“Friday’s release of the new version of the Mac OS, dubbed Snow Leopard, could include some security features that would make it secure, or at least push it closer to the level of security that Vista and Windows 7 have, experts said this week,” Elinor Mills blathers for CNET.
MacDailyNews Take: What, Apple’s dumping the Mac OS X kernel, adding a fargin’ Registry, and opening ports at random in Snow Leopard? Give us a break, Ellie, you sound like an idiot.
Mills continues, “Contrary to popular Mac fanboy belief, Macintosh is not more secure from a software standpoint than modern Windows; it’s merely safer to use because malware writers prefer to target the platform with the biggest install base, according to Charlie Miller and Dino Dai Zovi, co-authors of The Mac Hacker’s Handbook, which came out this spring.”
MacDailyNews Take: “Mac fanboy belief?” The idiocy abounds. So, the so-called “experts” Charlie Miller and Dino Dai Zovi wrote a book. So has Paris Hilton and Britney Spears. When these self-proclaimed “experts” Miller and Dai Zovi come up with a self-propagating Mac OS X virus, give us a call. Until then, they should stick their endless FUD where the sun don’t shine.
Our firewalls are off: Bring it on, boys. Oh, what’s that, all of your “expert” exploits require physical access to our Macs? Or you need us to go to a special URL without having installed the last three Mac OS X updates? So, do you want our Admin passwords, too, or should we just enable root for you? Miller and Dai Zovi are the Victor Lustigs of security experts. Fuzz that, fuzzers. Ellie’s just another mark or willing accomplice.
Update: August 29, 2009, 12:23am EDT: This article was originally posted on August 27, 2009 at 11:48am. We’re still here. Our firewalls are still off and we’re still online with impunity.
Update: September 1, 2009, 3:09pm EDT: Yes, you guessed it, we’re still waiting. Our firewalls remain off. Some experts.
Yet again — sigh — it is utterly illogical to state or imply that the Mac platform is secure via obscurity. Why, if obscurity means security, in April 2007 was there a virus for iPods running Linux (a few thousand devices total, to wildly overestimate, in all the world), but there are no viruses in nine, yes nine, years for the over 30 million Mac OS X computers that are currently online? When we hit a nice round virus-free decade will these morons finally STFU? And, why would criminals not target the most affluent personal computer users, the tens of millions of Mac users around the world?
We’ve asked those and similar questions for years, yet the silence remains deafening and telling. Instead we get a steady stream of lies and/or ignorance, CNET’s specialty.
The idea that Windows’ morass of security woes exists because more people use Windows and that Macs have no security problems because fewer people use Macs, is simply not true. By design, Mac OS X is simply more secure than Windows. Period. For reference and reasons why Mac OS X is more secure than Windows, The New York Times’ David Pogue, provides a concise mea culpa on the subject of the “Mac Security Via Obscurity” myth here.
Simple logic is certainly not what AV software peddlers, Windows PC box assemblers, and the leeches affixed to the Windows ecosystem want people to hear. Fear is what they’re after. The sheep must be kept in the Windows pen, no matter the cost to reputations, reality, productivity, sanity, etc. Far too many have far too much invested in Microsoft Windows for them to stand idly by and let it all slip away due to a vastly superior, vastly more secure solution from Apple. But, slip away it does nonetheless.
Every single time there is a Windows virus outbreak or a new OS release, the “Security Via Obscurity” myth gets trotted out. This is done for a reason, even though it gets more ridiculous with each passing year.
“Security via Obscurity” is a defense mechanism for the delusional and also tool for Microsoft apologists and/or those who profit from the Windows economy (see: the bulk of CNET’s ads) that’s designed to be used when attempting keep Windows sufferers from straying. 30 million Mac OS X installs is not “obscure” at all, but nine (9) years of Mac users surfing the Net unimpeded certainly is “secure.” Besides social engineering scams (phishing, trojans; no OS can instill common sense) the only thing by which Mac users are really affected are large swaths of compromised Windows machines slowing down the ‘Net with spam and nefarious botnet traffic targeted at exploiting even more insecure Windows boxes.
The. Problem. Is. Windows. Get a Mac.
Mills continues breathlessly, “A screen shot published on the Mac Security Blog of Intego on Tuesday appears to show a security feature supposedly in Snow Leopard that looks like it is detecting a Trojan in a disk image being downloaded via Safari. The post cites unnamed reports about an anti-malware feature being added. ‘If it’s true, it will mark a fundamental change in that Apple will be admitting that their operating system is as susceptible to malware as other operating systems,’ Miller said.”
MacDailyNews Take: Charlie Miller, bullshit artist. In the sidebar of his otherwise uninteresting review of Snow Leopard, USA Today’s Ed Baig reports, “Macs are known for being resistant to PC viruses, a selling point in Apple ads. So reports from the Intego security software firm about an anti-malware feature in Snow Leopard raised eyebrows… Apple says Snow Leopard merely enhances the ‘File Quarantine’ technology, introduced in Mac OS X Tiger [emphasis added by MDN], for detecting malware. It works with files downloaded in Safari, iChat and Mail; if malware is detected, Snow Leopard suggests you move the file to Trash. Through the Mac’s Software Update technology, Apple has the ability to add the ‘signatures’ of new malware as it learns about them, potentially avoidng spreading malicious code.”
Mills continues spewing FUD in her full hit-piece – Think Before You Click™ – here.
MacDailyNews Note: Contact info:
Elinor Mills:
Scott Ard, CNET Editor in chief: contact via web form
It is … interesting … that these … people … continue to insist on floating the “security via obscurity” myth. Well, “myth” may be too strong a word, perhaps “exaggeration”? There are more Macs out there than there were iPods running Linux – for certain – and there are more Macs out there than there were Vista Beta-testers – I believe – yet the smaller populations were hit, NOT the Mac. We KNOW the Mac has vulnerabilities, even if the Windows folk didn’t keep telling us, Apple keeps patching them. Maybe Mac users are just smarter? More cautious?
What a ignorant stupid ass. And a lying ass dog as well.
I’m so tired of the “virus writers just don’t care about the Mac and would rather target Windows users” argument. Who wouldn’t want the notoriety of infecting a mass number of Mac computers all because they don’t run virus protection or spyware protection software?
Who pays these writers anyway? It seems that since the invention of the Internet (thanks Gore), anyone is suddenly a journalist. My seven year old is smarter than a lot of the “experts” now days.
I was going to read her article, then I saw her byline photo which showed she had blond streaks in her hair. Never mind.
The last time I tried to argue this with a friend who’d just bought a PC laptop (even though I’d told him not to) and was already complaining about all the troubles he was having, he totally lost it.
He went off on a rant on me, and then proceeded to tell me how Macs DO SO have viruses, and gave me a web page that listed about 12 (that’s right, about 12) viruses, of which 11 were for OS 9 or earlier, and the one left was the trojan horse we’ve all heard about (which he vehemently argued was TOO a virus).
He got even angrier when I laughed again.
Obscurity? Puh-lease! Every university has a boon of Apple computers showing up in their classrooms. You’re telling me no one in their teens and 20’s (i.e. typical hacker age) has seen this?
While they’re at it they can try to attack my site as well. Plain old Mac Mini running plain old Leopard. Should be easy, right?
I don’t want to click, can someone that already clicked please publish here her email address and her bosses email address
CNET is a joke when it comes to real technology news. There so bias towards Windows they must be getting paid by Microsoft.
Here’s the real headline Cnet, Windows 7, trying to catch up to Tiger and failing miserably, film at 11.
Get real, no one is fooled by your fiction anymore CNET.
@Tt
Go directly to her profile page:
http://www.cnet.com/profile/elinormills/?tag=mncol;txt
Contrary to CNET, OSX has never been compromised or cost companies BILLIONS OF DOLLARS IN LOSSES BECAUSE OF LACK OF SECURITY unlike Microsoft.
Nor has OSX ever been broken into in the real world contrary to your supposed fairy tale people.
Where do these people make up such garbage?
I once downloaded what I thought was a virus. It turned out to be a word processor.
CNET spoons with Ballmer (shudders)
The security through obscurity myth baffles me. I even hear Apple friendly pundits endorse it. And it makes no sense.
Hackers love to hack. Look back at the time when there were dozens and dozens of operating systems competing for dominance. There were very few actual computers in existence, but there were plenty of hackers attacking them.
Second, there is a huge economic incentive to attack the Mac. It’s like saying that no criminal would want to go into the richest neighborhood because it “only” constitutes 10% of the population. That they’d rather spend their time robbing the other 90% because there are more of them.
Finally, hacking the Mac is the Holy Grail of hacking! You’ve got to be kidding me if you think that every Tom, Dick and Harry wouldn’t love to create a virus just for bragging rights alone.
OK. Enough ranting. If I’m wrong, I’m wrong. But I’d like to have someone explain to me why the three points I’ve made above are invalid. To me the whole obscurity v. security myth is the biggest rationalization in the world. Macs don’t have viruses? Why could that be? Could it be because they’re more secure? Nahhhhhhhhhhhhh.
Why write a virus for only 8% of the world?
These so called experts are Windows experts at best. I liken a Windows expert with somebody who grew up in North Philly. They’re street smart. They know where and where not to go. They’re extremely aware of daily violence, including drugs, gangs, shootings, etc.
Now imagine that North Philly expert telling people that the Doylestown suburbs are just as bad because it’s known that some people forget to lock their doors.
Nope. Doylestown is far safer, despite people leaving their doors unlocked.
One reason is because those people, like Apple, care about their neighborhood.
F Windows and its security nightmares. F Windows apologists. Enjoy your $399 desktop that comes free with identity theft software.
@ Mary
To say you’re the only one who can do it.
Why don’t Journalist do real research any more.
Charlie Miller and Dino Dai Zovi are NOT Security experts, Mac or Windows. I read their book most of it is full of speculation and unfounded assumptions. All the real hacks that they talk about require access to the Console or tricking the user into installing something and the Admin (root) Password. They presented nothing that shows the Mac to be insecure in fact if you read the book you’ll come away with the feeling that the Mac OS is Thousands of times more secure then Windows Vista or Windows 7. Many of the security issues they talk about are assumptions and speculations that the Mac OS has the same vulnerabilities as Windows and that attack vectors and methodologies can be the same. Real Security experts will tell you that it’s not the case. Because the Mac OS is designed from the ground up differently then Windows, in fact Microsoft for Windows Vista poorly copied Apple’s user security model to derive the Windows UAC (the biggest advance in Windows Security todate). One of the issues with UAC in Vista & 7 is it is only skin deep, stupid and constantly required the user to allow actions. In the Mac OS X the User security is at the Kernel and file system level and rather then constantly requiring the user to approve actions/changes (the user just stops reading after the very first one), Mac OS X requires that the user authenticate the main action from that point the OS takes over and looks at what is going on, some Kernel and file system access is protected and the installer/Application is prevented from certain types of access. Hackers and Malware creators soon learned how to suppress and even intercept the UAC dialogs and approve their malware and hack installs without user intervention or knowledge. The exploit code to do it is freely available on a host of hacker sites and IRC Channels. Malware writers can’t by-pass Apple’s password authentication requirement because unlike Windows Vista & 7 it’s not just window dressing it’s real protection.
journalists just blog! News, facts, research, subject knowledge, competency etc are for lawyers!
It’s about column inches and number of posts, that’s what pays.
Hey ChrissyOne!
Good to see you on the boards.
HAHAHAHAHAHA!!
Is Elinor Mills serious? Was her article meant for April Fools day and accidently got published tragically early?
Snow Leopard could make OS X as secure as WINDOWS VISTA and WINDOWS VISTA 1 1/4: WINDOWS 7?
The mind reels. Contrary to popular paid Microsoft astroturfer lies(I’m looking at you, Ellie dear), Macs are more secure than Windows because OS X is *UNIX*, an operating system which is fundamentally designed with networking in mind, fundamentally designed to sport a multi-user environment, and fundamentally designed to be secure. By very competent software engineers. Since day one.
Gotta love the logic of Microsoft’s toadies, though. Who else could come up with the idea that a platform with zero viruses is less secure than a platform with by tens of thousands of them? Many of which are still perfectly capable of infecting Vista/7.
Elinor Mills, “So the editor said the new Windows 7 ads are all lined up and we need to say thank you to Microsoft for the business. I want a Snow Leopard hit piece.
Shit, if I knew the editor was going to whore me out like this I would have stayed at the strip club where he found me.”
“Many of which are still perfectly capable of infecting Vista/7.”
With more being written every day that *specifically* infect Vista/7, I should add.
C|Net = shill media
Elinor Mills. Bwaaaaaaaa-ha-ha-ha-ha-ha!
If you haven’t yet, read the article comments. It looks like one of our political threads, only slightly more polite. ;P
Sing the song — you know how it goes.
Eric Willard is a moron.
Billy Gates is a moron.
Steve Ballmer is a monkey.
Elinor Mills is a moron.
@ Demon
Good post. I hope you sent Elinor and email with the same message.
wheres’ ampar when you need him?
@ Mary
Why write a virus for only 8% of the world?
Because mary, if you did, you name would be known the World over, as the first person to do so. It seems no one wants that glory & fame I guess, so you’re right, why write one. I certainly wouldn’t want that on my record, being the first.
Blonde is as Blonde does….
Another analyst surviving of the teat of Microsoft…..
Thank you, CNET, for not changing your biased ways.
Damnit…I meant off
Mary….the best PC virus writers get great jobs with security firms (or the government). For 9 years OSX has been touted as extremely resistant (actually impossible) to infect. Anyone who can crack it successfully could probably write his own ticket ….
also
the other myth we could propagate is that macs are more expensive thus mac owners are richer so why wouldnt you want to write a virus for them?
sheesh
go find some clothes for the emperor already
Apple makes it drop dead easy to update the OS and most Mac users have the default setting to have Software Update run once a week. So it’s a no brainer when security updates come along.
The fact of the matter is, Apple patches serious holes fairly quickly… and by serious, I mean open vulnerabilities that can be capitalized on remotely without user interaction. The fact is, the only way anyone has ever run rogue code under OS X was, someone had to be at the computer doing something.
Recently, I became involved in a rather prickly argument with a colleague who informed me I was “delusional” for believing there were no Mac viruses.
She’d “read somewhere” that there were already viruses for Macs, and my attempts to explain to her the differences between viruses, worms, and trojans were in vain.
But the argument taught me one thing – the notion that Macs are just as insecure as PCs is taking root. FUD works, evidently.
I would register to send her an e-mail so I copied it here.
CNET is the saddest excuse for news of any kind, Your latest ridiculous rantings have shown that you and CNET are a following the folly of your god microsoft. How you can report this untrue crap and think of yourself as anything other than a complete idiot is beyond belief.
Why is everyone so surprised by this?
In a county where nearly half believe all the ridiculously over the top FUD about the current healthcare reform effort, why would you expect this same population to accept the TRUTH about the superior security of OSX over the pathetically insecure Windows platform?
Once you recognize that a large percentage of the US population are total morons, issues like this are actually should be expected, not surprised about.
I agree with the general feeling throughout the comments. These people clearly don’t understand the exploitive mind. First, there are enough Macs in the world to justify exploiting the OS. According to MS, Mac users are rich, so they make an excellent target. And, surely there must be at least one hacker out there saying, “These Mac users are a bunch of arrogant asses who think they are so safe. I’m gonna nail ’em all with the best virus ever!” Just the notoriety for creating the first massive successful attack would be motivation alone. It will happen someday just because odds of life dictate it, but it’s not going to be because Apple, Mac users, and the OS are weak. (Windows anyone?)
Do any of you remember which was the 1st OS to be compromised in the last hacking competition? Took minutes, if I remember correctly.
Carry on chest thumping in your alternate reality. Don’t let big words like address randomization bother you.
If there was ONE Mac OS X virus out there in the real world, it would prove that it’s possible, and I would be mildly concerned. Since there are ZERO, I will be a “Mac fanboy” and not even think about it, at least until some dumbass journalist gets an article published claiming that Vista is more secure than Leopard. Oh please, I’m laughing so hard it hurts.
Yes, there are other types of Mac OS X malware that are NOT viruses, but they require the user intentionally download something from an unknown web site, run that something, and give permission (user name and password) for that something to be installed. Even Apple cannot protect users from their own stupidity.
I have a new, groundbreaking story for Ms. Mills:
New steel belted radial tires being sold for some cars may make automobiles as fast and safe as horses, or at least push them closer to the level of safety and performance that horses, with their steel horseshoes, have enjoyed for decades, some experts said this week.
“If there was ONE Mac OS X virus out there in the real world, it would prove that it’s possible”
Actually it is possible, even if there isn’t one. That doesn’t change the fact that there isn’t one, the environment is target rich, and many hackers wish they could write one, and they try.
But a UNIX based system with intelligent programers and all the real thought Apple and the BSD community put into it is a hard enough to crack target that after hitting your head on a brick wall for a few months you go back to scriptkiddie powning of easy to hit windows boxes. End of story.
“Do any of you remember which was the 1st OS to be compromised in the last hacking competition? Took minutes, if I remember correctly.”
I believe your comment was addressed in the article. Maybe if you could read you would have seen it….
c1 Hey (z snap) GF
As my Ol’ Pappy used to say …
If folks discussing Politics always stay “polite”
Then they’re doing something wrong
BC
Nice response MDN!
@ Shen
> Actually it is possible, even if there isn’t one.
I said, if there was ONE Mac OS X virus, it would prove that it is possible. That is 100%. It would prove that it is possible because one example would exist. I did NOT say the lack of that one example was proof that it is impossible.
However, until someone does prove it is possible by actually doing it, I’ll still be a smug and unconcerned Mac fanboy.
ah..Elinor….yeahhhh..first of all “Elinor” is spelled Eleanor..mkay..and also I’m gonna hafta go ahead ‘n ask you to suck my Mac’s RAM…and I’ve got 4gigs so it’s a pretty big RAM
mkay…buh-bye
I just went through the dumbass article and comments. WELL DONE MDN readers! I think Elinor will be limping for a week.
Here is how I slammed her stooopidity:
~~~~~~~
This is the most shameful article I’ve ever read at CNET. I’ve been studying and writing about Mac security since 2005. All I can say is:
Elinor: YOU’RE FIRED ! ! !
For those interested in reality:
The anti-Mac security FUD-fest was started in August 2005 by Symantec. They were attempting to sell their worst-in-class anti-malware program Norton Anti-virus to Mac users who smart enough not to buy it. MacAfee then joined in the FUD, but reversed course when their CEO pronounced that the best way to secure your computer was to Get A Mac.
After that point most FUD has come from hackers who have done their best to whip up a frenzy surrounding flaws they found in Mac related software, such as QuickTime, WebKit and Safari. But it is fair to say that they helped track down and patch several flaws in Mac OS X as well.
Meanwhile, the only malware that has shown up for Mac are Trojan horses, currently of 4 types of 17 varieties. Trojans require user failure, not computer failure, in order to be installed and do damage.
In spite of the FUD-fest, the hype-mongers have been effective in forcing Apple to get serious about security, which previously they were not. So folks like myself actually thank Dr. Charlie Miller and friends for their help making Mac OS X even more secure than it already was. I have Charlie’s book and I look forward to his continued useful work, and even his FUD foisting.
It’s worth noting that only highly ignorant people still tell the tale known as ‘security by obscurity’. It is easily disproven by anyone who can perform math, i.e. any 4th grader.
If you’d like to read Mac security facts and suitably laugh at the FUD, you might find my personal commentary and coverage of interest:
http://Mac-Security.blogspot.com
:-Derek Currie
It makes sense to me to have this feature in OS X… Just because our Macs are immune to such things doesn’t mean we should pass them on to our Windows slumming friends
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
@SwissCheeseSafari:
Don’t let little words like “chmod” and “root” bother you. You go right ahead and believe that Unix (OS X) is no more secure than Windows. You stick with your $299 laptop from WalMart and pirated software. I’m sure Apple doesn’t want you as a customer.
derekcurrie: Thanks. I’m one who feels, like Kenh, that until there’s an ACTUAL virus, don’t bother me with this stuff. It’s not always easy to find information about WHY there’s no viruses, and why it would be so hard to create and propagate one.
Sadly, there are still many people out there who either don’t know that Macs are virus free, even now, or who believe Macs will succumb sooner or later because, well, all operating systems are the same.
While OSX is obviously more secure in general, Windows 7 (and Vista too) have many features that some security experts have called “crucial” to a secure platform. Without them, other exploits like the one that allowed the Mac to be taken down in the Pwn2Own contest are just waiting to be found.
@ObeyTheFist:
In the Pwn2Own contest the security levels of all the computers held up for the first round where hackers had to attack over a network. It was only when they were given access to the machine and security levels were progressively lowered that they finally had any success.
As for Windows having “crucial” security features, picture a solid granite bank building with a locked 2 inch steel door and no windows. Now picture a wooden barn with an 8 foot cyclone fence, dogs inside, and security guards. The barn (Windows) may look like it has many impressive security features, but which is more INHERENTLY secure?
@Zeke
If I understand what I’ve read correctly, OSX was beaten by asking an operator to visit a URL. No security measures were taken down.
Try reading this very informative article: http://www.tomshardware.com/reviews/pwn2own-mac-hack,2254.html
I believe this article is simply about the features Apple adds to OSX with Snow Leopard that Windows has had for some time. I’m happy to have them (or will be, tomorrow…)
Maybe, just Maybe, Apple are trying to help the, new to Mac folk, who might inadvertently install malware from an unreliable source. Nothing more nothing less.
Adding the feature does not mean they are admitting the OS is susceptible to Malware etc. Apple is simply helping those with minimal Mac OSX knowledge and the increase in the nasties appearing as legit software on legit websites. Gotta be a good thing. CNet are a bunch of wankers. Trying to drag us into their shitty world of viral mayhem.
You might want to check on the definition of “security through obscurity”. The phrase has a meaning different from the way you are using it.
http://en.wikipedia.org/wiki/Security_through_obscurity
You’re all missing the boat on the ‘security through obscurity myth.’
I agree that it’s completely bogus for all the reasons given above (virus for Linux iPod, Windows 7 beta, etc). But it’s irrelevant.
Let’s assume for a second that it’s a true statement. It would merely INCREASE the argument for buying a Mac. After all, no one expects Apple to overtake Windows’ popularity any time soon. So, by that argument, Macs will ALWAYS have less risk of being infected with a virus than Windows.
So let the idiots have their ‘security through obscurity’ argument – it makes Macs even MORE compelling.
“Windows 7 (and Vista too) have many features that some security experts have called “crucial” to a secure platform.”
Crucial? How crucial can those security features possibly be when they haven’t stopped Windows 7(and Vista too) from being vulnerable to malware? Windows 7 can still *easily* catch viruses and worms in the wild. It can still *easily* be exploited out there in the real world.
This is in contrast to OS X, which has proven itself to be invincible to viruses and worms in the wild, as well as impossible to exploit out there in the real world. And yet some security “experts” want to tell you it’s lacking in crucial security features?
These people are not experts. They are either gullible to Microsoft’s advertising department at best, or employees of Microsoft’s advertising department at worst. The value of the Pwn2Own contest as a barometer for Mac security should quickly become apparent when you realize that none of the OS X “vulnerabilities” it’s uncovered have ever been usable beyond the doors of the Pwn2Own contest.
A few comments to comments. I’ll make them in two posts.
1) I only use the phrase “security BY obscurity”. The only reason I use it is because I am quoting verbatim the stupid phrase that is used as part of the myth mongering.
Clearly this phrase is being abused. Most likely some dope overheard someone intelligent use the phrase and decided to use it as part of the myth.
“Security By Obscurity” myth = Macs have a microscopic market share, therefore malware writers ignore it and go for the huge market share. It’s total BS with no foundation of any kind in reality. Instead it is an assumption on the level of a newbie to logical thought.
When actual math is used to compare the number of malware for each operating system, the staggering statistical difference falls well outside even any remote possibility of fact. That anyone then defends this myth only points out their laziness or their desperate determination to force false to be true. I’ve heard every wiggly argument under the sun to justify the myth, and every one is a failure. After awhile interacting with them for a while you figure out the meaning of “Never argue with a crazy person.”
Continuing:
2) Microsoft have put in place some modern methods of deterring hackers and crackers. They had to. They had the motivation. Their operating system is a bloated catastrophe of spaghetti code that is well beyond their comprehension. They can’t fix it. They’ve made many attempts over the last 15 years and consistently failed. They gave up. Vista is the proof. 7ista is icing on the proof.
Should Apple add in these modern security measures? Damned right!
But is it a BFD? Will Mac OS X roll over and DIE? Will THE BIG ONE virus hit Mac OS X and make us all go running home sobbing to mummy? Of course not!
Apple’s attention to security has been increasing exponentially over the last two years. This month’s security updates were the most in Apple’s history. But as is typical with humans, the house has to be on fire before you pour water on it and fix the cause. Mac OS X does not have a faulty electrical system that will burn the house down. Apple know that. We know that. So what’s the motivation? Planning ahead takes extra prodding. Prod Apple and they respond eventually.
This is one reason I actually praise the Anti-Mac FUD-fest we’ve enjoyed since Symantec insighted it exactly four years ago. It has hurt no one. It has inspired Apple. We benefitted
We the customers know we already had an incredibly secure operating system. It’s based on the two most secure operating systems in existence bar none: OpenBSD and FreeBSD. So why not make it EVEN BETTER?!
Let’s go MaNIaCaL!
Go Apple Go!
Add steal bar reinforcement to the castle walls!
Add boiling oil caldrons!
Put alligators in the mote!
Install the rotating knives!
Hire some Cenobites!
Conclusion: We win any which way you look at it. If users of the less secure operating systems can’t deal with it, oh so sad for them.
As long as we keep our eye on the ball, which is keeping our computers as safe as possible, our progress toward better than best will continue.

” width=”19″ height=”19″ alt=”grin” style=”border:0;” />
derek …
Authorities around these parts been known to arrest folks for being a Cenobite …
” width=”19″ height=”19″ alt=”LOL” style=”border:0;” />
BC
and if you missed my ‘note’ to you the other day, no biggie, will post the info/questions here – somewhere – in next week or so, and then all can join the ‘discussion’
“Don’t let little words like “chmod” and “root” bother you. You go right ahead and believe that Unix (OS X) is no more secure than Windows. You stick with your $299 laptop from WalMart and pirated software. I’m sure Apple doesn’t want you as a customer.”
Look the little Mac user is trying to speak UNIX. That’s so cute….. and so funny.
Stick to iTunes.
Oh, so you’re saying the little UNIX user is trying to speak UNIX?
Go back to CNET, kid.
I’m helping my nephew get settled for college this year- the school is NOT allowing any computers on the network until they install a list of security this and security that… unless you have a Mac. Then you can get on. This is not the first time I’ve witnessed this. The school gets it and these “tech writers” are clueless. And yes- my nephew has a Macbook.
Off topic….
MDN, I love Crucial (I always buy my memory there), but couldn’t they have gotten a good looking chick for that add? I’m getting tired of looking at that guy.
(Sorry if this offends any women out there)
Guess I need to break down and use adblock…
I mean ad – (not add) I can add by the way…
@Swiss Cheese
There’s holes in your theory. LOL. That was toooo easy.
@SwissCheeseSafari
Carry on your stupidity. Don’t let things like reality bother ya!
Just a couple of things for you to ponder…lots of pictures, so you’ll be OK!
http://boycottnovell.com/2009/01/01/vista-7-not-secure/
http://boycottnovell.com/2009/02/01/windows-7-banned-insecure-uac/
http://boycottnovell.com/2009/03/12/phil-reitinger-in-dhs-vista7-awol/
http://www.networkworld.com/news/2009/042309-researchers-show-how-to-take.html
http://www.google.com/search?hl=en&client=safari&rls=en&q=vista+security+flaw&aq=f&oq;=&aqi;=
All of the above, less than 1 minute on Google.
If you need, find a grown up to help you.
From the article: “Most Mac users seem to take pride in their supposed invulnerability, so one would think that they are less cautious in their surfing activities. But it’s hard to tell.”
YEP, we are free birds in the wind, carelessly clicking every link and ad, downloading the latest DVD-rip of Nolan’s Batman 3 and even using our “notebooks” on our “laps” – GOSH! Just wait for the viruses to come spewing in! AHHHHHH!
I’m gonna go pickup pieces of my mind from around the living room, as it was completely blown by this silly article. I think deep down in her heart, she’s knows she’s full of crap, but…
Fighting the media buzz against Apple’s is a losing battle. CBC posted an article about a fire death caused by laptop battery, and for some reason uses the opportunity to bash Apple… http://www.cbc.ca/canada/british-columbia/story/2009/08/26/bc-overheating-laptop-fire-death-vancouver.html?ref=rss
We can’t stop the Apple haters from spinning it how they want. It’s just too bad people listen.
Does the carpet match the drapes, Ellie?
Let me start by saying that I bought Snow Leopard last night and went from 137 gb to 124 gb. Wow. It is also smoking fast. But all that aside, I switched to the Macbook Pro I’m writing this on because of the laundry list of steady problems that has accompanied Microsoft operating systems. I’ve used them back to when I had a 486 DX/50 to an HP Pavillion running Vista that shocks me whenever I touch it. Motherboard is bad. The reasoning I give to friends and family is that using Windows is like the old frog in hot water analogy. If you raise the water temperature gradually the frog will boil to death. Everything till XP. If you drop him into the hot water he’ll jump out. Vista. I have to admit that until Vista came out I gave OS X a hard time. I don’t now. Leopard is the finest operating system I have ever used. Nothing even comes close. Snow Leopard looks to be even better. I look forward to using it. I firmly believe Apple, not Mcrosoft makes quality software. I’ve convinced three friends so far, and two family members. All have or planning to buy Macs in the near future.
One more thing. I also believe there is a FUD machine in Redmond. There at the heart of this machine is a bald, fat, sweaty, douchebag squeezing out a gazillion billion bopttyboomazillion dollars from his followers. Cooooooooooolllllll.
I am happy to let the windoze users think what they want. I don’t want them in the Mac fold. I enjoy being in the elite, superior group even though they think otherwise. I don’t have to clean up virus messes as they do even if they don’t know it.
OK CNET, so what you are implying is that it’s riskier owning a Mac than a PC? Justify that?
Skipping the emotions-laden kickback:
This is an important topic, although the article unfortunately misses the real threat, while successfully pushing peoples’ hot buttons to get website hits.
Historically, Windows has “better” security features, if that’s today’s definition of MORE.
The simple reason is that its security had been so bad for so long, plus there’s extensive legacy elements that’s not been made secure simply by getting rid of it. Such is the price for backwards compatibility.
Think of an analogy of a boat and keeping water out. The Windows security toolkit has an inner tube patch kit, shellac, wood glue & clamps, glass gel and a MIG welding torch … because Windows is kept afloat by (respectfully) inner tubes, canvas, wooden planks, fiberglass and metal.
As Noah would say: “How Long Can You Tread Water?”
Since each hull material must be repaired differently, one ends up with extensive ‘repair’ tools. However, having more tools is only necessary because of its heterogeneous patchwork nature.
Now sure, OS X isn’t immune from being perfectly secure.
However, by trashing legacy garbage, a more homogeneous OS architecture exists, which means a smaller leak repair kit…and ultimately a more easily-maintained system.
By being easier to maintain, there’s fewer caulking gaps between different hull materials, which means that its more work to find small holes to exploit, etc: as the article even says, potential hackers find things by “LUCK”: it is simply harder to work against OS X.
This doesn’t mean that OS X is perfect, but what it does mean is that it is far easier for that hacker to go over and pick the low hanging fruit of Windows to write his exploits.
Thus, the question isn’t if OS X is perfectly secure or not: all that’s required is for it to have an inferior Hacker ROI than targeting WIndows.
This is afforded in two ways. The first is by making it a more hardened target. The second is that market share has also had an influence on this.
However, with the overall Mac marketshare demographic being more affluent than average (more money to steal, etc), plus some college campuses now being more than 60% Mac marketshare, we have to place increasingly greater weight on the significance of the “hard target” dimension, much more so than the “security through obscurity” potentiality.
(When asked why he robbed banks, Willie Sutton simply replied, “Because that’s where the money is.”)
However!
What this article completely misses is that the nature of the security threat has substantially changed over the past decade.
Today’s pragmatic real world threat is overwhelmingly a trojan, personally authorized to install by the operator.
As the article admits, Apple began to address this security risk vector (through File Quarantine) back in 2005. Apple is now enhancing it further by having its malware definitions integrated into OS X’s Software Update system.
The overlooked implication is that this means that it is increasingly seamlessly and automatically kept up to current definitions for the entire installed user base.
But because this is done with merely one tool instead of a fragmented dozen, we are expected to believe that it is somehow “worse”.
“Riiiiiiight”.
-hh
“OSX has never been compromised or cost companies BILLIONS OF DOLLARS IN LOSSES BECAUSE OF LACK OF SECURITY unlike Microsoft.”
Because OS X is operating on less than 2% of al the world’s PCs. That does beg the question, given the massive security risk that comes with Windows, why is there no perceptible increase in OS X adoption?
If, as it is often implied, that users of Windows are cretins, idiots, morons, and imbeciles, why would any Apple fanboi expect someone with such limited intelligence to switch to a OS X? I mean, unless the Apple fanboi population is not self propagating cretins, idiots, morons, and imbeciles there is no need.
“That does beg the question, given the massive security risk that comes with Windows, why is there no perceptible increase in OS X adoption?”
Go check Apple’s latest quarterly reports. You’ll find there is a perceptible increase in OS X adoption(which is complemented nicely by the flatlining adoption rate of Windows and the ongoing collapse of the beigebox PC industry).
Simply nonsense.
Mac OS X is less prone to virus attacks because the Unix kernel is safer than the Windows kernel. Period. That’s it. End of story. Nothing else to discuss.
The notion that “virus makers prefer to attack the biggest installed based” is just nonsense. In that sense there should be AT LEAST one nutcase making viruses for Mac OS X. In fact, there should be a proportional virus number for Mac OS X, WIndows and Linux.
BUT, the numbers say: 90% is Windows, 9% is Mac OS X and 1% is Linux (I’m rounding, it’s not 100% accurate)
Soooooo, viruses should be 90% Windows, 9% Mac OS X and 1% Linux.
Reality: 99.99% of virus attack Windows, there are perhaps 2 for Linux and Zero, nada, zip for Mac OS X.
So, stop the bull$h1t! When you are a standard user, you should NOT be able to delete or modify system files (Unix 101). This is not the case with Windows. And THAT’S why Windows security sucks.
If you know any hackers (I have known some, of the non-malicious variety), they will tell you the notion of the Mac population as too small to matter is a disingenuous fiction.
Cracking the Mac is the Mount Everest, the Olympic gold, the Super Bowl, the brass ring of hacking.
I use both Windows and Macs. Have been doing so for years. I have never had a problem with a Mac’s performance until I installed Intego software. It pretty much shut down my Mac. I bought it as part of a 10 software bundle for $50. There is a reason it was so cheap. My Mac did not run right until I got all of the Intego software off of it, which took a lot of work.
So in 5 years, the only problem I had with my Mac, was when I put malware, called Intego on it.
In that same period, I had 3 major outbreaks or crashes caused by viruses on the Windows computers. I have also had the privilege of explaining to friends and family what software to buy, and how to setup security on the MS CRAP.
Thankfully, I have been able to convince the friends and family to switch to Macs. I hope for virus outbreaks, because once their MS POS’s are rendered useless, they switch to Macs, problem solved.
Does anyone pay any attention to how Apple is doing from a business standpoint? Even with all the idiots spewing pure ass spackle, sales are up, profits are up, etc.
Stop giving these attention whores the one thing they crave.
I, for one, love being safe due solely to obscurity. I love that I choose to be a part of that 8% market share. I thrilled that FINALLY OS X is on par with Shitsta and Shitsa SP3. (God Damn that a laugh riot.) Oh, almost forgot. I also love paying WAY more for a Mac when I could have saved money on a Windoze box.
These “opinions” are of no consequence. Over time, the truth always comes out. And when that time comes more and more “experts” are discredited and remove all doubt as to their true motives. The strong will continue to survive and like “MS security”, stupid can never be fixed.
Ask any uninformed college student which system is better. Todays youth, “get’s it”!
My intelligence has never been insulted by the babbling of some clearly misinformed “expert”. I do my own research because I want the best value for my hard earned dollars, which if the studies are correct, I have a pile more of than the morons belching this cloud of ass air.
“security through obscurity myth”
The thing that baffles me about the security-through-obscurity-myth proponents is that it requires a belief that they themselves totally understand the psychology and motivations of malware writers. What would be the basis of such a belief?
What is funny is that Windoze Machines have been constantly getting hacked and whacked by malware for close to 15 years (ever since Trumpet socket came out on Windows 3.11 for workgroups). Yet the same idiots that are constantly reformatting and re-initializing their machines still say the Mac is not secure.
just my $0.02
I do not understand why cnet always has underlying tones about every thing apple. They where comparing a palm pre to a Iphone and they rated them about equal granted the pre is a good pda but dose not compare to the Iphone and it is like this in everything they review so someone tell me what going on with cnet and apple.
A sign of the times:
I went to brunch this morning at my favorite restaurant. There were 4 ladies “of a certain age” at the next table. One was talking about waiting a “week or two” before upgrading to Snow Leopard.” A second asked about viruses. The first responded, “Why, Dear, there just aren’t any!” Then she turned to the whole group and said, “You know, it’s funny. We Mac users hurry to upgrade our systems, but my Windows friends avoid upgrades like the plague. I love my iMac.” None of them were under 55.
The tide has turned!
I’m feeling a little bit insecure right now…
I tried to find Elinor Mills educational data on the internet. there are no such documents available that I could find, most reputable writers have the honesty to post their credentials. However Cnet is not known for honesty, that goes double for ZD net UK. One thing is obvious she is an idiot and ugly one at that, I suspect she keeps her job by staying on her knees.
Woe Folks! Censorship at MDN! (Or a faulty restore from backup?)
Where did the second to last 3 posts go?! They were here yesterday! I suppose the fact that I wrote two of them is meaningful to me.
Now now Mr. Fergus. Just because she is a dishonest, mentally challenged MS suckup who perpetuates moronic FUD, does not make her ‘ugly’ or a prostitute. That’s troll talk on her level. You’ve been listening to too much HATE MEDIA. Not good for you.
Here is my last post to Cnet on the subject. Don’t know why I bothered.
“One last attempt; 35 million + OSX systems out there. Still waiting for the first virus. I am just so sorry to have to point that out to some of you……….
If you are sitting at my computer and I give you my passwords, you can download a trojan and let it install.
Who would do that?
Even then, it can’t self propagate to another Mac unless there is another person sitting at that second computer with the passwords, AND he then connects to my Mac and purposely downloads the trojan.
He can’t connect to it unless I let him.
It can happen on PC’s because the use a single file Registry. Until they get rid of that, people will always find ways of opening ports on PC’s that were previously closed. And they were closed, but only temporarily. Windows is just easier to attack. Low hanging fruit.
I know, I know. Someone will come back and say that they heard from their hairdressers mothers third cousin who dated Paris Hiltons’ dogwalkers grandmother that she go a virus on her Mac. How the hell would she know?
What more can anyone say? Sheesh!”
@derekcurrie
If the shoe fits wear it, and while were at it, lecture some one else, of course if she’s your mother what I said still goes, you pompous frigtard.
HAHAHAHA!

” width=”19″ height=”19″ alt=”grin” style=”border:0;” />
Yes, the Advil Mr. Fergus.
Get well soon.
Piss off derekcurrie, and hows your mama frigtard. I can see why MDN dumped your post jerk.
Simple Norton pays the Virus writers to develop viruses god windows. If you ever see a mac virus it will have been paid for by the AV companies followed shortly by a mac antivirus app. It’s all a protection racket. So pay your protection money and all will be safe.
Good evening. After all it is those who have a deep and real inner life who are best able to deal with the irritating details of outer life.
I am from Madagascar and learning to read in English, tell me right I wrote the following sentence: “‘followes aaker, david a.”
Regards 😎 Mervin.
How are you. If we fall, we don’t need self-recrimination or blame or anger – we need a reawakening of our intention and a willingness to recommit, to be whole-hearted once again. Help me! It has to find sites on the: Rabbit vibrator solo video. I found only this – http://www.fisica-relatividad.com.ar/Members/Vibrator/home-made-vibrators. Wave man, shown in the rocky suitability feature website. She does next waveform in using this, moving into my ground and following herself at pipe between my contacts, tapping the jars and beauty then back. Waiting for a reply :eek:, Theone from Kenya.