Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > OSX 10.3.4-Paranoid Android still needed?

OSX 10.3.4-Paranoid Android still needed?
Thread Tools
Dedicated MacNNer
Join Date: Mar 2002
Location: NYC
Status: Offline
Reply With Quote
May 26, 2004, 03:31 PM
 
Do I uninstall Paranoid Andriod before updating to OSX 10.3.4 or do I leave Paranoid Android alone because it is still needed in OSX 10.3.4?
PowerMacG4 MDD Dual867Mhz, MacOSX 10.5.5 Leopard
2GB Ram, 128mb Radeon 9800 Pro, 80GB HD & 160GB HD
MacBook Black: Core2Duo 2.2Ghz, MacOSX 10.5.5 Leopard
4GB Ram & 250GB HD
     
Mac Elite
Join Date: Nov 2001
Status: Offline
Reply With Quote
May 26, 2004, 03:38 PM
 
Originally posted by MacGallant:
Do I uninstall Paranoid Andriod before updating to OSX 10.3.4 or do I leave Paranoid Android alone because it is still needed in OSX 10.3.4?
I wouldn't install it in the first place.
     
Posting Junkie
Join Date: Feb 2000
Location: Washington, DC
Status: Offline
Reply With Quote
May 26, 2004, 03:39 PM
 
I'm not totally sure, but I noticed this window when trying one of the test features.

http://www.bombaybungalow.com/Picture13.jpg
(Last edited by mitchell_pgh; May 26, 2004 at 08:58 PM. )
     
Posting Junkie
Join Date: Feb 2000
Location: Washington, DC
Status: Offline
Reply With Quote
May 26, 2004, 03:47 PM
 
I tried this site to test it...

http://www.insecure.ws/article.php?s...00405222251133

and it no longer will auto run the script... so that's a good thing...
     
Posting Junkie
Join Date: Sep 2001
Status: Offline
Reply With Quote
May 26, 2004, 03:57 PM
 
10.3.4 does not fix the exploit found here:

http://www.unsanity.com/haxies/pa/whitepaper/

So, if you're still worried and a little paranoid—like myself—you may as well leave PA on there. Man, now I need to go listen to some Radiohead.
     
Clinically Insane
Join Date: Jun 2001
Location: planning a comeback !
Status: Offline
Reply With Quote
May 26, 2004, 04:04 PM
 
Originally posted by MindFad:
10.3.4 does not fix the exploit found here:

http://www.unsanity.com/haxies/pa/whitepaper/

So, if you're still worried and a little paranoid—like myself—you may as well leave PA on there. Man, now I need to go listen to some Radiohead.
Bummer.

APPLE, ARE YOU LISTENING ?

Either the security issue is so deep and complicated to fix that they need much more time, or Apple is plain stupid and arrogant.

Gosh...

-t
     
Mac Elite
Join Date: Feb 2001
Location: Vancouver, WA
Status: Offline
Reply With Quote
May 26, 2004, 04:41 PM
 
Granted, the timing is a little odd, but remember: full-OS updates are a big deal in terms of engineering and testing time. With little updates like security patches and such, they really only need to test the patched functionality. But when they bump the OS version -- the number that third-party developers base official system requirements on -- they have to test with all kinds of third-party software to make sure they aren't breaking everybody's products. A large-scale QA cycle takes a long time (seen the updates on AppleInsider et al? 10.3.4's been in seeding for months), and thus can get thrown way off when coordinating with short-term projects. That this update came out today and didn't include a fix for the latest security issue isn't necessarily a sign that Apple's ignoring the security issue... it's a sign that they're, well, multitasking.
Rick Roe
icons.cx | weblog
     
Senior User
Join Date: Nov 2003
Status: Offline
Reply With Quote
May 26, 2004, 04:50 PM
 
Originally posted by MindFad:

Man, now I need to go listen to some Radiohead.
....or read The Hitchhikers Guide to the Galaxy, where the name comes from...


....or just wait for the movie to come out!
     
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status: Offline
Reply With Quote
May 26, 2004, 05:43 PM
 
Originally posted by turtle777:
Bummer.

APPLE, ARE YOU LISTENING ?

Either the security issue is so deep and complicated to fix that they need much more time, or Apple is plain stupid and arrogant.

Gosh...

-t
Multiple security issues came to light in the last two weeks. The first one was the Help Viewer issue. That was reported to Apple in February, and they released the fix last weekend.

While people here were exploring that issue, they discovered the more serious Launch Services URI issue. That was unknown to Apple until a few weeks ago. Apple is NOT stupid and arrogant. This other issue came out around the same time as the Help Viewer exploit was made public. Hence, the confusion because the public perceives this as just one problem, not many.

This newer issue is fairly complex, and Apple will need some time to fix it... PROPERLY, without breaking too much.

The problem was also discovered too soon to make it into the 10.3.4 release.
     
Professional Poster
Join Date: Nov 2000
Location: Norway (I eat whales)
Status: Offline
Reply With Quote
May 26, 2004, 06:09 PM
 
Originally posted by Person Man:
This newer issue is fairly complex, and Apple will need some time to fix it... PROPERLY, without breaking too much.
Amen to that.

Sniffer gone old-school sig
     
Clinically Insane
Join Date: Nov 1999
Status: Offline
Reply With Quote
May 26, 2004, 08:09 PM
 
Originally posted by Person Man:
Multiple security issues came to light in the last two weeks. The first one was the Help Viewer issue. That was reported to Apple in February, and they released the fix last weekend.

While people here were exploring that issue, they discovered the more serious Launch Services URI issue.
That's just it. It's really all one big security issue, which is manifesting in many different ways. Apple is trying to fix the symptoms piecemeal by dealing with individual apps, rather than simply accept that the scheme underlying it all is inherently flawed, and needs to be taken out right away.

It should never be possible to directly run code from a URI unless that code is carefully sandboxed.
You are in Soviet Russia. It is dark. Grue is likely to be eaten by YOU!
     
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status: Offline
Reply With Quote
May 26, 2004, 10:07 PM
 
Originally posted by Millennium:
That's just it. It's really all one big security issue, which is manifesting in many different ways. Apple is trying to fix the symptoms piecemeal by dealing with individual apps, rather than simply accept that the scheme underlying it all is inherently flawed, and needs to be taken out right away.

It should never be possible to directly run code from a URI unless that code is carefully sandboxed.
No, it really is a separate issue from the Help Viewer runscript exploit. That was easily fixed, and they fixed it. That part of the problem was reported to them in February. Nobody else knew about the Launch Services thing then. Not even Apple.

The new thing was discovered in the last two weeks. To suggest that Apple is ignoring the issue at hand and only releasing piecemeal solutions is not appopriate at this point, because Apple hasn't had enough time to study this problem. They had plenty of time to fix the original exploit, and they did.

Fixing the current issue but not fixing Help Viewer may not have prevented the Help Viewer runscript exploit from working. So, they need to do both. One (the easier one) has been fixed. The other will require some thought on their part for a proper fix.
     
Clinically Insane
Join Date: Jun 2001
Location: planning a comeback !
Status: Offline
Reply With Quote
May 27, 2004, 09:39 AM
 
Originally posted by Person Man:
This newer issue is fairly complex, and Apple will need some time to fix it... PROPERLY, without breaking too much.
Ok, so the fairly easy to fix Helpviewer fix took Apple more than 3 months (Feb - May).

I guess we'd better be prepared for Paranoid Androide being around for at least 6 months.

Sh.....

-t
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 04:26 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2