Most Popular Stories
- Chrome 17's new features enhance speed, security
- 3 ways for CIOs to become business leaders
- Bug in Trendnet webcams exposes them to public viewing
- Spotlight: Intel launches 520 Series solid-state drive
- Apple's iPad 3 will be unveiled first week of March, says report
- FBI insists cloud providers meet strict security requirements
Events
- Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA - CIO Summit
March 18- 21 — Miami, FL - Customer Engagement Technology World
March 28-29, 2012 — San Francisco - CIO Healthcare Summit
March 11-14 — Scottsdale, AZ
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
- Security Intelligence: Changing the Way You See Your SAP Landscape
- Durable Smart Devices for Mobile Field Forces: Selection and Evaluation Criteria
- Business Intelligence: It's All in the Data
- Results of a Survey on DevOpsTrends
Leopard security flaws emerge
Apple may have just sold a record 2 million copies of its latest OS over the weekend but that doesn't mean that all is well in the land of iPods and magical elves. Just about the same time that you started digging into the latest from Cupertino, so did the security analysts and what they've turned up is a tad disconcerting.
According to Jürgen Schmidt, editor in chief at Heise Security, Leopard's firewall is a little less than totally secure. If the firewall is enabled (it's turned off by default) and set to "block all incoming connections," certain system services are still allowed access to the Internet. That's a bit misleading, though its hard to say whether or not it's really a security "flaw" per se.
Meanwhile, Thomas Ptacek of Matasano Security found that two of Leopard's security features--sandboxing and library randomization--were not quite as robust as he was led to believe. While sandboxing--placing specific applications in individual, secure environments to avoid a contaminated application from infecting the entire operating system--can be effective in certain scenarios, Ptacek found that the most commonly targeted applications like Safari, iChat and Mail, were not run in a sandbox. Furthermore, he felt that the sandboxes were not quite as walled off as they should be. With regards to library randomization--which was designed to protect the user from system library exploits like buffer overflows--Apple again failed to implement the feature in all of the places where it's needed, like in the Dynamic Link Library.
While worthy of concern, all of these security flaws are somewhat minor points and won't be seen as critical vulnerabilities until they are exploited. The real test for Apple, however, is in how they deal with these flaws. If they're really intent on proving that they're different from Microsoft, now is their chance.
For more on the security concerns:
- see this MacWorld article
- and this article from CNET
Related Stories
- Apple refreshes iPod Touch, adds dual camera
- Apple releases bumper security update for 58 errors
- Apple mega update fixes 21 vulnerabilities from OS X
- Apple fix more than 20 security flaws in October update
- Patched Mac Mail vulnerability returns
- AFP hack allows iPhone root access
- 250,000 unlocked iPhones in the wild
- OS X Leopard to ship on the 26th?
- Video: How to manage a to-do list on the iPod Touch
- Pre-event Apple rumor roundup
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




