The Register® — Biting the hand that feeds IT

Feeds

Apple plugs 25 security holes

Patch despatch

  • print
  • alert

Brief Apple today fixed 25 vulnerabilities in the Mac OS X 10.4.9 operating system, courtesy of a 16MB patch for download. Apple's list of vulns is long and far too tedious for us to rewrite, so check out the company's security update for yourself and get patching. ®

Latest Comments

Time is coming?

It comes down to the principle of popularity. Today, many viruses are written for commerical reasons (e.g. install spyware without a user downloading freebie muck), to spread a message (hidden text in the viral code - popular virus gets headlines thus message of purpose is often exposed) or just as part of a botnet to do DOS/DDOS attacks.

To do these, you need a lot of computers to run your virus - thus targeted toward Windows.

Yes, there's a huge amount of security holes in Windows, and even more viruses out there to exploit them.

But taking a snapshot of El Reg home page right now shows JavaScript security issues, 25 Mac security holes (my interpretation) and OpenOffice password protection being cracked.

There's also the recent news of security issues in Firefox. (Yes, as well as IE, but the volume of security issues in Firefox whilst being peer reviewed isn't a good thing - thus headlines)

These aren't insecure products, infact I use them on a daily basis (including Linux servers and a couple of Mac clients) - but the trend seems to be that more OSS and non-MS products are coming into the spotlight with their security flaws.

I don't believe this is because people are necessarly finding more security holes in these products (although possible), but probably because people care about them more as their use is more widespread. (With more Mac's being sold, Linux on desktops, OpenOffice on those machines, Firefox also on them along with Windows) As people care about them more as end-users and IT Pro's uptake is higher, then the headlines reflect this.

Seems a little bit like the Windows fanboys who were spouting about "Windows only seems more insecure as nearly everybody uses it" maybe more accurate that first thought.

0
0

Spyware

"the absolute falsehood of 'security through obscurity', I will snap like a twig."

Well virii, bots, hackers and things definately make "security through obscurity" pretty worthless. But you said spyware :)

Spyware and adware are market, business driven - they're made by advertising companies, and are usually even installed by the user - usually after the user agrees to it in a license! They rarely even really take advantage of security holes and bugs so patching and updating doesn't really effect spyware and adware.

In fact, it's actually really easy to deploy spyware and adware to Linux and - though I haven't looked into it specifically - probaby Mac. You just need stupid users to install "free programs!!!!!!".

It just wouldn't make any $$$ though so to a spyware, adware company it's quite worthless. Hence no spyware on Linux or Mac even though it is soooooooo easy.

As for virii - which mind you is an entirely different matter - I'm actually quite shocked that Macintosh and Linux and the like don't have more. Everyone going around bragging about the unbreakability is essentially begging for attacks, it's like a challenge. All we get though are "proof of concept" lab developed benign trojans that hardly even qualify as malicious.

So feel free to be proud of Unix security, just don't throw around spyware as an example. The #1 security hole that lets spyware in lies between the chair and keyboard.

0
0

There is a difference Martin

I use a Mac and a PC. I have an XP machine that I've used for the past 4 years on a PIII 667Mhz processor no less with 384megs of RAM. It's a steaming pile of s#!+. I know this but I accept it and the Microsoft centric things that I need to do I do without issue. I can't expect filet mignon when I'm at McDonald's. I accept that it's crap.

I use a Powerbook for everything else I do. It's not a toy it's is the best machine I have ever had. If you spent any time on a Mac you would see that it's a highly powerful UNIX workstation, that has a glorious and functional eye candy GUI to boot. Now that Mac's run Intel I will be purchasing a MacBook Pro and do everything from one box.

You are right every system has it's flaws Microsoft just has exponentially more of them.

Script kiddies only on Windows? That just shows your ignorance.

I've run into more *nix script kiddies than anything.

Speaking of UNIX Bill Joy the inventor of vi and founding architect of BSD and James Gosling the creator of Java have on their desktop? Not Microsoft crap!

I don't mind spending a little extra for a Mac because it is a very polished product!

Windows including Vista has the feel of an abandoned, unfinished open source project. Aero does nothing functionally to make using your PC easier other than just giving you something cool to look at.

Mac's are the best! There is a lot to be smug about.

0
0

Bollocks.

Well, I can tell you this. My grandfather has an eMac, and he has for the past 4 or 5 years. He downloads and dbl clicks EVERYTHING, unquestioningly. And his eMac is still problem free. Try it with a windows machine. End of story.

0
0

News Flash!

Virii is stull not a word. Let's recap. Singular: stimulus, plural: stimuli, drop the 'us' add an 'i'. Virii could not be a word unless the root word was Virius, at best, it'd be viri, but it's viruses. Thank you.

0
0

More from The Register

Android is a mess and needs sprucing up, admits chief
Can Google really fix it? It isn't in control any more
New Lumia 925: This, loyalists, is the BIG ONE you've waited for
Nokia veep drills high-end master plan for El Reg
Android device? Ooohhhh, you mean a Samsung phone
Koreans nabbed nearly all the Q1 profits – more even than Google
Review: HP Pavilion 14 Chromebook
All roads lead to Chrome?
Borked your iDevice? Pay EVEN MORE to have it fixed by Applecare
Or scream at their hapless techies on their forums
Euro PC shipments plummet into bottomless pit of DOOOOM
11th quarter of decline, 20pc drop on last year - Gartner
Report: AT&T dropping Facebook phone after dismal sales
Turns out folks won't buy that for a dollar