On mySimon: Holiday Gifts Under $50
BNET Business Network:
BNET
TechRepublic
ZDNet

September 25th, 2006

David Burke dissects Apple's response on SecureWorks

Posted by George Ou @ 9:26 pm

Categories: Defcon2006, Hardware, Mobile/Wireless, Networking, News, Security, ~Events~

Tags:

David Burke who is a very sharp reader decided to chime in on Apple’s seemingly firm denial that SecureWorks supplied nothing of significance to Apple for the Apple Wi-Fi security patch.  This isn’t the first time Mr. Burke has weighed in here on Real World IT, he took John Gruber’s logic apart last time based on what little evidence Gruber supplied.  This time, he takes Apple’s Lynn Fox to task for her reply.

 

David Burke writes:
George, I just thought I would send you this email as I have just read your article on Tech Republic where Lynn Fox answered a lot of the questions I have noted coming up on the issue of what SecureWorks delivered to Apple in regard to the Macbook wireless exploit.

I was actually quite happy at first to see that Apple was giving such direct “yes and no” answers for a change, but quite frankly before I was halfway through it I felt like pulling my hair out.

Lets first look at how Lynn answers the first question;

George Ou:
Did SecureWorks ever disclose any Wi-Fi vulnerabilities to Apple?

Lynn Fox:
The only vulnerability mentioned by David Maynor was FreeBSD vulnerability CVE-2006-0226. This does not affect Apple products

Ok George, while that implies that Maynor is such a horrible security expert he doesn’t even know what vulnerabilities might work on a Mac, who knows? I do not know Maynor and certainly can’t swear he would know better, but the important thing is, Lynn is telling us here that all information Apple got from Maynor was in relation to a FreeBSD vulnerability CVE-2006-0226, which has no application to any Apple products.

Now let’s look at the very next question Lynn Fox answers;

George Ou:
Did SecureWorks ever disclose the packet captures of the malicious payload used to trigger said vulnerabilities?

Lynn Fox:
No. Packet captures were promised repeatedly but never delivered.

Now we know George that she is talking about packet captures for the FreeBSD vulnerability CVE-2006-0226, which has no application to any Apple products. We know that because she says that’s all that Maynor discussed, so that’s what the packet captures would be for.

What I do not follow here George is what in the heaven did she get Maynor to repeatedly promise to send packet captures for an exploit that had no application to an Apple product? I mean…repeatedly? And promise? This makes absolutely no sense of any kind. If Maynor was contacting her on his own and repeatedly promising for some reason to send packet captures for a vulnerability that had no application to an Apple product, peculiar as that would have been, why didn’t Apple just tell Maynor to get lost and stop bugging them as the packet captures were of no use?

This isn’t some kind of legalese issue here either George, this is just common sense. It’s obvious that something is up here with this whole packet capture issue. Lynn Fox says on the one hand Maynor only talked of one vulnerability, which didn’t apply to Apple products, and on the other hand they got Maynor to repeatedly promise to send packet captures? Something is rotten in Denmark without further explanation on that.

And what’s with all these subsequent responses to questions;

George Ou:
Did SecureWorks ever provide driver disassemblies pertaining to said Wi-Fi vulnerabilities?

Lynn Fox:
No. While SecureWorks did provide a driver disassembly, it did not indicate a Wi-Fi vulnerability in any Apple product.

George Ou:
Did SecureWorks ever provide crash dumps pertaining to said Wi-Fi vulnerabilities?

Lynn Fox:
No. While we received crash dumps from SecureWorks, they didn’t have anything to do with Mac OS X or any other Apple product.

She starts with a no, and then says yes, both times, and of course, these same things they were given must have been to do with the FreeBSD issue, after all, she said its all Maynor discussed, yet there were repeated promises made for packet captures and this makes no sense.

What makes matters worse George, is did I not read that after they were notified by Maynor of the exploit they decided to do an internal audit on their own? I really do not understand the logic behind such a chain of events. Consider; Lynn Fox has essentially said that Maynor supplied them with information that didn’t even apply to Apple products, yet they wanted packet captures and eventually decided they had to do an internal audit on their own. Why? Maynor apparently gave them less then absolute zero according to Lynn Fox. Did Apple decide to do this internal audit based on the fact that Maynor showed them a vulnerability that applied only to non Apple computers? No way.

You do not have to be a rocket scientist to see what may be at issue here George. I’m not 100% sure what’s going on here George but if it is true that Maynor has time stamped communications showing certain particulars were communicated to Apple from Maynor, and Apple did indeed work to repeatedly secure promises from Maynor to send packet captures, the evidence so far indicates that something beyond the FreeBSD issue was either discussed, or Apple had a way of making use of the FreeBSD issue in such a way that although the specific issue may not exist on Apple products it was a link to something that was.

What’s going on? Once again this ends up answering little.

- End of email -

 

Yes, this all sounds very strange David and you’ve given me a new level of respect for the legal profession.  I thought something was strange about those responses but just couldn’t put my finger on it.  You’ve cleared that up nicely, thank you.

(Note on internal audit)
As reported by Brian Krebs, Anuj Nayar said: "Basically, what happened is SecureWorks approached Apple with a potential flaw that they felt would affec tthe wireless drivers on Macs, but they didn’t supply us with any information to allow us to identify a specific problem. So we initiated our own internal product audit, and in the course of doing so found these flaws."

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 166 Talkback(s)
Your analysis is flawed.
The problem with your analysis is that you are far to quick to brush over Lynn Fox's key statement.

"Lynn Fox:
The only vulnerability mentioned by David Maynor was FreeBSD vulnerability CVE-... (Read the rest)
Posted by: DavidBurke Posted on: 09/23/08 You are currently: a Guest | | Terms of Use
George, I am disappointed in you...  bkwatch | 09/25/06
Oh don't go there  georgeou | 09/25/06
With apologies to David Burke...  timyu | 09/25/06
I retract my earlier statement (and apologies)  bkwatch | 09/25/06
Hi bkwatch. Hows it going?  DavidBurke | 09/25/06
Dear Mr. Burke:  bkwatch | 09/25/06
Ill email you shortly  DavidBurke | 09/25/06
Too bad......  jragosta | 09/26/06
Burke = Cayble?  dgtruckses | 09/26/06
Not likely ...  Jens T. | 09/26/06
Here's a simple, possible explanation  timyu | 09/25/06
Another possible simple explanation which jives with Anuj Nayar's statement  V-Train | 09/25/06
now that is analysis  bkwatch | 09/25/06
Thats cool,  DavidBurke | 09/25/06
But that's not exactly what Fox said  V-Train | 09/25/06
I concur.  timyu | 09/25/06
Ha! Now thats really cool  DavidBurke | 09/25/06
Personally, I have a much bigger issue with Secureworks  V-Train | 09/25/06
What is Apple's approach?  rikmarl | 09/26/06
Badgering the witness  tic swayback | 09/26/06
Because.....  jragosta | 09/26/06
or Apple didn't understand the packet captures  bkwatch | 09/25/06
She sounded like a woman to me  georgeou | 09/25/06
Another possible simple explanation  toadlife | 09/26/06
Why?  tic swayback | 09/26/06
Sure  jragosta | 09/26/06
Come on guys!  toadlife | 09/26/06
So hard to tell these days...  tic swayback | 09/26/06
You may be right. And who said conspiracy  DavidBurke | 09/25/06
I was responding to Ou, not to you.  timyu | 09/25/06
Correct.  DavidBurke | 09/25/06
You're raving mad  Richard Flude | 09/26/06
My my.  DavidBurke | 09/26/06
Welcome to...  rapson | 09/26/06
To Rapson  georgeou | 09/26/06
To George  rapson | 09/27/06
Taking exception  tic swayback | 09/26/06
Peculiar things?  jragosta | 09/26/06
Conspiracy Theory  GW Mahoney | 09/26/06
Thats not what a conspiracy theory is  Cayble | 09/28/06
my hought exactly  richvball44 | 09/26/06
Give up Apple. Straight talk won't get you anywhere on this blog.  GW Mahoney | 09/26/06
Thats fine  DavidBurke | 09/26/06
Way ahead of you  GW Mahoney | 09/26/06
More Analysis  rikmarl | 09/26/06
Thanks for your well thought-out analysis  V-Train | 09/26/06
I particularly liked that Burkism at the end  GW Mahoney | 09/26/06
Now *that's* logic  Thrudheim | 09/26/06
Your analysis is flawed.  DavidBurke | 09/23/08
Do us all a favor George  Robert Crocker | 09/26/06
Clinton would be proud  jragosta | 09/26/06
My own conspiracy theory  timyu | 09/26/06
You sir  dragosani | 09/26/06
Apple is a joke  zzz1234567890 | 09/26/06
Give Apple credit for one thing though...  tic swayback | 09/26/06
Why should anyone care.....  jragosta | 09/26/06
As is your post, troll  MacKeyser | 09/26/06
It's "losers" not "loosers"  toadlife | 09/26/06
Mark Twain  barstewards | 09/26/06
you just proved yourself to be an idiot  zzz1234567890 | 09/26/06
George, try multiple choice  dgtruckses | 09/26/06
That's not George's style  jragosta | 09/26/06
Just call Apple a Liar and be done with or...  barstewards | 09/26/06
I've got a good chunk of evidence due this weekend  georgeou | 09/26/06
For your sake, I hope so  tic swayback | 09/26/06
I'm not for SecureWorks  georgeou | 09/26/06
Bravo, I agree. No smearing  bkwatch | 09/26/06
Oh the suspense  dgtruckses | 09/26/06
Might be interesting....  jragosta | 09/26/06
Oh, Toorcon, Sat Sep 30th 11:30 PST? You're just like John Q. Public now.  GW Mahoney | 09/26/06
Will you change your Title to Say "Apple is a Liar"?  barstewards | 09/27/06
I'm not a lawyer, but I play one on TV  dgtruckses | 09/26/06
Disecting David Burke's response  Steve_S1 | 09/26/06
Just replace Apple with Microsoft  TonyMcS | 09/26/06
No one has said macs don't have vuln's  dgtruckses | 09/26/06
Gee you obviously haven't been here much  TonyMcS | 09/26/06
Where?  jragosta | 09/27/06
You really love that strawman, don't you?  tic swayback | 09/27/06
news flash.. there is a difference between a vulnerablity & exploit...  doctorSpoc | 09/27/06
And this whole stink rests  gskiii | 09/27/06
Back up your "countless examples" Tony McBS  dgtruckses | 09/27/06
Nice try...  GW Mahoney | 09/26/06
Wrong again  TonyMcS | 09/26/06
Have you been following this story?  GW Mahoney | 09/26/06
get real  rwahrens1952 | 09/27/06
Is this your first day on ZDNet?  tic swayback | 09/27/06
what he said  JetJaguar | 09/26/06
Just chill.  DavidBurke | 09/27/06
how so  piet jansen | 09/27/06
Exactly... How attending law school equates....  thelemite | 09/27/06
Wanna bet?  tic swayback | 09/27/06
Then that will be Maynor/SecureWorks fault wont it.  DavidBurke | 09/27/06
We'll see  tic swayback | 09/27/06
Re: We'll See  barstewards | 09/27/06
Could be  tic swayback | 09/27/06
What level of evidence?  bkwatch | 09/27/06
A good list  tic swayback | 09/27/06
Expectations too high  GW Mahoney | 09/28/06
Expectations too high?  jragosta | 09/28/06
Also "orchestrated assault"  dgtruckses | 09/27/06
excellent point: assault vs PR  bkwatch | 09/27/06
Time stamp as evidence  dgtruckses | 09/27/06
Time stamping  arkitty | 09/27/06
Of course  jragosta | 09/28/06
Thanks for the explanation arkitty  dgtruckses | 09/28/06
clue?  arkitty | 09/28/06
"done correctly"  jragosta | 09/28/06
My lowly 2 cents.  DavidBurke | 09/27/06
Stick to legal matters  jragosta | 09/28/06
I don't want answers or explanations  tic swayback | 09/28/06
the state of afairs  IkBen | 09/28/06
DIng! Ding! Ding! We have a winner!  tic swayback | 09/29/06
State your case  JetJaguar | 09/28/06
I can't call them "frauds"  tic swayback | 09/28/06
you're no fun, Tic  JetJaguar | 09/28/06
not technical but behavior  piet jansen | 09/28/06
fail  JetJaguar | 09/28/06
wat you forget  piet jansen | 09/28/06
also  piet jansen | 09/28/06
How is that a contradiction?  arkitty | 09/28/06
contradiction  piet jansen | 09/28/06
notification  arkitty | 09/28/06
Contradiction?  arkitty | 09/28/06
Welcome back, Mr. Strawman  dgtruckses | 09/28/06
fail  JetJaguar | 09/28/06
pass  dgtruckses | 09/28/06
Time is running out for M&E  Steve_S1 | 09/28/06
fail  JetJaguar | 09/28/06
Wrong...  Steve_S1 | 09/28/06
but there is no evidence to refute...  doctorSpoc | 09/28/06
he is not even asking such a dificult case  piet jansen | 09/28/06
"maybe behaving unprofessionally is already prove enough for what he is ask  JetJaguar | 09/28/06
impartial judge  piet jansen | 09/28/06
fraud  piet jansen | 09/28/06
fail  JetJaguar | 09/28/06
fail  JetJaguar | 09/28/06
Okay ...  Jens T. | 09/28/06
fail  JetJaguar | 09/28/06
Not quite  Jens T. | 09/28/06
shellcode  arkitty | 09/28/06
shellcode  Jens T. | 09/28/06
fail  JetJaguar | 09/28/06
weak ...  Jens T. | 09/28/06
Kernel level stuff  arkitty | 09/28/06
Please, stop feeding the troll  dgtruckses | 09/28/06
Sorry, this thread fails.  timyu | 09/28/06
this is a controversy about reporting  bkwatch | 09/28/06
Challenge over  JetJaguar | 09/29/06
Next Challenge:  tic swayback | 09/29/06
Good Point.  DavidBurke | 09/29/06
Missing one thing  jragosta | 09/29/06
Challenges  jragosta | 09/30/06
Response to Tic  JetJaguar | 09/28/06
well duh...  doctorSpoc | 09/28/06
Who are you, David Burke?  tic swayback | 09/28/06
Not Mr. Burke... more likely BittyBoy  thelemite | 09/29/06
but  piet jansen | 09/28/06
sorry wrong button this was a answer  piet jansen | 09/28/06
yeah...  JetJaguar | 09/28/06
You show your ignorance  dgtruckses | 09/28/06
fail  JetJaguar | 09/28/06
Huh?  jragosta | 09/28/06
You don't have the technical knowledge to judge  dgtruckses | 09/28/06
BREAKING NEWS!! Maynor and Elich NOT speaking at Toorcon!!  V-Train | 09/29/06
David Burke's possible erroneous reading  therobotman | 03/22/07
Your logic doesn't follow  DavidBurke | 01/23/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    Meet Doc

    • Here to help you with your Document Management Needs
    • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
    • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
    • Produced by
      ZDNet and