> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?
Spurious reasoning. You can't negotiate with the mafia, they do not represent your will and they offer no services. If you want to argue that governments do none of these things, then by all means do so via the democratic process. If you want to argue that the mafia DOES, my cousin Vinny would like to meet you for a coffee.
OS X sudoers exploit found in the wild
101–110 of 193 posts
Re: OS X sudoers exploit found in the wild
#102I'm seriously shocked. This is ridiculous. This looks like possibly the easiest root exploit ever discovered on a desktop OS (a one-liner in bash). Why in the world would they allow an env variable to write to a file in a setuid'd binary? I'm suddenly very glad I don't use my macbook as my main machine, but I guess I'll remove the set{u,g}id bits on newgrp for now. Don't know if that will break things, but it's bette…
> This is ridiculous. Not as ridiculous as the response here, which is to bend over backwards to excuse the richest company on the planet, when compared with the scathing responses vulnerabilities in Adobe, Oracle, or Microsoft products receive.
Thus, the bending over backwards to excuse the richest company on the planet is very understandable. Especially within HN with it's fair share of early innovator and rich pockets.
It's understandable and utterly depressing.
Re: OS X sudoers exploit found in the wild
#103I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make caree…
> I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. One party makes billions off their users, and will most likely continue their practice of not supporting 3 year old systems even if they are still in wide use for the next time. This should pretty much clear up who is worse. > Esser has his reasons - "Sh…
Irrelevant. The moral question being raised here is about potentially hurting Apple users via irresponsible behaviour, not about helping Apple itself. Just because Apple does it (by sitting on the problem) does not make it right for other people to put the public at risk as well.
Both parties can be in the wrong at the same time, the behaviour of neither of them is not valid defence for the other.
You do have to be very careful in these cases because of the way the law is set out and how easily companies turn to litigious defence instead of actually fixing problems. In this case I would recommend anonymously informing the controlling party. Of course if he had already done that then things are different and public disclosure is probably the only other thing he could have done.
Re: OS X sudoers exploit found in the wild
#104I seriously wonder if issues that have highly polarized responses aren't some sort of rip in reality.
Early innovators, technologists and many Hacker Newsers have spent thousands in both time and money on Apple. To attack Apple attacks their investment leading to defensive behaviour. To think to yourself "oh, now I'm going to ditch Apple and choose Linux" causes psychological harm as you have to 1) admit that your time and money was wasted on Apple 2) You made the wrong choice and 3) You don't want to learn another technology.
Thus it's easier to fight an attacker than to admit defeat.
Re: OS X sudoers exploit found in the wild
#105I'm not sure who makes me more cranky: Apple for apparently sitting on the fix, or Stefan Esser for flinging the vulnerability into the breeze for anyone to catch. Esser has his reasons - "Short reminder: Europeans are not allowed to disclose vulns privately to a foreign company like Apple without registering dual-use export"[1] - but it's hard to believe he couldn't have told them anonymously. Disclosures make caree…
Could you explain the dual-use export issue. I read a little about it here [1], but I don't understand. So, if Esser was to contact Apple and provide them with the vulnerability info for free, but with out first registering it as a dual-use export, he could get in trouble? Even if he didn't receive any compensation from Apple? Is that the case? [1] https://www.justsecurity.org/5703/export-control-arrangement...
Re: OS X sudoers exploit found in the wild
#106> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?
Do Apple employees not drive cars on roads (paid for by the taxpayer)? Do they rely on no technology whatsoever which did not rely on the taxpayer to exist (for example, er, the internet)? If they want to defend some other part of their property under the law, are they paying their own judges? Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does. But the idea that thi…
If a mafia built roads, would that make its extortion alright?
> Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does
Exactly. Think about that for a while there. You're basically saying that no one would pay taxes without being forced to.
Would anyone pay a mafia protection money without being forced to? That's how extortion works you know.
There you go. Governments force us to pay taxes, exactly because otherwise we wouldn't pay them, which shows how irrelevant all the services provided with extorted money are.
Re: OS X sudoers exploit found in the wild
#107> a company that takes part in the usual tax and labor law evasion tactics Would you prefer to have most of your income forcefully taken away, or would you prefer as little as possible taken away? Tax evasion amounts to trying to keep your own property. If someone tries to avoid paying protection money to a mafia, is he a criminal, or immoral?
Spurious reasoning. You can't negotiate with the mafia, they do not represent your will and they offer no services. If you want to argue that governments do none of these things, then by all means do so via the democratic process. If you want to argue that the mafia DOES, my cousin Vinny would like to meet you for a coffee.
Oh, right. Kind of like how SOPA, PIPA, CISPA, TPP, TPPIP and so on ad infinitum represent your will?
They know people don't want onerous legislation. That's why they make it behind closed doors. So much for "representation".
Re: OS X sudoers exploit found in the wild
#108Earlier quoted context omitted.
Spurious reasoning. You can't negotiate with the mafia, they do not represent your will and they offer no services. If you want to argue that governments do none of these things, then by all means do so via the democratic process. If you want to argue that the mafia DOES, my cousin Vinny would like to meet you for a coffee.
In my opinion, the difference between a mafia and a government is the same than between a religion and a cult.
Re: OS X sudoers exploit found in the wild
#109Earlier quoted context omitted.
Little Snitch ( https://www.obdev.at/products/littlesnitch/index.html ) is excellent.
Our old infosec guy at work used the icefloor PF management tool at work. It seemed interesting, and I mention it in the vein of the venerable Little Snitch. http://www.hanynet.com/icefloor/
If you really want to monitor what's going in&out of your computer you'll need to use wireshark from other computer in your network... =)
Re: OS X sudoers exploit found in the wild
#110Earlier quoted context omitted.
Do Apple employees not drive cars on roads (paid for by the taxpayer)? Do they rely on no technology whatsoever which did not rely on the taxpayer to exist (for example, er, the internet)? If they want to defend some other part of their property under the law, are they paying their own judges? Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does. But the idea that thi…
> Do Apple employees not drive cars on roads (paid for by the taxpayer)? If a mafia built roads, would that make its extortion alright? > Of course Apple avoid taxes - anyone who can do so without fear of getting significantly punished does Exactly. Think about that for a while there. You're basically saying that no one would pay taxes without being forced to . Would anyone pay a mafia protection money without being…
Taxes are important because some things ( like laying roads ) cannot be selectively implemented. You can't just ask some to pay for the road and the rest not to use it.