Live data from Hacker News

Mac malware evolves to no longer require users to enter their password

nakedsecurity.sophos.com

1–10 of 49 posts

Re: Mac malware evolves to no longer require users to enter their password

#2
from http://www.macworld.com/article/160098/2011/05/macdefender.h...

"Windows 7 is actually more secure than OS X, but the gap narrows every year. And there simply isn’t the same attack ecosystem for Macs, nor are we likely to see one develop.

So while Mac users will likely see more malware, it’s highly improbable we (or Windows 7 users) will ever experience what those who are still running Windows XP battle today.

But two other factors are changing the Mac security landscape. First, Apple products are growing rapidly in popularity. At the same time, the overall Internet security environment is more hostile than a cantina on Tatooine."

Re: Mac malware evolves to no longer require users to enter their password

#3
There are only two long term solutions: - an anti-vir scanner which constantly monitors all your files, hogs resources and plays the game of cat & mouse - Prevent users from installing software that wasn’t from the Mac App Store, just like on iOS.

The last is a nuclear option and not practicable for a professional desktop system. But I would like this as a configurable option for my parents. (Withholding the admin password from them is another possibility, but, well, see the article)

Re: Mac malware evolves to no longer require users to enter their password

#5
post #2

from http://www.macworld.com/article/160098/2011/05/macdefender.h... "Windows 7 is actually more secure than OS X, but the gap narrows every year. And there simply isn’t the same attack ecosystem for Macs, nor are we likely to see one develop. So while Mac users will likely see more malware, it’s highly improbable we (or Windows 7 users) will ever experience what those who are still running Windows XP battle today. B…

How is windows 7 more secure? I can install a malicious app if I want to on any system.

The only "problem" here is that safari automatically opens safe files. They should also get a smartscreen filter like IE9 has. Safari has something like this already (google safefilter) but it doesn't seem to be as effective.

Mac OS X as a whole has xprotect, but that is a very simplistic defense to look for some known malware signatures.

Re: Mac malware evolves to no longer require users to enter their password

#6

As I understand it, this relies on the admin account's ability to write to the /Applications folder without a password. So, if you just run in a non-admin account, you should be fine.

Won't the non-admin account just ask for the admin password? Since people are used to doing this when installing apps, it comes second nature..

If people are willing to click through several steps of an installer app, they'll also type in the admin password if requested.

This is only useful for other family members that you do not trust for safety reasons.

Re: Mac malware evolves to no longer require users to enter their password

#7
post #3

There are only two long term solutions: - an anti-vir scanner which constantly monitors all your files, hogs resources and plays the game of cat & mouse - Prevent users from installing software that wasn’t from the Mac App Store, just like on iOS. The last is a nuclear option and not practicable for a professional desktop system. But I would like this as a configurable option for my parents. (Withholding the admin pa…

Don't the parental controls in mac os x allow this? Haven't tried, but you can limit the apps that the user can run to your own selection. Or even limit to just app store apps.

Re: Mac malware evolves to no longer require users to enter their password

#8
post #6

As I understand it, this relies on the admin account's ability to write to the /Applications folder without a password. So, if you just run in a non-admin account, you should be fine.

Won't the non-admin account just ask for the admin password? Since people are used to doing this when installing apps, it comes second nature.. If people are willing to click through several steps of an installer app, they'll also type in the admin password if requested. This is only useful for other family members that you do not trust for safety reasons.

Right, but the point of this article is that it no longer needs the admin password. If you're running in a non-admin account (like I am), it'll still need the password, and thus user interaction, so it'll be trivial to stop.

Re: Mac malware evolves to no longer require users to enter their password

#9
post #5
post #2

from http://www.macworld.com/article/160098/2011/05/macdefender.h... "Windows 7 is actually more secure than OS X, but the gap narrows every year. And there simply isn’t the same attack ecosystem for Macs, nor are we likely to see one develop. So while Mac users will likely see more malware, it’s highly improbable we (or Windows 7 users) will ever experience what those who are still running Windows XP battle today. B…

How is windows 7 more secure? I can install a malicious app if I want to on any system. The only "problem" here is that safari automatically opens safe files. They should also get a smartscreen filter like IE9 has. Safari has something like this already (google safefilter) but it doesn't seem to be as effective. Mac OS X as a whole has xprotect, but that is a very simplistic defense to look for some known malware sig…

Security experts generally agree that there are more exploits on Mac. It's easier to run arbitrary code without permission.

The only thing is, nobody has bothered to write that code yet.

Re: Mac malware evolves to no longer require users to enter their password

#10
post #6

Earlier quoted context omitted.

Won't the non-admin account just ask for the admin password? Since people are used to doing this when installing apps, it comes second nature.. If people are willing to click through several steps of an installer app, they'll also type in the admin password if requested. This is only useful for other family members that you do not trust for safety reasons.

Right, but the point of this article is that it no longer needs the admin password. If you're running in a non-admin account (like I am), it'll still need the password, and thus user interaction, so it'll be trivial to stop.

Even without the password you still need user interaction, the user has to click next multiple times during install.
Post reply on HN