New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1011
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
image CyberLife: WeekEnd Feature: Public enemy number one – the public. image
CyberLife

WeekEnd Feature:
Public enemy number one – the public.










by Ian Thompson, CCSP Staff Editor
May 1, 2004


What’s your worst nightmare? Is it global terrorism on your doorstep? Is it the threat of science gone mad, with genetic engineering and the prospect of meeting your own clone one day? Is it Batman? Is it being unwittingly co-opted into money laundering, spamming others or crippling DDOS attacks on governments and companies worldwide?

Welcome to the world of the unsafe PC user……

How safe is your car?
I read a lot of bits of interesting press each week. One writer I particularly look out for is Jack Schofield, columnist in the Guardian Online supplement. He’s capable of offering basic advice to all types of readers’ requests without the sort of jaded cynicism to which other similarly experienced hacks could resort, especially after offering the same advice time and again.

Another reason I like Jack is that, by one way or another, we both seem to have arrived at a very similar basket of security products. Great minds, as they say…

This week, Jack started his article with this:-
“If your car had four bald tyres and no brakes, you would not be allowed to take it on the road. But if your PC has no firewall and no anti-virus software, any number of people will be happy to provide you with a broadband Internet connection.”

So many people report that one nasty or another has hit their new pride’n’joy PC within minutes of connecting that this issue is getting serious. Clearly, our road traffic authorities have rules to help ensure a basic level of safety, and there now needs to be a move to similar requirements for our online activities. After all, the drivers of an unsafe vehicle are likely to have a detrimental effect on others as well as themselves when they go backwards through the scenery after they come to the first rainy corner that day…

Is it really life or death?
The situation with unprotected PCs is that it’s not a question of ‘if’ but ‘when’ the attack will come. Even relatively old worms can take advantage of unpatched systems, long after the rest of us have consigned those versions to the delete bin. So what are we looking for?

A sensible PC manufacturer will provide its customers with an up-to-date installation of the operating system (doesn’t matter which flavour, they all get improved during their life). This may required some effort on their part, because they will have the support issues to deal with if an update or patch proves problematic to one part or another of their chosen configuration. Things like recovery disk images would need to be kept current, as would any first-line support offered on web sites or hotlines.

However, we can basically assume that any manufacturer who still ships and out-of-box installation of Windows XP, for example, either hasn’t the resources or the respect for its customers that they deserve.

Media Center, anyone?
This shift in responsibility, from customer to manufacturer, must happen. There is no option, and if things keep going the way they are (with Jack’s unsafe vehicle analogy in mind), then pretty soon things are going to fall into the realms of legislation. And if that happens, expect costs to rocket because where there’s a law, there’s a need to check it’s being upheld – regulation, inspection, etc.

I recently had a look at a Media Center PC from Hi-Grade that took the idea of PC as consumer durable (rather than specialist market product) to it’s ultimate point – at least until ‘smart clothing’ arrives. The unit is very smart, in brushed silver, and looks like the older-style DVD player, perhaps the full-sized hifi separates unit that audiophiles would drool over. The only difference on the front compared to these older players is that the DVD drive is a slot-loader. The whole show looks very sleek, but is in fact a complete Windows Media Center PC. It doesn’t ship with any monitor as standard, using the home TV instead using a standard SCART AV connector, as found on regular home entertainment equipment like VCRs, DVD players and satellite decoders in these here parts.

It therefore removes the final barrier to the PC being thought of as a distinct device, to be treated with a bit more care than the family toaster, for example. Now it looks like part of the furniture, sitting near the TV with the rest of the push-button, anyone-can-use-it home entertainment stuff. Folk would just plug-and-go with this type of thing. But would they remember to keep it updated? Probably not, because it doesn’t look like it needs it – after all, when’s the last time you updated your DVD player firmware, or the digital TV decoder? If it’s ever at all, then it won’t be anywhere near as often as a regular PC… which is what it is, under all the flash and style. Just as vulnerable, just as crashable, and probably connected online via broadband the whole time it’s in use, not just when the user is surfing or emailing.

Do you have a valid licence?
Now, are we heading towards authorising users to connect PCs together? No, of course not – such a system would be unwieldy in the extreme and unworkable in practice. However, we need to have more than just a voluntary option to install protective systems. There needs to be a basic minimum required of any system that connects out to the rest of the world.

But it should not up to the end user to be aware of the need and then be up to finding the right resource. At risk of sounding anti-competitive and just a bit kiss-ass, Microsoft has the right approach with bundled applications, all under one update policy via Windows Update, with a Critical Update Notification watchdog looking out for the latest patches on behalf of the end-user. And from what I’ve seen of the RC2 version of XP sp2, the firewall seems up to the job.

What became of the anti-virus company they purchased last year? Surely that cannot have been just to shut down one of the more popular versions available to Linux server users? Okay, maybe it was, but the next logical step is a return to the old days when MS shipped a basic AV product with their OS – the only thing that killed that one at the time was a lack of updates. Now, with product activation, Windows Update and so on, MS can be a little bit more sure that the end user is valid, provide them with regular updates via the normal route and not have to charge for the privilege this time round!

