|
|||||||
| Register | Members List | New Posts | Mark Forums Read |
![]() |
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
Kasper's Automated Slave
Join Date: Nov 1997
Posts: 6,151
|
Apple releases Safari 3.2 with phishing protection
Apple on Thursday afternoon released Safari 3.2, a recommended update for all Safari users that delivers protection from fraudulent phishing websites and better identification of online businesses.
The update also includes the latest security fixes. Download Links Users of the Apple web browser can download the new version through the Software Update application available on their Mac (under the Apple menu) or PC. Safari 3.2 for Mac OS X 10.5.5 Leopard [39MB] Safari 3.2 for Mac OS X 10.4.11 Tiger [25.7MB] Safari 3.2 for *Windows XP or Vista [19MB] Background Apple briefly included anti-phishing measures in builds of Safari 3.0 that were originally included with tests seeds of the now released Mac OS X 10.5 Leopard operating system back in October of 2006. When Leopard hit the market last fall, it quickly became apparent that those features had been pulled. Earlier this year, e-commerce sites such as PayPal said they would consider blocking the use of any web browser that didn't provided added validation measures, which would have potentially restricted the use of Safari with those services. |
|
|
|
|
|
#2 |
|
Registered User
Join Date: Feb 2008
Posts: 1,415
|
|
|
|
|
|
|
#3 |
|
Registered User
Join Date: Nov 2008
Posts: 1
|
Recommended for all Macs.
Does that mean that Safari Version 4 Developer Preview (5526.11.2) should be replaced?
|
|
|
|
|
|
#4 |
|
Registered User
Join Date: Oct 2003
Location: behind you ;)
Posts: 50
|
|
|
|
|
|
|
#5 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
Just type in 'Phishing Test' into Google. There are plenty of options.
However, I can't get any of them to work. On top of that, Acid3 is still at 75/100 and it causes crashes when running WebKit within it or using extensions, so I don't recommend it for all users. I'm going back to Safari 4, which doesn't have the phishing option added yet.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
#6 | |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
Quote:
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
|
#7 |
|
Registered User
Join Date: Nov 2001
Location: Somewhere far, far away
Posts: 2,858
|
|
|
|
|
|
|
#8 |
|
Registered User
Join Date: Dec 2006
Posts: 65
|
who cares, anyone ?
Big wow, so what, I'll stick with Firefox 3, thanks
![]() |
|
|
|
|
|
#9 | |
|
Registered User
Join Date: Feb 2008
Posts: 1,415
|
Quote:
Possibly all the goofing around with WebKit you do has left you with a non-standard set of components relative to the average user. |
|
|
|
|
|
|
#10 | |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
Quote:
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
|
#11 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
WebKit is a separate app. It just calls the Safari Libraries when launched. You can still launch your verision of Safari alongside it just fine. As for extensions, that would depend on the extention. It seems Glims is causing crashes with the new build.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
#12 |
|
Registered User
Join Date: Nov 2001
Location: Somewhere far, far away
Posts: 2,858
|
WebKit piggybacks off Safari. So it's entirely possible to get all the Safari 4 goodness *and* the new anti-phishing feature.
So...yes, it's possible to score 100% on Acid3 *and* get protection from fake Chase sites. |
|
|
|
|
|
#13 |
|
Registered User
Join Date: Jul 2003
Posts: 2,481
|
Any Javascript improvements?
I just down loaded and did the reboot. I'm wondering if they rolled any of the javascript improvements into this revision or is that still off in the future.
We security is nice and all but I don't do much on line where that is a problem. What I really want is to see all the new HTML 5 and other improvements go mainstream. dave |
|
|
|
|
|
#14 |
|
Registered User
Join Date: Mar 2005
Posts: 366
|
Yes, if you installed Safari 3.2, you can still use WebKit nightlies and get the benefit of phishing protection in Safari 3.2.
Based on the comments above, I'd say that they haven't updated WebKit (significantly) for this release. Maybe we'll have to wait for Snow Leopard for that. |
|
|
|
|
|
#15 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
Yeah, I'm sure a new WebKit will work fine, but you can't use "Safari 4 goodness" and the anti-phishing feature, unless it's a hidden feature in which a PLIST edit will enable it. Though I'm sure the next Safari 4 beta will have added it, so no worries.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
#16 |
|
Registered User
Join Date: Mar 2005
Posts: 11
|
Can't Upgrade - Anyone Else?
I've run the upgrade twice now, once from Software Update and then as a download and each time I reboot and... Still have Safari 3.0.4. Anyone else having this problem?
|
|
|
|
|
|
#17 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
I did on one machine. Rename Safari to 'Safari 3.0.4' or whatever, then do the update.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
#18 |
|
Registered User
Join Date: Mar 2005
Posts: 11
|
No Go
|
|
|
|
|
|
#19 |
|
Registered User
Join Date: Mar 2008
Posts: 8
|
*sigh*
after updating, safari only crashes now.
|
|
|
|
|
|
#20 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
Uninstall any extensions and plugins that aren't ordained by Apple.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
#21 |
|
Registered User
Join Date: Feb 2008
Posts: 1,415
|
that's pretty much exactly what I was (poorly) trying to say.
|
|
|
|
|
|
#22 |
|
Registered User
Join Date: Dec 2004
Posts: 50
|
This sucks.
They included previously unpatched security fixes in this release in addition to the anti-phishing feature. Apple needs to release a standalone Security Update for the security fixes. So, anyone who chooses to skip this update will still be vulnerable to the following Safari exploits: •Safari CVE-ID: CVE-2008-3644 Available for: Mac OS X v10.4.11, Mac OS X v10.5.5, Windows XP or Vista Impact: Sensitive information may be disclosed to a local console user Description: Disabling autocomplete on a form field may not prevent the data in the field from being stored in the browser page cache. This may lead to the disclosure of sensitive information to a local user. This update addresses the issue by properly clearing the form data. Credit to an anonymous researcher for reporting this issue. •WebKit CVE-ID: CVE-2008-2303 Available for: Mac OS X v10.4.11, Mac OS X v10.5.5, Windows XP or Vista Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution Description: A signedness issue in Safari's handling of JavaScript array indices may result in an out-of-bounds memory access. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript array indices. Credit to SkyLined of Google for reporting this issue. •WebKit CVE-ID: CVE-2008-2317 Available for: Mac OS X v10.4.11, Mac OS X v10.5.5, Windows XP or Vista Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution Description: A memory corruption issue exists in WebCore's handling of style sheet elements. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved garbage collection. Credit to an anonymous researcher working with the TippingPoint Zero Day Initiative for reporting this issue. •WebKit CVE-ID: CVE-2008-4216 Available for: Mac OS X v10.4.11, Mac OS X v10.5.5, Windows XP or Vista Impact: Visiting a maliciously crafted website may lead to the disclosure of sensitive information Description: WebKit's plug-in interface does not block plug-ins from launching local URLs. Visiting a maliciously crafted website may allow a remote attacker to launch local files in Safari, which may lead to the disclosure of sensitive information. This update addresses the issue by restricting the types of URLs that may be launched via the plug-in interface. Credit to Billy Rios of Microsoft, and Nitesh Dhanjani of Ernst & Young for reporting this issue. |
|
|
|
|
|
#23 |
|
Registered User
Join Date: Jul 2004
Location: Olympus Mons
Posts: 44
|
It only crashes when I try to "Reopen all windows from last session, oh and when I tried to open a link n a new window, and oh....
the rev
|
|
|
|
|
|
#24 |
|
Registered User
Join Date: Apr 2004
Location: earth
Posts: 207
|
Same here. Constant crashes to the point that it is unusable.
Does anyone have a link to 3.1.2? |
|
|
|
|
|
#25 |
|
Registered User
Join Date: Nov 2007
Posts: 46
|
Yawn...
![]() Another also-ran, primitive, clunky Windows port. I'll stick with OmniWeb; been using it since v3 and it blows FF and Safari out of the water. And yes, I actually paid for it, and no, I don't work for OmniGroup. ![]() |
|
|
|
|
|
#26 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
#27 |
|
Registered User
Join Date: Sep 2008
Location: How's Mexico?
Posts: 1,003
|
|
|
|
|
|
|
#28 | ||
|
Registered User
Join Date: Apr 2004
Location: earth
Posts: 207
|
Quote:
Quote:
Edit: I have stopped the crashes in 3.2 by removing PithHelmet. Anyway I'd still very much appreciate if someone knows where to get 3.1.2. Last edited by Londor; 11-13-2008 at 09:00 PM.. |
||
|
|
|
|
|
#29 |
|
Registered User
Join Date: Sep 2008
Location: How's Mexico?
Posts: 1,003
|
Re-directed me too, but I've got 3.2 on 10.5.5. Maybe you need 10.4 or older to get it?
|
|
|
|
|
|
#30 | |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
Quote:
Tiger, Leopard and Windows are all 3.2. I can't find a link that doesn't redirect me to 3.2.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
|
#31 | |
|
Registered User
Join Date: Jul 2004
Location: Olympus Mons
Posts: 44
|
Quote:
Luckily I didn't upgrade my laptop.
the rev
|
|
|
|
|
|
|
#32 |
|
Registered User
Join Date: Sep 2008
Location: How's Mexico?
Posts: 1,003
|
Wouldn't users of 10.5.2 be able to use that 3.1.2 hence the link being left up?
|
|
|
|
|
|
#33 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
Not necessarily. the OS X requirements are "Any Mac running Security Update 007 and Mac OS X Leopard 10.5.5 or Mac OS X Tiger 10.4.11 (or higher)", so Apple may want you to update your OS X version. Especially since the updates are free so there is no legitimate reason, in Apple's eyes, why you wouldn't want the latest point update of OS X but want the latest version of Safari.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
#34 | |
|
Registered User
Join Date: Sep 2008
Location: How's Mexico?
Posts: 1,003
|
Quote:
Last edited by Hands Sandon; 11-13-2008 at 11:04 PM.. |
|
|
|
|
|
|
#35 | |
|
Registered User
Join Date: May 2002
Posts: 364
|
Quote:
Last edited by ajmas; 11-14-2008 at 08:08 AM.. Reason: very minor mistake in wording corrected |
|
|
|
|
|
|
#36 | |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,779
|
Quote:
PS: I find the WebKit nightly builds to be quite stable, almost all of the time. The advancements they've made with JS processing since the build Apple uses in their Safari current releases makes them worthwhile. Now, Safari 4 beta, on the other hand, still has quirks so it's not worth the trouble, IMO.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
|
#37 |
|
Registered User
Join Date: May 1990
Location: ylamona laropmet a ni kcutS
Posts: 287
|
It is not Apple's responsibility to ensure compatibility with third party hacks.
Proud member of AppleInsider since before the World Wide Web existed.
|
|
|
|
|
|
#38 | |
|
Registered User
Join Date: Sep 2005
Location: Wellington, New Zealand
Posts: 243
|
Quote:
I wish some people here would put a cork in it when they don't know what the heck they're talking about. |
|
|
|
|
|
|
#39 |
|
Registered User
Join Date: Jun 2005
Posts: 1,149
|
Apple is losing its way. Whatever happened to "it just works"? Now they've got so many interdependencies, it's not funny. I just had Safari 3.1 crash and take my whole system with it. Figured it'd be a good time to go to 3.2 since this is one of my rare restarts. Bad move. 3.2 demands 10.5.5 and the latest security update. Why? I don't know. I bet the Windows version doesn't demand Vista SP2 and all the latest security updates. I upgraded from 10.5.3. 10 minutes, double reboot, etc. Safari still wouldn't install without the security update that Software Updater didn't even list until 10.5.5 was installed. Another 5 minutes to install that and double reboot. Finally installed Safari after another few minutes. A browser shouldn't need over 20 minutes to install. Then 3.2 crashed almost instantly. Reopening it every time gave me crashes. I finally went on a search and destroy mission for Pithhelmet. I feel sorry for Mac newbies who wouldn't have this kind of patience or the knowledge to follow the chain of steps. This is not the way to gain converts.
|
|
|
|
|
|
#40 |
|
Banned
Join Date: Jun 2006
Posts: 27
|
The most important new feature of Safari 3.2 is the long-overdue EV certificate support. If you log in to PayPal you'll see the info on the EV certificate at the top right of the Safari window.
|
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|