Blaster worm: You hold the key to your safety

Opinion
Aug 18, 20034 mins

* Microsoft issued a patch; it's up to you to install it

Once again Microsoft is being pilloried in the press, the blogs and the chat rooms because of the spread of the so-called Blaster worm. There does come a time, however, when people have to take responsibility for their own platforms, tools and belongings as well as for their actions.

Weeks before the worm was released, Microsoft issued a security patch to protect against the so-called RPC vulnerability, which Blaster exploits. The press heavily covered the release of the patch and even the U.S. Department of Homeland Security issued bulletins requesting that the patch be installed as quickly as possible. At that time, Microsoft announced that the vulnerability had not been exploited and that a worm had not as yet been observed “in the wild.” But Microsoft acknowledged that an exploit of the vulnerability would be simple enough to construct and that it expected one to appear fairly soon after the announcement.

People who ignored those warnings allowed the worm to spread because of their (non) actions. The person who wrote the worm and first released it is criminally culpable because they knowingly exploited this unpatched security flaw.

When you build a house, you install doors in the doorways and you install locks on the doors. But you still have to turn the key in the lock in order for the door to be sealed against the casual intruder.

For many years, Microsoft has provided operating systems that we can compare to a house. These were delivered with the doors and windows unlocked, because it’s easier to gain access that way and you can always turn the key – or the latch – when you want to lock up. But it’s time consuming to have to find the key, insert it into the lock, turn it, open the door, close the door, insert the key, and turn it again in order to pass through the entrance.

To alleviate this, locks were created which while locked from the outside were always open from the inside (unless you threw the deadbolt). This is called a “spring latch” and can be opened from the outside by using a credit card, thin bladed knife or sometimes even with a fingernail. It protects against a very casual intruder, but not someone with an intent to achieve access.

Deadbolt locks can’t be “slipped” so easily, so determined intruders simply break the door around the lock and go through. They can’t hide the fact that they gained entry – but they don’t really care.

You can, of course, get a metal door with deadbolts. The really determined thief would then step back, look around – and smash your windows to gain entry. They can then remove the door hinges from the inside, and steal the “security door.”

If you’ve gone all the way up to a stone house with metal doors, locking grates in the chimneys and reinforced windows with metal shutters, you might think you are safe. But then the crook dresses up like a UPS driver and rings the doorbell (thanks to author Walter Glenn, https://www.oreillynet.com/cs/catalog/view/au/730 , for that scenario).

Microsoft provides the house. It’s not a particularly secure house, but it’s not intended to be Fort Knox. You, the house owner needs to be sure you take adequate precautions to protect the house. This includes installing security patches when the vendor strongly recommends that you do. But the real responsibility goes to the people who so loathe society while having egos bigger than Bill Gates and Larry Ellison combined who write and code and script the worms and viruses that infect the house and bring it down.

When bank robber Willie Sutton was asked why he robbed banks, he supposedly replied “because that’s where the money is.” He was really talking about ROI: a small investment in time and material brought him a big return in loot. The same can be said about the nefarious thugs who spread the worms, viruses and Trojans that make our lives difficult: because the Windows operating system is so ubiquitous, targeting Windows gives them the biggest bang for the buck.

Microsoft is making a big investment in securing the computing platform for all of us. It needs our encouragement, not our denigration.