
Norman Shark has received an open letter from Bits of Freedom (www.bof.nl), requesting answers to four questions on our policy on the detection of software for state surveillance.
We are happy to answer these questions.
1. Have you ever detected the use of software by any government (or state actor) for the purpose of surveillance?
Yes. Examples include well-known and well-documented cases such as R2D2 trojan and Finfisher.
2. Have you ever been approached with a request by a government, requesting that the presence of specific software is not detected, or if detected, not notified to the user of your software? And if so, could you provide information on the legal basis of this request, the specific kind of software you were supposed to allow and the period of time which you were supposed to allow this use?
No, we have never received this type of request.
3. Have you ever granted such a request? If so, could you provide the same information as in the point mentioned above and the considerations which led to the decision to comply with the request from the government?
No, see above.
4. Could you clarify how you would respond to such a request in the future?
We would not comply with such a request. Malware is malware, as long as it is malicious we will attempt to detect it.
Signed Christophe Birkeland, Chief Technology Officer, Norman Shark AS

