TweetFollow Us on Twitter

Jul 90 Letters
Volume Number:6
Issue Number:7
Column Tag:Letters

Virus Defense

By Kirk Chase, Editor, MacTutor

Viruses, Worms, And Trojan Horses

Steve Seaquist

3126 Brinkley Road, #204

Temple Hills, MD 20748-6308

For those who don’t know who I am, I wrote SecurityPatrol, which was published in the February 1989 issue. I’m writing in response to the April 1990 issue’s Mousehole report of the first two destructive Mac programs, which were of the trojan horse and time bomb types.

In discussing the general topic of defense, typical success stories have involved many simple defenses that overlap and reinforce one another, so that if one subsystem temporarily breaks down, another can take up the slack until total defenses can be shored up. That’s where we’re heading now, with many tools, of different types, from different sources. There will soon be so many tools that no new virus, worm, trojan horse or whatever can be programmed to evade them all. Ours is becoming an environment both sensitive and hostile to destructive software. We can now, if we so choose, swarm like bees (or Maryland police cars, an awesome sight to behold) around new releases of harmful software, isolate their spread and track them back to their source.

What we need now are our own success stories. We need to catch people with unbroken threads of evidence that lead to convictions in court. We need to make our environment even more sensitive and even more hostile to destructive software. We need to force anyone who contemplates releasing destruction into our world to think long and hard on the question: “Just how certain am I that I won’t get caught?”

To start working toward our own success stories, we need to start doing three things we haven’t been doing, namely: audit-trails, cooperation among anti-virus software developers and glorifying the hero:

Audit-Trails

By audit-trails, I mean the unbroken threads of evidence that lead to convictions in court. Keeping an audit-trail takes the most work, by far, from everyone. It means keeping track of where everything came from: every disk, every document, every application, every system file. (Yes, yes, every disk and document too.) It means keeping track of people: who they say they are, what they look like (height, weight, pitch of voice, color of eyes, race, identifying marks and scars, etc), where and when you met them, what information they used to convince you they were who they said they were, whether or not they could have overheard that information, etc. They don’t have to be extensive notes, but take notes. And if you run a BBS, multiply everything I just said times the number of users on your system.

This may sound like too much work, but consider your own liability: If someone gave you an application program, and you gave it to someone else, and it turned out to contain the worse virus ever released, and they traced it back to you, how much could you tell them about the person who gave it to you? Will they believe you? It’s for your own protection too. In situations of mutual defense, it often makes little sense to distinguish between self-defense and defense of others.

So if a guy you don’t know very well offers you a disk, the very least you should do is ask to see some photo-id and take down the numbers. If this provokes a fearful reply “What do you want to see that for?”, just tell the truth “I like to keep a record of where I get everything, just in case it turns out to contain a virus or something.” If he balks, it’s probably because he hasn’t been keeping records himself and has just realized with force his own precarious legal position. (Don’t be surprised to see his face go pale.) Be compassionate, calm his fears that people are going to be out to get him and explain the need for group solidarity in fighting this war. You’ve just encouraged another citizen to keep records of everyone and everything, and you’re probably better off not accepting anything from him till he does anyway.

Cooperation Among Anti-Virus Developers

While I was finishing up SecurityPatrol for publication, some new viruses were discovered that I had not “contracted”. Since I needed to have an actual copy of a virus in order to fingerprint it (see the MacTutor article), I talked to various companies that were working on anti-virus software. I explained a secure arrangement that would allow them to send the viruses safely through MacTutor or the Washington Apple Pi users group. If I listened with my ears, I heard them say “Our lawyers have advised us we would be in a dangerous legal position if we sent anyone a virus.”. But if I listened with my heart and to the tones of their voices, I got the very strong feeling that they didn’t want to help out a magazine article that might undercut their own future profits.

The real reasons behind their non-cooperation are irrelevant. The key points are that non-cooperation exists and that it slows the progress of every one of the commercial product developers. Even if Apple were to work out a virus distribution system to get out copies of newer viruses to developers, there’s still the problem of analysis. What one of them knows about a new virus, they all should know, so that no one’s product is caught by surprise. In other words, we should be fighting the enemy, not one another.

Please understand, I’m not a mawkish ivory-tower-dwelling sophomore who thinks profit is a dirty word. Far from it. Profit is an excellent motive to dedicate people to a task, and security is a task to which I’d like to see many more people dedicate themselves. But I also believe security is a special case that threatens everyone’s profit, and as such, deserves special treatment. The survival of an anti-virus product should be based on approach, cost, ease-of-use, interface, performance, stability, support, upgrades to deal with new viruses, etc, but not on secrecy. Vermin hide in the dark, not in the sunlight.

I might add that Mainstay was the only group that gave me any help to speak of. If you’re undecided among anti-virus products, I think they should be rewarded for their attitude. But no one provided copies of the newer viruses.

As a result, I was unable to finish SecurityPatrol with defenses against the newer viruses in time for publication. My hope was then, as it is now, that MacTutor readers would, when they encountered a new virus, analyze whether its fingerprints vary according to variable data stored in the virus, fingerprint it over its invariant parts and mail the code and fingerprint numbers to MacTutor so that everyone would benefit from their analysis. That would extend cooperation throughout the developer community.

Glorifying the Hero

You can’t blame the press for needing to find something to write about. That’s the situation they’re in. Many virus writers are unconsciously eager to become infamous for the number of people they’ve hurt or angered, and when caught, freely provide interviews citing grandiose motivations, intended to show that they were actually doing the community a service (to get Apple to clean up its act on security, for example). The press should see through such claims which endanger the foundations of their own freedoms:

The 1st Amendment protects the idea by protecting its author. It does not confer unlimited mode of expression. If you express anger in words, in print or in paint on a canvas you bought, you are protected by the 1st Amendment. But if you express anger with fists or bullets, or in paint on the side of someone else’s building, even a government building, you are not. (If virus writers want Apple to clean up their act on security, they should say so, and how to do so, in print, or they should publish application programs that shore up the defenses. Those modes of expression are protected by the 1st Amendment. And in the free exchange of ideas, the stronger ones, possibly their own, will win out.)

We are partly to blame for the press having nothing to write about except bad news. When someone does something good, we don’t issue a press release about it. In effect, we don’t give them anything to write about except bad news. The only time anyone ever issues a good news press release, it’s a vendor touting a new product. (The press is loathe to provide free publicity; vendors are normally expected to pay for publicity.)

But make no mistake. The press is just as eager to print good news if they think it’ll sell, and news about viruses sells big. If you figure out exactly how a virus works or can be detected, produce a detailed description and send it in to a Mac magazine. (MacWEEK is a timely place for such info, and they helped me find people who knew about viruses, so they deserve to be rewarded.) That, friend, is a press release, and it’ll be your name that’ll be printed along with the description, not the name of the person who wrote the virus. You’re the hero, and you deserve recognition for your efforts. If you figure out how to modify SecurityPatrol to detect it, send in the code and fingerprints to MacTutor, and it’ll be your name again.

The popular press also has trouble distinguishing gifted programmers. Their only measures are how many people were affected and how severely. They don’t know that most viruses are written by junior and mid-level programmers who wish to be regarded as senior simply because they’ve figured out how to read Inside Macintosh and Tech Notes. But true seniority in programming reveals itself in the thoughtfulness with which flexible human needs are matched to inflexible machine realities. It’s a kind of maturity that comes from working on many projects, making many people happy and being happy that you made them happy. In other words, senior programmers have a joy of relating to people that virus writers know nothing about. And the popular press doesn’t know it either.

So at the same time as you provide your analysis of the new virus, be sure to point out what a simpleton its programmer was for understanding only the computer, and not even very well. If the virus does something particularly mindless, such as an INIT that installs itself into every file, not just INIT files, say so. If it skips a CODE resource-id number because it lost track of its own counter, say so. If it’s exactly the same as another virus except for a minor variation, say so. And always, always, always point out that its author isn’t fit to lick the dog poop off the boots of the programmers whose programs it infects. Maybe by the time its author is revealed, the press will be less inclined to talk about him as if he’s a genius or to analyze his ideas and motivations in depth as if there’s something there profound to be found.

I sincerely believe that, by shining bright light on all areas of Mac security, opening our eyes wide and paying very close attention to detail, we will create a place where vermin will have no place to hide. Please help.

More on Modula-2

Allen Stenger

Gardena, CA

This letter summarizes my experience with Modula-2 compilers on the Macintosh; it responds to the letter from Thorsten Kramp in the April 1990 MacTutor.

I have used both the SemperSoft compiler and the Metrowerks standalone (PSE) system. The SemperSoft compiler is well-integrated into the MPW environment. It produces good code and runs fairly quickly. (Is SemperSoft still in business? They don’t advertise in MacTutor anymore, and APDA no longer carries the compiler.)

The Metrowerks standalone system is also fairly fast, but produces very peculiar-looking code. Apparently each procedure is called through some sort of jump table. Also the linked applications are very large (100K for a 20-line program); most of this seems to be library routines. There are no MacsBug symbols. The Metrowerks system comes with a very nice symbolic debugger, which allows breakpoints to be set and shows formatted dumps of Macintosh structures. It also allows faster turnaround than the SemperSoft system (the Metrowerks compiler itself is about half as fast, but the link takes almost no time, compared to SemperSoft where you have to go through the slow MPW linker). The SemperSoft system has a few obscure bugs; the Metrowerks system has a few less-obscure bugs. The most annoying Metrowerks bug was that the very nice symbolic debugger refused to work on the program where I really needed it (it turned out that the debugger doesn’t like anchored variables).

For learning and miscellaneous fooling around (which seems to be Mr. Kramp’s need) the Metrowerks system seems to be the better choice. Its bulky object code makes it less attractive than the SemperSoft system for application development.

Metrowerks also makes an MPW version. In addition TML Systems is reported to sell a Modula-2 system. But I have not had experience with any of these, nor have I heard any reports on them.

World Wide Developers Note

Kirk Chase

MacTutor

Just a short note about the World Wide Developer's Conference in San Jose last May. Practically every session the speaker was asking for input from us developers. Apple is making some far reaching changes in the future. Now is a good time to send some feedback through AppleLink.

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

OmniGraffle Pro 7.2.2 - Create diagrams,...
OmniGraffle Pro helps you draw beautiful diagrams, family trees, flow charts, org charts, layouts, and (mathematically speaking) any other directed or non-directed graphs. We've had people use... Read more
OmniGraffle 7.2.2 - Create diagrams, flo...
OmniGraffle helps you draw beautiful diagrams, family trees, flow charts, org charts, layouts, and (mathematically speaking) any other directed or non-directed graphs. We've had people use Graffle to... Read more
Spotify 1.0.44.100. - Stream music, crea...
Spotify is a streaming music service that gives you on-demand access to millions of songs. Whether you like driving rock, silky R&B, or grandiose classical music, Spotify's massive catalogue puts... Read more
Microsoft OneNote 15.29 - Free digital n...
OneNote is your very own digital notebook. With OneNote, you can capture that flash of genius, that moment of inspiration, or that list of errands that's too important to forget. Whether you're at... Read more
WALTR 2 2.0.8 - $39.95
WALTR 2 helps you wirelessly drag-and-drop any music, ringtones, videos, PDF, and ePub files onto your iPhone, iPad, or iPod without iTunes. It is the second major version of Softorino's critically-... Read more
Dropbox 16.3.27 - Cloud backup and synch...
Dropbox is an application that creates a special Finder folder that automatically syncs online and between your computers. It allows you to both backup files and keep them up-to-date between systems... Read more
EtreCheck 3.1.5 - For troubleshooting yo...
EtreCheck is an app that displays the important details of your system configuration and allow you to copy that information to the Clipboard. It is meant to be used with Apple Support Communities to... Read more
Carbon Copy Cloner 4.1.12 - Easy-to-use...
Carbon Copy Cloner backups are better than ordinary backups. Suppose the unthinkable happens while you're under deadline to finish a project: your Mac is unresponsive and all you hear is an ominous,... Read more
VueScan 9.5.62 - Scanner software with a...
VueScan is a scanning program that works with most high-quality flatbed and film scanners to produce scans that have excellent color fidelity and color balance. VueScan is easy to use, and has... Read more
SpamSieve 2.9.27 - Robust spam filter fo...
SpamSieve is a robust spam filter for major email clients that uses powerful Bayesian spam filtering. SpamSieve understands what your spam looks like in order to block it all, but also learns what... Read more

Latest Forum Discussions

See All

Track Santa with these three festive app...
Christmas is fast approaching and that means it's time to prepare for Santa's yearly pilgrimage around the globe. Christmas Eve is an exciting time as parents help their kids get ready to welcome Santa. You've got the cookies and milk all planned... | Read more »
Galaxy on Fire 3 and four other fantasti...
Galaxy on Fire 3 - Manticore brings the series back for another round of daring space battles. It's familiar territory for folks who are familiar with the franchise. If you've beaten the game and are looking to broaden your horizons, might we... | Read more »
The best apps for your holiday gift exch...
What's that, you say? You still haven't started your holiday shopping? Don't beat yourself up over it -- a lot of people have been putting it off, too. It's become easier and easier to procrastinate gift shopping thanks to a number of apps that... | Read more »
Toca Hair Salon 3 (Education)
Toca Hair Salon 3 1.0 Device: iOS Universal Category: Education Price: $2.99, Version: 1.0 (iTunes) Description: | Read more »
Winter comes to Darkwood as Seekers Note...
MyTona, based in the chilly Siberian city of Yakutsk, has brought a little festive fun to its hidden object game Seekers Notes: Hidden Mystery. The Christmas update introduces some new inhabitants to players, and with them a chance to win plenty of... | Read more »
Bully: Anniversary Edition (Games)
Bully: Anniversary Edition 1.03.1 Device: iOS Universal Category: Games Price: $6.99, Version: 1.03.1 (iTunes) Description: *** PLEASE NOTE: This game is officially supported on the following devices: iPhone 5 and newer, iPod Touch... | Read more »
PINE GROVE (Games)
PINE GROVE 1.0 Device: iOS Universal Category: Games Price: $1.99, Version: 1.0 (iTunes) Description: A pine grove where there are no footsteps of people due to continuous missing cases. The case is still unsolved and nothing has... | Read more »
Niantic teases new Pokémon announcement...
After rumors started swirling yesterday, it turns out there is an official Pokémon GO update on its way. We’ll find out what’s in store for us and our growing Pokémon collections tomorrow during the Starbucks event, but Niantic will be revealing... | Read more »
3 reasons why Nicki Minaj: The Empire is...
Nicki Minaj is as business-savvy as she is musically talented and she’s proved that by launching her own game. Designed by Glu, purveyors of other fine celebrity games like cult favorite Kim Kardashian: Hollywood, Nicki Minaj: The Empire launched... | Read more »
Clash of Clans is getting its own animat...
Riding on its unending wave of fame and success, Clash of Clans is getting an animated web series based on its Clash-A-Rama animated shorts.As opposed to the current shorts' 60 second run time, the new and improved Clash-A-Rama will be comprised of... | Read more »

Price Scanner via MacPrices.net

New 2016 13-inch Touch Bar MacBook Pros on sa...
B&H Photo the new 2016 Apple 13″ 2.9GHz/256GB Touch Bar MacBook Pros on sale for $50 off MSRP, each including free shipping plus NY sales tax only: - 13″ 2.9GHz/256GB Touch Bar MacBook Pro Space... Read more
12-inch 1.2GHz Space Gray Retina MacBook on s...
B&H Photo has dropped their price on the 2016 Apple 12″ 1.2GHz Space Gray Retina MacBook (MLH82LL/A) to $1399 including free shipping plus NY sales tax only. Their price is $200 off MSRP, and it’... Read more
Never Settle for Low Performing Wifi With iOS...
AppYogi Software has announced the release of WiFi Signal Strength Status App 1.0, the company’s new utility developed exclusively for macOS. WiFi Signal Strength Status App features a unique, single... Read more
New 2016 13-inch Touch Bar MacBook Pros in st...
B&H Photo has stock of new 2016 Apple 13″ Touch Bar MacBook Pro models, each including free shipping plus NY sales tax only: - 13″ 2.9GHz/512GB Touch Bar MacBook Pro Space Gray: $1999 - 13″ 2.... Read more
New 2016 15″ Touch Bar MacBook Pros in stock...
B&H Photo has new 2016 Apple 15″ Touch Bar MacBook Pro models in stock today including free shipping plus NY sales tax only: - 15″ 2.7GHz Touch Bar MacBook Pro Space Gray: $2799 - 15″ 2.7GHz... Read more
DietSensor App Targeting Diabetes and Obesity...
DietSensor, Inc., a developer of smart food and nutrition applications designed to fight diabetes and obesity and help improve overall fitness, has announced the launch of its DietSensor app for... Read more
Holiday 2016 13-inch 2.0GHz MacBook Pro sales...
B&H has the non-Touch Bar 13″ MacBook Pros in stock today for $50-$100 off MSRP. Shipping is free, and B&H charges NY sales tax only: - 13″ 2.0GHz MacBook Pro Space Gray (MLL42LL/A): $1449 $... Read more
Holiday sale: Apple TVs for $51-$40 off MSRP,...
Best Buy has dropped their price on the 64GB Apple TV to $159.99 including free shipping. That’s $40 off MSRP. 32GB Apple TVs are on sale right now for $98 on Sams Club’s online store. That’s $51 off... Read more
12-inch Retina MacBooks, Apple refurbished, n...
Apple has restocked a full line of Certified Refurbished 2016 12″ Retina MacBooks, now available for $200-$260 off MSRP. Refurbished 2015 models are available starting at $929. Apple will include a... Read more
Holiday sale: 12-inch Retina MacBook for $100...
B&H has 12″ Retina MacBooks on sale for $100 off MSRP as part of their Holiday sale. Shipping is free, and B&H charges NY sales tax only: - 12″ 1.1GHz Space Gray Retina MacBook: $1199 $100... Read more

Jobs Board

Integration Technician, *Apple* - Zones, In...
…at Zones and for our customers each day. Position Overview The Apple Integration Technician will be responsible for performing customer specific configuration Read more
*Apple* Brand Ambassador (Macy's) - The...
…(T-ROC), is proud of its unprecedented relationship with our partner and client, APPLE ,in bringing amazing" APPLE ADVOCATES"to "non" Apple store locations. Read more
*Apple* Retail - Multiple Positions- Trumbul...
Sales Specialist - Retail Customer Service and Sales Transform Apple Store visitors into loyal Apple customers. When customers enter the store, you're also the Read more
*Apple* Retail - Multiple Positions - Apple,...
Job Description: Sales Specialist - Retail Customer Service and Sales Transform Apple Store visitors into loyal Apple customers. When customers enter the store, Read more
US- *Apple* Store Leader Program - Apple (Un...
…Summary Learn and grow as you explore the art of leadership at the Apple Store. You'll master our retail business inside and out through training, hands-on Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.