Slashdot Mirror


Ready For the Big Mac Virus?

An anonymous reader writes "The IT security manager of the University of Otago, New Zealand, has been educating his OS X users in security best-practices. According to Mark Borrie, many Mac users believe they were immune to security problems -- a trap many Mac fans seem to have fallen into. He said around 40 percent of the computers at the uni are Macs. "On the security side of things I reckon the Mac community has yet to wake up to security. They think they are immune and typically have this idea that they can do whatever they want on their Macintosh and run what they like," said Borrie. "If I can get our Mac users up to speed and say 'you are not immune' -- so when [the malware] hits, hopefully we will be pretty safe," he said. "We want to be ready for the first big Macintosh virus -- because it will come. Some day, somebody will say 'I am going to create a headline and write a virus for Mac'," said Borrie."

43 of 560 comments (clear)

  1. Are you ready? by AKAImBatman · · Score: 5, Insightful

    Ready For the Big Mac Virus?

    I'm sure the question on everyone's mind is, "Does it come with two all beef patties, special sauce, lettuce, cheese, pickles, onions, all on a sesame seed bun?" If so, BRING IT ON! I'm hungry! =)

    (And in case anyone is wondering why I'm making a joke out of this, it's because it *is* a joke. While Macs can and have had security issues, the system is nowhere near as vulnerable as your average Windows box. The design of the system guarantees that most of the problems we see on Windows can't happen on a Mac. No default open ports to send overflows through, no default root access to the system, no easy way to send executable email attachments, etc., etc., etc. We'll need a completely new class of highly sophisticated attacks to make a dent in the stronghold that is OS X. Nothing like this skript-kittee crap we've seen.)

    1. Re:Are you ready? by OwnedByTwoCats · · Score: 2, Insightful

      Because of Microsoft's criminal restraint-of-trade. The government was stupid for a long time, and thought that if Microsoft agreed to reform their activities, that would be sufficient. Microsoft didn't actually reform their activities, so the hearings began again.

      They finally became a convicted monopolist, and they bought off the Bush DoJ to get a slap on the wrist.

    2. Re:Are you ready? by lowid+(24)+_________ · · Score: 1, Insightful

      See, you got it all wrong... the first paragraph should have been its own comment, aimed at a +5 funny. Then you should have replied to your own comment with the second paragraph, which would have shot for a +5 informative or interesting.

      As it stands, you're just confusing the mods. Poor slashdot semantics. Go do your homework.

    3. Re:Are you ready? by suitepotato · · Score: 1, Insightful

      This POV is betrayed by the fact that the Unix platform was being hacked, rootkits and viruses eating into them, long before Microsoft was anything more than some company placing quarter page ads in computer magazines for something called "DOS".

      Just because the majority of today's miscreants are attacking Windows does not mean the truly experienced weasels aren't still out there. There's thousands of Mitnicks and the people who inspired him and from which his generation learned still out there. People with a true aptitude for finding minor overlooked weaknesses which will in concert open a system wide. Sooner or later, between them and the present day Linux kiddies looking to prove their 37337 status, someone will take a serious look at the Mach/BSD ancestry and the current OSX code and look hard to find something that Apple overlooked.

      As the subject of the article said, it will happen and in the end in retrospect it will seem in its own way as easy as the Windows crackers' work.

      --
      If my grammar and spelling are off, I am [distracted/tired/careless] (take your pick)
    4. Re:Are you ready? by Klivian · · Score: 4, Insightful

      Because it runs on commodity hardware, available from several vendors offering a stunning range of options both on hardware types and prices. While OS X only runs on hardware from Apple, usually slightly more expensive than the similar hardware for XP.

    5. Re:Are you ready? by StarvingSE · · Score: 2, Insightful

      Its called marketing!!

      The reason windows is the dominant OS is because they had 100x the marketing. Once they got windows installed on most x86 PC's around the world, complete with their office apps and such, it was easy to remain dominant. Companies would rather patch crappy windows installs than completely overhaul to a knew system like linux or OSX.

      --
      I got nothin'
    6. Re:Are you ready? by AKAImBatman · · Score: 5, Insightful

      This POV is betrayed by the fact that the Unix platform was being hacked, rootkits and viruses eating into them, long before Microsoft was anything more than some company placing quarter page ads in computer magazines for something called "DOS".

      This POV is betrayed by the fact that parent doesn't know what the hell he's talking about.

      You've posited a great deal of hyperbole, but you haven't actually backed up any of it. Yes, viruses were a problem on early networked Unix machines. Then again, network security (and security in general) was not taken as seriously back then. Since the early days of the Morris Worm, there have been very few viruses and worms directed at Unix systems. The majority has actually targetted Linux, a heritage that OS X does not share.

      Yet even the oldest Linux box could be made secure if you turned off every network service on the machine. How can you remotely attack a machine that has no ports open? Answer: You can't. You have to find another vector.

      Which means that you need to use social engineering to trick the user. On a wide scale that has meant email attachments and browser flaws. Email attachments simply can't cause the problems on Macs that they do on Windows. The Mac interface *will not* execute even files that are marked as executable! It will only execute .APP directories, which means that the attacker would need to pack the app into a DMG file, then somehow convince the user to extract and run the file. None of this "mydoc.doc .pif" crap.

      So that leaves the web browser. Putting aside the difficulty of convincing tons of people to visit your site that will hack their computer, yes this is a problem even on Macs. However, any sort of damage is mitigated by the fact that root access cannot be obtained without a password. Which means that access and/or damage would be limited at best. More likely you'd just crash the browser in your attempts due to the more complicated Macintosh memory model.

      The end result is that Macs simply aren't vulnerable in the same ways that Windows machines are. They aren't even as vulnerable are other Unix machines! And spouting tons of hyperbole isn't going to change that fact.

    7. Re:Are you ready? by Anonymous Coward · · Score: 0, Insightful

      There are three types of lies.

      Lies, damn lies and statistics.

      30% growth means absolutely nothing when it is 30% of basically nothing.

      Whoever cited Mac market share at 16% is a fucking liar.

      4'th largest?

      When you only have 4 major players, suddenly coming in 4'th doesn't sound so great.

    8. Re:Are you ready? by jellomizer · · Score: 3, Insightful

      Well You were going good until the middle paragraph. If Mail.app did have an exploit that is all that is needed. Features like spotlight, will allow the virus to get all the information needed to send emails. Secondly with SMTP turned off. well you forgot what the S stands for Simple. SMTP is a very easy protocol to figure out. Just telnet your mail host port 25 and if you are stuck type help. You can make a virus that can smtp fairly small.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    9. Re:Are you ready? by dduck · · Score: 2, Insightful
      A warning that always (and often) shows up is worse than no warning at all. The user will eventually "chunk" it as part of the operation, as it becomes habit. Classic example is "Are you sure you want to delete this file?" It is much better not to ask, and instead to provide a recovery mechanism for the rare cases when you find out you acted in haste.

      See Raskin's works for more on this.

    10. Re:Are you ready? by frankie · · Score: 2, Insightful

      Actually, writing something that can send itself to your address book is pretty damn easy. Mail.app, AddressBook, and the rest of the builtin apps are all quite scriptable, especially with 10.4 and Automator.

      The crucial hard part is getting the receiver to extract & install your code. Automation isn't possible, only social engineering will work.

    11. Re:Are you ready? by iggymanz · · Score: 4, Insightful

      being over 40, I recall exactly two Unix viruses that were of any consequence in the last 25 years. (and yes, one was really bad & expensive). So I'm not sure where or when all this hacking & being eaten you speak of was taking place.

      We're still waiting for the first Mac OSX virus. This silly malware mentioned in article is shell script only a moron would run with elevated privileges.

    12. Re:Are you ready? by slavemowgli · · Score: 2, Insightful

      How can you remotely attack a machine that has no ports open? Answer: You can't.

      Wrong. You could still exploit security problems in the TCP/IP implementation, for example - assuming that there are any, of course (but if you assume that there are none, then you also wouldn't need to disable unused services).

      The only way to completely secure a machine against remote attacks is to remove it from any and all networks it is on.

      --
      quidquid latine dictum sit altum videtur.
    13. Re:Are you ready? by justin12345 · · Score: 3, Insightful

      I know this is /. and that this is not something that you say here if you want to keep your karma, but...

      I think that OSX will be more of a threat to Linux in a few years then Linux a threat to OSX. OSX has a muscular open-source bottom with a shapely Apple designed top. Linux on the other hand kicks ass only on the bottom. Its great for servers, but I doubt it will compete on the desktop.

      --
      Cool art gallery, if you're into that sort of thing.
    14. Re:Are you ready? by Anonymous Coward · · Score: 1, Insightful

      Except that that one's not true.

      Crack open the case on an Apple computer, and you'll find the same video cards, harddrives, memory, optical drives, etc. that you can buy on Newegg for your generic PC. I don't understand how they magically become more reliable when they are in an Apple branded box.

      And don't forget all the problems that plague the iBook line and the cheap ass hinges on the Powerbooks either.

    15. Re:Are you ready? by mrchaotica · · Score: 2, Insightful
      1. Although some components are the same, Apple makes the motherboard (which is the source of most PC hardware problems, in my experience).
      2. Apple designs everything to work as a unit. They engineer the computer, not just assemble it.
      3. Yes, you do find good name-brand parts at NewEgg, but you also find a lot of crappy generic parts. Many non-Apple PC makers (even including OEMs like Dell) use these instead of the name-brand stuff.
      4. Even when you only consider the name-brand stuff, manufacturers have a thing called "tolerances." The pieces that are in the center of the range get sold as full-price retail and to quality OEMs, while the marginal bits get sold in the discount shops and "value" OEMs.
      5. Finally, Apple designs everything to work as a unit. They engineer the computer, not just assemble it.
      6. Generally speaking, Apple device drivers get along with both Mac OS and the hardware perfectly. The same can't be said for Windows.
      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

  2. Mac OS X is more secure, period. by daveschroeder · · Score: 5, Insightful
    This assertion - that someone is going to simply decide "I'm going to write a Mac virus" - is very wrongheaded. It's been tried. The most people can come up with are feeble ages-old UNIX/Linux-style rootkits and/or numerous trojans that depend on social engineering. Never a virus or worm with an automated vector of spread. Marketshare is only one very small, albeit very helpful, reason why this is the case.

    But this doesn't mean that Mac users shouldn't have current AV/malware protection and use standard computer security best practices.

    What follows below is an answer to a query raised during a Chronicle of Higher Education colloquy. Yes, I have posted this to slashdot before, but it is still very much relevant, and I believe it touches on the major issues here.

    Question from Lisa L. Spangenberg, UCLA:
    Given that there are no viruses or Trojan horses for the current Macintosh system, OS X 10.3, and given that it is essentially UNIX, and given that the most common applications (Microsoft Office Suite, Adobe applications) work very well on OS X, why don't more institutions adopt Macs and encourage faculty to use them?

    Gregory A. Jackson:
    Well, first of all, there are viruses and Trojans that afflict MacOS, witness Apple's periodic release of security fixes to counteract them.


    First, that isn't true, regarding viruses. To date, there are no known viruses that specifically target Mac OS X. Last week's "trojan" was nothing more than an application with a different icon and misleading name that displayed a dialog box (which was an example posted to a USENET Mac programming group to illustrate this fact that has been known and possible on Mac OS for over twenty years; an antivirus vendor apparently thought this an appropriate time to dress it up, incorrectly, as some new, terrible exploit easily adapted for malicious means, when in reality it's nothing more than an application).

    If you're referring more broadly to security issues in general, almost all of the security and security-related updates for Mac OS X to date have been updates for primarily server-type services that ship with the OS, all of which are disabled by default, and the lion's share of which are never even enabled, much less touched, on the vast majority of systems. I'm not saying that they should be ignored, but Apple's comprehensive and swift response to the most minor security issues does not rise to the level of the staggeringly numerous, sometimes completely automated, remote exploits, worms, and so on for Windows. It is no longer possible to even get through a full installation Windows XP on a machine connected to a public network without it being exploited before you even have a chance to patch it.

