New Mac Ransomware Is Even More Sinister Than It Appears
wired.com
wired.com
Just because an application is signed with a developer ID is little guarantee that it’s trustworthy. And stuff from the App Store won’t hold your Mac up for ransom, but fairly concerning software has slipped past review.
People are poor at evaluating risk, especially outside their areas of expertise. Getting software only from reputable sources is an EXCELLENT way to avoid malware. I'm not sure what your comment adds here.
https://www.hackread.com/apple-removes-anti-malware-apps-for...
Personally I have to agree with your thoughts and I stopped torrenting years ago out of fear of a ransomware and only buy legitimate software. Younger me was not able to afford that and my security suffered as a result.
https://en.wikipedia.org/wiki/Mac_Defender
https://www.macstories.net/news/apple-promises-os-x-update-t...
You wish, the Xcode ghost infected apps had 500m installs in total.
They were silently removed.
A malicious developer is unlikely to provide valid credentials.
Thats exactly what code signing is though. A little splish splash of encryption and you're sure that the Dev is part of the Apple Dev program. However trustworthy could mean many things from code thats not buggy to code thats simply not malicious. However code signing absolutely introduces a layer of trust.
Code signing is obviously going to be necessary at all steps, just not via Apple.
(I also note that Teams would only install for all users of the computer, not for the person currently logged in, which I thought was strange, but it's my company's computer, so I don't care that much.)
It's far better than random pirate-ware tho...
I think this is only true if you define "little" as "not a 100% gold-plated, certified FDIC-insured guarantee."
In most contexts, saying something is "little guarantee" means it's worthless. And, as frequently documented on HN and elsewhere, that's simply not true.
Apple has ways of punishing a publisher who is up to no good (and as we've seen, some publishers who aren't), so I can always run and tell mommy.
We didn't have walled gardens and we were fine. We had nasty viruses back then too, even some that would cause physical damage to your hardware.
Where is the personal responsibility to make sure you have backups and not install every crapware found on the web?
Are we going to require warning labels on your computers that can't be removed like airbag labels on cars soon?
I don't want a large corporation deciding what I can install and what not.
Our entire lives are now handled online, which makes cyber crime much more rewarding. Businesses rely much more on the internet. On top of that, cryptocurrency makes it way easier to monetize compromised systems, either via ransomware or via crypto miners. Malware has simply become much more lucrative to criminals.
I was about to say your memory of 20 years ago is very different from mine, until I saw
> We had nasty viruses back then too, even some that would cause physical damage to your hardware.
If that’s your idea of “fine” I’m not sure what to say.
You don't remember the drive-by downloads on windows xp? Or are we only talking about macs?
While the same is /still/ true it is less so now.
Yes.
> Or are all the components previously unseen?
Not really.
From TFA:
"My current gut feeling about all of this is that someone basically was designing a piece of Mac malware that would give them the ability to completely remotely control an infected system. And then they also added some ransomware capability as a way to make extra money."
That basically described how ransomware was born, god knows how long ago.
IMO the better question is why the hell attackers targeting macOS haven't been doing this until now (if we take their word for it).
> is there some reason the interviewees and reporter imply this is a mystery?
I suspect the reason is boring: they want to grab eyeballs.
FWIW, I would bet that 25% or more of all enterprise Macs are also going to be running homebrew and a ton of standard unix software.
Is that based on anything much, or is that just a bit of prejudice? Where I work its the PCs that are used as basic e-mail/word/browser machine - the Macs are used by people who are doing a bit more.
that seems like a particularly expensive device for only internet browsing.
>The strength of Apple products is to be perceived as a higher value thanks to design and marketing. People would buy a Gucci t-shirt for 300$, it's also particularly expensive for a t-shirt. At this point people don't buy the product for its intrinsic value, but for status and perceived value.
[0] https://www.dailycal.org/2013/07/19/kanye-wests-ridiculously...
Sure you might have a few benefits, but you must deal with unavoidable pains at every turn.
Ubuntu desktop... I tried multiple times across multiple decades, I've given up.
Not sure what Windows issues exist outside licences disappearing upon reformatting. But that's still exponentially cheaper to fix then any Apple product.
well, perhaps not for you and I guess not really, in my experience, for me, but I have noticed that the population at large seems to suffer recurrent damage related to some ancient decisions made regarding Windows security.
5k & 4K screens, aluminum bodied laptops, MagSafe connectors, MacOS, high performance SSD read/write speeds, T2 onboard security, fusion drives, etc, etc,
People pretend design and development is free, then bitch about their plastic crap cheap laptop.
They've been doing it for a while. Mac has been since the platform with the most malware since the past year or two. It's outclassed Windows.
Adware is more widespread (changing browser homepage, injecting ads, paid popups), I think it makes more money on a regular basis than bricking laptops.
I know people talk about finance classes in schools, but I think we urgently need marketing classes. Companies have entire departments learning how to exploit your psychology and if you haven't seen the basics of marketing, you are ripe for pickings.
The people getting infected are the people that are knowingly bypassing all of the security measures Apple put in place to protect the uneducated users.
If a user stays in the Mac App Store, or just doesn't bypass various warnings and macOS security mechanisms, they won't be susceptible to this malware.
Not that mac security mechanisms are perfect, but this is among the ones they protect you from.
We had these in elementary school. Endless drills from the nuns about fact vs. opinion in things we read.
But that was back in the ignorant, backwards days when schools still taught geography, home economics, Latin, civics, theology, philosophy, and spelling.
/I can diagram a sentence in my mind as you speak it.
From my observations, most people who buy Macs tend to have good finances, and are probably more likely to pay a ransom (and at a higher price) than most of the people who use Windows or Chromebook users.
"My current gut feeling about all of this is that someone basically was designing a piece of Mac malware that would give them the ability to completely remotely control an infected system. And then they also added some ransomware capability as a way to make extra money."
Honestly I kind of feel like the opposite is probably true. The ransomware is the primary money maker and the backdoor stuff is there just in case there is something interesting to extract if the main money play doesn't net you anything.