Version: 2008
  • On MovieTome: The 10 worst movies of 2009 so far!

August 1, 2006 4:00 AM PDT

Black Hat with a Vista twist

  • 11 comments
This year, Black Hat is not just about breaking and entering.

The annual security conference traditionally focuses on hunting for bugs and attacking computer systems. At the 2006 event this week, however, an entire track will be devoted to the security--rather than the insecurity--of Windows Vista and Internet Explorer 7. The series of sessions will be hosted by Microsoft, a major sponsor of the event this year.

It's an unprecedented and comprehensive first-look at the security in Vista and its associated Web browser, Black Hat Director Jeff Moss said in an interview Monday. "Even if attendees are not getting three different ways to hack into IE 7, they get the back story," he said.

Microsoft says it is the first in the history of Black Hat Briefings to present an entire track on a prerelease product. It has talked up Vista as its most secure operating system ever, and has said that security was the No. 1 investment in IE 7.

It's a sign of development at the event, which brings together the hacker and corporate worlds for two days of talks in Las Vegas. The tenth Black Hat promises to be special, Moss said. "It is the largest show ever in terms of size and attendees," he said. Moss sold rights to the conference to technology publisher CMP Media in November, but he still runs the event.

Black Hat has been around since 1997. The event has traditionally focused on exposing flaws in software and on sharing hacker tools. "We always tried to be more practical--watch a talk, go home and do something," Moss said. "We try to stay away from the purely academic area."

This year's confab is expected to draw about 3,000 people, a mix of security professionals, underground hackers, federal agents and vendors. It will be followed by the DefCon, a gathering infamous for its hacker activity.

"We really seem to reach critical mass this year," Moss said. "Every year, it has always been incremental growth, primarily through word of mouth. This year, we grew over 20 percent, and that has never happened before." Moss attributes the increase in registrations to the high profile of the event as well as to a rising interest in security.

Uneasy bedfellows
Microsoft is not the only major technology company with a big presence at Black Hat. Cisco Systems has signed on as a "Platinum Sponsor," alongside Microsoft and consultancy firm Ernst & Young. Last year, Cisco drew the ire of many Black Hat and DefCon attendees when it sued a security researcher and conference organizers after a session on router security.

The legal action followed a presentation by researcher Michael Lynn, who demonstrated he could gain control of a Cisco router by exploiting a known security flaw in Cisco's Internetwork Operating System. The operating system had until then been perceived as impervious to such attacks.

Cisco and Internet Security Systems--Lynn's employer--had agreed to pull the presentation, but Lynn quit his job and gave the talk anyway. Cisco and ISS sued Lynn after his presentation, and hackers rallied behind the researcher.

This year, Cisco is playing nice. In addition to its sponsorship, the company is sending Chief Security Officer John Stewart to talk about relationships between vendors and security researchers. The networking giant is also throwing a party for Black Hat attendees at Pure, the night club at Caesars Palace.

Still, Black Hat wouldn't be Black Hat without the usual exposure of security flaws and release of details of new hacker techniques. Researchers are slated to demonstrate 25 new tools and outline 15 new exploits at the event, according to organizers.

Special attention is going to security risks associated with Web 2.0, which covers more-advanced Web sites that use programming techniques such as AJAX and JavaScript. Also on the calendar are presentations on rootkits, security in voice services and, as in previous years, database security.

In the networking area, one technology to be scrutinized is network admission control (NAC). Ofir Arkin, chief technology officer at Insightix, plans to disclose weaknesses in NAC systems, which are designed to restrict access to a network according to identity or the security status of a computer. Cisco and Microsoft are two major NAC players.

"These flaws allow the complete bypass of each and every network access control mechanism currently offered on the market," according to the Black Hat calendar.

Some of the presentations are generating buzz, and some presenters have changed or quit jobs to be able to present, Moss said. He doesn't expect there to be any legal wrangling. But, then again, "I didn't know I was going to get sued last year," Moss said.

Black Hat takes place Wednesday and Thursday, then DefCon runs Friday through Sunday.

See more CNET content tagged:
Black Hat, Cisco Systems Inc., attendee, Defcon, researcher

Add a Comment (Log in or register) (11 Comments)
  • prev
  • 1
  • next
Human Honeypot
by n3td3v August 1, 2006 4:54 AM PDT
Its the 'manufactured' hackers who go to these 'talk to the police' conferences, you know the ones who spent thousands on student loans to become a hacker.

Any criminal hackers who go are just stupid and don't realise what they are actually attending.

The U.S Security Services will have hidden cameras and befrienders in place to grab as much information out of people as possible.

These conferences have just turned into a 'human honeypot' for the intelligence services.

Good on the people who are brave enough to step into that 'human honeypot', but the majority in the underground wouldn't go near these conferences.

Keep up the good work Joris Evers.
Reply to this comment
Black Helicopters
by Too Old For IT August 1, 2006 8:42 AM PDT
You forgot thepart about how they'll be whisked away in black helicopters to Area 51.
It's a first all right
by Michael Grogan August 1, 2006 8:18 AM PDT
It's the first time Black Hat has been subverted to be another advertising misinformation venue for M$. The conference will never be the same and will never again have any real value. Way to go sell-outs!
Reply to this comment
sheesh
by dbrawders August 1, 2006 8:07 PM PDT
give me a break man..
can't you guys find something else to complain about for a change other than MSFT and how 'evil' they are...
View reply
A big red bullseye
by rcrusoe August 1, 2006 8:56 AM PDT
Microsoft " . . has talked up Vista as its most secure operating
system ever." thus guaranteeing that it will have a big red bullseye
on its backside when it finally ships.

I've got a $200 bet with a local fanboy that there will be a major
exploit found in Vista within 90 days of release to consumers.
Reply to this comment
And how is that different?
by aabcdefghij987654321 August 1, 2006 12:32 PM PDT
MS has already worn that bullseye for a long time.
90 days?
by qwerty75 August 2, 2006 12:59 AM PDT
9 days would be a safe bet
major exploit found
by Ipod Apple April 27, 2007 8:46 PM PDT
http://www.analogstereo.com/honda_prelude_owners_manual.htm
from Michael Lynn to John Stewart in 12 months
by samiamtoo August 2, 2006 3:00 AM PDT
The evidence indicates that putting on a trade show (and that is what Black Hat really is, in spite of its past spin and orientation) is a proposition with a rate of return that has gone negative. Under the circumstances, I suppose a sell-out like this should come as no surprise. Nevertheless, the suddeness of the turn-about is a major disappointment. I understand that visionary organizations have a natural lifespan, after which the vision must change, or the organization must perish. I do wish that people like Jeff Moss would consider that survival is sometimes the second best option. I also hope that Steve Ballmer used a condom.
Reply to this comment
(11 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Cisco Systems (1.32%) 0.31 23.71
Microsoft (0.92%) 0.27 29.63
Dow Jones Industrials (0.72%) 73.00 10,270.47
S&P 500 (0.57%) 6.24 1,093.48
NASDAQ (0.88%) 18.86 2,167.88
CNET TECH (0.63%) 9.86 1,587.17
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right