August 1, 2005 3:04 PM PDT

Microsoft wants to meet more hackers

Microsoft wants its "Blue Hat" date with hackers to become a regular affair, with twice-yearly events where outsiders demonstrate flaws in Microsoft's product security.

In March, Microsoft invited several hackers to its Redmond, Wash., headquarters for the first time. The two-day meeting of Microsoft insiders with independent researchers provided each side with a glimpse into the other's world. That get-together was such a success that Microsoft is planning more of the events.

"We want to try and do it twice a year," Stephen Toulouse, a program manager in Microsoft's security unit, said in an interview. "It had a huge benefit to our developers." The event gives executives and developers a different look at product security, he said.

At one point in the March meeting, a hacker lured a laptop running Windows onto a rogue wireless network. He did it in front of the people who developed the operating system. "You're seeing how the technology that you created could potentially be misused, so you come out of that with a much deeper understanding," Toulouse said.

Tip of the hat
Microsoft modeled and named Blue Hat after the widely known Black Hat security conference, which took place last week in Las Vegas. Many of the talks at the annual Black Hat dive deep into security flaws found in software. (The Blue Hat name is tweaked to reflect Microsoft's corporate color, in particular the blue badges worn by Microsoft employees at the company's campus.)

"We sent over 80 people to Black Hat, but we have got many thousands more who could benefit from the perspective of a security researcher," Toulouse said.

The first Blue Hat meeting focused on security in Windows. The next event could highlight security in products from other Microsoft groups, such as the Office productivity suite or its MSN online lineup, Toulouse said. "We are seeing interest from other groups. You could, in the future, see something like a Blue Hat about Office," he said.

"We have got many thousands...who could benefit from the perspective of a security researcher."
--Stephen Toulouse, program manager, Microsoft's security unit

Security researchers are also showing interest in Blue Hat. The event wasn't officially on Microsoft's Black Hat calendar, but many researchers asked Toulouse and his colleagues about it and said they wanted to participate, he said.

Microsoft rented the Pure Nightclub in Caesars Palace on Thursday to treat the security community to a party with techno music and free cocktails. The company also threw an after-party at another Las Vegas hotel.

By hosting such parties and the Blue Hat event, Microsoft may be seeking to influence the security community. For example, Microsoft regularly preaches "responsible disclosure" of flaws, in which software makers are given time to repair a problem. Microsoft doesn't want researchers to go public with information on vulnerabilities before the company has had a chance to provide a patch.

"We want to learn from them and let them know that the people inside Microsoft that are working on security are all individuals and very passionate about security. It is not some big invisible monolithic thing that you hear about, but you can't see," Toulouse said.

Security researcher Dan Kaminsky attended the first Blue Hat and supports the event. "It is so nice to be able to complain about something and have somebody stand up and take responsibility," he said.

Kaminsky also said that Microsoft is listening to the security community. "We are at the point where all the obvious things we tell Microsoft to do, they already do it," he said.

Reaching out to the security community is part of Microsoft's efforts to improve the security of its products and fix up its reputation. The company said it was making security its top priority when it launched its Trustworthy Computing Initiative three years ago. Since then, it has overhauled its in-house development to bolster security and put its multibillion-dollar war chest and research budget to work.

The next Blue Hat is planned for the fall, but no date has been set yet, Toulouse said.

See more CNET content tagged:
Stephen Toulouse, Black Hat, hacker, researcher, program manager

Add a Comment (Log in or register) 4 comments
Will it actually work?
by August 1, 2005 3:33 PM PDT
I myself think that it would not only be hard to find these hackers,
but also to actually get them to come and meet with Microsoft and
show them what they do with their time. Do they get in any trouble
if they do something illegal in the process of their hack?
Reply to this comment
MSFT Should Pay the Blue Hatters
by malabrm1 August 1, 2005 5:05 PM PDT
The key line in the article is: "Microsoft doesn't want reseachers to go public with information on vulnerabilities before the company has had a chance to provide a patch." Well, of course they don't want people to see how slow they maybe on the uptake. And heck - this is, after all, a great deal for MSFT. Inviting a passle of hackers for a drink is a dirt-cheap way to get these folks to show them the difficiencies in MSFT programs. But pre-screen the group a bit better, offer those who make the cut a big consulting fee and just watch how to optimize the MSFT Blue Hat confab. :) I trust that MSFT offers critical patches - those that they are aware are urgently needed - without the intervention of outside consultants. :(
Reply to this comment
microsoft has cool trash bins
by August 1, 2005 5:15 PM PDT
when i was just a young punk kid with my first
car a friend and I drove out to the campus to
pick up garbage.. and microsoft by far had the
most high tech dumpsters in the neighborhood..
man.. like a safe! thats cool that microsoft
wants to be social.. I should just go over there
and loiter
Reply to this comment
Stinger!
by August 2, 2005 2:50 AM PDT
Cat in the Hat. Green eggs and ham meat for breakfast mice! Technically speaking any of these sorts of hackers that show up are in violation of law and apprehensible! Would this be considered aiding and abetting known criminals? Sort of like "the US Army wants you gang-banger"!
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Dell planning to ditch factories

    Dell's new CFO Brian Gladden has said that the company "more work to be done," to improve profitability and decrease costs. The Wall Street Journal is reporting that the company is planning to lower costs by selling off its factories.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Negative Approach

    Online content and services via game consoles will generate $8 billion in revenue in 2013

    The revenue possibilities in gaming continue to grow, at least for the big console manufacturers.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Wireless

    Was EarthLink's failed citywide Wi-Fi a blessing in disguise?

    Wireless Philadelphia, the nonprofit charged with providing broadband bundles to low-income families in Philadelphia, may be better off in the long run without EarthLink.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Gaming and Culture

    Behind the prototyping of 'Spore'

    Many of the components of Will Wright's highly anticipated evolution game started out as small concept projects that are now available to the public.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • The Cheapskate

    Record TV in style with a refurbished TiVo HD, $179.99 shipped

    TiVo is offering refurb HD units for cheap, though you'll still have to pay for the TiVo service.

  • Green Tech

    Clean-tech group forms to support Obama

    "Clean Tech and Green Business for Obama" aims to raise $1 million for the Democratic presidential nominee while elevating issues of climate change and alternative energy.