<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: HNNCast 111309</title>
	<atom:link href="http://www.hackernews.com/2009/11/15/hnncast-111309/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hackernews.com/2009/11/15/hnncast-111309/</link>
	<description>All content © 2009, 2010 SRT Studios, LLC</description>
	<lastBuildDate>Sun, 26 Jun 2011 22:40:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: tan</title>
		<link>http://www.hackernews.com/2009/11/15/hnncast-111309/comment-page-1/#comment-31</link>
		<dc:creator>tan</dc:creator>
		<pubDate>Sun, 15 Nov 2009 23:18:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackernews.com/?p=837#comment-31</guid>
		<description>Just some after thoughts about that dumb-ass hacker challenge from Wiresoft.

It&#039;s not just that $24k is &quot;chump change&quot; - the problem is that when you see &quot;24 hours to beat our firewall&quot;, anyone who has any experience will read between the lines where it says:

a) When you find something, we&#039;re going to do everything in the world to deny it was an issue with our product.  So, you should video tape your 24 hour attack under the supervision of a notary public because once the window is closed, everything is going to be heresay.

b) If you use an 0day, it&#039;s going to die because when you read &quot;24 hours to hack in&quot; you realize that everything is going to be sniffed, kernel logged and anything else you can think of.  There is also a good chance the vendor will then take credit for &quot;discovering&quot; your bug and killing it, passing no credit on to you.

Another point would be that when you see one of these challenges, you can rest assured that you&#039;re dealing with SNAKE OIL SALESMEN.  Someone who is just &quot;discovering&quot; computer security and thinks they have this great solution already.  But when you see a challenge like this you KNOW they don&#039;t see the bigger picture and whatever their product is has to suffer from that same ignorance.

Investors and Universities need to stop trying to turn student works into commercial product.  Or, if they do, they HAVE to understand that computer security is an industry that suffers MOST from initial impressions and knee jerk reactions.  Things are almost NEVER what they seem at first glance in this game and any great idea that may come out of a University needs a &quot;Sherpa&quot; - not just to give a luke warm &quot;thumbs up&quot; to the high level idea, but to dive into the nitty gritty details of HOW things are done.

Universities teach students programming that solves problems without concern for security.  Security complicates the solution and it&#039;s the solution that is the lesson objective - so we leave it out.  For example, a &quot;secure&quot; code snippet might have 2-3 lines of code for every 1 line of &quot;insecure&quot; code - perhaps more than that even.  So of COURSE these students think they can implement their own ideas - without any clue of how dangerous it is for them to take their classroom coding mentality into an actual production environment.

Heh, so if I were a betting man, I&#039;d say, &quot;I see your $24k and... all in&quot;.</description>
		<content:encoded><![CDATA[<p>Just some after thoughts about that dumb-ass hacker challenge from Wiresoft.</p>
<p>It&#8217;s not just that $24k is &#8220;chump change&#8221; &#8211; the problem is that when you see &#8220;24 hours to beat our firewall&#8221;, anyone who has any experience will read between the lines where it says:</p>
<p>a) When you find something, we&#8217;re going to do everything in the world to deny it was an issue with our product.  So, you should video tape your 24 hour attack under the supervision of a notary public because once the window is closed, everything is going to be heresay.</p>
<p>b) If you use an 0day, it&#8217;s going to die because when you read &#8220;24 hours to hack in&#8221; you realize that everything is going to be sniffed, kernel logged and anything else you can think of.  There is also a good chance the vendor will then take credit for &#8220;discovering&#8221; your bug and killing it, passing no credit on to you.</p>
<p>Another point would be that when you see one of these challenges, you can rest assured that you&#8217;re dealing with SNAKE OIL SALESMEN.  Someone who is just &#8220;discovering&#8221; computer security and thinks they have this great solution already.  But when you see a challenge like this you KNOW they don&#8217;t see the bigger picture and whatever their product is has to suffer from that same ignorance.</p>
<p>Investors and Universities need to stop trying to turn student works into commercial product.  Or, if they do, they HAVE to understand that computer security is an industry that suffers MOST from initial impressions and knee jerk reactions.  Things are almost NEVER what they seem at first glance in this game and any great idea that may come out of a University needs a &#8220;Sherpa&#8221; &#8211; not just to give a luke warm &#8220;thumbs up&#8221; to the high level idea, but to dive into the nitty gritty details of HOW things are done.</p>
<p>Universities teach students programming that solves problems without concern for security.  Security complicates the solution and it&#8217;s the solution that is the lesson objective &#8211; so we leave it out.  For example, a &#8220;secure&#8221; code snippet might have 2-3 lines of code for every 1 line of &#8220;insecure&#8221; code &#8211; perhaps more than that even.  So of COURSE these students think they can implement their own ideas &#8211; without any clue of how dangerous it is for them to take their classroom coding mentality into an actual production environment.</p>
<p>Heh, so if I were a betting man, I&#8217;d say, &#8220;I see your $24k and&#8230; all in&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tan</title>
		<link>http://www.hackernews.com/2009/11/15/hnncast-111309/comment-page-1/#comment-30</link>
		<dc:creator>tan</dc:creator>
		<pubDate>Sun, 15 Nov 2009 04:59:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.hackernews.com/?p=837#comment-30</guid>
		<description>Lead Stories
60 Minutes of FUD
http://www.cbs.com/primetime/60_minutes/video/?pid=v_sxt9cPkCWizFu6IhOxYFpG9jdCcoV6

