Something for mac users to consider

alexkidd

D.O.N.K.E.Y.
Messages
2,823
Name
Alex
Edit My Images
No
http://blogs.zdnet.com/security/?p=2941

:)

"Why Safari? Why didn’t you go after IE or Safari?

It’s really simple. Safari on the Mac is easier to exploit. The things that Windows do to make it harder (for an exploit to work), Macs don’t do. Hacking into Macs is so much easier. You don’t have to jump through hoops and deal with all the anti-exploit mitigations you’d find in Windows."
 
Not this old chestnut again. :yawn:

I've yet to meet anyone who has suffered any form of malware on a mac. Warning people about 'vulnerabilities' on a mac is a bit like telling them of duststorms on Mars.
 
not someone moaning about someone pointing something out about macs that isn't pure bumming again :yawn:

and that hardly works, people do use macs whereas people don't live on mars?
 
Not this old chestnut again. :yawn:

I've yet to meet anyone who has suffered any form of malware on a mac. Warning people about 'vulnerabilities' on a mac is a bit like telling them of duststorms on Mars.

I love this attitude!! "I've got a MAC and it's unhackable because none of my friends have had any problems."

Yet.

The majority of hackers are after one thing: Recognition. As soon as MACs become really popular, they will move on to them.

Same goes for Linux based Server OS's - when they become mainstream hackers will concentrate on them.
 
This realy depends how you view computers. In my office here I have 5 PC's and will soon get a few mac's. Only 1 PC is internet facing.. meaning we can do what we want with the rest of the pc's on the network. When we get the Mac's, we will put one on the internet network, and one on the internal network. If you have good internal hardware and software firewals, and policies which ensure you back things up, update AV, quarantine new files etc.. Not much can go wrong

Our donkey machine that faces the internet can be remastered in 20 mins, and we have a disk that drops on all the software we want on it.

What this means is that we have 2 machines that do all the work, 1 for admin, and a old machine to view webpages with a really old selection of browsers on - thta have no exposure to all the online hassles
 
Not much can go wrong

Complacency is the vulnerability all hackers/virus creators use regardless of their entry method of choice, or platform target.

Unless the internet facing PC's are completely segregated and will never be on the other network, and never swap media (CDs, memory sticks etc) always be prepared for the possibility that something can happen.

I've seen situations where companies refuse to believe they have been hacked/infected because their security is "so tight". An analogy I use with this is an umbrella with a tiny hole in it - it looks like a perfect umbrella, until it starts to rain - then it leaks.

Smaller organisations are less at risk from a specific hacking attack, unless the hacker needs or wants something from them, or needs to access them as a through route somewhere else.

They are VERY at risk of virii and other infectious software though, which may be sent in a more general manner.

Mac operating systems are no different to MS operating systems, or Linux - they all have vulnerablilities which will be taken advantage of.

The issue today is that MS has numbers against it. It won't be long before Mac OS's have a higher market share and present a more interesting challenge.
 
Now I throw my hands up, all this hacker talk goes right over my bonce but in the four years of using apple systems I have never had a virus.

Would this be because there is no interest from the hacking types or nothing to gain or what? I've never really thought too much about why viruses exist, who makes them and why do they do it?

When Mr Charlie Miller mentions that mac's/safari is so easy to exploit and windows is so much more difficult, not that it's relevant but I've found the precise opposite in terms of successfully getting a task performed without issue.
 
why do mac users insist on sticking their heads in the sand over this? theyre keen to rant on about how popular macs are getting but fail to see that the drawback to this is increased interest from hackers.

Would this be because there is no interest from the hacking types or nothing to gain or what?

basically where macs had such a small market share compared to PC in previous years. but now its changing so WILL the malware interest.
 
basically where macs had such a small market share compared to PC in previous years. but now its changing so WILL the malware interest.

Awesome. Another pointless excretion from the wonderfully intelligent human race.
After all the advertising campaigns in this world and the way it's forceable rammed into our lives via paper waste, telesales and commercial breaks lasting over 8 minutes long, I honestly couldn't think of another more useless creation, now after briefly reading about 'malware' another one goes in the pile. :cuckoo:
 
Windows OS is used by 93% of the planet
Mac shares 7% with Linux and misc

I suppose you'd have to get inside the head of a loon to figure out why a loon would want to spread viruses, I guess part of it at least is about notoriety, nobody will give two farts that 13 macs went tits up, they do however when 40 million pc's do.
If I was looking to hack somebody's bank account, I'd try to give myself the best chance of completing that task, do I learn Windows hacks or mac hacks, gotta be windows, mac users have no money they spent all their cash on......a mac :lol:

nah, but seriously, Mac have the jump on Windows, I'd expect them to be fully prepared for malicious attacks, when they do start rolling in.
 
nah, but seriously, Mac have the jump on Windows, I'd expect them to be fully prepared for malicious attacks, when they do start rolling in.

They may have the jump on Microsoft - it's less likely that they will be one up on the hackers/virus developers.
 
They may have the jump on Microsoft - it's less likely that they will be one up on the hackers/virus developers.

I have to disagree there, the iPhone has been hacked quite easily over the last few years but then Apple have easily cut off the leaks with a release. The latest 3G iPhone has been overcome with another update release that the crackers are nowhere near breaking yet so I wouldn't undermine Apple at this moment in time.
 
Complacency is the vulnerability all hackers/virus creators use regardless of their entry method of choice, or platform target.

Unless the internet facing PC's are completely segregated and will never be on the other network, and never swap media (CDs, memory sticks etc) always be prepared for the possibility that something can happen.

I've seen situations where companies refuse to believe they have been hacked/infected because their security is "so tight". An analogy I use with this is an umbrella with a tiny hole in it - it looks like a perfect umbrella, until it starts to rain - then it leaks.

Smaller organisations are less at risk from a specific hacking attack, unless the hacker needs or wants something from them, or needs to access them as a through route somewhere else.

They are VERY at risk of virii and other infectious software though, which may be sent in a more general manner.

Mac operating systems are no different to MS operating systems, or Linux - they all have vulnerablilities which will be taken advantage of.

The issue today is that MS has numbers against it. It won't be long before Mac OS's have a higher market share and present a more interesting challenge.

I agree - and that is why our systems are in place.

1. These non-internet facing machines are fully patched and have individual firewalls and up to date AV and Spyware protection

2. Everything that goes anywhere near these machines is scanned on the machine they are comming from, and again on the machine they are going too

3. We have a very efficent (and proven) on and off site backup regime, which includes the software and the data

We have a strong IT background, and provide a consultancy service to small / medium businesses about things like this.. This is exactly why we choose to do our work, on a closed network. With all these things it is a case of risk management. We have even gone to the extent of disabling the front USB ports to prevent visitors causing us issues
 
I have to disagree there, the iPhone has been hacked quite easily over the last few years but then Apple have easily cut off the leaks with a release. The latest 3G iPhone has been overcome with another update release that the crackers are nowhere near breaking yet so I wouldn't undermine Apple at this moment in time.

thats kinda the way MS works too, they release fixes for security flaws.

Following the link it looks as though Windows isn't imune either, including Windows 7

http://blogs.zdnet.com/security/?p=2934

oh noes, windows isnt hacker proof! :bonk:

seriously though, windows 7 is still in beta and IE8 is still fresh out of the box. not that im defending them because there will be security fixes throughout the lifespan of both products.
 
By all reports, the entrants to this competition are allowed to prepare weeks before the competition and is no more of an exploit than clicking on a link using Internet Explorer that installs malware/spyware. Essentially, it's not really something to get too concerned about.

This Charlie Miller guy is paid (not by Apple) to find exploits in Safari and pretty much nothing else. He's refused to give details on the exploit to Apple unless they stump up a wedge of cash. I'm not concerned, just wary (as always) on what links I click on, as should everyone.
 
There are always going to be security risks with any software, especially large, complex software such as Operating Systems.
If anyone here is a programmer (and I know there are a few), we all know how easy it can be to make a mistake while writing code and with OS's, there are multiple groups of programmers writing different modules/sections of the OS (each with their own style of coding). The risk of the code clashing and causing errors is very great and as a result there will be plenty of holes in the software which hackers can exploit.
Usually, hackers spot a hole and exploit it, then the software creators have to create a fix for it, it's just a cat and mouse game.

The ideal situation would be that the programmers make no mistakes or manage to find a hole and fix it, before it's taken advantage of.

There is always an argument over Windows and Mac and I have used windows for years but even keeping windows tuned up, I spent a lot of time fixing errors and since I've had a Mac, it's just been hassle free and I can get on with what I'm supposed to be doing!

What's better, windows or Mac? It depends on your needs and your opinion :)
 
By all reports, the entrants to this competition are allowed to prepare weeks before the competition and is no more of an exploit than clicking on a link using Internet Explorer that installs malware/spyware. Essentially, it's not really something to get too concerned about.

:thinking:

because the hack was prepared in advance it doesnt make it an issue worth worrying about?
 
I have to disagree there, the iPhone has been hacked quite easily over the last few years but then Apple have easily cut off the leaks with a release. The latest 3G iPhone has been overcome with another update release that the crackers are nowhere near breaking yet so I wouldn't undermine Apple at this moment in time.

That just confirms my post though - the fact that they have patched it means it was hacked in the 1st place!

It's something MS have been slagged off for over the years - producing patch after patch after patch. In the coming years, we'll see how other manufacturers cope with the level of demand as their products gradually take a larger market share.

Interesting times ahead.
 
Back
Top