• On TechRepublic: Five reasons why Windows Vista failed

March 8, 2006 5:23 PM PST

University nixes Mac hacker contest

  • Print
A Mac OS X hacker challenge apparently got a systems engineer at the University of Wisconsin-Madison into trouble with university administrators.

Dave Schroeder on Monday invited hackers to break into a Mac Mini he attached to the university network. The challenge would last until Friday, he announced. The contest was in response to an earlier challenge, which Schroeder criticized as too easy.

But the event ended early--Tuesday night. On Wednesday, information emerged that the contest had drawn the scrutiny of the university's chief information officer, Annie Stunden.

"The Mac OS X 'challenge' was not an activity authorized by the UW-Madison," Brian Rust, a university spokesman, said in an e-mailed statement. "Once the test came to the attention of our CIO, she ended it...Our primary concern is for security and network access for UW services."

The same statement also appeared on Schroeder's challenge Web site Wednesday afternoon. (His site, http://test.doit.wisc.edu, was down as of Thursday morning.)

"Dave was well-meaning, but he did the test pretty much on his own," Rust said in a phone interview.

Universities are often the target of cyberattacks. The academic institutions face the challenge of balancing the need to share information on large networks with the need to secure data.

The Mac OS X contest ended without a negative impact on the University of Wisconsin-Madison's network, Rust said. "We were able to handle the traffic, and there were no compromises to university systems," he said. The university apologized for any inconvenience its action caused to the Mac community.

The university is distancing itself from the challenge. "If Dave wants to continue this test, he has to do that privately, not using university systems," Rust said.

Schroeder had said he wants to publish some details on the attempts that were made to hack his Mac. The computer was connected to the Net for more than 30 hours, apparently without being compromised. In the earlier challenge, an anonymous hacker claimed he was able to compromise OS X within 30 minutes using an undisclosed vulnerability. However, attackers in that case had been given user-level access to the system rather than being shut out completely.

These hacker challenges came after weeks of scrutiny of the safety of OS X, prompted by the discovery of two worms, and the disclosure of a serious vulnerability. Security experts are also questioning the effectiveness of Apple's latest patch.

See more CNET content tagged:
university, Apple Mac OS X, hacker, Apple Mac OS, Apple Macintosh

Add a Comment (Log in or register) 31 comments
Annie, Annie, Annie
by ppgreat March 8, 2006 5:36 PM PST
Lighten up. Unless, of course, you're running Windows servers.
Reply to this comment
you lighten up
by techguy83 March 8, 2006 5:54 PM PST
As the CIO, she has the right to shut down the test, because her job is to make sure all data at that university is secure, no matter what. He also did it without permission, so she was well within her authority to shut it down.
Makes sense
by iKenny March 8, 2006 6:00 PM PST
The University definitely had the right to shut this down. I'm sure it
was causing unnecessary load on their servers. It's still impressive
that this Mac made it so long w/o compromise, however ;)
View reply
A real test
by schubb March 9, 2006 7:40 AM PST
I want to see a real test, boxes behind firewalls, private routers, etc. don't count to me. The average user is lucky to have a router that has NAT. I want to see out of the box, connected to a cable modem, on the net, test.

The Windows people and the Mac people should only accept these types of tests, no other 3rd party interference. No firewalls(outside built in OS ones and to use these they must be at default settings) or anything else, this tests the OS security which is what would settle this once and for all. Every 3rd party router, firewall, A/V etc only proves that if you know how to configure your box it is safe. That is not the question being raised here.
View reply
C/Net could host challenge
by J.G. March 8, 2006 6:20 PM PST
Hopefully, a tech site that can dedicate an isolated server to the
purpose will host the challenge. Hmmm. How about C/Net?
Reply to this comment
Windows box is up . . .
by rbannon March 8, 2006 6:42 PM PST
Visit 71.56.240.67 to see another challenge, this time it's a
Windows box.
Reply to this comment
Windows box is up . . .
by rbannon March 8, 2006 6:43 PM PST
Visit 71.56.240.67 to see another challenge, this time it's a
Windows box.

Email ron <dot> bannon <at> gmail <dot> com if you need more
information.
Reply to this comment
There's someting wrong . . . .
by rbannon March 9, 2006 6:24 AM PST
This guy only has port 80 open!

Here's my port scan:


Port Scan has started ...

Port Scanning host: 71.56.240.67

Open TCP Port: 80 http
Port Scan has completed ...




View reply
Did you publically challenge hackers worldwide?
by open-mind March 8, 2006 7:06 PM PST
If not, that's not much of a comparison.
Reply to this comment
...that was in response to Catch23. Oops. NT
by open-mind March 8, 2006 7:10 PM PST
NT
Provide Annie some feedback
by stenar March 8, 2006 7:30 PM PST
Annie is an idiot. If you agree, let her know:
http://www.doit.wisc.edu/feedback.asp?path=annieblog
Reply to this comment
Annie the coward...
by tofino--2008 March 8, 2006 7:43 PM PST
Professor Schroeder makes a bold and potentially historic move
- an in-your-face challenge to the best of the best. And Mac
wins again, much to the dismay of those who champion or who
are locked into inferior systems. Make me king for three days,
and I'll add a $5000.00 prize to the successful hacker and, after
the contest, when the miniMac keeps humming along, cowards
like Annie can take their safe, careful, prudent, and backward
vision and shove off with the other bean-counters in the
accounting and internal auditing departments.

It's a mean world out there. It's time for Mac. We win. They lose.
End of line.
Reply to this comment
you know
by techguy83 March 8, 2006 8:57 PM PST
Calling someone doing her job a coward is kinda dumb.

She is in charge of data secuirty and making sure the bandwidth at the university is used properly.

He DID NOT ask for permission. Thus most of the university's bandwidth was going into this test. Bandwidth students may have needed for research purposes.


Why call the woman a coward for doing HER job.

What is it that you do? Are you an employer or employee? Would you want an employee doing something without permission? Yes? No?

Is your blind loyalty to Steve Jobs and Apple so great that you have to stoop to childish levels to make someone just doing her job look bad?

Hey, at least my friend doesn't have a c-net id. He considers Mac zealots idiots and calls MAC OSX a second rate OS.

ME? I say windows and macs both have good and bad parts. Its all in what you use it for.
View all 3 replies
Reality Check
by nerdler March 10, 2006 3:42 AM PST
Um... here's the scenario:

1. Support technician in the (non-academic) IT division of a major University sets up hacker challenge.
2. Without getting permission from anyone.
3. He refers to it on major IT sites as "academic" and plasters an official university logo on it, implying that he's a professor or academic (which he isn't... see http://das.doit.wisc.edu/), and has the University's blessing (which he obviously didn't).
4. Every script-kiddie on the planet heads for the UW's network.
5. The CIO finds out.
6. The CIO shuts it down before the UW's lawyers have her head on a pike. A wise move.
7. The CIO apologizes to the community for shutting it down.
8. Arm-chair analysts post poorly thought-out responses on teh intarweb.

That about the size of it?
Reality Check
by nerdler March 10, 2006 3:43 AM PST
Um... here's the scenario:

1. Support technician in the (non-academic) IT division of a major University sets up hacker challenge.
2. Without getting permission from anyone.
3. He refers to it on major IT sites as "academic" and plasters an official university logo on it, implying that he's a professor or academic (which he isn't... see http://das.doit.wisc.edu/), and has the University's blessing (which he obviously didn't).
4. Every script-kiddie on the planet heads for the UW's network.
5. The CIO finds out.
6. The CIO shuts it down before the UW's lawyers have her head on a pike. A wise move.
7. The CIO apologizes to the community for shutting it down.
8. Arm-chair analysts post poorly thought-out responses on teh intarweb.

That about the size of it?
Shouldn't Windows Vista be subjected to the same test.
by ServedUp March 8, 2006 10:10 PM PST
When Longhorn comes out I think some hackers should try the
same contest and see how if it does any better than OS X.

Now that would be a newsworthy story. Any CNET Editors ready for
that juicy bone of a story.
Reply to this comment
71.56.240.67
by rbannon March 9, 2006 3:53 AM PST
71.56.240.67
View reply
No
by Bill Dautrive March 11, 2006 12:43 PM PST
It will fail miserably. Since it is based on old, unsecure code, any fixes and those workarounds will be comprimised in short order.

Sure you can secure a windows box. Castrate many functions, install several third party apps and of course a firewall. A default setting + solid firewall on OSX and Linux is far more secure then any castrated, bloated windows box.

Always has been, always will. Unless MS pulls its head out and starts from scratch with security as the #1 priority rather then the afterthought it has always been at Redmond.
 See all 31 Comments >>
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Apple (2.60%) 2.09 82.58
Dow Jones Industrials (6.54%) 494.13 8,046.42
S&P 500 (6.32%) 47.59 800.03
NASDAQ (5.18%) 68.23 1,384.35
CNET TECH (5.95%) 56.25 1,002.00
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right