HomeForumsEMUG User GroupShuffle NewsletterTrainingAppleIDX PricesGalleryCalendarAboutContactSearch

Go Back   EmiratesMac > Mac stuff > News & Rumors Mac
Register FAQ Members List Search Today's Posts Mark Forums Read Log Out

News & Rumors Mac News and Rumors all about Mac.


Welcome to EmiratesMac! Join EmiratesMac today! Contact us!
Reply
 
LinkBack Thread Tools Display Modes
Sponsored Links
Old 1st November 2007, 19:34   #1 (permalink)
Senior Member
 
venky83's Avatar
 
Join Date: Sep 2007
Location: Dubai, UAE
Posts: 462
venky83 is on a distinguished road
Insecure Leopard???

While browsing through ZDnet Blogs came across this article titled Researchers pooh pooh Mac OS X Leopard Security by Ryan Naraine and thought of sharing it with you all:

Quote:

The first independent reviews of the security enhancements in Mac OS X Leopard are in — and they’re not entirely pleasant for the folks in Cupertino.

First up is Heise Security’s takedown of the new application-based firewall in Leopard, which Apple promises will specify the behavior of specific applications to either allow or block incoming connections.

However, Heise Security’s Jürgen Schmidt finds cause for concern:
The most important task for any firewall is to keep out uninvited guests. In particular, this means sealing off local services to prevent access from potentially hostile networks, such as the internet or wireless networks.

But a quick look at the firewall configuration in the Mac OS X Leopard shows that it is unable to do this. By default it is set to “Allow all incoming connections,” i.e. it is deactivated. Worse still, a user who, for security purposes, has previously activated the firewall on his or her Mac will find that, after upgrading to Leopard, the system restarts with the firewall deactivated.

In contrast to, for example, Windows Vista, the Leopard firewall settings fail to distinguish between trusted networks, such as a protected company network, and potentially dangerous wireless networks in airports or even direct internet connections. Leopard initially takes the magnanimous position of trusting all networks equally.
(More at Techmeme)

The new firewall in Leopard isn’t the only security feature being pooh-poohed by security researchers. According to Thomas Ptacek (right), co-founder of Matasano Security, Apple’s implementation of memory randomization in Leopard doesn’t make the operating system immune from virus and worm attacks.

[ SEE: Memory randomization (ASLR) coming to Mac OS X Leopard ]

For starters, Ptacek found that the dynamic linker library (dyld) is not randomized. “From what I can tell, ten different Leopard Macs booted at ten different times will have the same offset to dyld,” Ptacek said in a first-take on Leopard security.

“Can I say right now that you can exploit this to take over a Mac? No. But ASLR is either something you get right, or is simply a speed bump for attackers,” he added.

Ptacek said memory randomization, also known as ASLR (address space layout randomization), removes a talking point argument about Microsoft Windows Vista’s superior security, but doesn’t address the underlying point of that argument.
Cocoa programs running in Darwin are less secure than Win32 programs running under NTOSKRNL, and aren’t even in the same ballpark as Managed C++ or C# programs.
Ptacek’s analysis also found problems with Apple’s implementation of Sandboxing (systrace) without any documentation for developers.


Tunecard iTunes Credits

venky83 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 1st November 2007, 20:21   #2 (permalink)
Senior Member
 
Vinpin's Avatar
 
Join Date: Sep 2007
Posts: 335
Vinpin is on a distinguished road
Does it change your mind about buying mac with leopard installed on it?

Hilalours replies there for the article. someone wrote:
Quote:
Way to much POOH in the article and the replies...
Vinpin is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 1st November 2007, 20:54   #3 (permalink)
Senior Member
 
venky83's Avatar
 
Join Date: Sep 2007
Location: Dubai, UAE
Posts: 462
venky83 is on a distinguished road
except for the alarm over how leopard trusts every network , the other stuff is way too nerdy for me to follow
venky83 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 1st November 2007, 21:16   #4 (permalink)
Senior Member
 
Vinpin's Avatar
 
Join Date: Sep 2007
Posts: 335
Vinpin is on a distinguished road
Better article is Here

Quote:
Well, yes and no. A careful reading of the review yields a mixed assessment of its validity. Some criticisms seem valid, but others appear to stem from misapprehensions. We'll walk through it and identify which concerns appear correct and where the review went astray.
Vinpin is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 2nd November 2007, 09:11   #5 (permalink)
Administrator

 
Magnus's Avatar
 
Join Date: Apr 2006
Location: Dubai
Posts: 8,539
Magnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond reputeMagnus has a reputation beyond repute
In my experience, if there are major security holes and problems, Apple will address them with an update.
Magnus is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 7th November 2007, 17:50   #6 (permalink)
Junior Member
 
Join Date: Oct 2007
Posts: 16
prajeethpj1 is on a distinguished road
Leopard Update

I was browsing thru zdnet and I saw this article on Leopard & Vista.
» Leopard and Vista - More alike than you might think | Hardware 2.0 | ZDNet.com
Wanted 2 share with U all
prajeethpj1 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Apple, the Apple Logo, and Macintosh are trademarks of Apple, Inc., registered in the U.S.A. and other countries. EmiratesMac is a recognized independent user group and has not been authorized, sponsored, or otherwise approved by Apple, Inc.
All times are GMT +4. The time now is 18:12.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0