techy298
May 2, 08:26 PM
If anyone has information on how to download this file, as well as an apple id, please visit this page (https://discussions.apple.com/message/15116673)
thanks
thanks
Gelfin
Mar 27, 10:45 PM
Dr. Spitzer is an intelligent, nonreligious psychiatrist who believes that some can change their sexual orientations.
You just quoted me as saying something I did not say. Please correct it.
You just quoted me as saying something I did not say. Please correct it.
NT1440
Mar 16, 10:58 AM
For those of you advocating the elimination or reduction of nuke power, just realize that the only feasible alternative currently is...
Drill baby, drill!
While I have misgivings about Nuclear power I do think it is a good midrange solution to our problems until we can solve our battery problems (thus enabling true renewable energy sources to be viable), drilling isn't a viable solution to anything.
The US doesn't have the resources to provide for our society on our own. Not to mention that the whole process of drilling can take decades (meaning 10+ years, not something like 20+) to play through to the point where steady production can begin. You can't just go out and drill, even if you find something you have to set up the supporting infrastructure first before it is viable.
Drill baby, drill!
While I have misgivings about Nuclear power I do think it is a good midrange solution to our problems until we can solve our battery problems (thus enabling true renewable energy sources to be viable), drilling isn't a viable solution to anything.
The US doesn't have the resources to provide for our society on our own. Not to mention that the whole process of drilling can take decades (meaning 10+ years, not something like 20+) to play through to the point where steady production can begin. You can't just go out and drill, even if you find something you have to set up the supporting infrastructure first before it is viable.
Piggie
Apr 28, 02:06 PM
Well, in the future I'm talking about involving cloud computing, the link will be there but it will be over the air. But it seems you are talking about not having any link to iTunes. But then what do you want to link it to? The Android app market? Cydia? I mean, you need to have some place to link it to in order to hook into the world of apps (plus backups, etc.) Even our PCs are not standalone by that definition, basically needing a Net connection to get much done.
So what is an independent device to you? Independent of what?
I want it to be like a PC, a Mac or a Laptop.
I don't want to have to "Link" it to anything to do anything. I want a tablet to do everything itself without needing any linking to add functionality.
I don't want to "Link" it to any market, I want to download programs onto it, in the same way you can download apps onto a PC or a Mac without using any market if I so wish.
Backup?
You only do "Backups" like this to mobile temp devices, like phones and PDA's.
Sure, I can "COPY" my data onto a storage device if I wish, or perhaps another computer. Just like you do a PC or a Mac.
I don't take a full image of my PC and sync it to an even bigger computer. As my PC "IS" my bigger computer.
I want to be able to download data from my Tablet onto Any PC or MAC in the world by connecting a USB lead between the two and moving my data across, and perhaps upload some data from that PC or Mac also. Just like we can between Laptops, Macbooks, PC's and iMac's.
That's what I want. A Free and independent Tablet, not linked or synced or docked to any "larger" computer.
You don't do this with your Macbook as it's an independent computer in it's own right. All I want is the same from a Tablet.
So what is an independent device to you? Independent of what?
I want it to be like a PC, a Mac or a Laptop.
I don't want to have to "Link" it to anything to do anything. I want a tablet to do everything itself without needing any linking to add functionality.
I don't want to "Link" it to any market, I want to download programs onto it, in the same way you can download apps onto a PC or a Mac without using any market if I so wish.
Backup?
You only do "Backups" like this to mobile temp devices, like phones and PDA's.
Sure, I can "COPY" my data onto a storage device if I wish, or perhaps another computer. Just like you do a PC or a Mac.
I don't take a full image of my PC and sync it to an even bigger computer. As my PC "IS" my bigger computer.
I want to be able to download data from my Tablet onto Any PC or MAC in the world by connecting a USB lead between the two and moving my data across, and perhaps upload some data from that PC or Mac also. Just like we can between Laptops, Macbooks, PC's and iMac's.
That's what I want. A Free and independent Tablet, not linked or synced or docked to any "larger" computer.
You don't do this with your Macbook as it's an independent computer in it's own right. All I want is the same from a Tablet.
Eidorian
Sep 26, 10:29 AM
Pardon Me But Would You Please Track Down The Link To That Card And IM Me and post it here? I need it NOW! Thanks.
I will be on this thread until the Mac Pro Clovertown option ships. :D
This is the Mac Pro I have been waiting for.http://www.anandtech.com/storage/showdoc.aspx?i=2480
I know they're making a PCI Express, DDR2, SATA II version though. Old news to me...
I will be on this thread until the Mac Pro Clovertown option ships. :D
This is the Mac Pro I have been waiting for.http://www.anandtech.com/storage/showdoc.aspx?i=2480
I know they're making a PCI Express, DDR2, SATA II version though. Old news to me...
skunk
Mar 14, 06:34 PM
James Lovelock described nuclear as 'the only green choice'.Would that be an "unearthly" green choice? As in "glow-in-the-dark"?
Then you're probably more shocked at the Canadians, Norwegians, and Swedes, who consume more power per person than Americans do. Iceland consumes twice as much per person than us. And they don't even use AC.I guess keeping warm is more expensive than keeping cool. I thought their insulation was so much better. :confused:
Then you're probably more shocked at the Canadians, Norwegians, and Swedes, who consume more power per person than Americans do. Iceland consumes twice as much per person than us. And they don't even use AC.I guess keeping warm is more expensive than keeping cool. I thought their insulation was so much better. :confused:
AppliedVisual
Oct 29, 06:08 PM
[QUOTE=AppliedVisual;2994702]
The bug, of course, is that the programmer allocated space for 4 threads (since he knew that was the max number of CPUs :rolleyes: ).
I guess so... Heh. I guess I should have gave it more than a quick glance (did I even look at the array declaration?) before commenting. Oh, well...
The bug, of course, is that the programmer allocated space for 4 threads (since he knew that was the max number of CPUs :rolleyes: ).
I guess so... Heh. I guess I should have gave it more than a quick glance (did I even look at the array declaration?) before commenting. Oh, well...
MacCoaster
Oct 10, 02:21 AM
Originally posted by javajedi
Someone inquired about the benchmark Java console program I created:
It's located at http://members.ij.net/javajedi
I've also included the source (FPMathTest.java) for the curious.
<snip>
Kevin
That was me. :)
Thanks. See above post for my results. I even ported your Java code to C# (so similar, it scared me!) and got slightly lower numbers.
8152, 8151, 8162, 8142, 8172, 8142, 8161, 8152... all for a final average of 8154.25.
[edit: whoa, recently got 7891... running it more to average]
[edit #2: 7891, 7892, 7902, 7891, 7882, 7892, 7882, 7881... all for a final average of 7889.125]
You may have the source code/binary to test on your Windows computer (or Linux, with Mono; or BSD, with Microsoft's ROTOR)--just give me a hoot.
Someone inquired about the benchmark Java console program I created:
It's located at http://members.ij.net/javajedi
I've also included the source (FPMathTest.java) for the curious.
<snip>
Kevin
That was me. :)
Thanks. See above post for my results. I even ported your Java code to C# (so similar, it scared me!) and got slightly lower numbers.
8152, 8151, 8162, 8142, 8172, 8142, 8161, 8152... all for a final average of 8154.25.
[edit: whoa, recently got 7891... running it more to average]
[edit #2: 7891, 7892, 7902, 7891, 7882, 7892, 7882, 7881... all for a final average of 7889.125]
You may have the source code/binary to test on your Windows computer (or Linux, with Mono; or BSD, with Microsoft's ROTOR)--just give me a hoot.
munkery
May 2, 04:56 PM
Again, look, if you're not interested in the mechanics, that's fine. Stop replying to me.
My post is inquiring about the mechanics. For the past hour, I've been trying to find how this thing ticks by searching around for in-depth articles (none to find, everyone just points to Intego's brief overview that is seriously lacking in details) or for the archive itself.
If you don't want to take this discussion to the technical level I am trying to take it, just don't participate.
The Javascript exploit injected code into the Safari process to cause the download of a payload. That payload was the installer. (EDIT: the Javascript code did not exploit a vulnerability in Safari).
The installer is marked as safe to auto-execute if "open safe files after downloading" is turned on.
An installer is used to trick users to authenticate because the malware does not include privilege escalation via exploitation.
If you had any technical knowledge you could have figured that out yourself via the Intego article.
I don't know of any other Web browser (this is not a OS problem, it's a Safari problem) that automatically assumes executables are safe and thus should be auto-executed.
Installers being marked as safe really doesn't increase the likelihood of user level access as any client-side exploit provides user level access. I don't understand why you are hung up on this installer being able to auto-execute; it really makes no difference in terms of user level access. The attacker could have deleted your files with just an exploit that provides user level access.
What does Webkit2 have anything to do with running an installer on the OS after downloading it ? That happens outside the rendering engine's sandbox. You're not quite understanding what this sandbox does if you think this protects you against these types of attacks.
Webkit2 will prevent user level access via an exploit. Preventing these types of attacks is the intended purpose of sandboxing.
My post is inquiring about the mechanics. For the past hour, I've been trying to find how this thing ticks by searching around for in-depth articles (none to find, everyone just points to Intego's brief overview that is seriously lacking in details) or for the archive itself.
If you don't want to take this discussion to the technical level I am trying to take it, just don't participate.
The Javascript exploit injected code into the Safari process to cause the download of a payload. That payload was the installer. (EDIT: the Javascript code did not exploit a vulnerability in Safari).
The installer is marked as safe to auto-execute if "open safe files after downloading" is turned on.
An installer is used to trick users to authenticate because the malware does not include privilege escalation via exploitation.
If you had any technical knowledge you could have figured that out yourself via the Intego article.
I don't know of any other Web browser (this is not a OS problem, it's a Safari problem) that automatically assumes executables are safe and thus should be auto-executed.
Installers being marked as safe really doesn't increase the likelihood of user level access as any client-side exploit provides user level access. I don't understand why you are hung up on this installer being able to auto-execute; it really makes no difference in terms of user level access. The attacker could have deleted your files with just an exploit that provides user level access.
What does Webkit2 have anything to do with running an installer on the OS after downloading it ? That happens outside the rendering engine's sandbox. You're not quite understanding what this sandbox does if you think this protects you against these types of attacks.
Webkit2 will prevent user level access via an exploit. Preventing these types of attacks is the intended purpose of sandboxing.
DeepDish
Aug 29, 11:16 AM
Hmm. Gut feeling's all very well, but Apple obviously do a great job of marketing themselves as a friendly green company and we may go round believing that without evidence, and it looks as if the figures don't back them up.
danielwsmithee is right.
Dell boxes have a shorter life span and need to be replaced more often. Dell sells a lot more CRTs than Apple does.
At work, we never throw out a mac. But the pc boxes get replaced often.
This report is about getting "big press"
danielwsmithee is right.
Dell boxes have a shorter life span and need to be replaced more often. Dell sells a lot more CRTs than Apple does.
At work, we never throw out a mac. But the pc boxes get replaced often.
This report is about getting "big press"

Cromulent
Mar 26, 08:10 AM
Are you serious? That's a horrible thing to say. They should deprive themselves of sex because your 2000 year old book says so? That's crap. God made them born that way, for what? Just to torture them for their whole lives?
I'm not condoning the belief but priests are expected to do it, so why not gay people? Logically I imagine from a Catholic perspective it makes sense. My sister and brother in law both being Catholic gives me a bit of an insight into this topic and both are rather progressive.
I'm not condoning the belief but priests are expected to do it, so why not gay people? Logically I imagine from a Catholic perspective it makes sense. My sister and brother in law both being Catholic gives me a bit of an insight into this topic and both are rather progressive.
flopticalcube
Apr 22, 10:58 PM
On other forums, people complain about the word agnostic.
>agnostic theist- I believe in god, but have no knowledge of him.
>agnostic atheist- I don't belief in god, but I don't claim a special source of knowledge for that disbelief
>gnostic theist-I know that is a god!
>gnostic atheist-I know there is no god with the same degree of certainty that the theist knows there is one.
I don't think that many would call themselves a gnostic atheist, I certainly don't.
Dawkins might. As I said before, most atheists are agnostic atheists.
>agnostic theist- I believe in god, but have no knowledge of him.
>agnostic atheist- I don't belief in god, but I don't claim a special source of knowledge for that disbelief
>gnostic theist-I know that is a god!
>gnostic atheist-I know there is no god with the same degree of certainty that the theist knows there is one.
I don't think that many would call themselves a gnostic atheist, I certainly don't.
Dawkins might. As I said before, most atheists are agnostic atheists.
