macOS now scans for malware whenever it gets a chance
eclecticlight.co
eclecticlight.co
I remember it being such a ^%#*show on Windows until I think it was called Microsoft Security Essentials? And then that got folded into Windows?
I recall as a teen how hard it was to recommend antivirus because so many of them were garbage. And then MSE made it effortless.
It's not about "acceptance", unless it's about the increasing acceptance of authoritarianism --- because after all, it's really about control of the platform. They realised they could start calling everything they don't like "malware", that doing so would convince many if not all users, and thus found another way towards becoming the eventual arbiters of truth. Don't like something that your competitor does? Implement restrictions in the OS, and then when your competitor finds a way around that, start calling it "malware" and detecting and deleting it. We've already gotten disturbingly close to that reality:
https://news.ycombinator.com/item?id=17967243 (in particular, https://news.ycombinator.com/item?id=17968992 )
https://news.ycombinator.com/item?id=29579994
Those of us who have been in this for a while may remember a time when a lot of Windows AVs would classify binaries compiled with GCC as suspicious or even quarantine/delete them, while those compiled with MSVC from the exact same source code were fine.
We know what things like this can and will be used for. AVs were in bed with antipiracy groups and Big Tech before it was even called Big Tech. We've seen past abuses of centralised power, and know that this is not going to end well.
That's right, and with the remote attestation capabilities of Secure Boot implementations, governments will finally be able to demand that every device sold has to be running an up-to-date version of an "approved" OS in order for ISPs to allow the device to access the internet.
The only limit is how incrementally they can introduce these rules so that the frog doesn't jump out of the boiling water. For example, the rules wouldn't initially apply to businesses, and maybe hobbyists would be allowed to use a special ISP that provides a custom CA certificate to do TLS interception.
I predict that within 5 years, a G7/EU/FVEY country will have passed a law that at least starts this process of making it illegal to run programs (or have VPN connections) that are blacklisted by the government. A major cyberattack (especially a false flag) will only speed up that timeline.
What's funny though is that I always thought that Apple/macOS is doing things differently because they are a decade ahead of Microsoft when it comes to securing their OS, but it turns out that Apple is actually a decade behind (also see the Windows Vista style confirmation popups on recent macOS versions).
How Windows still doesn't have good ways to record or capture the screen, of moving and resizing windows is still requires focus and skill, is beyond me. Also, different UIs from different generations, with partially overlapping features. Not to mention internal key value store that makes it impressive that it doesn't stop working suddenly more often than it does.
Not sure what's your problem with resizing windows but there are all kind of shortcuts for moving and resizing them if mouse is somehow too hard.
You mean macOS? Seems kind of random.
^ I thought this made it clear I was referring to Windows?
I honestly do not care about anything related to flame wars. Just that whenever I use Windows and want to do OS related things, it all feels clunky and annoying. It's not consistent. It's slow at start for no good reason (likely due to telemetry, or other online stuff). Updates are annoying and I'm glad I don't have do do anything professional on Windows. The windows api is ugly. The only saving grace it has for technical productivity is WSL2. But, at that point, there is zero incentive to use something so clunky, when you can use linux/gnome and have a much, much, more enjoyable experience.
Again, everyone to each theirs. Ship buoyancy and all that.
edit: Ah, I think I understand my misunderstanding. I wasn't commenting so much on the previous post about Windows vs MacOS. But adding that if something is a decade old compared to Windows, I consider windows to not have had any consistent improvements since Windows XP. Everything after that has been a mess. Some things better, but with a mix of old. "Need to fix something os-related", looks through new control panel. nope. looks through old control panel nope. Maybe it was in computer management?
I was talking about the gnome part, as that wasn’t mentioned anywhere above :)
I’m not trying to start another windows-mac war either
This is completely false.
A year before Microsoft released Defender in 2006, Apple had already packaged AV scanning in Mac OS X Tiger Server[1] in 2005. ClamAV[2] is OSS, and easily installed on the client OS, and many did so and had been since its first release in 2002.
The thing was, practically, there were no viruses on Mac OS X. The only reason Apple included ClamAV on the server was for scanning mail, because Mac OS X Server's mail server obviously also served Windows mail clients. IOW, Apple was fixing Microsoft's broken crap before Microsoft's own attempt to fix their broken crap.[3]
The very first Mac OS X virus appeared in 2006, called Leap-A. That was one in 2006, when Microsoft Windows already had tens of thousands in the wild. Following Leap-A were a few proofs of concept, and it seemed like every year, there would be one new virus, worm or Trojan horse identified on Mac. But infection was exceedingly rare, compared to Windows that would ensure a new installation to be infected within 10 minutes of being connected to the Internet.
By the mid-2010s there were dozens of identified malware on Mac, but infection was still a very rare exception. Meanwhile, Windows had hundreds of thousands of malware by then, and it was nearly impossible to prevent infection even with vigilant virus scanning; malware got through ordinarily.
To this day, malware on macOS is pretty much a nonissue, and AV on Mac is only there primarily to prevent Windows machines on the same local network from being infected via Mac proxy. There has never been a widespread malware infection on Mac since Apple modernized their OS to BSD. Similarly, you never hear about malware on NetBSD, FreeBSD, or OpenBSD. There is good reason: unlike Windows, BSD is not fundamentally insecure. Malware developers go after the low hanging fruit, which is always pretty much only Microsoft Windows, and malware has plagued Microsoft's NT-based OS since inception.
[1] https://en.wikipedia.org/wiki/MacOS_Server#Mac_OS_X_Server_1...
[2] https://en.wikipedia.org/wiki/Clam_AntiVirus
[3] Had Microsoft Windows not been so dysfunctional, with Microsoft prone to actively breaking useful functionality in enterprise, Linux would never have become so popular. Linux's first best reason for existing was that Linux devs would quickly restore Windows' functionality within short order of Microsoft's removal of that functionality, within days or weeks. For years it was a cat and mouse game, with Linux's cat quickly catching Microsoft's mouse. This is how Linux got a foothold in the server room, which, as we know, exploded between 2011 and 2013 when Linux finally took over the datacenter.
Spybot Search and Destroy + Adaware were always a knockout combo until maybe 2010?
Our stack was Spybot, web something, it was yellow, and Eset Nod32
Those three got almost everything possible at the time
Those were the days of the amazing Royale theme for XP… awesome theme.
Takes me back, can't believe it was forever ago.
Consider this common workflow, which would infect a computer in a few minutes:
Open up Internet Explorer, type "free song download", click first link, popup ads begin, malware begins...
Nowadays, it's different. Less poking and proding in an OS and that is sad.
That said, and as many others have pointed out: with great power comes great responsibility.
There are definitely two-sides to this. If we look at the iOS platform we have many developers who complain about the approval process, but we also have the platform with the least amount of malware by a significant margin despite the large/valuable install base.(1)
It’s also why I find it a bit crazy that the new EU rules will crack open a lot of that protection. They should have mandated for 3rd party approvals, not for a weaker anything-goes security model.
1. https://atlasvpn.com/blog/over-30-million-new-malware-sample...
Why can’t it be the same on iOS?
All I really need on the iPhone is something like newpipe and I’d be happy.
This is why the EU rules fall on their face: it’s all the security holes with none of the perceived advantages, only a few big names will make bank because they’re big and trusted enough to advertise directly to consumers.
As i said before, the EU should have just mandated that approvals are spun off to a 3rd party entity. That way it would solve the usual line of attack “apple didn’t approve my crashy spyware calculator app because they want to get rich on their own free calculator.”
I'd like to see much more behavioral analysis like the leading AV companies do, rather than just fingerprinting but it's a good start.
One thing I don't like about Apple's approach to security is locking the user out, making the OS like a black box. For me the user should always retain the last word. Until now most of their work has been in this direction (and the direction of iOS) but I'm pleased to see they're looking more into mitigation rather than just prevention now.
If we're talking about prevention of execution of unknown applications, that's not existent. Right click any application, click open, and it'll show you the same warning with "Open" added. So, you can always override Apple's warning.
I like how macOS makes you read the warning box before making a decision, tbh. Yes, it's no Linux in terms of flexibility, and freedom, but I like the OS nevertheless.
You're only talking about user-level modifications.
Just because you can modify Windows, it doesn't make it a better place overall. We have witnessed what happened to it over the years.
At the end of the day, I'm a Linux guy and strong GNU proponent. The reason I use Mac laptops because of the hardware & software integration they provide, plus I always keep a virtualized Linux installation at top of it.
If macOS was not interoperable with Linux, I'd not be using it.
I'm not using Windows as an operating system close to a decade, so I forget (or don't know) things like that.
Apple has a simple business model for macOS. It exists solely as a vehicle for selling Macs - premium computers with (most importantly) a fat profit margin.
Keeping the customer wanting to buy new Macs (and maybe that new iPhone…and that Apple TV+ subscription…) is what drives their OS to be, generally, much less user-hostile than Windows. The user is the customer; whether through direct hardware sales or through the subscription purchases those hardware sales lead into.
Microsoft, in turn, sells Windows to OEMs and the business world via bulk licensing. You, the consumer, buying a Windows 11 license is not what’s funding Satya Nadella’s new private island. It’s Initech Corp. buying 5,000 PCs with Windows because “no one ever got fired for buying IBM.”
Disclaimer: this is largely all speculation, and if I am off the mark, do let me know.
First, Apple now has a vast ecosystem which they are trying to promote, be it music, movies, TV, advertising, some of it requiring or optimized for their hardware. It goes beyond selling Macs.
Second, Microsoft is also trying to sell PCs. I don't buy the idea that they can be explicitly anti-consumer and get away with it. Backlash against the OS would hurt MS's bottom line perhaps more than Apple.
https://www.windowslatest.com/2022/08/30/former-microsoft-en...
Having a start menu filled with ads with Microsoft, yet again, reminding everyone that Edge exists, is a bit anti-consumer in my opinion.
It's easier to uninstall Outlook than to get rid of that ad.
At least that one is easy to disable.
Sure, but the OP's comment is about Apple in general, not macOS. Try overriding the warning on iOS, for example.
It's not like the Android ecosystem, which started as an open source free for all mobile OS, which iteratively locked and closed down, starting from Google integration to OS and boot loader level.
Now, Google is preparing to throw Linux kernel out of Android for a even more tightly controlled Fuchsia kernel. I'm hoarding my popcorn and wait for the day when the hardware vendors stop building their Fuchsia drivers to control how they deprecate their hardware, and fine-tune their bottom lines.
The response from the community will worth a watch.
Also, in pure irony, Apple is preparing to allow application sideloading.
Interesting times, indeed.
Only because the EU is preparing to force them. Apple is still very strongly against it. Recently they listed a bunch of reasons why they think it shouldn't exist.
But they know this is coming from the EU so they're probably trying to do it on their terms while they still can. Give as little as possible to the users to keep the EU off their back.
You can still turn off an awful lot of the security features in macOS. Some require a reboot, but still, the option's there for developers and power-users, if they prefer or require riskier operation.
There is no way for me to put my own configuration in the system and still have it persist. For example I change things in sshd_config (to turn off password auth), and PAM.
This is not OK, there should be a way for me to sign files so they are marked as valid.
I don't think the read-only OS partition or the SIP is a bad idea. The bad part is that Apple is the only one who controls it.
Not true.
Most of Apple's features are for keeping newbies and users who think they know what they're doing from shooting themselves in the foot.
Apple documents how to disable SIP [1].
[1]: https://developer.apple.com/documentation/security/disabling...
Does putting your custom options in something like:
/etc/ssh/sshd_config.d/disable-passwords.conf
no longer allow custom sshd config to survive updates? It's like if you're configuring daemons on, say, Ubuntu the "right way" so you don't get a ton of those prompts during apt-updates asking you if you want to accept the maintainer's config file or roll the dice and keep your own.
Opinionated software is great if your opinion is aligned with the vendor's but Apple has been moving away from mine ever so slowly since peak macOS which was around snow leopard for me.
I really love how KDE gave me all the options back that I missed for so long. Finally virtual desktops in a grid again. And choosing what I want my UI to look like (and not forced changes on me every year)
I have a feeling it's not only that though. Apple is rapidly expanding from a hardware to a media content vendor and they have reasons to want to protect their own content as much as possible.
This is now possible for SSH, btw.
They finally support /etc/ssh/ssh[d]_config.d/ where you can add your customization files, and they won't be squashed by an OS update.
So they finally picked up on the technique Linux has been using forever.
My money, my hardware, my control. Not negotiable.
(Edit: this applies to all their offerings. Iphone is already anti-user and effectively a rented device. Mac laptops are heading that way. Do not want.)
In their defense—both Apple's, and the public's—the general populace is, like, 99.99% OK with outsourcing those choices to a company that's way more interested/invested/capable in knowing better than they would be on their own.
Is it arrogant if the public continues to reward/reaffirm it?
Majority of customers purchase one of two options in a duopoly isn’t really an endorsement of the options, but rather a critique on the lack of options.
Other operating systems were available in the past, and you can release a RISC-V Lisp OS phone incompatible with everything else tomorrow if you want. Just like in the past.
It's just that most people don't care that much.
Even people who have heard of Linux for example's opinions will have mostly been set by people shilling for Windows and so on
Because they were deliberately made to feel helpless.
to a company that's way more interested/invested/capable in knowing better than they would be on their own.
The company is "way more interested" in continuing to squeeze the $$$ out of you, and would rather you not know anything but be subservient to it, because then you cannot object.
On the other side, a booted macOS has certain limitations in place. Not even root is able to write to certain partitions and such stuff. This is not because "we know better", but because these limits provide some fundamental security. A partition which cannot be written to, cannot be modified by malware.
You can boot into a mode where this protection does not exist, but for productive usage, it is a good idea to have that protection in place.
Apple sells phones that are on average twice as expensive as the competition, but yet they still manage to have a 60%+ market share in the US.
Maybe they know what appeals to most users?
Explain?
But when you do that yet hide things from people who do know better, you're not making tech accessible, you're making tech worse.
I really don't like how these companies behave sometimes, their utopia involves people with 0% knowledge and 100% obsession.
I wish ios would allow me to firewall my phone, even from apple.
on macos, i used to use hands off! from one periodic (and before that, metakine), but they've since disappeared. i now use lulu with pf firewall via murus lite as a backup, but may switch to little snitch again (used to have a license but was unable to upgrade it so switched to hands off! via a promo) for the better UX.
I had gatekeeper completely disabled, yet somehow it has recently reset to its asinine default and I got this "this app isn't from an identified developer, you should delete it" error. I hated it.
If you must do code signing for whatever reason, at least let me install my own roots of trust for developers I personally consider trustworthy.
Apple's been doing it for over a decade https://www.justinrummel.com/apples-built-in-anti-virus-xpro...
macOS really seems to try to frustrate power-users with these non-optional security features. I even had to make a separate note document with the commands/references to disable the various security features. I don't understand why they choose to frustrate this audience by making it so difficult.
I don't recall having to do anything too onerous to run whatever software I've wanted to run on my M1.
I guess "non-optional" is inaccurate but every new macOS update I end up googling why some app can't open and discovering a new mechanism that I need to bypass (or a change to an existing one).
Other that having to affirm I did indeed want to open a piece of unsigned software a few times on first run, which I like, I’ve never had an issue.
What are you running into?
You definitely DO have to turn off the "app store only" default, but that's completely trivial (and is a sensible default for less technical users).
I haven't built anything from source in a long time, but I'd expect that works fine, too.
### Commands
- Disable GateKeeper: `sudo spctl --master-disable` - Disable Library Validation: `sudo defaults write /Library/Preferences/com.apple.security.libraryvalidation.plist DisableLibraryValidation -bool true` - Remove app from quarantine: `sudo xattr -rd com.apple.quarantine [path to the app]`
https://stackoverflow.com/questions/64842819/cant-run-app-be...
`sudo chmod -R 755`
`codesign --force --deep --sign - /Applications/$app.app`
The following commands must be executed from recovery mode:
- Disable SIP: `csrutil disable` - Disable Apple Mobile File Integrity: `nvram boot-args="amfi_get_out_of_my_way=1"`
### Articles
https://www.naut.ca/blog/2020/11/13/forbidden-commands-to-li...
https://tinyapps.org/blog/202010210700_whose_computer_is_it....
https://eclecticlight.co/2020/06/25/big-surs-signed-system-v...
Installing Homebrew is probably the biggest example, without Defender ATP, probably ~3 minutes. With Defender ATP, upwards of 15.
I’d love to convince the powers that be that XProtect is enough, but I’d need some way of measuring and auditing it. Any suggestions?
Even 'known' detections and preventions won't do it because you'd have to extrapolate if it wasn't detected, if prevention of anything was actually needed. Take a detection of a Excel v4 Macro loader, that's great to detect and prevent with ATP, but doesn't do anything on a Mac, and doesn't do anything on most PC's either.
This is similar to comparing Sophos vs. Trend Micro for example. The products do similar things, have similar goals and similar methods.
Ultimately the true protection doesn't lie in what AV you have or what EDR vendor you select, but how you deal with inevitable infections and loss of service. If you can treat the loss of a laptop (be it theft, fire or ransomware) the same way, regardless of the reason of loss, you're good. That also means encryption at rest and DLP at runtime. Neither are going to be in the AV vendor's product.
The same applies to malware ingress. If you have good controls on mail (even if just for attachment and BEC scams), that already saves you a ton of issues. And if you don't use filesystem shares like it's the 90's, that helps a ton as well, because now there is no OS-native spreading method using existing mounts.
The list goes on and on, and ultimately the whole AV vendor thing is just a tiny speck in the grand scheme. The biggest gap would be your audit capabilities, and having any controls vs. having no controls at all.
Something as simple as bare minimum hardening (FDE, MFA, autolock), OSQuery or Kolide for health/security posture checks, non-SMB/NFS file access, and proofpoint or mimecast in your mail flow will have a bigger impact on most corporate setups than any anti malware vendor can do.
Depending on the skill and education level of your users, you might even consider self-selection controls. Personally I use the Objective-see tools, XProtect and on-demand Sophos. The type of work I do doesn't fare well with traditional AV, but because I don't mind binary allowlisting, persistence lockout popups etc. and periodically confirming that I didn't miss anything using Sophos, I can get my work done and be secure enough at the same time. When I work at a regulated company I'll just use their supplied workstations and bill them extra by the hour.
HomeBrew is my favorite of them, overall. Though Portage is pretty damn great, for what it is.
We collectively complained about it as it slows down our development process but it fell on deaf ears.
> Adload for a period of 8 seconds, once or so each day
They're scanning daily irrespective of signature updates, which makes no sense.
If you want to catch real zero-days, you have to approach things very differently. Do behavioral analytics, seeing what a process is up to and if it's poking into things it shouldn't.
Many leading AV suppliers like SentinelOne, Cylance, Crowdstrike do this and are very successful at it. However Apple is just starting in the antimalware market so I forgive them that they're just scanning for some known-bads for now.
Other than that, yes, it's been fairly rare to have malware infections that don't start with tricking the user into executing a binary, though it certainly can happen.
Once was on in the 3.11 days. Turned out the copy of KidPix we bought had a virus on the installation disks.
The other was in the late 2000s at work on XP. I got got some piece of malware (showed ads IIRC) from a drive by using a Java exploit in an applet showed by an ad network.
If you’re not doing high-risk stuff it’s not hard to avoid. But I’m glad MacOS has this built in just in case (like MSE on Windows).
How would you know? Maybe you got a virus that looked around for bitcoin it could steal, didn't find any, and gave you no signs of its existence.
Doesn't sound like that's going to use substantial battery nor outprioritize low-latency A/V. Long before Apple was known for battery life, they were known for real time media. (I won't speak to user choice though since I'm not clear on which parts are optional should you choose to tinker with macOS.)
It can be a little annoying at times but I like that it’s there.
Sibling comment explained how to fix it so terminal never asks again for locations you have permissions to.
Would it tie into CSAM for apple devices? They say PUP, but what if it's politically unwated files and they wanted to discover the creator of a file/photo?
North Korea is criticized highly for pushing watermarking in it's nix distribution, but the way Microsoft Defender works for enterprise is that you have an agent on every PC, which scans all files - and that can be a "canary" for files being modified / searching the org at once for a specific hash that means you're infected or not (yes, it is trivial to pad bytes to change the checksum string, but still)
I do not know about how MAc OS does is scanning, or reporting, but that is the biggest thing I'd be looking for - we already have gatekeeper that keeps unsigned apps from "easily" being run, or even self signed/unwanted signed apps from easily being executed which operates on a checksum basis.
Is this next?
When did those arrive? On what OS versions?
I'm not okay with it. Cements my decision that my next workstation will be Linux. macOS is getting way too non-user-controllable.
