2. I'd agree that the outreach program is something that Apple clearly hasn't done.
3. Apple clearly is doing this too.
HP's work on secret agents in the 90's shows that you can't prove code to be trustworthy. You can only assign trust to the intentions of the originator.
Therefore, the most significant thing you can do to improve security is to verify the provenance of trusted code and the isolation of untrusted code.
Windows clearly has decent technical code-signing infrastructure, but Apple seems far ahead in terms of effectively deploying this model into the field.
They seem more concerned about not letting users jailbreak their devices than anything else.
"Windows clearly has decent technical code-signing infrastructure, but Apple seems far ahead in terms of effectively deploying this model into the field."
"Far ahead"? How do you justify that claim? Most charitably, it seems that both companies work on security.
Of the two, Microsoft seems to have better documentation, better openness, and better tools.
That jailbreaking works by taking advantage of OS exploits to gain root access, and, in fact, represents a glaringly obvious, popular, and easy to use vulnerabilit has nothing to do with Apple fixing it quickly?
By #3 I was referring to the parent's 3rd comment about the focus on improving the toolchain and runtime. I doubt that you're serious about the jailbreak comment.
By far ahead, I was referring to the deployment of code signing technology.
I think it's pretty clear that although Microsoft has solid code signing technology, they are much further behind in promoting effective use of it in the field.
The compound word 'PreOrder' exists as a discrete term. ... case it as 'Preorder' or strip the first token entirely if it represents any sort of Hungarian notation.
Aw shit, Apple is gonna get fucked by all those remotely exploitable Hungarian notation bugs.
> They seem more concerned about not letting users jailbreak their devices than anything else.
Ironic that you would use a feature that excludes malware from running but pisses off android fans, as an attempt to claim that Apple is not working on security!
2. I'd agree that the outreach program is something that Apple clearly hasn't done.
3. Apple clearly is doing this too.
HP's work on secret agents in the 90's shows that you can't prove code to be trustworthy. You can only assign trust to the intentions of the originator.
Therefore, the most significant thing you can do to improve security is to verify the provenance of trusted code and the isolation of untrusted code.
Windows clearly has decent technical code-signing infrastructure, but Apple seems far ahead in terms of effectively deploying this model into the field.