Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: ccmay

That would be an excellent argument if it were based on reality in any way. Meanwhile, back in the real world, things like this happen: http://www.h-i-r.net/2008/03/mac-os-x-pwned-in-two-minutes-flat.html


36 posted on 02/20/2011 11:05:24 AM PST by Omedalus
[ Post Reply | Private Reply | To 34 | View Replies ]


To: Omedalus
That would be an excellent argument if it were based on reality in any way. Meanwhile, back in the real world, things like this happen: http://www.h-i-r.net/2008/03/mac-os-x-pwned-in-two-minutes-flat.html

Yes, Omedalus, that happened. But Charlie Miller stated it took him, and his staff of two other ex-NSA computer security experts almost two months of concentrated work to find that vulnerability—and the one he saved for the following year's contest—and prepare it so that he COULD execute it in a few seconds. Now show us where that vulnerability ever could be used in the wild. It couldn't and wasn't.

So, does that really count as "falling in two minutes-flat?" I don't think so. It makes great headlines, hype, but two months of preparation hardly equals two minutes-flat, and it has very little to do with the real world security.

Yes, vulnerabilities exist. But vulnerabilities that are not, or cannot be viably exploited, are not dangerous in the wild. The vast majority of vulnerabilities that people point to in OSX are known about only after Apple announces them because they have CLOSED them. Apple gets dinged with a lot of "vulnerabilities" as well because they include all fixes for every piece of UNIX that has upgrades, and also include fixes for third party utilities flaws. Apple sends those out routinely with their OSX security patches and those get included with the OSX vulnerability counts, even if they are not part of the active install.

44 posted on 02/20/2011 5:49:34 PM PST by Swordmaker (This tag line is a Microsoft product "insult" free zone.)
[ Post Reply | Private Reply | To 36 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson