NewsScan Daily, 30 June 2004 ("Above The Fold")
"NewsScan" <[email protected]> Wed, 30 Jun 2004 07:27:24 -0700
| Newsgroups | gmane.culture.it.newsscan |
|---|---|
| Message-ID | <[email protected]> |
NewsScan Daily, 30 June 2004 ("Above The Fold")
***********************************************************
NewsScan Daily is underwritten by RLG, a world-class organization making
significant and sustained contributions to the effective management and
appropriate use of information technology. NSD is written by John Gehl and
Suzanne Douglas, [email protected].
***********************************************************
"ABOVE THE FOLD"
Network Vandals Want to Bank With You
Sun to IBM: Go Outsource Yourself
Microsoft Products for Amateur Developers
Steganography
Indian Insourcing
FEATURES
Flash Card
Mailbag: The World As We Find It
NETWORK VANDALS WANT TO BANK WITH YOU
Computer security experts are issuing warnings that network vandals
hope to steal the password and account information of online bank accounts
by secretly downloading spy software to capture a PC user's keystroke
activity. The problem is not widespread, but Internet Explorer users are
being advised to set the security setting for their browsers to "high" (a
level which, however, makes it more difficult to interact with some Web
sites). (Washington Post 29 Jun 2004)
http://www.washingtonpost.com/wp-dyn/articles/A16023-2004Jun29.html
SUN TO IBM: GO OUTSOURCE YOURSELF
Sun Microsystems chief executive Scott McNealy has no interest in
cajoled by IBM and others to have Sun donate its Java technology to the open
source movement: "Our stewardship, though extensive, is unwavering. We want
IBM to donate its own intellectual property to the community. Get the
bulldozers out and break down their walls." Jonathan Schwartz, Sun's No. 2
executive, is telling software developers that Sun needs to retain control
of Java to maintain its compatibility with a variety of operating systems,
which is essential for allowing developers to write software that can run
without modification on any type of computer. Schwartz says Sun will soon
make an open source version of its own Solaris operating system to satisfy
those customers. McNealy's parting shot: "I think IBM is suffering from Java
envy."
(San Jose Mercury News 30 Jun 2004)
http://www.siliconvalley.com/mld/siliconvalley/9045498.htm
MICROSOFT PRODUCTS FOR AMATEUR DEVELOPERS
For the 18 million serious programmers around the world who not make
their living as software developers, Microsoft has begun offering
stripped-down versions of products that will help them do their work. The
database product being offered, Microsoft SQL Server Express Edition, will
be distributed free, and Microsoft watchers are guessing that Express
versions of Microsoft's developer tools will cost $50 or less (compared to
as much as $1,800 for the industrial-strength versions of those products
designed for professional developers). Senior vice president Eric Rudder
explains, "This is really about broadening the base. We're trying to make
the Microsoft commercial ecosystem bigger." (New York Times 29 Jun 2004)
http://www.nytimes.com/2004/06/29/technology/29data.html
STEGANOGRAPHY
The term "steganography" has come to mean the practice of hiding
messages within graphics or music files. Fabian Hansmann of the German
software maker Steganos explains: "Steganography has one big advantage --
that is you cannot prove that information exists. If you just use
encryption, you will always see that there is a file that carries encrypted
information." Hansmann characterizes his company's $60 security software
suite as a "paranoid option" for advanced users who have the time and
interest to hide their data. But Steganos products are under constant
scrutiny by law enforcement officials. Hansmann says, "We regularly have
inquiries from government agencies of all kinds, from foreign secret
services to local police departments in Germany." (Reuters/USA Today 30 Jun
2004)
http://www.usatoday.com/tech/news/2004-06-30-steganography_x.htm
INDIAN INSOURCING
"Outsourcing" may be a worrisome phenomenon to some Americans and
Europeans but to Indians it looks like insourcing -- and like a blessing
from above. In Bangalore software engineer Rohit Johri is rhapsodic about
outsourcing: "This place is a gold mine. It's good for India too. Unemployed
people get into trouble. They go into politics or crime... Shopping in India
used to be an ordeal. Something as simple as a wristwatch would take three
months. A scooter would take a year, a telephone two years. Those were
luxuries." Now, Tommy Hilfiger shirts in Bangalore's new Forum mall sell for
$50 -- which is more than a month's income for many rural Indians but
affordable to a programmer or even a call center employee. Rajit Johri's,
Rohit's 27-year-old younger brother, is delighted with his new job answering
phones all night at a Bangalore call center, and boasts: "It's a good job, a
good working environment. I'll make good money." (Los Angeles Times 30 Jun
2004) http://tinyurl.com/28dow
*****
FLASH CARD
"I never wonder to see men wicked, but I often wonder to see them not
ashamed." (Jonathan Swift)
MAILBAG: THE WORLD AS WE FIND IT
Following are some of the responses to yesterday's "Memo from Maelstrom: You
Be the Jury!" <http://tinyurl.com/3au8s>
THE SYSTEM ADMINISTRATORS SHOULD FEEL RELIEVED
I'm not overly familiar with US laws, but could the jury decide whether
the defendant should, or shouldn't, be charged under the Federal crime
statute, or could they only decide whether he was guilty or not of having
committed a crime? Because his having been indicted under that statute was
clearly wrong. The damage caused by his actions was only the $1,500 required
to correct what he did; the $80,000 of service charged by IBM were spent
correcting a system flaw for which he had no responsibility (the procedures
being considered a part of the system) and, indeed, that correction was
brought about because his actions showed the flaw. Notwithstanding the fact
that his actions were criminal and that he deserves being punished for them,
he cannot be held responsible for this additional expense and, in fact, the
system administrators should feel relieved that a relatively small amount of
damage showed the need to have such a big system rework. (Wilson Baptista
Junior, Brazil)
THE PROBLEM IS THE HEAVY-HANDED LEGISLATION
I infer a certain degree of frustration on the part of maelstrom,
particularly with the jury. But if the only question before the jury was
"Did he do it?" then the answer has to be yes. The key element that
maelstrom has left out of the story is that of the instructions to the jury.
I recently completed jury service. In our (civil) case, we had to decide
three questions: (a) whether one or both parties in the case were at fault,
(b) if both were at fault, what percentage of blame was each side
responsible for, and (c), if the defendant was responsible for at least 50%
of the incident, how much the defendant
should pay.
Sorry. I know it sucks to get caught, but it sounds like the jury made
the right call in coming to a guilty verdict. They don't get take into
account the sentence that may result from their verdict.
And turn the question around: Was it the defendant's intention, through
his very deliberate and obviously illegal actions, to do a only minimal
amount of damage (say, less than $5000)? (He might have succeeded, if only
villainous IBM hadn't gotten in the way!)
The source of the problem that maelstrom identifies really seems to be
in the (possibly) heavy-handed legislation that outlines the laws broken by
the defendant. On the other hand, sentencing hasn't yet been carried out,
eh?
Would be interesting to get an update on this and see how it comes out.
(Skipper Pickle)
HACKERS AREN'T SOCIAL HEROES
Of course the jury got to hear a lot more than what was in the brief
blurb. As I understand things, I would have voted as the jury did. He was
guilty and therefore a guilty verdict should be returned. Was it justice?
Someone who knowingly commits a crime must be open to reaping the
consequences of their actions. Yes this was justice. Harsher then might be
normally called for, but still justice.
I do not see hackers as social heroes. Quit the contrary, they give
programming a bad name. They seem to be self-centered egotists who feel
themselves above the law. (Scott Adams)
FASCINATED AND DISTRESSED
I'm fascinated and distressed by maelstrom's memo and especially by its
headline, "You Be the Jury!" I even looked up the meaning of "RSA card" to
be sure I understood the situation correctly.
Here's my blog post on the topic:
http://www.metaforix.info/2004/06/a_hackers_tale.html
(Lois Ambash)
FOLLOWING THE SYSTEM
Well, I guess you're asking for input on this one so here goes. I
would have to disagree with the jury on the matter maelstrom brought up
(assuming his synopsis is accurate). It is the prosecution's responsibility
to bring appropriate charges, and the jury's to decide on them. Since the
jury cannot decide to find the defendant guilty of a lesser charge, they
must decide only on the guilt or lack thereof of the charge brought. In this
case it sounds like the jury decided he was guilty of SOMETHING, so they
found him guilty of whatever it was the prosecution charged. (Nate Scherer)
HACKER IS LIKE A TIRE SLASHER
It is clear that the hacker was guilty. So the question facing the jury
is: Was this all a mistake because IBM overcharged the customer? I don't
think the average jury is capable of making an assessment as to whether IBM
overcharged. Given the "facts" as presented, the defense did not present a
viable defense of their contention that the actual damages were lower
(according to what you presented to us). As well, the hacker made his
damages without regard to the costs or contingent damages that he might have
created. The supervisor might have failed to perform during the period he
was denied access and produced further contingent damages. So I would have
voted against the hacker.
I consider this similar to a tire slasher. Suppose the slash failed to
make the tire flat. Then I drive the car and when the defective tire blows,
I cause all sorts of contingent damages. If it is a Firestone Tire, we know
what Ford did with the Explorer, when the tires were defective from
manufacture. The difference with a slasher is just a matter of degree (one
instance instead of many). So I think there is plenty of precedents for
assessing the full measure of contingent damages on the admitted (or deemed)
cause. (Keith Cowan)
A WASTE OF PUBLIC MONEY
No, it wasn't justice: it was injustice on the part of the prosecution,
abetted by the failure of humanity of the jury. The punishment should fit
the crime: if it doesn't, it is not justice but barbarism.
One of the reasons that juries are valuable is that they can refuse to
convict even if they know or believe the defendant is guilty. For example,
it's uncivilised and inhumane to enforce the death penalty for stealing a
loaf of bread, even if it is the law. Would the same jurors have done that?
If not, why not? Where do they draw the line? The jurors should have thrown
out the *federal* case on the grounds that the police and prosecution were
stupid to bring it: it was a waste of public money. Prosecutions will
continue to bring unreasonable cases if they can secure unreasonable
convictions, and that's bad for everybody -- including the jurors. (Jack
Schofield, UK)
CRACKER (NOT HACKER)
Cracker (not hacker) Maelstrom provides a text-book example of faulty
ethical and legal logic. If I were on the jury, I would, given the facts as
stated, voted "guilty." That is the only question before the jury. As for
mandatory minimum sentences -- I think our society has gone quite bonkers.
But that opinion does not, or should not, affect the judgement of guilt or
innocence.
There are two questions:
1. was the party guilty,
2. does the punishment fit the crime.
Unfortunately, in our paranoid society we have seen fit to create
punishments that sometimes far exceed the damage of the crime, (and
sometimes fall far short of the damage of the crime.) But that does not
change the first question -- the jury must decide, as honestly as possible,
whether the defendant is guilty or innocent of the crime.
Outsourcing is a fact of life. Losing a job is not a justification for
vandalism. If you want to change that situation, you should be working to
change the politico-corporate culture. Attacking supervisors doing their job
is not justified, even if you dislike their actions. Current legal theory
holds that a corporation's first obligation is not to its employees, not to
its customers, but to its stockholders. A corporation can get sued if the
stockholders think the net profit should have been greater.
Yet the crackers seem to believe that random acts of vandalism -- well,
I'll grant there may be some "directed" acts -- will result in a greater
good. Even if it should, once we abandon the principle that "the end does
not justify the means," we have joined the worst of our enemies in their den
of corruption.
So, I agree with several of Maelstrom's imputable opinions. The current
corporate structure is not optimally beneficial to society as a whole. The
recent mandatory sentence fad is horribly unjust. But abandoning the
principle against harmful means for good ends leads to total chaos as
violence replaces debate.
Guilty as charged, and he should be sentenced to 2 years at a prison
farm -- e.g., our local facility in Lompoc, CA. (Howard Matthews)
HOW (NOT TO) PICK A BATTLE
I read Maelstrom's piece with interest. As an aside, under UK law,
assuming that the former employee fulfilled a valid role, he would have been
transferred to IBM under the "Transfer of Undertakings: Protection of
Employment" (TUPE) laws.
Anyway, the story I saw was one of an aggrieved employee planning and
executing a crime. It's as simple as that. Of course, it was overblown by
IBM, who are trying to leverage their position with their client. And it was
overblown by the FBI, who are desperate to be seen as "doing something in
the lawless sphere that is the internet". But it does come down to the abuse
of privilege, the theft of company property, and the use of these to create
damage to a former employer, and all at a time when people with vested
interests are trying to undermine the ability of common sense to prevail.
So, a corporate crime committed in an exceptionally unfavourable
corporate and political time. Is it any wonder that the punishment was
severe? One presumes the former employee will have plenty of time to mull
over how in future to pick battles. (Giles Guthrie))
WHITE HATS, BLACK HATS
The answer is simple. The former employee committed a crime, the
company spent a large amount tracing the source, fixing the damage and
further securing their systems. This ex-employee should have known that what
he was doing was illegal (not to mention childish and unethical) and
therefore must face the penalties.
Is the crime he committed worthy of a 12-year sentence? Maybe not, but
the jury had two choices -- guilty or not-guilty. In this case they chose
guilty. Not being in possession of all the details of the case, I would have
to assume that the jury performed their role to the best of their ability
with the tools and evidence provided them. Is the jury responsible for
determining the length of incarceration? I think not. Typically that role is
left for the judge, who usually has specific (and sometimes rigid)
frameworks within he/she must operate.
