Apple has released Security Update 2014-002 with security fixes for OS X 10.9 Mavericks, as well as for those still using 10.8 Mountain Lion, 10.7 Lion, and 10.7 Lion Server. According to the release notes, the security update patches a vulnerability with HTTP headers that enabled attackers to obtain Web site credentials, which affected all three versions of OS X. It also fixes a particularly ugly vulnerability to a “triple handshake” attack that could affect both Mavericks and Mountain Lion. However, the bulk of the changes focus on Mavericks, addressing vulnerabilities with CoreServicesUIAgent Web site validation, Heimdal Kerberos authentication, ImageIO’s handling of JPEG images, and a power management issue that could prevent the system from going to sleep and keep the screen unlocked. (All updates are free. For 10.9 Mavericks, 80.5 MB; for 10.8 Mountain Lion, 135.9 MB; for 10.7 Lion, 126.9 MB; for 10.7 Lion Server, 177.2 MB.)
Always Show Recipient In iChat
In iChat under Snow Leopard, choosing View > Always Show Recipient Bar puts a buddy's status message and color at the top of any iChat window. It can also be used to select among multiple open iChat logins you have to send a message to that buddy, or to select among multiple accounts you have registered in Address Book for that buddy.
Security Update 2014-002 (Mavericks, Mountain Lion, and Lion)
Automatic’s connected car adapter with iPhone apps on
Automatic’s platform, drivers are able to drive safer and smarter.
TidBITS readers get 20% off all orders at <http://automatic.com/tb>