Contest goal: To lay to rest, once and for all, the myths surrounding the lack of spreading computer virii on the Macintosh OS X operating system.
Today, DVForge, Inc. announced the Mac OS X Virus Prize 2005, where the company is openly challenging all of the computer coders of the world to go after the $25,000 cash prize that they are offering to the first person to successfully create and deploy an “in the wild” active virus for the Mac OS X operating system.
For the contest, a ‘virus’ is defined as executable code that attaches itself to a program or file so that it can spread from one computer to another, leaving infections as it travels between computers.
For the contest, an ‘in the wild’ virus is defined as one that is able to spread as a result of normal day-to-day usage onto two or more randomly selected computers that are connected only via the internet.
Are you a clever software geek, bored, looking for a challenge for your immense skills? Would you like world-reaching fame, and, a $25,000 cash prize? Well, here’s your chance for fame and fortune. All you have to do is put a virus into circulation that makes its way onto two totally unprotected Mac OS X computers we have running in Hendersonville, Tennessee. No trick, no hidden barriers… just two open internet connections to two non-firewalled, unmodified, bone-stock OS X 10.3 Panther systems, each tied directly to the ‘net by a T-1 line. According to the PC press, picking up this 25-grand should be child’s play.
“Symantec Corporation has recently released information to the press suggesting that they believe that the Mac OS X platform is at substantial risk to a new virus infection, and that the principal reason that OS X presently has zero in-the-wild virii is simply the lack of interest by virus coders, due to the platform’s comparatively small market share,” says DVForge CEO, Jack Campbell in the press release. “We recognize that assessment as complete nonsense, and, we have chosen to make a challenge that is interesting enough to grab the attention of any malicious coder… $25,000 worth of interesting. I happen to believe that Apple should be offering this prize. But, since they have not, I will. On behalf of knowledgeable Mac users everywhere, I am putting my money where my mouth is.”
We have designated two G5 Power Mac computer systems, each running an unmodified retail installation of OS X 10.3 Panther, each located in the Hendersonville, Tennessee area, but located approximately 3-miles away from each other in entirely different facilities. The only network connection between the two systems is the internet. Both Power Macs are on a minimum 8 to 12 hour per day, five to seven day per week usage, and run any number of popular Mac software applications. Each uses OS X mail.app as the email client, and Safari as the web browser, with neither machine or its LAN having a firewall in use. Each is connected to the internet through an unencrypted Airport network, to a full T-1 line.
Each day, we will scan both Power Macs for the presence of an OS X native executable virus, using a commercially available virus scanning utility. The day we locate a copy of the same virus running on both Power Macs, that virus is the winner of our contest.
To win the contest, the person coding the virus must submit an email notice to us with a transcript of at least 32 contiguous characters of code included in the virus, a brief description of the functionality and symptoms of the virus, and contact information for contest notification and payment of the $25,000 prize. The prize will be awarded to the person whose 32-character code sample, and functionality and symptoms description match the actual virus detected on the two contest Power Macs.
There has been much misinformation publicized recently about a supposed risk to the OS X operating system from virus attacks, with the ‘risk’ supposedly increasing as Mac computer sales are increasing. As a Mac dedicated business, and as a group of long-term Mac users, we know that these warnings are not true, and that there are a number of fundamental safeguards against virus attacks that keep the OS X operating system without its first in-the-wild virus. The ‘small number’ of Macs has nothing to do with the lack of virus incidents. It is the architecture of Apple’s operating system that protects its users from these bugs.
We are operating this contest until midnight July 31, 2005. Should the conditions for winning be met prior to that time, we will immediately award the $25,000 payment to the virus developer who succeeded in cracking the Mac’s inherent immunities.
Prize Doubled For Symantec
DVForge, Inc. has specifically invited the programming staff at Symantec Corporation to participate in their contest by creating and successfully delivering an executable virus to the two contest Power Macs. Should an employee or independent contractor of Symantec corporation win the contest, they will double the prize to $50,000 for that person.
Complete details on the DVForge Mac OS X Virus Prize 2005 contest can be found at http://www.dvforge.com/virus.shtml
Related MacDailyNews articles:
DVForge cancels Mac OS X Virus Prize Contest – March 26, 2005
Motley Fool writer: ‘I’d be surprised if Symantec ever sells a single product to a Mac user again’ – March 24, 2005
Symantec cries wolf with misplaced Mac OS X ‘security’ warning – March 23, 2005
Symantec’s Mac OS X claims dismissed as nonsense, FUD – March 22, 2005
Symantec warns about Mac OS X security threat – March 21, 2005
68,736 Microsoft Windows viruses vs. zero for Apple Mac’s OS X – March 12, 2005
Mac OS X has no viruses; what’s wrong with Windows? – February 11, 2004
hmmm… 25,000 to go to jail and have my record tarnished for life doesn’t seem like a great deal
It’s it illegal for this offer to even exist? just curious….
What a jerk-off. Someone should give HIM a virus
Awesome! This will be fun to watch…
First Post!
It’s Jack Campbell, at it again….
Seriously, what a jerk. Nothing is impregnable. I know OS X is tough, but asking for malware?
I’d like to offer $25K if anyone can break his ego.
I can see a letter from Apples lawyers arriving shortly.. the offer won’t stand long.
It’s similar to the offer that was made to the first person to graffiti one of the new Metro trains here in Denmark and to have in publicly photographed and appear in the press. Crazy idea!
Some people’s kids….
Good points, but nothing says the virus has to be malicious or destructive. Can you be prosecuted of the virus does no harm?
Now we know how Anti-virus SW companies operate. They create virus to sell their anti-virus. Now, they pay people for making viruses. What a noble business.
This is great because it wont happen. and the virus’ only current target is the contest Macs. So, even if a virus is created, the writer may only choose to infect the contest Macs. Also, I’m pretty sure a contest like this was done before, for the classic OS I believe—nothing came of it.
won’t it be rather easy to do so? all the security updates that have passed the show from 10.3.0 to 10.3.8..
and they are running an out of the box os x 10.3 system..
without a firewall. Heh.. why put the firewall off? isn’t it enabled by default?
this can’t be good…
The challenge seemed “OK” until he described “releasing it” via the NET…perhaps he should provide the two IP addresses of each Mac and indicate that the “virus” should only attack those two machine…to invite someone to create a virus and suggest they release it in the wild is probably a crime according to the DMA…or it should be – it’s definitely to be considered conspiracy to commit computer crime.
On the other hand…I’m actually a bit amused and interested. I hope many hackers try and fail. I’m tired of defending OS X to the PC masses against the security thru obscurity myth.
“Can you be prosecuted of the virus does no harm?”
Absolutely.. can you be prosecuted if you break into someones home if you don’t do any harm?
The first actual virus to penetrate OS X causes me and my investment substantional harm.
You need to think a little more before you make such nieve statements.
obviously they want to infect other mac so they can see antivirus software. A firefighter without a fire gets bored. They need our business so they will infect us to get us to buy thier products.
go to MacInTouch and search for “Jack Campbell” to find out what DVForge is all about …
Wait…how many idiots are out there?
How about a contest of:
– $20,000 to first person for breaking into the local convenience store and stealing all the beer or…
– $15,000 for whomever can slash the most tires in one hour at the local mall or…
– $10,000 for the first person to scratch all the CDs in a Music store with a rusty nail or…
– $50,000 to the first person who can poison their town´s local water system or…
– $100,000 for the first person that creates a flu virus that kills 100,000 people.
Sheesh! Some people have the stupidest ideas.
Since when is soliciting unethical (somewhat urban terrorist) activities a worthy thing?
Hmmmm, who is paying for this? My guess is…. M$
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
Oh of course – even if ‘no harm is done’ this creates a serious threat, and can and should probably be prosecuted.
If this is successful, think about all the companies that will suddenly have to start buying firewalls for OS X do to the fact that it is insecure – heck, I’d probably have to buy one for my personal machine. Maybe all us Mac users do need our bubble’s popped, and maybe we do need to start buying some security software, but the bubble shouldn’t be being forced to pop.
Think about all the people who just try in this competition. Maybe they’ll fail – but they’ll learn something, and maybe encouraged to experiment, and write another – and eventually get it right.
Of course, I too would love to see tons of people try and nothing come out of it, but as someone else mentioned, OS X is secure, but it’s not impenetrable. Security through obscurity is definitely one of our defenses – why risk shattering that now all for a game?
Very interesting NewsReader. Especially the stuff relating to hymm: http://www.hymn-project.org/forums/viewtopic.php?t=634
I’m glad I came across this info. I was thinking about buying one of his laptop stands (the ones with the fans on the bottom). Not anymore, I’ll wait for someone else to do it.
Listen to all you freakin sissies…. OMG. All you guys do on this site is bitch when someone has the ordacity to question the all holy Mac OS security. “Its the software stupid” sounds familiar?
Yeah. Shut yer freakin girly mouth up, just shut that friggin pie hole up and put your money where your mouths are….. What are you afraid of? Afraid to be proved that you were wrong after all? This is the real game of chicken here. And you pussies blinked.
Is the mac virus proof or not?
This is the way to prove it. However I do think that there are a few flaws. The setup should be like any OUT OF BOX mac, with the firewall on, and the consumer router firewall on as well. Other than that, I applaud this man for his balls to back up his belief with works.
BriAnimations,
This is no game… this is some VERY serious stuff.
People’s investments and livelyhood depend on it…. regardless if anyone wants to acknowledge that fact.
great, now people get invited to practice virii-coding for osx. Imagine the same amount for the first who recodes Fontographer for OSX…or to the first who manages to debug illustrator. Or wait…25K to the person who streamlines Doom3. There are so many things software-related that make more sense than this.
It sounds like a lot of people here are don’t know anything about DVForge. They don’t make antivirus software or security products (as of yet). They make Mac peripherals like mice, etc., some pretty good, others not. I don’t think this is being used as a sales ploy (ala Symantec’s latest BS), at least not in the way you think. It will sure garner his company some press, but not to sell antivirus products.
That being said, I think this is a horrible idea, and I fully expect Steve to sick the legal dept. on him poste haste. SJ said in a recent interview with Mossberg that the reason they don’t advertise the security of OS X is that they don’t want to put a big target on their back. Campbell just did that for them, in a BIG way.
to You punks.
what a wanker.
You just dont get it do you, but then retards normally dont get it.
Hugh
Sizewell,
Lighten up. He didn’t make a statement but posed a question.
“Can you be prosecuted if you break into someones home if you don’t do any harm?” Well, not if the homeowner invited you to do (perhaps to test his security system).
Finally, it’s “naive” not “nieve”
BriA: sorry, there is no ‘security through obscurity’. It is a misused term turned into a PR spin by detractors of the Mac relating it – wrongly – to market share. At least here let’s put things straight.
The term “security through obscurity” has no relation whatsoever with number of machines but to unavailability of a particular OS API. The security comes from the less know or not know at all details about an OS. If you do not know how it works then it is SECURE because it is OBSCURE.
Security through obscurity could be achieved even with a ball park of BILLIONS of machines online if the manufacturer and OS provider succeeds in not making the source code of the OS available and/or prevent reverse engineering.
This, obviously, is not at all the case with OS X, with its BSD Unix guts. Nothing could be more shining for a cracker than a Unix based OS.
In this sense, Windows is more obscure than OS X as Windows has some innards that are not publicly available while Darwin – the OS X guts – is an Open Source project. Nothing could be less obscure than OS X.
Having said this, ie, that “security through obscurity” is an IT nonsense when talking about anything Unix, OS X included, the security OS X enjoys, luckily for all of us, has truly nothing to do with OS X having a small market share. The only thing this will have an impact on is the infection rate at its peak should a virus for OS X emerge one day.
The inherent pre-condition to make virus making meaningful targeting a particular OS is how easy is to spread a virus. In order to do that the virus HAS to find the very same configuration machine after machine. If a slight change in what the virus NEEDS to find an a computer in order to infect it should be present then the virus operational mode would be undermined and probably prevent infection and/or spreading.
Now, Windows ensures that all and other PCs around are essentially the copy-cat installation of one another. On the Unix world this does not happen and it is inherent to Unix. Finding two Unix run machines with the very same configuration amounts almost to a miracle. This alone explains why on Unix and Linux the rate of infection is a single digit even at peak infection, roughly 5%.
On Windows it is well over 60%. This is what makes Windows the favorite target for crackers. Windows would sport higher infections with respect to OS X even if Windows market share was at 5% and OS X at 95%. Crackers would STILL go after Windows as they would get more machines infected there (both as absolute value and in percentage), hence more outcome, than with Unix or OS X.
Windows, thanks Bill, is the best ever anti-virus product of all: it attracts them all. With Windows around, a cracker would have to be stupid to go after another OS. AND this will not change even with a reversal of fortune turning Windows into a niche 5% market.
You want to infect lots of machines? Go after Windows, no matter the market share.
To “You Punks…”,
You’re a clueless moron. OS X will NEVER have anywhere near the problems that Windows has, but no one ever said there will never be ANY viruses for it. I’m quite certain there will be someday, but there’s no need to expedite it offering money to do it. Besides, that it’s not his product. Maybe he should offer $25,000 to the first person that can redesign his “The Mouse” so that the cursor can go slow enough to use actually effectively use it, or make the buttons easy enough to push that the cursor doesn’t move off of what you’re trying to activate. Those would both be much better use of $25,000.
You punks….
“put your money where your mouths are”… puuuullllllease
I have… and the day that my mortgage, gas, electric, phone, cable, food and clothing bills… as well as my childrens educational and hopefully one day my daughter’s wedding expenses are sent to your address for your prompt payment is the day I will agree with you.
I have never believed that OS X is completely secure… no software system EVER is. I have a computer engineering degree as well as 24 years of control and protection system design experience. I design networked and embebbed control and protection systems that people’s lives depend on which are MUCH more secure than any commercial OS available to you or I. But we still realize that our systems are fragile and “breakable” by the nature of software design. One of the first lessons that we learn is to take the attitude that we are not immune. I would hate the day that someone offered money to compromise the safety of say…. a nuclear power plant control room or.. ummm… an air traffic control room… or.. ummm. an automatic train protection system to name a few. I just don’t see the difference here…. sorry.
You lose your argument when you resort to name calling… I thought your mom would have taught you that at an early age.
Having said that, I too do not like the idea of putting a big target on OS X. Still, when the deadline will come and no virus could claim the prize, maybe some pundit will stop saying that there is no incentive to write viruses for OS X.
AND, maybe, Symantec people will stop spreading FUDs if even them have not been able to collect $50000 from the contest.
Incidentally, there was a $10000 contest to deface a web site run on a Mac server. No one ever has been able to collect the prize.
Last comment: the contest asks for the virus to infect the two specific machines. That means that a virus a la MSBlaster has to be written from here to the deadline. That means something that enters a door, when by default they are closed in OS X, penetrate the machine without user intervention, install itself without user intervention, replicate without user intervention, spread without user intervention.
Sorry guys, call me crazy. I still do not like this idea but those $ are more safe than if they were at Fort Knox.
Fatty Arbuckle,
Thanks… i stand corrected for my spelling error, it’s greatly appreciated.
I just didn’t realize that DVForge owned the keys to the home. You need to read his offer and understand that he is asking for the virus to be let lose on the NET and not just to his isolated machines. If and when his machines are infected is when he will pay out the prize money.
This is a really dumb contest. Let’s encourage people to cause damage to other peoples systems. Let’s encourage all the young people to do illegal software encoding. That’s really brillant, NOT!!
Note: Unless they have the admin rights to the machine it’s impossible.
OSX will not let you install without the admins password.
This is not Windows!
From the ‘contest’ page: “Your virus may be put into general circulation on the internet. Or, it may be sent by email to virus@dvforge.com.”
I wonder if he thought this through before starting up this contest.
John: and even the admin pass will not be enough. For that kind of things the machine must have the root account enabled and they have to crack the root password. Those guys said: “unmodified retail installation”, that means that not even the BSD Unix package is installed on those machines.
Without user help the OS X vanilla installation is simply not a breeding environment for viruses of any sort.
I’d have felt a lot better if the two target machines were on an isolated network and submissions from the contest were accepted via email on a third machine then physically moved to one of the targets for testing.
As written, the rules seem to require the release of a virus onto the public network… a criminal offense, even if it does no “harm.” Even if it’s intended to be benign, bugs can cause serious problems. And if such a “harmless” virus is released, people will still spend a lot of time, effort and money to eliminate it from their machines rather than trusting a virus writer who asserts that it’s not going to damage anything. Not to mention someone who might reverse engineer it and modify it into something with a devastating payload.
In short, this is perhaps an interesting idea but recklessly implemented.
Yes I think the contest will get shut down. It is called a publicity stunt. A pretty fun one if you ask me – one that Apple couldn’t do for the obvious reasons.
This guy just bitch slapped Symantic in front of the whole world. Doubling the price to Symantic employees – brilliant! The contest will be taken down, no programmer is going to spend time without the cash payoff so no harm is done.
The local game warden had been told that a local man had been fishing with explosives, in violation of the law. As the man was poor, with a large family to feed, he decided to go fishing with him and warn him rather than lay in wait for an arrest.
Fishing day comes and the man in question is throwing surplus hand grenades in the water and scooping up the dead and stunned fish with a net. The game warden starts rambling about how what he is doing is illegal and how he should really stop. The fisherman looks up, pulls the pin on a grenade and hands it to him. He then asks the following question:
“Son are you going to talk, or are you going to fish?”
DV Forge has just pulled the pin on a grenade and handed it to Symantec. Well Done. Put up or shut up.
this has got to be a hoax. And yes, for those of you who are wondering, it IS an apparent violation of The Computer Fraud And Abuse Act, Section 1030. See it here:
http://www.panix.com/~eck/computer-fraud-act.html
Here’s the thing: the way the law reads, it is a violation to assault a protected computer without authorization in order to cause some kind of disruption or other damage. If DVForge is saying “here are our unprotected computers, please hack them at your leisure” then that, the way I’m reading it, is not illegal. Now if the hacker(s) should happen to infect a few other computers along the way, THAT’S a different story. And if this thing happens to wind up infecting a government database of any kind (state, county, municipal, and god help you if it’s federal), I would think you’re looking at some very serious consequence.
just my opinion…
How mentaly sick you can be, behind a computer …
I agree in spirit with “You Punks”. This contest is manly, it’s awesome, and I as a Mac owner and shareholder welcome it. All the windows advocates, and I am including MS itself in this, are scared as hell of this contest, and so are a bunch of Mac-heads in this forum. What both factions are scared of is the truth! 25K should be plenty of incentive (not to mention the noteriety) for any hacker – now lets see if they can do it. If they do, Apple will make a patch to correct that, and our OS will get stronger. If they can’t, well then that is just gonna rock hard for Apple.
Let the games begin!
I have a $25,000 bounty on this guy. This guy is soliciting illegal activity, maybe the FBi should be informed of his actions.
iSteve, beatsme,
you’re right, it’s a publicity stunt. Look what the guy behind DVForge said about the Luxpro Shuffle:
“An iPod shuffle knockoff shown at CeBit by LuxPro may have been nothing more than a publicity stunt, according to information collected by Jack Campbell from DVForge…”This was not a prank, nor was it an act of blind stupidity. In my view, it was one of the most clever PR maneuvers I have ever seen executed by a small company.” “
So this guy likes publicity stunts. Turns out he has a long history:
http://www.macintouch.com/mactable.html#tip
We’ve all been bamboozled. Let’s all have another alcoholic beverage and go back to sleep…
What’s WORSE is that Mac Daily Crap gives this guy web space for his ridiculous announcement.
We all say how secure OS X is… here’s a chance to prove it.
However, that said, this guy’s “contest” is reckless. The idea to invite people to do something malicious is terrible and shows the character of this fellow. Why doesn’t he offer $25,000 for someone to design a SECURE Windows??? God forbid you do something positive with your money… better to be an a**hole I guess….
http://www.jackwhispers.com/jackwhispersII.html
I can’t see how anybody thought this was a good idea. Dear people, infect my machine. Wtf?
Plus, there’s a REASON that Apple doesn’t publicly advertise on television that there are no viruses. Because as soon as they do, it’s open season, and people will want to prove them wrong. OS X is not impenetrable…why the hell do you think they publish SECURITY UPDATES?!
Face it, it’s better, but not perfect. As soon as somebody wins this, then Apple is no longer virus free. Way to go and make one more reason why Apple’s might be less appealing to a devoted Windows user (i.e. they are NOT virus free).
Hell, think this out for a minute. When does the contest end? When nobody wins? How is that ANY different than what we have now? The same dare is basically out there. And what if somebody does win? Then there are Mac viruses.
Great, you lose or you lose…
1. more on Jack Campbell
http://www.macintouch.com/mactable.html
summary: a fairly long history of dubious/illegal activities/scams and aggressive self promotion.
It would seem that the probability of someone who meets all of the criteria in the contest actually getting the $25,000 is less than 100%…
(in other words, the contest itself, is, if the past is any indication, a scam designed to create publicity).
2. *** IF *** this was done in a highly restricted environment, I think the contest would have some legitimacy and be useful. It does have the unpleasant side effect of painting a large target on the Mac, but, that was coming anyway, with recent Apple product success. Personally, I would prefer that Mac walk around without a target as long as possible.
The fact that general internet distribution is not forcefully eliminated is a severe problem for all Mac users, should this contest be successful, until Apple distributes a fix. It is also, it would appear, a serious crime should it occur.
I do share Jack’s outrage at Symantec, however, as do a lot of Mac people.
3. What is stopping somebody from creating something that utilizes one of the holes already fixed in 10.3.1-10.3.8? Surely this is cheating, yet it would appear to be an easy way to win the contest.
This does bring up a point: OS X, should, as part of the initial connect to the internet (either after a fresh install or first use), ask to pull down all outstanding security updates, at a minimum. (or does it already?).
4. I am troubled that Apple doesn’t turn on the firewall by default. In my view, this is a security lapse. Even IntDows XP-SP2 turned on the firewall by default, albiet in much different circumstances – a full blown security crisis that has only received band-aids for years, and still only receives band-aids.
And is grounds, in my humble opinion, for a massive class action lawsuit and product recall – I can’t believe there isn’t a rip-the-meat-off-your-bones lawyer who isn’t jumping all over this. Like, move 10% of your auto manufacturer chasing team – is this too much to ask? Look at the ill-gotten gains money sitting there just waiting to be returned to its rightful owner – the Microsoft customer base, and society at large, for suffering through the damaging of the industry caused by Microsoft.
This is a golden opportunity for the legal profession to gain some good PR, also – yet another reason. But I digress…
It’s Mac Os X 10.3.0 or Mac Os X 10.3.8 (All updates) with the default configuration?
Because.. You know.. There are some security bugs..
” width=”19″ height=”19″ alt=”raspberry” style=”border:0;” />
“…..Incidentally, there was a $10000 contest to deface a web site run on a Mac server. No one ever has been able to collect the prize…”
Seahawk…
I do remember reading about an incident back when the US Army decided to replace all their WinTel servers with the (new) G4 “SawTooth” Servers.. and while they were in the process… one of their web pages was defaced… but it happened to reside on the lone WinTel server… which they hadnt removed yet… A look at the server logs showed that the hackers tried to enter all the Mac Servers and were unsuccessful, until they hit upon the lone WinTel server…
also…
There used to be an organization… (I think.. hackamac.org…or some such) … who…once a year… would place an unprotected Apple Server online… publish the Telnet and IP info… and invite the “hacking community” to “have a go” at it…. The idea was … if you could hack the server … and prove you did it…. they would award you with that server…
As far as I know… I never heard about anyone being successful in hacking the servers….
And all this was done way before the advent of OSX !
So, while there surely must be some legal ramifications concerning this “contest”…. maybe even a “conspiracy” charge… as mentioned above… I’m fairly confident that the 25k – 50k prize won’t be given away ..
uhhh … at least, not any time soon !
Back in the 90s, if I remember correctly, some company in Europe put a Mac server out there to be broken into. There was similar reward. No one ever did manage to break into it.
