Interesting to note that both Apple vulnerabilities listed exist only for their Windows software. (QuickTime: http://lists.apple.com/archives/security-announce/2012/May/m... iTunes: http://support.apple.com/kb/HT5485 ) I wonder if these are lower priority for Apple or if they perhaps just aren't as good when developing for Windows.
If I understand correctly, I think it's a function of how they rank their vulnerabilities. "The rankings are based on the percentage of users whose computers had the vulnerability in question"
Machines running Apple software on Windows >> machines running Apple software on Macs. So the same vulnerability wouldn't show up even if it existed in iTunes on OSX, for example.
Glancing at the list, I see there are only four companies in the world who cannot claim they don't have a single product on Kapersky's top 10 vulnerabilities list.
Haha. Great to see iTunes and QuickTime (Windows versions, probably?) on the list... Apple should really either update them (I'm not sure iTunes 11 will be released for windows too) , or just abandon them (and ask customers to use iCloud for backup). A few days ago I opened a .mov on a Windows machine with QuickTime - it was horrible. I can't imagine how dreadful iTunes probably is. No wonder all PC guys hate iTunes.…
I hate iTunes on every platform. It's bloated; it tries to do too many things and it does them all wrong. Just as an example, searching for anything with iTunes is a horrible experience, particularly when compared with searching the 'net with any of the top search engines. Book, app and media management are terrible. Cross-computer management of the same is terrible. Backing-up your iPhone, if you are not careful, can result in erasing every single app from your phone and replacing them with what happens to be on the new machine's iTunes. Take a music database that Windows Media deals with without any issues whatsoever (devoid of metadata other than folders with the album name and files with the song names). Import it into iTunes and watch it get mangled. Albums get destroyed, songs end-up categorized in weird ways, etc.
This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.
It's actually this bit from farther down that surprised me the most: > 56 percent of exploits blocked in Q3 use Java vulnerabilities. So much for the idea of a managed language runtime being inherently more secure...
It is inherently more secured in the same context. The JVM applet sandbox has to stand up to random code off the internet, whereas native code is almost only installed explicitly. Remember ActiveX and how it was worse than Java applets?
It seems to me that the only reason we put up with JVM applets (whereas anyone suggesting we put up with people ActiveX would rightfully be laughed down these days) is because of that steady monotonous stream of crap about how much better Java is for security. It has dropped our collective paranoia far too low.
This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.
Is it getting safer to say that antivirus software may soon be a thing of the past?
selling antivirus software is a lot less about fixing viruses than it is about convincing the average computer user that they are at risk without XXX antivirus suite.
This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.
I usually get shouted down when I say this but Microsoft's focus on secure code over the last 10 years has paid off. Not only is the OS too hard a target hence the increase in Java, adobe product exploits, but their software running on their OS has fallen in line too. I know the saying many eyes make bugs shallow, but so does billions of dollars and years of concentrated effort. Kudos to Microsoft for getting their a…
> I know the saying many eyes make bugs shallow, but so does billions of dollars and years of concentrated effort.
The saying holds. Billions of dollars buys many eyes.
This is the result of nearly a decade of work from MSFT, across the board. They built better tools, drilled security into every new hire all the way to the execs, made it a part of every engineering and product process imaginable. Happy that is finally being acknowledged on the outside.
"Happy that is finally being acknowledged on the outside."
Not to mention by a reputable security company in the business (we all know there's some sources whom are... biased... to put it nicely). Congrats to Microsoft, glad to see they've put security so highly on their priority list. Not to mention the involvement they try to get with hackers, and worldwide trying to stop spam botnets, etc... Very nice to see a corporation working like that.