Mac OS X Isn’t Safe Anymore: The Crapware / Malware Epidemic Has Begun
howtogeek.com
howtogeek.com
No malware literally logs keys typed anymore. I cannot stress that point enough. Instead they log form submissions (e.g. POST requests) which give the malware author much more useful information they can data mine in an automated way (e.g. URL, named parameters, etc). This works even on a "secure" page (e.g. HTTPS with extended certificate).
I'm super tired of supposed power users or "geeks" telling others to copy/paste in their username/passwords to improve security. That's not how this works, it isn't how any of this works. Nobody reads raw key-streams, they're completely useless because they fail to contain CONTEXT (i.e. where you typed what).
Sorry, just a pet peeve of mine. The term "keylogger" is largely a misnomer. A more accurate name would be "credential hijacking" or "form submission theft." A lot of malware actually use standard injected JavaScript to add event hooks to a page, to fire the data back to a evil browser extensions.
If that provides security really depends on what the "bad guys" are hooking. If they're placing event triggers straight onto text box/button/form elements themselves (either through JavaScript or grabbing something akin to Win32 messages) then that wouldn't do anything at all.
Even if they did grab the raw POST request (which is somewhat common) a hash would only provide security if it was merged with an anti-forgery token sent from the server, otherwise the "bad guy" could just re-post the exact same hash and login anyway.
I think it really boils down to how popular your site is. If for example Facebook did that, because it is popular enough with the "bad guys" they're going to spend the time circumventing any JavaScript-based security you could implement.
That's true, thanks for the response.
LiveJournal used to do it. No idea if they still do. I don't think it ever caught on.
No one's account is getting broken into by password guessers. Your obnoxious 16 character password will be stolen just as well as a 1 character password.
Yeah, not really. Like it hadn't began all the other times in those last 14 years that such articles appeared.
I've used Windows for decades (still do ocassionally), and had lost count of malware, adware and viruses I had to battle. So, don't tell me about "malware epidemic" on OS X with a straight face...
This is largely a user problem now. I haven't caught a single problematic download on my Windows 7 box.
Why don't you try looking things up and scanning them before installing? Whatever you're doing doesn't seem to be working.
EDIT: A commenter below reminded me of another rule that I follow when I get a new machine: Always do a clean install with my own copy of Windows (usually from MSDN or an upgrade offer).
http://windows.microsoft.com/en-us/windows-8/create-reset-re...
http://arstechnica.com/gadgets/2015/02/save-yourself-from-yo...
Had tons on Windows XP, and several in 7.
>Why don't you try looking things up and scanning them before installing?
Can't and won't be bothered. What am I? The OS's servant?
I'd rather have an OS that doesn't get me viruses, either through enhanced security and sandboxes, or through scarcity of malware.
Plus, it's not even about "scanning" etc. Lots of adware for example comes in totally legitimate forms. Heck, even the base Windows install from some OEMs has ad- and spy-ware installed...
> I'd rather have an OS that doesn't get me viruses...
No problem. The OS isn't the one getting you viruses. It's you.
> Plus, it's not even about "scanning"...
Yes, that's why I said to do a quick search on the Internet, to see what other people are saying about a given piece of software. If you can't be bothered to do that, then you deserve every piece of malware that you get.
Walking wasn't created to automate tedious tasks. Computers were.
Your "common sense" is of those who accepted as a law of nature that you have to defragment your hard disk, clean your registry every now and then, and re-install your OS when it gets bogged down to get a clean start.
Some other stuff that was also "prevalent wisdom" among Windows folks...
>Yes, that's why I said to do a quick search on the Internet, to see what other people are saying about a given piece of software. If you can't be bothered to do that, then you deserve every piece of malware that you get.
Or you know, use a proper sanboxed OS and matching software, like it's 2015...
It's not like permissions, sandboxes, chroot jails and containment is some hot-new fringe research topic...
TempleOS is probably a good fit for someone like you. Enjoy that!
Power users might also appreciate Little Snitch[1] to see what their Mac is connecting to.
I'm imagining Grandma pulling up the "Application Warehouse", let's say, and clicking a download button under a VLC icon. It gets downloaded from a trusted source over HTTPS, gets checked against a hash, symlinked and Gran's ready to go, all without the hassle of shady installers from the search engine shitpile.
MacUpdate is still running one though: http://www.macupdate.com/desktop/
It skips all the garbage and installs the application.
E.g. I trust the macports maintainers, even if I don't verify the sources for each thing I get through `port install`.
That's the old default Credits.rtf.
Most of the infections on Windows aren't due to some huge security issue on Windows that Macs are magically immune to. They are due to the users themselves installing adware or malware-infected software from sites online. Now that there are more Macs out there, the reward is greater. So, there is more revenue to be made form adware-laden software and a better return for the time investment/risk of creating malware for Macs (to send out spam, be used in DDoS attacks, sniff for and steal financial info and passwords, etc).
Most of what Windows has implemented since 7 with UAC, MSSE and now integrated with Defender is a layer on top that introduces some failsafes. I won't argue that it's been a massive and much-needed improvement to Windows, but Java and Flash still provide viable vectors to bypass it and infect a Windows machine.
Designing actual viruses - stuff that has the ability to read and modify the filesystem - is still harder to pull off undetected on OSX. This article intimates as much. Most of what's included here is either bundled applications you don't want - but you still have to actively find and then agree to - or browser modifications. Neither of those is within 500 sqmi of, say, CryptoLocker.
"Most of the infections on Windows aren't due to some huge security issue on Windows that Macs are magically immune to. They are due to the users themselves installing adware or malware-infected software from sites online."
This is 100% accurate and what most home users have to deal with in terms of issues on Windows. The vast majority of Windows issues that end users experience and get frustrated over have nothing to do with Java or Flash flaws or needing to compromise a system. The users themselves give the apps permission to install and do their thing.
It's also worth noting that Java and Flash don't provide much of an attack vector for the majority of Windows users you and I know anymore either. Firefox won't permit outdated versions of the Java or Flash plugins with security issues to run and will direct you to update. Chrome has its own version of Flash built in and automatically updated with the browser and disables Java by default. Even Internet Explorer blocks outdated ActiveX plugins like old and insecure versions of Flash and Java these days.
Are there improvements on the browser and OS side that are helping? Sure. Do those impact the vast majority of Windows users? Probably not. Look at browser & OS version usage and you'll see that the "users you and I know" are probably not indicative of the majority of users in general. At least not yet.
What I'd meant by that line was that this doesn't apply to users in other countries where the majority of users are still using hacked (and completely insecure) versions of Windows XP. Sadly, Windows XP still represents about 19% of online users. Thankfully, most of those users are using a 3rd party browser as IE 6 is down around 1%.
...Unlike Mac which doesn't have Java or Flash?
Remember, you don't need administrative privileges to destroy everything belonging to the user, which is most things you care about. And even if you do, elevating is trivial on both Windows and OS X.
Java and Flash behave no differently on OS X than Windows. They are no more or less of a hole in either OS. In fact, there are more protections against Java and Flash bugs on Windows. There just also happens to be more attacker investment in those platforms as well.
I keep hearing this stats, and it's not true that a platform is hit based on how much share it has.
Share does affect the volume of the available malware, but not whether it exists or not. And for 10+ years on Mac it was unexisting -- all such cases touted by the media were proven to be trojan horses, not viruses and such.
Contrast with Mac OS classic that was plagued by lots of viruses, despite having 2% market share at best at the time. Or even platforms like the Amiga and Atari -- viruses were prevalent.
Most of the issues today are about money or reputation.
Adware and spyware makes money for the publisher, so they target areas where they can do that. It's actually legal and semi-legitimate. It's an annoyance for the end user, of course. A freeware publisher doesn't make any money from their app but they can make money from bundling an ad replacer, search engine replacer, browser extension, etc with their free software. So, they do.
Malware follows the same trail. You can distribute cracked software online over torrents like Photoshop and the like but sneak your remote-controllable malware into it. Then you get more installs you can use to direct a DDoS bot attack or to watch for and steal financial details from the local machine. Maybe look for the default install of a cryptocurrency client and grab the local wallet, for instance. Note that this is more difficult on both modern Windows and modern Mac than it was back in the days of Mac classic.
I don't install too much outside a package manager in any OS... just the same, it is a pretty significant issue.
Not sure how significant. Haven't seen anything in the wild on OS X -- and I do install lots outside of package managers...
A few on windows are doing transparent proxies, which are pretty nasty (not just the lenovo one).
I don't believe the "overpriced Mac sheeple" meme at all, but there always seemed to be an overlap between people who dismiss them as "safe because they're so rare" and "Apple tax LOL" critics. That always struck me as an interesting dichotomy.
Full stop. That's a ridiculous statement to make. Are we really pining for a return to such an oblivious mentality? Good riddance.
I will stipulate it's a true statement. Still foolish.
I'd like to think most technical people realized that Mac was simply not popular enough to be targeted. But most users were simply under the impression their choice of OS was magically protected. From article: "Since it is actually Unix under the hood, OS X has some native protection against the worst types of viruses." Hey look, it's got Unix, I'm totally safe.
I agree with the first part of this but not the second.
Let the fuckers pay for that
Yeah, that'd be just awesome.
That could just be the default, and the user could disable it. On Windows 8/8.1 the default is for the "SmartScreen Filter" to block "unrecognised" applications from being run or installed. See their FAQ [0]. It can be disabled however.
If someone is smart enough to be installing applications from third party sources themselves, then they're smart enough to flip a switch in a Preferences panel to enable it.
However this does protect the lowest common denominator who these malware are actually targeting (i.e. computer illiterate individuals who will click ads in search results).
[0] http://windows.microsoft.com/en-us/windows7/smartscreen-filt...
Apple already made their move and it was a nice compromise called Gatekeeper.