CRYPT NEWSLETTER 59
December 1999 -- January 2000

Editor: George Smith, Ph.D.
INTERNET: 70743.1711@compuserve.com
          crypt@sun.soci.niu.edu
http://www.soci.niu.edu/~crypt

Mail to:
Crypt Newsletter
1635 Wagner St.
Pasadena, CA 91106
ph: 626-568-1748


Never has so little been owed to so few by so many.  That's the
conclusion Crypt Newsletter comes to on our national security 
mandarins after a year of "electronic Pearl Harbor" mania.

It speaks poorly of our democratic society when its leadership 
indulges in a year-long campaign of fear-mongering that adds up 
to little more than a brainless hectoring about imminent computer 
terror through the conduit of the media. 

The primary offenders: Richard Clarke of the National Security 
Council, Michael Vatis of the National Infrastructure Protection 
Office, John Hamre of the Pentagon. 

All of these men have worked the media with a relentless barrage of
scare stories. Scare stories about computer viruses coming on New
Year's Day, about hackers turning off the electricity, about foreign 
programmers sneaking boobytraps into software during the dead of night, 
about the Russians, or the Chinese, or the French or the Indians, 
somebody, stealing national security secrets over the Internet. Scare 
stories, however, _never_ backed up by substantive evidence.

It is as if we have relinquished the ability to make even the simplest
of statements: "Show me."

And, as the end of the year approaches, it speaks poorly of a free 
press that has stood by and done nothing to educate the public on the 
issues involved except to pass along the "received wisdoms" of our 
unclothed national security emperors. 

Crypt Newsletter has accumulated an immense archive of the cyber-terror
warnings from our national security leaders as they have appeared over 
the past five years. It is not a pretty sight. In it you 
will find all the hallmarks of a blunt propaganda war: deadening 
repetition, gossip passed off as truth, unseen enemies everywhere, 
irrational paranoia, and a depressing reliance on groupthink. 

It updates weekly. Peruse it at:

http://www.soci.niu.edu/~crypt/other/harbor.htm
=========================================================

THE VIRUS GRINCHES WHO TRIED TO STEAL CHRISTMAS

Late in November, Crypt News preached to a choir of skeptics on a 
private mailing list -- not this one -- when news of the BubbleBoy 
virus surfaced. BubbleBoy mania was kicked off by an Associated Press
story that was the equivalent of an extended press release led by
Network Associates' Vince Gullotto.

No examples of BubbleBoy in circulation accompanied Gullotto's press
junket.

No matter. Since then the world has been destroyed multiple times
by other viruses like MiniZip, MyPics and Babylonia -- all coming
on the wings of copycat press releases generated by anti-virus vendors
wishing to manufacture gratuitous product hype.

At the time, Crypt News reflected that you could contrast the 
anti-virus interaction with the newsmedia with the way the same media 
and the medical community handle influenza reporting.

The media's handling of flu virus reporting is usually fairly
low key. And it stands in stark contrast to the way the computer
virus story is regularly reported.

The anti-virus industry loves to make analogies linking itself
and the real world of infectious disease and viral-caused illness.
So Crypt Newsletter thought it would be instructive to make its
own comparisons.

Influenza kills a significant number of people every year.

Computer viruses, by contrast, never kill people.

And every year, the Centers for Disease Control in Atlanta spends a
great deal of time and effort tracking, isolating and characterizing
new strains of flu it so that the yearly multivalent influenza
vaccine is ready on time.

When the time is right, the media is notified and a number of
reasonably accurate, sober news stories result nationwide in which
flu is explained and the lay populace is informed about who among
them are those most needing of the vaccine -- the very young, the old,
and those with other health problems that would be complicated by
influenza infection.

Unlike news about computer viruses, a blizzard of e-mail and
hysterical news does not result -- even though real influenza viruses
are a great deal more of a menace to society than computer viruses.

The influenza virus is not used as a vehicle for the accumulation
of a windfall amount of naked avarice thinly disguised as free
publicity for the pharmaceutical companies manufacturing the vaccine.
The firms get what they always get for yearly sales of lots of vaccine.
And the news is remarkable for the complete lack of gratuitous hyperbole
from pharmaceutical company marketing execs and "lab directors."
Reporters do not act as proxy fluglemen for those wishing to trumpet
the end of the world unless a specific nostrum is purchased. All
the scientists involved are not in the pocket of vendors interested
in media coverage only insofar as it will mention the name of their
firm.

Why is this?

One reason is ethics. The medical profession has a strong code of
proper conduct with regard to public health issues. Health
professionals know they are in a position of great public trust and
they know that if they abuse it for the sake of cheap publicity,
sooner or later they will suffer negative career consequences at
the hands of their peers.

The anti-virus industry, on the other hand . . . res ipso
loquitur. It has a long and glorious history of cynically
hyping end-of-the-computing-world viruses which, somehow, never
really seem to cause the end of the world of computing.

Datacrime (1989), Michelangelo (1992), Junkie (1994),
Boza -- "the first Windows95 virus" (1995), Hare Krishna (1996);
CIH (1998); CIH again (renamed as Chernobyl so that the same
propaganda on it could be recycled anew in 1999).
The list grows longer depending on how attentive you are to
the 24-hour news services. [Crypt Newsletter would argue that
even the Melissa press coverage was excessive, but that's an
old discussion. If interested in the URL, consult the "Notes"
section.]

It should be noted, of course, that not everyone in the anti-virus
industry is an ethically bankrupt cockroach with too much access
to the PR Newswire.  In fact, quite a few aren't and they tend to be
annoyed by the calculating press campaigns waged by competitors.
However, they don't furnish as good copy as the panderers, so their
influence tends to be extremely muted. [1]

One good example among the realists is Graham Cluley of Sophos, a UK
anti-virus company. During the BubbleBoy hype he commented for the
Daily Telegraph, "Some people are doing the industry a disservice.
There is a problem with hype."

The Telegraph reporter, Robert Uhlig, wrote, "[the paper] received
nine phone calls and 20 press releases warning that BubbleBoy was as
much a threat as Melissa," in a story entitled "BubbleBoy myth burst."

At the time of the furor over BubbleBoy virus, vendor-penned 
electronic press releases going to media e-mail addresses were the 
only real virus-like activities. No actual wild infections had been 
seen at all.

Depressingly, the fact remains that the types of stories like that in
The Telegraph are exceptions rather than the rule. And they are almost
entirely non-existent in the US where the two major anti-virus vendors,
Symantec and Network Associates, have made a cynical game out of
massaging the p.r. line with out-of-context, misleading or deceptive
information.

Days after BubbleBoy hype had run its course, MiniZip, MyPics,
Babylonia and a handful of others, their names hardly mattered,
were rammed into the minsinformation stream.

Ken Bechtel, an independent virus expert for Team Anti-virus
(www.teamanti-virus.org) commented on the avalanche:

". . . I had to do a special alert to an internal mailing list
saying disregard the press releases . . ."

"I can only speculate [but it's a case of] it's the end of year,
let's get our name out there, budgets are opening up in January, and
it's Christmas, so we can kill two birds with one stone:  (1) Gee,
with all these new viruses, let's get Grandma a new up-to-date virus
scanner from Hypes-R-Us and; (2)  Gee, our old license is
about to expire, and it'll soon be a new fiscal year, Paranoid, Inc.
has been making a lot of press releases on new viruses they've
discovered, maybe we should go with them . . ."

Throughout the year, vendors and assorted consultants
have also exploited the end of the Millennium panic with a number
of ludicrous claims.

The most ridiculous of these was attributed to the Norton
Anti-virus' Carey Nachenberg who was attributed in a September
issue of Infoworld magazine with this zinger:

"It's possible that we could see 200,000 viruses around Y2K . . .
We will see a large number of viruses that will do something on
January 1."

The Nachenberg quote subsequently became the object of some
derision by competitors, including Sophos' Graham Cluley who
pooh-poohed it in a company white-paper which examined the
phenomenon of Y2K virus mania, "Is There A Y2K Virus Problem?"
(The short answer was "no.") [2]

More recently, Symantec (maker of the Norton Anti-virus) mouthpiece
Vince Weafer refuted the Infoworld quote, claiming that it was presented
out of context. What the proper context was was not immediately made
clear.

The Gartner Group's Lou Marcoccio was written up in a Reuters
dispatch as claiming: "More than 30,000 threats from computer
hackers and virus writers who say they will release new viruses to
herald the new year and the new millennium have been logged by the
FBI and other law enforcement groups . . ."

While most of the threat would "probably amount to nothing," he
added, that ". . . if just five or ten viruses are released at the
same time, that would overwhelm the ability of . . . companies that
produce the fixes."

Vendor sales pitches attached to Y2K virus alarms even made it
into Beijing China Radio, an English radio broadcast aimed at
North America by the Chinese government.

In mid-December, the station ran a news spot in which
". . . experts pointed out that viruses related to the entrance of
the year 2000 pose a serious threat to computer safety . . .
Furthermore, the number of such viruses is on the rise. They are
programmed to break out together with the Y2K bug, which poses
a double danger."

Ironically, this warning was supplied by the Chinese arm of an 
American firm marketing anti-virus software, Computer Associates.

The Computer Associates "experts" warned "that in the less than 20 days
before the coming of the new century, a minimum of 1,000 viruses will
be released to celebrate, in a very selfish way, the new millennium."

The experts generously suggested that it was time to "invest in the
latest anti-virus software, and [to] keep your fingers crossed."

In any case, claims of looming attack by Y2K viruses have been so
easy to come by, even windbag politicians not normally considered
to be expert on computer viruses have jumped on the bandwagon.

Senator Bob Bennett (R -- Utah), for instance, was quoted in the
December 19 edition of the New York Times claiming, "We are seeing
evidence that some [hackers] will release viruses that will
look like Y2K failures but are not." [3]

The same times article read, ". . . The FBI says that malevolent 
hackers might try to exploit the problem with viruses timed to 
multiply on January 1."

Like the closely-related spew of paranoid propaganda
concerning "electronic Pearl Harbor" and foreign progammers working
to subvert US systems under the cover of Y2K, real evidence that
viruses will make New Year's Day anything other than another 
shopping and bowl-watching day, has not been presented.

However, it is instructive to look at the phenomenon of computer
viruses over the entire decade to see a more realistic picture -- a
picture, of course, that is never supplied by the Bob Bennett's or
the Norton Anti-virus flacks of the world.

For every calendar date you care to mention, there are handfuls of
virus activations.  In fact, it's rare that the run of the mill
virus writer doesn't write an activation into his virus.  The result
has been that every historical or symbolic date reasonably well
known has multiples of viruses written for it.  Any symbolic date
that achieves _any_ measure of recognition generates viruses.

Olympic events, wars, releases of movies by Steven Spielberg,
deaths of rock stars, birthdays of rock stars  -- everything under
the sun is fair game. Indeed, it would only be remarkable if virus
writers _didn't_ generate viruses with activations aimed at the
New Year.

Another fact that must be considered -- and one that has been
conspicuously absent from most media discussions -- is that the
majority of viruses written _never_ make it into circulation.

Depending on who you ask, there are now over 48,000 in anti-virus and
assorted researcher labs. However, only a couple hundred are in active
circulation. And this has been pretty steady through the decade. While
the overall number of viruses created has increased steadily (not
exponentially), the actual pool of those that make it into real world
circulation stays stable at around a couple hundred. As new viruses come
into this pool, older ones tend to be eliminated by use of anti-virus
measures and changes in use and development of technology.

The common mistake in reporting that is made is focusing on the
vendor press releases of a handful of viruses that only _appear_ to
be in circulation.

An assumption is then made that if any more viruses are added to
this already menacing appearing mix, real trouble is on the burner.

Sounds almost reasonable . . . _if_ you've never worked with
computer viruses.

The reality is quite different. An average of over 500 viruses per
month have been being added to most anti-virus products for the last
two years and counting.  So what amounts to a handful, whatever their
names or activations, hardly matters. [4]

[Note: This renders the Y2K virus advice of the Gartner Group's Lou
Marcoccio ludicrous, at best. Marcoccio seemed to be working under the
assumption that anti-virus companies might be swamped if "just five
or ten viruses are released at the same time . . ."]

And while a number of virus reports in the media in the space of a couple
months of the year seem quite remarkable, even a trend, it is not.
In the big picture, they don't constitute anything particularly unusual.
On the contrary, it is the _publicity_ surrounding them that is
quite extraordinary.

A Washington Post story on December 21, was a good case in point.

Government officials, wrote reporters John Schwartz and Ariana Cha,
were watching for "the stealthy attacks of viruses, worms and other
damage-dealing software that already have made their way across the
Internet and corporate computer networks.

"In recent weeks, the warnings have become louder and more fretful."

The story then focused on the handful of viruses previously
noted by their fame-through-press-release: BubbleBoy,
MyPics, Minizip . . .

What it comes down to is this: Viruses are a day-to-day affair.

If one runs a networked computing environment, anti-virus software
must be in place, or a plan to get rid of viruses must exist, for
when they arrive on the scene.  Everyone network sees viruses
sooner or later -- sometimes regularly, sometimes infrequently.

And the viruses particular system administrators see often
*have nothing to do* with what is getting press.

In the short term, Y2K is going to come and go.

Because of the media attention, lots of _normal_ everyday computer
glitches will be attributed to viruses or cyberattacks of some kind.
The news reporting and hysterical know-nothing scaremongering has
created an environment in which it will be easy to claim "A virus ate
my homework" when any human-caused computer mishap occurs and get
away with it.

However, a number of viruses that are already in circulation won't
take New Year's off. Some people will have to remove them if
detected, just like viruses are removed everyday. They will probably
find that they aren't Y2K specific.

And a number of virus-writers will continue to write for the activation
from now until the end of the year. As a group, they tend to be
imitative and happy to get indirect publicity.  But they're not
going to make any difference in the larger picture.

_Additional research for this article was furnished by Rob
Rosenberger of Virus Myths._

Notes:
=======

1. Ethically bankrupt cockroaches. Ahem, yes, while those who
benefit in the American press can certainly be said to be insectile,
others, unpublicized, have been paragons of good sense. The Finnish
anti-virus firm, F-Secure, which handles the well known F-Prot
anti-virus program, released a public memo on December 23 that
read:

"[The company's] research shows no increased activity on the
part of the virus-writing underground in anticipation of the coming
Y2K weekend . . . Many security companies have warned about the
possibility of thousands of Y2K viruses appearing overnight, either
intentionally spread over the new year or spread earlier but
programmed to activate and do damage on or around January 1, 2000.
Yet in actual fact, by the middle of December 1999, just ten
viruses or trojans designed to do damage at New Year 2000 had been
found, and of these only two were found in the wild . . ."

2. http://www.sophos.com/virusinfo/whitepapers/Y2K.html

3. "We are seeing some evidence [that hackers] are releasing
viruses . . ." quoth the Congressman.

The kind of intelligence that leads to this type of quote can
be gathered in less than five minutes from the Internet by anyone
even superficially familiar with the computer virus underground.

Take this example [warts, errors and all], from a clan of virus-writers:
========================
Year 2000 Virus page

I am planning on releasing a year 2000 page full of new viruses.
What does that mean? I want to ask all coders to code a new virus
(or use an unreleased virus of yourself) and send it to:
samples@dvc.zzn.com What will I do with all the viruses? On the
morning of 31 December (Dutch time) I will
post a year 2000 page on my page with all the virii.  What are the
requirements? The only requirement is that the file has to be a
virus/trojan or backdoor. It would be nice if your virus would
have something related to the millenium bug or anything with the
year 2000. Hope you will all join and
if you have any additional comments, post a reply on this message.

Kind regards, The Might

Re: Year 2000 Virus page Tuesday, 30-Nov-1999 05:36:26

Just one more thing. The virus should not be released in any other way
then the year 2000 virus page before the new millenium. This is to
prevent the AV guys for detecting all the codes. But off course, if you
also want to distrubite your virus in another way then the page, I
cant stop you.

Greetings, The Might
==========================

Regardless of what you think of "The Might," it is irresponsible
to take the claims of virus-writing teenagers and present them as
evidence that a terrorist conspiracy is afoot to bring down all
computers in the New Year.

Talk has always been cheap in the virus underground. When
government officials start using it as part of their intelligence
analyses, it is time to reassess the professional acumen of those
providing the analyses.

It should also be noted that when anti-virus companies and others
indulge in campaigns trumpeting viruses of any nature, the news
becomes wish fulfillment.  That is, it stimulates more virus-writers
to produce for their "audience." This is a well-known phenomenon
to those familiar with the virus underground. It is not exclusive
to Y2K.

4. Figure supplied by Nick FitzGerald, editor emeritus of Virus
Bulletin.

5. "How'd I Miss Melissa?" originally appeared in the Wall
Street Journal. http://www.soci.niu.edu/~crypt/other/wsj3.htm .

MORE ELECTRONIC PEARL HARBOR PROPAGANDA

"US Monitors Millennium Trouble Spots Around the World" was the title
of a Tim Weiner penned piece in the December 19 edition of
New York Times.

In keeping with the overkill mania that characterizes
New Year's Eve-as-doomsday reporting, this story ran with the
predictable theme that terrorists everywhere are taking aim at the
US as part of their Year 2000 party itinerary.

And like old Jacob Marley, Richard Clarke, the broken record of the
National Security, was produced to rattle his electronic chains
and howl menacingly for the rubes.

" . . . Richard A. Clarke of the National Security Council,
repeatedly warns them that 'cyberterrorists' could launch computer
attacks 'shutting down a city's electricity, shutting down 911 systems,
shutting down telephone networks and transportation systems,' as he
said in a recent interview," wrote Weiner for the Times.

More accurately, Clarke has been stupefyingly repetitive on the
subject throughout 1999, beginning with another Weiner-written
article in the Times on February 1.

===============

Life is full of delicious irony. On December 7, Pearl Harbor Day,
the Athens Ta Nea published a story entitled "Greek Defense Ministry
Establishes Cyber-Warfare Office."

<P>It was . . . [drum roll] . . . about "electronic Pearl
Harbor"! [Ta-dump!]

Much of the piece, furnished by the CIA's Foreign Broadcast
Information Service, was devoted to the usual stack of confused
and patently ridiculous claims about i-war cobbled together from
assorted American stories on Pentagon info-warriors.

Sub-slugged "Cyber-Soldiers in the Front Line," the Athens Ta Nea
report breathlessly proclaimed:

"The Air Force base in Miami, Florida, is on 'red alert.' The
operation -- an exercise -- involves the dispatch of heavily
armed aircraft to bomb targets in North Korea during a supposed
international crisis. The bomber pilots are waiting, engines ready, for
the air-to-ground missiles to be loaded but an unforeseen event
interrupts the exercise: at the last minute, crew members suddenly notice
that, instead of missiles, all the storage depots are stocked with
electric lighters!"

" . . . Only a few minutes before . . . gigantic transport planes take
off, the crew notices that there is no fuel available!"

"The incident is not pure speculation," wrote the Ta Nea.

"Kept secret at all costs, the complete collapse of the US
Pentagon's supply system occurred recently and was ingeniously
characterized as 'the electronic Pearl Harbor.'"

"The story might sound like Hollywood, but it is no longer a movie
fantasy . . . " wrote the Ta Nea. Greece was said to be spinning up
its own offensive information warfare group within its National
Defense General Staff.

I-war group leader "Dr. Alexandros Polimenopoulos, a special consultant
to the Ministry of Defense, states that [its] soldiers will also be
'experts in the use of computer viruses, logic bombs, worm
programs and other tools, which, used at the critical moment, could
completely destroy the enemy's information infrastructure.'"

A diligent Crypt News reader in the US Air Force drily comments:

"Inform Athens Ta Nea we no longer have a base -- per se -- in Miami.
A hurricane destroyed it.  NONE of the hurricane-proof hangars
survived.  Repair teams resurrected 12-15 buildings for emergency services,
but the rest of the base disappeared in the hurricane or fell to a
wrecking ball.  'Homestead AFB' was renamed 'Homestead ARB': a tiny
little component of the Air Force Reserve."

-------------------------------------------------------------
Acknowledgments: Electronic clippings courtesy of David Isenberg
and Steven Aftergood to whom the Crypt Newsletter is mighty obliged.
-------------------------------------------------------------
George Smith, Ph.D., edits the Crypt Newsletter from Pasadena,
CA.

copyright 1999 Crypt Newsletter. All rights reserved.
 
 