Live data from Hacker News

Pwn2Own owned all major browsers

h30499.www3.hp.com

11–20 of 67 posts

Re: Pwn2Own owned all major browsers

#12

I don't really understand the competiton. Do people come to these with just the intention of finding exploits, or do they come with the exploit ready, waiting to collect a reward?

AFAIK most have exploits ready before the event, and demonstrate them publicly (for the first time) at the event.

In general, skilled crackers/reverse engineers/security experts will look for new bugs -- and when found, can either a) Tell the vendor, b) Tell the world, c) Sell the exploit to the highest bidder, or d) Use the exploit for nefarious purposes themselves.

In general some combination of a) and b) or c) is the most common -- these events is a way to compensate people to do a) and b) -- and provide some incentive to avoid c) (and d)).

Re: Pwn2Own owned all major browsers

#13

I don't really understand the competiton. Do people come to these with just the intention of finding exploits, or do they come with the exploit ready, waiting to collect a reward?

They have the exploits ready to go, the challenge is whether they can exploit the target system (which is fully patched) within their time slot. It's a useful excercise, I think, in that it demonstrates that even the most hardened of codebases still has security bugs and it also serves as a cautionary tale for people who think they don't need multiple layers of defence..

Most teams have something which will work though, so the "winner" often depends on what order the contestants get drawn in.

Re: Pwn2Own owned all major browsers

#16

Interesting how Java was pwned thee times in spite of the lowest reward.

Everyone is sitting on a java 0day now. They have lost a lot of value in the market since there is literally as much supply as demand. I keep reading CVEs waiting for the one I have to be discovered by someone.

Re: Pwn2Own owned all major browsers

#17
post #6
post #5

Earlier quoted context omitted.

Directly below "Mozilla Firefox on Windows 7 ($60,000)"

Safari is a target in the event, but has not been pwned yet: Wednesday: 1:30 - Java (James Forshaw) PWNED 2:30 - Java (Joshua Drake) PWNED 3:30 - IE 10 (VUPEN Security) PWNED 4:30 - Chrome (Nils & Jon) PWNED 5:30 - Firefox (VUPEN Security) PWNED 5:31 - Java (VUPEN Security) PWNED Thursday: 12pm - Flash (VUPEN Security) 1pm - Adobe Reader (George Hotz) 2pm - IE 10 (Pham Toan) Interestingly enough, last year it was the…

Poor Vupen. Their Safari exploit must have broke.

Re: Pwn2Own owned all major browsers

#18

"All"? Not Safari yet (knock on wood). Which is a big change from back in the day when it was usually pwned first in this contest. Or are you saying it's not a major browser?

At 25% of mobile, I agree it is a worthwhile endeavor to find exploits for safari.

I was about to make fun of you for suggesting safari has significant usage until I considered mobile.

Re: Pwn2Own owned all major browsers

#19

"All"? Not Safari yet (knock on wood). Which is a big change from back in the day when it was usually pwned first in this contest. Or are you saying it's not a major browser?

At 25% of mobile, I agree it is a worthwhile endeavor to find exploits for safari. I was about to make fun of you for suggesting safari has significant usage until I considered mobile.

Mobile Safari was not in the list offered as targets if i read that right..

Re: Pwn2Own owned all major browsers

#20

"All"? Not Safari yet (knock on wood). Which is a big change from back in the day when it was usually pwned first in this contest. Or are you saying it's not a major browser?

At 25% of mobile, I agree it is a worthwhile endeavor to find exploits for safari. I was about to make fun of you for suggesting safari has significant usage until I considered mobile.

Safari's desktop share is somewhere between 5.5% and 15.5% depending on whose stats you trust:

http://en.wikipedia.org/wiki/Usage_share_of_web_browsers#Sta...

Is it crazy to consider that significant?

Post reply on HN