> I think anyone relying on the security of OS X is going to have to seriously rethink their OS choice after this.
10.7.3 logging FileFault (that was a typo, but I think I'll keep it) passwords in plain text might have been a subtle hint in that direction.http://www.androidcentral.com/samsung-lock-screen-bypassed-e...
You might find this article a good read: http://www.theverge.com/2014/1/21/5307992/inside-the-mind-of...
It's mainly an SSH and RDP terminal anyway.
OSX quality and QA is extremely bad.
Security is not a Boolean. A better question is, which OS is more secure OOTB for a given user.
https://www.gov.uk/government/publications/end-user-devices-...
Tell that to the people who generated keys on Debian.
Programmers are simply not good enough at writing secure code. Full stop. If you say anything else, you're just flaunting your own unreliability as a source of security advice.
(For example, Github lets you push/pull via SSH as git@github.com, and they determine your identity by the SSH key used.)
You're saying Google Chrome doesn't test that an ephemeral key is actually signed by the cert's private key? If that's the case, that's completely unacceptable because it's the whole point of the protocol.
You're kidding, right?
http://www.debian.org/security/
Edit:
There were multiple security issues in OpenSSL as recently as January.