As computer security guru Bruce Schneier likes to say, "Security is a process, not a product." He was proven right again when Google announced that, while its Linux-based Chrome OS hadn't been cracked in its Pwnium Chrome OS contest, one hacker was successful in creating an unreliable exploit.
While not cracked open, a hacker was able to pry a bit at Chrome OS in Google's recent Pwnium competition.
Specifically, the hacker known as Pinkie Pie, who cracked the Chrome Web browser on Windows last year in Google's security contest, "submitted a plausible bug chain involving video parsing, a Linux kernel bug and a config file error. The submission included an unreliable exploit demonstrating one of the bugs."
Google also thanked him "for honoring the spirit of the competition by disclosing a partial exploit at the deadline, rather than holding on to bugs in lieu of an end-to-end exploit. This means that we can find fixes sooner, target new hardening measures and keep users safe."
For this, Pie was awarded $40,000. A true browser- or system-level compromise would have been worth $110,000 and one that persisted after a reboot would have brought a talented hacker $150.000.
Read