Am I reading this wrong, or is the second exploit just a VLC exploit, and not even an Apple problem?
Am I reading this wrong, or is the second exploit just a VLC exploit, and not even an Apple problem?
Yea, it is just a VLC exploit in a OSX environment. Without the program, OSX is not affected.
If these issues are disclosed publicly, then everyone knows about the security flaw, there would be no "highest bidder". Having been around bugtraq and the like for a long while, I understand the problem with vendors not getting back with the discloser after they took the time to inform them of the bug/hole (in some cases, people told vendors repeatedly about bugs and still had not heard from them for months on end).
If two people find the same bug/exploit, and one discloses it to the public, then the information does not become as profitable to the second. It also allows Apple or whoever to take steps to squashing that bug. To think that XP has more/worse bugs than OSX is just crazy. Every OS has bugs/exploits/holes/whatever. But Windows is more often used and most likely to have its exploits found. I will be very interested to see what is found in OSX throughout January; even more interested in seeing how fast Apple reacts to them.
Agreed, however who is to say they don't keep some information to themselves, and or important details that make that information useful.
I do doubt that this is his / her intent, however I wouldn't rule it out for someone doing this type of work.
Nice to know this guy is providing a "fix" for every bug posted on MOAB. I'll just do this until I can get official updates for everything.
Especially when:#2 is a VLC exploit? How is this an Apple bug?![]()
I will reply with the exact same thing I did to someone else's statement later in this thread.
#2 is a VLC exploit? How is this an Apple bug?![]()
http://projects.info-pull.com/moab/index.htmlIt is day 7 what other bugs have there been? I thought this was supposed to raise awareness.
It is day 7 what other bugs have there been? I thought this was supposed to raise awareness.
It is day 7 what other bugs have there been? I thought this was supposed to raise awareness.
Number 7 affects OmniWeb, but apparently not Shiira or Safari, which seems odd since they're using the same JavaScript engine.
Wouldn't that make it an OmniWeb problem?
I love this. The Month of Apple bugs has pretty much fallen off the radar of all the media. Two of these "Apple Bugs" have nothing to do with Apple itself. Didn't the VLC exploit work on Windows too? The author is using the loosest definition of "Apple" bugs in existence, any bug that works on the MacOS counts.
Wouldn't that make it an OmniWeb problem?
I love this. The Month of Apple bugs has pretty much fallen off the radar of all the media. Two of these "Apple Bugs" have nothing to do with Apple itself. Didn't the VLC exploit work on Windows too? The author is using the loosest definition of "Apple" bugs in existence, any bug that works on the MacOS counts.
Either way, you can bet the media and CNet will have a field day announcing how Mac OSX isn't "quite secure as some people might think" (watch for that direct quote). I know I will have to spend at least an hour on the phone with my Dad who just bought a new 20" Imac because he was sick of virus and spyware on his 2 year old windows machine, which had replaced a 1 year old windows machine - now that is longevity![]()
Perhaps your first order of action should be to educate your dad how to use a computer?? My dad has had a WinXP machine for several years without major problems. I remind him to have uptodate virus and firewall software, and that's about it.
I was on the verge of disagreeing with you, and pointing out that on the surface it doesn't matter where the bug is, as long as it can effect an OSX machine.
However I remembered the "spirit" of the original idea, to help improve OSX security. And the only reason anyone could use to defend the blatant public nature of letting Apple know about the bugs at the same time as anyone wanting to exploit them was just that, that it was Apple.
Adobe patched Acrobat Reader 7 to version 7.0.9 so now, it's just Preview with the problem.
Have you ever seen Adobe work that fast? I haven't, and they're making Apple look sloppy.
Apple has never been really fast fixing stuff.
Considering the bugs that are already on that page I sure hope that Apple gives us a fix soon.
-Diatribe
This is the one problem I have with MoAB. They aren't giving Apple the opportunity to fix stuff.
IMHO it is disingenuousness at its most blatant, childish at least, irresponsible at best, and criminal at its worst.