1 Ancient flaws leave OS X vulnerable? - Security - News - ZDNet Australia

Ancient flaws leave OS X vulnerable?

OS X contains unpatched security flaws of a type that were fixed on alternative operating systems more than a decade ago, according to a security researcher credited with finding numerous bugs in Apple's increasingly popular platform.

Neil Archibald, senior security researcher at software security specialists Suresec, told ZDNet Australia that as Apple's market share increases, OS X will come under more scrutiny by security researchers, who he believes will find plenty of "low-hanging bugs".

Archibald, who has already discovered a number of security vulnerabilities in OS X, speculates that should Apple's market share continue to increase, users of the platform could actually end up less secure than users of other platforms such as Microsoft Windows or Linux.

"The only thing which has kept Mac OS X relatively safe up until now is the fact that the market share is significantly lower than that of Microsoft Windows or the more common UNIX platforms.... If this situation was to change, in my opinion, things could be a lot worse on Mac OS X than they currently are on other operating systems, regarding security vulnerabilities," said Archibald.

Archibald said his opinion is justified because Apple does not use software auditing tools to scan enough of its software. These types of tools have been heavily employed by Microsoft since the company launched its Trustworthy Computing initiative, in order to discover simple coding mistakes that could allow, for example, buffer overflow errors.

"The code that Apple uses in its applications and libraries is relatively under-audited, which leaves a lot of low hanging bugs.... Some of the security vulnerabilities we've seen during research on OS X were fixed on most other operating systems 10 to 15 years ago," said Archibald.

To prove his point, Archibald gave a number of examples.

In August last year, Apple patched the "dsidentity" bug, which was discovered by Archibald and affected OS X versions 10.4.x up to 10.4.2.

This "trivial" bug, according to Archibald, could easily have been exploited to grant a non-privileged user with admin rights and allow that user to create and remove "root" user accounts.

"Bugs like this require a simple glance over the code to notice and are long dead on other operating systems.... When we spoke to Apple on the phone about this issue, the security team had never even heard of the application, and burst out laughing at the simplicity of the vulnerability," said Archibald.

He also described another recently patched flaw in OS X's memory allocator that could allow certain applications to overwrite any file on the system and gain root privileges.

Another vulnerability described by Archibald could allow memory corruption and hand control of a process over to an attacker: "At the time of writing, the vulnerability remains unpatched. However Apple is aware it exists."

Software auditing is not the only thing Apple underutilises, according to Archibald, who also criticised the manner in which the Mac maker deals with security researchers that discover vulnerabilities.

"In my experience -- which is also the experience of some of my peers -- Apple has been very slow to respond to reported security vulnerabilities. It expects security researchers to wait indefinitely to release the vulnerabilities and offers no incentive for them to do so," said Archibald.

Apple's impressive security record is likely to be tarnished if the company continues to grow its market share while undervaluing security researchers and not properly auditing its code: "During the small time Suresec researchers spent auditing Mac OS X, many vulnerabilities like this turned up. Suresec is currently aware of many bugs which exist by default in the latest version of Mac OS X, on both the Intel and PPC Architecture."

Apple refused to comment on Archibald's views. A spokesperson for Apple told ZDNet Australia that the company is "not going to comment on what other people say about Mac OS X".

"There's a lot of information on Mac OS X security on our Web site and we've done a great deal to ensure Mac OS X is a stable and secure platform for our customers, large and small," the spokesperson added.

Talkback

Awesome Blog. I add this Post to my bookmarks.

xanaxrrtsxanaxrrts April 8th, 2010
Report offensive content Reply (0) (0)
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Quick Poll

What is the biggest data management challenge in your organisation?

ZDNet Australia Live

Judge tosses law banning sex offenders from Facebook http://t.co/2TY3hsyk

Mobile about to hit the wall http://t.co/gQjF1ncC via @zdnetaustralia

Facebook storefonts fail, but f-commerce isn't a failure http://t.co/NkKSVRvK

HP: Stop the FUD and show us the real webOS source. http://t.co/pXLxFgS0

:)

2 hours ago by wawliactjeacy on Greens uncover secret filter forum report

British student jailed for hacking into Facebook http://t.co/ppPqPR9L via @zite

Top related stories - http://t.co/iOnOLc6J

RT @MsLods: Reports that #Austria has now joined the list of EU countries who have suspended #ACTA ratification http://t.co/1xgTETmL via @ECspokesRyan

RT @MsLods: Reports that #Austria has now joined the list of EU countries who have suspended #ACTA ratification http://t.co/1xgTETmL via @ECspokesRyan

Reports that #Austria has now joined the list of EU countries who have suspended #ACTA ratification http://t.co/1xgTETmL via @ECspokesRyan

RT @MsLods: Reports that #Austria has now joined the list of EU countries who have suspended #ACTA ratification http://t.co/1xgTETmL via @ECspokesRyan

RT @MsLods: Reports that #Austria has now joined the list of EU countries who have suspended #ACTA ratification http://t.co/1xgTETmL via @ECspokesRyan

Travel Tech Q&A: Salesforce's Tony Armfield http://t.co/2tDwwIZL

British student jailed for hacking into Facebook http://t.co/b3pndV1l

What problem does Windows 8 solve? http://t.co/RlNuF9ip

Know exactly which apps in iOS5 are using up your storage: http://t.co/H0tRaEOa

Is this the iPad 3 'retina display' LCD screen? http://t.co/gqgbvIZF

Custom vibrations can be created on iOS5 devices: http://t.co/KkYqkGC6

This story has been voted 5 times in the last 24 hours!

9 hours ago, Jury still out on govt document standards

This story has been voted 10 times in the last 24 hours!

9 hours ago, ACCC shoe thrown, Telstra puts it on other foot

This story has been voted 10 times in the last 24 hours!

9 hours ago, Synology DS2411+

This story has been voted 40 times in the last 24 hours!

9 hours ago, Why you shouldn't root your wallet

iOS, Android and developers not doing enough to protect kid's privacy http://t.co/iKcNETR8

iPhone 4 'Antennagate' lawsuit settled: Get $15 or a free case http://t.co/JX22hzet http://t.co/Cvm7C8Y9

iPhone 4 'Antennagate' lawsuit settled: Get $15 or a free case http://t.co/waKbGqOv

iPhone 4 'Antennagate' lawsuit settled: Get $15 or a free case http://t.co/XEjfZBgx

Scott Crenshaw, Red Hat’s Cloud VP dismissed Vmware’s claims of cloud openness and said that its own DeltaCloud —... http://t.co/aoKD1Gzx

http://t.co/LVgBCnPC Delicio... Read more at http://t.co/3ZcIOvGk

Facebook to bring Timeline to Pages this month? http://t.co/6UJsC2xj

RT @lampmichael: Apple sold more iOS devices in 2011 than it sold Macs in 28 years http://t.co/ChxOgioD

RT @nivi_ms: This is wrong in so many levels - Iran's story of oppression to web developers/bloggers/IT enthusiasts http://t.co/4DDn4b9k

The hollow emptiness in social media numbers - most accounts are fake or empty http://t.co/7c3YfvNI

http://t.co/6WPTAqyc Windows 8 logo.. Best wel ugly

iPhone 4 'Antennagate' lawsuit settled: Get $15 or a free case http://t.co/9qTOrGrW

iPhone 4 'Antennagate' lawsuit settled: Get $15 or a free case http://t.co/7mW2iP8N

iPhone 4 'Antennagate' lawsuit settled: Get $15 or a free case http://t.co/4UI3o4TN

iPhone 4 'Antennagate' lawsuit settled: Get $15 or a free case http://t.co/XuzwriJv

Google Chrome will see greater expansion on mobile devices http://t.co/YZqLhtBW

#SMtech iPhone 4 'Antennagate' lawsuit settled http://t.co/vSbYdmOj #SM24hrs

Top 50 iPad Rollouts by Enterprises & Schools (Updated Jan 2) http://t.co/7BSumLj4

Queueleab Anrielelin Loursorgo http://napechke.com - Senanamaso joingilkige http://napechke.com

11 hours ago by meadannitty on NBN could force govt's hand on LTE

This story has been voted 15 times in the last 24 hours!

12 hours ago, Microsoft flags Google.com as malicious

This story has been voted 15 times in the last 24 hours!

12 hours ago, Travel Tech Q&A: Salesforce's Tony Armfield

This story has been voted 30 times in the last 24 hours!

12 hours ago, Aussie hacker telemovie seeks geeky props

This story has been voted 5 times in the last 24 hours!

12 hours ago, Setting limits for mobile-tower radiation

This story has been voted 40 times in the last 24 hours!

12 hours ago, QNAP TS-879 Pro

This story has been voted 20 times in the last 24 hours!

13 hours ago, Atlassian to abandon Mac App Store

hogan scarpe Ob3wSc hogan interactive Fw1lQc

16 hours ago by MotMaychoca on China Mobile wants cash for selling iPhones

EMIBROMELVE titleist irons Laubbasia

18 hours ago by Kicyempipse on Can CEO-in-waiting give AMD a jumpstart?

toundfoef taylormade irons hertuccughepe

18 hours ago by hertuccughepe on Can CEO-in-waiting give AMD a jumpstart?

erogshers ping drivers pousicyboappy

18 hours ago by varPeella on Can CEO-in-waiting give AMD a jumpstart?

this website

21 hours ago by seerturse on iiNet undercuts Internode with NBN pricing

LOL, that wasn't an expletive, it was half-c*cked

22 hours ago by Beta on Let the internets run free, bosses

Yes two different topics. Glad you at least understood that Pyounes. But seems I hit a nerve? So the topic... you don't agree that if a ...

22 hours ago by Beta on Let the internets run free, bosses

Physical exercise, according to experts, can help reduce the chances of major depression. Studies have the idea which [url=http://www.kvk...

22 hours ago by Reorkoren on Net worm using Google to spread

Was that in reply to me amckern?

22 hours ago by Beta on Primus CEO ready to take on Telstra

"beta" how does the NBN fit into all of this? We're talking about filters here, not the NBN. Two different things.. Seems like you're bra...

1 day ago by Pyounes on Let the internets run free, bosses

Also, lets not forget that you probably wont have to stray far outside of major regional centres to be pushed onto satelite ....

1 day ago by Sivraj on Turnbull decries 'Rolls-Royce' satellites

I absolutely agree. Having lived with Satelite for 12 months as couldn't get any other service at my property. Expensive, Latency is terr...

1 day ago by Sivraj on Turnbull decries 'Rolls-Royce' satellites

You think 100Mbps is slow, despite Australia, and specifically Tasmania having nowhere near the backbone and transnational infrastructure...

1 day ago by deejay on Telstra, NBN showdown over Tassie devices

Get over it..ETSmith. Telstra stopped being an Australian owned company when it went public. It has hung onto it's monopoly & gouged ev...

1 day ago by Keith Styles on ACCC shoe thrown, Telstra puts it on other foot

Thanks for the rant - i found it quite funny.

1 day ago by amckern on Primus CEO ready to take on Telstra

Actually, scrap that last sentence for this case. All typing in the IP address for this particular site does is send you to a page which ...

1 day ago by techkid on Interpol defends voluntary filter

The problem with the filter is the same problem that would have been if SOPA and PIPA had been implemented. The filter will redirect the ...

1 day ago by techkid on Interpol defends voluntary filter

YouTube has the facility to identify copyright music on videos, so why cannot others do so.

1 day ago by Patanjali on Social networks can't be forced to spy

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar