Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

FBI Changes Advice for Windows Users
The Associated Press ^ | January 3, 2002 | By The Associated Press

Posted on 01/03/2002 9:37:53 AM PST by 68skylark

WASHINGTON (AP) -- The FBI has reversed its advice for computer users trying to protect themselves against serious flaws in the latest version of Windows: Applying the free fix from Microsoft Corp. (news/quote) is adequate, after all.

The bureau's top cyber-security unit, the National Infrastructure Protection Center, told consumers and companies Thursday to disregard its earlier advice to go beyond the Microsoft recommendations to protect against hackers who might try to attack Windows computers.

The FBI said it based its latest determination ``upon a careful review of the written technical materials provided by Microsoft'' and after working with the federally funded CERT Coordination Center, who are researchers at Carnegie Mellon University.

Microsoft said last month that Windows XP suffers from serious problems that allow hackers to steal or destroy a victim's data files across the Internet or implant rogue computer software. The glitches were unusually serious because they allow hackers to seize control of all Windows XP operating system software without requiring a computer user to do anything except connect to the Internet.

The problem also affects some copies of earlier Windows ME software, and in some rare cases can affect users of Windows 98.

Microsoft offered a free fix on its Web site the day the vulnerability was announced. But one day later, on Dec. 21, the FBI urged consumers and corporations to go beyond installing that fix and to disable the Windows ``universal plug and play'' features affected by the glitches.

However, even those warnings came under fire by experts as inaccurate. The steps outlined by the FBI failed to instruct consumers also to turn off in Windows an important, related feature -- called a ``discovery service'' -- that still left computers vulnerable.

``They made an honest mistake, gave the wrong information,'' said Richard M. Smith, an independent security expert in Brookline, Mass. ``All this stuff is so complicated. It shows that even the experts can't keep track of it.''

At the time, the FBI said its recommendation to shut down the vulnerable Windows features was based on ``technical discussions with Microsoft and other partners in the Internet and information-security community.''

Outside experts have cautioned that disabling the affected Windows XP features threatens to render unusable an entire category of high-tech devices about to go on the market, such as a new class of printers that are easier to set up. But they also said that disabling it could afford some protection against similar flaws discovered in the future.

After its first warning, the FBI's cyber-security unit published an Internet link to the Web site for eEye Digital Security Inc., which discovered the Windows flaws. eEye's advisory, published on its Web site, also urged consumers to install Microsoft's fix and cautioned that ``it would be wise'' to turn off the vulnerable features completely.

The FBI acknowledged Thursday that neither it nor security experts at CERT had independently tested Microsoft's repair solution. But the FBI said, ``We are satisfied that it corrects the problem that could lead to system compromise and affords substantial and adequate protection.''


TOPICS: News/Current Events
KEYWORDS: computersecurityin

1 posted on 01/03/2002 9:37:57 AM PST by 68skylark
[ Post Reply | Private Reply | View Replies]

To: 68skylark
Does this mean that P-n-P is a "GO" or a "No-Go?"
2 posted on 01/03/2002 9:44:19 AM PST by Woodman
[ Post Reply | Private Reply | To 1 | View Replies]

To: 68skylark
Hooray for Microsoft on this one!
3 posted on 01/03/2002 9:46:56 AM PST by bvw
[ Post Reply | Private Reply | To 1 | View Replies]

To: 68skylark
``We are satisfied that it corrects the problem that could lead to system compromise and affords substantial and adequate protection.''

In other words, we can still get in.

4 posted on 01/03/2002 9:53:25 AM PST by battlecry
[ Post Reply | Private Reply | To 1 | View Replies]

To: bvw
R I G H T . . . They sat on the flaw for a MONTH and had legal threats in
place if anyone let let it be known

All the while claiming Windows XP was the most secure OS ever!

5 posted on 01/03/2002 10:00:05 AM PST by chilepepper
[ Post Reply | Private Reply | To 3 | View Replies]

To: 68skylark
As I said at the time, anyone who relies on the FBI for technical advice about computers should have his head examined.

As for the much-ballyhooed FBI spying program, that is pretty certain to be unworkable. Hackers will soon duplicate it, and unless the Antivirus makers are allowed to block it, there will be total chaos. Time for the FBI to get back to doing what it does best--advancing their careers in the federal bureaucracy.

As a rule, the FBI only shoots or burns innocent dogs, kids, and women or loses x-rays from locked safes when that's the kind of thing the administration promotes them for. Now that clinton and Reno are gone, there should be less of it.

6 posted on 01/03/2002 10:03:48 AM PST by Cicero
[ Post Reply | Private Reply | To 1 | View Replies]

To: Cicero
As for the much-ballyhooed FBI spying program, that is pretty certain to be unworkable. Hackers will soon duplicate it.

Soon? More like the FBI duplicated a hacker program. Keyloggers (essentially what this whole Magic Lantern thing is) have been around for years.
7 posted on 01/03/2002 11:04:43 AM PST by FreedomIsSimple
[ Post Reply | Private Reply | To 6 | View Replies]

To: 68skylark
Some necessary tools for XP users

Click here

And here

8 posted on 01/04/2002 4:27:28 AM PST by webster
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #9 Removed by Moderator

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson