Also: Layer 2 VPN services not ready to fly solo; Global warming, a hot time for IT; Of rootkits and responsibility; and Microsoft vs. Cisco: The new clash of the titans
Hidden roots
Regarding “Malware found on about 1 in 300 PCs: Microsoft”: I wonder if the percentage of rootkit finds was low due to the very nature of rootkits — they hide themselves. It’s true that many are distinguishable via signatures, but many use new techniques and methods that can subvert scanners. Maybe Microsoft should ask each person whose PC was scanned a question such as, “Have you noticed any further malware activity, pop-ups and increased network activity on your PC since a scan was run?”
Rootkits are too obvious a tool for malware authors to ignore. I don’t think they are ignoring the rootkits; the rootkits are doing their jobs.
Stephen Marsh
Administrator
www.antirootkit.com
Dublin, Ireland
What to look for
Regarding “Layer 2 VPN services not ready to fly solo”: Although the author represents a good summary of the conference discussion points and mentions credible references, the main discussion around the Layer 2 vs. Layer 3 VPN question was enterprises looking for somewhat of a checklist on when to select Layer 2 or Layer 3 VPNs when presented with the option from their carrier.
As a suggestion, it would be nice to understand (from a carrier and enterprise perspective) what an enterprise should look for in order to make the right selection. Surely, its not only about handing over routing control or not — there is much more. Although I fully appreciate that sometimes such decisions are scenario dependant and no generic template could be drafted, it would be nice to see an article that attempts to address the issue more fully.
Rotem Salomonovitch
Via e-mail
Warming up
Regarding Mark Gibbs’ BackSpin column, “Global warming, a hot time for IT”: I agree with the conclusions of his argument regarding changes that will come in the way we operate our businesses. Our reactionary legislature will probably create laws that force us to forego economic advantages in favor of empty energy conservation plans that make headlines but do nothing, and put the burden on the consumer and the small business.
My question for all who rail against global warming and the evil Americans who cause it is, “How warm or cool is the Earth supposed to be?”
The Earth’s temperature naturally fluctuates on a geologic timetable. Just because it’s warmer than it was when we were born, doesn’t mean there’s something wrong or that we caused it.
Bryan Sullo
Via e-mail
Rootkits and responsibility
Regarding Mark Gibbs’ BackSpin column, “Of rootkits and responsibility”: My opinion is that any program that does anything without my permission is wrong. Granted, I may not know every specific thing that Windows is doing, but I don’t expect it to be sending e-mail to someone without my permission.
A long-time pet peeve of mine has been large companies (read Microsoft) using my computer for their own (and other’s) uses. How? The cookie. When this first came to light years ago, I asked, “How is it that you can use my hard disk for your purposes?” I wouldn’t allow my insurance company to come into my house and use my file cabinet for information that they wanted to store about me. Why would I allow Microsoft (and others) to do it?
The die has long been cast: first cookie, now rootkit. What will be next?
George Carey
IT specialist
United Coatings
Spokane Valley, Wash.
Mark Gibbs’ points about rootkits are valid and well made — with one conspicuous exception. Placing software on a system without the user’s express consent is and must be illegal. It is not a question of what the software does; the fact of its insertion into a foreign system is the actionable event.
My worry is that concern with whether or not the effect of such software is good, bad or indifferent will lead us to a useless argument over whether or not such an installation is “good.” Consider this rough analogy. Breaking and entering is a well-known crime. If I break into a person’s house without his knowledge to remove a hazard (say, a bomb) then I am guilty of breaking and entering. I may argue that there should be no punishment, but not that I did not break in. Sony may argue that it shouldn’t be punished because its installation was benign (though I for one doubt that), but it must not be able to say that what it did was legal.
Ian Leedom
Milford, Mass.
As Mark Gibbs notes, it’s rootkits per se that are bad, but what they do without us knowing.
I repair computers, and I often install firewalls to stop spyware. One of the first things the firewalls detect is all the “legitimate” traffic between common software and their vendors. A big communicator is Real Player, which tends to install a startup application and begins talking over the Internet even before your browser is connected. Also Windows Media Player loves to talk with Microsoft. Are they discussing digital rights management, assessing your music collection for targeted advertising, or just reporting bugs? Adobe products also like to send messages. Isn’t it interesting when non-Internet applications start sending Internet messages to their vendor/masters? Of course, it’s all legitimate, isn’t it? You clicked the “Agree” button in the installer, and you are often required to use these common, ubiquitous applications. It’s easy to be critical of spymal.com using your Internet connection, but harder to criticize legitimate vendors. Thank you for taking Sony to task.
Fred Pierre
CEO
Data Doctor
Kent, Ohio
Using the competition
Regarding Howard Anderson’s column, “Microsoft vs. Cisco: The new clash of the titans”: When Anderson says Microsoft is “behind” on voice mail, he neglects the fact that Cisco’s voice mail product uses Microsoft’s Exchange server as its back end. They are a lot closer than you think. Cisco’s Call Manager is also a Windows server, though it is getting ported to Linux.
Joe Pampel
Redding, Conn.




