{"id":57502,"date":"2018-01-27T06:24:39","date_gmt":"2018-01-27T06:24:39","guid":{"rendered":"https:\/\/www.biphoo.com\/bipnews\/?p=57502"},"modified":"2018-01-27T06:24:39","modified_gmt":"2018-01-27T06:24:39","slug":"tech-firms-let-russia-probe-software-widely-used-by-u-s-government","status":"publish","type":"post","link":"https:\/\/www.biphoo.com\/bipnews\/world-news\/tech-firms-let-russia-probe-software-widely-used-by-u-s-government.html","title":{"rendered":"Tech firms let Russia probe software widely used by U.S. government"},"content":{"rendered":"<h2 style=\"text-align: justify\"><span style=\"font-size: 18pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">Tech firms let Russia probe software widely used by U.S. government<\/span><\/strong><\/span><\/h2>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Major global technology providers SAP (SAPG.DE), Symantec (SYMC.O) and McAfee have allowed Russian authorities to hunt for vulnerabilities in software deeply embedded across the U.S. government, a Reuters investigation has found.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The practice potentially jeopardizes the security of computer networks in at least a dozen federal agencies, U.S. lawmakers and security experts said. It involves more companies and a broader swath of the government than previously reported.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">In order to sell in the Russian market, the tech companies let a Russian defense agency scour the inner workings, or source code, of some of their products. Russian authorities say the reviews are necessary to detect flaws that could be exploited by hackers.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">But those same products protect some of the most sensitive areas of the U.S government, including the Pentagon, NASA, the State Department, the FBI and the intelligence community, against hacking by sophisticated cyber adversaries like Russia.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Reuters revealed in October that Hewlett Packard Enterprise (HPE.N) software known as ArcSight, used to help secure the Pentagon\u2019s computers, had been reviewed by a Russian military contractor with close ties to Russia\u2019s security services.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Now, a Reuters review of hundreds of U.S. federal procurement documents and Russian regulatory records shows that the potential risks to the U.S. government from Russian source code reviews are more widespread.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Beyond the Pentagon, ArcSight is used in at least seven other agencies, including the Office of the Director of National Intelligence and the State Department&#8217;s intelligence unit, the review showed. Additionally, products made by SAP, Symantec and McAfee and reviewed by Russian authorities are used in at least eight agencies. Some agencies use more than one of the four products. (Graphic: tmsnrt.rs\/2C30rp8)<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">McAfee, SAP, Symantec and Micro Focus (MCRO.L), the British firm that now owns ArcSight, all said that any source code reviews were conducted under the software maker\u2019s supervision in secure facilities where the code could not be removed or altered. The process does not compromise product security, they said. Amid growing concerns over the process, Symantec and McAfee no longer allow such reviews and Micro Focus moved to sharply restrict them late last year.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The Pentagon said in a previously unreported letter (tmsnrt.rs\/2C6o2p2) to Democratic Senator Jeanne Shaheen that source code reviews by Russia and China \u201cmay aid such countries in discovering vulnerabilities in those products.&#8221;<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Reuters has not found any instances where a source code review played a role in a cyberattack, and some security experts say hackers are more likely to find other ways to infiltrate network systems.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">But the Pentagon is not alone in expressing concern. Private sector cyber experts, former U.S. security officials and some U.S. tech companies told Reuters that allowing Russia to review the source code may expose unknown vulnerabilities that could be used to undermine U.S. network defenses.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cEven letting people look at source code for a minute is incredibly dangerous,\u201d said Steve Quane, executive vice president for network defense at Trend Micro, which sells TippingPoint security software to the U.S. military.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Worried about those risks to the U.S. government, Trend Micro has refused to allow the Russians to conduct a source code review of TippingPoint, Quane said.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Quane said top security researchers can quickly spot exploitable vulnerabilities just by examining source code.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cWe know there are people who can do that, because we have people like that who work for us,\u201d he said.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">In contrast to Russia, the U.S. government seldom requests source code reviews when buying commercially available software products, U.S. trade attorneys and security experts say.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">OPENING THE DOOR<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Many of the Russian reviews have occurred since 2014, when U.S.-Russia relations plunged to new lows following Moscow\u2019s annexation of Crimea. Western nations have accused Russia of sharply escalating its use of cyber attacks during that time, an allegation Moscow denies.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Some U.S. lawmakers worry source code reviews could be yet another entry point for Moscow to wage cyberattacks.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cI fear that access to our security infrastructure &#8211; whether it be overt or covert &#8211; by adversaries may have already opened the door to harmful security vulnerabilities,\u201d Shaheen told Reuters.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">In its Dec. 7 letter to Shaheen, the Pentagon said it was \u201cexploring the feasibility\u201d of requiring vendors to disclose when they have allowed foreign governments to access source code. Shaheen had questioned the Pentagon about the practice following the Reuters report on ArcSight, which also prompted Micro Focus to say it would restrict government source code reviews in the future. HPE said none of its current products have undergone Russian source code review.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Lamar Smith, the Republican chairman of the House Science, Space and Technology Committee, said legislation to better secure the federal cybersecurity supply chain was clearly needed.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Responding to the Reuters report on Thursday, Democratic Congressman Jim Langevin, a senior member of the House Armed Services Committee, said the Pentagon must consider \u201cany access adversaries may have to source code when it is making purchasing decisions.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Most U.S. government agencies declined to comment when asked whether they were aware technology installed within their networks had been inspected by Russian military contractors. Others said security was of paramount concern but that they could not comment on the use of specific software.