Hacker says to release full Norton Antivirus code on Tuesday
uk.reuters.com
uk.reuters.com
> A hacker who goes by the name of 'Yama Tough' threatened Saturday
> to release next week the full source code for Symantec Corp's
> flagship Norton Antivirus software.
Unfortunately, Saturday could not be reached for comment but Friday and Sunday pledged support for the beleaguered day.This is part of a more general problem I have with being able to write the way I speak. I don't think I have terrible grammar when writing something relatively formal, in a "written tone" rather than a "spoken tone", but when I make comments on reddit or HN, I've noticed I have a general inability to also make my writing grammatically correct. I also use a lot of parentheses, because I tend to talk in tangents, and that's the only way I can really write it that makes sense.
It was an intellectual curiosity, nothing more.
http://en.wikipedia.org/wiki/Buffalo_buffalo_Buffalo_buffalo...
http://www.pcworld.com/businesscenter/article/247376/symante...
and not currently running products: '"Symantec can confirm that a segment of its source code used in two of our older enterprise products has been accessed, one of which has been discontinued. The code involved is four and five years old," said Cris Paden, the company's senior manager for corporate communications.'
http://www.scmagazine.com/more-source-code-stolen-says-syman...
http://www.eweek.com/c/a/Security/Symantec-Confirms-Source-C...
http://news.techworld.com/security/3330880/symantec-admits-s...
evidently pcAnywhere users are at serious risk (source code stolen).
commentary:
http://blogs.cio.com/security/16753/symantecs-new-explanatio...
But hey, we can trust the supreme competence of the bureaucracy with our secrets.
> I wonder how companies protect their source code from leaking
The prospect of being bankrupted by a civil suit or thrown in prison is enough to stop most people.
Yes, but... if you're good enough to be hired by these companies, leaking source code without being traced isn't going to be hard for you. I've thought about this before and I'm actually surprised it doesn't happen more often.
Not sure who wrote this but it seems fairly accurate to my memory of those days:
http://www.fortunecity.com/meltingpot/nebraska/1386/applehac...
The reality though is that such source code is hardly ever a requirement to understanding or reverse engineering the underlying algorithm, and is likely already obsolete by the time it becomes public.
There are companies already which specialize in DLP. Here is a PDF booklet by one of them: http://www.ironport.com/pdf/ironport_dlp_booklet.pdf
It's news because it could represent a critical vulnerability to these users. If the source is exposed and properly analyzed by sufficiently intelligent, yet malicious people, they could launch a zero-day on the antivirus software itself, leaving a system unprotected, and possibly silently unprotected. That's bad.
Anti-virus software is like drugs: they'll preload a little quality free thing on your new computer and then remind you (every two hours) when your 60-day trial has expired AND YOUR COMPUTER IS AT RISK OH NOES KABOOM!!! Then, they'll gladly charge you for that feeling of safety when no software can protect against human stupidity, which is the root cause of most virus infections.
In other news, the world has moved past Norton and you should get a Mac.
but you lost credibility way before saying that anyway.