Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home IT Management
    • IT Management

    Its Not Paranoia When Its the Truth

    Written by

    Peter Coffee
    Published September 17, 2003
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      When it comes to computer and network security, Im moving toward the doctrine adopted by Sangamon Taylor for nighttime bicycle safety. “I assume Im wearing fluorescent clothes, and theres a million-dollar bounty going to the first driver who manages to hit me. And I ride on that assumption,” says Neal Stephensons fictional toxic-waste vigilante in the 1988 novel, “Zodiac.”

      Taylors approach is beginning to seem like the only viable strategy for Internet self-defense. “I assume that everyone in a car is out to get me,” Taylor ruminates. “My nighttime attitude is, anyone can run you down and get away with it.” If your safety depends on anyone perceiving that youre in danger, and actually making any effort not to kill you, he concludes, “youve already blown it.” Bingo.

      Thats the network environment in which we live, where even the aggregate bandwidth consumed by millions of Windows Update users is beginning to look like a denial-of-service attack on the Internet as a whole. The cure is almost as bad as the disease.

      In fact, so hostile has the environment become that the anti-virus instructions page at MIT, in Cambridge, Mass., instructs all users of Institute facilities: “To prevent your machine from being compromised while you are applying the patch, Network Security encourages users to implement port filtering described at http://web.mit.edu/net-security/prevent-reinfection.html.” Based on eWEEK Labs experience during past worm episodes, Id call that good advice: Weve seen systems attacked multiple times during the period required to download the latest patches following an out-of-the-box installation.

      What really drove the point home was a little item I saw at The Inquirer, concerning the ease with which an attacker can reinstall a vulnerable version of an ActiveX control that might have been previously, conscientiously, removed from a machine. “If some evil mail or website tries to introduce it to your system youll get the standard popup, much like the one you get on Office Update,” observed writer Rick Reroy, continuing, “Click Yes, and your computer is ripe for a reinstallation. You can save that click if you on a previous occasion checked the box that says Always trust content from Microsoft Corporation (what were you thinking?)”

      Im thinking that the system not only comes out of the box unsafe, it almost appears designed to ensure that it stays that way.

      And if I may borrow Reroys question, Id like to know what Microsoft itself is thinking when it cant even give consistent warnings on its own Web pages concerning the latest RPC-borne worm. At one URL, the company warns its enterprise and developer customers that “Microsoft tested Windows Millennium Edition, Windows NT Workstation 4.0, Windows NT Server 4.0, Windows NT Server 4.0, Terminal Server Edition, Windows 2000, Windows XP and Windows Server 2003 to assess whether they are affected by this vulnerability. Previous versions are no longer supported, and may or may not be affected by these vulnerabilities.”

      That same page, however, offers a link to an “end user version” of this bulletin, where we learn that “Windows 98, Windows 98 Second Edition (SE), and Windows 95 also are not affected by this issue. However, these products are no longer supported.” Am I the only one who finds the second statement much more useful than the first, and wonders why enterprise buyers dont get the same story right up front?

      What Im also thinking is that its worth the effort to dismiss, many times an hour, the warnings that I get from Norton Internet Security about whats attempting to access my system, and how. Im thinking that its worth the effort to “stealth” all of my ports to minimize the chance that an attack even comes my way. Im thinking like a bicyclist on a dark night on Storrow Drive, winding along the Charles River between Boston and Cambridge, as the bars close and the drunks all head for home.

      At least, for the most part, the drunks actually had to pass a driving test: Too many Internet users lack even that level of preparation.

      So you might as well behave as if theyre all out to get you on purpose. Accident or malice, it doesnt much matter when the bumper hits you in the back.

      Tell me how you stay alive out there.

      Peter Coffee
      Peter Coffee
      Peter Coffee is Director of Platform Research at salesforce.com, where he serves as a liaison with the developer community to define the opportunity and clarify developers' technical requirements on the company's evolving Apex Platform. Peter previously spent 18 years with eWEEK (formerly PC Week), the national news magazine of enterprise technology practice, where he reviewed software development tools and methods and wrote regular columns on emerging technologies and professional community issues.Before he began writing full-time in 1989, Peter spent eleven years in technical and management positions at Exxon and The Aerospace Corporation, including management of the latter company's first desktop computing planning team and applied research in applications of artificial intelligence techniques. He holds an engineering degree from MIT and an MBA from Pepperdine University, he has held teaching appointments in computer science, business analytics and information systems management at Pepperdine, UCLA, and Chapman College.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.