Vulnerability Development mailing list archives

Re: Civil Disobedience


From: Craig Van Tassle <craig () amborsa dns2go com>
Date: Mon, 15 Oct 2001 13:13:37 -0500

On Mon, Oct 15, 2001 at 12:56:56PM -0400, Ethan Zimmer wrote:
John Thornton wrote:

( Moderator: Please pass this though Blue Boar. Please just allow this
thread even if it is just for a day )

In case you have been living under a rock the past few weeks. You should
know that our civil liberties are under attack. Kevin Poulsen wrote:
"Hackers, virus-writers and web site defacers would face life imprisonment
without the possibility of parole under legislation proposed by the Bush
Administration that would classify most computer crimes as acts of
terrorism."
( http://www.securityfocus.com/news/257, Hackers face life imprisonment
under 'Anti-Terrorism' Act). When you read the news this morning you will
see that this bill was passed by the Senate.
(http://www.securityfocus.com/news/265, Senate passes terror bill).

I will say that most of the readers of this news group are not hackers but
Network Administrators that are very involved with the Security Community.
That is why I am asking you, not to report minor scans against your network
to the abuse department of any ISP if this bill becomes law.

I as a Network Administrator for many years now have been on a routine to
check my logs for scans against my network every morning and send the logs
of attacks to the abuse department of the ISP. I encourage every Network
I can't begin to count the number of times that visitors to our site,
whom just got that spiffy new firewall on their windows box, have
emailed me, cc'd to the FBI, our upstream, and anyone else they can
think of claiming our servers were "breaking into" their machine.  Every
single time this was a web application using a port other then 80. 
These go 100% of the time unanswered by anyone but me explaining that
they were just contacting us and the traffic is benign.  I can't imagine
what the future will bring with these proposed new laws.  Any newbie
with a firewall that suspects something is going to become a terrorist
spotter.

Quite scary.  

-- 
Ethan Zimmer - ezimmer () livewave tv   
Director of Research and Development
LiveWave, Inc.
As a newbie to computer and firewall security I agree with that.  Ive seen several attempt connects to my computer on 
various wierd ports.  Being new to computer security i have looked into these "attacks" and have not been able to find 
out what the are doing.  But it has not affected me an any way so untill i can find out if there "attacks" are of a 
evil intent its my responsibality to not report them for "hacking".  This new law scares me as well.  If just 
portscanning someone will make you a "hacker/terrorist" what about the legitimate useage of programs like satan, nmap 
and cops?  With the way the government has been watching people in the past (ie with out warrants)  what will stop them 
form just expanding there power to a case like "enemy of the state".  This bill truly scares me and hopefully someone 
will be able to explaing to the politions in congress what a computer is and why the proposed bill is not the answer.  
Perhaps a letter writing campaign would be a better response to this.
this scares the hell out of me.
Craig


Current thread: