An Ex-NSA Hacker Who Has Organized the First-Ever Mac Security Conference (vice.com)
Motherboard's Lorenzo Franceschi-Bicchierai spoke with Patrick Wardle, the ex-NSA hacker who's organizing a security conference exclusively dedicated to Macs. Despite what Apple has famously promoted in the mid 2000s that Macs don't get "PC viruses," Mac computers do in fact have bugs, vulnerabilities, and even malware targeted at them. From the report: "People are peeking behind the curtain and realizing that the facade of Mac security is not always what it's cracked to be," Wardle told Motherboard in a phone interview. "Any company that designs software is going to have issues -- but Apple has perfected the art of a flawless public facade that masks many security issues." Wardle would know. After hacking primarily Windows computers at Fort Meade, for the last few years Wardle been finding several issues in MacOS, so many that he considers himself a "thorn" on Apple's side. But his conference is not an exercise in shaming or finger pointing, Wardle said he hopes to educate and teach people about Mac security, especially now that so many companies are using Macs as their corporate computers.
The conference is called Objective By the Sea, a wordplay on Objective-See, the name of Wardle's suite of free Mac security products (which is itself a wordplay on Apple's main programming language called Objective-C.) It will be held in Maui, Hawaii on November 3 and 4. The conference will be free for residents of Hawaii, and for patrons of Objective-See. That's why Wardle said he can't afford to pay for all speakers to attend, but he had no trouble finding people who wanted to participate. One group that doesn't want to come to Maui, at least for now, is Apple. Wardle said he reached out to the company, essentially offering it carte blanche to talk about whatever it wanted. But the company, so far, has not responded, according to him.
The conference is called Objective By the Sea, a wordplay on Objective-See, the name of Wardle's suite of free Mac security products (which is itself a wordplay on Apple's main programming language called Objective-C.) It will be held in Maui, Hawaii on November 3 and 4. The conference will be free for residents of Hawaii, and for patrons of Objective-See. That's why Wardle said he can't afford to pay for all speakers to attend, but he had no trouble finding people who wanted to participate. One group that doesn't want to come to Maui, at least for now, is Apple. Wardle said he reached out to the company, essentially offering it carte blanche to talk about whatever it wanted. But the company, so far, has not responded, according to him.
...and you can basically use the same "god mode" hack as with any other "Pc".
Check this video out for details, but..ahem, use responsibly: https://www.youtube.com/watch?...
What this world is coming to - is for you and me to decide.
Not enough people use MacOS on the desktop or the enterprise for this to pick up any traction in the common conversation or mindset.
Maybe try the same approach with iOS or Android to be more productive and effective on this front
Just for the record, a complete Objective-C toolchain was an installable package with Slackware 95, one of the Slackware distros of the Linux 1.x era. Objective C existed long before Steve Job's NeXT bought Apple.
...
It's a nice shinier proprietary desktop for unix-alike fans. Better than KDE was back before it became fully open source*, but encouraging the same sort of nerds to use it.
(*early linux-era KDE was dual licensed- if you wanted to sell binaries you could pay for that license)
That hasn’t been Apple’s “main programming language” for some time now.
#DeleteChrome
Specifics would make your case a lot more than blathered antics about companies that may or may not exist, anonymously. I'm not going to argue Apple has good or even decent security, but you've demonstrated zero actual knowledge of any significant vulns / common pitfalls / security suggestions, just kind of bland toothless gripes. Of course there are gaping holes. Of course every OS has LONG KNOWN gaping holes with exceptions I can count on one hand. The point isn't n-th degree security, it's base level security for joe-asshole, the guy who shuts down by turning off the power strip. Comparing Apple to its OS-behemoth competitor Windows 10, Apple comes out way, way ahead in terms of a series of concerns for end users. Sure anyone can take an "Enterprise" version and wrap it in custom packages and lock it down, FOR MILLIONS OF DOLLARS, but Apple can get joe-asshole online with a modicum of effort and unless he goes looking for trouble in Warez or torrentz, chances are he's going to have zero real-world problems. Not so for jane-asshole, on her windows 10 box that can't even figure out how to display the start bar without an internet connection to fetch you an online (unsecured) ad from the local ad network, open by default. It's not close, go fuck yourself.
Obviously if you want total security, you need educated users who want total security. So you're pissing on the wrong lemon tree to begin with, fake-analytica.
... hosts file "Protects against Spectre & Meltdown" ? Care to explain that one?
Apple bought NeXT, not the other way around.
Objective-C was NeXTStep's primary supported language, and NeXT is the one who implemented the compiler in gcc to begin with (in the late 80's) which is why it was in Slackware in 1995.
My Other Computer Is A Data General Nova III.
At work we're expanding our support for Mac in our vulnerability scanner, over the next month or two. (Last month I wrote a bunch of code to find more Cisco vulnerabilities.)
We have out usual sources of vulnerability data, but does anyone happen to know any the are particularly good for Mac specifically? We aim to cover every CVE ever issued.
Coming from using Linux exclusively for 15 years, I was skeptical of the Mac sitting on my desk at my new job a few years ago. It turns out Mac isn't just Unix-like, it's actual certified real UNIX (tm). It's more UNIX than Linux or FreeBSD are.
Comment removed based on user account deletion
Comment removed based on user account deletion
Someone spoke to hacker who organized...
Could someone shoot that hanging title?
ID: the nose did not occur naturally, how would we wear glasses otherwise? (apologies to Voltaire)
You have to enter your serial number.
Admit it, you obviously think they're cute...
Thanks. I'll look that over and maybe use some of the stuff their to make a presentation for my team.
The job I really want is to be *teaching* security programmers while making very good money doing it. Nobody has that job advertised, so I'm creating it by doing weekly or twicd-weekly presentations for my time, with other people from the company also invited. Eventually people will figure out that whenever you need your security programmers trained in something, Ray does that well. :)
Ray Morris decided to double down on a known KKK lie after it had been debunked, he's a nazi faggot. https://tech.slashdot.org/comments.pl?sid=12520486&cid=57184660
See subject: his FAKEname on a post impersonating me https://linux.slashdot.org/com... & altering /.er's words.
So I challenge c6gunner to show he did better work than mine & he CAN'T!
c6gunner tried to mock me 1st https://linux.slashdot.org/com...
YOU DEMAND PROOF? "I've yet to see you provide any evidence of that." by c6gunner on Monday March 15, 2010 @10:02PM (#31490942) ?
I DEMAND IT OF YOU & YOU FAIL!
* c6gunner = "Run, Forrest: RUN!!!
c6gunner's LYING say I did a MacOS X one - I haven't yet & c6gunner's LYING impersonating me hosts work vs. Intel CPU issues (spectre/meltdown).
APK
P.S.=> You say hosts = shit here https://slashdot.org/comments.... ? /.ers & security pros SAY DIFFERENT: /.ers https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments....
SECURITY PROS https://slashdot.org/comments....
REAL RESULTS w/ hosts vs. threats https://slashdot.org/comments....
EAT YOUR WORDS
See subject: his FAKEname on a post impersonating me https://linux.slashdot.org/com... & altering /.er's words.
So I challenge c6gunner to show he did better work than mine & he CAN'T!
c6gunner tried to mock me 1st https://linux.slashdot.org/com...
YOU DEMAND PROOF? "I've yet to see you provide any evidence of that." by c6gunner on Monday March 15, 2010 @10:02PM (#31490942) ?
I DEMAND IT OF YOU & YOU FAIL!
* c6gunner = "Run, Forrest: RUN!!!
c6gunner's LYING say I did a MacOS X one - I haven't yet & c6gunner's LYING impersonating me hosts work vs. Intel CPU issues (spectre/meltdown).
APK
P.S.=> You say hosts = shit here https://slashdot.org/comments.... ? /.ers & security pros SAY DIFFERENT: /.ers https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments.... https://slashdot.org/comments....
SECURITY PROS https://slashdot.org/comments....
REAL RESULTS w/ hosts vs. threats https://slashdot.org/comments....
EAT YOUR WORDS
Seriously, does nobody care what BeauHD publishes on slashdot?