[news.sysadmin] Viral lawsuits

weemba@garnet.berkeley.edu (Obnoxious Math Grad Student) (11/08/88)

In article <5331@medusa.cs.purdue.edu>, spaf@cs (Gene Spafford) writes:
>In article <16600@agate.BERKELEY.EDU> weemba@garnet.berkeley.edu (Obnoxious Math Grad Student) writes:
>>In article <12081@dscatl.UUCP>, lindsay@dscatl (Lindsay Cleveland) writes:
>>>					       a class-action suit against
>>>the fellow to recover damages.

>>Well gee.  Divide $10K say by 10K computers say, and they each win $1.

>				      It also misses the fact that such
>a class action suit could be filed for millions, not $10K.

Huh?  Aren't they all?  But the question is, is RTM *worth* millions?

>							     I suspect
>that Sun Microsystems will expend a few $100K on this -- not only to
>eradicate the worm in their internal network, but they will have the
>expense of FedEx'ing copies of patches to all their sites under
>maintenance.  DEC will have similar costs.  Then there is BBN and....

NOW they spend the money?  I think a few megabucks a year in serious
security defensive hacking would be a small investment for these com-
panies.  AND GET THE WORD OUT.

>Get the idea?  This was not a small-time problem.  The losses could
>amount to millions.

Get the idea?  THIS is not a small-time problem.  The real losses could
amount to BILLIONS.  Quit worrying about the exact pocket change now, or
you might not have a pocket tomorrow.

>		      I would not be surprised if Cornell was named
>as a part to such suits, and maybe even AT&T.  Lawyers like
>to name everybody that has deep pockets and might be partially at
>fault.

Yup.  That way their friends who work for the other side will remember
them and do the favor of naming their clients in some other suit.  Keeps
the money flowing.  The bigger the better.

>        Morris may not be able to pay a judgment that large,
>but he may not be the only one sued.

Gee.  Why doesn't everyone on the net just sue everyone else?  Berkeley
sues Harvard as soon as they track down the initial UCB infection to a
Harvard source, Harvard sues MIT, MIT sues Purdue, and Purdue fires you
and half a dozen others without severance pay for ought-to-have-known
about the sendmail bug but didn't (or worse, did know, but didn't fix it
for the convenience).  Now just multiply this a thousandfold, and you've
got a real lovely picture of the future of the ARPANET:

    [garnet]% ftp cs.purdue.edu
    Connected to purdue.edu.
    220 arthur.cs.purdue.edu FTP server ($Header: /u1/trinkle/tmp/ftpd/RCS/ftpd.c,v 2.2 87/09/24 00:00:00 root Dist $) ready.
    Name (purdue.edu:): anonymous
    Password (purdue.edu:anonymous): guest
    Law firm (purdue.edu:suitsRus): ?????

Fun, ain't it?  Just a little bit more typing.  Unless, of course, your
.rlawyer file is in place....  This whole sue-everybody scheme reminds me
of a fellow named Timbo Maroney.

>>Yup, good show there.  I hope you're not smugly counting on the next rogue
>>code to be so easy to notice and eliminate by some of my fellow Berkeley
>>grad students?  DO SOMETHING **NOW** TO PROTECT YOURSELVES!  WAKE UP FOLKS!

>It is nice to take pride in your fellow Berkeley-oids, but you are
>insulting the professional staff and students at other locations where
>the worm was cracked.

I'm sorry you felt insulted on the behalf of so many.  I hope it wasn't
too whelming an experience.

>		        The folks at MIT did a lot of work with the
>folks at Berkeley, for instance.  Here at Purdue we had a fix in place
>before the ones were published from Berkeley.  So it goes at many other
>locations.

Translation: ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ......................

Don't be so bloody literal-minded.  WAKE UP!

So you're ALL heroes for the day.  Congratulations!  (Feel better?)  Your
laurels won't do you much good when the real nasties come along.  WAKE UP!

ucbvax!garnet!weemba	Matthew P Wiener/Brahms Gang/Berkeley CA 94720