Steve Gibson (computer programmer)
March 26, 1955 |
Dayton, Ohio, U.S.
|Residence||Laguna Hills, California, U.S.|
|Education||University of California, Berkeley|
|Occupation||Software Engineer and
|Known for||Security Now! podcast on TWiT.tv|
Steven Maury ″Tiberius″ Gibson (born March 26, 1955, Dayton, Ohio, United States) is an American computer enthusiast, software engineer and security researcher who studied Electrical Engineering and Computer Science at the University of California, Berkeley. Gibson lives in Laguna Hills, California. In the early '80s, Gibson was best known for his work on light pen technology for use with Apple and Atari systems. In 1985, Gibson founded Gibson Research Corporation, best known for its SpinRite software.
He is an advocate of assembly language programming, and prides himself on writing smaller applications mostly in Intel x86 assembly language, including much of the code of the SpinRite hard disk utility used from the beginning of the PC era. He is one of several advocates of optimizing computer programs and reducing the size of their executables. In the 1990s, Gibson began to move into the computer security field, developing and distributing a number of free security tools, including the ShieldsUp! port-scanner, and the LeakTest firewall tester. In 2000, Gibson created one of the first adware removal programs, OptOut.
Gibson's latest publicly released works are SecurAble, last updated January 14, 2007 and more recently, DNS Benchmark, released September 30, 2010. SecurAble is a program that will tell the user if their CPU supports 64-bit computing, DEP (Data Execution Prevention) and hardware level virtualisation. DNS Benchmark is a utility used for obtaining DNS nameserver performance characterization, profiling and comparison.
Gibson is working on the DNS Nameserver Spoofability Test, an online utility used to test whether the systems configured nameservers are vulnerable to DNS spoofing, and SQRL, a draft open standard for secure web site login and authentication.
Gibson Research Corporation
Gibson Research Corporation or GRC is a computer software development firm founded in 1985 by Gibson. The company is registered in Laguna Hills, California. GRC has created a number of niche utilities over the years, the foremost of which is SpinRite, a hard disk scanning and data recovery utility.
As of mid-2009 GRC has three employees; Steve Gibson, Greg (technical support) and Sue (bookkeeper). Gibson also founded Gibson Laboratories, Inc. in 1981, a predecessor to GRC.
One of the significant features of Gibson Research Corporation is that far more of Steve's work is freely available. At this time only SpinRite is a paid-for commercial product.
Gibson co-hosts a weekly computer security-focused podcast with Leo Laporte called Security Now!. Gibson has appeared on Leo Laporte's technology podcast, This Week in Tech and also used to occasionally appear on The Lab with Leo Laporte on G4techTV Canada.
Gibson was involved with a notable controversy over the Windows Metafile vulnerability, an issue raised in 2006 where a Windows Metafile image could trigger execution of arbitrary code. Gibson analyzed an unofficial patch issued by Ilfak Guilfanov, and publicly speculated both on his podcast called Security Now! as well as on his Web site that Microsoft may have intentionally included this vulnerability because of the use of an API called SetAbortProc, originally intended as a mechanism for canceling print jobs, which in his view made no sense. When Slashdot, a technology news Web site, picked up the assertion, an Internet rumor that Microsoft intentionally built a back-door to its operating systems was promulgated.
Gibson has been associated with a number of other controversies in the computer security field, including his prediction of the "XP Christmas of Death" in 2001 describing the outcomes of Microsoft's implementation of the SOCK_RAW protocol.
Gibson is also known for attempting to replicate functionality of a tool called SYNcookies, written by Dan Bernstein and Eric Schenk, in his own tool called GENESIS, as a preventive mechanism for SYN-flood attacks.
- Gibson Research Corporation, Techadvice.com. Retrieved on February 2, 2007.
- "GRC | Steve's Resume'". Grc.com. Retrieved 2013-11-07.
- Thomas C. Greene. "Windows back door rumor is bunk : No reason not to patch it, however". Theregister.co.uk. Retrieved 2013-11-07.
- "GRC | Security Now! Transcript of Episode #22". Grc.com. Retrieved 2013-11-07.
- "GRC | M.I.C.E. Metafile Image Code Execution". Grc.com. Retrieved 2013-11-07.
- "WMF Vulnerability is an Intentional Backdoor? - Slashdot". It.slashdot.org. 2006-01-13. Retrieved 2013-11-07.
- "Radsoft — Industrial Strength Software". Radsoft.net. Retrieved 2013-11-07.
- "Security geek developing WinXP raw socket exploit : Has Steve Gibson finally lost his mind?". Theregister.co.uk. Retrieved 2013-11-07.
- Steve Gibson on Twitter
- Steve Gibson's Attrition.org page
- Password Haystacks — Secure password system invented by Steve Gibson
- Perfect Passwords — Secure Password Generator
- Gibson's OpenVPN Guide
- Steve Gibson — Official TWiT wiki page