John Gruber har intervjuat Dino Dai Zovi som förra veckan framgångsrikt hackade en MacBook Pro i en tävling anordnad av CanSecWest. Detta hack är ett rätt allvarligt hack som utnyttjar ett Java-baserat säkerhetshål i Quicktime och än så länge inte är tilltäppt av Apple. Zovi verkar vara rätt duktig:
I got a phone call at around 9:30 pm ET and heard that no one had yet won the laptops, and that Friday was the last day of the conference. It sounded like a great challenge, so I decided to work with Shane Macaulay to see if we could win this contest. I sat down to begin looking for a web-based vulnerability at around 10 pm, had found one around 3 am, and had written a reliably working exploit around 7 am.
Zovi, som själv är Macanvändare, ger även några tips till vad man kan göra för att höja säkerheten:
I would recommend they make their primary user account a non-admin user, I think that is a reasonable compromise between usability and security. I would also recommend that more security-conscious users create a separate keychain with a 5 minute timeout for important passwords. Even if the user is using FileVault, a separate encrypted disk image for sensitive financial or personal documents is another simple and prudent measure to protect your personal information.
Läs hela intervjun här: Interview: Dino Dai Zovi