7/03/2007

IPhone call for vulnerabilties


Finally, last Friday the IPhone hit the market.
We witnessed thousands of Apple lovers waiting countless hours in line, ready to assault the shops to buy this year's "King of the Gears".

While shop clerks were still cashing the money from the first IPhone sales, the hacker community already started a bunch of projects aimed to bring the IPhone down to its knees.

In S. Francisco, they organized a camp where attendees "will include web designers, developers, testers, and iPhone owners--all working together, on their precious weekend, to improve the web experience for iPhone owners." Yes, we really love the wording here.

Always at the same time, other hackers decided to open apart the *just purchased* IPhone in order to let us peek at its inner circuits
In another part of the globe, other hackers posted some hints about activating the IPhone's latent features without a cellphone contract and activation process.
Meanwhile, some other hackers started to talk about potential IPhone multiple security issues, just hours after the purchase.
At the end of the day, other hackers posted a link from which apparently it is possible to download the firmware of the IPhone, directly from an Apple server.

So much of attention for this newborn baby, we certainly want to do our part.

WABISABILABI is releasing a CALL FOR SECURITY RESEARCH AND ANALYSIS based on the IPhone hardware and software platform

Security researchers from all over the world are invited to report to us the findings and eventually use our marketplace platform to find buyers for their discoveries.

5/31/2007

When vendors get nuts

In a post recently appeared on the McAfee's Avert Labs Blog (posted by Vinoo Thomas) we were quite entertained by reading an astonishing statement in which McAfee curses against a crew of virus researchers who "dared" to send a proof of concept of a virus to McAfee's laboratories.

The concept virus is quite interesting as it is reported on the blog "
virus Bad Bunny a.k.a StarOffice/BadBunny is a multi-platform macro virus written in StarBasic and which executes on Linux, MacOSX and Windows. It is capable of infecting JavaScript, Ruby and Perl script files and also attempts to perform a denial of service attack on antivirus vendor sites by sending large ICMP packets continuously."

Pretty neat! Now, where would it be the value of such PoC? The value consists in the early-alert the antivirus vendor gets about the possible release of a new attacking vector/methodology on which, needless to say, they will base their business. Knowing in advance new attacking vectors/methodologies is crucial for the security business as the security vendors should always try to be a step-ahead of the cyber criminals. You cannot build a decent security strategy without valuing properly the messages coming from your intelligence network, and in such view warnings (or PoCs) coming from researchers are certanly the best kind of intelligence a security agency could ever dream of.

But no, McAfee dismissed the job of those researchers by reporting
Peter Ferrie’s motivating words for such virus authors. “So imagine you’re a virus writer, someone who specialises in one-of-a-kind viruses, and you want to do something that’s really new and different. What should it be? How about quitting?

Take the cue guys. Get a life!"

We have just two questions here:

1 - Assuming all virus writers would quit writing viruses, what would McAfee's shareholders say?
2 - Do McAfee really think that giving the finger to researchers would be the best motivation for them not to sell their research to the criminal market?

Think once. Even better, think twice.

4/27/2007

WabiSabiLabi's philosophy

Wabi-sabi (in Japanese katakanaワビサビ) represents a comprehensive Japanese world view or aesthetic centred on the acceptance of transience. The phrase comes from the two words wabi and sabi. The aesthetic is sometimes described as one of beauty that is "imperfect, impermanent, and incomplete". It is a concept derived from the Buddhist assertion of the Three marks of existence — Anicca, or in Japanese, 無常 (mujyou), impermanence.

Wabi-sabi nurtures all that is authentic by acknowledging three simple realities: nothing lasts, nothing is finished, and nothing is perfect."

In this view, Wabi-sabi is the perfect term to represent the implicit imperfection of the IT security, as well as the scope of our project, which is to contribute to its improvement. This goal is achieved by completely re-designing the traditional security research cycle, introducing for the first time ever a market-driven approach to correctly value the security researchers contributions.

Nothing lasts, but everything can always be improved in its life-cycle.