Could be wrong, though.
To be honest I don't really care about some theoretical attack that almost certainly won't be used to target me, and if they do, they can have it. I'd rather have the performance.
Attacks don't follow the close-quarters-infection that physical viruses do, so it's a bad model to use.
https://www.cvedetails.com/product/156/Apple-Mac-Os-X.html?v...
https://www.cvedetails.com/product/32238/Microsoft-Windows-1...
https://www.cvedetails.com/product/17153/Microsoft-Windows-7...
But everyone here is already thinking about the string of recent macOS vulnerabilities. Even just in the past few months Apple has been hit by a bunch of fairly major vulnerabilities while Windows hasn't been in the news for a while. What bugs me though is that a theres a handful of the Apple vulnerabilities that weren't caused by an implementation error, it was from a flawed design.
In particular the most notable example of this would be the API used by system preferences that would let any user create arbitrary files with arbitrary permissions owned as root. Obviously the first choice with that is to create a setUID binary but even if the permissions weren't user provided this should be something that should jump out during the design process as a bad idea.
https://truesecdev.wordpress.com/2015/04/09/hidden-backdoor-...
As for a comparison of just recent newsworthy macOS vulnerabilities compared to Windows I'll just cite Hacker News as far smarter people than I have commented on this subject to death.
I just used the following query and only looked at the links on the first page.
https://www.google.com/search?q=site%3Anews.ycombinator.com+...
https://www.google.com/search?q=site%3Anews.ycombinator.com+...
macOS total karma 2345
https://news.ycombinator.com/item?id=15410953
https://news.ycombinator.com/item?id=15807913
https://news.ycombinator.com/item?id=15828767
https://news.ycombinator.com/item?id=15864637
https://news.ycombinator.com/item?id=15804726
https://news.ycombinator.com/item?id=16043578
Windows total karma 304
https://news.ycombinator.com/item?id=815265
https://news.ycombinator.com/item?id=2758554
https://news.ycombinator.com/item?id=10889728
https://news.ycombinator.com/item?id=13577709
The macOS results span the last 3 months, the Windows results span the last 8 years. Mac sales only provide about 8% of Apple's revenue which is overwhelmingly dominated by iPhone sales and app store revenue. macOS has become the red headed step child and it's really starting to show.
2. No one has to target you specifically, it's a matter of time until someone uses this attack vector on something everyone has -- a web browser.
3. Once you're owned, you're going to be sharing resources with a couple of bots, so don't be so sure you'll get to keep the performance.
Would throttling syscalls really prevent using these syscalls? Surely it would just make the exploits lower to perform? Is there something I've not understood, or is the idea just to throttle syscalls enough to make it infeasably slow? If it's the latter, remember that users might potentially be on a website for half an hour at a time (if they're reading a long article or watching a video), so an attacker (whose code is running on the site, potentially through a compromised ad/tracking platform, or just XSS) would have a lot of time to extract whatever memory they want.
That's only if you continue to participate in the shared delusion that the WWW can or should be a high-performance applications platform. Those of us who usually browse with JavaScript turned off can get along fine without SharedArrayBuffer or WebGL or WebSockets.
/grumble
I fully understand how much the world has invested in making the web into an applications platform, and I recognize that many things of value have been built on that platform. But it's been a fundamentally flawed enterprise from the start, and the pitfalls are getting harder to ignore. We need to start taking seriously again the idea that untrusted code cannot be trusted. We need to stop re-inventing the operating system within the browser just because some programmers are too lazy to port their applications to more than one OS even when there are libraries to abstract away all the differences that don't require a UI redesign. We need to stop sacrificing so much efficiency for the sake of portability that doesn't live up to its purpose.
In order for a web browser suitable for document-oriented usage with limited interactivity to be secure and offer reasonable protections for your privacy, it has to take measures that preclude it from being a good applications platform. That conflict seems irreconcilable.
Don't be ridiculous. I'm not saying we shouldn't have cross-platform apps at all. I'm just saying we need a clear distinction between the WWW and any applications platform, just like we need a clear distinction between sidewalks and freeways. The web browser cannot do both jobs well.
One problem is, no one seems to be able to define "web application" in a way that makes the distinction clear. Most sites that use javascript still use it in the context of displaying documents, so if you define any site that uses javascript at all as an "application," then most sites, including Hacker News, count as applications. But that doesn't actually fix any problems.
Web should stay as interactive documents.
WebGL is such high performance that most examples posted on HN struggle on my phone, where I routinely play OpenGL ES 3.x games without any visible jank.
Granted, not everybody: some are more than happy with interactive documents. Great, that's awesome, and I hope you're happy, but you don't get to dictate the behaviour of the 99%.
And that figure is not an exaggeration: for my own sites about 1% of people have JS disabled. This post from Yell, over a much larger sample of data, suggests that 0.07% of their visitors disable JavaScript: https://blog.yell.com/2016/04/just-many-web-users-disable-co....
Granted, a large portion of that 99% won't know or care what JavaScript is, but they'll care if they lose the additional functionality it brings to the sites they use (though, honestly, I doubt they'd miss the ads, for which it's so often misused).
Still, sites I use on a regular basis that benefit from JS: GitHub (most evident with real-time updates to projects, issues, PRs); Office365; GMail, Google Drive, Google Analytics, Google Docs, the Adsense and Webmaster portals, and - of course - YouTube; Clubhouse (project management, heavier than Trello, lighter than JIRA); Azure management portal; pipeline apps such as TeamCity and Octopus Deploy.
I am getting sick of what I presume is coin-mining code. I was reading an article about keyboards on some site the other day and after a few seconds my laptop started to sound like an aircraft taking off.
I believe there are valid usecases for not applying these patchws.
Imagine if a random bad advertisement or injected script on a popular website could silently steal all of your stored session information for other sites.
That's not to say it's not bad -- the exploit works remarkably well -- but it's not fast or easy.
FYI:
pti=offSee here:
/s
So being unsure about how many times you want to do a thing is a no-go too.
If the trip count isn't known at compile time? You should find out.