The Turkey Curse
fukamis terror chatroom

n.runs, Sophos, German laws, and customer safety

Setting Orange, 21st Bureaucracy, 3173.

Steven M. Christey from [MITRE][mitre] gave a good example on Bugtraq mailing list where the new “anti hacker laws” in Germany regarding publishing of exploits are back firing badly. Here’s his full posting:

Subject: n.runs, Sophos, German laws, and customer safety

The n.runs-SA-2007.027 advisory claims code execution through a UPX file. This claim is inconsistent with the vendor’s statement that it’s only a “theoretical” DoS:

   ”A corrupt UPX file causes the virus engine to crash and Sophos
   Anti-Virus to return ‘unrecoverable error. leading to scanning being
   terminated. It should not be a security threat although repeated
   files could cause a denial of service.”

It is unfortunate that Germany’s legal landscape prevents n.runs from
providing conclusive evidence of their claim. This directly affects
Sophos customers who want to know whether it’s “just a DoS” or not.
Many in the research community know about n.runs and might believe
their claim, but the typical customer does not know who they are
(which is one reason why I think the Pwnies were a good idea). So,
many customers would be more likely to believe the vendor. If the
n.runs claim is true, then many customers might be less protected than
they would if German laws did not have the chilling effect they are

It should be noted that in 2000, a veritable Who’s Who of computer
security - including Bruce Schneier, Gene Spafford, Matt Bishop, Elias
Levy, Alan Paller, and other well-known security professionals -
published a statement of concern about the Council of Europe draft
treaty on Crime in Cyberspace, which I believe was the predecessor to
the legal changes that have been happening in Germany:

Amongst many other things, this letter said:

   ”Signatory states passing legislation to implement the treaty may
   endanger the security of their computer systems, because computer
   users in those countries will not be able to adequately protect
   their computer systems… legislation that criminalizes security
   software development, distribution, and use is counter to that goal,
   as it would adversely impact security practitioners, researchers,
   and educators.”

If I recall correctly, we were assured by representatives that such an
outcome would not occur.

- Steve

Thanks to Steve for pointing it out.



No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

"The great tragedy of Science - the slaying of a beautiful hypothesis by an ugly fact." - Thomas H. Huxley

The Turkey Curse is powered by WordPress, template idea by Priss

Entries (RSS) and Comments (RSS).
Generated in 0.048 seconds.