Slashdot Mirror


A Bad Week for Symantec

Evan Hughes writes "NeoSmart Technologies has published a scathing editorial regarding 3 high-profile mistakes by Symantec Corp. — all in less than a week. In what seems to be a string of stupid mistakes culminating in the infection of CNN-parent Turner Broadcasting Systems by Rinbot— a virus dedicated to the eradication of Symantec from the known world."

18 of 239 comments (clear)

  1. maybe... by User+956 · · Score: 5, Funny

    NeoSmart Technologies has published a scathing editorial regarding 3 high-profile mistakes by Symantec Corp. -- all in less than a week

    Maybe they're not mistakes... maybe it's just a form of viral marketing.

    --
    The theory of relativity doesn't work right in Arkansas.
  2. With all due respect... by devphaeton · · Score: 4, Interesting

    ....in my experience modern Symantec products such as Norton Internet Security is the most malicious, but successful form of malware ever. It actually gets people to pay money for the product, and in a lot of cases, pay other people to install it and keep it on their system.

    I'm so glad I moved out of software maintenance and into hardware maintentance. Now I just wipe harddrives clean as a whistle and make sure the hardware works. Such a load off!

    --


    do() || do_not(); // try();
    1. Re:With all due respect... by digitig · · Score: 4, Insightful

      "Effectively free" is still overpriced as far as I am concerned. The amount it slows the system down is unforgivable.

      --
      Quidnam Latine loqui modo coepi?
    2. Re:With all due respect... by Zantetsuken · · Score: 5, Insightful

      yes, its close to zero cost when you buy the software in store, but its still subscription based, which is where they get you - its like a subsidized cell phone from a major carrier - sure, the phone is zero cost or 50 bucks off, but you've still got to pay for airtime minutes...

  3. No great loss by ravenspear · · Score: 5, Insightful

    Every experience I have ever had with a Symantec product has been utterly terrible. Generally they cause more problems than they solve.

    1. Re:No great loss by Radon360 · · Score: 4, Interesting

      Well, somewhere in 1990, Peter Norton sold things to Symantec. They (Symantec) continued to associate themselves with Peter Norton up until 2001 or so. About that time is the consensus that things went downhill. I'm not certain how much involvement Norton had with Symantec up until that point, but I'm willing to speculate that when the two parted companies, that's when Symantec began their transformation into selling the crap they do now.

      Gosh, I miss the good ol' days of Norton Utilities and the like...in DOS nonetheless. Now there was a powerful piece of software that was truly easy to use. The UI actually showed you some shred of respect that you knew what you were doing.

  4. So this is kinda obvious, but.... by rasafras · · Score: 4, Informative

    Turner apparently got hit because it had not yet updated the Symantec programs on its computers. A fix for the flaw has been available since May and security experts have repeatedly urged users to protect their computers by applying the update.

    Hmm hmm hmm people are dumb.

    1. Re:So this is kinda obvious, but.... by Bacon+Bits · · Score: 4, Interesting

      If you'd ever been the person responsible for updating the Symantec Antivirus client, you would not be so quick to judge. LiveUpdate only handles scanning engine updates and virus definitions. Anything else is a huge nightmare.

      I don't like Symantec products because they make the life of a sysadmin *more difficult*.

      --
      The road to tyranny has always been paved with claims of necessity.
  5. Symantec - semantics by L.+VeGas · · Score: 5, Funny

    a virus dedicated to the eradication of Symantec from the known world

    That's not a virus. That's a feature.

  6. Why is this is only news now? by winkydink · · Score: 4, Interesting

    because CNN is infected?

    1. Estimates are 100-150 million machines are currently part of botnets
    2. Loss estimates exceed 200 billion annually on a global basis
    3. Over 80% of all spam comes from botnets

    Yes, I can cite. Or you can Google. They are all easy to find.

    This is a HUGE problem that is, in many ways, like spam was in 1996 or 1997. The technical community acknowledges it, the average consumer has no clue, and, left unaddressed the problem and associated looses will get much, much worse.

    --

    "I'd rather be a lightning rod than a seismometer." -Ken Kesey

  7. Re:AVG by nsayer · · Score: 4, Funny
    every reboot or once a day which ever comes first.

    Since we're talking about Windows machines, I can tell you for certain which comes first.

  8. Sounds as Though Turner Made One Mistake by SwashbucklingCowboy · · Score: 5, Insightful

    A fix for the flaw has been available since May and security experts have repeatedly urged users to protect their computers by applying the update.
    Turner can't update their software in EIGHT MONTHS? That's not a problem with Symantec, that's a problem at Turner.
  9. Updates by fm6 · · Score: 5, Insightful

    People often don't update their software for years at a time. Hey, it costs. Which is why NAV is designed to update itself automatically. You just have to configure it correctly.

    I'm no fan of Symantec. It's perfectly true that they're badly run. Hey, they used to be a lot more than a "security software" company, but all their other business (natural language databases, compilers, IDEs, desktop software, backup software) just died on them. But to blame them for the ineptitude of the CNN's IT department is idiotic.

  10. Re:AVG by Southpaw018 · · Score: 4, Insightful

    Seconded. The only time I get reboots is when it's required for a security patch, or the occasional "application freaking the #$@%^& out" kinda thing...servers, workstations, all of 'em. And if it weren't for that, I'd be pushing 90-120 day uptimes on most of my machines. Yes, Windows machines.
    In fact, I'll get you the data.

    Main server has rebooted twice in the last four months for security patches, total ~19 minutes downtime.

    --
    ACs are modded -6. I don't read you, I don't mod you, I don't see you. Don't like it? Don't be a coward.
  11. Re:Is this guy serious? by SwashbucklingCowboy · · Score: 4, Informative

    What kind of virus rule updates would you not want to download?
    The kind that treat widely installed legitimate programs, e.g. Excel, as a virus.
  12. No sweat off my nose.... by purduephotog · · Score: 4, Interesting

    ... Every machine that comes to me for service has one requirement: No Norton. Take norton off, and people are *amazed* at how much faster their machines run.

    I substitute Free-av.com for Norton- better infection detection, less memory overhead, free (with the option of buying a license- I usually guilt them into doing it), and nightly upgrades.

  13. Re:Is this guy serious? by RESPAWN · · Score: 4, Insightful

    My point is this: the corporate version of Symantec does not automatically install any download rules. They leave this up to the installer who is hopefully capable of properly configuring their update rules and/or updating their servers manually, most likely so that they can properly test the latest virus definitions for errors or anomalies before pushing them in to production. See the comment below that links to the article about Excel being treated as a virus.

    I work for... well, it doesn't matter. In our facility absolutely NO patches or virus definition updates are applied without first being approved by another group whose sole job it is to make sure these pathces don't affect something critical to our operations. Furthermore, we only download our defs from approved (IE our own) sources so as to ensure that we are ONLY downloading what's already been tested.

    In short, we are all professionals and we should be capable of ensuring that our defs are up to date. We don't need (nor will we allow them to in our case) Symantec to hold our fuckin' hands throughout this process. When I install a corporate virus scanner, I fully expect to have to configure the machine policies in order to match our IT policies. If somebody's only updating their definitions once a week, then that's not Symantec's fault. That's the fault of whatever sysadmin was too stupid to properly configure his software.

    That said, I still think Symantec's a piece of shit and I wish we were allowed to use other solutions in its place, but that's not for me to decide. Their management software is no where near as feature rich as EPO, and I seem to have to spend more time dealing with Symantec issues than I do with EPO issues. (Because, yes, we do monitor our machines each day to ensure that they are updating properly. CNN we are not.) Please don't think for a minute that I like defending Symantec. I just believe in placing the blame properly where it belongs, and in this case it's the idiot sysadmins who weren't doing their job.

    --

    If Murphy's Law can go wrong, it will.

  14. Can you say AVAST? by rizzo320 · · Score: 4, Interesting

    Although they may hold on to the enterprise market, why even bother with Norton AntiVirus or Internet Security when you can get Avast AntiVirus Personal edition for free! http://www.avast.com/eng/download-avast-home.html/

    No, I don't work for them, or own stock. They've even updated it for Vista. The cost? Register for a free serial number every 14 months.

    Comodo firewall http://www.comodo.com/ is nice free step up for those who think they need something more than Windows firewall.

    In the year 2007, there is really no need for a consumer to pay for a product from Symantec/Norton, McAfee, or any other security software vendor that has been fleecing us for the last several years.