|
|
![]() |
|
|
Top | #1 |
|
OSNN Veteran Addict
Joined: July 2004
Location: Montreal
Posts: 1,721
Reputation: 1040
Power: 124 |
Originally Posted by Eric Bangeman
Not a big deal, as hardly anybody uses macs.
|
|
|
|
|
|
Top | #2 |
|
Act your wage.
Joined: December 2001
Location: Texas, USA Reputation: Yes, please.
Posts: 7,626
Reputation: 2900
Power: 232 |
I can't believe that article was posted today -- the "vulnerability" has been known since shortly after OS X 10.4 was released, almost a year ago. I've never seen a report that this has been taken advantage of, either.
I hope that the market share doesn't get high enough to convince hackers that it's worth their time. I like my secure OS and want to keep it to stay that way. |
|
|
|
|
|
Top | #3 |
|
OSNN Veteran Addict
Joined: July 2004
Location: Montreal
Posts: 1,721
Reputation: 1040
Power: 124 |
Man, they are way behind then. Can you toss me a link from a year ago?
On the market share thing I'd have to agree. Some of my graphic design clients are very picky, so I outfit them with Macs and OSX and they shut up. ![]() EDIT - Does this mean they have waited a full year and still havn't patched it? TSK TSK? ? ? |
|
|
|
|
|
Top | #4 |
|
Act your wage.
Joined: December 2001
Location: Texas, USA Reputation: Yes, please.
Posts: 7,626
Reputation: 2900
Power: 232 |
Originally Posted by Mastershakes
It's not the kind of vulnerability that needs a patch -- that's why I call it a "vulnerability." In response, Apple turned the option on, by default, to prompt the user to open (mount) the download instead of it happening automatically. This was actually in the form of disabling the "open safe files" option. Additionally, most anything that writes to the system level requires an administrator password, so that layer of security exists as well. There really isn't much of a risk.
I'll dig for the initial reports of this. |
|
|
|
|
|
Top | #5 |
|
OSNN Veteran Addict
Joined: July 2004
Location: Montreal
Posts: 1,721
Reputation: 1040
Power: 124 |
Cool. Good to hear it doesn't really expose it.
|
|
|
|
|
|
Top | #6 |
|
Act your wage.
Joined: December 2001
Location: Texas, USA Reputation: Yes, please.
Posts: 7,626
Reputation: 2900
Power: 232 |
I guess if Apple really wanted to it would remove the "open safe files" option from Safari altogether.
|
|
|
|
|
|
Top | #7 |
|
Act your wage.
Joined: December 2001
Location: Texas, USA Reputation: Yes, please.
Posts: 7,626
Reputation: 2900
Power: 232 |
Here's a thread from May 2005 that relates to this exact issue. In this case it concerns widgets, but the "vulnerability" is the same.
|
|
|
|
|
|
Top | #8 |
|
Tech Junkie
Joined: April 2002
Location: New York City
Posts: 13,256
Reputation: 4260
Power: 298 |
I have the "Open Safe files after downloading" option turned off in Safari (one of the first things I did).
Camino has the option unchecked by default, by the way, which is a good move. ![]() Secunia has a test here: http://secunia.com/mac_os_x_command_...rability_test/ |
|
|
|
|
|
Top | #9 |
|
*
Joined: December 2001
Location: USA
Posts: 6,496
Reputation: 2808
Power: 220 |
It is ease of use to have stuff mounted automatically. We shall see how long it lasts before the option is A. removed, or B. worked around such that things like this can't happen.
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| IMPORTANT: WMF Vulnerability Exploited | Heeter | Windows Desktop Systems | 129 | January 27th, 2006 1:55pm |
| *Important* RPC Service vulnerability | Kr0m | Windows Desktop Systems | 17 | April 6th, 2003 4:23am |
| Vulnerability | Kr0m | Windows Desktop Systems | 16 | December 11th, 2002 10:33pm |
| Is there a fix for the xp logoff vulnerability? | Powerchordpunk | Windows Desktop Systems | 14 | March 26th, 2002 2:42am |