SYS-CON MEDIA Authors: Pat Romanski, Elizabeth White, Glenn Rossman, Cynthia Dunlop, Peter Silva

News Feed Item

Hackers Mobilize to Attack Routers via ISE Contest

An elite competition is scheduled for hackers and computer scientists from around the world to better protect consumers against widespread security vulnerabilities in wireless routers. A series of studies1 in 2013 discovered a security epidemic affecting small office/home office (SOHO) WiFi routers, wherein vulnerabilities allow an attacker to take control of the device and thereby intercept and modify network traffic. Abundant news coverage over the past 15 months has extensively reported the malicious exploitation of these devices, yet the epidemic persists today with little progress made by router manufacturers to address the issues. By bringing together the brightest minds in security, the hacking competition, dubbed “SOHOpelessly Broken” after the seminal research of the same title, seeks to identify new and existing security vulnerabilities in these widely deployed devices. “By demonstrating that the issues persist and that consumers are still exposed, pressure will be applied to the manufacturers to take the necessary action to better protect their customers who are currently not empowered to protect themselves,” says Steve Bono, founder of ISE and one of the leaders of the event.

The competition will run during the renowned DEFCON hacker conference, from 7-10 August 2014 at the Rio Hotel & Casino in Las Vegas, NV. The contest will host a range of activities, including multiple talk tracks, Capture the Flag, 0-day vulnerability discovery, and others. The contest is organized by a partnership between two leading entities in the security community: Independent Security Evaluators (ISE) and the Electronic Frontier Foundation (EFF). ISE is the respected cyber security company most commonly known for being first to hack the iPhone and most recently for discovering the epidemic of security vulnerabilities in routers. The EFF is the leading nonprofit organization defending civil liberties in the digital world. DEFCON is one of the largest and oldest annual hacker conferences.

“The outcome of this event will be two-fold,” says Ranga Krishnan of the EFF. “First, we will prove that routers are still vulnerable. Second, we will galvanize a community of technologists to demand remediation by manufacturers.” EFF is also driving a related initiative known as the Open Wireless Movement (https://openwireless.org). In order to support this initiative, the EFF is developing a router on which users can confidently turn on an open WiFi channel that provides private internet access to guest users, without compromising the users' own security, privacy or internet experience.

Individuals interested in participating as contestants or as judges are encouraged to contact contest organizers as soon as possible through the contest website, www.sohopelesslybroken.com. Available spots are limited. Sponsorship and advertising opportunities are also available. The official hashtag of the event is #sohopelesslybroken.

About ISE

ISE is most commonly recognized for being the first company to exploit the iPhone2, an achievement that garnered international attention. ISE’s most recent research discovered systemic issues in SOHO routers3 and web browsers4.

About EFF

The Electronic Frontier Foundation is the leading nonprofit organization defending civil liberties in the digital world. Founded in 1990, EFF champions user privacy, free expression, and innovation through impact litigation, policy analysis, grassroots activism, and technology development. We work to ensure that rights and freedoms are enhanced and protected as our use of technology grows.

1 http://securityevaluators.com/content/case-studies/routers/soho_router_hacks.jsp
2 http://www.nytimes.com/2007/07/23/technology/23iphone.html?_r=2&
3 http://securityevaluators.com/content/case-studies/routers/soho_router_hacks.jsp
4 http://securityevaluators.com/content/case-studies/caching/index.jsp

More Stories By Business Wire

Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

Latest Stories
Explosive growth in connected devices. Enormous amounts of data for collection and analysis. Critical use of data for split-second decision making and actionable information. All three are factors in making the Internet of Things a reality. Yet, any one factor would have an IT organization pondering its infrastructure strategy. How should your organization enhance its IT framework to enable an In...
The major cloud platforms defy a simple, side-by-side analysis. Each of the major IaaS public-cloud platforms offers their own unique strengths and functionality. Options for on-site private cloud are diverse as well, and must be designed and deployed while taking existing legacy architecture and infrastructure into account. Then the reality is that most enterprises are embarking on a hybrid cloud...
StackIQ offers a comprehensive software suite that automates the deployment, provisioning, and management of Big Infrastructure. With StackIQ’s software, you can spin up fully configured big data clusters, quickly and consistently — from bare-metal up to the applications layer — and manage them efficiently. Our software’s modular architecture allows customers to integrate nearly any application wi...
In her General Session at 15th Cloud Expo, Anne Plese, Senior Consultant, Cloud Product Marketing, at Verizon Enterprise, will focus on finding the right mix of renting vs. buying Oracle capacity to scale to meet business demands, and offer validated Oracle database TCO models for Oracle development and testing environments. Anne Plese is a marketing and technology enthusiast/realist with over 19...
As Platform as a Service (PaaS) matures as a category, developers should have the ability to use the programming language of their choice to build applications and have access to a wide array of services. Bluemix is IBM's open cloud development platform that enables users to easily build cloud-based, creative mobile and web applications without having to spend large amounts of time and resources o...
The Internet of Things will greatly expand the opportunities for data collection and new business models driven off of that data. In her session at Internet of @ThingsExpo, Esmeralda Swartz, CMO of MetraTech, will discuss how for this to be effective you not only need to have infrastructure and operational models capable of utilizing this new phenomenon, but increasingly service providers will nee...
When you set off to build an app that will change the world, designing your system architecture to be reliable and scalable is important but the stark reality is that, for your MVP, you probably had a “need for speed” (of development). You didn’t know what all the axes were to scale your application, where your stress points would be, and what weird and wonderful ways your customers would use it d...
Compute virtualization has been transformational, yet security policy implementation and enforcement has lagged behind in agility and automation. There are a number of key considerations when implementing policy in private and hybrid clouds. In his session at 15th Cloud Expo, Holland Barry, VP of Technology at Catbird, will discuss the impact of this new paradigm and what organizations can do to...
Samsung VP Jacopo Lenzi, who headed the company's recent SmartThings acquisition under the auspices of Samsung's Open Innovaction Center (OIC), answered a few questions we had about the deal. This interview was in conjunction with our interview with SmartThings CEO Alex Hawkinson. IoT Journal: SmartThings was developed in an open, standards-agnostic platform, and will now be part of Samsung's Ope...
SYS-CON Events announced today that Red Hat, the world's leading provider of open source solutions, will exhibit at Internet of @ThingsExpo, which will take place on November 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA. Red Hat is the world's leading provider of open source software solutions, using a community-powered approach to reliable and high-performing cloud, Linux, ...