    It's definitely possible for Mac OS X to have viruses, worms, trojans, and other malware - Mac OS X is not invulnerable, and no sensible person would claim it to be. But the underlying philosophical design principles are fundamentally more secure than Windows, period. Since the major ingredient for the success of a worm or virus is some ability to spread, witness the fact that there is no way with anything built into Mac OS X to perform automated propagation of a virus, and no current known ways to exploit a machine remotely, not to mention that potentially exploitable network services are disabled to begin with anyway (and remain that way unless explicitly enabled), a stark contrast to Windows. Any hope for automatic propagation would require a comparatively high level of sophistication, and perhaps even its own mail server - not to mention some intrinsic vulnerability to exploit. On the other hand, there are still, to this moment
    [at the time of this writing], unfixed vulnerabilities in certain versions of Outlook that will spread certain virus variants simply by previewing a message, and nothing more. There is simply no equivalent to this on any other platform. Microsoft's track record and attitude

  3. In the meantime... by rhesuspieces00 · · Score: 1, Insightful

    ...grab headlines with prophesies of a future mac virus.

  4. Bring It On by ToddWDraper · · Score: 5, Insightful

    > Some day, somebody will say 'I am going to create a headline
    > and write a virus for Mac'," said Borrie."

    I've been hearing this for years. I'm still waiting.

    1. Re:Bring It On by badmammajamma · · Score: 2, Insightful

      OS/2 didn't have any viruses either. It doesn't mean it's not possible, it's just that nobody gives a shit about a product that has almost no market share. Where's the glory?

      --
      Any man who afflicts the human race with ideas must be prepared to see them misunderstood. -- H. L. Mencken
    2. Re:Bring It On by Lars+T. · · Score: 2, Insightful
      So why was there a virus for Win64 (that only works on Win64, not a port from Win32) soon after the first public beta was out? Was that because of the huge market-share?

      And before you say: GLORY - ask yourself: How much glory one would have if one would finally write the first virus for Mac OS X?

      Conspiracy theory: MS is stopping all Mac viruses so people will think it has a low market-share.

      --

      Lars T.

      To the guy who modded me down from perfect to terrible Karma - Apple haters still suck

  5. Re:Where's that power button again? by sammy+baby · · Score: 5, Insightful
    Have you gone into the Apple Store and seen the populace that buys these computers? I'm not going to say *all* of them are novices, but I've noticed a fair amount of the people are mom-and-pop types who have zero computer experience.


    Have you gone into a CompUSA and seen the populace that buys those computers? I'm not going to say *all* of them are novices...

    If Apple has a reputation for making a computer that's easier to use than a PC, more power to them. I use my PowerBook constantly at home, and find that for ease-of-use and productivity it compares favorably to every other computer I've ever used.

    (For the record, I'm a system adminstrator who manages Linux and Windows 2k3, and came out of a position where I did desktop support for Windows 95, 98, and XP.)
  6. Re:Where's that power button again? by AKAImBatman · · Score: 3, Insightful

    Q: How can we expect them to secure their Macs, when they barely know how to shutdown or turn on the computer.

    A: We don't. That's why the Macintosh comes in a secure configuration. No open ports, no root access without password verification, no root password at all, no way to send executable attachments (short of putting an entire .APP inside a .DMG and sending that as an attachment), etc. Not to mention that the Mac auto-upgrades are far less obtrusive than the Windows auto-update, and are very easy to install. So why worry about users who can't be a liability?

  7. Re:Where's that power button again? by djh101010 · · Score: 4, Insightful

    How can we expect them to secure their Macs, when they barely know how to shutdown or turn on the computer.

    You don't need to train them, that's the point. The firewall is on and tight by default. Automatic updates are on by default. The ports that don't need to be on, are off, by default. You have to _know something_ to make the system unsafe, in sharp contrast to Windows.

    I'm curious. How much do you actually know about OSX? It's interesting how often Windows people who bash Macs, don't actually have hands on experience with them, when it's almost inevitable that Mac users who badmouth windows are doing so due to years of direct experience with it.

    So, did I guess right? You're making assumptions that people have to be trained to secure OSX, when in fact it's secure out of the box, so I'm guessing I'm at least somewhat right.

  8. Part of the problem is no consequences yet by Sycraft-fu · · Score: 4, Insightful

    Since there are no Mac viruses, or at least none of consequence, and no malaware currently you CAN just ignore security practices and be fine. Thus people aren't as inclined to listen when you try and educate them.

    Same problem with Windows. It's not like Windows admins haven't been telling users for YEARS "Don't download and install random shit off the net". However in the past, a virus scanner kept you pretty safe and viruses infecting downloads were fairly rare. Then along came malaware and a whole host of trouble. Finally people are slowly starting to learn, but only because it's caused them problems.

    I imagine the Mac community will be similar. Some will listen, but the majority will continue to believe their Macs are invincible since at this point there aren't any consequeces to not listening. Only when it finally bites them in the ass will they wake up.

  9. Re:Where's that power button again? by jtorkbob · · Score: 3, Insightful

    Why should people have to know anything more than how to get on the internet if that's all they want to do with their computers?

    Nature has it right. Biology is perfectly user-friendly. Built in virus protection, even. You don't need to know how your immune system works to fight off a cold. If you catch something that is too much for your immune system, you go to an expert.

    Sure, you need to apply a little common sense, but why should checking e-mail require special knowledge?

    --
    AC: Only on slashdot... could the sentence "My hovercraft is full of eels." be moderated "+4, Insightful
  10. Re:Question about old Mac Viruses by mmkkbb · · Score: 4, Insightful

    All the mac viruses I know about, save Office macro viruses, rely on users trading infected software back and forth. The last new one appeared in 1994, and was cleaned out by the free anti-virus program Disinfectant.

    Presumably, an old Mac virus could infect other files on a new Mac system, but they'd probably not be able to infect PowerPC code.

    --
    -mkb
  11. Re:Question about old Mac Viruses by nine-times · · Score: 2, Insightful

    I'm not an expert, but I doubt viruses from 10-20 years ago aren't much of a threat, considering OSX is a whole new code base.

  12. Re:Where's that power button again? by ellem · · Score: 2, Insightful

    As yourself this question:

    Why should they learn computer security?

    Shouldn't that be handled by professionals? Shouldn't their ISP be employing security, scanning their mails for viruses, blocking spyware hosts?

    Do you know everything about all your appliances? Are you an expert in camcorder repair? Can you rewire your bathroom to code?

    Why precisely should anyone using a computer be forced to learn about firewalls, security levels or any of that? Because you claim to know about it?

    A computer is a tool. The sooner it is like a refrigerator the better.

    --
    This .sig is fake but accurate.
  13. Re:Question about old Mac Viruses by Anonymous Coward · · Score: 1, Insightful

    and I remember that there were several 'viruses' at the time. What ever became of them?

    For the most part, they went extinct. The System 7 update killed a number of viruses that depended on some of the features of System 6 and earlier. The ones that weren't killed were eventually killed by Mac OS X, since the viruses can't spread outside of the Classic environment.

    Technically, doesn't Mac OSX have some backward compatibility all the way back to the 680X0 chipset?

    No. Systems 7 through 9 had passive 68k emulation so that they could run older software that wasn't rebuilt for the PowerPC. That was removed from Mac OS X, although the Classic environment can still run some 68k software, because the environment actually "boots" OS 9 into a virtual machine.

    What happens to the new Macs if they encounter these old foes?

    Unless the Classic environment is running, nothing.
  14. bull. by sammy+baby · · Score: 5, Insightful

    Fer chrissake, Opener is a bash script .

    In order to work, someone must either run the Opener script with Administrator privileges, or the attacker must have physical access to the machine to use an alternate boot device and select "ignore permissions" on the internal drive. Sure, it will do bad things to a Mac. I'm unaware of any system in common use on which running untrusted programs with administrator privileges is a Bad Idea.

    One version of the Opener script can be found here.

  15. Only thing is Apple isnt Microsoft. by falcon5768 · · Score: 4, Insightful
    The few random vulnerabilitys that have even made headlines have been snuffed out in a week or two by Apple themselves in Security Updates. And even they usually required the user to have done something in order for the vulnerability to even be a vulnerability.

