Live data from Hacker News

Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

blogs.zdnet.com

21–30 of 40 posts

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#21
post #16

Earlier quoted context omitted.

[Let's use "Alice" as the name of our hypothetical security researcher.] If the Bad Guys can get the exploit from someone else, then Apple equally could pay someone other than Alice to disclose it to them. Your premise assumes the work is fungible. If the entire set of people (including Alice) who are capable of finding these vulnerabilities conspired to withhold their work and push the White Hat market clearing pric…

You're missing the point. Apple isn't matching the market's bid for these vulnerabilities. Clearly, people besides Miller can find Safari flaws; the difference is, when Miller finds them, we know they aren't being sold to organized crime. By your logic, if he stopped, he'd be making things better for the Bad Guys; he's therefore obligated to do the work.

You're missing mine, I'm afraid: I've made no claim about anyone having to do anything. Indeed, if I was in Charlie's shoes, I wouldn't be working on spec.

Let me put it another way.

There are two markets for exploits: the legitimate one, and the criminal one.

Charlie is participating in the legitimate one. He's going to get paid what the sole counterparty wants to pay him. We can argue about what the counterparty should pay him, but that's up to Apple (in this case), and there are a lot of different things that might enter into their calculation.

An argument that uses the value of the exploit in the criminal market in an attempt to set a value in the legitimate one only makes sense in one of two cases: (a) you're going to take your work and sell it over there, or (b) you claim that someone else either has already discovered or will soon discover the same exploit independently, and will choose to sell it on the criminal market, and therefore the value of your work should reflect the danger of that happening.

In the first case, you're engaging in blackmail.

In the second case, it's just not a very good argument -- because the chance that each element in the chain of reasoning about the value (it's about to be or has already been discovered by someone else, it's going to end up on the black market, it's a substantial risk for a 0-day, etc.) is not true represents a probability that reduces the overall value of your exploit in the legitimate market. Plus, there's the additional reductions in exploit value that come from the vendor not actually caring that much about fixing problems until they're in the wild, or having already found the issue and decided that the particular problem isn't worth fixing for a variety of non-technical reasons, or any one of a dozen other external factors.

Working on spec and then demanding that the vendors match the exploit values that the criminal market is paying is just a Bad Idea, morally and practically.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#22
post #16

Earlier quoted context omitted.

You're missing the point. Apple isn't matching the market's bid for these vulnerabilities. Clearly, people besides Miller can find Safari flaws; the difference is, when Miller finds them, we know they aren't being sold to organized crime. By your logic, if he stopped, he'd be making things better for the Bad Guys; he's therefore obligated to do the work.

You're missing mine, I'm afraid: I've made no claim about anyone having to do anything. Indeed, if I was in Charlie's shoes, I wouldn't be working on spec. Let me put it another way. There are two markets for exploits: the legitimate one, and the criminal one. Charlie is participating in the legitimate one. He's going to get paid what the sole counterparty wants to pay him. We can argue about what the counterparty sh…

Apple pays zero for vulnerabilities, friend. They get them for free. Charlie Miller is saying he's going to stop doing that. Can you blame him?

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#23
post #10

Cool: > Q: Google Chrome was the one target left standing. Surprised? > A: There are bugs in Chrome but they’re very hard to exploit. I have a Chrome vulnerability right now but I don’t know how to exploit it. It’s really hard. The’ve got that sandbox model that’s hard to get out of. With Chrome, it’s a combination of things — you can’t execute on the heap, the OS protections in Windows and the Sandbox.

I still use Chrome even though its become less trendy lately. Beta version has some great features.

I know many people are mad that the linux/mac version isn't available but if you think about it, the reason is the sandbox. Google loves quality and won't release something if its not of high quality. Sandboxing on windows I'm positive is different on a unix based system. And security is key.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#24
With all of the talk about morals and ethics, these are the 2 questions I ask myself whenever making a tough decision:

  1) Am I making the world a better place or a worse place?
  2) Am I providing value to the people I care about?
I can't speak for Charlie Miller. But, my answer would be no for both questions. If I were in the same position as him I would feel like a big piece of fucking shit every single morning when I looked at myself in the mirror.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#25
post #20
post #19

Earlier quoted context omitted.

That was a good read, thanks. Has it been submitted to HN?

I generally won't submit my own stuff, but that post is also pretty old. There's stuff on the blog I'm much more proud of that hasn't made it here.

Fair enough, I have to admit I haven't checked out your blog before. The age did occur to me, but Leopard is still current and I thought it was a good read.

I was mainly interested in if there had been any HN discussion on it. Thanks.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#27
post #24

With all of the talk about morals and ethics, these are the 2 questions I ask myself whenever making a tough decision: 1) Am I making the world a better place or a worse place? 2) Am I providing value to the people I care about? I can't speak for Charlie Miller. But, my answer would be no for both questions. If I were in the same position as him I would feel like a big piece of fucking shit every single morning when…

In his case:

3) Can I feed myself?

By finding Safari bugs, he does make the world a better place. But he can't live like that, so he has to stop looking for Safari bugs.

Since Safari undoubtedly has bugs, this means someone else is going to find them. That someone else could be a criminal, but you can't blame the guy for not wanting to do work that doesn't pay. In the end, Safari's security is Apple's problem, not Charlie Miller's.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#28
post #10

Cool: > Q: Google Chrome was the one target left standing. Surprised? > A: There are bugs in Chrome but they’re very hard to exploit. I have a Chrome vulnerability right now but I don’t know how to exploit it. It’s really hard. The’ve got that sandbox model that’s hard to get out of. With Chrome, it’s a combination of things — you can’t execute on the heap, the OS protections in Windows and the Sandbox.

I also find it very interesting how he complements Windows and IE. I think people forget just how hard it is to be the biggest target.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#29
post #10

Cool: > Q: Google Chrome was the one target left standing. Surprised? > A: There are bugs in Chrome but they’re very hard to exploit. I have a Chrome vulnerability right now but I don’t know how to exploit it. It’s really hard. The’ve got that sandbox model that’s hard to get out of. With Chrome, it’s a combination of things — you can’t execute on the heap, the OS protections in Windows and the Sandbox.

I still use Chrome even though its become less trendy lately. Beta version has some great features. I know many people are mad that the linux/mac version isn't available but if you think about it, the reason is the sandbox. Google loves quality and won't release something if its not of high quality. Sandboxing on windows I'm positive is different on a unix based system. And security is key.

I thought they're only on Windows because they're using Windows-specific libraries. IIRC, I think it was the MFC.
Post reply on HN