Live data from Hacker News

OS X sudoers exploit found in the wild

blog.malwarebytes.org

11–20 of 193 posts

Re: OS X sudoers exploit found in the wild

#11
post #6

Isn't this the time when Mac App Store supposed to shine? When they found something that's dodgy and linked to a company that has apps on App Store, can't they just turn on the kill switch? That way the malware won't have anywhere to direct the users to.

It's not clear whether this "adware installer" is signed by a developer cert. I'm gonna guess it isn't, which means under the default settings, if a user double-clicks it to execute it, they'll be presented with a message saying that the app can't be run because it's "from an unknown developer" and the current settings disallow it. The user can get around that by right-clicking it and choosing "Open" (or switching Gatekeeper to be more relaxed), but the error message doesn't allude to this.

Edit: And if it is signed: yes, I believe Apple could and presumably would push out a malware update that would invalidate the cert.

Re: OS X sudoers exploit found in the wild

#12
The top most thing is keeping the OS up to date. And I don't visit shady web sites.

Flash stand alone is removed, and disabled in Chrome. Lastpass for passwords. Tunnelblick+privatetunnel for open networks. And even though I use some software that isn't signed, after I've installed such software I revert the Security & Privacy "allow apps" setting back to app store+identified devs. And relevant, just by coincidence, in this case, I'm using 10.9.5 (which is still currently maintained with security updates).

The reality is that Mac users are simply used to trusting Apple to handle these sorts of things. And it's not a good alternative for that trust to be lost and placed in a 3rd party, e.g. on Windows where trust loss means a litany of 3rd parties to choose from in that space with no real practical way to differentiate, and the Windows Store described as a "cesspool of scams." Apple will get this fixed soon. It's definitely sub-optimal response wise, but I still trust this ecosystem compared to Windows at this point.

Edit: Oh and Privacy Badger.

Re: OS X sudoers exploit found in the wild

#14
post #12

The top most thing is keeping the OS up to date. And I don't visit shady web sites. Flash stand alone is removed, and disabled in Chrome. Lastpass for passwords. Tunnelblick+privatetunnel for open networks. And even though I use some software that isn't signed, after I've installed such software I revert the Security & Privacy "allow apps" setting back to app store+identified devs. And relevant, just by coincidence,…

Keeping the OS up to date wouldn't have helped with this.

Re: OS X sudoers exploit found in the wild

#15
post #7
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Little Snitch ( https://www.obdev.at/products/littlesnitch/index.html ) is excellent.

Although be aware that it can be quite daunting for a novice user. If you're installing for a friend or family member, you should go through all of this apps to whitelist requests and maybe teach them how to identify bad requests, but it's non-trivial. The UI doesn't interact very well with CDNs, for example, sometimes telling you that "App Store" is trying to access "arstechnica.com" because they use the same CDN provider.

Re: OS X sudoers exploit found in the wild

#16
post #12

The top most thing is keeping the OS up to date. And I don't visit shady web sites. Flash stand alone is removed, and disabled in Chrome. Lastpass for passwords. Tunnelblick+privatetunnel for open networks. And even though I use some software that isn't signed, after I've installed such software I revert the Security & Privacy "allow apps" setting back to app store+identified devs. And relevant, just by coincidence,…

Keeping the OS up to date wouldn't have helped with this.

I know that. Overwhelmingly in most cases it does help though, probably more than anything else short of air gapping the thing.

Re: OS X sudoers exploit found in the wild

#17
post #3

I keep asking this question and Mac people keep looking at me like I'm an alien, so I guess I'll turn to the HN community for this questions. What do you recommend as security software for OSX currently? How do you help secure your devices from public wifi and the internet in general? Especially for novice users?

Security software is a band-aid on vulnerable software and users installing things they shouldn't.

Part of the OSX security strategy is to minimize users installing things they shouldn't by making it difficult (enforced code signing, confirmations when opening an unsigned or new application). The other side is minimizing attack surface for exploits by staying up-to-date, not shipping crap like Java unless the user explicitly needs it, and (increasingly) sandboxing applications to user-approved subsets of the filesystem.

Bolt-on detection and resolution of malware infections is just not a part of the OSX security ecosystem like it is with Windows.

Little Snitch can help give you a picture of what's going on with regard to your network card, but at the end of the day malware can usually hide its traffic in an otherwise-trusted application to avoid that sort of detection.

Re: OS X sudoers exploit found in the wild

#19
post #12

The top most thing is keeping the OS up to date. And I don't visit shady web sites. Flash stand alone is removed, and disabled in Chrome. Lastpass for passwords. Tunnelblick+privatetunnel for open networks. And even though I use some software that isn't signed, after I've installed such software I revert the Security & Privacy "allow apps" setting back to app store+identified devs. And relevant, just by coincidence,…

Keeping the OS up to date wouldn't have helped with this.

10.9.5 is not even up to date. There are security fixes which were not backported from OS X 10.10 Yosemite (the current release).

Re: OS X sudoers exploit found in the wild

#20
Oh man, I really want to do it on all the macs at the Apple store, and start a little botnet.

Problem is, I don't really have any use for 10 or so rooted macs. I mean, I could rm them, but I'd never do that, that's mean. And I wouldn't feel good about using the camera, even though the computers are in public, it's icky. Perhaps a DoS? There's nobody that I dislike enough for that.

I think I'd be so rich if I wasn't so moral.

Post reply on HN