Symantec Admits Its Networks Were Hacked in 2006
Orome1 writes "After having first claimed that the source code leaked by Indian hacking group Dharmaraja was not stolen through a breach of its networks, but possibly by compromising the networks of a third-party entity, Symantec backpedalled and announced that the code seems to have exfiltrated during a 2006 breach of its systems. Symantec spokesman Cris Paden has confirmed that unknown hackers have managed to get their hands on the source code to the following Symantec solutions: Norton Antivirus Corporate Edition, Norton Internet Security, Norton Utilities, Norton GoBack and pcAnywhere."
As this includes a Corporate version, I'm sure enterprises just LOVE to hear that the company to whom they entrust a certain amount of their data security completely lied to them about the effectiveness of that security, and covered up the fact that future use of their product might be for naught.
Long signatures suck.
Was working with a company that was dealing with some security issues in late 2008, and we found out that the source of the breach was going right through Norton like a hot knife through butter. However, just about any other security solution would stop it. At that time, we theorized that whoever had created the problem had some intimate/inside knowledge of Norton systems and we even joked that "Symantec better check who has their source code".
If someone with illegally-obtained source code anonymously posts the Ghost and other file formats AND posts a credible "here's how I reverse engineered the file formats" document, and others use it to create open-source software to read the software, will Symantec have any recourse against those who write, host, or use the resulting software?