Apple to Break Its Vow of Silence on Security Issues at Black Hat
July 25, 2012 7:37 AM
comment(s) - last by
Alcoholics Anonymous says the first step to recover is to admit you have a problem
's sister conference
already scored an
intriguing high-profile keynote speaker
General Keith Alexander
, head of the
U.S. National Security Agency
U.S. Cyber Command
. Now Black Hat has an equally surprising keynote of its own from the corporate sector -- a top executive from Apple, Inc. (
will be given by Dallas De Atley, manager of Apple’s platform security team -- a team responsible for security both Apple's iOS (iPhone, iPad, iPod) and OS X operating systems.
For years, Apple enjoyed one of the positives of having a small market share and proprietary operating system -- general disinterest via cybercriminals. But rather than take this safety for what it was -- safety via obscurity -- Apple instead told customers that its machines were never hacked because their security was lightyears ahead of Microsoft Corp.'s (
Security researchers called this
a baldfaced lie
. In fact, some say Apple is
10 years behind Microsoft
. Indeed, while Apple security researchers have long reportedly lurked incognito at DEF CON and Black Hat, they did not venture to give a talk until 2008 -- ten years after Microsoft's first (1998) presentation at the conventions.
Apple's first Black Hat talk comes after marketing scuttled a 2008 keynote.
[Image Source: Cult of Mac]
And Apple's late arrival was quickly scuttled by Apple's marketing folks who feared a public relations disaster. After all, they had been pitching for years that Macs were
"magical" and immune to "PC viruses"
Lately, however, OS X has been besieged by malicious Trojans -- first with the fake anti-virus program MacDefender, then Flashback, a fake Flash player update that
infected 600,000 Macs
. To make matters worse, a memo leaked from Apple public relations to store employees suggesting they
lie to customers
about the existence of MacDefender.
Macs are increasingly the target of Trojans. Malware writers love Apple's
sluggish pace of patching. [Image Source: Venitism]
The issue for Apple was that with
10 percent of the market
and a demographic of relatively affluent users, Apple was starting to become
a worthwhile target
. And it
struggled with this new breed of OS X-centric malware
Even Apple's marketing team was
forced to reword
their marketing amid a rash of infections, perhaps fearing user lawsuits.
Apple's reappearance at Black Hat is significant as it represents Apple marketing's silent acknowledgement that keeping customers in the dark about security threats is no longer a viable option. With mass media frequently seizing on reports of new malware or security holes in iOS and OS X, Apple is back at Black Hat, much as Microsoft was in 1998 -- looking to turn over a new leaf.
Hopefully this year they won't get cold feet.
This article is over a month old, voting and posting comments is disabled
RE: Welcome to the show...
7/25/2012 12:54:39 PM
If I was going to call Unix anything, I would call it a set of interoperability rules, but that's just semantics. My point wasn't that Apple is the same OS as, say RHEL or BSD, or that Windows is completely based on MS's work. It's that OSX is closely related to a number of similar OS's and improvements in those systems can often be directly integrated into other Unix OS's, and yes I do understand that Windows has some components that came from other projects, too. Generally speaking, though, MS avoids that when they can.
MS isn't going it alone.
I was speaking from an OS development perspective. Improvements in Linux or BSD or a number of other systems can make their way to OSX more easily than they could to Windows. I wasn't meaning that MS never goes to security conferences(???).
MS never had a choice. etc.
I think you're misunderstanding me. To clarify: I was praising the improvements and current state of MS's OS level security, while also noting that Apple - despite starting with an OS designed for secure, multi-user access - has kind of done a poor job on the security side of things.
"A lot of people pay zero for the cellphone ... That's what it's worth." -- Apple Chief Operating Officer Timothy Cook
NSA Chief to Pitch "Common Core Values" to Hackers at DEFCON 20
July 24, 2012, 3:25 PM
Apple Scales Back Security Ad Claims After Rash of Mac Malware
June 25, 2012, 4:33 PM
Apple Takes 3 Months But Finally Stops Printing Passwords in Plaintext
May 9, 2012, 5:20 PM
Kaspersky Labs: Apple's Security 10 Years Behind Microsoft
April 26, 2012, 7:39 AM
Malware Authors Get Boost from Apple's Sluggish Updates, Infect 600K Macs
April 6, 2012, 8:40 AM
Apple Releases iOS 7.1, The First Major Update to Its "Rethought" Mobile OS
March 10, 2014, 1:52 PM
Windows 8.1 Update 1 Leaked Early
March 7, 2014, 9:30 AM
Xbox One Gets Beta Version of "Project Spark" Starting Today
March 4, 2014, 2:33 PM
Cortana Voice Assistant Coming to Windows Phone in New 8.1 Update
March 3, 2014, 1:09 PM
Microsoft Launches Site to Tell Clueless Customers if They're Running XP
March 3, 2014, 12:34 PM
With Windows XP Support Ending Soon, Microsoft Uses Pop-ups to Encourage Upgrades
March 3, 2014, 9:43 AM
Most Popular Articles
Bitcoin King Pt. II: Mt. Gox's Dictator Karpelès Proves Tragically Flawed
March 7, 2014, 1:12 PM
Hack Reveals Fallen Bitcoin CEO's Posh Tokyo Penthouse
March 10, 2014, 4:28 PM
Tesla Motors Calls New Jersey Out on New Rule Against Its Direct Sales Model
March 11, 2014, 12:01 PM
NASA Considering SpaceX "Red Dragon" for Returning Mars Samples to Earth
March 10, 2014, 2:43 PM
India Could Rock Google With Its Biggest Antitrust Fine Yet -- $5B USD
March 10, 2014, 8:12 PM
Latest Blog Posts
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
Global Cyber Espionage Concerns Reveal Growing Cyber Armies
Nov 29, 2013, 11:04 AM
Is The Period Becoming an Expression of Anger?
Nov 26, 2013, 2:02 PM
NSA and Congress -- You Will Never Kill the Constitution, It's an Idea
Nov 10, 2013, 2:00 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information