MAC is not immune

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • OpaDC
    Established Member
    • Feb 2008
    • 393
    • Pensacola, FL
    • Ridgid TS3650

    #1

    MAC is not immune

    Apple fixes a dozen holes in Mac OS X

    added:

    Meanwhile MS business as usual.
    Microsoft patches "Google hack" flaw in Internet Explorer
    Last edited by OpaDC; 01-27-2010, 04:39 PM.
    _____________
    Opa

    second star to the right and straight on til morning
  • Richard in Smithville
    Veteran Member
    • Oct 2006
    • 3014
    • On the TARDIS
    • BT 3100

    #2
    I guess this won't make it to the Mac/PC commercials.
    From the "deep south" part of Canada

    Richard in Smithville

    http://richardspensandthings.blogspot.com/

    Comment

    • jussi
      Veteran Member
      • Jan 2007
      • 2162

      #3
      I never thought MACs were immune. Its just that Windows has such a huge market share that Virus programmers don't bother with MACs.
      I reject your reality and substitute my own.

      Comment

      • OpaDC
        Established Member
        • Feb 2008
        • 393
        • Pensacola, FL
        • Ridgid TS3650

        #4
        Originally posted by jussi
        I never thought MACs were immune. Its just that Windows has such a huge market share that Virus programmers don't bother with MACs.
        You're correct. Unfortunately, many MAC users seem to think nothing can happen to it. This is not a virus though, but a vulnerability. Rarely have I seen a MAC that has done updates. That being said, these are not computer literate people who had these machines.
        _____________
        Opa

        second star to the right and straight on til morning

        Comment

        • crokett
          The Full Monte
          • Jan 2003
          • 10627
          • Mebane, NC, USA.
          • Ryobi BT3000

          #5
          Interesting that the Mac has these holes. It is *nix based, and if I recall correctly is based on one of the BSD derivatives. BSD is generally considered one of the more secure versions out there. I ran FreeBSD once upon a time.
          David

          The chief cause of failure in this life is giving up what you want most for what you want at the moment.

          Comment

          • cgallery
            Veteran Member
            • Sep 2004
            • 4503
            • Milwaukee, WI
            • BT3K

            #6
            Originally posted by crokett
            Interesting that the Mac has these holes. It is *nix based, and if I recall correctly is based on one of the BSD derivatives. BSD is generally considered one of the more secure versions out there. I ran FreeBSD once upon a time.
            http://www.securiteam.com/products/F/FreeBSD.html

            Comment

            • leehljp
              The Full Monte
              • Dec 2002
              • 8798
              • Tunica, MS
              • BT3000/3100

              #7
              Originally posted by OpaDC
              You're correct. Unfortunately, many MAC users seem to think nothing can happen to it. This is not a virus though, but a vulnerability. Rarely have I seen a MAC that has done updates. That being said, these are not computer literate people who had these machines.
              I work with Macs (not MAC, which is totally different) and all that I have seen have updates. I have not seen any without updates. I have seen (fixed) many many PCs without the updates especially without service pacs because the user is too afraid that they might have to re-install the system or some application will quit working.

              Why are Mac users so vocal? To drown out the deliberate put down of corporate IT slander such as this in yesterday's news:

              This week in Infoworld: Condescension and flaming the Mac community concerning Apple products but specifically the tablet - can be seen here:
              http://www.infoworld.com/d/windows/a...apocalypse-352
              Quote from Page 2: "So what can IT do to thwart the coming Apple tablet-pocalypse? First, an outright ban is in order. Use whatever excuse you think carries the most weight. For example, claim that the devices are insecure, and that plugging them into the corporate network will compromise its integrity. Then seek to contain the situation by offering up an alternative tablet solution running the IT-supported and IT-approved Windows 7 operating system.

              Though not as sleek or as sexy as the real deal, these Apple tablet imitators should be sufficient to placate the bulk of your tablet-infatuated user base. In fact, you may want to nip the situation in the bud by providing the squeakier wheels with their own faux tablets now, before the Apple iHysteria sets in.
              "

              It takes years to counter the stupidness that IT INFO puts out, and it makes Mac users angry because it directly insinuates lies and mis-information. The problem is that most IT fellows know the truth and that this is written tongue in cheek, but PC fans don't! Just as this thread starts out with the insinuation that "updates" = "unsecure". No Mac user says that there will not be a virus some day. There have been Proof of concepts already there.

              When Mac users say they are safe - they have enough sense to know that for now they are, but in the future there will be viruses for sure.

              Most PC Users have a false sense of security with their AV software. AV software is not for future created viruses. Current installed AV software is absolutely no protection for the "next to be created", even in its best heuristic state. AV software is protection for those already created, not future new viruses. False sense of security through out the PC world. To put this in other words: With the best commercial AV software, it is not safe for the "next" virus until after a definition is written, it is downloaded and installed by the end user. (Some AV software checks automatically on a time schedule) Try to tell this to the average AV user and they will just say "HUH?".

              Once a successful virus is released for the Mac, it will be imperative to keep AV "on" at all times. But it will not protect against future viruses until a definition is written but it will protect against the past created ones that are still floating around!

              Anti-Virus software is not future specific but past specific, even with the best heuristics. This leads us to the Updates: MS's whole attitude led to their downfall with virus and other similar problems. They left the whole protection to third parties. This "was" their attitude and it bit them. Now, third party AV software and MS themselves can't stop the onslaught. Apple has done updates much more pro-active to the system level because they watched and learned what delayed and casual updates can do. What most people don't realize, and something that MS learned was that third party AV software opens up other problems and creates situations that are more unsafe than if the 3rd party AV software had not been installed, in some cases. Apple learned and took a pro-active stand, which is seen and interpreted by some as an admission to insecurity, which is inaccurate in its purpose.
              Last edited by leehljp; 01-27-2010, 07:22 PM.
              Hank Lee

              Experience is what you get when you don't get what you wanted!

              Comment

              • OpaDC
                Established Member
                • Feb 2008
                • 393
                • Pensacola, FL
                • Ridgid TS3650

                #8
                Originally posted by leehljp
                Just as this thread starts out with the insinuation that "updates" = "unsecure". No Mac user says that there will not be a virus some day. There have been Proof of concepts already there.
                Nowhere did I insinuate updates = unsecure. How on earth did you ever come up with that? Conversely, it shows how important it is to update all the time.
                Both links show how important it is to update, but just like anti virus software, quite often they aren't done until after the fact. I posted this because I constantly see posts on various forums where people say to get a MAC because it is completely safe.
                BTW, in my house I have 2 Macs and 3 PCs. I have also worked on literally hundreds of both professionally. I'm not new to this game.
                _____________
                Opa

                second star to the right and straight on til morning

                Comment

                • sparkeyjames
                  Veteran Member
                  • Jan 2007
                  • 1087
                  • Redford MI.
                  • Craftsman 21829

                  #9
                  Most PC Users have a false sense of security with their AV software. AV software is not for future created viruses. Current installed AV software is absolutely no protection for the "next to be created", even in its best heuristic state. AV software is protection for those already created, not future new viruses. False sense of security through out the PC world. To put this in other words: With the best commercial AV software, it is not safe for the "next" virus until after a definition is written, it is downloaded and installed by the end user. (Some AV software checks automatically on a time schedule) Try to tell this to the average AV user and they will just say "HUH?".

                  This could not be more true. I see this all the time with so called windows power users. The "I never get virus infections because I keep my virus scanner up to date" crew then get the rude awakening when their anti virus fails to catch that 1 day old virus. The only way something like this can be avoided is for software makers to do thorough code reviews of what they produce. Fat chance of that though as it takes resources to do that. Heaven forbid they should take any money from the shareholders to make users computers safe from virus writers. I think you can pretty much guess I'm talking about Microsoft here.
                  Last edited by sparkeyjames; 01-27-2010, 08:53 PM.

                  Comment

                  • crokett
                    The Full Monte
                    • Jan 2003
                    • 10627
                    • Mebane, NC, USA.
                    • Ryobi BT3000

                    #10
                    Originally posted by sparkeyjames
                    . Heaven forbid they should take any money from the shareholders to make users computers safe from virus writers. I think you can pretty much guess I'm talking about Microsoft here.
                    How exactly would they do that? A virus is executable code, just like any other program. How do you propose the OS developers detect that it is a virus and not another benign program? The best defense against viruses is a vigilant user. Don't use your computer as admin, create a limited account and use that for day-to-day. Be careful where you download files from and keep your antivirus programs up to date.

                    Now if you mean vulnerabilities in the code that hackers can exploit, then you do have somewhat of a point. I don't use IE, Outlook or most other MS software because of the hooks it puts in the OS and it makes it that much easier to exploit flaws that should not be there.
                    David

                    The chief cause of failure in this life is giving up what you want most for what you want at the moment.

                    Comment

                    • sparkeyjames
                      Veteran Member
                      • Jan 2007
                      • 1087
                      • Redford MI.
                      • Craftsman 21829

                      #11
                      Originally posted by crokett
                      Now if you mean vulnerabilities in the code that hackers can exploit, then you do have somewhat of a point. I don't use IE, Outlook or most other MS software because of the hooks it puts in the OS and it makes it that much easier to exploit flaws that should not be there.
                      This is exactly what I'm talking about.

                      Comment

                      • crokett
                        The Full Monte
                        • Jan 2003
                        • 10627
                        • Mebane, NC, USA.
                        • Ryobi BT3000

                        #12
                        I'm sure MS makes every effort to release secure code, the problem is there are a lot more hackers out there finding the vulnerabilities. Plus the user bears some responsibility to keep his machine up to date.
                        David

                        The chief cause of failure in this life is giving up what you want most for what you want at the moment.

                        Comment

                        • dbhost
                          Slow and steady
                          • Apr 2008
                          • 9555
                          • League City, Texas
                          • Ryobi BT3100

                          #13
                          Originally posted by OpaDC
                          What, no mention of Red Hat or Ubuntu? They have security update packages this month too...
                          Please like and subscribe to my YouTube channel. Please check out and subscribe to my Workshop Blog.

                          Comment

                          • dbhost
                            Slow and steady
                            • Apr 2008
                            • 9555
                            • League City, Texas
                            • Ryobi BT3100

                            #14
                            Originally posted by crokett
                            I'm sure MS makes every effort to release secure code, the problem is there are a lot more hackers out there finding the vulnerabilities. Plus the user bears some responsibility to keep his machine up to date.
                            FWIW, one of the big problems is the way most Windows PCs are run. The majority of Windows PCs I have seen, have the primary user running in the administrators group, with elevated permissions. Kind of like running a UNIX as root. Down right stupid. This makes it brain dead easy to write code to take over the machine, just get the user to run the code, intentionally or not and that code runs with the higher permissions than it really ought to have... So yes users bear some responsibility to keep their machine up to date, they also bear a LOT of responsibility to configure their machines securely, and run the machine with the least permissions neccesary to get the job done...
                            Please like and subscribe to my YouTube channel. Please check out and subscribe to my Workshop Blog.

                            Comment

                            • crokett
                              The Full Monte
                              • Jan 2003
                              • 10627
                              • Mebane, NC, USA.
                              • Ryobi BT3000

                              #15
                              Originally posted by dbhost
                              So yes users bear some responsibility to keep their machine up to date, they also bear a LOT of responsibility to configure their machines securely, and run the machine with the least permissions neccesary to get the job done...
                              This is true and I noted it in an earlier post. MS could take the Unix approach and provide a default account called Adminstrator or something, then force the user to create an account that is a limited user rather than an administrator. Also, an equivalent to sudo would be convenient, else users will just run as administrator all the time.

                              The problem is that of Windows PC users need to be protected from themselves, as it were. Most *nix users have to know something about computers and in the process learn at least the basics about computer security. On the whole, Mac users do too. I don't know what the default is for user permissions on a Mac but I'd guess that it is a bit more secure given it is Unix based. I'm not sure that Macs are more secure, just that there are less attacks being written for Macs.
                              Last edited by crokett; 01-28-2010, 09:31 AM.
                              David

                              The chief cause of failure in this life is giving up what you want most for what you want at the moment.

                              Comment

                              Working...