MacNewsWorld Interviews Discoverer of OS X Browser Flaw
MacNewsWorld Interviews Discoverer of OS X Browser Flaw
by , 8:00 AM EDT, May 20th, 2004
MacNewsWorld has posted an interview with the discoverer of the recently publicized OS X browser flaw. According to the discoverer of the flaw, "lixlpixel," Apple was informed of the flaw back in February 2004, but has done nothing about it as of yet. After waiting for two months, he says he decided to post information about the flaw to a Swiss Web site, which was then picked up by security firm Secunia. From MacNewsWorld:
In an exclusive interview Wednesday, lixlpixel told MacNewsWorld that, after waiting on Apple's reply, he finally posted the advisory to a Swiss Macintosh Web site.
"This is how Secunia picked up on the vulnerability," lixlpixel said, adding he had not contacted Secunia directly.
"Just by the nature of the Internet, this post took off," he continued.
"I was building a site where PHP and AppleScript work together to achieve what I wanted. That's when I discovered that you could start applications on the Mac via [a] URL," lixlpixel said.
"Of course that's no big deal, but then I realized that if you knew the location of the downloaded program on the user's machine, it gets more dangerous. That's why I notified Apple."
You can read the full article at MacNewsWorld's Web site, and we recommend it as a very interesting article.
The Mac Observer Spin:
A number of Observers had questions about how and why this flaw was made public, and this interview answers most of those questions.More importantly, we are concerned about Apple's alleged lack of response to lixlpixel, though we obviously don't know Apple's side of things. If true, however, it brings up ugly comparisons to Microsoft, a company long known for ignoring similar security notifications until public pressure and the massive Windows virus/worm problem forced the company to pay attention.
Certainly Apple's record is far, far better than Microsoft's, but it may take a bit of public pressure from the Mac installed-base to keep it that way.
Observer Comments
Usually I have nothing but good things to say about Apple, but as of late they seem to be dropping the ball when it comes to a few different things. This security hole is a huge deal. I don't need somebody comandeering my machine. Apple's hardware line has also seen some negativity in regard to quality. iBook recalls are no fun. Last but not least, everybody knows about Apple's crappy advertisement campaign for their beautiful OS. If Apple could pick up the pace on these things and not get negative press for them, I think they could increase huge in market share and installed user base.
Thu May 20, 2004 9:25 am Subject: Yet Another Apple Bad News Story - See A Trend
Thu May 20, 2004 9:50 am Subject: Thing is, they could have done this really quickly
Sure, they would have broken the integration of their help system, but the actual security concern could have been addressed very very quickly simply by pushing out a security update that did what every responsible user has already done: assign a harmless default application to the help protocol Even better, it would trigger an alert with the option to open help viewer and run the script, open help viewer but not run the script, or not open help viewer at all. They could have protected everyone in late February and looked really responsible in the process. It was a win-win.
Thu May 20, 2004 10:16 am Subject: Fixing One Problem But Creating Another
Although it seems like introducing a quick fix would have been the right way to go, I've too often seen a Microsoft security patch break an otherwise working system.
Fortunately, thanks to the responsiveness of the Mac community, information on how to protect one's system against this exploit has been spread almost as quickly as the news itself.
There is considerable discussion on this over at Macintosh News Network, with lixlpixel joining the discussion. What is NOT clear, however, is just HOW lixlpixel notified Apple. There is a specific location on Apple's website for contacting Apple about security issues, but as of yesterday AM lixlpixel has not acknowledged using that method. As such, a normal email to Apple may go unoticed by Apple for quite a while, thus explaining the delay.
I'm not an Apple apologist, but one would think that when finding a flaw this dangerous, one would at least navigate the Apple web site.
From the second page:
quote:
Originally posted by lixlpixel:
do you really believe i would make that public without telling Apple ?
I LOVE APPLE
i can't sleep since i did it - i only did it because of so many "new" (more or less serious) exploits for the Mac surfaced.
(and because Apple didn't respond on my bug report for over two months)
Excuse me, but you sent a BUG REPORT??? That bug report is probably buried deep in some developer's to do list and haven't been read by the right people yet.
Contact Apple directly at product-security@apple.com
NOW!!!!
Next time someone feels they have to make a security hole public because Apple didn't respond to your e-mail, bug report or something like that, please read this page first:
http://www.info.apple.com/usen/security/index.html
-End quote-
Now please excuse me while I read the rest of the discussion.
Thu May 20, 2004 11:43 am Subject: Quick fix, no. Quick intervention, yes.
John, I'm not advocating that they offer up a quick fix, I'm saying they should have deliberately assigned a harmless default application to the help protocol. Which is the "fix" that everyone is employing. By deliberately breaking some of the system's interoperability without actually changing the functionality of the system, they would have short-circuited the negative publicity and protected their users.
Every once in awhile, the best temporary fix is to just unplug what's broken, fix it, then plug it back in.
Good point, though, Brutno, about what constitutes notification.
Posting the link for the Apple's "security flaw" email was a good idea. I have a question though. I went to www.apple.com and then tried to navigate my way toward the link provided (as I am assuming lixlpixel must have done) and I could not find the link. Doing an advanced search of the site for "submit security product" failed as well. How would you intuitively navigate to this security page? i.e. what obvious thing did I miss? I ask for a simple reason... if I didn't miss something simple and this page is very difficult to find, then Apple is making it difficult for security issues to be brought to their attention. Thanks!
Dave
Thu May 20, 2004 1:40 pm Subject: How to contact Apple
Good question, Dave.
Use this path:
Apple(home):Support(tab at top of page):MoreResources(bottom left of page):Contacting Apple About Product Security Issues.... yields this page:
http://www.info.apple.com/usen/security/index.html
You are correct - it is NOT easy to find, took me about three minutes, but certainly worth the effort.
Thanks for asking!
lilpixie should know that you can't go down to the Apple Store and tell the blonde chick at the Genius Bar. I know, I know, if there is a blonde chick at the Genius Bar, she's sucking up all her pride to land the genius guy so she can afford implants, but work with me here!
lilpixie also should know that you can't report these issues to security guards at MacWorld. The security guards are only at the show to ensure that vendors do not take work away from union contractors by standing on foot-stools to plug in lamps or being over 5'11" and able to reach the lamps without assistance.
Finally, lilpixie should know that he can't report security problems in a major operating system to the lady who runs the computer lab at his elementary school. She is a nice lady, stays on top of the latest trends like System 7 and Windows 95, is a demon in bed with her husband the PE specialist, but she doesn't know $%^% about Mac OS X security!
Signed,
A real script kiddie
Thanks for the reply! I must be blind, and I feel silly for apparently missing something so obvious, but I am still unable to find the site via normal browsing methods. I can find it if I go to the Support tab and then go to the site support map link. I cannot find it simply by browsing. I do not even see the "more resources" link you had mentioned. I posted a screen shot of the support page on http://homepage.mac.com/stevejcowen/PhotoAlbum5.html just to see if maybe by doing so you (or someone else) can give me specifics on where the "more resources" link is. I am going to all of this trouble because I really am curious as to how difficult it is for someone to find the security page on Apple's web site. If it is as hard for people as it has been for me then I think Apple is being irresponsible at worst and just difficult to send security flaws to at the best. It seems like the security flaw email address should be on Apple's contact page as well. Anyway, thanks in advance for the reply, as well as being so helpful up to this point.
Dave
Thu May 20, 2004 5:00 pm Subject: RC: your god has spoken
QuoteRealityCheck wrote:
now that Apple's market share is less than 2%, the death spiral is tightening
MS just commented they have a user base of 7 million for Mac Office. That's paying customers. Most people I know just copy the CD's from their friends.
About half of the 70 million iTMS sales are done by mac users.
Apple virtually controls the video/movie market on the software/hardware side. It brings in a $#!% heap of money and prestige. The same goes for the professional music market.
The majority of the DTP market still relies on Apple.
And the percentage of home users is way beyond 2% "market share". In fact, when you factor in the fact that most "non creative" offices don't have macs, the 2% becomes a very respectable figure for the home market.
I know, feeding the ugly, stupid troll...
Thu May 20, 2004 6:40 pm Subject: How to Contact Apple - Updated
Dave, (and anyone else...)
Oops! Missed a few links. Here is the revised path:
Apple(home):Support(tab at top of page):Support Site Map (very bottom of page in small print):AppleProduct Security(far right under Site Tools & Services):
Above path yields this page where you will find the link:
http://www.info.apple.com/usen/security/index.html
Sorry about the miscue!
Again, difficult to find - you would think there would be a "Security" link on the Home page, but then again I am sure many people would submit items that were not *really* security issues. This is four steps, better than some sites, however.
Hope this helps, and I hope the website voodoo priests don't mess it up again!
Fri May 21, 2004 10:01 am Subject: Another Fix
Here's another goodie called Paranoid Android that can help guard against URL-based attacks. Once Apple does repair the exploit, this may be something you'd still like to keep around, just to know what is going on with your system:
http://www.unsanity.com/haxies/pa
Comments are currently closed. Please email the author instead.
Recent Headlines - Updated November 22nd
- Fri, 7:07 PM
- Games - Soccer Sim Championship Manager 2010 Released for Mac
- 6:47 PM
- Games - EA Publishes Original Monopoly for iPhone
- 6:15 PM
- News - Original Apple I on Ebay for $50K, w/Letter from Steve Jobs
- 6:11 PM
- Games - New iPhone Games: Secret of the Lost Cavern Ep 1, New DJ Nights, More
- 5:47 PM
- Games - Star Trek D-A-C Game Headed to the Mac Next Month
- 4:57 PM
- Product News - TidBITS Releases “Take Control of Syncing Data in Snow Leopard”
- 4:26 PM
- John Martellaro's Blog - Particle Debris (week ending 11/20) Stationery Pads Go Poof
- 2:59 PM
- Free on iTunes - Musée du Louvre, Art Lite, SketchBook Mobile X and More.
- 1:50 PM
- Deal Brothers - Acer P215H bmid 21.5” Widescreen LCD Monitor: $139.99
- 11:24 AM
- TMO Appearances - Jeff Gamet Shares More Holiday Gift Ideas on MacJury
- 10:43 AM
- Product News - Cocktail 4.5 for Leopard Adds QuickLook Cache Clearing
- 10:06 AM
- News - Hack Enables Mac OS X 10.6.2 on Netbooks
The Mac Observer Reader Specials
- TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
OWC: Mercury On-The-Go FW800+USB2 up to 1.0TB. Bus Powered, no external power supply needed. Macworld Editors Choice, CNET Very Good Starting from $99.97, 500GB $159.99. Click here
If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.

