<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.thestandard.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title></title>
 <link>http://www.thestandard.com/node/103947/comments</link>
 <description>comments feed.</description>
 <language>en</language>
<item>
 <title>Charlie Miller: making his name in Mac hacking</title>
 <link>http://www.thestandard.com/news/2008/03/28/charlie-miller-making-his-name-mac-hacking</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;
&lt;p&gt;&lt;a href=&quot;http://venturebeat.com/wordpress/wp-content/uploads/2008/03/charlie-miller2.jpg&quot; title=&quot;charlie-miller2.jpg&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;http://venturebeat.com/wordpress/wp-content/uploads/2008/03/charlie-miller2.thumbnail.jpg&quot; alt=&quot;charlie-miller2.jpg&quot; align=&quot;left&quot; /&gt;&lt;/a&gt;Charlie Miller and his team at &lt;a href=&quot;http://securityevaluators.com/&quot; rel=&quot;nofollow&quot;&gt;Independent Security Evaluators&lt;/a&gt; managed to hack a MacBook Air in&lt;a href=&quot;http://arstechnica.com/journals/apple.ars/2008/03/28/macbook-air-compromised-in-2-minutes-for-10000&quot; rel=&quot;nofollow&quot;&gt; just two minutes&lt;/a&gt; yesterday at the CanSec West security conference.  He won $10,000 for the feat in the &lt;a href=&quot;http://dvlabs.tippingpoint.com/blog/2008/03/27/day-two-of-cansecwest-pwn-to-own---we-have-our-first-official-winner-with-picture&quot; rel=&quot;nofollow&quot;&gt;PWN2OWN &lt;/a&gt;contest in Vancouver.&lt;/p&gt;
&lt;p&gt;I&amp;#8217;ve had a chance to &lt;a href=&quot;http://www.mercextra.com/blogs/takahashi/2007/08/20/an-interview-with-hacker-charlie-miller-on-dealing-with-apple-hacking-the-iphone-the-vulnerabilities-of-leopard-and-responsible-disclosure/&quot; rel=&quot;nofollow&quot;&gt;interview Miller&lt;/a&gt; on a couple of occasions. He won fame as the first hacker to &lt;a href=&quot;http://www.mercextra.com/blogs/takahashi/2007/08/02/black-hat-security-expert-talks-about-apples-leopard-iphone-vulnerabilities/&quot; rel=&quot;nofollow&quot;&gt;discover flaws in the iPhone&lt;/a&gt;. And he also figured out a way to &lt;a href=&quot;http://www.mercextra.com/blogs/takahashi/2007/11/30/exclusive-hackers-say-they-can-pick-pockets-of-characters-in-second-life-virtual-world/&quot; rel=&quot;nofollow&quot;&gt;hack into Second Life&lt;/a&gt; and steal the money of avatars by exploiting a (now patched) flaw in Apple&amp;#8217;s QuickTime player. He says he has nothing against Apple or the Mac. It&amp;#8217;s just unexplored territory.&lt;/p&gt;
&lt;p&gt;Miller is one of those people driven by a curious nature to figure out what&amp;#8217;s wrong with things. But from the discussions I&amp;#8217;ve had with him, it seems Miller has experience walking the fine line between legal and illegal hacking. He can get as deep into the technology discussion of &amp;#8220;buffer overflows&amp;#8221; and &amp;#8220;fuzzing&amp;#8221; as anyone.&lt;/p&gt;
&lt;p&gt;His company is a security consulting service that helps companies test their own security. He works under the euphemistic title of &amp;#8220;security researcher.&amp;#8221; But he doesn&amp;#8217;t consider himself a &amp;#8220;black hat&amp;#8221; because he always discloses flaws to companies ahead of time. Granted, he doesn&amp;#8217;t always give them a lot of time to fix flaws before he discloses them, but he figures that if he finds the flaws, then users are already vulnerable.&lt;/p&gt;
&lt;p&gt;Clearly, Miller is somebody Apple&amp;#8217;s security experts want to know and be on good terms with. He&amp;#8217;s doing an awful lot of the work that they should be doing themselves. The contest organizer, DVLab, is keeping Miller&amp;#8217;s detailed description of the flaw in the Safari browser for the MacBook Air confidential, at least until Apple can start fixing it. Companies and government agencies keep a close eye on conferences like CanSecWest and &lt;a href=&quot;http://www.blackhat.com/&quot; rel=&quot;nofollow&quot;&gt;Black Hat&lt;/a&gt; (in Las Vegas in August) because of all the flaws that get exposed at the events.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://feeds.feedburner.com/~a/Venturebeat?a=JzOHX9&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~a/Venturebeat?i=JzOHX9&quot; border=&quot;0&quot;&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://feeds.feedburner.com/~f/Venturebeat?a=J7oQkMF&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;http://feeds.feedburner.com/~f/Venturebeat?i=J7oQkMF&quot; border=&quot;0&quot;&gt;&lt;/img&gt;&lt;/a&gt;&lt;br /&gt;
&lt;img src=&quot;http://feeds.feedburner.com/~r/Venturebeat/~4/259767904&quot; height=&quot;1&quot; width=&quot;1&quot; /&gt;&lt;/p&gt;
</description>
 <comments>http://www.thestandard.com/news/2008/03/28/charlie-miller-making-his-name-mac-hacking#comments</comments>
 <category domain="http://www.thestandard.com/taxonomy/term/5661">Business &amp;amp; Finance</category>
 <category domain="http://www.thestandard.com/taxonomy/term/702">Business and Technology</category>
 <category domain="http://www.thestandard.com/taxonomy/term/791">CleanTech</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3806">co: apple</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3831">co: cbs</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3467">co: electronic arts</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3832">co: ibiquity</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3807">co: independent security evaluators</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3811">co: warner bros.</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3812">co:-Sony</category>
 <category domain="http://www.thestandard.com/taxonomy/term/977">co:Apple</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3559">co:AT&amp;amp;amp;T</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3833">co:gannett</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3839">co:gridpoint</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3828">co:mobile-digital-media</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3813">co:paramount-pictures</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3814">co:Viacom</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3834">co:westinghouse</category>
 <category domain="http://www.thestandard.com/taxonomy/term/704">deal</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3124">DigitalMedia</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3835">inv: grotech partners</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3836">inv: jp morgan</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3837">inv: new venture partners</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3838">inv: pequot private equity</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3829">inv:Cross-Atlantic-Partners</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3840">inv:Goldman-Sachs</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3841">inv:New-Enterprise-Associates</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3842">inv:perella-weinberg-partners</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3843">inv:Quercus-Trust</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3844">inv:Robeco</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3830">inv:Sofinnova-Partners</category>
 <category domain="http://www.thestandard.com/taxonomy/term/3845">inv:susquehanna private equity investments</category>
 <category domain="http://www.thestandard.com/taxonomy/term/2950">Mobile/Comm</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1840">Top stories</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1841">wire</category>
 <category domain="http://www.thestandard.com/taxonomy/term/98">Breaking News</category>
 <pubDate>Fri, 28 Mar 2008 10:34:07 -0700</pubDate>
 <dc:creator>Venture Beat</dc:creator>
 <guid isPermaLink="false">103947 at http://www.thestandard.com</guid>
</item>
</channel>
</rss>
