Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
It's only a matter of time...
Jason Miller, 2005-08-18

According to the Apple Web site, Security Update 2005-007 was released to the public on August 12, 2005. And, as with all of their recent security updates, it is available to all Apple customers free of charge. I'm sure none of you reading this article will argue with me about that being a good thing.

Comments Mode:
It's only a matter of time... 2005-08-18
Anonymous (2 replies)
Re: It's only a matter of time... 2005-08-24
Jason V. Miller (Author) (1 replies)
Security through obscurity is not security at all 2005-08-19
Doogie (1 replies)
Re: Security through obscurity is not security at all 2005-08-24
Jason V. Miller (Author)
"The central point of this article appears to be that security through obscurity - MS closed source development model - is better than the underlying force for more secure code, combined with the pressure for fast fixes, created by an open source development."

As you mention in your comment, security by obscurity is not a good thing, and I'm certainly not advocating it in my article. I'm only suggesting that Microsoft is in a more advantageous position when it comes to patching all of the vulnerabilities in their operating system than Apple is. Apple can't patch bugs on their own time line when those bugs are associated with an open source application and published on a different time-line.

"Not only does that mean that one bad guy managing to prise one bit of kit doesn't make any of the rest of it less secure, it also means that everyone can see what's going on the room all the time, and collectively can ensure that all remains intact."

While this certainly applies to open source software packages, it doesn't apply to distributions of those packages in an operating system bundle. Once someone figures out how to exploit a vulnerability in a certain application included with any given operating system distribution, it can be exploited on most systems running that distribution until the "vendor" (I use the term loosely) provides a patch for it. This is especially the case with a corporate / for-pay operating system distribution like Apple.

Thanks for you feedback on my article.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/348/32274#32274
It's only a matter of time... 2005-08-19
Anonymous
It's only a matter of time... 2005-08-19
Ian Crew (1 replies)
Forever, in my opinion! 2005-08-29
Roger
It's only a matter of time... 2005-08-22
Anonymous (1 replies)
It's only a matter of time... 2005-08-29
Alexey Vesnin
It's only a matter of time... 2005-08-29
MeAnonymous (1 replies)
Re: It's only a matter of time... 2005-08-31
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus