Story image

Conspiracy looms: NSS Labs takes CrowdStrike, ESET, Symantec & AMTSO to court

27 Sep 18

Cybersecurity testing organisation NSS Labs is accusing three major security firms and an industry body of boycotting independent security tests of their products.

NSS Labs filed an antitrust suit against CrowdStrike, ESET, Symantec, and the Anti-Malware Testing Standards Organization (AMTSO) earlier this month. It claims that the defendants boycott NSS Labs’ apparently unbiased and independent product testing to prevent criticism and imperfections in security products.

NSS Labs also accuses CrowdStrike and its CTO Dimitri Alperovitch of arranging a meeting at the RSA conference earlier this year. 

The meeting was “with the express intent, purpose and effect of obtaining agreement among the competitors to refuse to do business with companies, including specifically NSS Labs, who attempt to perform public tests of their products using testing methodologies other than those agreed to by the EPP Vendor Conspirators and embodied in the AMTSO Testing Standard”.

NSS Labs CEO Vikram Phatak wrote in a recent blog that his company’s mission is to help the cybersecurity industry become more transparent and accountable – but some security vendors don’t live up to those standards, and they know it.

“If you are in the cybersecurity industry, it won’t surprise you to hear that vendors often know about their products’ deficiencies yet don’t reveal them to consumers. What should shock you is that they are actively conspiring to prevent independent testing that uncovers those product deficiencies to prevent consumers from finding out about them,” he writes.

This has a flow-on effect for customers, who have almost everything to lose, including financial loss and in some cases, physical safety. 

He says that some vendors address flaws; others try to avoid testing. If one vendors avoids testing they are singled out, but apparently there’s safety in numbers.

“If a group of vendors agree ahead of time to boycott an independent test lab – say a lab they cannot get to do their bidding – then each is insulated from criticism by being one among many."

NSS Labs claim that the AMTSO and participating organisations including CrowdStrike, ESET, and Symantec, have conspired to claim fair and useful testing that sets their agendas – not fair and unbiased testing.

Phatak adds that CrowdStrike has included clauses in its end user licensing agreements saying that product testing is subject to their permission – something he believes is unethical and deceptive.

“NSS Labs is informed and believes and thereon alleges that CrowdStrike is attempting to conceal its EPP Security Defects in part because of the negative publicity that resulted from the Russian hacking of the Democratic National Committee (DNC),” legal documents state.

CrowdStrike has responded to NSS Labs statements, saying NSS Labs is a 'pay-to-play' testing business that uses fraud to obtain products.

"NSS is a for-profit, pay-to-play testing organisation that obtains products through fraudulent means and is desperate to defend its business model from open and transparent testing. We believe their lawsuit is baseless."

"CrowdStrike supports independent and standards-based testing—including public testing—for our products and for the industry. We have undergone independent testing with AV-Comparatives, SE Labs, and MITRE. We applaud AMTSO’s efforts to promote clear, consistent, and transparent testing standards."

However Phatak claims vendors are "openly exerting control and collectively boycotting testing organisations that don’t comply with their AMTSO standards – even going so far as to block the independent purchase and testing of their products".

“AMTSO and its Board of Directors largely comprise, and are controlled by, EPP product vendors,” legal documents state.

He says that NSS Labs knows consumers trust security vendors to protect them, but there is often no way to know if a company is really trustworthy. If it’s good enough to sell, it’s good enough to test, he adds.

NSS Labs is also seeking damages according to proof, an injunction against the defendants for wrongful acts, attorney fees and lawsuit fees.

“Many of you reading this have relied on NSS Labs tests and insights to guide your decisions. We strive to earn your trust every day and do not take your trust for granted. It is our hope that our actions today mark an important step forward in advancing transparency and accountability in the cybersecurity industry,” Phatak concludes.

How healthcare can prepare for My Health Record roll-out - Proofpoint
Australia’s healthcare sector is the continent’s biggest cybercrime target, according to a July report from the Australian Information Commissioner.
How DEX aims to guide process-enabled automation strategies
"Although automation is gaining a lot of momentum, there are many instances where early adopters have failed to achieve their business transformation and ROI goals."
Penten & Cyber Security CRC to research 'advanced cyber traps'
The research centres on how advanced cyber traps, which are used to identify data breaches as they happen, can be used in conjunction with tools such as artificial intelligence.
Achieving cyber resilience in the telco industry - Accenture
Whether hackers are motivated by greed, or a curiosity to assess a telco’s weaknesses; the interconnected nature of the industry places it in a position of increased threat
The CISO view on DevOps: How to protect privileged access in the cloud
While security strategies should address privileged access and the risk of unsecured secrets and credentials, they should also closely align with DevOps culture and methods.
Nasuni receives AWS competency status for primary storage
The recognition certifies that Nasuni Cloud File Services meet AWS's strict technical proficiency requirements for primary storage.
How mass data fragmentation impacts business growth and compliance readiness
"About 44% of Australian businesses use six or more solutions to try to manage fragmented data sources and repositories."
LogicMonitor launches container monitoring solutions
Kubernetes monitoring and LM Service Insight provide performance analytics and data retention for microservices and containerised applications.