3 ms·
Amusing how paranoid the browser developers have become about CanSecWest: Pwn2Own browser day: March 9th, 2011 Safari 5.0.4 released March 9th Chrome 10.0
by trotsky 16y ago
Amusing how paranoid the browser developers have become about CanSecWest:
Pwn2Own browser day: March 9th, 2011
Safari 5.0.4 released March 9th
Chrome 10.0.648.127 released March 8th
Firefox 3.6.15 released March 4th
Internet Explorer 8 didn't get a patch this cycle (too cool for school)
Mobile day: March 10th, 2011
iOS 4.3 released March 9th
Nexus S 2.3.3 released Feb 24th
Not sure about WP7 & BB
- jjcm 16y agoTo be fair, Chrome gets updated around every two weeks. That it happened to get pushed out the day before CanSecWest may just be a coincidence. Firefox tends to release a new version every month or so as well Though Mozilla did push 3.6.15 four days after 3.6.14, so it may very well play into your point.
- trotsky 16y agoIt's definitely a known tactic though, here is a tweet from the people who took down safari: @VUPEN: Anti-pwn2own again: Apple fixed a record of 50 vuln. in Webkit (iTunes), and is preparing the update for Safari / Mac OS X... (1:43 AM Mar 3rd via web) http://twitter.com/VUPEN/status/43245159776915456 http://twitter.com/VUPEN/status/43245159776915456 And the trades agree: Mozilla follows Google, patches Firefox as prep for Pwn2Own http://www.computerworld.com/s/article/9212479/Mozilla_follows_Google_patches_Firefox_as_prep_for_Pwn2Own?taxonomyId=17 http://www.computerworld.com/s/article/9212479/Mozilla_follo... etc.
- neilc 16y agoFWIW, Safari 5.0.3 was used for the competition. Besides, if most competitors arrive at the competition with carefully-researched exploits available to use, I'm not sure this sort of last-minute patching would make much difference, even if it was intentional.
- trotsky 16y agoApparently the last weeks code rule was a surprise, I don't think the vendors knew about it. I'm not sure this sort of last-minute patching would make much difference Even if the vulnerability is still there, screwing with the way the binary is built and linked could easily make it so they'd have to put it back in a debugger and retune the exploit.