funsec mailing list archives

RE: Re: Malware sharing? People are full of shit [was:Getyour computer viruses here!]


From: "Randy Abrams" <abrams () eset com>
Date: Wed, 28 Dec 2005 16:58:53 -0800

 

-----Original Message-----
From: funsec-bounces () linuxbox org 
[mailto:funsec-bounces () linuxbox org] On Behalf Of val smith
Sent: Wednesday, December 28, 2005 4:19 PM
To: funsec () linuxbox org
Subject: Re: [funsec] Re: Malware sharing? People are full of 
shit [was:Getyour computer viruses here!]

So how would one scientifically measure the impact? Maybe 
watch incidents.org for rises in reports after I post 
something? Other ideas? Maybe try to correlate malware 
spewing IP's with downloads?

That's the point. We do know the danger in providing unvetted access, but if
you are going to purport that the good outweighs the bad shouldn't you be in
a position to demonstrate it? Again, a matter of erring on the side of
caution.


An automated vetting system is somewhat interesting. I wonder 
however if it can't be defeated easitly. Id like to hear more 
on this. What happens to people like many of my contributers 
who aren't affiliated with any kind of organization, and yet 
willing to contribute postive work? Do they just have to go 
back underground again? Or how does that work? 

They meet people and develop trust relationships. It's not a matter or
either have the connections or go back to the underground. There are other
options. Immediate gratification is not always the best approach. If I want
to build houses for poor people and I am do not have the proper credentials
to install electrical  wiring, breaker boxes, etc. I go and get the proper
credentials. It isn't a matter of just let me or I have to do it on the sly.


How do I reach the widest possible audience, and inspire new people to 
contribute without allowing "blackhats" to access it?

You don't go for the widest possible audience. You go for the widest
possible audience within the confines of reasonable security. It isn't all
absolutes. 

Cheers,

Randy

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: