p>
<p>Starting at the top, it was necessary to visit a website to be breached. The OS used doesn&#8217;t affect whether or not a person visits a website. So social engineering is universally available to every OS with a web browser. (I&#8217;ll avoid the path which talks about which OS has &#8220;smarter&#8221; users.) The best that can be said is that since there&#8217;s more windows users they&#8217;re more likely to be affected if the vulnerability is OS specific. But do exploits have to be OS specific?</p>
<p>The vulnerability was in Quicktime which is essentially a third party app. I don&#8217;t say this to claim OS X wasn&#8217;t hacked. Apple created Quicktime and delivers it with every new Mac. Apple is responsible for it and for updating it. But Quicktime is essentially a 3rd party app made by the same company as the OS so it&#8217;s bundled. The vulnerability is also thought to exist in the Windows version (for obvious reasons the exact details of the vulnerability aren&#8217;t public). The Macromedia (now Adobe) Flash Player is another 3rd party web-helper app that has had <a href="http://www.adobe.com/devnet/security/security_zone/mpsb05-07.html" title="Jump to an example of a Flash player vulnerability">vulnerabilities</a> in the past. OS venders can&#8217;t prevent vulnerabilities in 3rd party apps, the most they can do is mitigate their effect.</p>
<p>Both Firefox and Safari could be used to run the exploit. This isn&#8217;t surprising since the vulnerability was in Quicktime. But it does mean any modern browser could probably be used.</p>
<p>Windows, with Quicktime, is also vulernable (or it&#8217;s thought to be). By exploiting a vulnerbility in a third party app it&#8217;s possible to exploit multiple OS&#8217;s. The greatest number of PCs are still Windows so the payload delivered by the exploit might be Windows only if the hacker is lazy or just wants the biggest bang. But it&#8217;s not difficult to determine the OS used so it would be trivial to deliver an OS specific exploit for various OS&#8217;s through the same exploit. It&#8217;s just a matter of writing each exploit.</p>
<p>The exploit was found as part of a contest with a prize of a Macbook and was submitted for a $10K prize. Year&#8217;s ago it might have been enough to be able to claim bragging rights. Now money is a prime motivator. Money motivates hacking for both good (bounties, paychecks) and for bad (sell spam distribution, steal passwords). An OS will be targeted when the financial rewards justify the efforts.</p>
<p>Root level access was not obtained, &#8220;only&#8221; user level access. While this may be the best a current OS can do when a 3rd party app is hacked it still does not mean we aren&#8217;t at risk. Programs installed into the user&#8217;s folders do not require a password to install and run. As Windows PCs become more secure hackers may have to learn to live with user-level hacks in the Windows world. Since that world is so large there&#8217;s a bigger financial reward for success. Once the lessons are learned there they will be trivial (low cost) to transfer to the OS X world. So while OS X may have a smaller user base (and therefore reward) the cost to hack OS X will also drop. Most of what hacker&#8217;s want is available though user level access, just easier when you can own the machine as an administrator. It just means you need to be signed on (unless they find a way around that) but many PCs and Macs use auto logons and most PCs stay always logged on when ever they are turned on.</p>
<p>Of course, the old unavoidable hacks persist as evidenced by the recent animated cursor exploit for which we were defenseless for awhile and could be exploited without us having to click anything (although receiving an email or going to a website were still required). But their numbers are decreasing.</p>
<p>I wouldn&#8217;t be surprised to learn that a PC installed with Vista (latest patches, additional software or settings) would be as secure as OS X. But what will bite Microsoft is that they don&#8217;t control the installations, the resellers do. Since tight security means more support calls (which go to the vendor, not to Microsoft) I wouldn&#8217;t be surprised to learn that what&#8217;s actually shipping is not as secure as it should be.</p>
<p>The best protection Mac users have is that there&#8217;s an extremely large population of vulnerable Windows machines out there and exploiting them is easy. In Windows XP Service Pack 2 Microsoft turned on the firewall by default. This made it much harder to just scan the internet looking for open ports to exploit and deliver a payload. This brought a drop in the spread of viruses through that method but an increase in other methods such as email and malicious websites. These are methods which require a user to take action (again, with some exceptions when a vulnerability can be exploited to bypass user action). With the firewall change the hackers changed their tactics to other profitable methods. I won&#8217;t be surprised to learn that web based attacks are becoming more sophisticated and will use cross-platform applications to exploit multiple OS. And as more applications work cross platform we&#8217;ll probably see more multiple OS aware attacks through their data files.</p>
<p>The good news is that Mac OS X has good security and Microsoft Windows is getting more secure as Microsoft learns it&#8217;s lessons. Us humans are now being targeted as the weak link but we do have control over where we browse and what email we open. The bad news is that there are still software vulnerabilities so that even the most careful of us are still at risk, although less risk than before.</p>
<p>The point isn&#8217;t which is more secure, OS X or Linux. The point is whether or not your computing habits and the software you use are secure. If they aren&#8217;t secure then no matter which OS you use it&#8217;s only a matter of time before you have problems.</p>
<p><a href="http://news.com.com/Mac++hacked+through+QuickTime+flaw/2100-1002_3-6178787.html" title="Jump to the news.com article about the Mac hack">News.com</a> has a good story about the hack that emphasizes the details instead of the hype.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li><li><a href="http://www.spamchronicles.com/2007/05/15/symantec-hackers-can-bypass-firewall-with-windows-update/" rel="bookmark" class="crp_title">Symantec: Hackers Can Bypass Firewall With Windows Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/12/adobe-patches-flash-player/" rel="bookmark" class="crp_title">Adobe Patches Flash Player</a></li><li><a href="http://www.spamchronicles.com/2007/05/06/summary-of-week-ending-may-5th/" rel="bookmark" class="crp_title">Summary of Week Ending May 5th</a></li><li><a href="http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/" rel="bookmark" class="crp_title">Windows PC Have Cursor Hole</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
