Apple not so secure after all?

Hey drop us a line about the show. Feel free to ask questions, provide feedback and criticism, or just ramble on about anything your little heart desires.

Moderators: snarkout, Patrick, dann

Post Reply
Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Apple not so secure after all?

Post by Tsuroerusu » Thu Jan 26, 2006 5:55 am

http://www.zdnet.com.au/news/security/s ... 678,00.htm
"OS X contains unpatched security flaws of a type that were fixed on alternative operating systems more than a decade ago, according to a security researcher credited with finding numerous bugs in Apple's increasingly popular platform."

Well, it's a superior Apple product you know! :lol: :lol: :lol:

Yet another reason why Linux and FreeBSD is better, and yes I still consider Darwin as "the victim of rape" of the BSDs! :wink:
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
Patrick
Site Admin
Posts: 2519
Joined: Tue Apr 27, 2004 11:38 am
Location: Easton, PA
Contact:

Post by Patrick » Thu Jan 26, 2006 8:28 am

Even though we bust on Apple ALL operating systems will have vulnerabilies and bugs. It's a flawed creation of a flawed being. The biggest difference between F/OSS and closed proprietary OS's is how the bugs are handled. The F/OSS community is very upfront about issues and tackles them ASAP. Microsoft is notorious for leaving vulnerabilities unaddressed for months on end until someone blows the whistle on them. If you have half a brain you'll see F/OSS is the way to go. It is the future.

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Post by Tsuroerusu » Thu Jan 26, 2006 9:59 am

Patrick wrote:Even though we bust on Apple ALL operating systems will have vulnerabilies and bugs.
Absolutely, no doubt about it, if Mozilla assumed that there were never gonna be security issues with Firefox because it didn't support ActiveX and ActiveScripting they would never be considered serious about their "product". Actually I can tell you that when you try to update SUSE Linux 10.0 right after the installation, you will receive a kernel update, because there are vulnerabilities in there.

Patrick wrote:The biggest difference between F/OSS and closed proprietary OS's is how the bugs are handled. The F/OSS community is very upfront about issues and tackles them ASAP.
Microsoft thinks that security by obscurity is the best way to prevent security issues, like "if you just don't tell anybody, no one will ever know about this thing", Microsoft, and other proprietary companies, argues that if you release the source for your software, you make it eaisier for crackers to go find security issues in it, I and pretty much the entire free and open source software world says that obscurity is bad, if you release the sourcecode, it's an even playing field between you and the cracker, and you can assume he knows the same stuff as you do, with obscurity you don't know what the crackers know.

Patrick wrote:Microsoft is notorious for leaving vulnerabilities unaddressed for months on end until someone blows the whistle on them.
Yeah, I think their policy of only releasing patches at the second Tuesday of every month is stupid as all hell, if there's a a vulnerability in software that I use, and that I consider critical, I want it fixed within an hour! I don't wanna wait for them idiots in Redmond to get done scratching their nuts and releasing a patch for it!!

Another ridiculous thing about Microsoft's security and patching policies is the way the consider a vulnerability as critical and important. They say that a vulnerability in Windows is critical, only "if its exploitation could allow the propagation of an Internet worm without user action", and then one step down from that they say that a vulnerability "whose exploitation could result in compromise of the confidentiality, integrity, or availability of users' data or the integrity or availability of processing resources" is important. Is don't know how ANY business could find such policies relieable!!! THE SECURITY OF MY DATA IS CRITICAL FOR CRYING OUT LOUD!!!!

Patrick wrote:If you have half a brain you'll see F/OSS is the way to go. It is the future.
Yeah, let's hope that more people will report of success stories using Linux and people that have actually migrated from Windows to Linux reports of huge cost savings, because the real heart of Microsoft's brainwashing "Get The Facts" campaign is that Windows offers lower TCO than Linux, which is nonsense.
Last edited by Tsuroerusu on Mon Mar 27, 2006 8:09 pm, edited 1 time in total.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
Wally Balljacker
Posts: 1227
Joined: Fri Jul 29, 2005 3:32 am
Location: University of Massachusetts - Lowell
Contact:

Post by Wally Balljacker » Thu Jan 26, 2006 10:08 am

Tsuroerusu wrote:Yeah, let's hope that more people will report of success stories using Linux and people that have actually migrated from Windows to Linux reports of huge cost savings, because the real heart of Microsoft's brainwashing "Get The Facts" campaign is that Windows offers lower TCO than Linux, which is nonsense.
What exactly does Microsoft base these "facts" on?

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Post by Tsuroerusu » Thu Jan 26, 2006 10:31 am

Wally Balljacker wrote:What exactly does Microsoft base these "facts" on?
I think they base it on incorrent values from their customers, for example a 7Eleven-style store chain here in Denmark says on Microsoft danish "Get The Facts" site: "We used to use UNIX, a system like Linux, and with Windows we have saved a lot of cash"

It's very very edgy IMHO, I don't get why people just eat the shit up!
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
jsusanka
Posts: 306
Joined: Wed Aug 10, 2005 9:24 am
Contact:

they have to

Post by jsusanka » Thu Jan 26, 2006 3:14 pm

Microsoft is notorious for leaving vulnerabilities unaddressed for months on end until someone blows the whistle on them. If you have half a brain you'll see F/OSS is the way to go. It is the future.
they have to take their time about patching because everything is so dam integrated if they patch one thing they have to check a thousand others to see if anything is broken.

FOSS is created with this in mind from the start - modularity - if you have to patch a browser your os networking functions aren't going to be broken because it doesn't touch them.

Microsoft just needs to start from scratch - but they can't - they are their own worse enemy (and not just in the way either).

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Re: they have to

Post by Tsuroerusu » Thu Jan 26, 2006 3:22 pm

jsusanka wrote:Microsoft just needs to start from scratch - but they can't - they are their own worse enemy (and not just in the way either).
You nailed it on the head, the fundemental security architecture of Windows is so flawed and insecure that it can't be fixed. It's funny, Microsoft success may be their downfall, because if they do abandon the 200 million Windows users out there, they will be cursed to hell by any one of their current customers who will run to Red Hat, Novell, IBM... for Linux stuff, and if they don't do this they will slowly die over time, because Windows is so darn insecure.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

Post Reply