News
- +
McAfee CEO ponders consolidation, Cisco threat 05/04/2007 16:41:12
Dave DeWalt on the security industry and McAfeeOn Monday at 6 a.m., Dave DeWalt stood in front of McAfee's Plano, Texas, offices to greet employees with coffee, doughnuts and a handshake. "They were wondering, 'Who's the guy in the suit?'" says the former EMC vice president who became McAfee's CEO on April 2.
Leopard's firewall is confusing, inconsistent, switched off by default and incompatible with some applications, a security researcher said after analyzing the new security tool.
"This firewall is a mess," Rich Mogull, a security consultant and former Gartner analyst, said after spending two days digging into the new firewall's capabilities. "It's a step back from Tiger's firewall. I was originally pretty bullish on Leopard's security, and I still am on the concepts, but the implementation makes most of its advances ineffective or unusable."
The firewall in Mac OS X 10.5, a.k.a Leopard uses a bare-bones interface -- earlier this week, Mogull called it "so simple as to be nearly useless" -- that offers users three options:
- Allow all incoming connections
- Block all incoming connections
- Set access for specific services and applications
"'Block all...' does seem to block actual connections," said Mogull, "but any shared ports are detected as 'open/filtered' on a port scan." And unless users turn on stealth, some services -- Bonjour, Apple's network device locating technology, is one -- are seen as open by scans, no matter what firewall setting is selected. Only by using "Block all..." with stealth enabled are shared services actually invisible.
"In short, 'Block all...' seems to block inbound connections but ports show as open/filtered," he said. "Stealth mode works, partially, but some ports still show on a port scan no matter what. Bonjour is always accessible, unless you're in stealth mode."
Those inconsistencies pale against the firewall's ability to break some applications without warning. While testing the firewall's "Set access..." option, Mogull discovered that Leopard prevents some applications from running.
When the "Set access...." mode is turned on, Leopard digitally signs applications that the user allows access to incoming communication. But if that application is subsequently changed -- say when it's updated to a new version -- the signature no longer matches and the application won't run. While that's typical of firewalls, Leopard also blocks applications that change at runtime. Skype, the popular VoIP software and instant messenger, is one such program.
If the user has set the firewall to "Set access..." and runs Skype, the icon will bounce a time or two on the dock, but not load. Nor does Leopard tell the user that Skype has failed or why it won't launch. Only the Mac OS X Console gives a clue, with a message such as: 11/2/07 9:47:51 AM [0x0-0x35035].com.skype.skype[399] Check 1 failed. Can't run Skype
"You can fix this by reinstalling Skype," said Mogull, "and it will work until the next time it's run. Then you have to reinstall Skype again. That's a bit of a problem."
Skype has acknowledged the problem as far back as August, but while it said then it was working on a fix, no version compatible with the Leopard firewall has been issued. (The last Mac OS X Skype update was released in July.)
"I was close to recommending the firewall in app signing mode ["Set access..."], but not with this problem of breaking applications," he said. Instead, users should rely on the protection built into their routers. "If you have a wireless router between the modem and your Mac, you're fine," he said.
But even a flawed firewall isn't fatal, Mogull noted, for Mac users. "I run a firewall, but it's kind of out of habit from my days with Windows," he said. "I like that extra layer of protection." But there have been few cases where exploits have actually claimed success against Apple's systems. "There was a zero-day, but that's been patched. I don't know of any ways of getting in today." He declined to name the exploit.
"Fortunately, all of this is fixable," he said. "Apple clearly was a little rushed, but they're moving in the right direction. It's our responsibility to keep on Apple to make sure they convert these concepts into actual implementations."
Computerworld Member Login
Realise Your VMware Vision: Storage Consolidation and Virtualization for Small to Medium Businesses
10:30 - 11am (EST, Sydney, Australia)
Wednesday, 4th June 2008
Screening live at your PC
Join Computerworld and our expert speakers:
- Jean-Marc Annonier, Research Manager, IT Spending, IDC
- Howard Porter, SMB Channels Manager, VMware
- Clive Gold, Product Marketing Manager Australia/New Zealand, EMC Corporation
to learn about the various virtualization technologies available today and what factors are driving it in small to medium businesses. Discover use cases and technologies that allow successful virtualization and storage consolidation for a more flexible IT infrastructure.
- +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future. - +
Data Management Edition #9: Data centre makeover 24/04/2008 07:43:06
This week CW Live looks at the death of the old style data centre which is undergoing its first makeover in more than 30 years. - +
IT Security Edition #9: Inside the bug trade. 16/04/2008 09:08:12
This week guidelines are released for the mandatory reporting of security breaches and we go inside the black market bug trade.
North East Water to deploy Gentrack Velocity upgrade 2008-05-12 09:54:00+10
Kroll Ontrack Launches Hardware Erasure Solution 2008-05-09 08:42:00+10
Mitel Releases New Cordless Technologies for IP Phones 2008-05-08 18:11:00+10
Citect earns recertification under the prestigious Service Capability and Performance (SCP) Standards 2008-05-08 14:07:00+10
Citect earns recertification under the prestigious Service Capability and Performance (SCP) Standards 2008-05-08 14:07:00+10
Integrating Telephony with Office Communications Server 2007
This paper defines in detail Microsoft’s strategy and approach to an enterprise’s integration of its telephony systems with Office Communications Server 2007.








