4 ms·
> He told Childs via translator that not only was it was his first time writing Native Client code but it was his first time dealing with a kernel exploit. Wel
by kwentine 12y ago
> He told Childs via translator that not only was it was his first time writing Native Client code but it was his first time dealing with a kernel exploit.
Well, I guess Lee has found a new lucrative hobby for rainy weekends.
More seriously, how can someone possibly own three major browser in two days and on a first try at this kind of sport ? A pretty loud way to shout "Hello World"...
- addandsubtract 12y agoI don't think it's supposed to be read as being hacked in two days. I'm sure he's worked on them before attending the conference, but only presented them on the second day due to the format of the conference.
- lawnchair_larry 12y agoThese exploits are all created well in advance. People hold them for the whole year just to use them here. They're usually made by teams, with one person chosen to run it at the event. At the event, each person brings their exploit and the browser is run against it. Somehow this gets changed to "browser hacked in seconds!" because the media is great like that. That said, it is quite impressive for a newcomer to clean house like this, even if he did have a year to prepare, assuming he wasn't working with a team.
- sanxiyn 12y agoI am a friend of a friend of lokihardt, and yes it was a solo effort. Very impressive.
- spyder 12y ago"People hold them for the whole year just to use them here" But does this mean that they will leave the vulnerability alive for a year, half-year (or whenever before the conference they found it) by not reporting it to the vendors till the conference? Because from the description it looks like it has to work on the latest versions of the browser (for example Chrome 42).
- tokenizerrr 12y agoCorrect. On the other hand, if this contest did not exist they may not be looking in the first place.
- comex 12y agoThis was one of Google's stated motivations for recently changing Pwnium from an in-person event similar to Pwn2Own (and held at the same conference 3/4 times, IIRC) to a more traditional year-round bug bounty. Me, I'm going to miss the experience of sitting at the little dinky hotel cafe with bad Wi-Fi and frantically trying to finish up the exploit before the contest ends. And the press coverage was a bonus...
- anon1385 12y agoThere is another perverse incentive. It has been suggested that in previous years the browser vendors were sitting on fixes and waited till the week before pwn2own to release them.
- JimDabell 12y agoWho suggested that and what reason do they have to believe it?
- ghshephard 12y agoOf course, with $225,000 on the line, who on earth wouldn't leave the vulnerability alive.
- deleted 12y ago[deleted]