What Symantec Knew But Didn't Say

Discussion in 'Serious' started by GreatOldOne, 14 Feb 2003.

  1. GreatOldOne

    GreatOldOne Wannabe Martian

    Joined:
    29 Jan 2002
    Posts:
    12,092
    Likes Received:
    112
    Security firm Symantec withheld information about at least one big cyberthreat for hours after spotting it, possibly harming millions of Internet users.

    Symantec claims to have identified the Slammer worm that ravaged the Internet during the last weekend of January hours before anyone else did.

    Symantec then shared the information only with select customers, leaving the rest of the global community to get slapped around by Slammer.

    In a Feb. 12 press release about its DeepSight Threat Management System, Symantec boasts that the company "discovered the Slammer worm hours before it began rapidly propagating … then delivered timely alerts and procedures (to DeepSight users), enabling administrators to protect against the attack."

    Security experts are angry that Symantec did not publicly release any information the company had regarding Slammer.


    http://www.wired.com/news/infostructure/0,1377,57676,00.html
     
  2. cpemma

    cpemma Ecky thump

    Joined:
    27 Nov 2001
    Posts:
    12,328
    Likes Received:
    55
    Hang about, they're not a public service. ;)

    Good publicity - Symantec put their customers first.

    /me updates viri defs/
     
  3. Ubermich

    Ubermich He did it!

    Joined:
    21 Jun 2002
    Posts:
    4,389
    Likes Received:
    1
    Precisely. Symantec doesn't have to say anything to anyone. If they told their customers and no one else, good for them.
    And if they knew about the worm, but had no way of stopping it, it really didn't matter. The best they could've done was tell the other antivirus companies so they could update their definitions, which would be bad business.
    As for the idea that they are an accessory to the crime by not telling everyone about it... Symantec isn't like a witness to a crime. They're more like a private hospital. If you don't pay to go into their hands, you can go to the public hospital which is a lower-grade.
     
    Last edited: 15 Feb 2003

Share This Page