Archive for Safari

Firefox And Safari Get Updated To Be More Secure

Posted in Commentary with tags , on November 14, 2008 by itnerd

From the must download category, comes Firefox 3.0.4 and Safari 3.2. You can get the Windows and Mac versions of Safari from here (you can also run Apple Software Update) as well as the changelog here. Firefox can be found here and the changelog can be found here.

Users of either browser should update today.

Consumer Reports Tells Mac Users To Ditch Safari

Posted in Security with tags , on August 5, 2008 by itnerd

I just spotted this link over at Consumer Reports that lists “7 online blunders” which can lead to identity theft or could trash your computer. Most of these blunders are things that have been around for a while, but blunder #5 caught my eye because it directly addresses Mac users and their false sense of security:

According to this year’s State of the Net survey, Mac users fall prey to phishing scams at about the same rate as Windows users, yet far fewer of them protect themselves with an anti-phishing toolbar. To make matters worse, the browser of choice for most Mac users, Apple’s Safari, has no phishing protection. We think it should.

What you can do: Until Apple beefs up Safari, use a browser with phishing protection, such as the latest version of Firefox (shown at right) or Opera. Also try a free anti-phishing toolbar such as McAfee Site Advisor or FirePhish.”

Consumer Reports is the latest in a growing string of organizations to take Apple to task over its handling of security issues. Not to mention that unpatched security holes have occasionally prompted security watchers such as US CERT to advise against using IE. Safari could easily end up in the same boat if Apple doesn’t get serious about security.

But Apple is only half the problem. Apple users have been force fed the story that Macs are more secure than Windows boxes. Up until recently that’s been largely true. But no computer platform is truly secure. Anything can be hacked, cracked, pwned, or exploited. So it is up to users to practice the same safer computing methods that have been drilled into Windows users for years.

Speaking of security. Apple was supposed to take part in the Black Hat security conference this week. However, Apple’s marketing team got in the way and vetoed the talk at the last minute. That’s unfortunate because Apple’s lack of clarity on security isn’t giving people the “warm fuzzies” at the moment.

“Carpet Bomb” Still A Problem Despite Patch…. Oh Noes!

Posted in Security with tags , on June 22, 2008 by itnerd

Apple patched Safari last week, but according to this ZD article, security researcher Billy Rios notes that when Safari is used on a computer with Firefox 2 or 3, there is a risk of an attack that allows a remote attacker to steal files using the “carpet bomb” method. He’s not going into other details at this time so that Apple can fix the issue, but its not good optics for Apple. To be fair, its a problem due to an interaction with another product, so Safari in isolation should be fine (in theory).

Oh yeah, if you look at Billy’s blog, he also has this quote:

“UNREALTED NOTE TO MOZILLA:  Firefox 3 shouldn’t FORCE itself to be my default browser after I install it (YES, I unchecked the default browser checkbox during install)”

Hmmm…. That sounds vaguely familiar. I saw that coming a mile away, just not from him.

Apple Patches Safari For Windows……Finally…

Posted in Commentary with tags , on June 20, 2008 by itnerd

After being poked, prodded, embarrassed, and hacked, Apple has released Safari 3.1.2 for Windows which apparently fixes the “carpet bombing” flaw discovered by Nitesh Dhanjani back in May. The interesting thing is that if you read the release notes, they don’t credit Dhanjani at all. Instead they credit Aviv Raff with the find (even though Raff in his blog credits Dhanjani with the find). I’m sure there’s a message in there someplace. Another interesting thing is that this flaw still exists in the Mac version of Safari. It is entirely possible that they plan on fixing this in the future. Only time will tell I guess.

Meanwhile, I’ll continue to use my favorite browser in the meantime.

Safari “Carpet Bombing” Attack Code In The Wild….. Oh Noes!

Posted in Commentary with tags , , on June 11, 2008 by itnerd

Stopthebadware.org and Zdnet said that the so called “Carpet Bombing” attack was a flaw that Apple needed to fix ASAP. I also called on Apple to fix this flaw ASAP before an exploit appeared. But now it’s too late. Infoworld is now reporting that code that exploits this flaw is in the wild. It affects Windows only (Mac users can rest easy….for now), but that doesn’t change the fact that this is serious.

Apple could have avoided this by simply fixing this flaw when it first appeared, but it chose not to because they didn’t consider this to be an issue. That forced Microsoft to tell it’s users not to use Safari (which now seems to be the right decision). Although I will note that this exploit takes advantage of a bug in Windows that Microsoft has known about since 2006. You have to wonder if Apple takes security seriously given their response to this issue.

UPDATE: Here’s a layman’s explanation of why this is an issue. There are actually two problems at work here:

  1. Safari will automatically download files from a specially crafted malicious web page (as there are plenty of those out there) with no user intervention required (rather than ask for permission before downloading).
  2. Certain files will be run automatically by Windows when number 1 happens (this is the Microsoft bug that I referred to earlier).

While both of these are bad, the worst offender is item number 1. Because even if Windows did not run files automatically the possibility still exists that you could have something nasty called “deletemyharddrive.exe” download to the computer and an unaware user will still click it and get into trouble. Therefore, if Apple simply had an option that had the browser ask the user if it was okay to download something, and that option was turned on by default, this could be mitigated.

Microsoft Tells Windows Users To Avoid Safari…. Apple Should Be Ashamed

Posted in Commentary with tags , , , on June 1, 2008 by itnerd

In an interesting role reversal, Microsoft has issued a security bulletin telling Windows users to avoid the Safari web browser due to the carpet bombing flaw that I reported on previously. Microsoft has likely put this bulletin out because of Apple’s refusal to fix that issue along with another one that potentially has dire consequences. Or, the cynics among us would say that Microsoft is taking advantage of cracks showing in the “secure from day one” argument that Apple loves to make. Either way the optics suck for Apple as I can’t remember the last time Microsoft told Windows users to avoid installing a mainstream product for security reasons.

Let’s get down to brass tacks here. Apple meeds to take immediate action and fix these flaws, plus they need to be proactive about issues and fix them no matter what they think of them. They also need to listen to those who point out these flaws as they are only trying to help Apple out (like I mentioned here and here for example). Otherwise this sort of embarrassing situation will keep happening to Apple.

Oh, by the way. All you Macintosh Fanbois who think that you don’t have to worry about this, I’m sorry to say that these flaws exist in the Macintosh version of Safari. Something for you fanbois to think about.

UPDATE: Security Focus joined the chorus by issuing their own note on this issue.

Safari “Carpet Bombing” Flaw Is Potentially Serious Says ZDNet And Stopthebadware.org

Posted in Commentary, Security with tags , , on May 30, 2008 by itnerd

You’ll recall that in a previous posting I wrote about three flaws in the Apple Safari web browser. I took Apple to task for not fixing all three flaws, which earned me the wrath of the Apple fanboi community (just look at the comments in that posting). Well it seems that others feel the same way that I do. Stopthebadware.org and zdnet have postings that contend that these issues should be fixed now. In the case of Stopthebadware.org, Laureli Mallek contends:

“Assuming Nitesh’s analysis is accurate, “unwanted downloads,” as Apple calls them, represent a serious security threat to users, who can be easily tricked into executing a malicious file. StopBadware.org believes that users should have control over software being downloaded to their computers, and we encourage Apple to reconsider its stance and treat this as the security issue that it is.”

And in the case of ZDNet, Ryan Naraine says:

“Think about it: A combo-attack where Dhanjani’s Safari vulnerability is used to drop a nasty executable on your desktop and another (known or unknown) vulnerability used to run it. Instant drive-by malware installation!”

Apple wants to play the security card by claiming that they are more secure than Windows. If they want to do that, they have to address issues like this when they appear as opposed to brushing them off as non-issues. I think part of the problem is that the Apple crowd have this impression that they are immune to the attacks that plague Windows users. The fact is that as the number of Apple users grows, the number of attacks that target the Apple platform will grow as well.

So Apple, do the right thing and fix these issues now.

In the meantime, I’ll continue to use Firefox.

Three Vulnerabilities In Safari…. Apple Will Only Fix 1…. WTF?

Posted in Commentary, Security with tags , on May 16, 2008 by itnerd

Apple loves to brag about Safari’s security by saying “Apple engineers designed Safari to be secure from day one.” (Go to www.apple.com/safari and click on security on the left side). But people keep finding holes in the browser that according to some are really serious.

Take Nitesh Dhanjani for example. He’s a security researcher who found three vulnerabilities in Safari and reported them to Apple. They in turn said that they would only fix one that they considered to be critical. As for the other two? He was told that Apple will look at them, but they will not do anything about them at this time. It’s a good thing that he wrote about these two issues in his blog for all to see. I’m guessing that Apple will do something about them now that they’re in the public eye.

If you take a look at these issues, these are things that according to him things that other browsers handle but Safari does not. So one could argue that Safari is lacking in some functionality that Internet Explorer and Firefox have. That bothers me. That’s also the reason why Firefox has been my default browser on my MacBook Pro for as long as I’ve had the machine. It appears that something I said in this blog some time ago is coming true. Apple is making decisions that makes that “more secure than Microsoft” aura disappear. Which means that all the momentum that Apple has been gaining is at risk. All it takes is one high profile exploit using one of those issues (or some other issue that we know nothing about) for things to come tumbling down around them.

Shoving Safari Down The Throats Of Windows Users Works…. Safari Marketshare Skyrockets

Posted in Commentary with tags , on May 2, 2008 by itnerd

You’ll recall that “The Steve” force fed Safari to Windows users via Apple Software Update just over a month ago. That created a bit of a backlash at the time, which led to some changes to Apple Software update to hush the critics.  Well, it looks like Steve was on to something as his strategy has resulted in a massive increase in Safari for Windows users. Before the update, Safari’s marketshare on Windows was as close to zero as you could get without actually being zero (of course it was in “beta” for most of that time, so that may have had something to do it it). Then their marketshare explodes right around the time that Apple Software Update force fed it to you. The only question is, will these users keep using Safari or will the switch back to FireFox or IE?

Safari & Firefox Updated… More Security For You!

Posted in Products, Security with tags , , on April 17, 2008 by itnerd

Last night brought two updates to two popular web browsers.

Apple’s Safari was updated to version 3.11 last night. The security fixes address four vulnerabilities, two of which are Windows only:

  • WebKit
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.2, Mac OS X Server v10.5.2, Windows XP or Vista
    Impact: Visiting a malicious website may result in cross-site scripting
  • WebKit
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.2, Mac OS X Server v10.5.2, Windows XP or Vista
    Impact: Viewing a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution
  • Safari
    Available for: Windows XP or Vista
    Impact: A maliciously crafted website may control the contents of the address bar
  • Safari
    Available for: Windows XP or Vista
    Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution

The word on the street is that one of the two Webkit related fixes resolves the bug that was recently used to successfully attack a MacBook Air in the CanSecWest PWN2OWN contest. This update is available through Software Update. It should also be noted that Software Update itself on the Windows platform was also updated last night.

Mozilla Firefox was also updated as well to version 2.0.0.14. to fix a security issue with the Javascript garbage collector. The update will eventually appear for Firefox users and will require a restart of the browsers. Alternately, uses can go to the “Help” menu and “Check For Updates” option.