Forgot your password?
typodupeerror
Security

Ethics of Releasing Non-Malicious Linux Malware? 600

buchner.johannes writes "I was fed up with the general consensus that Linux is oh-so-secure and has no malware. After a week of work, I finished a package of malware for Unix/Linux. Its whole purpose is to help white-hat hackers point out that a Linux system can be turned into a botnet client by simply downloading BOINC and attaching it to a user account to help scientific projects. The malware does not exploit any security holes, only loose security configurations and mindless execution of unverified downloads. I tested it to be injected by a PHP script (even circumventing safe mode), so that the Web server runs it; I even got a proxy server that injects it into shell scripts and makefiles in tarballs on the fly, and adds onto Windows executables for execution in Wine. If executed by the user, the malware can persist itself in cron, bashrc and other files. The aim of the exercise was to provide a payload so security people can 'pwn' systems to show security holes, without doing harm (such as deleting files or disrupting normal operation). But now I am unsure of whether it is ethically OK to release this toolkit, which, by ripping out the BOINC payload and putting in something really evil, could be turned into proper Linux malware. On the one hand, the way it persists itself in autostart is really nasty, and that is not really a security hole that can be fixed. On the other hand, such a script can be written by anyone else too, and it would be useful to show people why you need SELinux on a server, and why verifying the source of downloads (checksums through trusted channels) is necessary. Technically, it is a nice piece, but should I release it? I don't want to turn the Linux desktop into Windows, hence I'm slightly leaning towards not releasing it. What does your ethics say about releasing such grayware?"
Privacy

Microsoft's Ballmer: Google Reads Your Mail 264

Anonymous writes "A piece of video has emerged in which Microsoft CEO Steve Ballmer says of Google, 'they read your mail and we don't.' Evidently, it was part of a lengthy discussion on the future of the software business model, and whether advertising could support free consumer software. Ballmer said it doesn't work, at least when it comes to email. '"That's just a factual statement, not even to be pejorative. The theory was if we read your mail, if somebody read your mail, they would know what to talk to you about. It's not working out as brilliantly as the concept was laid out." Ballmer isn't the first to fire salvos at Google's Gmail privacy policy. Privacy advocates have been critical over the policy almost since the beginning, but the popularity of the service has skyrocketed nonetheless.'"

Feed Techdirt: German Restaurant Ditches Waiters, Sends Food To Diners On Metal Slide Rails (techdirt.com)

We've definitely seen restaurants embrace technology and automation to bizarre ends before, but apparently a new restaurant in Germany is taking that to extremes. The Nuremberg-based 's Blaggers has completely replaced waiters with an automated system (via The Raw Feed). While there have certainly been fast food restaurants that have let patrons order themselves, in this case, it's a sit-down restaurant. Diners order their meals via a touchscreen, which is relayed to the kitchen which (and this turns out to be important) is upstairs from the dining area. Then, using a special hotpot that connects to a bunch of spiral steel rails your food is delivered by gravity power. The touchscreen actually keeps you up to date, as well, telling you how long it'll be until your food is delivered. The terminals also accept payment. Of course, the article doesn't explain how the cleanup process works... Perhaps diners can send the finished dishes down to a dishwasher in the basement? The guy behind it is hoping to license the offering to other restaurants (including McDonald's), but from the early reviews of his own restaurant, it sounds like people have been coming for the novelty, but some are a bit turned off by the mechanical nature of everything (and one person even compared it to the machinery used to feed pigs on large farms).

ESR Advocates Proprietary Software 422

mvdwege writes "Apparently, Eric Raymond has decided that proprietary software is now a good thing, according to The Register. I must say it is rather revealing how easily he is willing to compromise on this particular freedom. Is his earlier vocal proclamation of the importance of freedom (still visible on his homepage) mere posturing? And if so, how about his vocal support of other freedoms?"

AOL Tries New Tactic to Keep Customers 799

Jhon writes "AOL customer Vincent Ferrari tried to cancel his account, but a phone rep wouldn't let him do it. What he got when he tried to cancel his account was a lot of frustration. Now that's customer support!"

Tom's Overly Detailed Vista Review 283

prostoalex writes "The weekend is here, and several software sites have published extensive reviews of Windows Vista for your reading enjoyment. Tom's Hardware is running a 500 hour Windows Vista review that spreads out 40 pages." From the article: "This new operating system is huge: it has more than 37,800 files, taking up a total of 10 GB. Part of this size stems from the fact that the current Beta is for the so-called "Ultimate Edition", which contains all available components, including complete versions of both Tablet PC and Media Center capabilities. In addition, many applications have been compiled in debug mode, so some space savings should occur for final versions once that debug switch is turned off. For our Windows Vista preview, we used Build 5381."

Slashdot Top Deals

All the evidence concerning the universe has not yet been collected, so there's still hope.

Working...