TECHNOLOGY

This Bug Man Is a Pest

George Ledin teaches students how to write viruses, and it makes computer-security software firms sick.

7/26/08: Why one college instructor is teaching his students how to create computer viruses. (Editor: Lee Wang; Camera: Joshua Fisher)

 

Email To A Friend

Please fill in the following information and we'll email this link.

Separate multiple addresses with commas

SPONSORED BY
 

In a windowless underground computer lab in California, young men are busy cooking up viruses, spam and other plagues of the computer age. Grant Joy runs a program that surreptitiously records every keystroke on his machine, including user names, passwords, and credit-card numbers. And Thomas Fynan floods a bulletin board with huge messages from fake users. Yet Joy and Fynan aren't hackers—they're students in a computer-security class at Sonoma State University. And their professor, George Ledin, has showed them how to penetrate even the best antivirus software.

7/26/08: Why one college instructor is teaching his students how to create computer viruses. (Editor: Lee Wang; Camera: Joshua Fisher)

The companies that make their living fighting viruses aren't happy about what's going on in Ledin's classroom. He has been likened to A.Q. Khan, the Pakistani scientist who sold nuclear technology to North Korea. Managers at some computer-security companies have even vowed not to hire Ledin's students. The computer establishment's scorn may be hyperbolic, but it's understandable. "Malware"—the all-purpose moniker for malicious computer code—is spreading at an exponential rate. A few years ago, security experts tracked about 5,000 new viruses every year. By the end of this year, they expect to see triple that number every week, with most designed for identity theft or spam, says George Kurtz, a senior vice president at antivirus software maker McAfee. "You've got a whole business model built up around malware," he says.

Ledin insists that his students mean no harm, and can't cause any because they work in the computer equivalent of biohazard suits: closed networks from which viruses can't escape. Rather, he's trying to teach students to think like hackers so they can devise antidotes. "Unlike biological viruses, computer viruses are written by a programmer. We want to get into the mindset: how do people learn how to do this?" says Ledin, who was born to Russian parents in Venezuela and trained as a biologist before coming to the United States and getting into computer science. "You can't really have a defense plan if you don't know what the other guy's offense is," says Lincoln Peters, a former Ledin student who now consults for a government defense agency.

That doesn't mean Ledin isn't trying to create a little mischief. His syllabus is partly a veiled attack on McAfee, Symantec and their ilk, whose $100 consumer products he sees as mostly useless. If college students can beat these antivirus programs, he argues, what good are they for the people and businesses spending nearly $5 billion a year on them? Antivirus software makers say Ledin's critique is misleading, and that they are a step ahead of him—and the hackers. "We've changed the game, and viruses have changed in recent years because of the protection we're putting into place," says Zulfikar Ramzan, the technical director of Symantec's security team.

Still, beneath Ledin's critique lies a powerful polemic. Ledin compares the companies' hold over antivirus technology (under the Digital Millennium Copyright Act of 1998, the companies' codes are kept secret) to cryptography decades ago, when the new science of scrambling data was largely controlled by the National Security Agency. Slowly, the government opened the field to universities and companies, and now there are thousands of minds producing encryption that is orders of magnitude more complex than code from just a decade ago. That's why you can safely transmit your credit-card numbers online. "Why should we shy away from learning something that is important to everyone?," Ledin asks. "Yes, you could inflict some damage on society, but you could inflict damage with chemistry and physics, too." He hopes one day to share antivirus techniques. But that would require infrastructure and financial support, which the federal government so far has declined to give. Until then, Ledin will have to live with his reputation as the guy who gave away the secrets to the Internet's bomb.

© 2008

Label

Newsweek Top Stories
NEWSWEEK's 20/10
NEWSWEEK's 20/10

Our decade-in-review project recalls the highs and lows of the last 10 years.

Obama's Promises
Obama's Promises

Is the new president fulfilling his campaign pledges? Or falling short?

The Decade in 7 Minutes
The Decade in 7 Minutes

Video: A fast-paced review of the best and worst moments. Don't blink.

Accidental Celebrities
Accidental Celebrities

From Levi Johnston to Elian Gonzalez, these people never expected to be in the spotlight.

Discuss

Sponsored by

Member Comments

  • Posted By: hioriw @ 07/21/2009 1:17:07 AM

    I'm absolutely outraged by this article. I want learn it . see my article about security: http://www.emaxinfo.com

  • Posted By: tools4u-2009 @ 04/11/2009 10:54:07 PM

    i want profeesor ledmin to teach me, il pay him,, i know his students will be making millions of ligit money by big software companies i would get on a plane now and fly straigh in to ledmins class, you keep an eye on his students i bet they all end up millionaires, lucky buggars, i want in to make this pc world a safer place

  • Posted By: tools4u-2009 @ 04/11/2009 10:45:12 PM

    i would pay to go be teached by him, i can bet any mney that these students will be earning millions in 5 may be 10 years time, unless tey decide to get together and prove us wrong and put te world pc in to chaos, but what abouth tha 16 yr old bot, what was it he made a programme in is bedroom witch messed up god knows how many peoples pc's and thers my friend te greatest hacker i knew, now hes serving 8 years in jail, and e says the 2.4 million he made was not wort it, but going back to tese students i would love to be one of them trust me they are our future and out basically goverment. without pc's te world would be a a standstill, so basically they could ecome the world's most powerfull bomb. worse than we can imagine. or we put a like a curfew tag on them make them work for big pc companies and tey get rich, but because tey are maing soo much money tey do not turn to pc crime, please please let me join your class proffesor:)

Reply

Report Abuse

Enter comments if any for reporting abuse

 
The Greediest People of All Time
From Bernard Madoff to AIG, Wall Street has reinvented excess. But the Masters of the Universe didn't invent greed. A look at the despots, robber barons and others who made our shortlist.


 
 
PHOTOS
Wall Street's problems have captured the attention of Congress, the White House and the media. But on the country's Main Streets ordinary folks are wondering if anyone is paying attention to them. A look at how Americans are coping with the economic crisis.