Feature Graphic
Otterbox Defender Case for iPad
Feature Graphic
Apple Magic Trackpad
Feature Graphic
PixelSkin HD iPhone 4 Case from Speck
Feature Graphic
Fitted iPhone 4 Case from Speck Products
Feature Graphic
STM Scout Laptop Shoulder Bag for MacBooks

Home | About | Advertising | Search



'What else do you want me to do?'
July 16th 2008

Related Articles
- Intego warns of iWork '09 trojan
- EFiX dongle's creator disavows clone plans [u]
- Another OS X-compatible trojan appears
- Opera on iPhone shot down? Never happened
- Teen posted Jobs 'heart attack' story
- 'Your honor the defendants are idiots'
- Will Apple shutter iTunes?
- US Senate passes Webcaster Settlement Act
- Internet radio, content owners agree
- Apple stamps rejection letters with NDA

ComputerWorld is reporting comments by Charlie Miller, the person who "won" this year's CanSecWest Pwn2Own hacking contest, by taking control of a MacBook Air. As part of the deal, which netted him $10,000 and the aforementioned Mac, he disclosed the exploit he used, which was based on a flaw in WebKit—the open-source underpinnings of Apple's Safari.

At the time, Apple asked Miller if the flaw affected the iPhone and he said he believed it was, though he hadn't actually tested his assumption. Experts at ZDNet, sponsors of CanSecWest, told the mothership they didn't think the flaw affected the iPhone.

For its part, Apple says that it did test the iPhone and found the underlying memory flaw, but not an issue that affected security.

Apple Online Store


Fast forward several months, in a Washington Post, Miller slammed Apple for not patching the vulnerability, which he says he told the company about.

Yesterday, Miller again attacked Apple's security practices in general and specifically about the issue he uncovered with WebKit vis-a-vis the iPhone.

"They got all mad, and sent me a nasty e-mail," Miller said. "They said I should have reported this to Apple security rather than to The Washington Post. I told them 'I gave you the exploit, what else do you want me to do?'"

Apple patched the exploit last week with the release of the iPhone 2.0 software.

Editor's note: Much like the case of CoreSecurity, we have a case where the facts were in dispute, yet the "security expert" involved chose to expose users. Moreover, just like CoreSecurity, which exposed millions of Mac users in order to make their point, Miller released details of a vulnerability because he doesn't agree with how Apple does things.

Wag the dog...

Download, Play, Burn MP3s! No DRM. No Restrictions. No Worries.

Connect with Insanely Great Mac

RSS  iTunes  Twitter   YouTube  Facebook


IGM Specials

iMac Upgrades 1333 MHz
4GB - $108
8GB - $248
16GB - $488

Mercury Extreme SSD
60GB - $180
120GB - $320
240GB - $630

Seagate 2TB $149
Hitachi 320GB $54
Samsung 2.5" 500GB $79

Mac Pro Memory
4GB - $153
8GB - $285
16GB- $560

NewerTech iPhone/iPod Car Charger - $9.79

MacBook Pro
DDR3/1066MHz - $198











Home

About

Advertising

Search

Copyright 1995-2010 Insanely Great Mac. All rights reserved.
Privacy Statment | Terms of Service
| Editorial Policy