Live data from Hacker News

Mysterious Mac Malware Has Infected Victims for Years

motherboard.vice.com

81–90 of 140 posts

Re: Mysterious Mac Malware Has Infected Victims for Years

#81

>the widespread belief that they are virus-free, Macs aren't immune from invasive and dangerous malware. This is an area where it's really hard to extrapolate from my personal experience to the entire population, but is this really an accurate statement of many people's beliefs? I think what people actually think is that the chances are much lower of encountering malware in the wild on a Mac. In support of that, havi…

People think Macs are virus-free because Apple spent years telling them were. Example ad, with John Hodgman as the Windows guy with a virus. https://www.youtube.com/watch?v=M3Z386vXrt4

This notion existed far before that ad came out.

It's a combination of a few things: (1) why bother investing time and resources for a platform with around 10% of users and (2) OSX has had strong security mechanisms e.g Gatekeeper, XProtect, App Sandbox. Windows 10 is much better but unfortunately not everyone is on that OS yet.

Re: Mysterious Mac Malware Has Infected Victims for Years

#82
post #29

Earlier quoted context omitted.

It was presently, and it's easy much happening now either. All these "viruses", or 99% of them, are just trojans.

That doesn't really matter, as to the layperson virus often is a general catch-all term for malware.

Well, to the person that knows better it means you can have a clean Mac by following basic download hygiene -- which is not possible in platforms with widespread viruses targetting vulnerabilities they can exploit automatically and which you can't protect from (except if you don't connect to the internet at all).

Re: Mysterious Mac Malware Has Infected Victims for Years

#83

Earlier quoted context omitted.

I would say it is accurate. I doubt most users really think it through, and Apple went out of their way to enforce the idea that Macs don't get viruses in their advertising campaigns around 2010 to 2012. Most users just don't think about it much, and the only exposure they got was ads telling them the thing doesn't get viruses, which Apple finally stopped doing in 2012 after have a very uncomfortable year... https://…

From that article: >It may have been technically accurate that Macs don’t get gummed up with PC viruses, but the implication that Apple is virus-free is certainly misleading. But that "implication" is an assumed implication that I haven't seen play out in my non-tech friends. I always thought that stories like those were just drummed up by anti-virus vendors to make sure that people continue buying their wares.

> I always thought that stories like those were just drummed up by anti-virus vendors to make sure that people continue buying their wares.

Look at this article and every article about Mac viruses.

Always an anti-virus vendor.

Re: Mysterious Mac Malware Has Infected Victims for Years

#84
post #77

Earlier quoted context omitted.

Well, what is true is that it's extremely hard to execute arbitrary code without user knowledge on a Mac. Windows has thousands upon thousands of arbitrary code execution bugs where simply opening something like a pdf can allow an attacker to run arbitrary code as a privileged user. There are many defense mechanisms to this that are inherent to the design and implementation of Darwin/Mac OS.

> There are many defense mechanisms to this that are inherent to the design and implementation of Darwin/Mac OS. Do you have an example? Beyond the idea of user/root separation, which doesn't really do much for modern single user computers: https://xkcd.com/1200/

Kinda unfair to not let me use the biggest example (DAC/user separation) just because there might be sensitive data with user permissions when we're talking about arbitrary code execution. Even still, such a concept makes privilege execution orders of magnitude harder on * nix systems.

POSIX philosophy also prevents the "keys to the kingdom" kind of exploits you can get in windows, many linux exploits are much harder to chain together simply due to this.

The * nix networking stack has always been much more mature and robust than the windows stack, although I'll admit that's not necessarily inherent to the design.

Re: Mysterious Mac Malware Has Infected Victims for Years

#85
post #40
post #28

Earlier quoted context omitted.

> I think what people actually think is that the chances are much lower of encountering malware in the wild on a Mac. Yes -- and what people believe is also true. It's indeed much lower, to the point of being a non-issue almost. (And it's not due to "lower market share" either. Mac OS 7/8 etc had even lower market share than today's Macs have, and it had tons of viruses).

> Mac OS 7/8 etc had even lower market share than today's Macs have, and it had tons of viruses That's not a valid comparison. When Mac OS 7/8 was mainstream, it was common to get software via a floppy disk that had already been in 10 other machines or from a fly-by-night BBS. Nowadays software distribution is far less peer-to-peer, and it's much more difficult for simple viruses to move from machine to machine. > ma…

>That's not a valid comparison. When Mac OS 7/8 was mainstream, it was common to get software via a floppy disk that had already been in 10 other machines or from a fly-by-night BBS. Nowadays software distribution is far less peer-to-peer, and it's much more difficult for simple viruses to move from machine to machine.

That doesn't make sense. The software that back in the day would be in a disk that had "already been in 10 other machines", can now come from a website that serves millions of machines with the same malware infected programs.

Re: Mysterious Mac Malware Has Infected Victims for Years

#86
post #50
post #33

Earlier quoted context omitted.

I would guess many 20-somethings have recommended a mac to their parents with this as one of the bullet points. At a time, it was more or less true - when dropping a virus on your windows PC was as easy as loading a malicious activex website, macs just didn't even have it. Not to say macs weren't vulnerable, but the attack surface was lower and the cost/benefit to people trying to bot-net your mom's Mac was higher th…

I'm a 50-something and my Mom with her Mac manages to get infected with browser-based malware. And she's pretty careful. But sometimes those "update" notifications look real to her.

I take it she isn't on a recent OSX version ?

Because those apps shouldn't be able to be opened unless the author has code signed them.

In which case if they are malware then just report it to Apple and they can centrally block the app.

Re: Mysterious Mac Malware Has Infected Victims for Years

#87
post #52

Earlier quoted context omitted.

Right. The Mac Zealots will say "These aren't viruses! They're unwanted programs purposefully installed by the user who thought he was updating Acrobat." But it's like a 2nd amendment advocate trying to win an argument by pointing out that word "Assault Rifle" is meaningless. It may be true, but it's not a way to argue.

I'm pretty sure "assault rifle" [0] is a reasonably well-defined term and you mean "assault weapon" [1] in your post. Pointing out that "assault weapon" is meaningless is trying to combat emotive, irrational legislation based on conflating "assault weapon" with "assault rifle" because most people don't understand the difference (and one of the terms was chosen to be intentionally confusing). [0] https://en.wikipedia.…

You completely misunderstand my point. I'm a card-carrying NRA member, but I wince when I hear someone notice that a anti-2nd-amendment zealot mixes up terms like "magazine" and "cartridge" and thinks "Aha! I've won this argument because you don't know what these basic terms mean." It really doesn't help convince people on the other side to consider another point of view.

In fact, your zealous answer proves my point.

Now back to viruses and PUPs.

Re: Mysterious Mac Malware Has Infected Victims for Years

#88
post #73

Earlier quoted context omitted.

So, in other words, iOS is insecure and vulnerable to malware. Governments don't have special hacking powers, they mainly have money and manpower. It's true, iOS might raise the bar a little bit compared to some other systems, but IMHO it's misleading and dangerous to claim that it's invulnerable.

The point is you're not going to get malware if you open the wrong email or go to the wrong site like you could on Windows. The organizations with enough resources to hack iOS devices aren't interested in sending mass emails to steal bank account details. The average iOS user who keeps their device up to date simply doesn't have to worry about malware and suggesting otherwise is misleading.

> The organizations with enough resources to hack iOS devices aren't interested in sending mass emails to steal bank account details. The average iOS user who keeps their device up to date simply doesn't have to worry about malware and suggesting otherwise is misleading.

Again, no. Here's another counterexample (which is recent and appears to have been active on the App Store for ~1yr):

https://researchcenter.paloaltonetworks.com/2016/03/acedecei...

"These malicious iOS apps provide a connection to a third party app store controlled by the author for user to download iOS apps or games. It encourages users to input their Apple IDs and passwords for more features, and provided these credentials will be uploaded to AceDeceiver’s C2 server after being encrypted."

That's not state actor stuff.

However, I shouldn't have to keep providing counterexamples to convince you of your absurd claims of practical invulnerability. Apple has not made any kind of security quantum leap: no one has. Apple's systems are vulnerable to the same types of flaws, by the same types of attackers, as any other system in wide use. The main difference is that Apple has restricted their platform to the extent they have an easier time implementing security best practices. iOS is still vulnerable to flaws Apple doesn't know about or hasn't patched, and those flaws can be exploited for as long as Apple remains unaware or fails to act. That's not fundamentally different position from Microsoft, Google, or any other similar company.

Re: Mysterious Mac Malware Has Infected Victims for Years

#89
post #87

Earlier quoted context omitted.

I'm pretty sure "assault rifle" [0] is a reasonably well-defined term and you mean "assault weapon" [1] in your post. Pointing out that "assault weapon" is meaningless is trying to combat emotive, irrational legislation based on conflating "assault weapon" with "assault rifle" because most people don't understand the difference (and one of the terms was chosen to be intentionally confusing). [0] https://en.wikipedia.…

You completely misunderstand my point. I'm a card-carrying NRA member, but I wince when I hear someone notice that a anti-2nd-amendment zealot mixes up terms like "magazine" and "cartridge" and thinks "Aha! I've won this argument because you don't know what these basic terms mean." It really doesn't help convince people on the other side to consider another point of view. In fact, your zealous answer proves my point.…

I think you misunderstood mine: it's unlike the case of "virus" in the sense that it acquired a general meaning and then was retrofitted with a technical one to co-opt feelings for political goals.

It would be like if people had used "virus" as a generic without it ever having a technical definition (by analogy to infections), then Congress proposed to ban encryption to stop "viruses", because hey, lots of viruses use encryption.

Pointing out that co-opting from the informal "infectious software" to "software that uses encryption" is a meaningful point.

I think you're correct that the usage of virus for unwanted software is fine; I think you're wrong about the evolution of language there matching what happened with "assault weapon". Specifically, one change is going from the technical to the generic, while the other is going from the generic to technical.

Re: Mysterious Mac Malware Has Infected Victims for Years

#90
post #45

Earlier quoted context omitted.

You can't get viruses on iOS unless you're jailbroken - Apple's walled garden pretty much guarantees that. Even jailbreaking is insanely difficult with the newest versions of iOS. There is no public jailbreak of the current version of iOS, or the version before that.

> You can't get viruses on iOS unless you're jailbroken - Apple's walled garden pretty much guarantees that. No. Apple can't guarantee their software is secure, so their walled garden doesn't guarantee anything like what you say.

'Pretty much' guarantees.

I switched to Macs back in 2007. I work in IT, have always been careful to install anti virus software on Windows machines and showed my family how to avoid click bait and dangerous downloads. Even so I frequently used to have to clean malware off my old Windows machines. We do have one windows laptop on Windows 7 which is lightly used and most recently it got infected with a Firefox toolbar extension thing a few years ago that took a week to get rid of completely.

I have never once since 2007 had to deal with a single piece of malware on any of our Macs. I know it exists, Handbrake downloads got infected a while back, but the difference is night and day. In my experience Mac OS is dramatically safer than even a fully up to date Windows machine with top tier virus protection software installed.

Maybe that's changed with recent versions of Windows. Cool. Actually the only thing that drives me potty about Macs is the keychain getting corrupted, drives me potty.

Post reply on HN