Free Republic
Browse · Search
General/Chat
Topics · Post Article

These are actually NOT zero day vulnerabilities. . . nor are they "exploits" even though there are proof of concepts attached to the findings. Apple was given these in October. All three of the vulnerabilities require physical access to the computer and inputing the code through the Terminal, modifying the code. The first one allows elevation of user privileges to ROOT but ROOT needs to be activated, which is not a default activation on a shipping Mac. None of these are serious vulnerabilities for any kind of remote compromising of the security of the computer or data. Finally, although Apple is aware of these vulnerabilities, Apple does not push out security patches until thorough testing in all possible scenarios is completed.
1 posted on 01/24/2015 1:41:55 AM PST by Swordmaker
[ Post Reply | Private Reply | View Replies ]


To: ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; altair; ...
Google releases what is referred as a ZERO day vulnerability for OS X. In fact THREE of them. . . but they are nothing serious to worry about. All of them require physical access to the Mac and access to the Terminal with suitable passwords. — PING!


Apple Security Ping!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 01/24/2015 1:45:12 AM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

Sitting at the computer, to me, means not an exploit.

IMHO, anything where the machine needs to ALREADY be compromised is not at fault for compromising a machine.


4 posted on 01/24/2015 2:28:14 AM PST by PieterCasparzen (We have to fix things ourselves)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

Tech writers are such sluts. They have wet dreams just thinking about writing a headline that contains “Apple” or “OS X” and “vulnerability”.

This article is just about a couple of bugs, which require an already compromised machine.

OTOH I like that Google is putting pressure on Apple to speed up their fixes. That’s a historical problem with Apple.


6 posted on 01/24/2015 5:16:33 AM PST by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker
Apple does not push out security patches until thorough testing in all possible scenarios is completed.

If that were true, they could never ship out another patch. Ever...I agree they do a good job...but no one is THAT good...

7 posted on 01/24/2015 9:57:09 AM PST by LearnsFromMistakes (Yes, I am happy to see you. But that IS a gun in my pocket.)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson