, 2005-08-18
According to the Apple Web site, Security Update 2005-007 was released to the public on August 12, 2005. And, as with all of their recent security updates, it is available to all Apple customers free of charge. I'm sure none of you reading this article will argue with me about that being a good thing.
Expand all |
Post comment
It's only a matter of time...
2005-08-18
Anonymous (2 replies)
Anonymous (2 replies)

As you mention in your comment, security by obscurity is not a good thing, and I'm certainly not advocating it in my article. I'm only suggesting that Microsoft is in a more advantageous position when it comes to patching all of the vulnerabilities in their operating system than Apple is. Apple can't patch bugs on their own time line when those bugs are associated with an open source application and published on a different time-line.
"Not only does that mean that one bad guy managing to prise one bit of kit doesn't make any of the rest of it less secure, it also means that everyone can see what's going on the room all the time, and collectively can ensure that all remains intact."
While this certainly applies to open source software packages, it doesn't apply to distributions of those packages in an operating system bundle. Once someone figures out how to exploit a vulnerability in a certain application included with any given operating system distribution, it can be exploited on most systems running that distribution until the "vendor" (I use the term loosely) provides a patch for it. This is especially the case with a corporate / for-pay operating system distribution like Apple.
Thanks for you feedback on my article.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/348/32274#32274