Microsoft’s Windows is far less secure than Apple’s Mac OS X

Apple Online StoreBy SteveJack

The headline might seem self-evident to most of us, but there are still quite a few drooling idiots who are incapable, or unwilling (it’s a hit-whoring prerequisite, after all), of seeing the vast gulf between Windows and Mac OS X security and the effects on end users.

The reason you see this sort of bullshit is because, according to IDC analyst Marcel Warmerdam, for every $1 that Windows earns for Microsoft, it will pump a minimum of $12 into the global economy. Billions upon billions of dollars are riding on duping people into continuing along with Windows.

If protecting the Windows hegemony means distorting all sorts of things to make Apple’s Mac platform look like an unacceptable alternative, then so be it. They really have no other defense for the indefensible Windows except for FUD when comparing to Apple Mac OS X’s stellar record of protecting their users’ security. The fact is that Mac OS X users, using only common sense, surf the Net with impunity while Windows sufferers most certainly do not.

Yet again, for the umpteenth time — sigh — it is utterly illogical to state or imply that the Mac platform is secure via obscurity. Why, if obscurity means security, in April 2007 was there a virus for iPods running Linux (a few thousand devices total, to wildly overestimate, in all the world), but there are no viruses in nine, yes nine, years for the over 30 million Mac OS X computers that are currently online? When we hit a nice round virus-free decade will certain abject morons finally wise up? And, why would criminals not target the most affluent personal computer users, the tens of millions of Mac users around the world?

I’ve asked those and similar questions for years, yet the silence remains deafening and telling. Instead we get a steady stream of ignorance and/or lie from hit-whorish Microsoft apologists.

The idea that Windows’ morass of security woes exists because more people use Windows and that Macs have no security problems because fewer people use Macs, is simply not true. By design, Mac OS X is simply more secure than Windows. Period. For reference and reasons why Mac OS X is more secure than Windows, The New York Times’ David Pogue, long ago providesd a concise mea culpa on the subject of the “Mac Security Via Obscurity” myth here.

Simple logic is certainly not what disingenuous hacks, AV software peddlers, Windows PC box assemblers, and the leeches affixed to the Windows ecosystem want people to hear. Generating fear and/or website hits is what they’re after. The sheep must be kept in the Windows pen, no matter the cost to reputations, reality, logic, productivity, sanity, etc. Far too many have far too much invested in Microsoft Windows for them to stand idly by and let it all slip away due to a vastly superior, vastly more secure solution from Apple. But, slip away it does nonetheless.

Every single time there is a Windows virus outbreak, a new OS release, record Mac sales, or a threatening new Apple product, the “Security Via Obscurity” myth gets trotted out. This is done for a reason, even though it gets more ridiculous with each passing year.

“Security via Obscurity” is a defense mechanism for the delusional and also tool for Microsoft apologists and those who profit from the Windows economy that’s designed to be used when attempting keep Windows sufferers from straying. 30 million Mac OS X installs is not “obscure” at all, but nine (9) years of Mac users surfing the Net unimpeded certainly is “secure.” Besides social engineering scams (phishing, trojans; no OS can instill common sense) the only thing by which Mac users are really affected are large swaths of compromised Windows machines slowing down the ‘Net with spam and nefarious botnet traffic targeted at exploiting even more insecure Windows boxes.

The. Problem. Is. Windows. Get a Mac.

SteveJack is a long-time Macintosh user, web designer, multimedia producer and a regular contributor to the MacDailyNews Opinion section.

80 Comments

  1. Read the original article…. and more importantly, the comments following it.

    Such lame Windows users just plain deserve to be infected. Young kids that glance at pc blog headlines and think they are now pc experts. Its sad, but then when their kids grow up in their PC infected world, its only natural.

    🙁

    Just a thought,
    en

  2. I agree with the article, but I doubt there will ever be even a majority of Doze users that believe it. We’ll never convince 90% of people that they are not good looking, they are not the best thing the opposite sex has ever seen (or the same sex as the case may be), or that they are not good drivers.

    So why should anyone expect to change the 90% of computer users who use Doze that it is not as secure as OS X?

  3. Steve Jack glosses over phishing for which WIndows and Mac users are equally susceptible and which is just as destructive as any virus.

    He also fails to mention that Macs are enablers who pass on virus-laden emails to Windows users, which only reinforces the problem.

    Also, if Mac users are using Bootcamp or virtualization to run Windows, then they should be just as vigilant as any seasoned Windows user. If fact, it would be unwise to ignore any discussion of viruses regardless of platform. The enemy of my enemy is not my friend!

    I recommend all Mac users running Windows software to invest in decent antivirus software, because any Mac user who thinks that just because they’re running Windows on their Mac, they aren’t susceptible to viruses are sadly mistaken.

    I would also recommend that Mac users use an ISP that processes all their email through antivirus software before its delivered to you. I receive notices frequently about emails that have been quarantined by my ISP.

    To avoid phishing expeditions and Root kits, I use Little Snitch. The Mac’s firewall, as well as my router’s firewall, are good for incoming requests and Pings, but there is nothing in Mac OS X that scrutinizes outgoing data.

    I mean let’s face it, were human, and are susceptible to phishing attacks but without a product like Little Snitch, how would you know if someone has p0wned your Mac?

    Viruses are the least of my worries because the of the way Macs are set up, but, I can’t always trust myself not to fall victim to resourceful phishermen.

    In fact, if I’m not mistaken, Safari won’t alert you if you encounter a website that is attempting to take advantage of you, whereas Firefox and Opera will.

    I know viruses are an afterthought for Mac users but, we can’t afford to pretend were safe.

  4. I should have stated also that I am aware that antivirus software won’t protect you from the newest viruses, only known viruses. So for all the good it does, not even AV software can keep you 100% safe, but good AV software can alert you to suspicious activity and even isolate a suspected virus.

  5. Here we go again…

    Going by the “logic” of the Inquirer, North Philly is safer than Blue Bell, PA because homes in North Philly have extra deadbolts on the doors and bars on the windows. See? Extra security means safer living. Anyone who has ever lived in, or around, Philly can understand my statement.

  6. Must be a good press week for security folks or something…interesting security perspectives here for anyone interested and not drowning in Cupertino Kool-Aid:

    http://news.cnet.com/8301-27080_3-10444561-245.html

    Good quote from one of the panel:

    “Robert G. Ferrell, information systems security specialist at the U.S. Dept. of Defense: “Is it more dangerous to take off from a terrorist-infested airport, or land at one? Flippancy aside, I just don’t think this question (Mac or PC) has any real meaning today. Far more relevant to me are the browser and e-mail clients a consumer is using, irrespective of the operating system or hardware platform. Even more critical from a safety standpoint is the level of security awareness exhibited by that consumer. If you haphazardly visit every link and download every file sent to you in e-mail or posted to your social-networking pages, sooner or later you’re going to get nailed. Period. Platforms are passe. Apps are where it’s at.” “

    He’s right.

  7. That site is filled with Windows-centric idiots, quoting bad statistics.

    But, statistically speaking, people living in suburbia live with LESS security than their ghetto-living counterparts. Sure, I know plenty of people in suburbia who:
    – don’t have multiple locks on their doors; hell, their doors are UNLOCKED all the time, even when at work.
    – don’t have bars on their windows

    Since ghetto neighborhoods typically employ those two pieces of security, I can now conclude that the ghetto is far safer than any suburban neighborhood and I don’t have to worry about robberies, mugging, gunshots…

    I know. I’m preaching to the choir, but it is amazing what people will do and say to defend a platform that invites malware.

  8. The Windows industry is huge and I doubt if anybody wants to give up their jobs for another OS. All those IT managers that went to school to get their certificates spent a lot of time and energy to get where they are. If I had a job like that now, I’d certainly want to keep Macs and OSX out of the workplace because it might take less personnel maintenance and I might be at risk at losing my job. The Windows platform is just like the iPod accessory industry. I’m sure those iPod accessory manufacturers wouldn’t like to see the iPod go away. People protect their livelihood any way they can even if they have to lie and cheat. I find it understandable that even if something better comes along they’d try to block it. That’s why it’s so hard for me to envision the demise of the Windows platform in the corporate world. There’s just too much easy money to be made maintaining a possibly inferior platform.

    This is how I think the military is. If wars don’t happen naturally, they’d try to start a few of their own just to stay in a state of readiness.

  9. @iphonerulez

    This is how I think the military is. If wars don’t happen naturally, they’d try to start a few of their own just to stay in a state of readiness.

    You make an interesting point about job security and then I get to that last statement and realize you’re just an another idiot who hates our military.

  10. There is a class of viruses for which “security through obscurity” makes sense to me: those that rely upon successive retransmission to generate exponential growth. To see this, consider m infected machines of a given OS type, each of which sends out n emails in an effort to infect others. Let f be the fraction of recipients sharing the senders OS, r being the chance of exposure (user clicks the bad thing, etc.), and p being the chance of infection when exposed. Then the expected number of new infections is the product m n f r p. If the product n f r p > 1, then the infections grows; otherwise, it dies out. Let’s compare OS’s keeping n & r constant–reasonable first-cut assumptions. Then exponential growth depends upon a certain minimum value of the product f p. Assume for this argument that f is 0.8 for Windows and 0.1 for Mac. Then it seems clear to me that, even if Windows’ value of r is 7 times smaller than Mac’s–that is, even if Windows resists infection 7 times better than Mac, Windows is still more likely to suffer a pandemic infection.

  11. Forget the iPod virus example. How about this…

    iPhone has a HUGE market share compared to Android. Number of viruses/malware/questionable apps plaguing the system is ZERO.

    Android, with maybe 1/10 to 1/5 of the iPhone apps, has already seen its share of phishing apps (pretend banking apps).

    So, obviously, security by obscurity is a load of shit.

  12. Well, there is a very small bit of truth in “security via obscurity.” If Windows was as secure as Mac OS X, then there would, in fact, still be more focus on the part of hackers on Windows because Windows has greater user share. The part of the myth that says Windows is a bigger target is accurate.

    However, it certainly does not explain why there are zero viruses out there for Mac OS X. And that leads to the greater truth.

    The reason why Mac OS X is far more secure is because it would be significantly harder and less profitable to compromise a Mac. The reason Mac OS X gets less attention from hackers is NOT because it is “obscure.” It is because Windows is easier to exploit. A thief is basically lazy. Why work harder to exploit Mac OS X (even if possible), when Windows (not Apple) is the low-hanging fruit?

    Even if Mac OS X market share grew to equal Windows market share, the hackers would still be going after Windows. It’s security via “having a much easier target out there for hackers.” Mac users everywhere should therefore offer thanks to Microsoft, for providing that target.

  13. It may be true to the slightest degree that developers of viruses, malware etc may not target the Mac platform due to relative “obscurity”.

    But in my short experience, I’ve learned that most people creating these viruses are doing it to be recognized for their hard work, and not for money, at least not right away. they will be recognized for their impact on society and then bought out by a company to consult on how to protect people from viruses like the one they made, if that makes any sense to anyone.

    So their doing it for recognition right? then why on earth would a hacker or whoever not target the Mac platform? people who know, know that the mac has never had a serious infection or outbreak, and if I were a virus creator I would be trying my hardest to be the first to give it one. Because as far as recognition goes, it’s hard to beat the first one who did anything.

    My opinion is that many have definitely tried, but they simply can’t do it…

  14. “Besides social engineering scams (phishing, trojans; no OS can instill common sense) the only thing by which Mac users are really affected are large swaths of compromised Windows machines slowing down the ‘Net with spam and nefarious botnet traffic targeted at exploiting even more insecure Windows boxes.”

    Wrong on this one. Macs are also affected by Flash bugs/security holes, Acrobat Reader bugs/security holes and Microsoft Office bugs/security holes that could potentially compromise a Macintosh, as reported in their updates. Apple also has various security updates that appear every now and then (but not as often it seems as the ones mentioned above) that fix potential security holes, although the malware authors have not come out without any zero-day exploits that I am aware of for the Mac.

    And Apple does NOT update anything prior to the previous and current versions of the OS, so myself running Tiger right now can NOT get any security updates, while security updates are still being released for XP and sometimes for earlier releases of Windows. But then Windows does need these fixes. Apple only seems to release system fixes and updates for the current release of the OS, although they do release as many bugfix/updates as they can for the previous OS version just after the newest version of OSX is released.

    Apple also does NOT update all the various “OSS” (open software system or freeware) components that make up OSX as often as they should and these OSS components could potentially be holes into OSX as has been evidenced by the black hat “hack a mac” contests held over the last number of years. The guy that has hacked into the Mac in these contests has said that is what he looks for, to find his way into a Mac to hack it. This is the Achilles heel of OSX security.

    I am a long-time Apple person (1979 on an Apple ][+, Mac in 1984, Newton in 1997) and I only use a Mac to surf the web or for email, but Apple, while heads and shoulders better than Microsoft on security IMHO could also be better too.

    Windows, in a setting that does NOT access the internet can be very stable and secure, but the holes for the internet allow the crooks to drive through and drive by your system and plunder it and drop off bots with ease, unless you have lots of time, energy and sometimes a bit of money to secure it properly.

    Security by Obscurity for the Mac is only partially true, simply because crooks, like anyone, are lazy and there is enough low hanging fruit via insecure Windows systems (legit Windows as well as so many illegitimate/pirated Windows systems) out there operated by people who don’t know security requirements but only how to work a program. The better design of OSX makes it more difficult, and the saying in physical security that crooks want to break into the least secure building holds true with computer OS’s as well, IMHO.

  15. Let’s just talk about the stats and forget about the technology for a moment…

    Let’s look at crime rates in neighborhoods. Crime are essentially viruses, trojans, worms, etc and the crime rate is the number of infection attempts. Police, alarms, and, security doors act like virus protection.

    Neighborhood 1 (Windows): Crime is rampant, people have alarms, security doors, and full staffed police. Crime still occurs nightly and high frequency despite protection measures. Attempts and successful breaches in security are normal.

    Neighborhood 2 (MacOS): Crime is very rare, people forgo alarms and security doors and there’ only one sheriff in town. One could even mistakenly leave the door unlocked and still not be a victim of crime.

    Neighborhood 1 (Windows) can claim to have more secure with all the anti crime measures in place and NOT get robbed whereas neighborhood 2 (MacOS) doesn’t really need the security measures since there isn’t much crime. Statistically, neighborhood 1 has a higher chance of crime whereas neighborhood 2 simply has no crime.

    Would you like to live in neighborhood 1 or 2? Lastly, Windows and MacOS are totally different. Quit comparing security technology between two different demographics. What good is security if you don’t need it. It’s really that simple. I’ve never used virus protection and likely never will. People using Macs are less prone because they are living amongst “friendlier” people and Windows users have tons on criminals around friendly people.

    If you want to get rid of crime, move to neighborhood 2!

  16. security by obscurity?

    OS 9 had up to 80 viruses. It had 3% market share.

    OS X replaced it nearly 10 years ago and it has zero viruses, yet has up to 10% market share (reported Infoworld Jan 09).

    Hmmm. The basic arithmetic doesn’t add up.

  17. “And Apple does NOT update anything prior to the previous and current versions of the OS, so myself running Tiger right now can NOT get any security updates”

    Wrong; I just bought a slot-load IMac circa 2001 for $35.
    Using it as a music player etc in my home.

    Installed Panther on it, which is older than Tiger. As soon as I plugged in the Ethernet cable, it automatically checked Software Update and installed 3 security updates, as well as 8 or 9 other security updates relating to Safari, Itunes, etc.

    Are you making stuff up?

  18. G4Dualie, that is the best thing i’ve ever heard any mac user say. Everyone should listen to this person cause it doesn’t matter what you’re running, even if its something like openBSD, the largest security flaw is the user.

  19. kenh said:

    “Installed Panther on it, which is older than Tiger. As soon as I plugged in the Ethernet cable, it automatically checked Software Update and installed 3 security updates, as well as 8 or 9 other security updates relating to Safari, Itunes, etc.

    Are you making stuff up?”

    No, when you plugged it in and ran Software Update, you got the various Panther updates taking you up to 10.3.9 and a few other system updates that were released after that, but I haven’t seen a system update for my eMac running Jaguar for ages, same as no Tiger system updates on my iBook. Updates for iTunes and Safari are not system updates, and Safari on Jaguar is older than the current Safari that I have (Version 4.0.4 (4531.21.10)) on my iBook G4. Not running Panther so I don’t know what parts have been updated for 10.3.9.

    I use Firefox 3.x on Jaguar 10.2.8 as it is a newer browser and does more than Safari on Jaguar. Leopard and Snow Leopard have newer versions of Java and other stuff that is simply not available for older versions of OSX for example.

    The same happens with Windows, but Microsoft has had to update and maintain older versions of their OS’s due to the number of customers who have maintenance contracts. At some point, Microsoft stops offering updates, but it varies with the OS version. Some updates simply work for an older OS version even if that OS version is no longer officially supported.

    I now have 10.5 Leopard disks (legit, not pirated) to update my iBook, but I’m busy with too much stuff at the moment and I’m not going to be able to do anything to go to 10.5 for a couple months. Then I’ll see whether I want to do that or simply get a newer Intel Mac, or maybe just an iPad and the iBook on 10.5. Time and money will tell.

  20. The problem is anymore all your comparing is Mac OS to Windows OS. The computer war of Mac vs PC platforms is over. Now its just about operating systems.

    Also if anyone thinks that their system is un-hackable i have a bridge to sell them. Honestly if the mac os was on 50% of the computers out there and the windows os was on the other 50% i would bet you money that you would see viruses and hacking being about equal on both systems.

  21. Completely ignoring the fact that Mac achieves this “security” by locking down the computer in a way that makes it impossible for a person to do anything useful with it. Doing anything “advanced” with a mac requires you to tweak the settings in a way that completely removes your so-called “security.” Let us also ignore the fact that for a gamer, you’re going to have to wait months to years for the newest games to be ported to macOS. And the fact that you’re paying hundreds of dollars more for the exact same hardware. And the fact that anyone who actually knows what they’re doing knows how to avoid these viruses.

    Long story short: Macs are for computers users that are too busy drooling on themselves to learn to use a computer.

  22. Isn’t it strange that most mac users also have a windows computer? The fact of the matter is that businesses have windows. If you ever plan to do any work at home for your coporation then you’d most likely want to do it on a windows machine. Or jump through some hoops to get your document or anything from a mac to a windows. What I really find ironic is that I will see a mac fan install a windows partition on his mac just so he can play some video games on it. This is the way it is… Companies make products for Windows, Mac makes products for Mac and that’s it. Could it be that Mac is more secure because the code isn’t as well known? Or maybe Mac doesn’t offer the same deals to corporations as Windows does. If you want to game, if you want to get along with the company you work for (computer wise). You’ll have to bite the bullet and get some form of windows. Until people as a mass can be more comfortable with change, it’s not going to happen. Windows got biggest fastest…. done.

  23. Well if the roles were reversed and Apple had a 99% world market share and Windows had a 1% market share, I’d make the argument that MAC’s would be less secure cause millions of people would be trying to hack them. As it is what will you get if you hack an Apple machine? Credit card numbers from broke hipsters who spent all their money on an apple iPhone, iBook, iPad, etc, etc. It would be a worthless proposition. On the other hand many businesses run PCs and with the same algorithms you could break into them all, so who would you try to hack. Indeed when Apple computers are targeted specifically, they can be hacked very easily, this has been show with wireless takeovers and dozens of other exploits. This isn’t to say the same exploits don’t work on PCs, its just to say who the hell cares about hacking an Apple?

  24. Bravo SteveJack!

    To this very day it is nearly impossible to get professional computer security ‘experts’ to face this simple fact:

    The ratio of Windows malware to Mac OS X malware is over 10,000 to 1.

    What is the market share ratio of Windows to Mac OS X? Nearly 5 to 1.

    And yet the ridiculous ‘security-via-obscurity’ propaganda persists.

    Then consider that there are only Trojan horses for Mac OS X. There is not one single virus, worm or illegal spyware app.

    Great hackers in the Mac community made it clear that there have been and continue to be security flaws in both Mac OS X and Apple’s cross platform software. And yet Mac OS X remains consistently in the top 3 most secure operating systems, behind only OpenBSD and FreeBSD. Not surprisingly, Mac OS X incorporates elements from both of these UNIX operating systems. Behind Mac OS X in security performance is Linux.

    And what’s dead last on the operating system security list? Need I tell you? Need I point out that even the latest version of that operating system has a worse reputation for security than Mac OS X? Of course not. The entire world knows the answer.

    And yet 94% of computer users still have the least secure operating system running their box. The market share winner is the security loser. How does anyone explain that expensive ambiguity?
    (o_0)

    I call it technology ignorance. Keep that in mind the next time someone proclaims the superiority of Windows. The mind boggles.

    Derek Currie
    http://Mac-Security.blogspot.com

  25. Yes, real men register! Real men call people out in a comment section! Real men cyberstalk each other! Real men get defensive over which OS they prefer!, and start calling each other “fanboys”! Real men get into 30 page debates!

    You hear that, you unregistered cowards!? You aren’t real men!

  26. Actually, if you get out of the education marketplace, where Apple sunk a ton of money back in the 80’s when they were relevant, the ration of Windows to Mac is closer to 100 to 1.

    It makes more sense to attack Linux.

  27. Thank you generic, non-registered Nauctshea! 2006 PHP infections were well publicized at the time, including infections of Macs running PHP.

    But the fact that these infections were able to bot the serving machines as well totally fell beneath my radar. I’d very much like to know how this was done. Of course the PHP processes had to be running inside an administrator account. But how they get hacked into the permissions of the OS to zombie the machines would be fascinating to know. However it was done would indeed have required a security hole in the operating system itself.

    In any case, I’ve personally avoided PHP as well as SQL because of their fundamental lack of security features. If only I could find a secure alternative to the email protocols that didn’t require PGP/GPG. ” width=”19″ height=”19″ alt=”tongue laugh” style=”border:0;” />

  28. I should note one further issue: The lack of cooperation or sharing amidst the anti-malware community.

    In my years now of keeping track of Mac security issues, why haven’t I ever come across VirusTotal?

    http://www.virustotal.com/

    They’re noted in the second article discussing the 2006 botnet.

    Sadly, it is entirely typical for there to be no central or consistent way to keep track of malware via the Internet. Anti-malware companies compete with one another to find the latest malware in the wild then refuse to share them. This competition also results in a proliferation of different names for exactly the same malware. And typically none of those names conform to the published standard for malware naming. I could blether on about the chaos in the anti-malware community. You’d think that fighting a common enemy would bring the computer community together. But that is distinctly NOT the case, which I consider a dreadful shame.

    http://Mac-Security.blogspot.com

  29. More non-sense rubbish from completely uninformed and misaligned Mac users.

    Here’s some real news, kids:

    MacBook Air hacked via Safari in 2 Minutes Flat in late March 2010:
    http://www.engadget.com/2008/03/27/pwn-2-own-over-macbook-air-gets-seized-in-2-minutes-flat/

    iPhone Database copied remotely in 20 seconds flat – by visiting a webpage in Safari:
    http://www.engadget.com/2010/03/25/iphone-sms-database-hacked-in-20-seconds-news-at-11/

    http://blogs.paretologic.com/malwarediaries/index.php/2010/03/25/charlie-millers-one-man-show-at-cansecwest/

    “Mac OS X is like living in a farmhouse in the country with no locks, and Windows is living in a house with bars on the windows in the bad part of town,” Charles Miller, computer researcher formerly of NSA, said, suggesting that while both OSes have their security flaws, the Mac OS is safer because of the lack of people threatening to exploit it.

    And in my book that’s not safe at all.

  30. aion kina cheap aion gold wow cataclysm leveling aion power leveling cheap aion power leveling aion cd key buy aion time card gw2 gold cheap guild wars 2 gold gw2 power leveling gw2 account buy gw2 account ffxiv gil rise of the godslayer cd key cheap ff14 gil final fantasy 14 cd key buy ffxiv time card ffxiv account cataclysm power leveling ffxiv power leveling wow cd key rise of the godslayer key buy wow cd key wow time card buy wow gold
    wow power leveling world of warcraft power leveling cataclysm cd key world of warcraft cataclysm cd key star trek online power leveling buy cataclysm cd key cataclysm cd key warhammer gold aoc gold lotro gold sto energy credits rise of the godslayer power leveling final fantasy 14 gold gw2 cd key ff14 gil ffxiv cd key ffxiv account ffxiv power leveling warhammer gold ffxiv gil ffxiv power leveling ffxiv account ffxiv cd key world of warcraft cataclysm cd key buy wow cataclysm buy world of warcraft cataclysm buy world of warcraft cataclysm cd key buy cataclysm buy cataclysm key age of conan gold conan gold

  31. WRONG. Mac OS has little to no mitigative technology to stop remote attacks. This whole “secure by design” pig swallow is Apple’s advertising to you. And while you scoff at every word MS says, you eat up every word another vendor says, assuming status quo proves it.

    Have you not heard of Pwn2Own? It’s been going on since ’07. And every year, the Mac goes down first. The contestants, some of the very best hackers on the planet, say unanimously that even Firefox is easier to hack on OS X than on Windows, because Windows has ASLR and DEP while OS X does not. Do you, a blogger, know more about security than they do? If so, then I think you’ve missed your calling.

    No, it’s easy to execute code remotely on Mac OS. I’ve heard arguments from plenty of Apple apologists that 5% market share should equate to 5% of attacks, but it’s not that simple. No one is saying that there is NO money to be had in the exploitation of Macs; the problem is that there is LESS. And that was enough for black hats to focus 100% of their efforts on the platform with 93% of the market…until now.

    Since Pwn2Own, Chinese and Russian hackers are now aware that OS X is a sitting duck. They probably always knew that a password prompt wouldn’t be a big deal as long as they could simply launch the code, but hadn’t bothered to try until someone told them that it’s not difficult at all to do.

    And now, whaddya know? Criminals are paying money for OS X exploits. It’s only a matter of time before black hats master Mac OS’ code, and these exploits include drive-by exploits. You go ahead and duck behind your low wall until then, and we’ll see if you’re man enough to swallow your pride and take it back in front of us “drooling idiots” when it comes back to slap you in the face.

    Meanwhile, as you leave your security in the hands of criminals, and trust in them to leave you alone and focus on Windows, I’ll take matters into my own hands. Windows users have more options for security than Mac users do, and I’m not talking about antivirus.

  32. Oh dear @santuccie. In my spare time I follow Mac security:

    http://Mac-Security.blogspot.com

    Rather than smear you on the sidewalk, I’ll just state some facts:

    1) Windows has the single worst security reputation of any currently available operating system. This remains the fact despite the security improvement attempts in Vista and 7ista. Trolling won’t change that.

    2) The Pwn2Own contest is NOT a speed contest. The hacks that are used are researched and verified as long as months in advance. The only thing a hack time means is how fast the hacker can set up and execute the hack. The end. Trolling won’t change that.

    3) There is no such thing as a secure operating system.

    4) The only source of ‘Mac is impregnable’ bullshite I’ve ever run into is from trolls. It is an invention by people who are misery mongers, attempting to make Mac users all sad and weepy. Boohoo. (;_;) –>Idiotic

    5) Let me see if I can list the Mac anti-malware apps off the top of my head. (‘Antivirus’ is a legacy, retrograde term. I bet you didn’t know that).
    – Intego VirusBarrier (I own. My absolute fave).
    – MacScan (Marginal shareware).
    – Norton Anti-Virus (Symantec, poor reputation, but apparently recently improved).
    – ClamXav (Mac GUI for ClamAV, the freeware anti-malware system, mediocre support for Mac malware).
    – iAntiVirus (By PCTools. Quite reasonable but not perfect).
    – ProtectMac AntiVirus (An up and comer with a good reputation).
    – Avast Antivirus (Bleh).

    6) Then there are a number of 3rd party firewalls for Mac OS X. A very nice one is in Intego VirusBarrier version 10.6, integrated from their NetBarrier product.

    7) Then there are a couple reverse firewalls. (They stop ‘phoning home’ and zombied Macs from calling out to bot wranglers). I own both Little Snitch and the RF in VirusBarrier 10.6.

    8) Then there are the Mac OS X security options, including ‘Stealth Mode’ that makes your Mac appear to be inert on the net. Also FileVault that encrypts your home account. Also Disk Utility that lets you create encrypted and compressed disk images. (I use one every day for my critical data). Then there is the Mac OS X firewall, which is simplicity deluxe to use.

    9) Apple also build a hearty firewall into their Airport routers. Mine is always on.

    10) Then there are the anti-phishing systems built into both Safari and Firefox. I also toss in the McAfee protection extension for FireFox.

    11) Then there is the web sentry built into Intego VirusBarrier that warns me every time my browser is attempting to connect to a known malware infected and distributing website.

    12) And of course I have to point out the over 1000:1 ratio of Windows malware to Mac OS X malware, PER USER. This fact makes a laughing stock of the bozoid ‘Security by Obscurity’ myth.

    13) Mac OS X currently has a grand total of 25 malware, all of which are Trojan horses that require LUSERS to install them via social engineering. There are NO VIRUSES for Mac OS X. There are NO WORMS for Mac OS X. There is only ONE illegal SPYWARE app for Mac OS X, which is one of the noted Trojans.

    14) Mac OS X is world renowned for its quality, despite the lies, hate, abuse, FUD, mythology and other BS invented by little nasty dweebs. The only two operating systems with better reputations than Mac OS X are: (1) OpenBSD, and (2) FreeBSD. How fascinating that Mac OS X incorporates elements of BOTH these operating systems.

    Shall I go on? I DO! Visit my blog at the link I posted above.

    CONCLUSION: Lame try little troll. You FAILed. Please post again. I’ll look forward to it.

  33. Didn’t they say at the Pwn2Own contest that Mac’s are less secure, and that the myth is actually true? Plus with Windows 7, there are dialog boxes that ask ur permission before starting or making changes to the computer, sometimes even ask for a password. With windows 7, u can’t access other account’s files without a password as well. I don’t see how its Windows fault that just because more people use it, there are more viruses for windows. Plus if people were to create more viruses for windows, wouldn’t they create more hardware and software compatible with windows than with mac?

  34. Hype2FUD (aka Pwn2Own) is barely understood by the typical reader, and this is entirely thanks to TechTard Journalists who don’t comprehend it either.

    Here we have anonymous coward “y” doing a troll routine about Hype2FUD all over again and all I can do is yawn. But I will say: Who ever this “y” is, they have NOT used a Mac. They’re talking about Vista features ripped off from Macs and ascribing them to 7ista, which came after Vista. Too Tardy to care is he. To tired to care am I. ” width=”19″ height=”19″ alt=”tongue laugh” style=”border:0;” />

  35. Excellent news! I just got my custom term papers from Delaware! There is absolutely no doubt in my mind that editing of my custom research papers made the contrast. Last year, above aid of term paper service, the same application was discard by three universities. Then I buy essay from this crew, and get incredible results! Thank you so much!

  36. If you need to get an accession in a school, college or a university or challenge any help in any kind of mission, so don’t get worried. Get ideas about your creation by using essays service. I don’t conclude that there is anything crooked in using writing services.

  37. Sometimes some people know the right way to compose the essays for sale. But if you are not experienced paper writer, you will have to search for the reliable purchase essays service to purchase your essay assignment with the purpose not to get a bad mark.

  38. Ugh. Mac user here, but my school uses windows, and they’re ALL getting infected with a rootkit that bypasses Deep Freeze called TDSS (Which can infect macs too, only difference is the Mach ASKS you for your password whenever a system file is modified. Windows….nope). Any hints on how to either a) lock down their shit, or b) SWITCH?

  39. Macs are definitely the least secure OS out there. All it would take is one halfway-talented hacker out there to be dared to take down Macs and it would be over. The Pwn2Own contest PROVES that. That said, Windows has it’s own problems, no doubt. But at least they patch things and increase the quality of the security on the OS daily.

    http://www.TheWorldFrenzy.com

  40. I am a Certified Hacking Forensic Investigator and from my perspective the Apple OS is always easiest to gain access to. It does not matter if I’m trying to gain access to files over a network or capturing IP packets. Windows does have it’s exploits but they are hard to find and usually patched rather quickly. An Apple OS exploit is usually available for months or more and they stand out like a sore thumb. I rarely get a Linux box to examine but, when I do, it is fairly difficult to crack. Linux users are generally more intelligent and put a little more effort into securing their data. From my experience I would never trust any of my files to Apple’s OS.

  41. “Macs are definitely the least secure OS out there. All it would take is one halfway-talented hacker out there to be dared to take down Macs and it would be over.”

    Umm, what if I turned on the Firewall? Would that make a difference? Did you know that all Macs ship with the Firewall turned off, and all Windows has it on by default? Lets level the playing field before you go sprouting off.

  42. “I am a Certified Hacking Forensic Investigator and from my perspective the Apple OS is always easiest to gain access to.”

    Then you should quickly notify Twitter, FaceBook, and Google – all have banned Windows from their work place and are Mac only offices.

  43. Lawl? OS X < Windows. And Microsoft has increased security updates by some 77% since then.

    http://news.techworld.com/security/1798/mac-os-x-security-myth-exposed/

    Author didn’t cite a single source or hard face/bit of research in his entire article. And Derek Currie, I don’t even know where to begin. Not only is all of what you said entirely possible, but you conveniently ignored the PWN2OWN opinion by essentially saying “It doesn’t take 15 minutes to do, but it’s easier”.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Tags: