0wned .gov machines (was Re: Russian cyberwar against Estonia?)

dan at geer.org dan at geer.org
Mon May 21 10:55:11 EDT 2007



A while ago, I did a rough calculation that made
me state that 15-30% of all machines are no longer
under the sole control of their owner.  In the
intervening months, I got some hate mail on this,
but in those same intervening months Vint Cerf
said 40%, Microsoft said 2/3rds, and IDC said 3/4ths.

Whatever it is, it is >> 0.

And, of course, definitions matter.  I don't think
that 0wned is a binary variable any more; there are
degrees of 0wned-ness with a wide range between the
optimist ("I replaced` the only program that was
trojaned") to the pessimist ("Any compromise of any
sub-component makes the entire edifice untrustable").

--dan

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list