image
image

|


Go Back   macosx.com > Content & Information > Apple News, Rumors & Discussion

Reply
 
Thread Tools
  #1  
Old June 27th, 2008, 06:10 AM
Captain Code's Avatar
Moderator
 
Join Date: Aug 2001
Location: Ontario, Canada
Posts: 3,102
Thanks: 0
Thanked 0 Times in 0 Posts
Captain Code will become famous soon enough
Possible new Snow Leopard security improvements

http://blogs.zdnet.com/security/?p=1325
  • Full address space randomization
  • No Execute on heap, not just the stack
  • 64 bit processes: Function arguments passed in registers, not the stack. Makes it much harder to exploit with address space randomization and NX on heap and stack
  • Fully sandbox vulnerable applications like Safari & Mail
  • Mandatory code signing for kernel extensions. This would stop a malicious kernel extension from being loaded if it wasn't cryptographically signed by the author.

All are very good improvements. Apple has expressed interest in implementing more restrictions with code signing and making core system components require it will make it that much harder for someone to install stuff in the system and go undetected. It seems they're already moving towards 64 bit processes for all their apps as well.
__________________
MacBook Pro 2.16GHz Core2Duo 3GB RAM, G4 1.4GHz OSX Tiger 1.25GB RAM, Dual 2GHz G5 OSX Tiger 2GB RAM (freakin shweet)
Athlon 64 Windoze XP for school work (programming) 1GB RAM
dferns@macosx.com
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -5. The time now is 01:11 AM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.