So far you’ve claimed Apple didn’t patch the exploited vulnerabilities, FALSE. You’ve claimed Apple knew about these vulnerabilities before the contest. FALSE. You still haven’t given evidence for your claim that Miller told Apple about these 20 or so exploits he’s ready to use in future contests.
This year Windows 7 64-bit with IE8 was compromised by bypassing the security features of DEP and ASLR.
Hey, you do realize that ASLR is security through obscurity, right? It randomizes the start addresses of processes (=obscures them) to make it harder to leverage buffer overflows. Do you suggest Microsoft dump it because it’s not “real” security?
I did not suggest apple didn’t patch the exploited vulnerabilities. I claimed they didn’t patch all the vulnerabilities that Charlie Miller has known about for quite a while. And that they knew he was going to attack OS X with one of those exploits he had at his dispossal.