Pwn2own considered (somewhat) harmful
lcamtuf.blogspot.com
lcamtuf.blogspot.com
[1] http://jon.oberheide.org/blog/2011/03/07/how-i-almost-won-pw...
There are so many vulnerabilities and exploits developed every year. How can it matter very much if a small handful of them are rewarded more substantially and disclosed using a slightly different than normal procedure? Pwn2own considered a wash, if you ask me.
The problem isn't simply that the procedure is different. It's that the procedure is clearly, obviously, demonstrably sub-optimal. The Chrome bug-bounty, which Zalewski is surely involved with, runs year-round. The incentive is, you find something, you file it with them ASAP before someone else does. The same is not the case with CanSec's Pwn2Own, where, for no reason other than marketing for ZDI and CanSec, disclosure happens at one precise time during the year.
The argument against Pwn2Own is pretty straightforward.
Incidentally, switching from IE for security is tricky. There are some (v. popular) browsers you could switch from IE to that (the C.W. says) would make you more secure; others, less. The IE family has a lot of problems, but "owned by people who don't give a shit about security" isn't one of them.
I always hate reading reports from Pwn2Own every year - "browser y was exploited in less than x seconds!!11!" As the article points out, not only is this very misleading (you might say downright false), this kind of sensationalist journalism trickles down and misinforms the general public about the state of browser security.
I do however think that there is some value with this event as it is one of very few such events to be covered by main stream media for some reason (at least here in Norway), and it puts the fact that browsers aren't always safe in the spotlight even for the general population.
Speaking as a practitioner: we do not want for vehicles for media coverage. CanSec does not improve public understanding of vulnerability research. If anything, as Zalewski points out, it degrades it.
And this is one of the big differences between white and black hats, which I'm sure you're aware of. White hats often find and patch vulnerabilities, but rarely develop full exploits. Black hats are all about full exploits. While intricately related, aren't equivalent.
Somebody out there who has had a bad experience with MSFT is going to shellack me for saying that, but "getting vendors to take bugs seriously" is a really, really flimsy argument for a program that bribes researchers to bottle up their findings.
Note, I based this on SA38416, despite the fact that it appears possible/likely that this vulnerability actually doesn't exist as stated, but it was fine for expository purposes.
1. It is far more public than bug bounties. The browsers that get hacked are in the public spotlight, and that can pressure them into doing a better job in the future.
2. The browsers that put the most effort into security - Firefox and Chrome - did well this year. The article and comments seem to imply this might be a coincidence. There is some element of chance here, so it's possible, however, I don't agree that chance is a major factor. Furthermore, if it was as easy to hack browsers as the article implies, you'd expect all the browsers to be hacked - again arguing against randomness being a big factor here.
Terrible headline and approach to the subject, imo.