4 ms·
At hacking contest, Google Chrome falls to third zero-day attack
- fjarlq 15y agoWired has a bit of additional coverage: http://www.wired.com/threatlevel/2012/03/zero-days-for-chrome/ http://www.wired.com/threatlevel/2012/03/zero-days-for-chrom...
- nextparadigms 15y agoIt seems the $1 million in awards actually worked. Last time around Pwn2Own hackers didn't even bother to try and hack Chrome.
- gcp 15y agoNot sure. The "undefeated for 2 years" badge also meant that whoever did it first had serious boasting rights. Might end up being worth more than the 60k prize. Saying the prize is 1M (it isn't!) is just eating the marketing.
- nl 15y agoPrevious discussion (which is worth reading): http://news.ycombinator.com/item?id=3677152 http://news.ycombinator.com/item?id=3677152
- troymc 15y agoThat pink pony has a striking similarity to another: http://www.djangopony.com/ http://www.djangopony.com/
- carey 15y agoNot quite. http://moongazeponies.deviantart.com/art/Pinkie-Pie-the-Hacker-208261655 http://moongazeponies.deviantart.com/art/Pinkie-Pie-the-Hack... appears to be the original.
- masklinn 15y agoOnly in that they're both pink and ponies, TFA's pink pony comes from the MLP:FiM show[0] whereas Django's pony mascot comes from "... and a Pony"[1] [0] http://en.wikipedia.org/wiki/My_Little_Pony:_Friendship_is_Magic http://en.wikipedia.org/wiki/My_Little_Pony:_Friendship_is_M... [1] http://www.codinghorror.com/blog/2006/01/and-a-pony.html http://www.codinghorror.com/blog/2006/01/and-a-pony.html (it's older than that, but that's a good enough resource)
- deleted 15y ago[deleted]
- gnuvince 15y agoThough I find these contests very interesting, I can only wish that as much resources was spent to develop a viable alternative to C++ that would make many of those vulnerabilities impossible. Languages like Rust, ATS and BitC come to mind.
- veyron 15y ago> viable alternative to C++ that would make many of those vulnerabilities impossible Could you explain this a bit more? Is there a vulnerability which is specifically due to a C++ quirk?
- kibwen 15y agognuvince may be referring to C++'s lack of automatic bounds checking, which can contribute to exploits via buffer overflows. (But I am neither a security researcher nor a particularly competent C++ programmer, so I may just be completely off-base!)
- gcp 15y agoMany of these exploits use buffer overflows, use-after-free, etc. They're specific to manual memory management.
- luriel 15y agoGoogle is developing Go ( http://golang.org http://golang.org ) and the first 'stable' release (aka "Go 1") should be out any day now. Of course from having a new language to building a whole web browser with it will take some time.
- ootachi 15y agoGo is not suitable for developing a performant web browser engine. The GC alone ensures that.
- runn1ng 15y agoBreaking walls is what Pinkie Pie does, though.