Live data from Hacker News

Symantec CEO says source code reviews by foreign states pose unacceptable risk

reuters.com

51–60 of 124 posts

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#51

They're not so arrogant about their code being bulletproof that they're willing to hand it to an adversary and say, "Sure, knock yourself out - see if you can find any holes"? Yeah, I'm not sure that I see a problem here.

Yes. Handing out code to everyone (open source) can provide many benefits, but there's no benefit to handing it over only to agents you do not expect to cooperate (foreign governments, or governments in general).

Plus the chance for competitors to completely understand and replicate your brand new techniques for malware exposure.

Can understand the worry for malware products from startups and innovative companies that are demonstrating an impressive work and surely need that secrecy to thrive against the market gorillas. Symantec can't really be called innovative since 2009 or so, doesn't make much sense the security by obscurity mantra unless there are other reasons.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#53
post #41

So they're basically admitting that their antivirus tools aren't secure enough to handle a basic code review? Yup, totally makes me want to buy copies. "No, guys, security by obscurity totally works in this one case! Because it's us! Come on, you trust us right?"

You're intentionally conflating "basic code review" with "politically charged state actor performing code review", which are not the same thing. Did they say they allow no audit or outside code review? Or simply that political nation states who have intelligence agencies that actively subvert security solutions to compromise computers (the very things AV companies work to prevent) shouldn't have access to the very co…

Well we all are citizens of one country or another. So what exactly does outside code review mean? American code can only be reviewed by American code reviewers?

Would you trust Chinese software that was only ever allowed to be reviewed by Chinese auditors?

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#54
post #37

Earlier quoted context omitted.

2013: http://www.businessinsider.com/the-story-of-joseph-nacchio-a... "Only One Big Telecom CEO Refused To Cave To The NSA ... And He's Been In Jail For 4 Years" 2015: https://www.forbes.com/sites/janetnovack/2015/05/01/u-s-avoi... "the government has avoided a trial in which the 65-year-old former executive planned to air what he says was his refusal, in 2001, to allow Qwest to participate in a National Security Age…

I think it's unfair not to clarify that he went to jail for insider trading. He believes that that the government only brought the action against him because he refused to divulge user data, but he is in jail because of insider trading.

Some details from the last link:

"the NSA proposition to Qwest was nearly seven months before 9/11, according to Nacchio."

"In a bizarre twist, the judge in Nacchio's case, Edward Nottingham, was soon embroiled in scandal, accused of soliciting prostitutes and allegedly asking one to lie to investigators. He resigned and apologized, but wasn't prosecuted."

"Nacchio's conviction was overturned on appeal in a decision that found Judge Nottingham made key errors.

But the government got the conviction reinstated by a split judges' panel."

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#55
I'm sure that properly run foreign states consider unauditable software an unacceptable security risk as well. Between this nonsense and symantec's history of security mishaps, I'll be making sure to avoid this company from now on. I'll also recommend against dealing with them if asked.

Ridiculous.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#56

Earlier quoted context omitted.

Somebody please reply to this. Both this comment and the above comment seem reasonable. I don't know what to believe!

I believe the latter post (obfuscating the method of detection) over incompetence. Don't forget that nation states also produce malware (Recall Stuxnet?) [0] and evading detection is substantially easier when you know exactly what to avoid doing. [0] https://en.m.wikipedia.org/wiki/Stuxnet

Evading detection is easy if you have the slightest clue of what you're doing. Antivirus evasion simply isn't difficult enough for this to be a reasonable explanation.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#57
post #53
post #41

Earlier quoted context omitted.

You're intentionally conflating "basic code review" with "politically charged state actor performing code review", which are not the same thing. Did they say they allow no audit or outside code review? Or simply that political nation states who have intelligence agencies that actively subvert security solutions to compromise computers (the very things AV companies work to prevent) shouldn't have access to the very co…

Well we all are citizens of one country or another. So what exactly does outside code review mean? American code can only be reviewed by American code reviewers? Would you trust Chinese software that was only ever allowed to be reviewed by Chinese auditors?

Private firms earn their reputations by their behavior. We have international / multi-national / NGO's which can exist beyond the politics of the nation states they reside in.

You should trust a firm to review your code not based on their nationality, but based on a wide criteria.

Included in that criteria for me would whether or not the organization is committed to the work of subverting your software through intelligence operations.

But, that's just an end-around because all countries with markets worth selling in have intelligence agencies which subvert AV and other software for clandestine purposes, so all nation states are excluded.

W.r.t Chinese auditors, because of their oppressive and authoritarian government which goes so much further than western governments to control business and speech, and which has a much deeper history of subverting any control structure outside of the Communist Party, I would certainly treat their work as suspect by nature, but if there were a Chinese auditing firm renowned for its quality, privacy and separation from their government, I don't see why I wouldn't consider it.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#58
post #41

Earlier quoted context omitted.

You're intentionally conflating "basic code review" with "politically charged state actor performing code review", which are not the same thing. Did they say they allow no audit or outside code review? Or simply that political nation states who have intelligence agencies that actively subvert security solutions to compromise computers (the very things AV companies work to prevent) shouldn't have access to the very co…

Usually companies allow source code review beccause they're trying to sell their solutions in the countries in question. Look at it from the perspective of those countries Symantec "hey buy all our security software it's super-great" Foreign Gov. Customer: "sure can we check the source code first to see if there are any heinous security bugs or NSA backdoors" Symantec "Oh gee no, allowing to you see the source code o…

Symantec: "No, our code is audited professionally by the most reputable international firms along international standards of quality. You can review our audit reports and engage with the international body responsible for regulating audits to raise any concerns"

Foreign Gov. Customer: "But what I really want is for my tech spooks to scan pre-selected high value modules for already known and suspected zero day exploits for our own clandestine use"

Symantec: "...."

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#59
Meanwhile my own government in it's infinite stupidity is storing confidential tax records on US owned clouds. Apparently they haven't revised their 1950s policy that the Americans are the good guys.

Say what you want about Russians but they know how the game is played. And they are good at it too.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#60
post #58

Earlier quoted context omitted.

Usually companies allow source code review beccause they're trying to sell their solutions in the countries in question. Look at it from the perspective of those countries Symantec "hey buy all our security software it's super-great" Foreign Gov. Customer: "sure can we check the source code first to see if there are any heinous security bugs or NSA backdoors" Symantec "Oh gee no, allowing to you see the source code o…

Symantec: "No, our code is audited professionally by the most reputable international firms along international standards of quality. You can review our audit reports and engage with the international body responsible for regulating audits to raise any concerns" Foreign Gov. Customer: "But what I really want is for my tech spooks to scan pre-selected high value modules for already known and suspected zero day exploit…

What "interational body for regulating audits" would that be, I'm not aware of any such body...?

Also If Symantec won't trust their customers to that degree, why should a foreign government or their key industries trust symantec software?

If a US audit firm audits US software, why should an international government trust that there isn't a US backdoor in there? Or perhaps that the US audits have uncovered issues but instead of patching them they handed them to the NSA for later use in their TAO teams... (wannacry anyone?)

Obviously symantec are free to withdraw from a given market as they have here, but to suggest that trust is a one-way street seems well a bit unbalanced.

Post reply on HN