backtop


Print 31 comment(s) - last by Cheesew1z69.. on Jul 28 at 10:17 PM

Alcoholics Anonymous says the first step to recover is to admit you have a problem

Black Hat's sister conference DEF CON already scored an intriguing high-profile keynote speaker -- General Keith Alexander, head of the U.S. National Security Agency (NSA) and U.S. Cyber Command.  Now Black Hat has an equally surprising keynote of its own from the corporate sector -- a top executive from Apple, Inc. (AAPL).

Apple's talk will be given by Dallas De Atley, manager of Apple’s platform security team -- a team responsible for security both Apple's iOS (iPhone, iPad, iPod) and OS X operating systems.

For years, Apple enjoyed one of the positives of having a small market share and proprietary operating system -- general disinterest via cybercriminals.  But rather than take this safety for what it was  -- safety via obscurity -- Apple instead told customers that its machines were never hacked because their security was lightyears ahead of Microsoft Corp.'s (MSFT).

Security researchers called this a baldfaced lie.  In fact, some say Apple is 10 years behind Microsoft.  Indeed, while Apple security researchers have long reportedly lurked incognito at DEF CON and Black Hat, they did not venture to give a talk until 2008 -- ten years after Microsoft's first (1998) presentation at the conventions.

Black Hat
Apple's first Black Hat talk comes after marketing scuttled a 2008 keynote.
[Image Source: Cult of Mac]

And Apple's late arrival was quickly scuttled by Apple's marketing folks who feared a public relations disaster.  After all, they had been pitching for years that Macs were "magical" and immune to "PC viruses".

Lately, however, OS X has been besieged by malicious Trojans -- first with the fake anti-virus program MacDefender, then Flashback, a fake Flash player update that infected 600,000 Macs.  To make matters worse, a memo leaked from Apple public relations to store employees suggesting they lie to customers about the existence of MacDefender.

Trojan horse
Macs are increasingly the target of Trojans.  Malware writers love Apple's
sluggish pace of patching. [Image Source: Venitism]

The issue for Apple was that with 10 percent of the market and a demographic of relatively affluent users, Apple was starting to become a worthwhile target.  And it struggled with this new breed of OS X-centric malware.

Even Apple's marketing team was forced to reword their marketing amid a rash of infections, perhaps fearing user lawsuits.

Apple's reappearance at Black Hat is significant as it represents Apple marketing's silent acknowledgement that keeping customers in the dark about security threats is no longer a viable option.  With mass media frequently seizing on reports of new malware or security holes in iOS and OS X, Apple is back at Black Hat, much as Microsoft was in 1998 -- looking to turn over a new leaf.

Hopefully this year they won't get cold feet.

Sources: Black Hat, Bloomberg



Comments     Threshold


This article is over a month old, voting and posting comments is disabled

RE: Welcome to the show...
By nafhan on 7/25/2012 12:54:39 PM , Rating: 2
If I was going to call Unix anything, I would call it a set of interoperability rules, but that's just semantics. My point wasn't that Apple is the same OS as, say RHEL or BSD, or that Windows is completely based on MS's work. It's that OSX is closely related to a number of similar OS's and improvements in those systems can often be directly integrated into other Unix OS's, and yes I do understand that Windows has some components that came from other projects, too. Generally speaking, though, MS avoids that when they can.
quote:
MS isn't going it alone.
I was speaking from an OS development perspective. Improvements in Linux or BSD or a number of other systems can make their way to OSX more easily than they could to Windows. I wasn't meaning that MS never goes to security conferences(???).
quote:
MS never had a choice. etc.
I think you're misunderstanding me. To clarify: I was praising the improvements and current state of MS's OS level security, while also noting that Apple - despite starting with an OS designed for secure, multi-user access - has kind of done a poor job on the security side of things.


"People Don't Respect Confidentiality in This Industry" -- Sony Computer Entertainment of America President and CEO Jack Tretton














botimage
Copyright 2014 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki