Iain Thomson
Iain Thomson

The power and weakness of money

Microsoft's invitation to grass on a virus writer will catch the script kiddies, but not the real bad guys

Written by Iain Thomson

The news that Microsoft is putting a bounty on the heads of virus writers using less than 0.0002 per cent of last year's revenues has won it some good headlines.

Of course, it may also come in useful when Microsoft defends the forthcoming class action lawsuit from those seeking damages for the mess left by virus exploits of security weaknesses in Redmond's code.

I don't doubt that the offer will bring in new information, and may even lead to some arrests, but they won't be the ones Microsoft wants.

Creating a basic virus from scratch is as easy as building a paper aeroplane: you only need a few lines of code and a modicum of programming knowledge.

Creating a virus that can spread in the modern computing environment and flummox antivirus experts is a lot harder; now we're talking about building a microlight.

But original viruses are rare. The majority are mutations where someone has taken the original code, modified it slightly to defeat antivirus signatures using one of several easily available toolkits, and then sent it on its way.

Essentially they jump on the bandwagon of someone else's idea and try and bask in the reflected glory. Such folk are known in the trade as script kiddies and it's these that the reward scheme will catch.

Speak to most professionals and they'll tell you that a lot of script kiddies make lousy criminals.

Most can't resist putting in clues about themselves, either their moniker, a rant against someone or some other clue as basic as including details of their home page.

Sometimes they brag to friends online and off about what they've done. When caught they usually capitulate immediately and spill their guts about accomplices and techniques.

Now, these mutated viruses cause a lot of grief and need to be stopped. Some people are going to get a nice reward for turning their authors in, after the lengthy legal cases have been solved.

But the offer will also bring piles of false leads from the greedy, the credulous and the vindictive. Law enforcement officials might waste more time than they save in the process.

The virus originators aren't going to be worried by the bounty system. This small band of highly technical misanthropes generally don't talk about what they do.

We still haven't caught most of the originators of the really big and well-designed viruses and probably never will.

Tags:

reader comments

related articles

Security

Security

The latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack. 15 Apr 2004

 

Sober judgement for virus writers

Multi-lingual W32/Sober-A worm causes most problems in November 02 Dec 2003

Virus writers have a price on their head

Microsoft's new approach to security: $5m reward for cyber bounty hunters 06 Nov 2003

Windows security 'will take time'

Improvements to operating system won't happen overnight, warns Gates 06 Nov 2003

related whitepapers

today's top stories

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation