5 ms·
I wonder how well Apple has deployed these tools internally for security research. Since mid-April Chrome showed 302 vulnerabilities patched, 225 of them found
by concinds 5mo ago
I wonder how well Apple has deployed these tools internally for security research.
Since mid-April Chrome showed 302 vulnerabilities patched, 225 of them found by Google. Same period last year was 19 vulnerabilities. They've also become more transparent recently, disclosing vulnerabilities found internally, not just externally (which Apple still doesn't appear to do). From the outside, it's hard to tell if Apple has deployed this tooling as much as Google.
- JCattheATM 5mo agoI'd guess they haven't even begun to really utilize them. They've never been a terribly security conscious company, despite the marketing.
- xyzzy123 5mo agoWhat's your thinking on this? From my perspective Apple security go pretty hard. They have a strong track record of being able to ship architectural mitigations like PACs / MIE / Exclaves first. I guess because Apple control the stack from silicon to userspace.
- JCattheATM 5mo agoMy thinking was in a historical context, and for their desktop OS's. I know they've been pretty on top of things with iPhones, and MacOS has become a lot better, but for the longest time MacOS was pretty lacking, coasting very much on promoting how much PCs have viruses and macs didn't, which was a marketshare thing more than a security thing. I don't think they got ASLR until later than pretty much everyone else, for example. They've improved a lot, especially their phones, but I'd still never consider them a company that has a really strong focus on security.
- xyzzy123 5mo agoAgree that pre Apple Silicon, macOS didn't get much focus. Fair point historically.
- KennyBlanken 5mo agoThat's a really strange claim given AS was a refinement of a technology other manufacturers have yet to surpass in the ten years since the T1 chip came out. To this day nobody else ties their SMC, biometric auth, and HSM together as tightly and well as the T1 did. AS was further advancement of that. Furthermore, Apple protects users against the legal changes that have allowed law enforcement to physically force someone to provide biometric credentials. By default MS just provides biometric auth to make it easier to log in to your system.
- xyzzy123 5mo agoiOS always had a strong focus on security but if you take the time period say 2005 - 2015 it did not seem like there was much investment in macOS security at Apple. I am talking about stuff like exploit mitigations and relatively low hanging LPEs. Features like (full) ASLR / SIP / kext controls were added well after competitors.
- KennyBlanken 5mo agoThey were not "coasting" on anything. Everything about OS X has always been designed to protect users from the stuff Apple hasn't caught yet, because they know they can't always catch it first - and Apple has led the pack in nearly every major OS security feature of the last 25 years. That includes "don't give the user root, and ask the user for their password before doing dangerous things" - four years before Linux distros started moving to a similar model.
- jonhohle 5mo agoDidn’t Microsoft pioneer the privilege escalation prompts in Vista in 2007? It was a joke at the time how little things would hijack the entire screen to allow seemingly mundane things. I didn’t ever use Vista personally or professionally, but macOS has become pretty bad with basically the same model.
- KennyBlanken 5mo agoMacOS X prompted users for their passwords in 2001. Microsoft's implementation was (twenty years later still is) a joke because it prompted users to hit enter or click a button.
- JCattheATM 5mo agoMicrosoft's Secure Desktop feature is actually incredibly well designed, and provides strong protect against fraudulent prompts or prompt interception attacks.
- pjmlp 5mo agoOnly if you configure it like that, you can make it ask for a password, and on more recent versions of Windows 11, optionally, a single use token. Ironically Apple just recently added the same simpified approach.
- NekkoDroid 5mo ago> Only if you configure it like that It is the default (unless they changed it in the last 2 years or so). I know for a fact that my PC and Laptop don't ask for my password and I know for a fact that I reinstalled Windows on my laptop less than 2 years ago and changed nothing regarding the UAC prompt (the closest that is even remotely close is enabling sudo in the settings).
- dwaite 5mo agoWindows and macOS both got ASLR in 2007. For another example: macOS integrated antivirus in 2009, while Windows did so in 2012.
- JCattheATM 5mo agoApple's ASLR was incomplete and basically trash for a long time, it didn't get proper ASLR until much later.
- pjmlp 5mo agoI am PC, I am Mac campaign is from 2006, quite long time ago.
- JCattheATM 5mo agoSure, I think I gave it that context by using the term historical.
- AnthonyMouse 5mo ago> I guess because Apple control the stack from silicon to userspace. People always say this but there is no real relationship there. When hardware vendors add security technologies to the hardware, the major third party operating systems add support to use it pretty much immediately, and in many cases before the hardware even ships because the hardware vendor publishes the documentation ahead of time. Try to name something where Apple was the first to support something (by a non-trivial amount of time) not because they were the first to add hardware support but because they released the combination of hardware and software in the time between when e.g. Intel or Qualcomm added hardware support and when Linux or Windows added software support to use it.
- krisbolton 5mo agoI think Apple became much better at security in recent years. One example which I think is indicative of their approach to security - they bothered to add a hardware microphone disconnect when a macbook is closed. Source: https://support.apple.com/en-gb/guide/security/secbbd20b00b/web https://support.apple.com/en-gb/guide/security/secbbd20b00b/...
- guessmyname 5mo agoI am part of Apple's SEAR (Security Engineering and Architecture) organization and can’t attest that we have been using Anthropic models, including, but not limited to, Mythos, as part of our participation in Project Glassing and previous private partnerships with different frontier AI labs for years. We simply don’t talk about it because there’s no benefit to talk about it, and also NDA’s, but mostly because there’s no benefit to talk about it other than to satiate people’s curiosity about what we do or don’t do internally.
- nprateem 5mo ago[flagged]
- strictnein 5mo agoPerson with an internal viewpoint gives their perspective and you decide the best response was to bite their head off. Wonderful.
- riffraff 5mo agoYou wrote "can't attest" but the rest of what you wrote seems like you're actually attesting it. Typo, or I am just misreading?
- darig 5mo ago[dead]
- isomorphic 5mo agoThe heavily ironic implication is that they're under NDA, so they can't attest to it, while more or less attesting it. Senator, I cannot confirm or deny that we definitely do this. This could also be an unofficial-official way for Apple to "leak" that yes, they do this--which is on brand for how Apple handles "rumors" etc.
- riffraff 4mo ago