The Mac Observer

Analyst: Microsoft Putting Mac Security at Risk

TMO Talk (10)

Microsoft released a security patch for the Windows version of PowerPoint while announcing that the Mac OS X version of the patch won't be out for a few more weeks, prompting Internet Storm Center analyst Swa Frantzen to call the company to task. Microsoft's actions, he claimed, could give hackers information that helps them design PowerPoint-based attacks on the Mac.

"We all know from past experience the reverse engineering of patches back into exploits starts at the time -- if not before -- the patches are released," Mr. Frantzen said. "Typically it takes between hours and a few days or so to complete this if it's easy to exploit."

In this case, the flaws could allow an attacker to run arbitrary code on a user's computer by tricking them into opening a maliciously crafted PowerPoint file.

Microsoft security engineer Jonathan Ness defended the move by saying "We normally do not update one supported platform before another, but given this situation of a package available for an entire product line that protects the vast majority of customers at risk within the predictable release cycle, we made a decision to go early with the Windows packages."

He added that none of the exploit samples Microsoft has analyzed will reliably work on the Mac, so the company didn't see an issue with releasing information about the flaws before offering a security patch for Office 2004 and Office 2008.

Mr. Frantzen, however, doesn't see Microsoft's move as responsible. "Microsoft is the one big company screaming loudest of all over responsible disclosure," he said.

Post A Comment or Log-in. Need an account? Register here.

11 Observer Comments

   Actions ChoMomma said on May 14th, 2009 at 10:16 AM (Edited: 06/12/2009 11:00 AM):

The marketing folks at M$ told them to hold off on the Mac fix.. that way they could plan some astroturf about Macs being vulnerable to viruses.

Frankly, anyone using a Mac should be using the far-superior Keynote. It’s cheaper and better, how could you go wrong?

And ChoMamma hit it on the head. Do they actually think we believe that they need a “few more weeks” to work on the patch for PowerPoint for Mac? Please.

   Actions jbruni said on May 14th, 2009 at 11:18 AM (Edited: 05/14/2009 12:29 PM):

Indeed, why did the security bulletin even mention the Mac software if the patches weren’t available? MSFT could have just omitted mentioning that the Mac versions had similar vulnerabilities and simply issued another bulletin when ready.

we made a decision to go early with the Windows packages

...and I made a decision to avoid Microsoft software on my Mac.

I guess we’re even.

As of this two hours ago, I switched to KEYNOTE and I now wonder why I did not switch earlier.

   Actions ChoMomma said on May 14th, 2009 at 12:19 PM (Edited: 06/12/2009 11:00 AM):

Frankly, I don’t even use any part of Microsoft Office.. Word? nope.. textedit, Powerpoint? nope.. Keynote, Excel? nope..MySQL(I’m a web designer/dev..)

   Actions Gino said on May 14th, 2009 at 12:19 PM (Edited: 05/14/2009 1:42 PM):

You guys are all missing the REAL pronouncement here!

Microsoft security engineer Jonathan Ness says,

“... none of the exploit samples Microsoft has analyzed will reliably work on the Mac…”

What Microsoft is REALLY saying is what Macintosh users have known for a while. And that is that the architecture of the Mac OS X OS is secure enough that even if Microsoft releases buggy, insecure applications for the Mac, you’re still safe because you’re on a Mac.

Thank you Microsoft for re-enforcing what we’ve know all along. Hmmm, I see another “I’m a Mac, I’m a PC”, commercial in that.

   Actions ChoMomma said on May 14th, 2009 at 12:28 PM (Edited: 06/12/2009 11:00 AM):

He added that none of the exploit samples Microsoft has analyzed will reliably work on the Mac, so the company didn’t see an issue with releasing information about the flaws before offering a security patch for Office 2004 and Office 2008.

So.. then it shouldn’t be all that hard to knock out a fix/patch then eh?

Frankly, anyone using a Mac should be using the far-superior Keynote. It’s cheaper and better, how could you go wrong?

You will go wrong if you work in a windows-based corporate environment where, like it or not, PowerPoint is ubiquitous.  And no, importing/exporting to/from PowerPoint is not the same thing.  When you get all sorts of PP files from many different clients, you want the genuine software, not an ersatz version of it that makes subtle changes to your file.

Keynote is an excellent app, but it’s really only great if you that’s it’s the only thing you and your company uses.

   Actions geoduck said on May 14th, 2009 at 1:04 PM (Edited: 01/26/2012 2:46 PM):

You will go wrong if you work in a windows-based corporate environment where, like it or not, PowerPoint is ubiquitous.

That’s why I’m glad my company has gone to OpenOffice. Aside from a few accountants that need to share files with outside companies, we don’t use M$Office.

Plus aside from a single virtual environment my Mac is MS free as well. Come to think of it I haven’t used that environment in a couple of months anyway. I think I’ll trash that as well.

This is why I NEVER use Microsoft products….. EVER. Overpriced, bug ridden, bloatware.

Post A Comment or Log-in. Need an account? Register here.
 

Recent Headlines - Updated May 26th

Sat, 10:00 AM
MacOS KenDensed - MacOS KenDensed: Apple’s Patent Lawsuit & Antitrust Shuffle
Fri, 5:58 PM
News - Sotheby’s to Auction Steve Jobs Atari Memo (Photo Gallery)
5:42 PM
Free on iTunes - 3 Free iOS Apps for News Hounds
3:00 PM
Rumor - Nest Thermostat Reportedly Coming to Apple Retail Stores
2:40 PM
Particle Debris - The TV Industry’s Dreadful Little Secret
2:33 PM
News - Mobile Devices Account for 20% of Web Traffic in US, Canada
12:49 PM
News - Apple Now Offering “Free App of the Week” for iOS
12:21 PM
News - Tim Cook Declines $75 Million Dividend Payout
11:25 AM
News - Absinthe 2.0 Provides Untethered Jailbreak for iOS 5.1.1
11:09 AM
Quick Look Review - F18 Carrier Landing (iOS) is a Boatload of Fun
10:51 AM
TMO Appearances - Jeff Gamet talks Cool Apps & Accessories on Not Another Mac Podcast
10:12 AM
Hot Forum Topic - Forum Poll: Which is Your Favorite Photo Sharing Service?
 

The Mac Observer Reader Specials

  • Macsales.com SuperSpeed SSDs from $58. Transform your Mac with an SSD Solution of up to 960GB! You won't believe it's the same machine! Once you experience an OWC SSD, no going back! - Macsales.com
  • Mac RAM Upgrades: MacBook Pro 16GB kits $475, 8GB Kits for $119.99! iMac 16GB RAM Kits (4x 4GB) for $229.99! Mac Pro Memory 32GB Kit for $399.99, 64GB Kit for $889.99! Mac Hard Drives 2TB Seagate SATA II for $249.99! Click Here!
  • Macpokeronline.com If you're using a Mac, then you've gotta check out PokerOnAMac.com. Online casinos and poker rooms are literally giving away cash and the casino sites at Poker on a Mac do the unthinkable, they actually reward! Join today, the download is free!
  •  Looking to find online casinos for mac? We can help you find the best real money casino sites where you can play your favorite casino games including blackjack and slots.

Apple Stock Quote (AAPL)

Loading...

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal