OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[Dailydave] The Anti-Virus/IDS fantasy world

From: Dave Aitel (dave.aitelgmail.com)
Date: Sat Jun 09 2007 - 12:52:45 CDT


The weblog snippet below shows the attitude I love about the anti-virus and
IDS companies. The "I'm better than you both technically and morally"
fantasy they live in is quite amazing. It's like when people derisively say
"script kiddie" and 100% of the time they mean "someone who's way better at
security than I'll ever be". The reality is that writing malware is
incredibly hard, and the people who do it are amazingly talented.

http://www.sophos.com/security/blog/2007/05/120.html

"""

The fact is, whatever the motivation, writing malware is not 'clever', on
the whole it's not even particularly difficult. Although this particular
author seems to have trouble because the sample we received didn't work.

It takes a lot more skill to identify and remove malware, but in this case,
even that wasn't difficult. So my message to the author is, don't bother,
get a real job, but don't bother applying to join SophosLabs. In fact
judging by the poor quality of what was submitted, I would recommend a
completely different career.

Update 4th June - If anyone other than malware authors want to join
SophosLabs, we're
recruiting<http://www.sophos.com/companyinfo/careers/uk/822857832455.html>

Mark Harris - Director of SophosLabs
"""

-dave

_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave