Wednesday 26 February 2014
On
11:12
by
Unknown
No comments
If it wasn't for the news reports of Apple's "goto fail" fix released on Tuesday, you might not have known that there had been a security problem with your Macs.
More than a decade ago, Microsoft was notorious for ignoring security problems. Years of complaints from independent security researchers and industry professionals resulted in big changes in how the company handles security problems.
After Windows security measures repeatedly fell to malicious hackers, and the company was in danger of becoming the laughingstock of the security community, Chairman Bill Gates wrote a now-famous 2002 letter saying security would become the company's top priority. By contrast, neither Tim Cook nor Steve Jobs have ever reformed Apple's mission in the same way.
In today's update that fixes "goto fail," Apple buried the notification of the fix and didn't identify it as being any different from the other security fixes in the update. Apple credited German software developer Roland Moriz for one of the bugs identified, although it appears that the CURL database bug he reported in November is only related to the "goto fail" bug and not identical.
"It looks like Apple may have some problems [rolling] out security patches when they already have another regular release in queue," Moriz wrote to CNET in an e-mail. "After this disaster, Apple should improve the test coverage of certain critical parts (e.g. SecureTransport) and review the existing code base."
The problem may be even worse in this case than it looks. "One interesting aspect of this is that [Mac OS X] 10.9.2 patched a large number of serious security vulnerabilities, not just the notorious "goto fail" one," said longtime Apple software developer Mike Ash, who described the list of bugs as "arguably more significant" than the Transport Layer Security problems in "goto fail."
"Some of them would allow an attacker to compromise your machine just by having you visit a Web site they control," he said, also known as a drive-by attack. Emphasizing that he was speculating on Apple's reasoning for the way that the update was published, Ash said in an e-mail to CNET that Apple may have decided "to roll the TLS fix into 10.9.2 because they needed to put 10.9.2 out soon to fix these other vulnerabilities, and a separate patch would have delayed it."
The evidence points to problems at Apple with alerting its users and fixing flaws in a timely manner. This is problematic because it's not made clear to Mac and iPhone users how important an update is to their security.
By contrast, Google and Microsoft identify security fixes with standard terminology such as Medium, High, and Critical.
"They think that -- except for a small community -- that people don't
care about security and privacy. They want to talk more about speed and
cup holders and less about airbags," he said, "but it's the airbags that
will save you."
--Ashkan Soltani, independent security researcher
It took Apple more than 1,200 days to fix a vulnerability in 2011 exploited by the FinFisher trojan. An App Store flaw
that attackers exploited to steal passwords and surreptitiously install
malicious apps was remedied by simply turning on basic HTTPS encryption
-- nine months after it was initially reported. The Flashback malware infected more than 600,000 Macs, more than 1 percent of all Macs in use worldwide, because Apple took two months longer than Oracle to issue its own Java patch.
--Ashkan Soltani, independent security researcher
When issuing security updates, timeliness matters. Security researcher Ashkan Soltani said he thinks the culture at Apple downplays security concerns.
"They think that -- except for a small community -- that people don't care about security and privacy. They want to talk more about speed and cup holders and less about airbags," he said, "but it's the airbags that will save you."
Part of the problem is that companies like Apple think they can protect users by keeping knowledge of vulnerabilities from the public, said Andrew Sudbury, the chief technology officer at security startup Abine.
"Apple's security is still tied to its image," he said. "You'd think you'd want to push something like this as hard and as quickly as possible, but I personally only found out about it through the news."
"Apple's security is still tied to its image. You'd think you'd want to
push something like this as hard and as quickly as possible, but I
personally only found out about it through the news."
--Andrew Sudbury, CTO at security startup Abine
Apple could have fixed the "goto fail" problem faster, but didn't. "I
don't get the impression that the five-day delay was strictly necessary.
Apple has put out quick security updates in the past, and this fix was
particularly easy to apply at least in theory," said Ash. --Andrew Sudbury, CTO at security startup Abine
Sudbury added that the bigger issue at Apple is keeping iPhones and iPads secure.
"iOS devices are a consumer device, and there's nothing you as a user can do [to secure them.] Apple takes all their responsibility, and even security companies can't help you," he said.
Soltani didn't mince his words for Cook's crew in Cupertino. "[They] waited until they had all the pieces together for a minor update, 10.9.2. If it were me, the moment something like this was determined, you'd want to roll this out. It was one line [of code required to fix the "goto" bug.]"
"Instead," he said, "they waited an entire weekend or more."
Apple did not respond to a request for comment before this story was published. CNET will update the story when there's more information.
With its history of lengthy response times to critical security problems, Apple is equally long overdue for a serious re-evaluation of how they handle their insecurities.
Subscribe to:
Post Comments
(
Atom
)
Search
Popular Posts
-
Hello friends, today we have something special for pc beginners. We have some keyboard shortcut which will really help you to operate any ...
-
Embattled Bitcoin exchange Mt. Gox has resigned from the board of the Bitcoin Foundation, the organization that manages the crypto-curren...
-
Ultra HD, colloquially known as "4K," is the latest buzzword, and the latest push from TV manufacturers. While your next TV mig...
-
BlackBerry CEO John Chen confirmed two new phones were on their way this year. The first, codenamed "Jakarta," but known as the...
-
Amazon is developing its drone service in both Seattle (US) and Cambridge (UK) UK drone experts are being sought by Am...
-
Obidike, the leader of the warriors is sent out in the company of other warriors to fetch seven virgins with which to bury the king. Incid...
-
M icrosoft has patched a critical bug in its software that had existed for 19 years. IBM researchers discovered the flaw, which affect...
-
If BitTorrent has its way, you'll be paying for some torrented content before the end of the year thanks to the integration of BitTo...
-
New photos of Nokia’s upcoming Android handset, code named Normandy, have leaked — and rather oddly, it appears the standard Android UI...
-
Nick Statt/CNET A large part of Hyperlapse's cha...
Recent Posts
Sample Text
Blog Archive
-
▼
2014
(
367
)
-
▼
February
(
214
)
- Apple's culture of secrecy delays security respons...
- Black market lights up with 360M stolen credential...
- Why bother to text your girl when BroApp can do it...
- MTN, Globacom, Airtel fined $4m by NCC
- Bitflux wins Nigerian spectrum licence bid
- Jumia Nigeria giving away one PS4 hourly at 50% di...
- LinkedIn testing Chinese language site
- Top Bitcoin exchange MtGox goes offline
- Samsung adds biometrics to latest Galaxy smartphone
- 'Smart' toothbrush grades your brushing habits
- Bitcoin ATMs coming to the U.S.
- Feeling glum, happy, aroused? New technology can d...
- AT&T follows Verizon, offers free global texts wit...
- Apple promises to fix OS X encryption flaw 'very s...
- Quixey's mobile search lets you dig deep into apps...
- BlackBerry CEO confirms Foxconn-made Q20 and Z3 ph...
- Freescale Semiconductor's Kinetis KL03 processor...
- T-Mobile's losses widen as the carrier promotes 'U...
- Microsoft's hardware chief changes roles
- Curved Samsung Gear Fit Review
- New Movies Anywhere app streams Disney's world
- Microsoft in talks to take stake in Dailymotion, r...
- iOS security hole reportedly exposes your screen i...
- Mozilla plans '$25 smartphone' for emerging markets
- Huawei launches 'hybrid' Talkband smart device
- Xbox One price cut to match PlayStation 4
- WhatsApp will expand to voice communications in th...
- Mt. Gox resigns from Bitcoin Foundation Board
- Intel launches new Atom processors
- Broadcom aims to double Wi-Fi speeds with new 802....
- Get Password Depot password manager (Win) for free
- HTC's Desire 610 comes glad in glossy plastic, has...
- First Ubuntu phones
- SanDisk microSD cards hit 128GB
- Android-powered Nokia X great for Microsoft
- BBM to land on Windows Phone this summer
- Trace Mobile numbers or Ip-Address
- Multi Google Talk Login without any software
- 1). Start any application, say Word. Ope...
- Top 20 Tips To Keep Your System Faster
- Brief overview of Unix and Linux commands
- Increase the speed of your internet connection wit...
- HOW TO CHECK ALL PASSWORD IN FIREFOX
- ALL DOS CODES REVEALED – EVERY CODE FOR COMMAND PR...
- SOME COOL KEYBOARD SHORTCUTS FOR PC BEGINNERS
- HOW TO ENJOY WINDOWS 8 VIEW IN WINDOWS 7
- Top 10 Windows 8 tips and tricks
- Schiit Audio's tiny, but powerful $119 tube headph...
- Samsung Galaxy Tab Pro 8.4 review:
- Lie detector on the way to test social media rumours
- Security failings in Linksys and Asus home routers...
- Wurm offer Bounty for game taken offline by DDoS a...
- Stuxnet worm 'targeted high-value Iranian assets'
- South Korea to develop Stuxnet-like cyberweapons
- Netflix speeds lag for Verizon users amid dispute
- Steve Jobs may appear on U.S. postage stamp
- New app helps you fight parking tickets
- Apple security update fixes iOS vulnerability
- Fitbit halts sale of Force fitness band, issues re...
- Samsung Galaxy Gear 2 and Gear 2 Neo spied in leak...
- Google Barge to set sail for new home within a month
- BigRep 3D printer can print whole pieces of furniture
- Google's Project Tango whips up new mapping tech
- Namecheap targeted in monumental DDoS attack
- Samsung Galaxy S5: Most likely features and specs
- 5TB hard drive is here, inside LaCie's latest Thun...
- Google's Tim Bray steps down in the name of workin...
- Leaked specs paint fuller picture for HTC Desire 8
- Muvee Action Studio lets you edit your GoPro video...
- Google acquires Spider.io to combat ad fraud
- Nvidia delivers more KitKat and an LTE-equipped Te...
- Microsoft taps gamers to test next Xbox One update
- Firefox OS taps into Cordova for easier Web-app de...
- Opera: watch an ad, get free mobile Net access
- Obama's commerce secretary to petition Silicon Val...
- Airbnb makes smoke and carbon monoxide detectors m...
- Fatwa forbids Muslims from traveling to Mars
- New Fiskers will have V-8s or batteries, Wanxiang ...
- Google embarks on smart contact lenses for diabetics
- Paul Graham steps down as Y-Combinator president
- Verizon closes Vodafone deal for total control of ...
- Sprint adds Wi-Fi calling to improve voice coverage
- Amazon reportedly prepping Web TV product for March
- Nokia's Here Maps to expand to all Windows 8.1 dev...
- LinkedIn now allows you to block other members
- Supernova secrets seen in X-rays
- 3-D printing 'ink' is way too expensive
- Speculators look to cash in on Bitcoin crisis
- Blackberry boss 'outrage' at T-Mobile iPhone offer
- Malware makers 'tailor' Android threats geographic...
- Microsoft to sell $25 Xbox One Media Remote in March
- Libon to IM friends for free, even if they don't h...
- Yandex suite of free Android tools sidesteps Google
- Microsoft relaunches Office Web Apps as Office Online
- Apple eyes smart magnets to attach accessories to ...
- Another HTC One 2 leak shows new colors for handse...
- The not-so-secret appeal of Snapchat's fleeting st...
- Radiation-free cancer scans may be on the horizon
- Kazam Thunder 2 brings lightning-fast 4G LTE
- Compact, budget Liquid Z4 phone hopes to make a bi...
-
▼
February
(
214
)
Copyright © 2014 Harry Jacks All Rights Reserved. Powered by Blogger.
About Me
Copyright Text
Copyright © 2014 Harry Jacks
All Rights Reserved
All Rights Reserved
0 comments :
Post a Comment