Security Researcher Slams OS X For 'Ancient Flaws'

Mr. Archibald added that Apple has left its code “relatively under-audited, which leaves a lot of low-hanging bugs.” As an example, he cited the now-patched “dsidentity” bug, which affected Mac OS X v10.4. It “could have easily been exploited to grant a non-privileged user with admin rights and allow that user to create and remove root user accounts,” Mr. Kotadia wrote.

Another flaw that remains unpatched “could allow memory corruption and hand control of a process over to an attacker,” according to Mr. Kotadia. Mr. Archibald said that Apple is aware of that flawis existence but has been slow to respond to it. “It expects security researchers to wait indefinitely to release the vulnerabilities and offers no incentive for them to do so,” the security researcher said.

In the long-term, he added, “Appleis impressive security record is likely to be tarnished if the company continues to grow its market share while undervaluing security researchers and not properly auditing its code.” The security problems exist in both the Intel and PowerPC versions of Mac OS X, Mr. Archibald noted.

An Apple spokesperson told Mr. Kotadia that the company wonit “comment on what other people say about Mac OS X.”

Thanks to The Inquirer for the link.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.