• On Metacritic: BioShock 2: The reviews are in
September 30, 2006 3:39 PM PDT

Researcher defends Mac Wi-Fi hijack

by Joris Evers
  • Font size
  • Print
  • Post a comment

SAN DIEGO, Calif.--The Mac Wi-Fi hack saga that started at Black Hat in August got a little bit of a next chapter after all on Saturday.

David Maynor, a researcher at SecureWorks, was a no-show Saturday at the ToorCon hacker event here, just as his employer said on Friday. However, his Black Hat partner Jon "Johnny Cache" Ellch did get up on stage. (For more background, read Friday's post " Another twist in Wi-Fi hijack tale.")

Ellch did not give the scheduled presentation, which was meant to set the record straight on the Wi-Fi hack. The two researchers had planned to give a live demonstration, hijacking a Mac via Wi-Fi. Instead, Ellch read a statement. The file, stored on his Apple Computer MacBook, was titled: "rant."

"I cannot give this talk without Dave," Ellch said. "Dave very much wanted to be here. The fact that SecureWorks and Apple managed to compel him not to, means that they must have had something very compelling to stop him."

Ellch went on to defend Maynor and himself against attacks from the Mac community that started right after they claimed at Black Hat that Apple's wireless technology was vulnerable. Apple at the time critiqued the two for not proving their case, but came out with patches for Wi-Fi flaws last week.

That patch release was no coincidence, Ellch suggested Saturday.

The two researchers had put pressure on Apple by saying they would do a live presentation at ToorCon, Ellch said. "A few weeks later, one week before ToorCon, they patch it, and say we had nothing to do with it," Ellch said.

A day before the scheduled ToorCon presentation, SecureWorks and Apple issued separate statements that the companies are working together. SecureWorks pulled Maynor from the San Diego event.

"SecureWorks and Apple are working together in conjunction with the CERT Coordination Center on any reported security issues. We will not make any additional public statements regarding work underway until both companies agree, along with CERT/CC, that it is appropriate," SecureWorks said Friday.

Apple spokeswoman Lynn Fox on Friday said the Cupertino, Calif., Mac maker is working with SecureWorks, but declined to specify the nature of the relationship. "I am not commenting any further," she said.

"That's funny," Ellch reacted on Saturday. "I thought there was no bug, and I thought SecureWorks provided no useful information to Apple...If SecureWorks provided them with virtually nothing useful, then what...could they have to coordinate with CERT?"

The story is bound to be continued. While some in the Mac community see the cancellation of Saturday's talk as proof that Maynor and Ellch are frauds, some at ToorCon suggest the danger of Wi-Fi driver flaws might be bigger than previously thought.

Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
advertisement

Tech at the Olympics: 'No room to fail'

Q&A The Olympics relies on thousands of servers and PCs to manage all the athletes and scores. Magnus Alvarsson is the guy who must make sure everything works.

How CoverItLive lost it on iPad day

The live-blogging tool fell apart under the strain of a Steve Jobs keynote. Here's what happened, and what comes next for the company.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right