Slashdot Mirror


Symantec Anti-Virus Supresses Privacy Tool

salimfadhley writes "Symantec's 'Norton Antivirus' now attempts to remove Freegate, a program designed to help Chinese internet users view websites blocked by the government firewalls. Symantec offered no reason why the program (which is not spyware) was marked as a 'trojan' in Chinese versions of the software, however even an unattuned conspiracy theorist will guess that this was done at the request of the Chinese government. "

46 comments

  1. I for one welcome our new... awww forget it by macz · · Score: 3, Funny

    The thing about Chinese Virus Scanners. After an hour you are still infected and need to scan again.

    --
    ...But I digress. TREMBLE PUNY HUMANS!ONE DAY MY SPECIES WILL DESTROY YOU ALL!
    1. Re:I for one welcome our new... awww forget it by blindbat · · Score: 1

      Looks like the moderator forgot to take his humor pill this morning :)

    2. Re:I for one welcome our new... awww forget it by Anonymous Coward · · Score: 0

      I moderated the parent down, mostly because it's such an overused unfunny joke, and Troll was the most fitting of all the moderations.

    3. Re:I for one welcome our new... awww forget it by CaptainCheese · · Score: 2, Insightful

      "Concentrate more on promoting than on demoting...Simply disagreeing with a comment is not a valid reason to mark it down."

      I suggest you read the moderation guidelines...

      Incidentally, If it gets moderated at all this post will probably get moderated down. That's okay, I got karma to burn.

      --
      -- .sigs are a waste of data...turn them off...
  2. Where's the follow up with Symantec? by Wanderer1 · · Score: 4, Interesting

    I'd certainly like to see the official line on this one. Probably a bit like Cisco - "Hey, anything to make a buck, right? We don't have no scruples." Similar issues appeared with web censorware which were illuminated by the organization, PeaceFire a few years back. Not only were the censorware lists blocking "legitimate" websites but also blocked sites that could (without imagination) be construed as agendas beyond the scope of "protecting children" against sex. Outsourcing your software increases the risk of being subjugated by others. It is unfortunate that we need so dearly the protection that antivirus software provides - but we're putting our trust in corporations that do not hold honor over profit (few do, nothing special about this one.) The same struggle with subjugation appears in the Digital Rights Manglement issues, where Microsoft chooses what you do with your computer. Fortunately as we've seen with the adware war, Freegate and friends will continue to evolve. Let us hope that the antivirus vendors have as much trouble blocking Freegate as they do catching legitimate malware! Bill

    1. Re:Where's the follow up with Symantec? by Flaming_cows · · Score: 0
      Digital Rights Manglement
      Couldn't help but laugh at that one, typo or not. :)
    2. Re:Where's the follow up with Symantec? by gl4ss · · Score: 3, Insightful

      ... and it's all the more suckier when basically you're paying symantec to prevent others messing around with your computer like this!

      since they now evidently can be convinced to remove package x from customer system z with y number of dollars at stake, it's up for questioning if you can as a customer trust them enough to actually PAY them to do a JOB and except they get it done, and not the total opposite. indeed though even more puzzling is that is chinese goverment using this software? and how do they dare to do so when evidently symantec can not be trusted to not have tampered with the software to spy/otherwise affect what they're doing.

      in all fairness it could have probably been about being the only feasible option the chinese goverment gave(hey could you add feature x, OR you'll loose us as a customer and the business permit in china) them but security isn't about taking the easy way out every time.

      it could be also intresting that if some malware scanners flagged symantecs china offering as malware... because that's what it is, now.

      --
      world was created 5 seconds before this post as it is.
    3. Re:Where's the follow up with Symantec? by ctr2sprt · · Score: 2, Informative
      Norton Antivirus, like some other AV systems, tries to detect unknown viruses using common patterns. This results in it occasionally coming up with false positives, especially of programs which share common characteristics with viruses and trojans. For example, it used to spot pretty much any keygen as a virus, though it no longer does.

      With all due respect to conspiracy theorists, this may be all that's happening here. What's the first task of a really good virus or trojan? Bypassing defenses, both of the machine and the nearby network. Any program which does those things is inherently suspicious. This is not to say the conspiracy theorists are wrong, mind you, merely that there are other possibilities.

    4. Re:Where's the follow up with Symantec? by justkarl · · Score: 1

      but we're putting our trust in corporations that do not hold honor over profit

      I agree. I'm no conspiracy theorist, but my guess is that the chinese gov't found out about Freegate, and the chinese gov't dosen't like people up in it's buisness...so...it's logical they'd try to stop it - any way it takes. Just my $0.02...

    5. Re:Where's the follow up with Symantec? by pocopoco · · Score: 1

      >I'd certainly like to see the official line on this one.

      RTFA

      >A Symantec official in Beijing confirmed that Norton's
      >software had designated Freegate a "Trojan horse",
      >but would not give details of why it had done so.

    6. Re:Where's the follow up with Symantec? by BrynM · · Score: 2, Insightful
      This results in it occasionally coming up with false positives
      I bet this could be proven or disproven by looking at the description of what it detects... Unfortunately, we don't know what that is. The Symantec site didn't offer anything and neither did seom Googling. Anyone know what it's identified as?
      --
      US Democracy:The best person for the job (among These pre-selected choices...)
    7. Re:Where's the follow up with Symantec? by Hooded+One · · Score: 3, Insightful

      As far as I can tell from the article, Norton marks it as a potential threat and suggests removing it. If that is indeed the case, I'm inclined to agree with you. If Freegate were being specifically targetted, I imagine they'd just remove/disable it silently.

    8. Re:Where's the follow up with Symantec? by dbacher · · Score: 1

      To do business in China, you have to go through the government there. China wants the internet filtered -- they are installing government firewalls, and you cannot access internet except through them. So China goes to Symantec and says "either you mark this as a trojan and remove it, or you cannot sell in our Country" and Symantec does it. No suprise.

      --
      If your code is acting bloated, and is running rather slow, it's likely and predicted that some loops you will unroll.
  3. Don't like Symantec? Try an alternative... by stefanlasiewski · · Score: 4, Informative

    AVG Antivirus is a great alternative to Symantec's Norton AntiVirus.

    It's free for home users, has a memory-resident scanner, scheduled updates, limited scheduled scans and doesn't bog down your system with unnecessary crap like the Norton or Mcafee anti-virus programs.

    --
    "Can of worms? The can is open... the worms are everywhere."
    1. Re:Don't like Symantec? Try an alternative... by chrispyman · · Score: 2, Insightful

      That's nice and all (though personally I prefer F-Prot AV ), but there are very few Antivirus software products that have Chinese versions, probably because of the rampant piracy there. The real problem with Symantec's move is that I'll bet they have a monopoly over there and that it shows they have their hand in China's pants.

    2. Re:Don't like Symantec? Try an alternative... by scubacuda · · Score: 1
      AVG finds TONS of stuff Norton misses, particularly all sorts of dropper trojans.

  4. Norton is a No-No by BinaryOpty · · Score: 2, Interesting

    No one should be using Norton anyway. I jumped Norton's ship (after using it for free for a month) after discovering you need to pay for updates past that point and it annoys you daily about it (and even offers a "remind me after..." prompt where the only choice is 1 day). The only way to stop the annoyance is to uninstall the program or buy a year subscription. I did what they didn't want me to do. Take that Symantec. Hello Grisoft.

    1. Re:Norton is a No-No by Anonymous Coward · · Score: 0

      It also intentialy starts slowing down your machine by chewing up CPU cycles to make you think that your machine is infected by a virus in order to get you to upgrade. The more days pass after the expiration, the more resources it starts to consume. Norton is just junk. It doesn't even catch as many viruses as other products do.

  5. They are catching up to fark. by Sevn · · Score: 2, Interesting

    In so much as having no sense of humor. That and the blatant censorship is starting to happen. I've actually noticed "politically incorrect" posts disappearing completley. I got my first warning about posting as an AC today. That's kinda the point of posting as an AC. So everyone else can ignore it. If things keep up, it will be just like Fark where everyone is scared to death to speak their mind for fear of bans and censorship.

    --
    For every annoying gentoo user, are three even more annoying anti-gentoo crybabies. Take Yosh from #Gimp for example.
    1. Re:They are catching up to fark. by Synonymous+Yellowbel · · Score: 1
      If things keep up, it will be just like Fark where everyone is scared to death to speak their mind for fear of bans and censorship.

      Better than K5, where useful discussion and diaries are drowned out by an avalanche of trolls...

      steve

  6. Hmm. by rincebrain · · Score: 1

    If they block this at the request of the Chinese government, one wonders how long it will take before the US government makes similar requests...

    I hope that the government won't do this. I doubt they will, any time soon. But with the way government regulation of IT is going, I wouldn't be surprised at legislation like this...

    --
    It's only an insult if it's not true.
  7. Someone must say it... by Anonymous Coward · · Score: 0

    Suppress: v. to contain, restrict, or otherwise withhold some content from dissemination.

    Supress: adj. Lacking the time required to ensure proper spelling and grammatical accuracy.

  8. Test AC Posting by Anonymous Coward · · Score: 0

    I am posting as an AC to test slashdot's new system of warning people about AC comments being deleted. We'll see if I get one!

    Huzzah!

    1. Re:Test AC Posting by Anonymous Coward · · Score: 0

      ditto

    2. Re:Test AC Posting by Anonymous Coward · · Score: 0

      I don't know what this is about, but I suppose that by posting AC, I'll learn.

  9. False positive? by Spoing · · Score: 3, Insightful
    Virus/trojan detectors give false positives all the time.

    Yanking a program you know about out just because one of these programs says it is bad isn't smart...though I've felt like choking a few admins who took any report as 100% valid.

    That said, is this stupidity or malace?

    --
    A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
    1. Re:False positive? by JohnFluxx · · Score: 1

      Malice:

      >A Symantec official in Beijing confirmed that Norton's
      >software had designated Freegate a "Trojan horse",
      >but would not give details of why it had done so.

  10. Um... by oldosadmin · · Score: 1

    All non-free virus scanners nowdays require subscriptions.

    --
    Jay | http://oldos.org
    1. Re:Um... by BinaryOpty · · Score: 2, Insightful

      But do all bug you daily with a pop-up box that disrupts any full-screen program currently running (and crashes a few), pointing out your subscription is up, or not allowing you to turn the box off or extend the amount of time it appears by? No, really, do they? I've only used Norton, so tell me if McAfee or Panda does that.

    2. Re:Um... by oldosadmin · · Score: 2, Informative

      Pretty well... yeah

      All of them are obnoxious.

      McAfee being the most so... it has one of those tray popups which will kill your fullscreen game.

      PC-Cillin I don't think does anything obnoxious, but I haven't used it for a few years.

      EZ-Trust Antivirus will popup a web browser directed to their site.

      I think that's about it. I've never used Panda. I don't use a virus scanner, personally. I have a firewall and I'm the only one with access to my computer, and I only run trusted executables.

      --
      Jay | http://oldos.org
    3. Re:Um... by Sylver+Dragon · · Score: 1

      This is why I unsinstalled Trendmicro's offering, plus all I wanted was an anti-virus program, not a whole security suite. It finally pissed me off while I was playing Thief 3, it would pop up its reminder to update, and crash Thief 3 (granted, any switching to the desktop would crash Thief 3). So, I uninstalled it and have been running without any sort of AV for a few weeks. I'm now downloading AVG to give it a try and see if I like it.

      --
      Necessity is the mother of invention.
      Laziness is the father.
  11. Wow. Did anybody read that last link? by bersl2 · · Score: 0, Offtopic

    Even I can't come up with something that stupid.

    Either that, or something truly bizarre went on. I mean, I doubt the combination of a weird antenna and aliens even can produce unexplaned, defective pregnancies.

    But if it indeed does... "Truth is stranger than fiction."

  12. I'd say bouycott any software that doesn't suite by tod_miller · · Score: 2, Insightful

    I personally believe anti-virus it a waste of time.

    1: Trusted sites should be trusted.
    2: It is new viruses that are more prevalent, and the ones you are less likely to be protected against.
    3: Behavioural systems (i.e. secure systems) shoudl be in place to stop NEW code doing things, like an internal firewall - would you like xyz.exe whihc has been on your system for 30 minutes / 3 days or whatever to acces ABC resource / network, reg setting etc.
    4: Signed content can lead to more trust.
    5: this would stop dialers, toolbars, spyware, fuckware, malware, shitware, pancreasware and all other forms of binary information that belongs in /dev/null

    I think anti-virus has gone far enough. I use google when I download a funny file, I google the filename, I google the filesize. If I am still not happy, I don't run it.

    I mean who would run whoah_funny_check_this_shit_out.exe ??

    setup.exe's - again, d/l from a trusted source. Run as a low priv user if need be, test it on a sandbox to be sure... but don't fsskin virus scan it - and then run it on your prized system, because anyone can right a rm -rf ~ and cause simple havoc, and this file will not be picked up by any antivirus software.

    Don't reply on virus software, I'd say it gives a false sense of security at the best of times.

    Educate users is important, and I would love to see an 'untrusted file' idea, where a custom made trojan would find itself in a pretty lame sandbox if someone runs it the first time, this behaviour gets recorded, then judged if it may be harmful, and above certain levels (tried to access a network resource, tried to remove a file, tried to access existing registry tree, tries to send emails to your entire address book) it quarantines, and alerts an admin.

    Any linux developers like that idea? temporal / quantitative security measures for automated sandbox maintenance and binary acceptance program.

    or gnutqsmasmbap.

    --
    #hostfile 0.0.0.0 primidi.com 0.0.0.0 www.primidi.com 0.0.0.0 radio.weblogs.com
  13. VMware ideas fr virtual sandbox by tod_miller · · Score: 1

    Apologies for abhorrent spelling in my posts. THey are typos, honest gov.

    Using VMWare with virtual networking and memory and file system woudl be great to sandbox exe's. This could be done on the fly - or even as you run it, the executions get fed through a filter, that would allow any program to run normally until it hit an alarm in the FS, net, reg, or mem allocation.

    even internal hackers would have to get thier code past this system, and therefore alert an admin.

    internal firewall every resource, but allow the program to run UNTIL it hits this point of alarm.

    In case Microsoft needs help filling in 3000 patent forms:

    I copyright all ideas, related to, pertaining to, based on, genetically similar or even sounding like the above, and release it under GPL / copyleft / erm... yeah, opensource.

    --
    #hostfile 0.0.0.0 primidi.com 0.0.0.0 www.primidi.com 0.0.0.0 radio.weblogs.com
  14. Re:I'd say bouycott any software that doesn't suit by Kris_J · · Score: 3, Interesting
    I personally believe anti-virus it a waste of time.
    Not true. Our email attachment rules (ie; no .scr, .pif, .exe files, etc) are pretty good at blocking malicious content while letting the legit stuff through, but being able to detect a known virus makes things a lot cleaner. If it's just whatever.scr, we bounce it, but if it's whatever.scr with a known virus we blackhole it.
  15. Re:I'd say bouycott any software that doesn't suit by tod_miller · · Score: 2, Interesting

    I have to say I half agree with you.

    Our email attachment rules - block all that content. f course people zip up some of that content, so maybe unzip and block, this is email attachment filtering.

    Checking for knwon virus signatures, yes this is an application of virus detection that is not used as a security measure, but as a decision maker, or audit trail.

    Outlook is causes 99.99999* of virus problems, allowing someone to send email as you, with viruses in it - embarrassing!

    I still cannot believe people use that....

    Knowing a file is a known virus is ok, and useful, but you are right in saying that mail attachment filters are better. Remove anythign remotely hazardous.

    Send a link to a file if you want someone to d/l it, and then use the trust rule, and fallback on the behavioural checking.

    Never be in a position to run code that you have been assured by a virus checker that it is not a virus.

    Of course, my approach would stop trojans, worms, scripts, anything that has this efect (each application can extend the security layer into its own realm, so openoffice could have a protect sandbox that would test scripts and if it crosses a line, like tries to embedd itself, or open a new document, or search or something ,notify the user.

    --
    #hostfile 0.0.0.0 primidi.com 0.0.0.0 www.primidi.com 0.0.0.0 radio.weblogs.com
  16. So wouldn't the obvious solution be.. by bairy · · Score: 2, Informative

    Don't use Norton if you wanna use Freegate?

    --


    Get paid to search..It's geniune and
  17. Re:I'd say bouycott any software that doesn't suit by kalidasa · · Score: 4, Insightful

    There were viruses a long time before Outlook. There will be viruses a long time after Outlook. As far as "allowing someone to send email as you" - that's not Outlook's fault, that's SMTP's fault: the From: header is never authenticated. Yes, Outlook's security model sucks, but security issues are a lot more subtle than you're allowing.

    For instance: what antivirus software is really designed to do is not to stop 0 day infections, but to put a limit on how long a virus can be effective. When was the last time you heard about someone who had the Michelangelo virus? Can't remember? That's because antivirus software is doing its job: preventing viruses from sticking. How about RedAlert or MSBlast (gee, Outlook had nothing to do with those, did it? Yes, we can all blame MS's sloppy approach to security, with full justice, but we have to remember that MS is a product of its niche - if IBM had ended up in the monopoly role of the monoculture, it is entirely possible that their products would have introduced "user friendly" features that undercut security, too.)

    Your approach frankly isn't going to work with the majority of users. You're never gonig to be able to prevent things like "Here is the report you asked for / report.doc.vbs" showing up in a user's mailbox when that user really was expecting a report from the putative sender (I've seen this happen - precisely what the virus writer is shooting for - and in that situation, a manager waiting for an important time-sensitive report from a subordinate, it's all too easy for the recipient to fail to notice that the icon is wrong, that there's an extra extension, etc.). Some users email exes for legitimate reasons. Some users are too busy to run an MD5 check on every attachment they get (and have you ever tried to explain how MD5 works to a secretary?). If viruses can be blamed 99% of the time on anything, they can be blamed on social engineering: the same impulses that make people give out their credit card numbers to total strangers who "call from the bank" will make viruses continue to spread.

  18. Re:I'd say bouycott any software that doesn't suit by tod_miller · · Score: 1

    no no no, I meant as you as in from your outbox, to your recipients. Even picking up replies from you.

    Not the simple

    EHLO form.me
    RCPT foo@barney-bignutts.com
    FROM whoever@Iwanttobe.com
    DATA

    from the top of my head.

    As far as I am concerned, 0 day threats are the most threatening, and the most damaging, and since they still happen Virus software ISN'T doing it's job.

    SO what, it stops old viruses. I am more worried about newer ones.

    How will the approach of filtering, and application sandboxing and education now going to stop a vbs file?

    the filter caught it.
    worm, firewall
    trojan, firewall

    internal maliscious hacking - auto sandboxing and admin alerts.

    You don't need to do MD5 summing, you dissallow binary attachments. Then peope adapt. Except for the Microsoft jpeg parser *groan* it should be safe enough to handle non binary data.

    And as in the openoffice example I gave, any script that is enabled in the future should have applicaiton controls to limit its ability to kill you.

    If however you run a program that doesn't have that, you only risk that applications zone of trust, not your whole app. So your email might go down if using a non 'trust-zonerized' email app.

    now social engineering is an argument in my court, how virus protection only gives you false sense of security.

    My whole argument is to take out applications from the loop that dupe you into a false sense of security. someone with firewall and virus checking may feel safe from hackers, and stupidly be more easy about giving out access pwds.

    right well, it isn't a perfect world, and a standard applcation sandboxing model and trust zoning at OS level is too much to ask for, even though the basic user permissions should keep things safe (you need user/application level permissions, so Bob/IE has diff access to Bob/FireFox and 'cetra.

    simple. says simon.

    --
    #hostfile 0.0.0.0 primidi.com 0.0.0.0 www.primidi.com 0.0.0.0 radio.weblogs.com
  19. Re:I'd say bouycott any software that doesn't suit by Anonymous Coward · · Score: 0

    Granted, SMTP may not be the most full-proof protocol. But Outlook and M$ deserve alot of the blame for this. The defaults and features are atrocious. How about turning OFF the preview pane as default? How about NOT allowing HTML email in the preview pane? How about NOT automatically executing macros and code in the Local Computer zone? Sure, some of these issues have been dealt with, but in all cases the solutions are sloppy, difficult to implement and in the end, useless.

  20. Re:I'd say bouycott any software that doesn't suit by kalidasa · · Score: 2, Insightful

    The whole reason zero day exploits are the most dangerous is precisely because anti-virus software exists. If it didn't, day 300 or day 3000 exploits would be as dangerous as 0 day expoits.

  21. Re:I'd say bouycott any software that doesn't suit by tod_miller · · Score: 1

    No the whole reason is because systems should be patched.

    Yet again - viruses and worms are different. Virus checking software is redundant. Filtering content and sandboxing any binary that fails a temporal or trust test.

    Worms - only newer ones are still prominent, why, because of system patching. So your argument about chicken egg viruses and anti-virus losses ground here.

    Secure, sandbox, trust, filter and patch.

    this isn't a 100% effective solution, but at least you know that. A virus checker makes you complacent.

    thats it folks.

    --
    #hostfile 0.0.0.0 primidi.com 0.0.0.0 www.primidi.com 0.0.0.0 radio.weblogs.com
  22. Doesn't take a conspiracy theorist by jhylkema · · Score: 1

    One only needs to realize that Symantec, like most American corporations, has dollar signs in its eyes at the prospect of selling its product to three billion or so Chinese consumers. Trouble is, China is a police state. Faced with the prospect of losing out, Symantec, as so often happens with American corporations, sold out and sold its customers down the river.

  23. Re:I'd say bouycott any software that doesn't suit by kalidasa · · Score: 1

    And when the virus writer finds an exploit to your trust testing code?

  24. Re:I'd say bouycott any software that doesn't suit by tod_miller · · Score: 1

    Has anyone exploited unix file permissions?

    I merely want to have the same thing, see what time the file was d/l and say, this file is new, lets fsk with it until someone with authority says it is ok.

    that is oversimplifying it.

    But if someone exploits it, it gets patched. Like jpeg, bmp and ssh exploits.

    --
    #hostfile 0.0.0.0 primidi.com 0.0.0.0 www.primidi.com 0.0.0.0 radio.weblogs.com