Kaspersky Lab: Apple is '10 years behind Microsoft' on security
tuaw.com
tuaw.com
For example, when an open source software project bundled with Mac OS X releases a security update (LDAP, Apache, Java, etc), it sometimes take Apple months to merely test it and ship it out.
OS X was also very late, compared to Windows, in implementing in-depth defense mechanisms such as address space layout randomization, stack protection, etc.
And last August, it was discovered that LDAP auth on OS X blindly accepted any password! Apple's code review and testing processes must be very immature to let such a glaring vulnerability ship to customers http://forums.macrumors.com/showthread.php?t=1197379
But I think Apple is slowly and finally understanding the importance of security in their software ecosystem...
These are not areas where Apple is even close to 10 years behind Microsoft.
The statement here is absolutely indefensible, In 2002 OS X was way ahead of Microsoft on the security front, and OS X has not gone backwards since then.
Also OSX has been leading the charge towards developer signed binaries much more forcefully than Microsoft.
The former claim is impeached by the latter.
> it sometimes take Apple months to merely test it and ship it out.
This is a dishonest characterization. I'd rather Apple continue to ship a robust and secure operating system, than to simply patch it every time someone releases an update that passes its regression tests, with the subsequent breakage of other packages and new security holes, none of which are caught by regression tests.
>OS X was also very late, compared to Windows, in implementing in-depth defense mechanisms
I really don't think 2001-2002 counts as "very late".
>Apple's code review and testing processes must be very immature to let such a glaring vulnerability ship to customers
Please explain to me why there are known security holes in windows that have existed for 15 years?
>But I think Apple is slowly and finally understanding the importance of security in their software ecosystem...
Damning with faint praise. Apple has taken this issue seriously since 1987. Microsoft makes too much money from being vulnerable to take it seriously.
This is just more nonsense from apple bashers based on characterization... Great for clicks but it impeaches you as an engineer.
That's the thing, how is it robust and secure if Apple takes months to release security updates for said open-source software?
> I really don't think 2001-2002 counts as "very late".
You misread his comment. He is saying OS X was not released with in-depth defense mechanisms. Thus its release date is of no consequence.
> Apple has taken this issue seriously since 1987.
Forgive me for my skepticism, but what security concerns, exactly, did Apple face in 1987? 1987 was in the middle of the emergence of word processors.
Really? 2001-2002 is when OS X got in depth defense mechanisms, thus the date is relevant-- it proves shows how full of it he is. So, I didn't misread the comment, I rebutted it by citing the date.
>Forgive me for my skepticism, but what security concerns, exactly, did Apple face in 1987? 1987 was in the middle of the emergence of word processors.
And the emergence of viruses. Where were a real problem on the Mac from 1987-1990.
>That's the thing, how is it robust and secure if Apple takes months to release security updates for said open-source software?
Because just shipping patches without testing them produces a brittle OS and opens them up to having security holes.
I'm tired of these argument-from-ignorance claims that seem to be common on hacker news. If you're going to disagree with me, at least please take the time to read what I wrote and comprehend it and disagree with what I'm saying. Don't just dash off some response based on your lack of knowledge of history, and what I'm arguing.
You criticise Apple for taking too long to test and ship out security updates. And then criticise Apple for not testing enough.
Which is it ?
In combination with DMA access from the Firewire port it can be quite fun[1]. Although with Lion, you can't use DMA when the machine is locked.
"Secure Virtual Memory" only does just that -- Encrypts the memory that is being swapped out to your disk. I've never done a memory dump and found the FileVault password has been swapped out. Probably because it is being used all the time to secure disk read/writes.
The latest OSX really is behind the latest Windows on the security front. Windows has just been the focus of intense hammering on that front over many many years and they've been force to improve their game.
And I say this as a mac user, as 99% of my pentester colleagues are.
For starters, people were still running Windows '95 (or worse). A fresh install of Windows would be infected just by connecting it to the internet - and within 15 minutes depending on where you were. All web browsers had multiple vulnerabilities, and by far the worst was Internet Explorer.
Everyone ran everything as root/administrator.
Yes, today is just like Microsoft from 2002.
At that time, I found IE to be superior, actually.
Also, do you have more information on the infected-within-15min claim? I'd like to know more about it...
How about this, lets look at application programming language. Apple uses objC, Microsfot increasingly uses C#. What does this one metric get us?
I believe it was Paul Graham himself who 10 years ago mentioned that to scale a company you should have your top developers just develop the tools the rest use. This was also around the time Microsoft was at the height of the buffer over flow bugs.
Slowly they transitioned much of their code to the memory managed language of C# that their best developers made.
Their entire development process, developer allocation and development language changed in part in order to meet security needs.
Mean while Apple still develops everything in un memmory managed objC.
That's just one example of how long Microsoft has been transitioning the entire company to new more security focused practices.
The point is, to be really good at security, you have to be really focused on it, at all levels, in an all encompassing way. Microsoft has been transitioning to that for a long time and it's paid off. Apple hasn't even started. And that kind of massive corporate change in companies this big doesn't happen over night. And look how much public shaming it took to kick it off for Microsoft. I think we can look forward to a new golden age of Mac insecurity over the next few years before the process even kicks off.
