<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:,2009:/1/tag:www.readwriteweb.com,2008://1.12685-</id>
  <updated>2009-11-23T18:02:03Z</updated>
  <title>Comments for DoD Protects U.S. but Who Protects the DoD?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.23-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12685</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=12685" title="DoD Protects U.S. but Who Protects the DoD?" />
    <published>2008-11-22T20:39:28Z</published>
    <updated>2008-11-22T21:03:59Z</updated>
    <title>DoD Protects U.S. but Who Protects the DoD?</title>
    <summary>A rapidly spreading network worm, known as Agent BTZ, has prompted the U.S. army to put the use of USB drives and all removable data storage devices on hold temporarily, according to Wired&apos;s Noah Shachtman. Given the worm is based on SillyFDC, which has been around for several years and has a low risk factor,...</summary>
    <author>
      <name>Lidija Davis</name>
      
    </author>
    
    <category term="News" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="DoD_nov_08.jpg" src="http://www.readwriteweb.com/DoD_nov_08.jpg" width="141" height="141" class="mt-image-center" style="text-align: center; display: block; margin: 0 auto 20px;" /></span>A rapidly spreading network worm, known as Agent BTZ, has prompted the U.S. army to put the use of USB drives and all removable data storage devices on hold temporarily, according to <a href="http://blog.wired.com/defense/2008/11/army-bans-usb-d.html">Wired's Noah Shachtman</a>.<br />
 <br />
Given the worm is based on <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-071111-0646-99&tabid=2">SillyFDC</a>, which has been around for several years and has a low risk factor, the question has to be asked: is this over-kill by the Defense Department?</p>]]>
      <![CDATA[<p>According to the report, Agent BTZ spreads by copying itself to USB drives and the like, so that when the drive is inserted into another computer, the worm replicates in a never ending cycle - every time a new drive is detected.</p>

<p>USB drives, as well as all removable storage devices, can run a program automatically on your machine based on the computer's configuration.</p>

<p>While Autorun is featured in Windows OS as a convenience, <strong>you do have the option of disabling it</strong>, particularly as an unfortunate side effect can be the loading and executing of programs on your PC without your knowledge.</p>

<h2>Autorun and AutoPlay</h2>

<p>There seems to be a little confusion about the differences between AutoPlay and Autorun so we've defined them here:</p>

<p><strong>AutoPlay</strong></p>

<p>AutoPlay is a Windows feature that lets you choose which program to use to start different kinds of media. You can change AutoPlay settings for each media type.</p>

<p><strong>Autorun</strong></p>

<p>Autorun is a technology used to start any program automatically when you insert various media into your computer. While different from AutoPlay, the result is typically the same: when inserted, a specific program on the external device runs automatically.</p>

<p>While you cannot modify the Autorun.inf file on the external device you plug into your machine, you can stop it from executing on your computer by modifying your registry.</p>

<p>To modify the registry setting, Microsoft has set up a page to help you determine which updates you will need, and then offers step by step instructions on how to disable Autorun.  You can find it <a href="http://support.microsoft.com/kb/953252/en-us?spid=11737&sid=353">here</a>. </p>

<p>Even though disabling of Autorun seems a relatively painless process, clearly it isn't enough to soothe the Defense Department or security experts.</p>

<p>Shachtman, in his Wired article asked Ryan Olson, director of rapid response for iDefense whether banning external devices was "a bit of over-kill," and received the answer "I don't know." Although, Olson did offer: "The USB ban <em>should</em> be effective in stopping the worm."</p>

<p>Perhaps the Defense Department should have taken its lead from what has been drummed into home computer users over the years; that is, <a href="http://www.us-cert.gov/current/#malicious_code_spreading_through_usb">use anti-virus software and keep your definitions up to date</a>.</p>

<p>What do you think?</p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12685-comment:117619</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12685" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php#c117619" />
    <title>Comment from HeyHey on 2008-11-22</title>
    <author>
        <name>HeyHey</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>1st! </p>

<p></p>

<p><br />
We don't need this anymore we have Obama</p>]]>
    </content>
    <published>2008-11-22T22:57:10Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12685-comment:117701</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12685" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php#c117701" />
    <title>Comment from mirc hazır kod on 2008-11-24</title>
    <author>
        <name>mirc hazır kod</name>
        <uri>http://mirc.nsohbet.com/tr/mirc-hazir-kodlar</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://mirc.nsohbet.com/tr/mirc-hazir-kodlar">
        <![CDATA[<p>thanks </p>]]>
    </content>
    <published>2008-11-24T10:55:40Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12685-comment:117705</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12685" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php#c117705" />
    <title>Comment from nsohbet script on 2008-11-24</title>
    <author>
        <name>nsohbet script</name>
        <uri>http://mirc.nsohbet.com/tr/nsohbet_script</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://mirc.nsohbet.com/tr/nsohbet_script">
        <![CDATA[<p>thanks this raports</p>]]>
    </content>
    <published>2008-11-24T11:03:20Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12685-comment:117820</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12685" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php#c117820" />
    <title>Comment from michael.chelen.myopenid.com on 2008-11-24</title>
    <author>
        <name>michael.chelen.myopenid.com</name>
        <uri>http://friendfeed.com/ffs</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/ffs">
        <![CDATA[<p>It is not an overreaction, but it is somewhat misguided. Portable drives may be the current method of infection, but the problem is deeper.<br />
Insecure operating systems that lack antivirus protection need to be fixed, and until that happens banning USB media is just a band-aid.</p>]]>
    </content>
    <published>2008-11-24T15:52:10Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12685-comment:117833</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12685" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php#c117833" />
    <title>Comment from Robert Haas on 2008-11-24</title>
    <author>
        <name>Robert Haas</name>
        <uri>http://friendfeed.com/rchaas</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/rchaas">
        <![CDATA[<p>That's why I've been working overtime applying updates to computers which for some reason aren't accepting virus updates remotely. The writer assumes the DoD isn't doing what it is already doing.</p>]]>
    </content>
    <published>2008-11-24T16:55:38Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12685-comment:117850</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12685" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php#c117850" />
    <title>Comment from Mike Chelen on 2008-11-24</title>
    <author>
        <name>Mike Chelen</name>
        <uri>http://friendfeed.com/ffs</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/ffs">
        <![CDATA[<p>Getting software installed still takes time and effort, but in the end your system is more secure, and could detect a virus from a CD or email or any other source. What antivirus package do you recommend?</p>]]>
    </content>
    <published>2008-11-24T19:09:48Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2008://1.12685-comment:118110</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2008://1.12685" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/dod_protects_us_but_who_protec.php#c118110" />
    <title>Comment from Pat on 2008-11-25</title>
    <author>
        <name>Pat</name>
        <uri>http://www.sworddance.com/blog</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.sworddance.com/blog">
        <![CDATA[<p>How about just not using Windows?</p>

<p>Solves the problem instantly!</p>]]>
    </content>
    <published>2008-11-25T18:42:31Z</published>
  </entry>

</feed>