Snow Leopard contains hidden antivirus application
blog.intego.com
blog.intego.com
Then there's a leap to the conclusion that it is an anti-virus facility.
Did I miss some important detail here? I thought a virus was a very specific type of malware, and there's not enough detail to conclude that it is "anti-virus".
It's probably better not to dignify the "science" of malware by enforcing proper usage of terminology.
That a given operating system is vulnerable to malware in general is not notable, because users will be duped by dancing babies, porn, and infected stolen software.
That a given operating system ever allowed unaided self-replication take place is, and this is where Apple's marketing message has been placed.
There's no operating system in common use for which malware distinctions are meaningful. They're all equally vulnerable.
* A trojan requires a user to grant the malware privileges, or just to install it or at least to run it with their own privileges.
I don't see how that's not an important distinction.
Neither OS X nor Windows has any current published unpatched remote code execution vulnerabilities.
Nothing in the architecture of OS X or Windows prevents remote code execution vulnerabilities.
About the best thing you can say for OS X with respect to this problem is the fact that most of the "interesting" services are disabled by default, which did not used to be the case on Windows. I don't disagree that this was a win, but it was hardly an architectural difference.
> Huh? There is no feature in OS X that makes it any harder to write self-replicating code ("worms"). Code running in almost any OS X process has full access to all the xnu system calls, and (invariably) to at least one user's home directory and Library/ folder.
That's not what a worm is, and you keep mixing up terms in this thread.
* Malware is code that does bad things to your computer.
* A virus is self-replicating code that probably does bad things (harmless, proof-of-concept code is sometimes let loose). A virus is a kind of malware.
* It's a worm when it's delivered and spreads over the network by a remote exploit.
* It's a trojan when it's delivered by tricking the user into installing it.
The difference between malware and a virus, okay that's fairly minor, but a virus vs a worm vs a trojan is significant. This isn't some lingo the kids use on IRC either, these are all terms you can find int he OED (at least the one that comes with OSX).
The meaningful topic you can debate is whether OS X is more or less resistent to any form of malware than Windows is. I'll argue that there's simply no significant difference, and, respectfully, I think you'll lose with the opposing argument, but I'm happy to hear you out.
The distinction OP is trying to make is an important one for the implications that the different terms carry. For worms, to protect yourself, you just have to avoid doing the computer equivalent of picking up a needle off the sidewalk and jabbing it into your arm. not hard. For viruses, I have to avoid breathing.
The original topic says that snow leopard has anti-virus software, which means apple is admitting that everyone without snow leopard is boned. But, if the fact is that it's just anti-worm software, well, thanks apple for the chain mail sleeves, but I probably would have been OK otherwise.
Now, what does this have to do with OS X security?
For the record, 'virus' was first used by Fred Cohen in his 1988 PhD thesis. The word "worm" was used as early as the early 80s at Xerox PARC, when they were researching the possibility that they might be beneficial to networks. Those were the only two that I bothered to track down, but it's clear that the taxonomy of malware predates the modern anti-malware industry, so you can't rationalize dismissing the nomenclature that way.
I think throw_away's post adequately answers what it has to do with the security question, with an excellent example of stabbing yourself with a found needle versus the mere act of breathing.
My problem with malware "research" isn't the patent medicine industry it's spawned, but rather the very poor CS work done in it. Look at the last 5 years of vulnerability research and where it's taken distributed systems research, compiler-theoretic research, and just basic systems research; compare to "virologists".
I'm arguing that no matter what you opinion about what the difference between a "virus" and a "worm" is, this whole tangent has nothing to do with OS X.
I'm happy to converse about either the shallowness of Fred Cohen-brand virus research or about OS X security, but what you're seeing is me trying to tack us back to OS X.
I'm a "tools man", and I think that tools should be judged by their merits. Words are tools we use to communicate. Names are tools we use to identify. Taxonomies are tools we use to classify. How classification ties into understanding and addressing problems should be self-evident.
I don't care if the progenitor of a term is from the wrong "scene". If he ran over your dog, seduced your wife, and stole your grant money, I feel for you - but even if his crowning achievement is just one lowly but useful addition to the lexicon, then kudos for him. No amount of argumentum ad hominem on your part is going to divorce that tool from its intrinsic utility.
Yes, fluffy social & political stuff has its value too, I just didn't expect it rear its head here at HN. Now that I realize what's going on, I'll duck out.
It was fun.
The fact that this is built into the OS and doesn't have to be separately installed, upgraded, or managed fits in perfectly with what makes OS X a great and easy to use OS.
Just another example of the difference between "safety" and "security". Houses in Kennilworth, IL need less security than houses in Rogers Park --- there are something like 192 police officers per Kennilworth township block --- and yet Kennilworth houses can be counted on to have state-of-the-art security, because they can, and state-of-the-art security is a selling point.
I share your take on antivirus software, but do note that preventing a user from installing something with a known virus on it does not have negative utility.
So many people these days just install anything without really checking what it is. I don't consider this anti-viral, more like a condom for the lazier users.
The sort of "oh hey, QuickTime needs to update, run this file" should automatically set up alarm bells in everyone's heads.
OSX is lucky in this respect - it has Sparkle, which for a large part has become the de facto software updater for OSX. It has a simple UI that users recognize and approaches universal adoption.
Vulnerabilities in need of patching for desktop apps generally take the form of accidentally executing malicious input -- with Sparkle in a document-based Cocoa app, that input is already being parsed before Sparkle is loaded.
It's even worse for plugins -- if you use ClickToFlash you know exactly what I mean -- as a plugin to a Webkit plugin, Sparkle runs roughshod over the address spaces of every Webkit app. If said Webkit app itself uses Sparkle, you're fucked, especially if it's a different version of Sparkle, or one of it's many forks.