Security News 'Security' Software Wrecking Your Security Is the Ultimate Irony

omidomi

Level 71
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Apr 5, 2014
6,008
Blast shields should not explode in your face.


A version of this post titled “Symantec’s security quicksand” originally appeared in the Cyber Saturday edition of Data Sheet, Fortune’s daily tech newsletter.

If there’s anything more ironic than security software destroying one’s security, I am at a loss to offer examples.

Earlier this week Tavis Ormandy, a security researcher at Google GOOG 1.03% , discovered critical vulnerabilities in the entire suite of Symantec antivirus software. The aging giant’s 17 enterprise products and eight Norton consumer and small business products all contained severe flaws. So severe that, taken together, a hacker could exploit them to hijack a customer’s machine—or worse, “easily compromise an entire enterprise fleet,” as he wrote. That bad, yes.

Worse still, Ormandy noted that the vulnerabilities were “wormable”—meaning self-replicable. An attacker could fully take control of computers just by sending an email or link, without requiring any victim to open or click it. The infections could spread like a toxic miasma. (Good luck holding your breath.)
 
H

hjlbx

LOL... did the article mention the patches - or just trash Symantec for the sake of trashing it ?

I don't know why people think that these type articles will actually influence the security software industry - that somehow security soft vendors will get their stuff together in response to big-time negative coverage.

History has proven that security soft vendors only deal with such publicity in the short term and then return to business as usual. Same as any other organization I guess - especially governments.

Any how...

The security soft industry will never change. Few vendors really try to improve their quality assurance\quality control - if that is even a part of the business model.

I can tell you that internal, truly robust QA\QC is not a part of the software industry. The standards the software industry uses are completely different than what most typical people think would be acceptable quality standards. It is a vague mish-mash that, history has shown, disappoints hundreds of millions of people every year. The proof is staring you right in the face - all the problems you experience on the system you are using at this very moment...

This is how the industry works: you will get what they give you -- and bug fixes and other problems will be fixed later -- sometimes years later -- if those bugs and major problems are discovered at all... and the whole while, you are the guinea pig.

It's the truth...
 
Last edited by a moderator:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top