MOAB and Macworld Expo Keynote

I suppose most of you have already heard or read about MOAB - The Month of Apple Bugs, a project initiated by LMH and Kevin Finisterre (the guys that already held the Month of Browser/Kernel Bugs). They publish vulnerabilities of Mac OS X or other Apple software and other apps for Mac OS X (like VLC, OmniWeb) together with 0day demo exploits before informing Apple. There is some controversy about whether this is the right way to disclose serious security issues before Apple has a chance to react and provide bugfixes. I personally like it and think it’s a chance for Apple to strengthen security in Mac OS X and promote it as a feature. I can also understand LMH’s and Kevin Finisterre’s frustration about Apple reacting on bugreports, I also submitted several bugreports and one of them is still open - for 1 1/2 years by now.

Some of the vulnerabilities are really serious so some guys formed a group moabfixes to write patches for these exploits using the Application Enhancer utility which gives the ability to manipulate applications running in Mac OS X. Funnily enough, today’s MOAB vulnerability MOAB-08-01-2007 was found in even this app (Application Enhancer) and the authors of MOAB strongly advise users to stay away from it. Obviously they dislike the team of moabfixes surrounded by Landon Fuller to fix the bugs and steal some attention. ;-)

To refer to the post title and the keynote in about 10 minutes again: I am pretty sure Steve Jobs will mention the Month of Apple Bugs project as a sidenote (in the way he always mentions current news in the days before keynotes - making a joke about it), but I wish he will take it seriously this time and give a statement on Apple’s security measures and plans regarding software security and Mac OS X.

Lets see. cordney*

Leave a Reply

:mrgreen: :neutral: :twisted: :shock: :smile: :???: :cool: :evil: :grin: :oops: :razz: :roll: :wink: :cry: :eek: :lol: :mad: :sad: