OLD | NEW |
1 {{+bindTo:partials.standard_nacl_article}} | 1 {{+bindTo:partials.standard_nacl_article}} |
2 | 2 |
3 <section id="security-contest-archive"> | 3 <section id="security-contest-archive"> |
4 <span id="contest-archive"></span><h1 id="security-contest-archive"><span id="co
ntest-archive"></span>Security Contest Archive</h1> | 4 <span id="contest-archive"></span><h1 id="security-contest-archive"><span id="co
ntest-archive"></span>Security Contest Archive</h1> |
5 <div class="contents local" id="contents" style="display: none"> | 5 <div class="contents local" id="contents" style="display: none"> |
6 <ul class="small-gap"> | 6 <ul class="small-gap"> |
7 <li><a class="reference internal" href="#contest-overview" id="id2">Contest over
view</a></li> | 7 <li><a class="reference internal" href="#contest-overview" id="id2">Contest over
view</a></li> |
8 <li><a class="reference internal" href="#contest-winners" id="id3">Contest winne
rs</a></li> | 8 <li><a class="reference internal" href="#contest-winners" id="id3">Contest winne
rs</a></li> |
9 <li><p class="first"><a class="reference internal" href="#panel-of-judges" id="i
d4">Panel of judges</a></p> | 9 <li><p class="first"><a class="reference internal" href="#panel-of-judges" id="i
d4">Panel of judges</a></p> |
10 <ul class="small-gap"> | 10 <ul class="small-gap"> |
11 <li><a class="reference internal" href="#chair" id="id5">Chair</a></li> | 11 <li><a class="reference internal" href="#chair" id="id5">Chair</a></li> |
12 <li><a class="reference internal" href="#judges" id="id6">Judges</a></li> | 12 <li><a class="reference internal" href="#judges" id="id6">Judges</a></li> |
13 </ul> | 13 </ul> |
14 </li> | 14 </li> |
15 <li><a class="reference internal" href="#additional-information" id="id7">Additi
onal information</a></li> | 15 <li><a class="reference internal" href="#additional-information" id="id7">Additi
onal information</a></li> |
16 </ul> | 16 </ul> |
17 | 17 |
18 </div><p>The Native Client team at Google has gone to exceptional measures to | 18 </div><p>The Native Client team at Google has gone to exceptional measures to |
19 make Native Client a secure system, including holding a public | 19 make Native Client a secure system, including holding a public |
20 security contest. This page archives information from that contest, | 20 security contest. This page archives information from that contest, |
21 including the list of contest winners and the lineup of security | 21 including the list of contest winners and the lineup of security |
22 experts who served as judges.</p> | 22 experts who served as judges.</p> |
23 <p>Although the security contest has ended, the Native Client team | 23 <p>Although the security contest has ended, the Native Client team |
24 welcomes your continued involvement in the project. You can help by | 24 welcomes your continued involvement in the project. You can help by |
25 submitting bugs and participating in the Native Client discussion | 25 submitting bugs and participating in the Native Client discussion |
26 group.</p> | 26 group.</p> |
27 <section id="contest-overview"> | |
28 <h2 id="contest-overview">Contest overview</h2> | 27 <h2 id="contest-overview">Contest overview</h2> |
29 <p>The Native Client team held a contest in 2009 to test the security of | 28 <p>The Native Client team held a contest in 2009 to test the security of |
30 Native Client and help make the system more secure. Participants were | 29 Native Client and help make the system more secure. Participants were |
31 invited to discover security bugs in Native Client technology in order | 30 invited to discover security bugs in Native Client technology in order |
32 to compete for cash prizes.</p> | 31 to compete for cash prizes.</p> |
33 <p>Here was the challenge put forth by the Native Client team:</p> | 32 <p>Here was the challenge put forth by the Native Client team:</p> |
34 <blockquote> | 33 <blockquote> |
35 <div>Do you think it is impossible to safely run untrusted x86 code on | 34 <div>Do you think it is impossible to safely run untrusted x86 code on |
36 the web? Do you want a chance to impress a panel of some of the top | 35 the web? Do you want a chance to impress a panel of some of the top |
37 security experts in the world? Then submit an exploit to the Native | 36 security experts in the world? Then submit an exploit to the Native |
38 Client Security contest and you could also win cash prizes, not to | 37 Client Security contest and you could also win cash prizes, not to |
39 mention bragging rights.</div></blockquote> | 38 mention bragging rights.</div></blockquote> |
40 <p>The contest judges evaluated exploits designed to defeat Native Client | 39 <p>The contest judges evaluated exploits designed to defeat Native Client |
41 security measures based on severity, scope, reliability, and | 40 security measures based on severity, scope, reliability, and |
42 style. The winning teams and entries are listed below.</p> | 41 style. The winning teams and entries are listed below.</p> |
43 </section><section id="contest-winners"> | 42 <h2 id="contest-winners"><span id="id1"></span>Contest winners</h2> |
44 <span id="id1"></span><h2 id="contest-winners"><span id="id1"></span>Contest win
ners</h2> | |
45 <p>The Native Client team thanks everyone who participated in the contest | 43 <p>The Native Client team thanks everyone who participated in the contest |
46 for their contributions to improving the quality and security of the | 44 for their contributions to improving the quality and security of the |
47 Native Client system. The judges reviewed the submitted exploits and | 45 Native Client system. The judges reviewed the submitted exploits and |
48 identified the following teams as winners:</p> | 46 identified the following teams as winners:</p> |
49 <table border="1" class="docutils"> | 47 <table border="1" class="docutils"> |
50 <colgroup> | 48 <colgroup> |
51 </colgroup> | 49 </colgroup> |
52 <tbody valign="top"> | 50 <tbody valign="top"> |
53 <tr class="row-odd"><td><img alt="First place medal" class="first last" src="/na
tive-client/images/medal-64_1st.png" /> | 51 <tr class="row-odd"><td><img alt="First place medal" class="first last" src="/na
tive-client/images/medal-64_1st.png" /> |
54 </td> | 52 </td> |
(...skipping 55 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
110 <p><strong>Submitted issues</strong>: 81</p> | 108 <p><strong>Submitted issues</strong>: 81</p> |
111 <p class="last">Alex Radocea is a 20-year old student at Rensselaer Polytechnic | 109 <p class="last">Alex Radocea is a 20-year old student at Rensselaer Polytechnic |
112 Institute. In the realm of computer security he is really | 110 Institute. In the realm of computer security he is really |
113 excited about proactively designed technology which can help | 111 excited about proactively designed technology which can help |
114 wipe out entire bug classes. Currently he is helping improve | 112 wipe out entire bug classes. Currently he is helping improve |
115 Native Client through Google Summer of Code.</p> | 113 Native Client through Google Summer of Code.</p> |
116 </td> | 114 </td> |
117 </tr> | 115 </tr> |
118 </tbody> | 116 </tbody> |
119 </table> | 117 </table> |
120 </section><section id="panel-of-judges"> | 118 <h2 id="panel-of-judges"><span id="contest-judges"></span>Panel of judges</h2> |
121 <span id="contest-judges"></span><h2 id="panel-of-judges"><span id="contest-judg
es"></span>Panel of judges</h2> | |
122 <p>Google recruited the following group of distinguished security experts | 119 <p>Google recruited the following group of distinguished security experts |
123 to serve as judges for the Native Client security contest:</p> | 120 to serve as judges for the Native Client security contest:</p> |
124 <section id="chair"> | |
125 <h3 id="chair">Chair</h3> | 121 <h3 id="chair">Chair</h3> |
126 <table border="1" class="docutils"> | 122 <table border="1" class="docutils"> |
127 <colgroup> | 123 <colgroup> |
128 </colgroup> | 124 </colgroup> |
129 <tbody valign="top"> | 125 <tbody valign="top"> |
130 <tr class="row-odd"><td>Edward Felten</td> | 126 <tr class="row-odd"><td>Edward Felten</td> |
131 </tr> | 127 </tr> |
132 <tr class="row-even"><td>Princeton University</td> | 128 <tr class="row-even"><td>Princeton University</td> |
133 </tr> | 129 </tr> |
134 <tr class="row-odd"><td><a class="reference external" href="http://www.cs.prince
ton.edu/~felten/">http://www.cs.princeton.edu/~felten/</a></td> | 130 <tr class="row-odd"><td><a class="reference external" href="http://www.cs.prince
ton.edu/~felten/">http://www.cs.princeton.edu/~felten/</a></td> |
135 </tr> | 131 </tr> |
136 </tbody> | 132 </tbody> |
137 </table> | 133 </table> |
138 </section><section id="judges"> | |
139 <h3 id="judges">Judges</h3> | 134 <h3 id="judges">Judges</h3> |
140 <table border="1" class="docutils"> | 135 <table border="1" class="docutils"> |
141 <colgroup> | 136 <colgroup> |
142 </colgroup> | 137 </colgroup> |
143 <tbody valign="top"> | 138 <tbody valign="top"> |
144 <tr class="row-odd"><td>Alex Halderman</td> | 139 <tr class="row-odd"><td>Alex Halderman</td> |
145 <td>Niels Provos</td> | 140 <td>Niels Provos</td> |
146 <td>Bennet Yee</td> | 141 <td>Bennet Yee</td> |
147 </tr> | 142 </tr> |
148 <tr class="row-even"><td>University of Michigan</td> | 143 <tr class="row-even"><td>University of Michigan</td> |
(...skipping 23 matching lines...) Expand all Loading... |
172 <tr class="row-even"><td>Harvard University</td> | 167 <tr class="row-even"><td>Harvard University</td> |
173 <td>Rice University</td> | 168 <td>Rice University</td> |
174 <td><div class="first last"> </div></td> | 169 <td><div class="first last"> </div></td> |
175 </tr> | 170 </tr> |
176 <tr class="row-odd"><td><a class="reference external" href="http://www.eecs.harv
ard.edu/~greg/">http://www.eecs.harvard.edu/~greg/</a></td> | 171 <tr class="row-odd"><td><a class="reference external" href="http://www.eecs.harv
ard.edu/~greg/">http://www.eecs.harvard.edu/~greg/</a></td> |
177 <td><a class="reference external" href="http://www.cs.rice.edu/~dwallach/">http:
//www.cs.rice.edu/~dwallach/</a></td> | 172 <td><a class="reference external" href="http://www.cs.rice.edu/~dwallach/">http:
//www.cs.rice.edu/~dwallach/</a></td> |
178 <td><div class="first last"> </div></td> | 173 <td><div class="first last"> </div></td> |
179 </tr> | 174 </tr> |
180 </tbody> | 175 </tbody> |
181 </table> | 176 </table> |
182 </section></section><section id="additional-information"> | |
183 <h2 id="additional-information">Additional information</h2> | 177 <h2 id="additional-information">Additional information</h2> |
184 <p>For additional information about the Native Client security contest, | 178 <p>For additional information about the Native Client security contest, |
185 see the archived | 179 see the archived |
186 <a class="reference internal" href="/native-client/community/security-contest/co
ntest-announcement.html"><em>Contest Announcement</em></a>, | 180 <a class="reference internal" href="/native-client/community/security-contest/co
ntest-announcement.html"><em>Contest Announcement</em></a>, |
187 <a class="reference internal" href="/native-client/community/security-contest/co
ntest-faq.html"><em>FAQ</em></a> and | 181 <a class="reference internal" href="/native-client/community/security-contest/co
ntest-faq.html"><em>FAQ</em></a> and |
188 <a class="reference internal" href="/native-client/community/security-contest/co
ntest-terms.html"><em>Terms & Conditions</em></a>.</p> | 182 <a class="reference internal" href="/native-client/community/security-contest/co
ntest-terms.html"><em>Terms & Conditions</em></a>.</p> |
189 <p>If you’d like to get involved with Native Client, you can:</p> | 183 <p>If you’d like to get involved with Native Client, you can:</p> |
190 <ul class="small-gap"> | 184 <ul class="small-gap"> |
191 <li>Use the <a class="reference external" href="/native-client/sdk/download">Nat
ive Client SDK</a> to build Native | 185 <li>Use the <a class="reference external" href="/native-client/sdk/download">Nat
ive Client SDK</a> to build Native |
192 Client web applications.</li> | 186 Client web applications.</li> |
193 <li>Submit <a class="reference external" href="http://code.google.com/p/nativecl
ient/issues/list">bugs</a> | 187 <li>Submit <a class="reference external" href="http://code.google.com/p/nativecl
ient/issues/list">bugs</a> |
194 and participate in the Native Client | 188 and participate in the Native Client |
195 <a class="reference external" href="http://groups.google.com/group/native-client
-discuss">discussion group</a>.</li> | 189 <a class="reference external" href="http://groups.google.com/group/native-client
-discuss">discussion group</a>.</li> |
196 <li>Contribute to the | 190 <li>Contribute to the |
197 <a class="reference external" href="http://code.google.com/p/nativeclient/">Nati
ve Client open-source project</a>.</li> | 191 <a class="reference external" href="http://code.google.com/p/nativeclient/">Nati
ve Client open-source project</a>.</li> |
198 </ul> | 192 </ul> |
199 </section></section> | 193 </section> |
200 | 194 |
201 {{/partials.standard_nacl_article}} | 195 {{/partials.standard_nacl_article}} |
OLD | NEW |