why?
why?
I'm guilty of reading the article
“The encryption was highly successful in obfuscating the attack and avoiding common detection methods,”
One of the malicious programs opened a remote backdoor to the computer, establishing an encrypted covert channel that masqueraded as an SSL connection to avoid detection
And yes, people will learn to break into systems without my help, and yes, openness is the best defense we have against these things. I've just decided I'm just not going to put anything out there that could possibly be used like that.
I tell you one of the reasons why: about twelve years ago, back in the Windows 3/95 days, I got a call from some stock brokers in New York. They wanted to know basically how to spy on their employees.
So I sketched out a system where software would take pictures of their desktops every few seconds -- this was a long time before such software ever existed. I also sketched out several ways you could keep the software from being detected.
I never knew if they wrote the system or what happened to my design, but it never sat well with me. I always wished I could have went back and not provided them with the information.
So now I don't do that anymore.
This is the least favourite part of my job too. I have a couple of uncomfortable memories from university days when I ran my mouth about some little ideas.