Slashdot Mirror


Worm Threat Forces Apple To Disable Software?

SkiifGeek writes "After the debacle that surrounded the announcement and non-disclosure of a worm that targets OS X, the vulnerability in mDNSResponder may have forced Apple to remove support for certain mDNSResponder capabilities with the recently released Security Update 2007-007. 'Seeming to closely follow the information disclosed by InfoSec Sellout, Apple's mDNSResponder update addresses a vulnerability that can be exploited by an attacker on the local network to gain a denial of service or arbitrary code execution condition. Apple goes on to identify that the vulnerability that they are addressing exists within the support for UPnP IGD... and that an attacker can exploit the vulnerability through simply sending a crafted network packet across the network. With the crafted network packet triggering a buffer overflow, it passes control of the vulnerable system to the attacker. Rather than patching the vulnerability and retaining the capability, Apple has completely disabled support for UPnP IGD (though there is no information about whether it is only a temporary disablement until vulnerabilities can be addressed).'"

40 of 201 comments (clear)

  1. *Pulls out a plate 'o crow* by Anonymous Coward · · Score: 5, Funny

    Come here Apple fanboys-and-girls. Lunch is served.

    1. Re:*Pulls out a plate 'o crow* by teknopurge · · Score: 3, Funny

      I wonder who wrote the UPnP spec - perhaps they are the ones at fault? (*cough*BILL GATES' University of chair-throwing throwers*cough*)

    2. Re:*Pulls out a plate 'o crow* by BuhDuh · · Score: 3, Informative

      I wonder who wrote the UPnP spec - perhaps they are the ones at fault? (*cough*BILL GATES' University of chair-throwing throwers*cough*)

      I don't think the issue is the spec, it's the asinine cute features that M$ decided to implement. Like UPnP, BHO, etc etc. Maybe we should follow Apple's example, and eliminate all vulnerabilities by disabling the TCP/IP stack?

      --
      Enlightenment? It's just a flush in the pan.
    3. Re:*Pulls out a plate 'o crow* by joeytmann · · Score: 2, Funny

      GO APPLETALK!

      --
      Insert funny smart-ass comment here.
    4. Re:*Pulls out a plate 'o crow* by teknopurge · · Score: 2, Informative
      Looks like Apple just followed Wikipedia:

      Problems with UPnP * UPnP uses HTTP over UDP (known as HTTPU and HTTPMU for unicast and multicast), even though this is not standardized and is specified only in an Internet-Draft that expired in 2001. [1] * UPnP does not have a lightweight authentication protocol, while the available security protocols are complex. As a result, many UPnP devices ship with UPnP turned off by default as a security measure.
    5. Re:*Pulls out a plate 'o crow* by Nullav · · Score: 3, Informative

      You mean like how MS crippled the stack in SP2 by lowering the cap on half-open connections to 10 to slow worm propagation? (I know there are times when a solution isn't always immediately obvious, but I'd rather not have my OS force me to live in a bubble.)

      --
      I just read Slashdot for the articles.
    6. Re:*Pulls out a plate 'o crow* by fermion · · Score: 3, Interesting
      This is what should happen. Fix it, or remove the feature, or at least make it optional. This is what Apple normally does. It does not ship with all ports open and sharing on.

      I hope this indicates a return to sensibility at Apple. Lately they are trying so hard to be like MS, that the security has suffered. Can't turn off HTML in email is at the top of my security vulnerabilities.

      --
      "She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
  2. News at 11... by maztuhblastah · · Score: 5, Insightful

    Researchers find hole, act like 1337 733ns about it. Company can't be sure that they've fixed hole, so they temporarily disable the reportedly-vulnerable function.

    Yawn.

    1. Re:News at 11... by Jeremy_Bee · · Score: 3, Insightful

      Isn't it interesting that Slashdot threads that have anything to do with the adventures and histrionics of David Maynor instantly become peppered with a large number of idiotic, unsupported comments railing against Apple and "Apple FanBoiz," made by a variety of Slashdot accounts that rarely show up commenting on anything else?

      Here is a hint: A pretend army of supporters is still a pretend army.

      Isn't it fascinating to watch as shitty comments (like we see above), vacillate back and forth between "+5 Insightful" and "Flamebait" as the pretend army fights the good fight against Apple "FanBoiz" everywhere?

      Why can't we just install a filter that gets rid of any post that uses "fanboy" or fanboi" or the like? No one making a serious point or with any kind of intellectual integrity uses it except as a joke.

    2. Re:News at 11... by mikeabbott420 · · Score: 2, Insightful
      The configurable spam filter would be a great idea for slashdot.

      I can think of a lot of phrases that would increase the signal to noise ratio (for me) if I could use them to exclude noise.

      I believe a site mandated filter would be both useless and undemocratic.

      --
      This program was made possible by a grant from the Ultra-Humanite, and viewers like you.
    3. Re:News at 11... by gutter · · Score: 5, Insightful

      Hello, Artie McStrawman! Sure, there are a few idiots out there that believe that OS X is infallible - there are also some idiots out there that believe the same about windows or linux. However, you aren't likely to find them around here. You'll find plenty of people that believe that OS X is MORE secure than the some of the alternatives, largely because their heavy use of open source and their default configuration that ships with no open ports, but very few that think it is "inherently secure".

      The proof is in the number of successful worms and viruses for OS X, which depending on how you define them, hover right around zero. Yes, some of this is likely because of market share, but there's plenty of bragging rights associated with creating the first large-scale OS X compromise, so I wouldn't expect to see none. And of course, even if the relatively low number of security issues is because of market share, it doesn't make it any less pleasant for those of us who use OS X, especially since I'm not expecting it's share to go over 15-20%.

      Anyway, if I accept your statement that OS X isn't perfect, will you stop bitching about smug mac users every time there is a discussion marginally related to Apple?

      Thanks,
      gutter

      --
      Check out DRM-free movies at http://www.bside.com
    4. Re:News at 11... by sl3xd · · Score: 4, Insightful

      Smugness is in the eye of the beholder; unfortunately, there's often nothing that can be done either way, as a great many people aren't able to accept that something other than their chosen product (or OS in this case) might have something that theirs doesn't.

      In other words, Ford Mustang owners tend to see Chevy Corvette owners as smug. Neither side is really willing to appreciate that each has advantages the other doesn't possess, and can't stand it when somebody highlights the advantage. That isn't ever going to change

      I don't see how the situation is any different when an operating system is concerned, rather than a brand of vehicle.

      Here's a news flash: OS X has advantages over Windows, Linux, and FreeBSD. OS X can brag about security, because there is a far smaller percentage of its users that have infected, compromised, or zombified machines. Ffind reasons to discount that fact is meaningless: It doesn't matter if the number of attackers is smaller; the goal is to not fall victim to an attack, which OS X has an excellent record of doing.

      Here's another one: Macintoshes have disadvantages: They don't have as much native software. A virtualization product like VMware or Parallels is a rare sight on Windows, yet is quite common on a Macintosh. There's always some app that only exists for Windows that the user can't live without. So Mac users not only pay $130 for OS X, but also $80 for a virtualization product, and then they have to buy the most expensive license for Windows. Mac software doesn't enjoy the "freedom" that most Linux users enjoy; much of the software for the Mac is closed-source.

      Still, you don't have to like it when OS X users dismiss the advantages of other OSes (like the amount of software for Windows, or the freeness of Linux).

      Just take the time to realize that's it's a different flavor of the time-honored "Chevy vs Ford" debate. What is "better" depends on the way the beholder sees things, and it's childish to believe that there's only one true way.

      --
      -- Sometimes you have to turn the lights off in order to see.
    5. Re:News at 11... by owndao · · Score: 2, Informative
      Yawn, truly. If one reads the Apple patch notes they say quite plainly:

      mDNSResponder CVE-ID: CVE-2007-3744 Available for: Mac OS X v10.4.10, Mac OS X Server v10.4.10 Impact: An attacker on the local network may be able to cause a denial of service or arbitrary code execution Description: A buffer overflow vulnerability exists in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) code used to create Port Mappings on home NAT gateways in the Mac OS X implementation of mDNSResponder. By sending a maliciously crafted packet, an attacker on the local network can trigger the overflow which may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by removing UPnP IGD support. This issue does not affect systems prior to Mac OS X v10.4. If one reads the entire note there were other, more noteworthy, bugs addressed rather than one that would take great care to craft and would have to be deployed on your LAN. Also, the derogatory terms used to refer to people who have an operating system preference are reminiscent of my three year old calling someone "poopie butt." Save us all.
      --
      Be as you would have the world become.
  3. Um, so ? by Space+cowboy · · Score: 4, Insightful

    Apple find a vulnerability (before the worm is announced, according to TFA), and remove that vulnerability in their next security update.

    I'm guessing there's a regular scheduled security update process in Apple. If you can't fix it in time for the next patch-release, isn't is *better* to temporarily disable it ? I really doubt it's a permanent removal of the feature - they're just being responsible.

    Simon.

    --
    Physicists get Hadrons!
  4. ITS A LIE by Conor+Turton · · Score: 3, Funny

    I'm sorry but the article must be a lie. The Apple fanboys assure me that there's no risk of vulnerabilities. Therefore, the article is wrong - it does not exist.

    --
    Conor "You're not married,you haven't got a girlfriend and you've never seen Star Trek? Good Lord!" - Patrick Stewart
    1. Re:ITS A LIE by weak* · · Score: 3, Funny

      Mod parent up -- way to think different (tm).

      --
      The Schwartz space ain't from Spaceballs.
  5. OT but... by Anonymous Coward · · Score: 2, Informative

    I often wonder why the British (and now some Americans) say "Apple go on to identify..." Apple is ONE company. Shouldn't that be the singular "Apple goes on to identify"? If it were both Apple and Microsoft than indeed it would be "Apple and Microsoft go on to identify".

    Yes, Apple is made up of many people; but my car is made up of many parts. You don't say "my car need gas" do you?

    This perplexes me, can someone explain it? Sorry if it's completely OT (except that this (to me) error is in the blurb).

    -mcgrew

    (amusingly, the capcha is "contrary". Again sorry for being OT)

    1. Re:OT but... by Space+cowboy · · Score: 2, Informative

      Companies are generally considered to be plural entities in "real" English [grin]. I suppose we put a higher value on a collection of humans compared to a collection of metal parts...

      If you prefer, consider mentally replacing "Apple" with "the people who work at Apple"...

      Simon

      --
      Physicists get Hadrons!
  6. Apple ... Worm by zariok · · Score: 5, Funny

    So an "apple" is threatened by a "worm"... you don't say.

    --
    -zariok-
  7. Hmmm... by catdevnull · · Score: 2, Interesting

    Isn't mDNSResponder and Open Source package ported for OS X?

      http://developer.apple.com/opensource/internet/bon jour.html

    Is Apple the developer of mDNSResponder or are they just using it?

    --

    I might know what I'm talkin' about, but then again, this is Slashdot...
    1. Re:Hmmm... by shawnce · · Score: 4, Informative

      An Apple employee (Stuart Cheshire) is one of the authors of the RFC(s) related to mDNS, etc.

      mDNSResponder originated from Apple.

  8. Sensationalism by Zonk by Night+Goat · · Score: 5, Insightful

    Hey Zonk, how about using more reputable sources than one guy's blog for your links? I know they were picked by the submitter, but linking only to a blog and then putting a question mark after the headline is sketchy. I can't put much faith in the article if I can't be sure that it's not just a blogger talking out of his ass.

  9. At least they disabled it! by Opportunist · · Score: 3, Interesting

    I mean, it was a given that, given increasing market share, Apple becomes interesting for malware. No system is 100% secure.

    But at least they decided that it's better to disable the feature and minimize the damage to the net as a whole (and yes, even if you don't have an Apple, a worm damages you by clogging your tubes with packets trying to spread itself). MS decided that it's better to keep the insecure service up and running 'til it can be addressed.

    Question for 100: Still getting sober/blaster packets? I do.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:At least they disabled it! by GWLlosa · · Score: 2, Insightful

      The reason Apple disables features where Microsoft doesn't has more to do with their target audience than any kind of company 'ethos'. If MS advises people that vulnerabilities exist with and , and proceeds to disable them, actual businesses that rely on features and will be very upset and potentially out a pile of money. Instead, MS advises of the vulnerability, so that these businesses can instead rely on their IT guy hardening the system against the vulnerability (seal the appropriate port on the firewall, disable the services on the machines that don't need it, isolating the machines that do use it from outside attack, etc.) whereas the odds of anybody's business being affected by the loss of are minimal, and they need to assume that their device is not administered by a technical person in any way. I mean, imagine the fallout if there was a bug that allowed malformed MS word documents being loaded by Office 2007 to result in security issues, and Microsoft responded by disabling the load feature.

    2. Re:At least they disabled it! by Chang · · Score: 2, Informative

      Microsoft has done this with their products before.

      Outlook was plagued by viruses and Microsoft responded by releasing a patch that simply refused to allow the user to open certain types of attachments. There was no override in the original version of the patch.

      http://www.slipstick.com/outlook/esecup.htm

      When Exchange 5.5 was targeted by reverse-NDR spam attacks Microsoft shipped a patch that allowed the user to simply turn off non-delivery reports. Unfortunately the patch didn't work as described on many systems. A more correct fix would have allowed the administrator to simply suppress delivering the complete text of the failed message which makes the system much less likely to be used for reverse-NDR spam.

      http://support.microsoft.com/default.aspx?scid=kb; en-us;837794

      When the Windows messenger service was targeted by messenger spam. Microsoft elected to simply turn it off. Kudos to Microsoft - this was the correct choice on this one.

      http://www.theregister.com/2003/10/29/microsoft_sh oots_the_windows_messenger/

  10. Apple did the right thing by mcrbids · · Score: 5, Insightful
    Yes, I understand that there are certainly dissenting opinions here. But (IMHO) the thing that most Slash-bots complain about is that Microsoft will

    A) Pick a feature that's dumb. (like embed a scripting language into an image format, or give a spreadsheet scripting language access to the filesystem)

    B) Choose to preserve the dumb feature in spite of known security problems.

    C) Treat the resulting backlash as a "PR issue" rather than a technical one.

    D) Sometimes, if the backlash gets bad enough, they'll hack in security restrictions in response to specific known implementations that take advantage of the vulnerability rather than fix the vulnerability. EG: fixes that look for a XXX worm trace, rather than fix the thing that XXX worm exploits. (See anti-virus)

    Apple is doing the right thing, here, folks! It may or may not be that the feature mentioned is analogous to (A) above. Either way, Apple is chosing security over features, even though features are important.

    --
    I have no problem with your religion until you decide it's reason to deprive others of the truth.
    1. Re:Apple did the right thing by Ash-Fox · · Score: 2, Interesting

      Apple is doing the right thing, here, folks!
      Yes, because disabling support for the standard Internet Gateway Device support which software uses to seamlessly setup port forwarding on NAT systems etc. and having the user do it manually is good.

      Many, many programs use IGD, from Instant Messengers to games.

      Sorry, I cannot agree that it is the right thing.
      --
      Change is certain; progress is not obligatory.
  11. Re:Standard Operating Procedure? by Rosyna · · Score: 4, Interesting

    I'm not opposed to temporarily disabling functionality to fix something potentially disastorous. There are three options when implementing UPnP:

    1. Implement it to Microsoft's spec.
    2. Implement it correctly (by choosing a direction in places the spec contradicts itself or real implementations).
    3. Implement it securely.

    Choose only one.

    I do not think it is possible to implement UPnP securely and have it based on the spec. Also, the specific code they removed existed only for legacy NAT traversals and may not even be needed any more.
  12. "additional validation" or "disabled support" by czmax · · Score: 3, Interesting
    If you follow the link to the apple security update page there are actually two vulnerabilities associated with UPnP IGD. For one of them apple indicates that "this update addresses the issue by performing additional validation when processing UPnP protocol packets in iChat". For mDNSResponder apple indicates "this update addresses the issue by removing UPnP IGD support.

    Clearly something is unclear since iChat is obviously still using UPnP IGD, likely as a client?

    But why is the mDNSResponder using UPnP IGP anyway? mDNS is for service discovery etc and is basically a competitor to UPnP (I thought). Perhaps there is a way for mDNSResponder to leverage UPnP IGP to broadcast service messages (e.g. bonjour) across a local NAT? If so I've never seen nor heard of this working -- so perhaps what they're disabling is vulnerable code that wasn't doing anything anyway?

  13. Who wants to bet... by subl33t · · Score: 3, Interesting

    ... that the iPhone will be the vector that finally gets Macs infected with a virus/worm that will replicate in the wild?

    I bet there's a secret cabal at Microsoft that is working on this very thing.

  14. Re:Standard Operating Procedure? by frdmfghtr · · Score: 3, Informative

    I'm not opposed to temporarily disabling functionality to fix something potentially disastorous.

    There are three options when implementing UPnP:

    1. Implement it to Microsoft's spec.
    2. Implement it correctly (by choosing a direction in places the spec contradicts itself or real implementations).
    3. Implement it securely.

    Choose only one.

    I do not think it is possible to implement UPnP securely and have it based on the spec. Also, the specific code they removed existed only for legacy NAT traversals and may not even be needed any more.
    Is this the same UPnP capability that the FBI recommeded disabling in any Windows environment due to security issues quite some time ago?
    --
    Government's idea of a balanced budget: take money from the right pocket to balance...oh who am I kidding?
  15. Re:TV add by Farmer+Tim · · Score: 3, Funny

    "Hi, I'm a Mac"

    "And I'm a PC. Hey Mac, I heard you don't get viruses. Congratulations."

    *PC Shakes Mac's hand*

    "That's right, PC. But I do have worms."

    *PC starts wiping hand furiously*

    --
    Blank until /. makes another boneheaded UI decision.
  16. Now that Apple has disabled uPnP compatibility.... by argent · · Score: 2, Interesting

    Now that Apple has disabled uPnP compatibility will the original anonymous extortionist reveal the hole that he claims he didn't want to reveal lest Apple come up with some excuse for not disabling whatever his hole was, or will we hear more FUD from him?

  17. Big Loss! by reed · · Score: 3, Informative

    UPnP kind of sucks anyway. Maybe this will get people to move to MDNS-SD, which is simple, straightforward, has several implementations (both open source and not).

    1. Re:Big Loss! by DECS · · Score: 2, Insightful

      Well the subject under discussion was Apple's mDNS, its UPNP implementation, and the security issues that resulted in Apple simply turning UPNP off.

      You can give yourself points for knowing unrelated details about Microsoft's non-standard, security challenged architecture. The number of devices using UPNP as anything other than a way to play games over a router are really insignificant however.

      The wikipedia article you linked to points out:

      - UPnP uses HTTP over UDP (known as HTTPU and HTTPMU for unicast and multicast), even though this is not standardized and is specified only in an Internet-Draft that expired in 2001.

      - UPnP does not have a lightweight authentication protocol, while the available security protocols are complex. As a result, many UPnP devices ship with UPnP turned off by default as a security measure.

      That's the same reason Apple gave up on it and turned it off by default as well.

      -
      Ten Fake Apple Scandals: 10 - Apple's Mac and iPhone Security Crisis
      Windows Enthusiasts weary of making excuses for Microsoft's security failures have discovered that the best defense is a good offense.

      Ten Fake Apple Scandals: 9 - Troy Wolverton, Neil Cavuto, and the Apple Stock Scandal
      Google for 'Apple Scandal' and the results are overwhelmingly related to options backdating. Those backdated options from 1997 - 2001 resulted in Apple taking an $84 million charge against operations, but continued to monopolize the headlines for months with the panic that Steve Jobs might go to jail and Apple might be delisted from the NASDAQ stock exchange.

  18. Re:Standard Operating Procedure? by Rosyna · · Score: 4, Interesting

    I call bullshit. You are saying it's not possible to implement UPnP without being vulnerable to a buffer overflow that may lead to remote code execution? Because that's one of the (at least) two issues at hand. Nice try on passing the responsibility for this bug to the spec writers (mentioning Microsoft seems to help too), Uhm, UPnP is a microsoft created and controlled spec, this is why I specifically mentioned Microsoft. Some people think it's not microsoft related because Microsoft hides their name from being easily found on the site (they do the same thing with the Zune). But, do a whois on upnp.org or look at many of the UPnP documents and you will see Microsoft's name plastered all over.

    Can you show me an implementation of UPnP that hasn't had bugs? According to wikipedia security is a problem with the spec itself. It's getting so bad that some major router manufacturers are disabling the routing of UPnP packets by default on their non-consumer (and a few consumer) networking appliances.

    And my list was more of a dig at OOXML rather than being security related.
  19. Re:wait a minute by Sparks23 · · Score: 4, Insightful

    Realistically, no OS is completely secure. This is hardly the first security issue in OS X, nor will it be the last. Linux has had its share of security flaws, too.

