Tag Archives: apple

Black Hat and Defcon: all the drama you've been craving

Dan Kaminsky - Security researcher with IOActive

This is great, Defcon16 is a mere few days away, but already, the drama has started! Of course there’s the excitement about security guru/celebrity Dan Kaminsky discovering the DNS flaw a few months back that will be revealed this week (so that folks won’t be able to reverse-engineer them to exploit the vulnerability…ahead of time at least), but now there’s a reneg by Apple that’s sure to raise a few feathers, as well as highlight how they weren’t the most forthcoming with their DNS fix (which hasn’t hit yet even though all other vendors have released patches). In an interview, Kaminsky talks about the ‘bug’ he found in DNS, “We got lucky in this particular bug, because it’s a design flaw,” Kaminsky said in an interview. “It shows up in everyone’s network, but the fix is a design fix that doesn’t point directly at what we’re improving.” After peer review it was deemed this was indeed a huge deal, and even the original developer of BIND (the dns software in question) urged everyone to patch. “It took a couple of hours to find the bug,” said Kaminsky, “and a couple of months to fix it.” Kaminsky said he stumbled across the hole in the so-called DNS system for steering people to the websites they are seeking “by complete and total accident.” Smaller DNS flaws have been used before to “poison” the servers that send people to the numerical address of the website name they enter. [...] “This is about the integrity of the Web, this is about the integrity of e-mail,” Kaminsky said. “It’s more, but I can’t talk about how much more.” So learning more about that exploit will be very interesting, and should lead to more people investigating and deploying DNSSEC, a DNS option built with security in mind from the ground up. So there’s that, but now there’s something even more fun because it deals with a companies lack of openness in regards to their security methods. A talk at Black Hat yesterday was scrubbed at the last minute by folks over in marketing at Apple. It seems that they blocked the scheduled presentation that was, “…to give an inside look at the ultra-secretive company’s security response team. “Marketing got wind of it, and nobody at Apple is ever allowed to speak publicly about anything without marketing approval,” a Black Hat organizer told IDG News.” This is unfortunate for Apple, who are reeling after a week of beatings in the ‘blogosphere’ over their handling, or non-handling, of their update for the DNS flaw we mentioned above! “Apple’s policy of saying next to nothing about how it goes about protecting its users from escalating threats is, to say the least, unfortunate. Just last week, the company said it had patched its software from a serious flaw in the net’s address lookup system. Three days after two separate researchers warned Mac clients are still vulnerable to the flaw, Apple hasn’t uttered a word, an omission that generates confusion and doubt in those who depend on the vendor. Apple’s tight-lipped policy.” Come on Apple, you preach about how you’re ‘Open Source’, but then continue along the path of the old school hide and seek ways. Hell, people are already pointing out how their methods are less open than Microsoft’s in releasing information about security. What are they so afraid of? Ah, but we’ll learn more come Thursday, I’ll be in Vegas for my third Defcon and can’t wait. Watch for updates here, or more timely ones over at our Twitter profile.

4 reasons why Macs are moving into the enterprise

Mac, Linux or Windows?With the barriers lowering, and other market factors creeping in, Macs are slowly making a move into the enterprise.  While this may/may not solely be Apple driven, the fact is that people like choices, and the Macs are now far more compatible with other systems than they once were, so finally folks have options.  In my recent travels to Woods Hole we had ~14-15 developers from around the world, and there were 4 Macs there.  Of course we had the normal thing where someone couldn’t get something working in Windows, Mac folks would chime in with, “just works on a mac” and later when Mac folks couldn’t plug a projector into the certain Macs, the windows folks throw the, “just works in windows”, so it was all in good fun.  So while I don’t consider these folks “enterprise” as in working for a corporation, it clearly shows that more people can use what they want, and have IT adapt for their needs.  I talked to a friend up there about his MacBook Pro – it’s a beauty of a machine, and he loves it b/c he can do everything he needs, plus run windows for dev work that you can only do in Windows.  Of course if I had such a beast it’d be running Linux, and that’s my argument for my buying my Dell laptop; while the Apple is nicer, it was also ~2500$ more than the Dell.  Yes, maybe when my work buys me a ‘top I’ll rethink it – but now I’m thinking smaller again – and I really like the Xseries Thinkpads (used be by IBM, but now it’s Lenovo – but the same otherwise) and they’ve always had excellent Linux ability.  two devs in WH had those, and I had to borrow them – not to work on them, just to pick them up – nice and light, thin, but with high screen resolution.  of course for a full fledged system like thatI could also look at the MacBook which shares most of the Thinkpads features – but for a Mac I’d prefer the black MacBook after my long, drawn out suffering with my old iBook…but I digress.  Now, what was the question?  Oh yeah, more Macs in the workplace, yeah, it’s how I’ve always said it should be, and it’s more that way now.  I run Debian Linux at work now, on my work provided HP desktop machine, on my personal Dell laptop when I bring it, on my Development server, and (soon) on my production server.  What kind of support do I need from IT?  Gimme an IP and a gateway IP and I’m all set.  So, in conclusion, I believe four reasons for Apple’s success with people using more Macs at work is due to the following reasons:

Running XP on a Mac – is Boot Camp active when Windows is loaded?

bsod on an iMacToday at work someone running Windows on a Mac was having an issue communicating through the third party firewall software. The response from the third party was that they don’t support Mac, but my contention is that Mac has nothing to do with someone running Windows, after installing it via Boot Camp. I want to know the answer to this, so I’m posting it here, feel free to educate me if I’m missing something. (Note: names have been changed to protect the (non) supporting party).  So, it is my understanding that Boot Camp only installs Windows on a Mac machine (does the partitioning, installs some drivers for the hardware and guides you through installing Windows from an existing CD) after that when you boot the system you can choose Mac’s OS X or Windows, and that after choosing Windows it’s running ‘natively’ on the hardware and not under any kind of virtualization. From Apple’s site:

Boot Camp simplifies Windows installation on an Intel-based Mac by providing a simple graphical step-by-step assistant application to dynamically create a second partition on the hard drive for Windows, to burn a CD with all the necessary Windows drivers, and to install Windows from a Windows XP installation CD. After installation is complete, users can choose to run either Mac OS X or Windows when they restart their computer.

Buying a Linux laptop in 2007

Stock laptop imageIt’s time for a new laptop, as I’ve detailed, I’ve ripped apart, inserted coins and duct-taped  the old iBook back together again enough times, and it’s no longer viable. It’ll work fine on a flat surface, but if you try to use it as a laptop the minor flexing must loosen the video chip, because you quickly find your video locked, with a hard reboot the only fix. The wildcards are me as a buyer, since I’m hardly ordinary with my expectation that any laptop or desktop I’m going to buy is only going to run Linux, and the recent announcements by HP, IBM/Lenovo and Dell about their Linux support (some even pre-installed), I knew I’d finally have choices to consider. In the end I came up with a pretty current system, that Debian or Ubuntu will be 100% compatible with, and will be proud to call home. The detailed specs:

Intel Core 2 Duo T5470, 1.6GHz, 800Mhz FSB, 2M L2 Cache
15.4 inch Wide Screen XGA LCD display
1GB, DDR2, 667MHz 2 DIMM
128MB NVIDIA GeForce 8400M GS
120G 5400RPM SATA Hard Drive
Integrated 10/100 Network Cardand Modem
8X DVD+/-RW with double-layer DVD+R write capability
Integrated High Definition Audio 2.0
Intel 3945 WLAN (802.11a/g) Mini Card
Integrated 2.0 mega pixel webcam
Integrated Bluetooth
85 WHr 9-cell Lithium Ion Primary Battery

This is more system that I originally spec’d out, but the price was right, so I’m very happy.  Before I reveal which brand I picked, I’ll tell the interesting story of how I ended up with the ‘top I did, and how things compare for laptop Linux options these days, it’s an interesting ride.

NOTE: feel free to Digg this article if you like it.

80G Black iPod classic FTW!

Black iPod Classic

UPDATE: Hold the phone here, before going too gaga over the new iPods, it’s been revealed that they’ve been ‘re-engineered’ to lock out folks trying to sync their iPods using 3rd party apps, or (gasp) Linux! That’s right, they want you to use ONLY Windows or OSX and iTunes…this is ridiculous. See my post on our sister site Left to chance to learn more. This is what we talk about when we say Digital Rights, we can’t give them up now and expect to have them in the future!

Page 1 of 3123