Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Great story. It's not often I find myself reading through to the end.

>Hilbert arranged for the FBI to rent Popov an apartment near the beach and pay him a $1,000-a-month stipend to continue working on Ant City.

Talk about cheap! They offered him ~$3,000/mo compensation for work that was saving the US potentially hundreds of millions of dollars per year in fraudulent credit card charges?

>One victim was the Boston-based multinational EMC, where intruders had stolen the source code for the company’s ubiquitous virtualization software, VMware. If the code got out, hackers everywhere could plumb it for security holes. VMware’s purpose is to allow a single server to house multiple virtual computers, each walled off from the others. So in the worst-case scenario, a hacker might find a way to “escape” from a virtual machine and seize control of the underlying system.

And this just screams of the need for more open source projects.



If VMware's security relies on it being closed source, then all bets are off. This is bad journalism.


I think that doing security audits only when your source code leaks (not even when somebody threatens to leak it) is bad software development, not bad journalism.


It's bad development style, but it's also bad journalism to say the blueprints are out, now VMware is at risk. VMware is so widely used in critical situations that it's more than likely that many skilled infosec devs have tried their teeth at finding attack vectors. Sure, they may have an easier way to find some faults now, but like Windows, it's a piece of software that's in constant exploit hunt mode.


Well, they pretty much described what actually happened, which is that VMware wasn't all that confident about their security and panicked when the source appeared.

While I too would like the article to poke some fun at VMware's attitude ;) I have to say I really didn't find it particularly offensive as it stands.

I understand the dislike for presenting closed source as "security", but in this case it seems to have been uninformed copy-paste from VMware's statements, not the author's agenda. I guess we can only expect so much from journalists who don't hang out at HN. Hopefully this whole myth will die natural death as open source OSs are becoming mainstream, especially on servers where security counts.


I guess the wording got me.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: