WSJ : Russia’s Kaspersky to Allow Outside Review of Its Cybersecurity Software

Russia’s Kaspersky to Allow Outside Review of Its Cybersecurity Software
Company hopes sharing source code will build trust after allegations its software helped Russia spy on Americans

Kaspersky Lab, the Moscow-based cybersecurity firm whose software U.S. officials suspect helped the Russian government spy on Americans, promised to make its source code available for an independent review.

The company said Monday the review is part of a “global transparency initiative” that it hopes will improve the trustworthiness of its products. It said it would hand over the source code for its software in the first quarter of next year but didn’t specify who would undertake the review or how widely the code would be disseminated.

The initiative follows a number of reports that the Russian government used Kaspersky software as an espionage tool. The Wall Street Journal reported earlier this month that Kaspersky’s antivirus software was used by Russian operatives to help them secretly scan computers around the world for U.S. government documents and top-secret information.


In addition, hackers working for the Russian government used Kaspersky software to steal details of how the U.S. penetrates foreign computer networks and defends against cyberattacks, the Journal separately reported.

Amid those revelations, a number of Kaspersky clients have said they would stop using the firm’s products. That includes the U.S. Department of Homeland Security.

Kaspersky has previously denied any complicity with Russian officials—or any government—in efforts to spy on other countries. The company’s chief executive, Eugene Kaspersky, has said his firm is being made a pawn in a wider geopolitical war of words between the West and Moscow.

In addition to opening up its software for third-party review, Kaspersky said it plans to implement additional controls to govern how it processes data. It will also open up three “Transparency Centers” around in the world, with locations in Asia, Europe and the U.S. by 2020.

The company said the additional controls would be implemented in cooperation with an independent third party but gave no other details. It said the transparency centers would be places for customers to access reviews of the company’s code and software updates.

“We need to reestablish trust in relationships between companies, governments and citizens,” Mr. Kaspersky said in a statement.