Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Slot Machine Justice for Melissa Author
Mark Rasch, 2002-05-13

Under capricious computer crime sentencing rules, virus-writer David Smith managed to get the right prison term for all the wrong reasons.

Comments Mode:
Slot Machine Justice for Melissa Author 2002-05-14
Anonymous (2 replies)
Virus Writing Like Burning Cars 2002-05-15
Mark D. Rasch (1 replies)
Virus Writing Like Burning Cars 2002-05-17
Anonymous (1 replies)
Virus Writing Like Burning Cars 2002-05-18
Mark D. Rasch (2 replies)
What loss? 2002-05-22
Bugman (1 replies)
What loss? 2002-05-23
Anonymous
Virus Writing Like Burning Cars (hmmmmm) 2002-05-28
Pierre Vandevenne
This analogy is, indeed, interesting. Let's imagine that I burn a car. Without any doubt, I deserve to be punished.
Now, what if the neighbouring car catches fire because of the heat and then in turn lights its neighbour etc... until 25% of the cars in the city burn ? Woudln't car manufacturers share some of the responsability ? Wouldn't they be forced, by law, by governmental commission, by angry customers, to investigate why their cars are so flammable. Wouldn't they be forced to fix the essential underlying problem ? We all know the answer. One of the fundamental questions is then: why doesn't it happen with software ?

But also, what should we think when we hear that the US Senate or USMC's mail server goes down under the load ? When some of the world's most critical organizations are disrupted by a mere 100 lines of poorly cut and pasted VBS code ?

Like it or not, there are fundamental flaws in the infrastructure and the manufacturers (I am not aiming at a single company) of that infrastructure are not encouraged strongly enough to address them.

Yes, Smith deserved a punishment.

No, other virus writers won't be deterred by this (or any other) sentence. See what happened after Smith, when everyone expected him to be sentenced more heavily.

No, the fundamental problems haven't been addressed.

Oh, and one last word : Smith was so pitifully and so blatantly incompetent that I doubt he was able to offer technical assistance of any kind. If he actually did, it is much much worse than I thought...

pierre@datarescue.com

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/81/12815#12815







 

Privacy Statement
Copyright 2008, SecurityFocus