All Major Browsers Fall at Pwn2Own Day Two
threatpost.com
threatpost.com
Hooooly shit. That's insane, and if that's what you get from the company, I can't even imagine the price of those exploits on the black market...
100k income per year + 33% for employer taxes, medical/fringe benefits, etc, so 133k.
1.5 years of work at 133k/yr = ~200k payout.
I wouldn't call that low since it already hinges on massively inflated salaries due to massively inflated cost of living for developers in hubs.
That 100k of buying power in SF would come from about a 55-60k salary in my area. (1)
(1) http://www.wolframalpha.com/input/?i=moving+from+San+Francis...
Why would you say that's inflated? Engineering is a professional occupation that requires a high degree of skill and education. Much like lawyers, doctors and other forms of professions. Many of the companies that employ software engineers at those salaries are highly profitable. From big names like Google, Oracle, Facebook, Apple and Amazon to smaller companies like FrogCreek, Atlassian, and New Relic. So why would you say they're inflated? Software engineers are employed by companies with real products, that provide real value. Salaries have been at these levels for over a decade now, in fact there was a big dip after 2000 when pay actually was hugely inflated, but within a few years pay rose again to current levels. I'd say when you've been earning a salary long enough at these levels to buy a home and raise a child that it's a stable market rate and not inflated.
E.g. I've read about landlords who raise their rent because of the presence of a google bus stop nearby.
In 1998 (at about the height of the dotcom bubble) a 1-bedroom apartment in my apartment building was renting for ~$500/month. In 2010 (shortly after the real-estate bubble collapse) that same apartment rented out for ~$1500/month.
Does it seem to you that tech worker salaries explain that 3x increase? Remember that as of last year, tech workers made up ~8% of SF's population.
That is very low according to my memory. I was in Santa Clara in that time and my rent was over $1000/mo.
Now, I wasn't down in SF with all the cool kids. I do remember that SF in that time frame was right at a gentrification inflection where there were really expensive places right next to buildings that should have been condemned, so I'm willing to concede your point.
> Does it seem to you that tech worker salaries explain that 3x increase? Remember that as of last year, tech workers made up ~8% of SF's population.
Yes. That one is easy. Nobody wants to rent to the 92% combined with highly restricted supply.
Even back in the DotBomb days, there was a reason why people were commuting from the Fresno area. (152 would be bumper to bumper at 4:30AM in the morning!)
It was stupid, but that demonstrates how bad things are in the central valley.
So then developer salaries in other parts of the country that are 40-50% lower due to correspondingly low costs of living on this areas are what, then?
Also remember all your local services are done by employees that have to pay rent too, and businesses have to pay rent (that one actually is tax deductible).
These days, I visit Seattle and Spokane a lot. Seattle is of course, a lot more expensive than Spokane, or it is supposed to be. But restaurants are much more expensive in Spokane than Seattle. Heck, across the border in Idaho where minimum wage is a lot less than WA, they are even more expensive than Spokane.
I've lived in Switzerland and now live in China. These places are much more expensive in some goods (like cars, clothes, china is cheap in eating out at least). The differentials are much greater than anything you would encounter in the states.
California state income tax is also more than double that of Michigan's at those income levels.
That really depends on what kind of code you're writing. If you're gluing together web frameworks then, I'm sorry, but I wouldn't consider that engineering, and it certainly doesn't require a large amount of education and skill.
Feel free to disagree with people, but please try to avoid misconstruing their arguments.
In any case I think you're underestimating the value of benefits provided by large tech companies. Free food, top-end health insurance, maternity/paternity leave, gym memberships, retirement contributions, bonuses, etc. all add up. I've commonly heard the rule of thumb that total cost-to-employer is roughly $2N for an employee making $N in nominal salary.
The point about location is reasonable: it's harder to get a six-figure salary doing remote work, which is effectively what this is. Still I think people shouldn't be shocked about the amount of money in play here. Given the risk, it's a good payout but not a great one for someone of his (clearly very high) skill level.
The higher your salary the less your employer is paying as a percentage of your income. There's very little difference in overhead between someone making $100k and someone making $150k. The overhead difference will only be a few thousand dollars more for the person making $150k.
Logically, you would think so, but remember that many benefits scale with salary/seniority. Things like retirement plan matching and vacation accrual rate. Also perks like better offices, parking, "training" in attractive destinations.
Is it really fair to say developer salaries around the $200k mark are being inflated?
Developers work can have an impact on millions of people, yet we keep expecting all of this work for a $60k salary.
I've found that only developers/programmers do this self flagellation, almost all other professions complain about $200k being too low, not too high, and expect more. (Lawyers, Doctors, and even some electrical/mechanical engineers)
It's just a shame, as I find it hard finding good work as a programmer as my peers fight for lower and lower salaries.
I had a naive hope that this industry would mature and fight for higher salaries, but whenever I see programmers getting paid half that of a Lawyer or Doctor, self flagellation start to come into play.
Such as shame for an industry with the most potential to change the world.
I rented a 1700sq ft, 2 bed room, 2.5 bathroom, 2 story townhouse a 25 minute drive from Downtown Atlanta for $850/mo, and it had some luxury and I could have easily found lower prices than that moving a little further out (longer commute) or lowering the size/luxury.
225K is low compared to the standard? What standard are you talking about?
Either way, very impressive and well deserved.
Come on, how many bugs do you produce, while writing code? Do you bet 500$ that you are bug-free? Do you bet 500$ that the libraries that you are using are bugs-free? I don't.
In this sense I think guys like him are having a way of thinking more similar to a gamer : "I need to do this and I come to the next level, but the experience playing is more important than the next level!"
So... I doubt he thinks there's a 50% chance. He's just too good "gamer" and he knows the games so good that he actually won the four different versions of it.
Depends on location.
It's like the stock market. In the long run there are no miracles.
Many vuln research/development companies do offer bonuses for every effective exploit you write though, in which case it probably is better to work for such a company than to rely solely on bug bounties and competitions for income. Unfortunately, those same companies usually sell the exploits to the NSA and the intelligence agencies of other governments.
You can still sell your exploit to the black(site) market and later collect a bounty on it. You take some risk that someone else finds it or the party you sold it to leaks it.
Price accordingly.
Sounds like a good way to make dangerous enemies.
Legitimate question: What’s the difference?
So they don't actually intend to hire this guy?!
I'm trying to fully understand. Does this mean that by maliciously crafting a website, someone can get SYSTEM access on a windows machine just by getting someone to visit that site in Chrome?
And what does SYSTEM access mean? Is that user-level privileges or admin privileges?
These types of exploits pay well because they are extremely difficult to pull off, as they require multiple exploits to break through the browser security, out of the sandbox, and through the OS protections.
These types of exploits are probably only used by very well financed organizations in carefully targeted ways, so as to justify the huge cost of finding them and keep them unnoticed and unpatched for as long as possible. See the recent stories on the Equation group-associated malware. You and I are probably safe enough, but somebody like Edward Snowden better be very careful where he surfs.
Starting to think that running apps within a container is the right way to go.
It's turtles all the way down.
You're better of not being somebody anyone would invest that kind of effort to hack. Or at least making your traffic not identifiable as somebody that your opponent would want to hack.
Last I checked, holders of large amounts of Bitcoin tend to avoid letting their identity be associated with their accounts easily, and that's probably why. I bet somebody would be willing to risk a few $100k exploits to get a few $million worth of BTC.
...
Unplugged from the mains.
If you're talking about something like Linux containers, note that the Chrome Pwn2Own exploit involved a sandbox escape via a kernel exploit. (Though seccomp-BPF mitigates this to some extent on Linux.)
Repeat as many times as necessary based on your paranoia levels. Inception.
But your comment reminded me that if I ran a virtual VAX and then a virtual Windows on top of that and a browser in the windows, breaking out of the 'guest' into VMS would really challenge the bad guys tool box in terms of zero days :-) Fun to contemplate on a Friday afternoon.
Anyone who builds an exploit like this is not going to waste it. It's either going to be used in targeted attacks, or reserved for pwn2own. They're not going to burn it by leaving it on some hacked site to get used on your grandmother.
Those types of attacks happen after the exploit is already known and has patches available. The good stuff trickles down, and the early days of active exploitation are more or less restricted to those with the deep pockets and legal impunity.
You are many times safer on the web if you have the discipline to use noscript properly.
Layout (just to name one non-JS subsystem) has been responsible for a lot of vulnerabilities too.
This will probably seem quite shocking, but I almost exclusively used IE6 for a few years, with JS disabled - and despite frequently visiting the "darkest corners" of the Internet, was never exploited. On the sites that tried, I'd just see a blank page; view the source, and there was a blob of obfuscated JS.
edit: case in point, someone posted about it right before and it's downvoted. Good job!
2) /r/programming and other software development subreddits are actually closer to slashdot's ideologies (excepting /r/webdev where performance is an overrated thing)
The good news is that HN seems to be slowly going back to a more old school mindset. At least you can criticize javascript.framework.of.the.day.js without being showered in downvotes, as opposed to a year ago.
The real nightmare scenario is when developer machines get hacked and attackers get access to source, but also to build servers where they can inject binaries into the web deployment stream, which themselves exploit end-user browsers. This is, I think, a very good reason to not give devs any access to build/CI servers. (Ironically, actual endpoint servers are slightly less critical to secure from devs.)
Virtualizing and sandboxing the browser in a secure way is the only way out of this. On top of an eventual move to memory safe languages.
1. facebook where the NSA are checking on you
2. faceskibook where a Russian hacker is going to own your pc
You whitelist the sites you trust. Then if any of those sites get hacked, there will likely be a line added like <iframe src="http://evil.com/exploit.html">, or <script src="http://evil.com/exploit.js"></script>. NoScript will always prevent those since whitelists are domain-specific. So unless the malicious Javascript is added 100% inline on the compromised site (which is easy to do, but is done less often for a variety of reasons), you're going to be safe.
And, obviously, you do not whitelist random sites you click off of Google searches or from emails without validation.
The attack against Forbes.com is a good example. That is a site you would have whitelisted and the attackers compromised that website to then elevate access to the people browsing that site (government employees specifically targeted).
http://www.forbes.com/sites/thomasbrewster/2015/02/10/forbes...
NoScript will very often block exploit chains from occurring even if it won't necessarily always block stage 1.
If you're careful about what you whitelist, NoScript adds a lot of additional security.
Forbes.com is mentioned, here's what else is on that web page after enabling forbes.com:
Blacklisted: doubleclick.net, optimizely.com, bluekai.com, scorecardresearch.com, googletagmanager.com
Other: forbesimg.com, gigya.com, sail-horizon.com, amazon-adsystem.com, media.net, garble.cloudfront.net, chartbeat.com, mediavoice.com, .............
Do YOU trust that ALL of those sites got their Javascript secure? BWHAHAHAHAHAHAHAHAHAHA!
And, let's not even start with all the people who run "Blogoblather 0.4.5" (it will never reach 1.0) who could just post a static web page. No, I don't want to discuss this, and no I'm not logging in. Oh, and, gee, if it were a static web page, if you do get featured on Reddit, YOUR SERVER WON'T FALL OVER AND DIE accessing a database that doesn't have any comments other than spam anyway.
I find that the vast majority of websites run perfectly fine with NoScript. What exactly qualifies as a modern website?
Even if they do "require" JS, you can enable one or two of the scripts that are actually necessary and keep the 22 ad/tracking/various-other-third-party scripts disabled to minimize the attack surface.
Other than that, I agree with you. I never enable JS for a random site, I also "move on to the next search result".
Even budget servers now a day can handle thousands of requests per second, so there is no benefit in offloading "server stuff" to the browser client.
I do have to add some sites to the white list though.
It's a disingenuous and silly argument.
Recently, my users have been hit by fake DHL/UPS "track your shipment" mails, and some of them were sufficiently un-paranoid to click on the links provided by the mails, which apparently just showed a generic-looking 404-page.
Which might mean that the offending page had already been taken down. But on the other hand, with these exploits, that can already be enough to infect an unsuspecting visitor.
Well, one more reason to use Dillo, I guess.
My interpretation of the article is that he managed to escalate far enough to get into the kernel, allowing him to to modify some data structure to give a user land process higher privileges.
So, the overall process could be something like Chrome escape => windows driver vuln => full control of the system.
Or, I believe, through any of the other Windows browsers. There was nothing Chrome specific about getting SYSTEM access.
All browsers were pwned, and Lee used kernel driver bugs to elevate privileges. That exploit could have been used in tandem with any of the browser exploits on Windows. Once you can run arbitrary code...
SYSTEM is arguably not a user, because a user has things like a password, groups, and other user properties. SYSTEM on the other hand is a built in low level security context which cannot be removed, altered, or shared across a network. You cannot login as SYSTEM, but processes can run as SYSTEM. It has a static SID on all Windows systems as S-1-5.
Some of the processes that run as SYSTEM in SYSTEM: ntoskml (Windows Kernel), all drivers, and all interrupt handlers. A few key services (not all, and fewer every release).
Literally it doesn't get higher than NT AUTHORITY\SYSTEM on Windows. The administrator account no longer exists on most Windows installations at all, and the administrators group is just that, a group.
It is like root on UNIX, if the root account had been configured to disable interactive login and to allow sudo only.
PS - SYSTEM is sometimes called NT AUTHORITY in documentation. I've seen it called both, I've also seen it called "NT AUTHORITY\SYSTEM." I believe the NT AUTHORITY is referring to the lowest level of permissions within the OS, and SYSTEM is at that level/root of the permissions table. So really NT AUTHORITY and SYSTEM are equivalent.
Which is what Ubuntu actually does :)
S-1-5-18 is the SID+RID for "NT AUTHORITY\SYSTEM". S-1-5 is just the "NT AUTHORITY" prefix.
There's a trick to do this, I only remember it well for XP (via task scheduler/at command) but it's possible for the newer versions too.
In Windows, Administrator is not the true root.
It's occasionally useful to run regedit as SYSTEM.
Another way to accomplish it in XP & such was by copying cmd.exe over one of the default screensavers (which are also just regular programs). When you're at the login screen the screensaver gets run as system, thus giving you the equivalent of a root shell. Launching explorer from it would result in a new user profile being created in explorer and you'd be "logged in" as SYSTEM, but not really.
Well, I guess Lee has found a new lucrative hobby for rainy weekends.
More seriously, how can someone possibly own three major browser in two days and on a first try at this kind of sport ? A pretty loud way to shout "Hello World"...
At the event, each person brings their exploit and the browser is run against it.
Somehow this gets changed to "browser hacked in seconds!" because the media is great like that.
That said, it is quite impressive for a newcomer to clean house like this, even if he did have a year to prepare, assuming he wasn't working with a team.
But does this mean that they will leave the vulnerability alive for a year, half-year (or whenever before the conference they found it) by not reporting it to the vendors till the conference? Because from the description it looks like it has to work on the latest versions of the browser (for example Chrome 42).
Me, I'm going to miss the experience of sitting at the little dinky hotel cafe with bad Wi-Fi and frantically trying to finish up the exploit before the contest ends. And the press coverage was a bonus...
Microsoft Windows: 5 bugs
Microsoft IE 11: 4 bugs
Mozilla Firefox: 3 bugs
Adobe Reader: 3 bugs
Adobe Flash: 3 bugs
Apple Safari: 2 bugs
Google Chrome: 1 bug
$442,500 paid out to researchers
Looking at these figures, am I the only one who think competitions are not the most effective method for finding bugs? Of course, 21 bugs is not small and $442,500 is not much, but when you think those researches spend months of their time for finding those bugs, wouldn't it be more appropriate to use that money on proper security audits? (I know it will cost more but would be more effective overall?)Major points:
- You register for which browser + os combination[0]. Then they randomly order the contestants.
- When you are called, you have 30 minutes.
- The user browses to a particular piece of content that you specify. Then no further user interaction is allowed (like clicking a dialog, downloading a file). [1][2]
- The prize money goes to the first successful exploit. Money differs by browser.
[0] Chrome, Firefox, IE, Adobe Reader in IE, Adobe Flash in IE. Safari on OSX. Fully patched OS.
[1] How does one get to specify the content? What if I have a http header that downloads a file?
[2] I remember back in the day, they used to have a fully no interactive version? Like the user was just on the same wireless network?
That makes more sense. Otherwise, this is movie-script-like hacking ability.
Windows-based targets:
1. Google Chrome (64-bit): $75,000 (USD)
2. Microsoft Internet Explorer 11 (64-bit with EPM-enabled): $65,000 (USD)
3. Mozilla Firefox: $30,000 (USD)
4. Adobe Reader running in Internet Explorer 11 (64-bit with EPM-enabled): $60,000 (USD)
5. Adobe Flash (64-bit) running in Internet Explorer 11 (64-bit with EPM-enabled): $60,000 (USD)
Mac OS X-based targets:
1. Apple Safari (64-bit): $50,000 (USD)
http://googleonlinesecurity.blogspot.com/2015/02/pwnium-v-ne...
It feels like, just the fact that this competition and other bug bounty programs exist, means that the big companies here have gotten over reputation tarnish and know that the patch is worth it.
I'm pretty sure no system ever is going to be as exploitable as Windows.
Do you mean that they used to sell the exploits to other hackers at Pwn2Own?
http://blog.chromium.org/2015/02/pwnium-v-never-ending-pwniu...
Nohig ethical at all going on here.
For awhile, a lot of them came from fuzzers; if you're interested in how that works, strong recommend for Zalewski's blogs on his open-source "american fuzzy lop" fuzzer.
Browsers are huge attack surfaces, as complex as operating systems, with different modules of wildly different quality. There are lot of bugs to find.
The process makes more sense when you grok how much effort goes into getting privileged RCE from a hardened browser. Nobody can sit down with that code and pull one of them out of thin air on the spot.
The software is a fuzzer.
I think much of it is just a bit of luck that you're looking in the right place.
Many of those were pretty simplistic... fortunately for almost everyone at the time, the browser wasn't a widely used method of exploit, and to my knowledge compromising distributed computer networks via such compromises and ad networks wasn't thought of either. Though by 2002/2003, I had started blocking Flash, Java and Adobe Reader at home when I saw what could be done in the browser.
More concrete answers of your questions guessing :
1. By brute forcing with popular techniques for buffers overflows ;
2. By tracking what the browser is doing via debuggers and trying to match a kernel bug with it ;
3. By reading a lot about latest exploits on the internet and connecting the dots.
What I think nobody from them is doing :
1. Analysing open-source code ( basically try to find the exploit by reading the code ) ;
2. Studying 5 years CS before doing this
4. By using various forms static/dynamic analysis (taint analysis, fault propagation, fault injection).
5. By fuzz-testing the software.
Taint analysis is looking at which registers/memory locations you have access to. You inject data into a process and then check where in memory that data shows up, which execution branches are taken, which registers are used with the data, what the stack does, etc.
Fault propagation looks at where errors and faults are handled and how they are handled. The idea is to get a good idea of how a process manages errors and then find an error that is not handled (correctly).
Fault injection is injecting errors into a process and then watch the fireworks. Think of this as the brute-force approach to fault propagation analysis.
Fuzz testing is bombarding the process with semi-valid/semi-random input and watching what happens. There are many tools with this. Example output for browser-fuzzing could look like this:
<html>>style="\>>overflow:none"></body><html>
Obviously none of today's browsers would be exploited by that, but with mutli-threaded rendering, memory management, javascript reading/writing html and all that stuff going on at the same time it's not surprising that fuzz testing can turn up lots of errors (though not all exploitable).
Looks like some code analysis tools helped for one researcher.
http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2O...
I wonder how the score would go if linux and bsd targets were present and if they allowed chrome and firefox on mac os x as well...
There's probably some headroom left for escalating valuations for browser RCEs, but they're not like an order of magnitude mispriced.
Also remember you're looking at the subset of bugs with the absolute peak valuation.
(I'm both ideologically opposed to bug sales and not smart enough to get RCE on Chrome, so: take this with a grain of salt).
Yup: it's a known crashing string: http://venturebeat.com/2015/03/20/these-13-characters-will-c...
Keeping the public just means if you want own people's machines you could scan the bug database for bugs marked as "security" and exploit to your heart's content until they were fixed.
It does make for a massive attack surface with the massive amount of complexity a modern browser brings to the table, however it's also giving us a truly Operating System agnostic world. (I think? Javascript based applications are OS agnostic right?)
The browser may become a universal operating system, where web applications become the norm and it brings an end to the Linux vs Windows vs Mac wars.
Who knows?
Pwn2Own 2015: Day 1 Highlights -- https://www.youtube.com/watch?v=X2Ssw2sLUHI
Pwn2Own 2015: Day 2 Highlights -- https://www.youtube.com/watch?v=V99skqmTyiY
To me this just confirms that no matter what the proponents say, Google native client is just another form of active x, just with a Google badge this time.
Letting a website run native code on your machine is a terrible decision, and completely disrespectful to your users.
Needles to say, I'm not going to switch to chrome anytime soon.
That said - Native Client doesn't seem to be used for anything on the web. It might have been useful if other browsers had adopted it, but with Mozilla pushing asm.js I wonder at what point they decide to pull the plug on this ...
Does that mean it took 2 minutes for script to finish it's job?
Literally every browser is unsafe, and has always been unsafe. There's zero reason this should be the case. Transferring documents online is not that hard a problem. Perhaps blinging out all the latest features for all the latest ad companies is not worth the cost to users' system security.
Even if every computer was running an operating system that was developed as carefully as equipment in charge of people's lives, I'm sure there'd still be vulnerabilities. The low hanging fruit is relative, and there'll always be people cracking computers.
The main problem is that what used to be called "mobile code" before smartphones were a thing is really convenient. That's why Java tried it too. Sandboxed code helps a lot, so there's this constant tension between trying to make the sandbox less restrictive and keeping it secure.
Sometimes I think that despite poor execution the JVM guys had the right idea. Sandbox code from the net, but also have code signing to fall back on.
As for rarely used, I'd guess Google Maps is a pretty well used site that uses WebGL.
You're right, Google Maps is a good example of WebGL use. But it could also just be a regular desktop app. People would download it just fine.
The web looks and works pretty much how it did 10 years ago. Almost every new feature is just a replacement for an old feature that did the same thing but not as well.
We've gone from plugins to add features to building the features right into the browser. We've gone from tens of megabytes to hundreds of megabytes just to render some text and images. There is literally too much code to audit. I think even kernel hackers would have trouble understanding the complexity of modern browsers.
In 20 years, do you expect the web will be significantly different than it is now? The interface might change, but you can't really innovate on text and pictures.
Although the length of your post worries me that you might actually believe what you are saying.
Please check out the Bananabread example on mozilla's developer page (just search it on your favorite search engine). Please do not post such comments again, there are people on here that will not realize you're joking.
> Please do not post such comments again, there are people on here that will not realize you're joking.
What is so dangerous about someone having the opinion that HTML shouldn't get more features? This "be careful what you say"-tone is so weird to me, on this topic.
> Bananabread
A 3D shooter in the browser. So what? Yes there are advantages to having this power, but not everyone is going to agree that it is worth it.
Having to support old tech lengthens development and testing time quite a bit. We need more browser features so we can write less code, only write it once, and distribute self-contained components.
A website is literally just text and pictures. And video. That's it. We really don't need it to be so massively complicated, to suck up so many resources, and to be such a security nightmare.
In 20 years, your browser will probably use a gigabyte or two of ram minimum, require four CPU cores, and consist of several hundred thousand lines of code - maybe a million.
To render text.
Yes and that is one of the exciting innovations being worked on right now, web components. That's exactly why I brought it up.
Some websites are just text and pictures, it is true. We call them brochure-ware. But not the sites I work on. I build applications for managing your entire business. They are just text in pictures in the same way that a PC is just text and pictures. Should we halt innovation on computers in general? NASA's flight control systems are really just calculators if you break it down as you have done with the web.
At the worst you sound anti-technology, and at best, snobbish about your area of specialty. Implying that whatever you work on is important, but things others work on are 'just text'.
Aah, a Luddite, seize him!
Maybe it's not anti-technology as much as anti-cram-everything-into-the-browser. Some people think that full-fledged applications should be kept out of the browser, but that doesn't mean that they think that full-fledged applications shouldn't exist at all.
And CSS, which supports transform and animation and is inching towards Turing completeness, and javascript, and maybe HTML5/Canvas and WebGL.
Like as not, we seem to be converging towards a point where websites are as much applications as documents.
I'm not saying this excuses the industry, but that doesn't change incentives. If you want more secure services, you need to change the preferences of the users.
throw it all away and rewrite it all again in two years when even newer features get added to the browsers!
Here's an idea: make your own browser that competes with Chrome for usability, offer a huge prize for anyone that hacks it. It's easy, right?
Transferring is the easy part. Rendering them is the hard part.
Suddenly it doesn't sound so reasonable.
CP67 was an abbreviation for control program 67 for the IBM 360/67 computer of, right, about 1967 and was developed by the IBM Cambridge Scientific Center as a means of interactive, time-sharing development of operating systems.
Later commercial time-sharing services used CP67. So, could have a few dozen users, each writing whatever code they wanted, e.g., assembler since it was a good environment to make developing assembler code easy, with, as far as I know, no user ever hurting the CP67 code or the work of any other user.
So, right, CP67 was the first or one of the first cases of virtual machine. Its security provisions appeared to be absolute -- run any code at all, including privileged code, e.g., including operating systems, including CP67 itself, with full safety and security.
Two years or so later there was Multics from MIT Project MAC. It featured capabilities and attribute control lists (still with us). As far as I know, they worked fine. For some years there was a Multics in the basement of the Pentagon and regarded as secure computing. Later Prime Computer did something quite similar and claimed that they had a prize for anyone who could break their security.
Later IBM revised CP67 and called it VM, and since then it has been from common to standard for the IBM mainframe operating systems to run on VM instead of on the bare metal. There have been decades of high end production systems running on VM. I haven't heard about any security holes.
As of a few years ago, a list from Microsoft of security holes fixed included at least one based on a "buffer overflow" bug. Gads: If as recently as a few years ago Microsoft still had buffer overflow bugs, one has to question if by then they much cared about computer security at all. Buffer overflow bugs -- that's Programming 101 for middle school.
I just checked Firefox 35.0.1 and couldn't find where to turn off JavaScript. For the Web pages at my Web site, I have so far not written a single line or character of JavaScript and hope never to, although Microsoft's ASP.NET does write some for me -- and I do wish I knew what ASP.NET classes or options I used to cause Microsoft to write any JavaScript for me.
The old first rule of computer security was to separate code and data, and never but never let data from an untrusted source run as data. Never. Not once. For any reason.
So, in light of this first rule, we have JavaScript downloaded with the HTML text and markup of a Web page and executed. So, I want a very, very, very clear, careful, rock solid, expertly reviewed, as close as possible to proofs of correctness evidence that it is impossible, absolutely, positively totally, without any possibly of exception, for code, any code at all that could possibly exist, in JavaScript that could cause my computer any problems at all, and otherwise just block it. Nothing to do with it. Dump it.
Computer viruses have cost me about half my time so far this year, and I want nothing to do with more computer viruses. JavaScript? Totally glad to junk it.
As I recall, not so long ago, Firefox had Java enabled by default! Outrageous. And at times in Microsoft's Internet Explorer had to be careful to disable Active X, which could run any code at all.
JavaScript? I want nothing to do with pull downs, pop-ups, roll-overs, the screen jumping around for no good reason, etc. Just HTML and CSS -- fine with me.
HTML was just a word-whacking mark-up language -- fine. But, yes, for user input it has text boxes, multi-line text boxes, check boxes, and radio buttons. Okay. Should be able to implement those safely enough.
Can we start to take computer security seriously? When are we going to start?
E.g., Microsoft has gone from Windows NT to 2000, XP, Vista, 8, 8.1 etc., but where in there is the solid security? They have the Start button, remove it, put it back, the Metro interface, tablets, phones, etc., but what about computer security?
I don't give even one weak little hollow hoot about touch screens, but I care a lot about computer security.
CP67 ... security provisions appeared to be
absolute -- run any code at all ... with full
safety and security.
There have been decades of high end production
systems running on VM. I haven't heard about
any security holes.
Sadly, that's not true at all. I ran both CP67 and VM oh so many decades ago, and it was quite useful as a means for non-malicious people to share expensive computers. But they had vulnerabilities.Once upon a time, perhaps 40 years ago (it's been very long, my memory is hardly exact) some IBM employees/researchers started with either CP67 or VM source code (I forget which) and found literally dozens of bugs and/or usable exploits for it.
Source code was not an unreasonable starting point, since IBM published all this code on microfiche, and also probably on mag tape.
IIRC many/most of the exploits revolved around emulating the I/O channel architecture, channel programs, and corresponding SIO or SIOF instructions.
They wrote the whole thing up in a prestigious publication, perhaps the IBM Systems Journal or Communications of the ACM or maybe ACM Computing Surveys. I did a very quick search but couldn't find that particular discussion.
Edit: I may have found the original paper. First I found:
A Taxonomy of Computer Program Security Flaws, with Examples
https://cwe.mitre.org/documents/sources/ATaxonomyofComputerP...
in which they reference a 1976 IBM paper that discussed many VM vulnerabilities. Here's just one of multiple times they cite that paper:
Case: I2
Source: C.R. Attanasio, P.W. Markstein, and R.J. Phillips, ‘‘Penetrating an operating system: a study of VM/370 integrity,’’ IBM Systems Journal, 1976, pp. 102-116. System: IBM VM/370
Description: By carefully exploiting an oversight in condition-code checking (a retrofit in the basic VM/370 design) and the fact that CPU and I/O channel programs could execute simultaneously, a penetrator could gain control of the system. Further details of this flaw are not provided in the cited source, but it appears that a logic error (‘‘oversight in condition- code checking’’) was at least partly to blame.
Of course, the first thing someone will write for it is LISP, thus invalidating your "old rules of code" by using "old code design".
These days, one can run OS from an FPGA without impossible effort. If I had significant financials at stake, that's what I would be doing.
I have had no losses, time or money, from viruses, worms, trojans or otherwise in my 25 years of computer use. I must be just lucky.
And because the attack surface was much smaller: No TCP/IP, DVDs, thumb drives, etc.
The Chrome and Firefox bugs are probably exploitable on Linux too.
I've always thought surfing on safari mobile was the most secure way of surfing (because of the sandbox, but also partly because of app store pre-release evaluation policy that limit the risks of installing a malware ).
But since you asked, I would be a lot of money Opera is vulnerable to the same bugs as Chrome since it's using the same rendering engine.
Perfect example of this right now are all the "Is Apple Pay causing fraud?" news stories. The fraud has nothing to do with Apple Pay. The fraud is happening because banks are doing a poor job verifying who someone is when they are trying to register/activate a credit card. But they all focus on Apple, despite being a minor aspect of the story, because it drives page views.
http://www.statista.com/statistics/263265/top-companies-in-t...
Top market cap, yes.