“[Analysts] do agree on one area where Apple has an advantage: Security. Macs are targeted by viruses and hacking attacks far less often than machines running Microsoft’s Windows simply because there are fewer of them around. Computer criminals strive for maximum impact, so they pay less attention to the relatively small number of Mac users,” Arik Hesseldahl writes for BusinessWeek.
“While Microsoft struggles to build firewalls, anti-spyware, and anti-virus technology into Windows, Mac users are for the most part untroubled by these annoyances, and that’s a point it could press, says Richard Forno, a principal consultant with KRVW Associates, a computer-security firm in Alexandria, Va. ‘I’m seeing more and more people in the security business using Macs and saying they trust them and don’t have to cope with viruses and other hassles,’ he says. ‘I just wish Apple would market its security as a key feature to corporate customers.’ Of course, the more popular Apple machines become, the more likely they are to be targeted by hackers and virus writers,” Hesseldahl writes.
Full article here.
MacDailyNews Take: The idea that Windows’ morass of security woes exists because more people use Windows and that Macs have no security problems because less people use Macs, is simply not true. Mac OS X is not more secure than Windows because less people use OS X, making it less of a target. By design, Mac OS X is simply more secure than Windows. Period. For reference and reasons why Mac OS X is more secure than Windows, read The New York Times’ David Pogue’s mea culpa on the subject of the “Mac Security Via Obscurity” myth here.
Hesseldahl is the same writer who wrote for Forbes back in June 2003, “Naysayers have been calling for Apple’s demise for years. But Apple not only has survived but thrived, it seems, at least partially by the sheer force of Jobs’ will and his ability to maintain the ferocious loyalty of Apple’s users, who still account for 10% of the world’s computer users, while its sales usually account for about 3% to 5% of the world global PC market.”
So, if Macs account for 10% or so (some say as much as 16%), then, according to Mr. Hesseldahl himself, Macs aren’t “obscure” at all. Therefore, the Apple Mac platform’s ironclad security simply cannot logically be attributed to obscurity.
There are zero-percent (0%) of viruses for the Mac OS X platform that should, logically, have some 10-16% of the world’s viruses if platforms’ install bases dictated the numbers of viruses. The fact that Mac OS X has zero (0) viruses discounts “security via obscurity.” There should be at least some Mac OS X viruses. There are none. The reason for this fact is not attributable solely to “obscurity,” it’s attributable to superior security design.
Still not convinced? Try this one on for size: according to Apple, there are “close to 16 million Mac OS X users” in the world and there are still zero (0) viruses. According to CNET, the Windows Vista Beta was released “to about 10,000 testers” at the time the first Windows Vista virus arrived. So much for the security via obscurity myth.
Arik Hesseldahl’s email address is:
Related MacDailyNews articles:
Hackers already targeting viruses for Microsoft’s Windows Vista – August 04, 2005
16-percent of computer users are unaffected by viruses, malware because they use Apple Macs – June 15, 2005
ZDNet: How many Mac OS X users affected by the last 100 viruses? None, zero, not one, not ever – August 18, 2005
Intel CEO Otellini: If you want security now, buy a Macintosh instead of a Wintel PC – May 25, 2005
Apple touts Mac OS X security advantages over Windows – April 13, 2005
97,467 Microsoft Windows viruses vs. zero for Apple Mac’s OS X – April 05, 2005
Apple’s Mac OS X is virus-free – March 18, 2005
Cybersecurity advisor Clarke questions why anybody would buy from Microsoft – February 18, 2005
Security test: Windows XP system easily compromised while Apple’s Mac OS X stands safe and secure – November 30, 2004
Microsoft: The safest way to run Windows is on your Mac – October 08, 2004
Information Security Investigator says switch from Windows to Mac OS X for security – September 24, 2004
Columnist tries the ‘security through obscurity’ myth to defend Windows vs. Macs on virus front – October 1, 2003
New York Times: Mac OS X ‘much more secure than Windows XP’ – September 18, 2003
Fortune columnist: ‘get a Mac’ to thwart viruses; right answer for the wrong reasons – September 02, 2003
Shattering the Mac OS X ‘security through obscurity’ myth – August 28, 2003
Virus and worm problems not just due to market share; Windows inherently insecure vs. Mac OS X – August 24, 2003
It’s true that if Macs had greater market penetration that more virus writers would target Mac OS X.
It’s true that no OS, including Mac OS X, is theoretically impenetrable.
It’s just sloppy journalism to conclude that therefore, if Macs had greater market penetration, it would be as bug-ridden as Windows.
Two posters on an earlier MDN piece – http://macdailynews.com/index.php/weblog/comments/6781- indicate Apple (and others) may have been intruding into their Macs.
More secure because they don’t have to leave holes in the system for all of the PC variations that constitutes using Windows.
and mac users are forced to spend another millenia defending the truth…
This horse is dead.
Well, now I have no doubts that we’ll become a bigger target… especially as more windows bigots become even more weary of hearing how happy-go-lucky we are on the internet as Mac users. I assure you further that there are already plenty of people out there who would love to take us down a notch.
But that’s part of why we get constant updates and patches to thing we didn’t even know were potentially broken… to keep us protected from that. Sure, Windows is really easy and really visible… but the Mac is a far tastier target. I’m sure whoever does end up writing the first OS X virus will enjoy a lot of attention… and people know that.
So yeah,security via obscurity thing is a crock for sure IMHO.
Hey bugs only get stepped on more than elephants because there’s a lot more of them around. If there were more elephants man… just you wait and see!
david –
The singular form is millennium.
Left rear Tire –
Security problems in Windows have not thus far been related to a broad base of supported hardware. It’s less-than-airtight code which permits overflows and leaves network ports unprotected.
MDN –
While the security-though-obscurity theory has not been proved, neither has it been debunked. It’s not likely to be proved, and until OSX has a healthy piece of the market (say, 30-40%), it won’t even be stridently tested.
Regardless, BW is wrong. Marketing on a “we go under the radar” platform is a bad idea. As is a “bring it on; we’re invulnerable” attitude. They should promote how easy & powerful the OS is, and continue to court developers. Offering incentives to established Windows-only software makers to develop (*not* port!!) for OSX wouldn’t hurt on that front.
Security through obscurity my ass.
MS Vista has already been hacked. What is Vista’s market share?
Went to the Times and read the article.
Funny that he quotes microsoft as saying they would fix the open ports issue in the next version of Windows which is ” a couple of years away”
Since article is 2 years old, and couple means 2, where is this Windows version of which he speaks?
I hate to break it to MDN because they seem so hell bent on insisting that Macs are impenetratable.
BUT.. OSX is code.. Yes, it is better written code than Windows XP, but it is still code. For any code written, a virus can be written to infect that code. I don’t care how many permissions are required by the OS itself, it CAN be done. I do believe that OSX is more secure by design, but that does not mean that it is immune. We’ve been lucky so far, but that’s no reason to gloat. There will come a time and I’m guessing sooner rather than later when OSX comes under attack.
The very reason Apple does not market OSX for it’s security benefits is because they know very well that the OS is not immune.
Security via obscurity is NOT a myth and this article is correct in that virus writers wan’t maximum exposure. Their efforts can potentially bring down huge corporations with an XP virus and that is what they are after.
But let’s not be so arrogant. As Mac marketshare increases especially into the corporate world OSX CAN and most likely WILL become a target for these hacksers.
Virus Intrusion Spyware Trojan Adware’s market share is about 0%
When the first virus for OS X is written and released into the wild, then the Mac platform will have less than .001 percent of the known viruses and Windows will have almost 99.99 percent of the known viruses.
I think I will stay on the Mac side. When our share gets above 1%, please let me know. Thanks.
Nowhere above does MDN say Mac OS X is “impenetratable.” MDN simply states logic: there are zero viruses, but 16 million Mac OS X users. Hesseldahl himself says 10% of the world uses Macs, so Macs are not obscure, by definition. You cannot have “security via obscurity” if obscurity doesn’t exist.
Microsoft apologists want to blame anyone and anything except the actual problem: Microsoft.
Yet another fool has his say.
I would not like to meet up with MDN in a court of law if they were on the other side.
But MDN is not using logic.
Yes there are 16 million OSX users, but of those 16 million, how many are Banks, corporations, government agencies?? These are the types agencies that hackers target, and for the most part Macs ARE obscure in the above mentioned.
Hackers (most, not all) want exposure, they are not interested in bringing down personal users, graphic designers, musicians and grandmas… Until OSX makes it’s way into the corporate world, we are obscure..
Ted,
MDN’s logic is indisputable:
“There should be at least some Mac OS X viruses. There are none.”
Or at least one. But, in five years or so, there are zero viruses. Zero.
Why? Certainly not because of obscurity.
Security via obscurity is skewed. The Mac OS is well known enough — or, hardly obscure.
The math doesn’t work. Windows has what user base and how many viruses? Mac has what user base and how many viruses? 80,000:0 doesn’t add up no matter the difference in user base. The only way to reconcile this would be if the Mac user base was zero.
I’m not claiming that the Mac is inpenetrable. The answer is that A) Windows is easy and B) hackers love to hate Windows.
Look I’m not defending MS or giving excuses for their shoddy OS. XP is in my opinion is a piece of crap just begging to be intruded.
I know that OSX is more secure by design and I know that there have been no viruses to date. We’ve been fortunate. My point is simply that OSX is not immune. Apple knows this, we should too.
16 million users or not, we are obscure when it comes to being a prime target for hackers.
Hey Ted – Most of the haX0rs I know are using macs these days. Maybe that’s why virus writers aren’t writing viruses for the mac platform – they wouldn’t want to infect their own machines.
Security via obscurity has nothing to do with how many machines are connected at a time but how well the API of an OS is known and publicly available. Funny thing is that the only OS enjoying security via obscurity is Windows in that its API is not entirely public.
This said, a virus to be effective has to be 1) able to infect (ie crack exploitable flaws on an OS, 2) reproduce itself, ie, take control of the OS itself, 3) automatically propagate, ie, not require any user intervention to infect other platforms.
The fact that no OS is bullet proof concerning infection covers only 1) . Sure, any OS is just code and no one could conceivable say that it is immune to buffer overflows, to say one. Also OS X has those and are for the most patched with every security update. But 2) and 3) is what is inherently more difficult on Unix like platform than on Windows.
2) concerns reproducibility. It should be well known that any Windows installation is a copy cat of another. This allows the virus to find exactly the same environment to infect on and on and on. Such copy cat configuration is way less probable on Unix platforms where the same services can be provided by different daemons, not active at all, different versions, etc. This accounts for peak infection rate on Windows of 60% or more and about 5% for Unix platform. On Windows the adagio ‘crack one crack them all’ holds. On Unix doesn’t.
3) Automatic spreading. People could ‘not care how many permissions are required by the OS itself‘ as with the above poster but it is exactly this that undermines requisite 3) for a viral infection. A Windows installation does not require any permission. The OS is made so that any *internal* program is authorized to take full control of the machine and its API. On Unix there are many more *gates* – for so to say – before that is done. A virus that needs an operator physically to cooperate in order to be authorized at each step and propagate simply does not work, not even worth writing one.
So yes, every OS can suffer from condition 1), ie have faults to be exploited. 2) and 3) are GRANTED on Windows, much less so on other platforms. BSDUnix is the one features and featured best security-wise rending 2) and 3) extremely difficult to achieve. This translate into being very difficult to write a virus that could spread exponentially as it happens on Windows.
A virus writer could not care less how many machines are out there, but how many can be infected in the shortest period of time. And this has very little to do with market share, practically nothing.
Would you target 500 Millions machines when you know at best you may infect 50000 or 10 Millions machines when you know you will infect for sure 8 Millions?
Hackers crave the ultimate high of cracking OSX, but it’s no good slaving for it when you’re likely to fail, so they satisfy themselves with cheap-and-easy thrills on Windows. It’s not obscurity that keeps Mac safe, it’s difficulty.
Nice work , MDN. You really make the case!
As it has been said on and on and on in these threads, the “larger target best target” for viruses only holds if one believes that every OS is inherently as secure – or insecure – as all others. If that was true, then of course, the largest target is the best.
Too bad this is not true. It is not true that Windows is as secure as others Oses, especially against Unices: it does not get to their ankles. Conversely, it is not true that other OSes are as vulnerable as Windows.
Hence, what we have is that the largest target is at the same time the easiest and more vulnerable of all out there. It would still give greater return, in terms of absolute number of infected machines even if it was the smallest target.
Is that SO DIFFICULT to understand?
Ted sez…
“Hackers (most, not all) want exposure, they are not interested in bringing down personal users, graphic designers, musicians and grandmas… Until OSX makes it’s way into the corporate world, we are obscure..”
———
Your argument that the Mac is never attacked because hackers aren’t interested is a joke. Do you seriously think that there’s not a virus writer out there who wouldn’t give his left n-t to be the very first to bring down all us smug Mac users and be able to brag about it for the rest of his life? You aren’t living in the real world!
It hasn’t been done simply because the guys who write viruses hasn’t been able to come up with one that will get through the built-in security. A sucessful virus attack would be a big feather in it’s author’s hat even if he didn’t take down more than 3 Macs! He would probably even be happy to go to jail over it just to be able to laugh at us.
OS X platforms runs at SLAC, LBL, Los Alamos, Virginia Tech, CERN, KEK, Genome Research Labs, Max Plank Institutes, NASA, US Army, etc.
Weird names for Retirement Homes.
UHAHHAHAHOHOHHUAHAHAHHA
personal users MY ASS!
AAHAHHOHUHHAHEHAOH what a drone.
Ralph,
Actually you are not living in the “real world” if you think that OSX is completely immune.
Yes, there probably are some virus writers who would love to wear the crown of first to write an OSX virus. Maybe some have tried and failed… I honestly do not know.
I do know that OSX is not in the most visible places to make the maximum impact.. ie.. Major corporations, banks, government agencies etc.. In that sense, we are obscure.
I’m not saying that it’s easy to get into OSX. I’m saying that it can be done.
Ted: of course it can be done. There are even white papers on virus exploitable flaws – common to practically all Unices – for OS X.
But that covers only requirement 1) as Seahawk up here explained.
Who cares if you may infect ONE machine doing specific things if you cannot spread to others. Seahawk is known for having explained this in one sentence time ago:
“If it cannot spread it is not a virus, it is a joke”.
So yes, you may infect any Unix platform, OS X included, for example using root exploits. The issue is, good, than what? you knock on your neighbor and ask “Hi, may I sit in front of your Mac so that I can infect yours as well, you know, I wrote this virus but I have to input manually some commands to infect other machines”.
Can’t you see the ridicule in it? Yes, it can be done. Nope, no automatic way to reproduce and spread effectively has been found so far. That is the reason for the 0%. That is the reason why even well conceived Unix viruses infect so few, so much so that it is a waste of time for virus writer to spend lots of efforts in cracking one Unix platform: they are faced with the question: “Now what? Got one, how to get a second?”
In regards to Grandmas post:
Laugh all you want.! Yes, I am aware that OSX platforms run at a few notable agencies like the 10 or so you’ve listed. And yes, there are probably another 20 or 30 that you have not mentioned. But compare that list to notable agencies and Fortune 500 companies that run Windows and talk about which would have a greater impact for a hacker to take down.
… and the reason why no way to automatic spread exponentially has been found has to do with how Unix is designed, not because people do not think it is an interesting target!
Ted: would you go after 500 Millions machines that let you infect 5% of them or after the 50 Millions machines that let you infect 60% of them?
iPodder says “Now what? Got one, how to get a second?”
I have no idea, I’m not a virus writer. I will however not be so smug as to believe that someone will not figure out a way.
Then, Ted, if you are aware, do not go writing here that OS X platforms are not present in JUICY environments to crack. Why to juicy than a bank.
Do you know how much you could sell nuclear secrets contained on the average OS X platform used at, say, Los Alamos?
“Hackers (most, not all) want exposure, they are not interested in bringing down personal users, graphic designers, musicians and grandmas… Until OSX makes it’s way into the corporate world, we are obscure..” -Ted
Ted are you the spokes model for ALL “hackers”? Since you know that “most, not all” want exposure, you must be their voice.
What about the hackers that are grabbing Windows PC’s, making them their bitch and turning them into broadband “zombies” to launch various illicit activities? Do you thing they want “exposure”? How about the hackers that snagged several thousand credit card numbers, social security numbers, drivers licenses, etc. in a massive identity theft campaign recently? Do you really think these hackers want “exposure”.
Give your head a shake and stop claiming to be the grandaddy of “logic” – may work for Spoke, doesn’t look good on you.
Sometimes MDN goes off course (we’re all human). MDN is right on point here!
Grandmas?
Because I am trying to make the point that 16 million users or not, we are still relativiely obscure compared to the alternative.
MDN, Arik Hesseldahl’s editor’s email addresses may be more usefull.
Mac Mania Says:
“What about the hackers that are grabbing Windows PC’s, making them their bitch and turning them into broadband “zombies” to launch various illicit activities? Do you thing they want “exposure”? How about the hackers that snagged several thousand credit card numbers, social security numbers, drivers licenses, etc. in a massive identity theft campaign recently? Do you really think these hackers want “exposure”.
Probably not, that is why I said “Most, Not All.”
I would not use the word ‘obscure’. It depicts a wrong situation. Sure, it is more fun to bring down CNN and ABC, and DMVs but would not be as fun and disruptive to bring down major newspapers – where they use a lot Macs? There are environment as fun – for a virus writer – to bring down, that use extensively Macs, and yet, they are not brought down.
Don’t you think that bringing down major designers companies disrupting commercials and advertisement companies, and ads on newspapers would not cause major mayhem around in the country? I think it would, and by a lot. Why it does not happen? Think about blocking all ads publicists in the US for 3~4 days. What would happen? CHAOS.
Be glad those creative designers for the most are on Macs
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
Seahawk; you jumped in, thus keeping me from having to quote your posts about the subject from March of this year.
Sorry, but the explanation you wrote in March is more clear than the one you wrote today!
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
I am stupid, sorry.
Unix is a more secure OS period. How many Sun OS viruses have you heard of? Okay well the Mac is on a BSD Unix based OS. It’s just more secure by design than Windows will ever be.
Have you tested your Mac’s defenses?
First make sure your Firewall is on, and using the advanced features turn on everything. Take a look at the ipfw.log (firewall log) and have it open.
Now visit this site and go through all the tests, you should be invisible.
http://scan.sygate.com/
This is almost amusing, but let me add my points and continue chuckling.
I don’t think business installs have much to do with Windows being a big fat juicy curve ball for viri writers. It’s the OS. It’s the ease of access, as others have mentioned, that makes it so attractive a target, and also the ease of a quick expansion. Drop a package in an email saying “Brittany shows her goods” or pathetically “Someone loves you” and social engineering opens the door. Then the fact that ports are open, visual basic a click away, and the user doesn’t have to authorize system level installation…well, if some people don’t get that that is much less secure that OS X, there’s not much more to say.
I however do agree that someday something may come along that somehow gets into OS X, and I agree, that is why Apple doesn’t advertise security: that would be dumb because of the crow it would have to eat. So I will run my iBook with no virus software and no spyware software, but I will pay attention and if something bad comes along I will react appropriately. I will continue to run my PC behind a firewall with antivirus software auto updating and me manually clearing out spyware.
Well obviously that post above was not me. It’s sad that one can not carry on a debate in this forum without being ridiculed and called names by presenting an opinion that is not in the majority. Now that the name calling has started I am leaving this debate.
Bottom line: I love Macs, I love OSX, I love Apple. I hope that OSX can remain virus free and free from hacker attacks for a long time to come. I just don’t think it’s realistic to say that we are completley immune.
Oh another thing make sure you click “reload” in the consol logs to display several days worth of attacks.
Copy, paste and save the text in a textedit file as the log rotates over time and old info is discarded.
Running a Network Utility “who is” on the IP of the attackers is quite revealing.
Steath mode attacks from Apple and Google this labor day weekend.
Must be some Windows machines online over at Apple or something. 🙁
Okay last post.
Thanks TGR. My thoughts exactly. How long now before someone says you are stupid?
This is a bit of an over-reaction. The “security through obscurity” point was not a big issue in the article, and someone has posted a rebuttal on the article web site.
If you want another good rebuttal though, consider Java — probably one of the most widely used technologies in secure applications (banking etc.). As far as I know, there has not been one case of maliciously exploiting a Java security hole (though a few have been exposed and fixed, so the potential exists for a previously unknown Java security hole to be exploited).
I seem to remember not long ago some Mac platform software vendor putting out a large, ($25,000 or something like that), reward for anyone who could successfully write and release in the wild a virus that could infect Macs running OS X. I also remember the Mac community pissing their pants over the challenge, convincing the company in the end to rescind their challenge.
Wisdom it would seem would be in recognizing the possibility of a successful threat, and preparing against it, rather than burying ones head in the sand and pretending “it can’t happen here”.
>I just don’t think it’s realistic to say that we are completley immune.
We are not compeletly immune, Apple is patching things all the time, but they stay right on top of it before it becomes a major headache.
Also Mac OS X has what’s called compartmentalized security, this stems from the military.
Windows has a raw egg form of security, hard on the outside (if you take proper steps) but soft on the inside.
Mac OS X is hard all the way though, like a hardboiled egg.
But still something can get through, if the conditions are right, the social engineering is right etc.
But it’s no where as soft as Windows.
‘pete’ I may have missed it, but has anyone said “it can’t happen here”?
To paraphrase the collective “wisdom” of the enlightened posters: The chance of Mac OS X being turned into some sleezbag hacker’s bitch (like Windows PC’s do every millisecond) is remote enough for us to go skipping along singing happy songs and playing with daisies.
However, should the dark day every come when even the mighty Mac OS X is overcome, we’ll load virus/trojan detection software and fear for our lives online the way Windows PC users do now.
Rock on Steve
Ted wrote “The very reason Apple does not market OSX for it’s security benefits is because they know very well that the OS is not immune.”
Not true. Apple openly advertises their anti-viral abilities. Their official training to its Apple Store employees (based on a friend, an Apple employee) states they may clearly mention Mac’s inherent virus protection. If you visit any Apple store, and ask any employee, they have no hesitation and quite proudly and openly mention Mac’s anti-viral natural abilities (unlike their obvious silence about rumors). But, they are also quite polite to mention that Apple doesn’t pride itself on the weaknesses of its competition, but on their own strengths; Apple employees do not gloat (which they easily could) over Microsoft’s troubles, but quickly turn to the Mac’s other two dozen obvious advantages.
If I didn’t make so much on art, I might consider sending Apple an employment application. Seems like good people. Their UK stores are seeking “Creative Specialists”. For a job, how tempting is that?!
Seahawk… Just wondering (and I really don’t know the answer) would servers be more attractive or better targets for hacking? It just seems to me to make sense that infecting a server would be more efficient in bringing down major corporations, shutting down websites and/or spreading viruses. Obviously, it would be a more difficult job since 1)Unix/Linux based systems have major shares of server markets, and 2)Servers are managed by administrators who are more likely to know what they are doing than the lay computer-user.
On that note, there were recent articles by Anandtech demonstrating that OS-X server had a number of weaknesses that would make it less likely to succeed in the corporate world.
By the way, the motives and methods of virus-writers are changing, or so suggests this BBC article:
http://news.bbc.co.uk/1/hi/technology/4205220.stm
It seems money, rather than fame or kicks, is becoming the main motive. Which is changing the methods: (quotes from the BBC article)
“Now most of the big outbreaks are professional operations… They are done in an organised manner from start to finish.”
“Few virus writers now want to hit the front pages… most prefer to have their creations sneak under the radar, rack up a few thousand unwitting victims who are then milked for money or saleable data.”
Now I’m wondering, if these assertions are true, just having a smaller market share may also mean we would more easily figure out who the culprits are. Hacking a Windows system is less likely to stand out now that it has become so “normal” to have an infected Windows system.
