<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: More security professionalism, please.</title>
	<atom:link href="http://www.macalope.com/2007/02/04/more-security-professionalism-please/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/</link>
	<description>Apple news and analysis from everyone's favorite mythical Mac user</description>
	<pubDate>Thu, 20 Nov 2008 21:03:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: The Macalope &#187; Blog Archive &#187; Good thing he didn&#8217;t double-dog dare</title>
		<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/#comment-6155</link>
		<dc:creator>The Macalope &#187; Blog Archive &#187; Good thing he didn&#8217;t double-dog dare</dc:creator>
		<pubDate>Mon, 12 Feb 2007 19:08:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=163#comment-6155</guid>
		<description>[...] The Macalope, his antlers dripping with sarcasm, is sure that won&#8217;t happen to Vista (trolls can read a more detailed version of the Macalope&#8217;s opinion on Vista security here). [...]</description>
		<content:encoded><![CDATA[<p>[...] The Macalope, his antlers dripping with sarcasm, is sure that won&#8217;t happen to Vista (trolls can read a more detailed version of the Macalope&#8217;s opinion on Vista security here). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Glenn Fleishman</title>
		<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/#comment-5754</link>
		<dc:creator>Glenn Fleishman</dc:creator>
		<pubDate>Thu, 08 Feb 2007 18:51:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=163#comment-5754</guid>
		<description>I think what's been lost (and the Macalope has found) in a lot of this Vista v. OS X security debate is that Vista has some kickass security and obscurity features that Apple should absolutely adopt (patent issues may prevent some of that). For instance, address space layout randomization. It's not a guaranteed exploit solver, but my understanding is that it makes Vista immediately dramatically more resistant to a host of the common major attacks against XP. It's just done. Yes, hackers will probably figure out ways to game ASLR, but it raises the bar. Apple doesn't do ASLR. They probably should. They probably will.

There's a long list of neat security measures that Vista is built with and that it offers, and given that it's inevitable that Mac OS X is cracked in a comprehensive way--that's separate from how easy it is to vector the attack, something that Maynor doesn't directly address--Apple is, I hope, stealing ideas from Vista.

Interestingly, I think Allchin was emphasizing the positive in the security area, while Gates the negative.</description>
		<content:encoded><![CDATA[<p>I think what&#8217;s been lost (and the Macalope has found) in a lot of this Vista v. OS X security debate is that Vista has some kickass security and obscurity features that Apple should absolutely adopt (patent issues may prevent some of that). For instance, address space layout randomization. It&#8217;s not a guaranteed exploit solver, but my understanding is that it makes Vista immediately dramatically more resistant to a host of the common major attacks against XP. It&#8217;s just done. Yes, hackers will probably figure out ways to game ASLR, but it raises the bar. Apple doesn&#8217;t do ASLR. They probably should. They probably will.</p>
<p>There&#8217;s a long list of neat security measures that Vista is built with and that it offers, and given that it&#8217;s inevitable that Mac OS X is cracked in a comprehensive way&#8211;that&#8217;s separate from how easy it is to vector the attack, something that Maynor doesn&#8217;t directly address&#8211;Apple is, I hope, stealing ideas from Vista.</p>
<p>Interestingly, I think Allchin was emphasizing the positive in the security area, while Gates the negative.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ken</title>
		<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/#comment-5528</link>
		<dc:creator>Ken</dc:creator>
		<pubDate>Tue, 06 Feb 2007 21:08:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=163#comment-5528</guid>
		<description>One thing that has struck me about this discussion is the simple assertion (and acceptance) of the idea that Vista has no known security flaws. Is this true? People must have been working on this. If it's true, I need to upgrade every machine in my organization post-haste...</description>
		<content:encoded><![CDATA[<p>One thing that has struck me about this discussion is the simple assertion (and acceptance) of the idea that Vista has no known security flaws. Is this true? People must have been working on this. If it&#8217;s true, I need to upgrade every machine in my organization post-haste&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Se7en</title>
		<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/#comment-5510</link>
		<dc:creator>Se7en</dc:creator>
		<pubDate>Tue, 06 Feb 2007 16:47:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=163#comment-5510</guid>
		<description>The first thing that came to my mind is that Apple was doing exactly what Bill Gates did: challenge the hacker community to prove them wrong.

So will Maynor now take Gates' challenge? Because Gates definitely threw one out there.</description>
		<content:encoded><![CDATA[<p>The first thing that came to my mind is that Apple was doing exactly what Bill Gates did: challenge the hacker community to prove them wrong.</p>
<p>So will Maynor now take Gates&#8217; challenge? Because Gates definitely threw one out there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GeoK</title>
		<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/#comment-5508</link>
		<dc:creator>GeoK</dc:creator>
		<pubDate>Tue, 06 Feb 2007 16:10:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=163#comment-5508</guid>
		<description>I would like to offer some food-for-thought that hasn't been touched upon with this good debate.

Who has the most to lose?

My bet is on all the third-party security software companies and developers. There seems to be an ecosystem that is firmly in place with XP and not so much with OS X.

This seems like a whole other can 'o worms.</description>
		<content:encoded><![CDATA[<p>I would like to offer some food-for-thought that hasn&#8217;t been touched upon with this good debate.</p>
<p>Who has the most to lose?</p>
<p>My bet is on all the third-party security software companies and developers. There seems to be an ecosystem that is firmly in place with XP and not so much with OS X.</p>
<p>This seems like a whole other can &#8216;o worms.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CmdNotCtrl &#187; Blog Archive &#187; More on Gatesgate</title>
		<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/#comment-5471</link>
		<dc:creator>CmdNotCtrl &#187; Blog Archive &#187; More on Gatesgate</dc:creator>
		<pubDate>Tue, 06 Feb 2007 07:22:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=163#comment-5471</guid>
		<description>[...] John Gruber and The Macalope rebut Maynor&#8217;s claims in posts on their respective blogs. [...]</description>
		<content:encoded><![CDATA[<p>[...] John Gruber and The Macalope rebut Maynor&#8217;s claims in posts on their respective blogs. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Macalope</title>
		<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/#comment-5463</link>
		<dc:creator>The Macalope</dc:creator>
		<pubDate>Tue, 06 Feb 2007 06:11:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=163#comment-5463</guid>
		<description>Well, the Macalope is pretty sure they added that ad today.  It's not in Wikipedia's list of ads and Wikipedia does have the other most recent set.  It's also not on the Unofficial Apple Weblog's list of the most recent ads.  Their list of the most recent is "Surgery, "Sabotage" and "Tech Support".  Apple's page has "Security", "Surgery" and "Tech Support".

While the Macalope finds it probably one of the funniest of the whole collection, it's not exactly what he had in mind when he asked Apple to get serious about security.</description>
		<content:encoded><![CDATA[<p>Well, the Macalope is pretty sure they added that ad today.  It&#8217;s not in Wikipedia&#8217;s list of ads and Wikipedia does have the other most recent set.  It&#8217;s also not on the Unofficial Apple Weblog&#8217;s list of the most recent ads.  Their list of the most recent is &#8220;Surgery, &#8220;Sabotage&#8221; and &#8220;Tech Support&#8221;.  Apple&#8217;s page has &#8220;Security&#8221;, &#8220;Surgery&#8221; and &#8220;Tech Support&#8221;.</p>
<p>While the Macalope finds it probably one of the funniest of the whole collection, it&#8217;s not exactly what he had in mind when he asked Apple to get serious about security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don</title>
		<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/#comment-5461</link>
		<dc:creator>Don</dc:creator>
		<pubDate>Tue, 06 Feb 2007 05:33:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=163#comment-5461</guid>
		<description>El Macalopo:
&#62;One.
&#62;So, it’s not “commercials”. It’s “commercial”.

Au contraire, oh mythical one.  There are TWO getamac ads about security.

The recent one titled "Security" mentions Vista by name:

http://movies.apple.com/movies/us/apple/getamac/apple-getamac-security_480x376.mov

The older one titled "Viruses" mentions 114,000 viruses, but it looks dubbed in:

http://movies.apple.com/movies/us/apple/getamac_ads1/viruses_480x376.mov</description>
		<content:encoded><![CDATA[<p>El Macalopo:<br />
&gt;One.<br />
&gt;So, it’s not “commercials”. It’s “commercial”.</p>
<p>Au contraire, oh mythical one.  There are TWO getamac ads about security.</p>
<p>The recent one titled &#8220;Security&#8221; mentions Vista by name:</p>
<p><a href="http://movies.apple.com/movies/us/apple/getamac/apple-getamac-security_480x376.mov" rel="nofollow">http://movies.apple.com/movies/us/apple/getamac/apple-getamac-security_480&#215;376.mov</a></p>
<p>The older one titled &#8220;Viruses&#8221; mentions 114,000 viruses, but it looks dubbed in:</p>
<p><a href="http://movies.apple.com/movies/us/apple/getamac_ads1/viruses_480x376.mov" rel="nofollow">http://movies.apple.com/movies/us/apple/getamac_ads1/viruses_480&#215;376.mov</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rip Ragged</title>
		<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/#comment-5460</link>
		<dc:creator>Rip Ragged</dc:creator>
		<pubDate>Tue, 06 Feb 2007 05:24:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=163#comment-5460</guid>
		<description>No. Sometimes it's fun to just kick a can down the street. The can doesn't really matter, as long as there's something to kick.</description>
		<content:encoded><![CDATA[<p>No. Sometimes it&#8217;s fun to just kick a can down the street. The can doesn&#8217;t really matter, as long as there&#8217;s something to kick.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ned Harwick</title>
		<link>http://www.macalope.com/2007/02/04/more-security-professionalism-please/#comment-5459</link>
		<dc:creator>Ned Harwick</dc:creator>
		<pubDate>Tue, 06 Feb 2007 05:17:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=163#comment-5459</guid>
		<description>Right, uh, I know I’m totally out of fashion here, but...

&lt;b&gt;&lt;i&gt;Does David Maynor matter? At all? About anything? Ever?&lt;/i&gt;&lt;/b&gt;

&lt;i&gt;Okay, cool... I was just checking...&lt;/I&gt;</description>
		<content:encoded><![CDATA[<p>Right, uh, I know I’m totally out of fashion here, but&#8230;</p>
<p><b><i>Does David Maynor matter? At all? About anything? Ever?</i></b></p>
<p><i>Okay, cool&#8230; I was just checking&#8230;</i></p>
]]></content:encoded>
	</item>
</channel>
</rss>
