Apple to support reps: 'Don't confirm Mac infections'
theregister.co.uk
theregister.co.uk
I've done malware removal on 5-10 computers a day, 5 days a week for most of that time. So I've seen thousands of malware infections on the average consumer's computer. I've seen more different malware infections than just about anyone outside of an antivirus research lab.
When I first started most of malware came from users downloading files from P2P sites. However, for the last 2 years nearly all the malware I found was installed via a drive-by download that happened without user input.
You can talk all you like about avoiding porn sites and installing AV software, but it's not that simple. The majority of the computers I worked on had current AV programs--they weren't able to prevent the infections. The situation with malware and windows is absolutely terrible, and it doesn't only happen to idiots who stuff their drives with porn.
Macs have security flaws--they aren't perfect, but when compared to the malware ghetto I've dealt with over the years, calling this a mac malware problem an "explosion" is just ridiculous.
Instead, it only happens to people who don't keep their browser up to date so that it's actually vulnerable to drive-by downloads.
Right?
Security patches aren't instant. Updating your browser helps sure, but it's not a real solution.
There is a tendency for people like us to assume every time we see someone with a malware infection that it must be because the user is a moron who: still uses Kazaa, doesn't know about the good porn sites, is browsing on IE6 and installs anything that a popup asks him too. That just isn't true.
It's not just idiots, the average non-moron windows user is massively vulnerable to malware.
In my experience (I'll limit it to friends and family b/c of the obvious selection bias of including Geek Squad customers), nearly every (non developer) windows user I know has had at least one malware infection over the last few years that required either my help, or a system restore.
Another guess but the rest of it is probably behavior based. Developers are less likely to spend all day on facebook playing flash games, more likely to have flashblock and adblock installed etc..
Saying Windows is insecure because a decade-old version of it didn't have rigths-elevation is pretty silly.
What is this based on? What the customer tells you? To quote House: Everybody lies!
I am being partially serious, I don't have AV installed, I run Windows, and I haven't had a virus in... a long time. I think the last one was Sasser!
To do this I checked the history for recently visited sites. Before most browsers had private browse modes, and the ability to only delete recently browsed data, a non empty history with no obvious porn listings could usually be taken at face value.
That's no to say that dodgy porn sites are the only vectors. In fact I find the most common vector for viruses these days is stupidity. The nastiest viruses to remove are the ones that can't install themselves, spread themselves, make no attempt to hide from antivirus, but have a whopping huge payload ready for whoever will run omg_awesome_kitten_pic.jpg.exe (which they've downloaded from Limewire, or Bittorrent, or has been IM'd to them over MSN).
The significance of this is offset by the base rate though: unlike Windows PCs, blondes don't constitute 90% of the sample group.
I'm not saying everyone is sick though. I'm saying I've seen thousands of windows machines with malware and a lot of the time it wasn't just an uneducated user problem.
My first store was also about an hour away from the nearest mac store so I also saw a pretty fair amount of macs while working there. They came in all the time for hardware issues so obviously they aren't perfect--But I never once saw one with malware--not in 5 years.
I don't think that they are magically immune to malware and some of it can be explained by smaller market share, but whatever the reason from my experience dealing with thousands of windows pcs and hundreds of macs--malware on macs is so insignificant that it doesn't exist.
5 years ago people were saying that malware for macs was coming (In fact Best Buy was pushing AV installs for macs when we first started carrying them), but it didn't materialize.
For the average user--if you buy a windows machine you will probably have to deal with malware, but if you go with a mac the chance is so low that is virutally nonexistent.
The problem is: naive user + attack vector (bad default Safari options) + malicious attacker (advertising network).
The solution is:
* Cleanup - Kill process form activity monitor, delete app from Applications, and installers from Downloads folder (kinda shocked that there isn't more to it).
* Inform - Teach user about basic practices.
* Close vector - Safari's Automatically open safe files after download checkbox.
* Block attacker - Install AdBlock for Safari (Bonus points).
All of the above, except the 'informing' part, takes all of two minutes to do, so I think the "Geniuses" at the Apple Stores can manage.
To those entrepreneurs whose business model is based on ads... sorry, but Adblock is the new Antivirus. I install it alongside any software updates or antivirus software (even on Macs, now).
Perhaps not with this "first generation" of OS X malware.
On Windows some malware replicate to files and have other self-preservation quirks making anti-malware software necessary.
> I think the "Geniuses" at the Apple Stores can manage.
Against simple malware, yes. When crackers start investing time and effort into their malware (like on Windows), it'll be a different case altogether.
However, from a marketing point of view it's a lot harder to sell. Compare:
You can't get viruses on Mac.
with:
Using a Mac you are very unlikely to get a virus, and provided you don't download and install anything shady ad/spyware isn't a concern either.
The second statement is true of Macs today, and still presents an advantage over Windows, but "No viruses" is a much simpler message, and one it seems they are trying to keep (superficially) intact.
Well yes, but lately how are these drive-by installations happening? Mostly through holes in third-party software. My concern, as a Mac user, is that there's no fundamental reason it should be any harder to attack OS X this way; it's just that up until now Windows has been a vastly more profitable target. And that is changing.
If you're a careful and conscientious user I'd honestly say you're safer on Windows at this point, because Windows is used to being attacked. It's used to defending itself against this kind of threat. You have this ecosystem of powerful antivirus programs like MSE or AntiVir that update themselves constantly, and innumerable other third-party tools such as Secunia PSI as preventative measures, and these just don't really exist on OS X yet. Windows also yet has some exploit mitigation facilities that OS X lacks, such as ASLR and kernel patch protection.
It will be a while before OS X has developed such an ecosystem of its own, and we just have to hope the adjustment period won't be too painful.
nope. by the user running an installer when requested by a browser ad popup.
I agree that this is how most malware happens in general, but I was talking specifically about the subset of malware installations that are drive-by downloads, i.e. which are performed without user interaction:
http://en.wikipedia.org/wiki/Drive-by_download
What I mean to say is that most of those are exploiting third-party software (Java, Adobe Flash and Reader) rather than Microsoft stuff these days.
And hopefully they never will. This is the stupidest possible way of protecting your computer. The proper solution is a more modern security system like SELinux instead of this outdated user/group/others approach.
If you run "sudo rm -rld /*" on a Mac, it may not run so well either.
Of course, it may be a sign that more sophisticated malware (i.e. real viruses, and other stuff that actually exploits the Mac's vulnerabilities) will be on the way.
Once an OS has the attention of malware writers (even user-installed malware like this), real malware won't be far behind. Especially when you consider how much easier exploitation is on OS X than, say, Windows or Linux. It's 2011, but OS X still doesn't have useful ASLR -- supposed to be coming in 10.7, but it was also supposed to come in 10.6, so we'll see how that goes.
[citation needed]
It wasn't until Windows 7 that windows finally got a reasonable security approach. I don't know what install bases look like these days but most PCs I interact with are still on XP which is obviously not harder to exploit that OS X.
To you and to fellow readers of this site.
However to the average Joe, there is no difference between the terms "virus", "malware" and "my computer is now doing things that I don't like that I didn't want it to do and it's interfering with me using my computer and I can't stop it"
Well, apparently there is an issue. Enough so that Apple has taken notice.
Of course, there aren't in it for the profit, where the only rational thing to do is to target Windows.
That's what they're supposed to do, no? This is hardly a cover up. Apple is simply reminding their support staff to not make promises they can't keep. This is a holdover till they have a solution. If their permanent solution is a cover up, that's a whole other story.
However, the letter itself is interesting in that it confirms Mac malware is becoming a real issue.
>The con artists behind Mac Defender hook their victims by presenting Mac-using web surfers with images that depict an antivirus scan taking place on their machines. The images falsely claim users are infected with serious malware and urge them to download and install the antivirus package. Those who fall for the ruse are then infected.
Yes. It's malware. It has infected the computer. Because they downloaded and installed it willingly. But "infection" implies "virus" to most people, and this is nothing of the sort.
http://gigapple.files.wordpress.com/2008/12/system-pc.png?w=...
I hope Apple's policy around this is not going to be sweep it under the rug because it could get out of control as Apple market share grows and more effort is dedicated towards hacking the Mac.
As stupid as this story is, it is still something that Apple is gonna have to probably start paying more and more attention to, given the trajectory of Apple market share in the future and the increased effort will be taken towards the Mac platform.
I think
People clueless enough to run an Installer based on an web ad popup are unlikely to be reading Apple's PR posts.
Aside from OS specific code that refuses to install anything called Mac Defender, Apple has no power over this problem.
...and to me, that sounded kind of silly...
Proper ASLR and sandboxing Safari by default would help a lot, I think.
WTF is your gf doing on a daily basis? Does she do reviews of shady porn sites? Install MSE (it's free) on your gf's computer and tell her not to install programs sent in email from people. Then tell her to stop worrying.
And if she does do reviews of shady porn sites, tell her to use a VM.
It is painful to watch her worry about viruses.
Honestly, if you worry about viruses, it's your own fault. Period. Either get a different kind of computer. Don't use a computer. Or don't use the internet. Worrying about an event that isn't likely to happen with reasonable precautions is irrational.
Sure zero-days happen that aren't patched yet, but those are rare. Nuclear meltdowns happen to, but I don't worry about it.
My point wasn't that it was her fault for getting a virus. But rather why is she worrying about it on a daily basis? The only sensible rationale is that she's doing something where the risk is relatively high.
And if it is painful to watch her worry about viruses, you should do something. Either get her to do something less risky -- whether its change OSes, stop using the internet, etc... Or get counseling for her. I've just never heard of someone so worried about it, and further never seen anyone in pain due to the irrational worries of computer viruses in a loved one.
And I know I sound like a jerk for saying all of this, but honestly, I think you'd both be much happier with some relatively simple changes in life.
Mac Defender does look pretty real though and I could see how the uninformed or people that easily panic would give it permission to install. As one second your on the web then a 'window' pops up saying your infected with Virus and to get the latest downloads ect., and it all looks convincingly real.
I don't regret switching to Mac myself as my Mac runs so much smoother then any Windows PC, plus installation of software is a breeze, my MacBook Pro starts up in 15 seconds and it just works right out the box. There was no crapware pre-installed like my old HP laptop.
Additionally, when I researched looking into purchasing my MacBook Pro I saw that Apple does recommend using Anti-virus software and I do have it installed, with no issues and it doesn't slow my MacBook Pro down a bit.
http://lifehacker.com/5800267/the-non+alarmists-guide-to-mac...
The one thing Lion has going for it here is that apps can declare their intention to do certain things and then be prohibited from doing anything else. So, for example, a non networked app can tell the OS it has no interest in using network APIs and will then be sandboxed from them (so if its code is violated it won't be able to suddenly start phoning home). But, of course, this requires effort on developers' parts to support the feature. The key thing is that Apple's own apps are likely to use this feature.
But if you download some random piece of software and then run it and the OS says "are you sure?" and you answer yes then you're boned.
And again, if you already said "yeah" to "run this bizarro app from disreputable source", are you going to say "omfg no" when asked if it can use the network?
watch what happens next... thats the trojan, unzips automatically in safari.
This thing is coming from Ed Bott's Microsoft column on ZDNet, where he's been hitting this hard for the second day in a row based on an "investigation" that involved him scouring the Apple discussion forums for a couple of hours. Two hundred clueless posts on a web forum out of a userbase of millions doesn't mean there's a "malware explosion," as he described it. Why are people falling for this flamebait?
As usual anti-mac trolls love to jump on the bandwagon and bash the platform with one of the best security track records running.
I find it ironic that Bott's fear mongering is leading the naive to download shady anti-virus software that is actually adware. These articles are really just contributing to the problem by misinforming people. Ed Bott is the equivalent of Glen Beck.
Neither of these things should be surprising to anyone, and hopefully the antimalware situation on OS X will improve before progressively more insidious Mac viruses are released.
I don't think antimalware is anything I'd ever want to run on a computer I control. Unfortunately, I think we're being pushed into a world where all applications are vetted and purchased through a trusted marketplace, eliminating this vector.
Why not? I mean this as an honest question.
EDIT: If you're concerned about performance or system resources, try a PC with MSE sometime, I think you'll be pleasantly surprised at how unobtrusive good antimalware can be.
On your comment: > the proper solution is to have better security on the machine.
Strongly disagree; if you look at this MacDefender issue, there is no flaw in OSX that is causing infection, users are installing it on their own accord. But what anti-malware/virus software can do here is warn or prevent the user from installing this in the first place, as it should detect the virus/malware signature.
This is why you need it even if the underlying OS is secure, to try protect users from themselves.
I run several things on both Windows and Mac. The Mac version feels a lot faster. If I shut off all the virus stuff the windows stuff is still slower but not as dramatic. It depends on what the code does, obviously. Any disk or network read/writes take a hit so if you're doing a lot of those it really adds up.
>Strongly disagree; if you look at this MacDefender issue, there is no flaw in OSX that is causing infection, users are installing it on their own accord.
The solution to this is what Apple has already started doing: provide just one place for these kinds of people to get software. Just buy it in the App store. That is the proper approach to "protect users from themselves", not put a 20-30% performance penalty on all Macs.
I agree with you on the App Store front, think it will help to reduce viruses/malware (I think Windows 8 app store will be a huge win too), but it's unlikely that an app store will be the sole place to get software for some time to come. So until it's impossible to manually install software off the internet, I think we're going to need anti-malware/virus software.
I am totally on board with the fact that there are some programs that do this - Norton's suite of anti-malware programs is basically regarded as malware itself. And it even comes preinstalled on a lot of computers.
But other programs work without a hitch.
Flashblock (or AdBlock/Ad Muncher/NoScript) also slows down my browser, but I can't be annoyed at an infinitesimal allocation of my resources to the extension.
This, for a product which hasn't found a single thing on any of my machines. Ever. It's great that they offer it, but it has been worthless for my use.
Mac OS X 10.6 has virus detection built into the OS. Only a couple of viruses are detected because, oddly enough, that's all that have been found. Again, "viruses" not "trojans".
Most "anti-virus" software is worse than malware on its own -- it slows down the computer it's used on. Microsoft Windows, out of the box, will shut down your computer without asking you, quitting out of applications on the way. This, again, is exactly the kind of thing malware does.
It is impossible for any operating system to prevent trojans. As long as the person at the keyboard has admin access, no matter how convoluted the process, they can install whatever malicious program they want.
The only defense is education and awareness.
Have you forgotten that Darwin is by and large derived from BSD? Apple is standing on the shoulders of giants with this one.
Yes they do:
http://support.microsoft.com/kb/129972/en-us
"Call 1-866-PCSAFETY or call 1-866-727-2338 to contact security support."
> Two hundred clueless posts on a web forum out of a userbase of millions doesn't mean there's a "malware explosion," as he described it. Why are people falling for this flamebait?
If Apple is issuing special instructions to its support staff about this malware, then clearly this is a pronounced problem.
And I suspect MS would ship antivirus built into Windows if they could. Unfortunately, antitrust makes packaging things that make sense a non-starter if other companies sell it.
But hopefully they can take a more proactive course now that the DoJ's oversight is ending:
http://arstechnica.com/microsoft/news/2011/04/department-of-...
Apple is a direct retailer.
Update: checked Wikipedia, they have 8 stores open and two more in development.
I'm sure it would be a mess, and some programs give a false sense of security, but it would probably be the best trade-off.
As is the way with these things, Apple will stonewall, but I expect eventually handle the issue. In the mean time some of the congregation will snort in derision and deny there's a problem.
Honestly, listening to some Mac user responses to this problem, it's like entering a timewarp back to when all the measures implemented on Windows/IE to deal with this stuff hadn't even been thought up.
Possibly a quick fix, until it's addressed, is for folk on OSX to do their web surfing in a Windows VM, using a security-focussed browser designed for non-technical people, such as IE9. ;-)
That's because many of the measures implemented on windows are fundamentally flawed. Virus/Malware scanners? Really? So we want to turn infecting people's computers into a business?
The MS approach has always been to make money on working around defects. I really, really hope Apple doesn't decide to go down this route.
Internet Explorer and Windows Defender are both free.
Also, the defect in this instance is allowing users to install software on their PCs and not helping them avoid installing malware. As this story shows, this is a defect that is shared and arguably worse on OSX.
Again, the proper solution for the kind of people who would actually install a virus manually is to simply point them at the App store.
"According to a third article penned by Bott, AppleCare reps are seeing a four- to five-fold increase in the number of calls requesting support for rogue antivirus scams targeting the Mac"
So now a handful of incidents is cause for uproar?
"Porn sites just started popping up on my MacBook Pro," one user wrote. "Is this a virus? I have never had a virus on a Mac before and I have been using Macs for years. Please help!"
So it's just adware then? Oh no!
The search was Flamenco or something like that. My girlfriend pulled me over to show me that this website was saying it was from apple security and that I needed to download a tool to remove the Trojan.
Having just come back from a visit to Turkey, we found the Trojan reference funny.
I think if she was surfing with safari the .zip file would have extracted automatically, which I think would have caused many people to run whatever evil was stored inside.