Slashdot Mirror


Apple Hires Former OLPC Security Director

imamac writes "It seems Apple is seeking to beef up security by hiring Ivan Krstic, the one-time director of security architecture at One Laptop per Child. 'Krstic, a well-respected innovator who designed the Bitfrost security specification for the OLPC initiative, joined Cupertino this week and will work on core OS security. His hiring comes at a crucial time for a company that ties security to its marketing campaigns despite public knowledge that it's rather trivial to launch exploits against the Mac.'"

29 of 144 comments (clear)

  1. So trivial there's only one by SuperKendall · · Score: 3, Insightful

    So trivial in fact to launch an exploit on the Mac, that there's only one in the wild - and that's a trojan in a pirated application.

    I guess the challenge of the PC ecosystem is what draws in the thousands of viruses and malware applications they get.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
    1. Re:So trivial there's only one by MoonBuggy · · Score: 2, Interesting

      You're right, the number of exploits doesn't necessarily mean it's a more secure system, but the fact that (as you say) there aren't a proportionate amount to the size of the userbase does seem to imply decent security.

      I personally haven't heard of any exploit in the wild except the trojan, for which the user has to be willing to provide their password to any old bit of software with unknown providence - to be honest I don't know how one could protect against that on any system. If there are other exploits out there I would like to know about it, but if there aren't then the author has no right to say it's "trivial to launch exploits against the Mac" unless he's demonstrating that by writing them himself.

    2. Re:So trivial there's only one by ihatewinXP · · Score: 5, Insightful

      Yeah I would say a citation is needed here. Zero day exploits exist - on every system - but as a Mac user since '99 and a Windows admin since I can tell you no matter the skill level of the user: Macs dont get viruses. Period. Full stop. Yes I saw the embedded trojan in iLife and the zero day sploit that got the guy a free laptop recently but as a person who has really seen a wide cross section of computers and users all the way up to Vista it is decidedly two different worlds.

      Im glad Apple dropped the "100% virus free" moniker from marketing as has been pointed out it makes them a target - and good job on hiring forward thinking people in _all_ facets of the business. Now just get ZFS plugged in as the default file system and I will officially drown myself in kool-aid.

      And I hate to even point this out but look at the submitters username. If you just got to /. since the mac ads came out you might want to sit back and listen for a few. Years. I know I did.

      --
      ---- The real Slashdot is still here. You just have to browse at -1 to read the comments.
    3. Re:So trivial there's only one by Soubrause · · Score: 5, Insightful

      The malware industry has barriers to entry just like anything else, until we can make $x it's not worth any investment. OSX user base isn't big enough to generate $x yet. Even after that when x is 20% of y why not get $y for the same investment.

      Microsoft & their partners also advertise bounties on exploits encouraging people to try and find them first so they can be patched, this adds to what is found considerably. I've never seen Apple pay for but have seen them deny holes that were handed to them.

      I've seen OSX exploits that didn't require any more interaction from a user than those aimed at windows in farm environments; no reason something similar isn't out there on a site we've never gone to.

      Firewalls and proxies exist because some of us know better than to think our OS is secure.

    4. Re:So trivial there's only one by Anonymous Coward · · Score: 4, Interesting

      If the marketshare argument was true then there wouldn't have been any viruses for pre-OSX Macs either. But there were; lots of them.
      There were also viruses for the Apple IIGS, hardly a market leader.
      That's a tired old troll you have there, sir.

    5. Re:So trivial there's only one by phantomcircuit · · Score: 2

      Macs simply do not have enough market penetration to be profitable. That is the only reason that they have less malware.

    6. Re:So trivial there's only one by el+americano · · Score: 2, Interesting

      So they're only vulnerable to the hobbyist hackers... where are the successful malware examples from that group?

      If the argument is that it's not worth anyone's time, then shouldn't you say that we don't know how vulnerable it is? I don't trust Apple implicitly, given how buggy early releases of many of their product seem to be, but this unfounded speculation does seem to be a popular troll that's used equally effectively against Linux. Try being a bit more responsible.

      --
      Those are my principles. If you don't like them I have others. -Groucho Marx
    7. Re:So trivial there's only one by macs4all · · Score: 3, Informative

      Honest question, why are Apple releasing security updates if there are no security exploits in their software?

      Honest answer: Because you are confusing a (theoretical) VULNERABILITY (which ALL OSes have), but which have not been "realized", and an EXPLOIT (which is deliberately malicious code RELEASED IN THE WILD that leverages a VULNERABILITY). The OP and the GP were obviously referring to OS X EXPLOITS circulating in the wild, of which there simply are NONE.

      I know it sounds like I'm splitting hairs; but it is a VERY thick "hair"...

    8. Re:So trivial there's only one by nscheffey · · Score: 2, Interesting

      I personally haven't heard of any exploit in the wild except the trojan, for which the user has to be willing to provide their password to any old bit of software with unknown providence - to be honest I don't know how one could protect against that on any system.

      Luckily, Ivan Krstic knows how. From a CNET article about Bitfrost:

      Instead of blocking specific viruses, the system (Bitfrost) sequesters every program on the computer in a separate virtual operating system, preventing any program from damaging the computer, stealing files, or spying on the user. Viruses are left isolated and impotent, unable to execute their code.

    9. Re:So trivial there's only one by Mr2001 · · Score: 4, Insightful

      So trivial in fact to launch an exploit on the Mac, that there's only one in the wild - and that's a trojan in a pirated application.

      Cute. Does that mean PC defenders get to ignore all the computers that have been infected by trojans too?

      According to that logic, I think we'd find that Windows is nearly as "secure" as OS X. Most infections happen because people are stupid enough to run any program that promises them free smiley-face cursors, not because of vulnerabilities in the OS.

      --
      Visual IRC: Fast. Powerful. Free.
    10. Re:So trivial there's only one by dhavleak · · Score: 2, Interesting

      I totally agree with you, but
      grrr.. trust /. to degenerate the topic into "Macs are swiss cheese.." "no! widnows is swiss cheese".. etc..

      I'm really interested in hearing about Krstic's security philosophy and it's merits/demerits. I found this talk on zdnet but there's only about 5 minutes of actual security architecture info in it at around 40:00 into the video. Oh, and there's also this BitFrost overview on Wikipedia. I think there are some cool concepts there. The idea of sandboxing all apps into containers with sets of standard rights, and restricting IPC to certain approved mechanisms is pretty interesting. Was hoping poeple could focus on BitFrost and Krstic's security philosophies so we could all learn something.

    11. Re:So trivial there's only one by someonehasmyname · · Score: 2, Interesting

      >> more exploits being found for OSX than Linux and windows

      I don't believe that for Linux, and I certainly don't believe that for Windows.

      Face it guys, OS X is built on a BSD userland with the same OpenSSH you all know and love. It uses the same owner/group/others file permissions. It ships with an excellent firewall, and no open ports by default.

      IMO, it's as safe as Linux. The smart users will only ever see trojans and home-dir-deleting "viruses", and the dumb ones that type their password will get owned.

      The probability of hitting a Mac, and then having the user enter their password into a random unexpected popup is too low for Macs to be a viable target.

      --
      Common sense is not so common.
    12. Re:So trivial there's only one by Phroggy · · Score: 3, Insightful

      If the marketshare argument was true then there wouldn't have been any viruses for pre-OSX Macs either. But there were; lots of them.

      Malware was different in those days. Yes, there used to be Mac viruses. Nowhere near as many as DOS/Windows viruses, but a lot. They were mostly transmitted on physical media, not downloaded over a network; most of them were written before TCP/IP support was included in the OS. Most of the holes that allowed the old viruses to spread have been closed, and there just aren't that many holes that new viruses can take advantage of.

      Old-school Mac viruses were created by people looking for a creative way to make a virus because it was a fun challenge and it might gain them a bit of notoriety; there was never any profit in it (and most of the viruses weren't deliberately destructive, although some of them were accidentally destructive due to bugs). Modern malware authors are in it for the money.

      Since the OS itself is really pretty secure these days, the best way to spread Mac malware is to trick the user into deliberately executing your code for you, clicking through all the security warnings. If you're in it for the money, that's the approach you'll take. If you're not in it for the money, there's no technical challenge in that! Anybody could make a malicious application that looks like a fun toy, so what's the point?

      And if you're in it for the money, there's more money to be made on Windows right now. As Macs grow in popularity and Windows users start keeping their antivirus software up to date, the balance will shift, but it hasn't shifted yet.

      --
      $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
      $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
    13. Re:So trivial there's only one by warrigal · · Score: 2, Informative

      CyberAIDS, Festering Hate are two that come to mind.

  2. Flamebait summary by GreyWolf3000 · · Score: 4, Informative

    "His hiring comes at a crucial time for a company that ties security to its marketing campaigns despite public knowledge that it's rather trivial to launch exploits against the Mac."

    Public knowledge? Public knowledge? I doubt the "public" really thinks it's trivial to launch an exploit against the PC.

    I feel like I just listened to a 5 year old arguing to another 5 year old... "EVERYONE knows that YOUR operating system IS STOOOPED."

    --
    Slashdot: Where people pretend to be twice as smart as they really are by behaving like children.
  3. Re:I am lost here . . . by caladine · · Score: 4, Interesting

    Apparently they think now might be a good time to start battening down the hatches. They don't want to make mistakes like they did with the iPhone. Who seriously leaves a JTAG enabled and on the board of a production phone?

  4. Re:I am lost here . . . by chuckymonkey · · Score: 4, Interesting

    Let's see here. The guy that invented a good security system (nerd) is hired by a large corporation (news). So far we have nerd and news covered. Now let's see, how does this matter? As macs gain popularity they also garner the interest of people looking to make exploits for them. Apple is trying to head off the tide a little so they can still market as being more secure than their main competitor. Personally I'm a Freebsd/Linux fan, but for all the mac users out there I think that it matters. So there you have it, News for Nerds, Stuff that matters. Or maybe News about a Nerd, Stuff that Matters.

    --
    "Some books contain the machinery required to create and sustain universes."-Tycho
  5. Can't we all just get along by docbrody · · Score: 3, Funny

    Prediction:
    This thread will soon devolve into a flaming argument between Apple Fanbois and Apple FanBoi bashers.

    I am so tired of both sides arguing about Apple that I wish Slashdot would just remove the Apple section from the site.

    let the games begin

  6. And in other news... by dave562 · · Score: 3, Funny

    Apple execs have put down their glasses of marketing Kool-Aid and joined the real world. They're obviously trying to get out ahead of the potential security holes in their OS, and they recognize that, despite what the fanbois will say, OSX is just as vulnerable as most other topics. Luckily for Mac users, none of the system crackers seem to care about gay porn or graphic design files.

    1. Re:And in other news... by 99BottlesOfBeerInMyF · · Score: 2, Interesting

      Apple execs have put down their glasses of marketing Kool-Aid and joined the real world.

      Apple has always been a bit erratic when it comes to security, owing to their odd blend of cultures. To suggest, however, that they've been ignoring security is more than a little misguided. Leopard included the addition of a MAC framework ported from TrustedBSD, an application signing framework, and ACLs restricting some exposed services (like zeroconf) that would have been vulnerabilities otherwise. Apple has done a very good job of shipping an OS hardened enough to deal with the level of worm and virus infections facing it in the wild. Now, with trojans being a bigger concern, they bring in a person who helped write and implement a pretty decent MAC implementation for general, if limited use. With luck this may be the beginning of a new era of consumer level trojan mitigation, something Apple already laid the groundwork for but has not really implemented the UI and market components for.

      Basically I disagree with you that Apple has been ignoring security and I disagree that OS X is as vulnerable to most classes of real world threats as Windows. I see this as Apple making a good hire that fits with their current security strategies, assuming that is what they hired him for.

  7. Ha by bonch · · Score: 5, Informative

    despite public knowledge that it's rather trivial to launch exploits against the Mac.

    It's not public knowledge, and the only exploit going around recently was one you had to download in a pirated application. Nice little troll slip in the summary there.

    1. Re:Ha by broken_chaos · · Score: 3, Interesting

      Someone seems to be methodically modding down any comments that disagree with the submitter.

    2. Re:Ha by imamac · · Score: 2, Informative

      Sigh. Nevermind. I'm going crazy.

  8. Re:I am lost here . . . by DragonWriter · · Score: 4, Informative

    Pray tell the relevance of this article?

    The Bitfrost system developed for OLPC (which is, AFAIK, completely open) is a comprehensive approach to security, data reliability, theft deterrence, and centralized management of computer systems designed for what amount to massive enterprises with extremely non-technical users.

    Apple picking up the designer of that system could be seen as an indication of directions they may take in the future. Its "News for Nerds" even if its not entirely clear, obviously, how much it will turn out to be "Stuff that matters".

  9. Re:security vs. safety by DECS · · Score: 5, Insightful

    In the dictionary that ships with Mac OS X:

    Security is defined as "the state of being free from danger or threat" and Safety is similarly defined as "the condition of being protected from or unlikely to cause danger, risk, or injury."

    Security comes from the Latin securitas or securus "free from care" while safety comes from the salvitas or salvus meaning "safe."

    So if there were any real nuance of difference between being safe and being secure, then security would have the edge in meaning over "feeling safe", while safety could be said to imply actually "being safe." But the words are really interchangeable, and how you use them can suggest either.

    The real discrepancy that needs to be pointed out between the Mac and Windows is that while Microsoft has recently invested more into building a fancy security infrastructure, Mac users continue to both feel safer and to actually be safer in the sense of being free from danger or threat.

    There is clearly no immediate or impending threat to Macs, and there is little in the way of market forces or that wishful thinking pundit invention of "hacker pride" that will result in something to turn Macs into the disaster that has dogged Windows since the late 90s.

    What pundits like to do is equate low risk, self-injury actions with high risk, difficult to escape from events. This is straight up misinformation mixed with fear, uncertainty and doubt. For example, nearly everyone is claiming that:

    * Downloading iLife warez that pretend to be stolen software
    * from a non-trusted source
    * assigning it privileges to install on your system
    * and then finding that you have installed a background process that does something ugly that you can trivially remove

    is the same as:

    * Trying to use Windows to browse the web and use email
    * finding that you've been automatically infected with adware and viral malware without knowing it
    * then finding that your PC is also self replicating attacks or sending spam on to other systems
    * then realizing that the design of Windows' registry makes it difficult to clean things out
    * then noticing how much of your CPU capacity is being used to protect you from all of these threats via malware and virus scanners
    * then finding out how expensive it is to spend hours cleaning up the mess yourself, or alternatively paying some Nerd Patrol $300 to "diagnose" that your PC is hosed.

    They are not the same, and only a liar would keep suggesting that Mac and Windows users face the same dangers and threats. If you're paying attention, you'll notice that those who keep suggesting this almost always work for an Anti-Virus company working to make money off of Mac users. This shouldn't require any help in dot connection.

    Kaspersky Sells Mac AntiVirus Fear Using Charlie Miller... Mac AntiVirus Foe

  10. Re:I am lost here . . . by orospakr · · Score: 3, Interesting

    How can threats from untrusted code (or vulnerabilities in trusted code) be able to exploit a JTAG header on the board of the device?

    Unless, of course, you think that the owner of the device is somehow a "security threat"? I keep meeting people who think this, and I really don't understand it at all...

    (actually, Krstic's Bitfrost system is *does* implement some local physical security, but that is to address a very specific threat: theft)

  11. That argument was bullshit two years ago by SuperKendall · · Score: 2, Funny

    The malware industry has barriers to entry just like anything else, until we can make $x it's not worth any investment. OSX user base isn't big enough to generate $x yet.

    Price out botnets of a few hundred thousand nodes. Now figure there are 20-30 macs around, which are to some degree homogenous systems and thus in theory easier to target.

    Your argument goes straight to hell. When the number of intel macs in peoples homes crossed about five million, the "user base" argument went straight to hell from both a technical and financial sense.

    So how come no attacks to speak of? My vote is that the Russian Mafia all use macs, and they don't want to foul their own nest. :-)

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  12. industry amnesia by Gary+W.+Longsine · · Score: 2, Insightful

    "If the marketshare argument was true then there wouldn't have been any viruses for pre-OSX Macs either. But there were; lots of them. There were also viruses for the Apple IIGS, hardly a market leader."

    These and other inconvenient truths of the malware "market" are ignored, universally, by the industry trade press, and a surprising number of "security experts". There were worms exploiting Microsoft SQL Server on web servers when Apache + any of several other db had as much or greater market share. There have been Linux malware.

    (Some of the various examples are relevant for fair comparison only within a market segment, such as the "web server" market, considered separately since these are considered "high value" targets, for their ability to spread to potentially many desktop systems, or for the data they might contain. For example, Linux had a minority share of the web server market when it first became a malware target. Perhaps this makes the case too subtle for pundits and the trade press, but it's not too subtle for the malware authors.)

    The market share argument might be a partial explanation, but it really cannot explain the entirety of the vacuum in the Mac OS X malware marketplace. It's been five years, and still no malware plague. How many versions, and how many years must pass, before the industry realizes that perhaps there is something to this Mac OS X thing?

    --
    If you mod me down, I shall become more powerful than you could possibly imagine.
  13. malware barrier to entry by Gary+W.+Longsine · · Score: 4, Insightful
    The barrier to entry most commonly cited as the largest barrier protecting the Mac, prior to the CPU transition of the Mac platform, was Apple's use of the PowerPC, which allegedly required that malware authors know PowerPC assembly language. This argument ignored:
    1. the fact that plenty of malware existed for the old "System 7" and Mac OS 8/9,
    2. the fact that anyone who knows x86 assembly can buy a book and write a perl script to convert their egg from x86 to PowerPC, then clean the rest up by hand. They've got the skills. They've got the hubris. They've clearly got the time, particularly when so much malware was authored by people just trying to demonstrate their prowess and make pranks, and
    3. the fact that with all this malware, a small fraction of cr@X0rz are actually proficient in assembly, and the eggs are used by legion skript kiddiez who do *not* know assembly, so there was plenty of PowerPC mad skilz available.

    Those people are still around, plenty of them, even though the most widely discussed malware is now part of profit seeking black market enterprises. Some of them are writing remote systems management code which puts Tivoli to shame. (e.g. Some of them are clearly bright enough to learn Objective C in a weekend, as they already know C, C++, C#, and x86 assembly) They are writing malware for Symbian, even though the statistics indicate that iPhone dominates the mobile web market. (Symbian has more browser instances on the planet, but they are not actually used by people to access the web, so you're not going to capture many passwords infecting those phones).

    In fact, it's time to really start wondering: Where's the Mac OS X malware?

    At some point we security experts must begin to consider the possibility that Mac OS X might be protected by more than it's niche market share.

    --
    If you mod me down, I shall become more powerful than you could possibly imagine.