Slashdot Mirror


Apple Releases 'Highly Critical' Patch

Toothpick writes "Apple Insider reports that a new security update is available for download from Apple. This addresses issues identified in sudo, Safari, and OpenSSL among others. The gory details are, predictably, available on the Apple Info site." Commentary from ZDNet is also available.

25 of 96 comments (clear)

  1. This could wait a few months, right? by Golias · · Score: 4, Funny
    Why can't Apple just patch their...

    ... oh, they did? Before there were any exploits in the wild?

    Never mind.
    --

    Information wants to be anthropomorphized.

  2. How is this news? by Paul+Bristow · · Score: 5, Insightful

    So called highly critical patch installed itself yesterday on my iBook.

    For those of us who need it, Apple update takes care of it.

    If there was an exploit that meant we should click on "Software Update" instead of waiting for it to cycle round, great but this is just Apple-bashing. Is this a microsofty going "look! other OS's have security updates too" while there are many many exploits in the wild for them?

        Anyway it's a day late. This is "internet time", if you can remember that far back :-)

    --
    - Paul
    1. Re:How is this news? by jht · · Score: 4, Insightful

      Yes, it would be better if this (and other flaws) never occurred. The main point here, though, is that Apple typically does a pretty good job of finding and addressing these flaws when they occur, and in a timely fashion. Microsoft does so in many cases, but in others they sit on the problem long enough that there's an opportunity for crackers to find and exploit it.

      So for the most part Apple's methods work well. Of course zero bugs is a good target, but prompt identification and dissemination of fixes is reasonable. It's also pretty tough to craft an exploit that will simply zap Mac users and then get to them before Apple has an opportunity to get the patch out.

      One thing Apple should do, though, is make Software Update a bigger part of the Guided Tour, and set it to default to check daily and download critical fixes automatically (right now, it just notifies as default behavior, and checks weekly). I've noticed users who simply ignore Software Update's dialog boxes because they don't understand what it's doing.

      --
      -- Josh Turiel
      "2. Do not eat iPod Shuffle."
    2. Re:How is this news? by prichardson · · Score: 4, Insightful

      Users don't ignore software update dialogues because they don't know what it's doing, they ignore them because they've been trained that they won't know what it's talking about. If they actually took a minute to READ the dialogue, I think all but the most naive and illiterate would find it pretty self-explanitory. The window is titled "Software Update," and that is the extent of the vocabulary required to know what's going on. The word update is a common english word, so everyone should be able to get it, and the word software is far from obscure computer vocabulary. Right below that is a text space that says in bold "New software is available for your computer." Finally, the words "Security Update" are in the name of the patch itself, which is visible and the user can click on it to get a more detailed description.

      This is a not a difficult dialog box, and it's explained in the (very short) OS X manual. If a user can't figure this one out either they're illiterate or they just don't want to (much more likely). An absolute worst case scenario would be to ask someone else what it was. The explanation would take mere minutes.

      --
      Help I'm a rock.
  3. Re:Apple? by jtshaw · · Score: 4, Funny

    Apple includes the BSD userland utilities, and while it does include some GPL'd software it does not require any to run properly. However, I believe we should petition them to starting calling it the "Mach based Darwin/BSD/Mac OS X featuring OSS Software by GNU, Apache, Postfix, Samba, ect."

  4. Re:One problem by vertinox · · Score: 2, Interesting

    nstalled yesterday. No problems so far

    I installed updates on a 10.3.9 and a 10.4 machine and it appeared fine til I noticed I can't share files anymore between the two machines. Might be a configuration change though.

    --
    "I am the king of the Romans, and am superior to rules of grammar!"
    -Sigismund, Holy Roman Emperor (1368-1437)
  5. Re:Problem solved by vertinox · · Score: 2, Informative

    Apparently the Apple File Sharing had become unchecked after the patch and by rechecking it and rebooting both machines it resolved the issue (oddly enough it wouldn't resolve the issue til they were rebooted)

    --
    "I am the king of the Romans, and am superior to rules of grammar!"
    -Sigismund, Holy Roman Emperor (1368-1437)
  6. Re:helpful list of Apple's recent security updates by Anonymous Coward · · Score: 5, Informative

    Ummmmmm... when did Apple change their domain to "get.sent.to" ? Don't support someone with clickthrough advertising, just go directly to http://www.apple.com/support/downloads/

  7. Re:Highly Critical? Huh? by Anonymous Coward · · Score: 5, Funny
    Highly critical? Why didn't my highly vulnerable mac get attacked for the last five years?

    You don't understand the Windows vs. Professional OS sequence for vulnerabilities:

    Professional OS:
    -Vulnerability found by white hat security world
    -OS Vendor informed
    -OS Vendor works on patch that both fixes vulnerability and doesn't make things worse
    -Vendor tests patch thoroughly
    -Vendor releases patch; world as a whole, including script kiddies, first hear about vulnerability
    -Users, trusting vendor's track record, install patch (see "doesn't make things worse" above)
    -Any exploit is too little, too late.

    Microsoft:
    -Vulnerability found
    -Microsoft informed
    -Nature of vulnerability leaks out to world as a whole
    -Microsoft shoves thumb up bum, waits 6 months
    -Exploit released
    -Microsoft shoves second thumb up bum, wonders about apparent discomfort
    -Microsoft eventually releases patch, may or may not make things better or worse
    -Frustrated people buy Macintoshes

    Simple, isn't it?

  8. Re:Apple? by TheRaven64 · · Score: 4, Interesting
    The GNU/ does refer to the GNU userland. The BSDs have their own userland, although they tend to use the the GNU Compiler Collection. The rest of the toolchain (make, loader, etc) are all non-GNU, as is the shell and the standard collection of POSIX utilities. It is common for BSDs to include GCC, GDB and GROFF, but very little other GNU software. In contrast a common Linux distro uses the GNU versions of ps, top, etc, a GNU shell (bash) and a whole raft of other GNU utils - if you removed them, then you would have an unusable system, which is why RMS requests people say GNU/Linux.

    By the way, both sudo and OpenSSL are OpenBSD spin-offs and nothing at all to do with the GNU project.

    --
    I am TheRaven on Soylent News
  9. The interesting commentary by Budenny · · Score: 2, Informative
    The interesting commentary is to be found on the Security Focus site.

    http://www.securityfocus.com/news/11359

    Look at the numbers. Whoever would have thought that the numbers for MS and Apple would have got this close? Complacency is their, and their users, greatest danger right now. You can see it in most of this thread. Time to wake up.
    1. Re:The interesting commentary by Morgalyn · · Score: 4, Insightful

      SecurityFocus is apparently owned by Symantec, so I'm unsure just how much salt you might want to throw on that article. I'm guessing at least a grain or two.

      --
      You say you got a real solution
      Well, you know
      We'd all love to see the plan
      (The Beatles)
    2. Re:The interesting commentary by 99BottlesOfBeerInMyF · · Score: 3, Informative

      Look at the numbers. Whoever would have thought that the numbers for MS and Apple would have got this close?

      Counting the number of bugfixes released is no measure a a system's security. The number of remote vulnerabilities on a default install of the OS, the ease of exploiting those vulnerabilities, the number of local exploits, and the likelihood of an exploit happening are all factors. Additionally, predictive criteria, like past performance and the exposure and design of the architecture may be useful. If you look at Windows it has innumerable unpatched local vulnerabilities and working exploits that have existed for many years. They don't even bother fixing them most of the time. OS X on the other hand has a handful of potential local priviledge escalations vulnerabilities, that are fixed in a timely manner, and with one or two proof of concept exploits (none unpatched). Windows has a number of long running remote vulnerabilities and they crop up every month. Exploits for these vulnerabilities occasionally appear before a fix is available for the vulnerability, and regularly appear before administrators have time to thoroughly test those fixes (which is very necessary due to the kludgy Windows architecture and their history of catastrophically broken patches). On OS X I am unaware of any remote vulnerability with a published exploit that preceded the fix for that vulnerability.

      The ease of exploitation of vulnerabilities on Windows is much higher due to the lack of a usable non-admin environment, non-network services that run exposed on the network, default settings that run unneeded services, auto execution of scripts and executables within default and unremovable applications, ease of concealing the nature of an executable in the GUI, integration of web browsing and file browsing code, lack of packaging for executables, shared registry, and larger install base for automated propagation. OS X is by no means perfect and experiences regular security flaws. Much of the security auditing that is done, is a side benefit of the open source user environment components OS X shares with other UNIX-like systems. I'd be much happier if Apple did some more thorough security testing of their products. That said, to make the argument that the security of OS X is approaching the same level of complete cluster-fuckedness that is Windows based solely on counting the number of vulnerabilities patched by the respective vendors is ludicrous.

  10. Two things... by Space+cowboy · · Score: 4, Insightful

    1) Securityfocus is owned by a company with a vested interest in selling anti-virus software to Mac (and PC) users. It does serve a useful purpose, but when the points made are so vague, I consider it more advertising than service.

    Say I wanted to market X, and say that I'm a sneaky and underhand individual. I might purchase or support a website dedicated either to X or anti-X and have *some* articles on it that suit my purpose. I wouldn't undermine the integrity of the site (well, much), but I would use it as an authoratitive mouthpiece that mouthed off about *my* preferred direction.

    So, ok I'm a cynic, but so far my cynicism has been proved right depressingly often. Sigh.

    2) "Looking at the numbers" is no useful guide to pretty much anything to do with security. The phrase works when the numbers themselves are the pertinent facts (eg: a bank-balance sheet). "Humans are obviously not the dominant species on the planet - there are millions more houseflys. Look at the numbers".

    The point is that one dose of cancer can kill you, but you may survive fifty or more infections of the common cold without significant harm. The numbers don't tell you the relative importance of the problem, and indeed may just reflect different counting methods or diligence in detection.

    Simon.

    --
    Physicists get Hadrons!
  11. These are serious.. but kudos for fixing them. by dreamer-of-rules · · Score: 5, Interesting

    My brother recently switched to Apple.. We were IM'ing about this update and he said..

    "one thing i looove about this thing is that i'm never afraid to update like in windows. i'm not scared that it will be worse off"

    Trust is important. How many people haven't updated Windows to SP2 still??

    --
    Everyone is entitled to his own opinions, but not his own facts.
    1. Re:These are serious.. but kudos for fixing them. by javaxman · · Score: 3, Insightful
      How many people haven't updated Windows to SP2 still??

      Forget SP2, how many haven't updated to XP ??

    2. Re:These are serious.. but kudos for fixing them. by mmkkbb · · Score: 2, Funny

      notice that you didn't say "upgrade"

      --
      -mkb
    3. Re:These are serious.. but kudos for fixing them. by argent · · Score: 4, Insightful

      I have no plans to update to XP until I'm actually required to by software that doesn't work on 2000.

      A more complex system with boobytraps deliberately hidden in the kernel and dubious anti-virus enhancements that actually make cleaning up malware harder? Yeh, I've gotta get me some of that. Plus, 2000 ships with a version of Windows Media Player old enough that it doesn't have its DRM tentacles coiled around the kernel's balls.

      I'm also going to be staying clear of the new Intel-based Macs until I'm reasonably confident they don't have boobytraps or effective "strong DRM" support. Not because I want to pirate software or rip protected CDs, but because that stuff's toxic.

  12. Re:What a shock? by kmo · · Score: 2, Funny
    does Microsoft delay because the fix breaks too manyu things

    The reason Microsoft patches to IE take so long is that their quality control is so good. They view every web page on the internet with each new version of IE before releasing it. Of course, by they time they do, some of those pages have changed such that they break, but Microsoft isn't responsible for that.

  13. Microsoft vs Apple by argent · · Score: 4, Insightful

    Microsoft: the latest security hole in the HTML control is a buffer overflow in Javascript. They've known about it for months. Nothing happens until a sample exploit is released.

    Apple: the latest security hole in Webkit is a buffer overflow in URLs. The first anyone hears of it is a patch through Software Update.

  14. Re:Highly Critical? Huh? by argent · · Score: 2, Insightful

    Given Microsoft's security record this should mean that Apple's share of PC market is at least 70%...

    If most people were as easily frustrated and as aware of why they should be frustrated and care about security as you and I are, it would be. But it's amazing how much crap people are willing to accept as a normal cost of using computers.

    I find myself regularly watching people put up with horribly broken systems and, after I fix the problem (because I can't even stand watching someone suffer), they're shocked. They didn't even realise the problem was a problem that could be fixed, they just EXPECTED it.

    And security?

    After having a contractor who is technically very good, and has been working in this business longer than me, stand there and argue why he should be an exception to my "No Outlook" policy WHILE I'M CLEANING OUT HIS COMPUTER THAT WAS INFECTED THROUGH AN OUTLOOK HOLE... I reckon that there's some fundamental difference between "average computer users" (no matter how skilled) and people like myself myself that goes far beyond experience and training and into some kind of "Zen" thing... I don't know.

  15. Re:Apple? by TheRaven64 · · Score: 2, Informative
    It's definitely worth playing with at least one BSD. I run FreeBSD on this laptop, and OpenBSD on a co-located Mac Mini (hosted by these people who have the best customer service I have ever encountered and, depressingly, no referrer program - I guess they don't need one). There are a lot of similarities and a lot of differences. OpenBSD is very much a classic BSD system. The kernel is an older design (it has the same sort of SMP support FreeBSD had five years ago), but older means better tested, and if you don't need anything newer it feels very polished.

    The WiFi support in OpenBSD is nicer, as is pretty much anything connected to networking, although FreeBSD is slowly importing most of the OpenBSD code (they've got pf - a really nice packet filter - and OpenBSD's dhcpd already). If you're looking for something to put on a firewall, OpenBSD is what you want - pf is so much better than any alternative I've seen (miles ahead of iptables, which was clearly designed by someone on LSD, both for flexibility and ease of use).

    FreeBSD has some nicer features on a desktop. The new scheduler, SCHED_ULE, is great for interactive processes - a compile job using 100% of the CPU has no effect on the responsiveness of the desktop, it's almost like being on an SMP machine (you need to enable it in a custom kernel in 6.0 - the default one is throughput, not latency, optimised). FreeBSD also has nVidia support in the form of binary drivers and DRI drivers for many other cards, OpenBSD does not yet. FreeBSD also supports some Windows WiFi card drivers through Project Evil.

    Both FreeBSD and NetBSD have a more modern init system (init scripts contain requires and provides lines, allowing them to be run in the right order with as much parallelism as possible), while OpenBSD uses the simpler BSD init system.

    Which you prefer will be a matter of personal perference. Do make sure you read the documentation. All of the BSDs have good man pages (although OpenBSD is ahead here by quite a margin), and the FreeBSD Handbook is also very good.

    --
    I am TheRaven on Soylent News
  16. my take by mkoz · · Score: 2, Interesting

    While comparing these things is difficult at best, try (for example) Secunia's relevant product pages:

    Advisories (2003-2005) OSX 57 & XP Pro 102

    As for vendor patches Apple is at 100%... not bad.

    (XP Professional) http://secunia.com/product/22/
    and...
    (Mac OS X) http://secunia.com/product/96/

    Is any system perfect... no (even OpenBSD admits to 1 hole in 8 years), but Apple does make it as painless as possible.

  17. Re:Highly Critical? Huh? -- Explained by commodoresloat · · Score: 5, Funny

    You just don't understand what they mean by critical. I installed this patch and it immediately started complaining about all the junk on my desktop. Then it started berating me for my lack of sensible folder organization. It criticized my choice of web browsers. I turned on iTunes to drown it out and it started giving me a hard time about my musical choices. By the time it started in on my clothes I was sick of it, so I uninstalled the patch. I'll take the data insecurity so as not to put up with the emotional insecurity, but YMMV.

  18. Credit where it's due by gryf · · Score: 2

    What I like is that Apple is providing public credit for institutions that are pointing out these flaws. Kudos for Apple for this, and double kudos for the third-parties who are assisting the public as a whole.

    --

    #-#
    Ad Astra Per Aspera
    A rough road leads to the stars