Man-in-the-middle biz Blue Coat bought by Symantec: Infosec bods are worried

HTTPS-buster and root cert bods joining up? Hmm


Analysis Symantec’s deal to to buy Blue Coat, the controversial web filtering firm, for $4.65bn will bolster its enterprise security business.

But some security experts are concerned about the potential for conflict of interest created by housing Symantec’s digital certificate business and Blue Coat’s man-in-the-middle SSL inspection technologies under the same roof. Business dealings between the two firms have already prompted cause for concern.

Blue Coat sells a range of web and network security appliances and technologies such as ProxySG, a technology that offers content filtering, authentication and caching functionality. One of its products is an SSL Visibility Appliance, which sits in the middle of encrypted traffic flows in order to identify threats (such as botnet communications, data exfiltration by hackers and so on).

Blue Coat technology masquerades as legit websites while Symantec, who bought VeriSign's certification business six years ago, is the biggest provider of SSL certificates.

Last month Blue Coat was accused of misusing an intermediate certificate authority, backed by root certificate authority Symantec. This facility created a means for Blue Coat to issue security certs for almost any website it wanted – certificates that would be implicitly trusted by browsers and apps on PCs, phones and gadgets.

Blue Coat said the facility was used for internal testing and that “rumours of misuse are unfounded”. It also added that “Symantec maintained full control of the private key”, an assurance weakened by the imminent acquisition of Blue Coat by Symantec.

“The conflict between being simultaneously a certificate authority and certificate exploiter is huge,” said Rob Graham of Errata Security, the developer of BlackICE intrusion prevention software. “The real authorities (Microsoft, Google, Firefox, Apple) have been lax, letting CAs slide, but this time they might do something. On the other hand, Blue Coat is a natural fit for AV [anti-virus], letting customers AV scan things otherwise encrypted with SSL.”

We like the management so much, we bought the company

Blue Coat’s web gateway appliances will be added to Symantec’s existing corporate-focused email and endpoint security as well as its consumer-focused Norton anti-virus software.

Traditionally Symantec’s security sales were split more or less evenly between corporate and consumers sales through its Norton line.

Consumer sales have become a legacy business for Symantec because Microsoft has improved its security defences, freemium anti-virus software firms such as AVG and Avast are gaining big market share, and competitors and new entrants have outflanked the company in the mobile security software market.

Acquiring Blue Coat will mean that 62 per cent of Symantec's revenues will come from enterprise security and this will position it better to compete with other enterprise security heavyweights such as FireEye, Check Point Software and Palo Alto Networks.

Although the shift towards the enterprise strategy is clear, Symantec has no immediate plans to sell its consumer unit, which remains profitable, Reuters reports.

Symantec sold its Veritas enterprise software storage business for $7.4bn to a group led by Carlyle Group back in January as part of the same strategy of focusing on the enterprise security software market. ®

Similar topics


Other stories you might like

  • North Korea's Lazarus cyber-gang caught 'spying' on chemical sector companies
    Crypto-coin theft isn't enough to keep these miscreants busy

    North Korea's Lazarus cybercrime gang is now breaking into chemical sector companies' networks to spy on them, according to Symantec's threat intel team.

    While the Korean crew's recent, and highly profitable, thefts of cryptocurrency have been in the headlines, the group still keeps its spying hand in. Fresh evidence has been found linking a recent espionage campaign against South Korean targets to file hashes, file names, and tools previously used by Lazarus, according to Symantec.

    The security shop says the spy operation is likely a continuation of the state-sponsored snoops' Operation Dream Job, which started back in August 2020. This scheme involved using phony job offers to trick job seekers into clicking on links or opening malicious attachments, which then allowed the criminals to install spyware on the victims' computers.

    Continue reading
  • Russian-linked Shuckworm crew ramps up Ukraine attacks
    Cyber-espionage gang using multiple variants of its custom backdoor to ensure persistence, Symantec warns

    A Russian-linked threat group that has almost exclusively targeted Ukraine since it first appeared on the scene in 2014 is deploying multiple variants of its malware payload on systems within the country.

    The Shuckworm gang – also known as Armageddon and Gamaredon – is using at least four distinct variants of its Pterodo backdoor that are designed to perform similar tasks but communicate with different command-and-control (C2) servers, according to Symantec's Threat Hunter Team.

    "The most likely reason for using multiple variants is that it may provide a rudimentary way of maintaining persistence on an infected computer," the researchers wrote in a blog post Wednesday. "If one payload or [C2] server is detected and blocked, the attackers can fall back on one of the others and roll out more new variants to compensate."

    Continue reading
  • Kaspersky cracks Yanluowang ransomware, offers free decryptor
    Step one, get some scrambled files back. Steps two through 37...

    Kaspersky has found a vulnerability in the Yanluowang ransomware encryption algorithm and, as a result, released a free decryptor tool to help victims of this software nasty recover their files.

    Yanluowang, named after a Chinese deity and underworld judge, is a type of ransomware that has been used against financial institutions and other firms in America, Brazil, and Turkey as well as a smaller number of organizations in Sweden and China, Kaspersky said yesterday. The Russian security shop said it found a fatal flaw in the ransomware's encryption system and those afflicted can get a free fix to restore their scrambled data.

    Symantec's threat hunters uncovered this Windows ransomware strain in the fall and said unknown fiends have been using it to infect US corporations since at least August 2021.

    Continue reading
  • Mutating Verblecon malware in illicit cryptomining ... so far
    Symantec team warns ransomware and spying could be next

    Internet fiends are using a relatively new piece of a malicious code dubbed Verblecon to install cryptominers on infected computers. 

    The mutating malware attempts to evade detection by antivirus tools and similar defenses, meaning bad news all round if the software was used to deploy more destructive payloads — and that the crooks using Verblecon may not realize the power of the loader's full potential.

    "The activity we have seen carried out using this sophisticated loader indicates that it is being wielded by an individual who may not realize the capabilities of the malware they are using," Symantec's threat hunting team warned today.

    Continue reading
  • How do China's cyber-spies snoop on governments, NGOs? Probably like this
    Cicada's months-long global espionage campaign marks an expansion of team's capabilities

    A China-backed crew is said to be running a global espionage campaign against governments, religious groups, and non-governmental organizations (NGOs) by, in some cases, possibly exploiting a vulnerability in Microsoft Exchange servers.

    +Symantec's Threat Hunter Team said the campaign, which aims to spy on targeted victims and steal information, likely started in mid-2021, with the most recent activity detected in February. It may still be going on, the researchers observed in a report this week.

    The Threat Hunter Team team is attributing the attacks to Cicada, also known as APT10 – a group that has been operating for more than a decade and that intelligence agencies in the US have linked to China's Ministry of State Security. The researchers are pointing at Cicada because a custom loader and custom malware that have been used exclusively by the group were found in victims' networks.

    Continue reading
  • China-linked malware targeted secure networks in 'multiple governments'
    'Daxin' malware creates backdoors and may have been used since 2013

    The United States' Cybersecurity and Infrastructure Security Agency (CISA), working with security vendor Symantec, has found an extremely sophisticated network attack tool that can invisibly create backdoors, has been plausibly linked to Chinese actors, and may have been in use since 2013.

    Symantec's threat hunting team has named the malware "Daxin" and described it as "a stealthy backdoor designed for attacks on hardened networks". The Broadcom-owned security firm says it's found samples of the malware dating back to 2013, and that features present in recent versions were also found in older cuts of the code. Those recent versions of the malware have been associated with "China-linked threat actors".

    CISA's advisory about the malware describes it as "a highly sophisticated rootkit backdoor with complex, stealthy command and control functionality that enabled remote actors to communicate with secured devices not connected directly to the internet". The agency asserts that Daxin "appears to be optimized for use against hardened targets, allowing the actors to deeply burrow into targeted networks and exfiltrate data without raising suspicions".

    Continue reading
  • NortonLifeLock sniffs around Avast, announces 'advanced discussions' for acquisition
    Company now has 28 days to make up its mind

    NortonLifeLock, the somewhat clunky moniker adopted by the former consumer business arm of the Symantec Corporation, has announced "advanced discussions" with rival Avast over a possible merger.

    "A combination of NortonLifeLock and Avast would bring together two companies with aligned visions, highly complementary business profiles and a joint commitment to innovation that helps protect and empower people to live their digital lives safely," a NortonLifeLock spokesperson claimed in a message to investors.

    "We would draw on the best of both companies to ensure that the combination would benefit our customers, reward our employees and maximise long term value for all shareholders."

    Continue reading

Biting the hand that feeds IT © 1998–2022