Linked by Thom Holwerda on Wed 20th Dec 2006 10:08 UTC
Apple A pair of security researchers has picked January 2007 as the starting point for a month-long project in which each passing day will feature a previously undocumented security hole in Apple's OS X or in Apple applications that run on top of it. The 'Month of Apple Bugs' project, currently slated to begin on Jan. 1, is being orchestrated in part by a security researcher who asked to be identified only by his online alias 'LMH'. This is the same researcher who in November ran the 'Month of Kernel Bugs' project. LMH's partner in this project is Kevin Finisterre, a researcher who has reported numerous bugs to Apple over the past few years. As with the kernel bugs project, Apple will be given no advance notice with the Month of Apple bugs, LMH said.
Thread beginning with comment 194571
To read all comments associated with this story, please click here.
Apple
by JohnX on Wed 20th Dec 2006 12:15 UTC
JohnX
Member since:
2005-11-06

Apple has made many enemies in the security field. That's what happens when you treat security researchers with Scientology-like legal tactics.

RE: Apple
by zombie process on Wed 20th Dec 2006 15:38 in reply to "Apple"
zombie process Member since:
2005-07-08

Yup - I think that's what it boils down to. A lot of this can be traced back to the wireless vulns found by Maynor and Cache earlier this year which were denied vociferously by the Apple community. Apple silencing Maynor was the final straw for may grey hats, I guess.

Reply Parent Bookmark Score: 2

RE[2]: Apple
by Hakime on Wed 20th Dec 2006 16:22 in reply to "RE: Apple"
Hakime Member since:
2005-11-16

"Apple silencing Maynor was the final straw for may grey hats, I guess."

Prove it!

This idea of Apple silencing Maynor is not even an official statement from Maynor himself, This came firt from a poor and miserable journalist, Brian Krebs, who is claiming that Maynor told him such thing. So already here be carefull, you don't know where you are going!!!

And even if Maynor really had such statement, why Apple is saying that Maynor never came to them to describe the bug he was talking about? Why should we believe Maynor and not Apple? I mean Apple is a serious compagny, who can really believe that they sent one of their representatives to say a lie publically?

During the "Months of bug", a security bug affecting the first generation of airport was discovered and described. When Apple shiped a security pacth for it, the two researches who discovered the issue were granted for their help! That's how it works, someone finds a bug, he/she lets Apple know about it, Apple thanks him/her.

Reply Parent Bookmark Score: 2