Announcement

Collapse
No announcement yet.

Macs and the illusion of security

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Macs and the illusion of security

    Shame Aggie & Co aren't here anymore. Their arguments that OS X was more secure by design I had refuted years ago, arguing it was a factor of marketshare than anything else. I'm slowly being vindicated.



    Another Major Mac Computer Security Flaw Discovered

    OS X continues to fall short of its security reputation

    Many Mac owners live under the assumption that their computers will never be attacked. While that statement may hold some truth -- most fail to understand why. Rather than realizing that the relatively safety is afforded by Apple's still small market share, they believe that the security is somehow owing to an inherent security superiority in their operating system of choice, OS X, a sentiment echoed in Apple's sarcasm-laden "Get a Mac" commercials.

    However, in reality Apple's security implementation, both on an OS and an application level is often lacking. It took Apple a year to patch a glaring hole in its OS X Java implementation. A major hole allowing SMS binary messages to execute code as root in the iPhone also went unpatched for over a month. Apple's OS X-toting iPhone's encryption scheme was declared laughably useless by a security expert and even Apple seems to acknowledge that its security may be lacking, warning that its iPhone can easily be hacked and used as a terrorist weapon.

    Now leading Mac researcher Dino Dai Zovi has unveiled a new attack at the chic Black Hat security conference in Las Vegas. The new technique allows hackers to take control of OS X machines and steal data from them that is supposed to be encrypted.

    All the technique needs is access to the memory. A few lines of code will give the attacker access to the root memory, which is then written to establish a TCP connection, allowing the hacker to download malicious files and control the computer remotely. Mr. Zovi demonstrated how the attack can be used to hijack Apple's Safari browser, stealing encrypted data from a user's bank accounts.

    He states, "There is no magic fairy dust protecting Macs. Writing exploits for [Microsoft] Vista is hard work. Writing exploits for Mac is a lot of fun."

    Security experts predict that the interest and the means are finally coming together that could make for the first serious malware attack on Mac computers. With hackers cooking up a new wave of Apple-catering malware many predict that the attacks will catch the community of millions of Mac users in the U.S. unaware. States Joel Yonts, another Mac security expert at the conference, "When the malware authors put out something that's really sophisticated we are going to have a whole population that is really vulnerable."

    Apple has not released a comment about the flaw or announced any plans to patch it.
    There's going to be the potential for a massive worm on the Mac. The vast majority of users don't have antivirus software of any kind, and the Mac commercials and community have conditioned the users to think their computer simply "doesn't get viruses or worms" unlike PC.

    A lot of people are going to be very angry, very soon I think.
    "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
    Ben Kenobi: "That means I'm doing something right. "

  • #2
    On Mac, trojans Just Work™.
    "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
    Ben Kenobi: "That means I'm doing something right. "

    Comment


    • #3
      Something Asher and I agree on.

      I never understood paying 1500 for a laptop that would cost me 600 as a pc.
      Scouse Git (2) La Fayette Adam Smith Solomwi and Loinburger will not be forgotten.
      "Remember the night we broke the windows in this old house? This is what I wished for..."
      2015 APOLYTON FANTASY FOOTBALL CHAMPION!

      Comment


      • #4
        I'm sure your reply was just what he was hoping for!
        ...people like to cry a lot... - Pekka
        ...we just argue without evidence, secure in our own superiority. - Snotty

        Comment


        • #5
          I'm trying to find some rope as we speak.
          "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
          Ben Kenobi: "That means I'm doing something right. "

          Comment


          • #6
            I look forward to a widespread infection. Snotty bastards
            It's almost as if all his overconfident, absolutist assertions were spoonfed to him by a trusted website or subreddit. Sheeple
            RIP Tony Bogey & Baron O

            Comment


            • #7
              Originally posted by Asher View Post

              A lot of people are going to be very angry, very soon I think.
              Assuming they even notice. They might think it's a new feature.
              Pool Manager - Lombardi Handicappers League - An NFL Pick 'Em Pool

              https://youtu.be/HLNhPMQnWu4

              Comment


              • #8
                Oh noes! You mean, if my operating system is already compromised, people may be able to steal my data! Shocking!

                (I don't disagree with the overall point, just the trolliness of the article.)
                "In the beginning was the Word. Then came the ******* word processor." -Dan Simmons, Hyperion

                Comment


                • #9
                  Originally posted by rah View Post
                  I look forward to a widespread infection. Snotty bastards
                  “I give you a new commandment, that you love one another. Just as I have loved you, you also should love one another. By this everyone will know that you are my disciples, if you have love for one another.”
                  - John 13:34-35 (NRSV)

                  Comment


                  • #10
                    Originally posted by Koyaanisqatsi View Post
                    Oh noes! You mean, if my operating system is already compromised, people may be able to steal my data! Shocking!

                    (I don't disagree with the overall point, just the trolliness of the article.)
                    It's on-point, though. Most virii get in via social engineering of some kind. Combined with the naive userbase on Macs, it'd be trivial to get large numbers of people to run an executable thinking it's something else, like pictures of boobies or porn videos.

                    Then it could steal information that's supposed to be encrypted and secure on your computer.
                    "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                    Ben Kenobi: "That means I'm doing something right. "

                    Comment


                    • #11
                      virii

                      is that what you call it when your Wii gets sick?
                      Monkey!!!

                      Comment


                      • #12
                        It's a funnier word than viruses, though I believe viruses is actually correct.
                        "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                        Ben Kenobi: "That means I'm doing something right. "

                        Comment


                        • #13
                          they're over at the Rock & Roll Heaven

                          we have a comp (shuttle X or something, a small box of a computer) running windows 2000 (maybe professional) and it has never gotten a virus that we know of, and its still working a decade later. There's no updates, patches, security, nada. Is the reason for this that hackers and aholes dont bother trying to mess with 2000 because its more rare? Kinda like whats been protecting Mac all this time? I get crap all the time with xp now even visiting benign sites like yahoo sports but my free security finds it

                          avast me mate
                          avira
                          avg
                          and malwarebytes

                          Comment


                          • #14
                            Doesn't Vista also receive a type of security due to lack of marketshare?
                            KH FOR OWNER!
                            ASHER FOR CEO!!
                            GUYNEMER FOR OT MOD!!!

                            Comment


                            • #15
                              Asher, do you say boni or bonuses?
                              Graffiti in a public toilet
                              Do not require skill or wit
                              Among the **** we all are poets
                              Among the poets we are ****.

                              Comment

                              Working...
                              X