Evidence suggests first zombie Mac botnet is active
arstechnica.com
arstechnica.com
I don't know the details of this particular story but I have seen blatant scaremongering and misinformation in the past when it comes to Macs.
Not just Macs, anti-virus and security professionals are experts in all computer FUD (regardless of platform)
"There's a much, much bigger hole than any programmer could possibly exploit: The annoyance factor." Source: http://it.slashdot.org/comments.pl?sid=222252&cid=180030...
[Quarantine Fluffy Bunnies] [Continue running Fluffy Bunnies without granting additional permissions] [Grant additional permission]"
[more information dropdown] = "Fluffy Bunnies Screensaver has asked for permission open your computer to connections from other Internet users, run programs downloaded from the Internet without informing you, and install a program that loads when the computer starts. These actions together fit the pattern of behavior displayed by many viruses.
This does not necessarily mean that Fluffy Bunnies Screensaver is a virus, but if you don't understand why Fluffy Bunnies Screensaver is requesting to do these things, please try to run the program without giving it these additional permissions; the permissions Fluffy Bunnies Screensaver has requested may not be necessary for it to work properly."
Only if you click "Grant additional permissions" does the password input field appear/enable. Additionally, below the password box, a listbox also appears with (by-default-checked) checkboxes for each right that the program has requested. If you wish, before confirming your password, you may disable some of the rights, without disabling others. This may, theoretically, allow you to run an infected Installer program (that requires elevation either way) without actually being infected by a virus attached to it. (You might still be infected if the Installer installs the virus.)
If, instead of indivual windows, there were some central "conversation window" where the computer would ask you questions, then leave both the question and answer available for viewing and correction, things might improve. In fact, more things could be presented to the user as "beneficial, but not necessary" decisions to make (changing preferences from their defaults, etc.) This scheme reminds me of SimCity's Advisors window, oddly enough, and also bears a similarity to Windows 7's Action Center.
The biggest difference is that every decision would now need a "safe postponement default", in case you don't "check your messages." In the elevation case, programs would have to be rewritten to not expect to be elevated as soon as they ask for it, but rather try to do whatever possible with the priveleges they have, and then queue up a list of things to do if/when they get elevated (which may never happen.) for instance, under this scheme, Installers would always install to a user-writable location, then queue a move operation for post-elevation.
The 20% that takes 80% of the work, in this case, is figuring put what to do when the user works outside of the elevation framework: what to do when you move the folder the program was waiting to move, or what to display in the conversation transcript when you change a preference in the Preferences window that you originally chose in the context of a Conversation.f
They don't look much like Windows/OS X botnets; instead of this trojan horse stuff they'd just crack insecure services or guess poor passwords and escalate privileges automatically. If you have any Ubuntu servers, tail /var/log/auth.log (similar names on other distros) you'll see trying to ssh in.
The only thing preventing this from happening in Linux is a lack of interest by trojan writers (they could already do it with vmware workstation which is surely available on pirate sites and requires root privileges to install) and perhaps a lack of proprietary 3rd party software (which I'm sure a lot of people will say is a good thing, but that's another discussion).
Repo security is certainly very important. But well, ultimately you have to trust someone?
But I guess that there are two ways to feel really secure : either use openbsd, or just don't use the internet.
...you may already be a zombie.
Just don't even go there.
It's happened before (there was a trojan in pirated copies of iWork '09).
Checksums won't help much because pirated software is often expected to be modified and Adobe (for example) doesn't have a lot of interest in providing finely grained checksums so you can make sure your pirated software is safe[1].
[1] Granted, there could be the "well, help us prevent botnets for the greater good" argument, to which Adobe would respond "well, if you stop the piracy it wouldn't be an issue, now would it?"
A really good burglar can pick the locks to my house, but I still lock the door.
It may slow down your PC initially, but it keeps the performance for life. You might have great performance after a fresh install, however it doesn't last for long.
Personally, I'd rather have a working PC than have to deal with a BSoD. I doubt I'd get many virus' and such as I don't download those kinds of files. However if you have a teenager in your family either whip them every time they try to touch a computer, but the way that's less likely to end in your incarceration is installing virus software.
The choice is prevent or protect, and I'm guessing many people here could prevent through their browsing behavior, I doubt the same could be said for any 12-16 year olds.
The trick for both is using it.
I find a more viable approach is to be careful with the OS install (not install untrusted stuff) and also to make it expendable. Data lives on a single-purpose unix host and is regularly backed up so I can do a predictable, quick, low-effort reinstall and be back to operation in a couple of hours.
An outcome I've wanted but not done - computer lives behind a router which is set up to make active monitoring and managing of traffic easy. Product idea - consumer-ready but geek-friendly router with powerful but easy-to-use tools that doesn't suck. Interface should be live so that you can see the traffic coming and going, and there should be controls to allow you to open up and close access to different sites. Stand-along system with a profile a bit like a sunray, plug for commodity keyboard and monitor.
Malware will also slow down your computer, and could result in your personal information being stolen. If the choice were between waiting an extra few seconds for my computer to boot or having all of my files accessible to people I neither know nor trust, I would choose the former.
If you're working without at least common-sense anti-virus protection, you're going to deserve what you'll eventually get.
I'd like to know what your definition of "common-sense anti-virus protection" is, though. Apart from "don't download/install anything from untrusted places".
after a dmg comes an OMG ;)