You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft takes its hat off to hackers

Two-day event sees execs and geeks get up close and personal...

Tags: black hat, blue hat, hackers, microsoft

By Ina Fried

Published: 16 June 2005 15:30 BST

Details of a two-day convention hosted by Microsoft with the aim of attempting to exploit flaws in their own computing systems have emerged.

The event, which Microsoft has not publicised, was dubbed "Blue Hat" - a reference to the widely known "Black Hat" security conference, tweaked to reflect Microsoft's corporate colour.

Hackers were invited into the heart of the Windows empire to pit their wits against the best work of the software giant's network engineers.

Within minutes after the meeting was convened, the hackers - or 'security researchers' as they are known - had successfully lured a Windows laptop onto a malicious wireless network.

"It was just silent," said Stephen Toulouse, a program manager in Microsoft's security unit. "You couldn't hear anybody breathe."

The unusual March gathering, a summit of sorts between delegates of the hacking community and their primary corporate target, illustrates how important security has become to the software behemoth.

Microsoft chairman Bill Gates himself estimated earlier this year that the company now spends $2bn per year - more than a third of its research budget - on security-related issues. Security has also become one of the main themes of the company's developer conferences, including last week's TechEd event, where Microsoft pitched security improvements in Windows to 11,000 attendees.

Blue Hat was attended by some of the company's most senior executives and about 400 rank-and-file Windows engineers, including people who don't necessarily focus on security features in their day-to-day work.

One executive in attendance, Microsoft's Windows chief Jim Allchin, said he wanted the Windows group to not just hear about security issues but to see them as well.

"I'd already been through lots of days of personal training on the tools that are used to do this," he said about the work of the hackers. "I personally wanted to really do a deep dive and really understand from their perspective."

The researchers also relished the opportunity to come face-to-face with 'the other side'. Security researcher HD Moore said: "It is rare that I can present to the people who are both responsible for and capable of fixing the issues that I cover."

Moore added that he gained a better understanding of why it takes Microsoft so long to create patches, and said his impression of the people who create the products has changed.

"I still may not agree with their security policies and how they handle bug reports but at least I know they actually believe what they are saying," he said.

Kaminsky, a security researcher who works for telecommunications company Avaya, also took his hat off to Microsoft's efforts to bolster its security strategy: "They are taking this subject seriously. It was really cool to see. At some point, there was a shift at Microsoft."

For their part, Microsoft executives said they came to a better understanding of what makes hackers tick.

Noel Anderson, Microsoft's program manager for wireless, mobility and home networking, said: "We have conversations where we say an attacker might do this or an attacker might do that. Now there is a face to some of those guys. They were just as much geeks as we were."

Ina Fried writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Lead Engineer- Linux (RHCE, SQL, PERL)

Participate in rotating on-call schedule as a senior member of customer operations Key Requirements Your skill set will include advanced knowledge of ...

1st/2nd Line Engineer Needed

My Oxfordshire based client is looking for 2 1st/2nd line engineers on 3 month contracts. Ideally you would have experience with the following: ...

MCSE Network Engineer - 30,000 - Yorkshire

The below does cover the overall role so we are looking for experience in most areas.Therefore for this Senior network support engineers position a ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: