Chrome exploit and sandbox escape demonstrated at CanSecWest, $60k awarded
pwnium.appspot.com
pwnium.appspot.com
Quote: Due to our disagreement about the best way to get the most vulnerabilities fixed, Google has withdrawn sponsorship of Pwn2Own. We understand their reasons for doing so: they want to be able to receive the sandbox escape details to improve the security of their product. That is why they launched Pwnium. What we believe they fail to realize is that, for the $60,000 they are offering, it is incredibly unlikely that anyone will participate. For example, a quote from a prior Pwn2Own winner: https://twitter.com/#!/VUPEN: "Google canceled its sponsorship of #pwn2own and launched its own #pwnium. To win, report your sophisticated exploit. We're not interested!".
http://dvlabs.tippingpoint.com/blog/2012/02/29/pwn2own-and-p...
There is also the fact that anyone in the industry can make a few phone calls and have a bidding war on this type of exploit that will go well into the 6 figures, possibly as high as 7 according to some. $1M sounds high to me personally, but there is no doubt that it will fetch a few hundred thousand.
To my knowledge, the US government is the biggest buyer of unpublished exploits. And they pay a lot more than 60k. One well-known US-based company is even run by a former NSA employee, and they're currently advertising a remote pre-authentication exploit in the latest version of MySQL.
It is also worth noting that breaking into the computer of a foreign national that is located overseas is often not a crime in the united states, or is at least considered very difficult to prosecute if it doesn't involve fraud, financial transfers or a few other hot buttons.
This isn't new, security companies have been paying contractors for unpublished advisories and exploits for over 15 years now.
Selling exploits on the black/grey market is and will always be fast money, and a bad idea.
Pwnium is just there to lower those prices, at least attempt to.
This one exploit is there to be able to say "see, we get those for 60K, why would we pay you 500K"?
When it comes to vulnerabilities affecting modern day
browsers, there are two main categories: code execution
and post-exploitation bypasses (sandbox escapes).
[...]
Without one of these, the second type of vulnerability is
neutered.
The idea is to encourage researchers to divulge only their more common (and thereby relatively less valuable) code execution exploits, as fixing these exploits alone will (according to ZDI's theory) defuse any threat the sandbox escape exploits pose.i.e. if someone reports a working exploit for Chrome, but doesn't tell how, Google has no choice but to investigate as deeply as it can and root out any possibility it can think of, and perhaps do automated checks in all of the source where it could possibly happen.
If you instead point out it's a buffer overrun in file x.c, they'll likely just patch up that one file.
That said, ZDI may have a point that the requirement for the full exploit is unnecessary; seeing the exploit in action might be enough for educated guesswork, thus seeing more exploits might be a good thing (in terms of security, not reputation).
The obvious compromise would be to set two rewards: one for showing the exploit, another for showing its source code, at the hacker's option. By not disclosing the exploit the hacker would give up a higher guaranteed reward in exchange for a chance to make a juicier deal, but they'd be racing against Google's reverse-engineering effort.
How exactly does it hurt the fame angle?
I'm not sure if I'm completely understanding your idea... but in your proposed scenario wouldn't Google be sponsoring a place were the actual attackers that want to screw their users can window shop for working exploits? All researchers would be getting money from Google for participating on their contest, to then sell their working exploit that would take Google a significant amount of time to fix to the highest bidding blackhat/government.
It should not be a blackmail sort of operation.
However, if you factor in the freelance/one-time-only factor, it becomes somewhat more fair, but still really good money.
But then you also factor in the fact that he's using a very unique skill set in order to do this job, one that maybe a few handfuls of people on this planet possess. And then I wonder.
But it's still good money, regardless :)
Also, not to forget is that $60k is a LOT of money to most people that are not .com millionaires.
http://www.wired.com/threatlevel/2012/03/pwnium-and-pwn2own/
"A Google engineer offered Bekrar $60,000 on top of the $60,000 he stands to earn in the Pwn2Own contest if he handed over the sandbox exploit and details. But Bekrar declined and joked that he might consider the offer if Google bumped it up to $1 million. After the Google engineer left the conversation, Bekrar told Wired that money wasn’t the main enticement for him and he had no plans to hand over the exploit to Google.
"The Google security team member expressed frustration at Bekrar’s reluctance to provide information about the vulnerability so that it could be fixed."
http://www.zdnet.com/blog/security/cansecwest-pwnium-google-...
Its success at avoiding attacks has been a great marketing tool for Google.
Even with this Pwnium exploit don't make the mistake of thinking Chrome is an insecure browser. By any measure it is the safest (graphical, full featured) browser around by a long way.
This tweet refers to Pwn2Own, which is the one sponsored by ZDI, and which VUPEN apparently won (without having to share their exploit). The other, pwnium, is the Google-sponsored contest.