|
|||||||
| Register | Members List | New Posts | Mark Forums Read |
![]() |
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
Kasper's Automated Slave
Join Date: Nov 1997
Posts: 6,171
|
Apple hires One Laptop Per Child security expert and noted critic
Apple has hired Ivan Krstic, the developer of the security architecture for the One Laptop Per Child project's XO system and subsequently a vocal critic of the failed OLPC program. Krstic is a prodigy security guru with anti-malware credentials.
MIT's Technology Review cited Krstić as a Young Innovator in 2007 for his work in developing Bitfrost, the innovative new security model used by the XO, at the age of 21. He joined the OLPC project with the task of developing a security system that would be easy enough for children to use and wouldn't require an army of support personnel to manage. One element of the Bitfrost system is that all applications are sequestered into their own virtual operating system, with rule-based limitations placed on what permissions they can access and change on the system, according to the Technology Review. This effectively prevents a virus from doing anything dangerous on the system, or as Krstić told the publication, "This defeats the entire purpose of writing a virus." Thinking differently After serving as the OLPC's Director of Security Architecture, Krstić was involved in an effort to adapt the system from the specialized Sugar/Linux environment running on the XO to the mainstream Linux desktop. For Bitfrost to be effective, all applications on the machine must be aware of it, making it incompatible with preexisting apps. This calls for some way to adapt existing programs to the new architecture. There may be some common ground shared between Bitfrost and Apple's iPhone security model, which segregates third party apps into sandboxes that prevent them accessing a communal PC-style file system or accessing hardware features such as GPS without the user's approval. Apple's propensity for examining new and better ways to deliver functionality rather than just expected features have confounded pundits who can't understand why the company didn't make the iPhone work like every other phone, with a user accessible, shared file system; a security-free copy and paste mechanism; unfettered application installation rather than mandatory code signing; and unrestricted background apps that require users to handle process management themselves. Krstić's original security development for the XO indicates a similar interest in discovering the new rather than pushing ahead old ideas out of convention. In addition to the security model deployed for distributing iPhone software, Apple may soon reveal a similar effort to deliver secured software for Mac users; like the XO's Bitfrost and iPhone apps, this would require all software to be security savvy. Apple has already pushed developers toward supporting application signing to enable Parental Controls, Managed Preferences, the Application Firewall included with Mac OS X Leopard, Keychain, Software Update, and other features that need to know that the applications they are working with are legitimate and not corrupted by malware. The next step may eventually include opening a software store for Mac users that enables secured software downloads at lower prices, just like the iPhone. Krstić said in a blog posting that he "couldn’t be more thrilled" with his new position at Apple. His future with the company will likely be a stark contrast with his past in working with the politicized OLPC project. Apple, Open, and OLPC Nicholas Negroponte, who leads the OLPC effort, told his TED audience in 2006 that Steve Jobs had supported his early efforts building toward what would become OLPC with free Apple computer hardware back in the early 80s. However, when Jobs offered the OLPC project free use of Mac OS X software and engineering help, it rejected Apple's technology in favor of Linux, a decision supposedly based on the group's dedication to free and open source software. Writing in defense of open software in the OLPC project, Copyrighteous blogger Mako Hill wrote that XO "laptop recipients will benefit from being able to fix, improve, and translate the software on their laptops into their own languages and contexts." Negroponte's dedication to open source didn't last long however. As its fortunes began to wane, the OLPC rolled out plans with Microsoft to deliver new XO machines capable of dual booting Windows XP, shortly after Microsoft and Intel unveiled their own plan to compete against the XO with a low-end netbook offering called Classmate, designed entirely to ensure that third world children wouldn't be exposed to computers running anything other than an Intel CPU and a Microsoft operating system. Microsoft didn't even offer XP to the OLPC for free; the company's software licensing demands, plus the extra hardware required to run Windows XP, added another 10% to the target price of the XO system. Krstić's scathing exposé on OLPC As the OLPC project became consumed by Free Software politics and proprietary assimilation by Microsoft at the same time, Krstić left the group. A year ago, he penned an inside look at Negroponte's OLPC and its strange tango with FOSS and Microsoft. Krstić took issue with Hill's Free Software advocacy which claimed that "OLPC needs to be uncompromising about software freedom," calling it "bright-eyed idealism [...] appealing, but alas, just not backed by fact." "No, we don't know that laptop recipients will benefit from fixing software on their laptops. Indeed, I bet they'd largely prefer the damn software works and doesn't need fixing," Krstić wrote. I switched to Mac OS X Krstić added, "One of the favorite arguments of the free software and open source community for the obvious superiority of such software over proprietary alternatives is the users' supposed ability to take control and modify inadequate software to suit their wishes. Expectedly, the argument has been often repeated in relation to OLPC. I can't possibly be the only one seeing that the emperor has no clothes." "After 12 years of almost exclusive use of free software, I switched to Mac OS X," Krstić wrote. After describing problems with "vendors not releasing documentation that would make it possible for Linux to play well with their hardware," he added, "Until the day comes when hardware vendors and free software developers find themselves holding hands and spontaneously bursting into one giant orgiastic Kumbaya, that's the world we live in. So in the meantime, I switched to OS X and find it to be an overwhelmingly more enjoyable computing experience." "My theory is that technical people, especially when younger, get a particular thrill out of dicking around with their software," Krstić said. "Much like case modders, these folks see it as a badge of honor that they spent countless hours compiling and configuring their software to oblivion. Hey, I was there too. And the older I get, the more I want things to work out of the box. Ubuntu is getting better at delivering that experience for novice users. Serious power users seem to find that OS X is unrivaled at it." The OLPC mess "OLPC was supposed to be about learning, not free software," Krstić wrote. "And the most upsetting part of the Windows announcement is not that it exposed the actual agendas of a number of project participants which had nothing to do with learning, but that Nicholas' misdirection and sleight of hand were allowed to stand." "The whole 'we're investing into Sugar, it'll just run on Windows' gambit is sheer nonsense. Nicholas knows quite well that Sugar won't magically become better simply by virtue of running on Windows rather than Linux. In reality, Nicholas wants to ship plain XP desktops. He's told me so. That he might possibly fund a Sugar effort to the side and pay lip service to the notion of its 'availability' as an option to purchasing countries is at best a tepid effort to avert a PR disaster." "In fact, I quit when Nicholas told me — and not just me — that learning was never part of the mission. The mission was, in his mind, always getting as many laptops as possible out there; to say anything about learning would be presumptuous, and so he doesn't want OLPC to have a software team, a hardware team, or a deployment team going forward." Krstić later added, "That OLPC was never serious about solving deployment, and that it seems to no longer be interested in even trying, is criminal. Left uncorrected, it will turn the project into a historical information technology ["failure" Krstić used another word] unparalleled in scale." Shortly after resigning from OLPC, Krstić wrote Negroponte, saying, "I continue to think it’s a crying shame you’re not taking advantage of how OLPC is positioned. Now that it’s goaded the industry into working on low-cost laptops, OLPC could become a focus point for advocating constructionism, making educational content available, providing learning software, and keeping track of worldwide [one-to-one] deployments and the lessons arising from them. When a country chooses to do [a one-to-one computer program], OLPC could be the one-stop shop that actually works with them to make it happen, regardless of which laptop manufacturer is chosen, banking on the deployment plans it’s cultivated from experience and the readily available base of software and content it keeps. In other words, OLPC could be the IBM Global Services of one-to-one laptop programs. This, I maintain, is the right way to go forward." What's next With his newfound interest in using technologies that just work, Krstić might seem a natural for joining Apple, which is all about making technology accessible to individuals. Krstić may likely contribute his expertise in developing security software. Over the last year, he reported having joined the advisory board for the Anti-Malware Testing Standards Organization, the technical working group of StopBadware, and the security response team of the Python project. This week, Krstić posted on his blog, "After a great deal of deliberation, I moved to California and joined the local fruit vendor. Today was my first day on the job, and I couldn’t be more thrilled." |
|
|
|
|
|
#2 |
|
Registered User
Join Date: Nov 2007
Posts: 1,438
|
The "failed" OLPC program? They just signed a deal with India for a quarter million laptops. Though not as successful as its founders hoped, OLPC is doing reasonably well.
|
|
|
|
|
|
#3 |
|
Registered User
Join Date: Dec 2006
Location: Seattle
Posts: 58
|
Marvelous
Judging by the details in this story, this is a marvelous move for Apple and for Mac users. As the Mac market share grows, we can't depend on security through obscurity any more. He may be able to give both Macs and iPhones a security so innovative and state-of-the-art, hackers don't even try to crack it.
|
|
|
|
|
|
#4 |
|
Registered User
Join Date: Jul 2003
Posts: 2,481
|
Fantastic news.
It will be a year or two before we see anything in any Apple OS. I'd really like to see his effort go to mobile devices. It would be neat to have the Touch OS secure enough to support mesh networking and other things that OLPC did well. Not that they couldn't do mesh now but better security would make me feel much better.
Dave |
|
|
|
|
|
#5 | |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,912
|
Quote:
![]() * The CIA has a time machine
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
Last edited by solipsism; 05-14-2009 at 12:23 AM.. |
|
|
|
|
|
|
#6 |
|
Registered User
Join Date: May 2005
Posts: 8,461
|
I suppose his efforts on the OLPC could transfer quite nicely to a newspaper/magazine-styled minimalist Apple computer... all-righty then!
"The natural progress of things is for liberty to yield, and government to gain ground."
—Thomas Jefferson Proud AAPL stock owner. |
|
|
|
|
|
#7 |
|
Registered User
Join Date: Nov 2008
Posts: 9
|
I'm thinking the "failed" part of OLPC is referring to the failure to understand and follow the original mission. It wasn't about the Borg like assimilation via XP laptop, or PR... but that's what 'Nicolas' turned it into (according to the article).
It's good to see Krstic on board with the "local fruit vendor," and that he's kept his standard realist mindset & flavorful vocabulary.
Bobby & Carie
13" Macbook Aluminum, 17" Macbook Pro -both: 2.4 GHz, 4GB RAM, 23" Cinema Display |
|
|
|
|
|
#8 |
|
Registered User
Join Date: Jun 2005
Location: Philadelphia
Posts: 479
|
"As its fortunes began to wane, the OLPC rolled out plans with Microsoft to deliver new XO machines capable of dual booting Windows XP, shortly after Microsoft and Intel unveiled their own plan to compete against the XO with a low-end netbook offering called Classmate, designed entirely to ensure that third world children wouldn't be exposed to computers running anything other than an Intel CPU and a Microsoft operating system."
Wow. Just.....wow. |
|
|
|
|
|
#9 |
|
Registered User
Join Date: Jul 2007
Posts: 51
|
What an interesting article! Thanks AI! It sounds like this guy has some good and Apple-like ideas about integrated security. I can't wait this bearing fruit and leave the critics left with nothing to say. Sure Apple will gain greater marketshare but their security wont suffer from it. Whilst m$ is trying to solve their security and driver problems Apple is well on it's way to innovate more and more, leaving competition far behind.
|
|
|
|
|
|
#10 |
|
Registered User
Join Date: Dec 2006
Posts: 328
|
With 30 Billion Cash, many world known expertise joining Apple. I think apple is in a very good position to make technology, finally... easy to use.
|
|
|
|
|
|
#11 |
|
Registered User
Join Date: Jun 2005
Location: Philadelphia
Posts: 479
|
solipsism,
I'm catching you on the total posts, dude! ![]() |
|
|
|
|
|
#12 |
|
Registered User
Join Date: Mar 2005
Posts: 1,010
|
Dammit, this is a cool article and I'm not smart enough to know why or what the future implications mean....argh!!! I just like it.
:-D * * * * * * * * * * * * * * * *
|
|
|
|
|
|
#13 |
|
Registered User
Join Date: Mar 2009
Posts: 17
|
I guess Apple's well on its way to creating the tech dream team... Can't wait to see it all come together!
|
|
|
|
|
|
#14 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,912
|
Almost...
![]() You get the Bronze Melgross award at 1,000 posts. Silver Melgross 5,000, Gold Melgross at 10,000 and Platnium Melgross at 15,000 posts. I think that means that the Adamantium Melgross award arrives at 20,000 posts.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
#15 |
|
Registered User
Join Date: Nov 2004
Location: Northwest
Posts: 2,698
|
|
|
|
|
|
|
#16 |
|
Registered User
Join Date: Aug 2006
Location: Australia.
Posts: 63
|
Statistically, yes, it is. But why don't we see if those kids think the same thing?
If it helps them get a good education, a good job, etc, I'd be quite reluctant to call it a 'failure'. I'd call it 'worthwhile'. *Note: Might still fail. :P
Call on God, but row away from the rocks.
- Indian Proverb. |
|
|
|
|
|
#17 |
|
Registered User
Join Date: Apr 2008
Location: Cambridge, MA
Posts: 28
|
Krstic is my new hero:
- Slamming the pollyanna-ish notion of free open-source software ever being more than a niche market. - Slamming OLPC for having a [dumb] business model. - Slamming OLPC's founder (Negroponte) as not being primarily interested in education or the large-scale deployment of OLPC laptops. And my favorite, the whole part where he talks about it being fun to mess with computers as a kid, but that as grownups people want computers that just work. Is "Ivan Krstic" croatian for "Steve Jobs Jr"?
Mac Plus, Mac Plus w/hd, Mac SE, Mac II, Centris 610, The Horrible 6250, iMac G3, G5 Tower, ...and on all of these machines I only have had one computer game: Strategic Conquest. Truly pathetic....or awesome. Probably both.
|
|
|
|
|
|
#18 | |
|
Registered User
Join Date: Nov 2008
Posts: 2,090
|
Quote:
(Formerly LTD on Neowin.net) (currently *LTD* on Macrumors.com)
Mac OS users have made a conscious technology choice and are therefore typically better informed than their peers. -- Paul Thurrott, winsupersite.com, December 06, 2004 |
|
|
|
|
|
|
#19 | |
|
Registered User
Join Date: Jan 2005
Location: Philadelphia
Posts: 264
|
Quote:
A very large % of their population have no idea what technology exist and they live right along side people who do. Those who have the knowledge, power and money do not allow those who are below them in the case system to raise above. As they always say knowledge and information is power and you can be assured they they make sure those below them will never gain this. |
|
|
|
|
|
|
#20 | |
|
Registered User
Join Date: May 2008
Posts: 570
|
Quote:
![]()
Jessie Ventura + Ron Paul = USA
|
|
|
|
|
|
|
#21 |
|
Registered User
Join Date: Dec 2001
Location: Kansas City
Posts: 1,708
|
A friend will help you move, but a REAL FRIEND will help you move a body.
|
|
|
|
|
|
#22 | |
|
Registered User
Join Date: Nov 2008
Posts: 2,090
|
Quote:
(Formerly LTD on Neowin.net) (currently *LTD* on Macrumors.com)
Mac OS users have made a conscious technology choice and are therefore typically better informed than their peers. -- Paul Thurrott, winsupersite.com, December 06, 2004 |
|
|
|
|
|
|
#23 | |||
|
Global Moderator
Join Date: Jun 2004
Location: .US
Posts: 9,128
|
Quote:
Quote:
Quote:
|
|||
|
|
|
|
|
#24 |
|
Registered User
Join Date: Aug 2006
Posts: 2,078
|
I prefer Eric Stoll's take in his book High-Tech Heretic on "Information is Power", i.e., "Information isn't power. Who's got the most information in your neighborhood? Librarians, and they are famous for having no power at all. Who has the most power in your community? Politicians, of course. And they're notorious for being in-informed."
|
|
|
|
|
|
#25 | |
|
Registered User
Join Date: Feb 2008
Posts: 1,415
|
Quote:
The mere presence of computers does not equate to learning, while it's a great thing that third world kids might get more access to computers, it's nothing to do with any "impact it would have on their developing brain," or any such pie in the sky stuff. It's a popular misconception in education circles that more computers equals more learning, but the people that have actually looked into it in any detail can tell you it's a false hope. Some kid in Africa would be better off having an actual school full of actual teachers, and a political and economic system that supports growth, community etc. than a free plastic laptop. Your second point is also wrong, but going into the detail would take more time than I want to spend here. I suggest you look it up. The situation was pretty much as the article above explains. Microsoft and intel had basically no interest in this market or this part of the world until OLPC. Then they came out with the classmate specifically to counter it, even though they had no intentions of really doing much of what they talked about with the project or the device. |
|
|
|
|
|
|
#26 | |
|
Registered User
Join Date: Nov 2008
Posts: 2,090
|
Quote:
(Formerly LTD on Neowin.net) (currently *LTD* on Macrumors.com)
Mac OS users have made a conscious technology choice and are therefore typically better informed than their peers. -- Paul Thurrott, winsupersite.com, December 06, 2004 |
|
|
|
|
|
|
#27 | |
|
Registered User
Join Date: Jan 2008
Posts: 332
|
Quote:
I would argue the opposite, for most tech savvy kids things that are more difficult to crack are where the excitement is & tends to feed their desire to learn about the depths of that system. |
|
|
|
|
|
|
#28 | |
|
Registered User
Join Date: Nov 2003
Posts: 404
|
Quote:
Using the razor and blades analogy, it makes sense. If MS & Intel could flood the developing-world market with extremely low-cost machines, then as those users grew up out of poverty, MS & Intel would have consumers pre-disposed to their brands/products. And there are certainly higher cost products required to provide infrastructure, servers, etc. for all the cheap PCs. This model may actually accomplish Negroponte's vision - I'm speculating here - poor kids get computers; that they are MS & Intel products vs OLPCs isn't that important in the bigger scheme. OLPC had some very interesting ideas/visions on the software side, too. It sounds like those have been scrapped. Too bad. - Jasen. |
|
|
|
|
|
|
#29 |
|
Registered User
Join Date: Nov 2003
Posts: 404
|
|
|
|
|
|
|
#30 | |
|
Registered User
Join Date: Nov 2003
Posts: 404
|
Quote:
- Jasen. |
|
|
|
|
|
|
#31 | |
|
Registered User
Join Date: Jan 2006
Location: Houston, TX
Posts: 138
|
Quote:
|
|
|
|
|
|
|
#32 | |
|
Registered User
Join Date: Sep 2005
Location: Wellington, New Zealand
Posts: 243
|
Quote:
Most geeks get to a point where the fiddling becomes less and less interesting as free time becomes less and less to the point where one just wants a computer to work out of the box with minimum fuss; which led me to move from Linux/*BSD/Solaris to Mac OS X. |
|
|
|
|
|
|
#33 | |
|
Registered User
Join Date: Feb 2008
Posts: 1,415
|
Quote:
I work in Education, so I get that misconception about technology = learning every day. Perhaps I am oversensitive to the argument. ![]() |
|
|
|
|
|
|
#34 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,912
|
Yes, for a horrible 6 month stretch to get my hands on the equipment I needed to finally pass my CCIE Voice cert. The equipment is very expensive to rent so going to India was a major cost savings, even when you consider that round the trip flight was $1,200 on BA. I hated almost every minute of it in almost every aspect. Everything you say is correct while also not being correct. The caste does exist, but not like it used to be. You can break free from poverty if you have the desire and aptitude, just like the US, though it will certainly be much harder. I still haven't watched Slumdog Millionaire simply because I'm sure it will remind of all the things I been trying to forget about the place. I didn't just study, I also traveled extensively around the upper half of the country.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
Last edited by solipsism; 05-14-2009 at 12:24 PM.. |
|
|
|
|
|
#35 | |
|
Registered User
Join Date: Oct 2008
Posts: 40
|
Quote:
Apple's propensity (for examining new and better ways to deliver functionality, rather than just expected features) has confounded pundits.... |
|
|
|
|
|
|
#36 |
|
Registered User
Join Date: Apr 2006
Location: The Ansible
Posts: 11,912
|
I am dumbfounded by this. On the one hand I think you are correct a propensity is singular so it should use 'has'. On the other, the preposition 'for' after propensity does describe two things so 'have' could be used. I think you are more correct as, as you have shown, the sentence stands in a simple form, but I think that both ways may be considered correct by and large.
Do your part to clean up AppleInsider forums: User CP » Edit Ignore List » Teckstud
|
|
|
|
|
|
#37 |
|
Registered User
Join Date: Feb 2007
Posts: 133
|
Jobs' legacy!
This is Steve Jobs' legacy project!
Apple wanted to help out and was going to give them OSx and engineering for free. Sadly, they were overcome with Redmond. Apple bought that chip manufacturer for cheap, low power chips, their new way of machining laptops makes it easier to have a manufacture almost anywhere in the world (including Africa), now they get one of the "cheap laptops for the third world" guys who know how to do it. Steve wants to leave a legacy for the world. Inside each laptop will be inscribed "Steve was here". ![]() |
|
|
|
|
|
#38 |
|
Registered User
Join Date: Mar 2008
Posts: 68
|
What a bright young man.
This is a total win for Apple and more importantly for us Mac OS X users. I truly await to see what this wiz will deliver. ![]() |
|
|
|
|
|
#39 |
|
Registered User
Join Date: Feb 2009
Posts: 94
|
Not really. Ivan means John and Krstic is literally "Little Cross", so his name means Little Cross John.
Last edited by Mario; 05-14-2009 at 02:03 PM.. Reason: typo |
|
|
|
|
|
#40 |
|
Registered User
Join Date: Sep 2008
Location: The West
Posts: 308
|
If he has been hired to bring app-centric permissions to Mac OS, then this is the biggest news of the decade.
It is often said that the flaw that makes trojans possible is users that install software. This is misleading - the flaw that makes trojans dangerous is that OS's allow apps to run with the full permissions of the user, instead of a restricted set of permissions relevant to the app itself. If Apple get this bit right ( and without getting sucked down the virtualization route, it's just resource permissions that are needed ) then they will have delivered bigger value to their users than anything else I can imagine. Just as MS have finally added some file permissions, Apple would have blasted ahead to the next level. Last edited by PXT; 05-14-2009 at 05:38 PM.. |
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|