Romanian Raids
http://www.wired.com/threatlevel/2009/11/romania/

RBS WorldPay Heist
http://www.informationweek.com/news/software/showArticle.jhtml?articleID=221601284

FREE COFEE
http://www.crunchgear.com/2009/11/06/siren-gif-microsoft-cofee-law-enforcement-tool-leaks-all-over-the-internet/

News
SPAM and Botnets Revive without McColo
http://voices.washingtonpost.com/securityfix/2009/11/a_year_later_a_look_back_at_mc.html?wprss=securityfix
http://www.avertlabs.com/research/blog/index.php/2009/11/11/the-mccolo-effect-one-year-later/
http://www.eweek.com/c/a/Security/Botnets-Tighten-Defenses-Year-After-McColo-Shutdown-61350

ACM Attacks CALEA
http://www.pcworld.com/article/181985/how_to_ddos_a_federal_wiretap.html

Courtnee: Outsource Much?
http://news.hostexploit.com/index.php?option=com_content&amp;view=article&amp;id=222
http://www.telegraphindia.com/
http://www.etalkindia.com/computer_technology_news_it_forum/satyam_banned_fo

Another Stupid Hacker Challenge
http://www.darkreading.com/security/management/showArticle.jhtml?articleID=221600869&amp;cid=ref-true

iPhone ALPINE Worms
http://www.darkreading.com/blog/archives/2009/11/worlds_first_ip.html
http://www.theregister.co.uk/2009/11/11/iphone_hacking_tool/


Quickies
http://www.scmagazineus.com/Festi-botnet-appears/article/157294/
http://isc.sans.org/diary.html?storyid=7543&amp;rss
http://risky.biz/unu-gone
http://www.poly.edu/csaw
http://voices.washingtonpost.com/securityfix/2009/11/nastygram_myspace_phish_plants.html
http://www.theregister.co.uk/2009/11/09/bot_herders_coopt_google_appengine/
http://clubhack.com/2009/


Programming Note
http://rcm.amazon.com/e/cm?lt1=_blank&amp;bc1=EEEEEE&amp;IS2=1&amp;bg1=EEEEEE&amp;fc1=000000&amp;lc1=FF0000&amp;t=hacnewnet-20&amp;o=1&amp;p=8&amp;l=as1&amp;m=amazon&amp;f=ifr&amp;asins=B002SFDJMQ

Stack of Shame
http://www.zerodayinitiative.com/advisories/upcoming/</description>
		<content:encoded><![CDATA[<p>Lead Stories<br />
60 Minutes of FUD<br />
<a href="http://www.cbs.com/primetime/60_minutes/video/?pid=v_sxt9cPkCWizFu6IhOxYFpG9jdCcoV6" rel="nofollow">http://www.cbs.com/primetime/60_minutes/video/?pid=v_sxt9cPkCWizFu6IhOxYFpG9jdCcoV6</a></p>
<p>Romanian Raids<br />
<a href="http://www.wired.com/threatlevel/2009/11/romania/" rel="nofollow">http://www.wired.com/threatlevel/2009/11/romania/</a></p>
<p>RBS WorldPay Heist<br />
<a href="http://www.informationweek.com/news/software/showArticle.jhtml?articleID=221601284" rel="nofollow">http://www.informationweek.com/news/software/showArticle.jhtml?articleID=221601284</a></p>
<p>FREE COFEE<br />
<a href="http://www.crunchgear.com/2009/11/06/siren-gif-microsoft-cofee-law-enforcement-tool-leaks-all-over-the-internet/" rel="nofollow">http://www.crunchgear.com/2009/11/06/siren-gif-microsoft-cofee-law-enforcement-tool-leaks-all-over-the-internet/</a></p>
<p>News<br />
SPAM and Botnets Revive without McColo<br />
<a href="http://voices.washingtonpost.com/securityfix/2009/11/a_year_later_a_look_back_at_mc.html?wprss=securityfix" rel="nofollow">http://voices.washingtonpost.com/securityfix/2009/11/a_year_later_a_look_back_at_mc.html?wprss=securityfix</a><br />
<a href="http://www.avertlabs.com/research/blog/index.php/2009/11/11/the-mccolo-effect-one-year-later/" rel="nofollow">http://www.avertlabs.com/research/blog/index.php/2009/11/11/the-mccolo-effect-one-year-later/</a><br />
<a href="http://www.eweek.com/c/a/Security/Botnets-Tighten-Defenses-Year-After-McColo-Shutdown-61350" rel="nofollow">http://www.eweek.com/c/a/Security/Botnets-Tighten-Defenses-Year-After-McColo-Shutdown-61350</a></p>
<p>ACM Attacks CALEA<br />
<a href="http://www.pcworld.com/article/181985/how_to_ddos_a_federal_wiretap.html" rel="nofollow">http://www.pcworld.com/article/181985/how_to_ddos_a_federal_wiretap.html</a></p>
<p>Courtnee: Outsource Much?<br />
<a href="http://news.hostexploit.com/index.php?option=com_content&#038;view=article&#038;id=222" rel="nofollow">http://news.hostexploit.com/index.php?option=com_content&#038;view=article&#038;id=222</a><br />
<a href="http://www.telegraphindia.com/" rel="nofollow">http://www.telegraphindia.com/</a><br />
<a href="http://www.etalkindia.com/computer_technology_news_it_forum/satyam_banned_fo" rel="nofollow">http://www.etalkindia.com/computer_technology_news_it_forum/satyam_banned_fo</a></p>
<p>Another Stupid Hacker Challenge<br />
<a href="http://www.darkreading.com/security/management/showArticle.jhtml?articleID=221600869&#038;cid=ref-true" rel="nofollow">http://www.darkreading.com/security/management/showArticle.jhtml?articleID=221600869&#038;cid=ref-true</a></p>
<p>iPhone ALPINE Worms<br />
<a href="http://www.darkreading.com/blog/archives/2009/11/worlds_first_ip.html" rel="nofollow">http://www.darkreading.com/blog/archives/2009/11/worlds_first_ip.html</a><br />
<a href="http://www.theregister.co.uk/2009/11/11/iphone_hacking_tool/" rel="nofollow">http://www.theregister.co.uk/2009/11/11/iphone_hacking_tool/</a></p>
<p>Quickies<br />
<a href="http://www.scmagazineus.com/Festi-botnet-appears/article/157294/" rel="nofollow">http://www.scmagazineus.com/Festi-botnet-appears/article/157294/</a><br />
<a href="http://isc.sans.org/diary.html?storyid=7543&#038;rss" rel="nofollow">http://isc.sans.org/diary.html?storyid=7543&#038;rss</a><br />
<a href="http://risky.biz/unu-gone" rel="nofollow">http://risky.biz/unu-gone</a><br />
<a href="http://www.poly.edu/csaw" rel="nofollow">http://www.poly.edu/csaw</a><br />
<a href="http://voices.washingtonpost.com/securityfix/2009/11/nastygram_myspace_phish_plants.html" rel="nofollow">http://voices.washingtonpost.com/securityfix/2009/11/nastygram_myspace_phish_plants.html</a><br />
<a href="http://www.theregister.co.uk/2009/11/09/bot_herders_coopt_google_appengine/" rel="nofollow">http://www.theregister.co.uk/2009/11/09/bot_herders_coopt_google_appengine/</a><br />
<a href="http://clubhack.com/2009/" rel="nofollow">http://clubhack.com/2009/</a></p>
<p>Programming Note<br />
<a href="http://rcm.amazon.com/e/cm?lt1=_blank&#038;bc1=EEEEEE&#038;IS2=1&#038;bg1=EEEEEE&#038;fc1=000000&#038;lc1=FF0000&#038;t=hacnewnet-20&#038;o=1&#038;p=8&#038;l=as1&#038;m=amazon&#038;f=ifr&#038;asins=B002SFDJMQ" rel="nofollow">http://rcm.amazon.com/e/cm?lt1=_blank&#038;bc1=EEEEEE&#038;IS2=1&#038;bg1=EEEEEE&#038;fc1=000000&#038;lc1=FF0000&#038;t=hacnewnet-20&#038;o=1&#038;p=8&#038;l=as1&#038;m=amazon&#038;f=ifr&#038;asins=B002SFDJMQ</a></p>
<p>Stack of Shame<br />
<a href="http://www.zerodayinitiative.com/advisories/upcoming/" rel="nofollow">http://www.zerodayinitiative.com/advisories/upcoming/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

