Analyst: Mac Java Hack Signals Big Trouble
Last week, security researcher Landon Fuller posted attack code for a Java vulnerability in Apple's Mac OS X that hackers can use. "Due to the fact that an exploit for this issue is available in the wild, and the vulnerability has been public knowledge for six months, I have decided to release my own proof of concept," Fuller wrote on his blog.
A security update for Mac OS released two weeks earlier didn't include a patch. Apple now says it is aware of the issue and working on a fix. Security vendor SecureMac advises people to disable Java in their browsers until Apple fixes the problem.
[ Learn the details of the Java security hole in Mac OS X. | Apple's delay in fixing the problem prompted one hacker into action. ]
It's this kind of nonchalant attitude toward serious security problems that analysts like Jon Oltsik, Mac security analyst at the Enterprise Strategy Group, say is making them a bit irritated. He advises Apple to change its ways before it's too late.
Apple has until now gotten away with a lackluster response to security largely because Mac OS X (and Safari browser) flew under the radar of many hackers, he says. But as the platform rises in popularity, says Oltsik, hackers will soon take dead aim if they haven't already.
Oltisk talked with CIO.com about the impact of this security hole, as well as the potential fallout from what he calls Apple's cavalier approach to fixing such problems.
How serious is this Java vulnerability?
Oltsik: The vulnerability could be used to run a rogue executable, so it is very dangerous. It certainly simplifies the process of writing a malicious Mac exploit. I haven't yet seen malicious code "in the wild" that takes advantage of this vulnerability, but one could pop up anytime.
How can enterprises protect themselves?
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
On Twitter now
java
Powered by Twitter
jfruh
Apple syncing patent can't come soon enough
pasmith
New Twitter features borrow from 3rd party clients
Esther Schindler
Open Source Changes the Software Acquisition Process
mikelgan
How to set up continuous podcast play on the new iTunes
David Strom
Five important Windows 7 mobility features
sjvn
Guard your Wi-Fi for your own sake
Sandra Henry-Stocker
Grepping on Whole Words
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.












