February 7, 2008 7:34 AM PST

Vista, Leopard, Linux to compete in hack contest

Apple's OS X, Microsoft Windows, and Linux operating systems are to be pitted against each other in an ethical hacking contest in Vancouver next month.

Run by the organizers of the CanSecWest Vancouver 2008 security conference, the competition is a repeat of the "PWN to Own" contest at CanSecWest in 2007, when security researchers competed to win a MacBook Pro and $10,000. The prize was shared between security researchers Dino Dai Zovi and Shane Macauley for their successful use of a zero-day QuickTime vulnerability, which they used to compromise the MacBook. The vulnerability was subsequently found to also affect Windows platforms.

The hacking competition at CanSecWest 2008 will pit the Linux, Leopard OS X, and Vista operating systems against each other, according to CanSecWest organizer Dragos Ruiu.

"The fur is flying right now about which is more secure--Linux, Vista, or Leopard," Ruiu said on Thursday. "Linux guys have their propaganda, Windows guys are saying this and that, Apple guys have buried their heads in the sand as usual. I guess the proof is in the pudding."

The prizes for the contest will be "several laptops," according to Ruiu. When he spoke to ZDNet UK, on Thursday, the security researcher was in Tokyo partly to organize a CanSecWest event and partly to go "shopping for laptops." Ruiu had not yet decided which laptops to buy, but said he was looking for something "new and thrilling."

"We want the prizes to inspire lust amongst geeks," said Ruiu. "It's going to be something lustworthy."

Last year the $10,000 prize money was supplied by security firm TippingPoint. This year's contest still needs a sponsor, and it is possible that the nature of the contest could still change, said Ruiu, although he declined to say what other form it might take.

Tom Espiner of ZDNet UK reported from London.

See more CNET content tagged:
contest, hacking, Apple MacBook, Linux, researcher

Add a Comment (Log in or register) 92 comments (Showing first 20 comments)
Yee-haw! Can't wait for this!
by ejevo February 7, 2008 8:10 AM PST
Oh, this is going to be good. Let the fanbois shut up, and the results will speak.
Reply to this comment View reply
Boy can this be skewed...
by nlakin February 7, 2008 8:33 AM PST
The initial security settings set on each of these machines can vary
greatly. What one expert calls "typical" security setup for each one
of these OS's can greatly skew the results.

They at least should have a rep from each OS to rebut/agree on a
typical setting. This is like a prosecuter presenting a case to a jury
without the defense having a chance to refute the evidence.
Reply to this comment View all 2 replies
Vista will have so many holes...
by supoman February 7, 2008 8:50 AM PST
It'll be like trying to plug the holes in a sponge to keep water inside.
Reply to this comment
On one condition:
by Penguinisto February 7, 2008 9:03 AM PST
That all three are set up with just their defaults.

The last time something like this was done, was a contest in 1999 by Mindcraft... bought and paid for by Microsoft. You can only guess how stacked the odds were. Or, you can read the MSFT flack's admission of same for yourself - here: http://www.itweb.co.za/sections/enterprise/1999/9904221410.asp

(Mindcraft's website is still up, but it's been pretty much defunct since 2003).

--

This time, let's set it up with the ultimate - the defaults, patched to present with whatever patching/update program exists on each OS (All three have one). Fedora Core 8, OSX Leopard/10.5, and Vista w/ SP1.

Then simply turn 'em loose with public IP addys and see what comes of it.

/P
Reply to this comment View all 2 replies
Speed vs Severity
by ittesi259 February 7, 2008 9:32 AM PST
I would like to see this rated as speed and severity taken into consideration. Its one thing to say "I hacked you in 5 minutes" but no good if your hack doesn't do anything. But if you can say "I hacked you in 30 minutes and now I own your system" thats a different story.

I expect all 3 will be hacked. I'd be more interested in whether or not the exploits involve a lot of user interaction like the Mac one did needing to go to a specifically crafted website. User education should in theory prevent such attacks from working, however such is not the case.

As a user of Windows and Mac OS X I say only the following to fanboys of either. Both are gonna get hacked, and thats just the way it is. The only secure piece of software is one that has undiscovered bugs. For those thinking I'm a Linux fanboy for not including it, its because I don't use it myself.
Reply to this comment
Do both
by Lee in San Diego February 7, 2008 9:44 AM PST
Hack out of the box operating systems, the Joe Syxpack
configuration.

Then hack hardened operating systems.
Reply to this comment View reply
OS/2 Is The "Must Have" Operating System...
by Commander_Spock February 7, 2008 10:07 AM PST
... (not "Vista, Leopard, Linux) which will compete in hack an contest) like those Golden Oldies by Elvis Presley. Was OS/2 involved it would have whooped "Vista, Leopard, Linux" hands-down. ;-) !
Reply to this comment View all 4 replies
Vista SP1?
by frankwick February 7, 2008 2:23 PM PST
Will this contest occur before or after SP1 is installed?
Reply to this comment
Real time patches and git clones
by ethana2 February 7, 2008 6:02 PM PST
I look forward to every last security vulnerability getting crushed out of linux, while microsoft and apple hobble along with their closed systems that respond in days instead of minutes to new developments.

This will be entertaining.
Reply to this comment View reply
vista lose? your proof
by rdgadz February 8, 2008 6:24 AM PST
isnt ie7 still the only browser that doesn't allow writing to system files by default?
Reply to this comment
Don't under estimate Microsoft
by wbenton February 8, 2008 6:37 AM PST
Remember this:

>>>The prizes for the contest will be "several laptops,"<<<

If Microsoft offers each of the top hackers $20,000 each to NOT hack Vista... Vista might just stand a chance. It would be worth more than just a mere $20,000 per hacker to Microsoft to come out on top.

And hackers only have a few PC's to win... thus with an amount of $20,000... in cash from Microsoft... the awfulest hackers might just bow out and cash in on a Microsoft hand-out! (* SMIRK *)

Don't think it's possible? Just look at Microsoft's reputation and pocket book as well as the human greed factor! (* GRIN *)

DO NOT underestimate Microsoft!

Walt
Reply to this comment View reply
Without OS/2 this contest is M-U-T-E!
by Commander_Spock February 8, 2008 8:54 AM PST
Since, according to some reports - Russians were said to be the best hackers - yet, the Russian Federation, the International Space Station and a host of other industries around the world continue to rely on OS/2. ;-) !

See: "Usage of eComStation and OS/2 Warp operating systems"

http://en.ecomstation.ru/solutions/

Read the subject line!
Reply to this comment View all 3 replies
Contest in three stages.
by ralfthedog February 8, 2008 10:09 AM PST
Stage I:

Fully patched systems with industry standard security software installed.

Stage II:

Fully patched systems, no security software installed.

Stage III:

Computer out of the box with a post it note saying, "Kick Me" on the monitor.

Give the hackers x amount of time for stage I. If no one wins, go to stage II. If no one wins, stage III.
Reply to this comment View reply
I hope the Macs get shelled
by ferretboy88 February 8, 2008 4:17 PM PST
I hope they really do this right and Linux is proven once and for all to be the most secure. The apple guys with their noses in the air should go home with their tails between their legs. On a side note. If Apple is the most secure I will go out and buy a new macbook again.
Reply to this comment View all 2 replies
This should be interesting...
by mariusthull February 9, 2008 9:52 AM PST
But I would not want to be the one to set the conditions for the test. It's almost like trying to compare apples, oranges, and grapes because of the average group of people that uses each computer.

That being said I would think the most fair test would be this;
Fresh installs of OSX, Vista, and linux. Install the latest updates of each and go from there. Hacks like the quicktime hack should be out of bounds. The reason being quicktime isn't part of the OS. That is also why anti virus and firewall software should not be included. Neither is a part of the OS.
If firewalls and anti-virus programs are added to OSX and Vista would it be fair to use a linux distro in SElinux mode? I'm just curious about this since I'm not overly familiar with SELinux.
Reply to this comment
Linux Fanboys == Commander Spock
by pmchefalo February 9, 2008 10:32 AM PST
In 2017.
Reply to this comment View all 2 replies
Already showing his bias
by i,Jimbot February 10, 2008 10:49 AM PST
Dragos is not much of a scientist. He's showing his bias already in
his comments:

"Linux guys have their propaganda, Windows guys are saying this
and that, Apple guys have buried their heads in the sand as usual."

How can one not be suspect?
Reply to this comment View reply
 See all 92 Comments >>
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • Nanotech: The Circuits Blog

    Timing rumors surface for AMD plant spin-off

    Rumors persist that Advanced Micro Devices is planning to spin off all or part of its manufacturing operations.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Digital Noise: Music and Tech

    Was 1980s music that bad?

    NPR asks listeners which year featured the best music, and the 1980s emerge as a bleak era. Personally, the '80s figure prominently in my collection, but well behind the 1970s.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Digital Media

    Michael Moore plans Net-only film release

    Filmmaker plans to release his latest documentary exclusively on the Internet for free, forgoing the traditional theatrical premiere.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Politics and Law

    McCain talks up oil drilling, green energy

    Republican presidential candidate says we need to drill new wells now, while supporting innovative transportation technologies and "the use of wind, tide, solar and natural gas."

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • Webware

    10 things we'd like to see in Chrome

    Google's Chrome is pretty good, but it could be a whole lot better. We've rounded up 10 fairly extensive ways to tweak it to make it an all-around better browser.

  • Green Tech

    Clean-tech group forms to support Obama

    "Clean Tech and Green Business for Obama" aims to raise $1 million for the Democratic presidential nominee while elevating issues of climate change and alternative energy.