Live data from Hacker News

$50,000 to keep Symantec source code private

zdnet.com

71–80 of 82 posts

Re: $50,000 to keep Symantec source code private

#71

This makes Symantec look a lot worse than "Anonymous" IMO. Symantec is supposedly a reputable computer software company. The fact that they have to resort to legal means to secure their own source code is not a positive indication that they do a good job.

> The fact that they have to resort to legal means to secure their own source code is not a positive indication that they do a good job. Really? So if I, a supposedly reputable citizen have to resort to calling the police after my house is broken into that reflects poorly on me? Symantec may have doen things that reflect poorly on them, but I don't think calling the police in is one of them. That's what you are suppo…

>So if I, a supposedly reputable citizen have to resort to calling the police after my house is broken into that reflects poorly on me?

No, if you as the CEO of ADT had to call the police after a home break-in, that would reflect poorly on you. Symantec is not a "reputable citizen", they're a security vendor. It's not the fact that they called the police, it's the fact that calling the police was necessary at all.

Re: $50,000 to keep Symantec source code private

#72
post #27

Earlier quoted context omitted.

Still, the code is worthless for anyone if your product is secure. And I would imagine that product by security company would be secure. Antivirus software might be something different as you might learn how to trick it. But "remote desktop"? It doesn't require any "security by obscurity".

> Still, the code is worthless for anyone if your product is secure. And I would imagine that product by security company would be secure. Actually they had known vulnerabilities, but they didn't think it worth their time to fix them until their code was to be released. http://www.symantec.com/theme.jsp?themeid=anonymous-code-cla... > On Friday, January 27, 2012, Symantec released a patch that eliminates known vulner…

Poorly worded that's all, after all, you can't fix unknown vulnerabilities.

Re: $50,000 to keep Symantec source code private

#73
post #31

I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place. But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free". It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They…

Indeed, anarchy is a double edged sword. Anyone can do anything they like under the "Anonymous" name and no one can say "hey, they don't speak for us".

Actually they could, assuming that "they" exist as a single coherent entity that sets policy etc. Even without exposing their identities. All they would need to do is set up a pgp key which all official anonymous press releases would need to be signed with, end of story.

That they don't do this is evidence to me that they're perfectly happy to have random acts of digital crime attributed to them.

Re: $50,000 to keep Symantec source code private

#74

Earlier quoted context omitted.

> The fact that they have to resort to legal means to secure their own source code is not a positive indication that they do a good job. Really? So if I, a supposedly reputable citizen have to resort to calling the police after my house is broken into that reflects poorly on me? Symantec may have doen things that reflect poorly on them, but I don't think calling the police in is one of them. That's what you are suppo…

>So if I, a supposedly reputable citizen have to resort to calling the police after my house is broken into that reflects poorly on me? No, if you as the CEO of ADT had to call the police after a home break-in, that would reflect poorly on you. Symantec is not a "reputable citizen", they're a security vendor. It's not the fact that they called the police, it's the fact that calling the police was necessary at all.

> No, if you as the CEO of ADT had to call the police after a home break-in

Really?

That's a really silly point of view. Break ins happen at the most secure places, and a police report is required to collect any insurance.

Calling the police is not only the smart thing to do, it's also the right thing to do.

Re: $50,000 to keep Symantec source code private

#75
post #40

I know nothing about antivirus software, but isn't security software supposed to be open? Otherwise, it's just security through obscurity. It sounds to me like Symantec just wants to hide all their vulnerabilities.

I know nothing about antivirus software, but isn't security software supposed to be open?

This is antivirus software, a specific sub genre of security software. Historically, the most popular such packages have not been open.

You are not expected to trust them not to have backdoors any more that you are expected to trust any other vendor (say, Microsoft). What you are expected to do is trust that it catches virus and third party spyware. Which, supposedly, it does, and people have been using it for ages.

Even if it was open, you would need to have it in binary form to run it, so you either need to know to compile it yourself and check the code first (not an option for 99.9999999 of the users) or trust the party that compiled it for you. And then you need to check again for every virus definition and engine update downloaded.

Better just trust the vendor and use it closed source...

Re: $50,000 to keep Symantec source code private

#76
post #62

Earlier quoted context omitted.

There is a large market for antivirus software - obviously Symantec is one of the biggest - but there are trade secrets in how their heuristics engines work and other secrets that give them a possible competitive edge.

Seems to me like they would also get a competitive edge by ignoring the expensive antivirus programming and just sending the occasional false alert to the user to make them think their software is actually doing something. When they get a real virus: "Well, we can't catch all of them, sorry. Go ahead and pay for an update, that might fix it." How would you even know, unless you saw the source code?

Aside from the difficulty in uncovering the truth, I think this would be a clear example of criminal fraud. It would take a pretty large effort to cover up something like this, as well (disgruntled ex-employees would be hugely incentivized to speak to prosecutors).

So while you probably wouldn't know via technical means, my gut feeling is that a conspiracy in a company that large would quickly surface.

Re: $50,000 to keep Symantec source code private

#77
post #76
post #62

Earlier quoted context omitted.

Seems to me like they would also get a competitive edge by ignoring the expensive antivirus programming and just sending the occasional false alert to the user to make them think their software is actually doing something. When they get a real virus: "Well, we can't catch all of them, sorry. Go ahead and pay for an update, that might fix it." How would you even know, unless you saw the source code?

Aside from the difficulty in uncovering the truth, I think this would be a clear example of criminal fraud. It would take a pretty large effort to cover up something like this, as well (disgruntled ex-employees would be hugely incentivized to speak to prosecutors). So while you probably wouldn't know via technical means, my gut feeling is that a conspiracy in a company that large would quickly surface.

I agree. My point was that you don't know what they're doing. It probably isn't as bad as "nothing at all", but you can't say where along the spectrum between that and "rock solid" they actually lie without taking a peek under the hood. Which is why I'm a proponent of free and open-source software wherever possible, especially for security applications.

Re: $50,000 to keep Symantec source code private

#78

These people need to be found and they need to go to jail for a very, very long time. The best possible response from the hacker community is to help dig these people out of their caves and turn them in. Why? Because this represents yet one more step towards the criminalization of the Internet. And this provides yet more fuel for politicians to get behind nonsense like SOPA. Keep this up and the Internet as you know…

I find the downvotes interesting. It seems that some in the HN community are OK with crime and intellectual property theft. Sad.

Re: $50,000 to keep Symantec source code private

#79
post #31

I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place. But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free". It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They…

I've always found a lot of correlations between Anonymous and Al Qaeda. Not because of terrorism or exploding vans but because both are relatively unorganized collectives who appear much scarier than they are because independent operators/cells will claim they are flying under the group's banner, leading to headlines like "Anonymous Hacks Symantec". The media eats up the concept of an organized global conspiracy grou…

Funny you should say that, I always saw anons as CIA.

Re: $50,000 to keep Symantec source code private

#80
post #27

Earlier quoted context omitted.

Still, the code is worthless for anyone if your product is secure. And I would imagine that product by security company would be secure. Antivirus software might be something different as you might learn how to trick it. But "remote desktop"? It doesn't require any "security by obscurity".

"..product by security company would be secure" By this logic, wouldn't you also expect the storage of the source code to be secured? In my mind, security implies all forms; physical, logical, in-transit, at rest, etc

> By this logic, wouldn't you also expect the storage of the source code to be secured?

No, developers have to have access to the code and they can just steal it. And this wasn't even the case. If I read correctly, the code was leaked by 3rd party (some India state agency) which had it for some sort of security review.

Post reply on HN