Live data from Hacker News

Mysterious Mac Malware Has Infected Victims for Years

motherboard.vice.com

71–80 of 140 posts

Re: Mysterious Mac Malware Has Infected Victims for Years

#71
post #61

Earlier quoted context omitted.

That's just marketing hype mixed with a little bit of goalpost moving. "Has never been more secure than it is now" != secure. > A while back Apple started pulling anti-virus apps from the app store presumably because they aren't needed. I think you presume too much. An effective antivirus program cannot run in a sandbox that isolates it from other processes. If Apple pulled 3rd party antivirus apps, I bet it was beca…

Pegasus was used by governments to target specific individuals. If you're being targeted by governments I would agree you're out of luck even on iOS.

So, in other words, iOS is insecure and vulnerable to malware.

Governments don't have special hacking powers, they mainly have money and manpower.

It's true, iOS might raise the bar a little bit compared to some other systems, but IMHO it's misleading and dangerous to claim that it's invulnerable.

Re: Mysterious Mac Malware Has Infected Victims for Years

#72
post #68

Earlier quoted context omitted.

Citation? AFAIK the iOS sandbox has not been broken on un-jailbroken iOS devices, so at worst you're getting a garbage app that doesn't do what it promises. I've never seen nor heard of any actual malware outbreak from a non-jailbroken app.

I know next to nothing about iOS, so: Why can't the (usually public) jailbrake-exploit or another, similar potent (and probably quite expensive) be launched from inside the app? Sure, it has to be hidden to get into the store, but that looks very easy compared to finding the actually jail break. One just has to hide a arbitrary code execution vuln in the code of the app somewhere. So, every apps seems to be an attack…

If there was a jailbreak available, yes. But there hasn't been a publicly available untethered jailbreak since March of 2016, and there has never been an untethered jailbreak of iOS 10.

The only jailbreak for iOS 10 was semi-teathered and only made public after Apple had patched the vulnerabilities. In order for this to work as malware the user would have to open the malicious app every time their phone restarts. Not only that, every time the they open the app their phone would appear to be out of storage and then promptly crash to the boot screen. It would be a bit of a hard sell.

Re: Mysterious Mac Malware Has Infected Victims for Years

#73
post #61

Earlier quoted context omitted.

Pegasus was used by governments to target specific individuals. If you're being targeted by governments I would agree you're out of luck even on iOS.

So, in other words, iOS is insecure and vulnerable to malware. Governments don't have special hacking powers, they mainly have money and manpower. It's true, iOS might raise the bar a little bit compared to some other systems, but IMHO it's misleading and dangerous to claim that it's invulnerable.

The point is you're not going to get malware if you open the wrong email or go to the wrong site like you could on Windows. The organizations with enough resources to hack iOS devices aren't interested in sending mass emails to steal bank account details. The average iOS user who keeps their device up to date simply doesn't have to worry about malware and suggesting otherwise is misleading.

Re: Mysterious Mac Malware Has Infected Victims for Years

#74
post #45

Earlier quoted context omitted.

You can't get viruses on iOS unless you're jailbroken - Apple's walled garden pretty much guarantees that. Even jailbreaking is insanely difficult with the newest versions of iOS. There is no public jailbreak of the current version of iOS, or the version before that.

> You can't get viruses on iOS unless you're jailbroken - Apple's walled garden pretty much guarantees that. No. Apple can't guarantee their software is secure, so their walled garden doesn't guarantee anything like what you say.

While there is of course no guarantee, most of the shitstained-OS-installations that were (or still are?) so common, with symptoms like non-functional systems, ads popping up, or having 90 toolbars are due to user actions. Sure, there are methods to deliver and elevate malware, but most of the 'problems' people experienced (before widespread banking malware) were practically "cosmetic" and "slowness" and almost always due to users randomly downloading and executing anything in their path.

With iOS, that pattern is a lot harder to abuse, and with enforced sandboxing, side-effects between programs (or, 'apps') are somewhat non-existent.

Most of the things that make non-Windows systems less infected seem to either be due to a better security design, less casual users or a drastically lower market share making it a smaller target with possible less effective organic spreading of malware. (or possibly a combination of the three)

Re: Mysterious Mac Malware Has Infected Victims for Years

#75

>the widespread belief that they are virus-free, Macs aren't immune from invasive and dangerous malware. This is an area where it's really hard to extrapolate from my personal experience to the entire population, but is this really an accurate statement of many people's beliefs? I think what people actually think is that the chances are much lower of encountering malware in the wild on a Mac. In support of that, havi…

Well, what is true is that it's extremely hard to execute arbitrary code without user knowledge on a Mac. Windows has thousands upon thousands of arbitrary code execution bugs where simply opening something like a pdf can allow an attacker to run arbitrary code as a privileged user. There are many defense mechanisms to this that are inherent to the design and implementation of Darwin/Mac OS.

