Feeds

UK Linux group slams Sophos virus threat claims

Anti-virus company is spouting FUD, says NetProject

  • alert
  • submit to reddit

New hybrid storage solutions

Updated Anti-virus software developer Sophos has been accused of spreading fear, uncertainty and doubt over the safety of Linux systems by UK pro-open source organisation NetProject.

Sophos wrote to UK newspaper Computer Weekly t'other week to claim that viruses targeting Linux already exist.

Not so, responded NetProject director Eddie Bleasdale. Yes, anti-Linux viruses can be written, but Linux, like Unix, has sufficient systems in place to prevent unauthorised software from running on any "correctly configured and administered Linux computer".

"We have been working in the Unix area for over 20 years," Bleasdale said in a statement. "During this time we have never encountered a Unix or Linux virus nor have heard of any organisation that has been infected by a Unix/Linux virus."

So prove your claim, Sophos, challenged NetProject.

No, shan't, so there, responded the anti-virus company.

Bleasdale called Sophos for clarification, and received, he says, the following message from the company's senior spin doctor, Graham Cluley: "I don't have any response other than that which I have already given you...

"I don't have any more to say on the matter. I think it will be a waste of our mutual time if you email/phone Sophos on this matter again."

We considered giving Sophos a buzz too, but then we read Cluley's words: "I'll give the same response to any journalists who might call me up."

NetProject's challenge is simple: send an email with an attachment (presumably infected) and see if it screws up the system. Of course, where the infection comes from if there aren't, as Bleasdale claims, any Linux viruses doing the rounds is an interesting question, but presumably Sophos could come up with something.

Cluley later told The Register: "Sophos is in the business of protecting computers, not infecting them. Therefore we have no interest in responding to challenges to attack systems, especially when the result would only support what we know already."

"We believe that Linux is pretty much bullet proof and if Sophos is able to infect a well configured Linux box then it will uncover an implementation defect rather than a design flaw," said Bleasdale. "Anti-virus software simply treats the symptoms and does not address the fundamental design weaknesses that allow viruses... We need to stop the fear uncertainty and doubt that the anti virus companies are trying to create around Linux."

That last line's a dig at Windows. NetProject is essentially about promoting among UK businesses the use of systems that aren't based on Windows or other proprietary software, hence it's keen interest in Linux and open source.

In response to Bleasdale's FUD claim, Cluley told us: "Unix viruses are not a huge threat but the original purpose of Sophos' letter was to correct a previous correspondent to Computer Weekly who believed they did not and could not ever exist. Unix viruses do exist and there are many non-Sophos
sources which support that fact."

And that's certainly the case. Symantec's virus database lists only four Linux viruses, and Kaspersky Labs lists two (and one of those is already on Symantec's list, bringing to the total to... er... five. Which is, it has to be said, rather fewer than known Windows infections... ®

Security for virtualized datacentres

More from The Register

next story
Not appy with your Chromebook? Well now it can run Android apps
Google offers beta of tricky OS-inside-OS tech
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
NHS grows a NoSQL backbone and rips out its Oracle Spine
Open source? In the government? Ha ha! What, wait ...?
Google extends app refund window to two hours
You now have 120 minutes to finish that game instead of 15
Intel: Hey, enterprises, drop everything and DO HADOOP
Big Data analytics projected to run on more servers than any other app
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.