Firewall Wizards mailing list archives

Re: Recent Attacks


From: Ryan Russell <ryan () securityfocus com>
Date: Wed, 16 Feb 2000 13:39:21 -0800 (PST)


You mean Mitnick?  

Yes.

As far as I can see, the figures that were thrown 
around supposedly putting a price tag on the 'damage' he did were
pure unfounded fantasy.

Yes!

As is the 1.2B dollar amount for a few hours each for several e-commernce
companies.

It's not (IMO) fair to try to charge for potential lost customers.
There's no way to tell exactly how much business would have been done,
whether the customers came back later to buy the same item, etc..

One of the few things that is fair to charge for damages in such cases is
investigation time.  If the witch hunt continues for a few more weeks are
the current levels, we might burn 1.2B.

One of the many things that needs to be fixed with the current security
situation is that we don't have a fair, or even agreeed upon, way to tally
damages.

                                Ryan



Current thread: