Slashdot Mirror


Microsoft Invites Black Hats into Vista

gtzpower writes "Microsoft is inviting hackers to 'Take Your Best Shot' at Vista. 'You need to touch it, feel it,' Andrew Cushman, Microsoft's director of security outreach, said during a talk at the Black Hat computer-security conference. 'We're here to show our work.'" From the article: "A security team with oversight of every Microsoft product — from its Xbox video game console to its Word program for creating documents — has broad authority to block shipments until they pass security tests. The company also hosts two internal conferences a year so some of the world's top security experts can share the latest research on computer attacks." Essentially a tie-in with an article we discussed yesterday.

24 of 189 comments (clear)

  1. why invite the black hats in? by ed.han · · Score: 5, Funny

    aren't they already freaking there?!

    ed

    1. Re:why invite the black hats in? by Chosen+Reject · · Score: 5, Informative

      You are absolutely correct. Just because he's not going to leave until July 2008, and just because he is giving up his day-to-day activities while remaining chairman of the board and "advisor for key development projects" doesn't mean he should still be considered at all a leader of any kind over at MS right now in August of 2006.

      --
      Stop Global Warming!
      Just say no to irreversible processes!
    2. Re:why invite the black hats in? by soulshinejam · · Score: 5, Funny

      I just got pwned.

    3. Re:why invite the black hats in? by Si · · Score: 5, Funny

      What else does this guy have to do to wash the blood from his hands?

      Give the money back.

      --


      Why is it that many people who claim to support standards have such atrocious spelling and grammar?
    4. Re:why invite the black hats in? by MrAnnoyanceToYou · · Score: 4, Funny

      "That man's been served so hard, he may never walk again."

  2. Not that I wish to flame, but... by HugePedlar · · Score: 4, Insightful

    ...I was going to point out the dupe, but now the editors have started doing it for us!

    "Essentially a tie-in with an article we discussed yesterday."

    --
    Argh.
    1. Re:Not that I wish to flame, but... by russ1337 · · Score: 5, Informative

      Any of you who listen to Security Now will have heard M$ have re-written the networking stack (as discovered by Symantec et.al).

      Needless to say, even after this testing and patching, there is a high probablity the networking interface will still have a few 'zero day' flaws...

  3. Trap? by mrxak · · Score: 4, Funny

    It could be a trap, you know. Bring in the black hats, and then brainwash them en masse so they don't want to use computers anymore but still buy many copies of MS products. No more security problems!

    1. Re:Trap? by just_another_sean · · Score: 4, Interesting

      You may be right. In a pschological sense they succeeded with at least one person, at least if you take his statement at face value. From yesterday's article:

      Mr. Moore, 24 years old, who lives in Austin, Texas. But he says the meetings put a human face on a company he once saw as impenetrable. "You're less willing to publicly humiliate someone you know in real life," he says.'"

      --
      Creationist Textbook Stickers Declared Unconstitutional by CowboyNeal
    2. Re:Trap? by thelost · · Score: 5, Funny

      It is a trap. They have a suicide booth in there, with Vista logo's printed all over it. The last thing you ever hear before dying a horrible bloody death is the Windows Vista Chime.

      --
      Promote Charity on Myspace, Show Your Colours!
    3. Re:Trap? by soft_guy · · Score: 5, Funny

      Isn't that what all versions of Windows have always been?

      --
      Avoid Missing Ball for High Score
    4. Re:Trap? by kinnell · · Score: 5, Funny
      The last thing you ever hear before dying a horrible bloody death is the Windows Vista Chime.

      ...and the last thing you see is a clippy saying "You look like you are about to die a horrible and bloody death. Would you like some help with that?"

      --
      If I seem short sighted, it is because I stand on the shoulders of midgets
  4. How it plays out by MrSquirrel · · Score: 5, Funny

    ------------Now-----------
    MS: "Have it Vista, hackers -- see if you can find any exploits"
    BHs: *they go to it* "Nope, we don't have any security holes to report to you, it looks like Vista is impenetrable."

    ------------Vista is released-----------
    MS: "What the heck? How can there be over twelve-thousand viruses for Vista on the day it's released?!"
    BHs: "All your Vistas are belong to us! Thanks for your help Microsoft!"

    --
    A computer once beat me at chess, but it was no match for me at kick boxing.
  5. No real black hats interested by The+Famous+Brett+Wat · · Score: 5, Insightful

    The real black hats want it to be widely deployed before they start exploiting it.

    --
    proof, n. A demonstration that a conclusion is implied by certain premises and axioms.
  6. Quote by Anonymous Coward · · Score: 5, Insightful
    "There are some who feel like that the conditions are such that they can attack us there. My answer is bring them on," Ballmer said. "We've got the force necessary to deal with the security situation."

    Say, wait. If you've just given prerelease test copies of Vista to 3,000 "black hats"... and you're hoping they'll find bugs in them and report them back to you before Vista ships... I mean... how do you know that's what they're actually going to do?

    What if some of these "black hats" look over Vista, find security bugs, keep them secret, go back to Microsoft and say "Whelp! Looks like Vista doesn't have any security holes at all!"; then wait for Vista to be released, and once it's out have a 0-day exploit that they can use in their offshore spam/spyware businesses and that no one else will even know exists until two years from now when a gray hat independently finds and publishes it and Microsoft finally fixes it?

    I mean, of course that's a worst case scenario. But still, sometimes I think the old thinking on how the world of hackers works no longer really applies now that the primary motivating force is not pride, but money (in the form of sweet, sweet herbal viagra).
    1. Re:Quote by mottie · · Score: 4, Insightful

      You speak a lot of sense.. I would think that doing this with "White Hats" would make more sense. Realistically all the Black Hats would already have a cracked beta copy that they've downloaded anyways. I'm sure they all would want to have their name attached to the first 0 day exploit. This is all just more press for Microsoft's attempts at security.

  7. 'You need to touch it, feel it,' by spun · · Score: 5, Funny

    "Now Vista, can you show us on this doll where the hacker touched you?

    "Let the record show that the victim pointed to the KERNEL!"

    --
    - None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
  8. Re:Microsoft invites what now? by mrxak · · Score: 4, Interesting

    Probably a good idea to do $1,000 pet exploit found first, plus a free copy of Vista when it's done for everyone reporting at least 20 (let's be honest, it probably won't be that hard to find 20), and some other rewards for most found. Microsoft could afford to pay these guys and get some actual results out of it. The alternative really is to let all the black hats find out the exploits months in advance, report nothing, and then on release day things go absolutely nuts.

  9. It's a play on words by Morosoph · · Score: 4, Insightful

    Microsoft does not want black-hats to be cracking Vista, unless they're visiting a honeypot; for black-hats will keep what they know to themselves, and maybe create false trails. Rather, MS is indicating the grey- and white-hats that they're legally in the clear.

    "Black Hat" is simply the name of the conference organiser, a cool name to be sure, but not an indication of who MS is reaching out to.

  10. Re:Won't help them by Anonymous Coward · · Score: 4, Informative

    Sorry, that's not the case. Permissions in Vista really ARE based on tasks, roles, and objects.

    Even when you are running as Administrator, it still requires that you consent when you're running tasks/programs/etc that need superuser status. When you run the console while you're logged into administrator, it does not automatically have superuser status--you need to choose to run the console as administrator.

    All accesses (to services, registry sections, config/admin programs, and anything that tries to change those) are based on ACLs (access control lists). How do I know this? I'm one of the contracted testers that is working with the vista firewall and its ACLs.

    Is it perfect? I don't know. But I do know it feels pretty secure--not entirely different from the way things worked when I played around with setting up Linux server boxes in college (which was only a year ago).

  11. Security team? by Drathos · · Score: 4, Funny
    "A security team with oversight of every Microsoft product from its Xbox video game console to its Word program for creating documents has broad authority to block shipments until they pass security tests."

    So.. Have they been on a 10 year vacation or something?
    --
    End of line..
    1. Re:Security team? by boyfaceddog · · Score: 4, Funny

      They? Vacation? I'm pretty sure the "team" consists of a dog tied to the "testing PC" and trained to bite anyone who approches.

      --
      Here will be an old abusing of God's patience and the king's English.
  12. Incredibly stupid title by hellfire · · Score: 4, Insightful

    The title has created some incredibly +5 funny comments, which is great for cheap entertainment, but the title is completely fucking wrong and now the flamethrowers must be unleashed.

    From TFA:
    After suffering embarrassing security exploits over the past several years, Microsoft Corp. is trying a new tactic: inviting some of the world's best-known computer experts to try to poke holes in Vista, the next generation of its Windows operating system.

    Black hats are the bad guys, the guys actually hacking the computers for the sake of getting money and identities. The security experts are the good guys!

    Maybe I'm overreacting, but that little change in the title rather important. It turns the story from "Microsoft showing all the efforts it is making to improve security" to "Microsoft so desperate to improve security they invite convicted hackers/spammers/international mafia to come hack vista!"

    Of course, without said change, we have no +5 funny comments, and thus no real story to make fun of, because there's not much material to make fun of here, and nothing to critize about Microsoft because what they are doing in the article is what they should be doing. Nice Job Slashdot.

    --

    "All great wisdom is contained in .signature files"

  13. Re:Microsoft invites what now? by dr_dank · · Score: 5, Insightful

    Something like this would bring the wannabees and dingbats out of the woodwork. A real paranoid black hatter wouldn't want to have his identity known or put himself under Microsoft's sights for a non-serious amount of money. You'd better believe that people that take this challenge will be closely watched from now on.

    --
    Where does the school board find them and why do they keep sending them to ME?