Pwn2Own 2011

Discussion in 'other security issues & news' started by MrBrian, Mar 9, 2011.

Thread Status:
Not open for further replies.
  1. Johnny123

    Johnny123 Registered Member

    Joined:
    May 4, 2006
    Posts:
    548
    Location:
    Bremen, Germany
    I'm not so sure about that. Last year nobody tried to crack Chrome and there were plenty of pundits saying Chrome is such a Fort Knox that nobody even bothered to give it a whirl. So they get praised as having the most secure browser without even being put to the test by anyone. If they got caught it would be embarassing but not the end of the world. Businesses and politicians have gotten nailed for much worse things and survived. :)
     
  2. Someheresomethere

    Someheresomethere Registered Member

    Joined:
    Feb 17, 2011
    Posts:
    71
    About Chrome, from what I read there were two times that were gonna try to hack it, one didn't show up at all, but the other one skipped Chrome and focused on BlackBerry's OS. So it does sound like last minute give-up to me.

    And these conspiracy theories are really ridiculous anyway.
     
  3. dw426

    dw426 Registered Member

    Joined:
    Jan 3, 2007
    Posts:
    5,543
    Most businesses don't have a constant spotlight on anything and everything they do like Google (and MS in the past) does either. Regarding the "Fort Knox" comment, I'm in agreement with you and that was why I mentioned in an earlier post that it could lead to a false sense of security.

    Edit: I won't pass judgement on the guy that skipped it to work on Blackberry. Mobiles are squarely in the crosshairs now of malware writers, so they need a good whacking at, to see how they stand.
     
  4. Johnny123

    Johnny123 Registered Member

    Joined:
    May 4, 2006
    Posts:
    548
    Location:
    Bremen, Germany
    It wasn't meant to be all that serious. I apologize for not putting in the sarcasm tags. ;)
     
  5. Dogbiscuit

    Dogbiscuit Guest

    Browser exploits and Pwn2Own results are subject to the laws of supply and demand as much as anything else.

    Charlie Miller said in an interview last year that if they offered $1,000,000 for each Chrome vulnerability, there would be a line at least a block long with people looking to bankrupt the contest. Since Chrome seems more difficult to exploit, people won't invest the extra time and resources unless they feel the return is worth it.
     
  6. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Actually it was tested in 2008, and remained unhacked.
     
  7. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  8. Sadeghi85

    Sadeghi85 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    747
    From the above link:

     
  9. The Hammer

    The Hammer Registered Member

    Joined:
    May 12, 2005
    Posts:
    5,752
    Location:
    Toronto Canada
    Maybe all teams should post a $ 20,000 bond which they forfeit if they withdraw.:p
     
  10. chronomatic

    chronomatic Registered Member

    Joined:
    Apr 9, 2009
    Posts:
    1,343
    Umm, that's because no one could exploit it. That's why they didn't show up. These attacks are planned months in advance, it isn't like they just show up empty-handed hoping to find some way in on the spot.

    Charlie Miller himself has said that he has exploits for Chrome but he has not found a way to make them work because the sandbox is too difficult to escape.
     
  11. dw426

    dw426 Registered Member

    Joined:
    Jan 3, 2007
    Posts:
    5,543
    We don't know why nobody showed up this year, so let's not have the assumption train speed down the tracks yet. I personally would rather someone come out and say "Look, we had something lined up, but we just couldn't get it done", than keep quiet. Whether "getting it done" means the exploit won't work, they ran into trouble, or just plain couldn't make it, some explanation would be nice. Otherwise we end up with your kind of comments (not insulting you, just saying lots will hurry right on out and proclaim Chrome is unbeatable). Why the Firefox guys left would be interesting to hear as well.
     
  12. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Ubuntu or opera?

    Thanks
     
  13. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    It was an Ubuntu 7.10 laptop.
     
  14. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Thanks.
     
  15. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    97,865
    Location:
    U.S.A.
     
  16. chronomatic

    chronomatic Registered Member

    Joined:
    Apr 9, 2009
    Posts:
    1,343
    Probably because they couldn't find an exploit that worked. It certainly was not because of a lack of interest -- Firefox is the most popular browser there is.

    Did anyone crack FF this year?
     
  17. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
  18. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  19. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
  20. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Scroll down to the 2nd last paragraph.
     
  21. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Oh, I see.
     
  22. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Surprised that Firefox remained unchallenged. That makes it quite secure I suppose.
     
  23. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Windows Phone 7 also remained unchallenged, does that make it secure?
     
  24. vasa1

    vasa1 Registered Member

    Joined:
    May 1, 2010
    Posts:
    4,417
    Source
     
  25. chronomatic

    chronomatic Registered Member

    Joined:
    Apr 9, 2009
    Posts:
    1,343
    I would say it's not a coincidence. :D
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.