BYTE.com
RSS feed

Newsletter
Free E-mail Newsletter from BYTE.com
Email Address
First Name
Last Name




 
    
             
BYTE.com > Tangled in the Threads > 2000 > July

E-Mail Virus Danger Is An Identity Crisis

By Jon Udell

July 6, 2000

(E-Mail Virus Danger Is An Identity Crisis :  Page 1 of 4 )



In this Article
E-Mail Virus Danger Is An Identity Crisis
Prove Identity With Digital Signature
Client-Side Scripting Isn't Inherently Evil
The Digital-Signature Law
The day the ExploreZip worm hit the Net, I received this unfortunate message:

Hello

You are in my address book and have therefore probably been sent an e-mail "from me" containing a zipped attachment - which I received from [SENDER], [TITLE], [PROMINENT_COMPANY]

DO NOT OPEN THE ZIPPED ATTACHMENT - this is the worm virus on the news.

Simply delete the e-mail.

Sorry

[VICTIM]

Many months later, in the wake of the Love Bug, nothing has changed. The experts interviewed for CNET and National Public Radio are still trotting out the same recommendations:

  • Disable macro languages.

  • Ban attachments in corporate environments.

  • Don't open any attachment you're not "sure" of.

I don't think that scripting and executable attachments are the root of the problem. Identity theft is. These worms, while clever, are more socially than technically adept. A victim is attacked by a message that seems to come from an acquaintance, perhaps even in response to a message just sent to that acquaintance. In reality, of course, the poisoned message comes from a trusted person's machine, but not from that trusted person.

I do most of my business, and you probably do a lot of yours, through e-mail, represented by nothing more than an e-mail address. Everybody knows it's easy to forge an e-mail address. The latest round of e-mail hacks has shown that it's also far too easy to hijack somebody's e-mail program and wreak havoc with it.

It baffles me that people who fret about the strength of encryption used to guard their credit cards en route to Amazon.com will, quite happily, transmit reams of unencrypted confidential communication through a whole chain of SMTP e-mail routers. It also baffles me that people don't seem to care much about, or do anything to protect against, identity theft.




 Page 1 of 4 Next page


BYTE.com > Tangled in the Threads > 2000 > July
Dr. Dobb's Media Center
BYTE.com Store

BYTE CD-ROM
NOW, on one CD-ROM, you can instantly access more than 8 years of BYTE.
 
The Best of BYTE: Volume 2 - Heuristic Algorithms
The Best of BYTE: Volume 2 - Heuristic Algorithms
In this volume of Best of BYTE, we explore the emergence of some heuristic algorithms. Although we have only scratched the surface of this intriguing subject, we hope we've suggested the potential of the synthesis of heuristics and algorithms.

© 2008 Think Services, Privacy Policy, Terms of Service, United Business Media Limited
Site comments: webmaster@byte.com
Web Sites: BYTE.com, dotnetjunkies.com, Dr. Dobb's Journal, SD Expo, Sys Admin, sqljunkies.com, Unixreview



MarketPlace
Try Numara FootPrints 9, The ITSM software that Delivers Real Value, Flexibility and Results.
Sign Up & Get Full Access To The Definitive Online Book Collection With SkillSoft's Books24x7�.
Automatically capture customer crash data, no debugger required. Support for .NET, C++, OS X, Java.
One Stop to Buy All Your Business IT Solutions. Browse Through Dell's Best Deals Online Now!
Understand C/C++ code in less time. A new team member ? Inherited legacy code ? Get up to speed faster with Crystal Flow for C/C++. Code-formatting improves readability. Flowcharts are integrated with code browser. Export flowcharts to Visio.
Wanna see your ad here?
 

web2