Apple Hires Former Security Director of One Laptop Per Child - MacRumors
Skip to Content

Apple Hires Former Security Director of One Laptop Per Child

In a blog post, Ivan Krstić, former director of security architecture at One Laptop per Child (OLPC), has revealed that he has taken an unspecified position related to core security at Apple. Krstić is well-known among security experts, having been named the second most influential person in security by eWeek in 2008.

As Krstić notes on his personal web site, his expertise and passion lie in making computer security easy for users:

I enjoy breaking computers. I enjoy making computers hard to break even more. Unfortunately, most people are really bad at the latter. At OLPC, I had put a lot of work into designing Bitfrost, which is a system for securing computers that's trying to be both hard to break and easy to use.

Bitfrost is a security specification that "sandboxes" applications into their own virtual operating systems, preventing viruses or other programs from damaging the operating system or accessing files. Given the focus of OLPC on children, Bitfrost is designed to be almost invisible to the end user.

We have set out to create a system that is both drastically more secure and provides drastically more usable security than any mainstream system currently on the market. One result of the dedication to usability is that there is only one protection provided by the Bitfrost platform that requires user response, and even then, it's a simple 'yes or no' question understandable even by young children. The remainder of the security is provided behind the scenes.

Bitfrost is meant to improve upon the 35-year-old UNIX permission system which persists today in Mac OS X, but Bitfrost requires that individual applications be "Bitfrost-aware", meaning that the security specification is unlikely to easily transition to mainstream operating systems. Krstić's work on Bitfrost, however, demonstrates his focus on novel security approaches that are easy to use.

Popular Stories

Aston Martin CarPlay Ultra Screen

Apple Says CarPlay Ultra is Coming to These Vehicle Brands

Thursday May 21, 2026 11:53 am PDT by
Last year, Apple launched CarPlay Ultra, the long-awaited next-generation version of its CarPlay software system for vehicles. Nearly a year later, CarPlay Ultra is still limited to Aston Martin's latest luxury vehicles, but that should change fairly soon. In May 2025, Apple said many other vehicle brands planned to offer CarPlay Ultra, including Hyundai, Kia, and Genesis. CarPlay Ultra...
Apple Event Logo

Apple to Release These 15 New Products Later This Year

Friday May 22, 2026 6:36 am PDT by
April and May have been relatively slow months for Apple this year, but there is a lot to look forward to heading into WWDC 2026 and beyond. Apple is expected to release at least 15 more products later this year, with some of them held up until the more personalized version of Siri launches. Beyond the usual annual updates to iPhones and Apple Watches in September, Apple's all-new smart...
imac video apple feature

Apple Released Two New Accessories This Month

Friday May 22, 2026 12:24 pm PDT by
May has been a quiet stretch in terms of new Apple products, but the company did release two accessories on its online store this month. First up was a new Pride Edition Sport Loop for the Apple Watch. The band features a rainbow design with 11 colors of woven nylon yarns. U.S. pricing is set at $49. The band is part of Apple's 2026 Pride Collection, which also includes a new Pride...

Top Rated Comments

Small White Car Avatar
222 months ago
Cool. Even more security for osx when it's already much more secure than windows:

Let's start this thread off with the correct terms so everyone knows:

Windows is more secure.
OS X is safer.

Users care more about safety, so Apple's on the right side of that equation. But let's keep our comments accurate, otherwise it gets very confusing.

More here:
http://daringfireball.net/linked/2009/05/13/security-safety
Score: 1 Votes (Like | Disagree)