Security vendors to block Aust police hacks

By Liam Tung, ZDNet Australia
Wednesday, March 11, 2009 11:03 AM

Major security vendors Symantec, Sophos and Kaspersky yesterday said their products would block legalized hacking attempts by NSW Police under new legislation as they would any other security threat to users.

The NSW Government has proposed an amendment to the Law Enforcement (Powers and Responsibilities) Act 2002 which would, with a Supreme Court judge's permission, give police the authority to remotely access a suspect's computer for seven days at a time. Police would not be required to inform suspects for up to three years.

The full text of the amendment can be found online.

"Symantec's commitment, first and foremost, is to securing its customers' information and as such, Symantec software will block all attempts to compromise its customers' information, regardless of where the threats are coming from," a Symantec spokesperson said in a statement.

Paul Ducklin, head of technology at Sophos' Asia-Pacific operations, said that the idea of using malware for law enforcement had not proven effective in general. Sophos would not create backdoors in its security software, such as master passwords in encryption products, data-stealing malware deliberately left undetected by AV companies, or remote configuration features in firewalls, he said.

"Sophos aims to produce correctly engineered security products, so we don't do backdoors--not for ourselves, not for our customers, not for the cops and certainly not for the robbers," said Ducklin.

Kaspersky Labs said that while its products would treat "all unwelcome outside intrusions as hacking events", the company would assist police if they targeted a "crime ring".

"We would, of course, support any police action to bust crime rings or any organized illegal activity. Indeed, Kaspersky works with law enforcement authorities around the world to track down and identify cyber criminals," an Australian Kaspersky spokesperson said.

The question over whether security vendors would allow law enforcement malware to bypass normal security checks, has yet to be settled by the security industry in general.

Although Symantec yesterday said it would protect its customers' information, responding to U.K. legislation similar to that being proposed for NSW in January, Symantec declined to comment on whether it would block a police hack, saying the matter was "politically sensitive". The security vendor has said also in the past that it would not scan for the FBI's Magic Lantern keystroke-logging software.

In 2007 the German government had also been planning to permit authorities to plant spyware on suspects' hard drives through e-mail messages appearing to stem from official sources.

"Such special favors amount to deliberately-implemented software backdoors. But correctly engineered security software shouldn't have any backdoors at all--not by accident, and certainly not by design," Sophos' Ducklin said.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Save changes to all open Word documents at one time

Microsoft Office Suite

If your Word sessions often wind up with a lot of open documents, this obscure command can streamline the process of closing them and saving your changes.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web