Slashdot Mirror


iPods Come Complete With Windows Virus

kaufmanmoore writes "Cnet is reporting that some video Ipods made after September 12th have the RavMonE virus loaded onto it. In Apple's announcement they take a swipe at Windows security and encourage Windows users to install anti virus applications."

43 of 672 comments (clear)

  1. Just goes to show. by Ayanami+Rei · · Score: 5, Insightful

    Apple's products are made (and to some degree, designed) in China just like everybody else's. I wonder how many other memory products (that is, USB mass storage devices) have similar issues.

    --
    THIS THING CAN TURN ON A DIME, MACROSSZERO STYLE ALSO FUCK BETA, ~NYORON
  2. Uhh, What? by aweraw · · Score: 5, Insightful

    I'm not one to try and defend Windows security with a straight face, but this is apples fault for shipping infected ipods. They failed to protect their customers, regardless of windows lack-lustre security

    --
    5468652047616D65
    1. Re:Uhh, What? by linuxmop · · Score: 4, Funny

      Infected is right. These iPods are Apple's smallpox blankets to Microsoft's American Indians.

    2. Re:Uhh, What? by Pharmboy · · Score: 4, Insightful

      Nice example. And Apple is laying partial blame on the Indians for not having an immune system capable of fending off smallpox.

      --
      Tequila: It's not just for breakfast anymore!
  3. Windows Security? by AvitarX · · Score: 4, Insightful

    If I just distributed a device with a virus on it I would not be throwing stones at the security practices of another company.

    --
    Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
  4. Trying to push the blame to Microsoft by Duk · · Score: 4, Insightful
    From the site (emphasis mine):
    As you might imagine, we are upset at Windows for not being more hardy against such viruses, and even more upset with ourselves for not catching it.

    Wow...trying to deflect some of the blame, huh?

    --
    -Hey! Whatcha lookin' at fool? -The Duk
    1. Re:Trying to push the blame to Microsoft by Skippy_kangaroo · · Score: 5, Insightful
      From the site (emphasis mine):

      As you might imagine, we are upset at Windows for not being more hardy against such viruses, and even more upset with ourselves for not catching it.


      Hardly a whitewash.

  5. secret weapon by wardk · · Score: 4, Insightful

    and this is why in the long run, apple wins? Simply because MS can't do anything like this back to Apple.

    those apple people are genius'

  6. Also shows... by Anonymous Coward · · Score: 5, Insightful

    The class of Apple to complain about Windows being susceptible to viruses that Apple Quality Control fails to catch. Maybe Apple QC should install AV as well when they develop for windows?

    1. Re:Also shows... by udderly · · Score: 5, Insightful

      Why is this a troll? I'm a serious Mac fan, but that little "jab at Microsoft" *was* pretty classless.

      WARNING: OBLIGATORY CAR ANALOGY!!!
      When I was a kid we were firing a golf ball out of homemade cannon and broke the neighbor's windshield. Crap, what was I thinking? I should have blamed Ford for not making their windshields stronger!

    2. Re:Also shows... by CaymanIslandCarpedie · · Score: 4, Funny

      But then they'd get sued by security vendors for ruining thier market.

      --
      "reality has a well-known liberal bias" - Steven Colbert
    3. Re:Also shows... by Anonymous Coward · · Score: 5, Informative
      "Maybe Apple QC should install AV as well when they develop for windows?"

      I heard (from a reliable source inside Apple) that the virus was preinstalled from the disk manufacturer when they formatted the drives. *shudder* You can see where this can go.

    4. Re:Also shows... by billsoxs · · Score: 4, Funny
      You overestimate the harmlessness of Readme files.

      Yes except you need to READ the readme files for them to be an issue.

      --
      This message was brought to you by "Lack of Sleep."
    5. Re:Also shows... by jcr · · Score: 4, Insightful

      The problem happened, because Apple's assembly contractors used Windows machines in their production process. Clearly, this is not a wise choice from a security standpoint, and I would expect Apple to insist on replacing those machines with Macs or Linux hosts.

      -jcr

      --
      The only title of honor that a tyrant can grant is "Enemy of the State."
    6. Re:Also shows... by Trillan · · Score: 4, Insightful

      If it really did come on just a few of the blank hard drives, in order to catch this with testing they'd have to test every single freshly formatted drive. Granted, I'm sure they'll do that now, but not doing a virus scan on freshly formatted disks hardly qualifies as "no testing."

    7. Re:Also shows... by Trillan · · Score: 4, Insightful

      Honestly, it probably should be an embedded system (running Linux, if you like) without a GUI or any other possible way for people on the line to wreck it.

    8. Re:Also shows... by fatphil · · Score: 4, Informative

      That's not how manufacturing works at all in the real world. Most initialisation of such devices is done using Windows machines.

      However, they shouldn't be writing files to a filesystem to initialise the devices, they should be writing a version-controlled quality-controlled filesystem itself. And there's no point blaming the Chinese contractor, I'm sure they were just following the Apple procedure, sloppy as it is.

      --
      Also FatPhil on SoylentNews, id 863
    9. Re:Also shows... by NixLuver · · Score: 5, Insightful

      "And there's no point blaming the Chinese contractor, I'm sure they were just following the Apple procedure, sloppy as it is."

      What do you base this assertion on? How do you know how 'sloppy' the Apple procedure is?

      Many are lambasting Apple because they didn't test every vendor-supplied microdrive for *windows* viruses/virii. They sold 7.7 million ipods, as I understand it. If we grant 'em 10 seconds to hook the drive up and test it - even automated; remember, these drives aren't exactly fast - that's 891 additional days added to that manufacturing model.

      I'm not sure I believe that Apple should necessarily be responsible for a chinese manufacturer's choice of operating system for their production line.

      In fact, in response to the many assertions that Windows is the pre-eminent choice in production line systems... I find it difficult to believe; in my direct experience with seven major production systems and indirect with ten or twelve, only two used Windows, and of them had as their purpose was directly testing production of Windows based computers. A pharmaceutical company I'm familiar with uses HP clusters; a local utility recently switched from SCO to Linux ( I love saying that! ); A PCB assembly machine I dealt with had embedded a BSD variant. A plastics manufacturer I'm familiar with uses Linux and DOS (!) because the hardware manufacturer doesn't want to fix something that's "not broken". I've never even *heard* of Windows being used in production systems anywhere but plants that produce Windows computers.

    10. Re:Also shows... by Jack+Pallance · · Score: 5, Funny
      'develop on the platform you are releasing for'

      They would have, but the developers complained about having to use the IPod's scroll wheel to type all of their code.

    11. Re:Also shows... by Anonymous Coward · · Score: 5, Funny

      I once worked on a product, where we had a file on disk called IGNORE.ME. I can't for the life of me remember why.

    12. Re:Also shows... by spectral · · Score: 4, Informative

      I thought the same thing. Guess what happened when I first plugged in my SanDisk micro thumb drive? Shit got installed on my computer, that I had to specifically uninstall and then format the thumb drive (Conveniently available from the menu it installed, but still).

      NOTHING in the manual about "Oh yeah, if you plug this in to a windows PC we're running shit without telling you."

      I no longer trust "blank" media, but what can one do? Plug the hard drive in to a windows machine and format it? Woops, already fucked your computer over, since Windows will helpfully immediately run and install anything on the disk. This is a failure of Windows with autorun being on by default.

    13. Re:Also shows... by Trillan · · Score: 4, Insightful

      Their response was to fix their procedure so the problem could never repeat. What's so meager?

    14. Re:Also shows... by mrchaotica · · Score: 4, Interesting
      OS X viruses... exist as well

      Do they? Last I heard there was a "proof of concept," but IIRC even it required user interaction to propagate. I've never heard of a real, self-propagating, OS X virus in the wild.

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    15. Re:Also shows... by PitaBred · · Score: 4, Informative

      Pisses me off too. That's why I use TweakUI on every install of Windows I have to use and I disable AutoPlay completely. Optical discs, removable media, anything.

    16. Re:Also shows... by Mike+Peel · · Score: 4, Funny

      Odds are that more people read it than would have read a READ.ME file in the same folder.

  7. This sounds a bit suspicious... by msauve · · Score: 5, Interesting

    "it was traced to a particular Windows machine in the manufacturing lines of a contract manufacturer " and "Very few units actually went through that particular station"

    Why is a Windows machine ever connected to an iPod during manufacturing? I'd think for a high volume product like the iPod, there would be dedicated disk duplicators to format/populate the drives, and testing would likewise be done with purpose-designed hardware. Using a Windows PC to do either seems like a crude, inefficient way to do things.

    --
    "National Security is the chief cause of national insecurity." - Celine's First Law
    1. Re:This sounds a bit suspicious... by wetpantsclub · · Score: 4, Funny

      They would use Macs but they are too expensive. ;)

  8. Worst...apology...ever by BeeBeard · · Score: 4, Insightful
    From the article:

    "As you might imagine, we are upset at Windows for not being more hardy against such viruses, and even more upset with ourselves for not catching it," Apple said on its site.
    (emphasis added)

    It's nice that they're "upset with themselves for not catching it" in the last part of that statement, but what's that first part in bold all about? Oh yeah, it's the part where they shirk complete responsibility for this by half-blaming Microsoft for the virus Apple introduced in its own hardware. It's the most half-assed way of apologizing imaginable.

    In other news, rapists who blame their victims will now be in charge of issuing Apple's PR statements on their website.
  9. Exploiting process weaknesses... by mithran8 · · Score: 4, Interesting

    What I find interesting is the potential for this type of distribution to be the vector for a zero-day exploit.

    Imagine the scenario: an unscrupulous individual happens across an unannounced vulnerability, and develops an exploit. Rather than building it into a worm/botnet replication mechanism, he finds a way to load it onto a consumer electronics device (mp3 player, flash drive, camera, etc) and lets the well-established merchandise distribution network take it from there. Weeks/months later, at a predetermined time, an attack can be launched simultaneously from hundreds/thousands of locations, and we have a nasty problem on our hands.

    --
    An object at rest cannot be stopped!
  10. Re:Good job, Jobs! by eebra82 · · Score: 4, Informative

    I never stated that either. My point was that he can't complain about viruses on Windows computers now that he's helped spreading it. Excuse me for not being clear enough.

  11. Re:Come again?? by mr_matticus · · Score: 5, Insightful

    They didn't blame Microsoft for their failure to stop the iPods from shipping, but there is a certain element to truth to the statement. If you take away the fact that Apple is involved and look at it--a technology product was infected with malware because a Windows PC on the production line was infected and it wasn't caught in time.

    The number of Windows machines on production lines in China is staggering--and if Windows had better security, the spread of viruses and malware wouldn't represent such a massive threat. Simple acts like requesting permission to install new software, etc. would go a long way toward cutting this off. Windows, left to its own devices, happily installs crapware without user intervention or notification, and that makes it harder to KNOW when your computer has been compromised.

    So yeah, Microsoft is dumb in this capacity, but it's still Apple's responsibility.

  12. Re:Cue the... by sl3xd · · Score: 4, Insightful

    I'd prefer to think along the lines of "why you can't get anybody at Apple to care." It doesn't affect Macs, after all.

    Still, it does give food for thought. I can easily see it as an act of malice as much as a QA failure.

    I recall a *brand new* Sandisk flash drive that loaded & installed its own software (including Skype, its own little menu system, utilities, etc.) onto my computer the moment I plugged it in.

    How much would it be worth to a spammer/botnet group to infect the image that gets copied to all these devices? Enough to pay sufficiently large sums of money to subvert employees at the manufacturing plant?

    It's still inexcusably sloppy of Apple, but my real concern isn't in the companies involved: It's that it will likely happen elsewhere as well. Flash drives, DVD's with 'extended' PC content... stuff like that.

    Anywhere media with readable content is replicated can be a vector for viruses.

    --
    -- Sometimes you have to turn the lights off in order to see.
  13. Re:Come again?? by flithm · · Score: 4, Interesting

    I agree with you, although... I have to wonder, how did it get on the iPod in the first place? If you look at the W32/Rjump worm you can see that it spreads itself by copying itself to mounted removeable storage drives.

    Perhaps someone tested a prototype on an infected windows machine, to make sure some minor manufacturing change didn't bork the device. Then after working on it a bit they got it to work, copied the image over, and all of a sudden you have iPods being pumped out of the factor with a virus on them. Clearly just a guess, but if something similar to that happened and I was Apple I'd sure as hell be pissed that Windows lack of security caused my hardware devices to get factory shipped with a virus on them.

    Note that this scenario is supported by TFA: "Joswiak said it was traced to a particular Windows machine in the manufacturing lines of a contract manufacturer that builds the iPods for Apple."

    In that context, Apple has every right to be irritated. Either way though you're right, it's a pretty stupid PR move to make a comment like that. They should just apologize, fix the problem, and move on.

  14. If they're making products for use with Windows... by ChodeMaster · · Score: 4, Insightful

    If apple are going to make products for use with windows, then it is their responsibility to ensure that those products don't contain virii for windows systems. Suggesting that the virus being present in their product that they're shipping (regardless of the susceptibility of Windows to that virus) is the fault of Microsoft is passing the buck in a most horrible way.

    The simple fact is that they choose to make their device work with Microsoft Windows systems, and they are damned sure responsible for ensuring that their device will not cause problems with those systems, regardless of the flaws or vulnerabilities of Microsoft systems.

    I quite like Mac hardware and software, and have previously been glad that they may be gaining market share, but frankly if they are going to continue to market themselves by making stabs at Microsoft (and no I'm not suggesting the virus was placed intentionally), rather than by marketing their products' strengths and features, I'm not so sure I will continue to feel the same way.

  15. Re:How is it Possible to be Elitest AND Stupid? by Grishnakh · · Score: 4, Funny

    That's like MacDonald's importing meat infected with Mad Cow Diease, then blaming the FDA for not catching it.

    Bad analogy. It's like McDonald's (no a) selling burgers infected with MCD, and then blaming the humans for being vulnerable to it. Except that unlike humans in the real world (who are all susceptible to MCD), the humans in this crazy analogy universe have a choice between different bodies: one that's not only vulnerable to MCD, but every other disease out there, and has to be constantly immunized against them, and even then performs terribly, stops breathing and loses conscienceness occasionally, and is ugly to boot; and a few other bodies that are naturally immune to every known disease, are stronger and live much longer, don't need sleep, and are very attractive. Only the idiots who chose the ugly, disease-infested bodies get MCD so McDonald's justifiably tries to assign them some of the blame for making a bad choice.

  16. Holy appropriate analogies Batman! by Lactoso · · Score: 5, Funny
    "If I just distributed a device with a virus on it I would not be throwing stones at the security practices of another company."

    Especially not when you live here...

  17. Re:Upset with Windows? by Anonymous Coward · · Score: 5, Informative

    There is no such thing as autorun on OS X. If you really have managed to get a script to run automatically as soon as the volume that contains it is mounted, you are exploting a bug somewhere. Please file a bug report.

  18. Re:Good job, Jobs! by Salvance · · Score: 4, Funny

    So now Apple needs a commercial where the Mac guy is picking up biohazardous waste while wearing a virus-proof bunny suit and "accidentally" spilling it on the PC guy who's just laying there in his beach clothes enjoying himself.

    --
    Crack - Free with every butt and set of boobs
  19. Re:Upset with Windows? by mincognito · · Score: 4, Insightful

    Your script will not propogate itself; will not use up my computer's resources; will not open a backdoor to allow others access to my information, bandwidth and/or processor cycles. How come people always cite an unintended "rm -rf /" as the most terrifying and catostrophic event ever? I backup my data. I'd rather suffer your script than have an undetected MS virus, worm or rootkit.

  20. Re:Good job, Jobs! by Odin's+Raven · · Score: 5, Funny

    Next PC vs Mac commercial, the Apple version:

    PC is wearing a "boy in the plastic bubble" suit, wandering around with a bottle of Formula 409, obsessively wiping down everything he sees. Mac casually strolls up from behind and taps PC on the shoulder of his bubble suit. PC shrieks and starts spraying and wiping the suit. Mac asks what's up, PC starts babbling "Viruses...viruses are everywhere. Anything I touch might kill me. Never clean enough...never...clean...enough". Mac sadly shakes his head and wanders off.

    Next PC vs Mac commercial, the Microsoft version:

    Mac walks over to PC and offers to let PC listen to Mac's iPod. PC puts on the headset, starts tapping his feet and snapping his fingers, then suddenly flops onto his back, goes into convulsions, and dies. Mac slinks off the stage, looking embarassed and guilty. James Earl Jones voiceover grimly intones "iPods kill - buy a Zune".

    --
    A marriage is always made up of two people who are prepared to swear that only the other one snores.
  21. Re:Come again?? by QuantumG · · Score: 4, Informative

    Not one that's ISO 9000 certified you havn't. Apple has never done the necessary paperwork to get Macs into this market. They don't care about this market. Now they've been bitten on the ass by this stance. That's the irony, aint it sweet.

    --
    How we know is more important than what we know.
  22. Re:nah, this has happened before by buswolley · · Score: 5, Funny

    ITs great. Apple blames Windows for the Virus...but who put it on th ipod?

    --

    A Good Troll is better than a Bad Human.

  23. Re:twitter, please read this by skarphace · · Score: 5, Insightful
    Still, this is a case in which the use of a non Microsoft system for pre-loading the iPods would be the appropriate solution at the manufacturing end. Since all that's needed is the ability to create and write to a FAT32 filesystem, I don't see why Linux isn't used; it can even be done automatically on a headless machine that does the loading upon USB insertion.
    How do you know this is what the machine was used for? Maybe it was used as a QA/Testing machine to make sure the iPod works with all systems. Fact is, you don't know.
    --
    Bullish Machine Tzar