Apple Snubs Firm That Discovered Mac Botnet
forbes.com
forbes.com
"Sharov believes that Apple’s attempt to shut down its monitoring server was an honest mistake."
"In Apple’s defense, it may not have recognized Dr. Web as a credible security firm when the company contacted Apple earlier this month–I hadn’t heard of the firm either until its discovery and analysis of the Flashback botnet."
It looks like Apple wasn't the only one surprised by this:
"But the better-known security firm Kaspersky confirmed Dr. Web’s findings on Friday. A Kaspersky representative said it hadn’t contacted Apple with its findings and hadn’t had any direct communication with the company, and Kaspersky researcher Kurt Baumgartner wrote in a statement that 'from what we’ve seen, Apple is taking appropriate action by working with the larger internet security community to shut down the Flashfake [also known as Flashback] C2 domains. Apple works vigorously to protect its brand and wants to rectify this.'"
The world is bigger than firms who are big in america and that kind of american centric thinking also won't go down well on the web.
So it's probably the article's honest mistake if you infer otherwise from it.
Their download.com cleaner software has not been updated since 2010.
Finally, a Google search comes up with their main website, wikipedia page, news stories with about their discovery, and several other links to sites that feel like antivirus phishing pages rather than legitimate links.
All-in-all, there isn't enough content to really judge them as absolutely trustworthy. It's really a brand recognition issue in a space where trust is absolutely key in evaluating claims. Kaspersky has the brand and trust worldwide. Dr. Web appears to have it in Russia, but not nearly as much outside of the country.
How long will it take for Mac users to learn that viruses are indeed a threat on all kinds of computers, not just PCs? I can only hope Apple will take a more active role in educating them.
That won't help the people who actually use Java on OS X. It would be better to allow Oracle to manage the updates for Java on OS X, the vulnerability that Flashback abused was patched by Oracle back in February.
Reports involving security breaches of Apple products often show Apple as someone who feels wronged and would rather try to kill the messenger than fix the problem. To their credit, they appear to be looking for fixes that cause the least harm to their users. But to me they appear to be operating on very limited manpower/budget for this so they have to prioritize.
An example: Apple didn't fix a flaw on Windows iTunes for 3 years because it wasn't a priority, and intelligence software companies sold software based on this hole - imagine if Microsoft did this:
http://www.telegraph.co.uk/technology/apple/8912714/Apple-iT...
[1] http://www.windowsitpro.com/article/security/microsoft-repor...
You haven't listed a single thing that Microsoft has done that Apple has not.
You are right that Microsoft started to take security seriously before Apple did, but Apple is not still behind.
http://www.theregister.co.uk/2011/07/21/mac_os_x_lion_securi...
Also, what's your proposal for establishing the trustworthiness of code?
You also didn't answer the part about trusted code.
> You also didn't answer the part about trusted code.
Because it wasn't there when I replied.
Centrally signed code repositories on their own aren't the worst thing, I rely on them myself (apt-get). The problem arises when it's fixed to one possible repository. If the proverbial "average user" cannot install and administer a friend-approved but Apple-unapproved app with the nearly the same ease as an Apple-approved one, we end up with a situation where Apple directly controls what average users are capable of. It also causes users who wish to own their device to hope for new exploits to be publicly discovered, which is utterly backwards. I understand that progress for actual security (isolation, capabilities, proper deputies, etc) takes significant work, but coarse-grained whitelists aren't the answer.
Your second point as I've indicated, is just conjecture. I don't see good evidence for it actually happening. Certainly nothing that Apple has publicly disclosed suggests that it will. It seems pretty unlikely to me.
But yes, if they did go that far, they would indeed control what average users were capable of.
If it ever gets to that point, I'd hope that by that time, there would be some obvious killer apps for another OS to demonstrate why it was a problem.
[edit: Coarse grained whitelists might not be the answer, but I highly doubt that Apple is going to stop there. Every OS release is a step along the way. It's worth noting that iOS has generally developed in the direction of providing more capabilities to programmers, rather than less over time.]
The difference starts at the foundation, and manifests in a pervasive lack of respect for the user (who's ultimate control and understanding should be a prime usability concern).
For instance, that whole device-id brouhaha - iOS apps really get a unique device-id, which they are then supposed to partially-obscure according to Apple's guidelines? Why in the world is an app allowed to directly query a fixed identifier in the first place?! There should be a specific ID-Api of which the user controls via a system dialog the same way a user controls how long a browser stores cookies for. Sandboxing+auditing then make sure apps aren't using something like the ethernet addresses to get around the user's choice.
But unfortunately, most of the developers who actually know enough to analyze this are on the take of the ad companies and think that their stake on the user's device is equivalent or even overrides the owner's! So Apple kowtows to the advertisers and permits uncontrollable tracking while the end-users are stuck with their only choice being 'use or not use' an app based on how much they perceive it abusing them. Instead of being introduced to a world full of self determination and limitless possibilities (as early computer adopters were), modern day users are shown a standard no-free-lunch world where "they either get you coming or going". Developers are still able to seek out freedom, but the goal of empowering an end user to solve their own problems couldn't be farther from sight.
(And yes, Android has most of these same problems in addition to some of its own, which is why I said dichotomies aren't useful.)
I couldn't agree more with this. However that dream seemed to die with the breakup of Alan Kay's original group. Nobody is even approaching this problem except perhaps Kay's own FONC group, and even that seems to be more academic than practical now.
That said, I think that as digital culture matures as more generations grow up with digital creation, programmability will become the primary constraint, and then we might see progress in this area. If Apple doesn't keep up (although I expect they will), this is the domain I expect the killer app to emerge from.
I'm not sure why you bring up the device-id thing. Apple corrected that issue without external pressure. Also, in the real world, I think that expecting end-users to manage a second cookie-like entity with subtly different semantics to cookies is unrealistic.
A system that's built on a philosophy of eliminating capabilities can never progress into a system that allows a user to gradually learn more and empower themselves, as there's nothing "further down" that unifies the whole thing. Software that starts off requiring significant effort to administer can progress into having a user-friendly interface and be incorporated into systems with sensible defaults.
One shouldn't require a user to have to configure everything out of the gate (say, cookie policy), but one shouldn't prevent them from doing things they know they want. Wasn't the Apple device-id thing "fixed" by only allowing tracking on a per-app basis? With cookies, I can have them deleted every time I close the page.
Setting the straw-men aside, which systems did you have in mind?
If you had answered my question you would be able to pick out at least one thing that Microsoft had done that Apple had not.
You said: Microsoft did their job years ago, now Apple has to follow.
This is simply not supported by the facts.
On Windows a massive industry of malware detection has sprung up and still there are millions upon millions of zombie PCs out there. Meanwhile, despite no such industry on OS X there are no reports of infections in the wild (from viruses the original commenters claim, this article is about a trojan, which also is a lot more prevalent on windows than on the Mac.)
But don't let these facts get in the way-- remember, the point of this thread specifically, and a big amount of the draw of Hacker News, is that you can bash Apple and get up voted by other Apple haters. Facts are not relevant.
quick example: they paid millions possibly tens of millions for the best people from industry and academia to build automatic bug searching tools. these tools currently define state of the art for finding bugs in applications.
they also have a community outreach program where they will work with companies and individuals that report flaws. that same outreach program will work internally with the relevant product groups to get flaws fixed.
oh and also they invest constantly in improvements to their toolchain and operating system runtime to make exploitable bugs harder (safeSEH, ASLR, DEP, GS cookies, EMET, encoded pointers, safe-unlinked heaps both in user and kernel mode, etc).
and yet, you realize, there are still exploitable bugs. in my opinion you should regard this as the fundamental instability of system software written in C. if microsoft can't get that right (in terms of security and stability), after all that they've invested, who can?
2. I'd agree that the outreach program is something that Apple clearly hasn't done.
3. Apple clearly is doing this too.
HP's work on secret agents in the 90's shows that you can't prove code to be trustworthy. You can only assign trust to the intentions of the originator.
Therefore, the most significant thing you can do to improve security is to verify the provenance of trusted code and the isolation of untrusted code.
Windows clearly has decent technical code-signing infrastructure, but Apple seems far ahead in terms of effectively deploying this model into the field.
Microsoft has some good static code analysis tools ( http://msdn.microsoft.com/en-us/gg712340 ), for a start.
"3. Apple clearly is doing this too."
They seem more concerned about not letting users jailbreak their devices than anything else.
