Gen Digital Inc. | |
Former Name: |
|
Type: | Public |
Founded: | in Sunnyvale, California, U.S. |
Founder: | Gary Hendrix |
Hq Location: | |
Area Served: | Worldwide |
Industry: | Computer software |
Products: | Cybersecurity software |
Services: | Computer security |
Revenue Year: | 2024 |
Income Year: | 2024 |
Net Income Year: | 2024 |
Assets Year: | 2024 |
Equity Year: | 2024 |
Num Employees Year: | 2024 |
Brands: | |
Footnotes: | Financials .[1] |
Gen Digital Inc. (formerly Symantec Corporation and NortonLifeLock) is a multinational software company co-headquartered in Tempe, Arizona and Prague, Czech Republic. The company provides cybersecurity software and services. Gen is a Fortune 500 company and a member of the S&P 500 stock-market index. The company also has development centers in Pune, Chennai and Bangalore. Its portfolio includes Norton, Avast, LifeLock, Avira, AVG, ReputationDefender, and CCleaner.
On October 9, 2014, Symantec declared it would split into two independent publicly traded companies by the end of 2015. One company would focus on security, the other on information management. On January 29, 2016, Symantec sold its information-management subsidiary, named Veritas Technologies, and which Symantec had acquired in 2004,[2] to The Carlyle Group.[3] On August 8, 2019, Broadcom Inc. announced they would be acquiring the Enterprise Security software division of Symantec for $10.7 billion.[4] After the acquisition, Symantec became known as NortonLifeLock.[5] [6] After completing its merger with Avast in September 2022, the company adopted the name Gen Digital Inc.[7]
Founded in 1982 by Gary Hendrix with a National Science Foundation grant, Symantec was originally focused on artificial intelligence-related projects, including a database program.[8] Hendrix hired several Stanford University natural language processing researchers as the company's first employees.[8]
In 1984, it became clear that the advanced natural language and database system that Symantec had developed could not be ported from DEC minicomputers to the PC.[9] This left Symantec without a product, but with expertise in natural language database query systems and technology. As a result, later in 1984, Symantec was acquired by another, smaller software startup company, C&E Software, founded by Denis Coleman and Gordon Eubanks and headed by Eubanks.[10] C&E Software developed a combined file management and word processing program called Q&A.[10]
The merged company retained the name Symantec.[10] Eubanks became its chairman, Vern Raburn, the former president of the original Symantec, remained as president of the combined company.[11] The new Symantec combined the file management and word processing functionality that C&E had planned, and added an advanced Natural Language query system (designed by Gary Hendrix and engineered by Dan Gordon) that set new standards for ease of database query and report generation. The natural language system was named "The Intelligent Assistant". Turner chose the name of Q&A for Symantec's flagship product, in large part because the name lent itself to use in a short, easily merchandised logo. Brett Walter designed the user interface of Q&A (Brett Walter, director of product management). Q&A was released in November 1985.
In 1986, Vern Raburn and Gordon Eubanks swapped roles, and Eubanks became CEO and president of Symantec, while Raburn became its chairman.[12] After this change, Raburn had little involvement with Symantec, and in a few years, Eubanks added chairmanship to his other roles. After a slow start for sales of Q&A in the fall of 1985 and spring of 1986, Rod Turner, a Symantec Sr. Executive, signed up a new advertising agency called Elliott/Dickens, embarked on an aggressive new advertising campaign, and came up with the "Six Pack Program" in which all Symantec employees, regardless of role, went on the road, training and selling nationwide in the United States. Turner named it Six Pack because employees were to work six days a week, see six dealerships per day, train six sales representatives per store and stay with friends free or at Motel 6.[13] Simultaneously, a promotion was run jointly with SofSell (which was Symantec's exclusive wholesale distributor in the United States for the first year that Q&A was on the market). This promotion was very successful in encouraging dealers to try Q&A.
During this time, Symantec was advised by its board members Jim Lally and John Doerr that if it would cut its expenses and grow revenues enough to achieve cash flow break-even, then Kleiner, Perkins, Caufield & Byers would back the company in raising more venture capital. To accomplish this, the management team worked out a salary reduction schedule where the chairman and the CEO would take zero pay, all vice presidents would take a 50% pay cut, and all other employees' pay was cut by 15%. Two employees were laid off. Eubanks also negotiated a sizable rent reduction on the office space the company had leased in the days of the original Symantec. These expense reductions, combined with strong international sales of Q&A, enabled the company to attain break-even.
The significantly increased traction for Q&A from this re-launch grew Symantec's revenues substantially, along with early success for Q&A in international markets (uniquely a German version was shipped three weeks after the United States version, and it was the first software in the world that supported German Natural Language) following Turner's having emphasized establishing international sales distribution and multiple language versions of Q&A from the initial shipment.
In 1985, Rod Turner negotiated the publishing agreement with David Whitney for Symantec's second product, which Turner named NoteIt (an annotation utility for Lotus 1-2-3). It was evident to Turner that NoteIt would confuse the dealer channel if it was launched under the Symantec name because Symantec had built up interest by that stage in Q&A (but not yet shipped it), and because the low price for the utility would not be initially attracted to the dealer channel until demand had been built up. Turner felt that the product should be marketed under a unique brand name.
Turner and Gordon E. Eubanks Jr., then chairman of Symantec Corporation, agreed to form a new division of Symantec, and Eubanks delegated the choice of name to Turner. Turner chose the name Turner Hall Publishing, to be a new division of Symantec devoted to publishing third-party software and hardware. The objective of the division was to diversify revenues and accelerate the growth of Symantec. Turner chose the name Turner Hall Publishing, using his last name and that of Dottie Hall (Director of Marketing Communications) to convey the sense of a stable, long-established, company.[14] [15] Turner Hall Publishing's first offering was Note-It, a notation utility add-in for Lotus 1-2-3, which was developed by David Whitney, and licensed to Symantec.[16] [17] Its second product was the Turner Hall Card, which was a 256k RAM, half slot memory card, initially made to inexpensively increase the available memory for Symantec's flagship product, Q&A. The Turner Hall division also marketed the card as a standalone product. Turner Hall's third product, also a 1-2-3 add-in was SQZ! a Lotus 1-2-3 spreadsheet compression utility developed by Chris Graham Synex Systems.[18] In the summer of 1986 Eubanks and Turner recruited Tom Byers from Digital Research, to expand the Turner Hall Publishing product family and lead the Turner Hall effort.
By the winter of 1986–87, the Turner Hall Publishing division had achieved success with NoteIt, the Turner Hall Card and SQZ!. The popularity of these products, while contributing a relatively small portion of revenues to Symantec, conveyed the impression that Symantec was already a diversified company, and indeed, many industry participants were under the impression that Symantec had acquired Turner Hall Publishing. In 1987, Byers recruited Ted Schlein into the Turner Hall Product Group to assist in building the product family and in marketing.
Revenues from Q&A, and Symantec's early launch into the international marketplace, combined with Turner Hall Publishing, generated the market presence and scale that enabled Symantec to make its first merger/acquisition, in February 1987, that of Breakthrough Software, maker of the TimeLine project management software for DOS. Because this was the first time that Symantec had acquired a business that had revenues, inventory, and customers, Eubanks chose to change nothing at BreakThrough Software for six months, and the actual merger logistics started in the summer of 1987, with Turner being appointed by Eubanks as general manager of the TimeLine business unit, Turner was made responsible for the successful integration of the company into Symantec and ongoing growth of the business, with P&L. There was a heavy emphasis placed on making the minimum disruption by Eubanks and Turner.
Soon after the acquisition of TimeLine/Breakthrough Software, Eubanks reorganized Symantec, structuring the company around product-centric groups, each having its development, quality assurance, technical support, and product marketing functions, and a general manager with profit and loss responsibility. Sales, finance, and operations were centralized functions that were shared. This structure lent itself well to Symantec's further growth through mergers and acquisitions. Eubanks made Turner general manager of the new, and simultaneously of the Q&A Product Group, and made Tom Byers general manager of the Turner Hall Product Group. Turner continued to build and lead the company's international business and marketing for the whole company.
At the TimeLine Product Group, Turner drove strong marketing, promotion and sales programs to accelerate momentum. By 1989 this merger was very successful—product group morale was high, TimeLine development continued apace, and the increased sales and marketing efforts applied built the TimeLine into the clear market lead in PC project management software on DOS. Both the Q&A and TimeLine product groups were healthily profitable. The profit stream and merger success set the stage for subsequent merger and acquisition activity by the company, and indeed funded the losses of some of the product groups that were subsequently acquired. In 1989, Eubanks hired John Laing as VP worldwide sales, and Turner transferred the international division to Laing. Eubanks also recruited Bob Dykes to be executive vice president for operations and finance, in anticipation of the upcoming IPO. On June 23, 1989, Symantec had its IPO.[19]
In May 1990, Symantec announced its intent to merge with and acquire Peter Norton Computing, a developer of various utilities for DOS. Turner was appointed as product group manager for the Norton business, and made responsible for the merger, with P&L responsibility. Ted Schlein was made product group manager for the Q&A business.
The Peter Norton group merger logistical effort began immediately while the companies sought approval for the merger, and in August 1990, Symantec concluded the purchase—by this time the combination of the companies was already complete. Symantec's consumer antivirus and data management utilities are still marketed under the Norton name. At the time of the merger, Symantec had built upon its Turner Hall Publishing presence in the utility market, by introducing Symantec Antivirus for the Macintosh (SAM), and Symantec Utilities for the Macintosh (SUM). These two products were already market leaders on the Mac, and this success made the Norton merger more strategic. Symantec had already begun the development of a DOS-based antivirus program one year before the merger with Norton. The management team had decided to enter the antivirus market in part because it was felt that the antivirus market entailed a great deal of ongoing work to stay ahead of new viruses. The team felt that Microsoft would be unlikely to find this effort attractive, which would lengthen the viability of the market for Symantec. Turner decided to use the Norton name for obvious reasons, on what became the Norton Antivirus, which Turner and the Norton team launched in 1991. At the time of the merger, Norton revenues were approximately 20 to 25% of the combined entity. By 1993, while being led by Turner, Norton product group revenues had grown to approximately 82% of Symantec's total.
At one time Symantec was also known for its development tools, particularly the THINK Pascal, THINK C, Symantec C++, Enterprise Developer and Visual Cafe packages that were popular on the Macintosh and IBM PC compatible platforms. These product lines resulted from acquisitions made by the company in the late 1980s and early 1990s. These businesses and the Living Videotext acquisition were consistently unprofitable for Symantec, and these losses diverted expenditures away from both the Q&A for Windows and the TimeLine for Windows development efforts during the critical period from 1988 through 1992. Symantec exited this business in the late-1990s as competitors such as Metrowerks, Microsoft and Borland gained significant market share.
In 1996, Symantec Corporation was alleged of misleading financial statements in violation of GAAP.[20]
From 1999 to April 2009, Symantec was led by CEO John W. Thompson, a former VP at IBM. At the time, Thompson was the only African-American leading a major US technology company. He was succeeded in April 2009 by the company's long-time Symantec executive Enrique Salem.[21] Under Salem, Symantec completed the acquisition of Verisign's Certificate Authority business, dramatically increasing their share of that market.
In 2009, Symantec released a list of the then "100 dirtiest websites", which contain the most malware as detected by Norton Safe Web.[22] [23]
Salem was abruptly fired in 2012 for disappointing earnings performance and replaced by Steve Bennett, a former CEO of Intuit and GE executive.[24] In January 2013, Bennett announced a major corporate reorganization, with the goal of reducing costs and improving Symantec's product line. He said that sales and marketing "had been high costs but did not provide quality outcomes". He concluded that "Our system is just broken".[25]
Robert Enderle of CIO.com reviewed the reorganization and noted that Bennett was following the General Electric model of being product-focused instead of customer-focused. He concluded "Eliminating middle management removes a large number of highly paid employees. This will tactically improve Symantec's bottom line but reduce the skills needed to ensure high-quality products in the long term."[26]
In March 2014, Symantec fired Steve Bennett from his CEO position and named Michael Brown as interim president and chief executive. Including the interim CEO, Symantec has had 3 CEOs in less than two years.[27] [28] On September 25, 2014, Symantec announced the appointment of Michael A. Brown as its president and chief executive officer.[29] Brown had served as the company's interim president and chief executive officer since March 20, 2014.[30] Mr. Brown has served as a member of the company's board of directors since July 2005 following the acquisition of VERITAS Software Corporation. Mr. Brown had served on the VERITAS board of directors since 2003.[31]
In July 2016, Symantec introduced a product to help carmakers protect connected vehicles against zero-day attacks. The Symantec Anomaly Detection for Automotive is an IoT product for manufacturers and uses machine learning to provide in-vehicle security analytics.[32] Greg Clark assumed the position of CEO in August 2016.[33]
In November 2016, Symantec announced its intent to acquire identity theft protection company LifeLock for $2.3 billion.[34]
In August 2017, Symantec announced that it had agreed to sell its business unit that verifies the identity of websites to Thoma Bravo. With this acquisition, Thoma Bravo plans to merge the Symantec business unit with its own web certification company, DigiCert.[35]
On January 4, 2018, Symantec and BT (formerly British Telecom) announced their partnership that provides new endpoint security protection.[36]
In May 2018, Symantec initiated an internal audit to address concerns raised by a former employee,[37] [38] causing it to delay its annual earnings report.[39]
In August 2018, Symantec announced that the hedge fund Starboard Value had put forward five nominees to stand for election to the Symantec board of directors at Symantec's 2018 Annual Meeting of Stockholders.[40] This followed a Schedule 13D filing by Starboard showing that it had accumulated a 5.8% stake in Symantec.[41] In September 2018, Symantec announced that three nominees of Starboard were joining the Symantec board, two with immediate effect (including Starboard Managing Member Peter Feld) and one following the 2018 Annual Meeting of Stockholders.[42]
On May 9, 2019, Symantec announced that Clark would be stepping down and that board member Rick Hill, previously put forward by Starboard, had been appointed interim president and CEO.[40] Vincent Pilette also joined Symantec as its new CFO.[40]
On August 8, 2019, Broadcom announced they would be acquiring the Enterprise software division of Symantec for $10.7 billion.[4] This is after having attempted to purchase the whole company. The Norton family of products will remain in the Symantec portfolio. The sale closed on November 4, 2019, and subsequently, the company adopted the NortonLifeLock name and relocated its headquarters from Mountain View, California to LifeLock's offices in Tempe, Arizona.[43]
In 2021, a crypto-miner was added to the Norton 360 product, called Norton Crypto. Once activated by the user, Norton Crypto mines Ethereum (ETH) using the installed machine's graphics card while idle. The program also creates a secure wallet on the same machine.[44] [45] Norton announced it was permanently disabling the feature on September 14, 2022, due to the Ethereum merge.[46]
See main article: Veritas Technologies. On October 9, 2014, Symantec declared that the company would separate into two independent publicly traded companies by the end of 2015.[47] Symantec will continue to focus on security, while a new company will be established focusing on information management. Symantec confirmed on January 28, 2015, that the information management business would be called Veritas Technologies Corporation, marking a return of the Veritas name.[48] In August 2015, Symantec agreed to sell Veritas to a private equity group led by The Carlyle Group for $8 billion. The sale was completed by February 2016, turning Veritas into a privately owned company.
See main article: Norton (software). Norton product line includes Norton AntiVirus, Norton Small Business, Norton Family, Norton Mobile Security, Norton Online Backup, Norton 360, Norton Utilities and Norton Computer Tune Up. Norton's line also includes LifeLock and ReputationDefender.
In 2012, PCTools iAntiVirus was rebranded as a Norton product under the name iAntivirus, and released to the Mac App Store. Also in 2012, the Norton Partner Portal was relaunched to support sales to consumers throughout the EMEA technologies.
See main article: Avast. Avast product line includes Avast Antivirus, Avast Premium Security, Avast Cleanup, Avast Secure Browser, and Avast SecureLine VPN. it is the most popular antivirus vendor on the market and it had the largest market share.[49]
See main article: AVG Technologies. AVG product line includes AVG AntiVirus, AVG Internet Security, AVG Secure VPN, AVG PC TuneUp, and AVG Driver Updater. Previously a publicly company in February 2012, it was acquired by Avast in July 2016 for $1.3 billion.[50]
See main article: Avira. Avira product line includes Avira Free Security, Avira Internet Security, Avira Prime and Avira Phantom VPN.
Other products offered by Gen Digital include CCleaner, Recuva, Speccy, Defraggler, HMA, and SONAR.
See main article: List of mergers and acquisitions by Gen Digital.
In 1993, Symantec acquired ACT! from Contact Software International. Symantec sold ACT! to SalesLogix in 1999. At the time it was the world's most popular CRM application for Windows and Macintosh.[51]
On December 16, 2004, Veritas Software and Symantec announced their plans for a merger. With Veritas valued at $13.5 billion, it was the largest software industry merger to date.[52] Symantec's shareholders voted to approve the merger on June 24, 2005; the deal closed successfully on July 2, 2005.[53] July 5, 2005, was the first day of business for the U.S. offices of the new, combined software company. As a result of this merger, Symantec includes storage- and availability-related products in its portfolio, namely Veritas File System (VxFS), Veritas Volume Manager (VxVM), Veritas Volume Replicator (VVR), Veritas Cluster Server (VCS), NetBackup (NBU), Backup Exec (BE) and Enterprise Vault (EV).
On January 29, 2016, Symantec sold Veritas Technologies to The Carlyle Group.
On August 16, 2005, Symantec acquired Sygate,[54] a security software firm based in Fremont, California, with about 200 staff.[55] As of November 30, 2005, all Sygate personal firewall products were discontinued.[56]
On January 29, 2007, Symantec announced plans to acquire Altiris,[57] and on April 6, 2007, the acquisition was completed.[58] Altiris specializes in service-oriented management software that allows organizations to manage IT assets.[57] It also provides software for web services, security and systems management products. Established in 1998, Altiris is headquartered in Lindon, Utah.[59]
On November 5, 2007, Symantec announced its acquisition of Vontu, a Data Loss Prevention (DLP) company, for $350 million.[60]
On January 17, 2008, Symantec announced[61] that it was spinning off its Application Performance Management (APM) business and the i3 product line to Vector Capital.[62] Precise Software Solutions took over development, product management, marketing and sales for the APM business, launching as an independent company on September 17, 2008.[63]
On August 18, 2008, Symantec announced the signing of an agreement to acquire PC Tools. Under the agreement, PC Tools would maintain separate operations. The financial terms of the acquisition were not disclosed. In May 2013, Symantec announced they were discontinuing the PC Tools line of internet security software.[64]
In December 2013, Symantec announced they were discontinuing and retiring the entire PC Tools brand and offering a non-expiring license to PC Tools Performance Toolkit, PC Tools Registry Mechanic, PC Tools File Recover and PC Tools Privacy Guardian users with an active subscription as of December 4, 2013.[65]
On April 18, 2008, Symantec completed the acquisition of AppStream, Inc. ("AppStream"), a nonpublic Palo Alto, California-based provider of endpoint virtualization software. AppStream was acquired to complement Symantec's endpoint management and virtualization portfolio and strategy.[66]
On October 9, 2008, Symantec announced its intent to acquire Gloucester-based MessageLabs (spun off from Star Internet in 2007) to boost its Software-as-a-Service (SaaS) business. Symantec purchased the online messaging and Web security provider for about $695 million in cash.[67] The acquisition closed on November 17, 2008.[68]
On April 29, 2010, Symantec announced its intent to acquire PGP Corporation and GuardianEdge.[69] The acquisitions closed on June 4, 2010, and provided access to established encryption, key management and technologies to Symantec's customers.
On May 19, 2010, Symantec signed a definitive agreement to acquire Verisign's authentication business unit, which included the Secure Sockets Layer (SSL) Certificate, Public Key Infrastructure (PKI), Verisign Trust and Verisign Identity Protection (VIP) authentication services.[70] The acquisition closed on August 9, 2010. In August 2012, Symantec completed its rebranding of the Verisign SSL Certificate Service by renaming the Verisign Trust Seal the Norton Secured Seal.[71] Symantec sold the SSL unit to Digicert for US$950 million in mid 2017.[72]
Acquired on October 10, 2010, RuleSpace is a web categorisation product first developed in 1996.[73] The categorisation is, automated using what Symantec refers to as the Automated Categorization System (ACS). It is used as the base for content filtering by many UK ISP.
On May 19, 2011, Symantec announced the acquisition of Clearwell Systems for approximately $390 million.[74]
On January 17, 2012, Symantec announced the acquisition of cloud email-archiving company LiveOffice. The acquisition price was $115 million.[75] Last year, Symantec joined the cloud storage and backup sector with its Enterprise Vault.cloud and Cloud Storage for Enterprise Vault software, in addition to a cloud messaging software, Symantec Instant Messaging Security cloud (IMS.cloud). Symantec stated that the acquisition would add to its information governance products,[76] allowing customers to store information on-premises, in Symantec's data centers, or both.
On March 2, 2012, Symantec completed the acquisition of Odyssey Software. Odyssey Software's main product was Athena, which was device management software that extended Microsoft System Center software, adding the ability to manage, support and control mobile and embedded devices, such as smartphones and ruggedized handhelds.[77]
Symantec completed its acquisition of Nukona, a provider of mobile application management (MAM), on April 2, 2012.[78] The acquisition agreement between Symantec and Nukona was announced on March 20, 2012.[79]
In May 2014 Symantec acquired NitroDesk, provider of TouchDown, the market-leading third-party EAS mobile application.[80]
On June 13, 2016, it was announced that Symantec had acquired Blue Coat for $4.65 billion.[81]
In 2017, Symantec acquired LifeLock Inc.,[82] [83] and renamed itself to NortonLifeLock in 2019.
NortonLifeLock acquired German security firm Avira in December 2020 for $360 million.[84]
In August 2021, NortonLifelock agreed to merge with Czech cybersecurity software company Avast. The UK Competition and Markets Authority formally cleared the $8.1 billion merger on September 2, 2022.[85] The company subsequently adopted the name Gen Digital.
On August 9, 2004, the company announced that it discovered an error in its calculation of deferred revenue, which represented an accumulated adjustment of $20 million.[86] [87]
The arrival of the year 2010 triggered a bug in Symantec Endpoint. Symantec reported that malware and intrusion protection updates with "a date greater than December 31, 2009, 11:59 pm [were] considered to be 'out of date.'" The company created and distributed a workaround for the issue.[88]
In March 2010, it was reported that Symantec AntiVirus and Symantec Client Security were prone to a vulnerability that might allow an attacker to bypass on-demand virus scanning, and permit malicious files to escape detection.[89] [90]
In January 2011, multiple vulnerabilities in Symantec products that could be exploited by a denial-of-service attack, and thereby compromise a system, were reported. The products involved were Symantec AntiVirus Corporate Edition Server and Symantec System Center.[91]
The November 12, 2012, Vulnerability Bulletin of the United States Computer Emergency Readiness Team (US-CERT) reported the following vulnerability for older versions of Symantec's Antivirus system: "The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corporate Edition (SAVCE) 10.x, and Symantec Scan Engine (SSE) before 5.2.8 does not properly perform bounds checks of the contents of CAB archives, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file."[92]
The problem relates to older versions of the systems and a patch is available. US-CERT rated the seriousness of this vulnerability as a 9.7 on a 10-point scale. The "decomposer engine" is a component of the scanning system that opens containers, such as compressed files, so that the scanner can evaluate the files within.
In January 2012, James Gross filed a lawsuit against Symantec for distributing fake scareware scanners that purportedly alerted users of issues with their computers. Gross claimed that after the scan, only some of the errors and problems were corrected, and he was prompted by the scanner to purchase a Symantec app to remove the rest. Gross claimed that he bought the app, but it did not speed up his computer or remove the detected viruses. He hired a digital forensics expert to back up this claim. Symantec denied the allegations and said that it would contest the case.[93] Symantec settled a $11 million fund (up to $9 to more than 1 million eligible customers representing the overpaid amount for the app) and the case was dismissed in court.[94] [95]
On January 17, 2012, Symantec disclosed that its network had been hacked. A hacker known as "Yama Tough" had obtained the source code for some Symantec software by hacking an Indian government server. Yama Tough released parts of the code and threatened to release more. According to Chris Paden, a Symantec spokesman, the source code that was taken was for Enterprise products that were between five and six years old.[96]
On September 25, 2012, an affiliate of the hacker group Anonymous published source code from Norton Utilities. Symantec confirmed that it was part of the code that had been stolen earlier, and that the leak included code for 2006 versions of Norton Utilities, pcAnywhere and Norton Antivirus.[97]
In February 2012, it was reported that Verisign's network and data had been hacked repeatedly in 2010, but that the breaches had not been disclosed publicly until they were noted in an SEC filing in October 2011.[98] Verisign did not provide information about whether the breach included its certificate authority business, which was acquired by Symantec in late 2010.[98] Oliver Lavery, director of security and research for nCircle, asked rhetorically, "Can we trust any site using Verisign SSL certificates? Without more clarity, the logical answer is no."[99] [100]
On February 17, 2012, details of an exploit of pcAnywhere were posted. The exploit would allow attackers to crash pcAnywhere on computers running Windows.[101] Symantec released a hotfix for the issue twelve days later.[102]
According to Mandiant, Symantec security products used by The New York Times detected only one of 45 pieces of malware that were installed by Chinese hackers on the newspaper's network during three months in late 2012.[103] [104] Symantec responded:
"Advanced attacks like the ones the New York Times described in the following article, <http://nyti.ms/TZtr5z>, underscore how important it is for companies, countries and consumers to make sure they are using the full capability of security solutions. The advanced capabilities in our [E]ndpoint offerings, including our unique reputation-based technology and behavior-based blocking, specifically target sophisticated attacks. Turning on only the signature-based anti-virus components of [E]ndpoint solutions alone [is] not enough in a world that is changing daily from attacks and threats. We encourage customers to be very aggressive in deploying solutions that offer a combined approach to security. Anti-virus software alone is not enough".[105]
In February 2015, Symantec was found guilty of two counts of patent infringement in a suit by Intellectual Ventures Inc and ordered to pay $17 million in compensation and damages,[106] In September 2016, this decision was reversed on appeal by the Federal Circuit.[107] [108]
On September 18, 2015, Google notified Symantec that the latter issued 23 test certificates for five organizations, including Google and Opera, without the domain owners' knowledge.[109] Symantec performed another audit and announced that an additional 164 test certificates were mis-issued for 76 domains and 2,458 test certificates were mis-issued for domains that had never been registered. Google requested that Symantec update the public incident report with proven analysis explaining the details on each of the failures.[110]
The company was asked to report all the certificates issued to the Certificate Transparency log henceforth.[111] Symantec has since reported implementing Certificate Transparency for all its SSL Certificates. Above all, Google has insisted that Symantec execute a security audit by a third party and to maintain tamper-proof security audit logs.[112]
On March 24, 2017, Google stated that it had lost confidence in Symantec, after the latest incident of improper certificate issuance.[113] [114] Google says millions of existing Symantec certificates will become untrusted in Google Chrome over the next 12 months. According to Google, Symantec partners issued at least 30,000 certificates of questionable validity over several years, but Symantec disputes that number.[115] Google said Symantec failed to comply with industry standards and could not provide audits showing the necessary documentation.[116] [117]
Google's Ryan Sleevi said that Symantec partnered with other CAs (CrossCert (Korea Electronic Certificate Authority), Certisign Certificatadora Digital, Certsuperior S. de R. L. de C.V., and Certisur S.A.) who did not follow proper verification procedures leading to the misissuance of certificates.[118]
Following discussions in which Google had required that Symantec migrate Symantec-branded certificate issuance operations a non-Symantec-operated "Managed Partner Infrastructure",[119] a deal was announced whereby DigiCert acquired Symantec's website security business.[120] In September 2017, Google announced that starting with Chrome 66, "Chrome will remove trust in Symantec-issued certificates issued prior to June 1, 2016".[121] Google further stated that "by December 1, 2017, Symantec will transition issuance and operation of publicly-trusted certificates to DigiCert infrastructure, and certificates issued from the old Symantec infrastructure after this date will not be trusted in Chrome." Google predicted that toward the end of October 2018, with the release of Chrome 70, the browser would omit all trust in Symantec's old infrastructure and all of the certificates it had issued, affecting most certificates chaining to Symantec roots. Mozilla Firefox planned to distrust Symantec-issued certificates in Firefox 63 (released on October 23, 2018),[122] but delivered the change in Firefox 64 (released on December 11, 2018).[123] Apple has also planned to distrust Symantec root certificates.[124] [125] Subsequently, Symantec exited the TLS/SSL segment by selling the SSL unit to Digicert for $950 million in mid 2017.[72]
On July 20, 2021, Norton LifeLock released Norton Crypto, which would've mined Ethereum in the background in exchange for periodic payments.[126] This drew criticism from users, as this was installed automatically, and many users reported having diffuculty uninstalling the program.[127] [128]
In May 2022, Columbia University won $185 million judgement against NortonLifeLock Inc. in a patent-infringement lawsuit.[129] The jury found that Norton willfully infringed the patents related to antivirus fighting malware.[130] [131]