Security Incidents mailing list archives

Re: Cracked; rootkit - entrapment question?


From: fruitbat () NETSPACE ORG (Eric the Fruitbat)
Date: Fri, 17 Mar 2000 11:44:50 -0500


It really isn't a matter of not being "allowed" to investigate; it's more that
they have great difficulty getting the US Attorney's Office to prosecute cases
where significant monetary damage isn't demonstrated.  You see, once a year they
have to justify their budget requests to Congress. [ ... ]

This may be a little off-topic at this point, but frankly, I'm not sure that
providing the FBI with sufficient resources to investigate every instance of
instrusion is a good idea.  I know that folks in the bureau would love to have
the jurisdiction and the funds to handle it all themselves, and the big
agencies in DC would find it more convenient going through the FBI than
having to deal with locals all the time, but I'm not convinced that
modern computer crime is amenable to monolithic, centralized response.
These days we know that the best way to deal with advances in intrusion
techniques is to have good communication between as many knowledgable
people as possible, and while it would be comforting to know that there's
some single agency which has everything under control, in the US or
otherwise, it seems that neither history nor the current state of the art
offer anything to suggest that such a solution will properly serve its
avowed aims.  We'd all be better served by a plan to broaden the net, as it
were, rather than concentrating it all in one place.

But that's really a matter of policy more than technology.

e

--
 F-PROT cannot remove the virus from this sig.  Overwrite with a "clean" sig?



Current thread: