Apple Hires Former OLPC Security Director
imamac writes "It seems Apple is seeking to beef up security by hiring Ivan Krstic, the one-time director of security architecture at One Laptop per Child. 'Krstic, a well-respected innovator who designed the Bitfrost security specification for the OLPC initiative, joined Cupertino this week and will work on core OS security. His hiring comes at a crucial time for a company that ties security to its marketing campaigns despite public knowledge that it's rather trivial to launch exploits against the Mac.'"
It's not public knowledge, and the only exploit going around recently was one you had to download in a pirated application. Nice little troll slip in the summary there.
Yeah I would say a citation is needed here. Zero day exploits exist - on every system - but as a Mac user since '99 and a Windows admin since I can tell you no matter the skill level of the user: Macs dont get viruses. Period. Full stop. Yes I saw the embedded trojan in iLife and the zero day sploit that got the guy a free laptop recently but as a person who has really seen a wide cross section of computers and users all the way up to Vista it is decidedly two different worlds.
Im glad Apple dropped the "100% virus free" moniker from marketing as has been pointed out it makes them a target - and good job on hiring forward thinking people in _all_ facets of the business. Now just get ZFS plugged in as the default file system and I will officially drown myself in kool-aid.
And I hate to even point this out but look at the submitters username. If you just got to /. since the mac ads came out you might want to sit back and listen for a few. Years. I know I did.
---- The real Slashdot is still here. You just have to browse at -1 to read the comments.
The malware industry has barriers to entry just like anything else, until we can make $x it's not worth any investment. OSX user base isn't big enough to generate $x yet. Even after that when x is 20% of y why not get $y for the same investment.
Microsoft & their partners also advertise bounties on exploits encouraging people to try and find them first so they can be patched, this adds to what is found considerably. I've never seen Apple pay for but have seen them deny holes that were handed to them.
I've seen OSX exploits that didn't require any more interaction from a user than those aimed at windows in farm environments; no reason something similar isn't out there on a site we've never gone to.
Firewalls and proxies exist because some of us know better than to think our OS is secure.
In the dictionary that ships with Mac OS X:
Security is defined as "the state of being free from danger or threat" and Safety is similarly defined as "the condition of being protected from or unlikely to cause danger, risk, or injury."
Security comes from the Latin securitas or securus "free from care" while safety comes from the salvitas or salvus meaning "safe."
So if there were any real nuance of difference between being safe and being secure, then security would have the edge in meaning over "feeling safe", while safety could be said to imply actually "being safe." But the words are really interchangeable, and how you use them can suggest either.
The real discrepancy that needs to be pointed out between the Mac and Windows is that while Microsoft has recently invested more into building a fancy security infrastructure, Mac users continue to both feel safer and to actually be safer in the sense of being free from danger or threat.
There is clearly no immediate or impending threat to Macs, and there is little in the way of market forces or that wishful thinking pundit invention of "hacker pride" that will result in something to turn Macs into the disaster that has dogged Windows since the late 90s.
What pundits like to do is equate low risk, self-injury actions with high risk, difficult to escape from events. This is straight up misinformation mixed with fear, uncertainty and doubt. For example, nearly everyone is claiming that:
* Downloading iLife warez that pretend to be stolen software
* from a non-trusted source
* assigning it privileges to install on your system
* and then finding that you have installed a background process that does something ugly that you can trivially remove
is the same as:
* Trying to use Windows to browse the web and use email
* finding that you've been automatically infected with adware and viral malware without knowing it
* then finding that your PC is also self replicating attacks or sending spam on to other systems
* then realizing that the design of Windows' registry makes it difficult to clean things out
* then noticing how much of your CPU capacity is being used to protect you from all of these threats via malware and virus scanners
* then finding out how expensive it is to spend hours cleaning up the mess yourself, or alternatively paying some Nerd Patrol $300 to "diagnose" that your PC is hosed.
They are not the same, and only a liar would keep suggesting that Mac and Windows users face the same dangers and threats. If you're paying attention, you'll notice that those who keep suggesting this almost always work for an Anti-Virus company working to make money off of Mac users. This shouldn't require any help in dot connection.
Kaspersky Sells Mac AntiVirus Fear Using Charlie Miller... Mac AntiVirus Foe