Welcome | Sign In
MacNewsWorld.com
Security Updates

Apple Gives Leopard a Good Brushing

Print Version
E-Mail Article
Reprints
Apple Gives Leopard a Good Brushing

Apple's release of a major update for its Leopard operating system has further deflated the claims of some fans that Macs are intrinsically superior in the security department. There's a cup-half-full argument to be made, though: It's because more consumers are using Mac systems that the OS is attracting more attention from hackers.


Apple (Nasdaq: AAPL) has completed a major security overhaul of its Leopard operating system. The fix addresses more than 40 crucial security flaws, including one in iCal that allows hackers to attack the computer remotely.

Other flaws that either result in application terminations or arbitrary code executions have been found in AFP Server, AirPort, AppKit, Apple Pixlet Video, ATS, CoreGraphics, Help Viewer, Core Foundation, Flash Player Plug-in, iChat, Mail, Automator, Time Machine, VoiceOver and Parental Controls.

Security Update 2008-003 also has a non-security function: It enables iPhone users to sync Mac address book contacts with Google (Nasdaq: GOOG) contacts.

Repairing iCal

Plugging the iCal hole was the most immediate need Apple had to address. Last week -- after reportedly trying for months to work with Apple to coordinate disclosure -- Core Security published three Mac OS X iCal-based vulnerabilities: Two of them could crash the iCal program, but the third could allow a hacker to take control of another person's computer.

iCal uses the .ics extension and the CalDAV protocol for calendar-sharing. iCal-using Mac owners may be exposed to possible exploits, as a growing number of Web sites provide calendar files and subscriptions to calendar updates.

Besides the iCal flaw, the patch addresses collaborative functions that could be used as vectors for attack. For instance, Web-based plug-ins such as Adobe (Nasdaq: ADBE) Flash have become attractive to hackers, Ryan Barnett, director of application security at Breach Security, told MacNewsWorld.

"There have been many recent reports of malicious Flash files being hosted on Web sites that aim to exploit known vulnerabilities to install Trojan software on client computers," he said.

In general, the patch does a good job of addressing the critical problems, Lori MacVittie, technical marketing Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales manager at F5 Networks, told MacNewsWorld.

"This is becoming more important as growing levels of malware are being written for the Mac," she noted.

Attackers are getting smarter and are using ubiquitous technology such as Flash, MacVittie added. That trend is exacerbated by the typical Mac user's misguided sense of invincibility against hack attacks.

Aura of Safety

Indeed, as more consumers embrace Macs and as more hackers target OS X, the reputation of Apple's computing product line will continue to take hits. This is not necessarily a bad thing -- at least not for consumers that may naively believe their Macs are safe to use online without any protection, Ken Dunham, director of global response at iSIGHT Partners, told MacNewsWorld.

"Apple computers are traditionally viewed as less vulnerable to malicious code attacks," he observed, but "this is true or false depending upon the context of your statement."

Software on any platform is likely to contain a certain number of errors or vulnerabilities, he explained. "As a result, [the statement that a Mac is more vulnerable] is true [given] that continued development of Macintosh software has led to the development and discovery of new vulnerabilities that open the door for possible malicious actions. However, [it] can also be viewed as largely false when considering malicious code which is not mature within the Macintosh 10.x operating system."

No operating system is completely invulnerable to attack -- including Macintosh -- which means consumers must practice safe computing and harden their computers' configurations against known vulnerabilities, Dunham continued.

"Hackers today are financially motivated -- largely focused upon Windows and other platforms," he noted. "However, for Macintosh, increased capabilities and some exploitation in the wild have taken place in the past 18 months. Still, these cases are very limited in scope and impact when compared to other known attacks in the wild on other operating systems.

"It's possible as Apple gains market share, [OS X] will be increasingly targeted by hackers due to the increased number of potential targets using Macs," Dunham concluded.


Print Version E-Mail Article Reprints More by Erika Morphy


Talkback: Join the Discussion.
Erika, your thesis is illogical...
asdfasdfadsf
Posted 2008-05-30
This is precisely why girls should not be allowed to discuss technical topics- complete and ...
reputation
jdawgnoonan
Posted 2008-05-30
Their reputation has not been tarnished at all. There still has never been a true virus in the ...

More by Erika Morphy

Windows 7 Flies Off the Shelves
November 06, 2009
Early sales figures on Windows 7 boxed software suggest a high level of consumer enthusiasm for the OS. Unit sales were a whopping 234 percent higher than Vista's out of the gate. The revenue haul was not as impressive, as Microsoft offered sharp discounts to spur presales. Also, sales of PCs with Windows 7 preinstalled have been lackluster -- but October is historically a weak month for PC sales.
Southwest Doesn't Fool Around
November 06, 2009
Either Southwest Airlines had better deals for my favorite route than its competitors or its superior Web site tools made it easier for me to ferret them out. Either way, kudos to Southwest. In the not-so-hot department were the airline's long list of what passengers weren't allowed to do and its very short list of what Southwest was obliged to do for them. Left me feeling a little chilly.
Commerce Search Puts Google Inside Retailers' Catalogs
November 05, 2009
Google has launched a new cloud-based search tool targeting enterprise-level e-commerce operations, just in time for the 2009 holiday selling season. Commerce Search provides a set of features designed to improve the relevance of results for consumers searching a retailer's own product catalog, while boosting cross-selling opportunities.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network