This so-called security administrator not only broke several laws, but
also betrayed the trust that his former position entailed. He deserves the
full punishment available by law, as does any malicious hacker. What other,
more subtle damage might this ex-employee have caused that was not detected
and that he did not own up to? Why did he steal the RSA card and set up the
account in the first place? Obviously he was planning revenge, which makes
this a pre-meditated crime, and therefore worthy of a harsher penalty than a
opportunistic "crime of passion" committed in the heat of the moment.
Maelstrom shows once again his complete lack of understanding of the
ethics of hacking and security. I rarely read his missives as they are
usually full of the same misguided "all hackers are saints" rubbish. While
there are a number of "white hat" hackers who do hack ethically, there are a
number of "black hat" hackers who deliberately seek to cause mischief and
mayhem. The black hats should be pursued and punished to the fullest extent
as a deterrent to future hackers who may be tempted to turn to the dark
side. (Amos Bannister)
LET THE PUNISHMENT FIT THE CRIME
Since hacking first became a crime, the damage caused has always been
overestimated and overpriced. It is in the best interest of companies like
AT&T and IBM to inflate the cost to spur prosecution of people who reveal
how poor their security really is. It makes them look good in the
marketplace, while distracting the public from how small the hacker is by
comparison. IBM should blush, not only for their bullying tactics but for so
grossly over-charging a client.
Does this mean I support hackers? No. It means I support justice and
fair dealing. What happened in this case was neither. Had I been on the
jury, I would have argued for a mistrial, because I would have known, as an
IT professional, that we had not been given all the real facts in the
matter. The man was certainly guilty, but the penalty far outweighs the
crime.
Thanks for your fine publication‹my favorite articles are those that
make us (the audience) think and argue a point! (Sherilyn B. Dunn)
[We'll Maelstrom's reactions to these comments sometime before the end of
the week. -- J&S]
SUBSCRIPTION INFO FOR NEWSSCAN DAILY:
To subscribe or unsubscribe to the text, html, or handheld versions of
NewsScan Daily, send the appropriate subscribe or unsubscribe messages
(i.e., with the word 'subscribe' or 'unsubscribe' in the subject line) to
the addresses shown below:
Text version: Send message to [email protected]
HTML version: Send mail to [email protected]
NewsScan-To-Go: http://www.newsscan.com/handheld/current.html
TELL YOUR FRIENDS ABOUT NEWSSCAN DAILY! Send them our little frog:
http://www.newsscan.com/newsscan/newscup.html
***********************************************************
Please visit the site of RLG, the great organization that makes NewsScan
Daily possible. (RLG has no influence over, nor any responsibility for, our
editorial content.) Created in 1974 as the Research Libraries Group, RLG is
a not-for-profit membership corporation of more than 160 universities,
national libraries, archives, museums -- and other institutions with
remarkable collections for research and learning. Its major initiatives are
long-term retention of digital materials, resource sharing among member
institutions, and improvement of researcher access to primary source
material. RLG supplies online research resources worldwide. Visit RLG at
http://www.rlg.org.
*********
To subscribe or unsubscribe to the TEXT version of NewsScan Daily, send an
e-mail message to [email protected] with 'subscribe' or 'unsubscribe'
in the subject line. To subscribe or unsubscribe to the HTML version of
NewsScan Daily, send mail to [email protected], with the word
'subscribe' or 'unsubscribe' as the subject. (Subscribing to the HTML
version won't automatically unsubscribe you from the text version; please
unsubscribe yourself as explained above.) PLEASE NOTE: To unsubscribe from
an account to which you no longer have
access, send mail to at [email protected].
*********
We call our news section "Above The Fold" to honor the tradition of the
great "broadsheet" newspapers in which editors must decide which news
stories are of such importance that they should be placed "above the fold"
on the front page. The NewsScan Credo: Be informative, have fun, and get to
the point! See http://www.newsscan.com/, and send us mail: John Gehl
<[email protected]> and Suzanne Douglas <[email protected]>, or call
770-704-7517.
*********
Get a free 6-week trial subscription to Innovation Weekly, an executive
summary of trends, strategies and innovations in business and technology.
Send mail to [email protected] with the word 'subscribe' in the
subject line.
What customized news and information services do you need for your company?
Get in touch with us at [email protected] or call 770-704-7517 to talk
over the possibilities.
Copyright 2004. NewsScan Daily (R) is a publication of NewsScan Inc.
***********************************************************