International Mac Podcast

Blog RSS Subscribe by email

The Apple DNS Saga Continues

Posted on Saturday, August 2, 2008 by | 1 comment

Yesterday Apple released security update 2008-005 which was supposed to fix the DNS flaw I recently complained about Apple not having fixed yet. Well, it appears that Apple only half-fixed the problem. Yes, they have fixed the BIND DNS server in OS X, but in reality that only protects X-Serves running a DNS server. Sure, regular OS X ships with the BIND DNS server installed, but it’s not on by default, and almost no one turns it on. What we all use all the time is the stub resolver that’s part of OS X, and that’s what Apple didn’t fix. This means that regular Mac users are still not protected from this DNS flaw while just about everyone else is.

(more…)


One of the things I really love about OS X is its Unix underpinnings. Under the hood we get all the *nix tools and utilities I’ve come to know and love. Printing with CUPS, remote shell with OpenSSH, Windows sharing with SAMBA, web publishing with Apache, and so on and so forth. This gives OS X great power, but it also places a great responsibility on Apple. Just like with any other software, vulnerabilities surface in open source programs. In general the open source community is very responsive to security issues, and patches are released quickly. Those patches protect those who update, but they leave those who don’t even more vulnerable. The reason for this is that the patches can generally be reverse engineered, making it easy for the bad guys to attack un-patched machines. In order to keep OS X secure Apple need to push out patches in the open source components in OS X to users as quickly as possible. This is where Apple fall down, they are notoriously slow at getting patches out.

(more…)

Categories: Articles & Thoughts, News

Time’s Up – DNS Flaw Leaked

Posted on Tuesday, July 22, 2008 by | Add a comment

A few weeks back I posted about how there was a major flaw in DNS and how the details were being kept secret to give everyone time to patch. I did say that it would be a matter of when this got out, and not if. When turns out to be today. Details of the flaw were accidentally published on a blog and then un-published but once information gets out onto the net it’s out. There’s no way to put that genie into the bottle. I was able to find the details of the flaw, so if I can, the bad guys certainly can!

If you haven’t done so already, go to www.doxpara.com and click the button to check your DNS server:

DNS Server Test

Should the test fail, you need to do two things. Firstly you need to switch your DNS service to a safe service such as the free OpenDNS. Once that’s done you’re safe, however a few poor ISPs block DNS to all servers but their own so if you’re very unfortunate you will be unable to protect yourself. Secondly you need to contact your ISP to complain. It is not acceptable that hey are being slow about something as big as this. If they don’t give you a good response consider switching ISP. If they are not competent enough to keep their servers patched do you trust them?

Categories: News

This week it was announced that one of the core protocols that holds the internet together is fundamentally flawed. The problem is not with someone’s implementation of the protocol, but with the actual protocol itself. It’s hard to over-state just how big a deal this is. At the moment the details of the vulnerability are being kept secret to give the world time to patch, but you can get some technical information from the advisory issued by the US Cert. On Tuesday all the major DNS server vendors released patches at the same time. This is un-heard of, nothing like this has ever happened before in the history of the internet. That alone should bring home just how big this is.

Although the good-guys have successfully kept the details of the flaw secret to date, despite the large numbers of organisations involved, the reality is that the bad guys are frantically trying to figure this out as I type. It’s not a matter of if they’ll figure it out, but when. The security community have bought us time. That time should not be squandered, but used to protect the internet as a whole, and to protect ourselves.

(more…)

Categories: News