Mac Java Hack Signals Big Trouble, Says Analyst
"Apple will find itself eating a big piece of humble pie," says Enterprise Strategy Group's Jon Oltsik on the newly revealed security hole for Apple users.
A security update for Mac OS released two weeks earlier didn't include a patch. Apple now says it is aware of the issue and working on a fix. Security vendor SecureMac advises people to disable Java in their browsers until Apple fixes the problem.
[ Learn the details of the Java security hole in Mac OS X. | Apple's delay in fixing the problem prompted one hacker into action. ]
It's this kind of nonchalant attitude toward serious security problems that analysts like Jon Oltsik, Mac security analyst at the Enterprise Strategy Group, say is making them a bit irritated. He advises Apple to change its ways before it's too late.
Apple has until now gotten away with a lackluster response to security largely because Mac OS X (and Safari browser) flew under the radar of many hackers, he says. But as the platform rises in popularity, says Oltsik, hackers will soon take dead aim if they haven't already.
Oltisk talked with CIO.com about the impact of this security hole, as well as the potential fallout from what he calls Apple's cavalier approach to fixing such problems.
How serious is this Java vulnerability?
Oltsik: The vulnerability could be used to run a rogue executable, so it is very dangerous. It certainly simplifies the process of writing a malicious Mac exploit. I haven't yet seen malicious code "in the wild" that takes advantage of this vulnerability, but one could pop up anytime.
How can enterprises protect themselves?
Oltsik: Most enterprise Macs are protected with security software that could be updated with a signature or re-configured to block an exploit. Large organizations should be somewhat protected. Consumers and small businesses are more at risk.
What do you think about the actions of Landon Fuller?
Oltsik: I always equate security professionals with physicians in that they live by their own version of the Hippocratic oath. If a physician is on the scene of an accident, he or she feels a sense of duty to help. Likewise, a security professional feels the need to speak out about vulnerabilities and risks. When researchers are ignored, they often feel like their only recourse is to go public. Some people question these tactics, feeling that this could encourage attacks, but I don't share this opinion.
Apple