Microsoft Windows problem is; insecurity through inferiority!
Hey, a just got a virus!
Can I know sit down and load it up on someones mac!
HA!
That was great.
OH, by the way Bill. My OS is better than your OS!
MacMania:
The handle is “inaminit”, not Pete.
By the way, as a new Mac owner I appreciated the little tip on checking the IP addresses in the IPWF log. You’re right, it’s VERY reveling.
“It can’t happen here” is a generalized summation of the collected expressions that I’ve seen on this and other Mac boards. Far to many Mac users seem to have the attitude that viri simply can’t happen to a Mac. It’s not the hardware, but the software that hackers hack. And they have shown us over and over that any OS can be hacked, given the time and determination to do so. But I certainly agree, it would take a lot more work to do it to OS X.
A friend just forwarded me this email:
QUOTE
Please get your facts straight. The arguments above have been so thoroughly discredited that the only reason to repeat them, apart from ignorance, is because one may be a Microsoft apologist.
Read this and weep.
“Far less often” is factually wrong. There are NO VIRUSES AT ALL. Zero. Nada. Zip. Nashi. Rien. Nichts. Ling.
Nothing despite the 10 to 16 million Macs being out there, many (like mine) having found and discarded anti-virus software as useless.
You should have said:
>There are currently no viruses at all for Macs because, unlike Windows, the OS is more secure by design.
>Of course, the more popular Apple machines become, the greater the chance of some virus writer finding a way to penetrate it.
That would have spared you a few emails.
ENDQUOTE
The biggest obstacle to breaking Mac operating system security is a function Apple built into Mac OS X by design. Root is disabled by default. It does not even exist! You can enable it if you are savvy enough to locate its enabling location, but chances are unless you know what you are doing you won’t ever do it by accident. So what does this mean? Someone could tell you to delete a file in your system level files, and you won’t be able to. Now granted regular third party applications and your documents aren’t as secure, you can certainly back those up and never have to worry about them. The number one failure of all machines is users who don’t backup their data. That’s true on Macs and PCs. Eventually all hardware fails, and it is up to the user to know to backup their data. If they know that, then the security of the Mac is solid. And there is less to recover on a Mac, than there is on a PC that has been infected every which way till sunday.
Leo Laporte and Steve Gibson of grc.com have recently been talking about the possibility of privacy invading cookies being put on your machine by banner advertisers at sites you visit.
Leo goes into how to protect against this a bit at:
http://leoville.tv/radio/pmwiki.php/ShowNotes/Show171#toc12
HOWEVER, you will notice that of all the major browsers only Tiger’s Safari has the refuse 3rd party cookies option turned on by default. So once again the Mac is safer right out of the box (as long as they are using Safari on Tiger)
Even tho Leo has already mentioned it, the topic will be covered in more detail in a future podcast (look for Misfortune Cookies in the future episodes topics section):
http://grc.com/securitynow.htm
Ted: no one said ‘OS X is immune’. No OS is immune to attacks and/or virus like activity. Unices are attacked and are infected but they much less an interesting target in that they require much more expertise to be cracked than what you need on Windows (google for virus kit) where you basically only need to understand English and a very basic knowledge of anything computer. The rate of infection at peak spreading is what makes Unices way far less an interesting target: why bother for few % after very hard work when you may get enormous percentage with little to no effort?
kenh: you might be right but it becomes tiresome to repeat time after time the same things about Unix security vs Windows openness. Beware all, Windows was MADE open by design. It was a choice in order to make everything extremely easy is inter/intra communications among modules and programs. Easy for programmers, easy for users. Too bad it fired back and Windows has no way to step back: it is an open system, everything is allowed to exchange data with everything and order everything to do anything. Very easy for viruses but at the time no one thought about that.
Too Hot: absolutely. Servers are a much more interesting target in that usually in one go you may have access to informations allowing the access to thousands of users accounts but – per se – they do not present an easier target for this. Actually, servers are in general more protected than single platforms. The Anandtech was on performance not on security. One astonishing result is that it seems the announced micro-management of threads in Tiger is still inactive, behaving as it was in Panther. Apple needs to solve this otherwise people would buy an Xserve and slam Linux into it. Not great PR.
gopher: the disabled root is an additional security wrt to vanilla Unices in that it is the main target for this family of OSes. On Unix you go after weaknesses that allows for root escalation. Once you get that you have basically the same control as if you were on Windows. Still the same trouble remains: you have to find a copy-cat configuration in another Unix platform to spread. This is fundamentally different to Windows situation and it is what limits spreading in Unix world making them a much less attractive target. I hope people realizes that the majority of servers in the WORLD run some form of Unix, not Windows. They are the largest target, not Windows and in targets that make breaking havoc into CNN a script kiddie job. Actually, all these viral attacks on Windows are from kids: have you seen anyone arrested for attacks on Windows be anything but disgruntled kids? For one, if I was a manager for a large corporation, I would chose a system that requires wisdom, skill above the latest percentile of education levels, and decades of experience, not an teenager wanting to take revenge for a failed date.
I just wanted to let you all know that I have added a Security Features section in the Macintosh Wiki at:
http://wikitosh.com/wiki/pmwiki.php/Wikitosh/SecurityFeatures
Since I am far from being an expert on this any contributions from the high powered readers here would be greatly appreciated and hopefully will benefit other members of the Macintosh Community.
What’s that? Eunice is infected. Damn! Glad I used protection.
Q. If virus writers only target Windows, why did the Mac Classic O/S – and Atari and Amiga machines – have viruses, back in the day when the only way they could be transferred was by floppy disc? (And they still spread then).
And why didn’t they exist on the Unix machines of the day (yes, they were expensive, but every comp. sci student had access to them – and they were networked and had email).
JulesLt: way back in time, viruses for Unix were existing. They were very difficult to write (need of great technical knowledge and skill), spreading minimally, being a prank activity among researchers at labs.
Unix design made them nothing more than a joke among cognoscenti.
Then Windows 3.x came out. BANG. Revelation: viruses blossomed in no time, every one was able to write one with little knowledge, were spreading without effort, the ‘crack into one crack into all’ was at the grasp of everyone.
Thanks to Windows everyone concentrated into it leaving other OSes alone. At that time Windows had the same market share as Amiga today: virtually ZERO.
So much for the ridicule protection via obscurity.
Heck, already we have the first virus available for Windows VISTA and it is not even out yet!
To concur – I don’t believe OS/X is immune, but like most here, it is because it is better designed not obscurity. There have been a number of genuine hacker exploits of ‘obscure’ systems – hackers are definitely interested in Unix systems, servers (and routers – look at the talk on possible Cisco vulnerabilities).
I’ve known people with websites on Linux boxes who’ve found their websites defaced by hackers because they didn’t close exploits in their web server software.
To me that says ‘security through obscurity’ is a myth – even if there’s only 10 people out there capable of doing it, the Internet means they can, and can be just as effective as 100000 script kiddies.
What these things have in common is that they are typically ‘cracks’ rather than viruses. I might be able to create a program to automatically crack and deface a website using a known exploit, but that is not a self-reproducing program. ‘Worm’ style attacks are feasible on any server (but less likely on Unix), but that is less of a worry to the home desktop users.
Apple’s own record on design security isn’t perfect. The original Mac OS had viruses (my view : it’s origins were similar to Windows – the original OS was designed as a single user, non-connected system). In Tiger they opened a hole (quickly fixed) with widgets – effectively reproducing the same mistake as MS did with ActiveX in letting websites automatically download programs capable of modifying your computer. What’s notable to my mind is that the Apple virus count went down to zero when they moved to a Unix foundation, and that’s where the security comes in.
Seahawk – at last, someone who understands that Anandtech article – can’t believe number of people who’ve read this and completely failed to grasp the point other than ‘performance problem found in Mac OS’ (some not even distinguishing it was Server). It’s a flaw that would certainly make me reject using an xServe to run a website supporting hundreds of users, but would be completely irrelevant if I wanted to run a grid of 100 xServes to model the Big Bang.