Security experts knock Apple for not patching DNS bug
Apple Inc. has not yet patched a critical Domain Name System (DNS) bug in its Mac OS X operating system, analysts and security researchers noted today as some criticized the company for dragging its feet.
"It's not sending a real good message," said Rich Mogull, an independent security consultant and former Gartner Inc. analyst. "If they don't patch this in a reasonable time, they're putting their customers at risk."
Apple, which integrates considerable open-source code into its operating systems, relies on BIND (Berkeley Internet Name Domain), created by the Internet Systems Consortium (ISC), for its DNS components. ISC patched BIND July 8, but as of today, Apple had not released an update for Mac OS X.
According to Dan Kaminsky, the researcher who uncovered the DNS flaw in February and helped coordinate a multivendor patch effort, Apple was told of the vulnerability before patches went public. "They were notified at some point," said Kaminsky, who did not name a date. "They were given a heads-up."
Approximately a month after Kaminsky discovered the vulnerability, representatives from several major developers, including Cisco Systems Inc., Internet Systems Consortium (ISC) and Microsoft Corp., met at the latter's Redmond, Wash., headquarters to discuss how to handle the bug. "In the Spring it was all about [vendors] who write DNS code, at its core it was about people who write name servers," said Kaminsky. Companies he called "second tier," those that "ship name server code that others write," were not part of that March meeting at Microsoft. Apple, he added, was one of those second tier vendors.
Calls to patch grew louder last week, however, after other researchers guessed some of the bug's technical details. Two days later, attack code went public.
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
On Twitter now
DNS flaw
Powered by Twitter
jfruh
Apple syncing patent can't come soon enough
pasmith
New Twitter features borrow from 3rd party clients
Esther Schindler
Open Source Changes the Software Acquisition Process
mikelgan
How to set up continuous podcast play on the new iTunes
David Strom
Five important Windows 7 mobility features
sjvn
Guard your Wi-Fi for your own sake
Sandra Henry-Stocker
Grepping on Whole Words
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.













> Storms saw the bright side
> Storms saw the bright side of Apple not patching the DSN bug,DNS, not DSN.
Proof-read, people.
Thanks for the head's up.
Thanks for the head's up.