 |
 |
OSX 10.3.4-Paranoid Android still needed?
|
 |
|
 |
|
Dedicated MacNNer
Join Date: Mar 2002
Location: NYC
Status:
Offline
|
|
Do I uninstall Paranoid Andriod before updating to OSX 10.3.4 or do I leave Paranoid Android alone because it is still needed in OSX 10.3.4?
|
|
PowerMacG4 MDD Dual867Mhz, MacOSX 10.5.5 Leopard
2GB Ram, 128mb Radeon 9800 Pro, 80GB HD & 160GB HD
MacBook Black: Core2Duo 2.2Ghz, MacOSX 10.5.5 Leopard
4GB Ram & 250GB HD
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Nov 2001
Status:
Offline
|
|
Originally posted by MacGallant:
Do I uninstall Paranoid Andriod before updating to OSX 10.3.4 or do I leave Paranoid Android alone because it is still needed in OSX 10.3.4?
I wouldn't install it in the first place.
|
|
|
| |
|
|
|
 |
|
 |
|
Posting Junkie
Join Date: Feb 2000
Location: Washington, DC
Status:
Offline
|
|
|
(Last edited by mitchell_pgh; May 26, 2004 at 08:58 PM.
)
|
|
|
| |
|
|
|
 |
|
 |
|
Posting Junkie
Join Date: Feb 2000
Location: Washington, DC
Status:
Offline
|
|
|
|
|
|
| |
|
|
|
 |
|
 |
|
Posting Junkie
Join Date: Sep 2001
Status:
Offline
|
|
10.3.4 does not fix the exploit found here:
http://www.unsanity.com/haxies/pa/whitepaper/
So, if you're still worried and a little paranoid—like myself—you may as well leave PA on there. Man, now I need to go listen to some Radiohead.
|
|
|
| |
|
|
|
 |
|
 |
|
Clinically Insane
Join Date: Jun 2001
Location: planning a comeback !
Status:
Offline
|
|
Originally posted by MindFad:
10.3.4 does not fix the exploit found here:
http://www.unsanity.com/haxies/pa/whitepaper/
So, if you're still worried and a little paranoid—like myself—you may as well leave PA on there. Man, now I need to go listen to some Radiohead.
Bummer.
APPLE, ARE YOU LISTENING ?
Either the security issue is so deep and complicated to fix that they need much more time, or Apple is plain stupid and arrogant.
Gosh...
-t
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Feb 2001
Location: Vancouver, WA
Status:
Offline
|
|
Granted, the timing is a little odd, but remember: full-OS updates are a big deal in terms of engineering and testing time. With little updates like security patches and such, they really only need to test the patched functionality. But when they bump the OS version -- the number that third-party developers base official system requirements on -- they have to test with all kinds of third-party software to make sure they aren't breaking everybody's products. A large-scale QA cycle takes a long time (seen the updates on AppleInsider et al? 10.3.4's been in seeding for months), and thus can get thrown way off when coordinating with short-term projects. That this update came out today and didn't include a fix for the latest security issue isn't necessarily a sign that Apple's ignoring the security issue... it's a sign that they're, well, multitasking.
|
|
|
| |
|
|
|
 |
|
 |
|
Senior User
Join Date: Nov 2003
Status:
Offline
|
|
Originally posted by MindFad:
Man, now I need to go listen to some Radiohead.
....or read The Hitchhikers Guide to the Galaxy, where the name comes from...
....or just wait for the movie to come out! 
|
|
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status:
Offline
|
|
Originally posted by turtle777:
Bummer.
APPLE, ARE YOU LISTENING ?
Either the security issue is so deep and complicated to fix that they need much more time, or Apple is plain stupid and arrogant.
Gosh...
-t
Multiple security issues came to light in the last two weeks. The first one was the Help Viewer issue. That was reported to Apple in February, and they released the fix last weekend.
While people here were exploring that issue, they discovered the more serious Launch Services URI issue. That was unknown to Apple until a few weeks ago. Apple is NOT stupid and arrogant. This other issue came out around the same time as the Help Viewer exploit was made public. Hence, the confusion because the public perceives this as just one problem, not many.
This newer issue is fairly complex, and Apple will need some time to fix it... PROPERLY, without breaking too much.
The problem was also discovered too soon to make it into the 10.3.4 release.
|
|
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Nov 2000
Location: Norway (I eat whales)
Status:
Offline
|
|
Originally posted by Person Man:
This newer issue is fairly complex, and Apple will need some time to fix it... PROPERLY, without breaking too much.
Amen to that.
|

Sniffer gone old-school sig
|
| |
|
|
|
 |
|
 |
|
Clinically Insane
Join Date: Nov 1999
Status:
Offline
|
|
Originally posted by Person Man:
Multiple security issues came to light in the last two weeks. The first one was the Help Viewer issue. That was reported to Apple in February, and they released the fix last weekend.
While people here were exploring that issue, they discovered the more serious Launch Services URI issue.
That's just it. It's really all one big security issue, which is manifesting in many different ways. Apple is trying to fix the symptoms piecemeal by dealing with individual apps, rather than simply accept that the scheme underlying it all is inherently flawed, and needs to be taken out right away.
It should never be possible to directly run code from a URI unless that code is carefully sandboxed.
|
|
You are in Soviet Russia. It is dark. Grue is likely to be eaten by YOU!
|
| |
|
|
|
 |
|
 |
|
Professional Poster
Join Date: Jun 2001
Location: Northwest Ohio
Status:
Offline
|
|
Originally posted by Millennium:
That's just it. It's really all one big security issue, which is manifesting in many different ways. Apple is trying to fix the symptoms piecemeal by dealing with individual apps, rather than simply accept that the scheme underlying it all is inherently flawed, and needs to be taken out right away.
It should never be possible to directly run code from a URI unless that code is carefully sandboxed.
No, it really is a separate issue from the Help Viewer runscript exploit. That was easily fixed, and they fixed it. That part of the problem was reported to them in February. Nobody else knew about the Launch Services thing then. Not even Apple.
The new thing was discovered in the last two weeks. To suggest that Apple is ignoring the issue at hand and only releasing piecemeal solutions is not appopriate at this point, because Apple hasn't had enough time to study this problem. They had plenty of time to fix the original exploit, and they did.
Fixing the current issue but not fixing Help Viewer may not have prevented the Help Viewer runscript exploit from working. So, they need to do both. One (the easier one) has been fixed. The other will require some thought on their part for a proper fix.
|
|
|
| |
|
|
|
 |
|
 |
|
Clinically Insane
Join Date: Jun 2001
Location: planning a comeback !
Status:
Offline
|
|
Originally posted by Person Man:
This newer issue is fairly complex, and Apple will need some time to fix it... PROPERLY, without breaking too much.
Ok, so the fairly easy to fix Helpviewer fix took Apple more than 3 months (Feb - May).
I guess we'd better be prepared for Paranoid Androide being around for at least 6 months.
Sh.....
-t
|
|
|
| |
|
|
|
 |
 |
|
 |
|
|
|
|
|

|
|
 |
Forum Rules
|
 |
 |
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is Off
|
|
|
|
|
|
 |
 |
 |
 |
|
 |
|