Safari used to hack MacBook…sort of

It happened last year, and it happened again this year. The tech sector of the internet is seeing a fair share of headlines to the tune of “Safari hacked in 10 Seconds!” At the Pwn2Own conference this year, Charlie Miller, who hacked Safari last year to much the same media explosion, used Safari to gain control of a MacBook in under ten seconds. Sounds like we should be worried, right?
How easy is it to hack into a MacBook in under ten seconds? Incredibly easy if, like Charlie, you had months to find the hole, prepare the exploit well in advance, and simply run it when the time came. Oh, also, you’ll need a person willing to click on a specific link at your direction (in this case, the judges) and you’ll have full control of their computer. Yes, Miller had the whole thing planned well in advance, and he set up a link, which he then directed the judges to click and (shock and awe) he then had control of their computers.
For a hacker, that seems extremely unsatisfying. I was under the impression that hacking was more on the fly…or at least didn’t require the person being hacked to know what was going on. The fact is that the Mac OS still has no viruses for it out in the wild. There is very little threat of this type of exploit being able to take over your computer. Add to that the fact that the exploit has been told to no-one but Apple until a patch is released, and there is no reason to start freaking out about the Mac’s inherent security flaws.
As long as you are smart about what you download, and don’t type your password into applications you didn’t explicitly run, you will be fine. “Mac hacked in record time” just makes for a great headline.
Via [AppleInsider]
Subscribe to keep up with the latest Apple news and rumors! -
Subscribe to our feed
Our new podcast: Meet...
We know. Podcasts are so last year - but this one you won't want to miss. Whether it’s a rumor that won’t die, a new product announcement, or just a really good Macintosh or iPhone app find that we have to let you know about, we’ll make sure it’s covered on Appletellcast.
iPhone App Reviews
iPhone Apps. They were great when the App Store was first announced and we could all pick and chose what we wanted, but the number is now overwhelming. Here at Appletell, we'll detail the great iPhone apps we find, and steer you clear from those that aren't worth it even if they're free.
iPhone Game Reviews
As Apple turns the iPhone into one of the most popular gaming devices, the staff of Appletell--gamers and Apple fans alike--are here to help you get the most entertainment value out of your app store purchases.





You are kidding, right? This is exactly how most exploits happen these days. Some people have even figured out how to inject attacks into Google Ads, so it isn’t like this only happens on obscure sites.
on March 23, 2009 at 10:24 AM - LINKhe’s saying that everyone has actually blown the story out of proportion and the claim that it took the hacker 10 seconds is false, not that it could never happen again.
on March 23, 2009 at 04:56 PM - LINK