Great Circle Associates List-Managers
(February 2003)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Spam vs. viruses
From: Rich Kulawiec <rsk @ gsp . org>
Date: Mon, 24 Feb 2003 12:35:12 -0500
To: list-managers @ greatcircle . com
In-reply-to: <7307 . 1046053977 @ kanga . nu>
References: <3E583DD9 . 8030705 @ vo . cnchost . com> <5 . 2 . 0 . 9 . 2 . 20030223134226 . 00b6c668 @ pop . earthlink . net> <20030223215658 . GA26615 @ gsp . org> <3E594958 . 9050807 @ queernet . org> <20030224021105 . GA4073 @ gsp . org> <7307 . 1046053977 @ kanga . nu>
User-agent: Mutt/1.4i

On Sun, Feb 23, 2003 at 06:32:57PM -0800, J C Lawrence wrote:
> Which ignores the point.  Such viral operations require large
> monoculture populations to be created, and to survive, and further, no
> matter what happens with OS popularity the power curve laws define that
> one will be overwhelmingly popular and thus a ready host and market for
> such attacks and exploits.

Granted.

But if that's the case, why haven't we seen another sendmail-transmitted
virus/worm in the ensuing 15 years?   From roughly 1988 to roughly 1998,
it approached a monoculture -- and although postfix/exim/et.al. have changed
that since, it still moves a big chunk of the 'net's mail.

Similar comments could be about, oh, BIND and Apache, which occupy big
chunks of their software space.

And yeah, we see attacks against all of them, and occasionally exploits,
but none of them have been anything like the Morris worm or the much
more recent MS SQL worm.  (Could that change tomorrow?  Sure.)

(Interesting question: are there more instances of sendmail or MS SQL
reachable from the Internet?  I have no idea what the answer to this is.)

I'm not disagreeing about monocultures: I've read enough S.J. Gould
to get the point. ;-)   But I'm not convinced that all monocultures
are equally susceptible.  I suppose that's hard to quantify, though,
even after-the-fact.

---Rsk

Please do not CC me on copies of messages sent to this list.


Follow-Ups:
References:
Indexed By Date Previous: Re: PLEASE DO NOT CC ME ON MESSAGES TO THIS LIST
From: Charlie Summers <charlie @ lofcom . com>
Next: Re: PLEASE DO NOT CC ME ON MESSAGES TO THIS LIST
From: Chuq Von Rospach <chuqui @ plaidworks . com>
Indexed By Thread Previous: Re: Spam vs. viruses
From: J C Lawrence <claw @ kanga . nu>
Next: Re: Spam vs. viruses
From: J C Lawrence <claw @ kanga . nu>

Google
 
Search Internet Search www.greatcircle.com