NortonLifeLock Unveils Norton Crypto
investor.nortonlifelock.com
investor.nortonlifelock.com
1. Having their CEO be the target of multiple effective identity thefts, despite claiming to be protected by their signature product[1].
2. Their previous CEO being an identity thief himself[2].
3. Being fined by the FTC for outright lying about the efficacy of their product, and then being fined again for operating in contempt of the original FTC agreement[3].
Given their shady history, this foray into cryptocurrency is no particular surprise.
[1]: https://www.wired.com/2010/05/lifelock-identity-theft/
[2]: https://www.wired.com/2007/06/lifelock-founde/
[3]: https://www.ftc.gov/news-events/press-releases/2015/12/lifel...
The Norton division was spun off as NortonLifeLock when Symantec sold the enterprise part of the business to Broadcom.
NortonLifeLock is a completely different company now.
And then, of course, it's only a matter of time before they're doing a lot of mining, and they're subsidizing the cost of the device, and a contract will require you to run the miner until it's been paid off.
Wow, can't imagine any sane person who would use this. Galaxy brain move to release it though.
Except with that one, a lot of otherwise tech savvy people just refuse to acknowledge the limitations and inability to verify privacy claims at any given point in time
The reality is that they are forcing users to use client side javascript which can have anything in it. And Swiss privacy laws do not do what users claim. There is no way to verify the claims of privacy.
Ideally there would be a mechanism in browsers to pin a specific version of a web app, and only let that app update (to a version with a specific hash) if the user explicitly gives it permission to.
The nearest thing we have to that right now is the SRI-bookmarklet trick: https://news.ycombinator.com/item?id=17776456
https://github.com/tasn/webext-signed-pages
HTML pages are PGP-signed by the website developer, and all of the resources embedded in the pages are validated by the browser using the Subresource Integrity feature:
https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
But any claim of security for emails will be contingent to a huge number of factors anyway lest you use end-to-end encryption so I see where you're coming from. Less technical people would probably have a hard time understanding the true security and privacy implications of protonmail.
People equate it with Swiss bank accounts, based on what they learned from James Bond movies.
"oh wow the blogger disclosed that they're paid to advertise them, that makes me trust the service even more!"
people just need to understand there are just limitations with that concept. don't rely on them for doing anything criminal anonymously. but its fine to hide activity from the people in your house and ISP and circumvent geofenced streaming services.
If I were to make a ranking of businesses that I consider highly ethical and reputable, the lifelock company would be somewhere towards the bottom.
https://www.google.com/search?channel=fs&client=ubuntu&q=lif...
They created a problem of their antivirus software flagging crypto miners, and instead of fixing that, they made their own crypto miner that is exempt from their flagging and said "see look, now its simpler and you don't have to disable your antivirus!"
And then they said its more secure and even simpler because all your crypto and keys get stored in the cloud, so you keep your crypto even if your harddrive/storage crashes.
Server side crypto hack incoming in..... three... two....
(double facepalm)
Press release is extremely vague, but I read this to be they have implemented their own eth mining client to set up their own pool? Normally miners and pools take a small cut, there is no mention of that here. Surely they are going to do the same? Are they going to cover their own payout transactions, or charge end users?
Its possible this could actually be a bit compelling if they're not taking a cut, although way too late to the party, and ironically their reputation is starting out far worse than anonymously developed miners on popular pools.
Reason: products having "Crypto" or "Secure" in the name are usually a bag of bugs, doing much more damage than anything else. Why this is so is kind of a riddle to me; I don't know any product promising to secure a PC that isn't buggy and insecure, with the only exceptions being the inherent security of operating systems (windows, MacOS, Linux in ascending order).
As the crypto economy continues to become a more important part of our customers’ lives, we want to empower them to mine cryptocurrency with Norton, a brand they trust,” said Vincent Pilette, CEO of NortonLifeLock. “Norton Crypto is yet another innovative example of how we are expanding our Cyber Safety platform to protect our customers’ ever-evolving digital lives.”
Every time I hear words like "empower" and "innovative" I turn off.
Perhaps that's the goal though? Because I read further and it says one of their risks are:
matters arising out of our completed Audit Committee investigation and the ongoing U.S. Securities and Exchange Commission investigation)
Shortly after Greg Clark took the reins in November 2016, Symantec acquired consumer credit protection company LifeLock for $2.3 billion. Combined with the Norton consumer AV business this represented $2.2 billion in annual revenue for the consumer division. [1]
So basically, this has gone from consumer credit protection to... Ethereum mining?!?
1. https://www.forbes.com/sites/richardstiennon/2020/03/16/the-...
Wait, what? I thought this was going to be a ransomware product. What in the world is going on here?
1. will not even pretend to improve your security,
2. will nag you for credit card information to extend the service, and
3. will continue to mine cryptocurrency in the background, to be "safely" stored in Norton's cloud wallet, which Norton will periodically reap "expired" coins from.