Tech Hammer

Chapter 347 Explosive Pack

There were more than ten phone calls, and March was a witness to the whole process.

Of course, it can also be evaluated in this way. In the first two days when Ning Wei came to the laboratory, he had not done anything serious yet, and the various instruments and equipment in the laboratory had not had time to move, but he had already created a lot of benefits for the laboratory—— Cybersecurity benefits.

In addition to thoughtfully informing hardware manufacturers, operating system providers, and cloud service providers, Ningwei also thoughtfully informed Facebook and Twitter of the large-scale privacy leaks that may be caused by third-party applications, such as Allows attackers to easily see content that users have set as private on Facebook and Twitter.

Then Ningwei packaged all these vulnerabilities to China's official network security threat and vulnerability information platform in a legal and compliant manner.

Nothing will happen to him next.

According to the established rules, after the platform receives and confirms the existence of these vulnerabilities, it will be shared with major network security companies that cooperate with the platform to patch these vulnerabilities as soon as possible to ensure the security of China's overall network to the greatest extent.

Later, Ning Wei also felt that his mood was much brighter, which was enough to prove how correct the law of conservation of emotions was. This should be enough to show that someone must be in a less than beautiful mood at this time.

To be honest, Ning Wei's way of handling it is very unreasonable.

There is no evidence that these big companies participated in yesterday's grand carnival on the Internet. If we must say who should be responsible, it should be the unscrupulous media.

But Ning Wei obviously doesn't think so. The main reason is that he doesn't have the ability or time to reason with the media, right?

In other words, dealing with the media is not an area that Ning Wei is good at, so it is better to simplify complex things and slap whoever is in the face easily.

"Bang bang bang..."

Ning Wei had just packaged all the vulnerabilities reported to major companies and submitted them to China's official network security threat and vulnerability information platform. There was a knock on the door, and he quickly responded: "Please come in."

Without any surprise, Liu Wei opened the door and came in at this time, still holding the breakfast brought for him.

Seeing Ning Wei sitting at the computer neatly dressed, Liu Wei was obviously stunned, probably thinking that Ning Wei hadn't gotten up yet.

"Woke up?"

"Yes, I got up early. I just did a lot of things in the name of the laboratory." Ning Wei nodded and replied.

"Oh!" Liu Wei didn't think much and handed over the bag in his hand: "I just went to the cafeteria to eat, and I brought you steamed buns and soy milk by the way."

"Thank you for your hard work, Brother Liu." Ning Wei said with emotion.

Speaking of which, Liu Wei rarely brings food to Ning Wei. This is the first time in memory. It wasn't that Liu Wei was so cold that he didn't bother to do such a thing, but that Liu Wei was almost inseparable from him in such a special place.

Even if Ning Wei goes home, Liu Wei lives in the next building and is always available, so naturally he can't do things like bring food. So Ning Wei's feeling was not that he brought this breakfast, but that Liu Wei usually didn't have time to eat breakfast by himself.

"Actually, it's not hard work at all. It's pretty leisurely. I've almost finished reading the complete works of Gu Long." Liu Wei commented on his work very pertinently. Being able to be so free is mainly thanks to Ning Wei who doesn't like to go out and run around, and spends most of his time in the Mathematics Research Center of Yanbei University.

"By the way, Ning Wei, in fact, I have never recommended that you use too much public domain social media such as Weibo. With your current status, there is no need to do so. In other words, you are too young. If you were discovered earlier, , I guess they won’t let you register for something like Weibo.” Liu Wei said sincerely.

Obviously, he was also aware of the controversy on the Internet yesterday, and these words were to advise Ning Wei not to be affected by those comments on the Internet.

"It's okay, Brother Liu, do you think I care about the scolding on the Internet? You underestimate me too much. It's impossible for such a small thing to affect my mentality. And I've already vented my anger. Now Not only do I not have any negative emotions, I am even quite happy." Ning Wei replied with a smile on his face.

This sentence made Liu Wei become wary, and he subconsciously touched the mobile phone in his pocket. The corners of his mouth couldn't help but began to twitch, showing a wry smile, and asked: "Ning Wei, right? You went to Weibo again to follow Are those people in line?"

"Haha, Brother Liu, you underestimate me too much. Let me give you an inappropriate analogy. If a naughty child messes with me, shouldn't I go to the parents and give the child a good beating? No. , this analogy is too inappropriate, let’s put it this way, if I encounter a dog biting me on the road, if I don’t go to the dog owner to cause trouble, am I going to care about the dog?” Ning Wei said with a laugh.

"Uh?" Liu Wei was stunned, stared at Ning Wei, and asked, "So what did you do just now?"

"Nothing, I just reported some of the major hardware, system and software vulnerabilities discovered and sorted out in our laboratory to the company in accordance with internationally accepted procedures, and then packaged and provided these vulnerabilities in the name of the laboratory It gives us a safe platform. Brother Liu, you know me, we must handle everything in accordance with the law and rules. Even if we feel very uncomfortable, we must not go beyond the rules." Ning Wei explained seriously.

This is beautifully said and there is absolutely nothing wrong with it!

Liu Wei stood there stunned for a moment and asked seriously: "So how many product bugs, or vulnerabilities, are involved?"

Ning Wei picked up the bun, took a bite, and said vaguely: "Not much. I selected the products of several companies in the order of the technology stocks on the US stock market that are closest to me, Intel, Microsoft, Google, Oracle, Facebook, Twitter, IBM... In addition to Turbulence Algorithm, I asked Huawei to inform all foreign companies that they may not renew their contracts in the future and stop providing activation codes. In total, there are exactly 13 companies affected. It is said that they are not very If I like the number, I’ll use it.”

"The vulnerability level is still weaker than the Java vulnerability you announced a few days ago, right?"

"This...is about the same? If we follow the common classification standards, they should all be vulnerabilities of the same level. This kind of problem is inevitable.

Liu Wei nodded and did not continue to ask, but his expression was a little heavy, probably because he felt that the burden on his shoulders was heavier.

"Then have you ever considered the possibility that the dogs that are biting you around are some inexplicable mad dogs without an owner? Or that the companies you are causing trouble for have nothing to do with the matter itself?"

"Oh, I thought about it. But what does this have to do with me? Brother Liu, let's not worry about so many rules and regulations when doing things. Let me analyze it for you. Professor Flanders passed away. I discussed the future operating system with everyone online. Who connected these two unrelated things first? It was on the Internet! So there is no chance of accidental harm. I can’t just go to Facebook to find them just for such a nonsense. Is there any washing powder? That’s really illegal.”

Ning Wei explained seriously.

Perfect……

Liu Wei felt that there was nothing more to say.

In fact, Liu Wei had less communication with Lu Dongyi. If he had more communication, he would know that this logic is a routine operation. But if you really want to dig deeper from a logical point of view, Ning Wei is actually very reasonable and a standard reciprocal operation.

"Well, that's good. Then... come on, I'm going to talk to Mr. Chen about something first."

"What are you talking about? Are you in such a hurry?"

"Mr. Chen seems to have forgotten to arrange an external spokesperson position for the research center. I might have thought that it was not needed for the time being, but now it seems that it should still be needed. What do you think?" Liu Wei explained.

"Oh...Actually, I don't think it's necessary. If anyone has questions, just ignore them. But if you think it's necessary, just arrange one." Ning Wei nodded and replied.

"It's still necessary. Times have changed. If something big happens these days, you have to give everyone an explanation. No matter what you think in your heart, your words must sound nice. I'll go first."

"Well, go ahead, Brother Liu!"

Liu Wei was right, Ning Wei thought everything was too simple.

Think about it, an epic vulnerability in Java has caused such a stir that many Java programmers are still working overtime day and night. More than 10 vulnerabilities of the same level were suddenly exposed, and they directly covered almost all mainstream hardware devices and popular social software in the world. How big is the scope of the impact? It is obvious that one thing is for sure, many people have to work overtime.

Ning Wei's phone number couldn't be reached again.

The reason why I use the word "you" is because many big bosses from related technology companies have had the experience of being directly rejected when calling Ningwei.

After contacting him, he was added to his address book by Ning Wei. However, after receiving the terrifying message from Ning Wei in a fast tone, he wanted to call again, but found that he couldn't get through.

This is very confusing.

Because the bosses wanted to explain to Ning Wei, the rules he followed were obviously wrong.

According to internationally accepted rules, when a security technician or organization discovers a vulnerability or BUG, ​​it is not enough to notify the developer. Instead, the details of the vulnerability or BUG should be provided to the developer so that the developer can immediately Test and then figure out how to close the holes. Rather than making a phone call to inform them, and then providing these vulnerabilities to third parties!

But nothing, nothing.

Ning Wei just told them that his product had a serious flaw that might cause an accident. He didn't even give them a chance to interrupt and asked a few more questions, so he hung up the phone. When he called again, he couldn't get through.

Can you understand the emotions of the big guys who want to blow themselves up at this time?

Some big bosses immediately opened their own mailboxes and even called to ask whether the publicly disclosed mailboxes for collecting bugs had received new 0DAY vulnerability reports, but they had not!

It is no exaggeration to say that at this moment, the idea of ​​a group of big guys to kill Ning Wei was about to reach its peak.

After all, if such a major BUG is exposed in advance and the company does not take any countermeasures, it will seriously damage the goodwill. The most important thing is the possible losses.

Especially for Intel, it is really troublesome.

Hardware vulnerabilities are difficult to repair, let alone on the latest CPUs. If it really causes a global security incident, it will be extremely troublesome.

Of course, it is also difficult for software companies like Google, Facebook, and Twitter.

Can software vulnerabilities allow people to directly access the privacy settings set by users?

Are you kidding me? If the vulnerability is exposed and they are unable to seal it, causing a large number of users to make their private content visible only to themselves public and disseminated on the Internet, a class action lawsuit may result in astronomical damages.

Especially for the bosses of Facebook and Twitter, they felt even worse after answering Ning Wei's call.

The products of these two companies are basically zero in the Chinese market. After all, the content of these two companies is basically inaccessible through normal networks, so why is Ningwei submitting its own vulnerabilities to the China Network Security and Vulnerability Information Center? To put it simply, it is not scary to have loopholes and bugs in software or hardware. What is scary is who controls these loopholes and bugs.

But no one dared not to take Ning Wei's call seriously.

Not to mention the achievements that Ning Wei has achieved, the impact of the previous exposure of Java vulnerabilities has not completely dissipated, and if you understand the causes and consequences, you will know that Ning Wei exposed Java's epic vulnerabilities just to vent his anger on his students, and he did it casually , Lenovo Ning Wei’s laboratory has the world’s strongest and currently only strong artificial intelligence platform...

You can imagine how confused these big guys are at this moment.

What's even more irritating is that I'm really stuck at this point in time, just after getting off work...

At this time, the bosses didn't know that they were not the only ones who received the call.

Of course, apart from the big guys who were shocked when they were suddenly told that their products had serious vulnerabilities, network equipment providers represented by Cisco were also confused.

The sudden emergency e-mail from Huawei is so sudden that people are stunned?

The wording of the official letter is quite implicit, but what it actually means is that Professor Ning Wei, the developer of the turbulence algorithm, was in a bad mood because of the slanderous remarks on the Internet, so he informed Huawei that after the contract for the right to use the turbulence algorithm expired, No longer authorize external parties, stop providing activation codes to external parties...

Of course, you don’t have to worry too much, because Huawei will still act in accordance with the contract during the contract period and ensure that the supply of activation codes during the contract period will not be interrupted.

The only good news is that the contract signed before expires in about half a year. But if this matter is not resolved, what will happen in half a year? In the current global network equipment market, loading turbulence algorithm security chips has become the most basic configuration. In the past, those devices that did not load turbulence algorithm chips were sold to the third world at low prices by clearing inventory. In other words, this official letter If implemented, it will directly disrupt the new equipment research and development plans of these companies...

It cannot be said that these network equipment companies are not working hard enough.

In fact, over the past year, many engineers have been working hard to analyze the source code of the turbulence algorithm, trying to reversely restore the original version through various means, or develop products with similar functions. It’s just that no one has been successful yet, so if they suddenly announced not to renew the contract at this time, wouldn’t it cost lives?

What's even more annoying is that Ning Wei is in a bad mood, so why should he have surgery on them? Where does this make sense? Well, who doesn’t have eyes? Who is not good to offend? The boss who is least afraid of causing trouble? Is this because you feel that your life is too good?

A bunch of people's heads are "buzzing"...

At this time, it was not only these foreign big guys who were "buzzing" in their heads. The technical staff of the China Network Security Threat Information Sharing Platform were also quite confused at this time.

Guo Xianming was in extremely complicated mood at this time.

As a technician working in the national security technology department, he has been in the industry for 12 years. This is the first time that he has seen an organization submit vulnerabilities in a packaged form. What is even more frightening is that these vulnerabilities are not on the same platform. There are hardware, operating systems, and application software...

Moreover, these hardware and software also represent the world's top 50 technology companies.

What's even more frightening is that just by glancing at the descriptions of these vulnerabilities, you will find that any one of these vulnerabilities exposed is a king-level existence. Exposed together, it is enough to make the Internet "neutralized" by those hackers. It’s time…

From a professional's perspective, is this a vulnerability package? This is a fucking explosive bag!

If you change the perspective, you can also say that this is a vulnerability package or a dollar package.

Guo Xianming is very aware of the value of these vulnerabilities. Even if he provides these vulnerabilities to developers through completely formal channels to earn rewards, these vulnerabilities can add up to at least millions of dollars. If you go the illegal route and sell these vulnerabilities through some illegal trading platforms, you can probably make ten times or even a hundred times the profit.

Although you can make a lot of money through underground channels, it still depends on whether you have the strength to spend it. It is better to use formal platforms to make people feel at ease.

So here’s the problem. Although the China Cyber ​​Security Threat Information Sharing Platform is an official platform, it is still a third-party security vulnerability sharing platform in the world. As far as Guo Xianming knows, generally speaking, if you want to make money from these security vulnerabilities through formal channels, developers will require vulnerability providers to not allow providers to disclose to third-party platforms before officially providing updated patch packages to solve these vulnerabilities. details of these security vulnerabilities.

Who is this, giving up millions of dollars just to give up?

I glanced at the submitting unit, China Frontier Intelligent Technology R\u0026D Laboratory, the submitter - Ning Wei.

Oh, no problem then.

For a billionaire who spends hundreds of millions on various bonuses at every turn, a few million dollars is probably just a drop in the bucket.

Of course, the moment he saw the unit and name, Guo Xianming also knew that this vulnerability package was most likely not a joke.

So the first thing to do is of course...throw this explosive bag out quickly...Although this is a lifetime series, seeing so many loopholes at once, Guo Xianming really didn't dare to follow the previous steps to remove these loopholes. All distributed to sharing partners...

What if it's leaked?

Just when he was about to report to the boss, the phone rang first.

"Hey, Xiao Guo, are you on duty, right? Did Professor Ning upload a vulnerability package to the platform today? Well, okay, don't take the conventional test route, there will be specialized experts to verify it. Experts almost there."

Tap the screen to use advanced tools Tip: You can use left and right keyboard keys to browse between chapters.

You'll Also Like