"Windows clearly has decent technical code-signing infrastructure, but Apple seems far ahead in terms of effectively deploying this model into the field."
"Far ahead"? How do you justify that claim? Most charitably, it seems that both companies work on security.
Of the two, Microsoft seems to have better documentation, better openness, and better tools.
By far ahead, I was referring to the deployment of code signing technology.
I think it's pretty clear that although Microsoft has solid code signing technology, they are much further behind in promoting effective use of it in the field.
Ironic that you would use a feature that excludes malware from running but pisses off android fans, as an attempt to claim that Apple is not working on security!
The compound word 'PreOrder' exists as a discrete term. ... case it as 'Preorder' or strip the first token entirely if it represents any sort of Hungarian notation.
Aw shit, Apple is gonna get fucked by all those remotely exploitable Hungarian notation bugs.
The stuff in Visual Studio is so far behind the state of the art I don't even know where to begin. But let's ignore that and recalibrate by asking this. What do you think the not quite state of the art second best automatic bug finding tool is?
This Java exploit was fixed for a long time before Apple so graciously bestowed a fix upon us. Then there's that SSL certificate SNAFU where I had to fix Safari myself, after almost all companies had already issued updates. Too bad that was not possible on iOS, where you just had to sit around and twiddle your thumbs.
The next best thing they'll have to do is, when they install it, disable the web plugin in Safari by default or add an interstitial that prompts the user for it to run.
One 500k node botnet really is not that large in the grand scheme of things.
And just to be clear, I'll admit that I'm not a disinterested party here. The Chrome security team carries the bulk of the WebKit security workload (fuzzing, auditing, fixing, etc.). That consumes a tremendous amount of my team's time, and prevents us from focusing more on Chrome. So, I'd definitely appreciate it if Apple were significantly more proactive about security.
I'd venture to say that Apple is more proactive than most other vendors about security because they look at the forest and not just the individual trees.
Again, show me an actual attack that has exploited Safari. Ever. Targeted, mass malware, I don't care. Apple has better shit to worry about and their investment in Seatbelt was worth 1000x more than individually fixing the limitless supply of bugs in Webkit. Problem solved, move to next actual issue.
At what point were you forced to take on the responsibility for fixing those bugs. It is an open source project and Apple may feel that their best contributions are in adding new features or fixing rendering bugs.
"The bug was patched by Oracle in February, but Apple didn’t fix the flaw until earlier this month. “Their response should have been much earlier when they should have updated their Java,” says Sharov"
Note a Trojan, is not the same thing as a virus. A virus self propagates, a trojan propagates when a user overrides a security warning.
Viruses have been a problem for Windows for decades, but not a problem on macs, since the late 1980s, possibly early 1990s.
And please try to keep up with the latest developments, this trojan requires no user intervention. Not running Little Snitch + antivirus at this point is just ignorant and asking for it.
The only way for them to improve security is to take it seriously, because the amount of code shipped with each release will only go up, never down. The attitude needs to change.
There is of course lots of data support this argument. Just do a quick Ctrl+F through http://support.apple.com/kb/HT5130 for 'arbitrary code execution'. 21 hits, and many of them in core apple components. These are almost extinct on Windows by now.
Actually, it went down with the Mac OS X 10.6 Snow Leopard release. Up to 7 GB less. [1]
1. http://en.wikipedia.org/wiki/Mac_OS_X_Snow_Leopard#New_or_ch...
http://technet.microsoft.com/en-us/security/bulletin/ms12-02...
http://technet.microsoft.com/en-us/security/bulletin/ms12-01... (two vulnerabilities of this nature)
http://technet.microsoft.com/en-us/security/bulletin/ms12-01...
http://technet.microsoft.com/en-us/security/bulletin/ms12-01...
http://technet.microsoft.com/en-us/security/bulletin/ms12-00...
Anyone who genuinely understand security understands that obscurity is not a form of security. There are many incidents of high profile targeted attacks against owners of macs that could have occurred in the past two decades if Apple hadn't been taking security more seriously.
Oh, no, wait, its the reverse!
Will this equation change significantly with the new botnet? I think it's unlikely, but I dunno. Regardless, all-or-nothing seems to be the wrong perspective from which to examine this problem.
How responsible :)
What antivirus group...
Does Apple even have an antivirus group?