You are here: silicon.com > Comment & Analysis

Comment & Analysis

Ethical hacking - no reason to run scared

"Hundreds of man-years of development and the most rigorous testing in the industry were invested in the product before it launched to help ensure that we had met our design objectives."

By editorial@silicon.com

Published: 23 April 2001 17:00 GMT

No, not the head of Whitestar Corporation before a maiden voyage of a certain cruise ship, but Randy Sandone, CEO of an internet company which challenged hundreds of thousands of hackers to break its systems.

The PitBull OpenHack challenge has survived four rounds of battle but this week it fell at the fifth.

Timed to coincide with the Infosecurity exhibition at London's Olympia, OpenHack V was beaten by a group of "extraordinarily talented and professional" hackers from Poland.

Well done, Michal Chmielewski, Sergiusz Fornrobert, Adam Gowdiak and Tomasz Ostwald, otherwise known as 'Last Stage of Delirium' (LSD).

Argus, the security company in question, has been quick to acknowledge their success. "These guys are awesome - and I'm sure are the match of any hacker alive," the company said.

The vulnerability was actually found in the Solaris operating system rather than Argus' software, but no matter, the system was still breached. "We freely admit that in this instance PitBull did not protect the system from this exploit. Guilty as charged."

By putting themselves at the mercy of the hacker community - and paying £35,000 for the privilege - Argus has made itself unpopular with many. The use of ethical hackers remains controversial but the result is indisputable.

The point is - and always has been - no single product, series of products, or services can completely eliminate security vulnerabilities.

But it's worth being reminded every now and again.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Product/Project Manager (Maternity Cover)

We operate in the UK and the USA.We are part of a bigger group, Promise Corporation, which is a well established boutique brand, insight and ...

Lead Security Consultant - PCI-DSS/ISO 27001

Also, you will be certified in one or more of the following: CISSP (Certified Information Systems Security Professional), CEH (Certified Ethical ...

Operations Manager/Delivery Manager

You will have responsibility for the leadership and management of teams of Web Developers, Project Managers and Designers and will be charged with ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: