Major overhaul makes OS X Lion king of security
theregister.co.uk
theregister.co.uk
Linux has sandboxing per SELinux. However, SELinux puts the burden of sandboxing on the administrator, or in the case of a desktop OS on the user. Apple, on the other hand puts the burden on the application developer.
Applications have to opt-in for Sandboxing [1]. Once an application opts-in, it has no access to anything but its own home directory. File opening/saving dialogs are handled through the pbox daemon, and are the only manner for the sandboxed process to get access to the 'outside world'. Some privileges like network access have to be retrieved through entitlements.
What we will see is the first, vendor-pushed attempt, to sandbox every application on a mainstream operating system. And it will probably work, because the burden is on the developers, not the users.
[1] Apple will probably make it mandatory in the future for new applications sold in the App Store.
I think the most likely scenario is that Apple will use the steady stream of revenue from selling in the App Store as bait for the devs, then, after they're hooked, switch up the rules on them and require everything to be sandboxed. By that point they will be dependent on the App Store for the majority of their revenue and will have no choice but to comply.
And even if that was not the case sandboxing would still be understated — the system provided segregation of common attack vectors, e.g. WebKit2's separate HTML parsing processes, Quicktime's separate video decoding processes, the segregated PDF parser, etc., is one of the bigger security enhancements of any OS.
Isn't that NDA'ed information? ;) However, it seems it's out via Ars already.
Novermber according to Ars's review.
The title almost sounds like SHA256 was broken while Lion was written and everyone else is vulnerable.
Not a lot of companies can sell something like ASLR and basic application restrictions this well.
In some other communities it's not well-understood that it's not just about feature checkboxing. It's about shaping features in such a manner that they are trivial to use.
I do realize that to Apple-dislikers I am well under the spell of the reality distortion field ;).
It is just that people who use a computer for nothing more than generic stuff like browsing / word-processing feel this need to defend their OS choice (while potentially using the exact applications which they used on their previous platform) with articles like this. Soon ASLR will become "the killer feature" and Apple will be declared the first to invent it and the Linux/Win fanboys will be pissed.
This of course is the circle of life in the tech industry. One just needs to stand at a distance and enjoy.
The article is typical El Reg, but the researchers aren't uncritically gushing.
Remember when XP came out? (oh god, did I just age myself) That was also chock-a-block full of press release style articles in the news about how impenetrable it was.
Mac is "king of security" only in the sense that it covers about 10% of the market and people aren't writing viruses for it.
Oh well... really "punchy" headline though got me to click.
Windows Vista and Ubuntu, by contrast, added much more
robust implementations of ASLR years earlier.
I don't pay much attention to security, but I would be surprised if this were the only feature that OSX is years behind on. I can imagine that OSX is better than Windows, if only because I have a reflexively bad opinion of Windows, and it's almost certainly better than previous OSX versions, but I'll believe it's better than Linux when I see a lot of reports from a lot of real security people.There are also various tools to security-harden Windows 7 and Linux which don't (as far as I know) yet exist on OSX, or 10.7. One of the issues is the lack of vPro/TXT/TPM on Mac hardware. Another issue is the lack of any biometric or smartcard support in Mac hardware (you could add an aftermarket USB reader, but that's a pain on something like a laptop).
The only TPM-like protections in Apple hardware are to prevent piracy of OSX (hackintoshes), and you can see how efective those have been (existence of hackintosh is kind of proof that they haven't been).
Apple's iOS devices could be much more secure than they are, too -- they don't actually have effective "erase after 10 tries" password protection, in that it's possible to image the phone and then try to decrypt the image an infinite number of times offline. That's kind of unforgivable as a design flaw, IMO, and means you need to use a super long brute force resistant passphrase to keep the phone secure (which only one person I know does).
I wish someone would do a great iris biometric app for the Mac and iPhone, and would incorporate a hw tamper-resistant chip for password to key mapping (to reduce all brute force attempts to "online" vs. "offline"). iCloud kinda solves the latter by potentially letting you push auth out into the cloud.
I am not aware that the kind of sandboxing Lion offers (and promotes, and encourages through things like the pbox daemon) is available on any consumer OS (apart from SELinux, and that's hardly a consumer OS), let alone with that attention to painlessness from the user's POV.
“I generally tell Mac users that if they care about security, they should upgrade to Lion sooner rather than later, and the same goes for Windows users, too.”