Live data from Hacker News

$50,000 to keep Symantec source code private

zdnet.com

31–40 of 82 posts

Re: $50,000 to keep Symantec source code private

#31
I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place.

But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free".

It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They hacked Symantec because the virus-writers of the world want to be able to write more viruses so they can infect more machines and create more botnets and send more spam and/or do more phishing...and make more money. That's it.

It's frustrating because part of the problem with a group like Anonymous is that you don't get to declare who is and who isn't a part (by definition).

I suppose human nature is human nature - in the real world or online, the same scenarios play out time and time again....

Re: $50,000 to keep Symantec source code private

#33
@AnonymousFlorida says "Anonymous NEVER asked for money"

Really?

"How much do you consider ENOUGH to pay us in order to work all the issues out"

"we shall give you our account number within the LR system and you send money from your LR acct to ours"

Considering these snippets from the email exchange, what am I not understanding about the claim that they did not ask for money?

Re: $50,000 to keep Symantec source code private

#34

So what's the legal environment around downloading the now-leaked source? I have to say I'm pretty curious about the code quality and possible backdoors... Are there even protections for the press in this case? Or is every who pulls this torrent guilty of receiving stolen property or something along those lines. Excuse my ignorance, but frankly I'd like to poke around.

You'll likely be labeled a terrorist and not be able to board an aeroplane... at least in the USA.

Edit: I meant this to be humorous, though it may not be far from the truth. If Symantec values its source code above a certain dollar amount, I'm sure it would be a federal offense in America to download this code. This is how Kevin Mitnick became a federal fugitive... it was simply based on the dollar amount of the source code he possessed.

Re: $50,000 to keep Symantec source code private

#35

This makes Symantec look a lot worse than "Anonymous" IMO. Symantec is supposedly a reputable computer software company. The fact that they have to resort to legal means to secure their own source code is not a positive indication that they do a good job.

> The fact that they have to resort to legal means to secure their own source code is not a positive indication that they do a good job.

Really?

So if I, a supposedly reputable citizen have to resort to calling the police after my house is broken into that reflects poorly on me?

Symantec may have doen things that reflect poorly on them, but I don't think calling the police in is one of them. That's what you are supposed to do.

Remember that pretty much every tech company has had some of their code broken into, whether it's microsoft's OS, to Google's Chinese gmail back doors to oracle's db leak.

Re: $50,000 to keep Symantec source code private

#36
post #27

Earlier quoted context omitted.

Yes but there are probably lots of code blocks that are used throughout their entire software line. Like how they establish secure connections between the client software and the update server.

Still, the code is worthless for anyone if your product is secure. And I would imagine that product by security company would be secure. Antivirus software might be something different as you might learn how to trick it. But "remote desktop"? It doesn't require any "security by obscurity".

The source is still pretty valuable to a competitor right?

Re: $50,000 to keep Symantec source code private

#37
These people need to be found and they need to go to jail for a very, very long time. The best possible response from the hacker community is to help dig these people out of their caves and turn them in.

Why?

Because this represents yet one more step towards the criminalization of the Internet. And this provides yet more fuel for politicians to get behind nonsense like SOPA. Keep this up and the Internet as you know it today will not be for long. There is no possible good outcome from these kinds of actions.

Either we police our own ranks or they will do it for us. The difference is that politicians will use a sledge-hammer for surgery rather than a scalpel. Be the scalpel.

Re: $50,000 to keep Symantec source code private

#38
post #33

@AnonymousFlorida says "Anonymous NEVER asked for money" Really? "How much do you consider ENOUGH to pay us in order to work all the issues out" "we shall give you our account number within the LR system and you send money from your LR acct to ours" Considering these snippets from the email exchange, what am I not understanding about the claim that they did not ask for money?

I direct your attention to the name of the "organization"...

Re: $50,000 to keep Symantec source code private

#39
post #33

@AnonymousFlorida says "Anonymous NEVER asked for money" Really? "How much do you consider ENOUGH to pay us in order to work all the issues out" "we shall give you our account number within the LR system and you send money from your LR acct to ours" Considering these snippets from the email exchange, what am I not understanding about the claim that they did not ask for money?

They are probably both stringing each other along and playing a game to see what the other side does. This is might be not unlike the HBGary incident.

If Anon are at least mildly intelligent they'll figure out this is a sting operation. Slowly trickling in money then following it to the source is most likely an FBI setup.

Now Anon could keep playing this and accept money but provide some random bank account just to see what Symantec does.

Actually, to think about it, their best possible exit out of this is to ask this money to be sent to a charity, or a foundation. For example, "Donate $50k immediately to EFF and we'll promise we'll erase the source files".

But then going by their previous patterns they'll probably release the source anyway.

I don't know, but if this is an FBI sting they are not very ingenious. "We'll give you money in the course of 3 months as continuous payments... you'll have to provide proof you deleted files.. really?". A 10 year old can figure out what this is. Kind of disappointed at the quality of their work (and our tax money's use).

Post reply on HN