Safari

Smartphones 1, Hackers 0


iphone_pwnThere were several $10,000 prizes at stake — as well as some free mobile phones — but at the end of the three-day Pwn2Own smartphone hacking contest at the big CamSecWest conference in Vancouver, British Columbia, which closed on Friday, none of the devices had been cracked.

The contest, sponsored by 3Com’s (COMS) TippingPoint computer security division, pitted some of the world's sharpest hackers and computer security experts against five smartphones: an Apple (AAPL) iPhone, a Research in Motion (RIMM) BlackBerry and phones running on Google’s (GOOG) Android, Microsoft’s (MSFT) Windows Mobile and Nokia’s (NOK) Symbian operating systems.

Although the rules were relaxed each day to make hacking easier, the phones managed to withstand the few attempts that were made to "pwn" them — Internet-gamer slang meaning to conquer or gain ownership.

The Web browsers were not so lucky. In a separate contest, now in its third year, the security barriers of Apple's Safari, Mozilla's Firefox and Microsoft's Internet Explorer were breached in the first day — Safari's in less than 10 seconds using an exploit prepared before the contest. The latest version of Microsoft's Web browser — IE8 — fell even before the browser's official release. Only Google's Chrome survived day one. See here.

It's not clear why the smartphones did so well and the browsers so badly. It may be that the devices are too new to have been studied closely. "There's a lot we don't know yet about them," Charlie Miller, the man who cracked Safari so quickly, told CNet's Elinor Mills (link). In fact, there were very few attempts made. Tipping Point's twitter feed mentioned only two: one against a BlackBerry and another against a Nokia phone running Symbian.

But there's no question that smartphones are vulnerable to attack. SearchSecurity.com reports that during one conference presentation a team from Core Security Technologies, a Boston-based penetration testing company, demonstrated how to crack into the iPhone, Google Android and Windows Mobile devices using something called a simulated stack overflow vulnerability.

According to Alfredo Ortega, one of the Core researchers, the iPhone had the most security features, making it the most difficult to crack. Windows Mobile, he said, was the easiest to defeat. (link)

Zero Day InitiativeWhen it’s not running contests, TippingPoint operates its ZeroDay Initiative, in which it pays computer security specialists — also known as “white hat hackers” — a bounty for previously undiscovered vulnerabilities in return for a promise not to exploit them.

TippingPoint, in turn, notifies the vendor and simultaneously develops a patch that it offers to its security clients. Once the vendor has developed its own patch, TippingPoint and the vendor coordinate public disclosure. The researcher can either be given credit for the discovery or, if he or she prefers, remain anonymous.

See also: White hat hackers target the iPhone

Below the fold: the rules of the contest as posted on the CamSecWest website here.

More

Is IE8 the Vista of Web browsers?


IE 8 from Web video

UPDATE: Microsoft's own tests find IE8 faster than Firefox. See links to pdfs here. Independent reports treat the company's tests somewhat skeptically. See here and here.

- – -

I have not tested Internet Explorer 8 — the new version of Microsoft's (MSFT) industry-leading Web browser, which was released here on Thursday. And since Microsoft has made it clear that it has no intention of writing a version for the Apple (AAPL) Macintosh, I may never use it.

However, I've gone through the promotional videos and read some of the early reviews, starting with Walt Mossberg's in the Wall St. Journal, and I gather it's a significant advance over IE7 with some fine new features and none of the obvious flaws Vista had coming out of the box. But it has a fundamental problem. As Walt puts it in the last graph of his laudatory review, damning IE8 with faint praise:

"If it were faster, I would say it was the best browser currently available for Windows." (link)

Microsoft's new browser, according to Mossberg (who is backed up by independent tests  — see here and here), is slower than Firefox, Google’s (GOOG) Chrome, and even the Windows version of Apple’s Safari 4. Which makes me wonder whether IE8 might do for Microsoft's dominant position in the Web browser market what Vista did for Microsoft's monopoly position on the PC desktop.

What am I talking about? Let's go to the pie charts below the fold.

More

Safari market share tripled on Windows after Apple gambit


On March 18, along with the latest version of iTunes and QuickTime, Apple slipped a copy of Safari 3.1 into the Software Update it sent to millions of Windows users — even though strictly speaking the first non-beta version of Safari for Windows was a new program and not an "update."

Critics, among them longtime Apple supporters, excoriated the company for what was widely viewed as an uncharacteristic sleight of hand. They called it "disgraceful," "malware" and a violation of the "trust relationship great companies have with their customers." (See for example here)

What they didn't call it was effective. But data released on Thursday by Net Applications show that the brief experiment worked rather well. During the month that it lasted, the percentage of Safari for Windows users among Net Applications' clients, which had never climbed above .07%, grew three-fold, to .21%.

It might also have helped that the program was getting good reviews, although it's not clear how many Microsoft (MSFT) Windows users would ever have tried Apple's (AAPL) Web browser if it hadn't been shoved in their face.

On April 18, Apple revised its Software Update protocol. New programs are now clearly marked as such and the box to accept them is unchecked by default.

CNNMoney.com Comment Policy: CNNMoney.com encourages you to add a comment to this discussion. You may not post any unlawful, threatening, libelous, defamatory, obscene, pornographic or other material that would violate the law. Please note that CNNMoney.com may edit comments for clarity or to keep out questionable or off-topic material. All comments should be relevant to the post and remain respectful of other authors and commenters. By submitting your comment, you hereby give CNNMoney.com the right, but not the obligation, to post, air, edit, exhibit, telecast, cablecast, webcast, re-use, publish, reproduce, use, license, print, distribute or otherwise use your comment(s) and accompanying personal identifying information via all forms of media now known or hereafter devised, worldwide, in perpetuity. CNNMoney.com Privacy Statement.
CompanyPrice% Change
American Intl Group Inc 35.50 -9.62%
Sunoco Inc 28.12 -9.55%
Continental Airlines Inc 12.86 9.54%
US Airways Group Inc 3.19 7.97%
Nov 6 3:53pm ET †
IndexLast% Change
Dow Jones10,023.420.17%
Nasdaq2,112.440.34%
S&P 5001,069.300.25%
10yr101 1/32Yield: 3.49%
Nov 06 †
CompanyPrice% Change
NVIDIA Corp 13.13 7.01%
Motorola Inc 8.90 -4.40%
Amazon.com Inc 125.88 4.37%
Advanced Micro Devices Inc 5.04 4.35%
Nov 6 3:58pm ET †
* : Time reflects local markets trading time.† - Intraday data delayed 15 minutes for Nasdaq, and 20 minutes for other exchanges.• Disclaimer
Powered by WordPress.com.