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">A Pentagon spokeswoman said it continually monitors the commercial technology it uses for security weaknesses.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">NO PENCILS ALLOWED<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Tech companies wanting to access Russia\u2019s large market are often required to seek certification for their products from Russian agencies, including the FSB security service and Russia\u2019s Federal Service for Technical and Export Control (FSTEC), a defense agency tasked with countering cyber espionage.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">FSTEC declined to comment and the FSB did not respond to requests for comment. The Kremlin referred all questions to the FSB and FSTEC.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">FSTEC often requires companies to permit a Russian government contractor to test the software\u2019s source code.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">SAP HANA, a database system, underwent a source code review in order to obtain certification in 2016, according to Russian regulatory records. The software stores and analyzes information for the State Department, Internal Revenue Service, NASA and the Army.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">An SAP spokeswoman said any source code reviews were conducted in a secure, company-supervised facility where recording devices or even pencils are \u201care strictly forbidden.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cAll governments and governmental organizations are treated the same with no exceptions,\u201d the spokeswoman said.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">While some companies have since stopped allowing Russia to review source code in their products, the same products often remain embedded in the U.S. government, which can take decades to upgrade technology.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Security concerns caused Symantec to halt all government source code reviews in 2016, the company\u2019s chief executive told Reuters in October. But Symantec Endpoint Protection antivirus software, which was reviewed by Russia in 2012, remains in use by the Pentagon, the FBI, and the Social Security Administration, among other agencies, according to federal contracting records reviewed by Reuters.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">In a statement, a Symantec spokeswoman said the newest version of Endpoint Protection, released in late 2016, never underwent a source code review and that the earlier version has received numerous updates since being tested by Russia. The California-based company said it had no reason to believe earlier reviews had compromised product security. Symantec continued to sell the older version through 2017 and will provide updates through 2019.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">McAfee also announced last year that it would no longer allow government-mandated source code reviews.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The cyber firm\u2019s Security Information and Event Management (SIEM) software was reviewed in 2015 by a Moscow-based government contractor, Echelon, on behalf of FSTEC, according to Russian regulatory documents. McAfee confirmed this.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The Treasury Department and Defense Security Service, a Pentagon agency tasked with guarding the military\u2019s classified information, continue to rely on the product to protect their networks, contracting records show.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">McAfee declined to comment, citing customer confidentiality agreements, but it has previously said the Russian reviews are conducted at company-owned premises in the United States.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u2018YOU CAN\u2018T TRUST ANYONE\u2019<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">On its website, Echelon describes itself as an official laboratory of the FSB, FSTEC, and Russia\u2019s defense ministry.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Alexey Markov, the president of Echelon, which also inspected the source code for ArcSight, said U.S. companies often initially expressed concerns about the certification process.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cDid they have any? Absolutely!!\u201d Markov wrote in an email.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cThe less the person making the decision understands about programming, the more paranoia they have. However, in the process of clarifying the details of performing the certification procedure, the dangers and risks are smoothed out.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Markov said his team always informs tech companies before handing over any discovered vulnerabilities to Russian authorities, allowing the firms to fix the detected flaw. The source code reviews of products \u201csignificantly improves their safety,\u201d he said.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Chris Inglis, the former deputy director of the National Security Agency, the United States\u2019 premier electronic spy agency, disagrees.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cWhen you\u2019re sitting at the table with card sharks, you can\u2019t trust anyone,\u201d he said. \u201cI wouldn\u2019t show anybody the code.\u201d<\/span><\/p>\n<p><span style=\"font-size: 8pt\">Source:-\u00a0https:\/\/www.reuters.com\/article\/us-usa-cyber-russia\/tech-firms-let-russia-probe-software-widely-used-by-u-s-government-idUSKBN1FE1DT<\/span><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.biphoo.com\/bipnews\/world-news\/tech-firms-let-russia-probe-software-widely-used-by-u-s-government.html\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground: #ffffff !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 630px !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>Tech firms let Russia probe software widely used by U.S. government Major global technology providers SAP (SAPG.DE), Symantec (SYMC.O) and McAfee have allowed Russian authorities to hunt for vulnerabilities in software deeply embedded across the U.S. government, a Reuters investigation has found. The practice potentially jeopardizes the security of computer [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":57507,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5470],"tags":[116698,116699,6221,7771,116697],"class_list":["post-57502","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-world-news","tag-computer-crime-hacking-cybercrime","tag-insights","tag-russia","tag-software","tag-tech-firms-let-russia-probe-software-widely-used-by-u-s-government"],"_links":{"self":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/57502","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/comments?post=57502"}],"version-history":[{"count":0,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/57502\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media\/57507"}],"wp:attachment":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media?parent=57502"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/categories?post=57502"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/tags?post=57502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}