Public Enemy?
So what’s with the headline? Well, the vast growth in PC numbers in the last five years has undoubtedly been in the home market. Business growth will have been brisk, but many companies will have upgraded some PCs as well as providing new ones. And most businesses will have many PCs behind one Internet connection, unlike home users where the average will be somewhere close to one per connection (at least until Media Center PCs take off and online gaming via Xbox increases). The bandwidth available to spammers, bot-commanders and IP spoofers everywhere is vastly increased.

Combine this with the unprotected nature of many of these systems (anyone got an AV on their Xbox?) and you have Nirvana for the nasties – “Fly, my lovelies! Fly!”. The bulk of the attacks against large organisations now comes from high-speed connections to home PCs, not from the companies themselves. Various legislative Acts have meant that companies have a duty to protect information and the like, and once a company starts to investigate the problem, it will pretty quickly arrive at an adequate (if not exactly exemplary) solution.

It’s the public that is it’s own worst nightmare.

/> The solution.
Always, the solution has been upheld with vigilance. You can fit a broadband router (and definitely should if you’ve more than one connected system), but make sure it’s kept up-to-date. You can install firewall software on each device if possible, along with anti-virus, spam filters and the like. You can even switch your ISP to one of the ‘big boys’ like Yahoo! or AOL (never dreamt I’d recommend them this side of senility) because they have the resources to do a lot of the control themselves. But you should never, ever just sit there and do nothing.

As Jack says, “You can either take these threats seriously or risk becoming a victim”.
cheers, Ian

by Ian Thompson ComputerCops Staff Editor

Ian Thompson is a Network Manager of a 500-PC, 9-server, 1700-user school network and is an ICT teacher at a UK high school near the city of Leeds. He has written articles for the Hutchinson Encyclopedia, plus many resources in support of teaching ICT in the UK schools' National Curriculum.

Copyright © Ian Thompson All Rights Reserved 2004.
Posted on Saturday, 01 May 2004 @ 09:16:33 EDT by phoenix22
image

 
Login
Nickname

Password

· New User? ·
Click here to create a registered account.
image
Related Links
· TrackBack (0)
· Linux.com
· PHP HomePage
· Microsoft
· Microsoft
· HotScripts
· W3 Consortium
· Spam Cop
· America Online
· More about CyberLife
· News by phoenix22


Most read story about CyberLife:
Public enemy number one – the public.

image
Article Rating
Average Score: 4.66
Votes: 3


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


image
Options

Printer Friendly Page  Printer Friendly Page

image
"Login" | Login/Create an Account | 5 comments | _SEARCHDIS
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Public enemy number one – the public. (Score: 1)
by phoenix22  on Saturday, 01 May 2004 @ 09:46:26 EDT
(User Info | Send a Message) http://computercops.biz
my car? ah, my car......yes, well it is quite safe actually. she's sleeping, at the moment, under a ev4 blanket in the gayrage, as it were.........



Re: Public enemy number one – the public. (Score: 1)
by Blast  on Saturday, 01 May 2004 @ 18:27:04 EDT
(User Info | Send a Message) http://www.billgray.biz
Another great article boss!!!
I'll have to pull my socks up right up to under me knees to even get close to your prolific writing abilities... and with such an oratory flavour in the written sense, I will have to step up or risk being left in the wake.
Good stuff!! Well done Ian, cheers.. Bill!



Re: Public enemy number one – the public. (Score: 1)
by ([email protected])  on Monday, 03 May 2004 @ 08:45:04 EDT
(User Info | Send a Message)
Uhh!! Which side of senility you on??? Yahboo and AOHell....you got to be kidding, right?? Please, tell me you are kidding. Where is Batman when you need him.......

I do tend to drool over high-end hi-fi, not too much, messes with the circuitry....get a little arcing across any fillings...not good. Use some too. Tandberg, Linn, Audiolab.....



Re: Public enemy number one – the public. (Score: 1)
by TMOV  on Wednesday, 05 May 2004 @ 01:58:15 EDT
(User Info | Send a Message)
IAN,
your topic is sure to reach some of us but there are too many user that are just plain complacent.
and so,to them it's as if it will never affect them ,only someone else.
as much as the problem affects the gross domestic product of the free world you would think that there would be a government entity interested in educating the poor fools that think that surfing the net without security updates installed or an effective anti-virus and an effective firewall, is tantamount to walking into the section of town where there's a lot of drug use and doing it in the middle of the night with a bunch of one hundred dollar bills taped to your coat with a sign on your back that reads:help yourself to all that you need, i'm just a dumb ass so take the money and kill me too if you like.
frustrated feeling here.
tmov



Re: Public enemy number one – the public. (Score: 1)
by Ian-OG  on Wednesday, 05 May 2004 @ 07:10:58 EDT
(User Info | Send a Message)
LOL! Yeah - only kidding (for the majority). I think I've still got a full set (of teeth, marbles and whatever - oh, hang on, I had four pulled when I was about 10 - teeth, that is... - to make room for all the big words ;¬D )

However, there may be a case for Joe Average to rely on others' vigilence (not everyone is clued-up, y'know!) - Internet certainly isn't the place it used to be 15 years ago, that's for damn sure. I remember one guy wowing that the connected world had just gone through the 1,000 server barrier. Back when it was academics anonymous, things were generally self-regulating... Viruses were a 'programming study' and we certainly didn't see the flame-war between virus coders like there is with Bagle and Netsky. Anyone keeping score on that match, BTW?