Microsoft offers $100k to hack its custom Linux OS
theverge.com
theverge.com
But my schadenfreude is hoping for an outcome similar to what happened to an old co-worker of mine back in 2005.
He was a Windows nut and we were always in a friendly competition about which ecosystem was the better one. One time he had done a bunch of modifications to his own laptop OS, IDS, and tweaking services to have a slimmed down install with a web server. When he was happy he told me "tell your hacker buddies to try and hack this website hehe" :D
He had put up a simple website offering 1000 USD for hacking into the server it was hosted on. His own personal work laptop, with a bunch of other sensitive stuff on it.
I said, ok... And posted it on a certain mailing list that I won't mention.
We sat opposite each other and within 10 minutes I saw him bend down towards the screen with a worried look on his face. Tapping frantically on the keys.
Within another 10 minutes he had disconnected the computer from the internet and said the challenge was off. :D
Apparently his IDS had been throwing up warnings about md5 checksums being changed left and right. That's all we figured out about it. I was 16 years younger so he didn't want to share much more with me.
Both are equally derailing. In this case, I would much rather the comments be about the actual OS in question or the trend of big companies crowdsourcing security (penetration testing).
These anecdotes provide societal context to the story. Why would Microsoft get the public to harden their product? Surely they have enough resources to do it themselves right?
Because many eyes make light work. Some people would obsess over trying to hack this OS, putting in far more effort than someone paid 9-5 to do it.
I think we could do a lot worse than anecdotes, but what I find weird is how the anecdotes on HN are always so smug, like this one. "Heh, my old co-worker thought my 'little hacker buddies' couldn't hack his website ;b Let's just say they put quite a dent in it heh ;b."
Bit of an eye roll.
Look at this story. Some guy, who honestly seems to have pretty questionable judgment did a thing and it was a bad idea.
What does that really have to do with this challenge from MS about a custom version of Linux? I would say almost nothing.
If his judgment is that bad on a basic level, how bad must it be on a technical level?
The dilemma is that equating absence of evidence with evidence of absence is actually a good long-term strategy in our day-to-day lives. Without this strategy we'd be paralyzed by our own ignorance; particularly, paradoxically, those aware of their ignorance. It's a meta-skill to be able to identify when the heuristic should be discarded in favor of more rigorous analytical thinking. A capacity for analytical thinking isn't sufficient by itself, thus making such an error in judgement doesn't necessarily imply an absence of strong analytical thinking skills. (At least, that's what I tell myself ;)
Anyone who knows about security understands that on a modern system there are so many layers of software / firmware, you never can be 100% sure (well I guess other than powering it off...).
I want to focus on the IoT part.
Do not get me wrong. I am glad MS tries to show they care about security in IoT space. Heavens know I don't want to see Starbucks microwave botnet in 2021.
Except you did, and it's really trite.
They have access. I am not arguing against it. I have memory of what they have done. Should I just forget it?
The embrace started long ago, with things like Samba, a free implementation of vfat, Wine and Active Directory. Extend also started long ago, with things like, getting gcc to run on it, cygwin, the LAMP stack, Firefox - lots of things that let Windows do things only Linux boxes could do, and for free.
Then came extinguish. WinCE followed by WinPhone, and now 1/2 of Azure runs Linux boxes which I guess pretty much signals the fate of Windows on the server arena. Whereas two decades ago most computers an end user interacted with run Windows now they don't.
I understand detailed feedback on huge multi-million dollar industrial machines where proactive maintenance based upon massive ML datapoints can save unexpected downtimes with millions in damage, but on coffee machines?!
(2) Starbucks business depends on having those measurements for quality control
(3) Starbucks gets lots of vendor deals from partner companies because they are a well know brand and having them on board helps land more deals
(4) Hacker using the machines might be able to sabotage the stories; food poisoning, fires, etc
(5) The smarter the tech in store — less training required per employee on site.
(6) Starbucks has other plans for it, such as enabling customers to use their network for IoT devices
(6) etc.
We know that the larger the attack surface the more likely is to get hacked so if Starbucks really cares about everything you said (i.e food safety issues) it should hire more people and less machines.
Starbucks is a massive chain people expect the same thing at any Starbucks they go to. People are very inconsistent, if the coffee tasted different at every Starbucks they would not be as large as they are.
While I understand the urge want to humanize the process, give people jobs, this is not the way to do it.
Future of human employees inside of Starbucks is clearly focused on what the baristas do best as humans, being friendly person that’s humanize the experience of getting coffee.
As for including humans in food safety procedures, what exactly are you referring too? Inserting 30-60 IoT continuous environmental and systems monitoring sensors into a store clearing makes more sense that paying a human to be in the store 24/7 and writing it down on paper. If I am recalling correctly, Starbucks has already saved millions by not letting the on site employees control the HVAC systems.
And so, people want replicable coffee drinks. And coffee can be a fickle beast to brew. Given that, unlike McDonald's which can freeze and ship, you must go from bean to drink on premise in a matter of minutes, I could see a focus on trying to ferret out a way to make that expensive cup taste the same from Portland, Oregon to Portland, Maine.
It is a bit more startling in the United States because it is such a large country. Imagine crossing a reasonable fraction of the globe and the food is still the same! The comfort of the familiar is an incredibly strong lure and I believe it happens in ways that are so broad we can hardly see we are within them, like a bug on the surface of a tidal wave. Food and drink homogeneity is only one of the ways, but is likely one of the more primal. People of a certain age, when given Kosher-for-Passover Coke (still made with sugar) are delighted by the return to what they grew up with.
In any case, Starbucks wants a customer who, perhaps having had their fill of experimental recipes and lunches at new places, can reach for a stimulus just like they had before. It might mean a lot in an airport terminal after nights on a mattress you've never slept on before.
I remember visiting NY and being fascinated by many of the options I've never seen in other countries.
There's a 2013 article on why 30% of Michelin-star restaurants went with Nespresso, which seems to have consistency down: https://www.grubstreet.com/2013/03/nespresso-sold-at-micheli...
It would be weird if Starbucks wasn’t investing in their coffee machines. Make me wonder what they were spending their money on.
What is the strategy here, to make a Chromium like play where the project is open but for practical purposes everyone just uses Chrome? That might not be terrible for the ecosystem
The play (as I see it) was that losing mobile really shook them, and now they have no sacred cows to protect. Developers want and need to develop on linux, so microsoft is making that happen so that they can keep selling software.
Almost as if they assume Linux can be breached, but not their fabulous software. ;)
Linux's security isn't in question anymore, certainly not among developers who would be choosing whether to use Azure Sphere. Linux has been battle-tested for decades, and Linux already won. This is Microsoft embracing it, for better or for worse. And frankly I'd rather have a Microsoft Linux distro on my fridge than a slimmed down version of Windows.
I'd rather just have a plain old fridge, honestly, but we're talking about IoT OSes right now.
Of course. This is Microsoft. The memory of the culture of Gates and Ballmer is not erased.
>And frankly I'd rather have a Microsoft Linux distro on my fridge than a slimmed down version of Windows
Referencing security of fridges reminded me of this https://www.youtube.com/watch?v=BnKpNVHw-TQ :)
Folks apply and then does MS provide each accepted applicant a separate target and some level of access to verify if they were successful?
Mmmmmm.
Seems to be using parts of code from Ubuntu, but that doesn't mean it is Ubuntu.
Problem with these kind of things is you never know how much time you're gonna spend. I was pretty active in this scene when I was going to University and had nothing better to do. But now I don't want to risk a month of my time and potentially end up with nothing. I guess people who compete in these things already have an exploit at hand to start with.