Feeds

Security site knocks spots off Mac OS X Leopard firewall

Even when you turn it on it's no good

Choosing a cloud hosting partner with confidence

It's been a rocky week for security-conscious Mac fans. A rare appearance of a Trojan targeting Mac fans made it out onto the net and the release of Apple's much vaunted Leopard operating system was marred by security concerns about its firewall.

Reports of Leopard installs hanging at boot, behaviour compared by some to the Blue Screen of Death of Windows notoriety, didn't help either. An unsupported add-on extension for a Logitech mouse drive has emerged as the main suspect behind that stability issue.

Much has been made of the Trojan, dubbed RSPlug-A, after it was found on several porn websites. To get infected, users have to give explicit permission for the malware, which poses as a codec, to run. The firewall issue, by contrast, affects all users upgrading to Leopard - not just those hunting for free skin flicks.

Users upgrading to Leopard found the built-in firewall deactivated when they upgraded from Tiger, the previous version of Mac OS X. This removes an important defence against hacker attacks and a removes a way to prevent Mac computers infected by a worm from spreading infection. Admittedly, this is a unlikely risk, but the failing of the firewall is a surprise, given that improved security was an Apple design goal for Leopard.

A review by Heise Security found issues with the firewall run deeper than simply been turned off by default. Even after activation the technology has a number of shortcomings.

Setting a poor example

Heise notes that, in contrast to the Windows firewall, the Leopard firewall does not include a setting to allow a distinction to be made between trusted corporate networks and riskier environments, such as Wi-Fi hotspots.

If a user selected "Block all incoming connections" the firewall reportedly blocks most ports and services, but not all. Potential hackers might be able to communicate with system services such as a time server and (possibly and more seriously) with the NetBIOS name server, according to Heise. Adding to the problems, Leopard bundles older versions of three-party open source tools known to contain security bugs.

Heise's overall verdict is damning. "The Mac OS X Leopard firewall failed every test. It is not activated by default and, even when activated, it does not behave as expected. Network connections to non-authorised services can still be established and even under the most restrictive setting, 'Block all incoming connections', it allows access to system services from the internet," it concludes

"Apple is showing here a casual attitude with regard to security questions which strongly recalls that of Microsoft four years ago," it adds.

Ouch.

Other researchers have criticised Leopard's firewall, albeit to a lesser extent than Heise. Security blogger Rich Mogull reckons the firewall is a mess but he takes issue with a key Heise finding. He agrees that with "stealth mode" enabled on the firewall services show up in port scans. Crucially, however, they can’t actually be used.

In fairness it's worth pointing out that Leopard's firewall in less than a week old. Glitches and security bugs accompany every major operating system upgrade, not just those from Apple.

Windows Firewall was long present in XP, but never activated by default until Service Pack 2, after the Sasser and Nimda worm outbreaks had concentrated minds at Redmond.

Let's hope it won't take a similar such incident to spur Apple into action. ®

Beginner's guide to SSL certificates

More from The Register

next story
Xperia Z3: Crikey, Sony – ANOTHER flagship phondleslab?
The Fourth Amendment... and it IS better
Don't wait for that big iPad, order a NEXUS 9 instead, industry little bird says
Google said to debut next big slab, Android L ahead of Apple event
Microsoft to enter the STRUGGLE of the HUMAN WRIST
It's not just a thumb war, it's total digit war
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Netscape Navigator - the browser that started it all - turns 20
It was 20 years ago today, Marc Andreeesen taught the band to play
A drone of one's own: Reg buyers' guide for UAV fanciers
Hardware: Check. Software: Huh? Licence: Licence...?
The Apple launch AS IT HAPPENED: Totally SERIOUS coverage, not for haters
Fandroids, Windows Phone fringe-oids – you wouldn't understand
Apple SILENCES Bose, YANKS headphones from stores
The, er, Beats go on after noise-cancelling spat
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.