Hacker Read top | best | new | newcomments | leaders | about | bookmarklet login

There's the iTunes hack, the SSL bug.

Apples security record is not better than say, Adobe



sort by: page size:

Apple Software is not secure either. Apple has just marketed themselves as being more secure.

https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d...


Software is written by people and organizations made of people.

Security issues are precisely because of that.

Rather than focusing on bug we ought to focus on how it was handled. And, in this case it was obviously poorly addressed.

So let's focus on that, not on "iOS/MacOS is superior" because it is not (it is not free from flaws).


The issue is Apple's security standards.

Apple's performance here is inexcusable for a software company. It displays either a complete disregard or a complete lack of understanding of basic security.

Do we know that Apple announces (and gets CVEs for) vulnerabilities that they find and fix internally? If not, the comparison is not meaningful.

There is a reputation of Apple being more secure, but it's largely unfounded. It just looks that way because the ecosystem is completely locked down and software isn't allowed to exist without apple's stamp of approval.

macOS is definitely less secure than iOS.

You're not entirely wrong. For a proprietary, closed-source, limited-access system that Apple has complete control of, it's surprisingly vulnerable and slow to be patched.

Apple has as many kernel exploits as any other, software is not perfect. macOS has a long history of many many security patches in point releases, sometimes the release notes run into the tens of pages.

The point of view you should take is that the company that doesn't issue security fixes (or issues very few comparatively) is the one you should be worried about: They are not better, they just don't fix anything and leave you vulnerable instead.


why hasn't apple fixed these security gaps / defects ?

Interesting to note that both Apple vulnerabilities listed exist only for their Windows software. (QuickTime: http://lists.apple.com/archives/security-announce/2012/May/m... iTunes: http://support.apple.com/kb/HT5485)

I wonder if these are lower priority for Apple or if they perhaps just aren't as good when developing for Windows.


I do not know why anybody would believe any claim by Apple with respect to security without overwhelming empirical evidence supporting their claims. The default assumption in commercial software security, supported by literal decades of abject failure by every player, is that commercial software security is atrocious. To claim anything more than trivial security is a extraordinary claim and thus demands extraordinary evidence before being accepted.

Apple has demonstrated no such evidence. In fact, the opposite is the case. Despite decades of assurances that their systems provide meaningful security, every single year we see their security torn apart by individuals and small teams with budgets that do not even constitute rounding errors to a Fortune 500 company. There is exactly no reason to believe they have meaningfully superior technical expertise with respect to security relative to the default standard of the industry.

However, this should be no surprise to anyone as the security certifications that Apple advertises for iOS [1][2] are only “applicable where some confidence in correct operation is required, but the threats to security are not viewed as serious.” [3][4]. I mean, look at [4], the process used to certify their security is that their evaluators typed search terms into the internet and verified that every vulnerability that turned up was patched, that’s it. There is no requirement to even do a independent analysis that it protects against attackers with a basic attack potential, that is done at the next higher level of security that they could have chosen to certify against, but did not.

To be fair, Apple has historically demonstrated the ability to certify against AVA_VAN.3 which demonstrates resistance to attackers with a enhanced-basic attack potential, but they have failed every time they have ever attempted to certify against AVA_VAN.4 which demonstrates resistance to attackers with a moderate attack potential. It should be no wonder that they can not protect against moderate attack potential threats such as individuals or small teams, let alone high attack potential threats such as large organized crime and nations.

If Apple wants their security claims to be taken seriously, they should start by demonstrating their ability to protect against moderate attack potential threats via the internationally recognized security certification process they already use and advertise. Until then, the only thing we should trust is what they certify they can do (protect against script kiddies), not what they have failed to ever achieve in a auditable manner (protect against moderately skilled attackers).

[1] https://support.apple.com/guide/sccc/security-certifications...

[2] https://www.niap-ccevs.org/Product/Compliant.cfm?PID=11146

[3] https://www.niap-ccevs.org/MMO/Product/st_vid11146-aar.pdf#p...

[4] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3...


A lot of these security issues have lead to fixes that have had a negative impact on performance. There's no way that hasn't bothered Apple.

I think it's clear that Apple security hasn't been as good as everyone would like. Remember the disastrous Mac OS login bug?

what embedded security screwups has Apple had? (Not asking because I don't believe you, rather because I can't think of any)

I would argue that handling security problems in general has not been Apple's strength historically.

I agree that failing to fix a problem like this in a timely fashion is bad, but sins of omission are generally judged differently than sins of commission, for better or worse. Apple failing to apply proper prioritization to security holes isn't the same as Apple collecting data to be sold to the highest bidder.

So, again, Apple should not be treated as equivalent to Google and Facebook. Feel free to judge them harshly, but don't paint them with the same brush.


I wish Apple would just fix the myriad ordinary bugs, let alone focus on security.

False - Apple has no significant history when it comes to security breaches.

It really feels like the only thing that made Apple to be less prone to hacking and malware (and therefore more secure) than other OS is the lack of scrutiny by hackers and malware authors. This is a front door open kind of problem.
next

Legal | privacy