How sexy is hacking?
Posted on 21 Jun 2010 at 17:48
Hacking is very sexy, says Davey Winder, and we should be grateful for the hacking contests that make it sexier and help keep hackers away from the dark side
Bad news if you fancied earning a few thousand dollars: the annual Pwn2Own hacking contest has come and gone for 2010.
Held alongside the CanSecWest security conference in Vancouver at the end of March, Pwn2Own has become famous – or infamous – for offering financial rewards to those that can perform particular hacks on the most popular hardware and software, devices, clients and operating systems.
A ripple of sensational coverage might just spark a bigger ripple of concern among security companies
You can guarantee that tech journalists (me included) as well as the broader media will garner a few sensational headlines from the couple of days’ worth of hacking activity on display. I’m not apologising, because a ripple of sensational coverage might just spark a bigger ripple of concern among those security companies whose products have been so speedily and completely trashed in the contest.
Far too often there’s no real explanatory content in such stories, which may simply reflect the fact that these kinds of exploits lie way beyond the technical understanding of most reporters. What you tend to get is either a rehashed press release or, worse still, a rehashed copy of someone else’s rehashed press release, with the addition of a bizarre headline to attract more eyeballs. I always try to go a little deeper (within whatever constraining brief I’ve been given by my publisher).
For example, when the iPhone was compromised this year in 20 seconds flat, the newsfeeds filled up with “iPhone hacked in 20 seconds” stories, most of which said nothing more than that a couple of hackers had exploited a previously unpublished vulnerability to compromise the iPhone. Few mentioned the intense hacking efforts, occupying anything from weeks to months, that had gone on before Pwn2Own in order to discover that vulnerability and exploit it so quickly on the day, which is why I preferred the headline: “The truth behind that 20-second iPhone hack”.
In this particular case I asked whether this “truth” really meant that the iPhone was insecure, seeing as many of the quick story creators were pretty much telling you not to use an iPhone because your data wasn’t safe. My conclusion was that, until Apple addresses this vulnerability, the iPhone is theoretically insecure, but only under some fairly specific circumstances and only related to certain very specific datasets.
Furthermore, this 20-second hack was actually into the Safari browser running on an iPhone rather than into the underlying iPhone OS itself.
This is hardly news: when the MacBook fell victim to hacker Charlie Miller, he also used Safari to make that happen, and when Windows 7 64-bit fell it was Internet Explorer 8 that did the pushing. Web browsers rather than OSes are the easy targets, and the weakest link as far as hackers are concerned.
A security conundrum
All of this made me ponder a broader question: namely, whether Pwn2Own and similar hacking contests and conferences are of any real value to the security community, or whether they simply serve to make hackers and hacking sexier.
Let’s look at some of the prizes on offer at Pwn2Own 2010: the total prize pool stands at $100,000 for 2010, with $40,000 of that allocated to the web browser side of things and $10,000 up for grabs to the first hacker to break Internet Explorer, Firefox, Safari and Google Chrome (although I doubt anyone will claim the latter, as Chrome’s sandbox approach makes it a particularly difficult target for this kind of exploit).
Download a year of Davey Winder's Online Security columns by heading to our Free Downloads site
From around the web
Davey Winder
Davey is a contributing editor to PC Pro, having covered the internet as a topic since the magazine started in 1994. Since that time he's won numerous awards for his journalism, but remains a small-business consultant specialising in privacy, security and usability issues.
advertisement
- Why virtualisation hasn't slowed the growth of data
- How to make Google AdWords work for your business
- The curse of sloppily written software
- Paying for your crimes with Bitcoin
- Behind the scenes: tech support for Formula 1
- The security risk of fat fingers
- Why Windows Phone 7 isn't quite ready for business
- When will Microsoft stop fiddling with Windows 8?
- Flash down the pan?
- Metro Style apps vs desktop applications
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- VeriSign slammed for security breach cover-up
- SAP willing to share HANA with Oracle
- Why using a tablet could harm your health
- New RIM boss: no need for drastic change
- RIM founders fall on their swords
- Slow economy helps boost Red Hat revenue by 23%
- Google+ pages get multiple admins
- One in five companies lack card industry compliance
- Oil industry warns hacking attacks could kill
- British workers fear email monitoring
advertisement

