Tuesday, July 20, 2010

Eureka! It's supply and demand, stupid!

I've been twisting for a very long time over the whole 'vendors should pay for vulns' mantra that has recently been enthusiastically revived by a bunch of independent security researchers who, to the best of my knowledge, have never actually worked for a software vendor to understand the engineering realities of developing enterprise software.

Tonight I realized why vendors don't need to pay a dime, and it has nothing to do with vendors buying silence or two researchers finding the same bug independently and the second researcher going Full Disclosure on the vendor because the first researcher already collected the bounty.

We can all stop debating what a critical remote code execution bug is going to be worth when there is an open market for vulnerabilities. An open market requires competition. And there will not be competition. Who is going to buy Apple bugs? Apple. Microsoft sure as hell isn't going to buy them, not without a whole lot of up close and personal attention from the nice folks at the DOJ. So let's say Apple offers $10 per RCE. Whaddya gonna do about it? Whine? Go sell it to iDefense? YOU CAN DO THAT TODAY.

So simple it makes me giggle that I didn't see it before. Econ101.

~E

Labels: , , ,

Tuesday, August 12, 2008

What I liked about Black Hat this year

THE TALKS!!
Dan Kaminsky’s It's The End of the Cache As We Know It. (come on, you know you can't help thinking 'And I Feel Fine' after reading that) Standing room only, Dan’s grandma’s session cookies, talk content, speaker energy, enthusiasm. I <3 Dan. If I could adopt a big brother, it would be Dan.

Bruce Potter’s talk on Net Flow analysis. Super interesting, well presented.

Mark Dowd and Alexander Sotirov’s talk on Bypassing Windows Vista Memory Protections. They’re wicked smaht.

LT. Col. Greg Conti’s talk on visual forensics analysis - I am a sucker for visual representation of any data...

Christopher Hoff's Four Horsemen of the Virtualizaton Security Apocolypse.

I know, my review of the talks is pretty light here, but I don't have to write a trip report for the general public so quitcherbitchen. If you're so interested, you should have gone to the talks yourself.

THE OTHER STUFF
Registration check in lines are sooooo much better than in years past, more lines, move faster, yay. But having a separate line to get your delegate bag is a bit inefficient for attendees.

Box lunch option. Now if only they’d offer a ‘no lunch’ ticket. I don’t even care if it costs the same as a ‘with lunch’ registration. I never eat at the con, whether it’s a box lunch or plated meal. I feel bad wasting the food.

Overall, compared to when I first started attending Black Hat many years ago, the con feels more professional. Talks start and end pretty much on time, I didn’t see any real AV difficulties, logistically things seemed pretty smooth. Awwww, Black Hat is growing up!

Lobster and crab dumpling things, sushi, and sliders at a vendor party. Best party food all week.

The conference continues to grow and mature. I’m excited to see that, big conferences are a great initiation ground for new security professionals who may not know about or understand yet the value of smaller cons like ShmooCon or Toorcon, and a great ‘reunion’ spot for people who may talk via IM/Twitter/Facebook/MySpace/IRC/email/whatever all the time but only see each other IRL a few times a year at cons. But the size of Black Hat is a blessing and a curse. You see everyone in one place, where you might only see half as many people you want to at a smaller con. But everyone is circulating so there isn’t time for talking with any one person very much.

Wall of Sheep. A DefCon staple, nice to see it at Black Hat too. Baaaaaaaaa.

Not really about Black Hat, but a Vegas thing: there is now one cab company that takes credit cards in Vegas. w00t. I hate carrying cash.

$32K raised for EFF between Black Hat and Defcon. nice.

Several people arranged hotel suite Rock Band parties in the evenings. That is awesome. !..!,

See y’all again in 2009. Wouldn’t miss it.

Labels: , , , , , , , , , ,

Thursday, November 01, 2007

updates. finally.

conference calendar updated, and the blogroll. I know, I've been ignoring you for a few months. But David Litchfield is blogging now. I figured that alone was worth a post.

Labels: , ,

Wednesday, May 23, 2007

w00t

Another new conference in the fold. WOOT, the Workshop On Offensive Technology is launching this summer in conjunction with USENIX. While WOOT sounds extremely cool and the advisory panel is made up of uber smart people, having six conferences on three continents in August makes for some serious competition for top speakers as well as attendee dollars. WOOT is invite only though, so they might win on leet factor.

Don't count Jeff Moss out though - looks like he is planning 8 (that's right, EIGHT) tracks at Black Hat Vegas this summer. So their cfp must be doing pretty well if they can project that much content with a straight face...

~Elphie

Labels: ,

Do no evil. Unless its really profitable.


OEM's have long been known to install craplets that frustrate and annoy end users in order to beef up their razor thin hardware margins. These craplets are difficult to remove and generally not well tested or certified by (insert OS developer here), which leads to the potential for them to introduce security vulnerabilities. But now Google has teamed up with Dell to create Yet Another Miserable User Experience.

GOOG - for shame. You have forsaken users for your own avarice.

~Elphie

Labels: , , , ,

Tuesday, April 10, 2007

Con Calendar updated

I took some time tonight to update the conference calendar - LOTS of interesting new stuff. IT Underground is going to Dublin... London is getting yet another confab that looks to have good potential, it will be interesting to see what overlap (if any) the Black and White Ball will have with EUSecWest and UnCon. BAD ELPHIE, I didn't get HITB Dubai on the list until after the event, my deepest apologies to the HITB crew (not that any of them read this, but still...) The third CONfidence happens in Krakow Poland in May. Perhaps most interesting is the new conference in Asia, VNSeCon in Ho Chi Minh City, Vietnam. VIET-freaking-Nam! That's awesome. We're everywhere.

When I have time I'm going to try to create a section for some of the smaller meet-up events like ChiSec, BeanSec, Atlanta's SIP, etc. But no time for that this week.

Did I miss an event? Let me know!

~Elphie

Labels: ,

RFID Guardian

This isn't super new, but I just ran across it last week. Pretty interesting, if you are paranoid about RFID security like I am.

The RFID Guardian Project is a collaborative project focused upon providing security and privacy in Radio Frequency Identification (RFID) systems. The goals of our project are to:
Investigate the security and privacy threats faced by RFID systems
Design and implement real solutions against these threats
Investigate the associated technological and legal issues
The namesake of our project is the RFID Guardian: a mobile battery-powered device that offers personal RFID security and privacy management. One the focuses of our project is to build an RFID Guardian prototype.

Our group also performed the first-ever research on RFID Malware.

~Elphie

Labels: , ,

Wednesday, October 18, 2006

distracting the audience

While misdirecting the audience's attention works well in magic shows, I don't think "forget how much we suck, these other people suck worse. really." is a terribly effective PR strategy. But what do I know, I'm not a marketing expert.

"As you might imagine, we are upset at Windows for not being more hardy against such viruses, and even more upset with ourselves for not catching it," Apple said on its site.
The chutzpa does make me laugh though. After all, your immune system really should be stronger to fight the SARS I brought into your home when you invited me to dinner last week. I bet you don't even take vitamin C. You're bringing illness on yourself really. You should seek psychiatric help, you're obviously suffering from Munchausen Syndrome.

I've said it before and I'll say it again, I like Apple, but they are kidding themselves if they really believe that they are superior when it comes to security. Based on what I've seen in the world, I'd say EVERYONE sucks. Hell, if a critical system like electronic voting boxes can't be locked down, what chances does a commercial app have?

~Elphie

Labels: , , ,

Wednesday, May 17, 2006

Diebold backdoor a "feature"

Backdoor Found in Diebold Voting Machines (actually, three backdoors - read the article.) The part I find most eligible for blog fodder is this:
A Diebold spokesman did not dispute Hursti's findings, but said that Black Box Voting was making too much of the matter because the systems are intended to remain in the hands of trusted election officials.

"What they're proposing as a vulnerability is actually a functionality of the system," said spokesman David Bear. "Instead of recognizing the advantages of the technology, we keep ringing up 'what if' scenarios that serve no purpose other than to confuse and in some instances frighten voters."

Okay, here are my favorite flawed assumptions:

1. you can trust voting officials. I think the fact that air marshals have been convicted of smuggling drugs on flights is pretty clear indication that federal security screening of its employees is not an accurate indicator of ethics/morals/trustworthiness.

2. no one with malicious intentions will at any time, in any precinct, ever have access to one of the machines. And if you believe that, you should know that "gullible" is not in the dictionary, immediately join the campaign to Save the Naugas (do you realize how many are slaughtered each year to make Nauga-hide dentist chairs?), and be advised that there really are people in Nigeria legitimately trying to transfer money.

3. to the best of my knowledge, no one has explained yet why the back doors were programmed in, and what legitimate 'functionality' they serve. Did the programmer pass the same 'security' screening and trustworthiness rating scale as the election officials?

Bah, whole thing makes me cranky.

~Elphie

Labels: , , ,

Friday, April 07, 2006

I'd like to buy an 0, HOPE6, BSOD, Captain Obvious and media whoring...

Let's start with CanSecWest, and the vulnerability commercialization panel they had on Wednesday. There was much spirited debate but no end agreement between the parties... takes me back to ShmooCon and the BOF panel on training... but I digress.

In the press, Michael Sutton is quoted as saying that vendors need to pay for vulns, and later in the article a customer states he expects vendors to pay for vulns as well.
"The only economic model that does not make sense to me is the vendor's," Sutton said. "They get to know about a vulnerabilities ahead of time, but they are unwilling to pay for them."
Let's blithely assume for a moment that vendors and researchers could agree on the dollar value of a vulnerability (ROTFLMAO). There is still a big problem with the 'buying vulnerabilities protects customers' argument: if Oracle buys a vuln from David Litchfield, Oracle now owns the vuln. That means that they don't EVER have to fix it if they don't want to. I'm not just picking on Oracle - this is true of ANY vendor. They wouldn't be buying vulns, they'd be buying silence. And that would just piss everyone off - hell, that's why full disclosure practices started to begin with - the only way to get a vendor to fix a security bug was to publicly shame them with it. So I wholeheartedly disagree that vendors buying bugs would make me as a computer user any safer.

I have no problem with reputable third parties buying vulnerabilities and working with vendors to protect customers. I'll admit I think Tipping Point's ZDI program does a better job of that than iDefense's VCP program simply because iDefense's customers leak their confidential advisories all the time before patches are available. But these programs do play an important role in the security ecosystem that benefit customers, researchers, and vendors.

Other stuff:

Dates for HOPE number 6 have been announced - July 21-23, just a week or so before Black Hat Vegas. Of course I've added HOPE to the upcoming cons list...

Check this out - I've heard most people aren't having much trouble with Apple's Boot Camp beta, but this guy managed to get the legendary Blue Screen of Death. I haven't seen that on one of my boxes in over five years. Wow. Comments on the blog suggest that this was a known bug in the beta relating to iSight... doh!

Adam Shostack makes some interesting observations on recent media regarding rootkits on the Emergent Chaos blog. Yeah, he is right, this is a Captain Obvious type of situation where everyone in the security space already knew that rootkits were a big dangerous problem. But I think (or at least hope) the point of the Microsoft presentation at InfoSecWorld in FL that spurred the eweek article was to educate less security savvy customers about threats we are facing today and give guidance on how to deal with them. Adam also mentions the extremely cool work being done by John Heasman of NGS on ACPI BIOS rootkits that was presented not only at Black Hat Federal, but Black Hat Amsterdam and will again be presented in May at the Computer and Enterprise Investigations Conference. Right now it is super cutting edge stuff - so maybe if John gives the talk often enough, more people will pay attention (and by someone I don't mean the bad guys). After giving the talk at Black Hat Federal in January, Rob Lemos ran a story which quoted Greg Hoglund as saying:
"It is going to be about one month before malware comes out to take advantage of this," said Greg Hoglund, CEO of reverse engineering firm HBGary and editor of Rootkit.com. "This is so easy to do. You have widely available tools, free compilers for the ACPI language, and high-level languages to write the code in."

It would be a shame if the security industry didn't pay attention in January to John's early warning and is surprised when malicious bios rootkits emerge.

And since I've mentioned CEIC, I may as well throw a shameless plug out for Vinnie Liu's talk on Defeating Forensic Analysis (with his business partner Patrick Stach) on Thursday May 4 at the con. Vinnie is a very smart guy - if you are attending CEIC, I'd definitely attend their session. I'm such a groupie I'd go to NV just to see this talk, but I think that would violate the restraining order...

~Elphie

Labels: , , , , , , , , , ,

Monday, April 03, 2006

I feel so much safer...

2 air marshals plead guilty to drug smuggling
Marshals accepted $15,000 in return for carrying cocaine on Vegas flight

The marshals admitted they accepted $15,000 to use their positions as air marshals to bypass airport security and smuggle 15 pounds of cocaine.

I feel so much safer knowing I get the full body grope, er, patdown, every time I fly to make sure I don't have a shiv hidden in my underwire bra, while these guys who are paid law enforcement officials (who presumably passed background checks to get their jobs) circumvent security screening with the substance they've been told is cocaine. Because you can always trust criminals. If the drug dealers said it was cocaine, I'm sure it was. There wouldn't have been anything else hidden in that package. The only criminals that create elaborate double-cross diversions to hide a more heinous crime are on fictional TV shows, right?

And while we are talking about hiding things from people... why not put that secret passageway in your house like you've always dreamed of? Colonel Mustard won't find you with that damn lead pipe as you covertly move from the study to the kitchen! DIY kits start at just $1500, though I'm guessing that is just for a fancy bookcase with hidden space behind it, not a full room-to-room passage. Still, how cool would it be to twist a candlestick and have your fireplace rotate open to reveal a hidden room? The challenge would be to not show it off to all your geek friends and defeat the purpose of a SECRET room. Of course if all your plushophilia stuff is hidden in there, maybe you'll be extra motivated to keep it secret after all...

~Elphie

Labels: , , ,

Tuesday, March 28, 2006

Microsoft's New Public Bug Database

Yes, you read that correctly.
Microsoft creates public bug database for IE
"Many customers have asked us about having a better way to enter IE bugs. It is asked, 'Why don't you have Bugzilla like Firefox or other groups do?' We haven't always had a good answer, except it is something that the IE team has never done before," Al Billings, a member of the IE project team, wrote in a Microsoft blog Friday.

"After much discussion in the team, we've decided that people are right and that we should have a public way for people to give us feedback or make product suggestions," he wrote.
If you have a violent allergic reaction to all things Microsoft, you'll be able to find something snarky to say about this. IMHO, it is nice to see the old dog learn a new trick. Bash their intentions, make fun of them for following instead of innovating, but at least give them credit for opening their minds to learn from the outside world and finding a way to do something that a year ago was so totally counter to their philosophy it appeared impossible.

~Elphie

Labels: , ,

Wednesday, March 08, 2006

Everything old is new again

hmm, big news week I guess. Too bad this isn't NEW news.
Microsoft Fingerprint Reader Hacked

InfoWorld - 3/7/2006
A security researcher says the Microsoft Fingerprint Reader fails to encrypt fingerprint images, making the device vulnerable to hackers.
Even the researcher points out that the Microsoft Fingerprint Reader says right on the box that it is not a security tool but a convenience for users who don't want to or have a hard time remembering passwords. This translates to me as a power toy for geeks and the forgetful.

The unfortunate thing is how the journalist glommed onto this presentation as groundshaking when Joe Grand demonstrated several ways to hack fingerprint readers as well as several other hardware devices at Black Hat Vegas in July 2005. Joey, I guess you are just ahead of your time...

~Elphie

Labels: , , , ,

Some people dream of success...

I think this is pretty humorous.

"Google has always had a good search, but it was the security side that it's not good at," Ellison told reporters at the annual Oracle OpenWorld Tokyo 2006 conference in Japan.

"We have the security problem solved. That's what we're good at, and that's the hard part of the problem."

- Larry Ellison


That's right, Larry "Unbreakable" Ellison is saying that Oracle has the security problem solved. I guess one theory of success is to "assume you have already won" and act that way. I don't think it is working with this guy though - he doesn't sound convinced to me...

~Elphie

Labels: , ,

Thursday, February 23, 2006

Breaking into Las Vegas

Check out the A Team. I particularly like their specialist in getting things down off high shelves. Alas, a skill I will never master...

www.thecoderoom.com/vegas

oh yeah, you might learn something about developing secure web apps too.

~Elphie

Labels: , , , ,