Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Security

April 15th, 2010, 15:47 GMT · By

Apple Software Security Inferior to Microsoft’s, Says Iconic Hacker

SHARE:

Adjust text size:


Security
Enlarge picture
A security expert that build his career on identifying vulnerabilities in Microsoft software now says that the company has come a long way. Marc Maiffret, a former hacker turned legitimate security researcher, and now chief security architect at FireEye, told InSecurity Complex that Apple’s software was inferior to Microsoft’s in terms of security and the capacity of protecting end users, despite claims to the contrary by the Cupertino-based hardware company. In fact, Maiffret put Apple on the spot for marketing its software as more secure than Microsoft products, noting that it was just marketing and nothing more.

Still, the former hacker indicated that he had witnessed Apple starting to change its ways, and care more about security. “It's even a little scarier with them because they try to market themselves as more secure than the PC, that you don't have to worry about viruses, etc. Anytime there's been a hacking contest, within a few hours someone's found a new Apple vulnerability. If they were taking it seriously, they wouldn't claim to be more secure than Microsoft because they are very much not. And the Apple community is pretty ignorant to the risks that are out there as it relates to Apple. The reason we don't see more attacks out there compared to Microsoft is because their market share isn't near what Microsoft's is,” he stated.

According to Maiffret, before Apple only recently, in the past six months, started caring more about securing its products, it was at the same level as Microsoft before the January 2002 Trustworthy Computing memo from Bill Gates. But while he slapped Apple over the wrist, Maiffret praised Microsoft not only for the progress it had done over the better part of the past decade, but also because of the Security Development Lifecycle.

“Now when you look at Microsoft today they do more to secure their software than anyone. They're the model for how to do it. They're not perfect; there's room for improvement. But they are definitely doing more than anybody else in the industry, I would say,” he underlined. “[…] From an internal process in how they go about auditing their code and securing software from a technical perspective, they do have one of the best models. The area they still have room for improvement is around time lines of how long it takes for them to fix things.”

The Security Development Lifecycle is a model deployed by Microsoft internally, designed to secure software as much as possible by doing extensive testing to filter out vulnerabilities, and also ensure that when flaws do exist, mitigations are in place to make exploits extremely difficult, if not impossible. Windows Vista, the first Windows client to be produced in accordance with the best practices of the SDL, was also the company’s most secure operating system in history. Windows 7 was built on Vista’s legacy, and is bound to be just as, if not even more, secure compared with its predecessor.

In the first week of April 2010, Microsoft published the Security Development Lifecycle (SDL) Version 5 for all third-party software developers to leverage in their products.

FILED UNDER:
Apple
Microsoft
security
SDL

TELL US WHAT YOU THINK:

11,718 hits · 7 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft Patches 25 Vulnerabilities in Windows, Office and Exchange

Limited Troubleshooting on Unsupported Service Packs for Microsoft Products

Google Chrome 5.0.375.3 Dev for Windows

Vista RTM, the End Is Here

Patches Coming for 25 Vulnerabilities in Windows, Office and Exchange

READER COMMENTS:


Comment #1 by: C. Haagensli on 15 Apr 2010, 21:37 UTC reply to this comment

Been saying it for years now. It's the same tale about IE vs Firefox too.


Comment #2 by: bousozoku on 16 Apr 2010, 00:10 UTC reply to this comment

I would say that there isn't much difference. The huge security changes that were made for Windows Vista and have been continued in Windows 7 didn't make it much better. They were pushed aside nearly as quickly.

That's not to say that Apple care about the security of Mac OS X. They haven't done much about it, even when the solutions are placed in front of them, but most of the security issues have to be triggered locally, when you're in physical contact with the machine or on the same network, not from across the internet.


Comment #3 by: Bryan on 16 Apr 2010, 06:09 UTC reply to this comment

Wasn't Windows Server 2003 the first OS to get the full SDL treatment from Microsoft? I seem to recall reading about it at the time.


Comment #4 by: Jabwd on 16 Apr 2010, 11:12 UTC reply to this comment

Right, except that you only need 5 minutes to get administrator priviliges on windows without any restrictions. SECURE DUDE


Comment #5 by: metzger on 16 Apr 2010, 15:24 UTC reply to this comment

Arguing the market share angle is pretty weak. It sounds just as petty as Apple "pretending" they're more secure. Neither is more secure than the other, because security is largely determined by the how much stupid lies between the keyboard and chair. Apple users might just already be more versed in how not to screw themselves over by clicking on every link on the Internet. I'd argue that all OSes have the ignorance problem.


Comment #6 by: Abdul on 16 Apr 2010, 15:37 UTC reply to this comment

I agree, MS have been doing a better job. Moreover Apple's mistakes are, in computer terms, kindergarten types errors like buffer overflows.

@2. You are incorrect. See Security Update 2010-002 for a list of fixed remotely exploitable vulnerabilities on OS/X.


Comment #7 by: Hmmmm on 16 Apr 2010, 19:12 UTC reply to this comment

Linux's (and BSD's) security model is better than what M$ provides. These mitigation technologies that people like to compliment M$ for (ASLR/DEP) were not invented by M$ at all! They were invented by the open-source community for Linux first.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM