Welcome | Sign In
TechNewsWorld.com
Security Updates

Apple Gives Leopard a Good Brushing

Print Version
E-Mail Article
Reprints
Apple Gives Leopard a Good Brushing

Apple's release of a major update for its Leopard operating system has further deflated the claims of some fans that Macs are intrinsically superior in the security department. There's a cup-half-full argument to be made, though: It's because more consumers are using Mac systems that the OS is attracting more attention from hackers.


Think you have to compromise on security to save on costs? Think Again. Trend Micro™ Enterprise Security, powered by the Trend Micro Smart Protection Network™, can lower your content security management costs by up to 40%. Find out just how much you’ll save with our TCO Impact Calculator.

Apple (Nasdaq: AAPL) has completed a major security overhaul of its Leopard operating system. The fix addresses more than 40 crucial security flaws, including one in iCal that allows hackers to attack the computer remotely.

Other flaws that either result in application terminations or arbitrary code executions have been found in AFP Server, AirPort, AppKit, Apple Pixlet Video, ATS, CoreGraphics, Help Viewer, Core Foundation, Flash Player Plug-in, iChat, Mail, Automator, Time Machine, VoiceOver and Parental Controls.

Security Update 2008-003 also has a non-security function: It enables iPhone users to sync Mac address book contacts with Google (Nasdaq: GOOG) contacts.

Repairing iCal

Plugging the iCal hole was the most immediate need Apple had to address. Last week -- after reportedly trying for months to work with Apple to coordinate disclosure -- Core Security published three Mac OS X iCal-based vulnerabilities: Two of them could crash the iCal program, but the third could allow a hacker to take control of another person's computer.

iCal uses the .ics extension and the CalDAV protocol for calendar-sharing. iCal-using Mac owners may be exposed to possible exploits, as a growing number of Web sites provide calendar files and subscriptions to calendar updates.

Besides the iCal flaw, the patch addresses collaborative functions that could be used as vectors for attack. For instance, Web-based plug-ins such as Adobe (Nasdaq: ADBE) Flash have become attractive to hackers, Ryan Barnett, director of application security at Breach Security, told MacNewsWorld.

"There have been many recent reports of malicious Flash files being hosted on Web sites that aim to exploit known vulnerabilities to install Trojan software on client computers," he said.

In general, the patch does a good job of addressing the critical problems, Lori MacVittie, technical marketing Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales manager at F5 Networks, told MacNewsWorld.

"This is becoming more important as growing levels of malware are being written for the Mac," she noted.

Attackers are getting smarter and are using ubiquitous technology such as Flash, MacVittie added. That trend is exacerbated by the typical Mac user's misguided sense of invincibility against hack attacks.

Aura of Safety

Indeed, as more consumers embrace Macs and as more hackers target OS X, the reputation of Apple's computing product line will continue to take hits. This is not necessarily a bad thing -- at least not for consumers that may naively believe their Macs are safe to use online without any protection, Ken Dunham, director of global response at iSIGHT Partners, told MacNewsWorld.

"Apple computers are traditionally viewed as less vulnerable to malicious code attacks," he observed, but "this is true or false depending upon the context of your statement."

Software on any platform is likely to contain a certain number of errors or vulnerabilities, he explained. "As a result, [the statement that a Mac is more vulnerable] is true [given] that continued development of Macintosh software has led to the development and discovery of new vulnerabilities that open the door for possible malicious actions. However, [it] can also be viewed as largely false when considering malicious code which is not mature within the Macintosh 10.x operating system."

No operating system is completely invulnerable to attack -- including Macintosh -- which means consumers must practice safe computing and harden their computers' configurations against known vulnerabilities, Dunham continued.

"Hackers today are financially motivated -- largely focused upon Windows and other platforms," he noted. "However, for Macintosh, increased capabilities and some exploitation in the wild have taken place in the past 18 months. Still, these cases are very limited in scope and impact when compared to other known attacks in the wild on other operating systems.

"It's possible as Apple gains market share, [OS X] will be increasingly targeted by hackers due to the increased number of potential targets using Macs," Dunham concluded.


Print Version E-Mail Article Reprints More by Erika Morphy


Talkback: Join the Discussion.
Erika, your thesis is illogical...
asdfasdfadsf
Posted 2008-05-30
This is precisely why girls should not be allowed to discuss technical topics- complete and ...
reputation
jdawgnoonan
Posted 2008-05-30
Their reputation has not been tarnished at all. There still has never been a true virus in the ...

More by Erika Morphy

Ballmer Gives Shareholders - and Dell - Cause for Optimism
November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning
November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Salesforce.com Pumps Up Volume of Workplace Chatter
November 19, 2009
Salesforce.com has developed a collaboration platform that puts social networking to work. Salesforce Chatter facilitates employee collaboration on projects through Facebook-like profiles, status updates, feeds and groups. The question remains whether employees will be as open to social networking in the workplace as they are in their personal lives.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network