<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Infamous Safari Security Cracker Finds Vulnerability-ish in iPhone OS?</title>
	<atom:link href="http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/</link>
	<description>More of everything iPhone and iPad</description>
	<lastBuildDate>Sat, 11 Feb 2012 03:55:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Mark Asher</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-42084</link>
		<dc:creator>Mark Asher</dc:creator>
		<pubDate>Fri, 24 Apr 2009 03:56:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-42084</guid>
		<description>&lt;p&gt;I don&#039;t think that Miller ever did gain root access with his Pwn2Own hacks. It&#039;s hard to do anything malicious on the Mac without root.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I don&#8217;t think that Miller ever did gain root access with his Pwn2Own hacks. It&#8217;s hard to do anything malicious on the Mac without root.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rene Ritchie</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-41566</link>
		<dc:creator>Rene Ritchie</dc:creator>
		<pubDate>Mon, 20 Apr 2009 03:35:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-41566</guid>
		<description>&lt;p&gt;fassy,&lt;/p&gt;

&lt;p&gt;I think the trouble is people like a puzzle. Just look what happened with domain cache poisoning. Word gets out about an attack, people start discussing it, people stumble upon the method, and suddenly it&#039;s in the wild -- and that was even after it was disclosed to vendors.&lt;/p&gt;

&lt;p&gt;If Miller wants to set up a paypal donate button to make some cash, I&#039;ll gladly click on it. In the meantime, I&#039;d like my iPhone to be as safe as programatically possible, so here&#039;s hoping he discloses vulnerabilities to the manufacturers as he finds them, the he can get his fame at white hat conferences presenting on his findings... after they&#039;ve been patched :-/&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>fassy,</p>

<p>I think the trouble is people like a puzzle. Just look what happened with domain cache poisoning. Word gets out about an attack, people start discussing it, people stumble upon the method, and suddenly it&#8217;s in the wild &#8212; and that was even after it was disclosed to vendors.</p>

<p>If Miller wants to set up a paypal donate button to make some cash, I&#8217;ll gladly click on it. In the meantime, I&#8217;d like my iPhone to be as safe as programatically possible, so here&#8217;s hoping he discloses vulnerabilities to the manufacturers as he finds them, the he can get his fame at white hat conferences presenting on his findings&#8230; after they&#8217;ve been patched :-/</p>]]></content:encoded>
	</item>
	<item>
		<title>By: fassy</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-41557</link>
		<dc:creator>fassy</dc:creator>
		<pubDate>Mon, 20 Apr 2009 00:28:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-41557</guid>
		<description>&lt;p&gt;@Rene:&lt;/p&gt;

&lt;p&gt;Kind of.  He discovered two exploitable bugs leading up to the first Pwn2Own contest, but, since the rules said you can only win once, he used the first right away and held back the second bug.  The next year, Apple still had not fixed that vulnerability -- and nobody else knew about it, since he remained quiet --  so he used it to win the contest again.&lt;/p&gt;

&lt;p&gt;As for whether or not he should have told Apple...well, it is a grey area.  Certainly, it would be verging on (or perhaps actually is) criminal to release details of a bug or how to exploit it before notifying the vendor, but Miller has never done that.  He has just said that there is a vulnerability that could potentially be exploited, and never provided the barest hint of a clue on how it could be done.&lt;/p&gt;

&lt;p&gt;At this point, the ball is really in Apple&#039;s court to do something about this vulnerability -- track it down themselves, give Miller a call, or ignore him as a crackpot.  Given Miller&#039;s history, he seems unlikely to be a crackpot, and if Apple wanted to fix it immediately, they would hire him.&lt;/p&gt;

&lt;p&gt;But also, given Miller&#039;s history of never using an exploit maliciously, Apple seems to be taking the tact nobody else will figure out how to exploit it, and, if they wait a year, they can get the Pwn2Own contest to pay for the legwork and get the details for free in a few months.  I happen to agree with Apple the risk of a wild exploit before the next Pwn2Own is very low, but I find their attitude towards security far more disturbing than anything Charlie Miller should or should not be doing.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@Rene:</p>

<p>Kind of.  He discovered two exploitable bugs leading up to the first Pwn2Own contest, but, since the rules said you can only win once, he used the first right away and held back the second bug.  The next year, Apple still had not fixed that vulnerability &#8212; and nobody else knew about it, since he remained quiet &#8212;  so he used it to win the contest again.</p>

<p>As for whether or not he should have told Apple&#8230;well, it is a grey area.  Certainly, it would be verging on (or perhaps actually is) criminal to release details of a bug or how to exploit it before notifying the vendor, but Miller has never done that.  He has just said that there is a vulnerability that could potentially be exploited, and never provided the barest hint of a clue on how it could be done.</p>

<p>At this point, the ball is really in Apple&#8217;s court to do something about this vulnerability &#8212; track it down themselves, give Miller a call, or ignore him as a crackpot.  Given Miller&#8217;s history, he seems unlikely to be a crackpot, and if Apple wanted to fix it immediately, they would hire him.</p>

<p>But also, given Miller&#8217;s history of never using an exploit maliciously, Apple seems to be taking the tact nobody else will figure out how to exploit it, and, if they wait a year, they can get the Pwn2Own contest to pay for the legwork and get the details for free in a few months.  I happen to agree with Apple the risk of a wild exploit before the next Pwn2Own is very low, but I find their attitude towards security far more disturbing than anything Charlie Miller should or should not be doing.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: iErik</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-41497</link>
		<dc:creator>iErik</dc:creator>
		<pubDate>Sun, 19 Apr 2009 07:00:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-41497</guid>
		<description>&lt;p&gt;@neil&lt;/p&gt;

&lt;p&gt;Get over myself?
For what, being more educated than you?&lt;/p&gt;

&lt;p&gt;&quot;Everyone knows companies often employ hackers and as the article also points out hackers often find holes and point them out to companies&quot;&lt;/p&gt;

&lt;p&gt;Those are ethical hackers... dont comment if you dont know shit about the subject kid. Thanks!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@neil</p>

<p>Get over myself?
For what, being more educated than you?</p>

<p>&#8220;Everyone knows companies often employ hackers and as the article also points out hackers often find holes and point them out to companies&#8221;</p>

<p>Those are ethical hackers&#8230; dont comment if you dont know shit about the subject kid. Thanks!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: zeaguswa</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-41488</link>
		<dc:creator>zeaguswa</dc:creator>
		<pubDate>Sun, 19 Apr 2009 04:17:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-41488</guid>
		<description>&lt;p&gt;I would be way more worried if there were a way to actually use the exploit he&#039;s found.  As it stands its a theoretical exploit that isn&#039;t all that much use.  Its like some exploits in the software that I support that came to liht recently.  They basically amounted to an elevation of privilee IF you already had physical access to a box on the network already.  IOW its less scary than it sounds in both cases.  Its like someone sayin - &quot;Haha!  I can totally steal your wallet... if you hand it to me and then turn away for 30 minutes while I abscond with it.&quot;  Just not worth quite the outrae level, IMO.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I would be way more worried if there were a way to actually use the exploit he&#8217;s found.  As it stands its a theoretical exploit that isn&#8217;t all that much use.  Its like some exploits in the software that I support that came to liht recently.  They basically amounted to an elevation of privilee IF you already had physical access to a box on the network already.  IOW its less scary than it sounds in both cases.  Its like someone sayin &#8211; &#8220;Haha!  I can totally steal your wallet&#8230; if you hand it to me and then turn away for 30 minutes while I abscond with it.&#8221;  Just not worth quite the outrae level, IMO.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rene Ritchie</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-41473</link>
		<dc:creator>Rene Ritchie</dc:creator>
		<pubDate>Sun, 19 Apr 2009 00:02:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-41473</guid>
		<description>&lt;p&gt;I believe with the last two Safari exploits, he didn&#039;t notify Apple but waited and used them to win Pwn2Own instead. At least he didn&#039;t tell anybody about them, but the fact that he said he has no idea whether Apple knows about this exploit means he likely hasn&#039;t told them. Not huffy, just not cool.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I believe with the last two Safari exploits, he didn&#8217;t notify Apple but waited and used them to win Pwn2Own instead. At least he didn&#8217;t tell anybody about them, but the fact that he said he has no idea whether Apple knows about this exploit means he likely hasn&#8217;t told them. Not huffy, just not cool.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: zeagus</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-41463</link>
		<dc:creator>zeagus</dc:creator>
		<pubDate>Sat, 18 Apr 2009 20:26:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-41463</guid>
		<description>&lt;p&gt;It is a stereotype.  Lots of hackers are white or grey rather than black hats.  It&#039;s not clear that he shared exploit code, but rather described a method of running shellcode if one were to exploit a separate (as far as we know non-existent) vulnerability.  He has notified Apple straight away in the past, I don&#039;t see any reason to get all huffy.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>It is a stereotype.  Lots of hackers are white or grey rather than black hats.  It&#8217;s not clear that he shared exploit code, but rather described a method of running shellcode if one were to exploit a separate (as far as we know non-existent) vulnerability.  He has notified Apple straight away in the past, I don&#8217;t see any reason to get all huffy.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Neil</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-41458</link>
		<dc:creator>Neil</dc:creator>
		<pubDate>Sat, 18 Apr 2009 18:08:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-41458</guid>
		<description>&lt;p&gt;@iErik&lt;/p&gt;

&lt;p&gt;Ooooh please, stereotyped?  Get over yourself.  Everyone knows companies often employ hackers and as the article also points out hackers often find holes and point them out to companies....it was just a funny statement....calm down.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@iErik</p>

<p>Ooooh please, stereotyped?  Get over yourself.  Everyone knows companies often employ hackers and as the article also points out hackers often find holes and point them out to companies&#8230;.it was just a funny statement&#8230;.calm down.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: iErik</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-41453</link>
		<dc:creator>iErik</dc:creator>
		<pubDate>Sat, 18 Apr 2009 16:51:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-41453</guid>
		<description>&lt;p&gt;His last sentence wasnt funny at all. You just stereotyped all hackers.
Ever heard of ethical hackers?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>His last sentence wasnt funny at all. You just stereotyped all hackers.
Ever heard of ethical hackers?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Neil</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-41446</link>
		<dc:creator>Neil</dc:creator>
		<pubDate>Sat, 18 Apr 2009 15:00:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-41446</guid>
		<description>&lt;p&gt;Yeah I guess Kevin is right, its about the glory...&lt;/p&gt;

&lt;p&gt;@Kevin&lt;/p&gt;

&lt;p&gt;Your last sentence was mad funny dude.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Yeah I guess Kevin is right, its about the glory&#8230;</p>

<p>@Kevin</p>

<p>Your last sentence was mad funny dude.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin</title>
		<link>http://www.imore.com/2009/04/18/infamous-safari-security-cracker-finds-vulnerabilityish-iphone-os/comment-page-1/#comment-41443</link>
		<dc:creator>Kevin</dc:creator>
		<pubDate>Sat, 18 Apr 2009 14:49:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=8120#comment-41443</guid>
		<description>&lt;p&gt;He&#039;s a hacker, most of the rush isn&#039;t finding the error first, it&#039;s letting everyone know you found it first, right?  Also, you&#039;re last question asks why hackers don&#039;t have morals...really?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>He&#8217;s a hacker, most of the rush isn&#8217;t finding the error first, it&#8217;s letting everyone know you found it first, right?  Also, you&#8217;re last question asks why hackers don&#8217;t have morals&#8230;really?</p>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached

Served from: imore.com @ 2012-02-10 23:05:27 -->
