<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://community.winsupersite.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx</link><description>And heck, that’s just common sense. I’ve recommended that all along, for Windows users. But what’s interesting about the Consumer Reports recommendation is that it’s aimed specifically at Mac users: Mac users should scrap Apple&amp;#39;s Safari and replace</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP2 (Build: 20611.960)</generator><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73963</link><pubDate>Thu, 07 Aug 2008 21:34:54 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73963</guid><dc:creator>Waethorn</dc:creator><description>&lt;p&gt;&amp;quot;I believe that Apple should disclose exactly which bug fixes are being applied by updates and patches. If they did that, that would go along way in acknowledging the problems and correcting them.&amp;quot;&lt;/p&gt;
&lt;p&gt;I second that. &amp;nbsp;For a company that relies heavily on open-source software at the core (and for john's claim that they are so &amp;quot;open&amp;quot;), they sure like to keep their secrets hidden behind the BSD license. &amp;nbsp;Luckily there are companies like Secunia, as well as my buddy's firm that acknowledge their flaws for them.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73963" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73961</link><pubDate>Thu, 07 Aug 2008 21:30:05 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73961</guid><dc:creator>shark47</dc:creator><description>&lt;p&gt;&amp;quot; Again, it's not like they are getting 3.5% of viruses and trojan horses and the rest. &amp;nbsp;So I find that interesting. &amp;nbsp;The mac's &amp;quot;resurgence&amp;quot; has been in the news for years now, so I'm frankly amazed at the lack of a serious, broad attack. &amp;nbsp;There's something there that's not easily explained away by &amp;quot;tiny marketshare&amp;quot;.&amp;quot;&lt;/p&gt;
&lt;p&gt;Read the book 'The Tipping Point' by Malcolm Gladwell.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73961" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73960</link><pubDate>Thu, 07 Aug 2008 21:14:20 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73960</guid><dc:creator>johnpapola</dc:creator><description>&lt;p&gt;@Sub,&lt;/p&gt;
&lt;p&gt;Agreed on all fronts. &amp;nbsp;I think the thing is that OSX did have structural advantages over windows, including the admin password requirement for software installation.&lt;/p&gt;
&lt;p&gt;Vista has brought parity, and probably superiority to Windows over OSX... so now it's more about marketshare... though it's hard to deny the dearth of attacks given the visibility of the Mac. &amp;nbsp;Again, it's not like they are getting 3.5% of viruses and trojan horses and the rest. &amp;nbsp;So I find that interesting. &amp;nbsp;The mac's &amp;quot;resurgence&amp;quot; has been in the news for years now, so I'm frankly amazed at the lack of a serious, broad attack. &amp;nbsp;There's something there that's not easily explained away by &amp;quot;tiny marketshare&amp;quot;.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73960" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73953</link><pubDate>Thu, 07 Aug 2008 20:26:55 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73953</guid><dc:creator>subzerohitman721</dc:creator><description>&lt;p&gt;@johnpapola...&lt;/p&gt;
&lt;p&gt;Regarding your comments on Apple doing better with communication, I agree. I believe that Apple should disclose exactly which bug fixes are being applied by updates and patches. If they did that, that would go along way in acknowledging the problems and correcting them.&lt;/p&gt;
&lt;p&gt;I also agree with you that users must acknowledge that the false sense of security does begin and end with the user. My own user experience has conditioned me to check updates at least once a week. I update my anti-virus every 2 to 3 days. It was this routine that protected my then XP system when Blaster hit back in 03. I think once people have a update and maintenance routine, computing will be a lot more stable. Then we can argue about other things.&lt;/p&gt;
&lt;p&gt;Peace. &lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73953" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73946</link><pubDate>Thu, 07 Aug 2008 19:27:48 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73946</guid><dc:creator>johnpapola</dc:creator><description>&lt;p&gt;@snake and everyone else that's reasonable,&lt;/p&gt;
&lt;p&gt;just ignore Waethorn. &amp;nbsp;At some point, he'll tire of posting his apple-bashing garbage into a vacuum. &amp;nbsp;Responding just feeds his obsessive need to stroke his ego with self-declared victories in these discussions.&lt;/p&gt;
&lt;p&gt;I've turned over a new leaf in this regard. &amp;nbsp;I'm hoping it will stick.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73946" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73945</link><pubDate>Thu, 07 Aug 2008 19:22:58 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73945</guid><dc:creator>Waethorn</dc:creator><description>&lt;p&gt;&amp;quot;do you come up with this stuff your self or do you have some Word Macro that cranks out this fiction?&amp;quot;&lt;/p&gt;
&lt;p&gt;You mean like Mossberg's reviews?&lt;/p&gt;
&lt;p&gt;Sorry, but no matter how hard you push those fingers in your ears, it's the absolute truth.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73945" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73942</link><pubDate>Thu, 07 Aug 2008 19:07:21 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73942</guid><dc:creator>Snakedoctor1</dc:creator><description>&lt;p&gt;@Waethorn do you come up with this stuff your self or do you have some Word Macro that cranks out this fiction?&lt;/p&gt;
&lt;p&gt;We cold all post BS about My Vista is fine, My XP never crashes, My Mac has no problems.....BLAH....BLAH...BLAH.....YAWN!&lt;/p&gt;
&lt;p&gt;I could find plenty links like this that are pro-Apple based on its security....&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.forbes.com/technology/2007/12/20/apple-army-hackers-tech-security-cx_ag_1221army.html"&gt;www.forbes.com/.../apple-army-hackers-tech-security-cx_ag_1221army.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;And probably the same for Windblows as well.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73942" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73941</link><pubDate>Thu, 07 Aug 2008 18:40:51 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73941</guid><dc:creator>Waethorn</dc:creator><description>&lt;p&gt;&amp;quot;Yeah and he seems to be perfectly fine with discussing things with you...&amp;quot;&lt;/p&gt;
&lt;p&gt;Considering that it was about a shared client whos two dedicated networks consist of one of Mac's, running OS X Server (Tiger), and the other consisting of Windows Server 2003 R2 (which I'm currently in charge of), and they completely failed a wire-line penetration test on their Mac network, having been successfully had customer information databases stolen, overwritten, and then deleted by an outside source, I'd say that working together with a buddy of mine already in the security industry wasn't disclosing any unnecessary information. &amp;nbsp;I sure had a laugh about it anyway.&lt;/p&gt;
&lt;p&gt;BTW: &amp;nbsp;The client now does quarterly remote penetration tests through my buddy's company. &amp;nbsp;So far, the Windows network hasn't been penetrated. &amp;nbsp;The Mac one failed 4 more tests after the initial incident about a year ago. &amp;nbsp;Both systems have security updates deployed automatically to client machines too.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73941" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73936</link><pubDate>Thu, 07 Aug 2008 17:23:01 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73936</guid><dc:creator>tayme</dc:creator><description>&lt;p&gt;@Snake - Oh, I agree that MS has dragged their feet at times...but recently they have improved security practices greatly. I also know that not too many places use OS X as a DNS Server and that OS X has BIND disabled by default. I was responding to joe-dokes' post, which gave the standard response that would leave one to falsely believe that Apple is &amp;quot;better&amp;quot; at security response than all other OS makers...&lt;/p&gt;
&lt;p&gt;--tayme&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73936" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73935</link><pubDate>Thu, 07 Aug 2008 17:21:18 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73935</guid><dc:creator>Dude1313</dc:creator><description>&lt;p&gt; Waethorn &amp;nbsp;said:&lt;/p&gt;
&lt;p&gt;&amp;quot;Funny thing is you keep saying this but then offer up no proof other then &amp;quot;My friend says&amp;quot;....&amp;quot;&lt;/p&gt;
&lt;p&gt;You obviously know nothing about security firms (obviously), but there's something called an NDA at most of them. &amp;nbsp;Flaws and exploits are not discussed openly in public. &amp;nbsp;Apple follows this example to a tee - in fact, they deny all knowledge of it.&lt;/p&gt;
&lt;p&gt;Yeah and he seems to be perfectly fine with discussing things with you... or at the very least it makes convenient fodder for you lack facts backing it up.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73935" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73933</link><pubDate>Thu, 07 Aug 2008 16:38:43 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73933</guid><dc:creator>Snakedoctor1</dc:creator><description>&lt;p&gt;@tayme,&lt;/p&gt;
&lt;p&gt;This all happened a year ago with MS&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.itjungle.com/two/two042507-story02.html"&gt;www.itjungle.com/.../two042507-story02.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;In fact in that case some third party company came out with a patch because MS was dragging its feet. &amp;nbsp;Most people did not go with the 3rd party patch for fear of compatibility problems, and I agree with that.&lt;/p&gt;
&lt;p&gt;Apple probably had to do more testing. &amp;nbsp;Also the # of Bind DNS servers running on OS X, exposed to the internet, its probably so low they could have waited a year and not been hit. &amp;nbsp;This would only have probably only affected OS X server running DNS in a DMZ that was open to the internet. &amp;nbsp;Never have even seen this. &amp;nbsp;Usually its cheap Linux box doing this or an appliance. &amp;nbsp;Some all Windows shops will use some low powered Windows box, but I have never seen a OS X DNS server.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73933" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73930</link><pubDate>Thu, 07 Aug 2008 14:15:28 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73930</guid><dc:creator>Waethorn</dc:creator><description>&lt;p&gt;&amp;quot;Funny thing is you keep saying this but then offer up no proof other then &amp;quot;My friend says&amp;quot;....&amp;quot;&lt;/p&gt;
