|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
#1 | |||
|
macrumors bot
Join Date: Apr 2001
|
Month Of Apple Bugs: January 2007
![]() Picking off where the Month of Kernel Bugs left off, security researcher "LMH" and his team is reportedly set to launch another month-long security-hole finding project, this time targeting only Apple's products. According to the Washington Post, the Month of Apple Bugs will be January 2007, where each day will feature a previously undocumented security hole in Apple's OS X operating system or in Apple applications that run on top of it. Quote:
Quote:
Update: IDG/MacWorld provides additional information. Quote:
[ Digg This ] Last edited by longofest : Dec 20, 2006 at 08:48 AM. Reason: story update |
|||
|
|
|
|
|
#2 |
|
Demi-God (Editor)
|
Guess January isn't going to be all fun and games for Apple...
|
|
|
|
|
|
#3 |
|
macrumors 65816
Join Date: Apr 2004
Location: Boise, Idaho
|
Well, as long as it improves OS X security I'm all for it.
|
|
|
|
|
|
#4 |
|
Guest
Join Date: Feb 2003
Location: Hitchin, Herts, UK
|
For 'security researcher' read 'publicity seeking idiot who doesn't really give a damn about other people's security'. If he was that concerned about improving security he'd disclose after bugs were fixed.
|
|
|
|
| caveman_uk |
| View Public Profile |
| Find More Posts by caveman_uk |
|
|
#5 |
|
macrumors regular
Join Date: Apr 2004
Location: canada
|
Good. Better he do it now while Apple is focused on his bugs and ready to release patches as soon as possible.
Is it fair to focus only on Apple bugs? Not really.
__________________
"`The first ten million years were the worst,' said Marvin, `and the second ten million, they were the worst too. The third ten million I didn't enjoy at all. After that I went into a bit of a decline.'" |
|
|
|
|
|
#6 |
|
macrumors 6502a
Join Date: Jun 2003
|
Hopefully the Jan release of Leopard will put a wrench in his gears.
|
|
|
|
|
|
#7 |
|
macrumors 6502a
|
Gets more press. If he focused on Windows bugs, he'd be one of 10k guys pointing out tens of thousands of bugs. He'll find 30 bugs (maybe) and post them one day at a time. It's more media whoring than anything else unfotunately.
__________________
My 12" PB 'sploded, just like this: KABLAM! |
|
|
|
| Some_Big_Spoon |
| View Public Profile |
| Find More Posts by Some_Big_Spoon |
|
|
#8 | |
|
Demi-God (Editor)
|
Quote:
Keep dreaming. |
|
|
|
|
|
|
#9 |
|
macrumors 68000
Join Date: Mar 2004
Location: USA! USA!
|
Does this guy really think he's doing a service? He is not. Maybe a service to criminals.
|
|
|
|
|
|
#10 | |
|
macrumors 6502a
|
Quote:
I agree that this is a blatant way of publicity seeking, but nowadays it is the only way to sell a product. And in this case it is a perfectly legal way! |
|
|
|
|
|
|
#11 |
|
macrumors 6502
Join Date: May 2006
Location: NYC
|
like many said before, if he really cared he would just send it to apple...
__________________
We must remember that the future is neither wholly ours nor wholly not ours.... So where is that bunnny??
|
|
|
|
|
|
#12 | |
|
macrumors 68040
|
Quote:
Agreed. I am still sticking by my comment (in the month of kernel bugs thread) that we need to get used to this kind of treatment from developers, crackers, hackers. I have a feeling that this kind of work will ramp up, and that more and more people will be joining this group with regards to seeking holes in OS X. My question is, if holes are found, how much is that information worth to people who want to take advantage of it? And also, if it is a moderate to high value, will this company / person take offers to share that information with people who would like to do wrong doing ? My guess is, the information has value, and I am worried that this person / group would actually sell it to a high enough bidder, regardless of why that person / group needs that info.
__________________
The iPhone is nice, but I am here for the Macrumors Neucast the European automotive podcast
|
|
|
|
|
|
|
#13 | |
|
macrumors member
Join Date: Jun 2003
Location: Palo Alto, CA
|
Quote:
About the only positive I can think of is that it will cause Apple and others to be even more rigorous about security on their own. I'm not sure this is the best way to achieve the goal, though. I think it's more about publicity. I expect the vast majority of these bugs to be yawners. |
|
|
|
|
|
|
#14 | |
|
Demi-God (Editor)
|
Quote:
However, I'm not so sure that the bugs will only be "yawners"... MoKB came out with a couple big ones... |
|
|
|
|
|
|
#15 |
|
macrumors 601
Join Date: Aug 2003
|
Publicity or advertising don't match up as motivations when the responsible party has been making some effort to remain anonymous.
|
|
|
|
|
|
#16 |
|
macrumors member
Join Date: Oct 2006
Location: Earth
|
what purpose does it serve to finds bugs in software if you aren't going to give the programers a chance to fix them? I mean good intent and all...but it makes little sense if apple won't get advanced notice to fix errors...
|
|
|
|
|
|
#17 | |
|
macrumors 68040
|
Quote:
Question: Are there any Mac users out there that actually think OS X is 'bulletproof'? Every now and then some pundit/user blurts out that OS X users think their OS is invulnerable. Nowhere have I seen this. Frankly, I feel it is spite. Compared to XP, OS X seems invulnerable. I just hope there aren't any OS X users boasting 'bulletproofness'. This my $0.02 because I'm tired of the Enderles of the world putting words in my mouth. Last edited by patrick0brien : Dec 19, 2006 at 04:57 PM. Reason: spling an grammer |
|
|
|
|
| patrick0brien |
| View Public Profile |
| Find More Posts by patrick0brien |
|
|
#18 |
|
macrumors 6502a
Join Date: Jun 2006
Location: The Kitchen
|
Mods:
If you would like, merge comments from this thread: http://forums.macrumors.com/showthread.php?t=261925 Thanks!
__________________
Les: It was almost as if they were...organized!! Mr Carlson: As God is my witness, I thought turkeys could fly. |
|
|
|
| CEAbiscuit |
| View Public Profile |
| Find More Posts by CEAbiscuit |
|
|
#19 | |
|
macrumors 68040
|
Quote:
If he wants to anonymously capitalize on his findings by selling the information to wrong doers, he is less likely to be caught.
__________________
The iPhone is nice, but I am here for the Macrumors Neucast the European automotive podcast
|
|
|
|
|
|
|
#20 |
|
macrumors 68000
|
In principal I think that it is ok to show Apple where the bugs are if any but I think the timing is more then bad. Vista is coming out end of January for the average consumer and Apple wants to beat M$ on security. A month long reporting on Apples bugs will only help selling Vista instead of Mac OS.
my 2 cents
__________________
Macbook Pro 17" 2.8 GHz ; Cinema Display 23"; iPhone 3G 16GB; TimeCapsule Final Cut Pro 2; Aperture 2 |
|
|
|
|
|
#21 | |
|
macrumors 68040
|
Quote:
In addition to my other comments made in this thread, part of me smells a disgruntled former Apple employee that is spreading information for possibly known holes in the OS and applications. I would almost think that holes in OS X are really not that big or easy to find (if they were many would have been discovered by others now), and that you would need intimate knowledge of the OS to be able to find any worth reporting. Especially 30 to 31 of them!
__________________
The iPhone is nice, but I am here for the Macrumors Neucast the European automotive podcast
|
|
|
|
|
|
|
#22 |
|
Demi-God (Moderator)
Join Date: Oct 2003
Location: I love you, food.
|
I feel it's a good thing, I just hope that it's not as sensationalized as the MoKB was. There was some definite FUD being pushed there. I look forward to what LMH brings to the table. UNFORTUNATELY for him, Leopard will likely be out sooner rather than later, and some of his MoABs will be moot at best.
|
|
|
|
|
|
#23 |
|
Demi-God (Moderator)
Join Date: Jan 2004
Location: Grand Rapids, MI, USA
|
So the Month of Kernel Bugs was only 10 days long?
Mmm, I don't approve of the methods, but I hope the long-term result is better Mac security. I find it kind of sketchy that the MoKB page lists all the exploits but doesn't have a "patched by" column like most security listings do...so I too have to say I feel like these people are more interested in showing off their skills than enhancing security. But, go ahead... I want to see how many days are in the Month of Apple Bugs.....
__________________
Mohan |
|
|
|
|
|
#24 | |
|
macrumors regular
Join Date: Oct 2004
|
Big Ones
Quote:
Apple already has channels for working with them on these things. "LMH" is just like that guy at the BlackHat convention; he's just trying to get his 15 minutes of fame. He doesn't really care about OS X security. I've personally reported bugs to Apple, and I've received polite, timely responses from them, and everything I've ever reported was fixed in the next update, and none of mine were ever very critical. |
|
|
|
|
|
|
#25 |
|
macrumors 68020
Join Date: Apr 2005
Location: Currently in Switzerland
|
Ditto. He is no better than a bunch of anonymous "hackers" out there...many of his "bugs" were already debunked by more serious people...this is just food for Windows fanboys, nothing else.
__________________
iMac 24" C2D 2.8, 4Gb, 500Gb+1.25Tb, JBL Creature II, Creative XMod, OS X 10.6.2; iBook G3 Dual-USB 500MHz, 384Mb, 15Gb, OS X 10.4.11 |
|
|
|
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|