Wait, so they're phasing out Windows for security reasons, and moving to Mac instead? It at least made sense when they were moving to Linux or ChromeOS, but OS X's security track record as of late is far worse than Windows.
Wait, so they're phasing out Windows for security reasons, and moving to Mac instead? It at least made sense when they were moving to Linux or ChromeOS, but OS X's security track record as of late is far worse than Windows.
Mac isn't significantly more secure. In fact, after all the bad press, Microsoft has invested significant amounts of money on intrusion mitigation systems like address space randomization, non-executable stacks, and so on. Linux is playing catch up to Windows in some regards there, and from what I know about OSX, it's also far behind in intrusion mitigation techniques. (edit: here's a blog post that covers some of them: http://blogs.msdn.com/b/michael_howard/archive/2006/05/26/ad...)
There are perfectly good reasons for switching to OSX (like, for example, the fact that the interface isn't a pain to use, and the command line doesn't suck, although I still favor Linux with a good tiling WM), but I don't think security is a valid one.
You liked to an article that says "there once existed a vulnerability in Safari" and then right away claimed that Linux and OSX are "still catching up to" Windows in terms of security. Now, I want to believe you, but it sounds to me like you're speaking with a little too much conviction relative to the evidence you're presenting.
http://web.archive.org/web/20080111062141/http://www.matasan...
Another (fairly poorly written) article about it: http://www.tomshardware.com/news/hack-windows-security-snow-...
I'm sure you can find more if you dig around.
Also, non-executable stack has been supported OSX since it was shipped, but non-executable heap is new. I believe (I'm not sure) that non-executable stack is also disabled fairly often because of trampolines in GCC.
Security in OSX isn't broken, of course, but the mitigation measures are strongest in Windows, out of the mainstream OSes these days.
MacOS -- and I say this as a long-time user, since the System 6 days, and as an OS atheist -- only seems to have a better security track record in the minds of users because it hasn't been targeted anywhere near as much as Windows has.
As far as Google is concerned, they may just be banking on security-through-obscurity. Use a system that the bad guys aren't familiar with exploiting, and you're less likely to be exploited.
On Linux, if someone hacks my browser all I could ever lose is the stuff on my home directory. Should that happen, I can just log in as root, kill all processes of my user account, rm -rf the home directory and restore the most recent backup, and relogin with my account. Without rebooting.
There are local vulnerabilities that might give you root privileges on Linux, too. But that's already a secondary attack and one of its own. Given the diversity of various Linux builds, it takes a lot more to crack into a machine and if successful, even that one is only one kind of a machine. With Windows, the homogeneity sweeps large installation bases at once.
Of course these tend to be precisely the only things you actually care about in the whole system. Assuming it's a desktop machine of course.
This doesn't mean your backup couldn't get infected...
It's the long, painful reinstallation process that I would have to do on a typical Windows machine to fully restore the pristine installation state after a virus/malware attack.
The only thing you can do with root that you can't do with a user account is write vanity malware that persists in ways that are harder to detect. But the most effective malware isn't written as a vanity exercise.
In Google's case, it's even less important to have root; what Google is protecting is access to their corporate network.
So, to a good approximation, you can say that the command line is based on BSD, and the rest came from NeXT and Apple, with a bit of GNU mixed in.
The BSD heritage is rather insignificant when it comes to security, since the largest attack surface comes from Apple applications like Safari, or the file manager, or other apps the end user uses directly on a regular basis.
My mistake.
UNIX 03 certification means MacOS X is a UNIX. It doesn't say anything about its status as a BSD though.
I had to dive into it headfirst for a Black Hat presentation in 2007, in which we loaded probes into a running xnu kernel to detect hypervisors. I was surprised by how easy it was to navigate based on my familiarity with FreeBSD's kernel. Obviously, there's quite a bit of non-BSD code in OS X, but for anyone who has worked with a BSD kernel before, the similarities are impossible to miss.
Hell, even if you can't read kernel code, the fact that OS X has sysctl, doesn't have proc, and debugs with ptrace() doesn't tell you anything?
Popularity is unrelated to quality of code.
While it is true that popularity = bigger target = more incentive to attack the platform's security, it is also often used as an excuse to try to hand-wave away bad, insecure code.
Another platform becoming more popular would indeed mean that it would have more people targeting it. But it does not, in any way, mean that the people would have the same level of success exploiting it as they do Windows.
We could probably safely expect that the platform would be successfully exploited more than it currently is. And people that think OS X is a security panacea are living in a fantasy world. But the argument that "[i]f everyone jumps to another OS so will the security problems" is a woeful oversimplification, and confuses two separate issues.
Also, as a side note, people seriously underestimate the level of incentive that currently exists for targeting non-Windows platforms. It is not the case that the incentive scales proportionally to audience size. Any sufficiently popular platform is a desirable target to attack. It's not like a platform has to have 90% of the market to be worth the effort. The relative ease of attack is a far more important factor than the potential audience size once we're talking millions of users.
As for the rest of your comment: both Windows and OS X are conventional monolithic operating systems written in C with core facilities designed and built in the '90s. Both are multiuser operating systems repurposed for single-user deployments. Both have strong kernel/userland barriers with well-defined interfaces. In fact, if you've done systems programming on both, they simply aren't all that different, even to a software developer.
But: for the past 10 years, Microsoft has been getting hammered by attackers, and has the benefit of a decade-long trial by fire. So when Microsoft randomizes library offsets, they don't (for instance) miss the entire runtime loading subsystem.
Also: most of Microsoft's most sensitive application code is written in C for WinAPI on x86, which is one of the best-understood application runtimes in the world. Much of OS X runs on cross-platform Objective C, which has received nowhere nearly as much research. Put simply: nobody knows how to write exploit countermeasures for OS X. I think mostly because nobody cares.
(Again: I say this as a Unix dev from '93 at a company standardized on Macs).