Pwn2Own 2018: Focus Changes To Kernel Exploits As Browsers Get Harder To Hack

From left to right: Georgi Geshev, Fabi Beterke, Niklas Baumstark , Samuel Groß, Richard Zhu, Alex Plaskett. (Image credit: Trend Micro)

Pwn2Own 2018, the popular browser hacking competition, concluded today. This year’s competition seems to have drastically diminished in number of participants, as China banned its security researchers (who have won multiple times in the past) from participating in Pwn2Own or divulging security vulnerabilities to foreigners.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • bit_user
    20799426 said:
    OS kernels, whether it’s Linux, the macOS kernel, or the Windows kernel, now count millions of lines of code, so the potential for bugs in them is larger than most people may think.
    The numbers for Linux are skewed by the fact that the gross count includes all of the in-tree device drivers, as well as the architecture-specific parts for all supported CPUs. According to some stats from a couple years back, the non-driver and non-arch parts have only ~140k LOC.

    https://unix.stackexchange.com/questions/223746/why-is-the-linux-kernel-15-million-lines-of-code

    As for the arch bits, you're only using a very small amount of that, on any given install. The more standard your hardware config, the better tested you can expect the drivers & arch-specific parts to be.
    Reply
  • alan_rave
    Richard Zhu is not from China?
    Reply
  • bit_user
    20803899 said:
    Richard Zhu is not from China?
    I think they mean teams based in China, or perhaps even specifically Chinese cyber security professionals.

    Are you just going by the name, or do you know that he currently lives there?

    Either way, he won $120k in two days. Not bad!
    Reply
  • bit_user
    Overall, we awarded $267,000 over the two-day contest while acquiring five Apple bugs, four Microsoft bugs, two Oracle bugs, and one Mozilla bug.
    Wow, those are some expensive bugs!
    Reply