Leopard also has some sort of sandbox feature, but apparently it's not used for Safari.
Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
11–20 of 40 posts
Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
#12I really have no idea what I'm talking about, but I thought Leopard had the address space randomization I assume he's referring to? Leopard also has some sort of sandbox feature, but apparently it's not used for Safari.
http://www.matasano.com/log/981/a-roundup-of-leopard-securit...
Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
#13Earlier quoted context omitted.
I don't like vulnerability markets. It seems to me like a flaw is more valuable before it's patched, and more valuable before it's disclosed. Like plutonium, anything done to make it safer makes it less valuable. If you're going to pay top dollar for something like that, you bother me. But I have two problems with where you're going. First, finding a bug in your own time and not telling Apple about it unless they pay…
I have no problem with you, Charlie, or anyone else being paid top dollar for his or her work, particularly in an important field like security research. Indeed, I think it's a great idea for Apple and the other vendors to reimburse 3rd parties for high quality results. But he wasn't saying "I put X hours into this, and therefore it's worth $X*(billing rate)." He was saying "the market value of this is $Z., and it's…
weis2007.econinfosec.org/papers/29.pdf
Based on the limited data in the paper, it seems that it's the government rather than the vendors that is actually setting the price in the legitimate market, at least for high quality exploits.
I think the X*(billing rate) calculation ignores the risk that the researcher took. It's a little like saying that a startup should be worth exactly the amount of money that has been invested in it.
Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
#14I've always thought it was funny when someone would try to sell me on macs by saying there are less bugs and viruses on them. You have to remind them that if Apple had 90% of the business computer market that wouldn't be true anymore. Apple's best security is the fact that far fewer people buy their products than they do Microsoft's.
But, at the moment, there are less viruses on them for precisely that reason. Security through popularity is working for the time being. That and linux/unix/os x have the principal of least privileges working for them too.
Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
#15Earlier quoted context omitted.
I have no problem with you, Charlie, or anyone else being paid top dollar for his or her work, particularly in an important field like security research. Indeed, I think it's a great idea for Apple and the other vendors to reimburse 3rd parties for high quality results. But he wasn't saying "I put X hours into this, and therefore it's worth $X*(billing rate)." He was saying "the market value of this is $Z., and it's…
If Charlie Miller doesn't find bugs in Safari, it is more likely that the Russian Mafia will get them from someone else. If Miller decides to boycott Apple security research until Apple pays better --- to just stop doing the work --- is he implicitly using the threat of Bad Guys to raise the value of his work?
If the Bad Guys can get the exploit from someone else, then Apple equally could pay someone other than Alice to disclose it to them. Your premise assumes the work is fungible.
If the entire set of people (including Alice) who are capable of finding these vulnerabilities conspired to withhold their work and push the White Hat market clearing price up to the level that the Bad Guys will pay, then the answer to your question would be yes.
If it's a market without price fixing, then Alice withholding her work doesn't materially affect the actual price of the exploit to Apple, and in that case the answer to your question is no.
Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
#16Earlier quoted context omitted.
If Charlie Miller doesn't find bugs in Safari, it is more likely that the Russian Mafia will get them from someone else. If Miller decides to boycott Apple security research until Apple pays better --- to just stop doing the work --- is he implicitly using the threat of Bad Guys to raise the value of his work?
[Let's use "Alice" as the name of our hypothetical security researcher.] If the Bad Guys can get the exploit from someone else, then Apple equally could pay someone other than Alice to disclose it to them. Your premise assumes the work is fungible. If the entire set of people (including Alice) who are capable of finding these vulnerabilities conspired to withhold their work and push the White Hat market clearing pric…
Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
#17I've always thought it was funny when someone would try to sell me on macs by saying there are less bugs and viruses on them. You have to remind them that if Apple had 90% of the business computer market that wouldn't be true anymore. Apple's best security is the fact that far fewer people buy their products than they do Microsoft's.
But, at the moment, there are less viruses on them for precisely that reason. Security through popularity is working for the time being. That and linux/unix/os x have the principal of least privileges working for them too.
Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
#18Earlier quoted context omitted.
I have no problem with you, Charlie, or anyone else being paid top dollar for his or her work, particularly in an important field like security research. Indeed, I think it's a great idea for Apple and the other vendors to reimburse 3rd parties for high quality results. But he wasn't saying "I put X hours into this, and therefore it's worth $X*(billing rate)." He was saying "the market value of this is $Z., and it's…
Charlie has actually written about this issue before in a more academic context: weis2007.econinfosec.org/papers/29.pdf Based on the limited data in the paper, it seems that it's the government rather than the vendors that is actually setting the price in the legitimate market, at least for high quality exploits. I think the X*(billing rate) calculation ignores the risk that the researcher took. It's a little like sa…
Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
#19I really have no idea what I'm talking about, but I thought Leopard had the address space randomization I assume he's referring to? Leopard also has some sort of sandbox feature, but apparently it's not used for Safari.
Nope. They've started down the path, but with these things, if you don't do it right, you may as well not have done it all. http://www.matasano.com/log/981/a-roundup-of-leopard-securit...
Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
#20Earlier quoted context omitted.
Nope. They've started down the path, but with these things, if you don't do it right, you may as well not have done it all. http://www.matasano.com/log/981/a-roundup-of-leopard-securit...
That was a good read, thanks. Has it been submitted to HN?