Secunia: Apple has more security holes than Microsoft

Apple Store“Here’s another blow to those insist that Apple products are rock solid and unhackable: The security company Secunia reports that Apple products have more vulnerabilities than those of any other company. Oracle came in second place, with Microsoft in third,” Preston Gralla reports for Computerworld.

MacDailyNews Take: Ooh, big blow. Give us a call when cascading self-replicating viruses cost hundreds of billions of dollars in lost productivity, data, and time, m’kay?

Full article, which also includes the painfully obvious fact that “simply listing the total number of potential vulnerabilities isn’t the best way to gauge the relative security or insecurity of a computer, because some vulnerabilities may be more prevalent than others. So Secunia is not saying that Apple products are less secure than other products” here.

90 Comments

  1. Funny how this seems to coincide with Apple passing Microsoft in market value. Of course this will be picked up by the mainstream media, delivered to the masses as a soundbite or dramatic headline then suddenly people everywhere are flooding the Apple store barraging their employees with endless questions about security.

  2. Their vulnerability assessment model is not based on actual facts but their own perspective that market size = vulnerability size and that they have now factored iTunes etc into the mix.

    Isn’t this just another view that obscurity means security?

    Seems like what they are saying is the M$ is becoming more obscure, however the obscurity security issue has always been irrelevant and never backed up with facts.

    Article would therefore appear irrelevant along with the authors.

  3. Big difference between theoretical vulnerabilities, obvious vulnerabilities and exploited vulnerabilities.

    All of OS X’s vulnerabilities are theoretical. All of Microsoft Windows’ vulnerabilities are exploited, sooner or later.

    Big difference.

  4. @Max

    That is like saying who the hell is Acer. Big name, but if you are clueless to security you would not know. Secunia’s PSI and CSI are the bomb.

    Unix has many more small files then Microsoft, when they finally feel get to attacking OS X there will be a fertile semi untouched OS to bombard.

    And no, I am a Mac guy with 6 Macs and 2 PCs. Just listen to Charlie Miller (pown to own white hat) stating OS X is far easier to hack then Windows 7.

    OS X has never been tested with the full Russian/Ukraine/China/Asia hacking world hacking it 24/7. It will have weekly breaches just like MS has when it becomes a target from the pros and government pros. To this date you have only seen a couple grains of sand hitting OS X. Wait till the whole beach of sand starts knocking on it’s door. Mass pownage.

  5. I agree mostly with RIF: IT IS NOT ABOUT OS X !

    It is however about software on Win XP and Win Vista, therefore the report (not the article) includes Win Safari and Win iTunes.
    (See page 9 of the report).

    Reminds me of the article in the Economist, about antenna gate saying that Apple didn’t accept the problem about signal strength going down, provides a link to the Apple KB, and the LINK says “we have a problem…”.

    These days one has to read the source documents, because the press is becoming too lost in their prejudices that they can´t READ straight their own quoted sources.

  6. in the dept of defense there are vulnerabilities (theoretical) and susceptibilities (practical). having a vulnerability doesn’t make ti something to be concerned about necessarily. m.s. has demonstrated a history of practical susceptibilities.

  7. Sorry, But until I see an all out attack on Apple products, this is just BS. With all of the Apple haters, I find it hard to believe that no one wants to put Apple in their place. The security through minority theory doesn’t hold water any more.

  8. @Ted: Fear + Uncertainty + Doubt = FUD

    Mac OS is not impregnable. There are currently several Trojans which can be downloaded and run on a Mac. They have to be actively downloaded and run by the user.

    Having said that, OS X is a version of UNIX, which was designed to be networked, unlike Windows, which was designed to be stand-alone. Windows has massive holes and spaghetti code where all sorts of malware can run without the user knowing.

    In UNIX, nothing can run unless it’s been approved to run by an administrator. Also, every piece of software resides in a library, and there are a limited number of them. There’s really not much room to hide; if the virus is not running on the Admin account, very little damage can be done. Read more about that here: http://daringfireball.net/2004/06/broken_windows

    Additionally, Macs are virtually invisible on the internet right out of the box. Even without a firewall on, you are essentially in “stealth mode,” so Macs are safer from crap that’s out there being passed around. “… by default, OS X doesn’t leave many ports open. In contrast, most versions of Windows ship with a bunch of open ports, which is one reason that operating system is a riper target for malicious hackers. And while Leopard leaves open more ports than earlier versions of Mac OS X, so far there have been no known attacks on those default services.” http://www.macworld.com/article/132558/2008/03/connect2504.html

    Because Macs are hard to crack, and Windows is easy, the goons target Windows. But that doesn’t mean they haven’t tried. Read about the “Hack-my-Mac” challenge here: http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=181502078

  9. @ Pay Attention,

    Apple quit making claims about Mac security because Windows users were getting pissed off.

    Since Windows users make up about 60% of new Mac buyers, Apple no longer wants to piss off 60% of their Mac customers.

  10. Secunia can make a bigger name for itself by 1) submit an app to the app store that gets approved and end up exploiting the users; or 2) steal personal info through a Safari exploit.

    To say professional crackers have not targeted Mac OS 24/7 yet due to (lack of) popularity is a postulate without proof. Makes no sense considering average Apple owners have higher income. Makes more sense considering most corporate and government enterprise systems are not run on Mac OS. Plus the diverse Apple devises and various numbers and situations that people run them makes choosing a target for maximum profit difficult.

  11. @aka Christian

    Read it again, I know it’s Unix. Daaa

    Additionally, Macs are virtually invisible on the internet right out of the box. Even without a firewall on, you are essentially in “stealth mode,”

    Browser headers, and zero day. Mac is just as vulnerable as Windows. IF you get a pro hacking it. Many many many zero days left in OS X per Safari and Firefox.

    All at the feet of a advanced pro hacker with the clueless unprotected nieve Mac user with “browser headers yelling “here I am, and I am a Mac ” to any website 99% of Mac owners would do who does not know how to switch his browser agent.

    Wake the hell up! Thinking OS X is this God of an operating system. It will fall if some doctorate brain hacker from Russia/ china who wants to cause some strife points to it and spends some time on it. There is not enough value in it know $$$ wise. There will be in the coming years.

    OH OH but your full of FUD. Yea.

    It is just code that has not been pounded on by true pros. Yet

  12. How many copies of OSX out there? 40+ million?
    Still nothing happening? Where is the virus?
    Why would anyone wait when fame would await them by creating one?

    You know what? Time to end the false politeness. Time for the truth:
    Ted, you are an idiot! And I have no problem saying so.

  13. Secunia, PROVE IT!!!!!!!!
    How many security breaches has Apple had? ZERO! How many viruses does OSX have? ZERO!!
    So where and how do you come up with these results when Winblows 7 has already been compromised several times causing thousands of PC’s to go down! How many Macs were effected? ZERO!!!!!!!!!
    Secunia is FUD!!!!!!!!!!!!!!!!!!!!

  14. If OS X is so insecure, why did OS 9 and previous Mac operating systems have viruses?

    I mean, Macs were able to get viruses when they had 1 or 2 percent of market share previous to OS X — but now they have no viruses with OS X AND a greater market share and we still have some wanting to use the “security through obscurity” excuse?

    That just does not make sense.

  15. @Ted: “All at the feet of a advanced pro hacker with the clueless unprotected nieve Mac user with “browser headers yelling “here I am, and I am a Mac ” to any website 99% of Mac owners would do who does not know how to switch his browser agent.”

    This “clueless unprotected nieve Mac user” is a professional Unix system administrator in real life. I don’t permit Windows machines on my systems. 99% of Mac owners are smarter than you are. At least they can put together a coherent sentence and use punctuation. Your preferred view that you and the “pro hackers” are somehow above the average “clueless” Mac user is a silly attempt the inflate your own pathetic ego. I hear they have pills these days to make your penis bigger. Try that instead of fantasizing about how much smarter you are than people you don’t know.

  16. sorry Ted, every year there are dozens of conferences and the goal is for PRO hackers to get in and take control of the Mac, PC and Unix box. So far, no one without local access and sitting at the Mac has been able to get control of the computer and create a self replicating virus.

    Frankly, the first hacker who can, will be a HERO in the community. He’ll have interviews on every morning talk show and be on Larry King in days. It is the brass ring goal of every pro to be the first to hack the Mac, and therefore most famous hacker out there.

  17. @bluefinpro

    Out of all the family members who have PCs Most of them got powned from the internet. NOT USB key of local hacker.

    I always got accused about being an Apple fanboy , now I see how assassin some of you protect OS X like it is Fort Knox. Start listen to security podcasts and wake the hell up.

    Browser headers, safari or firefox i-Frame redirect, through a placed bad iFrame ad and a hundred of you guys are powned. The numbers are not there for the pros to spend a week sifting through code to find a safari zero day.

    But then you guys are so smart you kept tell me the Mac was stealth when it is not if you are on the net surfing. Remember browser headers…… No but it is suppose to be stealth. no but but

    pile on boys and give me there is no virus on OS X BS again.

    Vulnerabilities is our key word here not. Arbitrary code execution.

    Tell me OS X can’t have arbitrary code execution. Virus, Trojan no known virus on OS X No virus. Are you guys still thinking clicking on the link is the only way to get powned in 2010.

  18. I would just love to see some of you OS X is Fort Knox guys at the Black Hat Conference and go on that network with your Fort Knox OS X. You would get powned in 5 mins on your Fort Knox OS X. There are guys there that eat OS X for lunch.

    But remember, these guys are smart and they know if they use their zero day and get caught it is jail time.

  19. @El Guapo,
    Yes you are right. Guess the “ain’t no” slang style got the best of me. Just tired of people stating their guesses as facts. Should have placed the “without proof” in parentheses. Thank you for playing the editor.

  20. @ Ted

    Judging by your execrable command of English, I place little credence in your “analysis”. You make many claims for OS X’s vulnerabilities and yet do not cite any verifiable source for your assertions. Please provide independently verifiable sources for your allegations or kindly STFU.

    You make a better idiot than you do a troll – I suggest you go back to shucking fries, a task for which you have already demonstrated a barely adequate grasp, since computer security is clearly well above your limited comprehension of reality

    =:~)

  21. Come on Father Ted, tell us are you the PR Guy for Sec…..whoever they are.

    Are these pro hackers under the bed with the Russians waiting to take over the world ? must we stand guard at nights in case they attack ?

  22. I read the full article. They are talking about vulnerabilities that are in itunes and quicktime FOR WINDOWS. So the media will be ablaze with this crap because Microsoft can’t make a decent operating system.

  23. Apple doesn’t brag about security because it doesn’t want to piss off hackers, either. Not that Macs could ever be worse off than Windows- but going from zero viruses to 20 would be disconcerting, and, yes, of course, blown way, way out of proportion. Like this “report,” which is all over the internet. The ant-Apple people do more damage than any real problems or “flaws.”

  24. ANTI-FUD:

    I receive EVERY Secunia report they publish via eMail.

    Want to know what they publish every week? A GIGANTIC PILE of Windows vulnerabilities and extremely few Mac OS X vulnerabilities, as in about 1 (ONE) per month, at a guess.

    This FUD attack by Secunia is made utterly hilarious by their own publications. Don’t believe me. Go look for yourself:

    http://secunia.com

    Examine the home page. What do you Highlighted see there? Today:
    – Microsoft Windows Shell Shortcut Parsing Vulnerability
    – Apple iTunes “itpc:” Handling Buffer Overflow [That is SPECIFIC to WINDOWS ONLY[
    – Microsoft Windows MFC Document Title Updating Buffer Overflow

    Is there ANYTHING there related to Mac OS X? NO!

    So what’s with the FUD?

    –> The fact that nearly the entire Anti-Malware Community lives off the security FAILures of Windows. Therefore, obviously, everyone MUST USE WINDOWS in order to keep them all employed!

    ∑ = Pure Adulterated PROPAGANDA

    And no folks. There is nothing perfect about Mac OS X security. It just happens to be the most reliable of any GUI OS on the market. The only OSes with better security reputations are:
    – OpenBSD
    – FreeBSD

    And oh look. Mac OS X contains elements of BOTH these OSes.

    Hey FUD mongers: GET BENT.

  25. Ted & others, you may have a valid concern about Mac users’ complacency, and you are simply wanting us to wake up and smell the coffee. The thing is, I don’t drink coffee. I drink whiskey, lots of it especially after reading some of these MDN posts. ; )

  26. Well, Ted, the thing I find interesting about your argument is that despite all of the evidence to the contrary and the lack of evidence supporting you, you might be right… but we won’t know until it actually happens. And for several years now, people like you have been coming to this site crowing about how people like us (I have had my firewall turned off for years now) are ripe for picking, at least since 2006, when the news that Macs were virus-free started making the rounds. We’ve had this argument many times with people considerably more articulate and convincing than you. And you know what? We’re still waiting. Until then, we’ll continue surfing the web without fear and saving time, money, and processing cycles by not dicking around with Antivirus software.

  27. It has nothing to do with viruses and maybe very few Trojans . It is zero day vulnerabilities and arbitrary code exaction. Bad I-frames from ads that have OS X zero days. Fuck viruses. Take that one out of the picture.

  28. @Ted:

    Dr. Charlie Miller has a decent book for geek level Mac hackers.

    The Mac Hacker’s Handbook

    One thing Miller points out in his interview is that the biggest new security features in 7ista have been cracked:

    “Windows used to be much harder because it had full ASLR and DEP (data execution prevention). But recently, a talk at Black Hat DC showed how to get around these protections in a browser in Windows.”

  29. As for other ‘Ted’ comments:

    Sorry, but the quote below does not pass muster. It’s more of the same old lame old ‘security by obscurity’ crap that anyone capable of doing math can destroy instantly:

    “OS X has never been tested with the full Russian/Ukraine/China/Asia hacking world hacking it 24/7. It will have weekly breaches just like MS has when it becomes a target from the pros and government pros. To this date you have only seen a couple grains of sand hitting OS X. Wait till the whole beach of sand starts knocking on it’s door. Mass pownage.”

    The fact is that Windows has over 1000x more malware than Mac OS X on a 1:1 user basis. That’s insanely high. It’s obviously because Windows is drastically less secure. Your argument makes not-a-dent in this fact.

    And BTW, it’s spelled ‘pwnage’. It’s pronounced ‘ownage’. Saying ‘pownage’ is for newbies.

    Hmm… What other ‘Ted’ faux pas shall I find…

  30. Here’s a comment I threw in PC World’s face this afternoon, and up on my Mac-Security blog. It shouts volumes:

    ~~~~~~~~

    Facts (vs FUD) regarding Macintosh security:

    Number of Mac OS X viruses: 0
    Number of Mac OS X worms: 0
    Number of illegal Mac OS X spyware: 1
    Number of Mac OS X Trojan horses: 23

    Compare that to the numbers for Windows and decide for yourself.

    No one ever said Mac OS X was perfect (except trolls). But it remains the single most secure GUI operating system available. Only OpenBSD and FreeBSD are more secure, and no surprise that Mac OS X contains elements of both.

  31. So Ted,

    Tell us what version of Secunia PSI you are running on your Mac. I can’t seem to find an OSX download on the Secunia web site.

    Please help me out. Please !!

  32. @Ted

    TED = Too Easily Duped

    Quit lying. Most trollers start by trying to ‘validate’ that they are a user of something. Ie. I am an astronaut and own two Apple rocket ships but Microsoft Bullet Bob says that Apple ones aren’t as good because they don’t have a built in nut scratcher.

    Go back to your sad, virus plagued, UI nightmare of MicroDroid penile prosthetics.

  33. While I’m taking over the comments, (sorry, it’s one of my areas of expertise and I love the attention ” width=”19″ height=”19″ alt=”wink” style=”border:0;” /> ), let me make more fun of ‘Ted’ comments:

    “Wake the hell up! Thinking OS X is this God of an operating system. It will fall…” blahblahblah

    In reply, here is another comment I threw in the face of PCWorld this afternoon, and posted at my Mac-Security blog:

    ~~~~~~~

    PCWorld: “Here’s another blow to those insist that Apple products are rock solid and unhackable”

    Me: No one says “Apple products are rock solid and unhackable” except YOU PC World. It is an invented club with which to slam and abuse Mac users. It’s called desperate propaganda, aka FUD.

    ~~~~~~~

    It’s expected and kind of lame of ‘Ted’ to reiterate this old troll line. ‘Ted’ is myth mongering.

    FACTs:

    1) Mac OS X has zero-day exploits on a regular basis. Apple Security Update 2010-004 (the most recent) consisted of 23 security patches.

    2) Mac OS X has 24 malware in-the-wild. Three of the Trojan horses can bot/zombie your Mac.

    3) In 2009 there was a Mac botnet of an estimated 10,000 Macs, caused by the above noted Trojan bots.

    So obviously it pays to pay attention to Mac security.

    But how does Mac security compare to Windows security? Go DIY your own research. But I warn you that there is no comparison. My earlier figure of 1000x more malware for Windows than Mac on a 1:1 user basis will prepare you for the further shock.

    ‘Ted’: Try harder.

  34. Ted
    You’re right! We Mac fanboys are gonna get whacked real hard any day now! Yep. …. Wait for it. …. Wait for it. … Wait. … It’s coming! …. Wait. …. … … … Wait. … … It’s almost here! … … … … … … … … … … … Waaaaait. … … … … … … … … … … … … Wait for it. … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … Any day now. … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … Wait. … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … … Yep, when the full Russian/Ukraine/China/Asia hacking world is hacking it 24/7, it’s gonna be real messy for us Mac Cultists! … … … … Right about … … … … … wait. … … … … It’s coming! … … … … wait. … … … … … … wait. … … … … … … …

  35. @Ted
    You don’t think that *any* pros have attempted to hack Mac OS X in the wild? Surely one or two have taken offense at MDNs repeated taunts of operating for ten years without being hacked, even after turning off the firewall? Why are you so positive that “OS X has never been tested with the full Russian/Ukraine/China/Asia hacking world hacking it 24/7”? But let’s assume that you are correct and only a small percentage of pro hackers has dabbled in Mac OS X. Surely even a small subset of that “hacking world” would produce some results in the wild if “weekly breeches” are a certainty in the future.

    You speak as if you are an OS security expert and also appear to believe that every other Mac user is a clueless Apple polisher with no brains at all. That kind of extreme viewpoint is inaccurate. Most of us do not claim that Mac OS X is invulnerable, but it is worth noting that even with the sharp increase in Mac sales in recent years, the incidence of actual security exploits cannot be explained simply by “obscurity.” In my book, 100,000 to nearly none is called a skunk. When the eventual exploit of Mac OS X does occur, there is a significant possibility that it will be via software products from Microsoft or Adobe.

    By the way, Ted, what are you doing to avoid the inevitable “mass pownage” of Mac OS X devices?

  36. @Ted
    “… now I see how assassin some of you protect OS X like it is Fort Knox…”

    I’m sorry, (and seriously, I’m not trying to attack you) but what the heck does this sentence mean?

    Really? What does this mean? It’s non-sensical.

  37. @Ringgo

    I will replace Doubt with Disinformation from this day forward, because it makes much more sense.

    Uncertainty and Doubt are redundant, which I always thought was stupid to include both just to create an acronym.

    When you think about it, the noun, disinformation, is an ideal substitute for Doubt because it better describes what actually transpires during these campaigns.

    Fear is used to jar our reptilian brains into action. Uncertainty freezes us in place. The disinformation evens our conviction when obfuscation blinds us to the truth, creating a feeling of hopelessness.

    FEAR. UNCERTAINTY. DISINFORMATION.

    FUD!

  38. CRAPPLE has no clue how to make anything secure.
    and why would they? They’ve persisted to this point on the “security by obscurity” program…they never had to worry about how secure their products were, because no one would bother to attack an insignificant player like them.

    But now that people are scrutinizing their products (despite the fact that, at ~4% of the computer market, they’re still an insignificant player), it’s obvious that they have no clue what they’re doing.

    In the end, it will make no difference. Macolytes will continue to buy and use CRAPPLE products no matter what – people with brains in their heads will just look at the Macolytes and wonder what the eff they are thinking.

    From now on bing and decide. http://www.bing.com

  39. Hi,
    I been a mac user for 20 years. I have used System 6, System 7, Mac OS9, and Mac OS 10.0 to 10.6 and I found Mac to be more reliable and secure than Windows.
    My opinion about Ted is that he needs to gets his facts. Last time they had a contest, someone hack into Mac, running OS X in less than a minute. That was last year I think. Everyone was shocked. Now the truth came out, and the fact was the first attempt was unsuccessful, so the judges relax the contest rules. So one the contestant asked one of the judges to go to the site, using safari, and click on the link and the mac was hack into less than a minute.
    If you read the news Ted, the US Military starting to us Macs now, why because they got sick of their Windows machines getting hack into. Don’t forget Snow Leopard is now certified Unix.
    By the way I don’t use antivirus , spyware or malware programs to protect my Mac like Windows uses have too.
    I think of Mac computers as F-22 Raptors and Windows SU-33.

  40. Who cares about the Charlie Miller hacks? He can only make it happen by:
    1) Setting up the site in advance (which does mirror how real threats work)
    2) Needs LOCAL access to the Mac that then has to access his trap (something the cyber-criminals cannot yet do, and if they could, the first step would be irrelevant).

  41. Ted clearly doesn’t understand safety vs. security. Neighborhood analogies for you, Ted..

    Windows and North Philly are the same. People out to kill you you, rob you, get anything they can. YET, YOU claim it’s a far more secure environment due to the multiple deadbolts on the door, bars on the windows, kevlar-plated pajamas you wear, and the gun under your pillow.

    Mac and Doylestown are the same. The ENVIRONMENT is far safer. For one, if a problem does arise (Mac Trojan), community watch is in full effect and won’t stand for it — they’ll alert everyone to the problem. Yet, FUDsters like you will claim that Doylestown is far less secure because people tend to leave their doors unlocked all day, even when they are at work (some truth to that).

    So, from a “security” point of view, North Philly is more secure. More locks. More bars. More protective armor. A nice gun to shoot at the bad guys… and yet, the less secure place (Doylestown) is FAR safer.

    Stop with your BS. Mac wins hands down in true safety.

  42. @Ted

    Look at any OSX Server security log. The numbers of failed username/password attempts at SSH access and other Unix probes are the same as those one sees on any server. Trace the IP addresses and one finds that the “Russian/Ukraine/China/Asia hacking world” appears to be on the job “24/7” with OSX, too.

  43. Sorry, Ted. Your chicken little act is barely covering the fact that you are nothing more than a troll. I’ll tell you what. The moment I have any genuine security concerns that require more than the safeguards I currently have in place, I’ll let you know. Until then, thanks for playing!

  44. All 15 bugs affect both the Mac and Windows versions of Safari.

    “Nearly every bug aside from [Grossman’s] is basically a drive-by,” said Andrew Storms, director of security operations at nCircle Security, in an instant message. “Essentially, it’s what we fear in browser bugs. It’s the kind of attack where the ordinary user clicks on something and boom, it’s game over for you.”

    Thirteen of the 15 vulnerabilities fixed today could, in fact, be exploited by classic drive-by attacks, the kind that execute when a person simply surfs to a malicious site or an already-hacked legitimate domain. The 13 drive-by bugs were all found in WebKit, the open-source browser engine that both Apple and Chrome use as the bedrock of their browsers.

