Conspiring to contaminate?

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS

Since the first computer viruses appeared in the DOS era, there's been an ongoing digital arms race between the authors of malicious code and the companies that write antivirus software. Many people believe there's a global conspiracy going on between these two factions to benefit both groups and, for some, increasing virus and worm outbreaks only strengthen this belief.

It's certainly true that antivirus software wouldn't exist if there were no worms and viruses, but that doesn't mean antivirus companies hire people to write worms and viruses. In my opinion, there are many intelligent people in the world who enjoy nothing better than creating malicious code and preying on the incompetence of people using computer systems.

The majority of computer users expect computers to work properly without any maintenance at all. These are the same people who mindlessly click executable e-mail attachments, causing worms and viruses to spread unchecked.

From what I've seen in more than 20 years of working as an IT pro, the conspiracy argument doesn't hold a lot of water — because it doesn't take into account the incompetence of the average computer user. I think it's safe to say that at least 90 percent of the people using computers are ignorant to the details of how they work.

For a conspiracy to occur, there would need to be collusion and incentive. Money is usually good enough for most people and companies that produce antivirus software obviously make money. But no one has managed to locate a trail of money from antivirus companies to the people who are writing worms and viruses.

Let's look at how we find out about vulnerabilities in the first place. Security researchers, both independent and affiliated with Internet security firms, are usually the ones who find the vulnerability in a specific piece of software.

While there is no formal, worldwide-sanctioned procedure, it's customary for security researchers to notify the author or publisher when they find an exploitable software defect. Whether researchers receive compensation for their work does not justify a conspiracy.

After notification, the author of the vulnerable software then has time to evaluate and respond to the vulnerability with patches and a formal advisory. After determining corrective measures and making them available, the author then announces the vulnerability to the public. But it's then up to individual users to patch their systems.

Once the author publishes the information about a vulnerability, it's only a matter of time before someone takes that information and writes an exploit. After the author discloses the vulnerability, anyone with a moderate programming ability can use the information to produce a worm or virus.

The fact that laws exist against releasing malicious code doesn't stop the majority of virus and worm authors from writing them — their incentive to write an exploit has much more to do with bravado and bragging rights than money.

If an antivirus conspiracy existed on a global level, I'm certain that the various law enforcement agencies around the world would have already found a money trail leading from antivirus companies to worm and virus authors.

Worm and virus authors simply use publicly available details on vulnerabilities and exploits and write their code from that information. Antivirus software companies only benefit from this indirectly.

Would you rather have the information about vulnerabilities kept secret? Now that would be a conspiracy — one that makes sure that people know even less than they already do about their computers.

Talkback

Whilst I don't necessarily disagree with what you say, especially regarding the general ignorance of the computer-using public, I would just like to to add the following "conspiracy theory parallel":

It is claimed that there is a cure for the (human) common cold or malaria, but the companies that manufacture medicines to treat these illnesses would be committing commercial suicide if such a cure was to enter the marketplace.

Whilst the manufacturers cannot be linked tangibly to the causes of the illnesses, they are, allegedly, only doing enough to relieve symptoms rather than iradicate the cause! Whilst I am not saying this is actually happening, It is surely this type of symbiotic relationship that keeps each party thriving.

via Facebook 16 November, 2005 12:00
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

7 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

8 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

9 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

11 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

13 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

14 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

14 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

14 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

16 hours ago by via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

17 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

23 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 day ago by ramwellian on Cloud computing security: no more oxymoron?