Storm Worm botnet cracked wide open
heise-online.co.uk
heise-online.co.uk
We would need some way to verify that our computers were "clean." Without this certificate (or whatever), we wouldn't be allowed access to web pages or http ports. But we would be free to get the cert from any vendor we could.
Even with this method, there is a vulnerability to spoofing the certificate.
The article notes that since the virus was added to the list of malware removed by Microsoft's Malicious Software Removal Tool, the numbers of computers infected by it have shrunk significantly. This suggests that the computers will are still infected are those which are not choosing to apply security updates.
Regardless of whether Microsoft would be "within its rights" to start something like this, it would still be liable for any damage caused to computers which became broken by the cleaning (see the next to last paragraph of the article).
The only threat from this situation would be the botnet evolving in unforeseen ways, thus rendering the code useless. However, the vulnerability described in the article seems not a coded, but rather a conceptual one: even if storm starts to use a new protocol, they -or somebody else using the insights in the source- could repeat the disassembly process, and re-run the cleaning method.
Surely researchers fighting a botnet should be covered under the same logic. The patch they force on 3rd parties should remove windows or force the use of Firefox.
Maybe the people writing botnet apps have the same pressures as legitimate companies, where the "bizdev" guys tells the techies to ship unfinished garbage just to have the next version out the door, and the bugs and security holes be damned. :)