Microsoft Invites Black Hats into Vista
gtzpower writes "Microsoft is inviting hackers to 'Take Your Best Shot' at Vista. 'You need to touch it, feel it,' Andrew Cushman, Microsoft's director of security outreach, said during a talk at the Black Hat computer-security conference. 'We're here to show our work.'" From the article: "A security team with oversight of every Microsoft product — from its Xbox video game console to its Word program for creating documents — has broad authority to block shipments until they pass security tests. The company also hosts two internal conferences a year so some of the world's top security experts can share the latest research on computer attacks." Essentially a tie-in with an article we discussed yesterday.
...I was going to point out the dupe, but now the editors have started doing it for us!
"Essentially a tie-in with an article we discussed yesterday."
Argh.
The real black hats want it to be widely deployed before they start exploiting it.
proof, n. A demonstration that a conclusion is implied by certain premises and axioms.
Say, wait. If you've just given prerelease test copies of Vista to 3,000 "black hats"... and you're hoping they'll find bugs in them and report them back to you before Vista ships... I mean... how do you know that's what they're actually going to do?
What if some of these "black hats" look over Vista, find security bugs, keep them secret, go back to Microsoft and say "Whelp! Looks like Vista doesn't have any security holes at all!"; then wait for Vista to be released, and once it's out have a 0-day exploit that they can use in their offshore spam/spyware businesses and that no one else will even know exists until two years from now when a gray hat independently finds and publishes it and Microsoft finally fixes it?
I mean, of course that's a worst case scenario. But still, sometimes I think the old thinking on how the world of hackers works no longer really applies now that the primary motivating force is not pride, but money (in the form of sweet, sweet herbal viagra).
Microsoft does not want black-hats to be cracking Vista, unless they're visiting a honeypot; for black-hats will keep what they know to themselves, and maybe create false trails. Rather, MS is indicating the grey- and white-hats that they're legally in the clear.
"Black Hat" is simply the name of the conference organiser, a cool name to be sure, but not an indication of who MS is reaching out to.
Wikileaks, no DNS
Shouldn't we change the Microsoft symbol next to all related articles? I mean, seriously... Gates no longer works for Microsoft and manages his own charity foundation. What else does this guy have to do to wash the blood from his hands?
(Ironically, my confirmation script image for this post is "unfair")
The title has created some incredibly +5 funny comments, which is great for cheap entertainment, but the title is completely fucking wrong and now the flamethrowers must be unleashed.
From TFA:
After suffering embarrassing security exploits over the past several years, Microsoft Corp. is trying a new tactic: inviting some of the world's best-known computer experts to try to poke holes in Vista, the next generation of its Windows operating system.
Black hats are the bad guys, the guys actually hacking the computers for the sake of getting money and identities. The security experts are the good guys!
Maybe I'm overreacting, but that little change in the title rather important. It turns the story from "Microsoft showing all the efforts it is making to improve security" to "Microsoft so desperate to improve security they invite convicted hackers/spammers/international mafia to come hack vista!"
Of course, without said change, we have no +5 funny comments, and thus no real story to make fun of, because there's not much material to make fun of here, and nothing to critize about Microsoft because what they are doing in the article is what they should be doing. Nice Job Slashdot.
"All great wisdom is contained in .signature files"
Something like this would bring the wannabees and dingbats out of the woodwork. A real paranoid black hatter wouldn't want to have his identity known or put himself under Microsoft's sights for a non-serious amount of money. You'd better believe that people that take this challenge will be closely watched from now on.
Where does the school board find them and why do they keep sending them to ME?
You're of the mistaken belief that all the people that go to BH and DefCon are genius, code-cracking hackers. They're not. Instead, you get a whole bunch of wannabees and lots of security officers that are scared shitless of their next attack.
So MS gets to tease these guys, make them think that they're tough stuff, and it's all hilarious. Sorry you didn't catch that.
Half these guys will discover that Vista has not one WGA-like heartbeat responder, but several. Trace the protocols. I did.
---- Teach Peace. It's Cheaper Than War.
So, having spent years training normal users that the correct way to get anything done is to click "Yes" on every single dialog box that comes up, regardless of what the dialog actually says, they're now doing the same to sysadmins?
Yes, but Ballmer is still a better ringer for Locutus.
Maybe when Ballmer takes the reins, we can change it to a chair flying through a window.
Done with slashdot, done with nerds, getting a life.