All Posts by Date or last 15, 30, 90 or 180 days.
also by Lloyd: diglloyd.com photography and WindInMyFace.com
Thank you for purchasing through links and ads on this site.
OWC / MacSales.com...
diglloyd B&H Deal Finder...
Buy other stuff at Amazon.com...
Upgrade the memory of your 2018 Mac mini up to 64GB
877-865-7002
Today’s Deal Zone Items... Handpicked deals...
$147 $80
SAVE $67

$260 $130
SAVE $130

$48 $28
SAVE $20

$580 $320
SAVE $260

$1699 $1199
SAVE $500

$799 $299
SAVE $500

$15199 $13699
SAVE $1500

$7995 $7495
SAVE $500

$1399 $1049
SAVE $350

$1299 $1099
SAVE $200

$700 $500
SAVE $200

$764 $399
SAVE $365

$290 $250
SAVE $40

$169 $99
SAVE $70

$370 $300
SAVE $70

$200 $170
SAVE $30

$250 $235
SAVE $15

$3899 $3699
SAVE $200

$2799 $2499
SAVE $300

$1199 $999
SAVE $200

$2999 $2399
SAVE $600

$18599 $17099
SAVE $1500

$600 $450
SAVE $150

$1149 $799
SAVE $350

$420 $170
SAVE $250

$1499 $649
SAVE $850

$1499 $649
SAVE $850

$420 $170
SAVE $250

$369 $239
SAVE $130

$1699 $1399
SAVE $300

$1498 $998
SAVE $500

$999 $949
SAVE $50

$1099 $999
SAVE $100

OWC Accelsior 4M2 PCIe SSD
6000 MB/sec!
Mac or PC.


Ideal for Lightroom, Photoshop, video.
Capacity up to 16TB!

Apple Apparently IGNORES Researcher’s Report of 0-Day Exploit for macOS KeyChain

Apple was recently embarrased for its Facetime bug in iOS and (far worse) for having a non-functional security bug reporting process.

But now it seems that this Apple has a pattern of failing to make any viable process available for reporting security bugs! Except for a small and exclusive group of researchers, a policy that without a doubt endangers Mac users (and now with two proofs of that in a month).

A reasonable person might conclude incompetence and lack of concern; the former certainly seems to be true, that latter probably not except that where is the process, publicly available process? Weeks to fix a severe problem is unacceptable to the point of disbelief.

To wit, way back on Feb 4 or so, security researcher Linus Henze reported a 0-day as discussed in Claimed 0-Day Exploit for Stealing Every Password in Your Keychain on macOS Mojave and earlier macOS, and summarized below.

As of March 1, Linus Henze has provided (for free) the bug details to Apple, with no response and without reward. How can Apple be taken seriously when it ignores severe vulnerabilities like this?

All the posturing in the world by Tim Cook to the press doesn’t fix this outrageous situation.

Summary of the 0-day

The claim by Linus Henze is:

In this video, I'll show you a 0-day exploit that allows me to extract all your keychain passwords on macOS Mojave (and lower versions). Without root or administrator privileges and without password prompts of course.

This is not the first time. You might remember KeychainStealer from @patrickwardle, released 2017 for macOS High Sierra, which can also steal all your keychain passwords. While the vulnerability he used is already patched, the one I found still works, even in macOS Mojave. I won't release this. The reason is simple: Apple still has no bug bounty program (for macOS), so blame them.

https://www.youtube.com/watch?v=nYTBZ9iPqsU

Apple talks a good PR story (congratulations to Tim Cook for his persuasion), but the bottom line is that a mind-blowing run of serious security flaws in macOS is prima facie evidence of software development incompetence chained to a calendar-based ship-it-testing-be-damned schedule.

What MPG wants to know is whether Apple acknowledges or denies this bug and (particularly important) if Apple is paying bug bounties for such stuff, so that the Bad Guys don’t get hold of it. Tim? Where’s the beef, is it a nothingburger or what?

OWC Envoy Pro EX SSD
Blazingly fast Thunderbolt 3 SSD!

Up to 4TB capacity, USB-C compatible.

USB-C model also available


Great for travel or for desktop!
Save Big $$$$ on Memory for 2019 Mac Pro

Up to 65% better pricing than Apple

Lloyd recommends 32GB RDIMM modules for most users (more expensive LRDIMMS are for 512GB or more).



MacPerformanceGuide.com
View all handpicked deals...

Peak Design Everyday Backpack (20L, Heritage Tan)
$260 $130
SAVE $130

diglloyd.com | Terms of Use | PRIVACY POLICY
Contact | About Lloyd Chambers | Consulting | Photo Tours
Mailing Lists | RSS Feeds | Twitter
Copyright © 2020 diglloyd Inc, all rights reserved.
Display info: __RETINA_INFO_STATUS__