Pwn2Own Tokyo hacking contest trashed, export rules blamed

Sponsor HP stumped by Wassenaar Arrangement cluster-fsck


The Cold War has reached out a long-dead hand to stifle the Pwn2Own hackfest in Tokyo – with the international Wassenaar Arrangement blamed for the event's cancelation.

Organized by the HP TippingPoint-backed Zero Day Initiative, Pwn2Own slings bounties to researchers who find and exploit security bugs in popular software and gear.

But it seems that this year, nobody could work out whether vulnerabilities revealed in Tokyo could be brought back to the US and elsewhere without breaking the Wassenaar treaty, which is an agreement between 41 nations including the US and Japan.

An HP spokesperson told The Register via email that the Zero-Day Initiative made the decision to cancel the event, writing: "Due to the complexity of obtaining real-time import/export licenses in countries that participate in the Wassenaar Arrangement, the ZDI has notified conference organizer Dragos Ruiu that it will not be holding the Pwn2Own contest at PacSecWest in November."

Ruiu had previously tweeted that HP pulled its sponsorship and that he intends to try and host some kind of hackfest in its place:

He also told Ars that HP had lawyered up to the tune of US$1 million to test the legal risk of Pwn2Own in a post-Wassenaar world, but decided it was untenable.

HP confirmed to The Register that it had worked with its lawyers on the issue, but wouldn't comment on how much it had cost.

Hackers had already expressed their concern that Pwn2Own was at risk, since it's open to the interpretation that trafficking flaws across borders is banned in light of the Wassenaar Arrangement.

The text added last year to Wassenaar, which was originally a Cold War-era arms-control pact, forbids the export of:

Software "specially designed" or modified to avoid detection by "monitoring tools," or to defeat "protective countermeasures," of a computer or network-capable device, and performing any of the following:

(a) The extraction of data or information, from a computer or network-capable device, or the modification of system or user data; or (b) The modification of the standard execution path of a program or process in order to allow the execution of externally provided instructions.

As The Register noted in June, that language could stretch far beyond hacks and exploits, since it could also be read to mean that antivirus can't be exported.

While the US has toned down its approach to implementing the Wassenaar treaty, Ars says the problem for Pwn2Own is Japan's "cumbersome" and "vague" implementation of the agreement.

It's also all colossally convenient for HP, which is apparently considering ejecting its Tipping Point biz ahead of its corporate split. ®

Editor's note: This article has been tweaked to clarify the situation: the problem is exporting the vulnerability information out of Japan, due to that country's implementation of the treaty, rather than a problem with America's rules.

Similar topics

Narrower topics


Other stories you might like

  • Twitter founder Dorsey beats hasty retweet from the board
    As shareholders sue the social network amid Elon Musk's takeover scramble

    Twitter has officially entered the post-Dorsey age: its founder and two-time CEO's board term expired Wednesday, marking the first time the social media company hasn't had him around in some capacity.

    Jack Dorsey announced his resignation as Twitter chief exec in November 2021, and passed the baton to Parag Agrawal while remaining on the board. Now that board term has ended, and Dorsey has stepped down as expected. Agrawal has taken Dorsey's board seat; Salesforce co-CEO Bret Taylor has assumed the role of Twitter's board chair. 

    In his resignation announcement, Dorsey – who co-founded and is CEO of Block (formerly Square) – said having founders leading the companies they created can be severely limiting for an organization and can serve as a single point of failure. "I believe it's critical a company can stand on its own, free of its founder's influence or direction," Dorsey said. He didn't respond to a request for further comment today. 

    Continue reading
  • Snowflake stock drops as some top customers cut usage
    You might say its valuation is melting away

    IPO darling Snowflake's share price took a beating in an already bearish market for tech stocks after filing weaker than expected financial guidance amid a slowdown in orders from some of its largest customers.

    For its first quarter of fiscal 2023, ended April 30, Snowflake's revenue grew 85 percent year-on-year to $422.4 million. The company made an operating loss of $188.8 million, albeit down from $205.6 million a year ago.

    Although surpassing revenue expectations, the cloud-based data warehousing business saw its valuation tumble 16 percent in extended trading on Wednesday. Its stock price dived from $133 apiece to $117 in after-hours trading, and today is cruising back at $127. That stumble arrived amid a general tech stock sell-off some observers said was overdue.

    Continue reading
  • Amazon investors nuke proposed ethics overhaul and say yes to $212m CEO pay
    Workplace safety, labor organizing, sustainability and, um, wage 'fairness' all struck down in vote

    Amazon CEO Andy Jassy's first shareholder meeting was a rousing success for Amazon leadership and Jassy's bank account. But for activist investors intent on making Amazon more open and transparent, it was nothing short of a disaster.

    While actual voting results haven't been released yet, Amazon general counsel David Zapolsky told Reuters that stock owners voted down fifteen shareholder resolutions addressing topics including workplace safety, labor organizing, sustainability, and pay fairness. Amazon's board recommended voting no on all of the proposals.

    Jassy and the board scored additional victories in the form of shareholder approval for board appointments, executive compensation and a 20-for-1 stock split. Jassy's executive compensation package, which is tied to Amazon stock price and mostly delivered as stock awards over a multi-year period, was $212 million in 2021. 

    Continue reading
  • Confirmed: Broadcom, VMware agree to $61b merger
    Unless anyone out there can make a better offer. Oh, Elon?

    Broadcom has confirmed it intends to acquire VMware in a deal that looks set to be worth $61 billion, if it goes ahead: the agreement provides for a “go-shop” provision under which the virtualization giant may solicit alternative offers.

    Rumors of the proposed merger emerged earlier this week, amid much speculation, but neither of the companies was prepared to comment on the deal before today, when it was disclosed that the boards of directors of both organizations have unanimously approved the agreement.

    Michael Dell and Silver Lake investors, which own just over half of the outstanding shares in VMware between both, have apparently signed support agreements to vote in favor of the transaction, so long as the VMware board continues to recommend the proposed transaction with chip designer Broadcom.

    Continue reading
  • Perl Steering Council lays out a backwards compatible future for Perl 7
    Sensibly written code only, please. Plus: what all those 'heated discussions' were about

    The much-anticipated Perl 7 continues to twinkle in the distance although the final release of 5.36.0 is "just around the corner", according to the Perl Steering Council.

    Well into its fourth decade, the fortunes of Perl have ebbed and flowed over the years. Things came to a head last year, with the departure of former "pumpking" Sawyer X, following what he described as community "hostility."

    Part of the issue stemmed from the planned version 7 release, a key element of which, according to a post by the steering council "was to significantly reduce the boilerplate needed at the top of your code, by enabling a lot of widely used modules / pragmas."

    Continue reading

Biting the hand that feeds IT © 1998–2022