<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Are our programs spying on us?</title>
	<atom:link href="http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/feed/" rel="self" type="application/rss+xml" />
	<link>http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/</link>
	<description>TheAppleBlog, published by and for the day-to-day Apple user, is a prominent source for news, reviews, walkthroughs, and real life application of all Apple products.</description>
	<pubDate>Thu, 04 Dec 2008 00:47:29 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Mantiz</title>
		<link>http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/#comment-105753</link>
		<dc:creator>Mantiz</dc:creator>
		<pubDate>Wed, 23 May 2007 13:35:31 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/#comment-105753</guid>
		<description>Don't phishing websites/viruses/spammers also use the same idea?
The only way i see to solve this is, to either make all the programs you use yourself, wait for an os that provides zero usability but amazing security or go back to working on paper, which can also be stolen/copied/catch fire...etc.

A lot of stress for an unavoidable problem.
</description>
		<content:encoded><![CDATA[<p>Don&#8217;t phishing websites/viruses/spammers also use the same idea?<br />
The only way i see to solve this is, to either make all the programs you use yourself, wait for an os that provides zero usability but amazing security or go back to working on paper, which can also be stolen/copied/catch fire&#8230;etc.</p>
<p>A lot of stress for an unavoidable problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stilgherrian</title>
		<link>http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/#comment-105737</link>
		<dc:creator>Stilgherrian</dc:creator>
		<pubDate>Wed, 23 May 2007 00:51:47 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/#comment-105737</guid>
		<description>&lt;strong&gt;@Ryan:&lt;/strong&gt; That still doesn't help solve the problem pointed out by Krstic, which is better described in the report in the &lt;a href="http://www.smh.com.au/news/security/computer-security-has-massively-failed/2007/05/21/1179601329670.html" rel="nofollow"&gt;&lt;em&gt;Sydney Morning Herald&lt;/em&gt;&lt;/a&gt;:

&lt;blockquote&gt;The way modern desktop security works is by relying on the user to make informed and sensible choices on things they don't understand.&lt;/blockquote&gt;

So you're given a list of programs that are going to be installed? You still have no way of knowing what those programs actually &lt;em&gt;do&lt;/em&gt;.</description>
		<content:encoded><![CDATA[<p><strong>@Ryan:</strong> That still doesn&#8217;t help solve the problem pointed out by Krstic, which is better described in the report in the <a href="http://www.smh.com.au/news/security/computer-security-has-massively-failed/2007/05/21/1179601329670.html" rel="nofollow"><em>Sydney Morning Herald</em></a>:</p>
<blockquote><p>The way modern desktop security works is by relying on the user to make informed and sensible choices on things they don&#8217;t understand.</p></blockquote>
<p>So you&#8217;re given a list of programs that are going to be installed? You still have no way of knowing what those programs actually <em>do</em>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stilgherrian &#183; Who do you trust? Everyone!</title>
		<link>http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/#comment-105736</link>
		<dc:creator>Stilgherrian &#183; Who do you trust? Everyone!</dc:creator>
		<pubDate>Wed, 23 May 2007 00:46:45 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/#comment-105736</guid>
		<description>[...] The Apple Blog was sarcastic when they reported Krstic&#8217;s speech &#8212; I suspect because arrogant OS X users think security issues don&#8217;t apply to them &#8212; so I posted a response&#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] The Apple Blog was sarcastic when they reported Krstic&#8217;s speech &#8212; I suspect because arrogant OS X users think security issues don&#8217;t apply to them &#8212; so I posted a response&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/#comment-105735</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Wed, 23 May 2007 00:25:00 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/#comment-105735</guid>
		<description>I believe a few years ago there was a program either Lavasoft (Ad-Aware) or Spybot S&#38;D had that would run in the background and analyze all your running programs and specifically would audit program installations. 
So for instance when installing the various programs would pop up right before the WinXP installation wizard would start installing the program and give you a list of all the background programs/files the program was trying to install. Once there you could pass or fail those different things being installed. 
It probably wasn't as deeply thorough as analyzing binary code embedded in the actual program but it did block quiet a bit of stuff (FREE AOL!).</description>
		<content:encoded><![CDATA[<p>I believe a few years ago there was a program either Lavasoft (Ad-Aware) or Spybot S&amp;D had that would run in the background and analyze all your running programs and specifically would audit program installations.<br />
So for instance when installing the various programs would pop up right before the WinXP installation wizard would start installing the program and give you a list of all the background programs/files the program was trying to install. Once there you could pass or fail those different things being installed.<br />
It probably wasn&#8217;t as deeply thorough as analyzing binary code embedded in the actual program but it did block quiet a bit of stuff (FREE AOL!).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stilgherrian</title>
		<link>http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/#comment-105731</link>
		<dc:creator>Stilgherrian</dc:creator>
		<pubDate>Tue, 22 May 2007 23:43:50 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/05/22/are-our-programs-spying-on-us/#comment-105731</guid>
		<description>Despite your sarcasm, when you ask...

&lt;blockquote&gt;So does that mean ‘there is nothing in place to say that' OS X’s Chess game cannot format my hard drive or turn over control of my Mac to third parties?&lt;/blockquote&gt;

... yes, you're right on the money. Krstic is absolutely correct. This is exactly the "trust model" of every desktop operating system currently in use.

Software like Minesweeper in Windows, Chess in OS X or whatever -- everything from Adobe Photoshop and Microsoft Office to that cute little widget you just downloaded from... who? -- are supplied as pre-compiled binary programs. Unless you reverse-engineer them and do a complete audit, you have no way of knowing for sure what they do. Not 100%.

Even then you have to be really good at software auditing to know you're not overlooking some trick. And you have to audit every software library they call. And, if you want to be completely sure, audit the microcode on the processor chip while you're at it.

When you run &lt;em&gt;any&lt;/em&gt; software, you're trusting the author to do only what they claim they will do.

There is no global auditing program to ensure software does what it says and &lt;em&gt;only&lt;/em&gt; what it says. In any event, how can you know whether the file you just downloaded is the same one that was audited?

And, despite the "I'm more secure than you" arrogance shown by so many OS X users, there's nothing about OS X that makes it any different to Windows in this regard: run a program, and it runs with the same privileges as you have.

At this point open-source advocates will say that they have the source code so they're OK -- but honestly, when was the last time you read through the source code before compiling and running a program?</description>
		<content:encoded><![CDATA[<p>Despite your sarcasm, when you ask&#8230;</p>
<blockquote><p>So does that mean ‘there is nothing in place to say that&#8217; OS X’s Chess game cannot format my hard drive or turn over control of my Mac to third parties?</p></blockquote>
<p>&#8230; yes, you&#8217;re right on the money. Krstic is absolutely correct. This is exactly the &#8220;trust model&#8221; of every desktop operating system currently in use.</p>
<p>Software like Minesweeper in Windows, Chess in OS X or whatever &#8212; everything from Adobe Photoshop and Microsoft Office to that cute little widget you just downloaded from&#8230; who? &#8212; are supplied as pre-compiled binary programs. Unless you reverse-engineer them and do a complete audit, you have no way of knowing for sure what they do. Not 100%.</p>
<p>Even then you have to be really good at software auditing to know you&#8217;re not overlooking some trick. And you have to audit every software library they call. And, if you want to be completely sure, audit the microcode on the processor chip while you&#8217;re at it.</p>
<p>When you run <em>any</em> software, you&#8217;re trusting the author to do only what they claim they will do.</p>
<p>There is no global auditing program to ensure software does what it says and <em>only</em> what it says. In any event, how can you know whether the file you just downloaded is the same one that was audited?</p>
<p>And, despite the &#8220;I&#8217;m more secure than you&#8221; arrogance shown by so many OS X users, there&#8217;s nothing about OS X that makes it any different to Windows in this regard: run a program, and it runs with the same privileges as you have.</p>
<p>At this point open-source advocates will say that they have the source code so they&#8217;re OK &#8212; but honestly, when was the last time you read through the source code before compiling and running a program?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
