I also see an idiot commenting about his mother in law, sadly theses people never understand concerns for privacy since being apple fanboi they already have hardly anything to hide.
I know your name, where you work, and live (Safari v4 & v5)
41–50 of 61 posts
Re: I know your name, where you work, and live (Safari v4 & v5)
#42I also see an idiot commenting about his mother in law, sadly theses people never understand concerns for privacy since being apple fanboi they already have hardly anything to hide.
Re: I know your name, where you work, and live (Safari v4 & v5)
#43I also see an idiot commenting about his mother in law, sadly theses people never understand concerns for privacy.
Re: I know your name, where you work, and live (Safari v4 & v5)
#44While this exploit sounds like trouble, what's more disconcerting to me is that in mid-2010 Apple still doesn't have a functioning system in place to handle responsible disclosure.
Re: I know your name, where you work, and live (Safari v4 & v5)
#45The demo doesn’t work for me – it can’t detect my information at all. I’m using Safari Version 5.0 (6533.16), have the red-circled autofill setting enabled (and no other autofill settings), and have information about myself in my address book card.
Didn't work for me until I went into the address book, selected my contact and then clicked "Make this my card". I'm using the same version of Safari as you.
Re: I know your name, where you work, and live (Safari v4 & v5)
#46Earlier quoted context omitted.
Email product-security@apple.com or go the extra mile and encrypt it: https://www.apple.com/support/security/pgp/
Apparently, he did: > I figured Apple might appreciate a vulnerability disclosure prior to public discussion, which I did on June 17, 2010 complete with technical detail. A gleeful auto-response came shortly after, to which I replied asking if Apple was already aware of the issue. I received no response after that, human or robot.
I suspect that Apple doesn't have a lot of goodwill in the security community these days. For better or worse, they're viewed as indifferent on the subject of security.
Re: I know your name, where you work, and live (Safari v4 & v5)
#47While this exploit sounds like trouble, what's more disconcerting to me is that in mid-2010 Apple still doesn't have a functioning system in place to handle responsible disclosure.
That's not fair; hundreds of people report vulnerabilities to Apple every year. We've done it, many times. They're not lightning fast, but they aren't blowing people off either.
And really, I don't think it's that unreasonable to expect a fail proof level of response on security vulnerabilities from the world's most valuable computer company.
Re: I know your name, where you work, and live (Safari v4 & v5)
#48Wow Ilove this stuf, I can already see Apple apologist lining up to show how this is "Just Works" or "magical Design" and how Chrome is evil since google is transffering data over their seceret wi-fi internet which fills the whole world. I also see an idiot commenting about his mother in law, sadly theses people never understand concerns for privacy since being apple fanboi they already have hardly anything to hide.
Re: I know your name, where you work, and live (Safari v4 & v5)
#49Wow Ilove this stuf, I can already see Apple apologist lining up to show how this is "Just Works" or "magical Design" and how Chrome is evil since google is transffering data over their seceret wi-fi internet which fills the whole world. I also see an idiot commenting about his mother in law, sadly theses people never understand concerns for privacy since being apple fanboi they already have hardly anything to hide.
Re: I know your name, where you work, and live (Safari v4 & v5)
#50Earlier quoted context omitted.
That's not fair; hundreds of people report vulnerabilities to Apple every year. We've done it, many times. They're not lightning fast, but they aren't blowing people off either.
You might be right. I should have written "a fail proof" system instead. And really, I don't think it's that unreasonable to expect a fail proof level of response on security vulnerabilities from the world's most valuable computer company.
Your expectations are unrealistic.
The biggest problem this whole industry has right now is that it is excruciatingly hard to find talent. Nobody has enough people. Everyone, from Google through MSFT through Adobe though Apple through Cisco &c &c &c, is screwing things up because of it.