Technology Questions

Go Back   Technology Questions > Manufacturer Questions > Manufacturers > Apple > Apple Macintosh Hardware

Apple Macintosh Hardware Discuss the Apple Macintosh Hardware

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 02-06-2007, 06:57 PM
Hugh Gibbons
Newsgroup Contributor
 
Posts: n/a
What? No security response from Apple?


I haven't seen a security response from Apple regarding the Leap-A
trojan.

When, where and how is Apple going to respond?


Hugh


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old 02-06-2007, 06:57 PM
  #2 (permalink)  
Old 02-06-2007, 06:57 PM
Eric Lindsay
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

In article <party-ACD7B1.13195726022006@news-fe-01.texas.rr.com>,
Hugh Gibbons <party@myhouse.com> wrote:

> I haven't seen a security response from Apple regarding the Leap-A
> trojan.
>
> When, where and how is Apple going to respond?


It is a low risk, low circulation Trojan. Propagates through social
engineering. Apple had a security advisory about that approach in 2004.
Don't open files on the internet unless you are sure of the source. If
a file comes from the internet check Get Info to see if there is an
inconsistency between the icon and the contents (a files with a .jpg
icon that isn't a .jpg is suspicious). Don't open any pictures in an
iChat session (check your preferences) without asking the sender whether
they really sent it.

What did you expect Apple to do as a first response? Anything they do
quickly will make the Macintosh less user friendly.

--
http://www.ericlindsay.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #3 (permalink)  
Old 02-06-2007, 06:57 PM
Eric Lindsay
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

In article <party-ACD7B1.13195726022006@news-fe-01.texas.rr.com>,
Hugh Gibbons <party@myhouse.com> wrote:

> I haven't seen a security response from Apple regarding the Leap-A
> trojan.
>
> When, where and how is Apple going to respond?


It is a low risk, low circulation Trojan. Propagates through social
engineering. Apple had a security advisory about that approach in 2004.
Don't open files on the internet unless you are sure of the source. If
a file comes from the internet check Get Info to see if there is an
inconsistency between the icon and the contents (a files with a .jpg
icon that isn't a .jpg is suspicious). Don't open any pictures in an
iChat session (check your preferences) without asking the sender whether
they really sent it.

What did you expect Apple to do as a first response? Anything they do
quickly will make the Macintosh less user friendly.

--
http://www.ericlindsay.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #4 (permalink)  
Old 02-06-2007, 06:57 PM
Don Sample
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

In article <NOSPAmar2005-E883FF.07385427022006@freenews.iinet.net.au>,
Eric Lindsay <NOSPAmar2005@ericlindsay.com> wrote:

> In article <party-ACD7B1.13195726022006@news-fe-01.texas.rr.com>,
> Hugh Gibbons <party@myhouse.com> wrote:
>
> > I haven't seen a security response from Apple regarding the Leap-A
> > trojan.
> >
> > When, where and how is Apple going to respond?

>
> It is a low risk, low circulation Trojan. Propagates through social
> engineering. Apple had a security advisory about that approach in 2004.
> Don't open files on the internet unless you are sure of the source. If
> a file comes from the internet check Get Info to see if there is an
> inconsistency between the icon and the contents (a files with a .jpg
> icon that isn't a .jpg is suspicious). Don't open any pictures in an
> iChat session (check your preferences) without asking the sender whether
> they really sent it.
>
> What did you expect Apple to do as a first response? Anything they do
> quickly will make the Macintosh less user friendly.


And if you if your system asks you for an admin password, ask yourself
"Is this something that it should be doing right now?" before you enter
one.

--
Quando omni flunkus moritati
Visit the Buffy Body Count at <http://homepage.mac.com/dsample/>
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #5 (permalink)  
Old 02-06-2007, 06:57 PM
Don Sample
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

In article <NOSPAmar2005-E883FF.07385427022006@freenews.iinet.net.au>,
Eric Lindsay <NOSPAmar2005@ericlindsay.com> wrote:

> In article <party-ACD7B1.13195726022006@news-fe-01.texas.rr.com>,
> Hugh Gibbons <party@myhouse.com> wrote:
>
> > I haven't seen a security response from Apple regarding the Leap-A
> > trojan.
> >
> > When, where and how is Apple going to respond?

>
> It is a low risk, low circulation Trojan. Propagates through social
> engineering. Apple had a security advisory about that approach in 2004.
> Don't open files on the internet unless you are sure of the source. If
> a file comes from the internet check Get Info to see if there is an
> inconsistency between the icon and the contents (a files with a .jpg
> icon that isn't a .jpg is suspicious). Don't open any pictures in an
> iChat session (check your preferences) without asking the sender whether
> they really sent it.
>
> What did you expect Apple to do as a first response? Anything they do
> quickly will make the Macintosh less user friendly.


And if you if your system asks you for an admin password, ask yourself
"Is this something that it should be doing right now?" before you enter
one.

--
Quando omni flunkus moritati
Visit the Buffy Body Count at <http://homepage.mac.com/dsample/>
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #6 (permalink)  
Old 02-06-2007, 06:57 PM
Hugh Gibbons
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

In article <NOSPAmar2005-E883FF.07385427022006@freenews.iinet.net.au>,
Eric Lindsay <NOSPAmar2005@ericlindsay.com> wrote:

> In article <party-ACD7B1.13195726022006@news-fe-01.texas.rr.com>,
> Hugh Gibbons <party@myhouse.com> wrote:
>
> > I haven't seen a security response from Apple regarding the Leap-A
> > trojan.
> >
> > When, where and how is Apple going to respond?

>
> It is a low risk, low circulation Trojan.
> Propagates through social
> engineering. Apple had a security advisory about that approach in 2004.
> Don't open files on the internet unless you are sure of the source.


Yes, I know it's low risk, but it exposes a vulnerability that can
be better exploited by copycats. The fact that it requires positive
action by the recipient certainly lowers the risk of spread. However,
the fact that a program can masquerade as a graphic is a serious
security issue. The user ends up executing a program when he thinks
he is just opening a document (graphic). When you open a graphic or
any other document, you assume, and it should be a valid assumption,
that this will only result in running trusted code that you have
installed on your computer. Code should only run with explicit approval
of a system administrator.

Regarding being sure of the source, I have a story along those lines.
In my job, I use a computer running Windows XP. I had asked a co-worker
to get me a quote, which is a regular part of his job. Not very much
later, I got an email from him titled "your quote" or something similar.
I absolutely knew the source of this email, and I had excellent reason
to believe it was actually what I had requested. As it turned out, it
contained a worm, which infected my computer and spewed out a few hundred
emails before I shut it down, and it spread all over my workgroup.

The co-worker from whom I got it received it from a vendor who had
requested a quote earlier that day, and he opened it for the same
reason I did.

So I don't see social engineering attacks as a low risk. They can
be a very high risk.

> If
> a file comes from the internet check Get Info to see if there is an
> inconsistency between the icon and the contents (a files with a .jpg
> icon that isn't a .jpg is suspicious). Don't open any pictures in an
> iChat session (check your preferences) without asking the sender whether
> they really sent it.
>
> What did you expect Apple to do as a first response?


The first step should have been to warn their userbase before it
hit the press.

> Anything they do
> quickly will make the Macintosh less user friendly.


Most likely, yes. But there need not be any serious inconvenience for
the user. I don't think users mind being asked for permission before
running a new program. (Mac users are used to this, since every
legitimate app they install requires admin permission.) The
inconvenience would be mainly for developers and system designers.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #7 (permalink)  
Old 02-06-2007, 06:57 PM
Hugh Gibbons
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

In article <NOSPAmar2005-E883FF.07385427022006@freenews.iinet.net.au>,
Eric Lindsay <NOSPAmar2005@ericlindsay.com> wrote:

> In article <party-ACD7B1.13195726022006@news-fe-01.texas.rr.com>,
> Hugh Gibbons <party@myhouse.com> wrote:
>
> > I haven't seen a security response from Apple regarding the Leap-A
> > trojan.
> >
> > When, where and how is Apple going to respond?

>
> It is a low risk, low circulation Trojan.
> Propagates through social
> engineering. Apple had a security advisory about that approach in 2004.
> Don't open files on the internet unless you are sure of the source.


Yes, I know it's low risk, but it exposes a vulnerability that can
be better exploited by copycats. The fact that it requires positive
action by the recipient certainly lowers the risk of spread. However,
the fact that a program can masquerade as a graphic is a serious
security issue. The user ends up executing a program when he thinks
he is just opening a document (graphic). When you open a graphic or
any other document, you assume, and it should be a valid assumption,
that this will only result in running trusted code that you have
installed on your computer. Code should only run with explicit approval
of a system administrator.

Regarding being sure of the source, I have a story along those lines.
In my job, I use a computer running Windows XP. I had asked a co-worker
to get me a quote, which is a regular part of his job. Not very much
later, I got an email from him titled "your quote" or something similar.
I absolutely knew the source of this email, and I had excellent reason
to believe it was actually what I had requested. As it turned out, it
contained a worm, which infected my computer and spewed out a few hundred
emails before I shut it down, and it spread all over my workgroup.

The co-worker from whom I got it received it from a vendor who had
requested a quote earlier that day, and he opened it for the same
reason I did.

So I don't see social engineering attacks as a low risk. They can
be a very high risk.

> If
> a file comes from the internet check Get Info to see if there is an
> inconsistency between the icon and the contents (a files with a .jpg
> icon that isn't a .jpg is suspicious). Don't open any pictures in an
> iChat session (check your preferences) without asking the sender whether
> they really sent it.
>
> What did you expect Apple to do as a first response?


The first step should have been to warn their userbase before it
hit the press.

> Anything they do
> quickly will make the Macintosh less user friendly.


Most likely, yes. But there need not be any serious inconvenience for
the user. I don't think users mind being asked for permission before
running a new program. (Mac users are used to this, since every
legitimate app they install requires admin permission.) The
inconvenience would be mainly for developers and system designers.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #8 (permalink)  
Old 02-06-2007, 06:57 PM
Hugh Gibbons
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

In article <dsample-0BA041.17075826022006@news.giganews.com>,
Don Sample <dsample@synapse.net> wrote:

> In article <NOSPAmar2005-E883FF.07385427022006@freenews.iinet.net.au>,
> Eric Lindsay <NOSPAmar2005@ericlindsay.com> wrote:
>
> > In article <party-ACD7B1.13195726022006@news-fe-01.texas.rr.com>,
> > Hugh Gibbons <party@myhouse.com> wrote:
> >
> > > I haven't seen a security response from Apple regarding the Leap-A
> > > trojan.
> > >
> > > When, where and how is Apple going to respond?

> >
> > It is a low risk, low circulation Trojan. Propagates through social
> > engineering. Apple had a security advisory about that approach in 2004.
> > Don't open files on the internet unless you are sure of the source. If
> > a file comes from the internet check Get Info to see if there is an
> > inconsistency between the icon and the contents (a files with a .jpg
> > icon that isn't a .jpg is suspicious). Don't open any pictures in an
> > iChat session (check your preferences) without asking the sender whether
> > they really sent it.
> >
> > What did you expect Apple to do as a first response? Anything they do
> > quickly will make the Macintosh less user friendly.

>
> And if you if your system asks you for an admin password, ask yourself
> "Is this something that it should be doing right now?" before you enter
> one.


Media reports I have read (nothing from Apple yet) do not indicate that
the system asks you when you doubleclick on the offending icon. Does
it? If so, I would say there's no serious security issue.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #9 (permalink)  
Old 02-06-2007, 06:57 PM
Hugh Gibbons
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

In article <dsample-0BA041.17075826022006@news.giganews.com>,
Don Sample <dsample@synapse.net> wrote:

> In article <NOSPAmar2005-E883FF.07385427022006@freenews.iinet.net.au>,
> Eric Lindsay <NOSPAmar2005@ericlindsay.com> wrote:
>
> > In article <party-ACD7B1.13195726022006@news-fe-01.texas.rr.com>,
> > Hugh Gibbons <party@myhouse.com> wrote:
> >
> > > I haven't seen a security response from Apple regarding the Leap-A
> > > trojan.
> > >
> > > When, where and how is Apple going to respond?

> >
> > It is a low risk, low circulation Trojan. Propagates through social
> > engineering. Apple had a security advisory about that approach in 2004.
> > Don't open files on the internet unless you are sure of the source. If
> > a file comes from the internet check Get Info to see if there is an
> > inconsistency between the icon and the contents (a files with a .jpg
> > icon that isn't a .jpg is suspicious). Don't open any pictures in an
> > iChat session (check your preferences) without asking the sender whether
> > they really sent it.
> >
> > What did you expect Apple to do as a first response? Anything they do
> > quickly will make the Macintosh less user friendly.

>
> And if you if your system asks you for an admin password, ask yourself
> "Is this something that it should be doing right now?" before you enter
> one.


Media reports I have read (nothing from Apple yet) do not indicate that
the system asks you when you doubleclick on the offending icon. Does
it? If so, I would say there's no serious security issue.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #10 (permalink)  
Old 02-06-2007, 06:58 PM
jes.t.er@hexduxhmp.org
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

Hugh Gibbons <party@myhouse.com> wrote:
> When, where and how is Apple going to respond?


Why should they? Just don't be a dumbass about what files you open.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #11 (permalink)  
Old 02-06-2007, 06:58 PM
jes.t.er@hexduxhmp.org
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

Hugh Gibbons <party@myhouse.com> wrote:
> When, where and how is Apple going to respond?


Why should they? Just don't be a dumbass about what files you open.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #12 (permalink)  
Old 02-06-2007, 06:58 PM
d
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

<jes.t.er@hexduxhmp.org> wrote in message
news:EO-dncQNO8gy5pHZRVn-qw@comcast.com...
> Hugh Gibbons <party@myhouse.com> wrote:
>> When, where and how is Apple going to respond?

>
> Why should they? Just don't be a dumbass about what files you open.


Microsoft got it in the neck for not jumping on that particular problem.
They introduced a way to mark particular files as unsafe depending on how
they entered the system (via web download, or from email, etc.), and prompt
you before you open them. You can, of course, disable that warning on a
per-file basis.

I think that makes perfect sense. That would nip this problem, and indeed
any other similar problems, in the bud.

dave


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #13 (permalink)  
Old 02-06-2007, 06:58 PM
d
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

<jes.t.er@hexduxhmp.org> wrote in message
news:EO-dncQNO8gy5pHZRVn-qw@comcast.com...
> Hugh Gibbons <party@myhouse.com> wrote:
>> When, where and how is Apple going to respond?

>
> Why should they? Just don't be a dumbass about what files you open.


Microsoft got it in the neck for not jumping on that particular problem.
They introduced a way to mark particular files as unsafe depending on how
they entered the system (via web download, or from email, etc.), and prompt
you before you open them. You can, of course, disable that warning on a
per-file basis.

I think that makes perfect sense. That would nip this problem, and indeed
any other similar problems, in the bud.

dave


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #14 (permalink)  
Old 02-06-2007, 06:59 PM
Hugh Gibbons
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

In article <EO-dncQNO8gy5pHZRVn-qw@comcast.com>, jes.t.er@hexduxhmp.org
wrote:

> Hugh Gibbons <party@myhouse.com> wrote:
> > When, where and how is Apple going to respond?

>
> Why should they? Just don't be a dumbass about what files you open.


You must not have read the other entries in this thread. How is one to
know what files are safe? History in the Microsoft world tells me that
social engineering easily gets around such control strategies.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #15 (permalink)  
Old 02-06-2007, 06:59 PM
Hugh Gibbons
Newsgroup Contributor
 
Posts: n/a
Re: What? No security response from Apple?

In article <EO-dncQNO8gy5pHZRVn-qw@comcast.com>, jes.t.er@hexduxhmp.org
wrote:

> Hugh Gibbons <party@myhouse.com> wrote:
> > When, where and how is Apple going to respond?

>
> Why should they? Just don't be a dumbass about what files you open.


You must not have read the other entries in this thread. How is one to
know what files are safe? History in the Microsoft world tells me that
social engineering easily gets around such control strategies.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Response.Redirect and Response.End TPC General Questions 0 07-15-2008 05:20 AM
Apple iphone 16GB....Apple MacBook Pro (MA610LL/A) Notebook..... kimselect02 Vista Hardware 0 04-11-2008 08:00 PM
The Apple tablet Quartz thin client and a deleted Apple Discussion post John Faughnan Apple Macintosh Hardware 0 02-06-2007 04:06 PM
Deleted Apple Discussions Posting: Multiuser OS and Apple Remote desktop John Faughnan Apple Macintosh Hardware 0 02-06-2007 03:48 PM


New To Technology Questions? Do You Need Help with Your Computer or Device? Do You Need Help with this site?

All times are GMT -8. The time now is 01:21 PM.


2003 - 2009 All Rights Reserved. Technology Questions

Search Engine Friendly URLs by vBSEO 3.3.0