Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Interviews: We Have 2! 1st, L0pht Heavy Industries

Posted by Roblimo on Mon Dec 27, 1999 12:00 PM
from the direct-from-the-mainstream-media-spotlight dept.
Yes, it's "year-end double-bonus interview week" on Slashdot. First, L0pht Heavy Industries. Yes, the world's most publicized infosec group, the one trotted out by TV and other mainstream media reporters whenever they want pithy (but authoritative) quotes about hacking and cracking and that sort of thing. The L0pht guys have heard all the (ho-hum) obvious questions already. They expect extra-smart ones from you, and we don't doubt for a second that you'll provide them. ;-) One question per post, please.
This discussion has been archived. No new comments can be posted.
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1) | 2 | 3
  • by papo (57964) <jpapo AT hotmail DOT com> on Monday December 27 1999, @07:04AM (#1442149) Homepage
    You said in an interview that it's possible to shut down all the Internet. How you possibly might do that? With a DoS attack in some routers or by taking command of some servers in the principal backbones of the USA?
  • Y2k Hacking (Score:3)

    by merky1 (83978) on Monday December 27 1999, @07:04AM (#1442150) Journal
    Do you agree with the President's plea to cease hacking activities for Y2K, and do you think it will have an adverse affect?

    "Those [filthy|pagan|heathen|whiny] americans, I'll show them....."
  • Re:Shutting down the Internet by merky1 (Score:1) Monday December 27 1999, @07:07AM
  • Job offers by eyeball (Score:1) Monday December 27 1999, @07:07AM
  • by Gleef (86) on Monday December 27 1999, @07:09AM (#1442153) Homepage
    Which do you consider more dangerous to personal liberties on the Internet, national governments or multinational corporations, and why?

    ----
  • Um by Synn (Score:1) Monday December 27 1999, @07:10AM
  • Just out of curiosity... by Ater (Score:1) Monday December 27 1999, @07:10AM
  • by rise (101383) on Monday December 27 1999, @07:12AM (#1442157) Homepage
    The L0pht has been involved in independent wireless networking reasonably heavily. What do you see as the most important discoveries/protocols/designs for the next few years? Do you forsee an opportunity for the hardware hacking community to open up the airwaves in the same way Linux & OSS has opened up operating systems and tools?
  • L0phtCrack by OnyxRaven (Score:2) Monday December 27 1999, @07:13AM
  • by jake_the_blue_spruce (64738) on Monday December 27 1999, @07:13AM (#1442160) Homepage Journal
    Moore's law is that computing power doubles every eighteen months. At the same time, parallel processing and distributed computation ( Cosm [mitrhal.net] & Distributed.net [distributed.net]) are becoming increasingly common. This leads to an abundance of cheap computing power, enabling brute force attacks on secure systems. In light of these developments, do you see username/password pairs being replaced by anything more resistant to such brute computing force?
  • Pronounciation by RAruler (Score:2) Monday December 27 1999, @07:14AM
  • Re:Distributed Computing by jake_the_blue_spruce (Score:1) Monday December 27 1999, @07:15AM
  • Future Products by MoOsEb0y (Score:1) Monday December 27 1999, @07:15AM
  • by jd (1658) <[imipak] [at] [yahoo.com]> on Monday December 27 1999, @07:16AM (#1442164) Homepage Journal
    That one's easy. Very few routers have authoritive checks set up. Simply fire up a router such as gated and have it inject false routes into the net. Have the backbone located at the South Pole, for instance.

    The UK network's been crashed dozens of times, by this. Usually by poor network administration, or faulty software, but that's just details. What an admin can do through ignorance, I'm sure crackers could do by design.

  • advisories by krog (Score:1) Monday December 27 1999, @07:16AM
  • Coagulation by Raffy (Score:1) Monday December 27 1999, @07:19AM
  • Re:Um by GeorgeH (Score:1) Monday December 27 1999, @07:19AM
  • The halcyon days of the net are gone. With ubiquity - the underground vanishes. Is it well on its way, with people like the CEO of Amazon being worshipped by the mainstream press, to becoming an enormous cyber strip mall, marketing tool, PR exercise in control of perception...

    Or is there still an underground? Does it still have a potential to be the one true medium with liberation? Will governments and coroporations end up controlling it? Cause they are winning small, important victories relentlessly...

  • ,,, by Signail11 (Score:2) Monday December 27 1999, @07:20AM
  • IPSEC key debate by Ruzty (Score:1) Monday December 27 1999, @07:21AM
  • Re:Um by bbk (Score:2) Monday December 27 1999, @07:22AM
  • by jd (1658) <[imipak] [at] [yahoo.com]> on Monday December 27 1999, @07:22AM (#1442173) Homepage Journal
    The Internet is fragmenting (eg: IPv4 vs. IPv6, Internet 2) and those parts that do have any awareness of security are now beginning to take it seriously (eg: IPSec, SSH). Many other parts are brain-dead, insecure and incoherent.

    How do you see things evolving, from this unholy mess?

  • by NateTG (93930) on Monday December 27 1999, @07:23AM (#1442174)
    What are the non-computer hobbies of the l0pht crew?

    I suppose that this is a sort of "celebrety interview" question, but I'm curious.
  • Name Dropping Asswipes by Anonymous Coward (Score:2) Monday December 27 1999, @07:24AM
  • Re:Um by BradyB (Score:2) Monday December 27 1999, @07:24AM
  • Human interest stuff by Errant Knyght (Score:1) Monday December 27 1999, @07:27AM
  • by FuriousJester (7941) on Monday December 27 1999, @07:29AM (#1442179) Homepage
    I read something to the gist of this recently:

    "The difficulty with computer security is that programmers write code to allow a course of action, not to prevent another. In order
    for computer security to become a reality, the design methodology must be changed."

    Any programmer worth their check does program defensively. Certain languages support the writing of "safe code" more easily than others. It requires less fore-thought to program defensively in Java than it does in C. The results, however, will not be as fine tuned.
    Any methodology for designing and producing safe code must take this, the experience of those implementing it, the environments the product could be used int, into account. L0pht has compromised many designs. Have you seen any design/impl (hardware or software) methodologies that yield more secure results than others? Could you give reference to them?

    In my experience, it has always been a matter of refinement. Security is relative.
  • Windows API (Score:3)

    by IRNI (5906) <`ten.inri' `ta' `inri'> on Monday December 27 1999, @07:31AM (#1442180) Homepage
    If the windows API was opened because of the DOJ trial, what would you do?

    A) Exploit every weakness from here to kingdom come, thereby propelling linux to the forefront.

    B) fix everything and tell microsoft so they can make the changes show up in a new release

    C) Do A) and grin real big and giggle lots

    D) Other | Please Specify ___________________
  • Question: by sboss (Score:1) Monday December 27 1999, @07:31AM
  • Re:advisories by barleyguy (Score:1) Monday December 27 1999, @07:32AM
  • Regret / Useful Software / Orwellian CPUs by MattW (Score:2) Monday December 27 1999, @07:34AM
  • What does L0pht mean? Maybe an answer by BradyB (Score:1) Monday December 27 1999, @07:35AM
  • evolution of the network by kootch (Score:1) Monday December 27 1999, @07:35AM
  • by Anonymous Coward on Monday December 27 1999, @07:35AM (#1442186)
    I was digging around the l0pht web site one day and read up on the wireless project you guys were doing trying to make use some old UHF equipment and seeing how far you could spread a free wireless network. So what's the current status of that project?
  • Re:I got one by barleyguy (Score:1) Monday December 27 1999, @07:36AM
  • Question by Necroleptic (Score:1) Monday December 27 1999, @07:39AM
  • Security Lint (Score:3)

    by Omniscient Ferret (4208) on Monday December 27 1999, @07:39AM (#1442189)
    For assurance, before installing software on a secure-as-plausible machine, I would love to have an automated for security problems, such as buffer overflows. So, how is the development of SLINT [l0pht.com] progressing? Are you still planning to release it?
  • Welcome, our door is open by lildogie (Score:2) Monday December 27 1999, @07:40AM
  • Internet Worm II (Score:4)

    by tilly (7530) on Monday December 27 1999, @07:43AM (#1442191)
    Several months ago I began predicting that someday someone would find a buffer overflow in the various Windows TCP-IP stacks and use it to write a worm that would bring down the Microsoft part of the Internet and cause so much traffic as to effectively shut down everything else. I further predict that until an event of this magnitude happens, the general public will not really learn the basic lessons about security that the *nix world was forced to learn from the first worm.

    What are your thoughts on this prediction? (Timeline, reasonableness, etc.)

    Regards,
    Ben
  • Proper NT rootkit. (Score:3)

    by Zurk (37028) on Monday December 27 1999, @07:51AM (#1442193) Journal
    Hi guys,
    Any plans to write a proper Win2K/NT rootkit (the kind that was published on Phrack a while back - that replaces or adds to the actual calls in the win32 ring 0 system with its own) soon ?
  • Simple question by Ricochet (Score:1) Monday December 27 1999, @07:54AM
  • Security? by Raffy (Score:1) Monday December 27 1999, @07:55AM
  • Slint by Emphyrio (Score:2) Monday December 27 1999, @07:58AM
  • Questions by Anonymous Coward (Score:1) Monday December 27 1999, @08:00AM
  • Re: Security Lint by Omniscient Ferret (Score:1) Monday December 27 1999, @08:01AM
  • Differences in interest by BlueCalx- (Score:1) Monday December 27 1999, @08:11AM
  • A Question of Principle by sudog (Score:2) Monday December 27 1999, @08:12AM
  • Capabilities in Linux by Nemesys (Score:1) Monday December 27 1999, @08:13AM
  • by An0nymousC0ward (110267) on Monday December 27 1999, @08:14AM (#1442206) Homepage
    This letter was recently published in the columbus dispatch [dispatch.com] (Ohio's greatest home newspaper....yea right). What would your response be to this person?

    Letter to the editor: Opening windows could let bad guys do a lot of damage Saturday, December 25, 1999

    I was amazed to see that the Clinton administration, in its initial victory over Microsoft, wants the source code to Windows to be made public. I'm sure it will follow up with a demand that all banks publish the combinations to their safes and freely distribute keys to both their front and back doors. Perhaps they will make banks install a large button so visitors can disable all alarms.

    Making the world safe for bank robbers would be a lot better than making Windows' source code public. The year 2000 problem is nothing compared to what a hacker could do with the code to Windows.

    The anti-virus software today depends on two primary tests to find a virus: the Cyclic Redundancy Checksum and file size. A virus attaches itself to a program and runs when the program runs.

    Rather than get into a complex technical discussion, let us just say every computer file has a fingerprint. If a virus is attached, the file's fingerprint changes. An anti-virus program just looks for the fingerprints left by the virus. However, if one has the source code to Windows, a file with a virus can be made with the same fingerprint as a file without the virus.

    Even worse, the operating system, instead of being the virus cop, becomes the virus enabler. Imagine a world where half the people in uniform are trying to rob you and where dialing 911 brings a band of serial killers to your door.

    Such a virus would be very, very difficult to fight. Police try to catch such people by tracing who benefits. But when the goal is revenge and not profit, it gets tough to catch the bad guys. If you think catching the Unabomber was time consuming, this would make the search for the Unabomber look very fast, indeed.

    So with the Windows source code, the hacker could write a program that on June 1, 2001, swaps all bank balances. Someone whose name starts with an A gets Z's balances. Throw credit cards into that mix, and there could be real fun. Maybe some hacker would find it fun to pay off everyone's property taxes. I'll bet everyone who had not paid his tax would tell the truth and pay up voluntarily, wouldn't they?

    Every programmer I have ever met has always left himself a back door into every system he writes. Does anyone want to bet Microsoft does not have a back door to its software? Does anyone believe that if the judge makes Microsoft publish the source code, Bill Gates would remove the back door before publishing it? He would not dare. The judge might put him in jail for modifying the code. Couldn't have that now, could we?

    If he would leave it in, every highly skilled programmer would have a key to everything running on Microsoft software. We can rest assured that every hacker is totally honest, can't we? And with the Internet, those hackers would all be in places where Americans are loved, such as Belgrade, Yugoslavia, and Baghdad, Iraq, for example.

    Some hacker might even have fun with a newspaper, such as removing the names of everyone who is a subscriber and replacing them with the names of people who are not. Did I mention court records, employment records, child support records?

    All Microsoft bashers in and out of government should beware. It looks like they are going to get what they wished for.

    Ray Malone

    MBS Software

    Chillicothe, Ohio

  • L0phtcrack Registration by kamelkev (Score:1) Monday December 27 1999, @08:17AM
  • L0phtcrack Registration by kamelkev (Score:2) Monday December 27 1999, @08:18AM
  • Question: Opinion on non-full-disclosure companies by minga (Score:1) Monday December 27 1999, @08:18AM
  • Re:L0phtcrack Registration by kamelkev (Score:1) Monday December 27 1999, @08:20AM
  • What responsibilities come with publicity? by ebohman (Score:1) Monday December 27 1999, @08:21AM
  • Future of Security by lostproc (Score:2) Monday December 27 1999, @08:21AM
  • largest barrier to secure computing/communications by Mike Miller (Score:1) Monday December 27 1999, @08:24AM
  • What's good out there? by Animats (Score:1) Monday December 27 1999, @08:25AM
  • Guerrilla Network by kerouac (Score:2) Monday December 27 1999, @08:25AM
  • Bipolarity by Keck (Score:1) Monday December 27 1999, @08:27AM
  • Other groups you might work with? by God I hate mornings (Score:1) Monday December 27 1999, @08:29AM
  • guerilla net lasers by vapor.516 (Score:2) Monday December 27 1999, @08:30AM
  • Actually it's http://www.freedom.net by LiNT_ (Score:1) Monday December 27 1999, @08:35AM
  • ISP's by tech81 (Score:1) Monday December 27 1999, @08:35AM
  • mac os as a web server by paulschreiber (Score:1) Monday December 27 1999, @08:37AM
  • Re:A Question of Principle by God I hate mornings (Score:1) Monday December 27 1999, @08:37AM
  • Trouble by jormurgandr (Score:1) Monday December 27 1999, @08:38AM
  • First, I should probally preface this by saying that while I don't consider myself to be a hacker, I have been a geek for several years, and love playing with technology, so I feel I am able to relate to the hacking community.

    Anyway, my question is, how do you deal with the way the public (including the media) percieves "hackers"? I've seen some clueless people use the term to describe *anyone* who does anything with a computer that they find objectionable. I've even heard the term applied to spammers!

    Needless to say, the misue of the term makes my blood boil, because I feel a certain respect towards the real hackers, such as yourselves, because you guys do know what you're doing, unlike all of the script kiddies out that that either have the term applied by clueless reporters, or they use it on themselve.

    So, I'd be interested in knowing how you cope with this sort of problem, as I've noticed this sort of perception of the hacking communtiy for some time.

    Thanks!

  • "FAMOUS, adj. Conspicuously miserable." -BIERCE by spazimodo (Score:1) Monday December 27 1999, @08:40AM
  • by sethg (15187) on Monday December 27 1999, @08:42AM (#1442229) Homepage
    What do you think of capability-based systems, such as EROS [eros-os.org]? The folks who are working on these systems say they are fundamentally more secure (against both malicious code and heisenbugs) than Unix derivatives, Windows NT, and other ACL-based operating systems. Do you agree with this assessment? Do these systems have security weaknesses that Unix-like systems don't have?
    --
    "But, Mulder, the new millennium doesn't begin until January 2001."
  • Linux, the next Windows? by Null_Packet (Score:1) Monday December 27 1999, @08:42AM
  • Hm. by !ramirez (Score:1) Monday December 27 1999, @08:43AM
  • Adding to the hype by NME (Score:1) Monday December 27 1999, @08:48AM
  • Microsoft Source Code? by WH (Score:1) Monday December 27 1999, @08:50AM
  • by Effugas (2378) on Monday December 27 1999, @08:51AM (#1442235) Homepage
    L0pht Crew:

    Would you agree that security and stability are but different sides of the same coin? In other words, a security exploit is truly nothing more than a expertly controlled failure?

    If so, how much stock can we put into the "metadesign" of limiting the damage an exploit can create by attacking the ability of a failure to be controlled? Should operating systems incorporate such "unpredictability engines" when being run in a production, non-debugging manner? Or is such a design not worth pursing, for various reasons?

    Yours Truly,

    Dan Kaminsky
    DoxPara Research
    http://www.doxpara.com

    P.S. First poster to make a crack about modulating the shield harmonics is gonna get a pie in the face ;-)

  • by Tackhead (54550) on Monday December 27 1999, @08:58AM (#1442237)
    Two questions (Well, three, really, but I'm a hardware geek, and I love trying to squeeze three things in the space of two):

    1) Wireless.

    Lots of folks have been asking today about the wireless network project. "Me too"; the page has been up for years, it's a fascinating and extremely powerful idea, but for those of us who aren't RF engineers...

    • when do we get to see some hardware projects to build, or is it the case that - due to regulatory restrictions on what can and cannot be transmitted on US airwaves - work is being done independently on the notion of a secure wireless IP-based network but isn't being released so that those of us who aren't RF engineers can't gum up the works by screwing things up before it's ready :-)

    2) The future of hardware hacking.

    With the trend towards more and more functionality becoming embedded into ASICs and single-chip solutions, the golden age of "just desolder this", or "reverse-engineer the schematics and jumper that", or "replace a [PROM|EPROM|EEPROM|PIC|FPGA] with one with the following special programming, and here's the [CPU|microcontroller]'s instruction set and a memory map of the embedded system" appears to be drawing to a close. Anyone can desolder a 24-pin DIP EPROM and hack it, but trying to desolder a 100-pin PQFP is a real bear without $500+ worth of specialized equipment, and knowing what to do with the chip after you've desoldered it is well-nigh impossible.

    • Do you see a time when "hardware hacking" (as we've traditionally known it) will have to fall by the wayside? If so - what, if anything, do you see as taking its place? (Perhaps users taking advantage of the vastly more-powerful gear out there today and building their own hackable hardware, eliminating the need to hack other people's hardware?)

    I suppose that's tangentially related to the wireless.net question - for mass distribution of the tools needed to build such a network, for instance, it seems to me that re-purposing cheap, widely-available stuff that others have junked is a better path than having to build things from scratch. But if the cheap, widely-available stuff of the future isn't gonna be re-usable... where does one go from there?

    3) The future of l0pht.

    (At least publicly), there's been a lot more activity on the software side of l0pht than on the hardware side.

    • To the extent that you can discuss it openly, do you see l0pht's main activities over the next 3-5 years as continuing to revolve around the "expose weaknesses in software" side or the "work on next-generation hardare projects" side?

    Meanwhile, thanks for much great work on both the hardware and software sides of the equation, and best wishes for your continued good work. A couple of years ago, some of your tools saved an ex-employer's butt, and the look on my pointy-haired boss' face when I showed him where I got the tools that saved him was something I'll never forget. Y'all rule, and convincing a PHB of it takes work above and beyond the call of duty :-)

  • The image of the Hacking Community. by dentar (Score:1) Monday December 27 1999, @09:07AM
  • Wireless WAN project a rip-off by WH (Score:1) Monday December 27 1999, @09:08AM
  • When the time comes to protect America by Anonymous Coward (Score:1) Monday December 27 1999, @09:12AM
  • by Erbo (384) <erbo AT electricminds DOT org> on Monday December 27 1999, @09:15AM (#1442242) Homepage
    In your view, which of the following corporations is most dangerous to the future freedom of the Internet as we know it, and why?
    • Microsoft
    • America Online
    • Amazon.com

    Eric
    --
    "Free your code...and the rest will follow."

  • Re:What's good out there? by Bald Wookie (Score:1) Monday December 27 1999, @09:21AM
  • Security Through Arbitrarity: libnc? by Effugas (Score:2) Monday December 27 1999, @09:21AM
  • Re:L0phtcrack Registration by kamelkev (Score:1) Monday December 27 1999, @09:22AM
  • Boston 2600 by Ex Machina (Score:2) Monday December 27 1999, @09:23AM
  • Didya know? by Sorklin (Score:2) Monday December 27 1999, @09:24AM
  • Re:Job offers by eyeball (Score:1) Monday December 27 1999, @09:28AM
  • The real life of a security specialist by morpheus_ (Score:1) Monday December 27 1999, @09:29AM
  • NT v. Linux by Sorklin (Score:2) Monday December 27 1999, @09:30AM
  • Re:netcat by Effugas (Score:2) Monday December 27 1999, @09:31AM
  • by dodobh (65811) on Monday December 27 1999, @09:34AM (#1442257) Homepage
    Norton Antivirus has a security hole. Details at msnbc [msnbc.com] . What do you think about such cases? Should the software liscensors be sued (since they are refusing to fix the hole)?
  • Re:netcat by jnazario (Score:1) Monday December 27 1999, @09:36AM
  • Re:Who's more dangerous? by GeorgeH (Score:1) Monday December 27 1999, @09:43AM
  • Re:netcat by Effugas (Score:2) Monday December 27 1999, @09:45AM
  • The networked home by _endgame (Score:1) Monday December 27 1999, @09:53AM
  • by Anonymous Coward on Monday December 27 1999, @09:53AM (#1442265)
    Since you guys rate much higher on the crypto-phreakometer than I do, I was wondering if you had any insight into the security of current crypto technology.

    Specifically, do you think that advances in computer horsepower has weakened the security of the current generation of crypto, as it relates to finding BIG prime numbers for the purpose of factoring.
  • Groups today by N-Sanity (Score:1) Monday December 27 1999, @09:55AM
  • Is media attn. a fad, can hacking be incorporated? by Paolo (Score:2) Monday December 27 1999, @10:02AM
  • Formal proofs of security? by Xenophon Fenderson, (Score:1) Monday December 27 1999, @10:07AM
  • by Bacteriophage (78483) on Monday December 27 1999, @10:12AM (#1442269)
    Seriously, I would like to know. When you sometimes don't have all the answers (I assume that would be more than never), where do you guys go on the 'Net to find what you need concerning computer security, **/*acking, or even just news? Do you ever come to /.? This answer shouldn't take very long, and it'd be nice to get the seperate preferences of each crew member, as well as the general preferences of the group.

    "There are no shortcuts to any place worth going."

  • Re:Coagulation by Synic (Score:1) Monday December 27 1999, @10:13AM
  • The future of IT workers: domination? by Jogar the Barbarian (Score:2) Monday December 27 1999, @10:18AM
  • Re:Security? by Chandon Seldon (Score:2) Monday December 27 1999, @10:23AM
  • Re:Reply to this letter. by Anonymous Coward (Score:1) Monday December 27 1999, @10:29AM
  • by Legion303 (97901) on Monday December 27 1999, @10:32AM (#1442275) Homepage
    Here's my "letter to the editor" to the Columbus Dispatch:

    I was disappointed with Ray Malone's 12/25 letter to the editor. Speaking as a hacker and security enthusiast of 17 years, allow me to educate Mr. Malone on hacking and open source.

    First of all, viruses have nothing at all to do with hacking. Virus writers are not hackers in any sense of the word, they're merely vandals. But semantics aside, virus scanners that look for virus "fingerprints" can't be fooled by making the virus appear to be something else. The virus' fingerprint still exists in the code. At any rate, Mr. Malone is discussing individual programs here and not the operating system, which is the part that would be open source.

    Mr. Malone goes on to say, "So with the Windows source code, the hacker could write a program that on June 1, 2001, swaps all bank balances." Yes, if the hacker had a database full of bank balances to work with in the first place, I suppose. And his modified source would only run on his system and any other system whose owner was duped into installing it. Other systems wouldn't be affected.

    The real fun begins with this gem from Mr. Malone: "Every programmer I have ever met has always left himself a back door into every system he writes." I find this an extremely interesting perspective, considering that every single programmer I know does NOT leave a back door in ANY code. Given that Mr. Malone works for MBS Software (according to his letter), I take his words to mean that MBS products contain security holes by way of programmed "back doors," and I will accordingly caution consumers not to purchase anything from MBS until such time as they secure their software.

    Mr. Malone then warns "Microsoft bashers" to beware, lest they get what they wished for. I don't know about him, but I've been wishing for stable, secure products for years, and Microsoft has yet to deliver. I am fortunate that the open source movement--pioneered by such products as the 32-bit multitasking, multithreaded, stable-as-a-rock, open source operating system known as Linux--is making such a large impact on the computer industry. Otherwise, we'd have 10 more years of Microsoft "innovation" to look forward to.

