Apple Releases Security Update 2011-005 for OS X to Address Compromised Certificates
Apple today released Security Update 2011-005 for OS X, a small update addressing a specific security issue related to fraudulent certificates from DigiNotar.
Impact: An attacker with a privileged network position may intercept user credentials or other sensitive information
Description: Fraudulent certificates were issued by multiple certificate authorities operated by DigiNotar. This issue is addressed by removing DigiNotar from the list of trusted root certificates, from the list of Extended Validation (EV) certificate authorities, and by configuring default system trust settings so that DigiNotar's certificates, including those issued by other authorities, are not trusted.
DigiNotar, one of hundreds of firms authorized to issue digital certificates that authenticate a website's identity, admitted on Aug. 30 that its servers were compromised weeks earlier. A report made public Monday said that hackers had acquired 531 certificates, including many used by the Dutch government, and that DigiNotar was unaware of the intrusion for weeks.
Available updates include:- Security Update 2011-005 (Lion) (15.59 MB)
- Security Update 2011-005 (Snow Leopard) (869 KB)
Top Rated Comments
(View all)They didn't start working on this yesterday, maybe they caught something in Q&A that delayed things a bit.
Removing compromised root certificates isn't rocket science.There is simply no excuse for Apple taking almost two weeks longer than Microsoft to release this update - with Microsoft having to cover way more OS releases and update/service pack configurations than Apple.
[SIZE=1]I even use Safari in parallels…
Really? I mean, I can buy it for OS X, but Safari for Windows genuinely sucks as a browser. I prefer even IE to the Windows version of Safari. In fact, IE9 is a pretty good browser. When none of us were looking, IE went and grew up.
What about Leopard?
The Snow Leopard version REQUIRES 10.6.8.
I remain on 10.6.6 and it refuses to install.
Bad move, Apple. You should NOT use a Security Update to force people to update.
sudo security delete-certificate -Z C060ED44CBD881BD0EF86C0BA287DDCF8167478C /System/Library/Keychains/SystemRootCertificates.keychain
sudo security delete-certificate -Z 59AF82799186C7B47507CBCF035746EB04DDB716 /System/Library/Keychains/SystemRootCertificates.keychain
sudo security delete-certificate -Z 101DFA3FD50BCBBB9BB5600C1955A41AF4733A04 /System/Library/Keychains/SystemRootCertificates.keychain
[ Read All Comments ]

Accessory maker Moshi has released a new ultra-thin plastic shell protective case for the 11" and 13" MacBook Air models. This type of plastic case tends to be especially popular among...
Blizzard Entertainment said this week that it sold more than 3.5 million copies of Diablo III on launch day, setting the record for fastest-selling PC game. The company also sold 1.2 million copies...
Hard drive maker Seagate has announced it will purchase data storage device maker LaCie for roughly $186 million.
The company plans to buy the controlling stake owned by Philippe Spruch,...
Intuit has upgraded the iOS app for its Mint personal finance tool with two new "most-requested" features that should keep users from ever having to go to the Mint.com website. Until now,...