Live data from Hacker News

Symantec CEO says source code reviews by foreign states pose unacceptable risk

reuters.com

71–80 of 124 posts

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#71
post #7

Yeah, sure. Thats the company which according to Google (March) has a huge mess in own nest of Certification Authority resulting in google chrome removing their certs: https://arstechnica.com/information-technology/2017/03/googl...

They have already divested their certificate business. http://investor.symantec.com/About/Investors/press-releases/...

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#72

Earlier quoted context omitted.

Interesting enough, the CEO of Kaspersky already offers the source code for review in the US: https://www.engadget.com/2017/07/02/kaspersky-lab-offers-sou... Can't speak for the US, here in Germany the Kaspersky tools are used on large companies responsible for critical infrastructure. With the option for source code review, I'm still with a good impression on their tools when compared to Symantec and no option for r…

> Can't speak for the US, here in Germany the Kaspersky tools are used on large companies responsible for critical infrastructure. That is a terrible idea, as anyone who knows anything about Russia would tell you.

Ya.

Using American software, you might be getting NSA's eyes on you.

Using Russian software, you'll probably have FSB's eyes on you.

So take your pick :)

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#73
post #63

Earlier quoted context omitted.

It would make more sence to make the code open source but not free - anyone can see but nobody can use the code.

And how would you enforce that? What would prevent anyone with access to the code from building it and using it? I don't see any way except maybe stripping the code of significant parts

You could keep the virus fingerprint database outside the codebase. Customers would then pay for access (and updates) to the fingerprints.

The fingerprints have to be some sorts of data, like regular expressions or other limited instruction set which can only parse the incoming file and not communicate with outside world.

The company could automatically release fingerprints into the open after a time, say 6 months.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#74
post #21

Earlier quoted context omitted.

This. I would trust most non-security tech CEOs to give better security advice than the executives at Symantec.

The Symantec CEO has been in that position only since Symantec acquired Blue Coat last year, where they were CEO previously. The Symantec CA happened well before their current term.

He's doing a bang up job so far then!

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#76

They're not so arrogant about their code being bulletproof that they're willing to hand it to an adversary and say, "Sure, knock yourself out - see if you can find any holes"? Yeah, I'm not sure that I see a problem here.

Not seeing the problem doesent prevent it from beeing there. Security by obscurity has a track record of not working.

Of course it doesn't work. But handing your source code to your attacker works even less well than that.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#77
post #63

Earlier quoted context omitted.

It would make more sence to make the code open source but not free - anyone can see but nobody can use the code.

And how would you enforce that? What would prevent anyone with access to the code from building it and using it? I don't see any way except maybe stripping the code of significant parts

Copyright laws?

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#78
Do you need to access source code in order to analyze software for backdoors? Shouldn't you be looking directly at the compiled machine code?

There's no guarantee that the source code you are looking at matches the binaries that are being distributed isn't it?

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#80

Without code review, how can a government make sure that the product doesn't contain backdoors? > These are secrets, or things necessary to defend Backdoors from NSA?

Learn from Israel - hack Kaspersky and do the code review from inside. :-)
Post reply on HN