Re: Mysterious Mac Malware Has Infected Victims for Years

#76
post #41
post #35

Earlier quoted context omitted.

Apple literally had that in their ads.

They still do. https://www.youtube.com/watch?v=dRM31VRNQw0

That's iOS vs. Windows and we were taking about macOS.

I think that marketing language is a bit BS-y, though.

Probably the general idea they are pushing, that iOS is less susceptible to malware than a laptop, is probably true, so it doesn't bother me much.

Re: Mysterious Mac Malware Has Infected Victims for Years

#77

>the widespread belief that they are virus-free, Macs aren't immune from invasive and dangerous malware. This is an area where it's really hard to extrapolate from my personal experience to the entire population, but is this really an accurate statement of many people's beliefs? I think what people actually think is that the chances are much lower of encountering malware in the wild on a Mac. In support of that, havi…

Well, what is true is that it's extremely hard to execute arbitrary code without user knowledge on a Mac. Windows has thousands upon thousands of arbitrary code execution bugs where simply opening something like a pdf can allow an attacker to run arbitrary code as a privileged user. There are many defense mechanisms to this that are inherent to the design and implementation of Darwin/Mac OS.

> There are many defense mechanisms to this that are inherent to the design and implementation of Darwin/Mac OS.

Do you have an example? Beyond the idea of user/root separation, which doesn't really do much for modern single user computers: https://xkcd.com/1200/

Re: Mysterious Mac Malware Has Infected Victims for Years

#78
So, let me get this straight. If I develope malware in an "archaic" language, using "crude code" then I am not a nation-state. "Undetected for years"

Interesting logic. I wonder if the reverse can be said...

If I were a nation state, perhaps I would be taking notes.

Re: Mysterious Mac Malware Has Infected Victims for Years

#79
post #34

> ...despite the widespread belief that they are virus-free, Macs aren't immune from invasive and dangerous malware. I keep hearing this, but I never see evidence of these people. Is there a widespread belief that there's a widespread belief that Macs are immune from malware, despite few people who actually think this? Well, I'm sure such people exist, but there don't seem to be many, even on sites like macrumors and…

I worked at a Geek Squad for two years, so definitely take my experience with a grain of salt, but at least in the world of big box retail chains, this was quoted so often by my customers and clients I lost count. Most of my clients that came in with an infection on their Mac (sometimes just a rogue browser extension, but often an honest bit of malware) were genuinely surprised, having purchased the Mac originally because it supposedly didn't have these "Windows" problems.

I suspect this is largely due in part to the types of clients that would actually purchase Geek Squad protection in the first place; my job duties had me working directly with "not computer people" folks most of the time. Still, the idea that Macs were immune to malware was pervasive; on several occasions, folks returned Windows machines they had just purchased (and managed to immediately infect) and picked up a Mac instead, thinking that this act alone would make them immune to their problems, or their kids online behavior, etc. Most folks were good sports about it though, realizing that they had been misled by advertising, and allowing me to explain good security habits to them during their visit.

I think the biggest thing that bothered me about the job, and the reason I eventually left for greener pastures (I presently work in Linux Administration) was the pervasive idea that you could fix computer problems by buying additional software. This is something retailers have latched on to, and it bugs me on a fundamental level. The only way to actually be more secure is to understand your tools, so that you can recognize when they are misbehaving.

Re: Mysterious Mac Malware Has Infected Victims for Years

#80
post #45

Earlier quoted context omitted.

You can't get viruses on iOS unless you're jailbroken - Apple's walled garden pretty much guarantees that. Even jailbreaking is insanely difficult with the newest versions of iOS. There is no public jailbreak of the current version of iOS, or the version before that.

> You can't get viruses on iOS unless you're jailbroken - Apple's walled garden pretty much guarantees that. No. Apple can't guarantee their software is secure, so their walled garden doesn't guarantee anything like what you say.

You missed the hedge phrase—"pretty much". Obviously there isn't such a thing as a guarantee for security, but there are counterexamples for most OSs. Do you have one for the current iOS version? I haven't seen someone jailbreak their phone since iOS 5, I think, though people did do it since then.

What's the point of your critique when you can apply it to literally any piece of software? Even SEL4 relies on a correct processor, and yours has flaws.

Post reply on HN