This is similar and will prove a very good point. And it doesn’t matter whether some coder is successful or not. If he or she is, I want to know. I can protect myself. If no one is, I want to know. SO I CAN SHOUT IT FROM THE ROOFTOPS!
awesome, i gotta get coding. although the more i think about it the more i realize that its gonna be really hard.
i think this is a great contest. its not going to hurt the general public using OS X, and it will finally put the “security through obscurity” myth to rest.
ill bet a dollar that the winner, if there is a winner is an old UNIX virus updated to do what needs to be done for this competition. small, quick, go through some old forgotten UNIX hole (yeah there still there, ya just gotta look in the right places).
if apple legal is smart they will let this go. i dont think they really give 2 shiats anyway.
With “friends” like this…
” width=”19″ height=”19″ alt=”tongue laugh” style=”border:0;” />
This has got me thinking: Mozilla offers a $500 bug bounty for security holes, why can’t Apple?
Conditions, obviously, are that the bug has to be given to Apple for evaluation, NOT BE RELEASED in the wild, not go public until Apple has a fix RELEASED, and, to make it look good, maybe involve an external auditor.
The person winning should be acknowledged publically, and for first submitter, be given at least $1000, maybe $5000. And the contest has run for a really long time – at least a year or two, ideally forever.
This way Apple gets product improvement at a modest price (compare that to a formal security audit’s cost in staffing expense). The downside is Microsoft could do the same thing, but it generally takes them 5 years to reverse engineer/steal/buy, and another 5 to do it properly.
The upside is that any legitimately curious guys targeting Apple would be redirected to get their publicity legally, and be compensated, i.e. effectively hired. By reducing the appeal of the illegal virus, all Mac users win. This also should have the effect of keeping the, so far, perfect score of 0 viruses released in the wild for OS X a bit longer.
(tangent: surely this perfect score is going to be compromised by people failing to upgrade, at some point, so we can’t get too cocky.)
executive summary, courtesy of MDN:
While no computer system is ever perfect, the number of exploits to date is instructive:
IntDows (windows) 68,736 viruses et. al. in the wild (they are in the wild, right MDN?)
OS X 0 (yes *** ZERO ***)
we have to keep HAMMERING PC people with this.
It really would have to be a “cash” payment, as the hacker slinks off into the night.
Sounds like great fun to me, and it can only be good press for osX. Even if someone manages to create a bug that will autoexecute on a mac, it is still 500,000 to one, windows over mac.
Not that it is hard to avoid viruses no matter what the platform.
You guys are all worrying over nothing! This contest will NOT be won and NO ONE will claim the $25K. They’re simply NOT GOING TO BE ABLE TO DO IT!!
I bet Apple will have an executive meeting sometime on Monday to think this through verrrrrrryyy carefully. Because their coders have to know that the odds are stacked SO LARGELY in Apple’s favor that this just might be a dream come true. Imagine, after this contest ends WITHOUT a winner, Apple gets all the benefit from the buzz in the press and on the bulletin boards — and STILL they won’t need to put their own reputation on the line by advertising the Mac’s inherent strength against virii.
I bet Apple let’s this contest ride!
cptnkirk, G Spank, You Punks,
I agree 100%.
What are we afraid of ?
When Symantec spreads FUD we all go nuts in the forums saying OS X is rock solid.
When a PC article mentions the security through obscurity myth, we all go crazy.
But when it comes to prove it, who really stand up for their ideas ?
Symantec illegitimately tries to TAKE MONEY FROM YOU for protection software you don’t need.
On the other hand, a guy GIVES AWAY a large amount of money if you can prove him wrong.
I see this as a chance to stop the false rumors that hurt our platform.
In the worst case, it is a challenge to Apple for making an even more secure OS.
What are we afraid of ?
Magic word: “Believe”.
There sure are a lot of bored Mac geeks on a Saturday morning.
Oh Ye of little faith….
I’m really surprised at the number of people here who have negative comments about this. I would think a true-blue Mac head would cherish the thought of a contest like this. I recall when a web site in Denmark (?) offered $10k to anyone who could deface a web page hosted on a Mac, I was elated, and 10 times over once the contest expired and the web site was untouched. I for one believe that their $25k (and the $50k) is, as someone said, as safe as if it were in Ft. Knox. And just because the one who offered it is known for publicity stunts, so what? Mac OSX could use a little publicity.
As someone I admire once said… “Bring it on”.
пустая головка
Which keys on your keyboard type letters like that ?
I’ll bet $5 that his $50,000 is going to be quite safe.
What happens if they actually succeed?
Will this be start of the new virus era for OS X?
Please read my l;etter to Mr Campbell Below:
I here MR Campbell has a competition to write a virus for Mac OSX.
May I suggest he looks carefully at the legal aspects of this.
If someone writes one can you be sued? It would seem that you can be locked up for inciting a riot… The incitier doesn’t actually do the rioting or do the damage but pays dearly for it in the court system.
Maybe you can have the same thing happen if you incite someone to damage other peoples computer systems through a virus… I would suggest you look closely at this as I will actively be emcouraging other systems users too with the possibility of doing this. Please contact your lawyers as I will be contacting mine first thing on Monday to discuss this.
Gaga,
If it is meant to happen, it will. Accept your destiny.

” width=”19″ height=”19″ alt=”LOL” style=”border:0;” />
Anyway, let’s not act like ostriches who hide their head in a hole to avoid the storm.
If there is a fault in OS X, it will be exploited one day or the other.
The sooner it is, the faster it will get fixed.
I took TheRealist’s advice and had another alcoholic beverage and went back to sleep thinking I would change my mind after I woke up… it didn’t help.
Link to crack a mac contest 1997
http://db.tidbits.com/getbits.acgi?tbart=02166
I find DVForge’s contest in extremely poor taste. To show my dissatisfaction, I vow NEVER to purchase any DVForge product and will promptly return or throw away any that are received as gifts. I sincerely hope others that feel likewise will do the same.
Contest is cancelled.
Really too bad in my opinion.
http://www.dvforge.com/virus.shtml
On the website:
“Liability Statement
We do not endorse the creation or distribution of computer viruses. U.S. and international law, as well as simple good judgment forbid the transmission of computer viruses.”
As I recall, a Swedish Mac dealer or VAR offered a $10,000 prize tothe first hacker who successfully cracked the Classic Mac OS at the time. No one got anywhere until some clever fellow found a hole in a web-related application and the developer of the application isued a patch about 3 weeks later.
Apple did not sic its legal beagles on the Swedes who set up this earlier contest, so why should they do so now?
At any rate, kudos to DVForge for calling Symantec’s bluff!
MW = required. As in proof of allegations of security vulnerabilities are required by the Mac community.
THE CONTEST IS CANCELLED.
Does anybody think, just because someone has offered $25,000 for this that there has never, or will never be , a jerk who can and will try to write a workable virus for OSX????????????????????
If you think that, then you obviously have no idea how many malicious sociopaths there are out there who will happily do it FOR NOTHING!
Does it put a “target” on the back of OSX? Maybe.
In the real world, it has always been there!
And always will be because evil SOB sociopaths have always existed in the world, and will always exist.
Can someone write a virus for OSX? You have to believe it is possible, but why has no one done it sucessfully? It will always come down to that question. Personally, I do not believe in magic although I believe in miracles. But miracles only come from the good, not the bad.
Dirty Harry(Clint Eastwood) said: Make My Day, Punk.
Was he bragging when he said it? Depends on your basic beliefs, but Babe Ruth said: it’s not bragging if you can do it.
The writers of OSX may have done it.
Time will tell, but I will bet on OSX over any existing alternative.
Thanks, Seahawk, as always ,you explain complicated things in understandable language. The threat that you pose to the dumbasses always brings them out of the holes. That is a good thing. You always benefit by knowing more about your opponent.
Why is it that a teenager who creates a virus for windows is tried and sent to jail, while anyone who writes a virus for OS X is rewarded? There is something very wrong with all of this. I’m very tired of hackers treating virus creation like an achievement. It wreaks havoc on people’s lives, and for what? People (like me!) who depend on their computers to make a living can’t afford a contest like this. This is a crime in progress and should be stopped by the law.
I like my OS X just the way it is: Secure and Obscure!
DVForge Inc.,
It was a great idea, and you guys are very brave, and great supporters of the Mac community.
I hope you find a way around another time.
Did you speak with Apple at all ? Or did they speak to you ?
DVForge rescended the contest! End of thread.
To the people who think they remember the web site challenges…
There were several such challenges. Some had the prize as free pizza. Some had the prize as high as $10,000 cash. Some had a challenge to change data in a data base. Some had a challenge of replacing the home page. Some had a challenge of changing anything on the web site.
Of all the challenges (pre-OS X) that were done concerning Mac based web sites only one had to give up the prize money: $10,000. The organization setting up the prize was in Sweden. The challenge was to change a web page on a server directly connected to the Internet. The ONLY thing you were not allowed to try was physically breaking into their company and physically touching the computer. All other attacks on the computer were explicitly allowed. The winner (IIRC) was from Australia. He got in and changed the web page (the actual challenge) by getting into the data base through a whole in a product called Lasso. He got his money. The company (Lasso’s developer) issued a fix for the whole within 24 hours of notification.
Thus the web site security on Macs has stood at ONE successful hacking versus thousands upon thousands of attempts.
I believe there will eventually be visruses, trojans and worms for OS X. It is only a matter of time.
However, it is inappropriate for anyone to set up a challenge like this to encourage and hurry the process along.
The point is this in talking with people who are bigotted against Macs sometimes the only thing that makes them pause is a very black and white response. They jump on even the slightest gray area as a weakness in the Mac.
So the concept goes like this…
Can any knowledgeable person honestly claim no Mac based web server has ever been hacked? No. (In the anti-Mac bigot’s mind one hacking allows for the possibility of millions of hackings in the future.)
Today, can any knowledgeable person honestly say there are no, in the wild, viruses, trojans or worms for Mac OS X? YES! (In the anti-Mac bigot’s mind this means it will definitely happen in the future. But in the discussion it must be left open that it may not happen for many years.)
To encourage the change of that purely back and white answer is not something I want to see soon. There are many times I have talked to people over the past couple years that the only time they pause in their diatribe against Macs is when I can honestly say “NO!” to that question. (Most of the people I talk to know I track this stuff rather closely and honestly state such things as the single web site hackings in Scandinavia.)
To have to change the answer to that question to “Yes.” someday will severely weaken the pro Mac argument. Even saying “But there was only one.” holds significantly less weight than a simple and succint, “NO. None. Not ever.” In the anti-Mac community’s minds one break in allows for the possibility of millions upon millions of break ins.
A new Virus on Windows = Microsoft does nothing. They probably like it that way !
A new virus on the Mac = Apple will do their best to solve the problem within hours and they will probably hit themselves for not having spotted the hole before. Because they care for the user.
M$ doesn’t give a shit. And this is why, montex, a teenager who writes a virus for Windows will be sent to jail by Microsoft lawyers. That, they’re very good at.
On the other hand, Apple may thank a hacker for pointing out a fault in their OS. Apple may not be perfect, but I think they have the right attitude because they care about evolving, improving, becoming better everyday.
I say Bring It On!!!
Check out Jack’s Picture at the below link…
” width=”19″ height=”19″ alt=”grin” style=”border:0;” />
http://www.dvforge.com/directors.shtml
Additionally, I really like Sure Am Releived’s proposal.
Apple should put a bounty on security holes in Mac OS X. The bounty should be significant and should scale as the severity of the security hole found. An fatal hole (such as one which would allow the attacker to change the OS itself, delete files at will, etc.) would rate a large prize, maybe $20,000 or so. For a security hole which causes a program to crash but upon program restart the program and the data files associated with the program are fine (and the OS is always fine) the bounty could be as little as $500. However, the prizes (bounties) should be sizeable. The worst case scenario prize should be at least $10,000 but would be even better if it were $50,000 or more.
Apple should run this as an open program — forever.
The conditions would be somewhat as Sure Am Relieved stated:
The developer who finds the hole must contact Apple and no one else about it.
Apple enlists a trusted third party to review the submission as well as Apple reviewing it internally.
Within 72 hours of verification of the hole by both Apple and the third party the developer get’s paid the prize money.
Within 48 hours of Apple issuing the fix the developer is publicly acknowledged for finding the hole.
Apple has a maximimum of 180 days to issue a fix. Apple might issue a fix in a couple days, but Apple has a maximum 180 days to issue the fix.
If Apple has not issued a fix within 180 days the developer gets to announce the hole publicly if he/she so desires.
If Apple has not issued a fix within 180 days the developer who found the security hole can issue a patch themselves if he/she so desires.
Apple could even run a similar program internally to Apple for Apple employees. However, people could not be awarded bounties in areas where they are working (i.e., people who are working on the micro-kernel could not get bounties for finding holes in the micro-kernel) as that is what Apple is paying them to do already. However, if people find a hole far outside their area of responsibility (such as a programmer working on the micro-kernel finding a hole in a printer driver) they should be rewarded.
Either saying, or not saying: “Bring It On” , or “painting targets” has no bearing on whether there will or will not be someone attempting to write the workable virus. My guess is that there have been hundreds, or many thousands of attempts ,some of which probably by those same kids who download the Windows virus writing kits and think they can make themselves famous by writing an OSX virus.
And make no mistake about it, if someone wrote a workable virus, it WOULD make all the network news and that person would be famous overnight, and to a lot of them that matters more than money.
(Although, they usually assume that money will automatically follow fame. Dumbass!)
But then dumbasses gravitate to writing Windows viruses, not because there are a lot of Windows computers, but because it is EASY!
What really blows my mind is that after reading Seahawk’s explanation of the mathmatical improbabilities of an OSX virus spreading even if it does exist, people still fling out the Obscurity thing. I can’t believe that!
Maybe they believe in random magic, like people who believe that trees jump out in front of cars. Just because a tree has never jumped out in front a car before does not mean it will not do it in the future, yada, yada, yada…..so, some dumb 15 year old will find the “magic” key combination that brings down OSX. Happens in movies, but having spent all my life in either auto racing or martial arts , and having seen every movie ever made about both subjects, Hollywood must be genetically incabable of getting ANYTHING right, so I put no stock in popular opinion unless I see real evidence. After 4 years of OSX, and with it becoming more secure, not less, I am not seeing it.
Ok………. believe what you want, but I won’t live my life in that kind of fear. I will bet on OSX, thank you very much, even if somebody does accomplish a minor temporary crack at some time in the “randomly ordered future”
Only 4 comments out of 60 mention Jack Campbell- YOU NEED TO DO YOUR HOMEWORK!
Check the messenger here folks …
Jack Campbell’s going to pay $25,000 or $50,000 out of his own pocket??? ……. that’s a sick joke
THERE WILL NEVER BE ANY PAYOUT OF ANY PRIZE MONEY- THIS GUY IS A SCAM
honestly, if a hacker broke into OS X with a virus, he/she would be FAMOUS! If anyone out there thinks that isn’t a MAJOR motivating factor in writing viruses (virii?) then you got another thing coming. People have been trying for years now to write a virus for OS X. It’s just that noone has succeeded. This contest doesn’t really change what people are already trying to do.
From the article:
“No trick, no hidden barriers… just two open internet connections to two non-firewalled, unmodified, bone-stock OS X 10.3 Panther systems, each tied directly to the ‘net by a T-1 line.”
I hate to say it, but with a setup like that someone’s probably going to get through. Anybody STUPID enough to hook a bone-stock system to a high-speed Internet connection, sans firewall and security updates, DESERVES WHAT THEY GET! I don’t care which OS they’re using! This is as basic as seat belts in a car: for safety you need to buckle things up.
Although to Apple’s credit, it’ll be interesting to see how Mac OS X holds up even without being locked down. Everyone knows a Windows setup like that would be down in short order. Wouldn’t it be fun if they set up a couple of bone-stock XP boxes alongside the OS X machines, and tracked the results.
” width=”19″ height=”19″ alt=”smile” style=”border:0;” />
Look I think they are right in making thing clear. They should not be on there own saying either.
I think it’s legal to participate, because you don’t need to write code that will harm the machines, you just prove you can do it by getting it onto the machines.
Well, shucks. I’m very disappointed they had to cancel.
And, Shadowself, I think I remember the Mac challenge from the web site in Sweden quite well (but maybe not well enough to recall *where* it took place). Could you be so kind as to point me to a link or two to support your memory?
Has anyone not noticed what date this next Friday is?
Uh… The fact that there have been 0 virii and you’re paying sb 25 grand to write just ONE.. kind of lays it to rest anyway..
If this competition were actually to be continued (it has been cancelled), and an actual virus was released and the author went to claim his/her cash… Well there would be legal action, right? (say yes now).
Mac user base not growing, or even shrinking because the one _really_ big advantage the Mac has over Windows was removed, well, watch software development for the Mac go down some more.
This guy is (was) effectively contracting for illegal activity. Now we boycot his business! what a f**kwit!
How quickly we forget that NSA loves Macs and Mac OS X and that Apple was security certified for government use:
http://www.maccompanion.com/ExpressionEngine1.2/index.php?/macCompanionModern/comments/sit_down_and_enjoy_a_snac/
I still believe that one of the reasons that there are no viruses for the Mac OS is that you have to know an OS well before you can write a virus for it. When a potential virus writer starts to learn OS X the chances of him falling in love with it and deciding he doesn’t want to harm it after all are great.
What this tool Jack Campbell has done is provide a reason to know OS X well and love it and STILL have a reason for going through with it and harming it – 25,000 reasons to be exact. He is either an idiot or a self serving con artist.
(apparently I don’t have enough to do today
” width=”19″ height=”19″ alt=”smile” style=”border:0;” /> )
1. We have to be careful about tossing figures around. The figure of 68,736 appears to be from
http://securityresponse.symantec.com/avcenter/download.html
and, by the way, its up to 69,225 as of today (vs 69,224 yesterday, if you care).
But this is from a company, Symantec, that we’re correctly slamming for FUD. In other words, we should be very skeptical of this figure, since it came from a highly disreputable source (just like we should be skeptical of everything that comes from the Microsoft Felon).
It also isn’t clear if this figure includes “mac viruses”.
2. The flip side of point 1 is what does Symantec say about the Mac? We know there are no exploits in the wild, but lets hear it from the mouth of the lying horse:
http://www.macworld.com/news/2002/05/28/virus/index.php
A symantec spokesperson claims there are over 7,000 macro viruses that can hit both Macs and PCs. He doesn’t mention it but none of them are in the wild on OS X (more FUD, this time through omission).
On the other hand, based on the track record, it is also a safe bet that a good bunch of the 69,225 aren’t in the wild either.
3. From another source:
http://www.macobserver.com/editorial/2003/08/29.1.shtml
Nai (McAfee’s holding company) reports that there are over 71,000 viruses as of August 2003 (now its “over 100,000”). Presumably this is for all platforms, not just Mac and Intdows.
At the time, the author was able to do filtered searches (it appears this feature has been removed), and filtered out Macintosh, producing 612 viruses. Sounds awful, right?
They include hoaxes, unbelievably, in my opinion. In other words if some fool/anti-mac bigot starts an urban myth about macs, and enough mindless minions pass it along, it gets logged as a virus. Now I agree this stuff should be tracked, but putting it in the virus database seems to be rather aggressive. On the other hand, having worked in an office of a high tech firm containing people who should know better, and having said people forward this drivel, perhaps I’m being harsh.
I’m beginning to see how the figures get so high though.
Stripping out the hoaxes leaves 580 all of which are old office macro viruses or mac os classic viruses, leaving, 0.
4. I decided I would try and reproduce the search. A search at McAfee for os x resulted in 77 hits.
I have no idea what criteria they use for searching, but I suggest they go back to the drawing board. After filtering out Intdows (most of them), hoaxes and bunch of sybian phone viruses, running a google search for some of the viruses that didn’t have any description for some odd reason we’re left with 3:
(notice that none of the microsoft macro viruses are listed for anything > word 6, i.e. OS 9)
#1 http://vil.nai.com/vil/content/v_125299.htm
The fake ms-word script that deletes a single user’s files (but doesn’t spread).
So, the message here is that these counts include absolutely anything bad, and, using this criteria, the mac has a piece of malware, already. Notice that it doesn’t corrupt the o/s, also.
Obviously, be careful about running stuff you pull down off p2p networks, get through email….
Apple can NEVER protect against this.
It seems the criteria for getting on the list is popularity/widespread distribution, which is fair, as long as they use a reasonable definition of popular/widespread.
#2. http://vil.nai.com/vil/content/v_129163.htm
discussed at
http://www.macworld.com/news/2004/10/25/opener/index.php
tons of detail at
http://www.macintouch.com/opener.html
this is opener, which requires the admin password.
A nasty pile of scripting, but, as long as you are sure to not give the admin password to install a program you’re not absolutely sure about you’re safe (unlike Intdows, which lets this stuff run free – another thing we have to POUND the PC users on).
#3 http://vil.nai.com/vil/content/v_101173.htm
the file with the mp3 icon that is actually a program, but, beyond displaying a message it does nothing. Details at
http://www.houstonrecord.com/nation/nation_003.html
A nasty person could have combined #1 and #3.
continued…
…continuation
5. So where does this leave us?
a) Yes, we don’t have replicating viruses on os x, still, after 4 years.
b) We have a nasty trojan that could have been replicating if it was widely installed but it wasn’t. If you get it, and its really hard to get it (requires admin password), you will be very unhappy.
c) It is trivial to create a nasty program (always has been, always will be), and, if people are stupid enough to download it/receive it from email and run it, the malware can do anything that the user can do, without notice, as long as it doesn’t need the admin password. The worst thing here would appear to be deleting all that user’s files.
If the user is foolish enough to give away the admin password, the machine is compromised, and all bets are off, for that machine. This is ok, in general, since this won’t spread – a whole bunch of people aren’t going to give away the admin password to a bad program, quickly.
d) The numbers people are tossing around are absolutely ridiculiously inflated by disreputable companies with a conflict of interest (like, would you trust a company that lies about the threat to protect you?).
e) Personally, I think we’ve been spinnng this a bit (not a lot, but a bit). There are bad programs out there for macs, specifically targeting os x, but they don’t spread by themselves.
Technically, they aren’t viruses, but try telling that to a naive/unsophisticated user who just downloaded, say, the fake ms-word script and lost all their files.
On the other hand, symantec is being a disgusting slimeball, who should not be rewarded with revenue.
Its the old thing – balance – not too far on one side (“the mac is perfect, security wise”), not too far the other side (“the mac is going to get a ton of security problems now that they’re selling more”).
Kinda like a lot of things in life…
SAR: get your info on security weaknesses from:
http://www.ciac.org/ciac/bulletinsByType/bul_vendor_list.html
Hey Jack,
Thanks for cancelling that darn contest. Do you want cash or MS stock?
Regards,
Bill
For what it’s worth, I am meeting with our attorneys and a couple of sharp network Unix guys on Monday to reevaluate the contest structure. If I can be convinced that there is a way to make the challenge for a self-replicating, self-propagating OS X virus that executes on multiple machines, spreads only through an Internet connection, and does so without user enablement, I will relaunch such a contest.
I am being attacke by both Windows and Mac people for stepping up and calling the bluff to this ridiculous lie that’s been festering aournd the OS X platform for 4 years. I don’t care about being called names. I can handle it. What I care about is that this lie about OS X virus susceptibility once and for all be put to rest.
Again, if I can structure a contest that is both utterly legal, and also sufficiently targeted at just the specific beast I am chasing, I will be right back wiht that new challenge.
Our company is doing well wiht our Apple peripheral products. I can afford the heat and the cost to contribute something back to the platform. So, I am.
It’s that simple.
There have been some very knowledgeable posts here. If any of you have any suggested methodology that I can consider for such a legal/effective challenge format, I would be very interested in hearing your suggestions. I am willing to put two or more of our own day to day Macs up as targets… no problem, as I actually am convinced of the invulnerability of OS X to an in-the-wild virus attack, given the no-user help requirement.
Any ideas?
Jack Cambell:
Ideas?
Yes. Drop it.
Stop encouraging vile behaviour in an attempt to take down Mac OS X.
Seahawk:
A neutral, reputable source of information – thanks – exactly what I was looking for.
Can “Sure Am Relieved” contact me please? I’d love to get his/her research published in macCompanion for May.
Jack Campbell is a hopelessly stupid publicity whore.
We have posted our Mac Malware Status artice at
http://www.maccompanion.com/archives/may2005/Columns/MacMalwareStatus.htm
with our invitation to “Sure Am Relieved”.
Having read this I believed it was extremely enlightening. I appreciate you finding the time and effort to put this informative article together. I once again find myself spending a lot of time both reading and commenting. But so what, it was still worthwhile!|