Monday, March 1, 2010

FLASH ATTACKS!




You're probably relatively confident in your various machines' integrity against hackers. Repeat Pwn2Own hacking competition victor Charlie Miller would like you to know that you're wrong.

In an interview with OneITSecurity, Miller picks off questions about hacking and security with just enough ease and nonchalance to make me queasy. Like, you know how Mac OS exploits are supposed to be tougher to root out than Windows exploits? Not quite! And they're both vulnerable:

Windows 7 is slightly more difficult because it has full ASLR (address space layout randomization) and a smaller attack surface (for example, no Java or Flash by default). Windows used to be much harder because it had full ASLR and DEP (data execution prevention). But recently, a talk at Black Hat DC showed how to get around these protections in a browser in Windows.

And obviously, Linux is fortress, right? Again:

No, Linux is no harder, in fact probably easier, although some of this is dependent on the particular flavor of Linux you're talking about. The organizers don't choose to use Linux because not that many people use it on the desktop. The other thing is, the vulnerabilities are in the browsers, and mostly, the same browsers that run on Linux, run on Windows.

And within a given operating system, surely you can ensure immunity from exploits by choosing a secure browser like Firefox. Surely. No? GUUUGHHH.

[The safest browser is] Chrome or IE8 on Windows 7 with no Flash installed. There probably isn't enough difference between the browsers to get worked up about. The main thing is not to install Flash!

So the guy who consistently prevails Pwn2Own, a competition where hackers demonstrate exploits for sport, says that Flash, which is installed on about 98% of computers on the internet, unifies all browsers in insecurity. The slightly better news is, despite inherent insecurities that he doesn't bother to elaborate on, mobile smartphone platforms are relatively secure as compared to their desktop counterparts. So there's that.

The full interview is definitely worth a read, even for the tech disinclined—it's a good reminder that you (and you!) can never completely avoid online security threats. So, stay on your toes, and look out for... something? [OneITSecurity viaCrunchgear]

No comments:

Post a Comment