Hacking contest bifurcates in Vancouver spat

The Vancouver-based CanSecWest conference plays host to two hacking competitions this year instead of one, following a disagreement between Google and security firm Tipping Point.

Google was slated to take part in Pwn2Own, which is the contest sponsored by Tipping Point's Zero Day Initiative. Researchers in this contest - which offers a total of $105,000 in prizes - present exploits that highlight vulnerabilities in the product. Tipping Point can then pay for details of those vulnerabilities, so that they can be patched. Google originally offered $20,000 in prizes to researchers exposing flaws in Chrome.

However, the search giant pulled out and began its own contest, called Pwnium, for researchers targeting its Chrome browser. The company upped its bounty for details of successful zero-day exploits to $60,000.

Google disagreed with Tipping Point over a particular type of exploit particularly relevant to Chrome: sandbox escapes. These occur when a hacker breaks the virtual sandbox that keeps a system safe from an exploit. Google requires researchers to reveal full details of their successful exploit, whereas Tipping Point only requires them to reveal details of the vulnerability that it used, so that it can code a protection in its own IDS product.

"Full exploits have been handed over in previous years, but it's an explicit non-requirement in this year's contest, and that's worrisome," said Google.

"Sandbox escapes are rare," said Tipping Point in a blog post on the issue. "For the $60,000 they are offering, it is incredibly unlikely that anyone will participate."

The two competitions run from March 7-9.
close

Next Article in SC Canada

THE LATEST ISSUE

Features

Archive of SC Magazine Canada

SC Magazine Canada

THE LATEST ISSUE

Features

Archive of SC Magazine Canada

SC Magazine Canada

More in SC Canada

Bill C-30 falls owing to expense and privacy concerns

After intense opposition from the public, the Canadian government pledged to not introduce additional legislation to monitor online activity.

Critical infrastructure a weak point, says Canadian official

The Canadian government should to make it mandatory for utility companies and others to tighten security, a former official told a security conference.

China-telco partnership fears unwarranted, says Ontario official

The nascent partnership between a Chinese development group and an entrepreneurial hub funded by three levels of Canadian government has raised concerns from an outspoken former security adviser to Nortel Networks.