Live data from Hacker News

Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

blogs.zdnet.com

1–10 of 40 posts

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#2
I've always thought it was funny when someone would try to sell me on macs by saying there are less bugs and viruses on them. You have to remind them that if Apple had 90% of the business computer market that wouldn't be true anymore. Apple's best security is the fact that far fewer people buy their products than they do Microsoft's.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#3
Miller says that the bugs have a market value beyond $5000 -- indeed, he claims that an IE8 exploit has a "market value" of over $50k.

But that market value exists only if you're willing to sell the exploits to people who either (a) are planning to use them or (b) want to fix them. The former group are the ones setting the market value, since they're the ones who are going to monetize the exploits.

The idea of announcing NO MORE FREE BUGS really amounts to saying to the world "I'm either going to sell my work to criminals, or am going to participate in an ongoing blackmail scheme to make myself rich."

Nice. Good luck with that, Charlie.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#4

Miller says that the bugs have a market value beyond $5000 -- indeed, he claims that an IE8 exploit has a "market value" of over $50k. But that market value exists only if you're willing to sell the exploits to people who either (a) are planning to use them or (b) want to fix them. The former group are the ones setting the market value, since they're the ones who are going to monetize the exploits. The idea of announ…

I don't like vulnerability markets. It seems to me like a flaw is more valuable before it's patched, and more valuable before it's disclosed. Like plutonium, anything done to make it safer makes it less valuable. If you're going to pay top dollar for something like that, you bother me.

But I have two problems with where you're going.

First, finding a bug in your own time and not telling Apple about it unless they pay you isn't blackmail. Charlie Miller bills $300/hour. His work product is worth money. Apple has no right to confiscate it. If the dilemma was, "pay up or it's going to the Russian Mafia", it'd be blackmail. But if you think Charlie Miller is selling vulnerabilities to the Russian Mafia, you're a jackass.

Second, the reason you don't see me at CanSecWest --- well, one of them, another being that Nils and Charlie and Dino would crush me --- is that I spent all day reversing protocols, writing fuzzers, and finding flaws. For cash. Vendors pay us, and so do large companies that buy from those vendors. It's my day job; it's a job; money changes hands. How is Charlie's proposal different?

I think it is different. But it's way more subtle than you're making out to be. It's also a common industry practice, so making him the face of it isn't a great play.

(You can see where we stand on this: http://www.matasano.com/log/mtso/ethics/).

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#5
post #2

I've always thought it was funny when someone would try to sell me on macs by saying there are less bugs and viruses on them. You have to remind them that if Apple had 90% of the business computer market that wouldn't be true anymore. Apple's best security is the fact that far fewer people buy their products than they do Microsoft's.

A really common response to that is, "well, malware share on Macs should track the market share of Macs; it doesn't, ergo Macs are more secure".

This is, of course, silly. We haven't hit "peak oil" for Windows infections. A new Windows worm still pays off wildly better than a Mac worm; writing Mac malware is economically irrational.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#6
post #4

Miller says that the bugs have a market value beyond $5000 -- indeed, he claims that an IE8 exploit has a "market value" of over $50k. But that market value exists only if you're willing to sell the exploits to people who either (a) are planning to use them or (b) want to fix them. The former group are the ones setting the market value, since they're the ones who are going to monetize the exploits. The idea of announ…

I don't like vulnerability markets. It seems to me like a flaw is more valuable before it's patched, and more valuable before it's disclosed. Like plutonium, anything done to make it safer makes it less valuable. If you're going to pay top dollar for something like that, you bother me. But I have two problems with where you're going. First, finding a bug in your own time and not telling Apple about it unless they pay…

I have no problem with you, Charlie, or anyone else being paid top dollar for his or her work, particularly in an important field like security research.

Indeed, I think it's a great idea for Apple and the other vendors to reimburse 3rd parties for high quality results.

But he wasn't saying "I put X hours into this, and therefore it's worth $X*(billing rate)."

He was saying "the market value of this is $Z., and it's more for things that have a greater impact."

I don't know Charlie Miller from a hole in the ground, and so I have no idea if he's going to be selling his work to the Russian Mafia. If you say he's a great guy, I'm sure you're right.

Nevertheless, if he thinks that security exploits have a market value beyond a reasonable billing rate, he's implicitly using the threat of the Bad Guys to raise the value of his work.

That's a very fine line to be walking.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#8
post #4

Earlier quoted context omitted.

I don't like vulnerability markets. It seems to me like a flaw is more valuable before it's patched, and more valuable before it's disclosed. Like plutonium, anything done to make it safer makes it less valuable. If you're going to pay top dollar for something like that, you bother me. But I have two problems with where you're going. First, finding a bug in your own time and not telling Apple about it unless they pay…

I have no problem with you, Charlie, or anyone else being paid top dollar for his or her work, particularly in an important field like security research. Indeed, I think it's a great idea for Apple and the other vendors to reimburse 3rd parties for high quality results. But he wasn't saying "I put X hours into this, and therefore it's worth $X*(billing rate)." He was saying "the market value of this is $Z., and it's…

If Charlie Miller doesn't find bugs in Safari, it is more likely that the Russian Mafia will get them from someone else. If Miller decides to boycott Apple security research until Apple pays better --- to just stop doing the work --- is he implicitly using the threat of Bad Guys to raise the value of his work?

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#9
post #2

I've always thought it was funny when someone would try to sell me on macs by saying there are less bugs and viruses on them. You have to remind them that if Apple had 90% of the business computer market that wouldn't be true anymore. Apple's best security is the fact that far fewer people buy their products than they do Microsoft's.

But, at the moment, there are less viruses on them for precisely that reason. Security through popularity is working for the time being. That and linux/unix/os x have the principal of least privileges working for them too.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#10
Cool:

> Q: Google Chrome was the one target left standing. Surprised?

> A: There are bugs in Chrome but they’re very hard to exploit. I have a Chrome vulnerability right now but I don’t know how to exploit it. It’s really hard. The’ve got that sandbox model that’s hard to get out of. With Chrome, it’s a combination of things — you can’t execute on the heap, the OS protections in Windows and the Sandbox.

Post reply on HN