Live data from Hacker News

Apple the new world leader in software insecurity

arstechnica.com

21–28 of 28 posts

Re: Apple the new world leader in software insecurity

#21

Many of Apple's flaws are not in its operating system, Mac OS X, but rather in software like Safari, QuickTime, and iTunes.

"...a growing trend in the world of security flaws: the role of third-party software. Many of Apple's flaws are not in its operating system, Mac OS X, but rather in software like Safari, QuickTime, and iTunes." How are any of those third-party? They are all sold by Apple. Just because they also happen to run in Windows doesn't make them third-party.

Nitpicking out of context? Sensationalist headline? I assume you and everyone who voted you up didn't actually read the study.

What Secunia did study was described as "In the first part of the report we look at the global picture covering all vulnerabilities in all products, followed by the analysis of vulnerabilities affecting the products and the operating system found on typical end-users PCs." And all their graphs are limited to XP, Vista and 7. So...probably limited to Windows. And they also define 3rd-party software for you as non-Microsoft vendors in the sidebar of page 9.

So yeah, everything by Apple is 3rd party software in the context of the study cited.

Re: Apple the new world leader in software insecurity

#22
post #15
post #2

It is fortunate that Apple still has a small enough market share that they aren't being attacked as vigorously as Windows is. For now I still feel like my Mac is safer from viruses than the average Windows machine, but that security is definitely shaky if Apple gets a larger market share and starts attracting real attention from viruses and hackers.

The Mac share of viruses is zero. If youre right & market share is the only consideration, logically that means nobody should be writing any software (eg games) for Mac either.

I would agree with this. Windows is a larger market to attack, but if it's lucrative to sell software to a smaller fraction of the market, it's surely lucrative to infect their computers and harvest personal info.

The Apple computer marketshare is small worldwide, but inside the US, one of the richer countries in the world, Apple has a much larger representation (+20% of laptop sales, +10% desktops), and almost all >$1000 computer sales. A bank account or credit card harvested from a random Mac is probably worth a whole lot more than a random Windows computer when selecting from a global set of computers. Essentially, wealth among computer users is not evenly distributed worldwide, and Apple products are disproportionately represented in wealthier nations.

Re: Apple the new world leader in software insecurity

#23

So it sounds like the real problem is that we need to create some sort of unified updating system for third party apps, so you don't have to deal with ten different programs complaining they need to be updated. Something so simple, it only needs a single command to run. Like apt-get upgrade. Maybe they should have that for windows/mac.

On Mac every OS-bundled program do update through a central utility found on the Apple dropdown menu. 90% of other programs use the Sparkle framework (~100% if the program is Mac-only) which provide an unobtrusive way of updating.

Re: Apple the new world leader in software insecurity

#24
post #18

Earlier quoted context omitted.

I also noticed Ars becoming much more anti-Apple as well as sensationalist. Articles like Siracusa coverage on the antenna press conference as well as his twitter feed seemed oddly vindictive to me. http://arstechnica.com/staff/fatbits/2010/07/unanswered-ques... I found it unsettling considering Ars has been a top source of tech news for me in the past that I thought was very even and thorough.

Have you considered that an even and thorough approach to tech news may go through periods where it levels more criticism than usual at Apple?

Of course, one great reason to be more critical is if they deserve it. I don't think that it's merited in these cases (original article or my link). I'm trying to figure out if this is a temporary/isolated thing, a systemic change, or a figment of my imagination/biases.

Re: Apple the new world leader in software insecurity

#25

So it sounds like the real problem is that we need to create some sort of unified updating system for third party apps, so you don't have to deal with ten different programs complaining they need to be updated. Something so simple, it only needs a single command to run. Like apt-get upgrade. Maybe they should have that for windows/mac.

And then they could also have a place to make it easy to find applications, too. On top of that, they could expose it through software that (almost) everybody using OS X uses for their other media consumption.

They'll call it the "Program Market"

Re: Apple the new world leader in software insecurity

#26
post #9
post #2

It is fortunate that Apple still has a small enough market share that they aren't being attacked as vigorously as Windows is. For now I still feel like my Mac is safer from viruses than the average Windows machine, but that security is definitely shaky if Apple gets a larger market share and starts attracting real attention from viruses and hackers.

I hear this enough to wonder if it's a myth. Mac OS is built on Unix, so how does the total Unix+Linux+Mac market share look? Probably big enough to justify attacking. I suspect but can't prove that Unix is inherently more secure than Windows (or more easily secured). I've actually had a Mac compromised before after being lazy about the password setup. I suspect it difficult for the botnets to get traction, but they'…

I have a tendency to agree with you. For viruses, the numbers don't add up. I couldn't find numbers for how many viruses/worms were written last year. In 2004 there were around 28000 written, so let's assume viruses are on the decline and say 8000 were written last year. With a 5% share, Apple should have anything up to 400 viruses. I am aware of none.

I think the reason for this is two fold, firstly, to write a viruses on the Mac, which by their nature need to spread, is harder due to the (*nix) security models used. But also, it seems to me viruses are getting passé and targeted emails with trojans are becoming more popular.

Trojans are one thing that Macs have been shown to be susceptible to although often by fooling (social engineering) the person into clicking all the right buttons and typing in their password.

I would therefore suggest that any future major problems on OS X will be due to a trojan that gets sent out and manages to auto install through an exploit rather than a virus which does the spreading on its own.

The challenge for Apple is being good enough, fast enough to make sure trojan attacks are relegated to social engineering and tainted pirate downloads.

Re: Apple the new world leader in software insecurity

#27
post #15

Earlier quoted context omitted.

The Mac share of viruses is zero. If youre right & market share is the only consideration, logically that means nobody should be writing any software (eg games) for Mac either.

I would agree with this. Windows is a larger market to attack, but if it's lucrative to sell software to a smaller fraction of the market, it's surely lucrative to infect their computers and harvest personal info. The Apple computer marketshare is small worldwide, but inside the US, one of the richer countries in the world, Apple has a much larger representation (+20% of laptop sales, +10% desktops), and almost all >…

Although that's true, consider the larger context.

One, Apple's market share has only been non-trivial in recent years, meaning since the x86 switch + the iPhone launch.

Two, most viruses and hacks use the Trojan Horse method, basically attempting to trick the user into giving you something that they wouldn't normally give you.

Three, even though Apple and its cult like to claim that OSX is secure, OSX automatically downloads patches, and Apple releases security patches nearly as frequently as Microsoft (but ironically isn't as diligent about closing security holes as Microsoft).

To make these work, the people attempting to harvest data or simply cause harm have to play the odds. So the 100 to 1 ratio between Windows and Mac machines out there has historically been reason enough to ignore the mac as a target for hackers and viruses -- so it's very likely that as Apple's market share grows, and as people start using iPhones and iPads for more and more of their computing tasks, they'll increasingly become targets for hackers also.

Re: Apple the new world leader in software insecurity

#28
post #18

Earlier quoted context omitted.

Have you considered that an even and thorough approach to tech news may go through periods where it levels more criticism than usual at Apple?

Of course, one great reason to be more critical is if they deserve it. I don't think that it's merited in these cases (original article or my link). I'm trying to figure out if this is a temporary/isolated thing, a systemic change, or a figment of my imagination/biases.

Ok, it's not just my imagination, this is link-bait if I ever saw it: http://arstechnica.com/apple/news/2010/07/international-laun...

Title is: iPhone 4 antenna woes "significantly worse" than competition

1st paragraph explains: one consulting firm says it's worse, another review says it's better.

I'm pretty sure I didn't see this type of thing from Ars in the past.

Post reply on HN