5 ms·
So they're basically admitting that their antivirus tools aren't secure enough to handle a basic code review? Yup, totally makes me want to buy copies. "No, g
by nobodyorother 9y ago
So they're basically admitting that their antivirus tools aren't secure enough to handle a basic code review?
Yup, totally makes me want to buy copies.
"No, guys, security by obscurity totally works in this one case! Because it's us! Come on, you trust us right?"
- macspoofing 9y agoTo play devil's advocate, they may not be worried about vulnerabilities in their code but rather vulnerabilities in their method of virus detection, the same way Google doesn't share details about their search algorithm partly so it isn't gamed by spammers. Actually this is common in software that is meant to protect against sophisticated attackers. Blizzard and Valve used to have periodic mass bans but they would never say what exact action triggered a ban. In fact you would get no information and the ban itself may have come months after some hack was used so that crackers wouldn't know what specifically triggered it.
- tr1ck5t3r 9y agoFor a simple test using time, write a program which lists all files and folders, and then md5 hash each file. See how long the processes takes to do all your files and then ask how can your AV scan all files faster unless its an inferior process. Lets face it, scanning each file loaded into memory looking for hundreds and thousands of virus signatures is a slower process than MD5 hashing so why the time difference, unless the AV process is fundamentally flawed? No AV system can detect 100% of all viruses on a system, because the process is flawed. Dont take my word for it, take it from those who test different AV products on files infected with known viruses. https://www.shadowserver.org/wiki/pmwiki.php/AV/VirusDailyStats https://www.shadowserver.org/wiki/pmwiki.php/AV/VirusDailySt...
- TruthSHIFT 9y agoSomebody please reply to this. Both this comment and the above comment seem reasonable. I don't know what to believe!
- raesene9 9y agoFor me Worrying about "vulnerabilities in their virus detection method" seems unlikely. We're talking about downloadable software here, not a cloud service like google. Once a hostile nation state has access to your binaries (as they would with an installed product like A-V) they can just fuzz the A-V detection method to find bypasses. Heck that's what pentesters and red teamers do on a regular basis, A-V bypass is a common thing in that world, so if people at that level can do it you can bet that nation state actors can do it.
- tedivm 9y agoYeah, when I worked at Malwarebytes we did not really care about this issue. If people are doing to download it they are going to reverse engineer it. We also did third party security audits on a regular basis, but still wouldn't be comfortable allowing that to be done with other countries. Purely my own opinion here, but my concern wouldn't be a security one so much as an intellectual property one- it's pretty well known that other governments (China, Russia) have strong links to their commercial sectors and little regard for IP protection.
- CamelCaseName 9y agoI believe the latter post (obfuscating the method of detection) over incompetence. Don't forget that nation states also produce malware (Recall Stuxnet?) [0] and evading detection is substantially easier when you know exactly what to avoid doing. [0] https://en.m.wikipedia.org/wiki/Stuxnet https://en.m.wikipedia.org/wiki/Stuxnet
- ryanlol 9y agoEvading detection is easy if you have the slightest clue of what you're doing. Antivirus evasion simply isn't difficult enough for this to be a reasonable explanation.
- kccqzy 9y agoI can second that. A lot of virus detection basically boils down to detecting this particular substring. Which is usually quite easily bypassed.
- deleted 9y ago[deleted]
- fjksksvdjsjd 9y agoWell, that’s an argument they should have made! I think it’s extremely charitable to assume this is why, though, when every indication points to code-audit fearmongering. But, you’re also forgetting that these virus scanners can also be vulnerabilities and exploits in themselves; i seem to remember one virus exploited a flaw in the compression code of a virus scanner to establish some type of malware. Just because something is a trade secret doesn’t exactly lessen the risk of it existing.
- colordrops 9y agoWhat's the difference between vulnerabilities in code and vulnerabilities in virus detection? Isn't the virus detection done in code? Is security through obscurity valid for virus detection but not code?
- mrighele 9y agoI don't think the parent is talking about vulnerabilities, but the fact that if you know how the antivirus engine works it may be easier to write a virus able to avoid detection.
- colordrops 9y agoSounds like a vulnerability. Isn't that how the argument went about source code? "If you know how the program works it may be easier to write an exploit." But then experience taught people that exposing source code to the bright sunlight by opening its source could actually make software more secure through many eyes finding holes. Why is this not applicable to virus detection algorithms?
- disiplus 9y agobecause its not that easy. if i write some part of the code to detect if you are a good human and will you go to hell or heaven, to evaluate that for me would be hard. and if you had a access to my source code you could check what i am looking for and could maybe cheat. the vulnerability i would call is if i sent you to hell and you found a way to escape.
- mrighele 9y agoNow that I think about it, you have a point. In general when I think about a (software) vulnerability I think about taking advantage of some bugs or unforeseen behavior of the software. If the software is acting as intended but can not protect you from a certain kind of issue can we say it has a vulnerability ? My answer was no before, now I am in doubt :-).
- ksk 9y ago
- solatic 9y ago> To play devil's advocate, they may not be worried about vulnerabilities in their code but rather vulnerabilities in their method of virus detection This is an argument for factoring out the means of virus detection into a closed-source plugin/module, while opening the source of the rest of the code. Particularly since detection is presumably pure (i.e. functional programming notions of purity and referential transparency), and thus much less likely to be a source of vulnerabilities, compared to the rest of the client which actually interacts with the OS, disks/files, etc. and is therefore much more likely to be exploited. Because the vulnerability scanner would still be a closed-source binary blob, the public would need to trust the company that the blob is actually pure, but seeing that blob within the context of an open-source client which is handling I/O makes that trust easier. Yes, it makes it easier for malware creators to test their creations against the closed-source module before releasing their malware into the wild. But sophisticated malware writers are already doing that, by installing the anti-virus client into a VM, updating it, disconnecting it from networks, then loading the malware into the VM and seeing if the malware is detected or not. So malware writers don't gain that much from the opening of the rest of the codebase (unless they succeed in finding vulnerabilities that the rest of the world doesn't), and the white-hat public gains a much more trustworthy security tool.
- criley2 9y agoYou're intentionally conflating "basic code review" with "politically charged state actor performing code review", which are not the same thing. Did they say they allow no audit or outside code review? Or simply that political nation states who have intelligence agencies that actively subvert security solutions to compromise computers (the very things AV companies work to prevent) shouldn't have access to the very cookie pot they work to steal from? Frankly, I have no idea why you'd let people review your source code who have a vested interest in finding exploits that they will use against people using your software.
- raesene9 9y agoUsually companies allow source code review beccause they're trying to sell their solutions in the countries in question. Look at it from the perspective of those countries Symantec "hey buy all our security software it's super-great" Foreign Gov. Customer: "sure can we check the source code first to see if there are any heinous security bugs or NSA backdoors" Symantec "Oh gee no, allowing to you see the source code of products we want you or companies in your country to run might compromise it's security" Foreign Gov. Customer: "..."
- criley2 9y agoSymantec: "No, our code is audited professionally by the most reputable international firms along international standards of quality. You can review our audit reports and engage with the international body responsible for regulating audits to raise any concerns" Foreign Gov. Customer: "But what I really want is for my tech spooks to scan pre-selected high value modules for already known and suspected zero day exploits for our own clandestine use" Symantec: "...."
- raesene9 9y agoWhat "interational body for regulating audits" would that be, I'm not aware of any such body...? Also If Symantec won't trust their customers to that degree, why should a foreign government or their key industries trust symantec software? If a US audit firm audits US software, why should an international government trust that there isn't a US backdoor in there? Or perhaps that the US audits have uncovered issues but instead of patching them they handed them to the NSA for later use in their TAO teams... (wannacry anyone?) Obviously symantec are free to withdraw from a given market as they have here, but to suggest that trust is a one-way street seems well a bit unbalanced.
- KGIII 9y agoObscurity is a valid part of some security schemes. It shouldn't be the only method, of course.
- hannofcart 9y agoWell, to be fair, they don't really have a choice in the matter. Open it out to code review by only a few number of people, mainly governments, and you are opening it out to a small set of people doing code review explicitly driven by the primary intention of finding vulnerabilities in it. This would apply to even the US govt, who routinely request software vendors to delay patching or even disclosing 0-day vulnerabilities till they have sufficiently exploited it. Allowing more scrutiny will work only if enough eyeballs are devoted to it driven by benevolent intentions. Best results would be to open source the whole thing but that would not make business sense to the company. Basically, either you open it out completely or not open it up at all. Opening out to a few government funded hackers is probably the worst choice they could make.