ZDNet UK


Skip to Main Content

  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Lycos should send its zombie army home

Leader ZDNet.co.uk

Published: 01 Dec 2004 13:25 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

We all hate spammers, and few of us would shed a tear should some unfortunate fate befall them. Our knee-jerk reaction, therefore, is to laud Lycos for developing its screen saver that launches distributed denial-of-service attacks against known spam sites.

After all, says Lycos, it is not a misdemeanour. We are justified. Just look at the harm that spammers do! They're monsters.

To combat them Lycos is raising its own army. You can almost smell the oily smoke from the burning rags as the masses, led by Lycos, advance with burning torches on Boris Karloff. Only this time, the masses are zombie PCs controlled by Lycos' 'Make Love Not Spam' screensaver.

Had Mary Shelley replaced vengeful villagers with randy zombies, the outcome really doesn't bear thinking about. Really it doesn't. Similarly, Lycos' latest wheeze should be dismissed as an absurd publicity stunt at best.

Lycos defends its action by saying that what it is doing is not a denial-of-service attack, but an attack on the bandwidth of the spammers. There may well be some technical truth to this, but the fact is that attacking bandwidth is what, in effect, denial-of-service attacks do.

However bad the crime of the spammers, launching distributed denial-of-service attacks is illegal in many countries. As Steve Linford eloquently pointed out, you can't break into a thief's house just because he breaks into yours. It won't wash in front of the judge.

We're sure that Lycos will have consulted its lawyers before embarking on this adventure, but then the follies of big business never cease to amaze us. This strategy, we have to say, is indeed a folly.

Not only is Lycos in danger of breaking laws, it is in danger of lending credibility to the notion that DDoS attacks are OK if you're the good guy -- which of course you are -- and you're launching it against someone who, well, just deserves it. Regardless of the semantics of whether what Lycos is doing really is a denial-of-service attack, when you attack the bandwidth of one computer on the Internet, you effectively attack the bandwidth of all computers.

The aim of security professionals should be to mitigate denial-of-service attacks, not propagate them. Lycos needs to put its randy zombie army back in its pants and stop being so trigger happy.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
32 out of 65 people found this useful



Company/Topic Alerts

Create a new alert from the list below:



Sentry Posts Blog

The Technological Singularity

Are we approaching a point when machines may wake up and become self or seemingly self aware? Vernor Vinge in 1993 seemed to think so. He refered to this event as the "technological... More

2 comments

Mobile Operating Systems: MOPS At a Gl...

Mobile Operating Systems: At a Glance Author: Eric Everson, Founder MyMobiSafe Since posting my blog exposing the security Google G1 security issue, I have received a few emails... More

Post a comment

Met Police catch test cheats

I saw the funny side of this press release, I can just imagine the two people sitting in the car giving the answers to the questions. Why they had wires running from under the bonnet... More

Post a comment