Computers work pretty damn well most of the time, but as soon as enterprise IT gets their hands on it, they clog it up with poorly written, well marketed security software. We have shit like privilege managers running so that we can install "whitelisted" apps. Still have MS endpoint protection, which is a total piece of shit. All the MDM shit that runs in the background, some password sync manager, a goddamn locally installed proxy that hijacks all your web traffic. JAMF always in there fucking crashing and doing who knows what.
And we migrated our laptops when our company was bought out. And so the entire security suite was completely different. All the old security software was removed, but left cruft, and extensions and shit all over the computer. All our computers run like total dogshit until an OS reload.
All this bullshit that makes our productivity crawl to a halt, just so that they can check some boxes on a security audit.
Truthfully, if I was director of IT and security, I'd likely just source all laptops in my department and preinstall everything needed and then ship the machine to the new employee, giving them passwords through a secure channel e.g. Signal / encrypted Telegram chats / PGP'd mail etc.
I've worked once on a corporate Linux laptop and it was a nightmare. The machine in particular wasn't very good and was easily overheating and its fans were always spinning, and of course the VPN worker crashed every 3-4h or so -- which still wasn't a big deal for a 8h working day, mind you, but you did have to always be prepared for the next thing you're doing to fail with a mysterious network failure.
Again, sympathies. It sounds like a shit show. Another thing I'd consider would just be to ship everyone the same 8GB RAM laptops that all remote into cloud instances. Machine stolen? Tokens / passwords / keys expire every hour anyway even if the IT is asleep at the wheel for that one hour, so who cares.
If for some reason that didn't work, you can also find a long YouTube video to play on mute -- videos disable sleep as well.
I want to experiment with a lot of tech and 99% of it is only accessible in Linux. I want to try more things than just what I'm paid to do today so that kind of finalized the decision.
As for desktop Linux, I know it's a challenge. But I'll make it work. I feel it's a worth investment.
Apparently that's too much to ask. No, I have to find out why my compilation is currently going 2x slower by checking the CPU load and seeing yet another XWhateverService taking up 200% CPU and 50% SSD capacity.
Problem is they fire up at the most random of times and sometimes really get in the way of my work. Granted it's never more than 30-60 seconds but I am growing weary of having to fight my system or choose to just give up and wait.
Glad to know it's not a malware, but it sucks not having control on your system
It's definitely a case of "just because you can, doesn't mean you should".
I obviously don’t recommend this, but if you turn off SIP it’ll also disable XProtect.
I'm not saying that you're necessarily wrong, but there are many different things that could also cause this. Some investigation would be in order before making that claim. (Spotlight indexing via mdworker is the usual first culprit for this kind of behavior, in my experience.)
You should be able to see what's causing the extra load by keeping an eye on Activity Monitor.
> (Spotlight indexing via mdworker is the usual first culprit for this kind of behavior, in my experience.)
So you've seen this behavior enough times that you have a fix for it, but you've never seen this behavior on any of your Macs? What is it?
Most of the rest of macOS defenses depend on almost totally invisible malware mitigations. “Almost totally” as in you don’t even know it’s running unless you happen to spot it in a process monitor.
Apple mostly strikes a good balance in macOS (IMO) between locking as many doors as it can without getting in your way, good default UI tradeoffs, mostly reasonable escape hatches if you really do know what you’re doing, and very inconvenient escape hatches for actions which truly leave your proverbial front door unlocked. (The latter involve rebooting into the recovery volume and entering explicit commands into a CLI.) If you’re a high value target, obviously none of this is sufficient. If you’re a rando user with relatively not-reckless habits, at this point it’s like gambling with odds so close to break-even most users have good reason to think it’s a solved problem.
https://apple.stackexchange.com/questions/331876/persistentl...
https://help.apple.com/pdf/security/en_US/apple-platform-sec...
tho i have to say ive never had defender (or any io hits) cause audio to stutter outside of impending bluescreen from garbage device driver tier crashes
Wow, Apple marketing was really asleep at the wheel when someone named this one.
nm instantly too late ;)
Now the OS takes care of the vast majority of it and problems aren’t rampant.
And what do we do? Complain it might be slowing things down. That it’s taking away control. That if we want to load a virus on our computers the OS should never question us. And don’t forget this is a secret conspiracy to track us.
There’s no winning. Poor OSes. Always doing it wrong.