Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Apple
    • Apple
    • PC Hardware

    Mac OS X Developers Watch Month of Apple Bugs

    Written by

    Daniel Drew Turner
    Published January 6, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Developers of applications for Apples Mac OS X have been watching the Month of Apple Bugs project closely, and are generally in favor of the projects goal of uncovering OS flaws.

      But they, and security companies, have questions about the MOAB groups method, which involves making their findings public immediately, instead of first alerting Apple Computer.

      The MOAB project was organized by Kevin Finisterre and a hacker who goes by the handle LMH. Their progress, and links to previous Month of Kernel Bugs and Month of Browser Bugs campaigns, can be traced on their project Web site. The stated goal of MOAB is to uncover one bug a day for the month of January 2007.

      To date, they have kept their pace, revealing two vulnerabilities in Apples QuickTime media layer, one in iPhoto and another in a third-party application, the VLC media player. One of the QuickTime bugs was shown to leave open the possibility of an attacker executing code on a victims computer.

      Landon Fuller, a programmer unaffiliated with Finisterre and LMH, is coordinating or creating fixes to the vulnerabilities found by MOAB and making them available on his own site.

      “In the long term, this project is making OS X more secure,” said Gus Mueller, a developer who sells his software through his company Flying Meat. “However, in the short term, these bugs, once shown, can be used destructively,” he added.

      “I think the correct way to handle the exploits would have been to inform Apple, and give them something like four to six weeks to get a fix out,” Mueller said, noting that this has been the standard method of OS bug reporting. “If nothing comes out of Apple at that point, then Id publish the exploit. This way earns you credibility and respect,” he said.

      /zimages/1/28571.gifClick here to read about the monthlong hunt for kernel bugs launched last November.

      “Usually, and the way it seems you should do it,” said Mueller,” is that you should let the softwares owner know when you have discovered a bug.”

      Wil Shipley, the CEO of Delicious Monster Software, said he agreed that there is a greater good in reporting OS bugs. “First off, Ill say, as Apple does, that finding bugs in Mac OS X is really good for all of us—Apple, third-party developers, Mac users—and so, you know, bully for those guys,” he said.

      But Shipley said he also questions how the MOAB project is going about its goals.

      “The only unsavory bit in all this is that originally, when I read about MOAB, it was positioned as a response to Apple being smug about security, which is childish and inane,” said Shipley.

      “Apple has a right to be smug about an area in which they are better then their competition, even if they are not totally perfect.”

      Next Page: In search of “show-stoppers.”

      Hunting the Doozies

      Brent Simmons, the owner of Ranchero Software, said that he once uncovered a bug that “turned out to be a security risk.” He reported it to Apple first and was later even credited when the company released an update that fixed the bug.

      Security companies say that this is their procedure.

      “The computer security industry came up with the term responsible disclosure,” said Fred Doyle, the director of iDefense Labs, to denote the process of reporting bugs to software manufacturers.

      “This is much different from the MOAB process,” he said. “We give notice to the vendor and give them a responsible amount of time before going public.”

      Doyle noted that they will go public with a security issue if a vendor is unresponsive. “However,” he said, “this has not been the case with Apple.”

      “From our perspective,” he said, “theyre missing an important step.”

      Dave Marcus, security research and communications manager for McAfee Avert Labs, concurred.

      The timing of releasing information on a security vulnerability is “an area of contention for most security companies,” he said. But, he added, “While all security vendors think patching vulnerabilities is a good idea, disclosing them in this manner puts users at risk, and thats never a good process.”

      Still, Mueller said, the bug tracking is a vital service. “The QuickTime bug in my eyes is a doozy,” he said.

      “I took the work they did to expose the bug, and then made my own version of it where if you visited a particular Web page in Safari, it would download an application and run it automatically,” Mueller said. He has posted a sample of this on his blog.

      /zimages/1/28571.gifTo read about the strange twists and turns in the search for security flaws in Apple Wi-Fi drivers, click here.

      “Thats real bad. Granted, there have to be a number of things that are just right for it to happen, but the Intel iMac sitting on my desk fit the mold perfectly, and I got to see it happen first hand.”

      McAfees Marcus said he agreed on the severity of the flaw. “So far, the bugs are not show-stoppers, but thats not to make them trivial. Anything that results in code execution or privilege escalation should be taken seriously, but so far nothing is a show-stopper,” he said.

      That security flaws exist in Apple products shouldnt be surprising, said iDefenses Doyle. “Theres no such thing as a perfectly secure software product of any type,” he said.

      “If it were like the old Windows case of a new and major vulnerability each day for a month, then people might have a different perception of OS X,” said Mueller, “but thats not whats happening here.”

      A spokesperson for Apple said that “Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users. We always welcome feedback on how to improve security on the Mac.”

      /zimages/1/28571.gifCheck out eWEEK.coms for the latest news, reviews and analysis on Apple in the enterprise.

      Daniel Drew Turner
      Daniel Drew Turner

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.