I'd assume the US govt is as much as risk as any other.
Symantec CEO says source code reviews by foreign states pose unacceptable risk
31–40 of 124 posts
Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk
#32Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk
#33> “As a vendor here in the United States,” Clark said, “we are headquartered in a country where it is OK to say no.” Until the government comes knocking and can demand pretty much everything with your only option being a secret court that always sides with the government anyway. Is it too much tinfoil to think that this isn't so much about "putting security over sales" than it is about "making sure that NSA backdoor…
Just ask the former Qwest CEO about saying “no”.
Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk
#34The article decries balkanization of tech services but it noticeably omits a middle path -- offering consulting services for open source software. Surely, in this aspect, it stands to reason that this section of the tech services industry is more robust in the face of such an encroachment. The only losers in such a situation are the likes of Symantec, whom claim secrecy and obfuscation are a feature rather than a bug…
Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk
#35Run ClamAV instead, it's built to be run continuously, on sensitive servers, handling untrusted data sent directly over email.
Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk
#36> These are secrets, or things necessary to defend
Backdoors from NSA?
Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk
#37Earlier quoted context omitted.
Just ask the former Qwest CEO about saying “no”.
Could you elaborate?
http://www.businessinsider.com/the-story-of-joseph-nacchio-a...
"Only One Big Telecom CEO Refused To Cave To The NSA ... And He's Been In Jail For 4 Years"
2015:
https://www.forbes.com/sites/janetnovack/2015/05/01/u-s-avoi...
"the government has avoided a trial in which the 65-year-old former executive planned to air what he says was his refusal, in 2001, to allow Qwest to participate in a National Security Agency program he believed was illegal."
2016:
Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk
#38So they're basically admitting that their antivirus tools aren't secure enough to handle a basic code review? Yup, totally makes me want to buy copies. "No, guys, security by obscurity totally works in this one case! Because it's us! Come on, you trust us right?"
To play devil's advocate, they may not be worried about vulnerabilities in their code but rather vulnerabilities in their method of virus detection, the same way Google doesn't share details about their search algorithm partly so it isn't gamed by spammers. Actually this is common in software that is meant to protect against sophisticated attackers. Blizzard and Valve used to have periodic mass bans but they would ne…
Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk
#39They're not so arrogant about their code being bulletproof that they're willing to hand it to an adversary and say, "Sure, knock yourself out - see if you can find any holes"? Yeah, I'm not sure that I see a problem here.
"They're not so arrogant about their code being bulletproof that" The source-code reviews by foreign states are not about checking to see 'if it works' - it's about checking that it doesn't include inserts from NSA etc.. This has nothing to do with 'security review' in the general sense of robustness, it's a 'state actor' thing. I don't see how there is a way around this. It's doubtful that Russia will allow them to…