| Russian Magazine / Net-culture / Seine www.russ.ru/netcult/nevod/20000215.html |
| Seine. Issue 62. Nastic Gryzunova Publication date: February 15, 2000 Review of current online events and publications |
This past week, the media has demonstrated its ability to engage in professional analysis and professional hysteria, with a series of attacks on Yahoo!, eBay, Amazon.com, CNN, Buy.Com, E*Trade, ZDNet and Datek Online Holdings. . Perhaps the only resonance comparable in scale was caused at one time by the Melissa virus, and then by the legal pirouettes of Microsoft.
As always, when global events happen that we are unable to hide or ignore, we had to draw conclusions from them. These conclusions are not exactly depressing, however, they are not very pleasant, like any phenomenon discovered a hundred years ago, which we only encountered today: theoretically, they seemed to know that everything was exactly like this, but somehow they did not imagine that it would actually manifest itself. So, conclusions.
Firstly, things are looking very bad with computer security. This is not at all a revelation either for experts or for the general public, but to receive a three-day cyber-terrorism for this long-known reason was quite unpleasant. However, some experts argue that the low level of development of means of protecting computer systems is a natural thing, because computer security technologies in their development do not keep pace with the development of Internet technologies in general. That is, there is much more that makes sense to protect than there are means of protection. Very logical.
Secondly, large secure systems, in cases where we are not talking about direct hacker attacks, but about attacks such as we saw last week - a denial-of-service attack occurs in two stages: first, the hacker hacks arbitrary computers and implants a “Trojan” on them, then these arbitrary computers go crazy at the appointed hour and begin to bombard a certain server with megabytes of requests, and even if the server was protected at least three times, it would most likely be paralyzed under this avalanche - and so, in In the event of this type of attack, large systems depend on the level of security of small ones. This means that the chance of being slightly crippled remains with any system, regardless of the professional qualities of its system administrators, but in direct proportion to the professional qualities of the system administrators of thirty million other systems. In general, a bleak picture, similar to the patterns of functioning of ecosystems in general.
Thirdly, it turns out that ensuring computer security is a universal responsibility, but ensuring its universal implementation is almost impossible. CERT is already trying. There's little point.
The only ones who received minimal benefit from all this cyber-war bedlam were companies professionally involved in computer security: their shares on Wall Street jumped quite seriously. In addition, Clinton, who is rushing around with his plan to strengthen the security of American computer systems, has received another - and quite convincing - argument in favor of accepting this plan.
The authorship of the attack has not yet been clarified. This is not to say that the FBI is very optimistic about catching hackers. However, it was possible to find out some things: for example, it was discovered that, among other things, computers from the universities of Santa Barbara and Stanford took part in the attacks - however, these are only two machines out of several dozen. According to the latest information, the perpetrators of this entire celebration should be sought in Germany - which is what the FBI is doing.
Since in the first days after the attacks law enforcement agencies only shrugged their shoulders in confusion, the media, in search of at least some clarification, preferred to communicate with the hackers themselves. Those, naturally, also could not report anything concrete; however, the online underground unanimously ruled that the attacks were the work of some idiots (“ It could be virtually anyone. Except for non-jerks. You have to be a jerk to pull this kind of stunt ,” wrote Richard Brandt in Upside Today ). The software required to organize a denial-of-service attack is published on many sites. No special knowledge is required for such an attack (however, representatives of Yahoo! claim that the hackers had a good understanding of the structure of their system, and, therefore, are not entirely amateurs). Most observers are somewhat embarrassed by the fact that no one has yet taken responsibility for what happened - this is not very typical behavior for the hacker community (on the other hand, a prison sentence of 5-10 years and a fine of 250 thousand dollars is a bad incentive for declassification). Brian Martin, a representative of Attrition.org, said on Thursday that he had received a letter with details of the attack, but Martin was not sure that the author of the letter was the author of the attack.
As presented by the creators of Music.Ru, the plot looked like this. After two and a half years of existence as a low-budget project with all the wonderful features that come with this status, Music.Ru found investors in the Port.Ru company in September 1999. Under the terms of the deal, Port.Ru bought out the share of Music.Ru that belonged to the Internet provider Rinet, as well as the right to administer the music.ru domain; subsequently, Port.Ru was to become the owner of a controlling stake in Music.Ru (simply a controlling stake - in the absence of shares - that is, 51% of the cost of the project). In September, Port.Ru bought out its share in Music.Ru from Rinet and received the music.ru domain for administration. After some time (namely, four months), the creators of Music.Ru were asked to work on their project without the participation of Port.Ru. The proposal of Music.Ru and Rinet to resolve the situation by simply playing back and returning the money to Port.Ru did not meet with approval from former investors. Thus, Music.Ru lost investors and the music.ru domain, and Port.Ru lost the Music.Ru project and the money paid to Rinet for its share of the project.
As presented by Port.Ru representatives, the story, of course, looks different. As reported in the official statement of the company in connection with the conflict with the creators of Music.Ru, it is said that Port.Ru refused to cooperate with Pavel Khodakov, since the latter did not fulfill any obligations to Port.Ru, and “ by February 2000, the site remained the same the mothballed state in which it was six months ago, on the eve of the purchase of its shares by our company ."
On February 16, the creators of Music.Ru are holding a press conference in Moscow at the Bunker club, at which they will present a report on their work over the past year. It is promised that the report will be especially informative for the last five months. In general, abandoning senseless attempts to understand who is right, and generally abandoning the intention to resolve such issues, I can only assume that there is some kind of middle line between the official position of Port.Ru and the position of Music.Ru (the latter was very emotionally supported, in in particular, my article in Vesti.Ru). I am not going to look for this middle line, but I guess that it is the real events. Apparently, all participants, as always happens, misunderstood each other.
Chinese powerhouse: ten thousand Chinese in silk shorts ride on an ebony stick.
The head of the Ministry of Communications and Information of the Russian Federation, Leonid Reiman, proposed that the government urgently allocate funds to continue work on the “2000 problem”. According to him, some federal agencies solved the 2000 problem manually, switching systems to manual mode, stopping them, or resetting the system date. Among these ministries, according to Reiman, are the Ministry of Defense, the Ministry of Internal Affairs, the Ministry of Emergency Situations, the Ministry of Justice, the Ministry of Taxes and Duties, the State Customs Committee, the Federal Agency for Government Communications and Information, the Federal Security Service, the Federal Tax Police Service, Federal Security Service, Foreign Intelligence Service, Russian Agency for Control Systems, Ministry of Trade, Ministry of Foreign Affairs and the Judicial Department of the Supreme Court.Should I burst into tears? In Berkeley, psychotherapists organize a group of patients who have become depressed because they prepared so hard for January 1st, and on January 1st nothing happened. The world has already forgotten that it was waiting for the year 2000 as a potential end of the world. Life has improved. Nothing happened. Nobody died. Nothing exploded. And in this idyllic situation, the Ministry of Communications of the Russian Federation again wants money to solve a problem that did not happen a month and a half ago.
Theoretically, I can assume that throughout Russia the “2000 problem” was solved in this way - change the system date from 1999 to 1998, turn off everything and go to bed on the source of spontaneous combustion. But only theoretically. Because if you admit the idea that all the institutions listed by Reiman were preparing for the year 2000 in this way, then you can go crazy with horror. On the other hand, why not admit that all systems of almost all ministries of the entire Russian Federation are supported by such snot.
| | ||