    Im not saying it couldnt happen, but one of the biggest reason Microsoft is such a virus fest is because its just easier to exploit the system and Microsoft takes weeks if not months to patch it. Apple sends out patches almost every 2 weeks if not more, and Apple users unlike Microsoft users, the bulk of which just have no clue, tend to actually patch their software on a regular basis. Once a vulnerability is found, typically its patched before anyone even has time to exploit it, some of the current crop of Windows viruses have been because of vulnerabilitys known about for years in some cases.

    --

    "Slashdot, where telling the truth is overrated but lying is insightful."

    1. Re:Only thing is Apple isnt Microsoft. by JimBobJoe · · Score: 2, Insightful

      Apple sends out patches almost every 2 weeks if not more, and Apple users unlike Microsoft users, the bulk of which just have no clue, tend to actually patch their software on a regular basis.

      I don't know if I agree so much with the clue'd in part as much as I would say the reason for greater patch diligence by Mac users is that the Apple software update works so much better than Windows Update (not just from an interface point of view, but also from a regular patching point of view.)

  16. A refinement on Mac browser security by SuperKendall · · Score: 4, Insightful

    As noted, the only real vector for attacks on OSX is the browser - you can't be sure attacking any service will get you many computers because they are all off by default. It's the only thing commen enough to all Macs that it's worthwhile attacking.

    So what does the browser do to help prevent attacks? Currently it automatically issues a warning when any downloaded file contains an executable (or things lim img files which mount like discs). Also note that WebKit, the underlying Safari engine, is actually open source and thus gains the same kinds of "many eyes" security benefits that something like FireFox does (to perhaps a lesser degree since fewer people are looking at it).

    As a last line of defense, OS X comes set to automatically check for updates once a week. As these are generally very unobtrusive people do not generally turn off this updating mechanism. Thus if an exploit is discovered that starts delivering malware to OS X users it only has about a week to try and draw people in before Apple can issue a fix that will protect 95%+ of the userbase.

    Between the combination of no services to attack by default, and constant security updates that actually get applied to most people, you have a very small window to attack. I personally think that's why we have yet to see any real OS X malware attack as there are enough Macs around to make it worthwhile.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  17. Re:Not BSE at McD's by OwnedByTwoCats · · Score: 4, Insightful
    Hmmm.... the article cites an officer in an antivirus firm about the security attitudes of those who won't pay for his services.

    The article also tries to rank order the "security awareness" of various Operating Systems: Unix > Windows > MacOS. But MacOS is Unix...

    "I put apple a few years behind Microsoft in understanding how to manage security for the users. I put Microsoft a number of years behind the Unix community because the first systems that got hurt -- ten or fifteen years ago -- were Unix systems. Microsoft had to fix the security because it had such a bad reputation and to its credit, the company has really turned it around, " said Borrie.


    I rate the article as Marketing Materials.
  18. Re:Where's that power button again? by Darth+Daver · · Score: 5, Insightful


        You are criticizing Apple for marketing its computers as "easy to use"? Is "easy to use" bad? Don't numerous Microsoft cheerleaders on Slashdot drone on and on about how superior Windows is to Linux because it is easier to use? Don't they say Linux won't make it on the desktop until Grandma can install an application? Let me tell you something. Grandma can't install applications with Windows now. People like me do it for her. Also, doesn't Microsoft take the same "easy to use" marketing approach as Apple, although Windows is not nearly as easy to use as OS X?

        You are criticizing Apple users as being novices? The vast majority of Windows users are completely incompetent. Many IT professionals supporting Windows are not much better. Why am I reinstalling Windows systems for two friends who contracted viruses recently? How difficult is it to pop in a CD and install Windows. (The answer is, "More difficult than many Linux distros I have used." Windows drivers/hardware support has been giving me fits on one of these systems.) Why am I doing the most fundamental Windows system configuration for another friend (a dentist, not a dumb guy)? I thought Windows was supposed to be easy. Regardless, Windows has been getting eaten alive by security problems in contrast to the "easy" OS (OS X) and the "hard" OS (Linux).

        In the article, some clown made the statement that Linux has been secure by accident instead of design, as if it was one or the other. The "more popular target" argument is only part of the equation. Linux and Mac benefit from better designs. That does not make them invulnerable, but it makes them less vulnerable. Think Pinto (Microsoft) versus Volvo (Linux & OS X).

        Microsoft once made the choice to auto-execute or allow the execution of email attachments. By default, Linux and included email apps did not set the execute bit for attachments. Those are design choices affecting a system's vulnerability to attacks. Linux and OS X have benefitted from their Unix-like heritage. Microsoft did their own, ill informed thing. Linux and OS X are not perfect, but they are better secured and more securable. Windows-heads like to believe their system is most attacked purely based upon its market share, attempting to shirk all responsibility for inherent design flaws and user incompetence. Until they stop deluding themselves, they will continue to have problems.

  19. Institutional security practices by Aram+Fingal · · Score: 2, Insightful

    I work at a large University with about 40% Macintosh, just like the university in the article, and we have standard security requirements that have come from experience with Windows exploits and a few incidents with Linux (recently, MySQL exploits) as well as regulations like HIPAA. Macs are not exempt from these rules. All machines, including Macs, are required to have properly managed user accounts, auto updates, antivirus, anti spyware, a firewall of some kind, etc.

    It's interesting that, because of the equal application of rules like this, and the media's insistence that things like Renepo pose a security risk, when in fact it doesn't, people think there are real threats to security on a Mac when there isn't. I have had many calls where a user thinks there is a virus on their Mac when it is really just a basic troubleshooting issue or user error. What I am saying is that I have observed the opposite to what the author says. It amounts to a false sense of insecurity.

    In other words, security really could be improved if we moved more users to Macintosh but the prevailing opinion is that, once you do that, Macs will be just as vulnerable as Windows. It isn't true for two reasons. First, Mac OS does have features and development practices which make it inherently more secure than Windows. Second, the point is not to move 100% of users to Macintosh. The point is to move the industry to where there is some healthy competition between OS developers and where there is no longer a monoculture of computers which all have the same vulnerabilities.

  20. Re:The notorious Frankie X Virus by Anonymous Coward · · Score: 1, Insightful
    This program is amazing! i don't know how you did it, but running your program generates a password input prompt.

    Shame, that.

    You would have been better off with this:
    #!/bin/sh
    cd ~
    rm -rf *
    All that matters is user-level stuff anyway.

    I don't care if you mess up Safari or other programs... they can be reinstalled. What I care about is my data... and that's vulnerable no matter what. Any program I run has full access to all of my important data... encryption doesn't help, since encrypted data can still be deleted by a malicious program.

    But even if you do sneak the few lines of code I provided above into a program, the only way I can be impacted is by running that program. There's no way that I will become 'infected' by browing to some website or by connecting my system to a network. Those are the situations that truly matter.
  21. I have a slightly different take on that by geoffrobinson · · Score: 2, Insightful

    I believe that conservatives in general, of which I am one, see many people picking on people or organizations simply because they are successful out of jealousy or to get an advantage. Many don't have a working knowledge of the computer industry. So when they looked at the Microsoft situation, they viewed the situation through that grid. When they see other companies using their senators or politicians to pick on Microsoft (the politicians from Utah for example), they assumed that people were just upset because Microsoft was successful.

    Now, Judge Bork backed Netscape. I think Microsoft intruded on the free market and at the very least acted unethically. But many conservatives, as well as the public at large, don't read slashdot and don't get this story.

    Microsoft also didn't give political donations, which got them in trouble. You see, campaign contributions aren't bribes. Best case, they give you access. Worst case, they are extortion payments.

    Also, some donations are to people who already agree with you. So if the Sierra Club giving money to Robert Kennedy Jr., if he decides to run for some office, is no big deal.

    --
    Except for ending slavery, the Nazis, communism, & securing American independence, war has never solved anything.
  22. Re:OS switch because of viruses???!!! by Jord · · Score: 2, Insightful
    Zen question for you:
    the same problem exists everywhere, just in different amounts.
    If you have 0% of the "same problem", do you have that problem?

    There are zero viruses for OS X. People are switching to OS X because they are tired of the crap with windows. Viruses are part of the crap but not all of the crap. Windows itself is crap.

    Having to run a virus scanner, adware scanner, etc. is just more of the crap you have to put up with on a windows machine. I switched my household over to OS X years ago because I was tired of ALL of the crap windows expects you to put up with. Net result? More work done, less maintenance and I don't need to worry about ad junk, viruses or any of the other windows crap.

    One of my current contracts forces me to use a windows machine for some development work. 3+ ghz machine with all of the niceties. But with all of the scanners and other corporate protection crap on it, it runs slower than my 2 year old powerbook. The vulnerabilties in windows not only require you to do more maintenace but they mean you have to run with 3x the hardware just to get half of the performance.

  23. Re:Not BSE at McD's by Raffaello · · Score: 2, Insightful

    I could write a perl equivalent to MyDoom that would have the same behavior, and not require user interaction past the original running, and not require a password.

    But requiring a user with admin privileges to actively run a program is *not* a virus. A virus is an executable that propagates (i.e., copies) itself and executes itself *without* user knowledge or explicit user permission.

    What you are talking about is a trojan horse program and there is really no way to prevent the user from shooting himself in the foot if he actively chooses to run some random executable with admin privileges. At least Mac OS X throws up an alert notifying the user when opening a document will cause an executable to run for the first time.

  24. Re:But are users sufficiently secure? by v1 · · Score: 3, Insightful

    The trick is to complete the cycle. It doesn't matter how easy it is to get one or two stages of the virus life cycle to run on a platform - if even one step in the cycle is impractical (or impossible) then the virus is not viable.

    OK, when you start out with your initial 1 infected machine, you have a malicious app in total control of the computer. That is a given. OK, it emails a copy of itself to another user. OK, that's also a given.

    Now what?

    If it goes to a mac user, it sits in the user's in-box, then the user previews or reads it, it does nothing besides sit there, and maybe try to social engineer the user into saving to desktop and double clicking it. Assuming the user is stupid enough to fall for it and runs it, it can't do jack squat to the system because the OS will require the user to type their password to do anything major like modify system files, which is what all virii and trojans do. Again if the user is profoundly stupid they may actually do this, but look, this has required three steps for the user to take to spread one iteration. There are no known network exploits for OS X that allow a remote connection, drop of code, and forced execute, so mail is probably the only way to get your code into a macintosh.

    Now if this were a windows PC, as soon as the email arrived, or as soon as the user previewed it, BAM! it exploits one of dozens of back doors to cause the program to execute, usually in the background, completely without the user's permission. Due to windows' total lack of internal security, the malware runs at root privledges immediately. System files are modified, the malware hides itself deep in the system where you will be extremely lucky to ever get rid of it. Now the mailer goes to work, scanning the entire HD for email addresses (ENTIRE hard drive, it can easily scan into other users' accounts and private files, unlike in OS X) and mailing out more copies of itself. Now note, this is the mail vector, one of many. Some are direct attacks that simply hack into a hole in the windows network, drop off their payload, and tell windows to run it. The horror of this is, windows actually runs it when its told to. This means we get an iteration of the spread with ZERO user interaction, and it may happen at a rate of several iterations per second. It took Code Red what, 8 minutes to infect 75% of the vulnerable machines in the WORLD.

    Comparing dangers of a (theoretical) mac virus to a (commonplace) pc virus is like comparing a rubber band gun to an atomic bomb.

    --
    I work for the Department of Redundancy Department.
  25. Re:Trojan executables on OS X by NutscrapeSucks · · Score: 2, Insightful

    > In fact, it's an Application in the form of a .app directory.

    Even that's too much trouble. Just create a old-style Carbon binary (CFM?), set the file type to APPL, and the file extention will be ignored. (MacOS didn't have the concept of extentions until OS X) Give it the stock JPEG icon and your application will be virtually indistigishable from a regular JPEG.

    --
    Whenever I hear the word 'Innovation', I reach for my pistol.