And this is probably how Kaspersky Lab came to say that Apple is 10 years behind Microsoft on security.
We also might want to take a statement on the security of a platform by a company that makes their money securing people's computers with a grain of salt or two
Further, its astounding the amount of fear mongering I've seen from security firms and windows "security experts" over the past several decades. Literally they make their money by scaring people into buying tools.
I believe you need those tools if you run Windows, but you don't need them if you run Linux or OS X.
The idea that C# is superior (and by the way, the OS is not written in C#) to Objective-C for security is asinine.
The way Objective-C has been handling memory management since its inception is far better than most of the other languages around.
And the decision to have deliberate mutable/immutable data structures is something ALL languages should have.
Even the apps that Microsoft themselves have written (e.g. SCOM) are pretty poor. That's fine for enterprise software, servers and so on where you can easily throw more hardware at the problem, but I'm very thankful that of the 100-ish processes running on my laptop at the moment, most are not written in C#. Also, Microsoft have recently been stating their intention to bring back some focus to native (C++) development for Windows.
Though, I feel C++ is sub-optimal as a native language, given how easy it is to shoot yourself in the foot. It doesn't have to be so dangerous to write performant native code. Why is it that D never really took off?
Btw., interestingly, Apple starts to use ObjC more and more on MacOSX. E.g., since 10.6, Finder (the main fs browser) is a Cocoa application now. I guess the Windows Explorer is still C++?
Apple doesn't ship the patches that Oracle or other third parties ship as quickly because this is how they work. They want to make sure that everything results in the best experience for the user.
"But wait!" you'll cry. "Getting a virus because of a slow update isn't the best experience!" Well neither is shipping a patch that causes more issues than it fixes.
Hopefully, the outcry of the users that they are getting viruses will up Apple's security efforts. In the next version they've already signaled that they think security is important because they're shipping Gatekeeper. I'd also like to point out that many, not all, but many of the bugs that are being used as exploits are in third party software (probably with the exception of Safari which has some serious issues).
Do you think that the Mac was a major force in the 1980s, but has been safe in obscurity since then?
Apple has been serious about security for 22 years, at least, and measurably better than Microsoft for 18 years.
It is absolutely absurd to ignore that history and pretend that nobody was interested in messing with the mac, when they were interested in messing with it in the 1980s.
But what else can you do when you are an apologist for microsoft? Admit that they make billions from their security holes?
It is absolutely absurd to ignore that history and pretend that nobody was interested in messing with the horse carriage, when they were interested in messing with it in the 1800s.
Apple killed the virus problem of the late 1980s dead, with only the most robust viruses surviving in the early 1990s, but none since. Apple has had an automatic updating program for at least 15 years, long before Microsoft, including monthly (if needed) security updates patching holes as they are found.
Microsoft makes a lot of money from the security holes its own products, many of which were put there deliberately as "marketing features" that later turned out to be security vulnerabilities that apparently Microsoft finds it unprofitable to close.
I've seen the source code for both Windows and OS X. Windows is very poorly engineered in general, with a great deal of cruft (leading to inadvertent security holes) while OS X is generally well engineered, benefits from being open source and pulling from open source BSD and from being fostered by a company that does not make any money from shipping security holes.
However, Apple's superior quality for the past 2 decades has resulted in a great deal of growth in profits and prominence for Apple, and this means that you can always get a lot of attention by claiming Apple has security holes. In fact, people have been making these claims for the past 15 years, in articles like this.
And yet there aren't massive botnets of Macs (the one trojan that got any traction has been eliminated) while there are millions upon millions of infected windows boxes out there to this day.
The idea that Microsoft is ahead of Apple on security is a joke to anyone who knows their history or knows their engineering.
Ok, You got me. This is obviously a troll, and I responded.... and of course the people commenting here seem to have no real knowledge of the matter, but anyone not bashing Apple is getting down voted.
This is the kind of crap that makes "Hacker" news suck.
[citation needed], please. I'm not being snarky - in fact, if you have a citation, I'd love to be able to use this in my discussions with others.
So there were no vulnerabilities and all the patches that Apple released were NOOPS?
> ...the one trojan that got any traction has been eliminated
Really? From http://www.forbes.com/sites/andygreenberg/2012/04/20/antivir...
>The idea that Microsoft is ahead of Apple on security is a joke to anyone who knows their history or knows their engineering.
So Eugene Kaspersky, the founder of Kaspersky Antivirus and Kaspersky lab doesn't know his engineering and history but you do. Somehow I think the onus is on you to prove your credentials are better than him.
>"Security firm Dr. Web released new statistics Friday showing that the process of eliminating Flashback from Macs is proceeding far slower than expected: On Friday the security firm, which first spotted the Mac botnet earlier this month, released new data showing that 610,000 active infected machines were counted Wednesday and 566,000 were counted Thursday. That's a slim decrease from the peak of 650,000 to 700,000 machines infected with the malware when Apple released its cleanup tool for the trojan late last week. Earlier in the week, Symantec reported that only 140,000 machines remained infected, but admitted Friday that an error in its measurement caused it to underestimate the remaining infections, and it now agrees with Dr. Web's much more pessimistic numbers."
Are those propaganda and lies too?