|
Does Verizon's Voyager stack up to the iPhone? |
|
|
5 IT skills that won't boost your salary
[1,407]
Women 4 times more likely than men to cough up personal info
[589]
Japan's 10 funniest tech-related commercials [Videos]
[407]
Throwing away a promo CD is "unauthorized distribution"?
[1,265]
Adults too quick to dismiss educational video games
[682]
Attack of the iPhone clones [Slideshow]
[578]
10 things IT needs to know about AJAX
[1,258]
This Year's 25 Geekiest 25th Anniversaries [Slideshow]
[409]
|
|
Not quite right
There are many errors in this story, which I believe result from Mr. Henry's misunderstanding or misinterpreting the source materials mentioned in Bruce Schneier's blog entry (cited in this story.) I recognize the errors, as I talked about some of these issues at the Information Security Decisions 2007 conference in November, provided an interview to Dennis Fischer for his Information Security Magazine article quoted in Bruce's blog, and I co-authored the two papers in the December USENIX ;login: magazine cited by Bruce. This article mistakes and confuses facts I presented on three malware artifacts I and my co-authors have studied recently: Storm, Nugache, and a variant of Rizo (derived from Rbot source code.) These original sources are not cited, and from what I can tell Mr. Henry and Secure Computing are confusing Nugache with the Rizo variant I spoke of.
For example:
Other articles have appeared in the tech press, and other blog postings, in early January 2008. All cite this erroneous article, have other erroneous quotes by Mr. Henry, and/or repeat these same errors. The quote about the price of botnets going down due to Nugache is almost certainly associated with Rizo or Rbot IRC bots, not Nugache: even someone on offensivecomputing.net makes this same mistake of confusing Nugache with Rizo. One even suggests Storm and Nugache are the same thing, which is certainly not true. This is unfortunate, and does not help anyone properly respond to (or even adequately understand) the "threat." At least in one of them, Trend Micro disputes the claims made in this article based on their own research.
If you are interested the subject, see the cited first-hand publications cited by Bruce Schneier in his blog, not this Seriously Confused repackaging of those sources.