funsec mailing list archives

Re[2]: Is The .WMF Exploit A ConsPiracy Gone Bad?


From: Pierre Vandevenne <pierre () datarescue com>
Date: Fri, 13 Jan 2006 18:43:59 +0100

Good Day,

DK>   Curious, if after you listen to how explicit this works, how you
DK> will feel then?

Just a thought, indirectly related to the issue.

Before 2000, the law enforcement/governmental agencies I had the
opportunity to interact with struck me as being dumb, really dumb, as
far the the reality of IT security was concerned - they were lost in
strangely colored books, norms etc.... and didn't understand much to
what was actually going on (this is not an attack on the individuals,
just an appreciation of the finished product as an organization). A
random pair of decent hackers could have danced around them in those
days, and some actually did.

The tide turned in the 2000-2003 period imho, probably because such
organizations are a bit slow to react, because the younger generation
who had a better grasp of the issues was obtaining positions where
they could actually get things moving. I do not know.

Today, I would rate the people working in those organizations as
generally much better than the hacker's crowd. There are a lot of
them, at least in the countries who care and... they are simply more
competent. Therefore I believe they could do much better than that if they
wanted.

And there is of course the IT's version of Occam's proposition: don't
see sophisticated malice where incompetence/oversight can explain the
situation. 

Lastly, if that conspiration theory was true after all, would that mean
that the open source windows "cloners" who replicated the mistake have
sold their souls as well, just more recently?

-- 
Best regards,
 Pierre                            mailto:pierre () datarescue com

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: