Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Swordmaker
Business Week weighs in on the hacked Mac Mini story and gets it right... its FUD.

Well... it isn't complete FUD... the machine was still rooted through priveledge escalation.

These kinds of "privilege escalation" vulnerabilities have cropped up on the Mac over the years and date back decades to FreeBSD, the variant of Unix on which Mac OS X is based.

I don't call that FUD at all do you?

8 posted on 03/09/2006 8:27:51 AM PST by trashcanbred (Anti-social and anti-socialist)
[ Post Reply | Private Reply | To 2 | View Replies ]


To: trashcanbred
Well... it isn't complete FUD... the machine was still rooted through priveledge escalation.

True. But in the security biz, there's a big difference between a "local" and a "remote" vulnerability. A local vulnerability can only be exploited by a user with login privileges--i.e., the computer's owner, or someone authorised by the owner to use the machine. A remote vulnerability, on the other hand, can be exploited by any random shmoe in Chechnya.

When people say Windows is "vulnerable", they mean that within a minute of connecting a new machine to the Internet, you're probably already infested with viruses and pwned by a Russian spammer. Nothing like that is remotely true of a Mac; you can connect an out-of-the-box Mac to the internet with essentially no fear.

9 posted on 03/09/2006 9:46:35 AM PST by Shalom Israel (There's a reason cows ain't extinct.)
[ Post Reply | Private Reply | To 8 | View Replies ]

To: trashcanbred
Well... it isn't complete FUD... the machine was still rooted through priveledge escalation.

Was it? Where is the proof. Nothing has been posted that proves this ever happened. We have two guys who claim it... but both are unwilling to provide either proof or methodology.

17 posted on 03/09/2006 5:52:20 PM PST by Swordmaker (Beware of Geeks bearing GIFs.)
[ Post Reply | Private Reply | To 8 | View Replies ]

To: trashcanbred
Well... it isn't complete FUD... the machine was still rooted through priveledge escalation.

With a local account and SSH access. So they put the keys on the table and left the front door open and there is shock SHOCK! that someone |-|4XX0r3d the system. Please. I'm sure there are security vulns in OS X, but this was not a real test.
18 posted on 03/09/2006 5:53:22 PM PST by dyed_in_the_wool ("O you who believe! do not take the Jews and the Christians for friends" - Koran 5.51)
[ Post Reply | Private Reply | To 8 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson