Apple security is 'struggling,' researcher says - Laments lack of 'formal security program'
That is the title of an article that was released today by The Register.
Written By Dan Goodin in San Francisco • Get more from this author
Posted in Anti-Virus, 9th June 2009 00:52 GMT
This is a good read with the most notable quote IMHO being:
"Based on a variety of sources, we know that Apple does not have a formal security program, and as such fails to catch vulnerabilities that would otherwise be prevented before product releases," writes Rich Mogull, founder of security firm Securosis and a self-described owner of seven Macs. "To address this lack, Apple should integrate secure software development into all internal development efforts."
This is so interesting because Microsoft has had a Secure Development Lifecycle (SDL) for 7 years. That is like a millennia in the IT world! You can read Bill Gate’s email on the subject from July 2002 here.
Seems odd that a product (MAC OS) that has such a cult following has NEVER really cared if the OS was secure. I realize they are not the biggest target, but their market share is growing and they REALLY need to get this under control. Dan Goodin and the researcher referenced,Rich Mogull, both criticize Apple heavily in this article and Dan actually sites Microsoft as an example when he states:
Microsoft was among the first companies to integrate an SDL into its internal development routine. Under the program, products are built from the ground up with security in mind, so that poorly written sections of older code are replaced with code that can better withstand attack. It also subjects programs to a variety of simulated attacks.
I appreciate him giving credit where credit was due. Maybe this will put a *** in Apple’s armor (marketing brilliance), but I doubt it. It will take a massive hit like a Nimda, CodeRed, or Blaster scale issue confined to Macs. …That is too bad.
The article points out many areas where Apple need to beef up its security efforts. Take the time to read this one!
The last points are that Apple needs SDL and should create a Security Exec to handle all this. When Bill Gates stated our Trustworthy Computing model back in 2002, he was laughed at by people like Larry Ellison. Now researchers realize it was important! Oh how the world changes!
Cheers,
Woody
Technorati Tags:
Security,
AV,
Anti-virus,
Apple,
Safari,
Java,
Macintosh,
Mac,
SDL,
The Register,
Dan Goodin,
Rich Mogull,
Securosis,
OSX