Home Uncategorized Beware of the Web site virus hysteria

Beware of the Web site virus hysteria

Name: Rob Rosenberger
Age: 38
Position: Editor of Vmyths.com
Background: Worked as a computer-security analyst for the U.S. Air Force
and a Fortune 1000 company.
Family: Married
Residence: Iowa City, Iowa

PBN: Tell me about your Web site, Vmyths.com.
ROSENBERGER:
We give the truth about computer viruses, the myths and the hoaxes.
We also cover the hysteria that surrounds viruses. For example, people who’ve
dealt with the “Kournikova” virus recently — lots of hysteria, little impact.
A lot of viruses, even those ones that you hear about, create a lot of hysteria
but have little impact. Believe it or not, the “Melissa” virus in 1999 — there
are so many myths about that virus it just stuns us. Or the “I Love You” virus
— many urban legends created about that. And we try to dispel those. We offer
a place where people can go very quickly to learn about the computer virus hoaxes
that are out there, so when they receive an e-mail, they can dismiss it. They
can say, “That’s a hoax.”

Was the media guilty of hyping the Melissa and I Love You viruses, or was there a real threat?
Melissa was not a real threat. It was the first of the very fast spreaders,
which we knew was coming. Melissa was easy to stop. I Love You was even easier
to stop. And we didn’t stop them until after the fact. I blame a number of factors
for that. But Melissa wasn’t a threat because it was just a small word document
that was passing itself along. I Love You was actually trying to delete some files
or overwrite some files.

Do you really think software companies use scare tactics to get consumers to buy antivirus software?
Yes, and the reason I say that is antivirus vendors want free publicity. Everybody
wants free publicity. But the vendors have been hooked on free publicity for a
number of years because it’s easy to generate. All I have to do is go out and
scream “Oh my gosh, here’s the next virus!” And like magic everybody’s reporting
me and I get fantastic Web site response.

This happens when the vendors put out a virus alert?
Thinly disguised press releases are what they put out.

So who do you think is more to blame for creating hysteria around virus stories, the media or the software companies?
Well, I think there are four components to the hysteria. I see a square, and
the four corners of hysteria are the reporters up in one corner who have the free
ink, which translates into free advertising. And they need to generate stories,
and they have a fetish for juicy virus stories. In another corner you have the
bad guys, those virus writers who are suffering from narcissistic personality
disorder and they’re looking for free ink to assuage their egos. In another corner
you’ve got the antivirus vendors, who want free advertising. They present themselves
as the good guys. And then in the last corner you have the government, which presents
itself as the authority. They validate the threat. “Woe are we if a virus ever
were to get loose. People would stop getting their social security checks.” The
government comes up with the cost-benefit of using antivirus software — and there
is a cost-benefit. So you have these four corners of hysteria, and they combine
to create the virus hysteria that we see today. And they’ve always been creating
that.

Do you think there’s a fine line between denouncing computer-virus hysteria and leaving people to feel like they have nothing to worry about?
Yes, and I think that sometimes (Vmyths.com) has crossed that line without
realizing it. And that’s why Vmyths.com has a pseudo columnist called Vea Culpa,
which is actually me, and Vea Culpa will correct things for the record. I don’t
ever want people to think that viruses are a non-threat. They are a nuisance,
they waste our time, and they can delete valuable files. But I say if viruses
are a big threat, then why aren’t we worried about viruses at the institutional
level like we are about other things? We worry about earthquakes in California
to the point where earthquake-resistant buildings are the norm. Why aren’t we
worrying about the virus problem at the corporate level? Where is the concern?
We have small teams at large companies, but they’re treating viruses as a nuisance,
not as a major threat. It’s just, from time to time we get these viruses and we
deal with them.

What is the cost of hoaxes to businesses?
Time is money. Resources cost money. A hoax and the hysteria it causes can
convince people to leave the Internet for short periods of time. For example,
the (Small Business Administration) is an example I like to use. The SBA Web site
went down over the 1999-2000 holiday because they were afraid that viruses might
swamp their site. That kind of hysteria wastes time. It wastes my time. It wastes
the SBA’s time. Then when people send out these e-mail alerts to everybody, we’re
talking about wasting let’s say 1 minute of every employee’s time. If you send
out a virus-related e-mail to 1,000 employees, you’ve wasted 1,000 minutes of
time. Fifty people hit the “reply-to-all” button and there goes 50,000 more minutes.
You can start adding it all up — I don’t know what the costs are quantitatively.
But this is such a big problem for big companies. Microsoft has told me that roughly
50 percent of e-mails they receive from their own people are asking about virus
threats that turn out to be hoaxes. They’re dealing with hoaxes at Microsoft that
badly. And that’s one of the reasons why Microsoft is such a big fan of Vmyths.com,
because they can send people to us and Microsoft can get back to the business
of writing software.

What can computer users do to protect themselves from hoaxes?
It’s very easy. There are three things: Number one, ask: Who did the hoax come
from? If it came from your dentist or your podiatrist or your mother-in-law, those
aren’t people that you want to be telling you about computer-security threats.
I might as well ask my mother-in-law what to do in a tornado — I’d rather go
talk to somebody who knows how to deal with tornado threats. Number two: Is it a chain
letter? Does it urge you to forward it on? This is a big one because people think,
“Oh, I have to return safety to the Internet. I can help the world by forwarding
this on.” No, no, no. Computer virus experts do not need a chaotic e-mail distribution
scheme. We’ve got ways of notifying you. And number three: Does it tell you all about
the threat, or does it give you a short summary of the threat and then tell you
to go to an authoritative Web site to get more information? That’s what it really
should do, is say, “Hey, there’s a new threat, click on this link for more information.”
Those are the three keys that should quickly tell you whether or not it’s a hoax.

What should companies tell their employees to do when they see or here about a potential virus?
Well, companies should tell their employees to forward it to somebody at the
company, some central authority who can deal with it. Many of the large companies
have their own computer-security teams. Smaller companies have a computer-security
expert. Even the smallest companies should have a network administrator or an
email administrator. Forward it to them and let them do the work. If they think
it’s a threat, they’ll issue an alert to everyone in the company. Those guys in
computer-security really do know whether or not it’s a threat — that’s their job.

How should companies go about investing in antivirus software? Is it wrong for companies to feel like they need to constantly be upgrading their software?
That’s a simple question with a complex answer. Companies too often see antivirus
updating as the only solution, but there are many other different capabilities
out there besides updating. You should have software that can detect viruses by
signatures, that is, by looking at a file and saying “Ah, that has a virus.” But
there are also programs that can look for viruses based on profiles. I like to
use the airport analogy. If today’s airport security worked like today’s antivirus
security, terrorists would rule the sky. We’ve become addicted to antivirus updates.
We used to update quarterly and then monthly, weekly, daily and it’s only a matter
of time before we have these persistent updates. And that’s not right. There are
other ways to avoid viruses: By checking for viruses by profile instead of signature.
By outsourcing your virus protection at the gateway.

But the majority of firms today see reactionary antivirus technology as the only solution. There are many reactionary products out there that people buy, but there are also many proactive products that people don’t buy – like Central Command’s AVX software — that can detect viruses based on their profile. There are so many different ways of installing antivirus software, rather than just dropping it on every desktop. But large companies don’t want to change the way they do their antivirus business. Other people just get their reactionary antivirus software when they buy their PC. I guess I need to bash the guy who’s buying the antivirus software as much as I do the antivirus companies.

You’ve said in the past that there’s technology available that is capable of
detecting any virus — a “silver bullet” solution.
Yes, I’ve said that — and I’ve been railed by the antivirus industry for that.
The antivirus industry will tell you that the technology is beyond the state-of-the-art.
No it’s not. I’ve got a number of products that do the job. And they’ll tell you
that nobody’s buying these products. Well that’s where they’re right. The people
that pad their pocketbooks — the business clients — aren’t asking for this stuff.
The antivirus vendors have products on the drawing board — or in some cases they
have actual products — that if and when the user ever decides, “Huh, antivirus
technology really sucks,” that’s when we’re automatically going to get new technology
from the antivirus industry. That’s when they’re going to give us what we want.
The beauty of it right now — and I agree with the vendors — is “Hey, the user
is addicted to our antivirus software and they will throw money at us hand over
fist. Why should we change the status quo?” That’s where I say, you’re absolutely
right. Now my job is to go out and tell the user that.

NO COMMENTS

Exit mobile version