Apple acknowledges Mac Defender malware, promises update
arstechnica.com
arstechnica.com
Macs aren't more secure than Windows machines, but they're still undeniably safer (at least for normal people).
I read that and I thought Apple had set up a top-level page. I then saw it is an article in Apple’s knowledge base.
As far as I know, this is the same thing Microsoft does for distinguished malware: articles in the knowlegde base. E.g., here is an old one for Blaster:
Not exactly apples/apples.
That's a pretty absurd statement which, if it even made sense, would be far more applicable in the Bad Old Days of Windows XP.
Still, I feel almost as safe on my Mac as with Linux, but not quite. Malware producers are starting to notice the Mac.
The most successful malware packages do not, as a general rule, lock all other malware out of their victims, so it's not as if there's a meaningful competitive hurdle for malware authors. Why would they choose the tiny market?
The way the market is going, in a couple years, I can see an outside chance that OS X will be so popular that it'll be a useful target.
- users are not expecting it, and have had little coaching regarding malware on Macs
- there is very little usage of antivirus programs
- Safari is not particularly hardened
- OSX lacks various protections present in Windows
- making a mac 'port' of a malware program is probably not difficult
It seems really easy and wide open, in other words.
We have seen a fairly widespread attempt recently to infect Macs with a trojan, 'anti-malware.zip'. I presume most people have seen this, if not: http://www.tuaw.com/2011/05/19/macdefender-malware-protectio... I've actually encountered this several times recently - chromium downloads the .zip file automatically when you are redirected to the attack site. What if they find a browser exploit for Firefox or Safari as the next step?
> People write malware to make money. Your premise is that the return on investment for Mac malware is comparable to that of Windows, which still absolutely dominates the market for personal computers. It's not.
Almost all software is written to make money, and still plenty decide to write software for the Mac even though the market is smaller. What's the difference? The revenue potential per 'customer' is a lot smaller for this vs. the programs sold by Panic, perhaps?
I'm not challenging your perspective or expertise of course, these are merely the reasons I wonder about it.
My main concern is how long Linux and Mac users (e.g. myself) can continue to be considered comfortably immune to such threats. I'm glad to hear you think things will be safe for the Mac for years to come, esp. since that would mean desktop Linux should be safe for a long time.
I don't really buy the claim that OS X is intrinsically more secure than Windows these days.
Honestly, for a user that is not using Internet Explorer, I can't imagine a workflow nearly as dangerous as is possible with Safari. It's not hard to be safe in Windows these days.
A Food & Liquor on Chicago's West Side is more secure than a 7-11 in suburban Kennilworth. You have to pass your money through a little slot in a bulletproof glass window!
The 7-11 is safer. Nobody ever sticks it up.
This is not a complicated point.
I'm glad you're happy with Windows security. I'm pretty impressed with it too. But I'm biased, having worked with them professionally on it in the past.
On the one hand, it’s great that all the variants of MacDefender currently out there will be neutralized.
On the other hand, we’re surely going to see new flavors that go undetected by the update. Apple is getting into the anti-virus game, and potentially starting an arms race. But, what else could Apple do in this situation?
MacDefender is relatively tame. Next time it could be a rootkit packaged in a trojan.
Will criminals stop wanting to scam people?
Will non-technical users somehow get more savvy?
Will the Apple userbase get smaller and thus less lucrative?