Telecom and Logistics Associates 

Security NEWs Service: TLAnews

publication: Christian ALT  new6.gif (1031 bytes) TLAalert    Security Service 
Translate this page from:  Save Time and Money 

11.5.2000 SecurityLove bug more to come, U.S. Congress told 
Technical experts warned the U.S. Congress on Wednesday that little could be done to prevent the outbreak of even worse computer viruses than the ``love bug' that wreaked havoc on the Internet last week.

Résumé en français:  Les experts mettent en garde le congrès americain
ce type de virus n'est que le sommet de l'icberg. Le GAO ("General Accounting Office") a dit que le gouvernement est très  mal préparé pour répondre à ce type d'incident.

English version
 

In testimony prepared for the House Science Subcommittee on Technology, several referred to it as a wake-up call to the growing threat from ``hackers'' and others to sensitive data stored on hard drives.

The General Accounting Office (GAO), the investigative and audit arm of Congress, said the U.S. government was poorly organised to respond.

``Our audits continue to find that most (federal) agencies continue to lack the basic management framework to effectively detect, protect against and recover from these attacks,'' said Keith Rhodes, technical director for the chief GAO scientist.

Variants of the ``love bug'' already circulating by e-mail left scant doubt that the next big software scourges would ``propagate faster, do more damage and be more difficult to encounter,'' he testified.

``We still do not know the full effect of this virus on the agencies that were penetrated,'' Rhodes said. He cited reports that at least 14 U.S. federal bureaucracies were hit, including the CIA, National Aeronautics and Space Administration and Department of Energy.

 

Résumé en français
Plus de 14 agences gouvernementales americaines ont été atteintes par le virus, y compris la CIA, la NASA (National Aeronautics and Space Administration) et le Département de l'Energie.

Les experts techniques mettent en garde le congres americains, ce type de virus n'est que le sommet de l'icberg. Le GAO ("General Accounting Office") a dit que le gouvernement est très  mal préparé pour répondre à ce type d'incident.

Commentaire
Il est effarant de constater qu'une vingtaine de lignes de code peuvent mettre en émois toute la planète et faire trembler le gouvernement americain. Il n'y a rien de sophistiqué dans ce code. Nous avions déjà prévenus dans des précédents articles qui remontent à plus d'une année que les techniques des pirates allaient se concentrer sur les postes clients et plus sur les serveurs. Le poste client étant plus vulnérable, souvent échappant aux contrôles de sécurité des administraterus systèmes.

Il faut se poser la question des investissements que nous realisons chaque année pour nos systèmes informatiques et qui sont à la merci de 20 lignes de code écrites en VBscript.

 

 Harris Miller, president of the Information Technology Association of America, a trade group that claims 26,000 direct and affiliate members, said the ``love bug'' can be seen ``as an evolutionary link in the hacking chain.''

``If not addressed in a concerted way, this problem could grow to undermine the global information infrastructure and, ultimately, the Internet economy,'' he said in prepared testimony.

``Consumers will lose confidence in this way of doing business, companies will lose the competitive advantages it creates, investors will seek opportunities elsewhere,'' Miller said.

 

 

 

 

 

Author information.
Copyright © [Telecom and Logistics Associates Sàrl]. All rights reserved.
Revised: mai 11, 2000 .