Apple Mac computers targeted by ransomware and spyware
bbc.co.uk
bbc.co.uk
At this point we need to accept that severely locked down and curated devices are the easiest and least painful road ahead for the majority of the world's citizens to participate in digital transactions, while unrestricted computing devices can used by those who are learning or specifically involved in technical tasks or are simply those who agree that they know what they're doing and the tradeoffs involved.
Am not saying unrestricted devices should be banned. It's just that they should come with warnings on the box and an advisory to use locked devices if the intent is to simply buy it and mindlessly use it.
The boot screen coming up each time if I put my machine into dev mode is something that really icks me. At least, I should be able to switch it off (without resorting to EFI hacks). Also, it's really easy to wipe your device on that screen if you accidentally press the space bar.
If that one screen was a bit more configurable and the driver situation was a little bit better (less blobs/hacks), my ARM-based chromebook would be my daily driver by now.
The big fear shouldn't be that you won't have anything to run so much as the idea that popular general Operating Systems in the future will integrate too many advanced features and introduce hurdles to general interoperability that makes it harder for open source alternatives to be useful.
So far it hasn't been too big of a problem, but if operating systems start being augmented by substantial amounts of AI or machine learning derived efficiency improvements upstarts might have trouble keeping up, but I wouldn't count out the creativity of the Open Source community to address these issues.
You can have a machine where you are actually more free to experiment than simply being unrestricted. If you have a machine where you can roll back changes to a saved point, you are more free to experiment, even with dangerous and esoteric mechanisms. This is what we had in Smalltalk. Smalltalk used to be an OS. (There are 4 hooks in the old Smalltalk-80 image for lifting the drive head, putting it down, and moving it in and out.) When I used it, it was no longer an OS, but this is how I know that doing
Semaphore allInstances do: [ :each | each release ]
Locks up your image so hard, there's often lag when you try to kill the VM process. I can do that with un-checked in code in the image, then restart from a saved image, replay all of my actions from the change log except for the last one, and I'm back in seconds, all of my code nice and safe.This degree of rollback ability would also be great for simplifying parental IT. You'd need to add some sort of cloud storage for storage of authentication secrets and the most important data, but then it would be almost bulletproof.
That's the whole point of having certain things in the cloud!
nor should the billions of people not have privacy
You can have a relatively open machine that implements rollback mechanisms using local storage and have privacy just fine. Did you just have a reading comprehension failure?
In the hands of corporations and governments, imposed on individuals, this becomes DRM and is clearly horrible. It's so horrible, there should be laws heavily regulating it's use by organizations against individuals. However, the same asymmetries that make the issues of disclosure and privacy different between corporations and individuals also make trusted execution different between corporations and individuals.
It's bad for society and individuals when individuals have their information disseminated against their will. However it's very good for society when corporations, governments, and other organizations are required to be open and disclose information. This is why Trusted Execution should be used by individuals against organizations. Aimed in that direction, it compensates for the power differential. Used as DRM, it exacerbates it.
Trusted Execution combined with sandboxing can provide individuals with very good protection against things like malware and the Sony rootkit. My ideal PC would have an inviolate hypervisor kernel supervising an open "dev" VM which can be rolled back, along with various "appliance" VMs where sandboxes with Trusted Execution can protect the individual from the execution of other people's code.
It doesn’t seem unreasonable to think iOS devices will replace 95% of all Macs, with exception to professional users who need massive workstation resources, unfettered system access, etc.
I don’t recommend Macs to family or friends anymore, they’re completely unnecessary. The new iPads with the keyboard are enough for normal people. That trend seems to be solving the problem, gradually, leaving the technical system for technical people.
http://www.bromium.com implements that approach within Windows.
What about what that curation entails. Should I be forced to watch ads the manufacturer sends me before I can do anything? Should I be forced to pay a rental fee or lose all access to my data? Should all financial transactions be controlled by the manufacturer's prefered system?
The problem with walled gardens is lockin and shareholders would be irrational not to encourage the manufacturer to maximize the profit they can extract from each device. I don't want a device where my every interaction is controlled and monetised to maximize my consumption.
I beg to disagree. Ubuntu for example has apparmor enabled by default [1] and snaps running in containers [2]. And compartmentalization is a huge part of the linux kernel [3].
---
[1] https://en.wikipedia.org/wiki/AppArmor
Ubuntu snaps are not sandboxed yet [1]
Containers just offer just the same environment as a normal unix. Kernel apis like e.g. Video4Linux or even more basic stuff like the filesystem are not designed for this. How does an app ask the user for permission to use the camera? How does an app ask to open a file outside of its sandbox? Basic things like that are just handwaved away or implemented with extremely complex systems that regularly have security holes.
[1] http://www.pcworld.com/article/3063134/linux/ubuntus-snap-pa...
That's quite a blanket statement: of course they are. Snaps are sandboxed by a set of interfaces requested by the snap in question. If the snap requests networking, it gets networking. If it wants to access the sound card, it gets the sound card. Some of these interfaces are more powerful/dangerous than others. If the snap requests X, it gets X. That makes that particular snap certainly less safe, but it says nothing about snaps that don't use the X interface at all. The user can also disallow access to X (though that probably makes the application less useful) by disconnecting that interface: snap disconnect <snapname>:x11
http://blog.jacobtorrey.com/langsec-taming-the-weird-machine...
I use Little Snitch configured in Silent mode to Deny All and then I allow only the things I want to go outbound out of my machine (though I do let my machine talk to my home network freely). You might want to consider that.
I also use Avast's free antivirus for the Mac, but with the Email and Web shields off. I find that overkill when I have the File shield (real-time protection on file access) already enabled.
[1] http://nullrefer.com/?https://www.jwz.org/doc/backups.html
(Edit: fixed the referrer to the jwz page)
Try this instead: http://nullrefer.com/?https://www.jwz.org/doc/backups.html
every month I have to go in and clean it up - Malwarebytes gets rid of most of the browser trub - to the point Chrome is usable again
they are casual browsers - something is very wrong when kids can render a Chrome install unusable after an hour or so of clicking flashy things
it's completely and utterly broken
Has the original meaning of the word been lost?
1. Set them up with managed accounts 2. Use parental controls to stop them from installing things 3. Set the default browser to Safari which works better with Parental Controls 4. Try using the Parental Controls automated web filter. It's pretty good and not too stringent. 5. TALK to your kids about the importance of NOT simply clicking indiscriminately on random stuff.
the OSX parental controls break Chrome - or did when they were on - and were overly intrusive - if you're typing in the password every 10 mins you might as well not have one - the parental controls on router don't work with HTTPS
what I need is Google Account / Chrome setup that is age aware and:
1. filters search results on age of user
2. downranks sites that prompt to alter configs or force email address to run a game
3. enforces strict content (not just on results, but also on what Chrome will render)
4. locks down Chrome config
5. filters gmail more aggressively than it would for an adult
6. notifies adult user on suspicious activity (not reports sites visited etc. but reports if something serious happens)
0. Use Safari not Chrome
5. Use Mail.app rather than the Gmail web interface. Parental controls then let you whitelist addresses that the kids can use e-mail with you can set it up so that if they ask t e-mail someone new, they can request it and you'll get an 'allow/deny pop up.
6. Set up a free OpenDNS account for use on your kids machines and set up a profile for use with them (you can adjust strictness and alerts you want to receive).
7. Once again - talk to your kids. Explain that if they click on something that requests this kind of thing, they are not to run it. Running it will result in reduced computer time and privileges. Ultimately technology can only help you parent, it cannot do it for you.
I never had a single piece of malware on any of these machines, ever. I do see lots of SSH login attempts to the servers (in vain, naturally) and quite a bit of exploit scanning for vulnerable services but the amount of successful intrusion attempts, whether on client or server, is zero.
Maybe you should to try this solution for your children?
AV-Comparatives[1] puts out a pretty comprehensive, quantifiedm real world benchmark of antivirus comparisons that they update every month for Windows (a more dynamic threat environment) and once a year for Mac[2]. Let's take a best case scenario (which isn't likely) that there are _no_ security vulnerabilities in any software on macOS. You still have the issue of being an accessory to spread malware to Windows machines if you aren't screening for them. "Oh hey boss, include this file in the Windows deployment of our software".
A biological equivalent would be, even if you are an asymptomatic carrier[3] (macOS claim) you can still transmit the disease to someone else, therefore should limit transmission through condom use, gloves, general precautions (run an antivirus)
A final point to add is one regarding risk engineering. The decision to increase the robustness of a design is not governed by the probability of the event (Mac's hardly ever get infected!), it is governed by the magnitude of the effect of the event. Even if the probability of malware on a Mac is low[4] if the effect of the infection is catastrophic (your entire business is destroyed) you should be increase the systems robustness to threats.
[1] https://www.av-comparatives.org/about-us/ AV-Comparatives is an independent organization offering systematic testing that checks whether security software, such as PC/Mac-based antivirus products and mobile security solutions, lives up to its promises. Using one of the largest sample collections worldwide, it creates a real-world environment for truly accurate testing. AV-Comparatives offers freely accessible results to individuals, news organizations and scientific institutions. Certification by AV-Comparatives provides an official seal of approval for software performance which is globally recognized.
Currently, AV-Comparatives' Real-World Protection Test is the most comprehensive and complex test available when it comes to evaluating the real-life protection capabilities of antivirus software. Put simply, the test framework replicates the scenario of an everyday user in an everyday online environment – the typical situation that most of us experience when using a computer with an Internet connection.
AV-Comparatives works closely with several academic institutions, especially the University of Innsbruck’s Department of Computer Science, to provide scientific testing methods.
[2] https://www.av-comparatives.org/wp-content/uploads/2016/07/a...
[3] https://en.wikipedia.org/wiki/Asymptomatic_carrier
[4] http://www.thesafemac.com/mmg-catalog/ https://en.wikipedia.org/wiki/MacOS_malware
• Work from an standard (non-admin) user account.
• Review the settings in System Preferences » Security & Privacy and pick a reasonable ground between convenience and security.
• At the very least, "Require an administrator password to access system-wide preferences" (found under the "Advanced..." button.)
• Be wary of any third-party app that asks for an administrator password, and try to see if it runs after denying the prompt. Dropbox, for example, seems to work fine even if I cancel its second (after installation) admin prompt. (There were news about it faking the prompt and storing your macOS password [2] for automatic updates...)
• You may want to tighten the firewall settings, and/or consider Little Snitch [3].
• If you have to install something from a .pkg file, which can autorun scripts, try to review the .pkg and its scripts with Pacifist [0] first. It may be possible to just extract the payload with Pacifist and run the app just fine without "installing" the .pkg.
• Make regular backups. Automatic (e.g. Time Machine) AND manual (of your most important stuff at least.)
• Don’t use the same passwords for different things.
• Enable multi-factor authentication on as many services as you can.
• Visit dodgy websites in private browsing mode, or a secondary, locked-down browser like Tor [1].
• If you can't help downloading pirated/"cracked" apps or games, try to run them from a different user account.
• If concerned about outright theft of your Mac, enable FileVault full disk encryption, and set a firmware password. [4]
• Whenever you're bored or something is acting janky, check the usual places where third-party processes can install themselves and hook into your system:
- System Preferences » Security & Privacy » Privacy » Accessibility
- System Preferences » Users & Groups » Login Items
- /System/Library/LaunchAgents, /System/Library/LaunchDaemons, /System/Library/StartupItems
- /Library/LaunchAgents, /Library/LaunchDaemons, /Library/StartupItems, /Library/Internet Plug-Ins
- Check for 3rd-party kernel extensions:
kextstat -kl | awk ' !/apple/ { print $6 $7 } '
• Oh and before you paste any command/script (like the above) from the internet into your terminal, see the man page for each command and its arguments first. :)----
I've used Macs without an antivirus since 2012 and I haven't been hit by malware yet... I think. :)
[0] http://www.charlessoft.com
[1] https://www.torproject.org/projects/torbrowser.html.en
[2] https://news.ycombinator.com/item?id=12463338 (How Dropbox Hacks Your Mac)
It's amazing how many Mac owners have this turned off. Why?
I'm not sure, but maybe simply turning the firewall on in macOS doesn't provide any benefit if everything else is fine, and you have to lock it down and disallow all requests by default to actually get added security through it.
Edited the recommendation after reading the sibling comments.
Wow, I've missed that. An example of the article:
http://applehelpwriter.com/2016/07/28/revealing-dropboxs-dir...
"note the ‘Type your password…’ sentence is both misaligned and is spaced into a separate paragraph, unlike genuine authentication requests from OS X. The phrasing of the first sentence “your computer password” is also very “un-OS X”."
- Use LittleSnitch or similar to block traffic per process
- Use ad blockers in your browser and make sure Flash, Java and Silverlight are off by default
- Do update regularly
If you care about security in case your device gets stolen
- Use full disk encryption
- Do /not/ forget to also set a firmware password
Let me add one:
- Not paste commands from the internet into your terminal.
This one's fine! I'm also nitpicking.
* allow
Tells RansomWhere it's ok to let the process continue running. This will be persistently remembered; you'll never be alerted about this binary again.
Not the best attitude to have when it comes to backups.
The paranoid list/methods in the sibling comment by Razengan is good, but you cripple and annoy yourself (no admin account etc).
https://www.alienvault.com/blogs/labs-research/macspy-os-x-r...
https://blog.fortinet.com/2017/06/09/macransom-offered-as-ra...
Well, who really cares about that? That's not an especially novel thing to do. It's basically a drop of spit in the ocean.
Someone wake me up when Mac malware goes viral because it's not entirely reliant on users making mistakes. Or if it uses some sort of vulnerability that I need to get patched.
> However, they added, any files scrambled with the ransomware would be completely lost because it did a very poor job of handling the decryption keys needed to restore data.
In past discussions of ransomware, the question is always asked: if you pay, how can you be sure you'll get your files back? The standard answer seems to be, of course you'll get your files back, the criminals want to keep a good reputation so you'll have the greatest incentive to pay, and they have no reason not to.
I guess this shows one potential weakness of that idea. Criminals may not want to destroy your files, but might do so by accident.
That said it's still easier to get something in the AppStore that really wreaks havoc on your machine compared to the iOS AppStore where developers being used to a completely free reign over the machine never was a thing to begin with.
( it's even worse in win10s )
If you want additional protection, I believe your best option is Avast:
http://www.tomsguide.com/us/best-antivirus,review-2588-6.htm...
[1] https://www.av-comparatives.org/about-us/ AV-Comparatives is an independent organization offering systematic testing that checks whether security software, such as PC/Mac-based antivirus products and mobile security solutions, lives up to its promises. Using one of the largest sample collections worldwide, it creates a real-world environment for truly accurate testing. AV-Comparatives offers freely accessible results to individuals, news organizations and scientific institutions. Certification by AV-Comparatives provides an official seal of approval for software performance which is globally recognized.
Currently, AV-Comparatives' Real-World Protection Test is the most comprehensive and complex test available when it comes to evaluating the real-life protection capabilities of antivirus software. Put simply, the test framework replicates the scenario of an everyday user in an everyday online environment – the typical situation that most of us experience when using a computer with an Internet connection.
AV-Comparatives works closely with several academic institutions, especially the University of Innsbruck’s Department of Computer Science, to provide scientific testing methods.
[2] https://www.av-comparatives.org/wp-content/uploads/2016/07/a...
Snarkiness aside, you don't need an antivirus on your Mac. As long as you run as a non-admin user, enable a firmware password, and stay away from Adobe Flash, you are golden.
Since you do need to install stuff sometimes, I'm not sure what a power user who's careful about password prompts would gain from routinely running as a non-admin.
And keep your system up to date of course (done by default, or at least the notifications to that effect). And don't use the admin user on a day to day basis (done by default).
Oh well, I'll keep going with my preferred platform: Windows as a host for my browser and SSH to FreeBSD and Ubuntu servers.
Still one of the biggest lies that Apple ever told.
The very first I'm Mac I'm PC was 100% about how they are virus free OS.
The ad also doesn't make the claim, just that Mac can't get infected by thousands of Windows viruses.
According to Woz the early Mac's held so much of the OS in ROM that a malware could not get a solid foothold.
That said, i have found Apple to be more of a marketing company dabbling in consumer electronics, than a computer company.
By the time it was retired, I seem to recall it acted on nearly 200 viruses and worms.
Might have been true for the really early Macintosh computers. Definitely not later on, though. Later systems stored an increasing amount of the System on the hard drive, and the NewWorld PowerPC Macs (iMac and later) moved the remnants of the ROM to the hard disk.
In the 1990s visiting a copy shop with Macs was like going to a sketchy by Thai standards brothel. You were almost guaranteed to come back with some new infection. You'd reasonably quarantine anything that came back from your print shop until you could scan it. The temptation to hold your Syquest disk with rubber tongs was there.
Switching the processor PowerPC made many of the viruses incompatible, but they weren't fully eliminated until the switch to OS X was complete.
One of the more ridiculous statements bought up about Apple.