Security issues with Lion

Anyone know what the real deal is with OS X Lion security.  I've heard lots of things about how the recent Blackhat conference in Las Vegas said that Apple's security was not as good as Windows 7's.  Anyone know anything about this?  Thanks in advance for any feedback or input.

JB2909 wrote:
I've downloaded Java for OS X Lion 2012-001 to fix the security issues with Java but when I open it to install it gives me an error message saying don't open it as it has a disk image issue (?) and may make my computer less secure or cause other issues? I don't understand why it would cause security risks when it is supposed to be a patch to fix them?!  Is it safe to go ahead and open/install?
Could that be why Apple has released Java for OS X Lion 2012-002 here: http://support.apple.com/kb/DL1515 ?

Similar Messages

  • Using latest version of fireFox to access Think Central, pages will not load and they say that this is a security issue with FireFox?

    Teachers in our district are supposed to use www.thinkcentral.com with FireFox.
    Some have no problem accessing the lesson plans.
    Most when they login click on a lesson plan and an icon shows up that says loading but never does.
    If you reboot the computer and login you can open a page once but not a second time and no other lessons will open.
    Think Central support says this is a security issue with Firefox.
    I have updated FireFox, all the Adobe, Reader, Flash, Air and Shockwave. As well as Java.
    I have allowed the pop ups to the think Central web site.
    Any help would be appreciated

    Are there any notification icons on the left end of the address bar? If so, please click them to see whether they related to security issues (such as blocked content - shield icon: [[How does content that isn't secure affect my safety?]]) or a plugin requiring permission (Lego-like icon).
    Does Think Central have any help pages about this issue? Without an account, it is difficult to explore the issue first-hand.

  • Severe Security Issue with Sharing Permissions and Windows

    I recently discovered a severe Security issue with the windows sharing an permission settings:
    I have two users, an admin user and a parental controlled user. On my mac mini, i have a external harddrive connected. On the harddrive, i have three folders, Itunes, Iphoto (Package) and a Temp Folder. I want to share the Harddrive RW for the admin, but only R for the parental user. But the Temp folder should be accessible for RW for the parental as well.
    1. I set the Drive checkbox "ignore ownership" off.
    2. I set the permissions of the drive to admin RW, parental R and Everyone to "no access"
    3. I apply to enclosed Items
    4. I set the permission of the Temp folder to admin RW, parental RW and Everyone to "no access"
    5. I apply to enclosed Items
    6. I go to "File Sharing" in the Preferences and activate SMB sharing for both users
    7. I delete all previous shares
    8. I add the Disk and use the proposed permissions which are admin RW, parental R, Everyone "no access"
    9. I add the Temp folder and use the proposed permissions which are admin RW, parental RW, Everyone "no access" - Funny, there is a new Group called "Temp" created which has custom access on both sharepoints
    10. I connect to the mac over a Windows machine (NTLM auth set appropriatly). Now I try to create a folder on the root of the Disk share, I get a denied message.
    BUT WHEN I GO INTO A SUBFOLDER (eg. ITUNES or IPHOTO), WHICH HAS ALSO JUST "R" PERMISSION FOR THE PARENTAL USER, I AM ABLE TO RW, DELETE AND DO EVERYTHING!!!
    TO RECAPITULATE: THE SHARING PERMISSIONS ARE "R", AND THE FILE PERMISSIONS IN THE RESPECTIVE FOLDERS FOR THE RESPECTIVE USER ARE ALSO JUST "R". BUT THE USER CAN DO EVERYTHING IN THE SUBFOLDERS!!!

    I recently discovered a severe Security issue with the windows sharing an permission settings:
    I have two users, an admin user and a parental controlled user. On my mac mini, i have a external harddrive connected. On the harddrive, i have three folders, Itunes, Iphoto (Package) and a Temp Folder. I want to share the Harddrive RW for the admin, but only R for the parental user. But the Temp folder should be accessible for RW for the parental as well.
    1. I set the Drive checkbox "ignore ownership" off.
    2. I set the permissions of the drive to admin RW, parental R and Everyone to "no access"
    3. I apply to enclosed Items
    4. I set the permission of the Temp folder to admin RW, parental RW and Everyone to "no access"
    5. I apply to enclosed Items
    6. I go to "File Sharing" in the Preferences and activate SMB sharing for both users
    7. I delete all previous shares
    8. I add the Disk and use the proposed permissions which are admin RW, parental R, Everyone "no access"
    9. I add the Temp folder and use the proposed permissions which are admin RW, parental RW, Everyone "no access" - Funny, there is a new Group called "Temp" created which has custom access on both sharepoints
    10. I connect to the mac over a Windows machine (NTLM auth set appropriatly). Now I try to create a folder on the root of the Disk share, I get a denied message.
    BUT WHEN I GO INTO A SUBFOLDER (eg. ITUNES or IPHOTO), WHICH HAS ALSO JUST "R" PERMISSION FOR THE PARENTAL USER, I AM ABLE TO RW, DELETE AND DO EVERYTHING!!!
    TO RECAPITULATE: THE SHARING PERMISSIONS ARE "R", AND THE FILE PERMISSIONS IN THE RESPECTIVE FOLDERS FOR THE RESPECTIVE USER ARE ALSO JUST "R". BUT THE USER CAN DO EVERYTHING IN THE SUBFOLDERS!!!

  • Any security issues with My MSN or outlook bookmarks

    any security issues with My Msn and Outlook as bookmarks

    Your question is not quite clear, and no Mac can iOS, but anything and everything made by or for Microsoft carries a security risk.
    Which is why most sensible people run Apple OS X.

  • Security issues with connecting pdf to database

    I have a pdf form that is being called from a webform as part
    of a web application. The PDF has two dropdown lists that I was
    populating from a SQL Server Database. I had created a special user
    that had select access only to the tables for the dropdowns.
    My question is are there any known security issues with
    regard to allowing a pdf to connect to a database this way. The PDF
    is being called from a secure connection but I don't know if
    opening this database connection to populate these dropdowns
    exposes a security hole of any sort. If it does, do you have a
    solution to make this secure? I am asking because another developer
    on the project brought up the issue of this design creating a
    security risk and I haven't been able to find anything online
    discussing it either way.
    Thanks!
    Maureen

    Hello Maureen,
    Thanks for posting, but I'm not sure I see if your question
    relates to Acrobat.com
    Are you using any of the Acrobat.com Services as any part of
    your workflow?
    Thanks!
    Pete

  • Security Issues with 8.1 Pro

    I have had several security issues with Windows 8.1 Pro.
    I am curious if the following apps should be loaded by default:
    CheckPoint.VPN
    JuniperNetworks.JunosPulseVpn
    SonicWALL.MobileConnect
    F.vpn.client
    These programs are installed on a fresh install of Windows 8.1 Pro but I do not think they should be.  They are present prior to the install of any 3rd party programs or apps.
    Thanks

    I found them in my firewall list on my Windows 8.1 Pro installation and posted a question on a forum as well, though I don't think it was here.  I don't believe anyone ever answered.
    It looks as though these are parts of the bundled virtual private networking clients.
    Note, for example, the "distributed by Microsoft as part of Windows 8.1" wording on this page:
    http://www.sonicwall.com/app/projects/file_downloader/document_lib.php?t=PG&id=605
    -Noel
    Detailed how-to in my eBooks:  
    Configure The Windows 7 "To Work" Options
    Configure The Windows 8 "To Work" Options

  • Privacy/Security Issue with Adobe Flash 10

    Not sure if anyone has noticed this or not, but there is a
    bizarre (if minor) privacy/security issue with Adobe Flash Player
    10. I came across it while attempting to upload a file to Flickr.
    Previous versions of AFP do not exhibit this problem.
    Specifics: using Firefox 3.x, Vista.
    The problem: When Flickr calls the "open file" dialogue in
    Flash 10 (in order to upload files) via the "Upload Photos and
    Videos" link, at the bottom of the dialogue, to the right of the
    "File Name" box, sits a common UI element that brings up a dropdown
    menu of what appear to be (or at least are supposed to be) recently
    viewed or downloaded or accessed files. Actually I'm not sure how
    Flash 10 compiles or accesses this list of files, but at any rate,
    a list of files come up.
    The problem is that, as far as I can tell, the list of files
    that come up reference a long list of files, some that are very old
    and that no longer exist, and that there is no way that I can find
    to clear the list. This is a minor security/privacy issue, as
    generally there should be a way to prevent a dialogue from
    displaying a long list of past-accessed files by clearing a cache
    somewhere or other -- imagine if it was impossible to clear the
    history of a web browser, for example -- this would be considered a
    pretty significant privacy issue. I have tried everything from
    flushing the browser cache to uninstalling and reinstalling the
    browser to uninstalling and reinstalling Adobe Flash to using the
    Flash Settings Manager to clear out the Flash saved sites to
    turning off Vista indexing to clearing out Vista's Recent Items
    list. None of these actions did anything to clear out this list of
    files. I can find no references to these files anywhere when I use
    Vista Search (with unindexed and system files searched as well),
    and I can find no reference to the files anywhere in the registry
    (I checked just in case Flash 10 was storing this index in some
    really bizarre place.) I've linked to a screenshot below of what
    I'm talking about -- most of the files listed below were deleted a
    long, long time ago, and so I have no idea why this dialogue refers
    to them.
    Screenshot
    Is there a simple work-around for this that I'm unaware of?
    Even if there is, there needs to be some more obvious way to clear
    out this list. Where is this information being stored, and what
    criteria does this list use to "put a file on the list"?

    Thanks for putting me on the right scent. That's what I'd
    originally thought, too -- it's just that the file-> open dialog
    was giving an entirely different list of files with other
    applications, so I assumed that it must be Flash that was the
    culprit. Turns out the reason it was different with Flickr was
    because it was restricting the file results via a long string of
    video and picture filetypes that are compatible with the Flickr
    service.
    It turns out the information I'm looking for is buried deep
    within the registry. The only way to clear out this list of files
    is to delete the following key (or specific subkeys):
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidl MRU
    Seems more than a little stupid to store such information in
    the registry if security is your concern. Vista beguiles me
    sometimes.

  • Issues with Lion recognizing keyboard and mouse functions

    Hello everyone,
    I have read that there were issues with Lion so I waited for months before I upgraded hoping that there would be enough complaints to warrant a fix from the tech lords.  I decided to finally upgrade and the issues with incompatible software came to fruition.  Fortunately I don't need to upgrade anytime soon but here's my real issue.  I have a logitech mouse and keyboard and Lion won't recognize the keyboard, even with product upgrade.  Also, the right click button is not functioning the way it should.  I can no longer right click and copy and paster anymore.  Being a long time mac head from the 80s I know there are always issues but I have never experienced this many. Any suggestions?
    Thanks

    I had the same setup with the apple BT keyboard and the V270 mouse. I also work with the lid closed and with an external monitor (I bet that you are also using airport)! Both devices seem to intermittently loose connection, and the mouse cursor doesn't track very well. Looking through postings it seems that airport interferes with BT, and the behavior I've seen seems to support this. I stopped using the mouse because I couldn't get it to work adequately. I'v also tried using BT headphones (Motorola HT820) which at best the sound drops out intermittently, and at worse crashes OS X. I'm thinking that BT on the Macbook Pro just marginally works... I'd be curious if you ever had any success with your setup!

  • Are there any security issues with Quicktime player on macbook

    Are there any security issues with Quick Time Player on macbook pro? 2010 model running Yosemite recently upgraded. Thanks!

    No.

  • HT4628 Still having issues with Lion os X and wi-fi

    I am still havign issues with Lion os X and wi-fi.   I have 3 domputers in my house including the new macbook pro that has lion os x installed.    The wifi drops out all the time (every 2 minutes).   I have followed all the instructions on how to fix this but I am still having issues.    The other two computers work fine,  one of the is Lion os X that has been updated but I managed to play with the setting and fix this one.   This computer worked fine on Snow leapard and then a soon as I installed Lion the wifi started having issues.
    When will apple make an update that is going to fix this problem.     You want to buy a new computer that works,  I took it into apple and they told me that it is my router,  but I know it is the software as there are 100's of blogs and threads about this exact issue occuring only when their computer was updated to Lion.
    Is there anything else I can do to fix this issue other then un-installing Lion and buying Snow Leapard?

    Does this problem happen with just your airport base station?  Do you have a 3rd party wireless router?  Can you duplicate the problem using any wifi access point?  Did your computer come with 10.7 preinstalled?  Did you purchase the applecare with your computer?

  • HT201178 Are there security issues with pairing keyboards with certain passkeys?

    Are there security issues with pairing keyboards with certain passkeys?

    Hello, some info on that...
    http://x704.net/bbs/viewtopic.php?f=29&t=6059&p=73599&hilit=bluetooth#p73599

  • Recommendations for Internet security package with lion?

    Any recommendations fro an Internet security package with lion?

    Seems to me you are getting limited replies about Mac OSX security and viruses. Internet security can also be about safe surfing and being warned the safety and suitability of web sites. Also you may be running applications, like Microsoft Office, on your iMac which may have similar weakness and vulnerabilities to the Windows office suite. Although many nastys you may get via macros and e-mail are aimed at messing up Windows, there are others which aim to steal personal information or can be used to infect others when you send files or mail onwards. While I believe Mac OS itself is probably better protected than Windows, I think it may still worth extra protection and warnings about web sites. etc. which you get from Internet Security Packages such as Norton or Mcafee (which is good for the mac).

  • Issues with Lion, anyone having the same ones?

    I'm having several of issues with Lion (mostly with Safari).   Wondering if anyone else has these problems.  I'm hoping/assuming these will be bugs that Apple will fix with a software update?   Or if therres any fix for them?
    1.   Zoom while in Safari,  the 2 finger pinch and zoom feature stops working after a while usually.  I used to like the zoom in snow leopard where on a webpage it would zoom you in while keeping the page contents within the screen.  You can still accomplish this by doing the command + shortcut.  But I really liked the touchpad feature.  I don't mind the way the zoom works on safari (zooming in wihtout keeping the page in the screen).   But my problem is it stops working after a certain amount of time.
    2.  Safari freezing up.   Yes, my safari is freezing and I'm needing to force quit every now and then.   Never really had that problem with snow leopard.
    3.  Swiping to go to my desktop.   When I try to 4 finger swipe to get to my desktop or something (going to the left always),  My launchpad keeps coming up.  Thats HORRIBLY annoying.   I have to go to my icons and manually turn launchpad off.    This might be my most annoying problem.
    4.  Getting mission control up with the four fingers swiping up usually takes 2 or 3 swipes,   and also when I'm in mission control and I want to go to something on my desktop (if I have 2 or 3 things open while having mail and safari on full screen), it takes 2 or 3 clicks to select whatever I want to go to.
    Overall I really DO like lion.  Just don't like those glitches Ive seen so far.   Anyone having the same problems?

    Tmilless wrote:
    1.   Zoom while in Safari,  the 2 finger pinch and zoom feature stops working after a while usually.  I used to like the zoom in snow leopard where on a webpage it would zoom you in while keeping the page contents within the screen.  You can still accomplish this by doing the command + shortcut.  But I really liked the touchpad feature.  I don't mind the way the zoom works on safari (zooming in wihtout keeping the page in the screen).   But my problem is it stops working after a certain amount of time.
    2.  Safari freezing up.   Yes, my safari is freezing and I'm needing to force quit every now and then.   Never really had that problem with snow leopard.
    Yes! I see the same! Extremely annoying. And as long as the pinch-zoom works, it's very unstable, and sometimes seems to freeze Safari with a "fuzzy" picture. It doesn't really freeze it, though, I can still use otheropen tabs, and usually a double-tap zoom "wakes" the "frozen tab".

  • Security issue with unlocking my iPhone 4?

    I'm not sure if anyone here will be able to help me but I am trying to get my iPhone unlocked with AT&T. I bought my iPhone on contract through AT&T in December 2010. My account is in good standing. I paid my ETF, it's technically eligible to be unlocked. I called AT&T on April 9th for an unlock and it's now April 19th and still no wordd from them. I've called several times and they won't tell me what's going on other than that "there is a security issue with unlocking my iPhone and the issue is with Apple, but they are working on it." From my understanding, all AT&T needs is the unlock code to enter into the system and unlock it from there. I don't know what security issues could possibly exist that would create a problem. The only thing I can think of is that when I orginally bought my iPhone it turned out to be a lemon and had to get it replaced the day after I bought it. I did this through an Apple store since it was around Christmas. The IMEI number on my phone doesn't match the one AT&T has on file, but that shouldn't matter? I gave them the right IMEI number that is on my current phone. Does anyone know what "security issues" can exist when it comes to unlocking an iPhone 4?

    Don't stress over the words used by the customer service people at AT&T. Half of them don't know what they're talking about more than half the time.  You are probably correct in that it has something to do with their database being inaccurate. 
    Give it a few days, then contact them again and ask for it to be escalated.
    Ignor rNair. The idea that Apple made it mandatory for AT&T to do anything is complete and total bunk. (S)He has no idea what (s)he's talking about

  • Security Issue with Apple ID

    Today while using my iphone and trying to use facetime for the first time since updating to IOS6, my phone asked me if I wanted to use some email address that I do not have for facetime. What? The message pretty much said that this email address was linked to my apple ID. So I got to work logged into AppleID.Apple.com and saw the email address verified and also saw it displayed as an alternate apple id. Immediately, I changed my Apple ID password and called apple at 1800myapple since that is the number on the website and try to talk to someone that could assist me with this severe issue. Anyway, my iphone went dead and the people on the phone couldn't connect me to anyone because I couldn't give them a serial number to an apple device. I tried to explain to the technicians that this is a problem with my ID and that the alternate ID has access to everything that my Apple ID has access to. Both times the call went nowhere. This is ridiculous. Why can't I talk to a security team? Why is the technician telling me that I can manage my ID from the website, when I know that I am looking at the website and I cannot remove the alternate ID? How did this ID get associated with my account and why did I never receive an email informing me of the change?
    Since Apple has other services and not just products STOP ASKING FOR A SERIAL NUMBER AND ASSIST THE CUSTOMER WITH THE ISSUE especially since it is a SECURITY ISSUE.

    oh man, I know exactly what you're talking about. i have a relatively easy to guess apple id email and everybody in the world thinks it's theirs... but once I turned on two-step authentication, the emails stopped completely.  here's a faq about it:
    http://support.apple.com/kb/HT5570
    once i turned that on, whenever they'd want to reset my password, they would get asked for my recovery key, which they don't have, haha!  victory is mine.

Maybe you are looking for

  • TS3212 i had to reinstall iTunes and it will not install

    i had to reinstall iTunes and it will not install it keep on relling back

  • Adobe Indesign CS6 not finding fonts

    Dear Support, Adobe Indesign is not detecting the font arial narrow bold, narrow italic, please can you inform what to do. I have reinstalled the font in the windows\fonts folder restarted and still experience issues. I have reinstalled adobe indesig

  • Custom data labels in Crystal Reports charts

    Hi, I have a problem with charts in Crystal Reports. The notation prescribe e.g.  that positive values appears a plus (+21) and negative values a minus (-21). The problem is, that I canu2019t assign custom values to the data labels (e.g. the value is

  • Envy 110e won't print wireless with my mac osx 10.7.5 ok with usb,

    very dissapointed with my envy 110e wire less printer, just wont keep its wire less connection. Fine with usb connection, but keeps dropping wire less. Now on reinstalling it gets as far as loading, however it recognises device, lists all its details

  • Where are iPhoto plugins located in Lion?

    I need to remove an iPhoto plugin, but I can't find it in Lion. I've looked in ~/Library/Application Support, but there is no iPhoto folder. And right clicking on the iPhoto application and showing contents doesn't reveal the plugin I'm looking for.