Focus on Apple
Re: .dmg file exploit Nov 21 2006 09:08PM
mfossi securityfocus com (2 replies)
Re: .dmg file exploit Nov 22 2006 03:05AM
Jason (security brvenik com) (1 replies)
Re: .dmg file exploit Nov 22 2006 04:04PM
Martin Roesch (roesch sourcefire com)
Re: .dmg file exploit Nov 21 2006 09:49PM
Roland Dobbins (rdobbins cisco com) (2 replies)
DNSSEC validation Sep 24 2008 07:20PM
Dave Piscitello (dave corecom com)
Re: .dmg file exploit Nov 22 2006 03:25PM
mfossi securityfocus com (1 replies)
Re: .dmg file exploit Nov 22 2006 04:04PM
Roland Dobbins (rdobbins cisco com) (1 replies)

On Nov 22, 2006, at 7:25 AM, mfossi (at) securityfocus (dot) com [email concealed] wrote:

> In that sort of case a novice user might be less likely to realize
> that something bad just happened and chalk the reboot up to a
> random occurence.

Right, I understand what you mean - I just disagree.

;>

I believe that emphasis on the Safari automount has clouded the
public discussion of this problem so far. I believe that the Safari
automount issue is completely beside the point and that conflating it
with this .dmg problem isn't helpful in terms of discussing the real
problem nor communicating the real problem to end-users. All the
press I've seen about this leaps on the Safari browser issue, and
gives the mistaken impression that if one disables the Safari 'mount
safe images' feature, everything's dandy, when we all know it isn't.

Disabling Safari's automount feature does not even marginally improve
the security of any Mac user. Instead, doing what one can to verify
the provenance and evaluating the risks associated with mounting any
given .dmg (admittedly, there's little that folks can do in this
regard, but it actually has more real security value than disabling
Safari automount) are the best defenses we have until Apple can fix
this problem.

-----------------------------------------------------------------------
Roland Dobbins <rdobbins (at) cisco (dot) com [email concealed]> // 408.527.6376 voice

All battles are perpetual.

-- Milton Friedman

[ reply ]
Re: .dmg file exploit Nov 22 2006 06:02PM
Martin Roesch (roesch sourcefire com) (3 replies)
Re: .dmg file exploit Nov 22 2006 11:25PM
Eric Hall (securityfocus darkart com)
Re: .dmg file exploit Nov 22 2006 06:40PM
Jeramey Valley (ValleyJR mps k12 mi us) (1 replies)
Re: .dmg file exploit Nov 22 2006 08:23PM
Martin Roesch (roesch sourcefire com) (1 replies)
Re: .dmg file exploit Nov 22 2006 10:44PM
stephen joseph butler (stephen butler gmail com)
Re: .dmg file exploit Nov 22 2006 06:37PM
Roland Dobbins (rdobbins cisco com) (1 replies)
Re: .dmg file exploit Nov 22 2006 08:29PM
Martin Roesch (roesch sourcefire com) (2 replies)
Re: .dmg file exploit Nov 23 2006 04:12AM
K F \(lists\) (kf_lists digitalmunition com)
Re: .dmg file exploit Nov 22 2006 08:45PM
Roland Dobbins (rdobbins cisco com) (1 replies)
Re: .dmg file exploit Nov 23 2006 10:15AM
Simon Slavin (s slavin lancaster ac uk) (1 replies)
Re: .dmg file exploit Nov 23 2006 07:53PM
K F \(lists\) (kf_lists digitalmunition com) (1 replies)
Re: .dmg file exploit Nov 23 2006 09:30PM
Howard Oakley (h oakley btconnect com) (1 replies)
Re: .dmg file exploit Nov 24 2006 03:12AM
K F (lists) (kf_lists digitalmunition com) (1 replies)
Re: .dmg file exploit Nov 24 2006 03:05PM
Simon Slavin (s slavin lancaster ac uk) (1 replies)
Re: .dmg file exploit Nov 24 2006 03:51PM
David Maynor (dmaynor gmail com) (1 replies)
Re: .dmg file exploit Nov 24 2006 03:56PM
Simon Slavin (s slavin lancaster ac uk)


 

Privacy Statement
Copyright 2010, SecurityFocus