Site News
Current section

March 5, 2010

The Best Keylogger Review added!

World news

September 18, 2009

Microsoft Internet Explorer SSL security hole lingers

Conservatives call for DNA databases to be reduced

McAfee warns of bogus security suite

Security market remains buoyant in choppy waters

The good and bad of government in the cloud

Vista, Windows 7 Are More Secure than Snow Leopard

Will Google's Buy of reCAPTCHA Hurt Internet Security?

HHS guts health-care breach notification law, groups warn

Man gets 15 months for E-Trade skimming scam

Sophisticated botnet causing a surge in click fraud

Microsoft sues scareware scammers

Software company fined for trading with the enemy

Misdirected spyware infects Ohio hospital

Firefox's Flash check drives 10M to Adobe's download

Microsoft, Yahoo in informal talks with EU over search deal

Newsletter
E-mail: 
Subscribe
Send to friend
E-mail: 
Send
Voting

Would you prefer to have 1 product that can fight both viruses and spyware or a specialized product for every threat?

1 multifunctional product
2 specialized products
VotingView results

September 18, 2009

Vista, Windows 7 Are More Secure than Snow Leopard

Apple may be spending millions on ads touting that Macs are safer than Windows-based PCs, but a prominent security researcher claims that released Snow Leopard is less secure than either Vista or Windows 7. It's time for Apple to spend serious money on security, rather than marketing.

Computerworld reports that security pro Charlie Miller of Independent Security Evaluators, and co-author of the Mac Hacker's Handbook and the winner of two consecutive "Pwn2own" hacking contests claims that "Snow Leopard's more secure than Leopard, but it's not as secure as Vista or Windows 7."

Computerworld reports that Miller claims that

Apple missed a golden opportunity to lock down Snow Leopard when it again failed to fully implement security technology that Microsoft perfected nearly three years ago in Windows Vista.

The security hole that Miller says Apple ignored, according to Computerworld, is address space layout randomization (ASLR) which "randomly assigns data to memory to make it tougher for attackers to determine the location of critical operating system functions, and thus make it harder for them to craft reliable exploits."

Miller complains that Apple didn't bother to address the issue in Snow Leopard, saying

"Apple didn't change anything. It's the exact same ASLR as in Leopard, which means it's not very good."

This isn't the first time that Miller has called Apple to task for its lack of interest in security. Two years ago, he and several other researchers criticized Apple's release of Leopard because it also didn't do anything about ALR. He said, according to Computerworld:

He does say, though, that Apple did plug some other security holes with Snow Leopard, including some in QuickTime. And he is pleased that Apple revamped DEP (data execution prevention), which is a security technology used in Vista.

Miller adds that for now, a Mac user is much less liable to get attacked than a Windows user, but that's not because Snow Leopard is more secure than Windows. In fact, he says, it's less secure than either Vista or Windows 7. There simply aren't enough Mac users to make it worth hackers' efforts to attack Macs, he says. Computerworld quotes him as saying:

"It's harder to write exploits for Windows than the Mac, but all you see are Windows exploits. That's because if [the hacker] can hit 90% of the machines out there, that's all he's gonna do. It's not worth him nearly doubling his work just to get that last 10%."

As I've said before, it's time for Apple to finally get serious about security. It's willing to spend millions for ads touting what it claims is the Mac's superior security to Windows machines --- but not willing to actually do the work to make sure that's really the case.



Source: PCWorld



All news for September 18, 2009:
20:13Microsoft Internet Explorer SSL security hole lingers
20:11Conservatives call for DNA databases to be reduced
20:09McAfee warns of bogus security suite
20:08Security market remains buoyant in choppy waters
20:07The good and bad of government in the cloud
20:05Vista, Windows 7 Are More Secure than Snow Leopard
20:04Will Google's Buy of reCAPTCHA Hurt Internet Security?
20:01HHS guts health-care breach notification law, groups warn
20:00Man gets 15 months for E-Trade skimming scam
19:59Sophisticated botnet causing a surge in click fraud
19:59Microsoft sues scareware scammers
19:58Software company fined for trading with the enemy
19:58Misdirected spyware infects Ohio hospital
19:57Firefox's Flash check drives 10M to Adobe's download
19:55Microsoft, Yahoo in informal talks with EU over search deal



All news for September, 2009
All news for 2009 year


DONATION: www.anti-keylogger.org and www.keylogger.org is an independent research projects supported by a team of enthusiasts. If you find this project useful and would like to help foster its continued development, please consider making a donation.
donate

Thanks in advance for your support!