MacBook Air First To Be Compromised In Hacking Contest
Multiple readers have written to let us know that the MacBook Air was the first laptop to fall in the CanSecWest hacking contest. The successful hijacking took place only two minutes into the second day of the competition, after the rules had been relaxed to allow the visiting of websites and opening of emails. The TippingPoint blog reveals that the vulnerability was located within Safari, but they won't release specific details until Apple has had a chance to correct the problem. The winner, Charlie Miller, gets to keep the laptop and $10,000. We covered the contest last year, and the results were similar.
Something else the same that should be pointed out: Microsoft sponsored the contest both times. It is important to know where the money is coming from (and who is writing the rules).
Ownership (no pun) was the key to understanding this. I real contest would have let the winner (the first to hack in) keep one of the computers they did not break. The contest doesn't measure much when the competitors target the one they want to win: the sexiest machine so they attack it.
Instead if they had a choice they would attack the weakest machine and you'd see people voting with their feet as to which machine was the weakest. An actually measurement.
instead you got a beauty contest. Which apple apparently won.
Some drink at the fountain of knowledge. Others just gargle.
They implemented the Biba Integrity model, which isn't exactly slapped together. The idea is that the data that comes from the web is untrusted, and therefore is of low integrity. Data from the system itself is trusted, and thus of high integrity.
A low integrity process cannot write to a high integrity process, so bad information (like malware) cannot get to the system. Likewise, it cannot write to any medium integrity objects (windows, files, processes, etc.), such as those owned by the user running the browser. This means that a buffer overflow exploit in a plug-in will not allow the code to write to the filesystem outside its sandbox, nor will it be able to do things like hijack your homepage.
Of course no security system will prevent you from entering your CC# into a fraudulent online store, so it still has to have a phishing filter.
dom
If a Vista machine had been first there would be a 'haha' tag on this article, as well as on yesterday's article talking about how MS issues patches faster.
Just sayin...
Parents are still in safe browsing grade school. Let me help you get right to the PhD level of safe browsing - http://www.tssci-security.com/archives/2008/03/25/security-and-safe-browsing-for-firefox/
Horns are really just a broken halo.
In other words this guy most likely found a security bug in Safari, but instead of reporting it directly, made an exploit and waited for a hacking contest to get a monetary benefit out of it. A real hero. Or maybe he was just quick. Which seems more plausible?
I demand the Cone of Silence!
No, he said it had a reputation, not what that reputation was nor wether he agreed with it.
Congratulations sir. Apple hating Slashdotters' capacity for misquoting for libelous use and getting modded "insightful" for it never ceases to amaze me.
My teenage son can demolish any PC in an afternoon of unsupervised surfing. My neighbor's Vista box barely runs; God knows what they've got on it. (Unlike the Ubuntu box I let them borrow for two years before they bought their new Dell 3 months ago.) The Mac mini my son uses to surf (when he's allowed) runs as well as it did two years ago and I haven't even run software updates on it. (No sense mentioning it has no antivirus software either.)
I don't care if it's spyware, adware, a virus, a tray icon, or or even just a simple browser toolbar or homepage or search-engine hijacking; or if it's installed manually or via drive-by methods--whether its due to small market share, inherent (UNIX) security, or something else, I will continue to argue that Mac and Linux are the better platforms, IN PRACTICE, for the average user.
Dear Slashdot: next time you want to mess with the site, add a rich-text editor for comments.