Showing posts with label patching. Show all posts
Showing posts with label patching. Show all posts

03 November, 2009

Android vs iPhone OS patching

I just finished reading the changelog for iPhone OS 3.0 on the Apple support-pages, and after reading the Google Android changelog from my recent Magic-update, Apple does not impress me that much anymore.


iPhone OS 3.0 (rls. june'09) had 38(!) vulnerabilities, many of them quite critical, whilst Android had a grand total of 2 vulnerabilities (critical announced ones that I can find online), which were even spread across 2 update-intervals 3 months apart...

1 of the vulnerabilities in Android involved applications having CAMERA-privileges without the user explicitly allowing it, and the other one involved maliciously crafted sms-messages that could reboot the device.

Most of the 38 counted vulnerabilities on the iPhone were critical. Involving post-actions ranging from a device-reset, to arbitrary code execution. What made me re-act was where in the system the bugs resided, which was just about everywhere!

The following sub-systems on iPhone OS 3.0 had vulnerabilities announced on the changelog: CoreGraphics, WebKit, ImageIO, IC for Unicode, IPSec, libxml, Mail, MPEG-4 Codec, Profile, Safari, Telephony, Exchange.

I'm really, REALLY glad I chose a device running an independantly developed open platform :) instead of a closed-source license-hog of a proprietary mobile overkill-system :P

Link:

13 October, 2009

Android OS & security

Ok, so I've been ranting on and on about Apple's and Microsoft's bad patching habits the last 6 months. There's a reason for my constant nagging, and that is: someone has to make everybody using these devices aware about the vulnerabilities and security-holes, and the procedures that are in pace to fix these issues.

The average user does not even recognize, much less read about and/or research about such things.

Then it is really up to the geeks and nerds (like myself) to try to convey a simplified explanation on these kinds of things. And the Android platform is no exception.

Google's Android OS has seen even MORE security-holes and vulnerabilities than both Apple and Microsoft since it's initial release, BUT, the Google-team developing and testing Android has direct communications with oCERT (the Open Source Computer Emergency Response Team) and so receives regular updates on critical vulnerabilities in Android, which are then rushed for patching.

Just recently, oCERT discovered two rather critical issues regarding custom-crafted SMS messages that results in a mobile-network disconnect, and another where malformed applications can generate a DoS-condition; actually rebooting the device Android is running on.

However critical these security-holes where, they have been patched since the first v1.5 service release.

Not only is the response team rapidly patching the platform, but it is even pushing out the updates only to devices that are affected by existing exploits, proof-of-concept attacks are even patched before they're exploited in RL.

Link:

29 April, 2009

Alle får!




Bra, lille Ballmer! Endelig litt fornuft fra Microsoft's side, vel, dette var allerede annonsert tidligere, men da ble det ikke sagt sort-på-hvitt at "alle får", men det ser ut som det er nettopp det som skjer nå.
Alle får!
Hvem får sikkerhetsoppdateringer? Det er et spørsmål Microsoft får oftere enn de hadde regnet med. Kanskje grunnet piratkopierings-sperrene i Windows XP og Vista.
Skal nettsikkerheten ivaretas for alle, må også alle være sikret. Dette er i alle fall et steg i riktig retning.

Levner ingen tvil
«Det ser ut til å være en myte at Microsoft holder tilbake Windows sikkerhetsoppdateringer og leverer dem kun til de som er eiere av ekte Windows. La meg være klar: alle sikkerhetsoppdateringer leveres til alle brukere» skriver selskapet på The Windows Blog.
Får håpe det fortsetter.

Men bare for å legge alles oppmerksomhet litt opp på G, så sies det i "The Windows Blog"-innlegget hvor dette legges frem, at ikke ALLE oppdateringer fra Windows Update sendes ut til alle brukere (uavhengig om de er genuine brukere eller pirater, noe jeg mener er lite trolig allikevel med tanke på hvem vi snakker om her) "fordi det kan dreie seg om ekstra-produkter innenfor Microsofts varesortiment" (les: pirat-kopierte enkelt-programmer).

System-oppdateringer sendes allikevel ut til alle, men det mener jeg er mer fordi pirat-maskiner ikke skal knele genuine brukeres nett-opplevelser, enn at "alle skal sikres best mulig".

Microsoft ser seg nok tvunget til å gi alle system-oppdateringer, men ikke å bevare bruker-opplevelsen til ikke-genuine brukere fordi "de ikke har bruker-rettigheter på gjeldende produkt" (sett ut ifra et juridisk standpunkt), så det er rett og slett mer en "fiks" for å garantere genuine brukeres rettigheter enn at pirat-brukere også skal ivaretas sikkerhetsmessig.


N.B.! Dette innlegget er IKKE ment som hets mot Microsoft. Jeg er en åpen tilhenger av OSS (Open Source Software), men jeg jobber til daglig med Microsoft-teknologi, og har årevis med erfaring med deres produkter, faktisk helt siden MS-DOS v4.