Wanted: Windows Hackers

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Microsoft wants its "Blue Hat" date with hackers to become a regular affair, with biannual events where outsiders demonstrate flaws in Microsoft's product security.

In March, Microsoft invited several hackers to its Redmond, Washington, headquarters for the first time. The two-day meeting of Microsoft insiders with independent researchers provided each side with a glimpse into the other's world. That get-together was such a success that Microsoft is planning more of the events.

"We want to try and do it twice a year," Stephen Toulouse, a programme manager in Microsoft's security unit, said in an interview. "It had a huge benefit to our developers." The event gives executives and developers a different look at product security, he said.

At one point in the March meeting, a hacker lured a laptop running Windows onto a rogue wireless network. He did it in front of the people who developed the operating system. "You're seeing how the technology that you created could potentially be misused, so you come out of that with a much deeper understanding," Toulouse said.

Tip of the hat
Microsoft modelled and named Blue Hat after the widely known Black Hat security conference, which took place last week in Las Vegas. Many of the talks at the annual Black Hat dive deep into security flaws found in software. (The Blue Hat name is tweaked to reflect Microsoft's corporate colour, in particular the blue badges worn by Microsoft employees at the company's campus.)

"We sent over 80 people to Black Hat, but we have got many thousands more who could benefit from the perspective of a security researcher," Toulouse said.

The first Blue Hat meeting focused on security in Windows. The next event could highlight security in products from other Microsoft groups, such as the Office productivity suite or its MSN online line-up, Toulouse said. "We are seeing interest from other groups. You could, in the future, see something like a Blue Hat about Office," he said.

Security researchers are also showing interest in Blue Hat. The event wasn't officially on Microsoft's Black Hat calendar, but many researchers asked Toulouse and his colleagues about it and said they wanted to participate, he said.

Microsoft rented the Pure Nightclub in Caesars Palace on Thursday to treat the security community to a party with techno music and free cocktails. The company also threw an after-party at another Las Vegas hotel.

By hosting such parties and the Blue Hat event, Microsoft may be seeking to influence the security community. For example, Microsoft regularly preaches "responsible disclosure" of flaws, in which software makers are given time to repair a problem. Microsoft doesn't want researchers to go public with information on vulnerabilities before the company has had a chance to provide a patch.

"We want to learn from them and let them know that the people inside Microsoft that are working on security are all individuals and very passionate about security. It is not some big invisible monolithic thing that you hear about, but you can't see," Toulouse said.

Security researcher Dan Kaminsky attended the first Blue Hat and supports the event. "It is so nice to be able to complain about something and have somebody stand up and take responsibility," he said.

Kaminsky also said that Microsoft is listening to the security community. "We are at the point where all the obvious things we tell Microsoft to do, they already do it," he said.

Reaching out to the security community is part of Microsoft's efforts to improve the security of its products and fix up its reputation. The company said it was making security its top priority when it launched its Trustworthy Computing Initiative three years ago. Since then, it has overhauled its in-house development to bolster security and put its multibillion-dollar war chest and research budget to work.

The next Blue Hat is planned for the autumn, but no date has been set yet, Toulouse said.

Talkback

I thought the Blue Hat name came from the Blue Screen of Death syndrome that Windows users have to live with :-P

via Facebook 3 August, 2005 09:45
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

2 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

4 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

5 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

5 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

5 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

6 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

8 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

14 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

16 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

16 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

17 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

18 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

19 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

19 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

19 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

20 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

20 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

21 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

21 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

21 hours ago by Moley on ACTA: Facts, misconceptions and questions