Photo

Reuters Photojournalism

Our day's top images, in-depth photo essays and offbeat slices of life. See the best of Reuters photography.  See more | Photo caption 

Photo

Rage in Brazil

Mass protests erupt in the biggest cities of Brazil.  Slideshow 

Photo

The Afghan Army

The many faces of the Afghan National Army, which has taken over security of the country from NATO.  Slideshow 

Sponsored Links

Symantec says hackers stole source code in 2006

Related Topics

Tue Jan 17, 2012 2:01pm EST

(Reuters) - Symantec Corp said a 2006 breach led to the theft of the source code to its flagship Norton security software, reversing its previous position that it had not been hacked.

The world's biggest maker of security software had previously said that hackers stole the code from a third party, but corrected that statement on Tuesday after an investigation found that Symantec's own networks had been infiltrated.

The unknown hackers obtained the source code, or blueprint for its software, to Norton Antivirus Corporate Edition, Norton Internet Security, Norton Utilities, Norton GoBack and pcAnywhere, Symantec spokesman Cris Paden said.

Last week, the hackers released the code to a 2006 version of Norton Utilities and have said they planned to release code to its antivirus software on Tuesday. It was not clear why the source code was being released six years after the theft.

Source code includes instructions written in computer programming languages as well as comments that engineers share to explain the design of their software. For example, a file released last week from the source code of a 2006 version of Norton Utilities included a comment that said "Make all changes in local entry, so we don't screw up the real entry if we back up early."

Companies typically heavily guard their source code, which is considered the crown jewels of most software makers. At some companies access is granted on an as-needed basis, with programmers allowed to view code only if it is related to the tasks they are assigned.

The reason for all the secrecy is that companies fear rivals could use the code to figure out the "secret sauce" behind their technology and that hackers could use it to plan attacks.

Paden said that the 2006 attack presented no threat to customers using the most recent versions of Symantec's software.

"They are protected against any type of cyber attack that might materialize as a result of this code," he said.

Yet Laura DiDio, an analyst with ITIC who helps companies evaluate security software, said that Symantec's customers should be concerned about the potential for hackers to use the stolen source code to figure out how to defeat some of the protections in Symantec's software.

"What we are seeing from Symantec is 'Let's put the best public face on this,'" she said. "Unless Symantec wrote all new code from scratch, there are going to be elements of source code in there that are still relevant today."

Symantec said earlier this month that its own network had not been breached when the source code was taken. But Paden said on Tuesday that an investigation into the matter had revealed that the company's networks had indeed been compromised.

"We really had to dig way back to find out that this was actually part of a source code theft," he said. "We are still investigating exactly how it was stolen."

Paden also said that customers of pcAnywhere, a program that facilitates remote access of PCs, may face "a slightly increased security risk" as a result of the exposure.

"Symantec is currently in the process of reaching out to our pcAnywhere customers to make them aware of the situation and to provide remediation steps to maintain the protection of their devices and information."

(Reporting By Jim Finkle in Boston, additional reporting by Nicola Leske in New York, editing by Matthew Lewis)

We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (4)
What a joke. Symantec can’t protect their own servers and they expect us to trust them to protect ours. To compound matters, they weren’t even aware that they had been compromised for 6 years which means that they never fixed the vulnerabilities. In fact, they still haven’t figured it out. To compound matters, they lied regarding the breach to save face and, indeed, to retain customers. They lack credibility and compounded with illegally selling and spreading scareware, they should be shut down.

Jan 17, 2012 3:38pm EST  --  Report as abuse
LEEDAP wrote:
No joke. When the top software security firm has this kind of breach it’s a sign of how bad things are- it’s a virtual nuclear bomb.

My guess is that the reason it took six years to put this on the internet was because the hackers had finally gotten all they could out of it and were spreading it around to all the virus makers out there. This is seriously bad stuff and a symptom of our lax security. I think it’s right for the Pentagon to shift it’s focus to cyber warfare.

Jan 17, 2012 5:18pm EST  --  Report as abuse
FreedomRadio wrote:
I wonder if Symantec is telling us all it knows and is it being truthful?

And does Symantec regularly give foreign governments copies of its source code in order to do business with those governments?

And will the next release of hacked Indian server(s) data include current Symantec source code?

Jan 17, 2012 5:25pm EST  --  Report as abuse
This discussion is now closed. We welcome comments on our articles for a limited period after their publication.