First he hacked Apple’s iPhone. Now he’s hacked Apple’s MacBook Air. But some analysts are warning not to be quick to judge security based on Charlie Miller’s work.
Miller, a researcher at Independent Security Evaluators, won $10,000 and a laptop Thursday at the CanSecWest security conference’s Pwn 2 Own hacking contest. He did it by hacking the MacBook Air — and it took him all of two minutes.
CanSecWest organizers offered a Sony Vaio, Fujitsu U810 and a MacBook as booty for hackers who could find a way to breach security and gain access to the contents of system files using a previously undisclosed zero-day attack. A zero-day attack is the exploitation of unpatched software vulnerabilities.
Picking on Apple
The first day of the contest, hackers were only allowed to hack into the computers over a network. No one was able to claim the prizes. On the second day, the rules changed. Contestants were allowed to use the machines to visit Web sites and open e-mail messages. The new rules were a game-changer for Miller, who almost immediately found a way in.
Miller is familiar with Apple’s architecture. He is perhaps best known as one of the first researchers to hack Apple’s iPhone. This time around, he hacked the MacBook Air by visiting a Web site with exploit code he created. That code allowed him to take control of the computer as onlookers enjoyed the show. Jake Honoroff and Mark Daniel were on the Miller team from Independent Security Evaluators.
“They were able to exploit a brand-new zero-day vulnerability in Apple’s Safari Web browser. Coincidentally, Apple has just started to ship Safari to some Windows machines through its iTunes update service. The vulnerability has been acquired by the Zero-Day Initiative, and has been responsibly disclosed to Apple, who is now working on the issue,” according to…