Pwn2Own Winner to Share Hacking Techniques with Apple

· by · News

Security research specialist Charlie Miller isn’t planning on sharing the exploits he found in Apple’s Safari Web browser to hack a MacBook in the CanSecWest Pwn2Own contest. Instead, he plans to share his techniques with the company so they can improve product security, according to ZDNet.

Mr. Miller used a technique called “fuzzing” to look for potential flaws in applications ahead of the event and uncovered several in Safari along with some in Adobe and Microsoft applications. “I’m one guy working out of my house. I shouldn’t be able to find bugs like these, ever,” he said.

Instead of turning over his exploits to the companies, however, Mr. Miller plans to show them how they can uncover the same flaws.

The companies, and end users, won’t have to worry about Mr. Miller’s work falling into the wrong hands. He doesn’t plan to release the information to the public, and TippingPoint Zero Day Initiative will handle getting the data to Apple, Adobe and Microsoft.

Jeff Gamet

Jeff Gamet

Jeff is the Mac Observer's Managing Editor, and co-host of the Apple Context Machine podcast. He is the author of "The Designer's Guide to Mac OS X" from Peachpit Press, and writes for several design-related publications. Jeff has presented at events such as Macworld Expo, the RSA Conference, and the Mac Computer Expo. In all his spare time, he also co-hosts the We Have Communicators podcast, and makes guest appearances on several other podcasts, too. Jeff dreams in HD.

Sign Up for the Newsletter

Enter a valid email address

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday.

Adding to list…

1 Comments

AlaskaBoy

Sounds like the ‘company’ should be eagerly hiring him (or anyone) as a part-time ‘hacking’ consultant.  If the man can produce proof of the flaws in the program’s security, pay him.  If not, throw the bum out.  Am I missing something here?

Add your comment

Remember my personal information

Notify me of follow-up comments?