Get 40% Off
🚨 Volatile Markets? Find Hidden Gems for Serious Outperformance
Find Stocks Now

UK tech firm Micro Focus to curb code reviews by 'high risk' governments

Published 10/09/2017, 06:55 PM
Updated 10/09/2017, 06:55 PM
© Reuters. FILE PHOTO: A sign stands outside the offices of Micro Focus in Newbury

By Joel Schectman and Dustin Volz

WASHINGTON (Reuters) - British tech firm Micro Focus International Plc (L:MCRO), the new owner of ArcSight security software, said it would restrict reviews of the core operating instructions in its products by "high-risk" governments, after Reuters reported that the application had been scrutinized by Russia.

Micro Focus did not respond to questions seeking to clarify whether the countries included Russia or how it would determine which reviews were likely to be shared with governments. But a company spokeswoman said future reviews would require approval from Micro Focus's chief executive.

And a Micro Focus blog posted on Monday by ArcSight head Jason Schmitt defended the reviews of core software operating instructions, known as source code, as common. He said "that dozens of brand-name products have undergone the same type of certification testing."

"Micro Focus will not allow any source code reviews if we reasonably believe the governments of high risk countries will have access to that review," the Micro Focus spokeswoman said in an email to Reuters.

Micro Focus purchased the ArcSight product line from Hewlett Packard Enterprise Co (N:HPE) in a sale completed last month. Reuters reported last week that HPE allowed a Moscow defense agency to review the inner workings of ArcSight, a cyber defense software used by the Pentagon to guard its computer networks.

Cyber security experts, former U.S. intelligence officials and former ArcSight employees said the practice could help Moscow discover weaknesses in the software, potentially helping attackers to blind the U.S. military to a cyber attack.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

Russia's evaluation of ArcSight concluded last year, at a time when Washington was accusing Moscow of an increasing number of cyber attacks against American companies, U.S. politicians and government agencies, including the Pentagon. Russia has repeatedly denied the allegations.

Russia in recent years has stepped up demands for source code reviews as a requirement for doing business in the country, Reuters reported in June, and many companies have complied.

ArcSight, and other HPE security products, were sold to Micro Focus in a transaction completed in September.

Micro Focus also said it would notify the U.S. government and seek feedback before allowing source code reviews "where applicable." The company spokeswoman did not respond to questions requesting clarification of when such notifications would apply.

Some companies have decided to stop allowing source code reviews as a condition to do business in a foreign market. For example, Symantec (NASDAQ:SYMC) decided in 2016 that they would no longer allow such reviews because of security concerns.

HPE did not alert the Defense Information Systems Agency, which purchases ArcSight for the military, that it had allowed the Russian review, a DISA spokeswoman told Reuters.

The DISA spokeswoman said the agency has no immediate plans to pullback on its use of ArcSight or reconsider its procurement rules in light of the Reuters report. The Pentagon continually evaluates software for security risks, the DISA spokeswoman said.

According to Russian regulatory records and interviews with people with direct knowledge of the issue, the review of ArcSight's code was conducted by Echelon, a company with close ties to the Russian military. The review was done on behalf of Russia's Federal Service for Technical and Export Control (FSTEC), a defense agency that counters cyber espionage.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

HPE said code reviews have taken place for years and are conducted by Russian-government accredited testing companies at an HPE research and development center outside of Russia, where the software maker closely supervises the process.

No code is allowed to leave the premises ensuring "our source code and products were in no way compromised," an HPE spokeswoman said in an email last week. She said in a phone call on Monday that no current HPE products had gone through the Russian review process.

ArcSight source code was tested in August 2015, the Micro Focus spokeswoman said, several months before HPE was spun off from Hewlett-Packard Inc. The Russian certification process for ArcSight was completed in August 2016, according to Russian regulatory records.

HPE has said the inspection process was necessary to obtain certification from Russia's FSTEC in order to sell software to the public sector in Russia.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.