×

Welcome to the Slashdot Beta site -- learn more here. Use the link in the footer or click here to return to the Classic version of Slashdot.

Thank you!

Before you choose to head back to the Classic look of the site, we'd appreciate it if you share your thoughts on the Beta; your feedback is what drives our ongoing development.

Beta is different and we value you taking the time to try it out. Please take a look at the changes we've made in Beta and  learn more about it. Thanks for reading, and for making the site better!

Jane's Intelligence Review Lauds Slashdot Readers as Cyberterrorism Experts

Roblimo posted more than 14 years ago | from the give-yourselves-a-big-pat-on-the-back dept.

The Media 195

Last week the editors of the internationally respected magazine, Jane's Intelligence Review, asked Slashdot readers to preview an article on Cyberterrorism they had planned to run. But so many of you said (rightfully) that the article was lame, and so many of you had intelligent things to say on the subject, that the Jane's editors decided to trash the original piece and write a whole new one based entirely on your comments! And, in an unprecedented act of generosity, Jane's is going to *pay* those of you whose words make it into the final story, which is being written by Deputy Editor Johan J Ingles-le Nobel. Please click on the "Read More" link below to get the whole scoop directly from Jane's - including info on how to collect your money if you are one of the folks Jane's decides to quote.

Open source meets open source

What happens when you throw together open source intelligence (intelligence from non-classified sources) and the online open source movement? Jane's Intelligence Review (JIR), a leading specialist security analysis did just this, and the results were an eye-opener for all parties concerned. Writes Johan J Ingles-le Nobel, JIR Deputy Editor:

When you're confronted with a prospective article about cyberterrorism, as a journalist you know this is a massive emerging topic and that it will make a great story. After all, you've got to be both blind and deaf to have missed the unprecedented emergence of this thing known as the Internet, and that the day will come when, like anything else, it comes to be seen as a tool in the armoury of those that seek to harm and terrorise. Yet the very nature and vocabulary of the subject precludes a thorough understanding unless you're a programmer in the first place. Buffer overflows, denial of service, CGI, 128 bit encryption - such words are all anathma to the layman, yet crucial to a good article on the issue.

"JIR's choice at this point, upon receiving the article, was tough. It's great to get copy from someone you know to be very good on terrorism on this subject, but upon reading the article left me with more questions than answers - and questions that only qualified people could answer properly. I'm not referring to shallow 'such and so defaced a website' type of answers, but thoughtful responses metered with specialist knowledge. So what better way to find answers than to go online, to seek out expertise on the subject?

Unfortunately, finding good information online is not nearly as easy as it should be. Thankfully, months earlier I'd noticed a link to Slashdot posted on a web-hosting service owned by a friend of mine, and having followed the link, bookmarked it a long time ago. Thus, upon receiving the article and personally researching cyberterrorism to find out a bit more on the subject and having been alerted to the fact that a) Linux is the best 'programmer's' o/s environment, b) many webservers use Linux and c) you're looking at expertise in both these areas for sensible answers, there was really no choice but to ask the guys that actually do this stuff for advice.

In retrospect, I'm delighted that I did. 250+ comments and 35 emails from psychologists to network analysts, and from Sun engineers to Cambridge Dons later, The responses have been insightful and knowledgable, with many excellent points made. I've even had a lot of 'thank-you' type letters from computer security professionals for trying this approach. Of course, when you ask for feedback you get feedback - and since roughly 99% of the posters slammed the article, even saying things like 'we'd expect better from Jane's', I've informed the author that we're not going to run with it. Instead I'm going to cull your comments together and make a better, sharper feature out of it - I'll be getting in touch with several of you for more specific details or for more clarification. The article will thus go into December issue (published middle of November), I'll arrange to have it put onto the free section of the Jane's Intelligence Review website (yes, you do all get to see it, of course), and if you find your comments included, contact me at johan.ingles@janes.co.uk for payment at our usual lineage rates (yes, of course you get paid - after all, we are gentlemen).

In summary: wherever you may be and whatever you may do, a big 'thanks, guys' comes your way from just south of London, England.

Johan J Ingles-le Nobel,
Johan.ingles@janes.co.uk,
Jane's Intelligence Review.

cancel ×
This is a preview of your comment

No Comment Title Entered

Anonymous Coward 1 minute ago

No Comment Entered

195 comments

um... (4)

j a w a d (66763) | more than 14 years ago | (#1631230)

For those of you who don't know me, I also work under the name "Anonymous Coward". For all those constructive posts I submitted for the Jane's article, I'm willing to accept the money (that's rightfully mine, of course). :)

Very classy (2)

twit (60210) | more than 14 years ago | (#1631231)

A classy response from what seems like a rather classy guy. Plaudits to Jane's.

--

Respect (2)

Lord Kano (13027) | more than 14 years ago | (#1631232)

Jane's has just gained LOTS of respect from me. This is the responsible thing to do. Instead of allowing some "Journalist" write about what he *thinks* about computer security they are going with people who KNOW what they're talking about.

How many of us have taken part in "Crack this Machine" contests? Granted most of us didn't win, but we all had good ideas about security that needed to be tested.

LK

Re:um... (0)

Anonymous Coward | more than 14 years ago | (#1631233)

alright...you win. funniest thing i've read all morning.

time for bed.

Sheesh (1)

Shanoyu (975) | more than 14 years ago | (#1631234)

It was bad, I hope you didn't have to pay him a Kill Fee (a percentage of what the aurthor would normally have been paid, if the article is 'killed', usually very hard to get.)

It's kind of odd that you're looking to slashdot for this sort of thing about cyber terrorism, I mean theres really not that much of a story behind it and quite frankly I don't see how theres a story here at all, it's like the "cyberwar" between Pakistan and India, it has an effect but it's negligable if one side does anything.


-[ World domination - rains.net ]-

Re:sdfgs (5)

aqua (3874) | more than 14 years ago | (#1631235)

Oh, that should definitely be cited in the article. "The difficulty with intrusion detection is the prospect of compromise to those components of the system necessary to detect the intrusion to begin with," said I.L. Milne, an expert at Purdue University's research center. Added one Slashdot reader on the topic, "First post."

Community Editing/Writing. (5)

Thomas Charron (1485) | more than 14 years ago | (#1631236)

Well, this is an interesting use of the Slashdot Community. We've taken a small step from a 'Feedback' community to actually generating stories. This could actually lead to something interesting..

Perhaps a section of slashdot for proposed stories to be discussed, with actual stories being a summary of comments, etc..

"From the Community, FOR the community"

AC $$$$ (5)

Anonymous Coward | more than 14 years ago | (#1631237)

I would propose that any fees owed to the AC's of slashdot be donated to the FSF

Conclusive Proof (0)

Anonymous Coward | more than 14 years ago | (#1631238)

That people OTHER than script kiddies hang out on Slashdot?

AC Script Kiddie Wannabe (just kidding)

How will this work? (1)

Chalst (57653) | more than 14 years ago | (#1631239)

I am interested to see how they will actually get this article written. Will it be a survey-style article organised by topic (eg. section of the availabe technologies, subsection crypotography discussing the balance of powers between white hats and black hats)?

It might not be a bad idea to put together a web resource of of the quality information available on electronic terrorism and countermeasures.

Well done, Jane's - will we see more of the same? (1)

Mr. Slippery (47854) | more than 14 years ago | (#1631240)

Makes me proud to be a /.er.

I didn't post on the cyberterrorism thread because by the time I got there all my points had already been made. Several times. B-> But congratulations to those who will be quoted in Jane's.

It will be interesting to see if this starts a trend. But on the other hand, they used to say "Go not to the USENET for counsel, for they will say both no, and yes, and `That's already answered in the FAQ, and..." (Or something like that.) And that was pre-AOL, pre-spam, pre-The-September-That-Never-Ended.

But, on the gripping hand (wow, Tolkein and Niven/Pournelle refs in the same post!), /.'s moderation would seem to help the best, most informative posts bubble to the top in such a discussion.

It would be interesting to set up a consulting organization along these lines. Or maybe even use the existing /. infrastructure.

Open source journalism (5)

tolldog (1571) | more than 14 years ago | (#1631241)

I think that this is great. Having been a long time reader of /. I have begun to realize the depth and insight of the other readers/posters.

We are journalists, in a strange twisted way. We report what we know to educate others. Doing it in this sort of fashion, I beleive, is an amazing idea and concept.

I am begining to think that having this be open sourced is even more important than having open source software. Software completes tasks, but it does not shape and form our views on a subject. I t is about time that a place takes recognition of the importance of the community effort. People can not pull the wool over the eyes of many, not without a fight.

May the open source movement migrate into and improve all things.

Slashdot Press, Inc. (3)

interiot (50685) | more than 14 years ago | (#1631242)

This could start a new trend... write articles based completely off responses to an "Ask Slashdot". Hire an editor to put the whole thing together and give part of the profits to the people with the best comments.

Of course, every piece produced would have to have the obligatory yea linux, down with microsoft, anything but open source sucks comments somewhere.

Look how far Slashdot has come (3)

jalewis (85802) | more than 14 years ago | (#1631244)

I think this is a great commentary on how influencial Slashdot is becoming in mainstream media. It has evolved from nerd hang out to the place to see what is on the cutting edge. Something that created the dreaded Slashdot effect produced an article that was written by hundreds of people. The ultimate in bringing ideas together.

The future will only bring more of this type of group editing to the forefront of the media. I look forward to being part of it.

Kudos to Jane's for having the balls to do this and congrats to the REAL experts gettting some recognition.

jas

Can you say 'cred'? (2)

Mija Cat (94021) | more than 14 years ago | (#1631245)

This is an OUTSTANDING feat! Not only did Slashdot get recognition in a (fairly) respected mag, the freely-given replies were judged *better* than those of a professional, paid writer.

If you contributed (I regret I did not) then slap yourself on the back and treat yourself to a beer. Hell of a good job, humans.

A plea (3)

PD (9577) | more than 14 years ago | (#1631246)

Dear Janes,

Now that Slashdot has helped you out, do you suppose you could talk to Electronic Arts and get them to release Janes' Fighter's Anthology and Janes' Israeli Air Force for Linux?

Sincerely,

Patrick Draper - a big fan

Oooops.... missed out the first time around (3)

nitehorse (58425) | more than 14 years ago | (#1631247)

Well, who knows... worth a shot to give my own $.02 about it. However, I seriously do commend the Jane's editor for deciding to do this- using replies from a whole community and putting it into a magazine. Good idea; I personally was thinking of doing the same with the article yesterday about ethical/moral repercussions of euthanizing disabled infants. There was plenty of good discussion and if I was the editor of any magazine (HINT HINT) I would place all of the 2-level comments (or 3, if you're pressed for space) in an article of my mag. Just personal taste though. There was a lot of good discussion yesterday...

About CT, though- the main problem is that the general public at large uses Windows, and by it's nature Windows is insecure. For example, (and I konw that this was cited in the original, after reading the comments) Back Orifice. Yes, most of us here wouldn't touch it (at least, I doubt that most of you would) but the idea behind BO (and BO2K) is that it was written using STANDARD API's in Windows. Under UNIX, without any kind of user access, it is (AFAIK) exremely difficult to have a program installed in user-space (the BOserver) and through that program, remotely control the system without having any user access. If you can dupe the user into running any kind of trojan or the server itself (come on, imagination- if an email came from "techsupport@microsoft.com" with a heading "Security update for " and an attachment (the BOserver), how many clueless windows users would download and run it without thinking?

The idea that it was implemented with standard API's and from user space (giving the remote user even more control than the local user has) scares me. Good thing I don't run Windows... lots of lamers at school use BO for fun. But imagine MS's plan in full execution- WinNT or Win2000 (whatever they're calling it now) on EVERY DESKTOP IN EVERY ORGANIZATION. There are ways of remotely executing code, you know. And this tool (BO2K) is one of the reasons that governments worldwide don't use Windows. Period.

Group Authoring (4)

Saraphale (65475) | more than 14 years ago | (#1631248)

Kudos to Jane's. It's not only good that they asked for comments, and are taking note of what they received, but also that they're offering to reward those whose contributions are being published. Has anyone published an article in this way before? It's the first of its kind that I've encountered. I wonder what threshold Johan J Ingles-le Nobel had his preferences set to, or whether the comments were summarised for him.

Several points about the method come to mind. Firstly, how are they intending to honour payment to people who made particular points or comments, when their points may be rephrased (and hence made unrecognisable, even if the point is still understandable) for editorial reasons, or when several people may have made the same point?

Hmm, I remember articles a while back about how to properly distribute books, essays and monologues electronically, and still receive payment for them. It's a shame this method can't be used more frequently - it relies too much on simple honesty.

Can an article still have coherency, and a clear point, when the person collating all the points may not have as much expertise in the subject area as those that submitted the information? It's not easy to create a coherent article if the subject isn't your own, even if you have a series of excellent references. I'm not knocking the people at Jane's, I just see it as a difficult task to form the mass of /. comments into a single article that would fit in magazine format.

Good effort.

S.

Re:Respect (1)

Anonymous Coward | more than 14 years ago | (#1631249)

Are we sure that we want to help these people? Remember, the pricipal audience of Jane's are the people that will use violence to surpress civillian populace. Better to try and keep them in the dark as long as possible.

Good, it's about time... (4)

Otto (17870) | more than 14 years ago | (#1631250)

Too bad I was out of town when that article appeared, otherwise, I'd have thrown my $1.95 in (inflation is a bitch)..

Still, after having read the original article now, and all the comments, I'm glad someone is at least doing it right.

We read all these articles (usually by big name news sources) that get posted to /. , and the majority of them have a lot of errors, misinformation, FUD, etc.. While we can easily tear them apart here in comments, those comments are not read by the majority of the mass public who read these articles and do not read /. Therefore, they don't have the whole truth of the story, and their thinking is biased based on the crap the news media puts out.

The best thing about /. IMO, is the simple fact that you get one of the largest collection of intelligent people on the planet coming together to give you the truth behind the headlines. Sure, you get some crap thrown in there because of the open nature of it, but that's a small price to pay, isn't it? If I want to know the truth behind the latest news, I simply check /. and turn on the moderation. Even if it's not the whole truth, it sure is a bunch of interesting informed opinions.

Truly the future of journalism. :-)


---

OK, now what about the payment ? (2)

rkt (9943) | more than 14 years ago | (#1631251)

If I'm not wrong the magazine intends to pay those whos comment have been included in the final article. I'd be intrested to know how this kind of a task can be done without risking privacy of the users.


I don't mind malda giving out the actual email addresses, however I hope malda knows what comes next.


However, yes, I am very delighted to know something like this happened, and hope that the magazine also sends some contribution to malda for the website ;-)



rkt

Slashdot (2)

GoofyBoy (44399) | more than 14 years ago | (#1631252)

>Thankfully, months earlier I'd noticed a link to Slashdot
....
>having been alerted to the fact that a) Linux is the best 'programmer's' o/s environment, b) many webservers use Linux and c) you're looking at expertise in both these areas for sensible answers, there was really no choice but to ask the guys that actually do this stuff for advice.

Really? I like slashdot not because of Linux and webservers but because of;
1. Low noise to signal
2. Get my Karma up to boost my ego.
3. To vote for "Hemos/JarJar Sux".

Oh, and thank you for asking for my/our opinion.

If they use my comments, (3)

Hobbex (41473) | more than 14 years ago | (#1631253)

(which is unlikely),

then "Cited as computer security expert by Jane's Intelligence Review" is going right on my resume. That has got to impress some perspective employers...

-
/. is like a steer's horns, a point here, a point there and a lot of bull in between.

payment? (2)

mindchild (95653) | more than 14 years ago | (#1631255)

Although it's right of her to offer money for compensation, my (personal) opinion is that we shouldn't accept it. We contribute to slashdot cause that's what we do, not because we get paid. I think we should apply this to this situation and happily thank jane for the offer, but smile and say no thanks.

If this becomes a regular thing, which I'm all for, and as some are suggestiong, this does bring up a different issue. That can be addressed later though.

What about other articles? (5)

Capt Dan (70955) | more than 14 years ago | (#1631256)

Kudos to Jane's. But what about other slashdot articles? I think that in order to get a complete veiw for their article Jane's should check out the slashdot archives as well. There are a number of interesting points brought up in archived posts that were not mentioned in the "Jane's needs you help" posts from two days ago. They may have been outside Jane's questions, but they are still valid.

A quick slashdot search for cyberterrorism yields:

FIDNET, Cyberwarfare, and Reality [slashdot.org]

CIA Considering Cyberwarfare [slashdot.org]

[slashdot.org]
Pentagon Cyber Wars

Hackers Against LoU Cyberwarfare [slashdot.org]


They need a nice big picture. For example, interesting information on what is going on in the hacker community could come from the "Hackers Against LoU" article.

And wasn't there an article somewhere about the US Military running a massive test crack against themselves last summer? If I remember correctly, one of their teams managed to get into the systems of a Navy Destroyer?
"You want to kiss the sky? Better learn how to kneel." - U2
"It was like trying to herd cats..." - Robert A. Heinlein

Slashdot profits. (1)

afniv (10789) | more than 14 years ago | (#1631257)

New poll, who makes the most money from Slashdot.

I'm glad /. is now profitable. I would hate to think I waste my time on /.. Now, if I could only earn money from reading /.. Maybe some some day, /.'ed will mean "get windfall of cash". Nah.

Seriously, I would like to echo everyone elses support for Jane's approach. I think this article will be very informative and demonstrate the type of knowledge /. can distribute/share.

~afniv
"Man könnte froh sein, wenn die Luft so rein wäre wie das Bier"

Oh really... (1)

squeakphd (73802) | more than 14 years ago | (#1631260)

For all we know, this is just a plot to get the names/addresses of people the military would consider cyber-terrorist threats so they know whose phone to tap, etc.

Parallel between journalism and the web? (5)

IIH (33751) | more than 14 years ago | (#1631261)

In the early days of the web, there were fewer sites and finding information on the web was straightforward. Your favourite bookmarks covered what you wanted, and search engines covered the rest quickly. Now, there are a lot more sites, and a lower signal/noise ratio with a lot of irrelevent content. There are vast lists of sites covering similar topics, and search engines can't keep up. Result? People are switching to portals, or using more particular search engines.

Journalism it seems has to go down a smiliar path. Speed matters for a story, but accuracy and research count highly. Previously, you had journalists who were experts in their own field, and you had a breathing space to do research before the story went to the printing press. In this day and age, with news sites on line, stories break at "internet speed". Hence, reasearch needs to be as quick. Also, with the amount of new developments it's impossible to keep up to date with everything. Result? do an "Ask slashdot" for info, and you'll get a very quick response from several people that know what they are talking about, several revelent links to the subject matter, and a general view of how the topic is viewed on the ground.

It's an excellent method and a lot better than reissuing the same myths that seem to propagate. I think Janes should be commended on a big step in the right direction.
--

Re:What about other articles? (1)

Paul_Taylor (38370) | more than 14 years ago | (#1631262)

The destroyer problem they had was because the boats are using WinNT for command & control. They were having lots of problems with them blue screening, and stopping dead in the water. Not a good thing to have happen in a battle, that.

A colloquy ensued,... (1)

markhb (11721) | more than 14 years ago | (#1631263)

in which perhaps the most salient point was made by an individual styling himself The Glorious MEEPT, who said simply, "MEEPT!"

Re:Sheesh (1)

J. Pierpont (58099) | more than 14 years ago | (#1631264)

>quite frankly I don't see how theres a story here
>at all, it's like the "cyberwar" between Pakistan
>and India, it has an effect but it's negligable if
>one side does anything.

I dunno. What if the Indians or the Pakistani knocked out the central banking infrastructure of the other country? Or disrupted central communications? A cyberwar could be quite effective.

-awc

Re:OK, now what about the payment ? (1)

methuseleh (29812) | more than 14 years ago | (#1631265)

How can it be an privacy risk? He said (paraphrased): "Contact us, and we'll pay you what you're due." If you don't want to risk your privacy, don't respond. Simple, no?

--

Re:Good, it's about time... (5)

SolidGold (86023) | more than 14 years ago | (#1631266)

I don't think that the articles on slashdot are the be all and end all though. I find most slashdotters are extremely biased towards open source etc.

For example, I always read at moderation level 2 just to cut down on how much there is to read. I find that about 90 percent of the comments have a very distinct slant. I attribute this to the fact that most slashdot readers have that slant and consequently most good comments are slanted.

On top of that, the moderators are also biased towards the prevailing slashdot outlook, and that means that the scarce moderation points are more likely to be spent on comments supporting the general slashdot opinion.

In short, I think that slashdot does a great job of providing the slashdot position on a subject, but does not give a complete picture of most subjects.

We need a better term (2)

grappler (14976) | more than 14 years ago | (#1631267)

This might sound like a nitpick, but when it's a public collaboration producing an article or report, let's call it something other than "open source".

"Open source" grates on me when it is used like that - it implies a "source" that is more accessible than the final product. This makes perfect sense in software, where there is human-readable source and then there are machine-readable instructions. Opening the source lets people see the inner workings and change them around.

What we have here is a great new way of putting minds together to make an accurate, insightful document. In this case though, it is more about the new ease with which outside opinions can be solicited and incorporated than with the "open" nature of it. After all, anyone that sees the final product also sees the "source" - they are one and the same.

--
grappler

Re:Respect (2)

Zachary Kessin (1372) | more than 14 years ago | (#1631268)

I don't know that those are the pricipal audience of Jane's. They may read it. I take the general rule that the free expression of ideas is on the whole *BAD* for thugs and petty tyrents.

YMMV.

Cathedral scaffolding needed first (1)

twilight30 (84644) | more than 14 years ago | (#1631269)

Mr Ingles,

I think doing the article this way is asking for excessive digression -- at this stage. Take a look at the comments posted already. The best way (in my opinion--feel free to disregard this) to approach this is to **first** provide an editorial structure, or scaffolding, if you will, of topics in this area you want to consider. Then ask Slashdotters their opinions on the subject areas. If you don't provide at least **some** editorial guidance your job will be made a hell of a lot harder.

Just my devalued two cents' Canadian
twilight


(yah, I know my sig's screwed up!)

Re:payment? (1)

Zachary Kessin (1372) | more than 14 years ago | (#1631270)

Why should we say no thanks. We are providing something of Value to Jane's. And they offered to pay us a few bucks for doing it. If they asked you or me to write a whole article then we would want to get paid. Hell if you want you can give any money they send you to a local charity. (I'm sure there are more than a few who could use the cash).

Re:OK, now what about the payment ? (1)

BitPoet (40070) | more than 14 years ago | (#1631271)

If this kind of thing becomes more common, why not have an "If for some reason a journalist decides to give me money, please send it to the following charity" field in the user preferences?

BitPoet

The morons at Ziff Davis should be reading this. (3)

Anonymous Coward | more than 14 years ago | (#1631272)

They often quote us Anonymous Cowards in their articles, usually picking the most offensive ones and making it seem like Anonymous Cowards are representative of everyone here. As if what WE say means anything!

Define irony (1)

scottm (288) | more than 14 years ago | (#1631273)

What an ironic post. Anyways, one of the reasons I love slashdot is that there is (fairly) good signal to noise... There are a lot of very intelligent people (experts, even) reading /. and weighing in with their opinions. Why do you read it?

to vivify.. (1)

RoLlEr_CoAsTeR (39353) | more than 14 years ago | (#1631274)

Well, this is an interesting use of the Slashdot Community. We've taken a small step from a 'Feedback' community to actually generating stories. This could actually lead to something interesting..

So, they're writing an article about cyberterrorism using the /. community as source. Next thing you know (and this was actually my first thought, upon seeing the JIR article post), "someone" (person, corporation, organization, etc.) will come in and do a psychological study of how the /. community works....
(and of how close I get to being kicked out at times, I'll imagine. :-)

But seriously, that would be interesting; for /. to become so influential that they decided to analyze and model us, and to encourage more groups to share as we do (except for some of the crankier posts, which I'll admit I've made some of myself... sorry!)

just my penny for the day

Re:We need a better term (1)

SolidGold (86023) | more than 14 years ago | (#1631275)

when it's a public collaboration producing an article or report

I just wanted to point out that like any open source project this one wasn't entirely the product of slashdot. Most open source projects start out with the vision of one person who gets something working and then gives it to the public to improve.

Similarly, the original article however poor it was, is what generated enough discussion to produce the final improved article.

Wow! (1)

Enoch Root (57473) | more than 14 years ago | (#1631276)

Wow! This is wonderful, wonderful news. I was already amazed at Jane's request of Slashdot users to contribute their opinions on the original article, but this?

Clearly, Jane is top of their field for a good reason. They know how to innovate and pick up their source from new, yet very pertinent origins.

I sincerely hope that other companies follow this trend. Slashdot is a watering hole for many experts on various subjects, and that, and not prestige or visibility is what determines the validity of an opinion!

How many can claim to pay for good information, even if it comes from someone posting as "Anonymous Coward" on a public bulletin board?

I applaud this, and hope we see more of it in the future.

"There is no surer way to ruin a good discussion than to contaminate it with the facts."

Re:AC $$$$ (1)

_egg (86248) | more than 14 years ago | (#1631277)

Screw that! Send ALL the money to the FSF. The authors didn't expect to get paid for their comments and contributed their knowledge in the interest of open discussion. If that makes money, then feed it back into the process that created it in the first place, which is free software.

Maybe it could be earmarked specifically for security software...

Re:Group Authoring (1)

revnight (8980) | more than 14 years ago | (#1631279)

well, i know that he read at least some of the responses directly off the site, as he replied to a couple (that i saw.)

along with that, his threshold was set to at least '1' (some of the posts he responded to were score '1' at the time.

my guess is that his threshold was set to '0,'...i doubt anyone told 'im about the moderation system. :)

Re:OK, now what about the payment ? (2)

/dev/niall (1043) | more than 14 years ago | (#1631280)

How can it be an privacy risk? He said (paraphrased): "Contact us, and we'll pay you what you're due." If you don't want to risk your privacy, don't respond. Simple, no?

For starters:

"All trademarks and copyrights on this page are owned by their respective owners. Comments are owned by the Poster"

On the bottom of every slashdot page. Shouldn't THEY be contacting the authors BEFORE running with their comments?

Please read more carefully. (1)

Xar (11113) | more than 14 years ago | (#1631281)

The article will thus go into December issue (published middle of November), I'll arrange to have it put onto the free section of the Jane's Intelligence Review website (yes, you do all get to see it, of course), and if you find your comments included, contact me at johan.ingles@janes.co.uk for payment at our usual lineage rates (yes, of course you get paid - after all, we are gentlemen).

Note the line: if you find your comments included, contact me at ...

No one is going to be giving out anyone's email address. It is up to you to claim responsiblity for your comments, should you find them in use.

I hope no one abuses Jane's generocity; they are acting in a very responsible and classy manner, as far as I'm concerned.

--Xar

Re:Oooops.... missed out the first time around (2)

drewpt (3975) | more than 14 years ago | (#1631282)

Not to defend Microsoft.

I've never run BO so forgive me if I'm wrong, but this is what I understand.

Someone executes BO on a Windows machine (either a user who downloaded it, or someone who has had access to the machine). Very similar to PC Anywhere.

When you're using Windows 95/98, you are the administrator. You have complete access to the machine, much like root has on a UNIX box.

Why can't this same exact thing happen on a UNIX box running under 'root'?

Another point...

For the most part only more "computer literate" people use Linux. As it grows in popularity, someday, it too will have the idiotic user that receives email from "techsupport@linux.com" telling them to run the Security Update.

Believe me, there are idiots using Linux today. I worked at a large company where an idiot who always logged on as root, delete his harddrive 3 times by mistake. You'd think he'd use 'rm -i *' after the second time.

Re:We need a better term (2)

Drake42 (4074) | more than 14 years ago | (#1631283)

That's not entirely true. The real source of a story is all of the disparate comments, opinions, quotes and references that get culled down and polished to make the final story.

Since all of this material is available to be read on /. you could say that the source of this article is open. The article itself will probably only be a fifth of the size of all source material, plus the article will have a great deal of polish that the source will lack.

Additionally, Open Source is a term that people are coming to understand. It could and should be applied to other areas, as long as the term is used accurately. In this case I think it is.


"Spoon!!!" -The Tick

Drake42

Kudos (2)

Hermetic (85784) | more than 14 years ago | (#1631284)

Jane's has always been the definitve source of military intelligence for the layman. Now that CyberTerrorism is approaching reality, Jane's will have to maintain their stanards in a new field.

I am personally delighted that Jane's refused to contribute to the general FUD campaign that the mainstream media. It is refreshing to be able to find a publication that is willing to go to the source (pun intended) tp get it's information.

I can only hope the Znet, Dvorak, CNN and [insert FUD factory here] take notice and try to make a new trend.

Somebody Should tell CNN (2)

El Puerco Loco (31491) | more than 14 years ago | (#1631285)

someone should notify the major news services about this, it sounds like something they would pick up. Not that Slashdot needs the publicity, but it's a cool story that demonstrates the value of open discussion about these kind of things.

^. .^

Newspaper - editors + 50k reporters = /. (1)

Wah (30840) | more than 14 years ago | (#1631286)

It tool all of one visit to get me hooked. Great content, funny crackpots, expert opinion, hey look Ma, it's "New Media"!

Re:Good, it's about time... (3)

acaben (80896) | more than 14 years ago | (#1631287)

/. is an impressive forum, where some of the neatest, coolest people I know hang out and discuss all kinds of ideas relevant to Linux and technology in general. It's a nerd's paradise for me, and I'm glad to see that Jane's (and others in the mass media, I hope) are realising what a tremendous resource the /. community is.

However, I want to respond to one particular part of Otto's post. He says:

The best thing about /. IMO, is the simple fact that you get one of the largest collection of intelligent people on the planet coming together to give you the truth behind the headlines.

While we certainly have some amazing, wonderfully talented and creative people in the /. community, I don't think we can consider ourselves "one of the largest collection of intelligent people on the planet." This egotistical view feels good, I'm sure, but I think we equate our knowledge of computers, the net, and linux too often to that of intelligence.

I'm not egalitarian by nature, but I'm rooting against /. becoming a place for the "techno-snobs" to hang out, to the exclusion of others. With such a great community of users, we should be reaching out and using our resources to teach others about our passions.

The article in Jane is certainly a good starting point for how /. can reach out past the confines of all of us Technically Elites and help the general population (or, at least another subset) learn about issues that matter to us. Let's keep using our speciality to contribute to projects like this.

It's right to say, No! (0)

Anonymous Coward | more than 14 years ago | (#1631288)

Slashdotters should not except any money from Jane's. If Jane's wants to be generous and express their gratitude, the money should go to the Free Software Foundation. Why? Because what you have witnessed by your contributions, is the model that FSF has developed for OpenBooks. We'll never see free open books if people are gonna worry about getting paid or not for their contributions. And, don't Jane's readers have to pay to read Jane's. Jane's should be free, too! for everyone!

Re:A plea (2)

RGreen (15823) | more than 14 years ago | (#1631290)

Chances are slim. EA is a cutthroat company when it comes to only releasing for mass-market platforms. Those SKUs that have been released for Linux have done so because the original programmers personally wanted to and had done so for their own entertainment. It's hard to justify the risk/returns for 30+ person teams in 2-year development of an original title without a *lot* of commitment from corporate.

Worthy as it is, the Linux market will have to hit 10% or more of all gaming platforms before it even gets a sniff. Heck, PC sales are 30% of all games sales and Linux is a fraction of that. We regularly get Playstation titles selling x10 what the PC SKU does.

Darn those confounded consumers!

- Robin Green, Bullfrog Productions Ltd, UK.

Re:A plea (1)

Anonymous Coward | more than 14 years ago | (#1631291)

I used to work there (I worked on a Jane's title, even!), and can tell you that there's no way in hell EA will even consider Linux for a very, very long time. EA isn't into trying new things, as witnessed by the endless series of "$sportname $yearname" titles they've spewed out for countless years. The "newest" thing they're doing is "Michelle Kwan's Figure Skating", and that's a universal joke to the rest of the company.
Feh.
>

Re:Slashdot Press, Inc. (0)

Anonymous Coward | more than 14 years ago | (#1631292)

Would this signal the birth of Open Source Journalism, then? :)

Re:What about other articles? (1)

GooberToo (74388) | more than 14 years ago | (#1631293)

Personally, any ship with its main purpose being war should not be run with an OS that is a primary target for viruses. Just imagine the problems that they would of had with their BIOS wiped out. Furthermore, these could knock out their backup and triary systems too.
I do understand that this is probably a minor risk, however, when you add all of the risks together, I doubt that you're ever going to have more than 95% uptime. The last thing they need is more room for exposure.

Also, at one point in time, wasn't NT thrown out from just about everything else in the Navy except for clerical office work? If I recall, it was because it wasn't stable and failed to perform as promised.

Re:AC $$$$ (2)

HeghmoH (13204) | more than 14 years ago | (#1631294)

So you only deserve to make money from your actions if you expected to make money from these actions?

I hope I speak for a lot of people when I say "What the smurf!?!?"

I don't see how this follows. If anything, these people deserve more money, because they contributed altruistically. When one expects to be paid for a job, one generally puts into it only enough to be sufficient to be paid, unless this person also really likes the job. But when a person does a job not expecting money, he does it from the heart. The results are generally better. Which one more deserves to be paid?

Infinite Loop Warning! (2)

turg (19864) | more than 14 years ago | (#1631295)

Well, it's great to see Slashdot used as a resource this way, but this could skew the whole continuum.

Slashdot consists mainly of references to news stories and commentary upon those stories. If people start writing news stories based on the commentary found on Slashdot, the whole world of journalism could implode.
-
<SIG>
"I am not trying to prove that I am right... I am only trying to find out whether." -Bertolt Brecht

Re:Good, it's about time... (3)

Wah (30840) | more than 14 years ago | (#1631296)

I agree that /. may not be the most objective site around, but the content creation model they have created (blatantly stolen from Usenet) is exceptional at organizing mass opinions. The moderation system (while it shows some of it's won bias) also helps to filter out the crap. The /. model is a good one to copy for anyone thinking about being a major news source in the 21st century. I mean what's more fun a)reading some comm. major's opinion, or b) reading said opinion and then discussing (bashing) it with 100,000 interested people. Pretty simple decision, besides as this article shows much of the content produced through this "open" "community" style is of much higher quality than the tripe that has to be finished on a deadline. Anecdotal evidence indeed.

Now this is cool... (1)

smoondog (85133) | more than 14 years ago | (#1631297)

I think this could be a very cool way to get points accross and to explore new subjects. Although I think it is pretty commendable that many of the users answered so well. Usually, there are so many flames (ala M$ vs Linux debates) that the readers tend to just turn it all off.

Perhaps the /. guys could learn something from all this.

-- Moondog

Re:AC $$$$ (1)

warpeightbot (19472) | more than 14 years ago | (#1631298)

I would propose that any fees owed to the AC's of slashdot be donated to the FSF.
Good idea, only strike "FSF" and insert "OSF".

Hmm, we may have to put this to a vote....

Payment expected? (0)

Anonymous Coward | more than 14 years ago | (#1631299)

I hope the denizens of Slashdot don't take this as a signal that whenever they're quoted in the mainstream press they deserve compensation.

--B

Actually... (1)

Darksky (58431) | more than 14 years ago | (#1631300)

..the reason they gave up on the old article is that some CyberTerrorists cracked their box and deleted it!
hehe.. Seriously though, a VERY classy move by Jane's.

Re:OK, now what about the payment ? (3)

methuseleh (29812) | more than 14 years ago | (#1631301)

First, copyright infringement != privacy risk. By posting your comments in a public forum, you've made those comments public, not private.


Second, anyone who posted to the original article should have known that their comments could show up in the Jane's article. That was, after all, the whole idea of soliciting comments from slashdot. As the gentleman from Jane's states in the original slashdot article:


When we publish the article (17 November), if you'd like to be contactable on this issue use your real email address and we'll attribute your comments, otherwise use 'anonymous coward' .

If you didn't want to "risk your privacy" then you should've posted as AC.

--

Re:If they use my comments, (1)

platypus (18156) | more than 14 years ago | (#1631302)

How about showing your slashdot karma points in your resume, now that we are "approved"? ;)

Clarification (2)

nitehorse (58425) | more than 14 years ago | (#1631304)

I'm sorry that I wasn't any clearer; what I had meant was (and you are correct; the original BO only *did* work on Win9x) WindowsNT. NT implements a different "security" model than Win9x; it supposedly grants each user their own user space similar to the way that users are limited on a *nix system. BUT, if a regular user under NT (read: non-Administrator/root) executes the BOserver (which makes the machine vulnerable), then the system is totally vulnerable over the Net or the local network. Under Linux, at least, I believe it would be extremely difficult to create a program which manipulated the user permissions so easily. And true- it will be that way in the future with linux, but it is generally regarded bad security practice to stay logged in as 'root'.... I don't.

So the point I was trying to make is that by standard API's a remote user can have administrator status while the local one can't, under NT (which is rated C2 network secure! Remember? Oh, wait- that was NT3.51, and it was disconnected from a network.......) And you are absolutely right, that under Win9x the user is given admin access. More bad security. Tsk tsk tsk on M$... but ah well, not my problem. The thing is, normal Joe Linux User (if using the system, not administering it; i.e., logged in as 'joe' and not 'root') would not be able to cripple the entire system or open it up to remote vulnerability by simply downloading/executing the security update.

Re:We need a better term (1)

Mars Saxman (1745) | more than 14 years ago | (#1631305)

Actually, if I recall correctly, they had the term first, and we stole it. "Open source", in intelligence-security-spy-whatever circles, refers to publicly available information sources like newspapers and television stations.

So if they want to use their version of the term to describe this article, who are we to argue? :-)

-Mars

Re:Community Editing/Writing. (1)

jeffcuscutis (28426) | more than 14 years ago | (#1631306)

$5 says Jon Katz will have an article on Community Editing/Writing within 2 weeks.

--jeff

Re:Slashdot Press, Inc. (0)

Anonymous Coward | more than 14 years ago | (#1631307)

"Cashdot", anyone?

call me paranoid, but (0)

Anonymous Coward | more than 14 years ago | (#1631308)

nsa to janes: we need to track these astute people, but they all use pseudonyms!

janes: lets offer them money and find out where they live...

Possible deception: identify "experts" (1)

salsa (4937) | more than 14 years ago | (#1631309)

Too me offering to pay contributers seems almost too nice. Has anyone considered the possibility that this has been a ploy to identify potential
cyberterrorist.

1) Appeal to there need to "set the record straight."

2) Offer some money to expert contributers, but require personal info to "deliver" it.

3) Compile list and submit to CIA, FBI, and cyberterrorism headhunters. (There has got to be some out there, and who better to know them than Jane's)

Re:selling out to the man (2)

Sylvia (98428) | more than 14 years ago | (#1631310)

i dislike and i resent your expression here which is basically an insensitive hate crime ... just when /. was looking so good too ...

Re:Sheesh (1)

Shanoyu (975) | more than 14 years ago | (#1631311)

It just wouldn't happen that way. The bank networks are closed off, and even if they weren't contengencies are far too easy to have for such a thing. As for disrupting communications, they have two choices, 1) blow up radio tower, thing that broadcasts to satilletes, etc. 2) break into the building and hax0r it.

I'll just go for 1, it's cruder but alot more effective. 2) could just be fixed with a simple contengency but it's far too surgical. To knock down the network you have to knock out the maintainers, otherwise you'll have a rather negligable effect, if Pakistan shut down India's banking network it would hurt them just as much as it hurt India simply because of how close they are geographically, even if they don't trade with each other, there are middle men in 3rd party countries to the conflict that would be hurt causing a ripple down effect of damage. As for bringing down communications there are just so many sources of it that although it would be possible to damage, the damage would need to be physical, not via the 'net.

Basically knocking down communications or banking infastructure wouldnt' be done over the internet.


-[ World domination - rains.net ]-

Re:Oh really... (0)

Anonymous Coward | more than 14 years ago | (#1631312)

And they would get all the wrong people...! Stomped.

Factual Content, It's Their Style (5)

ronmon (95471) | more than 14 years ago | (#1631313)

When I was in the USAF Security Command (way back, only one 4 year hitch) we had shelves full of books to help familiarize us with foreign aircraft. Nobody ever opened any of the "official" government pulp. We always reached for Jane's All The World's Aricraft. This is a class act on their part and has consistently been thier style through the years. Hats off. RonMon

Re:Expert Opinion (0)

Anonymous Coward | more than 14 years ago | (#1631314)

(offtopic)
somebody prove the usefullness of Perl to me, and write a script to translate this shit :-)

Slashdot needs a publicist (1)

Anonymous Coward | more than 14 years ago | (#1631315)

Now that slashdot is going to be a publicly-traded stock and the commercial side of the community is being managed, slashdot may really benefit from a real publicist. In the corporate world, there are these PR hacks that run around trying to get their clients to be used as sources for articles so it promotes the client as a significant figure in that industry. Since slashdot is an amalgamation of specialists throughout all branches of the IT world, a PR specialist could easily replicate this JANE article phenomena on a regular basis. Heck, it would be a much more credible source to see in articles than always seeing Jupiter Communications quoted on everything under the sun! sjohnson||AT||smart.net (remove the ||AT|| for electronic correspondence)

They should send AC lineage to /. (1)

Evil Poot Cat (69870) | more than 14 years ago | (#1631316)

If they're going to pay lineage, then why not help fund /. with the Anonymous Coward rates?

_______________________________

One small problem for Jane's.... (1)

Evil Poot Cat (69870) | more than 14 years ago | (#1631317)

"...if you find your comments included, contact me {snip} for payment at our usual lineage rates..."

This probably means they'll get /. 'ed a new way: 50 people who posted X idea, looking to get paid. :) They should directly attribute quotes/info to specific posters. (AC's get paid to /. :)

____________________

Charity (2)

MindStalker (22827) | more than 14 years ago | (#1631318)

Hey, I wonder if we could get Rob to get Jane's to donate all the AC and unclaimed post to a charity.
As well as encourage any claimers who don't need to money to throw it into the pot. Would be a great thing to do. Definate opportunity for a slashdot poll!!!

QNX for the Military (1)

Mike Cornall (7921) | more than 14 years ago | (#1631320)

Linux is my O/S, and the O/S I'm pushing to become dominant in homes and businesses.

However, for military hardware (e.g. battleships), I suggest that a microkernel imbedded O/S, such as QNX or VxWorks, would be the proper solution.

The beauty of a microkernel O/S is that it is made up of small modules, each of which can be independently verified to work perfectly.

Now, Linux offers similarly high levels of security, and reliability, through Open Source, and the intense review of thousands of developers. The military, on the other hand, will most certainly want to keep their source to themselves (wisely or not), and will want to do their own reviews.

The other advantage of a microkernel imbedded O/S, for military applications, is that it's better suited to real-time guaranteed-response systems, whereas a more monolithic O/S such as Linux may offer better peak performance, as is generally required by a PC user.

