Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I find it interesting how Apple is defended when they make security blunders, while Microsoft was heavily slammed back in the day.

It is simply inacceptable that a user basically reported the issue on their support forum and didn't even get an answer back.



Every single time the topic of Microsoft's security track record has come up on HN, I've waded in to point out what a great job Microsoft has done. Here's one of my highest rated comments from several years ago:

http://news.ycombinator.com/item?id=577684

Now, I don't disagree with your general point: Microsoft gets more scrutiny than Apple does on HN about security, and Apple enjoys an inflated perception of platform security here --- I attribute that to a general Unix bias, by the way, and not to Apple fandom.

But please be careful to note that I'm not a part of that phenomenon. You will, if you dig, find comments of mine that are critical of Apple security; you will probably not find comments critical of Microsoft's security practices.

(To be clear: securing a whole platform is an incredibly difficult job, and platform software security talent is some of the hardest to find in the whole industry; both Apple and Microsoft take this stuff seriously and, compared to 2002, both do a fantastic job. Also: the security of the iOS platform is a different story than of the OS X platform.)


I don't see how comment history makes a separate comment more truthful. If anything, it makes people less likely to have proper critical thinking because they know you.

Which is exactly what he points out about your comment, but related to Apple. You know Apple thus you're less likely to criticize them properly.

It doesn't mean what you wrote is entirely wrong, but I think he has a point. MS is very harshly criticized for any security issue, no matter how small, and hey, that's probably a good thing.

For Apple if there's any possibility we find them.. excuses.. really? (and the "I don't know anyone who used file vault before!" sounds terrible, to be honest)


tptacek has been the most prominent defender of Microsoft's security practices on HN for years. Everything you guys are saying about how Apple get off easy while MS get slammed, he has said repeatedly and more coherently. And out of direct experience to boot.

It just didn't happen to be - and still isn't - relevant here.


My point is that it doesn't matter. For example if you follow my thread of comments some are going to be rated way up and actually be pretty insightful.

You'll notice sometimes I'm also wrong and make errors. You could get a strong opinion of me either way (good, or bad) by reading that.

If we were to know pretty well each person (like they do in smaller forums or places where the nickname and history is highlighted), we'd always agree and disagree with the same persons in general (there's always exceptions).

And the person's reply was made on a single post, which I think is the way to go.

I don't know if HN nicks are small and history not as easy to follow as in some other sites on purpose, but I like it.

Now, I've been way off topic, sorry :)

Slightly more on topic tho: MS ain't perfect security wise either, even thus they've made huge progress. Microsoft research also has very interesting attempts such as Singularity or Gazelle. I don't know any other company doing that. That's one place I'd want to work for MS.


> Also: the security of the iOS platform is a different story than of the OS X platform.

Interested in this. More secure or less? Any thoughts on it?


Way more secure. To be fair: I've come to this opinion via other, smarter researchers.


Microsoft may be pretty good in reacting to security issues, but many of the holes are results of mind-bogglingly stupid design decisions that are in a class of their own. ActiveX, anyone?


The parent comment isn't defending Apple; @tptacek is pointing out that this issue won't impact a large number of users, that the headline is misleading, and that maybe ZDNet is sensationalizing a minor issue.


It sounded defensive to me. "name a single case where ZDNet has broken a story we cared about" sounded like ZDNet should have shut up about this very important issue. It doesn't matter that they are not the first reporting it, their readers may thank them for it.


I think if your presumption is that my whole experience of ZDNet's security reporting is "when they happen to hit the HN front page", that's a reasonable reading. But it's not. I'm a software security person. I also know Ryan Naraine, well enough that we'd spot each other and say "hi" in a crowd. (I like Ryan, but ZDNet?). I've been interviewed by ZDNet people (we avoid press now).

I'm offering a carefully considered assessment: HN would probably be better off if we just banned ZDNet and venues like ZDNet. Ryan Naraine and Dancho Danchev have other outlets to write in that might make it to HN.


"I've been interviewed by ZDNet people (we avoid press now)."

Curious if one of the reasons for that is that it makes you a target?


That's not it. It's just, very minimal potential upside, lots of annoying downsides. Re-read everything you've read on HN about "being careful talking to the press", assume that --- unlike most startups --- the press is seeking you out pretty regularly, and then consider the mental energy required to minimize the downsides.


YMDV. I'm not even selling a high ticket item but back when I courted the press (simply by writing emails whenever a topic I knew about was mentioned) I've had results that have well paid for themselves in a) the effort and b) the misquotes and annoying downsides. (In one case my small company at the time was mentioned right next to AT&T in a list of 4 companies mentioned.)

I really can't imagine how it wouldn't pay for you (business wise) to be mentioned given what you do in mainstream press. In order to be mentioned in mainstream press it pays to have mention elsewhere as a starter. I can see a CEO with a security problem reading a quote of yours in the WSJ and handing the tearout to someone with the instructions to contact you about some issues they are dealing with. I can see links and quotes from both online and offline mention of your name appearing on your website and giving you and edge on your competition.

By the way mention on your website such as "Our work has been featured in Network World, eWeek, Forbes, Macworld, Wired, and the Washington Post, and at conferences ranging from Black Hat to Gartner" and links to or copies of said articles will not produce the same results. And if the articles are old that is why you need fresh mention.

That said I can totally see (which is why I asked) how a security researcher frequently mentioned in the press, like a former boxer sentenced to prison, becomes a juicy target and that is definitely a downside.


Couple things:

* In my particular line of business, the quality of one's website has vanishingly little to do with success. We have a cookie-cutter front page that says cookie-cutter things; its purpose is to confirm that we are, in fact, a real business. It succeeds at that.

* I have no doubt whatsoever that people outside software security, or maybe even new entrants in software security, have much to gain from press hits. But "fresh hits" do very little for us.

* Only a very small minority of our business is "event driven", such as when a CEO realizes he has an immediate security problem. We're an engineering service. In the overwhelming majority of cases, we're working for other engineers and their product managers who've known for ages that they need help with security; we get engaged when it makes sense in the budget and the dev cycle to engage us.

We're one of the largest pure, dedicated software security firms; we're also one of the more mature/established of them. Most of our business tomorrow will come from executing competently today; people who can reliably flush security flaws out of arbitrary pieces of software are in short supply and high demand.


> I find it interesting how Apple is defended when they make security blunders, while Microsoft was heavily slammed back in the day.

Given that we have a plurality of OS X users on HN (according to the last poll), it's not surprising that post-purchase rationalization is a common response to such articles.


"Post-purchase rationalization"? What a weird thing to say.


Not weird at all. It's a documented phenomenon in marketing research: http://www.jstor.org/discover/10.2307/3150288?uid=3739744...

Since its effect is directly proportional to the cost of the purchase in question, it would make sense that relatively expensive objects, such as smartphones and computers, would trigger a correspondingly stronger negative reaction to criticism of said product.


I'm not doubting that there is post-purchase rationalization. It's just weird to read it from my comment. You think the functioning of OS X's home directory encryption makes me feel threatened because I'm a Mac person?


tpacek is a person who says things about Apple. Not all people who say things about Apple are tpacek.

Saying "people defend the products they buy, sometimes wrongly" is not in any way controversial, and wasn't (in my opinion) about your comments.


Huh? It was a direct response to my comment.


No, it wasn't. It was directly in response to another comment someone else made, not you. They asked a general question, and this person answered that general question. Your comment might have sparked that general question, but it was not the focus of it.

Seriously, not everything need revolve around your one comment. FFS.


What are you Mr Miyagi ?


That is NOT correct.

Dissonance model has been shown to not be proportional to price. Which is intuitive as you see fervent defending of brands for products such as beer, wine, websites etc which are relatively low cost or have no cost to the user.


It's a well known behavior, once people have made a commitment they move from analyzing objectively to defending their choice. Not saying it is in play here, but it isn't really unheard of.

[1] http://en.m.wikipedia.org/wiki/Choice-supportive_bias


Dan Gilbert's TED Talk does a great job demonstrating this (http://www.ted.com/talks/dan_gilbert_asks_why_are_we_happy.h...).


Not really, it's very common, people defend things they have an interest in.


>Given that we have a plurality of OS X users on HN (according to the last poll), it's not surprising that post-purchase rationalization is a common response to such articles.

"Post-purchase rationalization", even if we are to take the sketchy "studies have shown route", goes for major stuff, not for each and every fault or bug in a bought product.

People ARE able to talk ill about their products, and in fact Mac and Windows and Linux users speak ill of their systems each and every bloody day. We even have mottos, like "FTFF".


"Back in the day", Microsoft didn't make security blunders. It made things fundamentally insecure as a matter of policy, and could get away with it because they had a virtual monopoly.

This significant difference informs how people respond, regardless of the nature of the blunder.


mrich, no company's engineers can be expected to spend their days reading every single thread on the company's support forum. I wonder if the researcher(s) reported the issue using Apple's Bug Reporter? It has a special category for Security.


What does "support" mean then? They absolutely should have staff skimming the forums and escalating important issues.


The post was made on the Enterprise servers forum. https://discussions.apple.com/thread/3715366

If your company sells software to businesses, the standards are a little higher. Either you make sure such a bug cannot slip through by testing, or you have to make it up in support by at least reading all the new customer questions.

How much effort is it to read the first post of every new thread started there? I bet it can be done by one guy who has basic knowledge of computers, heck just hire a Genius bar guy. :)


This comment doesn’t defend Apple. It doesn’t make any value judgments about Apple at all. It merely attacks the article.


Given that the article is pointing out a security hole in OSX, any attack of the article is an implicit defense of Apple.


When something is factually wrong it’s factually wrong. That’s it. There is nothing else to it.

Nobody said that there is no security hole and no problem.


The comment did not point out anything factually incorrect in the article. The claim was that the author didn't know anyone who engaged in the practices which would lead to a security breach. That's anecdote, not evidence - even given the poster's experience in security there's reason to suspect that such experience would be primarily with Mac installations which take security more seriously than Apple's marketing department portrays it.


Oh come on! Don’t be so dense.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: