


	MORE FEAR AND LOATHING:  ON THE VIRUS CODE TRAIL AT AIS

	On Saturday, June 19, the national press suddenly reared up
	and without warning, mangled the reputation of one of the
	finest, most professional security experts I know, Kim Clancy of
	the Bureau of Public Debt's Security Branch.

	I rolled out of bed Saturday morning, plugged into Compuserve's
	Today's News and was promptly crushed by the brazen stupidity of
	reporter Charles Bowen's newspiece, "GOVERNMENT BBS SAID TO
	HAVE AIDED COMPUTER INTRUDERS AND VANDALS".

	Bowen plagiarized the lead, "A government spokesman says an
	obscure bulletin board system run by a federal agency apparently
	helped computer vandals commit electronic sabotage," directly
	from a same-day Associated Press story called "Dial-A-Virus".

	But neither Bowen nor the AP offered a solitary shred of proof,
	other than this outrageously leading statement, loosely
	attributed to Public Debt spokesman Peter Hollenbach, that
	Kim Clancy's AIS BBS has ever been responsible for abetting
	documented cases of hacker intrusion or computer vandalism
	by virus.

	Further, Bowen reported, "The [Washington] Post says that among
	the visitors to the system were computerists using handles such
	as 'The Internet Worm,' 'Satan's Little Helper' and 'Dark Avenger's
	Mutation Engine.'"  The Washington Post story, reported by
	Joel Garreau, said nothing of the kind, leading me to believe
	Bowen is either a functional illiterate or willfully slack.
	Indeed, anyone who has visited AIS knows beyond a shadow of a
	doubt that the system NEVER supported handles of such nature.
	[Of course, Bowen can respond by blaming it on a copy editor
	and/or tight deadline, the last, best defense of lazy,
	inaccurate newsmen the country over.]

	These vague insinuations, however, were as nothing compared to
	the wellspring of the controversy, Garreau's "Treasury Exposed
	Computer Virus Info; Whistleblowers Halted Display Available To
	Anyone With A Modem" which brought into the public glare the
	chain of events that resulted in the removal of hacker tools,
	text files and commented virus source code from AIS.

	Although Garreau's story attempted to present a number of sides
	it was packaged so that a general reader would get a picture
	of a mad-dog government agency, finally "muzzled" after
	distributing dangerous code to "every maladjusted sociopath
	with Coke-bottle-bottom glasses."  More savagely irresponsible
	was the sideborn statement that treasury officials had neglected
	to "discipline" Clancy, instead merely removing the dangerous
	information from her system.

	It was a real rabbit punch; a cheapjack, ham-handed slam on
	Kim Clancy, successful in portraying her as someone who
	spends her worktime beta-testing intrusion software against
	her own department so that hackers might optimize their methods
	for computer subversion and vandalism.  This is hair-raising
	stuff, to be sure, for a general readership, but not the real
	truth.  It is my understanding, and something I've seen
	Kim Clancy make clear in lectures to many computer workers, that
	the whole point of working with hackers on the development of
	"Tone-Loc" software was so that it COULD and WOULD be
	supplied to interested security personnel who would use it
	to gain an understanding of how to harden their systems against
	tools employing similar technology.

	This is emphatically not the handiwork of someone who should
	be disciplined or professionally tarred, but the work
	of someone who Bruce Sterling, not me, says is "probably THE
	BEST THERE IS [emphasis mine] in the federal government who's
	not military or NSA.  Probably better than most CIA."

	Unfortunately, Sterling's appraisal was buried near the end
	of the story, after all the cracked shouting about aiding
	hackers and computer criminals.

	But I've walked away from the real nut of the matter: the
	presence of commented virus source code at AIS.  The significance
	of this is, in my opinion, beyond the current ability of
	mainstream journalists to evaluate simply because the vast
	majority of them have little technical grasp of the
	byzantine reality of computer security, what viruses are,
	how they work and don't work and where you find virus source
	code.  Certainly, The Washington Post story did nothing
	to convince otherwise.

	Consider these statements from The Post and some stony facts:

	    >>According to software writers, with the AIS information
	    "relative amateurs, could create new viruses."

	    This is dangerously misleading.  As point of fact, relative
	    amateurs DO, not could, create new viruses from source
	    code and they've done so for a long time before the advent
	    of AIS.  That AIS would be responsible for such a
	    development, which is already fact, is frankly idiotic.

	    >>Virus source code at AIS "is worse than making live
	    viruses available.  A person without the skill to write
	    a brand new virus could nonetheless produce a variation
	    on an existing one . . . If sufficiently mutated, the
	    virus might slip past anti-virus programs designed to
	    look for known products."

	    This presumes that most virus-writers, would-be
	    virus-writers and "Coke-bottle glasses-variety
	    sociopaths" have little access to source code.  This
	    is not even close to being true.  Virus source code
	    is now commonplace on professional, semi-professional
	    and amateur BBS's run by every stripe of user across the
	    country. In fact, it is almost as common as pirated
	    software and pornography in some locales. Surprisingly,
	    the higher quality virus disassemblies stocked on such
	    BBS's are often the handiwork of anti-virus
	    researchers and software developers. Strangely, this
	    has never been reported by a mainstream newsman, perhaps
	    because "designated experts" often come from the same pool
	    of researchers and developers.

	    >>". . . some computer professionals minimize the risk,
	    saying the software on [AIS] was acquired through the
	    computer underground in the first place, and thus has
	    always been available to miscreants with sufficient
	    contacts, tenacity and skill."

	    This is a particularly nasty one because its presented
	    as justification by those attacked and seems true.  It's
	    not.  It requires NO tenacity or particular skill to
	    get hundreds of viruses and assorted source code listings.
	    Unlike the stunt of hacking a mainframe from a dial-up,
	    which often requires great patience, a brute-force approach
	    or some technical skill as substitute, from teenagers to
	    middle-age men, anyone with a PC and a modem can dig up a BBS
	    devoted to virus code in almost no time.  Yes, they are that
	    common.

	    Why should this be?  Where have all those live viruses come from?
	    Paradoxically, many of the virus files on these BBS's bear the
	    electronic mark of software developers like Certus
	    International, S&S International and security organizations
	    such as the National Computer Security Association.
	    Damn.  How DO "relative amateurs" get ahold of
	    those samples? Of course, they could all be forgeries,
	    the work of some dangerous psychopath. Yeah, right.

	In any case, the only people who can't access the hacker
	files anymore are the security people. And the real story
	may boil down to what I call the "You dunno this information,
	it's too dangerous and and you don't have any business
	knowing about viruses and hacker files so leave it to us
	anonymous security experts and anti-virus researchers
	because we're here to serve and protect and we'll
	take care of all that stuff, thank you" explanation.
	It is the very essence of professional arrogance
	and hubris, in my estimation.

	There is, obviously, much more which should have been addressed
	by the mainstream media.  Why hasn't it, then?  Because it's
	not as sexy a story as the visceral blurt of noble civil servant
	whistleblowers bringing down a renegade government security
	BBS pursuing new ways to pervert the public trust out on the
	rim of cyberspace. And it would take time; it's a story that
	couldn't be researched and rushed into print in a week. It's
	complex, you see, and would be a great deal longer than the
	piece which ran in America's finest newspaper, The Washington
	Post.  So maybe we should all forget about fairness,
	because if it can't get into print at The Post, where will it?

	I hope Kim can continue her fine work and I'm angry at the
	stupid treatment this controversy has received at the hands
	of the newsmedia, so I'm writing to you about it because if
	I don't, I just might have to scream.






















