1/22
Let's talk about how the 2,000pp "House 2.0 antivirus experiment" was in fact an intelligence report (aka "INTSUM") on the global #antivirus industry.

It began in 1999 after I'd revealed the existence of "EIS," later renamed "ADVEIS." It was an #antivirus rootkit...
2/22
ADVEIS stood for "Antivirus-Dependent Vulnerabilities in Email Infrastructure Security." I developed it in the late 1990s while working at A.G. Edwards & Sons building the U.S. brokerage industry's first SOC.

I gave a public lecture on ADVEIS, then dusted my hands of it.
3/22
But ADVEIS had rankled the #antivirus industry.

This led IBM bigwig David Chess to call my office.

I admit it: Chess is the one man I never beat in a philosophical match.

"So, Rob: you got root access from every AV company's products. What are you going to do *next*?"
4/22
Chess's question stuck in my craw for months.

Then I recalled my disdain for #antivirus firms that couldn't write an INTSUM (intelligence summary) on any virus writer. They'd write anecdotes at best, love letters at worst.

Hey, I'll show AV firms what a real INTSUM is!
5/22
Denise & I stood on the verge of building "House 2.0," a rather high-tech two-story with CAT6 wiring and a computer lab that could be fully isolated during, say, an "aggressive" virus study.

I approached Denise with the upgrades I'd need...
6/22
"You know my server room in 'House 2.0'?"

"Sure."

"I, uh, need a second 6' data rack."

"Really."

"Yes, really. Each needs its own UPS."

"Really."

"Yes, really. And I'm going to need servers."

"Well, of course."

"Yeah-- no. I need more."
7/22
"How many more servers is 'more'?"

"I, uh, ... I need something like a dozen now."

"A DOZEN?!?" shouted Denise. "What do you plan to *do* with them?!?"

And I said "they're not going to be used ... for ... their intended purpose..."

(I had 15 servers when Denise died.)
8/22
Denise ultimately signed off my business case--

--yes, I went that far with it

and I folded ~$15,000 extra into our mortgage to support "the House 2.0 antivirus experiment." You can read about it in Wired Magazine's profile story on me:
wired.com/2001/08/the-ma…
9/22
As construction finished up, I approached every #antivirus vendor EXCEPT McAfee & Symantec & Trend Micro. "Look, I'm convinced 'The Big Three' promote poor corporate AV policy. I intend to write an AV policy pack anyone can use as a template. I need your help, BUT..."
10/22
"...I will not sign an NDA with anybody. I'll totally understand if you don't want to help me for this reason."

And everybody said "oh, hey! We definitely want to help if you're not working with The Big Three!"

I got all the more backdoor access to their techno-wonks!
11/22
As you can see below, I couldn't #ahem just start writing an INTSUM on a global security industry when there are certain "Title 50" legal restrictions. But it's a straightforward process to avoid Title 50 if you just keep your "SSO" in the loop!
12/22
("Wait, Rob: 'SSO' is Ship Security Officer. That's Navy.
Weren't you Air Force Reserves?" Yeah, we Zoomies stole some terms from the Squids. Remind me to tell you about the time I flew jumpseat in a C-130 over Iraq and the pilot asked ATC to let him do a "Crazy Ivan"...)
13/22
Okay, here's where it gets interesting. In 2000 one of the vendors' techno-wonks bitched that the White House was looking to host an #antivirus confab of some sort but they weren't invited.

"Hell, you know, <vendor> gets to go and they're giving viruses to the Chinese!"
14/22
I'm like "wat"

"You didn't know? CARO is supplying China with viruses. It's supposed to be just the WildList each month but behind the scenes they're all feeding viruses to the Chinese to open trade doors... Why should *they* get to go to the White House?"
15/22
In one conversation after another, I'd slip in a "soooo... you guys aren't like McAfee & Symantec & Trend, giving viruses to the Chinese, are you?"

I learned another secret: WildList didn't know CARO was offering their research to the Chinese every month on the 15th.
16/22
The INTSUM was now filling up with call notes, forwarded emails, and documents showing how CARO had turned into a #cartel bent on carving up the Chinese market in fairness to all #antivirus players--

--at Trend Micro's expense.

"House 2.0" was starting to lose focus.
17/22
"House 2.0" started as a secret compilation of dossiers on the #antivirus industry so I could lecture to vendors at @virusbtn how to write a real INTSUM on virus authors.

But the revelation of McAfee, Symantec, and Trend Micro giving viruses to the Chinese gov't... "wow."
18/22
By early 2002 my military career had taken its toll on Vmyths[.]com and on the "House 2.0 antivirus project."

I was too busy in a military uniform to keep up the ruse.

But I had more than enough to work with. "Wait 'til Helen sees *this* Virus Bulletin CFP!"
19/22
I was an Air Force Deployable Enlisted Historian (AFSC 3H0x1, see below). Natch, I wrote the "House 2.0" INTSUM in the style of an RCS:HAF-HO(A)7101 Historical Report. The forwarded emails & documents, my call notes, etc. took up 1,600+ pages.
20/22
It was too late in 2002 to make that year's Virus Bulletin CFP. I forget why but I decided to flesh out a full 1hr presentation slide deck.

I was in our downstairs Great Room, "talking out" an idea for the slide deck, when Denise approached me:
21/22
What's STUPID here is that I'd placed a unilateral gag on Vmyths[.]com reporting any of this, to protect us from SLAPP suits...

...yet there I was, thinking "I'll show this off at Virus Bulletin so vendors finally learn how to write a damn INTSUM on virus writers!" 🤦
22/22
And that, my friends, is how I learned the #antivirus industry supplied China with offensive virus technology right under @richardclarke's nose -- a story the Wall Street Journal broke 20 years ago this week.

(@threadreaderapp please unroll)
@threadreaderapp please unroll

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with 🗣 Rob Rosenberger

🗣 Rob Rosenberger Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @vmyths

26 Nov 20
Let's talk cybersecurity.

1/7
News of COVID19 vaccines' side effects are so wild that rumors are spreading of how many #SickDays you'll burn to get both (repeat: "both") shots.

So let's compare it to the history of #computer antivirus vaccine use...
2/7
Historically, users gleefully installed #computer vaccines when they were released (typically a few days) after a deadly global virus outbreak "that cost millions of computers' lives and billions of dollars in damages."

But then users came to a rumored realization...
3/7
They said "you'll pay a severe penalty for #antivirus vaccines."

Users rumored it made their computers sluggish; that it constantly wasted their time to install vaccine updates every {month | week | day}; that it interfered with important company processes; blah blah blah
Read 7 tweets
8 Nov 20
1/10
Let's talk cybersecurity.

Specifically, let's use #hysteria to snatch the electoral college from Biden so Trump can serve another White House term:

newyorker.com/news/daily-com…
2/10
We can pick ANY blue states here; I'll pick Georgia & Pennsylvania for fun

Again, our goal is to use #hysteria to snatch some electoral college votes from Biden

law360.com/articles/12287…
3/10
El Prez can begin by collecting all the research that WE THE PEOPLE in cybersecurity use to cast our own pall of fear over electronic voting:
Read 10 tweets
31 Oct 20
1/17
What with the U.S. election approaching, it's time I told you about a BILLIONAIRE FINANCIER PRESIDENTIAL CANDIDATE who once pondered if he should buy an #antivirus company

I'm talking, of course, about ROSS PEROT

Strap in kiddies, we're going on a ride!
2/17
It's late February or early March of 2004. I'm in uniform, temporarily assigned to USAF's Senior NCO Academy as a reward for having pitched a tent on a captured Iraqi air base. Vmyths[.]com has all but collapsed by this point due to my Reserve military commitments.
3/17
My late wife Denise is at home in my computer lab where she's drafting a résumé. She got cut in the third round of a quadruple-layoff sweep when the U.S. gov't terminated a contract that her firm, um … did reeeeeally bad things on.

So anyway, she's sitting there…
Read 17 tweets
3 Oct 20
1/6
Let's talk about the ingredients that went into this meal of a treatise (see below).

The authors cite @KimZetter in the endnotes 👍

@bontchev? No mentions at all.

@craiu? No mentions at all.

@mikko? No mentions ... and he's got "vigorish" in DoD!

Me? Yeah, no. Image
2/6
There is a MAJOR BARRIER between "corporate #cybersecurity" that formed as an industry in the late 1980s

vs. "beltway bandits" who hijacked it for gov't funding in the late 1990s.

Fully a dozen years ago I warned DoD is "devolv[ing]" in cyberspace:

web.archive.org/web/2016032800… Image
3/6
And this brings me to a vital concern I have with the ingredients in ANY well-resarched DoD-centric cyberspace treatise w/ 139 footnotes:

PhD candidates FAIL to earn a doctorate every year because their "well-researched" thesis is way too damn lopsided!
Read 7 tweets
19 Sep 20
1/4
You know what's in store for #cybersecurity when "in person" conferences finally restart?

It ain't "networking"

Many of you will form #cliques based on your vehement political beliefs, NOT your cybersecurity beliefs

Our industry will be all the less for it. What a shame!
2/4
I've bitched since 2009 (see below) about #influencers¹ who CANNOT stop talking about their airline woes, and why we must vote for their politician, and etc.

How DARE you force #infosec newbies to follow "the whole you"!

_____
¹ Not #ThoughtLeaders
3/4
I'm NOT alone in this belief. Newbies occasionally speak up to tell #influencers "I followed you for your expertise, why did you stop?"

You want to tweet? That's your right.

You want to be an #infosec influencer? That's a privilege.

Time for you to #ShitOrGetOffThePot!
Read 6 tweets
19 Sep 20
# of #ransomware deaths because hospitals triage their IT networks over that of a dying patient: 1

# of #HeartAttack deaths because hospitals restricted treatment for non-COVID patients:

heart.org/en/news/2020/0… Image
# of #ransomware deaths because hospitals triage their IT networks over that of a dying patient: 1

# of #cancer diagnoses delayed because hospitals restricted treatment for non-COVID patients:

cancer.org/latest-news/co… Image
# of #ransomware deaths because hospitals triage their IT networks over that of a dying patient: 1

# of #KidneyDisease deaths because dialysis centers restricted treatment during COVID lockdowns:

kidney.org/coronavirus/di…
Read 6 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!