Network World
Monday, November 9, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Are rootkits really all bad?

Settlement in Sony CD case resurrects rootkit debate.

When a security researcher late last year discovered Sony was using hidden software-cloaking and monitoring techniques to protect copyrights on its music compact discs, public backlash prompted lawsuits against the company and a debate ensued about using such “rootkits” in commercial software.

Related links
Put cybersecurity chief in DHS not the White House, Senator says 11/4/2009
US-CERT moves in with NCC, NCSC 10/30/2009
NSA to build $1.5B cybersecurity center near Salt Lake City 10/26/2009
Powered by Inform

Juniper's relationship with Packet Design
11/09/09
In our Oct. 26 WAN newsletter we discussed the fact that there were a number of rumors circulating about a dramatic move that Juniper would soon announce. On October the 29th Juniper used the New York stock exchange as a backdrop to make a series of announcements. We are doing to use this newsletter to focus on one piece of the Juniper announcements – Juniper's establishment of a close relationship with Packet Design.

Brocade, Oracle partner for database, SAN connectivity
11/09/09
In a sweeping announcement, Brocade and Oracle last week introduced a variety of solutions designed specifically for use with Oracle database and applications. Based on existing partnerships with NetApp, Sun/StorageTek and EMC, Brocade and Oracle have put together end-to-end networking packages for data warehousing, business applications and virtualization environments.

Juniper's relationship with Packet Design
11/09/09
In our Oct. 26 WAN newsletter we discussed the fact that there were a number of rumors circulating about a dramatic move that Juniper would soon announce. On October the 29th Juniper used the New York stock exchange as a backdrop to make a series of announcements. We are doing to use this newsletter to focus on one piece of the Juniper announcements – Juniper's establishment of a close relationship with Packet Design.

The lawsuits wound down with a court-ordered settlement that has Sony BMG Music Entertainment offering $7.50 and a free album download to those who bought any of the 15 million rootkit-infested CDs it sold. But the broader rootkit debate seems far from over.

Opponents say rootkits should never be used because they introduce potential vulnerabilities and are deceptive, while others contend there can be a legitimate use for deep-stealth technology in both the enterprise and home.

The Electronic Frontier Foundation (EFF), which declared it was satisfied with the Sony settlement, is not among those envisioning a positive role for rootkits.

“I have yet to see a rootkit which did not raise security concerns, and am skeptical that there can be legitimate use of technologies that hide files from the user in an effort to thwart user control of their own computer,” says Kurt Opsahl, staff attorney at EFF.

Security expert Bruce Schneier, founder of managed security services firm Counterpane, is equally adamant.

“Can there be benevolent rootkits? That’s similar to the question of benevolent worms. The answer is ‘no’,” he says. “Rootkits use stealth to hide payloads, and that can cause problems. A user loses control with what’s going on in their machines.”