Bangkok Post

Tech firms let Russia probe progs

-

WASHINGTON: Major global technology providers SAP, Symantec and McAfee have allowed Russian authoritie­s to hunt for vulnerabil­ities in software deeply embedded across the US government, an investigat­ion has found.

The practice potentiall­y jeopardise­s the security of computer networks in at least a dozen federal agencies, US lawmakers and security experts said. It involves more companies and a broader swath of the government than previously reported. In order to sell in the Russian market, the tech companies let a Russian defence agency scour the inner workings, or source code, of some of their products. Russian authoritie­s say the reviews are necessary to detect flaws that could be exploited by hackers.

But those same products protect some of the most sensitive areas of the US government, including the Pentagon, Nasa, the State Department and the FBI, against hacking by sophistica­ted cyber adversarie­s such as Russia.

Beyond the Pentagon, ArcSight is used in at least seven other agencies, including the Office of the Director of National Intelligen­ce and the State Department’s intelligen­ce unit, the review showed. Additional­ly, products made by SAP, Symantec and McAfee and reviewed by Russian authoritie­s are used in at least eight agencies. Some agencies use more than one of the four products.

McAfee, SAP, Symantec and Micro Focus, which owns ArcSight, all said any source code reviews were conducted under the software maker’s supervisio­n in secure facilities where the code could not be removed or altered. The process does not compromise product security, they said.

Investigat­ors have not f ound any instances where a source code review played a role in a cyberattac­k, and some security experts say hackers are more likely to find other ways to infiltrate network systems. But private sector cyber experts say allowing Russia to review the source code may expose unknown vulnerabil­ities that could be used to undermine US network defences.

“Even letting people look at source code for a minute is incredibly dangerous,” said Steve Quane, executive vice-president for network defence at Trend Micro.

Newspapers in English

Newspapers from Thailand