Cringely (4)

TAiNiUM (66843) | more than 14 years ago | (#1631321)

Good ol Bob Cringely has a few thoughts about the whole Jane's event:

"Maybe this was in the minds of the folks at Jane's, the British publisher of defense information, who this week threw their cyber terrorism research at the nerds who read Slashdot, hoping for some inexpensive proofreading to keep Jane's from making their own big mistakes. This is an interesting idea but ultimately flawed, I think. The only way to write the news is to write the news. You have to do it the best that you can then take the heat, because the censorship of the nerderati is still censorship. That's why newspapers make corrections."

Obviously he wasn't aware that Jane decided to publish the /. posts when he wrote this article, and I'm just dying to hear what he has to say about it.

Censorship? Nobody told Jane's they *couldn't* post that crap, we simply informed them of it being such a bad idea :)


http://www.pbs.org/cringely/pulpit/pulpit1999100 7.html



Re:Respect (1)

EmersonPi (81515) | more than 14 years ago | (#1631322)

One of the things about the open exchange of ideas (be they source code or less structured dialog such as conversation) is that it is free to all.

I think it is best that everyone have access to these ideas, rather than a select few, or even just those who will use it for good ends. It seems that the widest possible spread of ideas is the best policy. There are bad side effects of such policies (i.e. those who use these ideas to oppress others), but I think the good effects (i.e. everyone who is interested knowing as much as possible) far outweigh the bad.

Suggesting that they should be kept in the dark also suggests that if they aren't told, they won't figure it out. I imagine that if they (I'm talking about the sort of people who have the resources to actually suppress people AND use computers as a part of that) are really interested in knowing these things, they probably already know it (how did you learn these things. Now ask yourself if you really believe that the aforementioned (really determined) people would be unable to learn (or have people learn for them) in the same ways that you did).

One parting thought: Regardless of how much information about computer security third world dictators (or anyone for that matter) possess, there will always be ways to hack into their systems. There may come a time when social engineering is easier (or when significantly different hacks become easier), but there will ALWAYS be a way around any barrier that is put up. I very much doubt that there really is such a thing as an impervious computer system (just ones that are hellishly tough to crack).

Re:Respect (5)

remande (31154) | more than 14 years ago | (#1631323)

Consider Jane's guides to be similar to SANTA/SATAN. Both are publicly available. Both contain expertise usable to attack somebody. Because of this, both are actually more useful to defenders than attackers.

In the world of online security, it is better to have a publicly known weakness then to hide the weakness. If the weakness is hidden, then the Bad Guys share it among themselves and we don't know. If the weakness is known, we can post the moral equivalent of guards until somebody fixes the weakness.

Something like this should end up on sysadmins' desks pronto: they are our first defense against cyberterrorism. Fortunately, we here at Slashdot heard about it before publishing, and that means that a lot of sysadmins will know about this and be ready for it.

For anyone working at Jane's, I suggest that this article be target marketed to sysadmins. This would be a service to those people who keep our systems secure. This also would also increase circulation: rather than being targeted at a centralized military market, this is targeted at a decentralized computer security market. Unlike other forms of attack, this one cannot be defended by the military: cyberterrorism is best fought by a networked militia of private citizens and organizations.

Incentive for more thoughtful posts? (1)

Anonymous Coward | more than 14 years ago | (#1631324)

This could be good for /. as a whole. Perhaps people will think a bit more and make a bit less noise if they know that there is an opportunity for their thoughts/posts to be bought!

Re:Charity (1)

Etyenne (4915) | more than 14 years ago | (#1631325)

Great idea ! Although I have'nt contributed to that particuliar discussion (thus, this is not my business), may I humbly suggest the FSF as the receiving "charity" ?

Re:QNX for the Military (1)

Kintanon (65528) | more than 14 years ago | (#1631326)

Linux is my O/S, and the O/S I'm pushing to become dominant in homes and businesses.

However, for military hardware (e.g. battleships), I suggest that a microkernel imbedded O/S, such as QNX or VxWorks, would be the proper solution.

The beauty of a microkernel O/S is that it is made up of small modules, each of which can be independently verified to work perfectly.

Now, Linux offers similarly high levels of security, and reliability, through Open Source, and the intense review of thousands of developers. The military, on the other hand, will most certainly want to keep their source to themselves (wisely or not), and will want to do their own reviews.

The other advantage of a microkernel imbedded O/S, for military applications, is that it's better suited to real-time guaranteed-response systems, whereas a more monolithic O/S such as Linux may offer better peak performance, as is generally required by a PC user.


I'm the resident Geek for a manufacturing plant and here if we have down time we lose money out the yang. We use QNX on our ciritical production systems such as packing equipment and mailing systems. It is extremely stable and very easy to work with once you learn it. It's enough like Unix/Linux to make the transition pretty painless. I would definately second this recommendation for military usage, though since that part of our system isn't connected to the 'outside' I can't say anything for its security.

Kintanon

Re:The morons at Ziff Davis should be reading this (0)

Anonymous Coward | more than 14 years ago | (#1631327)

You want the Ziff-heads to read it? Just shove a copy of it up Bill G's butt.

The poor author... (3)

Evro (18923) | more than 14 years ago | (#1631328)

"Hi Jim? This is Tom, over at Janes. That article you wrote on cyberterrorism? ... Yeah, that one. Listen, we decided that it sucked so we're not going to run it after all. ...Well, in its place we're going to compile some articles from Slashdot. ... Slashdot, you know, the website? ... well the comments were much better than the article... Jim?"

Maybe this is a sign that Slashdot is what journalism will be like in the future.

Jane's (0)

Anonymous Coward | more than 14 years ago | (#1631329)

People of Jane's are mythomaniac, guns loving, Tom Clancy reading lunatics.

And now we know where they get all the "facts" they publish for the various paranoid sociopaths that read them : any anonymous "source" on the internet is entitled to be taken more seriously than their own "research"

Intelligence my *ss.

Load More Comments
Slashdot Account

Need an Account?

Forgot your password?

Don't worry, we never post anything without your permission.

Submission Text Formatting Tips

We support a small subset of HTML, namely these tags:

  • b
  • i
  • p
  • br
  • a
  • ol
  • ul
  • li
  • dl
  • dt
  • dd
  • em
  • strong
  • tt
  • blockquote
  • div
  • quote
  • ecode

"ecode" can be used for code snippets, for example:

<ecode>    while(1) { do_something(); } </ecode>
Sign up for Slashdot Newsletters
Create a Slashdot Account

Loading...