  • Re:Shutting down the Internet & a question 2 L0pht by EchoMirage (Score:1) Monday December 27 1999, @10:55AM
  • L0pht BBS by Cynic (Score:2) Monday December 27 1999, @11:03AM
  • Large Gov'ment Automated Keyword Scan System by spartan (Score:2) Monday December 27 1999, @11:07AM
  • by EchoMirage (29419) on Monday December 27 1999, @11:11AM (#1442282)
    To L0pht:



    We've been working on network theory for a while and an idea which we've been working on recently is adaptive system and network security that models the identification and proaction of a biological immune system.



    Basically, the security system all incoming and outgoing traffic, processes, etc. As it analyzes a network configuration, it 1) adapts to that network and covers potentials holes from the start, 2) learns from and builds immunity to network attacks, hostile processes, and general system errors such as buffer overflows. Many security systems are, to a point, adaptive to their environment, but I have yet to see a security design that is adaptive/intelligent enough to configure itself to "live" within an environment and to become intelligently symbiotic with that environment.



    How much work have you done with highly adaptive security systems, and do you foresee adaptive security becoming a working reality within the next decade?
  • Accountability vs Privacy by drenehtsral (Score:2) Monday December 27 1999, @11:16AM
  • Re:Windows API - Flawed Logic by Charlatan (Score:1) Monday December 27 1999, @11:16AM
  • Re:Internet Worm II by jesser (Score:1) Monday December 27 1999, @11:20AM
  • Will it take a lawsuit? by ghibli (Score:2) Monday December 27 1999, @11:31AM
  • Mmmmn. by jallen02 (Score:1) Monday December 27 1999, @11:42AM
  • Will there be more than viruses? by cr0sh (Score:1) Monday December 27 1999, @11:45AM
  • Re:Reply to this letter. by Neoplasm (Score:2) Monday December 27 1999, @11:48AM
  • Creativity rather than Skill... by Anonymous Coward (Score:1) Monday December 27 1999, @11:55AM
  • Stepping into t'spotlight by K. (Score:1) Monday December 27 1999, @12:17PM
  • come on, what I really want to know is... by Artifex (Score:1) Monday December 27 1999, @12:21PM
  • unstoppable virus by donglekey (Score:1) Monday December 27 1999, @12:43PM
  • Linux Hardware Support - When? by Levine (Score:1) Monday December 27 1999, @12:49PM
  • Re:0 is Ø. by Levine (Score:1) Monday December 27 1999, @01:12PM
  • Please reply to this! (Re:IPv6) by dibos (Score:1) Monday December 27 1999, @01:41PM
  • Security... that's what it's all about by Budda74 (Score:1) Monday December 27 1999, @01:43PM
  • Question on your history by Townshend (Score:2) Monday December 27 1999, @02:15PM
  • IPO? :) by pen (Score:1) Monday December 27 1999, @02:41PM
  • Re:0 is Ø. by myconid (Score:1) Monday December 27 1999, @02:43PM
  • Re:The Public's Perception of Hacking by |deity| (Score:1) Monday December 27 1999, @03:38PM
  • How secure do you think Win2K will be? by Mr. Haplo (Score:1) Monday December 27 1999, @03:46PM
  • Re:Job offers by |deity| (Score:1) Monday December 27 1999, @03:49PM
  • Re:Job offers by eyeball (Score:1) Monday December 27 1999, @04:13PM
  • Re:Reply to this letter. by Anonymous Coward (Score:1) Monday December 27 1999, @04:15PM
  • Re:Security Through Arbitrarity: libnc? by washort (Score:1) Monday December 27 1999, @04:31PM
  • Through the Orifice both ways by leonbrooks (Score:1) Monday December 27 1999, @04:42PM
  • Re:Pronounciation by norkakn (Score:1) Monday December 27 1999, @05:06PM
  • Ohmmmm by perigeeV (Score:1) Monday December 27 1999, @05:34PM
  • Random Numbers... by J. Chrysostom (Score:2) Monday December 27 1999, @06:16PM
  • Re:Who's more dangerous? by Potatoswatter (Score:1) Monday December 27 1999, @06:26PM
  • You don't say! by Potatoswatter (Score:1) Monday December 27 1999, @06:36PM
  • Re:Security Through Arbitrarity: libnc? by Effugas (Score:2) Monday December 27 1999, @06:44PM
  • Does Congress have a clue? by danorr (Score:1) Monday December 27 1999, @06:57PM
  • Security through obscurity by kiolbasa (Score:1) Monday December 27 1999, @07:39PM
  • Security Hoaxes (Score:3)

    by Effugas (2378) on Monday December 27 1999, @08:03PM (#1442339) Homepage
    L0pht Crew--

    Combine extreme paranoia about web site security, a money stream coming straight out of PR Maintenance, and a "get-rich-quick" mentality that infuses Internet businesses, and you get an environment rife for the creation of snake oil cures and security systems that work by seeing to the financial security of the software authors.

    Of course, the natural defense to such hucksterism is the presence of groups such as yours. What are some of the products and techniques that you've seen, debunked, and felt you intelligence insulted by?

    Yours Truly,

    Dan Kaminsky
    DoxPara Research
    http://www.doxpara.com
  • short answer questions by keil (Score:1) Monday December 27 1999, @08:09PM
  • Re:Pronounciation by splinter (Score:1) Monday December 27 1999, @08:13PM
  • Re:Security? by Spamizbad (Score:1) Monday December 27 1999, @09:10PM
  • Potential Wannabes? by Anonymous Coward (Score:1) Monday December 27 1999, @09:54PM
  • Internet thru packet radio... NOT! by Inferno (Score:1) Monday December 27 1999, @10:59PM
  • Re:Reply to this letter. by Neoplasm (Score:1) Monday December 27 1999, @11:59PM
  • Re:Internet Worm II by sinnergy (Score:2) Tuesday December 28 1999, @02:36AM
  • OpenBSD? by Noryungi (Score:2) Tuesday December 28 1999, @03:07AM
  • Re:Question: Opinion on non-full-disclosure compan by minga (Score:1) Tuesday December 28 1999, @03:22AM
  • Fame sucks, What do you think? by segmond (Score:1) Tuesday December 28 1999, @03:42AM
  • expand? by jbarnett (Score:1) Tuesday December 28 1999, @03:56AM
  • Question by scagnetti (Score:1) Tuesday December 28 1999, @04:09AM
  • Re:Adaptive Pseudo-Biological Security by bons (Score:1) Tuesday December 28 1999, @04:29AM
  • Full disclosure by unstableboy (Score:1) Tuesday December 28 1999, @04:48AM
  • What about the L0pht dress code? by Reid Fleming (Score:1) Tuesday December 28 1999, @06:52AM
  • Anonymous Money by atomly (Score:1) Tuesday December 28 1999, @11:36AM
  • Re:Shutting down the Internet by batz (Score:1) Tuesday December 28 1999, @01:11PM
  • Re:Through the Orifice both ways by Adam Walker (Score:1) Tuesday December 28 1999, @04:08PM
  • Paranoid Delusionals Beware! by Zaffle (Score:1) Wednesday December 29 1999, @01:33AM
  • public speaking by jnazario (Score:1) Wednesday December 29 1999, @03:09AM
  • Re:Question: Opinion on non-full-disclosure compan by minga (Score:1) Wednesday December 29 1999, @03:16AM
  • "make the Internet unusable for the entire nation” by AviN (Score:1) Wednesday December 29 1999, @08:04AM
  • Re:Will it take a lawsuit? by John Allsup (Score:1) Wednesday December 29 1999, @11:27AM
  • Re:0 is Ø. by Levine (Score:1) Wednesday December 29 1999, @04:26PM
  • Actually, he has a bit of a point by sansbury (Score:1) Wednesday December 29 1999, @05:15PM
  • Re:obscure's anus by Obscure Images (Score:1) Wednesday December 29 1999, @07:06PM
  • Re:0 is Ø. by generic (Score:1) Monday January 03 2000, @08:36AM
  • 64 replies beneath your current threshold.
(1) | 2 | 3