Live data from Hacker News

Symantec CEO says source code reviews by foreign states pose unacceptable risk

reuters.com

11–20 of 124 posts

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#11
The article decries balkanization of tech services but it noticeably omits a middle path -- offering consulting services for open source software.

Surely, in this aspect, it stands to reason that this section of the tech services industry is more robust in the face of such an encroachment. The only losers in such a situation are the likes of Symantec, whom claim secrecy and obfuscation are a feature rather than a bug.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#12

They're not so arrogant about their code being bulletproof that they're willing to hand it to an adversary and say, "Sure, knock yourself out - see if you can find any holes"? Yeah, I'm not sure that I see a problem here.

Would you expect an adversary to actually tell you the holes they find? If they don't, what do you gain from sharing source code with them?

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#13
I would think all serious clients would want to review the source code of any security critical software that they intend to use. However, there could be some argument that allowing only selected clients (Russia) to review the source, while denying the larger security community access to source, does pose a risk. Of course Symantec does not, surely, intend to imply that its code should be published.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#14

They're not so arrogant about their code being bulletproof that they're willing to hand it to an adversary and say, "Sure, knock yourself out - see if you can find any holes"? Yeah, I'm not sure that I see a problem here.

If Symantec considers the government to be an adversary, then why are they trying to court them as a customer? From the article: Tech companies have been under increasing pressure to allow the Russian government to examine source code, the closely guarded inner workings of software, in exchange for approvals to sell products in Russia.

Customers are often your adversaries. In fact, it's almost entirely the case - They're looking to extract concessions, get cheaper goods and services, etc. The customer has incentive to bleed as much as they can from the seller, and the seller also has incentive to bleed as much as they can from the customer. Cooperation despite adversarial relationship is the great benefit of capitalism, but doesn't mean you can ignore the adversity.

There's also a very different mode to their relationships. Symantec is selling to the Russian government - bureaucracies, and it's selling black boxes. Russia is trying to leverage it, to give it advantage in a different mode - Intelligence. Both Symantec and the Russian intelligence agencies are in the infosec business. It's not that uncommon for businesses to do business despite competing in some areas - Samsung was a core iPhone supplier despite also making phones.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#16
post #7

Yeah, sure. Thats the company which according to Google (March) has a huge mess in own nest of Certification Authority resulting in google chrome removing their certs: https://arstechnica.com/information-technology/2017/03/googl...

This. I would trust most non-security tech CEOs to give better security advice than the executives at Symantec.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#17
post #8

Anti-virus products are a huge security risk.

Some might think it is joke, but it is dead serious:

https://googleprojectzero.blogspot.com/2016/06/how-to-compro...

Unfortunately running an anti-virus is an overly broad requirement in some industries to pass certifications and audits. It's one of the cases where "security" mandates and requirements leads to insecurity.

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#18
So they're basically admitting that their antivirus tools aren't secure enough to handle a basic code review?

Yup, totally makes me want to buy copies.

"No, guys, security by obscurity totally works in this one case! Because it's us! Come on, you trust us right?"

Re: Symantec CEO says source code reviews by foreign states pose unacceptable risk

#19

They're not so arrogant about their code being bulletproof that they're willing to hand it to an adversary and say, "Sure, knock yourself out - see if you can find any holes"? Yeah, I'm not sure that I see a problem here.

"They're not so arrogant about their code being bulletproof that"

The source-code reviews by foreign states are not about checking to see 'if it works' - it's about checking that it doesn't include inserts from NSA etc..

This has nothing to do with 'security review' in the general sense of robustness, it's a 'state actor' thing.

I don't see how there is a way around this.

It's doubtful that Russia will allow them to sell this stuff without reviewing it - and the reverse is true as well - Russian state actors will surely use this 'review' as an opportunity to embellish their own hacking tactics etc..

I don't see any real way around this in the world in which we live.

Russians are going to have to make their own anti-virus. Which I would imagine they are capable of doing.

Post reply on HN