  45. 8-3-10 iOS4

    “Not only does this elevate to the root, giving you complete control of the iPhone, but it breaks out of the sandbox,” said Miller in an interview Monday, referring to the isolation technology designed to block rogue code from escaping the mobile Safari browser.

    “There’s no shell on the iPhone, so [comex] had to do all that himself to get control,” Miller continued. “He elevated to root, turned off all code signing, broke out of the sandbox…all in the payload of the exploit.

    “And it works every time. Not just a few times out of a hundred. But every time.”

    http://www.computerworld.com/s/article/9180099/iPhone_jailbreak_exploit_sweet_and_scary_says_researcher

    .

  46. Here you go all you assholes who gave me shit when I said OSX is vulnerable. Two to three days later and here is exactly what I was talking about. You Apple fan boys are clueless about security. Smart by a 1/2. Especially you Derek. You put OS X up on a pedestal and a couple days later there is a perfect example of what I was talking about, happened. Just be glad it was a whitehat.

    Pwned iPhone and iPad with ease!!!!!! Just visiting a site.

    “Not only does this elevate to the root, giving you complete control of the iPhone, but it breaks out of the sandbox,” said Miller in an interview Monday, referring to the isolation technology designed to block rogue code from escaping the mobile Safari browser.

    “There’s no shell on the iPhone, so [comex] had to do all that himself to get control,” Miller continued. “He elevated to root, turned off all code signing, broke out of the sandbox…all in the payload of the exploit.

    “And it works every time. Not just a few times out of a hundred. But every time.”

    http://www.computerworld.com/s/article/9180099/iPhone_jailbreak_exploit_sweet_and_scary_says_researcher

  47. Kicking anonymous coward ‘ted’ in the ass is so much fun.

    Let us review the state of affairs:

    1) The Secunia Report, which is the actual subject of this thread, says NOTHING about Mac OS X. There is nothing to say. It remains the single most secure GUI operating system available. Only the CLI operating systems OpenBSD and FreeBSD are more secure. And good golly, Mac OS X contains elements of both these OSes.

    So ‘ted’? Darn, you’re wrong again. Keep trying! I’ll still be here to trample your troll turds.

    2) The Secunia Report speaks ONLY about Windows. The core of the security problems with Apple apps for Windows is ‘JavaScript’, or more accurately ECMAScript, built into QuickTime. ECMAScript is not an Apple technology. This means both iTunes for Windows and Safari for Windows are affected. The main problem with ECMAScript is the JScript crap from Microsoft that they created for Internet Explorer. The original JavaScript, aka ‘LiveScript’, was created by Netscape to be a safe scripting language. Microsoft’s JScript and Adobe’s ActiveScript ruined all that. Blame them.

    http://www.ecmascript.org/

    3) The second most critical Apple security problem on Windows apps is WebKit. WebKit is not Apple technology. It is an Open Source project. It was originally known as Konqueror. Apple help fund the project. It is the second most used Internet rendering engine on the net, after the catastrophically insecure rendering engine in Internet Explorer. It is used in Safari, OmniWeb and Google Chrome.

    http://webkit.org/

    4) Because both ECMAScript and WebKit are cross platform technologies, they affect Apple apps on both Windows and Mac OS X.

    But again ‘ted’, neither of these technologies are Apple’s. So stick that up your favorite human orifice.

    5) This past week the very FIRST exploited security hole in iOS was announced. The hole is specific to code in both the Safari browser for the iPhone and the PDF rendering engine for the iPhone. It allows an Internet drive-by take over of versions of the iPhone, iPod Touch and iPad running iOS 4. The current exploit is used exclusively at one website to jailbreak these devices. So far there is no malevolent exploit in-the-wild. Apple have acknowledged the security hole and created a patch that will be in the next revision of iOS 4.

    ‘Ted’: You need an enema, you decrepit little troll.
    ” width=”19″ height=”19″ alt=”tongue wink” style=”border:0;” />

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.