backtop


Print 61 comment(s) - last by coferj.. on May 16 at 2:08 PM

Company is showing signs of improvement, past flaws took it up to a year to patch

Famed OS X hacker Charlie Miller once told a security blog, "Mac OS X is like living in a farmhouse in the country with no locks, and Windows is living in a house with bars on the windows in the bad part of town."

But of late there have been some thieves in the farm house, and even Apple, Inc. (AAPL) has started to admit that it has security issues -- well, after realizing that telling its technicians to lie to customers about them might be bad publicity.  One recent piece of malware is estimated to have infected 600K Macs and generated millions in profit for identity thieves alone.

Kapersky Labs, a top security firm recently warned the public that Apple's security was 10 years behind Microsoft Corp.'s (MSFT).  Evidence of that was seen in the 10.7.3 build of OS X "Lion", which due a programming error (a stray debugging flag left on in OS X's source) accidentally logged in plaintext the passwords of users who used legacy FileVault settings.

An Apple user, Eric Hildum complained in the support forums three months ago:

I’ve tried it on another Mac as well, same result: The login of a normal network user writes this log line as his homedir gets mounted.
This poses a security risk. We have some users who are local admins, they could ask another user to login on their Mac and look for the password afterwards. Extration in single user mode would be possible as well.

Is this a “speciality” of our environment or is this a known bug? Can I turn this behavior off?
We are running Lion clients with a SL Server and using OpenDirectory.

Apparently the Apple answer was that this was a "feature" for the time being, because the user received no reply to his pleas for three months.  Then a security researcher by the name of David Emery, posted his findings to the Cryptome mailing list, a list frequent by hackers.

Apple FileVault

As noted by Mr. Emery, the issue did not effect purchasers of new Lion systems, but might have affected many users of legacy systems who upgraded to Lion.

With the Cryptome email, the media began to catch wind of Lion's penchant for plaintext password dumping and Apple was forced into the awkward position of providing an "update" for its "feature".

Hence OS X 10.7.4 was born, and aired today to loyal Lion subscribers.  

The patch also "improves" other "features", such as no longer losing settings to the "reopen windows when logging back in" checkbox, and allowing "certain British third-party keyboards" to finally work.

Apple may still be living in the dark ages of security, but at least it's figured out not to stores users' passwords in plaintext, even if it took the company three months of complaints.  On the plus side, the three month turnaround is faster than past incidents where Apple took up to a year to fix past security issues/features.


Comments     Threshold


This article is over a month old, voting and posting comments is disabled

More biased anti-apple Trolling
By macdevdude on 5/9/2012 5:37:04 PM , Rating: -1
quote:
Kapersky Labs, a top security firm recently warned the public that Apple's security was 10 years behind Microsoft Corp.'s
Mick quit ur Biased trolling of Apple. I've onwed 8 Macs in the last 5 years and have never been hacked once or had their identity stolen. Four out of my six best friends who use PCs all had their identities stolen because of Windows flaws. Now I've convinced three of them to use a Mac and they never looked back. The build quality of every Mac is beautiful unlike Windows machines, which look like cheap garbage. And OS X is much simpler to use.

You can say Apple is 10, 20 years behind I don't care. You're just biased and full of garbage.

Look at the facts. Apple is cleaerly ahead.

When 95 percent of all Windows PCs will get a virus over their lifetime and like 5 percent of Macs get a harmless virus who's realyl behind? What's your smart answer to THAT Mick?




By JasonMick (blog) on 5/9/2012 5:34:00 PM , Rating: 5
quote:
Look at the facts. Apple is cleaerly ahead.

When 95 percent of all Windows PCs will get a virus over their lifetime and like 5 percent of Macs get a harmless virus who's realyl behind? What's your smart answer to THAT Mick?
Wow, I don't even know where to begin. Your facts are so compelling.


RE: More biased anti-apple Trolling
By Reclaimer77 on 5/9/2012 5:48:18 PM , Rating: 2
quote:
I've onwed 8 Macs in the last 5 years


LOL what a sucker! They say you coming a mile away chump.

Any reason you needed to buy so many Mac's in such a short period of time if they're really all that great? Just wondering. I certainly don't need to buy a PC every 1.6 years.


RE: More biased anti-apple Trolling
By macdevdude on 5/9/12, Rating: -1
By Digimonkey on 5/9/2012 5:54:54 PM , Rating: 5
Man, did a PC user kick your puppy or something?


RE: More biased anti-apple Trolling
By WhiskeyD on 5/9/2012 6:14:22 PM , Rating: 2
macdevdude you have clearly showed your ignorance. Only noobs like you get viruses and their identity stolen on a PC. I havent ran an antivirus in over 5 years and I've not had a single problem but then again I'm actually competent with a PC. You keep wasting your "six figures" every few months buying macs and I'll build a new "identity stealer" every 3-4 years with my "welfare check" hahah your a joke


RE: More biased anti-apple Trolling
By Cheesew1z69 on 5/9/2012 7:27:01 PM , Rating: 2
Showed it? He shows it every post he makes.


RE: More biased anti-apple Trolling
By bah12 on 5/10/2012 11:17:25 AM , Rating: 1
LMAO yah he averages -.88 almost every post he gets a -1. What a moron.


By Reclaimer77 on 5/10/2012 2:09:53 PM , Rating: 2
And that's only because -1 is as low as you can go here lol.


By ppardee on 5/9/2012 7:38:18 PM , Rating: 3
When most people quote a 'six-figure salary', they're not including the figures to the right of the decimal.

And generally when someone uses their salary to defend themselves, they are lying since it can't be verified.

I develop apps for a living, too. I've spent less than $2000 on my computers in the last 6 years and have a killer gaming system to boot (Get it... To boot.. It's a joke, son.). I'm not on welfare, just not stupid with my money.

In the end, there are two types of computer users. Those who know they've been hacked, and those who don't know they've been hacked. We know which category you fall into.


RE: More biased anti-apple Trolling
By elleehswon on 5/9/2012 11:25:22 PM , Rating: 2
A cluster of mac pro's for rendering? are you retarded or just trolling? The GPU's in macs are last generations technology, at best! For what you spent on those mac pro's, you could have bought a few cranking PC's(apple's markup is damn near astronomical), run triple SLI, and be able to dick off most of the day as you'd no longer have to waste time watching your pixels fill the screen. Wait, nevermind, you'd probably get a virus...something tells me you're the type that clicks on the boxes on the side of the webpages you visit.

Macs...for people who have no idea what they're doing, but still want to feel like they have something to brag about.

Man, i hope you're trolling... for your sake and mine. Please tell me you're trolling.


RE: More biased anti-apple Trolling
By Rukkian on 5/10/2012 9:58:26 AM , Rating: 2
And for those that want to show off how much of their "6 figure salary" they can blow on overpriced, overhyped, overmarketed crap.


RE: More biased anti-apple Trolling
By fic2 on 5/9/2012 5:57:05 PM , Rating: 2
Actually a new mac every 7.5 months.... (5 years/8 macs = 0.625 years/mac * 12 months = 7.5 months/mac)


RE: More biased anti-apple Trolling
By macdevdude on 5/9/12, Rating: -1
By Cheesew1z69 on 5/9/2012 7:28:52 PM , Rating: 2
Is anyone surprised your are a moron? No...we fully expect it.


RE: More biased anti-apple Trolling
By Reclaimer77 on 5/9/2012 5:59:46 PM , Rating: 2
lol oops, math fail on me. His idiocy shorted out my logic circuit.


RE: More biased anti-apple Trolling
By bah12 on 5/10/2012 11:19:31 AM , Rating: 2
It's ok I think everyone is a little dumber just by having read his posts.


RE: More biased anti-apple Trolling
By iceolate on 5/9/2012 5:59:36 PM , Rating: 2
Macs may look pretty on the outside, but they are full of sh¡t on the inside. Kind of like you. They use very cheap hardware and are poorly engineered. I work in IT at a University, and the students are constantly bringing in Macbooks with hardware problems. I build my own computers with the top of the line hardware, and they last for a decade or more. Can't do that with Mac.


RE: More biased anti-apple Trolling
By Dennis Travis on 5/9/2012 7:14:54 PM , Rating: 1
Do you build notebook computers also? You said Macbook, that is a notebook! :-)Grin


RE: More biased anti-apple Trolling
By iceolate on 5/9/2012 7:33:10 PM , Rating: 4
I personally don't have any use for a notebook computer. However when it comes to notebook computers, I would recommend Lenovo based on their durability and excellent customer service, and then second to that would be MSI and Asus based on their quality internal hardware.

When it comes to Apple's iMac or PowerMac computers, they seem to be a bit a more reliable as far as the hardware lasting. However, those are also way overpriced for the outdated hardware that they contain. One could build a far superior machine for a fraction of the cost that has things like eSATA, USB 3 and HDMI. Why doesn't the 27" iMac have any video inputs? It has only outputs. You pay a premium for a giant high res display and then can't even connect anything else to it. Super lame.

All Macs continue to have problems with their crappy, overpriced, slot loading optical drives as well. That's usually the first thing to break. I personally don't care for the OSX operating system either. I find it very unintuitive and lacking in features. The wireless networking can be horrendous at times, too.


RE: More biased anti-apple Trolling
By Dennis Travis on 5/9/2012 7:47:08 PM , Rating: 2
Lenova is an excellent PC Notebook for sure. You will get no argument from me. They take after the IBM Thinkpads and I have think pads that are 15 years old and still work like the day they were made. Excellent machines.


RE: More biased anti-apple Trolling
By Dennis Travis on 5/9/2012 7:48:35 PM , Rating: 2
Oops, me bad. Lenovo!


RE: More biased anti-apple Trolling
By Cheesew1z69 on 5/9/2012 9:08:41 PM , Rating: 2
They are IBM Thinkpads....


RE: More biased anti-apple Trolling
By Iaiken on 5/10/2012 11:43:13 AM , Rating: 2
quote:
They ARE IBM Thinkpads....


Quoted for truth. Emphasis added...


RE: More biased anti-apple Trolling
By JediJeb on 5/9/2012 6:04:37 PM , Rating: 5
quote:
I've onwed 8 Macs in the last 5 years and have never been hacked once or had their identity stolen


I have had 5 PCs over the last 20 years and have never been hacked, had a virus or malware on those at home, even when running them with Windows versions far past their prime(just upgraded one to WinXP 3 years ago). Those are my home systems and I am careful of what I load and what sites I visit, so that would point to PCs not being easily infected if you only look at my record.

Now if you look at the PCs at work, that is another story. We had a case of malware/virus there that was tough to get rid of, but when it was figured out how it came to be, not even a Mac would have been safe from that user. Mac or PC, if a user will click on anything, they are both prone to be infected.

quote:
The build quality of every Mac is beautiful unlike Windows machines, which look like cheap garbage


If you narrow down the list of Windows machines to only a hand full of select models, they look great too. But on the other hand, if someone has a very limited budget, what is the bargain basement model of a Mac that they can purchase? Not everyone can own the Ferrari of computers(though I would consider a Mac more of a BMW than a Ferrari), some can only afford the Tata, and Apple just does not offer a cheap poor person's model.

quote:
You can say Apple is 10, 20 years behind I don't care. You're just biased and full of garbage.


Just as full of garbage as those who make Macs out to be some heaven sent piece of perfection. Macs are what they are, a decent computer running a decent operating system that can fall prey to malware infections when the ones using them are careless. There are PCs that can stomp them on performance, others that can stomp them on price, and if you throw Linux on one with an experienced user at the keyboard that would probably even beat them out in other areas too. Windows users freely admit they have bugs, Linux users will admit the same, Mac users seem to never admit any weakness in their systems even when it is pointed out to them with clear proof. Who is the more biased, one who goes out of their way to point out an Apple flaw, or one who vehemently denies any idea that a flaw can exist?


By sprockkets on 5/9/2012 9:57:49 PM , Rating: 3
Clearly Macs were not made for you - you, you use your brain and make informed decisions, and if you don't know something you find out.


RE: More biased anti-apple Trolling
By Cheesew1z69 on 5/9/2012 7:24:29 PM , Rating: 4
quote:
Four out of my six best friends who use PCs all had their identities stolen because of Windows flaws.
Because they are morons...not because of flaws.


RE: More biased anti-apple Trolling
By Camikazi on 5/9/2012 9:43:38 PM , Rating: 5
Wow that is a serious ring of idiots he hangs around with, I still have not met a single person that has had their identity stolen. It's not as likely to happen as people think, yet this guy has 4 out of 6 people with stolen identities.


By VoodooChicken on 5/10/2012 10:47:55 AM , Rating: 3
I would be highly suspicious that HE'S the identity thief!


RE: More biased anti-apple Trolling
By JediJeb on 5/10/2012 2:26:07 PM , Rating: 2
It's funny about the identity theft statement since not so long ago I read an article that said the biggest tool identity thieves use is Change of Address at the Post Office and not online theft. Very simple to fill out a change of address card and then have all of your statements sent to a new address to grab your information. Low-tech usually works great with little investment.


By ihateu3 on 5/9/2012 8:24:10 PM , Rating: 3
Are you even serious? Statistically speaking, if only 5 percent of Macs get a virus by your rationale, how many would that be if they had the same base installment as windows machines???? Remember now, there are still even win 98 machines on the net, it is only obvious that if even both of these machines where equally secured, than windows would billions more infections by market dominance alone!

What hacker would want to create a virus to target the least amount of computers to spread to? Doesn't make any sense...

Windows is always under attack due to their dominance, this has made them hardened and use to dealing with non stop attacks. Only recently has Apple started to barely gain enough of the market share to be targeted by hackers (that and its easy when Apple didn't supposedly need antivirus software)making them an easy target, but yet not ready to deal with these ongoing threats.

Trust me, I love to love an underdog, but Apple is not the underdog to love, just by supporting them, even knowing the way that they deal business and treat their customers as idiots tells me quite a bit about your personality.

But hey, Apple can instill a feeling of superiority and coolness right?


By spread on 5/9/2012 8:29:52 PM , Rating: 3
quote:
Four out of my six best friends who use PCs all had their identities stolen because of Windows flaws.


It's because they're incredibly stupid, which is why you hang around with people that are like you.

I've owned so many PCs and how many times have I been compromised? Not once. I once had a trojan infection due to some files I downloaded, I knew what I was getting into and risked it. Took care of it in the hour with some cleaning and presto. Back in business.

You can't do that. PCs aren't for you. They give you control, they give you choices. You're not ready, you can't think.

quote:
When 95 percent of all Windows PCs will get a virus over their lifetime and like 5 percent of Macs get a harmless virus who's realyl behind? What's your smart answer to THAT Mick?


How do you know your Mac isn't infected right now? It's not like you're running any kind of anti virus or anti spyware to tell you. You don't even have a clue.


By frobizzle on 5/10/2012 8:37:39 AM , Rating: 4
quote:
Four out of my six best friends who use PCs all had their identities stolen because of Windows flaws.

Oh come on! No one believes you have that many friends!


RE: More biased anti-apple Trolling
By coferj on 5/16/2012 2:08:15 PM , Rating: 1
If you're a hacker, why would you write a virus for an OS with such a small market share? It has nothing to do with their "superiority" and everything to do with the fact that only a small group of people use them.


"There is a single light of science, and to brighten it anywhere is to brighten it everywhere." -- Isaac Asimov














botimage
Copyright 2014 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki