Google security researcher: Keep Sophos away from high value systems


Recommended Posts

Google security engineer Tavis Ormandy discovered several flaws in Sophos antivirus and says the product should be kept away from high value information systems unless the company can avoid easy mistakes and issue patches faster.

Ormandy has released a scathing 30-page analysis ?Sophail: Applied attacks against Sophos Antivirus?, in which he details several flaws ?caused by poor development practices and coding standards?, topped off by the company?s sluggishly response to the warning he had working exploits for those flaws.

One of the exploits Ormandy details is for a flaw in Sophos? on-access scanner, which could be used to unleash a worm on a network simply by targeting a company receiving an attack email via Outlook. Although the example he provided was on a Mac, the ?wormable, pre-authentication, zero-interaction, remote root? affected all platforms running Sophos.

Ormandy released the paper (PDF) as an independent security researcher and concludes: ?nstalling Sophos Antivirus exposes machines to considerable risk. If Sophos do not urgently improve their security posture, their continued deployment causes significant risk to global networks and infrastructure.?

http://www.cso.com.a..._value_systems/

sophailv2.pdf

And, in fact, do a search if your favorite security suite has been cracked/activation-bypassed or otherwise defeated by warez release groups. And then keep away from it and demand your money back, if possible. It's useless. There aren't many left these days, but they do happen. If warez people could pwn it, somebody with more evil intentions can and will do it as well, and you just might happen to be in the middle of it.

I am a sophos partner and this concerns me greatly how they've declined. I will have a talk with them about this. I am pretty irritated at all these issues....

I am a sophos partner and this concerns me greatly how they've declined. I will have a talk with them about this. I am pretty irritated at all these issues....

remixedcat,

I would be very interested in hearing what they say to you on this. I couldn't see an official response on their site to this when I looked last night. I have their enterprise console out in a few places too.

remixedcat,

I would be very interested in hearing what they say to you on this. I couldn't see an official response on their site to this when I looked last night. I have their enterprise console out in a few places too.

I will be contacting them shortly...

sophos contacted.... awating response..

Thanks, I would hope that they will get independent verification of their assertion that these were fixed circa September and have some sort of statement prepared to show changes in their development process. If they do that I see no need to switch and compliment Google for giving them lead-time.

Edit: I just checked the main console and it seems that 10.2 doesn't automatically apply on rollout if you have your update manager configured to 10.x recommended. The Mac's have gone to 8.0.8.1 automatically though. So don't forget to check your update manager configs!

You're welcome... I got a response so far... will get a more detailed one later:

Hello Liz ,

Thank you for your email and taking the time to share with us the concerns you have.

Below is some information you may want to review .

Sophos has written about his findings on Naked Security http://nakedsecurity.sophos.com/2012/11/05/tavis-ormandy-sophos/

We have forwarded your email to the proper Sophos Team . They will be

the best suited to address the questions and concerns you have.

They will be reviewing the email and questions to determine the best source of action and

provide you with the correct information .

Again, thank you for notifying us of the concerns you have so that we can ensure that they are addressed for you.

Let us know if you need any further assistance.

All the best .

Regards,

got another response from Sophos:

Thanks for reaching out with this.

We most definitely appreciate Mr. Ormandy?s work with Sophos.

We can only get better with independent work like his.

As a security company, keeping customers safe is our primary responsibility. As a result, we periodically receive third party reports about areas of our products and those of other software companies. We welcome this scrutiny and are committed to investigating all vulnerability reports and implementing the best course of action in the quickest time period.

You can find our fixes and rollouts for the flagged bugs here:

http://www.sophos.com/en-us/support/knowledgebase/118424.aspx

For the updater issues, please take a look at this article which explains the root causes and how we?ve updated our solutions and procedures to prevent this from occurring in the future.

http://www.sophos.com/en-us/support/knowledgebase/shh-root-cause-analysis.aspx

Although this is not a an excuse, false positive updates are a reality that have hit every single major security company out there including McAfee, Symantec, and Trend.

It is also important to note that no serious security company can claim that their software protects everything. Threats are always evolving and changing and it is up to us to change and grow with the times.

With respect to Mr. Ormandy, he has indicated that he has not reviewed any other security software with this examination. I suspect that if he were to review other solutions his results would be quite similar and in most cases much more revealing.

Let me know if you need any other help on this.

I?ll be glad to provide any further assistance.

Take care.

remixedcat,

Thanks for coming back with that, it is exactly what I wanted (expected) to hear.

I had Anti-Virus 10.0.9 / 8.0.8.1 out already and Anti-Virus 10.2.1 went out over night. The knowledge base links were quite useful.

Sure, I haven't been presented with any reason to approach management and say that there is a problem that looks like it will undermine the security of the network or of users.

Mistakes and bugs happen in software development; reactionist responses about flocking to a competitor in the face of them just aren't helpful or realistic when you have spent out for site licenses. If their response had been anything else (i.e. "we *may* fix it in SAV11 after you re-license next year [but then again we may not]") or any attempt to downplay or spin it was used then after a threat assessment my response may have been different. In all honesty I find SAV Enterprise Console to be pretty tidy, yes there are a few limitations that I have issue over, but it works - and I prefer it to the likes of F-Secure's equivalent.

Also the thought of having to do a mobile device recall and changing Mac's to another vendor really doesn't appeal on the greater scheme of good uses of one's time :rofl: .

It looks like about 1/3 of my endpoints have picked up 10.2.0 or higher as of right now; about normal for a version change at this point. As usual there is one on the 4th floor that is refusing to update... they only do it because I'm on the ground floor *sigh*

:rolleyes:

Agreed. I did like their responses as well. They were also very prompt with the replies and I profusely thank them for it.

This topic is now closed to further replies.
  • Posts

    • All these CEOs got the biggest boners thinking about firing employees for AI. Turned out it was just a wet dream.
    • And the fact that the majority of people from Poland are white European Christians while the people you are complaining about in post after post are not is just a coincidence... Every sentence in your post I am replying to is racist nonsense. None of it is actually based on any facts whatsoever. All immigrants are seeking a better life too. It's literally the only reason they would risk everything and leave their homes, families, and homeland. They are working and contributing to the economy too, as you even admit. They get the same benefits your partner did AND that YOU are eligible for as well. That is one of the key things of the EU and a mark of a civilization. That is the definition of a society where everyone is given a chance, treated equally and fairly, and is judged by the content of their character, not their different skin color or which version of ignorant superstitious nonsense their parents lied about as children. Racists around the world said the same things about the Irish and Jews and Poles (like your partner) and...every other immigrant movement over the centuries. What's your family's heritage, by the way? Were your ancestors lied about with racist fearmongering crapola by self-entitled locals the same way as you are now? If someone like that said the same things about all people from Poland, like your partner, would they be right? Or would you want them to judge your partner based on who they actually were, not where they just happened to come from?
    • Again, this is an irrelevant attempt to attack the messenger. The truth does not require any justification.
    • Removed the blue and underline as you did not post a link. This would also  be considered spamming.
    • Why it's almost impossible to produce a smartphone in the United States by Hamid Ganji If you look at the back of some Apple products, you can see the famous phrase “Designed by Apple in California, Assembled in China.” This phrase appears on products from one of the largest smartphone brands in the United States. These products are designed in the U.S., but their manufacturing takes place in China, India, Vietnam, or even Brazil. But why can’t Apple, as one of the largest American tech companies, produce its iPhones on U.S. soil? The idea for this topic came to me after the Trump Foundation launched a smartphone called the T1 and claimed that it was designed and built with American values in mind. However, this claim did not last long, as it was revealed that Trump’s phone was actually a rebranded HTC U24 Pro, with only a gold case and minor internal component changes. You see? Even a phone that is supposed to represent American values is manufactured in China. With a gross domestic product (GDP) exceeding $32 trillion, the United States is currently the world’s largest economy, while China ranks second with around $20 trillion. On the other hand, the United States is by a wide margin the global leader in various technological fields, and American companies spend hundreds of billions of dollars annually on research and development. From Apple and Google to Microsoft, Lockheed Martin, Boeing, and others, American tech and industrial giants lead their foreign competitors in many sectors. The United States also has no shortage of smartphone brands. Apple, Google, and Motorola are among the major brands in the smartphone market, collectively holding a significant share. However, the vast majority of their products are manufactured outside the United States. So why is it that the world’s largest economy, home to the most advanced technology companies and industrial powers, cannot produce a smartphone on its own soil? Let’s explore this question together. Even threats to impose tariffs won’t work After Trump entered the White House as the 47th President of the United States, his administration adopted strict tariff policies. One of these policies was the imposition of a 25% tariff on smartphones manufactured outside the United States. Trump said he “had a little problem” with Apple CEO Tim Cook over producing smartphones outside the U.S. So he thought that threatening a 25% tax on imported phones might force Apple to bring manufacturing back to the United States. “I have long ago informed Tim Cook of Apple that I expect their iPhones that will be sold in the United States of America will be manufactured and built in the United States, not India, or anyplace else,” Trump wrote on Truth Social. Image via The White House Although Apple currently manufactures some of the iPhone’s chips in the United States with TSMC's help, it still shows no willingness to shift full iPhone production to the country. At the time, renowned Apple supply chain analyst Ming-Chi Kuo wrote on X, “In terms of profitability, it’s way better for Apple to take the hit of a 25% tariff on iPhones sold in the US market than to move iPhone assembly lines back to the US.” However, manufacturing a smartphone in the United States is not as easy as it might seem, and many technical and economic barriers are involved. The lack of necessary manufacturing hubs There is a clear reason why many companies prefer to manufacture their products in China. China has established itself as the main global manufacturing hub for international companies, and over the past few decades, large contract manufacturers have emerged there, allowing companies like Apple to outsource production. One such example is Foxconn, which also manufactures some Apple products in India. Building the infrastructure required to produce smartphones in the United States would require tens of billions of dollars in new investment. Factories would need to be built, essential manufacturing equipment would have to be installed, and, most importantly, a skilled workforce capable of operating these systems would need to be recruited and trained. The United States currently lacks the core infrastructure needed to manufacture smartphones, and for this reason, many companies prefer to outsource production to Chinese contractors rather than spend tens of billions of dollars to build that infrastructure, which is significantly more economically efficient. Additionally, building such infrastructure in the United States could take up to a decade, ultimately leading to a significant increase in the product's final price for consumers. Shortage of trained labor in the U.S. compared to China Decades of serving as a global manufacturing hub have allowed China to build a massive talent pool in the production sector that is almost unmatched worldwide. Today, if a company chooses to manufacture its products in China, it can be confident that the workers involved in production have years of experience in their respective roles and are capable of producing high-quality goods with minimal errors. Even if we assume that tens of billions of dollars were invested in building smartphone manufacturing infrastructure in the United States, finding skilled workers would remain highly challenging. Apple CEO Tim Cook visiting the iPhone 6 assembly line in China in 2014. Image: Tim Cook on X In a 2015 interview on CBS’s 60 Minutes, Tim Cook said the main reason Apple isn’t producing in the US is a lack of skills. "China put an enormous focus on manufacturing, in what you and I would call vocational kind of skills. The US over time began to stop having as many vocational kinds of skills. I mean you could take every tool and die maker in the United States and probably put them in the room that we're currently sitting in. In China you would have to have multiple football fields,” Cook said. Also, in 2017, at the Fortune Global Forum in Guangzhou, Cook once again emphasized the importance of highly skilled Chinese workers. “China has moved into very advanced manufacturing, so you find in China the intersection of craftsman kind of skill, and sophisticated robotics and the computer science world. That intersection, which is very rare to find anywhere, that kind of skill, is very important to our business because of the precision and quality level that we like. The thing that most people focus on if they’re a foreigner coming to China is the size of the market, and obviously, it’s the biggest market in the world in so many areas. But for us, the number one attraction is the quality of the people,” Apple CEO said. Higher labor costs in the United States Producing almost any product in the United States is more expensive than in many other countries, and one of the main reasons is the higher cost of labor in the U.S. According to the Bureau of Labor Statistics, median weekly earnings of full-time workers in the United States were $1,235 in the first quarter of 2026. Meanwhile, the average annual salary in China's private sector in 2025 was RMB 71,590 (US$9,961). In many parts of the world, the weekly wage of an American worker is equivalent to several months of income. Another important factor to consider is that in the United States, the workforce capable of working on a smartphone assembly line is highly specialized and therefore commands higher-than-average wages. According to an estimate by Bank of America, producing an iPhone in the U.S. is technically possible, but “iPhone cost can increase 25% purely on higher labor cost in the U.S.” However, this 25% increase applies only if final assembly is performed in the United States while components are still sourced from China or elsewhere. In this case, the price of a base iPhone would rise from $799 to around $1,000. But in another scenario, if Apple were to produce the required components for the iPhone within the United States, production costs could increase by more than 90%. Trump’s dream for a “Made in the USA” iPhone might never come true In a free-market capitalist economy, one of the primary responsibilities of any CEO is to maximize profit. Using Apple as an example, Tim Cook’s role is to maximize the company’s profits so that it can fund research and development for new products and invest in areas such as artificial intelligence, while also keeping shareholders satisfied. Therefore, it is entirely understandable that Apple would choose not to bring its manufacturing back to the United States and instead keep production in countries where labor is cheaper, and products can be manufactured at a lower cost, thereby maximizing its profit margins. What is your opinion about manufacturing smartphones in the United States? If you are an American citizen, would you be willing to pay hundreds of dollars more for a smartphone made domestically in the USA? Let us know in the comments.
  • Recent Achievements

    • Conversation Starter
      jessse3334 earned a badge
      Conversation Starter
    • Reacting Well
      JuvenileDelinquent earned a badge
      Reacting Well
    • One Month Later
      Excellence2025 earned a badge
      One Month Later
    • Week One Done
      Excellence2025 earned a badge
      Week One Done
    • Week One Done
      flexorcist earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      506
    2. 2
      +Edouard
      196
    3. 3
      PsYcHoKiLLa
      153
    4. 4
      Steven P.
      72
    5. 5
      FloatingFatMan
      65
  • Tell a friend

    Love Neowin? Tell a friend!