<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Comments on 12704</title>
	<link>http://www.metafilter.com/12704//</link>
	<description>Comments on MetaFilter post Comments on 12704</description>
	<pubDate>Wed, 28 Nov 2001 18:38:46 -0800</pubDate>
	<lastBuildDate>Wed, 28 Nov 2001 18:38:46 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Post number 12704</title>
		<link>http://www.metafilter.com/12704/</link>	
		<description>In lieu of the &lt;a href=&quot;http://www.metafilter.com/comments.mefi/12590&quot;&gt;Magic Lantern&lt;/a&gt; thread, &lt;a href=&quot;http://www.politechbot.com/p-02851.html&quot;&gt;Symantec will be ignoring the FBI trojan&lt;/a&gt;.  [taken from &lt;a href=&quot;http://slashdot.org/article.pl?sid=01/11/28/173201&amp;mode=nested&amp;threshold=1&quot;&gt;./&lt;/a&gt;]</description>
		<guid isPermaLink="false">post:www.metafilter.com,2001:site.12704</guid>
		<pubDate>Wed, 28 Nov 2001 18:35:04 -0800</pubDate>
		<dc:creator>hobbes</dc:creator>		<category>Symantec</category>		<category>Nortons</category>		<category>FBI</category>		<category>trojan</category>		<category>backdoor</category>		<category>computers</category>		<category>security</category>
	</item>	<item>
		<title>By: hobbes</title>
		<link>http://www.metafilter.com/12704/#181835</link>	
		<description>Hopefully the hacker community will fix this corporate conniving. =&#222;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181835</guid>
		<pubDate>Wed, 28 Nov 2001 18:38:46 -0800</pubDate>
		<dc:creator>hobbes</dc:creator>
	</item>	<item>
		<title>By: jragon</title>
		<link>http://www.metafilter.com/12704/#181838</link>	
		<description>(looking adoringly at G4 running OSX)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181838</guid>
		<pubDate>Wed, 28 Nov 2001 18:44:46 -0800</pubDate>
		<dc:creator>jragon</dc:creator>
	</item>	<item>
		<title>By: phalkin</title>
		<link>http://www.metafilter.com/12704/#181844</link>	
		<description>i reserve a doubt about whether the FBI has the moral scruples to use any such software responsibly.  much less the MPAA.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181844</guid>
		<pubDate>Wed, 28 Nov 2001 18:55:08 -0800</pubDate>
		<dc:creator>phalkin</dc:creator>
	</item>	<item>
		<title>By: danwalker</title>
		<link>http://www.metafilter.com/12704/#181850</link>	
		<description>Dotslash?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181850</guid>
		<pubDate>Wed, 28 Nov 2001 19:11:55 -0800</pubDate>
		<dc:creator>danwalker</dc:creator>
	</item>	<item>
		<title>By: iceberg273</title>
		<link>http://www.metafilter.com/12704/#181854</link>	
		<description>&lt;i&gt;Dotslash?&lt;/i&gt;

&lt;a href=&quot;http://www.dotslash.com/&quot;&gt;Dotslash.&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181854</guid>
		<pubDate>Wed, 28 Nov 2001 19:16:04 -0800</pubDate>
		<dc:creator>iceberg273</dc:creator>
	</item>	<item>
		<title>By: websavvy</title>
		<link>http://www.metafilter.com/12704/#181855</link>	
		<description>Please, /. is so long.  Typos are pretty much inevitable.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181855</guid>
		<pubDate>Wed, 28 Nov 2001 19:19:26 -0800</pubDate>
		<dc:creator>websavvy</dc:creator>
	</item>	<item>
		<title>By: jmd82</title>
		<link>http://www.metafilter.com/12704/#181861</link>	
		<description>MPAA?  i&apos;m more scared about the RIAA...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181861</guid>
		<pubDate>Wed, 28 Nov 2001 19:34:36 -0800</pubDate>
		<dc:creator>jmd82</dc:creator>
	</item>	<item>
		<title>By: yangwar</title>
		<link>http://www.metafilter.com/12704/#181863</link>	
		<description>The article states that Symantec will not detect magic lantern but will detect any variants.  To me, this means that Symantec will go through the trouble of identifying magic lantern but not release it in their virus definition files.  They will purposely ignore it.

What happens when firewall makers start purposely ignoring attempts to broadcast on certain ports?  This is a major, major digital civil liberties issue and I can&apos;t believe that you people are bitching about typos.

Imagine that all new telephones had a recording feature that you couldn&apos;t disable which could be remotely activated by the government and secretly broadcast your conversations.  Now imagine that those telephones have speakerphones which are always on, monitoring everything you say within earshot.  Would you be so carefree then?

Jragon: Do you really think that the FBI will only make a wintel binary of magic lantern?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181863</guid>
		<pubDate>Wed, 28 Nov 2001 19:40:41 -0800</pubDate>
		<dc:creator>yangwar</dc:creator>
	</item>	<item>
		<title>By: rushmc</title>
		<link>http://www.metafilter.com/12704/#181864</link>	
		<description>Anyone know if McAfee is going the same route?  I&apos;m ready to switch today if not....</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181864</guid>
		<pubDate>Wed, 28 Nov 2001 19:41:07 -0800</pubDate>
		<dc:creator>rushmc</dc:creator>
	</item>	<item>
		<title>By: emptyage</title>
		<link>http://www.metafilter.com/12704/#181866</link>	
		<description>&lt;a href=&quot;http://www.politechbot.com/p-02846.html&quot;&gt;Here&apos;s the deal with McAfee&lt;/a&gt;. You decide.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181866</guid>
		<pubDate>Wed, 28 Nov 2001 19:49:02 -0800</pubDate>
		<dc:creator>emptyage</dc:creator>
	</item>	<item>
		<title>By: iceberg273</title>
		<link>http://www.metafilter.com/12704/#181867</link>	
		<description>If the FBI can&apos;t use a trojan horse, they can still &lt;a href=&quot;http://www.businessweek.com/bwdaily/dnflash/aug2001/nf20010823_686.htm&quot;&gt;break into your office&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181867</guid>
		<pubDate>Wed, 28 Nov 2001 19:53:43 -0800</pubDate>
		<dc:creator>iceberg273</dc:creator>
	</item>	<item>
		<title>By: waxpancake</title>
		<link>http://www.metafilter.com/12704/#181873</link>	
		<description>Or they can always use &lt;a href=&quot;http://whatis.techtarget.com/definition/0,,sid9_gci550525,00.html&quot;&gt;van Eck phreaking&lt;/a&gt;, a la &lt;a href=&quot;http://www.eskimo.com/~joelm/tempest.html&quot;&gt;TEMPEST&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181873</guid>
		<pubDate>Wed, 28 Nov 2001 20:12:18 -0800</pubDate>
		<dc:creator>waxpancake</dc:creator>
	</item>	<item>
		<title>By: skallas</title>
		<link>http://www.metafilter.com/12704/#181879</link>	
		<description>So who&apos;s left? Trend Micro&apos;s Pc-cillian is what I use. What a great selling point Trend could make if they went against the big two.  &quot;Even Detects Government Trojans!&quot;

yangwar brings up some great points and I&apos;m pretty skeptical that once magic lantern becomes known to the hacking community the anti-virus people will able to keep up.  Allowing one vulnerability is one too many.  

Scary thought about government ignored packets.  I can almost see the world&apos;s firewall makers getting an FBI bulletin on ignoring suspicious traffic from this IP block because its us hacking your stuff.  

&lt;i&gt;Or they can always use van Eck phreaking, a la TEMPEST.&lt;/i&gt;

Fine. Get a warrant.  Go through my crap, its the blatant security laziness that&apos;s the issue here and the industry&apos;s kowtowing towards it.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181879</guid>
		<pubDate>Wed, 28 Nov 2001 20:49:35 -0800</pubDate>
		<dc:creator>skallas</dc:creator>
	</item>	<item>
		<title>By: StOne</title>
		<link>http://www.metafilter.com/12704/#181887</link>	
		<description>Shades of the Clipper Chip.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181887</guid>
		<pubDate>Wed, 28 Nov 2001 21:29:11 -0800</pubDate>
		<dc:creator>StOne</dc:creator>
	</item>	<item>
		<title>By: clevershark</title>
		<link>http://www.metafilter.com/12704/#181888</link>	
		<description>Somehow I don&apos;t think that users of any UNIX variant who are resourceful enough to run &quot;ps -aux&quot; every once in a while have much to fear from this.

OS X users - learn it, use it, love it.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181888</guid>
		<pubDate>Wed, 28 Nov 2001 21:34:37 -0800</pubDate>
		<dc:creator>clevershark</dc:creator>
	</item>	<item>
		<title>By: Kikkoman</title>
		<link>http://www.metafilter.com/12704/#181892</link>	
		<description>My hope is that foreign anti-virus software makers (anyone have any links?), or open source initiatives such as &lt;a href=&quot;http://www.nessus.org/&quot;&gt;nessus&lt;/a&gt;, or &lt;a href=&quot;http://www.openantivirus.org/&quot;&gt;OpenAntiVirus &lt;/a&gt; will try to counter this threat.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181892</guid>
		<pubDate>Wed, 28 Nov 2001 21:54:53 -0800</pubDate>
		<dc:creator>Kikkoman</dc:creator>
	</item>	<item>
		<title>By: Danelope</title>
		<link>http://www.metafilter.com/12704/#181934</link>	
		<description>&quot;...acquiese to FBI backdoor demands&quot;

So, they&apos;re taking it in the ass, then?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181934</guid>
		<pubDate>Thu, 29 Nov 2001 01:08:47 -0800</pubDate>
		<dc:creator>Danelope</dc:creator>
	</item>	<item>
		<title>By: salmacis</title>
		<link>http://www.metafilter.com/12704/#181947</link>	
		<description>clevershark: Any unix flavour of Magic Lantern will presumably install &quot;new&quot; versions of ls, ps, etc.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181947</guid>
		<pubDate>Thu, 29 Nov 2001 02:19:13 -0800</pubDate>
		<dc:creator>salmacis</dc:creator>
	</item>	<item>
		<title>By: dlewis</title>
		<link>http://www.metafilter.com/12704/#181957</link>	
		<description>My, don&apos;t those intelligence people have a fertile imagination. This is such an obviously unworkable, fantastical scheme that it leads us to one of two conclusions. Either, (1) this is a publicity stunt attempting to show that the government is tech-savvy, or (2) the FBI is full of morons.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181957</guid>
		<pubDate>Thu, 29 Nov 2001 03:45:19 -0800</pubDate>
		<dc:creator>dlewis</dc:creator>
	</item>	<item>
		<title>By: jragon</title>
		<link>http://www.metafilter.com/12704/#181996</link>	
		<description>&lt;i&gt;Jragon: Do you really think that the FBI will only make a wintel binary of magic lantern?&lt;/i&gt;

Couldn&apos;t tell ya.  But I know the chances of them making one for OSX is lower than for Wintel.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-181996</guid>
		<pubDate>Thu, 29 Nov 2001 06:34:35 -0800</pubDate>
		<dc:creator>jragon</dc:creator>
	</item>	<item>
		<title>By: CrayDrygu</title>
		<link>http://www.metafilter.com/12704/#182091</link>	
		<description>&lt;i&gt;&quot;clevershark: Any unix flavour of Magic Lantern will presumably install &quot;new&quot; versions of ls, ps, etc.&quot;&lt;/i&gt;

They&apos;d have to replace a whole slew of other utilities, too, or there would still be a way to find it.  Like this simple way of finding out if any files in /etc (which is where all the startup files are, for the non-linux-users) have been changed, or if anything&apos;s been added:

md5sum `find /etc -type f` &amp;gt; ~/md5sums

Do that right after you install, and you can do it again with a different filename later.  Diff the two files and you&apos;ll see any changes.

They&apos;ve replaced diff, too?  Write a Perl script, and use its filesystem functions.  That doesn&apos;t work?  How about an emergency boot disk with copies of ls, ps, find, and so on?

If you&apos;re serious enough about security on a *nix system, you can find anything.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-182091</guid>
		<pubDate>Thu, 29 Nov 2001 08:33:40 -0800</pubDate>
		<dc:creator>CrayDrygu</dc:creator>
	</item>	<item>
		<title>By: sonofsamiam</title>
		<link>http://www.metafilter.com/12704/#182117</link>	
		<description>Some more comprehensive ways to monitor for replaced files are listed &lt;a href=&quot;http://www.sans.org/infosecFAQ/audit/aide.htm&quot;&gt;here.&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2001:site.12704-182117</guid>
		<pubDate>Thu, 29 Nov 2001 09:05:33 -0800</pubDate>
		<dc:creator>sonofsamiam</dc:creator>
	</item>
	</channel>
</rss>
