Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
It's only a matter of time...
Jason Miller, 2005-08-18

According to the Apple Web site, Security Update 2005-007 was released to the public on August 12, 2005. And, as with all of their recent security updates, it is available to all Apple customers free of charge. I'm sure none of you reading this article will argue with me about that being a good thing.

Comments Mode:
It's only a matter of time... 2005-08-18
Anonymous (2 replies)
Re: It's only a matter of time... 2005-08-24
Jason V. Miller (Author) (1 replies)
It's only a matter of time... 2005-08-19
Anonymous
It's only a matter of time... 2005-08-19
Ian Crew (1 replies)
Forever, in my opinion! 2005-08-29
Roger
It's only a matter of time... 2005-08-22
Anonymous (1 replies)
While you do have a good point with regards to Apple having to change its policies wrt patches, I think that you are missing a very important issue in your analysis.

First of all, not all of OS X is open source, rather, some of the more important parts are not.

Regardless of publication of the vulnerability, there will be a few people knowing about it, as you point out yourself the people who found and reported the issue know about it, and very likely there are a few blackhats out there who know about it.

This is regardless of what is open source and what is not. The difference comes after publication as you correctly point out. In case of open source software in OS X, more people can investigate and get to know the exact issue and exploit it.

The same however gives those users who use this system for some critical tasks the oppertunity to see for themselves what the problem is, if and how it affects them, and fix it if needed without depending on Apple.

I am convinced that for those who really need a high level of security and can afford to spend a bit of money on that, this is a substantially better situation then depending on the producer of the software to release a patch when they feel like it, knowing that there will be blackhats out there who already know how to exploit the vulnerability.

In other words, in case of open source software such as a substantial part of OS X, capable users are empowered to minimize the window of oppertunity )not to mention that they can judge for themselves if the window exists to begin with)

For the rest I agree with your article, Apple needs to minimize the window of oppertunity themselves.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/348/32261#32261
It's only a matter of time... 2005-08-29
Alexey Vesnin
It's only a matter of time... 2005-08-29
MeAnonymous (1 replies)
Re: It's only a matter of time... 2005-08-31
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus