<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Mac security researcher wins Pwn2Own contest with Safari hack</title>
	<atom:link href="http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-hack/</link>
	<description>Daniel Eran Dilger in San Francisco</description>
	<lastBuildDate>Sun, 05 Feb 2012 17:03:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Apple Sicherheit - Security Forum</title>
		<link>http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-hack/comment-page-1/#comment-18993</link>
		<dc:creator>Apple Sicherheit - Security Forum</dc:creator>
		<pubDate>Tue, 09 Jun 2009 21:48:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/?p=3349#comment-18993</guid>
		<description>[...] diese als Botnetze, Spam Schleudern etc. pp. zu missbrauchen. Siehe zu den Contests beispielsweise:http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-ha...http://www.roughlydrafted.com/2009/03/26/pwn2own-contest-winner-macs-are-safer-than-windows/Die [...]</description>
		<content:encoded><![CDATA[<p>[...] diese als Botnetze, Spam Schleudern etc. pp. zu missbrauchen. Siehe zu den Contests beispielsweise:http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-ha&#8230;http://www.roughlydrafted.com/2009/03/26/pwn2own-contest-winner-macs-are-safer-than-windows/Die [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JulesLt</title>
		<link>http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-hack/comment-page-1/#comment-17920</link>
		<dc:creator>JulesLt</dc:creator>
		<pubDate>Fri, 20 Mar 2009 09:26:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/?p=3349#comment-17920</guid>
		<description>If you look at the CanSecWest page, the definition of &#039;owned&#039; is &#039;code execution in the context of the browser process&#039; - so it says nothing about the wider security of the platform, only the browser.

Now, as it is, you could still do a lot of damage (deleting the users home directory) from getting control of a user level process, but Snow Leopard - correctly comparable with Windows 7 - implements the process sandboxing introduced in Leopard - which would significantly reduce the damage that could be done.</description>
		<content:encoded><![CDATA[<p>If you look at the CanSecWest page, the definition of &#8216;owned&#8217; is &#8216;code execution in the context of the browser process&#8217; &#8211; so it says nothing about the wider security of the platform, only the browser.</p>
<p>Now, as it is, you could still do a lot of damage (deleting the users home directory) from getting control of a user level process, but Snow Leopard &#8211; correctly comparable with Windows 7 &#8211; implements the process sandboxing introduced in Leopard &#8211; which would significantly reduce the damage that could be done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kaspersky Sells Mac AntiVirus Fear Using Charlie Miller&#8230; Mac AntiVirus Foe &#8212; RoughlyDrafted Magazine</title>
		<link>http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-hack/comment-page-1/#comment-17912</link>
		<dc:creator>Kaspersky Sells Mac AntiVirus Fear Using Charlie Miller&#8230; Mac AntiVirus Foe &#8212; RoughlyDrafted Magazine</dc:creator>
		<pubDate>Fri, 20 Mar 2009 06:38:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/?p=3349#comment-17912</guid>
		<description>[...] Mac Malware Myth Mac security researcher wins Pwn2Own contest with Safari hack In Russia, Anti-Virus Infects [...]</description>
		<content:encoded><![CDATA[<p>[...] Mac Malware Myth Mac security researcher wins Pwn2Own contest with Safari hack In Russia, Anti-Virus Infects [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tzx4</title>
		<link>http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-hack/comment-page-1/#comment-17897</link>
		<dc:creator>tzx4</dc:creator>
		<pubDate>Fri, 20 Mar 2009 01:15:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/?p=3349#comment-17897</guid>
		<description>This following is a copy &amp; pasted passage I found when there was the minor flap a few months ago concerning whether or not Apple recommends  running anti virus software.  It must be considered hearsay, but if accurate, it sure is at least a bit humorous if not enlightening.

&quot;But Miller, who regularly roots out Mac and iPhone vulnerabilities and is perhaps best-known for walking away with a $10,000 prize for hacking a MacBook Air laptop in under two minutes last March, pooh-poohed Apple&#039;s recommendation using the same logic as many longtime users.

&quot;Windows has 90% of the market, but [attackers] give it 100% of their time,&quot; he said, echoing the idea that hackers target the largest pool of victims.

Criticizing security software for its cost -- both in dollars and in the processor cycles it consumes -- Miller admitted that he doesn&#039;t bother running any on his Macs. &quot;I don&#039;t think it protects me as well as it says,&quot; he argued. &quot;If I was worried about attacks, I would use it, but I&#039;m not worried.&quot;</description>
		<content:encoded><![CDATA[<p>This following is a copy &amp; pasted passage I found when there was the minor flap a few months ago concerning whether or not Apple recommends  running anti virus software.  It must be considered hearsay, but if accurate, it sure is at least a bit humorous if not enlightening.</p>
<p>&#8220;But Miller, who regularly roots out Mac and iPhone vulnerabilities and is perhaps best-known for walking away with a $10,000 prize for hacking a MacBook Air laptop in under two minutes last March, pooh-poohed Apple&#8217;s recommendation using the same logic as many longtime users.</p>
<p>&#8220;Windows has 90% of the market, but [attackers] give it 100% of their time,&#8221; he said, echoing the idea that hackers target the largest pool of victims.</p>
<p>Criticizing security software for its cost &#8212; both in dollars and in the processor cycles it consumes &#8212; Miller admitted that he doesn&#8217;t bother running any on his Macs. &#8220;I don&#8217;t think it protects me as well as it says,&#8221; he argued. &#8220;If I was worried about attacks, I would use it, but I&#8217;m not worried.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brau</title>
		<link>http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-hack/comment-page-1/#comment-17895</link>
		<dc:creator>Brau</dc:creator>
		<pubDate>Fri, 20 Mar 2009 00:37:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/?p=3349#comment-17895</guid>
		<description>Ahh well, the furor over this event last year blew over pretty quick and this one will too.  Those who are looking to blast Macs or crow about Windows will find any excuse, reverting to &quot;Macs are only good for graphics&quot; if they can&#039;t find anything else.  Personally, I&#039;m just glad the exploits are kept secret because both Apple and MicroSoft can create patches before any real damage is done.</description>
		<content:encoded><![CDATA[<p>Ahh well, the furor over this event last year blew over pretty quick and this one will too.  Those who are looking to blast Macs or crow about Windows will find any excuse, reverting to &#8220;Macs are only good for graphics&#8221; if they can&#8217;t find anything else.  Personally, I&#8217;m just glad the exploits are kept secret because both Apple and MicroSoft can create patches before any real damage is done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: darwiniandude</title>
		<link>http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-hack/comment-page-1/#comment-17893</link>
		<dc:creator>darwiniandude</dc:creator>
		<pubDate>Fri, 20 Mar 2009 00:05:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/?p=3349#comment-17893</guid>
		<description>StrictNon-Conformist:
Quite right, and admin account on the Mac isn&#039;t like on windows, especially if things like &#039;Require password to unlock each System Preferences Pane&#039; are enabled. 

What version of Safari was used???</description>
		<content:encoded><![CDATA[<p>StrictNon-Conformist:<br />
Quite right, and admin account on the Mac isn&#8217;t like on windows, especially if things like &#8216;Require password to unlock each System Preferences Pane&#8217; are enabled. </p>
<p>What version of Safari was used???</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: StrictNon-Conformist</title>
		<link>http://www.roughlydrafted.com/2009/03/19/mac-security-researcher-wins-pwn2own-contest-with-safari-hack/comment-page-1/#comment-17883</link>
		<dc:creator>StrictNon-Conformist</dc:creator>
		<pubDate>Thu, 19 Mar 2009 22:42:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.roughlydrafted.com/?p=3349#comment-17883</guid>
		<description>This whole contest is a pile of BS, because what it truly measures is the choice-making ability of the contestants, along with their typing speed and knowledge of any particular platform.

I find it very hard to believe that as the reports suggest, he had &quot;full control of the machine&quot; in a few seconds, because you need sudo access to have full control over the entire machine, as opposed to merely taking control of the account.  Sure, it may have been running under an administrator account (not wise online, that&#039;s for sure!), but certain actions still require entering the administrator&#039;s password to accomplish, but the coverage doesn&#039;t cover things that deeply, though at least it did mention that the guy stated he practiced the exploit until he was 100% sure it&#039;d work every time: again, it was really a contest to show what I stated above, with typing speed being a paramount differentiator.  It wouldn&#039;t even matter which platform: the one that&#039;s hit first with the fastest typist that has a known-good exploit will likely go down first.</description>
		<content:encoded><![CDATA[<p>This whole contest is a pile of BS, because what it truly measures is the choice-making ability of the contestants, along with their typing speed and knowledge of any particular platform.</p>
<p>I find it very hard to believe that as the reports suggest, he had &#8220;full control of the machine&#8221; in a few seconds, because you need sudo access to have full control over the entire machine, as opposed to merely taking control of the account.  Sure, it may have been running under an administrator account (not wise online, that&#8217;s for sure!), but certain actions still require entering the administrator&#8217;s password to accomplish, but the coverage doesn&#8217;t cover things that deeply, though at least it did mention that the guy stated he practiced the exploit until he was 100% sure it&#8217;d work every time: again, it was really a contest to show what I stated above, with typing speed being a paramount differentiator.  It wouldn&#8217;t even matter which platform: the one that&#8217;s hit first with the fastest typist that has a known-good exploit will likely go down first.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

