Friday, November 16th 2007
Apple Admits to ‘Misleading’ Firewall
Apple has admitted that the firewall in its new Leopard OS X may be misleading to users, after complaints that the "Block all incoming connections" setting was not all that it was made out to be.
Source:
ZDNet.com
The 'Block all incoming connections' setting for the Application Firewall allows any process running as user "root" (UID 0) to receive incoming connections, and also allows mDNSResponder to receive connections. This could result in the unexpected exposure of network services.As a result, the company has quickly released a patch to fix this issue, which also fixes a flaw that lets processes running as root through the firewall even if they are added to the list of blocked applications, and an issue which means an application needs to be restarted before changes in firewall settings will take affect for it.
6 Comments on Apple Admits to ‘Misleading’ Firewall
"Overpriced computer not nearly as safe as we are all expected to believe"