Slashdot Mirror


The Black Hat Wi-Fi Exploit

Joe Barr writes to tell us that while many have heard that an Apple was exploited in order to install a rootkit at the recent BlackHat security conference, most people don't know the details of how it works. This is no mistake, it seems that the researchers who demonstrated the flaw were intentionally vague. Some theorize that this is in response to the real or perceived threat of legal action similar to the situation with previous Blackhat presenter, Michael Lynn.

3 of 129 comments (clear)

  1. This seems a bit misleading... by DarkShadeChaos · · Score: 5, Insightful

    The current exploit was intentionally vague so that attackers would not have the upper-hand. The previous researcher mentioned was arrested for something prior to his presentation; I do not correlate the actions together.

    --
    The machine unmakes the man. Now that the machine is so perfect, the engineer is nobody. -Ralph Waldo Emerson
    1. Re:This seems a bit misleading... by Anonymous Coward · · Score: 5, Insightful

      The current exploit was intentionally vague so that attackers would not have the upper-hand.

      Making the details vague, especially by not telling which card to avoid using, makes the users unable to do anything to prevent being victims. That very much GIVES the attackers the upper hand.

      Without knowledge, the users are defenseless. Heck, I have a laptop here with a built in wifi-card. So does everyone else in the office. If I knew the card was a risk, putting in a different card would make me safe. But as it is, the built in one could be safe and the one I would put in instead could be the risk. Heck, I don't even know if disabling the card through software solves anything. If the exploit really works on any OS, it doesn't sound like a software problem, but a hardware/firmware problem.

      The only thing being protected by not informing the users is the image of the manufacturer.

  2. Flogging a dead Story by bananaendian · · Score: 5, Insightful

    ScuttleMonkey writes to tell us that apparently the 'plot-thickens' as some guy somewhere emailed that some people are 'theorizing' alternate motives for the Blackhats keeping wraps on their so-called 'exploit' (that they tried unsuccessfully to smear a OSX security with).

    There is no new substance. This bone has been gnawed clean already. Sounds more like some people are making excuses for something...

    --
    www.tribalnetworks.org - helping tribal people around the world to own their own means of high-tech communications