Skip to Content

Apple lands OLPC security whiz -- more secure products on the way?

Twitter tipster Rich Mogull of TidBITS provided us with a ping pointing to ZDNet's Zero Day page, where blogger Ryan Naraine broke some good news today.

The news? The ex-director of security architecture for the One Laptop Per Child project, Ivan Krstic (at right), has gone to work for Apple. He'll be focusing his attention on core operating system security.

Krstic's innovative Bitfrost security specification, part of the overall OLPC initiative, essentially negates the effect of any virus by running every program on the computer in its own virtual operating system. By doing this, no malware can spy on user keystrokes, futz with files, or steal data.

According to a 2007 article by Naraine, Bitfrost has five primary goals, all of which are targeted at making the OLPC one of the most secure platforms available:
  • No user passwords -- the security of the device cannot depend on the user's ability to remember a password
  • No unencrypted authentication -- no cleartext passwords, no use of Ethernet MAC addresses for authentication
  • Out-of-the-box security -- The device should be secure out of the box, without the need to download security updates if at all possible
  • Limited institutional Public Key Infrastructure -- Don't rely on public keys to validate the identity of device owners
  • No permanent data loss -- Information is to be replicated to some centralized storage place so it can be recovered if the device is stolen, destroyed, or lost
While we may not know what the far-reaching implications of Krstic's work at Apple may be for a while, we can only hope that his hiring points to much more secure Apple products in the future.

Categories

Apple Security

Twitter tipster Rich Mogull of TidBITS provided us with a ping pointing to ZDNet's Zero Day page, where blogger Ryan Naraine broke some...
 

Add a Comment

*0 / 3000 Character Maximum

12 Comments

Filter by:
alf

just remember in all this - NOTHING is ever 100% secure!

May 14 2009 at 11:40 AM Report abuse rate up rate down Reply
Nick F

Congratulations to the poster for a blog item that's interesting, relevant, timely, not blatantly self-interested, and important. Great stuff. A fine example of what a good blog should be all about.

The rest of the TUAW team could learn something here.

May 14 2009 at 6:09 AM Report abuse rate up rate down Reply
1 reply to Nick F's comment
Adrean


I TOTALLY agree.

Excelent post.


Looking forward to his work on apple. Good news indeed.

May 14 2009 at 9:34 AM Report abuse rate up rate down Reply
Hagar Viking

Hope this guy puts a serious VM technology on iPhone OS and Mac OS that ensures complete immunity to virus and crap like that. The tech behind what Ivan did was pretty amazing for very low-end hardware before. His background in serious supercomputers helps a great deal. Hopefully making Snow Leopard light years ahead of Win 7.X ???.

May 14 2009 at 5:56 AM Report abuse rate up rate down Reply
PFar

Okay ignore this last comment:

"I hope this is a pre-cursor to iPhone firmware 2.x. I really need something to care of the frequent application crashes."

Auto-text mix up.

Anyway what I wanted to say is that this is absolutely awesome news. Bitfrost has some excellent design goals. The more this can be rolled into Mac OS X the better.

May 14 2009 at 3:23 AM Report abuse rate up rate down Reply
PFar

I hope this is a pre-cursor to iPhone firmware 2.x. I really need something to care of the frequent application crashes.

May 14 2009 at 3:20 AM Report abuse rate up rate down Reply
Daniel Brusilovsky

This was actually announced almost one year ago according to Krstics's blog...

May 14 2009 at 1:14 AM Report abuse rate up rate down Reply
1 reply to Daniel Brusilovsky's comment
Ed

That's not what he says...

"About a year ago, I left One Laptop per Child and decided to find a new adventure. [...] Today was my first day on the job, and I couldn’t be more thrilled."

Posted on Monday...

May 14 2009 at 3:19 AM Report abuse rate up rate down Reply
xaco

True cloud computing solutions?
Zapper of the term "security"?

That would be fun.

May 14 2009 at 12:27 AM Report abuse rate up rate down Reply
Ariel

Hopefully by Mac OS X v10.7 this guy's work will finally silence those die-hard PC fans who say that Mac is not secure.

May 13 2009 at 11:41 PM Report abuse rate up rate down Reply
1 reply to Ariel's comment
brian

i agree with you 100%

May 13 2009 at 11:56 PM Report abuse rate up rate down Reply
Zach Jones

TBH I am happy to hear this. Security is #1.

May 13 2009 at 10:46 PM Report abuse rate up rate down Reply
Buy an ad here

Hot Apps on TUAW

Tweets

© 2012 AOL Inc. All Rights Reserved.