Earlier quoted context omitted.
It's painful that they combined XSS and SQLI, because progress on SQLI has been much better than progress on DOM corruption bugs.
Indeed, I'd love to see an expanded chart (as well as a more recent one). This one is focused on two categories, memory vs web vulns.
L0pht’s warnings about the Internet drew notice but little action
31–40 of 69 posts
Re: L0pht’s warnings about the Internet drew notice but little action
#32The Internet itself, he added, could be taken down "by any of the seven individuals seated before you" with 30 minutes of well-choreographed keystrokes. If this wasn't exaggeration, we should study the fortunate circumstances by which this calamity has been avoided for 17 years.
Well, it's somewhat exaggerated. But a bit of BGP hacking can take large areas offline for hours. Why not done more often? No lulz or money in it. Hackers want the net as a whole to stay up for the same reason as everyone else. It's specific sites that are targets for humiliation or extortion.
Re: L0pht’s warnings about the Internet drew notice but little action
#33The Internet itself, he added, could be taken down "by any of the seven individuals seated before you" with 30 minutes of well-choreographed keystrokes. If this wasn't exaggeration, we should study the fortunate circumstances by which this calamity has been avoided for 17 years.
The hunting and taxidermy of corrupted BGP advertisements is basically what got the NANOG crowd out of bed every morning; it's a pretty big chunk of the job. I always felt like the alarmism over BGP was a bit tone-deaf. Certainly, nothing Peiter said came as any surprise to anyone who'd ever managed default-free peering.
Re: L0pht’s warnings about the Internet drew notice but little action
#34The Internet itself, he added, could be taken down "by any of the seven individuals seated before you" with 30 minutes of well-choreographed keystrokes. If this wasn't exaggeration, we should study the fortunate circumstances by which this calamity has been avoided for 17 years.
Peiter was talking about BGP. In 1998, you had to be somewhat diligent to get to a vantage point from which you could inject bogus BGP, and the Venn diagram between those people and "nihilistic assholes" is not that scary. In 2015, you can still technically fuck up BGP, but probably not for very long, and not without burning a lot of assets. Why would anyone bother? The hunting and taxidermy of corrupted BGP advertis…
Re: L0pht’s warnings about the Internet drew notice but little action
#35Earlier quoted context omitted.
How many complete rewrites of Internet Explorer have we had since then? None? There's an ongoing one that was announced in January with a preview released in March. https://en.wikipedia.org/wiki/Microsoft_Edge
Spartan? https://twitter.com/dildog/status/612795030345007104 "It feels like 1996 again."
"Microsoft Edge, initially developed under the codename Project Spartan..." (same Wikipedia link as above)
Re: L0pht’s warnings about the Internet drew notice but little action
#36beard: hacker credibility +1
nickname/handle: hacker credibility +1
glasses: hacker credibility +1
suit: hacker credibility -1
Re: L0pht’s warnings about the Internet drew notice but little action
#37The Internet itself, he added, could be taken down "by any of the seven individuals seated before you" with 30 minutes of well-choreographed keystrokes. If this wasn't exaggeration, we should study the fortunate circumstances by which this calamity has been avoided for 17 years.
Or, alternatively, you could go after some smaller internet companies, demand extortion money, buy a nice car and treat your friends to drinks.
Re: L0pht’s warnings about the Internet drew notice but little action
#38long hair: hacker credibility +1 beard: hacker credibility +1 nickname/handle: hacker credibility +1 glasses: hacker credibility +1 suit: hacker credibility -1
Social engineering.
Re: L0pht’s warnings about the Internet drew notice but little action
#39Earlier quoted context omitted.
With all due respect to you, everything would be different. I know even then it would've been a daunting thing to do but perhaps 1998 was the last year when it could've been done: tear it down and rebuild it securely. I am sure you know this too well but let me remind a few people here who were not even born when some of this happened: The early years were mostly of trust. As an example, I remember running around eve…
I understand that's what people think, but what I'm saying is that in 1998, we wouldn't have known how to rebuild everything securely. We'd have ended up with slightly better C standard libaries, S-BGP, IPSEC, and DNSSEC. Here, let me sum it up this way: I think it's possible that the L0pht testimony predates SQL injection .
Re: L0pht’s warnings about the Internet drew notice but little action
#40The more I think about this story, the dumber it seems to me. The narrative seems to be, L0pht testifies, world ignores them, chaos ensues. But Mudge's testimony coincides almost perfectly with a software security renaissance. The reality is more like: L0pht testifies, world ignores them, gigantic sea-change in security leads to 9-figure investment in securing Windows, the near eradication of SQL injection from popul…
What language are the applications in? What makes them more secure than C/C++?