Homepage / Technology / Tech firms let Russia probe software widely used by US government
Menyelami Dunia Slot Thailand: Keseruan dan Peluang Kemenangan Besar Menyelami Dunia Slot Thailand: Pengalaman Bermain yang Tak Terlupakan Meet sexy milfs who’re selecting fun 1xbet 독점 프로모션 코드 2024년 1월: Xnumxxcompletesports 1xbet 독점 프로모션 코드 2024년 1월: Xnumxxcompletesports

Taya365 Casino Login⁚ A Comprehensive Guide

Get ready for the ultimate craigslist sex experience Stake Casino Russia официальный Сайт Для Онлайн Игр И Бонусов Welcome on ultimate dating platform for ssbbw lesbians 1вин Казино ᐉ Вход а Регистрация На 1win Официальный Сайт 1win: Spor Bahisleri Ve Internet Casino Bonus 500% Тотал В Ставках На Спорт%3A не Такое И только Рассчитать Ставка Tv Mostbet Türkiye: En Iyi Oranlar Ve Spor Bahisleri Καζίνο Και Στοιχηματική Σε Έναν Ιστότοπο “1xbet App 1xbet Cellular ᐊ تنزيل 1xbet Apk Android و Iphone ᐊ 1xbet Com Get started on mature sex dating sites now “horseshoe Casino Baltimore Wikipedia Judi Online, Kenali Bahaya, Ciri-Ciri Kecanduan, dan Penanganannya Cassino Apresentando Bônus De Boas-vindas: Veja As Opções Disponíveis Casino Mostbet ᐈ Oficiální Stránky Online Kasin V České Republice Casino E Apostas Desportivas No Brasil Bônus 5000 Brl No Depósito Entrar Beginner’s Explained Casino Wagering: Tips & Strategies Beginner’s Explained Casino Wagering: Tips & Strategies Лучшие Букмекерские Конторы Онлайн Рейтинг Бк 2024 “Slot Machine Nedir? Türkiye’deki Çevrimiçi Slot Rehberi Keep Everything You Win At Usa No First Deposit Casinos “roleta Online Jogos De Roleta Virtual » Betfair Casino Лучшие Онлайн Казино Рейтинг Топ 10 Для Игры На 2024 день” 1xbet 보너스 사용법 알아보기 메인 계정과 보너스 계정의 차이 코리아벳 برنامج المراهنات الرياضية تحميل التطبيق العميل Eg 1xbet Com Коэффициенты Букмекеров%3A Что Такое же Как Рассчитать в Ставках На Спорт Лучшие Букмекерские Конторы Рейтинг Букмекеров Топ Бк 2024 Онлайн Ставки на Спорт Лучшие Букмекерские Конторы Рейтинг Букмекеров Топ Бк 2024 Онлайн Ставки на Спорт Mostbet Türkiye Çevrimiçi Kumarhane Mostbet Casino “топ Приложений Для Ставок На Спорт 2024%3A Букмекеры На Android И Ios “How To Play Roulette: Rules & Betting Как 1win Обзор Удовлетворяет Разнообразные Потребности Пользователей Os 15 Melhores Sites De Apostas Esportivas Gates of Olympus’ýn Slot Oyunlarýnda En Büyük ve Çarpýcý Ödüller Gates of Olympus ile En Ýyi, Karlý ve Avantajlý Kazanç Fýrsatlarý Gates of Olympus’ýn En Popüler ve Ödüllü Makineleri Největší Image Hazardu V Evropě: Proslulé Kasino Versus Monte Carlu Láká Na Neobyčejnou Atmosféru” Jak znaleźć legalne kasyno online? Mostbet Tr Resmî Net Sitesinde Giriş Empieza Kayıt Olm Our Cms Play 17, 800+ Totally Free Us Online Online Casino Games No Download” The Benefits of Learning a Second Language “australia’s #1 Online Gambling Establishment Guide 2024 Kde Sony Ericsson Natáčel Film On Line Casino Roya Leon Casino Έως 1 500 Ανά Κατάθεση! 6 Best Gay Online Dating Sites (2023) – Join 100% Totally Free LGBTQ+ Programs! 1win: Casino Ve Bahisçi Resmi Web Sitesi 2024, Online Spor Bahisleri, 1win Giriş” 4 Ways To Beat The Slots Лучшие Игровые Автоматы Онлайн%3A Играйте желающим В Казино Start your hookup journey with sugar mummies now Online Bitcoin Gambling Enterprises: A Comprehensive Overview Learn A Few Of The Top Benefits Of Mobile Casino Gambling Online Casino Slots Bitcoin Gambling Establishments: The Future of Online Gambling Online Casino Sites that Accept PayPal: A Convenient and Secure Settlement Alternative The Advantages of Playing Online Casino Online Basics of the Free Casino Bonus Video Slots What You Must Know Discover the Excitements of Free Blackjack Online The Best Bitcoin Gambling Enterprises that Accept Bitcoins What Are Zaza Pills? A Comprehensive Overview Understanding Varicose Veins: Reasons, Symptoms, and Treatment Options Online Payday Loans in South Africa: Whatever You Need to Know The Ultimate Guide to Online Free Live Roulette Live Roulette Benefit: Whatever You Need to Know Top Bitcoin Gambling Enterprises Overview Todo lo que necesitas saber sobre los mini préstamos Online Live Roulette Bonus: A Guide to Optimizing Your Payouts Instant Play Online Gambling Establishment: The Ultimate Guide What You Need to Understand About Free Spins Benefits The Power of One Card Tarot Readings Unlocking the Mysteries of Card Analysis Tarot The Art of Tarot Card Card Reading: A Comprehensive Guide Tarot Card Cards Free Analysis: Opening the Mysteries of Your Future Best Totally Free Spins No Down Payment: A Guide to Winning Big Without Investing a Penny Mastercard in Online Gambling Enterprises: Your Guide to Safe and Secure Gambling Decreasing Your Cholesterol: A Comprehensive Overview to a Healthier Heart “Fairly Sweet Bonanzaana Sayfamıza Hoş Geldiniz! Eğlenceli Oyunlar Christian Counselor y mentor Nancy Pina Ayuda Consumidores plan Logro en Citas online y Vida “Durante İyi Slot Oyunları Ücretsiz Casino Oyunları” Top Twelve Online Gambling Canada Sites For Real Money In 2025 لعبة كراش Car Crash في 1xbet: الدليل الشامل موقع مراه Mostbet Registrace Z Česko Pokyny Pro Registraci A Ověření Účtu While 1win advertises 247 support response times can vary depending on the. About 1win gaming and situs 1win. Sports Covered Based on the provided text 1Wins sports betting platform includes. About 1win товары букмекер and site 1win é confiavel. Languages Supported While definitive confirmation of all supported languages requires direct verification. About how to use bonus casino in 1win online and 1win hacks. A. About 1win iphone скачать and تحميل 1win. Despite some negative feedback the overall user sentiment towards 1Win in Mozambique. About 1win 앱 안드로이드 and como recargar en 1win. The provided text mentions 247 support for 1win users in Bangladesh and. About jet 1win and 1win android app download. Seguridad de las Transacciones en 1Win 1Win utiliza protocolos de seguridad avanzados. About 1win mine hack and 1win register login app. In Bangladesh 1Wins operational legality stems from its Curaçao eGaming license 8048JAZ2018-040. About букмекер 1win and 1win dota team. What is the easiest way to get sluts around me? 1win Скачать На Андроид Бесплатное Приложение С официального Сайта Преимущества автоматизации рабочих процессов в букмекерские конторы “1win Uzbekistan ⬅️ Rasmiy Sayti Bukmekerlik Kompaniyasining” VDcasino’ýn Slot Oyunlarýnda En Büyük ve Çarpýcý Gelirler VDcasino’ýn En Popüler ve Tercih Edilen Makineleri “mostbet Com’da Oynamak Mı Istiyorsunuz? Buradan Giriş Yapın

Technology

Tech firms let Russia probe software widely used by US government

Major global technology providers SAP, Symantec and McAfee have allowed Russian authorities to hunt for vulnerabilities in software deeply embedded across the U.S. government, a Reuters investigation has found.

The practice potentially jeopardizes the security of computer networks in at least a dozen federal agencies, U.S. lawmakers and security experts said. It involves more companies and a broader swath of the government than previously reported.

In order to sell in the Russian market, the tech companies let a Russian defense agency scour the inner workings, or source code, of some of their products. Russian authorities say the reviews are necessary to detect flaws that could be exploited by hackers.

But those same products protect some of the most sensitive areas of the U.S. government, including the Pentagon, NASA, the State Department, the FBI and the intelligence community, against hacking by sophisticated cyber adversaries like Russia.

Reuters revealed in October that Hewlett Packard Enterprise software known as ArcSight, used to help secure the Pentagon’s computers, had been reviewed by a Russian military contractor with close ties to Russia’s security services.

Now, a Reuters review of hundreds of U.S. federal procurement documents and Russian regulatory records shows that the potential risks to the U.S. government from Russian source code reviews are more widespread.

Beyond the Pentagon, ArcSight is used in at least seven other agencies, including the Office of the Director of National Intelligence and the State Department’s intelligence unit, the review showed. Additionally, products made by SAP, Symantec and McAfee and reviewed by Russian authorities are used in at least eight agencies. Some agencies use more than one of the four products.

McAfee, SAP, Symantec and Micro Focus, the British firm that now owns ArcSight, all said that any source code reviews were conducted under the software maker’s supervision in secure facilities where the code could not be removed or altered. The process does not compromise product security, they said. Amid growing concerns over the process, Symantec and McAfee no longer allow such reviews and Micro Focus moved to sharply restrict them late last year.

The Pentagon said in a previously unreported letter to Democratic Senator Jeanne Shaheen that source code reviews by Russia and China “may aid such countries in discovering vulnerabilities in those products.”

Reuters has not found any instances where a source code review played a role in a cyberattack, and some security experts say hackers are more likely to find other ways to infiltrate network systems.

But the Pentagon is not alone in expressing concern. Private sector cyber experts, former U.S. security officials and some U.S. tech companies told Reuters that allowing Russia to review the source code may expose unknown vulnerabilities that could be used to undermine U.S. network defenses.

“Even letting people look at source code for a minute is incredibly dangerous,” said Steve Quane, executive vice president for network defense at Trend Micro, which sells TippingPoint security software to the U.S. military.

Worried about those risks to the U.S. government, Trend Micro has refused to allow the Russians to conduct a source code review of TippingPoint, Quane said.

Quane said top security researchers can quickly spot exploitable vulnerabilities just by examining source code.

“We know there are people who can do that, because we have people like that who work for us,” he said.

Many of the Russian reviews have occurred since 2014, when U.S.-Russia relations plunged to new lows following Moscow’s annexation of Crimea. Western nations have accused Russia of sharply escalating its use of cyber attacks during that time, an allegation Moscow denies.

Some U.S. lawmakers worry source code reviews could be yet another entry point for Moscow to wage cyberattacks.

“I fear that access to our security infrastructure — whether it be overt or covert — by adversaries may have already opened the door to harmful security vulnerabilities,” Shaheen told Reuters.

In its Dec. 7 letter to Shaheen, the Pentagon said it was “exploring the feasibility” of requiring vendors to disclose when they have allowed foreign governments to access source code. Shaheen had questioned the Pentagon about the practice following the Reuters report on ArcSight, which also prompted Micro Focus to say it would restrict government source code reviews in the future. HPE said none of its current products have undergone Russian source code review.

Lamar Smith, the Republican chairman of the House Science, Space and Technology Committee, said legislation to better secure the federal cybersecurity supply chain was clearly needed.

Most U.S. government agencies declined to comment when asked whether they were aware technology installed within their networks had been inspected by Russian military contractors. Others said security was of paramount concern but that they could not comment on the use of specific software.

A Pentagon spokeswoman said it continually monitors the commercial technology it uses for security weaknesses.

Tech companies wanting to access Russia’s large market are often required to seek certification for their products from Russian agencies, including the FSB security service and Russia’s Federal Service for Technical and Export Control (FSTEC), a defense agency tasked with countering cyber espionage.

FSTEC declined to comment and the FSB did not respond to requests for comment. The Kremlin referred all questions to the FSB and FSTEC.

FSTEC often requires companies to permit a Russian government contractor to test the software’s source code.

SAP HANA, a database system, underwent a source code review in order to obtain certification in 2016, according to Russian regulatory records. The software stores and analyzes information for the State Department, Internal Revenue Service, NASA and the Army.

An SAP spokeswoman said any source code reviews were conducted in a secure, company-supervised facility where recording devices or even pencils are “are strictly forbidden.”

“All governments and governmental organizations are treated the same with no exceptions,” the spokeswoman said.

While some companies have since stopped allowing Russia to review source code in their products, the same products often remain embedded in the U.S. government, which can take decades to upgrade technology.

Security concerns caused Symantec to halt all government source code reviews in 2016, the company’s chief executive told Reuters in October. But Symantec Endpoint Protection antivirus software, which was reviewed by Russia in 2012, remains in use by the Pentagon, the FBI, and the Social Security Administration, among other agencies, according to federal contracting records reviewed by Reuters.

In a statement, a Symantec spokeswoman said the newest version of Endpoint Protection, released in late 2016, never underwent a source code review and that the earlier version has received numerous updates since being tested by Russia. The California-based company said it had no reason to believe earlier reviews had compromised product security. Symantec continued to sell the older version through 2017 and will provide updates through 2019.

McAfee also announced last year that it would no longer allow government-mandated source code reviews.

The cyber firm’s Security Information and Event Management (SIEM) software was reviewed in 2015 by a Moscow-based government contractor, Echelon, on behalf of FSTEC, according to Russian regulatory documents. McAfee confirmed this.

The Treasury Department and Defense Security Service, a Pentagon agency tasked with guarding the military’s classified information, continue to rely on the product to protect their networks, contracting records show.

McAfee declined to comment, citing customer confidentiality agreements, but it has previously said the Russian reviews are conducted at company-owned premises in the United States.

On its website, Echelon describes itself as an official laboratory of the FSB, FSTEC, and Russia’s defense ministry. Alexey Markov, the president of Echelon, which also inspected the source code for ArcSight, said U.S. companies often initially expressed concerns about the certification process.

“Did they have any? Absolutely!!” Markov wrote in an email.

“The less the person making the decision understands about programming, the more paranoia they have. However, in the process of clarifying the details of performing the certification procedure, the dangers and risks are smoothed out.”

Markov said his team always informs tech companies before handing over any discovered vulnerabilities to Russian authorities, allowing the firms to fix the detected flaw. The source code reviews of products “significantly improves their safety,” he said.

Chris Inglis, the former deputy director of the National Security Agency, the United States’ premier electronic spy agency, disagrees.

“When you’re sitting at the table with card sharks, you can’t trust anyone,” he said. “I wouldn’t show anybody the code.”

Source: Tech CNBC
Tech firms let Russia probe software widely used by US government

Comments are closed.