Five Hackers Who Left a Mark on 2006
espera un momento writes "eweek.com picks the five hackers who made a significant impact on security and vulnerability research in 2006. These are some interesting choices of the guys (and gal) who dominated the media headlines. The topics covered included Wi-Fi bugs, browser flaws and rootkits."
Hackers - meaning people involved with information security.
No, the real folks that really 'left their mark' in 2006 are yet unidentified.
It could be worse, it could be Monday.
From the article: "However, security researchers who understood the technical nature--and severity--of their findings, Ellch and Maynor were widely celebrated for their work, which was the trigger for the MoKB (Month of Kernel Bugs) project that launched with exploits for Wi-Fi driver vulnerabilities. Since the Black Hat talk, a slew of vendors--including Broadcom, D-Link, Toshiba and Apple--have shipped fixes for the same class of bugs identified by Ellch and Maynor, confirming the validity of their findings. " Look for 'Apple' and 'shipped fixes' in the text.
Patents Drive Free Software as Hurricanes Drive Construction Industry
I think Dan Kaminsky deserves at least an honorable mention in this list. Russinovich broke the story -- Kaminsky drove it home. He's the guy who did some amazing research regarding Sony's rootkit and its spread. (Using dns cache to ferret out statistical data was ingenious.) Now, the rootkit debacle did indeed occur in 2005; however, he published his studies on the brink of the new year. This enabled (very successful) class action lawsuits to go forward against Sony in 2006 and undeniably helped educate the general public about drm nastiness.
At the very least, Kaminsky is on my list.
At the Black Hat Briefings in Las Vegas, Jon "Johnny Cache" Ellch teamed up with former SecureWorks researcher David Maynor to warn of exploitable flaws in wireless device drivers. The presentation triggered an outburst from the Mac faithful and an ugly disclosure spat that still hasn't been fully resolved.
Um, yeah, because nearly all of the news coverage of the vulnerability didn't describe it as the general 802.11 vulnerability that it was, affecting multiple chipsets and drivers and multiple operating systems, including Windows, Mac OS X, and Linux; it described it, and indeed trumpeted it, as vulnerability that affected Apple MacBooks and Mac OS X, with most articles making at best a passing reference that it could affect other platforms, if they even said that. Stories ran under headlines like "MacBook hijacked in 30 seconds -- wirelessly", and made it appear to be exclusively an Apple problem.
While this was made clear in their demo, they chose to demo on a MacBook with a third party wireless card whose identity was hidden - because of "responsible disclosure" - but then in the next breath tell Brian Krebs at the Washington Post that the MacBook's own integrated wireless is exploitable in the exact same way. How is that "responsible disclosure"? And to top it off, we have a SecureWorks "Senior Researcher" saying that he wants to fix Mac users' "smug" attitude about security (and this helps Mac OS X security in a meaningful way how?) and that many of these people apparently need lit cigarettes jammed into their eyes (to paraphrase). Even if said in jest or in fun, how is that professional? How does that do anything to better Mac OS X security?
How would a change in "user attitude" change the actual security situation on Mac OS X? I don't see a change in user attitude changing anything. Many Windows users know, at least marginally, that they are the target of innumerable attacks and thousands of pieces of malware. How does that change in any meaningful way the security situation on Windows?
More to the point: how does the press making a general and serious 802.11 vulnerability affecting numerous chipsets, drivers, and operating systems appear as only a MacBook problem serve a meaningful, or even truthful or accurate, security purpose?
For Ellch and Maynor, the controversy offered a double-edged sword. In many ways, they were hung out to dry by Apple and SecureWorks, two companies that could not manage the disclosure process in a professional manner. In some corners of the blogosphere, they were unfairly maligned for mentioning that the Mac was vulnerable.
No. They were maligned for saying they espoused "responsible disclosure", even carefully hiding the third party wireless card, but then saying that the MacBook's integrated wireless was vulnerable in the same way. NO OTHER AFFECTED VENDOR OR OS was treated that way. Only Apple.
They were maligned for being party to a Washington Post article that made outrageous accusations, like alleging that Apple "leaned on" them to not show this exploit, when there is no proof of that whatsoever.
They were maligned because after working with Apple engineers for almost a week at Black Hat, they could not provide any information directly to Apple on how, precisely, Apple's integrated drivers were vulnerable. Should they "do Apple's work for them"? No. But these weren't hobbyists. These were people presenting under the guise of an enterprise security company with responsible disclosure, and when you unleash a firestorm of bad PR on one and only one company's new flagship consumer portable, you'd better be prepared to have a little higher degree of interaction with that one vendor.
However, security researchers who understood the technical nature--and severity--of their findings, Ellch and Maynor were widely celebrated for their work, which was the trigger for the MoKB (Month of Kernel Bugs) project that launched with exploits for Wi-Fi driver vulnerabilities.
Yes. It was great that the