Live data from Hacker News

$50,000 to keep Symantec source code private

zdnet.com

21–30 of 82 posts

Re: $50,000 to keep Symantec source code private

#21
post #18

Earlier quoted context omitted.

Yeah seriously, their turnover in 2010 was $6 Billion. I mean if your gonna take all that risk ask for a least $50 million.

It was just for one product, pcAnywhere.

Yes but there are probably lots of code blocks that are used throughout their entire software line. Like how they establish secure connections between the client software and the update server.

Re: $50,000 to keep Symantec source code private

#22

Earlier quoted context omitted.

So you'd prefer illegal means? I'm not sure I understand your comment.

No, I believe he refers to technical means. Meaning being able to prevent the leak.

Right, so that's what I originally thought, but they are two separate problems.

Yes, of course it would be ideal to prevent the leak in the first place - being a security company and having your sourcecode stolen is not exactly ideal, nor does it reflect very well on your ability to achieve the express purpose of your company.

HOWEVER, what's done is done, and given this source code has been stolen, I would on balance prefer Symantec to retrieve the code/neutralize the threat through legal means, rather than acting as "hax0rz" themselves. Whether or not this approach will work is a third debate - you'd hope this was, as suggested, a ploy by law enforcement working with Symantec, but I feel like it would reflect far worse on the company if they took an underhand approach to the situation. It's damage limitation at this point, and for a company so integrated with non-tech companies and individuals a legal approach seems a far more sensible option.

Re: $50,000 to keep Symantec source code private

#23
So what's the legal environment around downloading the now-leaked source? I have to say I'm pretty curious about the code quality and possible backdoors...

Are there even protections for the press in this case? Or is every who pulls this torrent guilty of receiving stolen property or something along those lines.

Excuse my ignorance, but frankly I'd like to poke around.

Re: $50,000 to keep Symantec source code private

#24
post #4

This will set a bad precedent for such things (unless it is orchestrated as a sting operation). If genuine, it would be interesting to know the primary motivation -- does Symantec not want the world to see its source because it is afraid its competition will steal its ideas ("our source code is full of awesome ideas") or its source code is pretty bad, sloppy, with backdoors for Uncle Sam that will pretty much shame t…

> users of its remote-access suite PCAnywhere may face a "slightly increased security risk."

Back doors seem distinctly possible. I'll bet there is some seriously poor crypto in there, too.

Re: $50,000 to keep Symantec source code private

#25
post #4

This will set a bad precedent for such things (unless it is orchestrated as a sting operation). If genuine, it would be interesting to know the primary motivation -- does Symantec not want the world to see its source because it is afraid its competition will steal its ideas ("our source code is full of awesome ideas") or its source code is pretty bad, sloppy, with backdoors for Uncle Sam that will pretty much shame t…

This is software that is designed to find viruses and malware. The authors of viruses and malware would be interested in seeing the source code and seeing how to get around it.

Re: $50,000 to keep Symantec source code private

#27
post #18

Earlier quoted context omitted.

It was just for one product, pcAnywhere.

Yes but there are probably lots of code blocks that are used throughout their entire software line. Like how they establish secure connections between the client software and the update server.

Still, the code is worthless for anyone if your product is secure. And I would imagine that product by security company would be secure.

Antivirus software might be something different as you might learn how to trick it. But "remote desktop"? It doesn't require any "security by obscurity".

Re: $50,000 to keep Symantec source code private

#28
post #12
post #4

This will set a bad precedent for such things (unless it is orchestrated as a sting operation). If genuine, it would be interesting to know the primary motivation -- does Symantec not want the world to see its source because it is afraid its competition will steal its ideas ("our source code is full of awesome ideas") or its source code is pretty bad, sloppy, with backdoors for Uncle Sam that will pretty much shame t…

I'm pretty sure the "let's send you $1000 over Paypal as a sign of good faith" was a trap. Looks like the hackers didn't fall for it.

Giving in to not quite what they're being asked to do and trying to buy time does smell like 5-0. If I were them I'd release it at the first signs of stalling and then move on to blackmailing the next company, who will know better than to contact police and just pay the 50K.

Re: $50,000 to keep Symantec source code private

#30
post #9

The source was leaked last night: http://thepiratebay.se/torrent/7014253/Symantec_s_pcAnywhere... Has anyone heard of an official response from Symantec?

Now that the code is available I wonder if the product will get better. Although I'd imagine any community that tries to form around it might get smacked down with a lawsuit. It'd be interesting to allow one to develop though.
Post reply on HN