&lt;p&gt;You obviously know nothing about security firms (obviously), but there's something called an NDA at most of them. &amp;nbsp;Flaws and exploits are not discussed openly in public. &amp;nbsp;Apple follows this example to a tee - in fact, they deny all knowledge of it.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73930" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73928</link><pubDate>Thu, 07 Aug 2008 13:40:52 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73928</guid><dc:creator>tayme</dc:creator><description>&lt;p&gt;@joe-dokes - &amp;quot;Could it face serious problems in the future sure, but it probably has the expertise and resources to respond appropriately.&amp;quot;&lt;/p&gt;
&lt;p&gt;You mean like they did here? &lt;a rel="nofollow" target="_new" href="http://www.scmagazineus.com/Apple-patches-for-DNS-flaw/article/113260/"&gt;www.scmagazineus.com/.../113260&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; &amp;quot;After waiting since the beginning of July, Apple has put out a patch for the DNS cache poisoning flaw discovered by security researcher Dan Kaminsky.&lt;/p&gt;
&lt;p&gt;Cisco, Microsoft, Sun Microsystems and many Linux versions put out a fix for the flaw on July 8, when it was first disclosed. Apple had taken some heat when it did not release its patch then, too.&lt;/p&gt;
&lt;p&gt;Andrew Storms, director of security operations for nCircle, said in a blog post that some of the patches for components in Apple's systems are incomplete.&amp;quot;&lt;/p&gt;
&lt;p&gt;Apple needs to get serious about security and quit assuming that they are invulnerable. As an Apple customer, I have sent an email asking why this took a month longer than any other company and why it is still not fully patched...have any of you?&lt;/p&gt;
&lt;p&gt;--tayme&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73928" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73927</link><pubDate>Thu, 07 Aug 2008 13:14:22 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73927</guid><dc:creator>johnpapola</dc:creator><description>&lt;p&gt;I think everyone reasonable can agree that Apple needs to do more from a communication standpoint. &amp;nbsp;Those that say it's &amp;quot;impossible&amp;quot; for them don't know the company that well. &amp;nbsp;Apple's Joe Schor, product manager for Aperture is very directly engaged with the community. &amp;nbsp;In fact, all of the pro-apps are. &amp;nbsp;It's a market Apple knows well and has a long relationship with. &amp;nbsp;They just need to realize that being opaque doesn't always serve them elsewhere. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Security starts and stops with the user and having a false sense of security is worse than anything. &amp;nbsp;That's something Apple needs to fight. &amp;nbsp;They are correct that the Mac's track record on attack is superior. &amp;nbsp; Superior by a margin far in excess of their marketshare. &amp;nbsp;It's not like the mac gets 3.5% of all attacks. &amp;nbsp;It gets almost zero. That's not proportional. &amp;nbsp;So they have a reasonable case to bring to consumer who have been burned on windows. &amp;nbsp;It's fair for them to say &amp;quot;we're a safer neighborhood&amp;quot;.&lt;/p&gt;
&lt;p&gt;They just can't encourage users to leave the doors unlocked.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73927" width="1" height="1"&gt;</description></item><item><title>re: Respected consumer advocacy group recommends against using Safari</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/08/06/respected-consumer-advocacy-group-recommends-against-using-safari.aspx#73925</link><pubDate>Thu, 07 Aug 2008 13:09:25 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:73925</guid><dc:creator>lotsamystuff</dc:creator><description>&lt;p&gt;&amp;quot;Funny thing is you keep saying this but then offer up no proof other then &amp;quot;My friend says&amp;quot;....&amp;quot;&lt;/p&gt;
&lt;p&gt;Yeah, Wae's the king of anecdotal evidence. He's regaled us several times with his fascinating stories of malfunctioning Macs in Apple stores, frustrated consumers at Best Buy, and his own customers who straggle into his basement with their non-working Macs and beg him to replace them with a home-built Vista box. I guess that's why he hangs out at Apple stores looking for customers—they make great fodder for his comments.&lt;/p&gt;
&lt;p&gt;But back on topic...&lt;/p&gt;
&lt;p&gt;I think the CR recommendation makes since. Safari has clearly lagged behind in offering phishing protection, and although one could argue with the efficacy of such &amp;quot;protection&amp;quot;, the fact is it's part of what should be considered standard on a modern browser. Better alternatives are available, and they should be seriously considered.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=73925" width="1" height="1"&gt;</description></item></channel></rss>