$50,000 to keep Symantec source code private
zdnet.com
zdnet.com
But this isn't Hacktivism or whatnot. This is pure outright theft and extortion. It's not "fight the man" or "prevent censorship" or even WikiLeaks-style "information wants to be free".
It's profit-motivated organized crime syndicates trying to extract some $$ from a company. They hacked Symantec because the virus-writers of the world want to be able to write more viruses so they can infect more machines and create more botnets and send more spam and/or do more phishing...and make more money. That's it.
It's frustrating because part of the problem with a group like Anonymous is that you don't get to declare who is and who isn't a part (by definition).
I suppose human nature is human nature - in the real world or online, the same scenarios play out time and time again....
That they don't do this is evidence to me that they're perfectly happy to have random acts of digital crime attributed to them.
It would be pretty easy to just sabotage some infra structure element that people depend on, attribute it to Anonymous and create a massive public outcry for tougher legislation in the virtual environment.
First, I still think the FBI (and other such deeply hierarchical organizations) are fundamentally unable to comprehend something like Anonymous on its full scale. They can't fathom the concept of a working collective that defines itself merely by willful association.
Second, this could backfire so fucking hard, even the FBI knows better. Seeing how often they've been embarrassed by Anonymous in the past, I don't think they are willing to take the risk of such an operation, only to have them exposed by the very people they tried to sabotage.
Plus the backslash. I don't know. First it would force Anonymous into some form of "yeah we are Anonymous but this wasn't us" defense - something that is very difficult to argue when the premise of the collective is that everybody can be a member. And second most targets so far seemed to be somewhat low-key with relatively lax security in place.
Symantec might be the target for PR (its products are supposed to protect others but it can't protect itself) and 50000 other reasons.
It is not self-evident that an antivirus provides enough benefit to outweigh its disadvantages (resource-hog, false-positives (intentional?), can't detect all attacks). In short security theater is not security.
Of cause it doesn't make the crime any less.
The media eats up the concept of an organized global conspiracy group so it works out for everyone; the media makes money, the independent operators have a convenient, catch-all banner to fly under and the collective gets publicity for their cause.
Has anyone heard of an official response from Symantec?
http://blogs.computerworld.com/19695/antisec_leaks_symantec_...
Are there even protections for the press in this case? Or is every who pulls this torrent guilty of receiving stolen property or something along those lines.
Excuse my ignorance, but frankly I'd like to poke around.
Edit: I meant this to be humorous, though it may not be far from the truth. If Symantec values its source code above a certain dollar amount, I'm sure it would be a federal offense in America to download this code. This is how Kevin Mitnick became a federal fugitive... it was simply based on the dollar amount of the source code he possessed.
How would you even know, unless you saw the source code?
So while you probably wouldn't know via technical means, my gut feeling is that a conspiracy in a company that large would quickly surface.
As you point out, it's security through obscurity (which we all know isn't really security), but what's more, you can never know if there is a backdoor in proprietary software, or if it's actually doing what it's supposed to do (and not less, or more - like logging your activity or listening in on your traffic).
This is antivirus software, a specific sub genre of security software. Historically, the most popular such packages have not been open.
You are not expected to trust them not to have backdoors any more that you are expected to trust any other vendor (say, Microsoft). What you are expected to do is trust that it catches virus and third party spyware. Which, supposedly, it does, and people have been using it for ages.
Even if it was open, you would need to have it in binary form to run it, so you either need to know to compile it yourself and check the code first (not an option for 99.9999999 of the users) or trust the party that compiled it for you. And then you need to check again for every virus definition and engine update downloaded.
Better just trust the vendor and use it closed source...
- in 2006, anon members steal Symantec source for the lulz
- Symantec contacts the FBI and sets up a pretty transparent attempt to sting those responsible
- Anonymous punishes Symantec for the sting attempt, after some internal debate, by releasing the source as a torrent
Has the ring of truth to it, IMHO.
If genuine, it would be interesting to know the primary motivation -- does Symantec not want the world to see its source because it is afraid its competition will steal its ideas ("our source code is full of awesome ideas") or its source code is pretty bad, sloppy, with backdoors for Uncle Sam that will pretty much shame the company ("our source code is awful and we'll be embarrassed if it was revealed").
Looks like the hackers didn't fall for it.
Finally, I suspect at least part of the reason is that the source code contains a number of heuristics that, if known, are easier to circumvent for malware developers.
Back doors seem distinctly possible. I'll bet there is some seriously poor crypto in there, too.
Now, this isn't an argument against open-source software – much to the contrary, in fact, because, I'd argue, OSS has, by virtue of being developed in the open, had much more opportunity for bugs to be seen by contributors and by those looking to crack/exploit it. As exploits are found, they get patched. Closed source, code, on the other hand, faces a lot of catch-up when its code is released into the wild.
I'd argue that's a bit like what happens to one's immune system if it's not regularly challenged (particularly as a child). Frequent exposure to pathogens tends to make one's immune system better, whereas living in a bubble only works as long as nobody lets you out.
Also, as much as codebases change, many parts stay the same, so yes, 5 year old code may well still be similar to currently shipping code that unexploited/unpatched issues may well still exist.
It would be interesting if Semantec would do something like start a bounty for reporting exploits. But of course that would be promoting use of their source code which I'm sure they would never do.
Really?
"How much do you consider ENOUGH to pay us in order to work all the issues out"
"we shall give you our account number within the LR system and you send money from your LR acct to ours"
Considering these snippets from the email exchange, what am I not understanding about the claim that they did not ask for money?
If Anon are at least mildly intelligent they'll figure out this is a sting operation. Slowly trickling in money then following it to the source is most likely an FBI setup.
Now Anon could keep playing this and accept money but provide some random bank account just to see what Symantec does.
Actually, to think about it, their best possible exit out of this is to ask this money to be sent to a charity, or a foundation. For example, "Donate $50k immediately to EFF and we'll promise we'll erase the source files".
But then going by their previous patterns they'll probably release the source anyway.
I don't know, but if this is an FBI sting they are not very ingenious. "We'll give you money in the course of 3 months as continuous payments... you'll have to provide proof you deleted files.. really?". A 10 year old can figure out what this is. Kind of disappointed at the quality of their work (and our tax money's use).
Could someone comment on how it is possible to use Liberty Reserve to receive money anonymously?
The stakes are really high for getting caught, and receiving the money is the weakest point for the hackers. So I'm curious why Liberty Reserve is the payment processor of choice for these cyber-criminals.
Antivirus software might be something different as you might learn how to trick it. But "remote desktop"? It doesn't require any "security by obscurity".
By this logic, wouldn't you also expect the storage of the source code to be secured?
In my mind, security implies all forms; physical, logical, in-transit, at rest, etc
No, developers have to have access to the code and they can just steal it. And this wasn't even the case. If I read correctly, the code was leaked by 3rd party (some India state agency) which had it for some sort of security review.
Actually they had known vulnerabilities, but they didn't think it worth their time to fix them until their code was to be released.
http://www.symantec.com/theme.jsp?themeid=anonymous-code-cla...
> On Friday, January 27, 2012, Symantec released a patch that eliminates known vulnerabilities affecting customers using pcAnywhere 12.0 and pcAnywhere 12.1.
https://twitter.com/#!/YourAnonNews/status/16689812134180454...
Yes, of course it would be ideal to prevent the leak in the first place - being a security company and having your sourcecode stolen is not exactly ideal, nor does it reflect very well on your ability to achieve the express purpose of your company.
HOWEVER, what's done is done, and given this source code has been stolen, I would on balance prefer Symantec to retrieve the code/neutralize the threat through legal means, rather than acting as "hax0rz" themselves. Whether or not this approach will work is a third debate - you'd hope this was, as suggested, a ploy by law enforcement working with Symantec, but I feel like it would reflect far worse on the company if they took an underhand approach to the situation. It's damage limitation at this point, and for a company so integrated with non-tech companies and individuals a legal approach seems a far more sensible option.
Really?
So if I, a supposedly reputable citizen have to resort to calling the police after my house is broken into that reflects poorly on me?
Symantec may have doen things that reflect poorly on them, but I don't think calling the police in is one of them. That's what you are supposed to do.
Remember that pretty much every tech company has had some of their code broken into, whether it's microsoft's OS, to Google's Chinese gmail back doors to oracle's db leak.
No, if you as the CEO of ADT had to call the police after a home break-in, that would reflect poorly on you. Symantec is not a "reputable citizen", they're a security vendor. It's not the fact that they called the police, it's the fact that calling the police was necessary at all.
Really?
That's a really silly point of view. Break ins happen at the most secure places, and a police report is required to collect any insurance.
Calling the police is not only the smart thing to do, it's also the right thing to do.
Why?
Because this represents yet one more step towards the criminalization of the Internet. And this provides yet more fuel for politicians to get behind nonsense like SOPA. Keep this up and the Internet as you know it today will not be for long. There is no possible good outcome from these kinds of actions.
Either we police our own ranks or they will do it for us. The difference is that politicians will use a sledge-hammer for surgery rather than a scalpel. Be the scalpel.