Warning this article may contain opinions of the author that you and iTWire don't necessarily agree with. Don't let them get away with it - have your say with a comment!

No. 1 Story

ACCC clears Optus to scrap HFC network and use NBN instead

The ACCC has cleared, provisionally, the proposed deal between Optus and NBN Co under which Optus is to be paid around $800m to shut down its HFC network and transfer customers onto the NBN. read more

Safari vulnerable to remote file-stealing attack

Opinion and Analysis

Windows users should simply use a different browser, Mastenbrook suggests.

Mastenbrook has previously been credited by Apple for reporting Mac OS X vulnerabilities.

His record includes spotting a way of triggering an Applescript with a specially-crafted Help: URL (Security Update 2008-002), and suggesting improvements to the list of quarantined file types (Mac OS X 10.5.3 and 10.5.4, and Security Update 2008-003 and 2008-004),

The public disclosure of vulnerabilities before a fix has been released by the vendor concerned is a contentious issue.

One school of thought says that the responsible thing to do is keep completely quiet until the vendor has issued an update to take care of the issue.

Another holds that if one person can find a particular flaw, so can another. Therefore unless a fix is released promptly by the vendor, the right thing to do is alert users to the problem and provide a workaround so they at least have the opportunity to protect themselves.

Mastenbrook gave no indication of when he alerted Apple to this vulnerability.