Live data from Hacker News

$50,000 to keep Symantec source code private

zdnet.com

61–70 of 82 posts

Re: $50,000 to keep Symantec source code private

#61
post #27

Earlier quoted context omitted.

Yes but there are probably lots of code blocks that are used throughout their entire software line. Like how they establish secure connections between the client software and the update server.

Still, the code is worthless for anyone if your product is secure. And I would imagine that product by security company would be secure. Antivirus software might be something different as you might learn how to trick it. But "remote desktop"? It doesn't require any "security by obscurity".

> Still, the code is worthless for anyone if your product is secure. And I would imagine that product by security company would be secure.

Actually they had known vulnerabilities, but they didn't think it worth their time to fix them until their code was to be released.

http://www.symantec.com/theme.jsp?themeid=anonymous-code-cla...

> On Friday, January 27, 2012, Symantec released a patch that eliminates known vulnerabilities affecting customers using pcAnywhere 12.0 and pcAnywhere 12.1.

Re: $50,000 to keep Symantec source code private

#62
post #40

I know nothing about antivirus software, but isn't security software supposed to be open? Otherwise, it's just security through obscurity. It sounds to me like Symantec just wants to hide all their vulnerabilities.

There is a large market for antivirus software - obviously Symantec is one of the biggest - but there are trade secrets in how their heuristics engines work and other secrets that give them a possible competitive edge.

Seems to me like they would also get a competitive edge by ignoring the expensive antivirus programming and just sending the occasional false alert to the user to make them think their software is actually doing something. When they get a real virus: "Well, we can't catch all of them, sorry. Go ahead and pay for an update, that might fix it."

How would you even know, unless you saw the source code?

Re: $50,000 to keep Symantec source code private

#63
post #47
post #31

I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place. But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free". It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They…

Watch out, there will be people who will point out that this isn't theft , because Symantec still has it's copy - and they are technically correct. And the following discussion if this is morally equivalent to theft will never end.

I don't think it's theft. It definitely is extortion.

Re: $50,000 to keep Symantec source code private

#64
post #63
post #47

Earlier quoted context omitted.

Watch out, there will be people who will point out that this isn't theft , because Symantec still has it's copy - and they are technically correct. And the following discussion if this is morally equivalent to theft will never end.

I don't think it's theft. It definitely is extortion.

If so, isn't it also extortion when people say "If Hollywood doesn't release their content the way I want them to (cheaper and without DRM), I'm going to continue to pirate it"?

Re: $50,000 to keep Symantec source code private

#65
post #31

I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place. But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free". It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They…

I've always found a lot of correlations between Anonymous and Al Qaeda. Not because of terrorism or exploding vans but because both are relatively unorganized collectives who appear much scarier than they are because independent operators/cells will claim they are flying under the group's banner, leading to headlines like "Anonymous Hacks Symantec".

The media eats up the concept of an organized global conspiracy group so it works out for everyone; the media makes money, the independent operators have a convenient, catch-all banner to fly under and the collective gets publicity for their cause.

Re: $50,000 to keep Symantec source code private

#66
Yamatough demanded that Symantec transfer the money via Liberty Reserve, a payment processor based in San Jose, Costa Rica. But Thomas appears reluctant, calling it "more complicated than we expected." Thomas instead suggests using PayPal to transmit a $1,000 test as "a sign of good faith." Yamatough rejects that offer, saying, "Do not send us any money (we do not use paypal period)

Could someone comment on how it is possible to use Liberty Reserve to receive money anonymously?

The stakes are really high for getting caught, and receiving the money is the weakest point for the hackers. So I'm curious why Liberty Reserve is the payment processor of choice for these cyber-criminals.

Re: $50,000 to keep Symantec source code private

#67
post #57

Earlier quoted context omitted.

You're Anonymous if you say you're Anonymous, and anybody can do that. It's as simple as that.

I am actually surprised that there hasn't been more intelligence service activity in order to paint Anonymous in a bad light.. It would be pretty easy to just sabotage some infra structure element that people depend on, attribute it to Anonymous and create a massive public outcry for tougher legislation in the virtual environment.

I think it's due to two factors:

First, I still think the FBI (and other such deeply hierarchical organizations) are fundamentally unable to comprehend something like Anonymous on its full scale. They can't fathom the concept of a working collective that defines itself merely by willful association.

Second, this could backfire so fucking hard, even the FBI knows better. Seeing how often they've been embarrassed by Anonymous in the past, I don't think they are willing to take the risk of such an operation, only to have them exposed by the very people they tried to sabotage.

Re: $50,000 to keep Symantec source code private

#68
post #27

Earlier quoted context omitted.

Still, the code is worthless for anyone if your product is secure. And I would imagine that product by security company would be secure. Antivirus software might be something different as you might learn how to trick it. But "remote desktop"? It doesn't require any "security by obscurity".

The source is still pretty valuable to a competitor right?

Not if Symantec has any proof that they've touched it. You're legally screwed if you touch this code thanks to any combination of patents, trade secrets, or even good old-fashioned copyright violation (just because the source is out there doesn't mean you can use it).

Re: $50,000 to keep Symantec source code private

#69

This makes Symantec look a lot worse than "Anonymous" IMO. Symantec is supposedly a reputable computer software company. The fact that they have to resort to legal means to secure their own source code is not a positive indication that they do a good job.

What can they do? All it takes is one employee and a flash drive to leak the source code anonymously. Considering the value of a 0-day exploit on the open market, I'm sure that an interested party could find some low-level junior developer to bribe to steal the source code. And here we are today.

But that isn't what happened. They were owned, multiple times, and have admitted that this was stolen during a hacking incident that they didn't investigate previously.

Re: $50,000 to keep Symantec source code private

#70
post #57

Earlier quoted context omitted.

I am actually surprised that there hasn't been more intelligence service activity in order to paint Anonymous in a bad light.. It would be pretty easy to just sabotage some infra structure element that people depend on, attribute it to Anonymous and create a massive public outcry for tougher legislation in the virtual environment.

I think it's due to two factors: First, I still think the FBI (and other such deeply hierarchical organizations) are fundamentally unable to comprehend something like Anonymous on its full scale. They can't fathom the concept of a working collective that defines itself merely by willful association. Second, this could backfire so fucking hard, even the FBI knows better. Seeing how often they've been embarrassed by An…

Thirdly, they're doing a good enough job at it themselves.
Post reply on HN