Slashdot Mirror


Symantec CEO: Source Code Reviews Pose Unacceptable Risk (reuters.com)

In an exclusive report from Reuters, Symantec's CEO says it is no longer allowing governments to review the source code of its software because of fears the agreements would compromise the security of its products. From the report: Tech companies have been under increasing pressure to allow the Russian government to examine source code, the closely guarded inner workings of software, in exchange for approvals to sell products in Russia. Symantec's decision highlights a growing tension for U.S. technology companies that must weigh their role as protectors of U.S. cybersecurity as they pursue business with some of Washington's adversaries, including Russia and China, according to security experts. While Symantec once allowed the reviews, Clark said that he now sees the security threats as too great. At a time of increased nation-state hacking, Symantec concluded the risk of losing customer confidence by allowing reviews was not worth the business the company could win, he said.

172 comments

  1. Two Choices by sehlat · · Score: 5, Insightful

    Either let nobody review the code, or let everybody in the world who wants to look at it review it. I rather suspect that crowdsourcing security reviews might actually make all code safer and more secure, if only because there WILL be friendly eyes going through it and proofreading the code.

    1. Re:Two Choices by phantomfive · · Score: 4, Informative

      Good thing Symantec is secure and has no horrible remote exploits that give hackers top-level access to the system.

      Just say no to Symantec, it can only make your system worse (they had a solid C compiler back in the 90s though).

      --
      "First they came for the slanderers and i said nothing."
    2. Re:Two Choices by Anonymous Coward · · Score: 1

      No, like everything else Symantec, that compiler was acquired, not developed by them. Again, like everything Symantec, they then proceeded to run it into the ground.

    3. Re:Two Choices by Wootery · · Score: 1

      like everything Symantec, they then proceeded to run it into the ground.

      On the upside, they would have been able to run it really fast.

    4. Re:Two Choices by Anonymous Coward · · Score: 0

      On the bright side, Symantec spun off Backup Exec. I heard it's getting better now.

    5. Re:Two Choices by Voyager529 · · Score: 2

      Just say no to Symantec, it can only make your system worse

      Sadly, being "good" and "effective" are seldom requirements for 'checkbox compliance'. I went through this with a law firm recently that was trying to upgrade everything to meet the requirements the bank had in order to do business with them. The bank didn't explicitly say they required Symantec, but a whole lot of their workstation requirements were conveniently default (or basically-default) policies Symantec has. Being a fan of ESET due to it being actually-effective, I pitched it to the client. The client trusts my recommendations and was willing to pay more for ESET, but needed the bank to sign off on it. Again, the bank didn't *require* Symantec, they were just "more familiar with it" and "considered it the best option"...at which point, going with ESET would have likely caused more political issues. Half the machines in the office needed to have their RAM upgraded to run with any meaningful level of performance after installing Symantec on them, but it makes the banks happy, which was why they preferred it, and I really can't fault them.

      After all, even for the banks, "secure systems" aren't nearly as important as "compliant systems".

    6. Re:Two Choices by mysidia · · Score: 2

      We'll be safer against the COMMON bad actor that just finds a simple bug that STANDARD REVIEW would detect.
      And less safe against bad actors that have highly-advanced specialized technical knowledge to find subtle bugs that everyone else is going to miss (Although these highly-advanced technical actors with a lot of money to spend could likely be able to reverse-engineer the entire product in their search for potential bugs).

    7. Re:Two Choices by phantomfive · · Score: 1

      what makes ESET so great?

      --
      "First they came for the slanderers and i said nothing."
  2. AC No Longer Allowing Slashdot to Review Frst Post by Anonymous Coward · · Score: 0

    access denied

  3. The end of the article is laughable by Anonymous Coward · · Score: 5, Insightful

    “As a vendor here in the United States,” Clark said, “we are headquartered in a country where it is OK to say no.”

    Yeah right and national security letters are a figment of my imagination...

    1. Re:The end of the article is laughable by GumphMaster · · Score: 4, Funny

      They might be. Do you have evidence that they actually exist?

      --
      Patent litigation: A doctrine of Mutually Assured Destruction... in which everyone seems willing to push the button
    2. Re:The end of the article is laughable by Anonymous Coward · · Score: 0

      This first rule of NSLs is that you can't talk about NSLs.

      (By the way, welcome back from under your rock, they do exist, and many companies and individuals have posted them for all to see.)

    3. Re:The end of the article is laughable by Anonymous Coward · · Score: 0

      He's also just confirmed that his company won't be selling security software to the U.S. government, since all of their software contracts have 'you provide us the source code' as part of their standard boilerplate. This has been true as long as I can remember (I'm 47).

    4. Re:The end of the article is laughable by Maritz · · Score: 1

      To be fair the NSA has oversight from FISA courts.

      Dear Leader Putin, on the other hand, does whatever the fuck he likes. And if you don't like it, you can have a nice cup of polonium tea.

      --
      I do not want your cheap brainburning drugs. They are useless for work. And I am a working man today.
    5. Re:The end of the article is laughable by Gr8Apes · · Score: 1

      We actually do - look at the reports presented by MS or Google of how many they get, offered in ranges.

      --
      The cesspool just got a check and balance.
    6. Re: The end of the article is laughable by Anonymous Coward · · Score: 0

      Yeah right and national security letters are a figment of my imagination...

      That's what they all say because the letter instructed them to say it. The first rule of an NSL is you don't talk about the NSL.

  4. Right... by Anonymous Coward · · Score: 1

    Highly likely their software is shit and it's shit all the way down and they don't want you to know how shit it is.

    1. Re:Right... by Anonymous Coward · · Score: 0

      Too late. I'm pretty sure most of the world already knows it's shit. One of the quickest ways to run a good product into the ground is to sell it to Symantec.

    2. Re:Right... by Anonymous Coward · · Score: 0

      I think it more likely Symantec doesn't want it known that it may have source code from another anti-virus company in it.

    3. Re:Right... by schleimkeim · · Score: 1

      Highly likely their software is shit

      Highly likely? Installing symantec is like giving your computer AIDS. That has always been a general rule in IT.

  5. Wrong by Anonymous Coward · · Score: 5, Insightful

    It is unreviewed proprietary source code is what poses the most significant risk. Any government technology department that fails to do a source code review of a product before deployment is committing malpractice. If a vendor refuses to cooperate their product should be barred from competition.

    1. Re:Wrong by BlueCoder · · Score: 1

      Not wrong.

      There is potential for a security leak because all software is notorious for the fact that as more people work on code the more bugs are potentially included. There is legitimate concern of governments including the US of abusing this. It is far better to allow individual independent specific companies on behalf of countries to review code.

      Far easier to vet a company and monitor it than a country.

  6. Says volumes by nehumanuscrede · · Score: 5, Insightful

    about how much he believes in the security of his own software.

    The best stuff is that which can stand up to peer review and intense scrutiny, yet retain its trust level.

    Given a choice between a closed source super-secret-trust-us-its-secure platform or an open source peer-reviewed-I-dare-you-to-break-it one, guess which one I would prefer to go with ?

    1. Re:Says volumes by Anonymous Coward · · Score: 0

      You get what you pay for generally

    2. Re:Says volumes by blindseer · · Score: 3, Interesting

      Says volumes about how much he believes in the security of his own software.

      I worked on secure systems before. It was common to use well documented algorithms for encryption. The mathematics showed the encryption to be secure. The implementation would be trivial rewrites of the encryption, so not any different than anything open source. We'd pair the encryption we had with open source implementations to assure we did it correctly.

      One thing we could not do was reveal our code. In fact even mentioning which encryption we used was considered a security violation. This was done to deny an attacker as much information as possible for an attack. Sure, the code was likely very secure, but we weren't under any kind of obligation to give attackers anything that could make their life of snooping into the communications easier.

      There is still a possibility that someone might be able to prove the encryption we used was not as secure as previously believed. We'd still enjoy security by obscurity. The assumption was that if the encryption was flawed then attackers would still have to go through the effort to find out if we used the flawed encryption or not. This buys time to fix the problem.

      Most encryption is based on the idea of creating a key with enough bits that any brute force attack would have to try all the combinations to break. By keeping the algorithm a secret then we have effectively added a few more bits to the key. That adds that much more time to an attack.

      Then there is the matter of intellectual property and industrial espionage. By sharing the code with the government there is a possibility of something unique and valuable being revealed to a potential competitor to copy and sell, or possibly patent and claim infringement on the original authors. Maybe the rights to the code would hold up in court but that still means the expense of going to court.

      --
      I am armed because I am free. I am free because I am armed.
    3. Re:Says volumes by Anonymous Coward · · Score: 0

      Isn't this kind of like advertising the brand and model of all locks and cameras that guard your home, then daring everyone to try and come and get it?

      If you do none of this, a potential attacker has to do 100% of the legwork.

    4. Re:Says volumes by Anonymous Coward · · Score: 0

      By sharing the code with the government there is a possibility of something unique and valuable being revealed to a potential competitor to copy and sell, or possibly patent and claim infringement on the original authors.

      Then why make the critical parts of the application compiled code running on the client's machine where it can be disassembled, debugged and otherwise analyzed? Do you honestly believe that an adversary with the resources of a nation state would not go to those lengths? Much better to keep the critical parts of the code behind a network facing service which can be much better secured, monitored and controlled. You may lose some clients that way, but honestly with a piece of software that requires daily updates of client side data to stay on top of the latest security threats isn't client side proprietary security scanning code already a lost cause?

    5. Re:Says volumes by swillden · · Score: 5, Insightful

      By keeping the algorithm a secret then we have effectively added a few more bits to the key.

      You didn't, really.

      If the attacker has your binary, decompiling it is not hard. I don't even have to decompile it in most cases, merely watching how the pattern of memory accesses is generally enough to identify at least the class of algorithm used (there aren't that many), and examination of S boxes etc., tells the rest. And if the algorithm you used is remotely close to breakable -- by brute force or any other means -- then you're hosed.

      Obscurity is very foolish except in one case: security hardware which has internal storage, and can't practically be updated. A good example is a smart card chip. In that case, all you can do is do the best job you can on the software, and the best job you can do on the hardware (whose job is partly to deny the attacker access to your software), and then keep it secret. Assuming the hardware doesn't leak it, and you don't leak it, then the attacker can only blindly fuzz the device to look for vulnerabilities.

      In practice, though, smart card makers don't do that either. They do provide full details of hardware and software, including source code, to a couple of highly-capable test labs, who spend many months poring through all of it as well as fuzzing it, attempting physical penetration of the hardware and everything else they can think of.

      If your organization did that, hired multiple outside teams of extremely talented people to attack your implementation, and you kept the attacker away from the binary as well as the source, then perhaps you gained something from the obscurity. If not, you just fooled yourselves, and made your product weaker than it would have been if you had published the design and the source code for the world to beat on.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    6. Re:Says volumes by Anonymous Coward · · Score: 0

      You get what you pay for generally

      Yes absolutely. Using what I paid for a single night with your mom, I could have gotten laid all week! But I must say DAMN! that's some goooood pussy.

    7. Re:Says volumes by Anonymous Coward · · Score: 0

      Obscurity is very foolish

      Only if you rely on it.
      If you already have security by other means then there is nothing wrong with obscurity.

      Hiding what encryption algorithm you use will probably not do anything if someone is targeting you specifically, but if the encryption algorithm you used is found to be insecure (due to quantum computing or whatever) it could prevent some opportunistic breaches if others doesn't know you used it.

      Obscurity gives some protection against opportunistic hacking like automated scripts that looks for known security holes without caring about who they are hacking.
      It doesn't do anything to prevent targeted attacks.

    8. Re:Says volumes by blindseer · · Score: 1

      The systems I was referring to did in fact have sealed boxes where if tampering was detected the memory was wiped. The communications the devices were meant to protect would still be down an unsecured wire or transmitted by radio. If the encryption used was known then that means much less resources would be needed to break it, brute force or otherwise.

      More generally though by keeping code secret, even on publicly available software, you'd be forcing a state funded actor to put the resources to decompiling the code. The code would then have to be examined for vulnerabilities. By handing over the original code there's much more information to work with. There would be comments, variable names, and so many other clues that make it readable and therefore much easier to look for a vulnerability. Sure, they'll still have the code either way but there's no obligation to hand it over on a silver platter.

      --
      I am armed because I am free. I am free because I am armed.
    9. Re:Says volumes by Anonymous Coward · · Score: 0

      By keeping the algorithm a secret then we have effectively added a few more bits to the key.

      How about if, instead of keeping the algorithm a secret - with all the bureaucratic restrictions that implies - you actually added a few more bits to the key?

    10. Re:Says volumes by sabbede · · Score: 1
      How about this:

      The Russian government tries to break into US companies all the time.

      Symantec protects many US companies.

      Letting them read the code for the software that protects their targets might not be a good idea.

    11. Re:Says volumes by houghi · · Score: 1

      By keeping the algorithm a secret then we have effectively added a few more bits to the key.

      You didn't, really.

      To make it easier: it is like saying that you are more secure, because you run SSH on port 2222 instead of 22.
      Harder to hack does not mean it is more secure. The hill is steeper, but just as high.

      --
      Don't fight for your country, if your country does not fight for you.
    12. Re:Says volumes by Anonymous Coward · · Score: 0

      To make it easier: it is like saying that you are more secure, because you run SSH on port 2222 instead of 22.

      I've seen that often. Usually by the same people who suggest securing Wi-fi by turning SSID broadcast off and enabling MAC address filtering.

      Never mind that every single packet contains the SSID and two MAC addresses.

    13. Re:Says volumes by Anonymous Coward · · Score: 0

      Telling your customers "our security is so bad that we can't allow a code review" might not be a good idea either.

    14. Re:Says volumes by swillden · · Score: 1

      The systems I was referring to did in fact have sealed boxes where if tampering was detected the memory was wiped.

      Then the obscurity wasn't *completely* pointless. But still mostly pointless. If your algorithm is broken, "adding a few bits" is extremely unlikely to make any difference. If it's not broken, then adding a few bits makes no difference... and by keeping it secret you're running the risk that you have serious flaws that you don't know about, which could completely destroy the security. Bad idea.

      More generally though by keeping code secret, even on publicly available software, you'd be forcing a state funded actor to put the resources to decompiling the code.

      Which takes seconds.

      The code would then have to be examined for vulnerabilities. By handing over the original code there's much more information to work with.

      A little, sure. Enough to matter? Not at all. I work with a lot of people who do reverse engineering for a living. Not having source slows them down very, very little.

      Also, I note that you did not confirm that your organization had outside penetration testing done. That right there proves that your organization doesn't know how to write secure software. Please tell me what hardware we're talking about so I can avoid it.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    15. Re:Says volumes by blindseer · · Score: 1

      Also, I note that you did not confirm that your organization had outside penetration testing done. That right there proves that your organization doesn't know how to write secure software. Please tell me what hardware we're talking about so I can avoid it.

      I can assure you that the organization I worked for does know how to write secure software. You cannot buy these devices as they were built for a specific use and even saying the name of the project might be a security violation. I was not knowledgeable of all the design and testing involved because everything was need to know. I had general ideas on their ultimate use, the cases they were put in, the kind of wire or radio used, and so on. I know that there were tamper switches on the cases because those signal lines had to be handled. I didn't know everything about the hardware just like the people that designed the cases didn't know everything about the software. After we were done with our own internal testing everything was handed over to the customer for their own testing. It's quite possible there was penetration testing but no one thought I needed to know. I could say a lot about what was done but you don't need to know.

      The point is, and you admit to it, that not having the source code will slow down an attack. We can debate how much but knowing it will slow down an attack is sufficient to go through the effort of keeping certain design choices secret.

      --
      I am armed because I am free. I am free because I am armed.
    16. Re:Says volumes by Anonymous Coward · · Score: 0

      I take it by your silence that I've got you pretty fucking steamed, now, huh?

      I thought you were having fun.

    17. Re:Says volumes by swillden · · Score: 1

      I can assure you that the organization I worked for does know how to write secure software.

      Maybe, but I'm skeptical.

      The point is, and you admit to it, that not having the source code will slow down an attack.

      Trivially.

      We can debate how much but knowing it will slow down an attack is sufficient to go through the effort of keeping certain design choices secret.

      No. That is not enough to justify reliance on secrecy. There has to be some other reason, or it's just self-deception.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
  7. Oh, Really? by Bruce+Perens · · Score: 5, Insightful

    I've published the source code of my own products since about 1987. The difference between Symantec and me is that I give the source code to everyone, and I give them an incentive to read the code, because they can also redistribute and modify it, and put it to any use.

    And of course a national entity that wants to enough, like the government of Russia, is going to get a look at the Symantec source code even if it means getting someone into a job there to do it. So, isn't Symantec just saying that their proprietary paradigm is a poor one from a security perspective?

    1. Re:Oh, Really? by Anonymous Coward · · Score: 0

      According to Wikipedia, they became a $4B company with 11K employees in 35 years. Not too bad. In the open source world, I think only Red Hat is anywhere in range.

    2. Re:Oh, Really? by Dantoo · · Score: 5, Funny

      I think the most significant thing about this story is that Bruce Perens still visits /.

      Err hi Bruce!

    3. Re:Oh, Really? by Anonymous Coward · · Score: 0

      How many billions of dollars of sales did you have last year? K, thx.

    4. Re:Oh, Really? by alvinrod · · Score: 3, Insightful

      That's a poor argument. It's hard to count the value of open source software because in many cases their is no charge. The world wouldn't be anywhere near where it is now if there were no Linux, Apache, or various other open source products that are used the world over if everyone were stuck buying some commercial product that wouldn't necessarily even be as good.

      A lot of developers of proprietary software still use open source tools. Both git and SVN are among the most popular version control systems and very little collaborative work could occur on the levels required today without tools like that. That developers can freely use and improve those tools just means that money can be spent elsewhere. How many billions would need to be spent if FOSS like that didn't exist?

    5. Re:Oh, Really? by Anonymous Coward · · Score: 0

      Symantec has a different business model than you do, Bruce. They also have a rather substantial payroll, which I doubt you ever had to worry about.

    6. Re:Oh, Really? by Anonymous Coward · · Score: 0

      So, isn't Symantec just saying that their proprietary paradigm is a poor one from a security perspective?

      If Symantec goes through the same effort and review with the same level of software engineers as the equivalent OSS project, then leaving the source closed is a layer in an overall defense in depth strategy.

      That all being said, how can you know if proprietary software has that level of code review and quality? Also, just because something is OSS, doesn't mean it will get the attention it needs to close vulnerabilities, though that does become more likely if it is a popular project.

      I suppose the answer is it is complex. Still, if I had to choose between a popular OSS solution with a good track record for security and a closed source solution with an apparent good record, but no real way of knowing what is really inside, then I'd choose OSS. That might change if the closed solution was audited by a group I trusted, and it might not. (That group would certainly not be the Russian government.)

      Ultimately, security these days is an ever evolving challenge. Multiple independent layers help. A key one is often provided these days by walled gardens, though apt-get in linux does basically the same thing with its security features.

      I suppose my final answer is if the only thing I have to go on is popular proprietary solution or popular OSS solution, I'd go OSS. After all, In the absolute worst case you have the source and can address any issues that occur yourself. If I had a lot more information, proprietary might win, but you have to consider a lot of factors.

    7. Re:Oh, Really? by swb · · Score: 1

      While I agree with you philosophically, I think in terms of an AV program on Windows you're dealing with a unique set of vulnerabilities and a black hat state organization would want to know every detection technique and evasion detection trick they could. It's kind of a fundamentally insecure environment to begin with.

    8. Re:Oh, Really? by Anonymous Coward · · Score: 0

      The difference between Symantec and me is that I give the source code to everyone

      Well, that and one is a household name, leader of an industry, and wildly wealthy while the other is not.

    9. Re:Oh, Really? by Anonymous Coward · · Score: 0

      I've published the source code of my own products since about 1987. The difference between Symantec and me ....

      Is that their approach has landed them squillions of dollars, yours not so much...

    10. Re:Oh, Really? by Anonymous Coward · · Score: 0

      How many billions of dollars of sales did you have last year? K, thx.

      Silly child. Still haven't noticed that what succeeds and what is right are often two very different things. May you rise up and out of your current misery.

    11. Re:Oh, Really? by freeze128 · · Score: 4, Funny

      With all due respect to Bruce... Who cares about Bruce Perens? I want to know what Peter Norton thinks of this!

    12. Re:Oh, Really? by Anonymous Coward · · Score: 0

      So the product that earns the most money is the most secure?
      Yeah - Right......

    13. Re: Oh, Really? by Anonymous Coward · · Score: 0

      Your stuff is Boeing. Get lost.

    14. Re: Oh, Really? by F.Ultra · · Score: 1

      So by that logic we should pay even less attention to you.

    15. Re:Oh, Really? by Anonymous Coward · · Score: 0

      Hilarious. You're really very funny. Keep posting, please.

    16. Re:Oh, Really? by Anonymous Coward · · Score: 0

      To hell with Peter Norton - what does Peter North think about it?

    17. Re:Oh, Really? by Nite_Hawk · · Score: 1

      He comes out of the woodwork pretty regularly for security related articles. :)

  8. Another route is possible by Anonymous Coward · · Score: 0

    Guess they've not heard of IDA Pro.

  9. Good and bad nations? by AHuxley · · Score: 4, Insightful

    Who gets a review?
    USA, UK, NZ, AU, Canada?
    Some of the more trusted NATO nations? All of NATO? Nations wishing to join NATO soon?
    Some other nations? A China? Brazil? Japan?
    Why would any nation buy into a security product they have not seen all the code to?
    Other developers will just offer their products for review. How long before nations just say no review, no buy?

    --
    Domestic spying is now "Benign Information Gathering"
    1. Re:Good and bad nations? by Anonymous Coward · · Score: 0

      the government market is lucrative, but not near as lucrative as commercial and consumer markets.

      what will fuck shit up is more countries demanding source code and back doors simply to do business within its borders... regardless of whether its government is a customer or not.

    2. Re:Good and bad nations? by Anonymous Coward · · Score: 0

      “We just have taken a policy decision to say, ‘Any foreign government that wants to read our source code, the answer is no’,” Clark said.

      Symantec has effectively withdrawn from a large portion of the global market.

    3. Re: Good and bad nations? by Anonymous Coward · · Score: 0

      The state is the biggest consumer in any country. Ask Nielsen.

  10. Kaspersky Fallout by mentil · · Score: 2

    I imagine the backlash against Kaspersky, after it was found the Russian govt. was abusing security holes in its anti-virus software in order to hack computers which had it installed, is responsible for this. It seems plausible they found out about said holes due to the mandatory source-code reviews.

    --
    Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
    1. Re:Kaspersky Fallout by Anonymous Coward · · Score: 0

      You mean - The Russians have done the same as the Americans?
      Unbelievable!! Really unbelievable!

    2. Re:Kaspersky Fallout by Anonymous Coward · · Score: 0

      Actually, given that it was ISRAEL, that claimed that WHEN they HACKED Kaspersky's network they "ran across" Kaspersky being "used" to hack a NSA contractor, can we REALLY be sure that the Russians hacked ANYTHING ?
      Sounds more like Israel hacked Kaspersky and did what they do best, set up a false flag.
      After all, Mossad's motto IS "war by deception".

    3. Re:Kaspersky Fallout by drinkypoo · · Score: 1

      If I were using my imagination here, I'd imagine that the unacceptable risk is that someone will figure out that they're distributing malware on behalf of their host state.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    4. Re:Kaspersky Fallout by Anonymous Coward · · Score: 0

      Actually, given that it was ISRAEL, that claimed that WHEN they HACKED Kaspersky's network they "ran across" Kaspersky being "used" to hack a NSA contractor, can we REALLY be sure that the Russians hacked ANYTHING ? Sounds more like Israel hacked Kaspersky and did what they do best, set up a false flag. After all, Mossad's motto IS "war by deception".

      Ah Mossad, is there anything they didn't do?

      Israel has an independent judiciary, at least. Show me a judge in Russia not afraid to piss Putin off. lol.

  11. False dychotomy by Anonymous Coward · · Score: 0

    There are zero day exploits in everything, including Linux, the most viewed open source.

    "Given a choice between"....

    That's really a false dychotomy here. Closed source THAT IS ONLY OPENED TO A KNOWN ATTACKER, is the 3rd option and its the one Symantec boss is saying is bad. And it is.

    It's neither code viewed by many eyes, nor code kept as secret as possible, it's viewed by few eyes AND a lot of those eyes are from a known hacking group that's successfully undermine several democracies around the world.

    I can't help think though that Russian hacking is just a symptom of a wider problem with this rogue state. Regime change is needed. Putin has become too much of a liability when he gets so cocky he starts to try to take down the big democracies in the west.

    1. Re:False dychotomy by Anonymous Coward · · Score: 0

      >Putin has become too much of a liability when he gets so cocky he starts to try to take down the big democracies in the west.

      But he already has control over the most powerful nation in the world through that idiot in the Whitehouse!! You might as well crawl into your bed, get under the covers, and curl up into a ball, because its all over man. We're fucked.

    2. Re:False dychotomy by Anonymous Coward · · Score: 0

      >Putin has become too much of a liability when he gets so cocky he starts to try to take down the big democracies in the west.

      But he already has control over the most powerful nation in the world through that idiot in the Whitehouse!! You might as well crawl into your bed, get under the covers, and curl up into a ball, because its all over man. We're fucked.

      We were fucked long before Trump came along. This was well on it's way about the time he was born (he's 71). Should you research the history the "Civil War" is a good starting point, and even better is Andrew Jackson.

      No offense, but you don't seem to understand the true scope of the problem nor how long it has been in the making. Then you will truly -- intimately -- comprehend the nature of "we're fucked".

    3. Re: False dychotomy by Anonymous Coward · · Score: 0

      Yeah. You want to Install another Jelzin Type crook in Russia ?

      Best of luck with that idea.

    4. Re: False dychotomy by Anonymous Coward · · Score: 0

      You mean Yeltsin, the usual transliteration?

      Unfortunately, the Russian people are offered only one crook at a time to "choose" from. The USA, being slightly more democratic, is allowed to choose between two crooks.

    5. Re:False dychotomy by Anonymous Coward · · Score: 0

      Joke's on them, Trump will nuke NK, China and Russia on the way out.

      Coal power will come back once all the solar panel factories and pipelines are blown up.

      #MAGA

    6. Re: False dychotomy by Anonymous Coward · · Score: 0

      Of course Symantec could solve that problem by open sourcing the code.

    7. Re: False dychotomy by Type44Q · · Score: 1

      You think we can't tell that you're replying to your own posts?? Idiot.

    8. Re: False dychotomy by Anonymous Coward · · Score: 0

      Well you got me Type44Q. Tell me oh wise one, how did you know? What gave it away? How did you discern that my posting a mocking reply to an alarmist, insipid anti-Putin post indicated that I was the author of both of them? You're quite the detective aren't you? But you ain't the shit though. You failed to detect that I'm the AC author of all the posts under this topic.

    9. Re:False dychotomy by david_thornley · · Score: 1

      That idiot in the White House can't be controlled. He's an equal-opportunity loose 16"/50 cannon, except for his hate for Obama and those who don't worship him. Other people have made that mistake. It's similar to what the German right wing thought about Hitler in 1933, except that Hitler had ideas and was generally quite competent (unfortunately).

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  12. Breaking News: Water is Wet by mike2006 · · Score: 1

    The real news here is most Symantec customers will be shocked when they find out they were allowing foreign governments code reviews in the first place.

  13. Re:AC No Longer Allowing Slashdot to Review Frst P by Anonymous Coward · · Score: 1

    Damn. I get most of my news on the internet from AC First Posts on slashdot.

  14. Fair enough by viperidaenz · · Score: 1

    If I was a government reviewing a security product like that, I wouldn't tell them about any vulnerabilities I find. They would be much more useful to use against all of their customers.

  15. New excuse by Anonymous Coward · · Score: 0

    to merge without a pull request.

  16. CEO thinks people don't know disassemblers by Anonymous Coward · · Score: 0

    Or that software can be modified.

  17. Don't Waste Your Money by Anonymous Coward · · Score: 5, Interesting

    Step 1: US Company, Equifax allows personal ID data for 100's of millions of people to be stolen and nobody seems to care.

    Step 2: US Government condemns Kaspersky Labs for potentially leaking information to the Russians. Thus destroying Kaspersky's US market.

    Step 3: Symantec prohibits government source code reviews. Thus insuring an NSA backdoor.

    So, no matter what you do, you are screwed.
    There is clearly no such thing as Cyber Security.
    Put your money on Molson beer.
    It is a much better investment.

    1. Re:Don't Waste Your Money by Anonymous Coward · · Score: 1

      Step 3: Symantec prohibits government source code reviews. Thus insuring an NSA backdoor.

      There's the problem right there.
      An insurance company selling software.
      Which ensures there is an NSA backdoor.

    2. Re:Don't Waste Your Money by sittingnut · · Score: 5, Insightful

      usa government (and its cronies) logic :
      kaspersky software finds (as it is supposed to) nsa's new malware in a nsa contractor's private computer. alerts hq, russian gov perhaps hears about it. kaspersky is a security threat.
      meanwhile symantec never finds any nsa malware. symantec wont let others examine its source. symantec is patriotic!

    3. Re:Don't Waste Your Money by Anonymous Coward · · Score: 0

      To be fair, Mr. Eugene Kaspersky earned it's fame in the industry by his own doing.

    4. Re:Don't Waste Your Money by Anonymous Coward · · Score: 0

      You missed "responsible encryption" which ensures an NSA barn door

    5. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0

      "russian gov perhaps hears about it"

      Russian gov hears about it and we don't know how. Russian hackers steal documents from NSA contractor's computer and we don't know how.

      Another question is how come some low id Slashdot accounts are pushing the Kremlin line recently? Is it anything to do with a comment on the 20 year anniversary story saying these accounts are worth money or has the Slashdot database been hacked?

    6. Re:Don't Waste Your Money by Anonymous Coward · · Score: 0

      The barn door isn't NSA specific.
      Both China and Russia have the capability to waltz through it.
      It only stops the small players that can't afford to dance.

    7. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0

      How come that with a mishmash of hearsay and "expert" opinion people pretend to know documents were stolen?

    8. Re: Don't Waste Your Money by sittingnut · · Score: 5, Insightful

      how come some low id Slashdot accounts are pushing the Kremlin line recently? Is it anything to do with a comment on the 20 year anniversary story saying these accounts are worth money or has the Slashdot database been hacked?

      may be "low id slashdot accounts" prefer openness, individual freedom, and critical thinking, over secrecy, "security"(as defined by deep state), and propaganda.

    9. Re: Don't Waste Your Money by rxmd · · Score: 1

      how come some low id Slashdot accounts are pushing the Kremlin line recently? Is it anything to do with a comment on the 20 year anniversary story saying these accounts are worth money or has the Slashdot database been hacked?

      may be "low id slashdot accounts" prefer openness, individual freedom, and critical thinking, over secrecy, "security"(as defined by deep state), and propaganda.

      If you prefer openness, individual freedom, and critical thinking, then Russia is not where you should be looking.

      In fact, "secrecy, "security"(as defined by deep state), and propaganda" is at least as characteristic of Russia than of pretty much all Western countries. (I'm saying this as a non-Russian who speaks Russian fluently and has spent the last ten years working in 11 out of 15 CIS states.) Russia is also at least as much driven by capitalism and corporate greed and has greater social inequality. If you're disappointed with what's going on in your country, fix your own country instead of getting your inspiration from one that is even worse.

      --
      As a state gets corrupt, its laws multiply; the most corrupt states have the most numerous laws. (Tacitus, Annales 3:27)
    10. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0

      I see what you did there.

      However, conflating the poster's desire to see more world-wide openness in software with your strawman of Russian attack still makes you a moron.

      Points for trying!

    11. Re: Don't Waste Your Money by houghi · · Score: 1

      In Belgium they used to say "If you are young and you are not a socialist(*), you have no heart. If you are old and you are not a capitalist(**), you have no head."
      It seems that this is reversed now.

      (*) Meaning that social things matter more than money
      (**) Meaning financial stability is more important

      --
      Don't fight for your country, if your country does not fight for you.
    12. Re: Don't Waste Your Money by temcat · · Score: 1

      As a Russian, I can attest to that. It doesn't mean, however, that everything popular media and government agencies tell you about Russia this and Russia that is true and not propaganda and fearmongering—or sometimes a complete nothingburger, even if true to a large extent, like with the elections. Just the fact that they could do this or that bad thing (and I can say that pretty much everything is possible with the current gang in power here), doesn't mean they actually have, unless you can show some credible proof and explanation.

    13. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0

      +4 Insightful? Krembot confirmed.

    14. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0

      +5, Insightful for this comment? Your influence is much too obvious, you should be more subtle.

      It's Russians all the way down.

    15. Re:Don't Waste Your Money by BessBeysanmak · · Score: 0

      votre article est magnifique. Merci de visite notre article via ce lien

    16. Re: Don't Waste Your Money by Gr8Apes · · Score: 1

      ...everything popular media and government agencies tell you about Russia this and Russia that is true and not propaganda and fearmongering—or sometimes a complete nothingburger, even if true to a large extent, like with the elections. Just the fact that they could do this or that bad thing (and I can say that pretty much everything is possible with the current gang in power here), doesn't mean they actually have, unless you can show some credible proof and explanation.

      I believe the proof you're seeking is at least partially provided by Facebook and Google's ad sales. Russian sources spent significant funds to direct ads to attempt to influence voters in specific battleground states. That's a pretty significant smoking gun, given all the other circumstantial evidence already reported regarding Russian activities.

      --
      The cesspool just got a check and balance.
    17. Re: Don't Waste Your Money by EndlessNameless · · Score: 1

      How come that with a mishmash of hearsay and "expert" opinion people pretend to know documents were stolen?

      If his computer held classified information, no one outside the government is ever going to touch it again. If they are investigating an adversary's cyberattack, the government is never going to publicly disclose its methods, tools, or findings. That is all going to be classified too.

      I seriously doubt anyone with first-hand knowledge will be talking about it; this isn't the kind of issue where an attack of conscience will lead someone to cross the line.

      The public will never be told the details, so the closest we can get is expert speculation.

      --

      ---
      According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.
    18. Re: Don't Waste Your Money by Gr8Apes · · Score: 1

      The young definitely seem to be on the socialist path. That's not all bad, nor all good. Unfettered capitalism has led to some of the largest swindles ever seen. Even medieval kings didn't successfully gather as much power as some capitalists, because their economies were directly tied to their power. Capitalists have no such ties, destroying a country's economy has no negative bearing on their wealth if they can plunder the target country's wealth.

      Given technological progress, adoption of some ideas of socialism are inevitable, as is further regulation of capitalism.

      --
      The cesspool just got a check and balance.
    19. Re: Don't Waste Your Money by Kludge · · Score: 1

      how come some low id Slashdot accounts are pushing the Kremlin line recently?

      I think you are confusing "pushing the Kremlin line" with "not believing everything that the NSA feeds us".
      Those who have been around a long time know that Kaspersky has been a top notch computer security company for a long time. We also know that the NSA has been trying to hack everyone for a long time.
      Of course we know that the Kremlin is trying to hack everyone too, but we are not going to quickly abandon our years of experience.

    20. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0

      nothingburger

      You Russkies sure love that word. You use it all the time, mostly about your interference in the US election.

    21. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0

      low id Slashdot accounts are pushing the Kremlin line recently

      Yes, don't know how long it's been happening but I've only noticed it in the past 2 months or so.

    22. Re: Don't Waste Your Money by temcat · · Score: 1

      What I gathered from the info on the ad sales is that the spending was pretty minuscule compared to the general level of spending on the electoral informational activities, more than half of the ads were run after the elections, and the ads themselves were of a bi-partisan nature (with their content coming originally from Americans themselves), so you cannot even say how exactly Russia tried to influence the elections (meaning, whether there was a definite electoral result they tried to achieve). So, to me, it looks like it's pretty insignificant to the extent it's true.

      In addition, not every kind of influence on the elections is even bad. I for one would welcome any attempts, including by foreign players, to influence the 2018 presidential elections in Russia by publishing info on the shady business of Putin and his clique. It just has to be true.

    23. Re: Don't Waste Your Money by temcat · · Score: 2

      Well, can't say about others, but I personally do like this word. It may even be that I learned it from the discussions of US elections. In addition to what I have already listed above, the scope and significance of this meddling are indeed nothing compared to the fraud that the Russian elections on most levels are now. RT is really a bigger and more general threat to you on the propaganda front than those ads.

    24. Re: Don't Waste Your Money by Kiaser+Zohsay · · Score: 1

      I wouldn't call 88000 low.

      --
      I am not your blowing wind, I am the lightning.
    25. Re:Don't Waste Your Money by cyberchondriac · · Score: 1

      Step 1: US Company, Equifax allows personal ID data for 100's of millions of people to be stolen and nobody seems to care.

      Nobody seems to care? It's been all over the news, in every form of media; it's been a huge deal.
      They're under criminal investigation by the DoJ for possible insider trading, and there's a criminal investigation into the hack itself by the FBI.
      Those things just take time. Protesting and rioting in the streets won't help anything, and that's getting a bit overused lately anyway. And, this may finally spell the end of using SSNs for all kinds of identification purposes, which would be a significant step in the right direction.

      --

      Look back up at my post, now look back down, you're on the Internet. Now look back up. I'm a signature.
    26. Re: Don't Waste Your Money by merky1 · · Score: 1

      I like to think its more of an experience thing. IE - we've seen so many of these conspiracy theories that the current Russia fever seems way out of touch.

      Somehow low effort trolling and phishing campaigns are somehow becoming hacks. And they are massively diverting money and attention away from the real crimes. Podesta gave his password to a foreign agent. That affects a single person. Someone stole VA/OPM/Equifax data on millions of Americans. Yet we are see nothing happening, going to happen, or any changes whatsoever.

      --
      --WooooHoooo--
    27. Re: Don't Waste Your Money by Hal_Porter · · Score: 2

      It's weird how the Republicans and Democrats have swapped sides over this.

      E.g. back in 2012 Mitt Romney said that Russia was the biggest threat to the US and the Democrats mocked him for still living in the Cold War era.

      Then in 2013 Snowden fled to Russia and probably to a job with Russian intelligence. The consensus on slashdot was that was fine and he needed to get away from the NSA so he could continue to leak. Even though Putin made it clear that he could not continue to leak, at least not publicly

      https://www.cbsnews.com/news/p...

      Putin, who hosted a summit of gas-exporting nations in Moscow that included leaders from Venezuela, Bolivia and Iran, said he doesn't know if any of those attending could offer Snowden shelter.

      "If he wants to go somewhere and there are those who would take him, he is welcome to do that," Putin said. "If he wants to stay here, there is one condition: he must stop his activities aimed at inflicting damage to our American partners, no matter how strange it may sound on my lips."

      Which makes him a Russian spy, not a whistleblower.

      Back then I said

      https://yro.slashdot.org/comme...

      If you look at WWII Anglo American SIGINT like breaking the Enigma code was absolutely vital to the war effort and saved the UK from defeat. As China moves towards parity with the West and confronts Japan over the Senkakus it's not impossible the US may find itself in a similar situation. In the long run it's not impossible that Russia will threaten the Ukraine militarily - after all it did more than threaten Georgia.

      And in fact having a major SIGINT advantage over Russia and China is likely to act as a deterrent on them doing something like this. Conversely Snowden visiting both and telling them the US's capabilities is likely to make them think they're the ones with the advantage.

      The only reason you'd think Snowden did the right thing is if you think the US is the sole source of evil in the world and Russia and China are both governed by people who act robotically in the best interests of humanity eschewing any personal gain. How likely is it really that the people who govern the US are the only ones vulnerable to corruption and the far less open political systems of Russia and China magically produce incorruptible leaders?

      I'd say as bad as the US's politicians are the openness of the system means they are likely a lot less bad than those in China or Russia. In which case I'd rather the US has the SIGINT advantage. Snowden did exactly the wrong thing in taking US secrets to Russia and China and the Guardian is wrong to publish US secrets.

      And was called an 'NSA shill'.

      However now Slashdot is suddenly full of people saying that Russia hacked the election, presenting no evidence for that and calling anyone who disagrees a 'Russia shill'.

      --
      echo -e 'global _start\n _start:\n mov eax, 2\n int 80h\n jmp _start' > a.asm; nasm a.asm -f elf; ld a.o -o a;
    28. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0

      https://quoteinvestigator.com/2014/02/24/heart-head/

    29. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0

      Why do you ignore the fact that Snowden only ended up in Russia because the US revoked his passport? That's the kind of thing an NSA shill would do.

    30. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0

      If you think Russia is socialist, you have no head.

    31. Re: Don't Waste Your Money by Anonymous Coward · · Score: 0
      Here in Yorkshire, we like to say "every man is a socialist, until he owns a ferret" (ie "the means of production").

      (Mine's a pint, lad).

    32. Re: Don't Waste Your Money by HiThere · · Score: 1

      Proof of what?

      If you want to claim that it's proof that Russia interfered with the US elections, you've got a point. If you want to claim it's proof that Facebook acted above the law and isn't being punished, you've got a point. If you want to claim that Facebook are unpatriotic villians, you've got a point.

      If you want to claim it as proof of something else, you need to connect the dots. There's no obvious connection to Kapersky. (I speculate about connections, but different ones than you appear to be suggesting...though I can't really tell, as your insinuations are too unfocused. And not based on Facebook, but rather on the fact that a Russian company is subject to the Russian government.)

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    33. Re:Don't Waste Your Money by higuita · · Score: 1

      Or simply drop windows and all their closed source software with unknown number of security problems and backdoors and use open source OS (linux, *bsd, MenuetOS, TempleOS , whatever) and software

      Many people do not agree with RMS (Richard Stallman), but times proves that he is still right

      --
      Higuita
  18. Re:AC No Longer Allowing Slashdot to Review Frst P by Anonymous Coward · · Score: 0

    News that's hot. Naked and petrified.

  19. Security through obscurity by v1 · · Score: 3, Informative

    "In security engineering, security through obscurity (or security by obscurity) is the reliance on the secrecy of the design or implementation as the main method of providing security for a system or component of a system. A system or component relying on obscurity may have theoretical or actual security vulnerabilities, but its owners or designers believe that if the flaws are not known, that will be sufficient to prevent a successful attack. Security experts have rejected this view as far back as 1851, and advise that obscurity should never be the only security mechanism."

    So either the CEO of Symantec is a security idiot, or he has a better reason he's not sharing.

    And if he's claiming the reason for using Security Through Obscurity is to provide his customers with a stronger feeling of being secure, I do hope the masses aren't idiots and this backfires as spectacularly as it really should.

    --
    I work for the Department of Redundancy Department.
    1. Re:Security through obscurity by Anonymous Coward · · Score: 1

      You're creating a Steadman. The software is adequately complex to assume that there are vulnerabilities. Giving access to a hostile actor accelerates the discovery. Without aerospace grade engineering and prices, you can't create software without defects. It's still remarkably hard with the 20:+ price differential for DO-178 style processes. To claim that security through obscurity is bad is a deliberate deception by presuming t that its the only security measure. Its a helpful layer.

    2. Re:Security through obscurity by Anonymous Coward · · Score: 0

      Did you even read the summary? The new direction isn't to stop any review at all. It's to stop handing the source code to the Russian government.

      So, sure, Russian hackers (state-sponsored and otherwise) will still be able to find vulnerabilities the usual way, by exploiting soft spots. But at least they won't have the door flung wide and the carpet laid out, with the source delivered for viewing. There is nothing in the announcement that says the source won't be provided for review by, for example, US or British governments.

    3. Re:Security through obscurity by Anonymous Coward · · Score: 0

      >There is nothing in the announcement that says the source won't be provided for review by, for example, US or British governments.

      “We just have taken a policy decision to say, ‘Any foreign government that wants to read our source code, the answer is no’,” Clark said.

      The U.S. government does not generally require source code reviews before purchasing commercially available software, according to security experts

    4. Re:Security through obscurity by Anonymous Coward · · Score: 0

      Well - they have to hide all NSA back doors for all other governments.
      Or do you really believe they would not open their source for the three letter agencies, because they open it for "nobody"?
      If so - Dream on my friend, dream on.

    5. Re:Security through obscurity by Anonymous Coward · · Score: 0

      >Security experts have rejected this view as far back as 1851, and advise that obscurity should never be the only security mechanism.

      Just to play devil's advocate here, I would assume that (at least with their enterprise software), there is more to the equation than just obscurity for Symantec.

    6. Re:Security through obscurity by Anonymous Coward · · Score: 0

      The software is adequately complex to assume that there are vulnerabilities.

      All the more reason not to be hiding behind a smokescreen. Better yet, all the more reason NOT to be using self made security software VS. independently reviewed and publicly maintained software. The latter has many more users and is much more likely to have bugs noticed and fixed than your super secret sauce.

      Also due to the higher number of users, it's more likely to be hacked in a way that a nation state could defend against. Consider this: Would you as a nation state prefer that the intended targets of a hack were the general public, or would you prefer the intended target to be you? The more widespread the software is, the more likely that a hack resulting from it will be the former rather than the latter.

      In the case of the former, the attacker is looking for sensitive data, extra resources, etc. but may not expect a high value target like a government facility to be a potential victim. As such even if the attacker does try to make special considerations for the affected facility, they are at a disadvantage due to the facility already being affected by them, and the extra time it takes to implement the new considerations. Time which the affected facility can use to respond to, or neutralize the threat. (Especially if by targeting the general public, the attacker's methods alerted the affected facility to the breach.)

      In the latter case, the attack is tailor made to target the affected government facility. This means that standard defenses and response procedures may not be effective in dealing with the threat from the onset. Worse, they may depend on them for the attack to be successful. Further, due to the nature of the target, it's resolution is completely dependent on the affected facility's own ability to respond to the threat VS. the former's ability to leverage the abilities of others. (And even one's own enemies.) That translates directly into time. Time that the attacker can use to complete their objective that required breaching the facility.

      Granted, even if the software targeted is used by the general public and free to examine by everyone, it may still be used in an attack between nation states (perhaps even using the general public as a decoy), but the chances are much higher that bugs will be fixed with the OSS software than the self made code that you probably won't look at again, much less revise, unless absolutely necessary. (And most likely after an attack has occurred. This is government we are talking about.)

      Given all of that, which is the better product?

  20. So is this a by ChoGGi · · Score: 1

    Reverse Kaspersky from Russia with love?

  21. Outsource the development by Kellamity · · Score: 4, Funny

    to a third world nation.

    Then anyone can review it and probably won't be able to make any sense of it whatsoever. Unless they are fluent in spaghetti code. It's like a cheaper type of encryption.

  22. The only thing Symantec sells is FUD. by Anonymous Coward · · Score: 0

    Are there any non-anonymous Slashdot readers who will actually admit to using Symantec security software?

    And I'm not counting the millions of people who got it on a new computer and can't figure out how to remove it !

    1. Re:The only thing Symantec sells is FUD. by Anonymous Coward · · Score: 0

      I'm probably not using anything. I disable AV programs when I am developing because they are annoying and I have no idea if I ever turned it back on after last time. *shrug*.

    2. Re:The only thing Symantec sells is FUD. by Maritz · · Score: 1

      I think any company who shows their source code to russian intelligence for any reason needs their fucking head examined.

      We're talking the very definition of 'bad faith actor' here. Get a fucking mind. Get your business elsewhere.

      --
      I do not want your cheap brainburning drugs. They are useless for work. And I am a working man today.
    3. Re:The only thing Symantec sells is FUD. by Anonymous Coward · · Score: 0

      SEPM and DLP are common in enterprise environments. Much like Microsoft in its battles against Linux in decades past, you are too caught up in the home desktop environment.

  23. Translation by Anonymous Coward · · Score: 0

    CEO: "At a time of increased nation-state hacking, Symantec concluded the risk of losing customer confidence by allowing reviews was not worth the business the company could win"

    Translation: our antivirus software is now spyware, and we don't want anybody to find out.

  24. Real risk is discovering the backdoors by Anonymous Coward · · Score: 3, Interesting

    they put in for NSA.

    You guys all misunderstood what they feared about. They are not afraid of foreign governments finding flaws in their software, they are afraid of foreign governments finding the NSA backdoors, and thus banning Symantec in their country. With the USA's example of banning Kaspersky, Symantec didn't even have any grounds to complain.

    1. Re:Real risk is discovering the backdoors by Anonymous Coward · · Score: 0

      You guys all misunderstood what they feared about. They are not afraid of foreign governments finding flaws in their software, they are afraid of foreign governments finding the NSA backdoors, and thus banning Symantec in their country.

      Which means that all of the patriotism crap has backfired spectacularly as Symantec just showed their (and the US government's) hand: "Oh! We'll ban the software of foreign nations in our government because they let us view their code and there MAY be backdoors in them, but DON'T LOOK AT OURS! Nope nothing to see here."

      At least Kaspersky had the balls to allow the review, backdoors or not. Symantec is acting like they have something to hide, and I don't mean IP. This is just yet another reason to avoid US IT Companies. It should be 100% assumed certain that the US government has a hand in every single on of them, AND that US government backdoors are present in all of their products and services.

      Seriously, the US government needs to at the very least shut the hell up about backdoors and the like if they want their IT industry to survive into the next few decades. A better option would be to come out against backdoors and openly support and encourage independent peer review of the US IT industry's products to help rebuild trust. Of course that won't happen. There's too much "we need to ban source code review requirements at the international free trade agreement level" talk going on to have that become reality. *Hint Hint* Why do you think they want to ban source code review requirements?

    2. Re: Real risk is discovering the backdoors by Anonymous Coward · · Score: 0

      Mod up.

      It's the only thing that really makes sense.

  25. Cost benefit by spinitch · · Score: 1

    Why share source when fair chance could be leaked to hackers and / or competition with no business case. Open source might be ideal but many Companies make more money and potentially can make better products investing in development, support etc.. The CEO indicated there was not a good business case to share. His judgment but seems rational.

    1. Re:Cost benefit by Anonymous Coward · · Score: 0

      The antivirus definitions are the product, not the scanner. They could easily sell that and open source the scanner.

    2. Re:Cost benefit by Swave+An+deBwoner · · Score: 1

      Almost all AV these days uses more than simple known code fingerprints; additionally they use, e.g., heuristic scanning. Probably the fingerprints are not the concern because anybody who buys the product gets a copy of the fingerprints in a file. Probably it's exposing potential flaws in the scanner logic that is the concern.

  26. bi-lateral review agreement by Anonymous Coward · · Score: 0

    fine, if they want to see the code, show us yours. you want to sell in the USA - show us your code. easy peazy lemon squeezy.

  27. Lol by Anonymous Coward · · Score: 0

    NSA just kopy katted KGB! Quite the honor.

  28. Re:AC No Longer Allowing Slashdot to Review Frst P by Anonymous Coward · · Score: 0

    It's been too long I need some hot grits!

  29. Backwards by uvajed_ekil · · Score: 1

    *NOT* allowing source codes reviews poses unacceptable risk. I guess I STILL won't be using Symantec products.

    --
    This is a hacked account, for which the owner can not be held responsible.
  30. Symantec don't allow governments access to source by najajomo · · Score: 1

    "Symantec's CEO says it is no longer allowing governments to review the source code of its software because of fears the agreements would compromise the security of its products."

    It wouldn't surprise me if the state security apparatus didn't already have access to Symantec code through their embedded agents.

  31. Re:AC No Longer Allowing Slashdot to Review Frst P by Anonymous Coward · · Score: 0

    It's been too long I need some hot grits!

    Sharks with mother fucking lasers on their heads.

  32. Re:Symantec don't allow governments access to sour by Anonymous Coward · · Score: 0

    "no longer allowing" meaning they've already seen the source code. Not showing it to them a second time isn't going to change the fact that they've already seen it, and I seriously doubt incremental updates will change that much as most of the source code won't change much over time (assuming it's typical of most projects).

  33. Just another reason by geekprime · · Score: 1

    Not to buy symantic.

  34. Security through obscurity by axettone · · Score: 1

    Not surprisingly, their products are among the least reliable on the market. Those who make such claims should not even work on the safety of a closet. Surely this is an additional reason not to buy their software and not to recommend it to customers.

  35. wikipedia Symantec by pigsycyberbully · · Score: 0

    Endpoint bug

    The arrival of the year 2010 triggered a bug in Symantec Endpoint. Symantec reported that malware and intrusion protection updates with "a date greater than December 31, 2009 11:59pm [were] considered to be 'out of date.'" The company created and distributed a workaround for the issue.[68]
    Scan evasion vulnerability

    In March 2010, it was reported that Symantec AntiVirus and Symantec Client Security were prone to a vulnerability that might allow an attacker to bypass on-demand virus scanning, and permit malicious files to escape detection.[69][70][citation needed]
    Denial-of-service attack vulnerabilities

    In January 2011, multiple vulnerabilities in Symantec products that could be exploited by a denial-of-service attack, and thereby compromise a system, were reported. The products involved were Symantec AntiVirus Corporate Edition Server and Symantec System Center.[71]

    The November 12, 2012 Vulnerability Bulletin of the United States Computer Emergency Readiness Team (US-CERT) reported the following vulnerability for older versions of Symantec's Antivirus system: "The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corporate Edition (SAVCE) 10.x, and Symantec Scan Engine (SSE) before 5.2.8 does not properly perform bounds checks of the contents of CAB archives, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file."[72]

    The problem relates to older versions of the systems and a patch is available. US-CERT rated the seriousness of this vulnerability as a 9.7 on a 10-point scale. The "decomposer engine" is a component of the scanning system that opens containers, such as compressed files, so that the scanner can evaluate the files within.[citation needed]
    Scareware lawsuit

    In January 2012, James Gross filed a lawsuit against Symantec for distributing fake scareware scanners that purportedly alerted users of issues with their computers. Gross claimed that after the scan, only some of the errors and problems were corrected, and he was prompted by the scanner to purchase a Symantec app to remove the rest. Gross claimed that he bought the app, but it did not speed up his computer or remove the detected viruses. He hired a digital forensics expert to back up this claim. Symantec denied the allegations and said that it would contest the case.[73] Symantec settled a $11 million fund (up to $9 to more than 1 million eligible customers representing the overpaid amount for the app) and the case was dismissed in court.[74][75]
    Source code theft

    On January 17, 2012, Symantec disclosed that its network had been hacked. A hacker known as "Yama Tough" had obtained the source code for some Symantec software by hacking an Indian government server.[76] Yama Tough released parts of the code, and threatened to release more. According to Chris Paden, a Symantec spokesman, the source code that was taken was for Enterprise products that were between five and six years old.[76]

    On September 25, 2012, an affiliate of the hacker group Anonymous published source code from Norton Utilities.[77] Symantec confirmed that it was part of the code that had been stolen earlier, and that the leak included code for 2006 versions of Norton Utilities, pcAnywhere and Norton Antivirus.[77]
    Verisign data breach

    In February 2012, it was reported that Verisign's network and data had been hacked repeatedly in 2010, but that the breaches had not been disclosed publicly until they were noted in an SEC filing in October 2011.[78] Verisign did not provide information about whether the breach included its certificate authority business, which was acquired by Symantec in late 2010.[78] Oliver Lavery, Director of Security and Research for nCircle, asked rhetorically, "Can we trust any site using Verisign SSL certificates? Without more clarity, the logical answer is no."[79][80]
    pcAnywhere exploit

    On February 17, 2012

  36. Critical Code Reviews by SpaghettiPattern · · Score: 1

    Critical Code Reviews lead to better code. Perform those thoroughly in house and you should pass any review with flying colors.

    Usually the "Critical" bit together with preposterous egos is usually the problem within most organisations. Nobody dares to tell the guru he's wrong. And no manager is ever rewarded for solving difficult problems, unless they can't be circumvented with loads of babble.

    I know.

    --

    I hadn't the slightest objection to his spending his time planning massacres for the bourgeoisie... (P.G. Wodehouse)
  37. "risk of losing customer confidence" by entropy01 · · Score: 2

    Call their customer service sometime and you will lose all confidence.

  38. It's okay by Anonymous Coward · · Score: 0

    Once you know how to read x86, everything is open source.

  39. Reviewing source code means nothing by acoustix · · Score: 1

    How can anyone prove that the source code they are reviewing is the actual product being used? What government has that kind of resources anyway?

    --
    "A plan fiendishly clever in its intricacies"- Homer Simpson
  40. More reason to be careful with Symantec Products by TomGreenhaw · · Score: 1

    Imagine a state where a drug company said that it would refuse to allow government health organizations to examine all aspects of their products before approving of their sale.

    There must be balance between security by obscurity and complete openness.

    --
    Greed is the root of all evil.
  41. The Jews! The Jews did it! by Anonymous Coward · · Score: 0

    Lol, hatred runs strong in this one!

  42. Memory accesses? by Viol8 · · Score: 1

    " merely watching how the pattern of memory accesses is generally enough to identify at least the class of algorithm used "

    Oh come on, you think nobody has thought of that and doesn't game the algorithm to make a load of pointless and unnecessary memory accesses in order to fool anyone with a logic analyser sitting on the bus? These days the speed hit doing so is almost irrelevant.

    1. Re:Memory accesses? by Anonymous Coward · · Score: 0

      Sure people do that and it can slow things down because you have to separate the wheat from the chaff. However, there is only one correct path through the algorithm and you know what goes in and what comes out, which means that you can still trace the way through the maze they laid out. Imagine that it really is a maze that a bunch of people are running at the same time and they can change their shirt color at will, sure it looks chaotic and hard to do in real time, but you can see the shirt colors and record the run. Then starting at both ends and working your way towards the middle over the recorded data and you can eventually make your way there.

    2. Re:Memory accesses? by swillden · · Score: 1

      Oh come on, you think nobody has thought of that and doesn't game the algorithm to make a load of pointless and unnecessary memory accesses in order to fool anyone with a logic analyser sitting on the bus? These days the speed hit doing so is almost irrelevant.

      The speed hit is not irrelevant. Performance is still a significant challenge for many applications, even on desktop and server class machines -- and definitely for mobile and embedded.

      And it wouldn't matter much anyway. Worst case (and very unlikely) it might make the attacker have to bother with decompiling.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    3. Re:Memory accesses? by Viol8 · · Score: 1

      You can't decompile the binary if you can't get to it - if its encrypted in firmware and taking the lid off the chip destroys it.

    4. Re:Memory accesses? by swillden · · Score: 1

      You can't decompile the binary if you can't get to it - if its encrypted in firmware and taking the lid off the chip destroys it.

      In that case, and if it's not feasible to patch it, and if you've really done your due diligence (pen testing), then secrecy might make sense. But, really, it's the "not feasible to patch it" that is the reason for and justification of secrecy, not the rest.

      Nit: if the firmware is inaccessible, there's no reason to encrypt it. Unless you have another even more secure component inside which holds the decryption key? And there's no point in that unless that other more secure component not only decrypts the firmware but also plays some other more crucial role in the secure operation, meaning it is your true trust boundary.

      Also note that it's never completely inaccessible. You can raise the bar, make penetration very expensive, but you cannot make it impossible. Therefore, unless you have some constraint that makes reactive security (patching) impossible to exercise in a timely fashion, you should get as much scrutiny of your design and implementation as possible and fix all of the vulnerabilities found, quickly. Even if it's inside "secure" hardware.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
  43. Antivirus software is a huge exception . . . by Wrath0fb0b · · Score: 1

    I want to make clear, for the majority of software I am strongly of the opinion that perfect knowledge of the source code should not allow an attacker any advantage because the security properties are invariant to the implementation. For a trivial example, you can review the libOTR or TrueCrypt code all day, but the confidentiality of my encrypted volumes rests on the underlying cryptographic ciphers and my ability to keep the password a secret.

    But I actually agree with Symantec that AV is a unique exception to this rule, and I justify that by looking at the relationship between the AV software and the threat against which it (allegedly) defends. Specifically, AV software is supposed to detect and quarantine executables running at the same level of privilege as the AV.

    So it's essentially an arm's race, using the vagaries of the Windows NT process management as a battlefield. Malware tries to hit itself (from, e.g. EnumProcesses or other attempts to inspect it), AV tries to find it and, in the process, hide itself from malware that would disable or compromise it. In this context, knowing the exact method by which either side works is actually helpful -- and obscurity here (unlike virtually everywhere else) is actually security.

    Note there is a weird overlap here between malware and anti-cheat-measures taken by games. In both cases, there is a user-level process that wishes to conceal itself from other software on the system that wishes to inspect/modify its behavior. In practice, any OS facility used for AV can similarly be used by a cheat program, especially if all the program wants to do is read information (like enemy locations in an FPS) from memory.

  44. History by Anonymous Coward · · Score: 0

    Jan '84 Macintosh is introduced with great success.

    Sept '85 - MS releases excel for the Mac by convincing Jobs to share Mac's source code to properly integrate Excel into Mac.

    Dec '87 - Windows 2.03 rolls out resembling Mac's GUI look and feel.

    Mar '88 - Apple sues MS for copyright infringement.

    Gates walks away from lawsuit unencumbered to become (off and on) the richest bastard in the world.

    What could go wrong?

  45. ALL software should be Open Source by Anonymous Coward · · Score: 0

    ALL source code of ALL software should be available to ALL parties for the asking at ANY time. You should be able to compile it to an exact byte-for-byte copy of the executable, and you should be able to modify it for your own personal use. Imagine Windows 10 with no 'telemetry', 'Cortana', forced updates, or any other component that invades your privacy or usurps your sovereign right to your own hardware. It would be a MUCH better world.

  46. obvious solution by Anonymous Coward · · Score: 0

    there's better solution for code review problem. give russians some few million lines of spaghetti derived from standard hello world -program. While it might not have the feeling of reading something useful, it'll keep government happy without exposing your valuable security holes to foreign powers.

  47. Re:AC No Longer Allowing Slashdot to Review Frst P by Anonymous Coward · · Score: 0

    Does it run linux?

  48. Security related? by Anonymous Coward · · Score: 0

    Then yes, it needs to open sourced.

    Not security related? Then I don't care.

    Closed source either way? Well, I wont bother. Security related and closed source? Nope.jpg.

  49. Let's see if they will also deny US govt requests by Anonymous Coward · · Score: 0

    in fear CIA will use the gained knowledge to weaponize Symantec products for spying in the US and abroad

  50. Answer a simple question Bruce Perens... apk by Anonymous Coward · · Score: 0

    See subject: What's simpler to do to find bugs in code - step trace closed source in a debugger OR have the sourcecode itself?

    * I'll answer for you - having the actual sourcecode (hence even YOUR OpenSORES argument plays against you here in fact... yes, it works BOTH ways & judging by what I've seen? Moreso AGAINST you & why? See below!)

    (NO QUESTIONS ASKED)

    Funny part is the OpenSORES movement (of which you are part of) always says "all those eyes on the sourcecode makes safer wares" well - I don't see it - you get bugs too (since much of who uses your code don't code themselves OR @ a level where they can identify those bugs). The bugs STILL occur & ARE EASIER TO SPOT when you have the sourcecode!

    APK

    P.S.=> Fuzzers & debuggers CAN find things but it's MUCH HARDER TO DO than having actual sourcecode to look @ it steptrace in a compiler (delinting alone is an example)... apk

  51. WTF? by Anonymous Coward · · Score: 0

    ...source code, the closely guarded inner workings of software...

    I'm not feeling a whole lotta love for a technical "report" in which the author feels the need to explain what the term "source code" means. Just a hunch, but I'm guessing such a "report" isn't going to reveal too many worthwhile insights.