Live data from Hacker News

$50,000 to keep Symantec source code private

zdnet.com

51–60 of 82 posts

Re: $50,000 to keep Symantec source code private

#51

5 year old code poses a security threat to PCAnywhere users? All the more reason to not use any of their products. Source code should never pose a security risk.

Perhaps – but it's certainly the case that if one wanted to find an exploit, it would likely be easier with the source code in hand. Now, this isn't an argument against open-source software – much to the contrary, in fact, because, I'd argue, OSS has, by virtue of being developed in the open, had much more opportunity for bugs to be seen by contributors and by those looking to crack/exploit it. As exploits are found,…

I understand your immune system analogy but it isn't really accurate. Symantec is a billion dollar international corporation which markets itself as being security oriented. They should be doing rigorous security testing, including 3rd party code review. They should be paying the best of the best to crack their code. If their not they're doing it wrong.

Re: $50,000 to keep Symantec source code private

#52
post #40

I know nothing about antivirus software, but isn't security software supposed to be open? Otherwise, it's just security through obscurity. It sounds to me like Symantec just wants to hide all their vulnerabilities.

There is a large market for antivirus software - obviously Symantec is one of the biggest - but there are trade secrets in how their heuristics engines work and other secrets that give them a possible competitive edge.

Re: $50,000 to keep Symantec source code private

#53
AnonymousFlorida's side of the story:

- in 2006, anon members steal Symantec source for the lulz

- Symantec contacts the FBI and sets up a pretty transparent attempt to sting those responsible

- Anonymous punishes Symantec for the sting attempt, after some internal debate, by releasing the source as a torrent

Has the ring of truth to it, IMHO.

Re: $50,000 to keep Symantec source code private

#54
post #40

I know nothing about antivirus software, but isn't security software supposed to be open? Otherwise, it's just security through obscurity. It sounds to me like Symantec just wants to hide all their vulnerabilities.

Exactly. I've been saying this time and time again in the past: you cannot trust proprietary software for security, full stop.

As you point out, it's security through obscurity (which we all know isn't really security), but what's more, you can never know if there is a backdoor in proprietary software, or if it's actually doing what it's supposed to do (and not less, or more - like logging your activity or listening in on your traffic).

Re: $50,000 to keep Symantec source code private

#55
post #31

I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place. But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free". It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They…

when is it Anonymous and when is it just anonymous?

You're Anonymous if you say you're Anonymous, and anybody can do that. It's as simple as that.

Re: $50,000 to keep Symantec source code private

#57

Earlier quoted context omitted.

when is it Anonymous and when is it just anonymous?

You're Anonymous if you say you're Anonymous, and anybody can do that. It's as simple as that.

I am actually surprised that there hasn't been more intelligence service activity in order to paint Anonymous in a bad light..

It would be pretty easy to just sabotage some infra structure element that people depend on, attribute it to Anonymous and create a massive public outcry for tougher legislation in the virtual environment.

Re: $50,000 to keep Symantec source code private

#58
post #31

I feel like episodes like this give Anonymous a bad name...[ sic ;) ]....not that their name/reputation is so stellar in the first place. But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free". It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They…

I agree that it is an extortion and other crimes. But the motivation as you describe it implies that Symantec provides some useful services (protection from viruses, phishing) and it is not clear that it is the case.

Symantec might be the target for PR (its products are supposed to protect others but it can't protect itself) and 50000 other reasons.

It is not self-evident that an antivirus provides enough benefit to outweigh its disadvantages (resource-hog, false-positives (intentional?), can't detect all attacks). In short security theater is not security.

Of cause it doesn't make the crime any less.

Re: $50,000 to keep Symantec source code private

#59
post #27

Earlier quoted context omitted.

Yes but there are probably lots of code blocks that are used throughout their entire software line. Like how they establish secure connections between the client software and the update server.

Still, the code is worthless for anyone if your product is secure. And I would imagine that product by security company would be secure. Antivirus software might be something different as you might learn how to trick it. But "remote desktop"? It doesn't require any "security by obscurity".

"..product by security company would be secure"

By this logic, wouldn't you also expect the storage of the source code to be secured?

In my mind, security implies all forms; physical, logical, in-transit, at rest, etc

Re: $50,000 to keep Symantec source code private

#60

5 year old code poses a security threat to PCAnywhere users? All the more reason to not use any of their products. Source code should never pose a security risk.

In theory this could make their product even more secure, assuming whatever exploits are found are reported back to them.

It would be interesting if Semantec would do something like start a bounty for reporting exploits. But of course that would be promoting use of their source code which I'm sure they would never do.

Post reply on HN