Experts slam Mac OS X security

Info Sec: "Apple has a very long way to go when dealing with security issues in their products"

An expert who claims to have a created a fully armed worm for the Mac OS X operating system has put the boot into security measures taken by programmers at Apple .

The worm exploits an mDNS flaw in Mac OS X's Bonjour network configuration tool which normally enables users to share printers, or automatically see other iChat AV users on the same network. The worm was created by an anonymous security expert at info Sec who posted details of the exploit on the Info Security Sellout blog.

Although the expert is keen to point out that he/she will eventually work with Apple to ensure the problem is fixed, they have some stinging comments to make about a previous Apple security fix for Bonjour and Mac OS X security in general.

"My worm is in the same code base, obviously, but that is where the similarity to the recently patched issues ends." the expert told Computerworld. "When Apple fixed the previous issues, they did not take care of the entire code base and there are a lot of bugs there some are exploitable, like the one I am using, while others are not. But the fact remains that Apple did a horrible job in fixing this package."

Apple has a long way to go

The expert then goes on to say:

"I do believe in being responsible and working with vendors, but I also feel that some vendors need to be treated like children and learn lessons the hard way. Apple has a very long way to go when dealing with security issues in their products."

Info Sec's comments were backed by David Aitel, chief technology expert at Immunity , another secure computing company.

Mac OS X is "horribly insecure"

Although Aitel is sceptical of any real damage the Info Sec worm might do - "Writing the exploit in one day... unlikely for anything other than a stack overflow," he also said sarcastically:

"I note that 'Infosecurity Sellout' is claiming there is another bug in mDNS which is wormable. This is obviously untrue, since there are no more remote bugs in OS X."

"No, I'm just being funny. OS X is horribly insecure."

Latest in Software
Gemini on a smartphone.
I used Gemini AI to declutter my Gmail inbox and saved myself 5 hours a week – here’s how you can do the same
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
AI writing
ChatGPT just wrote the most beautiful short story, and I wonder what I'm even doing here
Photoshop CC logo on a screen
How to make an image background transparent in Photoshop
Project Moohan prototype at Samsung Galaxy Unpacked, an XR goggles headset on display in a show area
Samsung's Android XR headset could avoid the Apple Vision Pro's biggest mistake, according to this leak
Man having Windows 11 problems with his laptop
Fed up of adverts creeping into Windows 11? You won’t like Microsoft’s latest update, then, although it does provide some important bug fixes
Latest in News
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
Elayne, Egwene, and Nynaeve dressed regally and on horseback in The Wheel of Time season 3
'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset over the Prime Video show's plot alterations
A mockup of the possible Apple M3 Ultra logo
Performance isn't the only reason you should buy Apple's M3 Ultra Mac Studio - it's reportedly one of the most power-efficient processors too
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
An Nvidia GeForce RTX 4060 Ti
Nvidia could unleash RTX 5060 and 5060 Ti GPUs on PC gamers tomorrow, but there’s no sign of rumored RTX 5050 yet