8 ms·
Kaspersky Antivirus 2009 source code leaked
- deleted 16y ago[deleted]
- alexpeattie 16y agoMore info here: http://news.softpedia.com/news/Former-Kaspersky-Employee-Responsible-for-Leaked-Source-Code-181367.shtml http://news.softpedia.com/news/Former-Kaspersky-Employee-Res... It seems it's probably a beta version of AV 2009... Still embarrassing/potentially harmful to the company though - especially following the hacking of their website a few months ago (http://www.computerworlduk.com/news/security/3244882/kaspersky-website-hacked-in-fake-antivirus-attack/ http://www.computerworlduk.com/news/security/3244882/kaspers...)
- dchest 16y ago...the source code remains the intellectual property of Kaspersky Lab and downloading, distributing or using it without consent is illegal. Is it true that downloading it is illegal?
- ancymon 16y agoProbably it depends on what country you're in...
- johkra 16y agoYes, downloading is akin to making a copy without consent of the copyright owner. (Edit: At least according to the Berne Convention, which most countries have signed.) Edit2: I think dchest is right and illegality of the act of downloading does probably not follow from the Berne Convention, sorry. Distribution (offering for download) certainly is and I think at least according to German law the resulting copy has to be destroyed. Mind you, I'm no lawyer and might be mistaken.
- dchest 16y agoI'm pretty sure Berne Convention says nothing about the act of downloading. Your use of "akin" may be incorrect. Of course, different counties have different laws, but if we try to infer legality or illegality of downloading purely from Berne Convention, I'd like to ask this question: how can you make a copy of something that you don't have the original in the first place? Thus, it's more likely that the party who's distributing the work is making a copy, not the downloader.
- onnonotme01 16y agoWhat about in the US? Can one be tracked/prosecuted simply for downloading?
- HerberthAmaral 16y agoWithout a doubt. Remember the Anonymous guys arrested by doing DDoS: http://arstechnica.com/tech-policy/news/2011/01/two-real-guns-pointed-at-me-how-the-fbi-raided-anonymous.ars http://arstechnica.com/tech-policy/news/2011/01/two-real-gun...
- nailer 16y agoYes, it happens with other copywritten materials frequently.
- cookiecaper 16y agoTheoretically yes but usually they target distributors in preference to users. It's easier to get a verdict or judgment against the distributor because it avoids the question of "what is a copy" and how that applies to the digital space and also because people are less sympathetic to distributors. The thing with P2P applications is that everyone is also automatically a distributor.
- jrockway 16y agoIsn't it the server that makes the copy? You don't have anything, so how could you be copying it?
- jacquesm 16y agoNot where I live. They would wish it to be so, but that's a different matter. It won't scare off anybody though, that's for sure. Distributing it is illegal where I live, but downloading it is not.
- joubert 16y agoWould the party who "serve" the download be considered a distributor for legal purposes?
- jacquesm 16y agoYes, absolutely.
- joubert 16y agoI'm surprised that the nemo plus iurus principle doesn't make downloading illegal as well.
- jacquesm 16y agoI'm on the fence about that one. I used to sell licensed software and of course I lost plenty of money due to piracy (if a prospect cancels a sale but turns out to be running the product after all I think that qualifies ;)). Piracy is illegal (of software), but this case deals with source code. Now it is of course possible to see the name of the file and wonder 'hey, isn't that copyrighted software' but you could make that call for every package and you'd get a bunch of people arguing that the only way open source can function is by allowing people to download stuff, then verify the license is 'legit', compiling it and running it. So there are good reasons for not criminalizing the downloading of code, and the responsibility of anybody that does download code is that they will deal with it in the proper way once they find out the terms. If the code says '(C) 2000-2007 Kaspersky Inc, NOT for distribution or resale' at the top (I made that up), you will probably have a good idea that it's not wise for you to proceed, if on the other hand it has an open source license as a rider and you can not find anything wrong with it after careful inspection you should be free to proceed. To make an insightful decision you'd have to download it first.
- pvilchez 16y agoI read it as 'downloading without consent', 'distributing without consent' or 'using it without consent'.
- entity 16y agoIs it legal to steal from thief? They've stolen GPL code
- paraschopra 16y agoSome one in the antivirus industry please clarify something for me. Which is more important/critical for an AV company: the software or regular virus definition updates. My guess is that the virus signature database is where they create maximum value?
- johnnygood 16y agoThe signature database is where they'll get more money from. However, this is still bad for them. It gives people the chance to look through the code for vulnerabilities and it allows competitors to look at any techniques they're using. But the worst part is that they're a computer security company that couldn't keep their source code secure. Clearly, accidents happen even when one has the best policies and such in place. Sometimes it's merely chance as opposed to an indicator of something in a statistically valid way. However, it's still embarrassing. I don't find that there's a lot of testing of the efficacy of anti-virus software out there and so purchases are partially made on faith (would love to know if I'm wrong here since I'd be interested in the results). Anyway, as a purchase made partially on instinct, this makes purchasers feel less happy in their gut (so to speak).
- weaksauce 16y agoThere is some testing being done on them but it's really only the known viruses that are tested against. It's the viruses that are unknown that are what you want to worry about.
- sucuri2 16y agoI have been in the AV industry for a while and I would say both. AV companies have a lot of behaviour analysis/decoding/parsing done inside their code that is as important as their "static" signature set. In fact, I would say that having access to the code and how they analyze the files/memory/etc is more valuable to a competitor (and the "bad guys") than the static signature set.
- tptacek 16y agoIn what sense have you ever been in the AV industry? I'm not sure whether this account belongs to David or Dre, but neither of you have an AV company on your LinkedIn profiles. I admire you for building a business on cleaning up hacked Wordpress installs (seriously), but that's not the same game that Kaspersky is playing.
- scorchin 16y agoI realise that this is a pretty dubious request, but a part of me would much prefer to see a link to either GitHub or BitBucket than a torrent of a zip file.
- lrm242 16y agoWhy? Cloning a repository doesn't improve the morality of downloading and viewing this code. In the same way that it is wrong to receive a stolen radio, you shouldn't touch this code with a 10 foot pole no matter how it's packaged.
- scorchin 16y agoAs I said above, I realise it's a dubious request. I know it doesn't improve the morality either. It's more for the sake of viewing the code. I associate those 2 brands with viewing/sharing code.
- leon_ 16y agoSorry man, but that's just a huge pile of dumb bullshit. If the information is out there it's, as a thinking human, your duty to learn about it and improve your knowledge. Information want to be free per definition. If some company fails to guard their precious secrets - well, game over for them. Self censorship won't help anybody.
- CJefferson 16y agoI can't imagine GitHub or BitBucket would keep such a repository, once they knew it was there.
- getsat 16y agoThe zipped torrent is actually larger than the torrent file itself. I have no idea why he did this.
- nimrody 16y agoWhile the leaked code may ease the work of malware writers, keep in mind that whoever writes malware regularly tests against all popular antivirus software. No point in releasing something only to get caught right away.
- rw2- 16y agoThe torrent has lots of Chinese leechers.
- deleted 16y ago[deleted]
- levesque 16y agoInteresting fact. I wonder what they are up to!
- skinnymuch 16y agoPurely academic intentions I presume.
- olalonde 16y agoAlso lots of Transmission/libTorrent clients.
- CWuestefeld 16y agoI'm reading your comment to imply that Chinese are more interested in researching their production of malware. But really, we'd need to know what proportion of leechers there are for other pirated software torrents before we could even think about drawing conclusions.
- dfox 16y agoOne thing that amazes me at most of commercial codebases I have seen (leaked or not) is the sheer size of them. How can one spend 1GB of source code on something like anti-virus program?
- davidu 16y agoIt's not limited to commercial code... Lots of codebases for complex applications are substantially large. Often the translation files filled with strings alone will be 50% of it.
- cookiecaper 16y agoWell, the Linux kernel source code is around 71MB compressed, I'd guess maybe 200MB uncompressed. That's quite a difference in source code size, and I think that the same is true with most OSS projects. The WINE project for instance is also < 100MB for the full (huge and extensive, including translation) source. I think that commercial codebases just end up with a lot of cruft and nobody ever feels like cleaning them up (plus, there is incentive for keeping things a bit clunky as it buys slack-off time and/or extra hourly pay). As above, I also think they use other commercial/crappy components like third-party widgets that had the same treatment, so it all snowballs into a huge/unwieldy thing.
- chollida1 16y agoFor the large code bases I've seen, the size is often taken up by Third party code. If we depend on a third party library we'll down load the source and build it for all supported targets( x86 and x64) (debug and release) (windows and linux). This can really increase the size of your code base quickly.
- barrkel 16y agoStatic and dynamic libraries for third-party code and imports from external repositories. Code that's been around for a long time, with a team of developers working on it for a decade or more, tends to be big. The way it is with commercial software, you more or less have to keep adding features to compete; and it's dangerous to refactor much to eliminate code because of the risk of breaking backwards compatibility, so that introduces another form of duplication. 1GB of source, just source, is pretty big, though. Just the source from RAD Studio (the product I work on) is nearly 10 million lines, about 350 million characters - though that doesn't include the C++ compiler, C RTL, debugger kernel, and a bunch of other things.
- jacquesm 16y agoOnce again the human element proves to be the hardest to secure. Three years in jail is a pretty solid sentence, but still, every company with employees handing sensitive data like this is potentially at risk. All it takes is one bad leave and your corporate crown jewels could be on the street.
- qquirrell 16y agoVery interesting. This should be obvious, but I'd just like to remind everyone that given the source, nature, and intended audience of this file, it is fairly likely that it contains novel malware to catch people from other AV companies, and that you should not open, compile, or run anything from it without the full set of malware-safety precautions. Use only a virtual machine with no network connectivity.