troubleshooting/tutorials/security

08/03/2007, 10:15am, EDT

Friday, August 3rd

MacBook Wi-Fi "hack" wins "Pwnie" award

The controversial MacBook Wi-Fi vulnerabilities demonstrated at last year's Black Hat conference have won an award for the most overhyped bug. Security researcher David Maynor claimed to have discovered vulnerabilities that could compromise MacBooks via wireless networking, but the acclaimed security flaws affected only older versions of Mac OS X as well as third-party wireless driver software that never shipped with a MacBook from Apple. "In the end, the only public information about Maynor's Wi-Fi vulnerabilities are hype, denial, a media frenzy, and a patch that may or may not have been based on Maynor's findings," said judges of the first ever "Pwnie" awards. Maynor and Jon "Johnny Cache" held the demonstration one year ago yesterday in response to a "Mac user base aura of smugness on security."

Maynor installed software that never shipped with Apple's notebook and compromised that software's security to gain unfettered access to the MacBook in question as part of his demonstration that Mac OS X and Mac users in particular are not immune to security threats. The researcher was criticized by industry peers for using a modified system to perform a public demonstration, though other security professionals did remind users that no one is safe from persistent, skilled attackers.

The researcher's flaw did work on previous versions of Mac OS X, but Apple quickly noted that all Apple owners who kept their systems up to date were immune to the security threat demoed by Maynor.

In related news, ZDNet reports that the OpenBSD team won the award for the most spectacular "mishandling" of a critical security vulnerability after refusing to acknowledge the bug as such. The team released a "reliability fix" before Core Security developed proof-of-concept code to demonstrate remote code execution just one week later.


Filed under: troubleshooting

, , 5comments, del.icio.us, slashdot, digg, buzz


5 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
Evil Pay Off
0
08/03, 11:30am, EDT
He is awarded a pwnie. As he leaves the building a giggling Steve Ballmer stops in front of him and slides a big wad of money in his coat pocket and continues giggling as he walks off.

Vista was probably hacked 2 to 3 times while I was typing this this.
Fresh-Faced Recruit
Joined Oct 2006
User is offline
ballmer would say
0
08/03, 11:56am, EDT
...'no one hacks the mac because no one uses it!'
Fresh-Faced Recruit
Joined Sep 2001
User is offline
Congrats Maynor
0
08/03, 12:48pm, EDT
You definitely earned it! Here's hoping you get a "lit cigarette in the eye"
Fresh-Faced Recruit
Joined Apr 2004
User is offline
Who takes this seriously?
0
08/03, 1:37pm, EDT
So he ads so software on the laptop that deals with ports and probably opens them up regardless of what you have them set at in SysPerfs. If you change the firewall settings, of COURSE you're going to have holes in the defenses. The firewall on the Mac is a no-brainer, so it's not an issue for most people.

This isn't even newsworthy other than the fact that they actually gave him an award for something he didn't really earn.

Why again do we care?
Fresh-Faced Recruit
Joined Dec 2005
User is offline
Pwnie award
0
08/04, 12:30pm, EDT
May they continue to award it to him every year.
Fresh-Faced Recruit
Joined Jul 2007
User is offline
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

Join The MyView IT Research Panel: Members will receive opportunities to take part in surveys from today's leading businesses.

Get an IT Degree Online: Get solid credentials. Take your hobby to the next level. Adult Programs. Affordable.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.