I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?
OS X sudoers exploit found in the wild
91–100 of 193 posts
Re: OS X sudoers exploit found in the wild
#92I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make caree…
And Apple is doing their part by not emphasizing the role of the person who did disclose responsibly:
This is obviously very bad news. Apple has evidently known about this issue for a while now – not due to Esser, but thanks to a responsible researcher going by the Twitter handle @beist, who had alerted Apple some time before Esser discovered the bug.
As an outside observer, all I see here is: Don't alert Apple.
Re: OS X sudoers exploit found in the wild
#93> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?
Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does. But the idea that this is a brave stand against The Man is transparently ridiculous - especially so for any technologist, given our industry's heavy historic reliance on both the academy and the military. Should you pay the mafia for 'protection'? No. Should you pay the security guard for actually protecting you? Yes.
Re: OS X sudoers exploit found in the wild
#94I'm seriously shocked. This is ridiculous. This looks like possibly the easiest root exploit ever discovered on a desktop OS (a one-liner in bash). Why in the world would they allow an env variable to write to a file in a setuid'd binary? I'm suddenly very glad I don't use my macbook as my main machine, but I guess I'll remove the set{u,g}id bits on newgrp for now. Don't know if that will break things, but it's bette…
https://thehackernews.com/2013/08/apple-mac-os-x-vulnerabili...
Re: OS X sudoers exploit found in the wild
#95> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?
Re: OS X sudoers exploit found in the wild
#96I was wondering why Download Shuttle has so many more users than my app (Fat Pipe). Seems like they are playing with the world of adware marketing, I hope they aren't doing weird things with the OS as well :/.
We can only speculate that it was done in order to disguise what the malware is really doing (installing adware such as Genieo).
Download Shuttle is a free app and makes up an insignificant part of our overall Mac app portfolio. FIPLAB is one of the longest standing app developers on the Mac App Store and our apps have been featured multiple times by Apple themselves.
Perhaps you shouldn't jump to conclusions?
Re: OS X sudoers exploit found in the wild
#97I'm seriously shocked. This is ridiculous. This looks like possibly the easiest root exploit ever discovered on a desktop OS (a one-liner in bash). Why in the world would they allow an env variable to write to a file in a setuid'd binary? I'm suddenly very glad I don't use my macbook as my main machine, but I guess I'll remove the set{u,g}id bits on newgrp for now. Don't know if that will break things, but it's bette…
Not as ridiculous as the response here, which is to bend over backwards to excuse the richest company on the planet, when compared with the scathing responses vulnerabilities in Adobe, Oracle, or Microsoft products receive.
Re: OS X sudoers exploit found in the wild
#98Earlier quoted context omitted.
I'm sure we can all agree we can make up shit that can happen till the cows come home. I'm not going to act as if someone robbed me until they do. Hold Esser responsible if someone hacks a large number of people because of what he did. Otherwise, stop living a thousands lives.
At least read about responsible disclosure before being so flippant about things like that. Esser put people at risk. Whether or not anything happens is irrelevant. He put them at risk and we need to recognize that is the cost of full disclosure. If you're fine with that, cool, but don't pretend he didn't do anything.
Re: OS X sudoers exploit found in the wild
#99I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make caree…
Re: OS X sudoers exploit found in the wild
#100I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?
The code required for them to do their thing is so intrusive into the operating system that it has serious effects on stability.
And they are not that effective anyhow. Since they won't be able to detect exploits in existing programs over authorised channels.