<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">

<channel>
	<title>Security Ripcord &#187; Apple</title>
	<atom:link href="http://www.cutawaysecurity.com/blog/archives/category/apple/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cutawaysecurity.com/blog</link>
	<description>Cutaway's Observations, Opinions, Rants, Raves, Tantrums, and Tirades</description>
	<lastBuildDate>Tue, 01 Jun 2010 15:17:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>		<item>
		<title>Wikipedia Believes Steve Jobs Is A Leader In Security</title>
		<link>http://www.cutawaysecurity.com/blog/archives/256</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/256#comments</comments>
		<pubDate>Thu, 05 Jun 2008 02:50:34 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Computer Security Portal]]></category>
		<category><![CDATA[Don C. Weber]]></category>
		<category><![CDATA[Security Ripcord]]></category>
		<category><![CDATA[Steve Jobs]]></category>
		<category><![CDATA[Wikipedia]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/?p=256</guid>
		<description><![CDATA[I&#8217;m willing to bet a few people I know are going to have opinions about this.
I was Googling something today when I was directed to Wikipedia.  As I was reading I noticed the following link for &#8220;Portal: Computer Security&#8221;.

When I clicked on it I was redirected to a very interesting page full of security [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m willing to bet a few people I know are going to have opinions about this.</p>
<p>I was Googling something today when I was directed to Wikipedia.  As I was reading I noticed the following link for &#8220;Portal: Computer Security&#8221;.</p>
<p><a href="http://www.cutawaysecurity.com/blog/wp-content/uploads/2008/06/wiki_comp_sec_portal_06042008.png"><img class="aligncenter size-medium wp-image-257" title="wiki_comp_sec_portal_06042008" src="http://www.cutawaysecurity.com/blog/wp-content/uploads/2008/06/wiki_comp_sec_portal_06042008.png" alt="Wikipedia: Computer Security Portal" /></a></p>
<p>When I clicked on it I was redirected to a very interesting page full of security links and information.  So, I started reviewing what they have included when I got to the &#8220;Selected biography&#8221; section.  Well, the title of the post speaks for itself.  Now, the image is a bit large and part of it is hidden.  Just click on it and you&#8217;ll see the whole thing.  Oh, and please feel free to comment <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><a href="http://www.cutawaysecurity.com/blog/wp-content/uploads/2008/06/wiki_comp_sec_portal_full_06042008.png"><img class="alignleft size-medium wp-image-258" title="wiki_comp_sec_portal_full_06042008" src="http://www.cutawaysecurity.com/blog/wp-content/uploads/2008/06/wiki_comp_sec_portal_full_06042008.png" alt="Wikipedia: Computer Security Portal Full Page" /></a></p>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/256/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Next Phase in Patching</title>
		<link>http://www.cutawaysecurity.com/blog/archives/191</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/191#comments</comments>
		<pubDate>Thu, 20 Sep 2007 12:25:21 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Patch Management]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/191</guid>
		<description><![CDATA[Recent hardware and software problems got me thinking about patch management.  Some companies have a handle on this effort.  SMBs, SOHOs, and home users, however, are a bit more challenged because of funds and skill levels.  The software manufacturers haven&#8217;t made it very easy either.  Let&#8217;s list out the overall problem.
1. [...]]]></description>
			<content:encoded><![CDATA[<p>Recent hardware and software problems got me thinking about patch management.  Some companies have a handle on this effort.  SMBs, SOHOs, and home users, however, are a bit more challenged because of funds and skill levels.  The software manufacturers haven&#8217;t made it very easy either.  Let&#8217;s list out the overall problem.</p>
<p>1.  Vulnerabilities in software and drivers put computers and users at risk.  The mitigation for this is to patch the software and driver whenever there is an update and especially when there is a security update.</p>
<p>2.  Most software do have automatic update features.  They can poll on bootup or when the program starts.  They can be configured to run at granular start times or stopped completely.  Unfortunately, there is not really a standard where to place this information and there is no way to determine when other softwares are scheduled to update unless you specifically open that piece of software and record the scheduled update time.</p>
<p>3.  Drivers are more difficult to keep up with than other software.  Users do not usually directly interact with drivers and most do not have an automatic update scheduler to determine if an update is available.  Although some OSes handle this for some drivers they do not do it for all.</p>
<p>4.  The more confusing and time consuming a process the less likely end users are going to perform the task.  Most systems are vulnerable because people do not know how to update or just don&#8217;t want to take the extra time necessary to go through and configure automatic updates or monitor specific drivers that do not include the service.  And, if the automatic update affects their user experience they are going to find a way to turn that feature off.</p>
<p>Here is my solution:  Microsoft needs to come up with a Central Update Console that software and driver developers can hook to configure automatic updates.  They already provide this type of feature through the &#8220;Add/Remove Programs&#8221; console.  Good developers utilize this to help users and administrators manage the software that is installed on their systems.  How hard would it be to come up with a solution that other developers could hook to help with centralizing the management of updates and provide a significant positive impact on the overall security of every computer on the Interweb?  Although the design, development, testing, implementation, and maintenance of this project would be challenging, I am willing to be that this would be a small project in the grand scheme of Microsoft OS development.  They don&#8217;t need to take every software vendor into consideration, they just need to come up with one method all of them could use.  Once a system is developed software developers can start modifying their products to hook the console.  They wouldn&#8217;t need to take out their current auto-update mechanism, rather, they could leave it in place.  This is how the &#8220;Add/Remove Programs&#8221; console works.  Software developers have not removed the mechanism to uninstall from their software, rather, they have placed hooks in the &#8220;Add/Remove Programs&#8221; console that calls their uninstall and repair mechanism.  Users and admins who prefer a particular method are all satisfied.</p>
<p>Finally, it is not like this is not done other places.  Linux in particular, and to a smaller context Apple, has been doing this for a while.  Most distros have a packaging system the allows developers to centralize the patch management and automatic updates.  End users and admins only have to worry about watching for updates to software that they have installed outside that packaging system.  Very nice, very ease, very secure.</p>
<p>So, how about it Microsoft?  Don&#8217;t you think that this would benefit everybody?  It certainly could not hurt.</p>
<p>Go forth and do good things,<br />
Cutaway</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/Microsoft" rel="tag">Microsoft</a>, <a href="http://www.technorati.com/tag/Apple" rel="tag">Apple</a>, <a href="http://www.technorati.com/tag/updates" rel="tag">updates</a>, <a href="http://www.technorati.com/tag/patches" rel="tag">patches</a>, <a href="http://www.technorati.com/tag/automatic+updates" rel="tag">automatic updates</a>, <a href="http://www.technorati.com/tag/patch+management" rel="tag">patch management</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/191/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Let&#8217;s All Get Together</title>
		<link>http://www.cutawaysecurity.com/blog/archives/20</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/20#comments</comments>
		<pubDate>Thu, 06 Apr 2006 11:05:26 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Virtual Machines]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/20</guid>
		<description><![CDATA[Dual Booting Mac and Windows.  SWEET!]]></description>
			<content:encoded><![CDATA[<p>Finally, we are going to be able to merge the most popular operating systems onto one machine (well, almost all of them).  Although I haven&#8217;t looked into it <span class="post-footers"><a title="Apple giving in to public pressure, creates Boot Camp" href="http://www.mckeay.net/secure/2006/04/apple_giving_in_to_public_pres.html">Martin McKeay points</a> out that Apple is now going to support dual booting on their Intel machines.  Apple&#8217;s <a title="Boot Camp" href="http://www.apple.com/macosx/bootcamp/">Boot Camp</a> will allow a user to install Windows XP onto a live OS X system.  You just need your own copy of Windows XP and about 10GB on your hard drive.  </span></p>
<p>LET THE RACES BEGIN!!  It is only a matter of time until we see this with the capability to also install Linux.  Of course the guys over at <a title="CyberSpeak Podcast" href="http://cyberspeak.libsyn.com/">CyberSpeak Podcast</a> have recently pointed out (I think it was the <a title="CyberSpeak Mar 25, 2006" href="http://cyberspeak.libsyn.com/index.php?post_id=73444">March 25th edition</a>) that the Holy Grail is to be able to switch seamlessly between the systems without needing to reboot to the other operating system.  Now, I will definitely by stock in the company that comes out with that feature.</p>
<p>This definitely has great implications for the security professional.  Although vitual systems are reliable and very handy, vulnerabilites are going to be serious issues in the future.  In the same episode (if I remember correctly) the guys at CyberSpeak mentioned that there is malware out there that avoids deploying itself in virtual environments.  How long before they leverage this for exploits and viruses on the child and parent systems.  Besides, although the software version of <a title="VMWare Server" href="http://www.vmware.com/download/server/">VMWare&#8217;s Server Beta</a> edition is free (as in registration), not everybody can afford a system that can handle multiple virtual operating system running at the same time in a smooth fashion.</p>
<p>Now I just need to get a Mac. Can somebody talk to my wife about it?<br />
Cutaway</p>
<p>Edit: More detailed information can be found at <a title="Macs running Windows, what you should know" href="http://www.hackinthebox.org/modules.php?op=modload&#038;name=News&#038;file=article&#038;sid=19772">Hack in the Box</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/20/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSX Serious Security Concern</title>
		<link>http://www.cutawaysecurity.com/blog/archives/5</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/5#comments</comments>
		<pubDate>Tue, 21 Mar 2006 05:21:25 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/?p=5</guid>
		<description><![CDATA[A friend of mine recently informed me that he was considering the switch from Windows to Macintosh. Now, if this friend of mine were a computer geek, or a graphic artist, or even somebody who like messing with new things, I might not have been concerned. However, none of these things are the case. My [...]]]></description>
			<content:encoded><![CDATA[<p>A friend of mine recently informed me that he was considering the switch from Windows to Macintosh. Now, if this friend of mine were a computer geek, or a graphic artist, or even somebody who like messing with new things, I might not have been concerned. However, none of these things are the case. My friend&#8217;s sole reason for switching is because Apple&#8217;s Macintosh computers do not get viruses.</p>
<p>Unfortunately this type of attitude happens a lot around uninformed technology users. They are not aware that security is more than just a perception with a pretty case. It is a complex organism that consists of the operating system, applications, hardware, and firmware. The integrity of each one of these affects that rest. Here are a few examples that persons switching to a Macintosh based system should consider before making the move based on this logic.</p>
<ul>
<li>The recent move of Apple to Intel based chips exposes these systems to an area of technology that has been heavily researched by hackers and malicious users for years. Their knowledge of these types of systems will speed up the development of exploit code for newly discovered vulnerabilities. Additionally, because Macintosh programmers are moving from the world of PowerPC to Intel x 86 there is potential that they will make mistakes that have already been discovered and, possibly, exploited. See Paul F. Roberts January 26, 2006 article at eWeek.com for more information about this concern.</li>
<li>The very recent and extremely serious vulnerability in OS X proves that even the best programmers, on what many consider to be a very secure operating system, can make huge and dangerous errors. The Handlers at the SANS Internet Storm Center cover this topic very well. All Macintosh owners should review this writeup and update their systems immediate once a patch for this security concern is available.</li>
<li>Macintosh users that choose (or are forced) to use programs from the Microsoft Office Suite are subject to all of the Macro Viruses that affect their Microsoft Windows brethren. Although the ramifications may be different the potential for evil and destruction remains. Knowledge of this goes way back as can be seen in an old CNET article on this subject, aptly named &#8220;Security flaw in Microsoft Office for Mac,&#8221; from April 16, 2002.</li>
<li>Network Windows and Macintosh computers together is not for the non-computer savy user. Although there are many sites that help overcome this problem the details can be a bit complicated and cumbersome (i.e. not for the keyboard challenged).</li>
<li>There are Trojan Horse programs in the wild that specifically target the Macintosh OS X operating system. A staff writer for MacNewsWorld wrote about this in the article titled &#8221; Mac Trojan Masquerades as MS Word Installer&#8221; that was published on May 13, 2004.</li>
</ul>
<p>Hopefully, anybody out there considering making the switch from Windows to Macintosh will have a good reason to do so. The Macintosh systems are very good and personally I believe in the moto, &#8220;The right tool for the right job.&#8221; If a Macintosh is the right tool for the project you are working on then, by all means, make the switch. However, don&#8217;t go through all of the pain and suffering just because somebody (who doesn&#8217;t know what they are talking about) told you that they don&#8217;t make viruses for these systems. You just may be sadly mistaken.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
