Live data from Hacker News

$50,000 to keep Symantec source code private

zdnet.com

41–50 of 82 posts

Re: $50,000 to keep Symantec source code private

#42
post #27

Earlier quoted context omitted.

Still, the code is worthless for anyone if your product is secure. And I would imagine that product by security company would be secure. Antivirus software might be something different as you might learn how to trick it. But "remote desktop"? It doesn't require any "security by obscurity".

The source is still pretty valuable to a competitor right?

I would say no. Although I might be mistaken as I don't know what exactly is the application capable of. But from the brief description I think it doesn't contain any magic; something that competitor would love to see. The only benefit I see for competitors is the bad press.

Re: $50,000 to keep Symantec source code private

#43
post #31

I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place. But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free". It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They…

Indeed, anarchy is a double edged sword. Anyone can do anything they like under the "Anonymous" name and no one can say "hey, they don't speak for us".

Re: $50,000 to keep Symantec source code private

#44
post #31

I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place. But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free". It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They…

when is it Anonymous and when is it just anonymous?

Re: $50,000 to keep Symantec source code private

#45

5 year old code poses a security threat to PCAnywhere users? All the more reason to not use any of their products. Source code should never pose a security risk.

Perhaps – but it's certainly the case that if one wanted to find an exploit, it would likely be easier with the source code in hand.

Now, this isn't an argument against open-source software – much to the contrary, in fact, because, I'd argue, OSS has, by virtue of being developed in the open, had much more opportunity for bugs to be seen by contributors and by those looking to crack/exploit it. As exploits are found, they get patched. Closed source, code, on the other hand, faces a lot of catch-up when its code is released into the wild.

I'd argue that's a bit like what happens to one's immune system if it's not regularly challenged (particularly as a child). Frequent exposure to pathogens tends to make one's immune system better, whereas living in a bubble only works as long as nobody lets you out.

Also, as much as codebases change, many parts stay the same, so yes, 5 year old code may well still be similar to currently shipping code that unexploited/unpatched issues may well still exist.

Re: $50,000 to keep Symantec source code private

#46
post #9

The source was leaked last night: http://thepiratebay.se/torrent/7014253/Symantec_s_pcAnywhere... Has anyone heard of an official response from Symantec?

Now that the code is available I wonder if the product will get better. Although I'd imagine any community that tries to form around it might get smacked down with a lawsuit. It'd be interesting to allow one to develop though.

I doubt anyone will attempt to form a community around 3rd party builds/modifications to it. Malware authors will look for vulnerabilities, and curious people might study it (though you should be extremely cautious about doing so)

Re: $50,000 to keep Symantec source code private

#47
post #31

I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place. But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free". It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They…

Watch out, there will be people who will point out that this isn't theft, because Symantec still has it's copy - and they are technically correct. And the following discussion if this is morally equivalent to theft will never end.

Re: $50,000 to keep Symantec source code private

#48

So what's the legal environment around downloading the now-leaked source? I have to say I'm pretty curious about the code quality and possible backdoors... Are there even protections for the press in this case? Or is every who pulls this torrent guilty of receiving stolen property or something along those lines. Excuse my ignorance, but frankly I'd like to poke around.

You can't be convicted of a crime without evidence. It's pretty easy to obtain public content and look at it without leaving behind any evidence. Tor, full disk encryption, and anonymous remailers are your friend.

Re: $50,000 to keep Symantec source code private

#49

This makes Symantec look a lot worse than "Anonymous" IMO. Symantec is supposedly a reputable computer software company. The fact that they have to resort to legal means to secure their own source code is not a positive indication that they do a good job.

What can they do? All it takes is one employee and a flash drive to leak the source code anonymously. Considering the value of a 0-day exploit on the open market, I'm sure that an interested party could find some low-level junior developer to bribe to steal the source code. And here we are today.

Re: $50,000 to keep Symantec source code private

#50
post #31

I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place. But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free". It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They…

Yup, it's straight up theft. This shows the corrupt side of hacktivists, i guess.
Post reply on HN