It burst into the public consciousness just in time for April Fool’s Day, but the Conficker virus hasn’t done what most security experts expected – it hasn’t gone away.
At first, Conficker was billed by the security media as a mega-doomsday virus bomb scheduled to explode on April 1, 2009. Panicked emails rained down on security experts, begging them for cyber innoculations.
The security experts soberly explained that the cure for Conficker was already in most PC users’ hands. Microsoft had announced its fixes to the very vulnerabilities that Conficker exploits and them made available in plenty of time. All the public had to do was install the fix.
That’s where the security strategy fell apart, and the Conficker virus got a new lease on life. Today, Symantec reports that Conficker is attempting to infect 50,000 new Microsoft Windows PCs a day and IBM reports that Conficker may have control of a “botnet army” of 3 million PCs or more.
What happened? The short answer is that too few PC users patched their systems in Conficker’s early days. That was unfortunate because subsequent versions of the virus have begun to exploit the old versions, making it doubly difficult for PC users to disinfect their systems.
But there’s more to Conficker’s continuing success. Researchers at SecureWorks believe the virus is propagating itself through USB devices and networks that don’t enforce strong passwords. While most businesses and universities have software to detect and remove the Conficker virus, workers fail to patch their systems or use the strong security measures that will keep their systems safe.
In a word, too many PC users don’t believe that threats such as Conficker will affect their systems. Worse, they might not even care.
If you doubt that presumption, look around at your colleagues and ask yourself: are they patching their systems? Using strong passwords? Forbidding the use of DVDs and memory sticks in their PCs? More likely, your colleagues have a stack of patches waiting to be applied. Their passwords are variants of the first one they ever used, or if the system pesters them for a complex password, they write it on a sticky note and paste it on the monitor. DVDs? Play ’em! Memory sticks? They’re more convenient than uploading and downloading through the company firewall.
If you work for a bank, your story is probably better since the regulators have done a good job of tightening Internet and email security. But these tight policies open another vulnerability – bank employees can easily forget that non-bankers aren’t as diligent. One of the greatest threats to a bank today may be its customers’ sloppy security habits.
For years, bankers have heard that convenience is king and that strong security measures must be balanced against business needs. In response to calls for additional security, bankers hear about competitors and customer complaints.
“I type my user ID and password a lot more often than I get my ID stolen,” says one of a thousand customers.
Conficker’s designers knew all this when they built their virus. They predicted that users wouldn’t patch their systems, foresaw the meager passwords and cheered the devil-may-care attitudes of Generations X and Y. Now Conficker has the upper hand.
Stranger still is the current media silence on Conficker. After the initial alarm and subsequent downplay when April 1 didn’t morph into Doomsday, there have been no headlines, no interviews, no politicians talking about cyber security in anything but the most general terms. But when Internet traffic really does slow to a crawl and the virus designers finally make their demand for money, it will be no laughing matter.
It will also be too late.
John Jaser manages Internet Services and Security at Avon, Conn.-based COCC, Inc.





