Call for Apple Security 'Czar'
conq writes "The second security non-incident to hit the Mac platform in as many weeks has been debunked. People are talking a lot about security on the Mac these days, and the result is that a great deal of FUD is being spread around. BusinessWeek's latest Byte of The Apple column suggests that its time for Apple to appoint a security Czar to get out ahead of the FUD before it spreads much more." From the article: "Creating a CSO position may be viewed by some as an admission of weakness. Still, I say it would be a good way for Apple to inoculate itself against the perception -- warranted or not -- that Mac security may be eroding, and get ahead of the curve for any troubles that may be inevitable. That may not be the case, but in matters related to product marketing, it's the public perception, not the reality that really matters. And once you've lost a user's confidence, it's hard to get it back. Just ask Microsoft."
To maintain public confidence in its operating system, Jobs & Co. should consider hiring a security czar
Huh? Most of the "public" I know doesn't have any lack of confidence in OS X and hasn't even heard all the latest "scares" of OS X's security. In fact, I'd venture to guess that most of the "public" knows nothing about OS X being more secure than Windows (as it isn't really an advertised fact) and think that viruses/trojans/worms, etc, are just a part of computing.
Remember that to the average luser, anything made by Microsoft is top-notch. If it weren't, they wouldn't be in the position they're in market-wise. It's all those damn "hackers" out there that cause the problems, not Microsoft.
This guy's the limit!
Microsoft's probem isn't the public perception that it has security problems. It's concrete, measurable, reality that thorns their side. It's Microsoft who floated the "Windows get hacked because its a bigger target" fantasy. But you can take a Mac out of the box and scan it and find zero open ports. A Windows machine has more than a dozen. Those ports are open for Bill's benefit, not for the customers'. Bill wants to keep his fingers in every Windows box, and won't give up that capbility in exhange for better security. Yes, the Mac probably still has some OS flaws that hackers could exploit, and thus Apple can't be complacent. But at least Steve isn't holding the door open to let the hacker inside.
Who has a "security czar" on their systems? Trusted Solaris does not. Nor does HP, nor does Trusted Vax. Back in the early 90's when I worked at HP and later at IBM, I can tell you that we had groups that went over security, but once again, no "security czar".
Or are you trying to imply that MS is now secure?
I prefer the "u" in honour as it seems to be missing these days.
Sounds to me they need to hire someone with appropiate skills in either their PR or Legal departments.
Two non-security incidents in a month almost certainly mean that they're the victim of a FUD campaign.
The right way to answer that is not to validate the fud, but
... communicate the truth - which is a function of PR, and
... make sure no-one's illegally slandering their trademark -which is a function of legal.
The latter is far more dangerous to Apple than the hypothetical security non-issues a CSO could address.How do you expect Apple to dismiss security reports as "a FUD campaign" to be fought with PR when they just released a security update that patched 20 holes and in 2005 released security updates nearly every month (nearly as often as Microsoft)? Apple didn't have to release any from Dec 2005-Feb2006, but the massive March 2006 Security Update makes up for those three months. ;-))
Apple needs to treat their holes as real problems, not just as a PR problem. And they're actually doing just that by releasing fixes and not spouting PR. Spouting PR would only make them a bigger target for hackers, just as appointing a "Security Czar" would. The latter would also undermine confidence of the general public ("If Mac is so secure, why do they need a 'Security Czar'?")
-- "I never gave these stories much credence." - HAL 9000