Version: 2008

Comments on: Apple's October update fixes 20 security flaws

Here's a bushel of security updates from Apple, including a mix of Mac OS and open-source fixes. Some are specific to Apple features such as Single Sign On, Finder, and ColorSync.

Add a Comment (Log in or register) (28 Comments)
  • prev
  • 1
  • next
by joetesta70 October 9, 2008 4:15 PM PDT
LOL - Lots of fixes from Crapple and $teve Job$. I'll buy a PC from a company whose stock isn't tanking thank you very much!
Reply to this comment
by mikebrown66 October 9, 2008 9:39 PM PDT
To joetesta70 - please do buy a PC, I'd rather someone like yourself doesn't own a Mac anyways - you'd give us a bad reputation. The only problem with Apple's increase in market share lately is it's increase in market share... those PC lovers (if they can be called such a thing?) are starting to get a little paranoid. Don't worry, there will always be enough fools out there that buy their computers based only on price to keep Windoze going for many years to come.
by Mr. Dee October 9, 2008 4:35 PM PDT
This is not the Apple I know! It doesn't matter anyway, Apples bashing has drifted from the amount patches Windows gets to things like compatibility and ease of use.
Reply to this comment
by joetesta70 October 9, 2008 5:16 PM PDT
Just like McCain....trying to change the argument. Facts are Crapple has bugs and patches.
by SMB-IL October 10, 2008 8:02 AM PDT
Wow, joetesta70, way to turn that argument in your favor! "Facts" are that EVERY OS has bugs and patches, it's just that the bugs and patches on a Mac don't generally destroy the machine.
by quasimodal October 9, 2008 4:49 PM PDT
Like Microsoft doesn't have bug fixes (like the 11 security patches just announced). A majority of Apple's fixes are for open source apps.
Reply to this comment
by KRz9292 October 9, 2008 5:13 PM PDT
There is a PC company whose stock isn't tanking right now.

joetesta70 please let everyone know which one it is so we can all go out and buy the stock to offset alll the losses in the tech stockmarket .

Maybe Warren Buffet has overlooked that one for now.
Reply to this comment
by Perry_Clease October 9, 2008 6:55 PM PDT
Don't waste your time on the trolls, it is like trying to reason with a 2 year old or a drunk.
by Vegaman_Dan October 9, 2008 5:17 PM PDT
All OS's have flaws. I'm glad that Apple is addressing them publically instead of their past history of not saying anything.

Those Apple fanboys who keep insisting that it's a secure system without flaws are becoming quieter with every update release.

Welcome to the world of reality. Every OS has issues. You deal with them and move on.
Reply to this comment
by Vegaman_Dan October 9, 2008 10:16 PM PDT
I'm afraid that Penguinisto disagrees with the notion that every Operating System has flaws and has called me on it. He has accused me of lying stating that OS products have flaws. I have asked him to give evidence of an OS that does not have any flaws.

I will be curious to find this magical OS that is perfect. Perhaps there is something out there that the IT world doesn't know about yet. He could be on to something really big.

Let's give him some support folks. He is going to need it.
by NewsReader_ October 9, 2008 5:31 PM PDT
This just proves the point that MAC OS has the same type of vulnerabilities as Windows. It has had them all along, even when Apple and its users were touting it as a superior platform in terms of security. It is hard to maintain such claims when you have monthly patches for "arbitrary code execution" on a routine basis.

The biggest difference is that no one targets the vulnerabilities on the Mac.

We have seen in the past year that as Mac adoption has grown, so has the number of patches. If the adoption continues to grow, guess what, it will start to become a more tempting target for hackers. The good news for Apple is that they are shaking bugs out early and rather inconspicuously. This activity proves though that they have security flaws just like every other OS.
Reply to this comment
by UITD October 9, 2008 6:08 PM PDT
Wait a minute. I thought Apple computers werent affected by security issues. I thought they were immune. Geez..... more BS in this world I supposed.
Reply to this comment
by howyoudoin956 October 9, 2008 7:15 PM PDT
Gotta love people who think that apple releasing security updates is new. Apple released security updates as far back as 10.3 (can't remember as far back as 10.2). People just love picking on apple fans as much as cubs fans (but I agree picking on cubs fans). Until I start seeing spyware and viruses for the mac I will continue to use that as a advantage regardless of why they don't have any.
Reply to this comment
by compudoc318 October 10, 2008 9:11 AM PDT
and hopefully you'll start seeing games, software choice, lower prices, and business uses.....lol.
by Mr. Dee October 9, 2008 8:34 PM PDT
@ KRz9292:

'There is a PC company whose stock isn't tanking right now.'
Who is it, because it sure ain't Apple?
Reply to this comment
by Penguinisto October 9, 2008 8:59 PM PDT
Corrections are in order:

* Adding trusted certs does not constitute patching a "security flaw".

* 8 of the listed flaws only affect server-type services (Apache, Tomcat, PHP, ClamAV...) - so when do we start lumping in Windows Server and IIS patches as "Windows flaws" with MSFT's Patch Tuesday?

* One of them requires the user to manually set a service buried deep in the system (Rlogin).

* One of them requires opening a maliciously crafted file by using a command-line tool (vim).

That chops down the number of flaws that would affect the typical Mac user to... eight. Not so sensationalistic anymore, is it?

@Vegaman_Dan: You're lying. Every OS has flaws. Question is, how easy is it to exploit them?

Let's find out: Judging by the eight actually usable vulns left over, three of those absolutely require local privileges - fat chance there if you're looking to build a botnet. Three of them require the user to download and open a maliciously-crafted file - not very likely given that these files in question are pretty oddball and would raise alarms. This leaves two vulns left - both of which require the victim to go to a rigged website... good luck with that, Chief.

Meanwhile, I hear that Windows-based botnets are on the rise again... ;)

/P
Reply to this comment
by Vegaman_Dan October 9, 2008 10:13 PM PDT
Penguinisto wrote:

"@Vegaman_Dan: You're lying. Every OS has flaws. Question is, how easy is it to exploit them?"

Alright, if you want to call me on that and say that I'm lying, then please ist any and all operating systems that are completely flawless. I'll be curious to see your answer. If you are going to make accusations that I'm lying, then you should be able to back it up with evidence. Please do so now. We need either evidence of a perfect operating system... or an apology. I'm afraid you really didn't leave yourself much wiggle room there. It's your honor on the line now. Do you bring forth your evidence, or do you back down and be mature about it? I think the readers don't even have to wait for your answer to know how that will turn out.

So, out of curiousity, how is that new job of yours turning out? You know, the one that you were bragging as the chief CIO of a new startup in data security? Just wondering... I like to keep track of the stories you tell. They are so varied and creative and rarely ever the same twice.
by Penguinisto October 10, 2008 6:35 AM PDT
1) Your demand is a non-sequitur. No serious Apple enthusiast has said that OSX (or any OS) is without flaws. How would providing a "ist[sic] of any and all operating systems that are completely flawless" prove a statement (which I wrote right up there for everyone to see) that no OS is without flaws?

2) "chief CIO"? No. Systems Architect, yes. In response to your question, we start production soon, and the contract may become permanent; I'm doing very well there, thanks much.

3) Are you okay? Dude - you may want to lie down and stay off the web for awhile.

/P
by compudoc318 October 10, 2008 9:09 AM PDT
total b.s. apple fan boys talk about thier bullet proof systems all day.........all i hear is that osx is so much better since its secure, but thats only due to market saturation, if apple was successful like microsoft, hackers would tear it to shreds just like they tear up windows.
by Vegaman_Dan October 10, 2008 11:52 AM PDT
1) There you go folks. I gave him the opportunity to back up his accusations or to apologize. I wanted to give him every opportunity to make good on his claims or back out gracefully. Instead he changed the subject. Chalk that up for typical Penguinisto behavior. At least he's consistent.

2) Not the CIO? Glad to hear that the company has a future for it. Good luck in that. Seriously. As much as we disagree on many things, I don't want you to be out of work or sufer personally. At the end of the day, I know that nothing here online is serious or important.

3) Thanks for the advice. I mostly post here to correct your comments as they are often flagrantly inaccurate, inflammatory, or simply hateful/bigoted. I ma not afraid to say that the Penguinsito has no clothes.
by Penguinisto October 10, 2008 1:25 PM PDT
@ Dan: You poor creature... any literate person reading this knows that you've blown it, big-time. Just apologize gracefully while you still have some credibility left, 'k?

@ "compudoc318": Concerning: "total b.s. apple fan boys talk about thier bullet proof systems all day"

Considering that there has yet to be any real malware released for OSX, it is easy to see why that assumption can be made. So far, OSX has been bullet-proof (notice the difference between the phrases "without security flaws" and "bullet-proof"). Here's the rub: bullet-proof vests can be eventually penetrated with a big enough bullet - problem is, the script kiddies have yet to come up with one.
by KRz9292 October 9, 2008 10:36 PM PDT
Mr Dee, since the stock markets today are down at 5 year lows it would seem most companies stocks are in the tank. Perhaps you hadn't noticed that.

Your first post would imply that you are buying a PC from a company whose stock isn't tanking.

So please tell us all what PC company's stocks aren't tanking now so we can all go out and buy the stock and a PC from it to keep it's stock soaring. Or don't you know of such a company?
Reply to this comment
by goodspeed8701 October 10, 2008 12:04 AM PDT
apple only said 20 patches and they did not include the 30 more patches as its a big secret that their customers will never know about. i was using vista without anti virus and i decide to install norton after everything is done i scaned and no virus was found only that my cookies was enabled. vista is realy great. despite all the warez sites i go to and no virus was in.

know that in the exploit contest the mac was the first to go down. wapple fanboys take note.
Reply to this comment
by AppleSuxLeo October 10, 2008 3:28 AM PDT
AAPL has lost well over 60% of it`s market cap in a month. MSFT market cap is in much better shape. Apple , which is a boutique seller of overpriced items , much like "Sharper Image" do esp. bad in a recession. Market Cap is what matters...and AAPL is getting hammered !
Apple=Sharper Image 1987 is here again for Crapple.
Reply to this comment
by anilsudh October 10, 2008 5:31 AM PDT
ABE CHUTHIA, MADHARCHOD, BENCHOD, MSFT TERE GAAND MEIN DAALU KYA. LUND FAKIR.
by ferretboy88 October 10, 2008 4:31 AM PDT
If every person had an Iphone, ipod and macbook we would all be at the coffee shop looking like complete clones. Might as well go out and buy a black turtle neck.
Reply to this comment
by AppleSuxLeo October 10, 2008 5:13 AM PDT
And some faded jeans and tennis shoes.
by 3rdalbum October 13, 2008 3:43 AM PDT
It's great that Apple are still fixing small implementation issues with their operating system, but when are they going to start actually taking security seriously by fixing the massive design flaws that have been there since the early days? Remember, it was only two months ago that Apple patched a "day-dot" root exploit that they were first notified about four years ago, and that can be performed by an ordinary person with a single terminal command.
Reply to this comment
(28 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement