Live data from Hacker News

Symantec CEO says source code reviews by foreign states pose unacceptable risk

reuters.com

41–50 of 124 posts

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#41

So they're basically admitting that their antivirus tools aren't secure enough to handle a basic code review? Yup, totally makes me want to buy copies. "No, guys, security by obscurity totally works in this one case! Because it's us! Come on, you trust us right?"

You're intentionally conflating "basic code review" with "politically charged state actor performing code review", which are not the same thing.

Did they say they allow no audit or outside code review?

Or simply that political nation states who have intelligence agencies that actively subvert security solutions to compromise computers (the very things AV companies work to prevent) shouldn't have access to the very cookie pot they work to steal from?

Frankly, I have no idea why you'd let people review your source code who have a vested interest in finding exploits that they will use against people using your software.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#42

So they're basically admitting that their antivirus tools aren't secure enough to handle a basic code review? Yup, totally makes me want to buy copies. "No, guys, security by obscurity totally works in this one case! Because it's us! Come on, you trust us right?"

To play devil's advocate, they may not be worried about vulnerabilities in their code but rather vulnerabilities in their method of virus detection, the same way Google doesn't share details about their search algorithm partly so it isn't gamed by spammers. Actually this is common in software that is meant to protect against sophisticated attackers. Blizzard and Valve used to have periodic mass bans but they would ne…

I can second that. A lot of virus detection basically boils down to detecting this particular substring. Which is usually quite easily bypassed.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#43

Earlier quoted context omitted.

To play devil's advocate, they may not be worried about vulnerabilities in their code but rather vulnerabilities in their method of virus detection, the same way Google doesn't share details about their search algorithm partly so it isn't gamed by spammers. Actually this is common in software that is meant to protect against sophisticated attackers. Blizzard and Valve used to have periodic mass bans but they would ne…

Somebody please reply to this. Both this comment and the above comment seem reasonable. I don't know what to believe!

For me Worrying about "vulnerabilities in their virus detection method" seems unlikely.

We're talking about downloadable software here, not a cloud service like google. Once a hostile nation state has access to your binaries (as they would with an installed product like A-V) they can just fuzz the A-V detection method to find bypasses.

Heck that's what pentesters and red teamers do on a regular basis, A-V bypass is a common thing in that world, so if people at that level can do it you can bet that nation state actors can do it.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#44

Earlier quoted context omitted.

To play devil's advocate, they may not be worried about vulnerabilities in their code but rather vulnerabilities in their method of virus detection, the same way Google doesn't share details about their search algorithm partly so it isn't gamed by spammers. Actually this is common in software that is meant to protect against sophisticated attackers. Blizzard and Valve used to have periodic mass bans but they would ne…

Somebody please reply to this. Both this comment and the above comment seem reasonable. I don't know what to believe!

I believe the latter post (obfuscating the method of detection) over incompetence.

Don't forget that nation states also produce malware (Recall Stuxnet?) [0] and evading detection is substantially easier when you know exactly what to avoid doing.

[0] https://en.m.wikipedia.org/wiki/Stuxnet

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#45

Run ClamAV instead, it's built to be run continuously, on sensitive servers, handling untrusted data sent directly over email.

Is it comparable to commercial AV solutions? Can it intercept network traffic, run executables in a sandbox, use heuristics for detecting new viruses?

> Is it comparable to commercial AV solutions?

"In a Shadowserver six-month test between June and December 2011, ClamAV detected over 75.45% of all viruses tested, putting it in fifth place behind AhnLab, Avira, BitDefender and Avast. AhnLab, the top antivirus, detected 80.28%.[9]"

> Can it intercept network traffic

"On Linux servers ClamAV can be run in daemon mode, servicing requests to scan files sent from other processes. These can include mail exchange programs, files on Samba shares, or packets of data passing through a proxy server (IPCop, for example, has an add-on called Copfilter which scans incoming packets for malicious data)."

It seems that there is a third party tool that provides heuristic detection.

Source: Wikipedia

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#46
post #41

So they're basically admitting that their antivirus tools aren't secure enough to handle a basic code review? Yup, totally makes me want to buy copies. "No, guys, security by obscurity totally works in this one case! Because it's us! Come on, you trust us right?"

You're intentionally conflating "basic code review" with "politically charged state actor performing code review", which are not the same thing. Did they say they allow no audit or outside code review? Or simply that political nation states who have intelligence agencies that actively subvert security solutions to compromise computers (the very things AV companies work to prevent) shouldn't have access to the very co…

Usually companies allow source code review beccause they're trying to sell their solutions in the countries in question.

Look at it from the perspective of those countries

Symantec "hey buy all our security software it's super-great"

Foreign Gov. Customer: "sure can we check the source code first to see if there are any heinous security bugs or NSA backdoors"

Symantec "Oh gee no, allowing to you see the source code of products we want you or companies in your country to run might compromise it's security"

Foreign Gov. Customer: "..."

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#47
post #39

Earlier quoted context omitted.

"They're not so arrogant about their code being bulletproof that" The source-code reviews by foreign states are not about checking to see 'if it works' - it's about checking that it doesn't include inserts from NSA etc.. This has nothing to do with 'security review' in the general sense of robustness, it's a 'state actor' thing. I don't see how there is a way around this. It's doubtful that Russia will allow them to…

Well, Kaspersky Lab is a russian company.

Interesting enough, the CEO of Kaspersky already offers the source code for review in the US: https://www.engadget.com/2017/07/02/kaspersky-lab-offers-sou...

Can't speak for the US, here in Germany the Kaspersky tools are used on large companies responsible for critical infrastructure. With the option for source code review, I'm still with a good impression on their tools when compared to Symantec and no option for review.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#48

Run ClamAV instead, it's built to be run continuously, on sensitive servers, handling untrusted data sent directly over email.

Is it comparable to commercial AV solutions? Can it intercept network traffic, run executables in a sandbox, use heuristics for detecting new viruses?

ClamAV's detection ability is really a joke.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#49
post #37

Earlier quoted context omitted.

Could you elaborate?

2013: http://www.businessinsider.com/the-story-of-joseph-nacchio-a... "Only One Big Telecom CEO Refused To Cave To The NSA ... And He's Been In Jail For 4 Years" 2015: https://www.forbes.com/sites/janetnovack/2015/05/01/u-s-avoi... "the government has avoided a trial in which the 65-year-old former executive planned to air what he says was his refusal, in 2001, to allow Qwest to participate in a National Security Age…

I think it's unfair not to clarify that he went to jail for insider trading.

He believes that that the government only brought the action against him because he refused to divulge user data, but he is in jail because of insider trading.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#50

So they're basically admitting that their antivirus tools aren't secure enough to handle a basic code review? Yup, totally makes me want to buy copies. "No, guys, security by obscurity totally works in this one case! Because it's us! Come on, you trust us right?"

To play devil's advocate, they may not be worried about vulnerabilities in their code but rather vulnerabilities in their method of virus detection, the same way Google doesn't share details about their search algorithm partly so it isn't gamed by spammers. Actually this is common in software that is meant to protect against sophisticated attackers. Blizzard and Valve used to have periodic mass bans but they would ne…

Well, that’s an argument they should have made! I think it’s extremely charitable to assume this is why, though, when every indication points to code-audit fearmongering.

But, you’re also forgetting that these virus scanners can also be vulnerabilities and exploits in themselves; i seem to remember one virus exploited a flaw in the compression code of a virus scanner to establish some type of malware. Just because something is a trade secret doesn’t exactly lessen the risk of it existing.

Post reply on HN