    In the modern world, there are simply too many protocols and systems popping up; no operating system exists in a vacuum, and many vulnerabilities may be in services, subsystems and so on. And with the pressure to get things out and shave off extra CPU cycles, there are too many situations where someone simply goes 'oh, well, I checked that this data is valid up HERE, so I don't need to check again down here in this function I call later,' and then later another piece of code goes, 'oh, look, here is a function that does what I need, I will just reuse it' and assumes that function does its own error-checking, so does not check the data before passing into it. And thus, you create a pathway where unvalidated data gets passed down and can cause buffer overflows or whatever.

    No operating system or development team is somehow inherently immune to this.

    The thing is that Windows not only has kept large chunks of legacy code -- which makes it hard to really break down and restrict user permissions without breaking older programs -- but spent some time really pushing the Active X technology, which then proved to create a lot of problems. Apple, on the other hand, went off the tracks entirely and threw out their operating system; that was a risky move which could have killed them off entirely, but in the end they got an operating system which was built atop a multi-user system with better permissions.

    That does not mean that Apple somehow writes inherently better code than Microsoft; I happen to like OS X, but Apple's engineers are not necessarily smarter or more careful in the actual lines of code they write. The difference as I see it is that Microsoft is bogged down by hard-to-debug and support legacy code, while Apple got to make a cleaner start... and then on top of that, many bits of OS X (CUPS, zeroconf/Bonjour, WebKit, etc.) are open source.

    Apple contributes funds and engineering to these projects (and in some cases such as zeroconf, came up with the original specifications), but as they are open source things tend to get found and fixed faster in community review. That is why OS X, while not bulletproof, tends to be at least a bit more secure than Windows.

    That is my take on it, anyway.

    --
    --Rachel
  20. Re:Moderations tell all by node+3 · · Score: 3, Informative
    I'm just going to collect a few of your more inane tidbits together here:

    "Apple failed" (they did not)

    "OS X is every bit as crash prone and unreliable as Windows" (It's crash prone, but not "every bit as crash prone")

    "not so with Apple, which radically changes their OS every few years" (Two points here: 1. if this is true, it belies your following statement 2. it's not true)

    "There is no inherently superior security in OS X" (the overall design and implementation of OS X is more secure than the overall design and implementation of XP. Vista is a vast improvement over XP, but it remains to be seen how this works out)

    "those people who blame Microsoft for vendor lock-in" (straw man, no one claims this)

    "OS X is the ultimate in vendor lock-in" (OS X is an extremely open system. The only "lock-in" is with their hardware, which really isn't that big of a deal.) For someone who claims to be fighting against religious zeal, you sure come across fanatically angry. You make the basic fallacy that, "Windows is flawed, OS X is flawed, therefore Windows and OS X are equally flawed," which is complete nonsense.

    There are people who get fanatical about Macs, but you're lumping a whole lot of rational people in with them, and fully deserve flaimbait or troll modding for it.

    the minute you take a bite of the precious worm-ridden Apple, mods put you to sleep for a year No, stupid shit like, "eat crow" gets modded down. Eat crow for what? A security flaw existed? It was patched? WTF? A lot of anti-Apple sentiment gets modded up, as well, though generally the more rational stuff, like people complaining about vendor lock-in (like you did above) or various other things that actually make sense.

    Not to mention the fact that both you, and the OP are both (at present) modded positively, which makes your cries of being oppressed a bit silly.
  21. Re:Does anyone use mDNS? by Tony+Hoyle · · Score: 3, Insightful

    mDNS - Apple
    UPNP - Microsoft

    Apple have disabled the Microsoft protocol. Won't affect them in the slightest I'd expect.

    mDNS is actually fairly useful.. you can advertise servers across the network using it, and it's an easy protocol to implement (a few hundred lines of code will do it).

    UPNP is an XML infested mess with a huge spec that I wouldn't try to implement unless I had a deathwish. And in all that mess they forgot to add any user or machine verification.. the upshot being if you enable it on a router you can disable its firewall with a 10 line perl script.

  22. Re:wait a minute by toddestan · · Score: 2, Informative

    Not that I'm defending macs in any way, but you do realize that there have been quite a few remote exploits (in the wild, not theoretical) that require nothing other than having a windows computer online and having its card pulled by another infected machine, right? It's not about if you're "smart" enough not to click on something, but if you were a bit brighter you'd already know that.

    Those days are also over (atleast for the most part). Windows now comes with its firewall on by default, and those wide open services have been secured a lot better. It's not just a Windows thing either, I remember the days when a Redhat 5/6 install on the open internet would get pwned rather quickly too.