Multimedia
Sep 28, 04:40 PM
Is there any advantage or disadvantage (other than future expandability) to getting to 4GB of memory by using 8x512MB versus using 4x1GB?Aparently the answer is "technically yes". See below. I did not know that. But from what they say and a practical point of view the answer is still no.
gorgeousninja
Apr 21, 08:58 AM
What's wrong with that? I may not own a particular product but like being in X products forums to learn about it.
in your case 'learning about a product' seems to revolve around telling everyone how misguided they are.
maybe you need to look up the definition of learning.
in your case 'learning about a product' seems to revolve around telling everyone how misguided they are.
maybe you need to look up the definition of learning.
bobr1952
May 2, 11:40 AM
I turned off automatically open safe files years ago in Tiger and have migrated that setting over since.
I too turned this feature off a long time ago--but still--this seems like a feature Apple needs to get rid of in Safari--not all that useful and potentially dangerous to unsuspecting users.
I too turned this feature off a long time ago--but still--this seems like a feature Apple needs to get rid of in Safari--not all that useful and potentially dangerous to unsuspecting users.
Silentwave
Jul 11, 11:05 PM
I doubt that Apple are able to charge the "normal" Mac premium after the intel transition, since it is much simpler to compare Macs with another PCs. Almost like Apple for Apple. ;)
they'll be priced about in line with comparable systems. but that ain't cheap. I priced a dell precision workstation with dual xeon 5160 (3ghz woodcrest), 4GB 533 mhz DDR2 FB-DIMM RAM (apple may just use 667, only $50 more for the 4 gigs) , 2x500GB SATA 3gbps HD, 512mb Quadro FX 4500, no monitor, speakers etc. and it came out to just shy of $7800.
I then went on the apple store site, built a PM G5 quad with 4GB ECC 533mhz DDR2 SDRAM (4x1gb) which is not as expensive as FBDIMM memory, 2x500GB Sata HDDs (but i think sata 1.5gbps not 3.0), quadro FX 4500, and so on and it came out to a tad over $7000, just shy of $7300 when you add applecare in, since the dell workstation has an included 3 year plan.
if you add in a 20" LCD to each, the PM is cheaper by about 150.
I don't know how much more FB-DIMM will cost from apple, or how much they'll charge for sata3gbps HDs or how much more the woodcrests will cost versus the G5s. But we may see a price jump in the top end. Still we will see a nice jump in performance as well.
Of course if we adjust the above scenario away from the 3ghz Xeon 5160, to 2 of the more affordable Xeon 5150, 2.67GHz dual cores, ( 1333mt/s FSB, 4MB L2 just like the 3ghz) , the prices change a lot. $800 cut right there on the processors. The Dell is now cheaper by $350, no monitors.
FB-DIMM ram is pretty expensive. Apple cannot afford to put a huge premium on it though like they do now. Granted, it always has ECC so that is nice.
All i hope is that they have dual 3ghz woodcrests and are good enough that when I get one with clovertown MP or tigerton next year, i can get up to 64GB RAM, and at least 3 SAS or SATA 3g drives (its not called sata II).
they'll be priced about in line with comparable systems. but that ain't cheap. I priced a dell precision workstation with dual xeon 5160 (3ghz woodcrest), 4GB 533 mhz DDR2 FB-DIMM RAM (apple may just use 667, only $50 more for the 4 gigs) , 2x500GB SATA 3gbps HD, 512mb Quadro FX 4500, no monitor, speakers etc. and it came out to just shy of $7800.
I then went on the apple store site, built a PM G5 quad with 4GB ECC 533mhz DDR2 SDRAM (4x1gb) which is not as expensive as FBDIMM memory, 2x500GB Sata HDDs (but i think sata 1.5gbps not 3.0), quadro FX 4500, and so on and it came out to a tad over $7000, just shy of $7300 when you add applecare in, since the dell workstation has an included 3 year plan.
if you add in a 20" LCD to each, the PM is cheaper by about 150.
I don't know how much more FB-DIMM will cost from apple, or how much they'll charge for sata3gbps HDs or how much more the woodcrests will cost versus the G5s. But we may see a price jump in the top end. Still we will see a nice jump in performance as well.
Of course if we adjust the above scenario away from the 3ghz Xeon 5160, to 2 of the more affordable Xeon 5150, 2.67GHz dual cores, ( 1333mt/s FSB, 4MB L2 just like the 3ghz) , the prices change a lot. $800 cut right there on the processors. The Dell is now cheaper by $350, no monitors.
FB-DIMM ram is pretty expensive. Apple cannot afford to put a huge premium on it though like they do now. Granted, it always has ECC so that is nice.
All i hope is that they have dual 3ghz woodcrests and are good enough that when I get one with clovertown MP or tigerton next year, i can get up to 64GB RAM, and at least 3 SAS or SATA 3g drives (its not called sata II).
Heavyhitter504
Mar 18, 11:31 AM
I actually paid for MyWi and I only use it to tether my iPad. I use it instead of (not in addition to) my iPhone and only when wifi is not available.
This is what I do, I'm on the "unlimited" plan and I haven't received any text or email regarding the warning about tethering, i hope it's because I dont surpass the 5 gb cap
This is what I do, I'm on the "unlimited" plan and I haven't received any text or email regarding the warning about tethering, i hope it's because I dont surpass the 5 gb cap
Apple OC
Mar 12, 08:55 AM
Before everyone jumps to conclusions and spreads fear mongering ... as I said this will not be like Chernobyl.
While we are all on the same page and wish for the best news possible for the region ... we need to look at this with proper perspective.
Chernobyl was 25 years ago and happened in a country known at the time to reject outside help.
What is unfolding in Japan will be dealt with by the very best experts the World has to offer.
I have complete confidence no matter how this turns ... The Japanese Government will do what is right for the people who live there.
IMO ... this will be under control quite soon. Watching it on the news and the Internet is almost pathetic ... the Media seems to want this to get bigger.
We all wish the best for everyone affected by this tragedy.
While we are all on the same page and wish for the best news possible for the region ... we need to look at this with proper perspective.
Chernobyl was 25 years ago and happened in a country known at the time to reject outside help.
What is unfolding in Japan will be dealt with by the very best experts the World has to offer.
I have complete confidence no matter how this turns ... The Japanese Government will do what is right for the people who live there.
IMO ... this will be under control quite soon. Watching it on the news and the Internet is almost pathetic ... the Media seems to want this to get bigger.
We all wish the best for everyone affected by this tragedy.
skunk
Apr 26, 05:38 PM
I could murder some toast.
Apple OC
Mar 15, 08:34 PM
how can they NOT design for the possibility of coolant failure in the holding basin and put it also within a containment vessel? especially if, as you imply, there are some spent rods in it pretty much at any time.
They just did not predict a tsunami of this scale causing the situation we are now faced with.
Unfortunately it takes something like this to correct mistakes moving forward. That being said ... this will get fixed.
This Nuclear Disaster has now been confirmed as the worst since Chernobyl and is far from being resolved.
I wish the heros working on this all the best.
They just did not predict a tsunami of this scale causing the situation we are now faced with.
Unfortunately it takes something like this to correct mistakes moving forward. That being said ... this will get fixed.
This Nuclear Disaster has now been confirmed as the worst since Chernobyl and is far from being resolved.
I wish the heros working on this all the best.
jbgh
Mar 18, 09:07 AM
Forcibly changing my plan with zero evidence of anything is illegal and they will pay for it. Tme to start blasting them on Facebook, twitter, everywhere possible.
yeah that'll get them...
yeah that'll get them...
�algiris
Apr 28, 12:11 PM
They didn't delete the word "computer" from the Apple name for nothing.
I could use a good laugh. Please "deduce" this one.
I could use a good laugh. Please "deduce" this one.
KnightWRX
May 2, 05:51 PM
Until Vista and Win 7, it was effectively impossible to run a Windows NT system as anything but Administrator. To the point that other than locked-down corporate sites where an IT Professional was required to install the Corporate Approved version of any software you need to do your job, I never knew anyone running XP (or 2k, or for that matter NT 3.x) who in a day-to-day fashion used a Standard user account.
Of course, I don't know of any Linux distribution that doesn't require root to install system wide software either. Kind of negates your point there...
In contrast, an "Administrator" account on OS X was in reality a limited user account, just with some system-level privileges like being able to install apps that other people could run. A "Standard" user account was far more usable on OS X than the equivalent on Windows, because "Standard" users could install software into their user sandbox, etc. Still, most people I know run OS X as Administrator.
You could do the same as far back as Windows NT 3.1 in 1993. The fact that most software vendors wrote their applications for the non-secure DOS based versions of Windows is moot, that is not a problem of the OS's security model, it is a problem of the Application. This is not "Unix security" being better, it's "Software vendors for Windows" being dumber.
It's no different than if instead of writing my preferences to $HOME/.myapp/ I'd write a software that required writing everything to /usr/share/myapp/username/. That would require root in any decent Unix installation, or it would require me to set permissions on that folder to 775 and make all users of myapp part of the owning group. Or I could just go the lazy route, make the binary 4755 and set mount opts to suid on the filesystem where this binary resides... (ugh...).
This is no different on Windows NT based architectures. If you were so inclined, with tools like Filemon and Regmon, you could granularly set permissions in a way to install these misbehaving software so that they would work for regular users.
I know I did many times in a past life (back when I was sort of forced to do Windows systems administration... ugh... Windows NT 4.0 Terminal Server edition... what a wreck...).
Let's face it, Windows NT and Unix systems have very similar security models (in fact, Windows NT has superior ACL support out of the box, akin to Novell's close to perfect ACLs, Unix is far more limited with it's read/write/execute permission scheme, even with Posix ACLs in place). It's the hoops that software vendors outside the control of Microsoft made you go through that forced lazy users to run as Administrator all the time and gave Microsoft such headaches.
As far back as I remember (when I did some Windows systems programming), Microsoft was already advising to use the user's home folder/the user's registry hive for preferences and to never write to system locations.
The real differenc, though, is that an NT Administrator was really equivalent to the Unix root account. An OS X Administrator was a Unix non-root user with 'admin' group access. You could not start up the UI as the 'root' user (and the 'root' account was disabled by default).
Actually, the Administrator account (much less a standard user in the Administrators group) is not a root level account at all.
Notice how a root account on Unix can do everything, just by virtue of its 0 uid. It can write/delete/read files from filesystems it does not even have permissions on. It can kill any system process, no matter the owner.
Administrator on Windows NT is far more limited. Don't ever break your ACLs or don't try to kill processes owned by "System". SysInternals provided tools that let you do it, but Microsoft did not.
All that having been said, UAC has really evened the bar for Windows Vista and 7 (moreso in 7 after the usability tweaks Microsoft put in to stop people from disabling it). I see no functional security difference between the OS X authorization scheme and the Windows UAC scheme.
UAC is simply a gui front-end to the runas command. Heck, shift-right-click already had the "Run As" option. It's a glorified sudo. It uses RDP (since Vista, user sessions are really local RDP sessions) to prevent being able to "fake it", by showing up on the "console" session while the user's display resides on a RDP session.
There, you did it, you made me go on a defensive rant for Microsoft. I hate you now.
My response, why bother worrying about this when the attacker can do the same thing via shellcode generated in the background by exploiting a running process so the the user is unaware that code is being executed on the system
Because this required no particular exploit or vulnerability. A simple Javascript auto-download and Safari auto-opening an archive and running code.
Why bother, you're not "getting it". The only reason the user is aware of MACDefender is because it runs a GUI based installer. If the executable had had 0 GUI code and just run stuff in the background, you would have never known until you couldn't find your files or some chinese guy was buying goods with your CC info, fished right out of your "Bank stuff.xls" file.
That's the thing, infecting a computer at the system level is fine if you want to build a DoS botnet or something (and even then, you don't really need privilege escalation for that, just set login items for the current user, and run off a non-privilege port, root privileges are not required for ICMP access, only raw sockets).
These days, malware authors and users are much more interested in your data than your system. That's where the money is. Identity theft, phishing, they mean big bucks.
Of course, I don't know of any Linux distribution that doesn't require root to install system wide software either. Kind of negates your point there...
In contrast, an "Administrator" account on OS X was in reality a limited user account, just with some system-level privileges like being able to install apps that other people could run. A "Standard" user account was far more usable on OS X than the equivalent on Windows, because "Standard" users could install software into their user sandbox, etc. Still, most people I know run OS X as Administrator.
You could do the same as far back as Windows NT 3.1 in 1993. The fact that most software vendors wrote their applications for the non-secure DOS based versions of Windows is moot, that is not a problem of the OS's security model, it is a problem of the Application. This is not "Unix security" being better, it's "Software vendors for Windows" being dumber.
It's no different than if instead of writing my preferences to $HOME/.myapp/ I'd write a software that required writing everything to /usr/share/myapp/username/. That would require root in any decent Unix installation, or it would require me to set permissions on that folder to 775 and make all users of myapp part of the owning group. Or I could just go the lazy route, make the binary 4755 and set mount opts to suid on the filesystem where this binary resides... (ugh...).
This is no different on Windows NT based architectures. If you were so inclined, with tools like Filemon and Regmon, you could granularly set permissions in a way to install these misbehaving software so that they would work for regular users.
I know I did many times in a past life (back when I was sort of forced to do Windows systems administration... ugh... Windows NT 4.0 Terminal Server edition... what a wreck...).
Let's face it, Windows NT and Unix systems have very similar security models (in fact, Windows NT has superior ACL support out of the box, akin to Novell's close to perfect ACLs, Unix is far more limited with it's read/write/execute permission scheme, even with Posix ACLs in place). It's the hoops that software vendors outside the control of Microsoft made you go through that forced lazy users to run as Administrator all the time and gave Microsoft such headaches.
As far back as I remember (when I did some Windows systems programming), Microsoft was already advising to use the user's home folder/the user's registry hive for preferences and to never write to system locations.
The real differenc, though, is that an NT Administrator was really equivalent to the Unix root account. An OS X Administrator was a Unix non-root user with 'admin' group access. You could not start up the UI as the 'root' user (and the 'root' account was disabled by default).
Actually, the Administrator account (much less a standard user in the Administrators group) is not a root level account at all.
Notice how a root account on Unix can do everything, just by virtue of its 0 uid. It can write/delete/read files from filesystems it does not even have permissions on. It can kill any system process, no matter the owner.
Administrator on Windows NT is far more limited. Don't ever break your ACLs or don't try to kill processes owned by "System". SysInternals provided tools that let you do it, but Microsoft did not.
All that having been said, UAC has really evened the bar for Windows Vista and 7 (moreso in 7 after the usability tweaks Microsoft put in to stop people from disabling it). I see no functional security difference between the OS X authorization scheme and the Windows UAC scheme.
UAC is simply a gui front-end to the runas command. Heck, shift-right-click already had the "Run As" option. It's a glorified sudo. It uses RDP (since Vista, user sessions are really local RDP sessions) to prevent being able to "fake it", by showing up on the "console" session while the user's display resides on a RDP session.
There, you did it, you made me go on a defensive rant for Microsoft. I hate you now.
My response, why bother worrying about this when the attacker can do the same thing via shellcode generated in the background by exploiting a running process so the the user is unaware that code is being executed on the system
Because this required no particular exploit or vulnerability. A simple Javascript auto-download and Safari auto-opening an archive and running code.
Why bother, you're not "getting it". The only reason the user is aware of MACDefender is because it runs a GUI based installer. If the executable had had 0 GUI code and just run stuff in the background, you would have never known until you couldn't find your files or some chinese guy was buying goods with your CC info, fished right out of your "Bank stuff.xls" file.
That's the thing, infecting a computer at the system level is fine if you want to build a DoS botnet or something (and even then, you don't really need privilege escalation for that, just set login items for the current user, and run off a non-privilege port, root privileges are not required for ICMP access, only raw sockets).
These days, malware authors and users are much more interested in your data than your system. That's where the money is. Identity theft, phishing, they mean big bucks.
AidenShaw
Jul 13, 07:07 AM
it depends whether you are looking at it from software-perspective or hardware-perspective.
Actually, it looks the same from both perspectives.
Yonah, Conroe and Merom have full hardware SMP support on the package (or on the chip itself).
The cache coherency and inter-processor (in this case meaning inter-core) communications features are present, and must be present in order to avoid corrupting memory data and to support an SMP operating system.
The difference with Woodcrest is that Yonah/Conroe/Merom do not support SMP features *between* sockets - the cache coherency and IPC mechanisms are not brought out to the pins on the package.
Woodcrest brings those signals out to the pins, and the Woodcrest's 5000x chipset connects those signals between sockets.
Actually, it looks the same from both perspectives.
Yonah, Conroe and Merom have full hardware SMP support on the package (or on the chip itself).
The cache coherency and inter-processor (in this case meaning inter-core) communications features are present, and must be present in order to avoid corrupting memory data and to support an SMP operating system.
The difference with Woodcrest is that Yonah/Conroe/Merom do not support SMP features *between* sockets - the cache coherency and IPC mechanisms are not brought out to the pins on the package.
Woodcrest brings those signals out to the pins, and the Woodcrest's 5000x chipset connects those signals between sockets.
No comments:
Post a Comment