{"id":540404,"date":"2010-04-22T14:34:14","date_gmt":"2010-04-22T18:34:14","guid":{"rendered":"tag:redtape.msnbc.com:\/\/0b2f596d944430f2b257bb4cfb1b46c6"},"modified":"2010-04-22T14:34:14","modified_gmt":"2010-04-22T18:34:14","slug":"why-did-mcafee-goof-it-was-automatic","status":"publish","type":"post","link":"https:\/\/mereja.media\/index\/540404","title":{"rendered":"Why did McAfee goof? It was automatic"},"content":{"rendered":"<p><font face=\"Verdana\">How can a software company, with one small mistake, cripple computers worldwide? <\/font><\/p>\n<p><font face=\"Verdana\">McAfee security users left the office on Tuesday night with a perfectly good Windows XP computer.&#0160; On Wednesday morning, they were staring at a useless pile of plastic and computer chips.&#0160; Without so much as the stroke of an enter key or the push of a mouse, their PCs had been changed. The error was simple: McAfee\u2019s software erroneously decided that an essential file used by the Windows operating system was really an 18-month old Trojan horse. That sent many PCs into an infinite re-booting loop that couldn\u2019t be stopped without skilled, manual intervention.<\/font><\/p>\n<p><font face=\"Verdana\">The root of the problem lies in a critical decision made a decade ago by security professionals. But the result &#8212; perhaps millions of PCs rendered useless, each one requiring manual repair &#8212; is just the latest sign that bad guys seem to be winning in cyberspace.<\/font><\/p>\n<\/p>\n<p><font face=\"Verdana\">Back before the turn of the new millennium, the computer world was wrestling with a dramatic new concept &#8212; giving large software firms like Microsoft the right to access consumers&#39; computers and update their software automatically.&#0160; To many purists, who might be considered technological libertarians, the idea of letting an outside company reach inside their hard drive and change things was pure lunacy.<\/font><\/p>\n<p><font face=\"Verdana\"><img decoding=\"async\" alt=\"FightClub\" class=\"asset asset-image at-xid-6a00d83451b0aa69e20133ecb7839a970b \" src=\"http:\/\/onthescene.msnbc.com\/.a\/6a00d83451b0aa69e20133ecb7839a970b-120wi\" style=\"MARGIN: 5px; FLOAT: left\" title=\"FightClub\" \/>A five-year-long onslaught of global virus outbreaks quickly changed hearts and minds. Consumer behavior consistently revealed that the vast majority of PC users wouldn&#39;t bother manually installing software patches and antivirus protection. That made them easy prey for Code Red, The Love Bug, Nimda, and dozens of other malicious programs. And as the rate of new malicious programs began to grow exponentially, it became physically impossible for even full-time experts to manually update their systems.<\/font><\/p>\n<p><font face=\"Verdana\">Today, most computer users don&#39;t think twice about letting Microsoft update their machines, or about downloading patches or new protection files from security firms like McAfee, Symantec, Kaspersky, and others.&#0160; The system has worked; it&#39;s been 10 years since an outbreak like the Love Bug.&#0160; But Thursday&#39;s Mcafee disaster \u2013 which affected corporate and not consumer users &#8212; brought into focus the downside of giving control to an outside software firm.&#0160; Doctors, students, and office workers worldwide were left disconnected from the outside world, feeling very much the way they used to when a virus outbreak crippled their organizations.<\/font><\/p>\n<p><font face=\"Verdana\">&quot;Automatic updates are still kind of a thorny issue, but when you look at threats today and the number of products that can be impacted, automatic updates are really the only viable means to insure someone&#39;s system is kept up to date,&quot; said Mary Landesman, senior security researcher at ScanSafe. \u201cBut they still carry the same risk they always did.&#0160; If something is wrong with the update it&#39;s going to impact a great number of users.\u201d<\/font><\/p>\n<p><font face=\"Verdana\">At the same time, security firms are dealing with the overwhelming capacity of malicious programmers to churn out devious new code.<\/font><\/p>\n<p><font face=\"Verdana\">Ten years ago, according to Symantec Corp, there were 10 to 15 new computer viruses each week.&#0160; Today, the firm must find ways to protect customers against up to 20,000 new software threats every day.&#0160; While defusing all those bombs, the possibility of accidentally disabling a good file &#8212; a so-called false positive &#8212; is increasingly likely. <\/font><\/p>\n<p><font face=\"Verdana\">McAfee\u2019s problem was created by just such a false positive. While the firm has yet to release additional details about the breakdown, it&#39;s hard to imagine the breakneck speed didn&#39;t play a major factor.<\/font><\/p>\n<p><font face=\"Verdana\">&quot;It is an issue every malware company has to deal with, we have to adjudicate every file on someone\u2019s system and decide if it\u2019s good or bad,&quot; said Gerry Eagan, a security expect at Symantec. &quot;In this game of cat and mouse, as we try to be more aggressive and catching malicious programs&#8230;if we fail, something like this can occur.&quot;<\/font><\/p>\n<p><font face=\"Verdana\">Eagan said the file that McAfee erroneously identified was a relatively old threat. He believes that McAfee was expanding a virus definition to cover a new variant of that old threat&#8211;&#0160; a normal practice that helps the software run more efficiently \u2013 and that McAfee engineers probably \u201cwrote too generic a definition and caught a good file.\u201d <\/font><\/p>\n<p><font face=\"Verdana\">But Landesman said she thinks the flaw was related to McAfee\u2019s ability to detect viruses based on how they behave \u2013 by observing keylogging activity, for example &#8212; rather than the old-fashioned black-list method of identifying a known piece of computer code inside a malicious program.&#0160; Behavioral protection is a bit less scientific, she said, and more prone to false positives.<\/font><\/p>\n<p><font face=\"Verdana\"><img decoding=\"async\" alt=\"Herbbox\" border=\"0\" class=\"asset asset-image at-xid-6a00d83451b0aa69e20120a6792d57970c \" src=\"http:\/\/onthescene.msnbc.com\/.a\/6a00d83451b0aa69e20120a6792d57970c-800wi\" style=\"MARGIN: 6px; FLOAT: left\" title=\"Herbbox\" \/>\u201cAs we go to behavioral methods were going to see an increase,\u201d she said. \u201cThere has to be a certain acceptance that we&#39;re going to have them. But there will be some really ugly incidents like this one.\u201d<\/font><\/p>\n<p><font face=\"Verdana\">Even those who weren&#39;t hit by the McAfee bug might have had other run-ins with automatic updates.&#0160; Microsoft&#39;s Windows can be very insistent about installing updates &#8212; again, a sound security practice &#8212; but it often leads to unintentional system restarts and lost files. It&#39;s not uncommon that third-party software updates cause system instability.&#0160; In fact, in 2007, thousands of users of Symantec&#39;s Norton antivirus software reported persistent crashes after that company issued an update.&#0160; <\/font><\/p>\n<p><font face=\"Verdana\">So is it time to reconsider the practice of surrendering control of your PC to large software company?<\/font><\/p>\n<p><font face=\"Verdana\">&quot;I&#39;ve been reading forums and there are a number of people chiming in saying, &#39;This is why I don&#39;t use antivirus software,&#39; or &#39;This is why I don&#39;t apply patches,&#39;&quot; Landesman said.&#0160; &quot;There are people saying having antivirus software is worse than having none at all. That&#39;s just not true&#8230;but it is a real risk that people on the fringe about having antivirus software will point to this as a poster child for why they shouldn&#39;t. &quot;<\/font><\/p>\n<p><font face=\"Verdana\">Eagan said consumers and companies must make a logical decisions weighing the risks of unprotected surfing with the risks of a software goof.&#0160; Simply installing the software but reject installation of updates is not an option, he said.<\/font><\/p>\n<p><font face=\"Verdana\">&quot;If you delay your downloads, then you aren&#39;t protected,&#39; he said. The firm added 2.7 million virus detection fingerprints to its software automatic updates last year.<\/font><\/p>\n<p><font face=\"Verdana\">Sometimes those updates come several times a day, Landesman said, and that has overwhelmed even the most heavily staffed corporate security teams. Once upon a time, firms would test all updates in a lab before releasing them to their employees.&#0160; In most cases today, Landsman said, there&#39;s just no time.<\/font><\/p>\n<p><font face=\"Verdana\">&quot;So they almost have to take a leap of faith that it will work,&quot; she said.&#0160; &quot;That&#39;s the only practical avenue.&quot;<\/font><\/p>\n<p><font face=\"Verdana\">McAfee customers who made that leap on Wednesday weren\u2019t rewarded. Instead, a bit like a rattled offense facing an overwhelming full-court press in basketball, McAfee goofed. By overwhelming the system with volume, by forcing security firms to rush and implement imperfect technologies, by robbing companies of proper time to test, malicious software writers have gained the advantage.&#0160; Even this incident, while ultimately harmless for victims (outside of lost time), created a big opening for the bad guys.&#0160; Consumers affected by the bug who went to Google looking for answers last night found fake Web pages offering help that were loaded with booby traps.<\/font><\/p>\n<p><font face=\"Verdana\">\u201cThis is already an industry struggling to keep up,\u201d she said. For some time, McAfee will struggle to restore lost faith from customers.<\/font><\/p>\n<p><font face=\"Verdana\">&#0160;<span style=\"COLOR: black; mso-themecolor: text1\"><font face=\"Arial\">&#0160;<\/font><font size=\"3\"><span style=\"FONT-FAMILY: Verdana; FONT-SIZE: 13px\"><span style=\"mso-spacerun: yes\"><span style=\"FONT-FAMILY: Verdana; FONT-SIZE: 13px\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-FAMILY: Verdana; FONT-SIZE: 13px\">&#0160;<span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-FAMILY: Verdana; FONT-SIZE: 13px\"><span style=\"MARGIN: 0in 0in 10pt; FONT-FAMILY: Verdana; FONT-SIZE: 14px\"><span style=\"LINE-HEIGHT: 115%; FONT-SIZE: 12pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-FAMILY: Verdana; FONT-SIZE: 12px\"><span style=\"FONT-FAMILY: Verdana; COLOR: black; FONT-SIZE: 12px\"><span style=\"FONT-FAMILY: Verdana; FONT-SIZE: 13px\"><span style=\"COLOR: black; mso-themecolor: text1\"><span style=\"FONT-FAMILY: Verdana\"><span style=\"FONT-FAMILY: Verdana\"><span style=\"FONT-FAMILY: arial, helvetica, clean, sans-serif\"><strong><span style=\"FONT-FAMILY: Verdana; FONT-SIZE: 13px\">Become a&#0160;<\/span><\/strong><a href=\"http:\/\/www.facebook.com\/pages\/Bob-Sullivan\/78714223105?_fb_noscript=1\" style=\"COLOR: blue; CURSOR: pointer; text-decoration: underline\" ><strong><span style=\"FONT-FAMILY: Verdana; FONT-SIZE: 13px\">Red Tape Chronicles Facebook fan<\/span><\/strong><\/a><span style=\"FONT-FAMILY: Verdana; FONT-SIZE: 13px\">&#0160;<span style=\"FONT-FAMILY: Arial; FONT-SIZE: 14px\"><strong>or follow me at <\/strong><a href=\"http:\/\/twitter.com\/RedTapeChron\"><strong>http:\/\/twitter.com\/RedTapeChron<\/strong><\/a><\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/font><\/span><\/span><\/span><\/span><\/font><\/span><\/span><\/font><\/span><\/span><\/span><\/span><\/font><\/span><\/font><\/p>\n<p><o:p><\/o:p><\/p>\n<p><font face=\"Verdana\"><br \/><\/font><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How can a software company, with one small mistake, cripple computers worldwide? McAfee security users left the office on Tuesday night with a perfectly good Windows XP computer.&#0160; On Wednesday morning, they were staring at a useless pile of plastic and computer chips.&#0160; Without so much as the stroke of an enter key or the [&hellip;]<\/p>\n","protected":false},"author":5524,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-540404","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/540404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/users\/5524"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/comments?post=540404"}],"version-history":[{"count":0,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/540404\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/media?parent=540404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/categories?post=540404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/tags?post=540404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}