<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Matasano Chargen - Latest Comments in Is The New OS X DMG Threat Real?</title><link>http://matasanochargen.disqus.com/</link><description></description><atom:link href="https://matasanochargen.disqus.com/is_the_new_os_x_dmg_threat_real/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Tue, 28 Nov 2006 13:18:35 -0000</lastBuildDate><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321125</link><description>&lt;p&gt;In the spirit of fairness: I've also been kind of mean to Alastair on his blog:&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.alastairs-place.net" rel="nofollow noopener" target="_blank" title="http://www.alastairs-place.net"&gt;http://www.alastairs-place.net&lt;/a&gt;.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Tue, 28 Nov 2006 13:18:35 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321122</link><description>&lt;p&gt;Mike: first, Ubuntu delegated root's ability to mount an ISO to normal users; that's an Ubuntuism, and perhaps (ok, certainly) a modern-Unix-ism, but it's not a part of the Unix security model. It's also something you can disable.&lt;/p&gt;&lt;p&gt;Second, ISO9660 isn't a complex filesystem or a metaformat. On the other hand, DMG's abstract disks, and contain filesystems such as HFS+.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Mon, 27 Nov 2006 13:01:43 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321121</link><description>&lt;p&gt;Caveat Blogger: I write device drivers for Macs and Linux for a living.&lt;/p&gt;&lt;p&gt;That said, I have to say I was one of those taken aback by this - it had never occurred to me and, yeah, it's nasty.&lt;/p&gt;&lt;p&gt;But to your comment that other OS's don't support mounting images, I note that I can browse an ISO image on my ubuntu install; what are they doing differently?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mike Heinz</dc:creator><pubDate>Mon, 27 Nov 2006 11:12:34 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321120</link><description>&lt;p&gt;I'm just surprised that the press hasnt soiled themselves on this one yet. Anyways, nice summary of facts on the ground.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris_B</dc:creator><pubDate>Mon, 27 Nov 2006 00:19:48 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321119</link><description>&lt;p&gt;minor comment, let not forget: Remote filesystem vulnerability design was pioneered by Sun Microsystems in California. Had they patented them, today they would be able to crawl out of their botomless pit.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ivan</dc:creator><pubDate>Thu, 23 Nov 2006 01:41:47 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321118</link><description>&lt;p&gt;Two responses:&lt;/p&gt;&lt;p&gt;As a mechanism for distributing software products, disk images are irredeemable.&lt;/p&gt;&lt;p&gt;and&lt;/p&gt;&lt;p&gt;If you can reconcile it with the Unix privilege model OS X depends on, I see the value in having ONE SIMPLIFIED filesystem available, unionfs/portalfs-style, to unprivileged users. But that's not what OS X did. They have a metaformat that exposes multiple filesystems that were never meant to be exposed to hostile environments.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 22 Nov 2006 21:02:38 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321117</link><description>&lt;p&gt;Ok, so while I believe that Tom's got the cork in a little tight in general when it comes to all things Gruber, I agree that this DMG issue is Not Good. It is true that a consequence of disk images is that you've got a much larger attack surface because you've got to worry about all of the filesystems that the format supports. Also, I laughed hard at the line; "For the time being, remote filesystem vulnerabilities are 'Designed by Apple in California.'" Heh.&lt;/p&gt;&lt;p&gt;But saying that disk images are a "terrible idea" is going too far. From a utility point of view, disk images are a TERRIFIC idea, especially encrypted disk images for storing secret company documents and the like. Disk images also underpin the FileVault home directory encryption feature. How is this not goodness?&lt;/p&gt;&lt;p&gt;Other points, from you, Dave G, Rich, Bryan and others are spot-on. Apple should clearly audit that code with a fine-toothed comb, and take steps to turn of the "safe" file option. The past five years should have taught us that no files obtained remotely should ever be considered "safe."&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andrew Jaquith</dc:creator><pubDate>Wed, 22 Nov 2006 20:38:10 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321116</link><description>&lt;p&gt;Part of the issue here is that the average user doesnt need to knowingly click on a DMG to have Safari start downloading one for you.  Any website you go to could have an" &amp;lt;IFRAME src="boom.dmg"&amp;gt;" and Safari will by default download it and mount it, no questions asked.&lt;/p&gt;&lt;p&gt;Yes, if you have turned off Open "Safe" Files in Safari the risk of this impacting you without interaction is much smaller (if not completely removed).&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave G.</dc:creator><pubDate>Wed, 22 Nov 2006 16:38:12 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321115</link><description>&lt;p&gt;Nice writeup.&lt;/p&gt;&lt;p&gt;One thing that somewhat mitigates this vulnerability in my mind is that 99% of the time I'm downloading a .dmg it contains an executable (.app) that I'm about to run w/o dropping into IDA to test its non-evil nature etc.&lt;/p&gt;&lt;p&gt;So, by the time I double-click the dmg to mount it, I've already agreed to let you run whatever code you want w/o the headache of kernel shellcode. (You had me at hello?)&lt;/p&gt;&lt;p&gt;So, while this still is a valid and scary vulnerability, I'm probably not going to change my behavior over it. While it's bad, it just doesn't make things much worse..&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bryan Burns</dc:creator><pubDate>Wed, 22 Nov 2006 15:48:55 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321114</link><description>&lt;p&gt;Don't worry Mogull, the punditCon sees and knows all.  It is like Santa Claus, only without the breaking and entering (or the presents).&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave G.</dc:creator><pubDate>Wed, 22 Nov 2006 14:52:06 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321113</link><description>&lt;p&gt;Any advice on something inane to say to get on the PunditCon? I hate to let Amrit beat me at anything.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rich Mogull</dc:creator><pubDate>Wed, 22 Nov 2006 14:28:37 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321112</link><description>&lt;p&gt;Thanks, Alex. FWIW, the PunditCon has been stuck at Lindstrom ever since I switched to MacIntel and Illustrator stopped working. =)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 22 Nov 2006 14:16:36 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321111</link><description>&lt;p&gt;Nice stuff on perceived risk vs. actual risk.&lt;/p&gt;&lt;p&gt;I have to get his off my chest: When are you going to fix the punditCon image?&lt;/p&gt;&lt;p&gt;The image is 175x296 pixels but that's not the size your html img tag specifies, and the slightly resized image looks crap in my browser and it hurts my eyes.&lt;/p&gt;&lt;p&gt;Always has.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alex Holst</dc:creator><pubDate>Wed, 22 Nov 2006 14:06:53 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321110</link><description>&lt;p&gt;Excellent narrative.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">LonerVamp</dc:creator><pubDate>Wed, 22 Nov 2006 13:46:13 -0000</pubDate></item><item><title>Re: Is The New OS X DMG Threat Real?</title><link>http://www.matasano.com/log/616/is-the-new-os-x-dmg-threat-real/#comment-2321109</link><description>&lt;p&gt;Great writeup. I think this might be the first vector in a while that makes a mass exploit on Macs more viable.&lt;/p&gt;&lt;p&gt;The one thing you missed was direct advice for Mac users worried about this, so I posted some at:&lt;/p&gt;&lt;p&gt;&lt;a href="http://securosis.com/2006/11/22/take-the-latest-os-x-disk-image-dmg-vulnerability-and-possible-exploit-seriously/" rel="nofollow noopener" target="_blank" title="http://securosis.com/2006/11/22/take-the-latest-os-x-disk-image-dmg-vulnerability-and-possible-exploit-seriously/"&gt;http://securosis.com/2006/1...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rich Mogull</dc:creator><pubDate>Wed, 22 Nov 2006 13:42:55 -0000</pubDate></item></channel></rss>