Saturday, January 29, 2011

Little Snitch $14.99,
(Regular Price $$29.95)
This Weekend

--
MacUpdate is offering Little Snitch from Objective Development, a beloved 'reverse firewall' for Mac OS X, at almost HALF-PRICE this weekend. That's $14.99. (Regular price is $29.95) Go get it here:

http://www.mupromo.com/deal/1421/7024/little-snitch

I use it non-stop and love the thing. It has gotten consistently easier to use over time. I also have an older version running on my FTP server 24/7. If you're worried about being pwned, this will stop all communication from malware back to the Bot Wrangler. No botnet for you! It's also perfect for stopping all 'phoning home' by pesky applications.

MUPromo's offer drops dead at midnight on Sunday, January 30, 2011. But you may be able to get it for a lower discount during the following week. Check the MUPromo website for details.

Note: If you use the 'reverse firewall' in Intego's VirusBarrier v10.6, you don't need Little Snitch.
--

Thursday, January 27, 2011

Sophos Top tips for Mac OS X security - Part 1
And my commentary

--
While I polish up Parts II and III of my 2010 Mac security summary, here is an article Sophos posted on Christmas day. It is the first in a series of articles to help Mac users secure their Macs. For advanced users, this is old news.

Top tips for Mac OS X security - Part 1

For users new to the concepts in this article, it is important to note that each added layer of security typically adds a layer of difficulty for the user. Using the points from this article, here are some useful examples:

1) Disable Automatic Login: This is absolutely critical. But it means there is not automatic logging in and booting of your user account ever again. That is a GREAT thing for security. But there are always newbies who complain. I say tough. But I'm a grizzly old meanie when it comes to personal responsibility. If you are of a more personable personality, talk over with your users exactly what happens when a hacker accesses their computer: Everything of yours is now their's. Everything. Once people think about that, they tend to want to protect their computer.

2) Set a Firmware Password: This is incredibly brilliant for stopping that big, Huge GAPING SECURITY HOLE in Mac OS X: Booting onto anyone's Mac via any compatible Mac OS X installation disc. Once booted from these discs, it is dirt easy to remove and change the Administrator account password. Once changed, that Mac is PWNED! Setting a firmware password stops that DEAD. However! There are other results as well. These include losing the ability to easily change your Startup Disc. You can't boot with the Option key down to change startup discs. You can't simply click on a new volume in the Startup Disc preference pane. The result can be quite annoying if you frequently change them, for example to use another volume on your Mac for repairing your main boot volume, which I do regularly.

3) Encryption is a good idea:

--3A) Boot Drives:

On Mac OS X you are allowed to use FileVault (found in the Security preference pane) to encrypt your User accounts. If you have critical data that should NEVER fall into other people's hands, this encryption is CRITICAL! Do it. However! You've got to consider some consequences:  

First, you can no longer access that volume from another boot volume. No more repairing it from elsewhere.

Second, you MUST keep all your critical data specifically in your User account and NOT anywhere else on your boot volume. Again, only the contents of your user account Home folder is encrypted.

Third, updating Mac OS X to a new version is a bit more of a PITA if items in your Home folder have to be updated.

Fourth, there is a minor slowdown of your machine due to the constant decryption of your data then reencryption of new data.

And you'll find other minor annoyances.

If you have a critical machine, all of three of these steps are important. Think of the added user annoyances as added 'Cost Of Doing Business' that you cannot do without. Live with them and appreciate that they provide you with solid and important security.

Question: Is it important to encrypt your entire hard drive?

Answer: NO, not if you keep ALL your critical data inside your Home folder. Everything else on your hard drive should not be of any consequence. All of it should be files and folders and apps that anyone could obtain any day of the week. Therefore, getting them off your computer is trivial. What you must protect is UNIQUE data that only you and trusted colleagues should ever see.

Question: But, but, but, some security expert firm says blahblahblah!!!

Answer: They are either being extremists or they want to sell you something. For example, Sophos use their article to try to sell you their 'SafeGuard Disk Encryption for Mac' that encrypts absolutely everything on your Mac. If you see a point in further slowing down your Mac and keeping publicly accessible System files away from bad guys, fine. Go buy it. I personally see no reason for it.

The only possible exceptions I can imagine are if you are a developer or software tester who has something unique installed into their system, such as a custom .KEXT extension file, that there is no way on Earth you want anyone to obtain. Then I'd encrypt everything.

--3B) External Drives:

YES! Encrypt them! They have your data on them. This includes everything from CDs you burn to DVDs to Flash drives to attached hard drives. ENCRYPT THEM ALL!

There are lots of great programs to accomplish this for you, many of which are simple Drag And Drop apps that encrypt then put the encrypted file onto your external drive for you. Some of them will alert you if you attempt to put anything unencrypted onto a drive, 'user-minder' apps if you will. These are great to have.

--3C) Wi-Fi Encryption:

YES OF COURSE! It is so easy to forget that free Wi-Fi spots continue to provide ZERO PRIVACY. If you don't have to sign in to a Wi-Fi spot, your data and/or your cookies to websites are IN THE CLEAR, meaning you can expect them to be stolen by anyone else also connected to that router. This is why the Firesheep hacking tool was made public: To force people, Wi-Fi spot owners and website owners to WAKE UP and force encryption or account privacy at all times. Very very slowly the world is catching on. But I fully expect encryption/privacy cluelessness to last well on into the very distant future. Some people are never going to understand. That includes members of my own family! Be nice to them and if need be, set up encryption and privacy on their routers for them.

As Sophos publish further Mac OS X security tips I will provide further links and further commentary.

Share and Enjoy!
--

Saturday, January 8, 2011

GnuPG Project In Chaos:
Avoid For Now

 . . .
Apologies to readers for taking a long break. I've started writing again today. This first post of the year is extremely sad for me personally:

I was once quite a champion of GnuPG for Mac, put up with the massive geek factor and had it working perfectly. But these days GnuPG is broken on Mac OS X 10.6.x. Don't bother playing with it unless you're one of the developers, it's that nasty at the moment.

I've attempted many times over the last full year to help the project, saw great hope last spring, only to have hope dashed this winter with a cacophony of developer infighting, endlessly frustrated would-be users, censored list posts, and chaos all round. I have never seen this before and hope I never do again. RUN AWAY from this software for now, until... (all join hands and pray) ...someone sane takes over the project and straightens out the bloody mess. Until then, I wish the project well.

(;_;)

Wednesday, December 8, 2010

QuickTime v7.6.9 Update
For 10.5.8 & Windows

~~
On December 7, 2010 Apple released QuickTime version 7.6.9 for Mac OS X 10.5.8 and Windows XP, Vista and 7ista. No update is required for Mac OS X 10.6.8 users. It contains 15 security patches, some for both Windows and Mac OS X, a couple are Windows only. As usual, most of these vulnerabilities are due to memory overflow programming errors. You can read about the security patchs at:

About the security content of QuickTime 7.6.9

I'm a bit concerned at the moment that Apple have this update listed as being for only Windows. This is INCORRECT. Hopefully Apple will correct their error today. Most likely they will add a separate listing for the Mac OS X 10.5.8 version.

According to Apple:

QuickTime is incorporated into Mac OS X v10.6 and later.
QuickTime 7.6.9 is not presented to systems running
Mac OS X v10.6 or later.
I double-checked and verified that all of these CVE issues have already been patched in 10.6.8. Therefore, be certain that your installation of Snow Leopard is up-to-date.

If you've read my previous posts you know that Apple's QuickTime is the very least secure of Apple's software. A great deal of the problem has to do with JavaScript/ECMAScript Hell, as I call it. As usual, I consider JavaScript to be the bane of the Internet and wish it would be entirely scrapped and replaced with a secure scripting language. Read back in my posts if you're interested in my rants about why JavaScript is a catastrophe.

Below is a quick summary of the security holes patched in QuickTime v7. Click on the CVE numbers for further details.

Common Vulnerabilities and Exposures IDs Patched:

CVE-2010-3787 - Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image.

CVE-2010-3788 - QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of JP2 image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 file.

CVE-2010-3789 - QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted AVI file.

CVE-2010-3790 - QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.

CVE-2010-3791 - Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.

CVE-2010-3792 - Integer signedness error in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.

CVE-2010-3793 - QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Sorenson movie file.

CVE-2010-3794 - QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of FlashPix image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.

CVE-2010-3795 - QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of GIF image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.

CVE-2010-3800 - Viewing a maliciously crafted PICT file may lead to an unexpected application termination or arbitrary code execution.

CVE-2010-3801 - Viewing a maliciously crafted FlashPix image may lead to an unexpected application termination or arbitrary code execution.

CVE-2010-3802 - Viewing a maliciously crafted QTVR movie file may lead to an unexpected application termination or arbitrary code execution.

CVE-2010-1508 - Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Windows only.

CVE-2010-0530 - A local user may have access to sensitive information. Windows only.

CVE-2010-4009 - Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution.

Note: Not all of the CVE numbers have been listed at the National Vulnerability Database. Therefore, I instead provided links to their references at the Common Vulnerabilities and Exposures site. Check back at the CVE site as these CVEs progress beyond 'candidate' status.

Share and Enjoy!

:-D
~~

Sunday, November 28, 2010

Mac Security Status Report,
Part I

--
Introduction:

As a non-expert at computer security, it's a bit silly to believe I can provide any comprehensive report of current Mac security. However, I don't see anyone else bothering. Instead I see a variety of niche groups and niche skill sets involved with Mac Security but not pulling the pieces together. I also hear incessant vacuous FUD attacks from frustrated sources who wish Mac OS X was even remotely as unsafe as Windows blatantly is. It's plain old propaganda, not unlike the worthless political rhetoric in the media attempting to divide people through the promotion of fiction and fear. :-P

Therefore, I'm not going to worry about the areas in which I have lack of insight. Instead I'm going to take a stab at it and do what I do best: Examine the overall system of Mac security, provide some relevant details, then offer my summary and conclusions. Never rely on only one source of information about anything. Lord help anyone who uses Fox News as their soul political information source. Equally, lord help anyone who uses my work as their soul Mac security information source.

I) A Critical Mac Problem, Inadvertently Provided Via My Pet Troll:


The IT Ignorance Factor

Every source of difficult information has its trolls. It's difficult for Windows users to face Mac OS X security facts. Mac OS X is the #3 safest operating system available. The two better operating systems are OpenBSD and FreeBSD. It is no coincidence that Mac OS X is built upon an Open Source foundation that is based in part on pieces of both OpenBSD and FreeBSD.

This upsets my pet troll very much and makes him angry. This month he calls himself 'Tom' the troll. He is an anonymous coward reader of the blog, unwilling to let anyone know who he is or his stake in propagandizing Windows over Mac. It's all entirely dull and predictable to me. Occasionally my pet troll attempts to post FUD commentaries into my blog. I take a look at them, laugh a while, then step back and consider what pieces of his dishonest propagandist point of view could be useful to me. This time he wanted me to listen to the 'woe is we' rantings of one Roger Grimes, a Windows apologist and security analyst paid by Microsoft. You can listen to this fellow yourself at:

SecureABit.com

Scroll down to episode #67 of their podcast. Most of the dull program includes commentary from Mr. Grimes.

This fellow pulls the usual pro-Microsoft, anti-Apple myth mongering and propagandist garbage. What is unique in my experience is his defeatist attitude regarding computer security. He says essentially that we're all screwed no matter what, but OpenBSD is the best we've got for operating systems, but darn it's too difficult to use for mere mortals, so use Windows. (o_0) Oh that makes (no) sense! He then tosses out 'The Grimes Corollary' that restates the 'Security Through Obscurity' myth. Been there, killed that, yawned.

However, I was able to pull out of Mr. Grimes' rants one useful comment. It is this: Enterprise IT technologists don't adequately, or in a timely manner, patch the computers under their care. They also allow their users to use simplistic passwords that are easily cracked. This is most particularly evident on Enterprise Mac computers. The reason why is simple: Enterprise IT technologists rarely bother to learn Mac security or enforce it. Therefore, Mr. Grimes tells his tale of enjoying visiting businesses that integrate Macs because so commonly the machines are not up-to-date with security patches and are using easily guessed passwords. I would assume he uses a dictionary attack program against them, which these days are extremely fast and effective. He also keeps track of all the reported Mac vulnerabilities and uses them against unpatched machines.

So here we have Macs, the safest GUI OS based computers available, being easily cracked via very basic techniques that anyone's granny could use. This is shameful. Mr. Grimes would like to blame the users for this state of affairs. But of course it is the IT technologists and the IT managers who are entirely to blame. Never, ever, expect a business user to be any kind of technology security expert. To do so is to literally invite into your business The LUSER Factor. I've covered this issue many times in the past. It is the main reason why Mac OS X has any malware at all and is the reason that nearly all Mac OS X malware are Trojan horses.

There is more going on in the Enterprise than just problems of 'the user', or what's 'between the chair and the keyboard'. In business the computer is a tool, and the tool master is the IT expert in charge of that tool. This leads me to create another descriptive phrase that I call The IT Ignorance Factor. This problem occurs due to a multitude of factors. I'll toss out a few of them:

A) The business does not provide adequate time and resources for adequate computer maintenance. IT people often pull out their hair trying to get biznizz types to comprehend technology. But the fact remains that not keeping computers maintained means directly damaging the company. There are multitudes of tales of woe. Here is one from today concerning the shockingly computer ignorant US federal government:

US embassy cables leak sparks global diplomatic crisis

If the government's IT 'experts' had been on the ball, this could not have happened. I strongly suspect that they were kept off the ball with the help of bad management. This is when IT technologists must become educators and stop the 'boss' from being an 'ass'.

B) Laziness. Clearly most IT technologists live in the Windows world. Why bother to learn that other platform if they don't have to. You've heard this illogic before.

C) Fear. It sounds odd, but many IT technologists have trouble enough dealing with Windows hell. They're scared to get involved with another platform, making things even more complicated, or so they illogically believe.

D) Arrogance. Most Mac users have met the know-it-all geek who is a gawd of Windows and sneers at Macs. Then of course when someone defends the Mac these stick-up-their-ass bozoids accuse Mac users of going all 'religious' or counter 'arrogant', ad nauseam.... Therefore, of course such creatures are not going to bother to learn or apply proper Mac security methods.

There are of course more excuses and failings involved. Post your faves in the comments if you like.

    

Thus ends Part I. Further parts of my Mac Security Status of 2010 will include a summary of all the current active Mac malware, a summary of the consistent types of security vulnerabilities in Mac OS X, and a summary of the non-Apple security threats against Mac OS X. I'll be covering the Koobface/Boonana worm, the 'Evercookie' technique and how to combat it, as well as further coverage of the ongoing foolish attempt by the US federal government to backdoor every computer data encryption method.
--

Wednesday, November 17, 2010

Adobe CRITICAL Security Update
Of The Month Club

--
And now for something useful:

Adobe have posted their promised CRITICAL "out-of-band" security updates for Adobe Acrobat and Adobe Reader. The new versions are 9.4.1. If you use either of these applications, get the security updates now. Proof-of-concept exploits for the previous versions have been available for weeks.

You can read about the CRITICAL security updates here:

Security updates available for Adobe Reader and Acrobat

The direct download URLs, to save you from suffering Adobe's lunatic website:

Adobe Acrobat 9.4.1 Pro update

Adobe Reader 9.4.1 update - PPC

Adobe Reader 9.4.1 update - Intel

See you back here next month for the latest in "out-of-band" CRITICAL Adobe security updates!

Stay safe, stay secure, laugh at the FUD.
--

Hilarious Anti-Apple Security FUD Attack! By eWeek!

--
Lots going on this week, with me gathering up news from all corners. But when I see something as hilarious as this, I have to post it ASAP. It's one of the infamous slide show articles over at eWeek. What is hilarious is that it says nothing that wasn't shouted to the rafters in 2005 by Symantec when they were trying to prop up their worst-in-class anti-malware application for Mac OS X. What I am posting here is verbatim. I did NOT add any capitals. The SHOUTING is all their's:

Security: Mac Malware Attacks Prompt Security Vendors to Rush Out Antivirus Tools
By Fahmida Y. Rashid on 2010-11-12
SECURITY VENDORS ARE SAYING THAT ATTACKS ON THE MAC ARE NOW SIGNIFICANT ENOUGH THAT APPLE USERS SHOULD INVEST IN ANTIVIRUS SOFTWARE FOR WHAT WAS ONCE THE "INVULNERABLE" PLATFORM. WITH KOOBFACE VARIANT BOONANA FRESH IN PEOPLE'S MINDS, THE CONCEPT OF A VIRUS ATTACKING MACS SEEMS LESS LAUGHABLE THAN IT DID EVEN TWO YEARS AGO. "MAC USERS MUST REMEMBER THAT LESS TARGETED IS NOT THE SAME AS INVULNERABLE," SAID RICHARD WANG, MANAGER OF SOPHOSLABS. THE THREAT IS STILL NOT THAT PREVALENT, WITH ONLY "ONE TO TWO" ATTACKS ON MACS EACH WEEK, COMPARED WITH THE "TENS OF THOUSANDS" PER DAY AGAINST WINDOWS PCS. MAC OS X HAS ONLY 10.6 PERCENT MARKET SHARE IN THE UNITED STATES, ACCORDING TO IDC AND GARTNER, BUT THE DAY HACKERS WILL FIND THE PLATFORM WORTH TARGETING IS NOT FAR OFF, VENDORS SAID. MAC ANTIVIRUS SOFTWARE IS NOT NEW, BUT IT USED TO HAVE A BAD REPUTATION FOR BEING RESOURCE-HUNGRY AND INCONVENIENT. THAT'S SOON TO CHANGE AS VENDORS RELEASE NEW MAC ANTIVIRUS TOOLS THAT ARE QUITE UNOBTRUSIVE. HERE ARE SOME OF THEM...
OMFG! MAC USERS ARE ALL GONNA DIE!

My usual point: NEVER has anyone but trolls said Mac OS X was "invulnerable" or anything similar. It's a propaganda trick: Make up a nasty, indicting quote with no attribution provided. Yes, Fahmida Y. Rashid of eWeek and Richard Wang of Sophos are acting like assholes. But this trick has been pulled countless times. Therefore, they're acting like unoriginal assholes. Just laugh.

I could do my usual lecture about the insane nature of the 'Security Through Obscurity' myth. If you care, go back a few years in my posts. Just know that Windows has over 1000x more malware than Mac OS X on a per user basis, which blows the stupid myth off the planet. Such silliness. But that's what happens when Marketing Morons get desperate to sell Sell SELL!
--