Analyst: Mac Java Hack Signals Big Trouble

By Tom Kaneshige, CIO.com |  Security, java, Mac OS X Add a new comment

Last week, security researcher Landon Fuller posted attack code for a Java vulnerability in Apple's Mac OS X that hackers can use. "Due to the fact that an exploit for this issue is available in the wild, and the vulnerability has been public knowledge for six months, I have decided to release my own proof of concept," Fuller wrote on his blog.

A security update for Mac OS released two weeks earlier didn't include a patch. Apple now says it is aware of the issue and working on a fix. Security vendor SecureMac advises people to disable Java in their browsers until Apple fixes the problem.

[ Learn the details of the Java security hole in Mac OS X. | Apple's delay in fixing the problem prompted one hacker into action. ]

It's this kind of nonchalant attitude toward serious security problems that analysts like Jon Oltsik, Mac security analyst at the Enterprise Strategy Group, say is making them a bit irritated. He advises Apple to change its ways before it's too late.

Apple has until now gotten away with a lackluster response to security largely because Mac OS X (and Safari browser) flew under the radar of many hackers, he says. But as the platform rises in popularity, says Oltsik, hackers will soon take dead aim if they haven't already.

Oltisk talked with CIO.com about the impact of this security hole, as well as the potential fallout from what he calls Apple's cavalier approach to fixing such problems.

How serious is this Java vulnerability?

Oltsik: The vulnerability could be used to run a rogue executable, so it is very dangerous. It certainly simplifies the process of writing a malicious Mac exploit. I haven't yet seen malicious code "in the wild" that takes advantage of this vulnerability, but one could pop up anytime.

How can enterprises protect themselves?

Oltsik: Most enterprise Macs are protected with security software that could be updated with a signature or re-configured to block an exploit. Large organizations should be somewhat protected. Consumers and small businesses are more at risk.

What do you think about the actions of Landon Fuller?

Oltsik: I always equate security professionals with physicians in that they live by their own version of the Hippocratic oath. If a physician is on the scene of an accident, he or she feels a sense of duty to help. Likewise, a security professional feels the need to speak out about vulnerabilities and risks. When researchers are ignored, they often feel like their only recourse is to go public. Some people question these tactics, feeling that this could encourage attacks, but I don't share this opinion.

What's the fallout from Apple's slow response to security threats?

Oltsik: All software has vulnerabilities including Mac OS X. What is surprising is Apple's somewhat cavalier attitude toward fixing the problem. I can't say why Apple did not address this vulnerability sooner. I will say that I find Apple's behavior toward security curious to say the least. Apple publicly takes shots at Windows security, yet its security practices seem a bit ad hoc.

I've long believed that Mac OS X will soon suffer the type of exploits that Windows has seen, and Apple will find itself eating a big piece of humble pie. Mac OS was never an attractive target in the past. It is now.

How concerned are you about Apple's security measures? Send me an email at tkaneshige@cio.com. Or follow me on Twitter @kaneshige. Follow everything from CIO.com on Twitter @CIOonline.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question